Jump to content

help with Random MSIE pages


Recommended Posts

You've heard it before. Several times a day I get bombarded with random website hits. They seem to get triggered when I open a google search, but also loads dozens of pages through the night. Previously, I have tried several different antivirus and malware programs which seem to slow it down for 24 hours or so, but then they start back up. I have followed your instructions which has brought me to this point and am attaching the logs as requested. The attach.txt file and ark.txt files have been zipped and attached to this post as attach.zip Thanks in advance for your help.

Malwarebytes' Anti-Malware 1.46

www.malwarebytes.org

Database version: 5014

Windows 5.1.2600 Service Pack 3

Internet Explorer 8.0.6001.18702

11/3/2010 7:26:35 PM

mbam-log-2010-11-03 (19-26-35).txt

Scan type: Full scan (C:\|)

Objects scanned: 364963

Time elapsed: 1 hour(s), 1 minute(s), 29 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

(No malicious items detected)

DDS (Ver_10-11-08.01) - NTFSx86

Run by Jim at 11:46:29.78 on Mon 11/08/2010

Internet Explorer: 8.0.6001.18702

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3061.2128 [GMT -7:00]

AV: Norton Internet Security *On-access scanning enabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}

FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch

svchost.exe

C:\WINDOWS\System32\svchost.exe -k netsvcs

svchost.exe

svchost.exe

C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

svchost.exe

C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe

C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe

C:\Program Files\PDF Suite 2010\ConversionService.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

C:\WINDOWS\system32\igfxpers.exe

C:\WINDOWS\system32\igfxsrvc.exe

C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe

C:\Program Files\Analog Devices\Core\smax4pnp.exe

C:\Program Files\Common Files\AOL\1286184261\ee\AOLSoftware.exe

C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe

C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe

C:\Program Files\dvd43\dvd43_tray.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe

C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe

C:\WINDOWS\system32\dllhost.exe

C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe

C:\WINDOWS\system32\NOTEPAD.EXE

C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE

C:\Program Files\AOL 9.0b\waol.exe

C:\Program Files\AOL 9.0b\shellmon.exe

C:\Program Files\Common Files\AOL\Topspeed\3.0\aoltpsd3.exe

C:\Documents and Settings\Jim\Desktop\777hhvd4.exe

C:\WINDOWS\System32\vssvc.exe

C:\WINDOWS\system32\dllhost.exe

C:\Documents and Settings\Jim\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = about:blank

uInternet Connection Wizard,ShellNext = "c:\program files\outlook express\msimn.exe"

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll

BHO: PDF Suite Helper: {1ad61d5b-58a3-4592-9b34-dc84688ff805} - c:\program files\pdf suite 2010\PDFIEHelper.dll

BHO: IsoBuster Toolbar: {266fcdca-7bb3-4da7-b3bf-f845dea2ebd6} - c:\program files\isobuster\tbIso1.dll

BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll

BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton internet security\norton internet security\engine\18.1.0.37\coIEPlg.dll

BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton internet security\norton internet security\engine\18.1.0.37\IPSBHO.DLL

BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll

BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll

BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll

BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5805.1910\swg.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll

TB: PDF Suite Toolbar: {261f6a8b-7aaf-4bf5-8552-6610f4d67819} - c:\program files\pdf suite 2010\PDFIEPlugin.dll

TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton internet security\norton internet security\engine\18.1.0.37\coIEPlg.dll

TB: IsoBuster Toolbar: {266fcdca-7bb3-4da7-b3bf-f845dea2ebd6} - c:\program files\isobuster\tbIso1.dll

TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll

TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File

TB: {851552F5-B878-4B03-904F-2AD6A4CC8994} - No File

uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe

uRun: [AOL Fast Start] "c:\program files\aol 9.0b\AOL.EXE" -b

uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background

uRun: [yDecode] c:\program files\ydecode\yDecode.exe

uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"

uRun: [spybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe

mRun: [igfxTray] c:\windows\system32\igfxtray.exe

mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe

mRun: [Persistence] c:\windows\system32\igfxpers.exe

mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"

mRun: [soundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe

mRun: [HostManager] c:\program files\common files\aol\1286184261\ee\AOLSoftware.exe

mRun: [Carbonite Backup] c:\program files\carbonite\carbonite backup\CarboniteUI.exe

mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"

mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"

mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"

mRun: [switchBoard] c:\program files\common files\adobe\switchboard\SwitchBoard.exe

mRun: [AdobeCS5ServiceManager] "c:\program files\common files\adobe\cs5servicemanager\CS5ServiceManager.exe" -launchedbylogin

mRun: [yDecode] c:\program files\ydecode\yDecode.exe

mRun: [dvd43] c:\program files\dvd43\dvd43_tray.exe

StartupFolder: c:\docume~1\jim\startm~1\programs\startup\limewi~1.lnk - c:\program files\limewire\LimeWire.exe

StartupFolder: c:\docume~1\jim\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE

StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\quickb~1.lnk - c:\program files\common files\intuit\quickbooks\qbupdate\qbupdate.exe

IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe

IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe

IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL

IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll

DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab

DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} - hxxp://picture.vzw.com/activex/VerizonWirelessUploadControl.cab

DPF: {CF4A2C45-CB89-4018-94BB-C2CACB83A537} - hxxps://www.myremotemanager.com/myrm/device/xancamx.ocx

DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

TCP: {600AAE40-FB2E-49AB-B088-41C29A750534} = 72.19.128.53,72.19.128.99

Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll

Notify: igfxcui - igfxdev.dll

SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll

Hosts: 127.0.0.1 www.spywareinfo.com

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\jim\applic~1\mozilla\firefox\profiles\po7mzqvu.default\

FF - prefs.js: browser.search.selectedEngine - Google

FF - prefs.js: browser.startup.homepage -

FF - component: c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_18.1.0.37\coffplgn\components\coFFPlgn.dll

FF - component: c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_18.1.0.37\ipsffplgn\components\IPSFFPl.dll

FF - component: c:\documents and settings\jim\application data\mozilla\firefox\profiles\po7mzqvu.default\extensions\{ad55c869-668e-457c-b270-0cfb2f61116f}\components\FFExternalAlert.dll

FF - component: c:\documents and settings\jim\application data\mozilla\firefox\profiles\po7mzqvu.default\extensions\{ad55c869-668e-457c-b270-0cfb2f61116f}\components\RadioWMPCore.dll

FF - component: c:\program files\pdf suite 2010\firefoxextension\components\FFPDFConverter.dll

FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll

FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll

FF - plugin: c:\program files\nos\bin\np_gp.dll

FF - plugin: c:\program files\pdf suite 2010\firefoxextension\plugins\NPPdfExt.dll

FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}

FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----

c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);

c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);

============= SERVICES / DRIVERS ===============

R0 O1394B;OW 1394b Bus Filter Service;c:\windows\system32\drivers\o1394b.sys [2010-10-15 10112]

R0 SFAUDIO;Sonic Focus DSP Driver;c:\windows\system32\drivers\sfaudio.sys [2010-10-3 24064]

R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\nis\1201000.025\SymDS.sys [2010-10-12 339504]

R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nis\1201000.025\SymEFA.sys [2010-10-12 666672]

R1 BHDrvx86;BHDrvx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_18.1.0.37\definitions\bashdefs\20101029.001\BHDrvx86.sys [2010-11-1 692272]

R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\nis\1201000.025\Ironx86.sys [2010-10-12 134704]

R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2010-9-23 1375992]

R2 NIS;Norton Internet Security;c:\program files\norton internet security\norton internet security\engine\18.1.0.37\ccSvcHst.exe [2010-10-12 126904]

R2 PDF Suite 2010 Service;PDF Suite 2010 Service;c:\program files\pdf suite 2010\ConversionService.exe [2010-9-28 791360]

R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-10-12 102448]

R3 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_18.1.0.37\definitions\ipsdefs\20101104.004\IDSXpx86.sys [2010-10-19 341880]

R3 k57w2k;Broadcom NetLink Gigabit Ethernet;c:\windows\system32\drivers\k57xp32.sys [2010-10-3 176640]

R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\lavasoft\ad-aware\kernexplorer.sys [2010-9-23 15264]

R3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_18.1.0.37\definitions\virusdefs\20101108.002\NAVENG.SYS [2010-11-8 86064]

R3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_18.1.0.37\definitions\virusdefs\20101108.002\NAVEX15.SYS [2010-11-8 1371184]

S0 cerc6;cerc6; [x]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]

S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-10-9 136176]

S3 SwitchBoard;Adobe SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096]

S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]

=============== Created Last 30 ================

2010-11-08 00:19:10 43952 ----a-r- c:\windows\system32\drivers\SymIM.sys

2010-11-07 22:56:35 -------- d-----w- c:\program files\active ports

2010-11-07 22:51:30 49664 ----a-w- c:\windows\unvise32.exe

2010-11-07 21:49:46 24983 ----a-w- c:\windows\system32\21494682841.dll

2010-11-06 14:32:43 98392 ----a-w- c:\windows\system32\drivers\SBREDrv.sys

2010-11-05 19:30:39 -------- d-----w- c:\docume~1\jim\applic~1\CopyToDvd

2010-11-05 19:27:44 -------- d-----w- c:\docume~1\jim\locals~1\applic~1\ApplicationHistory

2010-11-05 19:27:18 -------- d-----w- c:\program files\Lantronix

2010-11-05 19:26:18 -------- d-----w- c:\windows\system32\URTTEMP

2010-11-05 19:18:51 -------- d-----w- C:\e74ce0d18378dfb83afaf1e93c276606

2010-11-03 16:56:37 15880 ----a-w- c:\windows\system32\lsdelete.exe

2010-11-03 14:14:48 -------- d-----w- c:\docume~1\jim\locals~1\applic~1\Sunbelt Software

2010-11-03 14:14:16 -------- dc-h--w- c:\docume~1\alluse~1\applic~1\{E961CE1B-C3EA-4882-9F67-F859B555D097}

2010-11-03 14:14:03 -------- d-----w- c:\program files\Lavasoft

2010-11-01 14:27:08 -------- d-----w- c:\docume~1\jim\applic~1\Malwarebytes

2010-11-01 14:27:01 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-11-01 14:27:00 20952 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-11-01 14:27:00 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2010-11-01 14:27:00 -------- d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes

2010-11-01 08:43:40 -------- d-----w- c:\program files\trend micro

2010-10-31 00:28:32 -------- d-----w- c:\program files\common files\Data

2010-10-31 00:26:27 197632 ----a-w- c:\program files\common files\OnlineFilesManager.dll

2010-10-27 21:41:59 43264 ----a-r- c:\windows\system32\drivers\ser2pl.sys

2010-10-27 15:49:07 -------- d-----w- c:\docume~1\jim\locals~1\applic~1\Microsoft Help

2010-10-27 15:43:50 -------- d-----w- c:\docume~1\jim\locals~1\applic~1\PCHealth

2010-10-26 22:01:19 -------- d-----w- c:\windows\system32\NtmsData

2010-10-24 10:59:48 -------- d-----w- c:\docume~1\alluse~1\applic~1\vsosdk

2010-10-19 14:56:03 -------- d-----w- c:\docume~1\jim\applic~1\Office Genuine Advantage

2010-10-19 09:05:22 -------- d-----w- c:\windows\system32\XPSViewer

2010-10-19 09:04:49 89088 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll

2010-10-19 09:04:35 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll

2010-10-19 09:04:35 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe

2010-10-19 09:04:35 597504 ------w- c:\windows\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

2010-10-19 09:04:35 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll

2010-10-19 09:04:35 575488 ------w- c:\windows\system32\xpsshhdr.dll

2010-10-19 09:04:35 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll

2010-10-19 09:04:35 1676288 ------w- c:\windows\system32\xpssvcs.dll

2010-10-19 09:04:35 117760 ------w- c:\windows\system32\prntvpt.dll

2010-10-19 09:04:35 -------- d-----w- C:\9000a4901a3e329d7f

2010-10-18 20:24:58 -------- d-----w- c:\docume~1\jim\applic~1\StageManager.BD092818F67280F4B42B04877600987F0111B594.1

2010-10-18 20:24:58 -------- d-----w- c:\docume~1\jim\applic~1\Adobe Mini Bridge CS5

2010-10-18 17:12:21 -------- d-----w- c:\docume~1\jim\applic~1\PDF Software

2010-10-17 17:43:27 -------- d--h--w- C:\BJPrinter

2010-10-17 07:39:27 -------- d-----w- c:\docume~1\jim\locals~1\applic~1\Temp

2010-10-16 06:50:09 -------- d-----w- c:\docume~1\jim\locals~1\applic~1\Conduit

2010-10-16 06:47:36 -------- d-----w- c:\docume~1\jim\locals~1\applic~1\IsoBuster

2010-10-16 06:47:35 -------- d-----w- c:\program files\IsoBuster

2010-10-16 06:38:59 -------- d-----w- c:\docume~1\alluse~1\applic~1\1Click DVD Copy

2010-10-16 01:01:19 43904 -c--a-w- c:\windows\system32\dllcache\sbp2port.sys

2010-10-16 01:01:19 43904 ----a-w- c:\windows\system32\drivers\sbp2port.sys

2010-10-16 00:44:51 10112 ----a-w- c:\windows\system32\drivers\o1394b.sys

2010-10-16 00:44:51 -------- d-----w- c:\windows\drivers

2010-10-15 10:31:38 18816 ----a-w- c:\windows\system32\drivers\dvd43llh.sys

2010-10-15 05:44:55 25856 -c--a-w- c:\windows\system32\dllcache\usbprint.sys

2010-10-15 05:44:55 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys

2010-10-15 05:42:24 7680 ----a-w- c:\windows\system32\CNMVS5p.DLL

2010-10-15 05:42:24 50176 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\CNMPP5p.DLL

2010-10-15 05:42:24 17920 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\CNMPD5p.DLL

2010-10-15 05:42:24 113152 ----a-w- c:\windows\system32\CNMLM5p.DLL

2010-10-15 05:42:22 86016 ----a-w- c:\windows\system32\CNMCP5p.exe

2010-10-14 06:25:48 1024 ---h--r- c:\windows\system32\NTIDBD32.dll

2010-10-14 06:25:20 1024 ---h--r- c:\windows\system32\NTIBUN4.dll

2010-10-14 06:24:49 692224 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\iKernel.dll

2010-10-14 06:24:49 57344 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\ctor.dll

2010-10-14 06:24:49 5632 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\DotNetInstaller.exe

2010-10-14 06:24:49 237568 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\iscript.dll

2010-10-14 06:24:49 155648 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\iuser.dll

2010-10-14 06:24:48 163972 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\iGdi.dll

2010-10-14 06:24:47 282756 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\setup.dll

2010-10-14 06:24:45 226816 ------w- c:\windows\system32\htvcdsvcd.ax

2010-10-14 06:24:09 1024 ---h--r- c:\windows\system32\NTIMPEG2.dll

2010-10-14 06:24:09 1024 ---h--r- c:\windows\system32\NTIFCD3.dll

2010-10-14 06:24:09 1024 ---h--r- c:\windows\system32\NTICDMK7.dll

2010-10-14 06:24:04 6912 ----a-w- c:\windows\system32\drivers\NTIDrvr.sys

2010-10-14 06:14:31 87608 ----a-w- c:\docume~1\jim\applic~1\inst.exe

2010-10-14 06:14:31 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys

2010-10-14 06:14:31 47360 ----a-w- c:\docume~1\jim\applic~1\pcouffin.sys

2010-10-14 06:14:24 102439 ----a-w- c:\windows\system32\sipr3260.dll

2010-10-14 06:14:23 65602 ----a-w- c:\windows\system32\cook3260.dll

2010-10-14 06:14:23 626688 ----a-w- c:\windows\system32\vp7vfw.dll

2010-10-14 06:14:23 217127 ----a-w- c:\windows\system32\drv43260.dll

2010-10-14 06:14:23 208935 ----a-w- c:\windows\system32\drv33260.dll

2010-10-14 06:14:23 176165 ----a-w- c:\windows\system32\drv23260.dll

2010-10-14 03:04:59 -------- d-----w- c:\program files\Duplicate Finder

2010-10-14 01:11:45 -------- d-----w- c:\windows\system32\appmgmt

2010-10-14 00:12:49 665424 ----a-w- c:\windows\system32\wmv8dmoe.dll

2010-10-14 00:12:49 572752 ----a-w- c:\windows\system32\wmvdmoe.dll

2010-10-14 00:12:49 438608 ----a-w- c:\windows\system32\wmv8dmod.dll

2010-10-14 00:12:48 285184 ----a-w- c:\windows\system32\wmidx2.ocx

2010-10-14 00:12:48 1683792 ----a-w- c:\windows\system32\wmvcore2.dll

2010-10-13 23:33:34 -------- d-----w- c:\docume~1\jim\applic~1\Tific

2010-10-13 23:33:33 -------- d-----w- c:\docume~1\jim\locals~1\applic~1\Symantec

2010-10-13 21:26:38 1687625 ----a-w- c:\windows\system32\InetClnt.dll

2010-10-13 21:26:17 225280 ----a-w- c:\windows\system32\AWRTL30.DLL

2010-10-13 21:26:17 111616 ----a-w- c:\windows\system32\LTIH30TB.DLL

2010-10-13 21:21:24 -------- d-----w- c:\windows\Intuit

2010-10-13 21:21:20 212992 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\ILog.dll

2010-10-13 20:38:51 -------- d-----w- c:\docume~1\jim\applic~1\Easy Duplicate Finder

2010-10-13 20:38:50 -------- d-----w- c:\program files\Easy Duplicate Finder

2010-10-13 20:28:39 -------- d-----w- c:\docume~1\jim\applic~1\KompoZer

2010-10-13 20:27:29 -------- d-sh--w- c:\documents and settings\jim\IECompatCache

2010-10-13 20:25:59 -------- d-sh--w- c:\documents and settings\jim\PrivacIE

2010-10-13 20:25:50 -------- d-----w- c:\docume~1\jim\locals~1\applic~1\Google

2010-10-13 18:56:46 -------- d-----w- c:\program files\yEnc32

2010-10-13 18:51:59 -------- d-----w- c:\docume~1\jim\locals~1\applic~1\Mozilla

2010-10-13 18:24:26 -------- d-----w- c:\docume~1\jim\applic~1\Anthropics

2010-10-13 18:20:16 -------- d-----w- c:\docume~1\jim\locals~1\applic~1\WinZip

2010-10-13 17:49:22 -------- d-----w- c:\docume~1\jim\applic~1\uTorrent

2010-10-13 15:15:14 42368 -c--a-w- c:\windows\system32\dllcache\agp440.sys

2010-10-13 15:15:14 42368 ----a-w- c:\windows\system32\drivers\AGP440.SYS

2010-10-13 15:14:33 5504 -c--a-w- c:\windows\system32\dllcache\intelide.sys

2010-10-13 15:14:33 5504 ----a-w- c:\windows\system32\drivers\intelide.sys

2010-10-13 15:14:21 1897408 -c--a-w- c:\windows\system32\dllcache\nv4_mini.sys

2010-10-13 15:14:21 1897408 ----a-w- c:\windows\system32\drivers\nv4_mini.sys

2010-10-13 15:14:20 4274816 -c--a-w- c:\windows\system32\dllcache\nv4_disp.dll

2010-10-13 15:14:20 4274816 ----a-w- c:\windows\system32\nv4_disp.dll

2010-10-13 15:14:16 6400 -c--a-w- c:\windows\system32\dllcache\enum1394.sys

2010-10-13 15:14:16 6400 ----a-w- c:\windows\system32\drivers\enum1394.sys

2010-10-13 15:14:16 61696 -c--a-w- c:\windows\system32\dllcache\ohci1394.sys

2010-10-13 15:14:16 61696 ----a-w- c:\windows\system32\drivers\ohci1394.sys

2010-10-13 15:14:15 53376 -c--a-w- c:\windows\system32\dllcache\1394bus.sys

2010-10-13 15:14:15 53376 ----a-w- c:\windows\system32\drivers\1394bus.sys

2010-10-13 15:13:28 52480 -c--a-w- c:\windows\system32\dllcache\i8042prt.sys

2010-10-13 15:13:28 52480 ----a-w- c:\windows\system32\drivers\i8042prt.sys

2010-10-13 15:06:13 -------- d-----w- c:\docume~1\jim\locals~1\applic~1\Adobe

2010-10-13 15:05:17 -------- d-----w- c:\docume~1\jim\locals~1\applic~1\yDecode

2010-10-13 15:00:25 -------- d-----w- c:\docume~1\jim\applic~1\LimeWire

2010-10-13 14:58:44 -------- d-----w- c:\docume~1\jim\locals~1\applic~1\Identities

2010-10-13 14:35:44 -------- d-----w- c:\docume~1\jim\applic~1\AOL

2010-10-13 14:12:09 -------- d-----w- c:\docume~1\jim\locals~1\applic~1\PowerDVD DX

2010-10-13 09:37:11 2560 ----a-w- c:\docume~1\alluse~1\applic~1\microsoft\usmt\iconlib.dll

2010-10-13 07:44:44 -------- d-----w- c:\docume~1\alluse~1\applic~1\regid.1986-12.com.adobe

2010-10-13 03:40:05 -------- d-----w- c:\docume~1\alluse~1\applic~1\NortonInstaller

2010-10-13 00:22:26 274288 ----a-w- c:\windows\system32\mucltui.dll

2010-10-13 00:22:26 215920 ----a-w- c:\windows\system32\muweb.dll

2010-10-13 00:22:26 16736 ----a-w- c:\windows\system32\mucltui.dll.mui

2010-10-13 00:15:11 33104 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\msonpppr.dll

2010-10-13 00:15:11 32656 ----a-w- c:\windows\system32\msonpmon.dll

2010-10-13 00:12:28 -------- d-----w- c:\windows\SHELLNEW

2010-10-12 21:14:12 737280 ----a-w- c:\windows\iun6002.exe

2010-10-12 21:13:18 -------- d-----w- c:\program files\WYSIWYG Web Builder 7

==================== Find3M ====================

2010-10-13 03:41:56 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL

2010-10-04 22:09:56 423656 ----a-w- c:\windows\system32\deployJava1.dll

2010-09-18 18:23:26 974848 ----a-w- c:\windows\system32\mfc42u.dll

2010-09-18 06:53:25 974848 ----a-w- c:\windows\system32\mfc42.dll

2010-09-18 06:53:25 954368 ----a-w- c:\windows\system32\mfc40.dll

2010-09-18 06:53:25 953856 ----a-w- c:\windows\system32\mfc40u.dll

2010-09-10 05:58:08 916480 ----a-w- c:\windows\system32\wininet.dll

2010-09-10 05:58:06 43520 ----a-w- c:\windows\system32\licmgr10.dll

2010-09-10 05:58:06 1469440 ------w- c:\windows\system32\inetcpl.cpl

2010-09-01 11:51:14 285824 ----a-w- c:\windows\system32\atmfd.dll

2010-08-31 13:42:52 1852800 ----a-w- c:\windows\system32\win32k.sys

2010-08-27 08:02:29 119808 ----a-w- c:\windows\system32\t2embed.dll

2010-08-27 05:57:43 99840 ----a-w- c:\windows\system32\srvsvc.dll

2010-08-26 12:52:45 5120 ----a-w- c:\windows\system32\xpsp4res.dll

2010-08-23 16:12:04 617472 ----a-w- c:\windows\system32\comctl32.dll

2010-08-17 13:17:06 58880 ----a-w- c:\windows\system32\spoolsv.exe

2010-08-16 08:45:00 590848 ----a-w- c:\windows\system32\rpcrt4.dll

============= FINISH: 11:47:03.89 ===============

Attach.zip

Link to post
Share on other sites

Hi,

Download ComboFix from one of these locations:

Link 1

Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Here is a guide on how to disable them:
    Click me
    If you can't disable them then just continue on.
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

RcAuto1.gif

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

whatnext.png

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt log in your next reply.

Link to post
Share on other sites

ComboFix 10-11-12.06 - Jim 11/13/2010 10:07:34.1.2 - x86

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3061.2557 [GMT -7:00]

Running from: c:\documents and settings\Jim\Desktop\ComboFix.exe

AV: Norton Internet Security *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}

FW: Norton Internet Security *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

c:\documents and settings\Jim\Application Data\inst.exe

C:\ErrLog.txt

c:\program files\Search Toolbar

c:\program files\WinPCap

c:\program files\WinPCap\LICENSE

c:\windows\system32\15325643741.dll

.

((((((((((((((((((((((((( Files Created from 2010-10-13 to 2010-11-13 )))))))))))))))))))))))))))))))

.

2010-11-11 10:01 . 2010-11-11 10:01 -------- d-sh--w- c:\documents and settings\Default User\IETldCache

2010-11-08 21:39 . 2010-11-08 21:39 73728 ----a-w- c:\windows\system32\javacpl.cpl

2010-11-08 00:19 . 2010-07-22 01:27 43952 ----a-r- c:\windows\system32\drivers\SymIM.sys

2010-11-07 22:56 . 2010-11-08 16:14 -------- d-----w- c:\program files\active ports

2010-11-07 22:51 . 1999-12-17 17:13 49664 ----a-w- c:\windows\unvise32.exe

2010-11-07 20:07 . 2010-11-07 20:07 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache

2010-11-06 15:04 . 2010-11-06 15:04 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache

2010-11-06 14:32 . 2010-11-06 14:32 98392 ----a-w- c:\windows\system32\drivers\SBREDrv.sys

2010-11-05 19:30 . 2010-11-05 19:31 -------- d-----w- c:\documents and settings\Jim\Application Data\CopyToDvd

2010-11-05 19:27 . 2010-11-05 19:28 -------- d-----w- c:\documents and settings\Jim\Local Settings\Application Data\ApplicationHistory

2010-11-05 19:27 . 2010-11-05 19:27 -------- d-----w- c:\program files\Lantronix

2010-11-05 19:26 . 2010-11-05 19:26 -------- d-----w- c:\windows\system32\URTTEMP

2010-11-05 19:18 . 2010-11-05 19:24 -------- d-----w- C:\e74ce0d18378dfb83afaf1e93c276606

2010-11-03 16:56 . 2010-09-23 07:46 15880 ----a-w- c:\windows\system32\lsdelete.exe

2010-11-03 14:14 . 2010-11-03 14:14 -------- d-----w- c:\documents and settings\Jim\Local Settings\Application Data\Sunbelt Software

2010-11-03 14:14 . 2010-11-08 00:27 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{E961CE1B-C3EA-4882-9F67-F859B555D097}

2010-11-03 14:14 . 2010-11-03 14:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft

2010-11-03 14:14 . 2010-11-03 14:14 -------- d-----w- c:\program files\Lavasoft

2010-11-01 14:27 . 2010-11-01 14:27 -------- d-----w- c:\documents and settings\Jim\Application Data\Malwarebytes

2010-11-01 14:27 . 2010-04-29 21:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-11-01 14:27 . 2010-11-01 14:27 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2010-11-01 14:27 . 2010-11-01 14:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes

2010-11-01 14:27 . 2010-04-29 21:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-11-01 08:43 . 2010-11-01 08:43 -------- d-----w- C:\rsit

2010-11-01 08:43 . 2010-11-01 08:43 -------- d-----w- c:\program files\trend micro

2010-10-31 09:54 . 2008-04-14 07:00 26624 ----a-w- c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll

2010-10-31 09:39 . 2010-10-31 09:39 -------- d-----w- c:\windows\system32\drivers\UMDF

2010-10-31 00:28 . 2010-10-31 00:43 -------- d-----w- c:\program files\Common Files\Data

2010-10-31 00:26 . 2010-10-31 00:26 197632 ----a-w- c:\program files\Common Files\OnlineFilesManager.dll

2010-10-27 21:41 . 2003-07-16 09:27 43264 ----a-r- c:\windows\system32\drivers\ser2pl.sys

2010-10-27 15:49 . 2010-10-27 15:49 -------- d-----w- c:\documents and settings\Jim\Local Settings\Application Data\Microsoft Help

2010-10-27 15:43 . 2010-10-27 15:43 -------- d-----w- c:\documents and settings\Jim\Local Settings\Application Data\PCHealth

2010-10-26 22:01 . 2010-11-11 10:01 -------- d-----w- c:\windows\system32\NtmsData

2010-10-24 10:59 . 2010-10-24 10:59 -------- d-----w- c:\documents and settings\All Users\Application Data\vsosdk

2010-10-19 14:56 . 2010-10-19 14:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage

2010-10-19 14:56 . 2010-10-19 14:56 -------- d-----w- c:\documents and settings\Jim\Application Data\Office Genuine Advantage

2010-10-19 09:05 . 2010-10-19 09:05 -------- d-----w- c:\windows\system32\XPSViewer

2010-10-19 09:04 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll

2010-10-19 09:04 . 2010-10-19 09:04 -------- d-----w- C:\9000a4901a3e329d7f

2010-10-19 09:04 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll

2010-10-19 09:04 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll

2010-10-19 09:04 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll

2010-10-19 09:04 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll

2010-10-19 09:04 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll

2010-10-19 09:04 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll

2010-10-19 09:04 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe

2010-10-19 09:04 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe

2010-10-19 06:38 . 2010-10-24 06:14 -------- d-----w- c:\documents and settings\Jim\Application Data\vlc

2010-10-18 20:24 . 2010-10-18 20:24 -------- d-----w- c:\documents and settings\Jim\Application Data\StageManager.BD092818F67280F4B42B04877600987F0111B594.1

2010-10-18 20:24 . 2010-10-18 20:24 -------- d-----w- c:\documents and settings\Jim\Application Data\Adobe Mini Bridge CS5

2010-10-18 17:12 . 2010-10-18 17:12 -------- d-----w- c:\documents and settings\Jim\Application Data\PDF Software

2010-10-17 17:43 . 2010-10-17 17:43 -------- d-----w- C:\BJPrinter

2010-10-17 07:39 . 2010-10-23 08:44 -------- d-----w- c:\documents and settings\Jim\Local Settings\Application Data\Temp

2010-10-17 06:19 . 2010-11-06 15:04 -------- d-----w- c:\documents and settings\Jim\Application Data\FileZilla

2010-10-16 06:50 . 2010-10-17 06:51 -------- d-----w- c:\documents and settings\Jim\Local Settings\Application Data\Conduit

2010-10-16 06:47 . 2010-10-17 06:51 -------- d-----w- c:\documents and settings\Jim\Local Settings\Application Data\IsoBuster

2010-10-16 06:47 . 2010-11-03 16:56 -------- d-----w- c:\program files\IsoBuster

2010-10-16 06:47 . 2010-10-16 06:47 -------- d-----w- c:\program files\Smart Projects

2010-10-16 06:38 . 2010-10-30 22:08 -------- d-----w- c:\documents and settings\All Users\Application Data\1Click DVD Copy

2010-10-16 01:01 . 2008-04-14 06:10 43904 -c--a-w- c:\windows\system32\dllcache\sbp2port.sys

2010-10-16 01:01 . 2008-04-14 06:10 43904 ----a-w- c:\windows\system32\drivers\sbp2port.sys

2010-10-16 00:44 . 2010-10-16 00:44 -------- d-----w- c:\windows\drivers

2010-10-16 00:44 . 2004-10-15 15:58 10112 ----a-w- c:\windows\system32\drivers\o1394b.sys

2010-10-15 10:31 . 2010-10-15 10:31 18816 ----a-w- c:\windows\system32\drivers\dvd43llh.sys

2010-10-15 05:44 . 2008-04-14 06:17 25856 -c--a-w- c:\windows\system32\dllcache\usbprint.sys

2010-10-15 05:44 . 2008-04-14 06:17 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys

2010-10-15 05:42 . 2004-02-03 20:00 7680 ----a-w- c:\windows\system32\CNMVS5p.DLL

2010-10-15 05:42 . 2004-02-03 20:00 50176 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPP5p.DLL

2010-10-15 05:42 . 2004-02-03 20:00 17920 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPD5p.DLL

2010-10-15 05:42 . 2004-02-03 20:00 113152 ----a-w- c:\windows\system32\CNMLM5p.DLL

2010-10-15 05:42 . 2003-08-27 18:11 86016 ----a-w- c:\windows\system32\CNMCP5p.exe

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-11-08 21:39 . 2010-10-04 08:43 472808 ----a-w- c:\windows\system32\deployJava1.dll

2010-10-14 06:25 . 2010-10-14 06:24 6912 ----a-w- c:\windows\system32\drivers\NTIDrvr.sys

2010-10-14 06:14 . 2010-10-14 06:14 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys

2010-10-14 06:14 . 2010-10-14 06:14 47360 ----a-w- c:\documents and settings\Jim\Application Data\pcouffin.sys

2010-10-13 03:41 . 2010-10-13 03:41 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL

2010-10-13 03:41 . 2010-10-13 03:41 126512 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS

2010-10-12 23:58 . 2010-10-12 21:14 737280 ----a-w- c:\windows\iun6002.exe

2010-09-18 18:23 . 2008-04-14 07:00 974848 ----a-w- c:\windows\system32\mfc42u.dll

2010-09-18 06:53 . 2008-04-14 07:00 974848 ----a-w- c:\windows\system32\mfc42.dll

2010-09-18 06:53 . 2008-04-14 07:00 954368 ----a-w- c:\windows\system32\mfc40.dll

2010-09-18 06:53 . 2008-04-14 07:00 953856 ----a-w- c:\windows\system32\mfc40u.dll

2010-09-10 05:58 . 2008-04-14 07:00 916480 ----a-w- c:\windows\system32\wininet.dll

2010-09-10 05:58 . 2008-04-14 07:00 43520 ----a-w- c:\windows\system32\licmgr10.dll

2010-09-10 05:58 . 2008-04-14 07:00 1469440 ------w- c:\windows\system32\inetcpl.cpl

2010-09-01 11:51 . 2008-04-14 07:00 285824 ----a-w- c:\windows\system32\atmfd.dll

2010-08-31 13:42 . 2008-04-14 07:00 1852800 ----a-w- c:\windows\system32\win32k.sys

2010-08-27 08:02 . 2008-04-14 07:00 119808 ----a-w- c:\windows\system32\t2embed.dll

2010-08-27 05:57 . 2008-04-14 07:00 99840 ----a-w- c:\windows\system32\srvsvc.dll

2010-08-26 13:39 . 2008-04-14 07:00 357248 ----a-w- c:\windows\system32\drivers\srv.sys

2010-08-26 12:52 . 2010-10-04 06:28 5120 ----a-w- c:\windows\system32\xpsp4res.dll

2010-08-23 16:12 . 2008-04-14 07:00 617472 ----a-w- c:\windows\system32\comctl32.dll

2010-08-17 13:17 . 2008-04-14 07:00 58880 ----a-w- c:\windows\system32\spoolsv.exe

2010-08-16 08:45 . 2008-04-14 07:00 590848 ----a-w- c:\windows\system32\rpcrt4.dll

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1AD61D5B-58A3-4592-9B34-DC84688FF805}]

2010-09-29 00:13 107328 ----a-w- c:\program files\PDF Suite 2010\PDFIEHelper.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{266fcdca-7bb3-4da7-b3bf-f845dea2ebd6}]

2010-10-16 06:50 2735200 ----a-w- c:\program files\IsoBuster\tbIso1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

"{266fcdca-7bb3-4da7-b3bf-f845dea2ebd6}"= "c:\program files\IsoBuster\tbIso1.dll" [2010-10-16 2735200]

[HKEY_CLASSES_ROOT\clsid\{266fcdca-7bb3-4da7-b3bf-f845dea2ebd6}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]

"{266FCDCA-7BB3-4DA7-B3BF-F845DEA2EBD6}"= "c:\program files\IsoBuster\tbIso1.dll" [2010-10-16 2735200]

[HKEY_CLASSES_ROOT\clsid\{266fcdca-7bb3-4da7-b3bf-f845dea2ebd6}]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Green]

@="{95A27763-F62A-4114-9072-E81D87DE3B68}"

[HKEY_CLASSES_ROOT\CLSID\{95A27763-F62A-4114-9072-E81D87DE3B68}]

2010-09-21 01:25 731280 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Partial]

@="{E300CD91-100F-4E67-9AF3-1384A6124015}"

[HKEY_CLASSES_ROOT\CLSID\{E300CD91-100F-4E67-9AF3-1384A6124015}]

2010-09-21 01:25 731280 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Yellow]

@="{5E529433-B50E-4bef-A63B-16A6B71B071A}"

[HKEY_CLASSES_ROOT\CLSID\{5E529433-B50E-4bef-A63B-16A6B71B071A}]

2010-09-21 01:25 731280 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Online Files]

@="{B82655E9-B81D-4A97-8154-0D84A4C048E4}"

[HKEY_CLASSES_ROOT\CLSID\{B82655E9-B81D-4A97-8154-0D84A4C048E4}]

2010-10-31 00:26 197632 ----a-w- c:\program files\Common Files\OnlineFilesManager.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"AOL Fast Start"="c:\program files\AOL 9.0b\AOL.EXE" [2007-02-06 50736]

"yDecode"="c:\program files\yDecode\yDecode.exe" [2006-09-08 704008]

"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-10-10 39408]

"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-08-18 150040]

"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-08-18 170520]

"Persistence"="c:\windows\system32\igfxpers.exe" [2008-08-18 141848]

"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2009-04-02 128232]

"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2009-06-22 1044480]

"HostManager"="c:\program files\Common Files\AOL\1286184261\ee\AOLSoftware.exe" [2006-09-26 50736]

"Carbonite Backup"="c:\program files\Carbonite\Carbonite Backup\CarboniteUI.exe" [2010-09-21 913552]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]

"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]

"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]

"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]

"yDecode"="c:\program files\yDecode\yDecode.exe" [2006-09-08 704008]

"dvd43"="c:\program files\dvd43\dvd43_tray.exe" [2009-10-24 827904]

"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]

c:\documents and settings\Jim\Start Menu\Programs\Startup\

LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2010-9-30 503808]

OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

c:\documents and settings\All Users\Start Menu\Programs\Startup\

QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2010-10-13 663552]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=

"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=

"c:\\Program Files\\AOL 9.0b\\waol.exe"=

"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=

"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=

"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=

"c:\\Program Files\\yDecode\\yDecode.exe"=

"c:\\Program Files\\uTorrent\\uTorrent.exe"=

"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=

"c:\\Program Files\\LimeWire\\LimeWire.exe"=

"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=

"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=

R0 O1394B;OW 1394b Bus Filter Service;c:\windows\system32\drivers\o1394b.sys [10/15/2010 5:44 PM 10112]

R0 SFAUDIO;Sonic Focus DSP Driver;c:\windows\system32\drivers\sfaudio.sys [10/3/2010 11:23 PM 24064]

R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NIS\1201000.025\SymDS.sys [10/12/2010 8:41 PM 339504]

R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1201000.025\SymEFA.sys [10/12/2010 8:41 PM 666672]

R1 BHDrvx86;BHDrvx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20101104.001\BHDrvx86.sys [11/3/2010 5:07 PM 691248]

R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NIS\1201000.025\Ironx86.sys [10/12/2010 8:41 PM 134704]

R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [9/23/2010 12:46 AM 1375992]

R2 NIS;Norton Internet Security;c:\program files\Norton Internet Security\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe [10/12/2010 8:41 PM 126904]

R2 PDF Suite 2010 Service;PDF Suite 2010 Service;c:\program files\PDF Suite 2010\ConversionService.exe [9/28/2010 5:13 PM 791360]

R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [10/12/2010 8:41 PM 102448]

R3 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20101112.001\IDSXpx86.sys [10/19/2010 1:36 PM 341880]

R3 k57w2k;Broadcom NetLink Gigabit Ethernet;c:\windows\system32\drivers\k57xp32.sys [10/3/2010 11:06 PM 176640]

S0 cerc6;cerc6; [x]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 12:16 PM 130384]

S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [10/9/2010 9:54 PM 136176]

S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\kernexplorer.sys [9/23/2010 12:46 AM 15264]

S3 SwitchBoard;Adobe SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2/19/2010 12:37 PM 517096]

S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 12:16 PM 753504]

.

Contents of the 'Scheduled Tasks' folder

2010-11-13 c:\windows\Tasks\Ad-Aware Update (Weekly).job

- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-09-23 14:32]

2010-11-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cb6dce7ba088c0.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-10 04:54]

2010-11-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA1cb6dce7bc6ae60.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-10 04:54]

2010-11-13 c:\windows\Tasks\OGALogon.job

- c:\windows\system32\OGAEXEC.exe [2009-08-03 21:07]

.

.

------- Supplementary Scan -------

.

uStart Page = about:blank

uInternet Connection Wizard,ShellNext = "c:\program files\Outlook Express\msimn.exe"

TCP: {600AAE40-FB2E-49AB-B088-41C29A750534} = 72.19.128.53,72.19.128.99

DPF: {CF4A2C45-CB89-4018-94BB-C2CACB83A537} - hxxps://www.myremotemanager.com/myrm/device/xancamx.ocx

FF - ProfilePath - c:\documents and settings\Jim\Application Data\Mozilla\Firefox\Profiles\po7mzqvu.default\

FF - prefs.js: browser.search.selectedEngine - Google

FF - prefs.js: browser.startup.homepage -

FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\coFFPlgn\components\coFFPlgn.dll

FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\IPSFFPlgn\components\IPSFFPl.dll

FF - component: c:\documents and settings\Jim\Application Data\Mozilla\Firefox\Profiles\po7mzqvu.default\extensions\{ad55c869-668e-457c-b270-0cfb2f61116f}\components\FFExternalAlert.dll

FF - component: c:\documents and settings\Jim\Application Data\Mozilla\Firefox\Profiles\po7mzqvu.default\extensions\{ad55c869-668e-457c-b270-0cfb2f61116f}\components\RadioWMPCore.dll

FF - component: c:\program files\PDF Suite 2010\firefoxextension\components\FFPDFConverter.dll

FF - plugin: c:\documents and settings\Jim\Application Data\Mozilla\Firefox\Profiles\po7mzqvu.default\extensions\LogMeInClient@logmein.com\plugins\npRACtrl.dll

FF - plugin: c:\program files\Google\Update\1.2.183.39\npGoogleOneClick8.dll

FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll

FF - plugin: c:\program files\PDF Suite 2010\firefoxextension\plugins\NPPdfExt.dll

FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);

.

- - - - ORPHANS REMOVED - - - -

WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)

WebBrowser-{851552F5-B878-4B03-904F-2AD6A4CC8994} - (no file)

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2010-11-13 10:15

Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NIS]

"ImagePath"="\"c:\program files\Norton Internet Security\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files\Norton Internet Security\Norton Internet Security\Engine\18.1.0.37\diMaster.dll\" /prefetch:1"

.

--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]

"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]

@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]

@Denied: (A 2) (Everyone)

@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

Completion time: 2010-11-13 10:16:35

ComboFix-quarantined-files.txt 2010-11-13 17:16

ComboFix2.txt 2008-02-09 04:56

Pre-Run: 792,742,346,752 bytes free

Post-Run: 793,670,361,088 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

UnsupportedDebug="do not select this" /debug

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - 6239EF7AD743C5932D4060F2C78EC7F7

Link to post
Share on other sites

Hi,

Open notepad by going to Start > Run and type notepad.exe in the box that appears. In the window that pops up please copy and paste the following:

@echo off

>Router_Log_Gammo.txt (

ipconfig /all

nslookup google.com

nslookup yahoo.com

ping -n 2 google.com

ping -n 2 yahoo.com

route print

)

start Router_Log_Gammo.txt

del %0

In Notepad click on the "File" menu > Save As...

Under "File name" type Router_Gammo.bat

Change "Save as type" to All Files

Save it to your Desktop

Double click on Router_Gammo.bat. It will open a notepad windows. Please post the contents of this file in your next reply.

Link to post
Share on other sites

Windows IP Configuration

Host Name . . . . . . . . . . . . : desk

Primary Dns Suffix . . . . . . . :

Node Type . . . . . . . . . . . . : Unknown

IP Routing Enabled. . . . . . . . : No

WINS Proxy Enabled. . . . . . . . : No

Ethernet adapter Local Area Connection:

Connection-specific DNS Suffix . :

Description . . . . . . . . . . . : Broadcom NetLink Gigabit Ethernet

Physical Address. . . . . . . . . : 00-25-64-B4-E4-28

Dhcp Enabled. . . . . . . . . . . : No

IP Address. . . . . . . . . . . . : 72.19.172.49

Subnet Mask . . . . . . . . . . . : 255.255.255.128

Default Gateway . . . . . . . . . : 72.19.172.1

DNS Servers . . . . . . . . . . . : 72.19.128.53

72.19.128.99

Server: ns7.skybeam.com

Address: 72.19.128.53

Name: google.com

Addresses: 209.85.225.103, 209.85.225.104, 209.85.225.105, 209.85.225.106

209.85.225.147, 209.85.225.99

Server: ns7.skybeam.com

Address: 72.19.128.53

Name: yahoo.com

Addresses: 67.195.160.76, 69.147.125.65, 72.30.2.43, 98.137.149.56

209.191.122.70

Pinging google.com [74.125.95.106] with 32 bytes of data:

Reply from 74.125.95.106: bytes=32 time=43ms TTL=52

Reply from 74.125.95.106: bytes=32 time=44ms TTL=52

Ping statistics for 74.125.95.106:

Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

Minimum = 43ms, Maximum = 44ms, Average = 43ms

Pinging yahoo.com [98.137.149.56] with 32 bytes of data:

Reply from 98.137.149.56: bytes=32 time=58ms TTL=50

Reply from 98.137.149.56: bytes=32 time=58ms TTL=50

Ping statistics for 98.137.149.56:

Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

Minimum = 58ms, Maximum = 58ms, Average = 58ms

===========================================================================

Interface List

0x1 ........................... MS TCP Loopback interface

0x2 ...00 25 64 b4 e4 28 ...... Broadcom NetLink Gigabit Ethernet - Packet Scheduler Miniport

===========================================================================

===========================================================================

Active Routes:

Network Destination Netmask Gateway Interface Metric

0.0.0.0 0.0.0.0 72.19.172.1 72.19.172.49 20

72.19.172.0 255.255.255.128 72.19.172.49 72.19.172.49 20

72.19.172.49 255.255.255.255 127.0.0.1 127.0.0.1 20

72.255.255.255 255.255.255.255 72.19.172.49 72.19.172.49 20

127.0.0.0 255.0.0.0 127.0.0.1 127.0.0.1 1

224.0.0.0 240.0.0.0 72.19.172.49 72.19.172.49 20

255.255.255.255 255.255.255.255 72.19.172.49 72.19.172.49 1

Default Gateway: 72.19.172.1

===========================================================================

Persistent Routes:

None

Hi,

Open notepad by going to Start > Run and type notepad.exe in the box that appears. In the window that pops up please copy and paste the following:

In Notepad click on the "File" menu > Save As...

Under "File name" type Router_Gammo.bat

Change "Save as type" to All Files

Save it to your Desktop

Double click on Router_Gammo.bat. It will open a notepad windows. Please post the contents of this file in your next reply.

Link to post
Share on other sites

After reviewing my actions in the last step requested, I realized that I did not follow your directions correctly. Here in the correct log as requested. There do seem to be some differences.

Windows IP Configuration

Host Name . . . . . . . . . . . . : desk

Primary Dns Suffix . . . . . . . :

Node Type . . . . . . . . . . . . : Unknown

IP Routing Enabled. . . . . . . . : No

WINS Proxy Enabled. . . . . . . . : No

Ethernet adapter Local Area Connection:

Connection-specific DNS Suffix . :

Description . . . . . . . . . . . : Broadcom NetLink Gigabit Ethernet

Physical Address. . . . . . . . . : 00-25-64-B4-E4-28

Dhcp Enabled. . . . . . . . . . . : No

IP Address. . . . . . . . . . . . : 72.19.172.49

Subnet Mask . . . . . . . . . . . : 255.255.255.128

Default Gateway . . . . . . . . . : 72.19.172.1

DNS Servers . . . . . . . . . . . : 72.19.128.53

72.19.128.99

Server: ns7.skybeam.com

Address: 72.19.128.53

Name: google.com

Addresses: 209.85.225.99, 209.85.225.103, 209.85.225.104, 209.85.225.105

209.85.225.106, 209.85.225.147

Server: ns7.skybeam.com

Address: 72.19.128.53

Name: yahoo.com

Addresses: 67.195.160.76, 69.147.125.65, 72.30.2.43, 98.137.149.56

209.191.122.70

Pinging google.com [74.125.95.147] with 32 bytes of data:

Reply from 74.125.95.147: bytes=32 time=43ms TTL=52

Reply from 74.125.95.147: bytes=32 time=44ms TTL=52

Ping statistics for 74.125.95.147:

Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

Minimum = 43ms, Maximum = 44ms, Average = 43ms

Pinging yahoo.com [98.137.149.56] with 32 bytes of data:

Reply from 98.137.149.56: bytes=32 time=59ms TTL=50

Reply from 98.137.149.56: bytes=32 time=58ms TTL=50

Ping statistics for 98.137.149.56:

Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

Minimum = 58ms, Maximum = 59ms, Average = 58ms

===========================================================================

Interface List

0x1 ........................... MS TCP Loopback interface

0x2 ...00 25 64 b4 e4 28 ...... Broadcom NetLink Gigabit Ethernet - Packet Scheduler Miniport

===========================================================================

===========================================================================

Active Routes:

Network Destination Netmask Gateway Interface Metric

0.0.0.0 0.0.0.0 72.19.172.1 72.19.172.49 20

72.19.172.0 255.255.255.128 72.19.172.49 72.19.172.49 20

72.19.172.49 255.255.255.255 127.0.0.1 127.0.0.1 20

72.255.255.255 255.255.255.255 72.19.172.49 72.19.172.49 20

127.0.0.0 255.0.0.0 127.0.0.1 127.0.0.1 1

224.0.0.0 240.0.0.0 72.19.172.49 72.19.172.49 20

255.255.255.255 255.255.255.255 72.19.172.49 72.19.172.49 1

Default Gateway: 72.19.172.1

===========================================================================

Persistent Routes:

None

Link to post
Share on other sites

Hi,

Download TFC to your desktop

  • Open the file and close any other windows.
  • It will close all programs itself when run, make sure to let it run uninterrupted.
  • Click the Start button to begin the process. The program should not take long to finish its job
  • Once its finished it should reboot your machine, if not, do this yourself to ensure a complete clean

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Start Malwarebytes' Anti-Malware

  • Once the program has loaded, click the "Update" tab and click the "Check For updates" button.
  • Once the updates were downloaded, click the "Scanner" tab, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

I'd like us to scan your machine with ESET OnlineScan

  1. Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  2. Click the esetOnline.png button.
  3. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

    1. Click on esetSmartInstall.png to download the ESET Smart Installer. Save it to your desktop.
    2. Double click on the esetSmartInstallDesktopIcon.png icon on your desktop.

    3. Check esetAcceptTerms.png
    4. Click the esetStart.png button.
    5. Accept any security warnings from your browser.
    6. Check esetScanArchives.png
    7. Push the Start button.
    8. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    9. When the scan completes, push esetListThreats.png
    10. Push esetExport.png, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    11. Push the esetBack.png button.
    12. Push esetFinish.png


      Please also tell me if the problem is resolved after following the steps above.
Link to post
Share on other sites

It is Sunday night about 12:30 am and I haven't experienced an attach since I ran ComboFix which removed the following files unidentified by the other programs. To recap, it removed the following:

c:\documents and settings\Jim\Application Data\inst.exe

C:\ErrLog.txt

c:\program files\Search Toolbar

c:\program files\WinPCap

c:\program files\WinPCap\LICENSE

c:\windows\system32\15325643741.dll

If you would like me to run your latest requests, I will....and/or I will also report if I experience any more attacks, but as of right now, I have about about 36 hours of the system on line without incident. Previously, this meant about 75 or more web sites stacked up which I would have to delete. If you are familiar with this exploit, could you explain how it works? Thanks so very much for your help.

Jim

Hi,

Download TFC to your desktop

  • Open the file and close any other windows.
  • It will close all programs itself when run, make sure to let it run uninterrupted.
  • Click the Start button to begin the process. The program should not take long to finish its job
  • Once its finished it should reboot your machine, if not, do this yourself to ensure a complete clean

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Start Malwarebytes' Anti-Malware

  • Once the program has loaded, click the "Update" tab and click the "Check For updates" button.
  • Once the updates were downloaded, click the "Scanner" tab, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

I'd like us to scan your machine with ESET OnlineScan

  1. Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  2. Click the esetOnline.png button.
  3. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

    1. Click on esetSmartInstall.png to download the ESET Smart Installer. Save it to your desktop.
    2. Double click on the esetSmartInstallDesktopIcon.png icon on your desktop.

    3. Check esetAcceptTerms.png
    4. Click the esetStart.png button.
    5. Accept any security warnings from your browser.
    6. Check esetScanArchives.png
    7. Push the Start button.
    8. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    9. When the scan completes, push esetListThreats.png
    10. Push esetExport.png, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    11. Push the esetBack.png button.
    12. Push esetFinish.png


      Please also tell me if the problem is resolved after following the steps above.
Link to post
Share on other sites

Good morning. After running MBAM and ESET, I am still getting the phantom web hits. Interesting, there were no hits over the weekend at all. Then this morning, when I opened MSIE, it all started again. They come in bursts 20 or 30 per burst every 30 minutes or so. If I close MSIE, they stop, but seem to stack up somewhere, so when I open it again, the backlog of hits immediately dump. I'm also getting HAMMERED by intrusion attempts this morning that Norton is blocking.

Here's the logs as requested.

Eset:

C:\Documents and Settings\Jim\Desktop\Sound and Videos\Top of Charts - 2003 (animusic).wma WMA/TrojanDownloader.Wimad.K trojan cleaned by deleting - quarantined

MBAM:

Malwarebytes' Anti-Malware 1.46

www.malwarebytes.org

Database version: 5127

Windows 5.1.2600 Service Pack 3

Internet Explorer 8.0.6001.18702

11/16/2010 8:21:56 AM

mbam-log-2010-11-16 (08-21-56).txt

Scan type: Quick scan

Objects scanned: 153086

Time elapsed: 4 minute(s), 19 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

(No malicious items detected)

Link to post
Share on other sites

Hi,

Please delete your copy of ComboFix.exe from the desktop.

Then download the latest version of ComboFix from one of these locations:

Link 1

Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Here is a guide on how to disable them:
    Click me
    If you can't disable them then just continue on.
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

RcAuto1.gif

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

whatnext.png

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt log in your next reply.

Link to post
Share on other sites

ComboFix 10-11-15.06 - Jim 11/16/2010 13:12:08.4.2 - x86

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3061.2577 [GMT -7:00]

Running from: c:\documents and settings\Jim\Desktop\ComboFix.exe

AV: Norton Internet Security *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}

FW: Norton Internet Security *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

c:\windows\system32\16512379641.dll

.

((((((((((((((((((((((((( Files Created from 2010-10-16 to 2010-11-16 )))))))))))))))))))))))))))))))

.

2010-11-16 15:27 . 2010-11-16 15:27 -------- d-----w- c:\program files\ESET

2010-11-11 10:01 . 2010-11-11 10:01 -------- d-sh--w- c:\documents and settings\Default User\IETldCache

2010-11-08 21:39 . 2010-11-08 21:39 73728 ----a-w- c:\windows\system32\javacpl.cpl

2010-11-08 00:19 . 2010-07-22 01:27 43952 ----a-r- c:\windows\system32\drivers\SymIM.sys

2010-11-07 22:56 . 2010-11-08 16:14 -------- d-----w- c:\program files\active ports

2010-11-07 22:51 . 1999-12-17 17:13 49664 ----a-w- c:\windows\unvise32.exe

2010-11-07 20:07 . 2010-11-07 20:07 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache

2010-11-06 15:04 . 2010-11-06 15:04 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache

2010-11-06 14:32 . 2010-11-06 14:32 98392 ----a-w- c:\windows\system32\drivers\SBREDrv.sys

2010-11-05 19:30 . 2010-11-05 19:31 -------- d-----w- c:\documents and settings\Jim\Application Data\CopyToDvd

2010-11-05 19:27 . 2010-11-05 19:28 -------- d-----w- c:\documents and settings\Jim\Local Settings\Application Data\ApplicationHistory

2010-11-05 19:27 . 2010-11-05 19:27 -------- d-----w- c:\program files\Lantronix

2010-11-05 19:26 . 2010-11-05 19:26 -------- d-----w- c:\windows\system32\URTTEMP

2010-11-05 19:18 . 2010-11-05 19:24 -------- d-----w- C:\e74ce0d18378dfb83afaf1e93c276606

2010-11-03 16:56 . 2010-09-23 07:46 15880 ----a-w- c:\windows\system32\lsdelete.exe

2010-11-03 14:14 . 2010-11-03 14:14 -------- d-----w- c:\documents and settings\Jim\Local Settings\Application Data\Sunbelt Software

2010-11-03 14:14 . 2010-11-08 00:27 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{E961CE1B-C3EA-4882-9F67-F859B555D097}

2010-11-03 14:14 . 2010-11-03 14:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft

2010-11-03 14:14 . 2010-11-03 14:14 -------- d-----w- c:\program files\Lavasoft

2010-11-01 14:27 . 2010-11-01 14:27 -------- d-----w- c:\documents and settings\Jim\Application Data\Malwarebytes

2010-11-01 14:27 . 2010-04-29 21:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-11-01 14:27 . 2010-11-01 14:27 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2010-11-01 14:27 . 2010-11-01 14:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes

2010-11-01 14:27 . 2010-04-29 21:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-11-01 08:43 . 2010-11-01 08:43 -------- d-----w- C:\rsit

2010-11-01 08:43 . 2010-11-01 08:43 -------- d-----w- c:\program files\trend micro

2010-10-31 09:54 . 2008-04-14 07:00 26624 ----a-w- c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll

2010-10-31 09:39 . 2010-10-31 09:39 -------- d-----w- c:\windows\system32\drivers\UMDF

2010-10-31 00:28 . 2010-10-31 00:43 -------- d-----w- c:\program files\Common Files\Data

2010-10-31 00:26 . 2010-10-31 00:26 197632 ----a-w- c:\program files\Common Files\OnlineFilesManager.dll

2010-10-27 21:41 . 2003-07-16 09:27 43264 ----a-r- c:\windows\system32\drivers\ser2pl.sys

2010-10-27 15:49 . 2010-10-27 15:49 -------- d-----w- c:\documents and settings\Jim\Local Settings\Application Data\Microsoft Help

2010-10-27 15:43 . 2010-10-27 15:43 -------- d-----w- c:\documents and settings\Jim\Local Settings\Application Data\PCHealth

2010-10-26 22:01 . 2010-11-11 10:01 -------- d-----w- c:\windows\system32\NtmsData

2010-10-24 10:59 . 2010-10-24 10:59 -------- d-----w- c:\documents and settings\All Users\Application Data\vsosdk

2010-10-19 14:56 . 2010-10-19 14:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage

2010-10-19 14:56 . 2010-10-19 14:56 -------- d-----w- c:\documents and settings\Jim\Application Data\Office Genuine Advantage

2010-10-19 09:05 . 2010-10-19 09:05 -------- d-----w- c:\windows\system32\XPSViewer

2010-10-19 09:04 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll

2010-10-19 09:04 . 2010-10-19 09:04 -------- d-----w- C:\9000a4901a3e329d7f

2010-10-19 09:04 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll

2010-10-19 09:04 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll

2010-10-19 09:04 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll

2010-10-19 09:04 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll

2010-10-19 09:04 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll

2010-10-19 09:04 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll

2010-10-19 09:04 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe

2010-10-19 09:04 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe

2010-10-19 06:38 . 2010-10-24 06:14 -------- d-----w- c:\documents and settings\Jim\Application Data\vlc

2010-10-18 20:24 . 2010-10-18 20:24 -------- d-----w- c:\documents and settings\Jim\Application Data\StageManager.BD092818F67280F4B42B04877600987F0111B594.1

2010-10-18 20:24 . 2010-10-18 20:24 -------- d-----w- c:\documents and settings\Jim\Application Data\Adobe Mini Bridge CS5

2010-10-18 17:12 . 2010-10-18 17:12 -------- d-----w- c:\documents and settings\Jim\Application Data\PDF Software

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-11-08 21:39 . 2010-10-04 08:43 472808 ----a-w- c:\windows\system32\deployJava1.dll

2010-10-15 10:31 . 2010-10-15 10:31 18816 ----a-w- c:\windows\system32\drivers\dvd43llh.sys

2010-10-14 06:25 . 2010-10-14 06:24 6912 ----a-w- c:\windows\system32\drivers\NTIDrvr.sys

2010-10-14 06:14 . 2010-10-14 06:14 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys

2010-10-14 06:14 . 2010-10-14 06:14 47360 ----a-w- c:\documents and settings\Jim\Application Data\pcouffin.sys

2010-10-13 03:41 . 2010-10-13 03:41 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL

2010-10-13 03:41 . 2010-10-13 03:41 126512 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS

2010-10-12 23:58 . 2010-10-12 21:14 737280 ----a-w- c:\windows\iun6002.exe

2010-09-18 18:23 . 2008-04-14 07:00 974848 ----a-w- c:\windows\system32\mfc42u.dll

2010-09-18 06:53 . 2008-04-14 07:00 974848 ----a-w- c:\windows\system32\mfc42.dll

2010-09-18 06:53 . 2008-04-14 07:00 954368 ----a-w- c:\windows\system32\mfc40.dll

2010-09-18 06:53 . 2008-04-14 07:00 953856 ----a-w- c:\windows\system32\mfc40u.dll

2010-09-10 05:58 . 2008-04-14 07:00 916480 ----a-w- c:\windows\system32\wininet.dll

2010-09-10 05:58 . 2008-04-14 07:00 43520 ----a-w- c:\windows\system32\licmgr10.dll

2010-09-10 05:58 . 2008-04-14 07:00 1469440 ------w- c:\windows\system32\inetcpl.cpl

2010-09-01 11:51 . 2008-04-14 07:00 285824 ----a-w- c:\windows\system32\atmfd.dll

2010-08-31 13:42 . 2008-04-14 07:00 1852800 ----a-w- c:\windows\system32\win32k.sys

2010-08-27 08:02 . 2008-04-14 07:00 119808 ----a-w- c:\windows\system32\t2embed.dll

2010-08-27 05:57 . 2008-04-14 07:00 99840 ----a-w- c:\windows\system32\srvsvc.dll

2010-08-26 13:39 . 2008-04-14 07:00 357248 ----a-w- c:\windows\system32\drivers\srv.sys

2010-08-26 12:52 . 2010-10-04 06:28 5120 ----a-w- c:\windows\system32\xpsp4res.dll

2010-08-23 16:12 . 2008-04-14 07:00 617472 ----a-w- c:\windows\system32\comctl32.dll

.

((((((((((((((((((((((((((((( SnapShot@2010-11-13_17.15.36 )))))))))))))))))))))))))))))))))))))))))

.

+ 2010-11-16 20:12 . 2010-11-16 20:12 16384 c:\windows\Temp\Perflib_Perfdata_a8.dat

+ 2010-11-16 20:11 . 2010-11-16 20:11 16384 c:\windows\Temp\Perflib_Perfdata_7e8.dat

+ 2010-11-16 20:11 . 2010-11-16 20:11 16384 c:\windows\Temp\Perflib_Perfdata_700.dat

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1AD61D5B-58A3-4592-9B34-DC84688FF805}]

2010-09-29 00:13 107328 ----a-w- c:\program files\PDF Suite 2010\PDFIEHelper.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{266fcdca-7bb3-4da7-b3bf-f845dea2ebd6}]

2010-10-16 06:50 2735200 ----a-w- c:\program files\IsoBuster\tbIso1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

"{266fcdca-7bb3-4da7-b3bf-f845dea2ebd6}"= "c:\program files\IsoBuster\tbIso1.dll" [2010-10-16 2735200]

[HKEY_CLASSES_ROOT\clsid\{266fcdca-7bb3-4da7-b3bf-f845dea2ebd6}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]

"{266FCDCA-7BB3-4DA7-B3BF-F845DEA2EBD6}"= "c:\program files\IsoBuster\tbIso1.dll" [2010-10-16 2735200]

[HKEY_CLASSES_ROOT\clsid\{266fcdca-7bb3-4da7-b3bf-f845dea2ebd6}]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Green]

@="{95A27763-F62A-4114-9072-E81D87DE3B68}"

[HKEY_CLASSES_ROOT\CLSID\{95A27763-F62A-4114-9072-E81D87DE3B68}]

2010-09-21 01:25 731280 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Partial]

@="{E300CD91-100F-4E67-9AF3-1384A6124015}"

[HKEY_CLASSES_ROOT\CLSID\{E300CD91-100F-4E67-9AF3-1384A6124015}]

2010-09-21 01:25 731280 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Yellow]

@="{5E529433-B50E-4bef-A63B-16A6B71B071A}"

[HKEY_CLASSES_ROOT\CLSID\{5E529433-B50E-4bef-A63B-16A6B71B071A}]

2010-09-21 01:25 731280 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Online Files]

@="{B82655E9-B81D-4A97-8154-0D84A4C048E4}"

[HKEY_CLASSES_ROOT\CLSID\{B82655E9-B81D-4A97-8154-0D84A4C048E4}]

2010-10-31 00:26 197632 ----a-w- c:\program files\Common Files\OnlineFilesManager.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"AOL Fast Start"="c:\program files\AOL 9.0b\AOL.EXE" [2007-02-06 50736]

"yDecode"="c:\program files\yDecode\yDecode.exe" [2006-09-08 704008]

"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-10-10 39408]

"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-08-18 150040]

"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-08-18 170520]

"Persistence"="c:\windows\system32\igfxpers.exe" [2008-08-18 141848]

"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2009-04-02 128232]

"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2009-06-22 1044480]

"HostManager"="c:\program files\Common Files\AOL\1286184261\ee\AOLSoftware.exe" [2006-09-26 50736]

"Carbonite Backup"="c:\program files\Carbonite\Carbonite Backup\CarboniteUI.exe" [2010-09-21 913552]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]

"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]

"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]

"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]

"yDecode"="c:\program files\yDecode\yDecode.exe" [2006-09-08 704008]

"dvd43"="c:\program files\dvd43\dvd43_tray.exe" [2009-10-24 827904]

"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]

c:\documents and settings\Jim\Start Menu\Programs\Startup\

LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2010-9-30 503808]

OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

c:\documents and settings\All Users\Start Menu\Programs\Startup\

QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2010-10-13 663552]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=

"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=

"c:\\Program Files\\AOL 9.0b\\waol.exe"=

"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=

"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=

"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=

"c:\\Program Files\\yDecode\\yDecode.exe"=

"c:\\Program Files\\uTorrent\\uTorrent.exe"=

"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=

"c:\\Program Files\\LimeWire\\LimeWire.exe"=

"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=

"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=

R0 O1394B;OW 1394b Bus Filter Service;c:\windows\system32\drivers\o1394b.sys [10/15/2010 5:44 PM 10112]

R0 SFAUDIO;Sonic Focus DSP Driver;c:\windows\system32\drivers\sfaudio.sys [10/3/2010 11:23 PM 24064]

R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NIS\1201000.025\SymDS.sys [10/12/2010 8:41 PM 339504]

R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1201000.025\SymEFA.sys [10/12/2010 8:41 PM 666672]

R1 BHDrvx86;BHDrvx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20101104.001\BHDrvx86.sys [11/3/2010 5:07 PM 691248]

R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NIS\1201000.025\Ironx86.sys [10/12/2010 8:41 PM 134704]

R2 NIS;Norton Internet Security;c:\program files\Norton Internet Security\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe [10/12/2010 8:41 PM 126904]

R2 PDF Suite 2010 Service;PDF Suite 2010 Service;c:\program files\PDF Suite 2010\ConversionService.exe [9/28/2010 5:13 PM 791360]

R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [10/12/2010 8:41 PM 102448]

R3 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20101115.001\IDSXpx86.sys [10/19/2010 1:36 PM 341880]

R3 k57w2k;Broadcom NetLink Gigabit Ethernet;c:\windows\system32\drivers\k57xp32.sys [10/3/2010 11:06 PM 176640]

S0 cerc6;cerc6; [x]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 12:16 PM 130384]

S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [10/9/2010 9:54 PM 136176]

S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [9/23/2010 12:46 AM 1375992]

S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\kernexplorer.sys [9/23/2010 12:46 AM 15264]

S3 SwitchBoard;Adobe SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2/19/2010 12:37 PM 517096]

S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 12:16 PM 753504]

.

Contents of the 'Scheduled Tasks' folder

2010-11-13 c:\windows\Tasks\Ad-Aware Update (Weekly).job

- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-09-23 14:32]

2010-11-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cb6dce7ba088c0.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-10 04:54]

2010-11-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA1cb6dce7bc6ae60.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-10 04:54]

2010-11-16 c:\windows\Tasks\OGALogon.job

- c:\windows\system32\OGAEXEC.exe [2009-08-03 21:07]

.

.

------- Supplementary Scan -------

.

uStart Page = about:blank

uInternet Connection Wizard,ShellNext = "c:\program files\Outlook Express\msimn.exe"

TCP: {600AAE40-FB2E-49AB-B088-41C29A750534} = 72.19.128.53,72.19.128.99

DPF: {CF4A2C45-CB89-4018-94BB-C2CACB83A537} - hxxps://www.myremotemanager.com/myrm/device/xancamx.ocx

FF - ProfilePath - c:\documents and settings\Jim\Application Data\Mozilla\Firefox\Profiles\po7mzqvu.default\

FF - prefs.js: browser.search.selectedEngine - Google

FF - prefs.js: browser.startup.homepage -

FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\coFFPlgn\components\coFFPlgn.dll

FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\IPSFFPlgn\components\IPSFFPl.dll

FF - component: c:\documents and settings\Jim\Application Data\Mozilla\Firefox\Profiles\po7mzqvu.default\extensions\{ad55c869-668e-457c-b270-0cfb2f61116f}\components\FFExternalAlert.dll

FF - component: c:\documents and settings\Jim\Application Data\Mozilla\Firefox\Profiles\po7mzqvu.default\extensions\{ad55c869-668e-457c-b270-0cfb2f61116f}\components\RadioWMPCore.dll

FF - component: c:\program files\PDF Suite 2010\firefoxextension\components\FFPDFConverter.dll

FF - plugin: c:\documents and settings\Jim\Application Data\Mozilla\Firefox\Profiles\po7mzqvu.default\extensions\LogMeInClient@logmein.com\plugins\npRACtrl.dll

FF - plugin: c:\program files\Google\Update\1.2.183.39\npGoogleOneClick8.dll

FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll

FF - plugin: c:\program files\PDF Suite 2010\firefoxextension\plugins\NPPdfExt.dll

FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);

.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2010-11-16 13:18

Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NIS]

"ImagePath"="\"c:\program files\Norton Internet Security\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files\Norton Internet Security\Norton Internet Security\Engine\18.1.0.37\diMaster.dll\" /prefetch:1"

.

--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]

"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]

@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]

@Denied: (A 2) (Everyone)

@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

Completion time: 2010-11-16 13:19:40

ComboFix-quarantined-files.txt 2010-11-16 20:19

ComboFix2.txt 2010-11-13 18:57

ComboFix3.txt 2010-11-13 18:39

ComboFix4.txt 2010-11-13 17:16

ComboFix5.txt 2010-11-16 19:52

Pre-Run: 783,200,739,328 bytes free

Post-Run: 783,310,790,656 bytes free

Link to post
Share on other sites

Hi,

Please go to: VirusTotal

  • virustotal2-SWI.png
  • Click the Browse button and search for the following file: C:\Qoobox\Quarantine\C\windows\system32\16512379641.dll.vir
  • Click Open
  • Then click Send File
  • Please be patient while the file is scanned.
  • Once the scan results appear, please provide them in your next reply.

If it says already scanned -- click "reanalyze now"

Please post the results in your next reply.

Link to post
Share on other sites

0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware.

File name: file-1524946_dll

Submission date: 2010-11-05 17:25:56 (UTC)

Current status: finished

Result: 0 /43 (0.0%)

VT Community

not reviewed

Safety score: -

Compact Print results

Antivirus Version Last Update Result

AhnLab-V3 2010.11.05.01 2010.11.05 -

AntiVir 7.10.13.143 2010.11.05 -

Antiy-AVL 2.0.3.7 2010.11.05 -

Authentium 5.2.0.5 2010.11.05 -

Avast 4.8.1351.0 2010.11.05 -

Avast5 5.0.594.0 2010.11.05 -

AVG 9.0.0.851 2010.11.05 -

BitDefender 7.2 2010.11.05 -

CAT-QuickHeal 11.00 2010.11.04 -

ClamAV 0.96.2.0-git 2010.11.05 -

Comodo 6624 2010.11.05 -

DrWeb 5.0.2.03300 2010.11.05 -

Emsisoft 5.0.0.50 2010.11.05 -

eSafe 7.0.17.0 2010.11.04 -

eTrust-Vet 36.1.7957 2010.11.05 -

F-Prot 4.6.2.117 2010.11.05 -

F-Secure 9.0.16160.0 2010.11.05 -

Fortinet 4.2.249.0 2010.11.05 -

GData 21 2010.11.05 -

Ikarus T3.1.1.90.0 2010.11.05 -

Jiangmin 13.0.900 2010.11.05 -

K7AntiVirus 9.67.2903 2010.11.03 -

Kaspersky 7.0.0.125 2010.11.05 -

McAfee 5.400.0.1158 2010.11.05 -

McAfee-GW-Edition 2010.1C 2010.11.05 -

Microsoft 1.6301 2010.11.04 -

NOD32 5594 2010.11.05 -

Norman 6.06.10 2010.11.05 -

nProtect 2010-11-05.01 2010.11.05 -

Panda 10.0.2.7 2010.11.05 -

PCTools 7.0.3.5 2010.11.05 -

Prevx 3.0 2010.11.05 -

Rising 22.72.03.04 2010.11.05 -

Sophos 4.59.0 2010.11.05 -

Sunbelt 7225 2010.11.05 -

SUPERAntiSpyware 4.40.0.1006 2010.11.05 -

Symantec 20101.2.0.161 2010.11.05 -

TheHacker 6.7.0.1.076 2010.11.05 -

TrendMicro 9.120.0.1004 2010.11.05 -

TrendMicro-HouseCall 9.120.0.1004 2010.11.05 -

VBA32 3.12.14.1 2010.11.05 -

ViRobot 2010.10.4.4074 2010.11.05 -

VirusBuster 12.71.7.0 2010.11.05 -

Additional informationShow all

MD5 : b4dd33bead5af42028102819a2e4634f

SHA1 : c13e61dd26757a5fd76e0c76ebf343f95d26f929

SHA256: c38d5b644fcc0884f485ad324928885b34685837c319e1cad6b44ba70c84c808

ssdeep: 384:gQfcm4hv3oraaom9rNiSib6zgjR57J7HcJoHOMRWRSLxXuLCXyoMRkPTNawOWHlY:gQfcm4

hvr8wSPckm8oMReTUc92

File size : 24983 bytes

First seen: 2010-11-05 17:25:56

Last seen : 2010-11-05 17:25:56

Magic: Non-ISO extended-ASCII text, with very long lines, with NEL line terminators

TrID:

Unknown!

sigcheck:

publisher....: n/a

copyright....: n/a

product......: n/a

description..: n/a

original name: n/a

internal name: n/a

file version.: n/a

comments.....: n/a

signers......: -

signing date.: -

verified.....: Unsigned

PEiD: -

ExifTool:

Link to post
Share on other sites

The previous file was their current information. My mistake. Here is the RE-Analyzed version.

0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware.

File name: 17224529641.dll.vir

Submission date: 2010-11-17 16:17:37 (UTC)

Current status: queued queued (#1) analysing finished

Result: 0/ 43 (0.0%)

VT Community

not reviewed

Safety score: -

Compact Print results

Antivirus Version Last Update Result

AhnLab-V3 2010.11.17.01 2010.11.17 -

AntiVir 7.10.14.31 2010.11.17 -

Antiy-AVL 2.0.3.7 2010.11.17 -

Avast 4.8.1351.0 2010.11.17 -

Avast5 5.0.594.0 2010.11.17 -

AVG 9.0.0.851 2010.11.17 -

BitDefender 7.2 2010.11.17 -

CAT-QuickHeal 11.00 2010.11.09 -

ClamAV 0.96.4.0 2010.11.17 -

Command 5.2.11.5 2010.11.17 -

Comodo 6749 2010.11.17 -

DrWeb 5.0.2.03300 2010.11.17 -

Emsisoft 5.0.0.50 2010.11.17 -

eSafe 7.0.17.0 2010.11.16 -

eTrust-Vet 36.1.7982 2010.11.17 -

F-Prot 4.6.2.117 2010.11.17 -

F-Secure 9.0.16160.0 2010.11.17 -

Fortinet 4.2.254.0 2010.11.17 -

GData 21 2010.11.17 -

Ikarus T3.1.1.90.0 2010.11.17 -

Jiangmin 13.0.900 2010.11.17 -

K7AntiVirus 9.68.3011 2010.11.17 -

Kaspersky 7.0.0.125 2010.11.17 -

McAfee 5.400.0.1158 2010.11.17 -

McAfee-GW-Edition 2010.1C 2010.11.17 -

Microsoft 1.6402 2010.11.17 -

NOD32 5626 2010.11.17 -

Norman 6.06.10 2010.11.17 -

nProtect 2010-11-17.01 2010.11.17 -

Panda 10.0.2.7 2010.11.17 -

PCTools 7.0.3.5 2010.11.17 -

Prevx 3.0 2010.11.17 -

Rising 22.74.02.03 2010.11.17 -

Sophos 4.59.0 2010.11.17 -

SUPERAntiSpyware 4.40.0.1006 2010.11.17 -

Symantec 20101.2.0.161 2010.11.17 -

TheHacker 6.7.0.1.086 2010.11.17 -

TrendMicro 9.120.0.1004 2010.11.17 -

TrendMicro-HouseCall 9.120.0.1004 2010.11.17 -

VBA32 3.12.14.2 2010.11.17 -

VIPRE 7332 2010.11.17 -

ViRobot 2010.11.17.4153 2010.11.17 -

VirusBuster 12.76.3.0 2010.11.16 -

Additional informationShow all

MD5 : b4dd33bead5af42028102819a2e4634f

SHA1 : c13e61dd26757a5fd76e0c76ebf343f95d26f929

SHA256: c38d5b644fcc0884f485ad324928885b34685837c319e1cad6b44ba70c84c808

ssdeep: 384:gQfcm4hv3oraaom9rNiSib6zgjR57J7HcJoHOMRWRSLxXuLCXyoMRkPTNawOWHlY:gQfcm4

hvr8wSPckm8oMReTUc92

File size : 24983 bytes

First seen: 2010-11-05 17:25:56

Last seen : 2010-11-17 16:17:37

TrID:

Unknown!

sigcheck:

publisher....: n/a

copyright....: n/a

product......: n/a

description..: n/a

original name: n/a

internal name: n/a

file version.: n/a

comments.....: n/a

signers......: -

signing date.: -

verified.....: Unsigned

VT Community

0

This file has never been reviewed by any VT Community member. Be the first one to comment on it!

VirusTotal Team

Link to post
Share on other sites

In that quarantine fold were 2 other similar files....it seems that each time one is deleted, there is a code generator someplace that replaces it with a new file using a random, yet similar file name. Here is the analysis of the other two files. Following this post will be the analysis of the 3rd file.

0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware.

File name: 16512379641.dll.vir

Submission date: 2010-11-17 16:26:55 (UTC)

Current status: queued (#11) queued (#11) analysing finished

Result: 0/ 43 (0.0%)

VT Community

not reviewed

Safety score: -

Compact Print results

Antivirus Version Last Update Result

AhnLab-V3 2010.11.17.01 2010.11.17 -

AntiVir 7.10.14.32 2010.11.17 -

Antiy-AVL 2.0.3.7 2010.11.17 -

Avast 4.8.1351.0 2010.11.17 -

Avast5 5.0.594.0 2010.11.17 -

AVG 9.0.0.851 2010.11.17 -

BitDefender 7.2 2010.11.17 -

CAT-QuickHeal 11.00 2010.11.09 -

ClamAV 0.96.4.0 2010.11.17 -

Command 5.2.11.5 2010.11.17 -

Comodo 6749 2010.11.17 -

DrWeb 5.0.2.03300 2010.11.17 -

Emsisoft 5.0.0.50 2010.11.17 -

eSafe 7.0.17.0 2010.11.16 -

eTrust-Vet 36.1.7982 2010.11.17 -

F-Prot 4.6.2.117 2010.11.17 -

F-Secure 9.0.16160.0 2010.11.17 -

Fortinet 4.2.254.0 2010.11.17 -

GData 21 2010.11.17 -

Ikarus T3.1.1.90.0 2010.11.17 -

Jiangmin 13.0.900 2010.11.17 -

K7AntiVirus 9.68.3011 2010.11.17 -

Kaspersky 7.0.0.125 2010.11.17 -

McAfee 5.400.0.1158 2010.11.17 -

McAfee-GW-Edition 2010.1C 2010.11.17 -

Microsoft 1.6402 2010.11.17 -

NOD32 5627 2010.11.17 -

Norman 6.06.10 2010.11.17 -

nProtect 2010-11-17.01 2010.11.17 -

Panda 10.0.2.7 2010.11.17 -

PCTools 7.0.3.5 2010.11.17 -

Prevx 3.0 2010.11.17 -

Rising 22.74.02.03 2010.11.17 -

Sophos 4.59.0 2010.11.17 -

SUPERAntiSpyware 4.40.0.1006 2010.11.17 -

Symantec 20101.2.0.161 2010.11.17 -

TheHacker 6.7.0.1.086 2010.11.17 -

TrendMicro 9.120.0.1004 2010.11.17 -

TrendMicro-HouseCall 9.120.0.1004 2010.11.17 -

VBA32 3.12.14.2 2010.11.17 -

VIPRE 7332 2010.11.17 -

ViRobot 2010.11.17.4153 2010.11.17 -

VirusBuster 12.76.3.0 2010.11.16 -

Additional informationShow all

MD5 : b4dd33bead5af42028102819a2e4634f

SHA1 : c13e61dd26757a5fd76e0c76ebf343f95d26f929

SHA256: c38d5b644fcc0884f485ad324928885b34685837c319e1cad6b44ba70c84c808

ssdeep: 384:gQfcm4hv3oraaom9rNiSib6zgjR57J7HcJoHOMRWRSLxXuLCXyoMRkPTNawOWHlY:gQfcm4

hvr8wSPckm8oMReTUc92

File size : 24983 bytes

First seen: 2010-11-05 17:25:56

Last seen : 2010-11-17 16:26:55

TrID:

Unknown!

sigcheck:

publisher....: n/a

copyright....: n/a

product......: n/a

description..: n/a

original name: n/a

internal name: n/a

file version.: n/a

comments.....: n/a

signers......: -

signing date.: -

verified.....: Unsigned

VT Community

0

This file has never been reviewed by any VT Community member. Be the first one to comment on it!

VirusTotal Team

0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware.

File name: 15325643741.dll.vir

Submission date: 2010-11-17 16:43:57 (UTC)

Current status: queued (#3) queued (#3) analysing finished

Result: 0/ 43 (0.0%)

VT Community

not reviewed

Safety score: -

Compact Print results

Antivirus Version Last Update Result

AhnLab-V3 2010.11.17.01 2010.11.17 -

AntiVir 7.10.14.32 2010.11.17 -

Antiy-AVL 2.0.3.7 2010.11.17 -

Avast 4.8.1351.0 2010.11.17 -

Avast5 5.0.594.0 2010.11.17 -

AVG 9.0.0.851 2010.11.17 -

BitDefender 7.2 2010.11.17 -

CAT-QuickHeal 11.00 2010.11.09 -

ClamAV 0.96.4.0 2010.11.17 -

Command 5.2.11.5 2010.11.17 -

Comodo 6749 2010.11.17 -

DrWeb 5.0.2.03300 2010.11.17 -

Emsisoft 5.0.0.50 2010.11.17 -

eSafe 7.0.17.0 2010.11.16 -

eTrust-Vet 36.1.7982 2010.11.17 -

F-Prot 4.6.2.117 2010.11.17 -

F-Secure 9.0.16160.0 2010.11.17 -

Fortinet 4.2.254.0 2010.11.17 -

GData 21 2010.11.17 -

Ikarus T3.1.1.90.0 2010.11.17 -

Jiangmin 13.0.900 2010.11.17 -

K7AntiVirus 9.68.3011 2010.11.17 -

Kaspersky 7.0.0.125 2010.11.17 -

McAfee 5.400.0.1158 2010.11.17 -

McAfee-GW-Edition 2010.1C 2010.11.17 -

Microsoft 1.6402 2010.11.17 -

NOD32 5627 2010.11.17 -

Norman 6.06.10 2010.11.17 -

nProtect 2010-11-17.01 2010.11.17 -

Panda 10.0.2.7 2010.11.17 -

PCTools 7.0.3.5 2010.11.17 -

Prevx 3.0 2010.11.17 -

Rising 22.74.02.03 2010.11.17 -

Sophos 4.59.0 2010.11.17 -

SUPERAntiSpyware 4.40.0.1006 2010.11.17 -

Symantec 20101.2.0.161 2010.11.17 -

TheHacker 6.7.0.1.086 2010.11.17 -

TrendMicro 9.120.0.1004 2010.11.17 -

TrendMicro-HouseCall 9.120.0.1004 2010.11.17 -

VBA32 3.12.14.2 2010.11.17 -

VIPRE 7332 2010.11.17 -

ViRobot 2010.11.17.4153 2010.11.17 -

VirusBuster 12.76.3.0 2010.11.16 -

Additional informationShow all

MD5 : b4dd33bead5af42028102819a2e4634f

SHA1 : c13e61dd26757a5fd76e0c76ebf343f95d26f929

SHA256: c38d5b644fcc0884f485ad324928885b34685837c319e1cad6b44ba70c84c808

ssdeep: 384:gQfcm4hv3oraaom9rNiSib6zgjR57J7HcJoHOMRWRSLxXuLCXyoMRkPTNawOWHlY:gQfcm4

hvr8wSPckm8oMReTUc92

File size : 24983 bytes

First seen: 2010-11-05 17:25:56

Last seen : 2010-11-17 16:43:57

TrID:

Unknown!

sigcheck:

publisher....: n/a

copyright....: n/a

product......: n/a

description..: n/a

original name: n/a

internal name: n/a

file version.: n/a

comments.....: n/a

signers......: -

signing date.: -

verified.....: Unsigned

VT Community

And the 3rd.....

This file has never been reviewed by any VT Community member. Be the first one to comment on it!

VirusTotal Team

Link to post
Share on other sites

Hi,

Using Internet Explorer or Firefox, visit Kaspersky Online Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.

2. To optimize scanning time and produce a more sensible report for review:

  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan. Click HERE to see how to disable the most common antivirus programs.

3. Click Run at the Security prompt.

The program will then begin downloading and installing and will also update the database.

Please be patient as this can take quite a long time to download.

  • Once the update is complete, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:

    • Spyware, adware, dialers, and other riskware
    • Archives
    • E-mail databases

    [*]Click on My Computer under the green Scan bar to the left to start the scan.

    [*]Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.

    [*]Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.

    [*]Click View report... at the bottom.

    [*] Click the Save report... button.

    KasReport.png

    [*] Change the Files of type dropdown box to Text file (.txt) and name the file KasReport.txt to save the file to your desktop so that you may post it in your next reply

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Download Dr.Web CureIt to the desktop.

  • Doubleclick the drweb-cureit.exe file, then on Start and allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, chose the Complete Scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow drweb_green_arrow.jpg at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, look and see if you can click the following icon next to the files found:
    drweb_check.gif
  • If so, click it and then click the next icon right below and select Move incurable as you'll see in next image:
    drweb_move.gif
  • This will move it to the %userprofile%\DoctorWeb\quarantaine-folder if it can't be cured. (this in case if we need samples)
  • After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
  • Reboot your computer to allow files that were in use to be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web you saved previously in your next reply along with a new OTL log.

NOTE: During the scan, a pop-up window will open asking for full version purchase. Simply close the window by clicking on X in upper right corner.

Link to post
Share on other sites

I have tried mutiple times to run the Kaspersky Scanner. Each time, it check the computer and says good, then after starting the program, when it begins to update the database, it quits giving the following error message. I have ensuring that all the virus software has stopped, and have tried rebooting the machine. Nothing works. I just get the error message as follows:

Update has failed The program could not be started. Please close the window of Kaspersky Online Scanner 7.0 and start the program again from the web site of Kaspersky Lab. Successful updating of Kaspersky Online Scanner 7.0 and scanning of your computer requires uninterrupted Internet connection. Please make sure that the Internet connection is established. [ERROR: License has expired]

Asvice? Thanks. Jim

Link to post
Share on other sites

Hi,

Save these instructions so you can have access to them while in Safe Mode.

Please click here to download AVP Tool by Kaspersky.

  • Save it to your desktop.
  • Reboot your computer into SafeMode.

    You can do this by restarting your computer and continually tapping the
    F8
    key until a menu appears.

    Use your up arrow key to highlight SafeMode then hit
    enter
    .


  • Double click the setup file to run it.
  • Click Next to continue.
  • Accept the Licence agreement and click on next
  • It will by default install it to your desktop folder.Click Next.
  • It will then open a box There will be a tab that says Automatic scan.
  • Under Automatic scan make sure these are checked.


  • Hidden Startup Objects

  • System Memory

  • Disk Boot Sectors.

  • My Computer.

  • Also any other drives (Removable that you may have)

Leave the rest of the settings as they appear as default.

  • Then click on Scan at the to right hand Corner.
  • It will automatically Neutralize any objects found.
  • If some objects are left un-neutralized then click the button that says Neutralize all
  • If it says it cannot be Neutralized then chooose The delete option when prompted.
  • After that is done click on the reports button at the bottom and save it to file name it Kas.
  • Save it somewhere convenient like your desktop and just post only the detected Virus\malware in the report it will be at the very top under Detected post those results in your next reply.

    Note: This tool will self uninstall when you close it so please save the log before closing it.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Download Dr.Web CureIt to the desktop.

  • Doubleclick the drweb-cureit.exe file, then on Start and allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, chose the Complete Scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow drweb_green_arrow.jpg at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, look and see if you can click the following icon next to the files found:
    drweb_check.gif
  • If so, click it and then click the next icon right below and select Move incurable as you'll see in next image:
    drweb_move.gif
  • This will move it to the %userprofile%\DoctorWeb\quarantaine-folder if it can't be cured. (this in case if we need samples)
  • After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
  • Reboot your computer to allow files that were in use to be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web you saved previously in your next reply along with a new OTL log.

NOTE: During the scan, a pop-up window will open asking for full version purchase. Simply close the window by clicking on X in upper right corner.

Link to post
Share on other sites

OK...ran Kaspersky in Safe Mode and included the log herein. Note: No viruses or malicious files found.

Ran Dr. Webb Cureit. The program did not give me the option of saving the file (grayed out), but it also found nothing. I have included a screen shot of it's results window.

Here's a couple thoughts that may be obvious to you, but have been what I've been chasing but to no avail. Would it not be a correct assumption that if I am "seeing" all these web sites, that my computer is initiating a call to the web sites' URL's? My thought was to monitor outging port traffic and then block or delete the offending program, but I quickly learned that I don't understand enough to weed through all the valid port calls to isolate a malicious one....assuming I'm even on the right track. Also, with all these unique pages being called, it would seem to me that there must be a list being communicated to my computer.

Norton has been recording many initiations from my Explorer.exe to malicious websites. I am guessing that these are coming from the same source as the web site "calls" that I am seeing. It's not been blocking them, but rather recording them as "IPS Detection Statistical Submission. Some are recorded as merely submitted others (more recently) are getting blocked. That said, I do not know how to look for what script or program is telling MSIE what sites to call. Or how it is getting its information to tell MSIE what site to call.

Also, Norton is blocking incoming attacks every few minutes (or less) around the clock. As I have a static IP, I see a potential partial solution. Change IP. I won't do anything until I hear from you.

Maybe this information will help.

Jim

Kas.txt

Link to post
Share on other sites

More information. After I change IP, according to Norton, explorer.exe sent out a call to an IP address, though nothing visible happened right away. I am guessing it is using the outgoing access to say "here I am" because as soon as that happens, an incoming hit came from the same address (to my NEW address!). In the latest case, it was blocked by Norton as a known attack, but my current thought is that the source IP keeps switching IPs until it finds one that Norton isn't aware of and when when Norton doesn't catch it, the new intrusion contains the next set of web site that my computer will call next.

Even as I type this, I am cancelling dozens of web site hits.

Jim

Link to post
Share on other sites

Hi,

Lets take a look on your PC with another analysis tool. :D

Download OTL to your Desktop

  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Check the box that says Scan All Users.
  • Under the Custom Scan box paste this in
    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time and post them in your topic

Link to post
Share on other sites

I will start your most recent request in a bit. Meanwhile, here's some more information. As I'm sure you know, Norton monitors port traffic so last night I started going through the recent items that were blocked and found incoming and outgoing attempts that Norton called: Fragus Toolkit - Activity 1.

Link to post
Share on other sites

OTL logfile created on: 11/23/2010 12:05:12 PM - Run 1

OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Jim\Desktop

Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 72.00% Memory free

7.00 Gb Paging File | 7.00 Gb Available in Paging File | 90.00% Paging File free

Paging file location(s): C:\pagefile.sys 4546 6092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 931.50 Gb Total Space | 729.47 Gb Free Space | 78.31% Space Free | Partition Type: NTFS

Computer Name: DESK | User Name: Jim | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: All users | Quick Scan

Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2010/11/23 12:01:24 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Jim\Desktop\OTL.exe

PRC - [2010/09/28 17:13:24 | 000,791,360 | ---- | M] (Interactive Brands Inc.) -- C:\Program Files\PDF Suite 2010\ConversionService.exe

PRC - [2010/09/20 18:25:06 | 003,117,200 | R--- | M] (Carbonite, Inc. (www.carbonite.com)) -- C:\Program Files\Carbonite\Carbonite Backup\CarboniteService.exe

PRC - [2010/09/20 18:25:04 | 000,913,552 | R--- | M] (Carbonite, Inc.) -- C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe

PRC - [2010/07/22 22:05:56 | 000,126,904 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe

PRC - [2009/10/23 18:34:36 | 000,827,904 | ---- | M] () -- C:\Program Files\dvd43\DVD43_Tray.exe

PRC - [2009/06/22 13:21:40 | 001,044,480 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\Core\smax4pnp.exe

PRC - [2009/04/02 16:33:16 | 000,128,232 | ---- | M] (CyberLink Corp.) -- C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe

PRC - [2009/01/26 14:31:16 | 002,144,088 | ---- | M] (Safer Networking Limited) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

PRC - [2008/04/14 00:00:00 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe

PRC - [2007/02/06 08:25:24 | 000,039,472 | ---- | M] (AOL, LLC.) -- C:\Program Files\AOL 9.0b\waol.exe

PRC - [2007/02/06 08:25:22 | 000,054,832 | ---- | M] (AOL, LLC.) -- C:\Program Files\AOL 9.0b\shellmon.exe

PRC - [2007/02/05 14:27:11 | 000,063,120 | ---- | M] (AOL LLC) -- C:\Program Files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe

PRC - [2006/10/23 05:50:35 | 000,046,640 | R--- | M] (AOL LLC) -- C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe

PRC - [2006/09/25 17:52:48 | 000,050,736 | ---- | M] (America Online, Inc.) -- C:\Program Files\Common Files\AOL\1286184261\ee\aolsoftware.exe

PRC - [2006/09/08 13:25:32 | 000,704,008 | ---- | M] () -- C:\Program Files\yDecode\yDecode.exe

PRC - [2005/02/24 00:31:56 | 000,663,552 | ---- | M] (Intuit, Inc.) -- C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe

========== Modules (SafeList) ==========

MOD - [2010/11/23 12:01:24 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Jim\Desktop\OTL.exe

MOD - [2010/08/23 09:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll

MOD - [2010/08/16 20:39:11 | 000,413,552 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\18.1.0.37\asOEHook.dll

MOD - [2009/07/11 23:02:02 | 000,653,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll

MOD - [2009/07/11 23:02:00 | 000,569,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcp90.dll

MOD - [2007/02/06 08:25:18 | 000,006,144 | ---- | M] (AOL, LLC.) -- C:\Program Files\AOL 9.0b\idleproc.dll

========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] -- C:\WINDOWS\System32\hidserv.dll -- (HidServ)

SRV - File not found [Auto | Stopped] -- C:\Program Files\Google\Update\GoogleUpdate.exe -- (gupdate) Google Update Service (gupdate)

SRV - [2010/11/22 21:43:04 | 000,465,792 | ---- | M] (Sysinternals - www.sysinternals.com) [On_Demand | Stopped] -- C:\Documents and Settings\Jim\Local Settings\temp\Y.exe -- (Y)

SRV - [2010/09/28 17:13:24 | 000,791,360 | ---- | M] (Interactive Brands Inc.) [Auto | Running] -- C:\Program Files\PDF Suite 2010\ConversionService.exe -- (PDF Suite 2010 Service)

SRV - [2010/09/20 18:25:06 | 003,117,200 | R--- | M] (Carbonite, Inc. (www.carbonite.com)) [Auto | Running] -- C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe -- (CarboniteService)

SRV - [2010/07/22 22:05:56 | 000,126,904 | R--- | M] (Symantec Corporation) [unknown | Running] -- C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe -- (NIS)

SRV - [2010/03/18 15:47:22 | 000,035,160 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe -- (aspnet_state)

SRV - [2010/03/18 12:16:28 | 000,753,504 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe -- (WPFFontCache_v0400)

SRV - [2010/03/18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)

SRV - [2010/03/18 12:16:28 | 000,124,240 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe -- (NetTcpPortSharing)

SRV - [2010/02/19 12:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)

SRV - [2006/10/23 05:50:35 | 000,046,640 | R--- | M] (AOL LLC) [Auto | Running] -- C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe -- (AOL ACS)

========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys -- (Lavasoft Kernexplorer)

DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\Jim\LOCALS~1\Temp\catchme.sys -- (catchme)

DRV - [2010/11/22 02:52:47 | 000,007,168 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\utm3mjg4.sys -- (utm3mjg4)

DRV - [2010/11/06 01:46:00 | 001,371,184 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20101123.002\NAVEX15.SYS -- (NAVEX15)

DRV - [2010/11/06 01:46:00 | 000,086,064 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20101123.002\NAVENG.SYS -- (NAVENG)

DRV - [2010/11/03 17:07:06 | 000,691,248 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20101104.001\BHDrvx86.sys -- (BHDrvx86)

DRV - [2010/10/19 13:36:22 | 000,341,880 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20101122.004\IDSXpx86.sys -- (IDSxpx86)

DRV - [2010/10/15 03:31:38 | 000,018,816 | ---- | M] (RIF) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\dvd43llh.sys -- (dvd43llh)

DRV - [2010/10/13 23:25:19 | 000,006,912 | ---- | M] (NewTech Infosystems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NTIDrvr.sys -- (NTIDrvr)

DRV - [2010/10/12 20:41:56 | 000,126,512 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS -- (SymEvent)

DRV - [2010/08/13 02:00:00 | 000,371,248 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)

DRV - [2010/08/13 02:00:00 | 000,102,448 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)

DRV - [2010/07/28 20:33:05 | 000,666,672 | R--- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\NIS\1201000.025\SYMEFA.SYS -- (SymEFA)

DRV - [2010/07/28 19:54:36 | 000,489,008 | R--- | M] (Symantec Corporation) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\NIS\1201000.025\SRTSP.SYS -- (SRTSP)

DRV - [2010/07/28 19:54:36 | 000,050,096 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\NIS\1201000.025\SRTSPX.SYS -- (SRTSPX) Symantec Real Time Storage Protection (PEL)

DRV - [2010/07/21 18:27:14 | 000,043,952 | R--- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SymIM.sys -- (SymIMMP)

DRV - [2010/07/21 18:27:14 | 000,043,952 | R--- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SymIM.sys -- (SymIM)

DRV - [2010/07/12 18:20:22 | 000,369,072 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\NIS\1201000.025\SYMTDI.SYS -- (SYMTDI)

DRV - [2010/06/26 21:05:55 | 000,134,704 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\NIS\1201000.025\Ironx86.SYS -- (SymIRON)

DRV - [2010/06/13 03:50:57 | 000,339,504 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\NIS\1201000.025\SYMDS.SYS -- (SymDS)

DRV - [2009/05/18 12:26:54 | 000,339,456 | ---- | M] (Analog Devices, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ADIHdAud.sys -- (ADIHdAudAddService)

DRV - [2008/06/19 17:52:30 | 000,176,640 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\k57xp32.sys -- (k57w2k) Broadcom NetLink

DRV - [2008/06/11 17:15:38 | 006,021,184 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\igxpmp32.sys -- (ialm)

DRV - [2008/04/14 00:00:00 | 000,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)

DRV - [2008/04/13 21:04:32 | 001,897,408 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)

DRV - [2008/03/28 10:14:02 | 000,024,064 | ---- | M] (Sonic Focus, Inc) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sfaudio.sys -- (SFAUDIO)

DRV - [2004/10/15 08:58:38 | 000,010,112 | ---- | M] (OrangeWare Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\o1394b.sys -- (O1394B)

DRV - [2003/07/16 02:27:40 | 000,043,264 | R--- | M] (Prolific Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ser2pl.sys -- (Ser2pl)

DRV - [2003/01/10 14:13:04 | 000,033,588 | R--- | M] (America Online, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wanatw4.sys -- (wanatw) WAN Miniport (ATW)

========== Standard Registry (SafeList) ==========

========== Internet Explorer ==========

IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-606747145-1770027372-682003330-1014\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank

IE - HKU\S-1-5-21-606747145-1770027372-682003330-1014\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us

IE - HKU\S-1-5-21-606747145-1770027372-682003330-1014\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Yahoo-FlvTube"

FF - prefs.js..browser.search.defaultenginename: "Yahoo-FlvTube"

FF - prefs.js..browser.search.order.1: "Yahoo-FlvTube"

FF - prefs.js..browser.search.selectedEngine: "Google"

FF - prefs.js..browser.search.selectedEngineURL: "http://flvtubesearch.co/?tmp=toolbar_FLVTube_results&prt=flvtubetb01ff&clid=99b18cfd5d184cdc80820914e75451de&subid=2728&Keywords={searchTerms}"

FF - prefs.js..browser.startup.homepage: ""

FF - prefs.js..extensions.enabledItems: {ad55c869-668e-457c-b270-0cfb2f61116f}:2.7.2.0

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20

FF - prefs.js..extensions.enabledItems: FFPDFConverter@ib.com:1.0

FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0

FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:5.1

FF - prefs.js..extensions.enabledItems: LogMeInClient@logmein.com:1.0.0.608

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22

FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0

FF - HKLM\software\mozilla\Firefox\extensions\\FFPDFConverter@ib.com: C:\Program Files\PDF Suite 2010\firefoxextension [2010/10/05 11:11:01 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Firefox\extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\IPSFFPlgn\ [2010/10/12 20:42:11 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Firefox\extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\coFFPlgn\ [2010/10/12 20:41:29 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/10/04 23:29:24 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/11/23 01:39:36 | 000,000,000 | ---D | M]

[2010/10/13 11:52:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jim\Application Data\Mozilla\Extensions

[2010/10/13 08:00:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jim\Application Data\Mozilla\Extensions\mozswing@mozswing.org

[2010/11/23 01:42:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jim\Application Data\Mozilla\Firefox\Profiles\po7mzqvu.default\extensions

[2010/10/29 20:46:37 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Jim\Application Data\Mozilla\Firefox\Profiles\po7mzqvu.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}

[2010/10/29 20:46:35 | 000,000,000 | ---D | M] (livetvbar Toolbar) -- C:\Documents and Settings\Jim\Application Data\Mozilla\Firefox\Profiles\po7mzqvu.default\extensions\{ad55c869-668e-457c-b270-0cfb2f61116f}

[2010/11/11 14:08:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jim\Application Data\Mozilla\Firefox\Profiles\po7mzqvu.default\extensions\LogMeInClient@logmein.com

[2010/11/23 01:42:16 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions

[2010/10/08 22:51:46 | 000,000,000 | ---D | M] (livetvbar Toolbar) -- C:\Program Files\Mozilla Firefox\extensions\{ad55c869-668e-457c-b270-0cfb2f61116f}

[2010/10/08 22:52:03 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}

[2010/11/23 00:12:34 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}

[2010/11/23 00:12:12 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

[2010/10/13 16:39:06 | 000,008,603 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\flvtube.xml

O1 HOSTS File: ([2010/11/18 01:53:46 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts

O1 - Hosts: 127.0.0.1 localhost

O2 - BHO: (PDF Suite Helper) - {1AD61D5B-58A3-4592-9B34-DC84688FF805} - C:\Program Files\PDF Suite 2010\PDFIEHelper.dll (Interactive Brands Inc.)

O2 - BHO: (no name) - {266fcdca-7bb3-4da7-b3bf-f845dea2ebd6} - No CLSID value found.

O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)

O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\18.1.0.37\CoIEPlg.dll (Symantec Corporation)

O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\18.1.0.37\IPSBHO.dll (Symantec Corporation)

O3 - HKLM\..\Toolbar: (PDF Suite Toolbar) - {261F6A8B-7AAF-4BF5-8552-6610F4D67819} - C:\Program Files\PDF Suite 2010\PDFIEPlugin.dll (Interactive Brands Inc.)

O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\18.1.0.37\CoIEPlg.dll (Symantec Corporation)

O3 - HKU\S-1-5-21-606747145-1770027372-682003330-1014\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\18.1.0.37\CoIEPlg.dll (Symantec Corporation)

O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)

O4 - HKLM..\Run: [Carbonite Backup] C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe (Carbonite, Inc.)

O4 - HKLM..\Run: [dvd43] C:\Program Files\dvd43\DVD43_Tray.exe ()

O4 - HKLM..\Run: [HostManager] C:\Program Files\Common Files\AOL\1286184261\ee\aolsoftware.exe (America Online, Inc.)

O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)

O4 - HKLM..\Run: [soundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)

O4 - HKLM..\Run: [switchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)

O4 - HKLM..\Run: [yDecode] C:\Program Files\yDecode\yDecode.exe ()

O4 - HKU\S-1-5-21-606747145-1770027372-682003330-1014..\Run: [AOL Fast Start] C:\Program Files\AOL 9.0b\AOL.EXE (AOL, LLC.)

O4 - HKU\S-1-5-21-606747145-1770027372-682003330-1014..\Run: [iSUSPM] C:\Documents and Settings\All Users\Application Data\FLEXnet\Connect\11\ISUSPM.exe File not found

O4 - HKU\S-1-5-21-606747145-1770027372-682003330-1014..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)

O4 - HKU\S-1-5-21-606747145-1770027372-682003330-1014..\Run: [yDecode] C:\Program Files\yDecode\yDecode.exe ()

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit, Inc.)

O4 - Startup: C:\Documents and Settings\Jim\Start Menu\Programs\Startup\LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe (Lime Wire, LLC)

O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-21-606747145-1770027372-682003330-1014\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-21-606747145-1770027372-682003330-1014\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O7 - HKU\S-1-5-21-606747145-1770027372-682003330-1014\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O7 - HKU\S-1-5-21-606747145-1770027372-682003330-1014\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)

O15 - HKU\S-1-5-21-606747145-1770027372-682003330-1014\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)

O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2...78f/wvc1dmo.cab (Reg Error: Key error.)

O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)

O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} http://picture.vzw.com/activex/VerizonWire...loadControl.cab (Verizon Wireless Media Upload)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_22)

O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_22)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_22)

O16 - DPF: {CF4A2C45-CB89-4018-94BB-C2CACB83A537} https://www.myremotemanager.com/myrm/device/xancamx.ocx (XancamX Camera Control)

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab (Shockwave Flash Object)

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)

O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2010/10/13 23:24:53 | 000,000,050 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]

O34 - HKLM BootExecute: (autocheck autochk *) - File not found

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37 - HKLM\...com [@ = ComFile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

NetSvcs: 6to4 - File not found

NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found

NetSvcs: Ias - File not found

NetSvcs: Iprip - File not found

NetSvcs: Irmon - File not found

NetSvcs: NWCWorkstation - File not found

NetSvcs: Nwsapagent - File not found

NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)

Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)

Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)

Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)

Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)

Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()

Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()

Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)

Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT

Error starting restore point: System Restore is disabled.

Error closing restore point: System Restore is disabled.

========== Files/Folders - Created Within 30 Days ==========

[2010/11/23 12:01:23 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Jim\Desktop\OTL.exe

[2010/11/23 01:55:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jim\Local Settings\Application Data\NPE

[2010/11/23 01:51:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jim\Desktop\TMRBLog

[2010/11/23 01:51:19 | 000,161,296 | ---- | C] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmcomm.sys

[2010/11/23 01:51:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jim\Desktop\log

[2010/11/23 01:34:35 | 000,000,000 | ---D | C] -- C:\WINDOWS\Minidump

[2010/11/23 00:58:16 | 005,716,848 | ---- | C] (Symantec Corporation) -- C:\Documents and Settings\Jim\Desktop\NPE.exe

[2010/11/23 00:01:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jim\Desktop\Super Flex

[2010/11/23 00:00:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jim\Desktop\Malware Project

[2010/11/22 09:05:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jim\DoctorWeb

[2010/11/19 15:46:08 | 000,000,000 | -HSD | C] -- C:\RECYCLER

[2010/11/18 22:04:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jim\Application Data\FLEXnet

[2010/11/18 22:04:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jim\Application Data\Nuance

[2010/11/18 01:38:30 | 000,000,000 | ---D | C] -- C:\ComboFix

[2010/11/17 15:30:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jim\Application Data\Zeon

[2010/11/17 15:30:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Nuance

[2010/11/17 15:30:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Downloaded Installations

[2010/11/16 08:27:25 | 000,000,000 | ---D | C] -- C:\Program Files\ESET

[2010/11/13 09:58:08 | 000,000,000 | RHSD | C] -- C:\cmdcons

[2010/11/13 09:56:24 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe

[2010/11/13 09:56:24 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe

[2010/11/13 09:56:24 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe

[2010/11/13 09:56:24 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe

[2010/11/13 09:56:17 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT

[2010/11/09 06:59:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jim\My Documents\ChondroitinSpecs

[2010/11/08 13:11:31 | 000,000,000 | ---D | C] -- C:\epson

[2010/11/07 17:19:10 | 000,043,952 | R--- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\SymIM.sys

[2010/11/07 15:56:35 | 000,000,000 | ---D | C] -- C:\Program Files\active ports

[2010/11/07 15:51:30 | 000,049,664 | ---- | C] (MindVision Software) -- C:\WINDOWS\unvise32.exe

[2010/11/07 15:45:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jim\Desktop\Aports

[2010/11/06 07:32:43 | 000,098,392 | ---- | C] (Sunbelt Software) -- C:\WINDOWS\System32\drivers\SBREDrv.sys

[2010/11/05 12:30:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jim\Application Data\CopyToDvd

[2010/11/05 12:27:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jim\Local Settings\Application Data\ApplicationHistory

[2010/11/05 12:27:18 | 000,000,000 | ---D | C] -- C:\Program Files\Lantronix

[2010/11/05 12:26:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\URTTEMP

[2010/11/05 12:18:51 | 000,000,000 | ---D | C] -- C:\e74ce0d18378dfb83afaf1e93c276606

[2010/11/03 07:14:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jim\Local Settings\Application Data\Sunbelt Software

[2010/11/03 07:14:16 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\~0

[2010/11/03 07:14:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Lavasoft

[2010/11/01 07:27:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jim\Application Data\Malwarebytes

[2010/11/01 07:27:01 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys

[2010/11/01 07:27:00 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys

[2010/11/01 07:27:00 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware

[2010/11/01 07:27:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes

[2010/11/01 01:43:40 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro

[2010/11/01 01:43:40 | 000,000,000 | ---D | C] -- C:\rsit

[2010/10/31 02:39:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\UMDF

[2010/10/31 00:37:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jim\Desktop\Movies

[2010/10/30 17:28:32 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Data

[2010/10/30 17:26:27 | 000,197,632 | ---- | C] (Microsoft) -- C:\Program Files\Common Files\OnlineFilesManager.dll

[2010/10/30 15:46:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jim\Desktop\Minolta

[2010/10/27 14:41:59 | 000,043,264 | R--- | C] (Prolific Technology Inc.) -- C:\WINDOWS\System32\drivers\ser2pl.sys

[2010/10/27 14:40:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jim\Desktop\USB Converter

[2010/10/27 14:14:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jim\Desktop\LSR Project

[2010/10/27 12:18:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jim\Desktop\Console(2)

[2010/10/27 10:51:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jim\My Documents\polka

[2010/10/27 10:42:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jim\My Documents\mox

[2010/10/27 08:49:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jim\Local Settings\Application Data\Microsoft Help

[2010/10/27 08:43:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jim\Local Settings\Application Data\PCHealth

[2010/10/27 00:36:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jim\My Documents\bests

[2010/10/26 23:55:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jim\My Documents\me4

[2010/10/26 15:01:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\NtmsData

[2010/10/13 23:14:31 | 000,047,360 | ---- | C] (VSO Software) -- C:\Documents and Settings\Jim\Application Data\pcouffin.sys

========== Files - Modified Within 30 Days ==========

[2010/11/23 12:01:24 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Jim\Desktop\OTL.exe

[2010/11/23 11:44:00 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA1cb6dce7bc6ae60.job

[2010/11/23 06:50:15 | 000,024,983 | ---- | M] () -- C:\WINDOWS\System32\13501517141.dll

[2010/11/23 06:48:19 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl

[2010/11/23 06:48:01 | 000,000,236 | ---- | M] () -- C:\WINDOWS\tasks\OGALogon.job

[2010/11/23 06:47:59 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore1cb6dce7ba088c0.job

[2010/11/23 06:47:49 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat

[2010/11/23 05:18:26 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat

[2010/11/23 01:51:19 | 000,161,296 | ---- | M] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmcomm.sys

[2010/11/23 01:39:37 | 000,001,736 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk

[2010/11/23 00:58:16 | 005,716,848 | ---- | M] (Symantec Corporation) -- C:\Documents and Settings\Jim\Desktop\NPE.exe

[2010/11/22 23:43:52 | 000,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx

[2010/11/22 23:43:26 | 000,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb

[2010/11/22 23:43:25 | 000,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb

[2010/11/22 23:43:01 | 000,000,811 | ---- | M] () -- C:\Documents and Settings\Jim\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk

[2010/11/22 02:52:47 | 000,007,168 | ---- | M] () -- C:\WINDOWS\System32\drivers\utm3mjg4.sys

[2010/11/19 18:00:06 | 000,015,581 | ---- | M] () -- C:\Documents and Settings\Jim\Desktop\Cosequin Analysis.xlsx

[2010/11/19 12:20:24 | 000,040,041 | ---- | M] () -- C:\Documents and Settings\Jim\My Documents\MeGohar.jpg

[2010/11/18 01:53:46 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts

[2010/11/17 08:57:44 | 000,022,165 | ---- | M] () -- C:\Documents and Settings\Jim\My Documents\PanvoPurchaseorder.pdf

[2010/11/16 19:02:11 | 000,020,480 | ---- | M] () -- C:\Documents and Settings\Jim\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2010/11/13 09:58:27 | 000,000,327 | RHS- | M] () -- C:\boot.ini

[2010/11/13 08:28:38 | 000,268,024 | ---- | M] () -- C:\Documents and Settings\Jim\Desktop\Cheyenne Systems Group, LLC.QBI

[2010/11/13 08:28:36 | 007,151,616 | ---- | M] () -- C:\Documents and Settings\Jim\Desktop\Cheyenne Systems Group, LLC.QBW

[2010/11/12 09:13:52 | 000,000,177 | ---- | M] () -- C:\WINDOWS\LSR120 Config(3.4).INI

[2010/11/12 07:44:04 | 000,166,759 | ---- | M] () -- C:\Documents and Settings\Jim\Desktop\IO file Rev 02.pdf

[2010/11/11 15:48:05 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Jim\defogger_reenable

[2010/11/11 12:17:29 | 000,010,435 | ---- | M] () -- C:\Documents and Settings\Jim\Desktop\Phone barcode.jpg

[2010/11/11 11:54:15 | 000,000,279 | ---- | M] () -- C:\Documents and Settings\Jim\Desktop\lbqht3.png

[2010/11/11 10:19:55 | 000,002,521 | ---- | M] () -- C:\Documents and Settings\Jim\Desktop\Microsoft Office Outlook 2007.lnk

[2010/11/09 06:59:42 | 000,076,479 | ---- | M] () -- C:\Documents and Settings\Jim\My Documents\ChondroitinSpecs.zip

[2010/11/08 22:56:21 | 000,125,973 | ---- | M] () -- C:\Documents and Settings\Jim\My Documents\howman leather.mht

[2010/11/08 17:22:56 | 000,024,000 | ---- | M] () -- C:\Documents and Settings\Jim\Desktop\BR900.jpg

[2010/11/08 13:21:40 | 001,870,780 | ---- | M] () -- C:\Documents and Settings\Jim\Desktop\RJAcheck.jpg

[2010/11/08 10:30:50 | 000,011,687 | ---- | M] () -- C:\Documents and Settings\Jim\My Documents\460D.jpg

[2010/11/08 04:32:32 | 000,008,199 | ---- | M] () -- C:\Documents and Settings\Jim\Desktop\Piano Stage Dolly.jpg

[2010/11/08 04:28:44 | 000,001,493 | ---- | M] () -- C:\Documents and Settings\Jim\Desktop\Calculator.lnk

[2010/11/08 01:20:24 | 000,089,088 | ---- | M] () -- C:\WINDOWS\MBR.exe

[2010/11/07 15:56:35 | 000,000,645 | ---- | M] () -- C:\Documents and Settings\Jim\Desktop\active ports.lnk

[2010/11/07 13:43:50 | 000,504,724 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat

[2010/11/07 13:43:50 | 000,088,570 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat

[2010/11/06 07:32:41 | 000,098,392 | ---- | M] (Sunbelt Software) -- C:\WINDOWS\System32\drivers\SBREDrv.sys

[2010/11/05 12:27:44 | 000,000,126 | ---- | M] () -- C:\Documents and Settings\Jim\Local Settings\Application Data\fusioncache.dat

[2010/11/03 07:11:50 | 000,000,958 | ---- | M] () -- C:\Documents and Settings\Jim\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk

[2010/11/02 10:00:21 | 000,022,283 | ---- | M] () -- C:\Documents and Settings\Jim\Desktop\WPS.Hines.Invoice.pdf

[2010/11/01 15:15:09 | 000,022,173 | ---- | M] () -- C:\Documents and Settings\Jim\Desktop\Quote 871.pdf

[2010/11/01 15:14:34 | 000,021,957 | ---- | M] () -- C:\Documents and Settings\Jim\Desktop\Quote872.pdf

[2010/11/01 15:13:16 | 000,021,940 | ---- | M] () -- C:\Documents and Settings\Jim\Desktop\Quote.pdf

[2010/11/01 07:36:41 | 000,001,917 | ---- | M] () -- C:\WINDOWS\imsins.BAK

[2010/11/01 03:14:39 | 000,001,057 | ---- | M] () -- C:\Documents and Settings\Jim\Application Data\vso_ts_preview.xml

[2010/10/31 02:39:21 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf

[2010/10/30 14:51:05 | 000,063,622 | ---- | M] () -- C:\Documents and Settings\Jim\My Documents\IrinaMe.jpg

[2010/10/27 14:01:00 | 000,120,319 | ---- | M] () -- C:\Documents and Settings\Jim\Desktop\LSR120 Config(3.4).zip

[2010/10/27 12:48:55 | 000,001,511 | ---- | M] () -- C:\Documents and Settings\Jim\Application Data\Microsoft\Internet Explorer\Quick Launch\Calculator.lnk

[2010/10/27 12:38:06 | 000,714,279 | ---- | M] () -- C:\Documents and Settings\Jim\Desktop\Unofficial Code and Rules 8-18-2009.pdf

[2010/10/27 12:18:14 | 001,754,532 | ---- | M] () -- C:\Documents and Settings\Jim\Desktop\Console(2).zip

[2010/10/27 11:03:55 | 000,461,505 | ---- | M] () -- C:\Documents and Settings\Jim\My Documents\mox.zip

[2010/10/27 10:51:23 | 000,461,505 | ---- | M] () -- C:\Documents and Settings\Jim\My Documents\polka.zip

[2010/10/27 00:36:15 | 000,062,520 | ---- | M] () -- C:\Documents and Settings\Jim\My Documents\bests.zip

[2010/10/27 00:31:12 | 000,187,115 | ---- | M] () -- C:\Documents and Settings\Jim\My Documents\mox.jpg

[2010/10/27 00:20:59 | 000,464,002 | ---- | M] () -- C:\Documents and Settings\Jim\My Documents\pool.jpg

[2010/10/27 00:00:21 | 000,275,521 | ---- | M] () -- C:\Documents and Settings\Jim\My Documents\polka.jpg

[2010/10/26 23:57:17 | 000,180,461 | ---- | M] () -- C:\Documents and Settings\Jim\My Documents\mox1.jpg

[2010/10/26 23:55:24 | 000,272,372 | ---- | M] () -- C:\Documents and Settings\Jim\My Documents\me4.zip

[2010/10/26 23:49:21 | 000,964,038 | ---- | M] () -- C:\Documents and Settings\Jim\My Documents\me.bmp

[2010/10/26 15:48:40 | 000,088,179 | ---- | M] () -- C:\Documents and Settings\Jim\My Documents\imageee.jpg

[2010/10/25 11:03:28 | 000,921,654 | ---- | M] () -- C:\Documents and Settings\Jim\Desktop\untitled.bmp

[2010/10/25 04:13:53 | 000,598,176 | ---- | M] () -- C:\Documents and Settings\Jim\Desktop\Time Warp.mp3

[2010/10/25 04:11:34 | 000,797,472 | ---- | M] () -- C:\Documents and Settings\Jim\Desktop\timewarp.mp3

========== Files Created - No Company Name ==========

[2010/11/23 06:50:15 | 000,024,983 | ---- | C] () -- C:\WINDOWS\System32\13501517141.dll

[2010/11/22 23:43:07 | 000,023,392 | ---- | C] () -- C:\WINDOWS\System32\nscompat.tlb

[2010/11/22 23:43:07 | 000,016,832 | ---- | C] () -- C:\WINDOWS\System32\amcompat.tlb

[2010/11/22 02:52:47 | 000,007,168 | ---- | C] () -- C:\WINDOWS\System32\drivers\utm3mjg4.sys

[2010/11/19 12:20:24 | 000,040,041 | ---- | C] () -- C:\Documents and Settings\Jim\My Documents\MeGohar.jpg

[2010/11/17 08:57:43 | 000,022,165 | ---- | C] () -- C:\Documents and Settings\Jim\My Documents\PanvoPurchaseorder.pdf

[2010/11/13 09:58:27 | 000,000,211 | ---- | C] () -- C:\Boot.bak

[2010/11/13 09:58:13 | 000,260,272 | RHS- | C] () -- C:\cmldr

[2010/11/13 09:56:24 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe

[2010/11/13 09:56:24 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe

[2010/11/13 09:56:24 | 000,089,088 | ---- | C] () -- C:\WINDOWS\MBR.exe

[2010/11/13 09:56:24 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe

[2010/11/13 09:56:24 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe

[2010/11/12 09:13:15 | 000,000,177 | ---- | C] () -- C:\WINDOWS\LSR120 Config(3.4).INI

[2010/11/12 07:44:04 | 000,166,759 | ---- | C] () -- C:\Documents and Settings\Jim\Desktop\IO file Rev 02.pdf

[2010/11/11 15:48:05 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Jim\defogger_reenable

[2010/11/11 12:17:29 | 000,010,435 | ---- | C] () -- C:\Documents and Settings\Jim\Desktop\Phone barcode.jpg

[2010/11/11 11:54:29 | 000,000,279 | ---- | C] () -- C:\Documents and Settings\Jim\Desktop\lbqht3.png

[2010/11/09 06:59:38 | 000,076,479 | ---- | C] () -- C:\Documents and Settings\Jim\My Documents\ChondroitinSpecs.zip

[2010/11/08 22:56:20 | 000,125,973 | ---- | C] () -- C:\Documents and Settings\Jim\My Documents\howman leather.mht

[2010/11/08 17:23:23 | 000,024,000 | ---- | C] () -- C:\Documents and Settings\Jim\Desktop\BR900.jpg

[2010/11/08 13:21:38 | 001,870,780 | ---- | C] () -- C:\Documents and Settings\Jim\Desktop\RJAcheck.jpg

[2010/11/08 09:16:28 | 000,011,687 | ---- | C] () -- C:\Documents and Settings\Jim\My Documents\460D.jpg

[2010/11/08 04:33:06 | 000,008,199 | ---- | C] () -- C:\Documents and Settings\Jim\Desktop\Piano Stage Dolly.jpg

[2010/11/07 15:55:23 | 000,000,645 | ---- | C] () -- C:\Documents and Settings\Jim\Desktop\active ports.lnk

[2010/11/05 12:27:44 | 000,000,126 | ---- | C] () -- C:\Documents and Settings\Jim\Local Settings\Application Data\fusioncache.dat

[2010/11/03 07:11:50 | 000,000,958 | ---- | C] () -- C:\Documents and Settings\Jim\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk

[2010/11/02 10:00:20 | 000,022,283 | ---- | C] () -- C:\Documents and Settings\Jim\Desktop\WPS.Hines.Invoice.pdf

[2010/11/01 15:15:08 | 000,022,173 | ---- | C] () -- C:\Documents and Settings\Jim\Desktop\Quote 871.pdf

[2010/11/01 15:14:33 | 000,021,957 | ---- | C] () -- C:\Documents and Settings\Jim\Desktop\Quote872.pdf

[2010/11/01 15:13:16 | 000,021,940 | ---- | C] () -- C:\Documents and Settings\Jim\Desktop\Quote.pdf

[2010/11/01 10:50:08 | 000,268,024 | ---- | C] () -- C:\Documents and Settings\Jim\Desktop\Cheyenne Systems Group, LLC.QBI

[2010/10/31 02:39:21 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf

[2010/10/30 14:51:05 | 000,063,622 | ---- | C] () -- C:\Documents and Settings\Jim\My Documents\IrinaMe.jpg

[2010/10/27 14:01:34 | 000,120,319 | ---- | C] () -- C:\Documents and Settings\Jim\Desktop\LSR120 Config(3.4).zip

[2010/10/27 12:38:06 | 000,714,279 | ---- | C] () -- C:\Documents and Settings\Jim\Desktop\Unofficial Code and Rules 8-18-2009.pdf

[2010/10/27 12:18:06 | 001,754,532 | ---- | C] () -- C:\Documents and Settings\Jim\Desktop\Console(2).zip

[2010/10/27 10:51:16 | 000,461,505 | ---- | C] () -- C:\Documents and Settings\Jim\My Documents\polka.zip

[2010/10/27 10:42:32 | 000,461,505 | ---- | C] () -- C:\Documents and Settings\Jim\My Documents\mox.zip

[2010/10/27 00:36:14 | 000,062,520 | ---- | C] () -- C:\Documents and Settings\Jim\My Documents\bests.zip

[2010/10/27 00:31:11 | 000,187,115 | ---- | C] () -- C:\Documents and Settings\Jim\My Documents\mox.jpg

[2010/10/27 00:00:19 | 000,275,521 | ---- | C] () -- C:\Documents and Settings\Jim\My Documents\polka.jpg

[2010/10/26 23:57:16 | 000,180,461 | ---- | C] () -- C:\Documents and Settings\Jim\My Documents\mox1.jpg

[2010/10/26 23:55:23 | 000,272,372 | ---- | C] () -- C:\Documents and Settings\Jim\My Documents\me4.zip

[2010/10/26 23:49:14 | 000,964,038 | ---- | C] () -- C:\Documents and Settings\Jim\My Documents\me.bmp

[2010/10/25 11:03:28 | 000,921,654 | ---- | C] () -- C:\Documents and Settings\Jim\Desktop\untitled.bmp

[2010/10/25 04:13:46 | 000,598,176 | ---- | C] () -- C:\Documents and Settings\Jim\Desktop\Time Warp.mp3

[2010/10/25 04:12:35 | 000,797,472 | ---- | C] () -- C:\Documents and Settings\Jim\Desktop\timewarp.mp3

[2010/10/24 19:12:02 | 000,088,179 | ---- | C] () -- C:\Documents and Settings\Jim\My Documents\imageee.jpg

[2010/10/20 11:06:23 | 000,001,456 | ---- | C] () -- C:\Documents and Settings\Jim\Local Settings\Application Data\Adobe Save for Web 12.0 Prefs

[2010/10/14 22:42:24 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\CNMVS5p.DLL

[2010/10/13 23:25:48 | 000,001,024 | RH-- | C] () -- C:\WINDOWS\System32\NTIDBD32.dll

[2010/10/13 23:25:20 | 000,001,024 | RH-- | C] () -- C:\WINDOWS\System32\NTIBUN4.dll

[2010/10/13 23:24:09 | 000,001,024 | RH-- | C] () -- C:\WINDOWS\System32\NTIMPEG2.dll

[2010/10/13 23:24:09 | 000,001,024 | RH-- | C] () -- C:\WINDOWS\System32\NTIFCD3.dll

[2010/10/13 23:24:09 | 000,001,024 | RH-- | C] () -- C:\WINDOWS\System32\NTICDMK7.dll

[2010/10/13 23:15:49 | 000,001,057 | ---- | C] () -- C:\Documents and Settings\Jim\Application Data\vso_ts_preview.xml

[2010/10/13 23:14:34 | 000,000,034 | ---- | C] () -- C:\Documents and Settings\Jim\Application Data\pcouffin.log

[2010/10/13 23:14:31 | 000,007,887 | ---- | C] () -- C:\Documents and Settings\Jim\Application Data\pcouffin.cat

[2010/10/13 23:14:31 | 000,001,144 | ---- | C] () -- C:\Documents and Settings\Jim\Application Data\pcouffin.inf

[2010/10/13 15:28:16 | 000,020,480 | ---- | C] () -- C:\Documents and Settings\Jim\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2010/10/13 14:24:16 | 000,375,296 | ---- | C] () -- C:\WINDOWS\System32\tx32.dll

[2010/10/13 14:24:16 | 000,000,202 | ---- | C] () -- C:\WINDOWS\System32\Ic32.ini

[2010/10/03 23:08:58 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4957.dll

[2010/10/03 16:44:01 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI

[2009/08/03 14:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll

[2005/03/11 17:41:10 | 000,021,952 | -H-- | C] () -- C:\Program Files\folder.htt

[2001/12/26 15:12:30 | 000,065,536 | R--- | C] () -- C:\WINDOWS\System32\multiplex_vcd.dll

[2001/09/03 22:46:38 | 000,110,592 | R--- | C] () -- C:\WINDOWS\System32\Hmpg12.dll

[2001/07/30 15:33:56 | 000,118,784 | R--- | C] () -- C:\WINDOWS\System32\HMPV2_ENC.dll

[2001/07/23 21:04:36 | 000,118,784 | R--- | C] () -- C:\WINDOWS\System32\HMPV2_ENC_MMX.dll

========== LOP Check ==========

[2010/10/30 15:08:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\1Click DVD Copy

[2010/10/08 20:59:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Avery

[2010/10/03 23:49:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Carbonite

[2010/11/17 15:30:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Downloaded Installations

[2010/10/08 21:00:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\GARMIN

[2010/10/08 21:00:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\LightboxSA

[2010/10/08 21:01:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Napster

[2010/10/08 21:01:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NtiDvdCopy

[2010/11/18 22:04:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nuance

[2010/10/13 00:44:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe

[2010/10/08 21:01:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Seagate

[2010/10/08 21:01:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP

[2010/10/08 21:01:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint

[2010/10/24 03:59:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\vsosdk

[2010/10/06 07:01:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip

[2010/10/04 06:35:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{75EE35BC-E993-41FD-9DBA-9AD37F50E521}

[2010/11/23 07:30:25 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\~0

[2010/10/13 11:24:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jim\Application Data\Anthropics

[2010/11/05 12:31:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jim\Application Data\CopyToDvd

[2010/10/13 20:10:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jim\Application Data\Easy Duplicate Finder

[2010/11/18 01:14:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jim\Application Data\FileZilla

[2010/10/13 13:28:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jim\Application Data\KompoZer

[2010/11/23 06:49:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jim\Application Data\LimeWire

[2010/11/18 22:04:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jim\Application Data\Nuance

[2010/10/18 10:12:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jim\Application Data\PDF Software

[2010/10/18 13:24:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jim\Application Data\StageManager.BD092818F67280F4B42B04877600987F0111B594.1

[2010/10/13 16:33:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jim\Application Data\Tific

[2010/11/16 07:36:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jim\Application Data\uTorrent

[2010/11/01 03:14:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jim\Application Data\Vso

[2010/11/17 15:30:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jim\Application Data\Zeon

[2010/11/23 01:34:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\PDF Software

[2010/11/23 06:48:01 | 000,000,236 | ---- | M] () -- C:\WINDOWS\Tasks\OGALogon.job

========== Purity Check ==========

========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >

[2010/04/03 09:58:35 | 000,000,124 | ---- | M] () -- C:\.htaccess

[2009/03/25 12:35:59 | 000,001,024 | ---- | M] () -- C:\.rnd

[2009/12/24 06:43:04 | 000,007,944 | ---- | M] () -- C:\3n43k03o4ZZZZZZZZZ948cd2cd94528181ed0.jpg

[2010/11/23 06:47:44 | 000,005,774 | ---- | M] () -- C:\aaw7boot.log

[2007/08/24 21:21:58 | 000,000,000 | ---- | M] () -- C:\adv1.err

[2005/12/05 21:54:21 | 000,001,039 | ---- | M] () -- C:\aolconnfix.txt

[2010/10/13 23:24:53 | 000,000,050 | ---- | M] () -- C:\AUTOEXEC.BAT

[2010/02/15 20:20:34 | 000,021,766 | ---- | M] () -- C:\avi_log.txt

[2010/10/03 22:50:16 | 000,000,211 | ---- | M] () -- C:\Boot.bak

[2010/11/13 09:58:27 | 000,000,327 | RHS- | M] () -- C:\boot.ini

[2004/08/03 23:00:00 | 000,260,272 | RHS- | M] () -- C:\cmldr

[2010/11/18 01:55:09 | 000,022,837 | ---- | M] () -- C:\ComboFix.txt

[2010/10/03 22:53:57 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS

[2008/03/27 15:04:52 | 000,000,006 | ---- | M] () -- C:\epson1200.txt

[2008/03/27 15:05:01 | 000,000,009 | ---- | M] () -- C:\epson1201.txt

[2009/05/31 13:40:22 | 000,000,000 | ---- | M] () -- C:\famstats.txt

[2009/05/31 13:40:22 | 000,000,000 | ---- | M] () -- C:\Folders.txt

[2007/08/21 15:12:26 | 000,030,496 | ---- | M] () -- C:\homepage2.htmL

[2010/10/03 22:53:57 | 000,000,000 | RHS- | M] () -- C:\IO.SYS

[2010/10/03 22:53:57 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS

[2007/08/25 22:32:49 | 000,610,632 | ---- | M] () -- C:\needyou.mp3

[2008/04/14 00:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM

[2008/04/14 00:00:00 | 000,250,048 | RHS- | M] () -- C:\ntldr

[2010/11/23 06:47:45 | 471,859,199 | -HS- | M] () -- C:\pagefile.sys

[2007/03/24 02:22:22 | 000,010,022 | ---- | M] () -- C:\pb2a.jpg

[2010/03/28 10:17:16 | 000,001,279 | ---- | M] () -- C:\playlist.m3u

[2007/06/09 20:11:20 | 000,254,893 | ---- | M] () -- C:\rmnp0122bs.jpg

[2007/06/09 20:24:55 | 000,260,699 | ---- | M] () -- C:\rmnp0123as.jpg

[2008/02/24 17:28:54 | 000,000,232 | -H-- | M] () -- C:\sqmdata00.sqm

[2008/03/03 02:57:39 | 000,000,232 | -H-- | M] () -- C:\sqmdata01.sqm

[2008/03/03 11:34:23 | 000,000,232 | -H-- | M] () -- C:\sqmdata02.sqm

[2009/09/29 02:01:14 | 000,000,232 | -H-- | M] () -- C:\sqmdata03.sqm

[2009/11/04 03:15:57 | 000,000,232 | -H-- | M] () -- C:\sqmdata04.sqm

[2010/01/13 03:21:31 | 000,000,232 | -H-- | M] () -- C:\sqmdata05.sqm

[2010/01/22 03:22:09 | 000,000,232 | -H-- | M] () -- C:\sqmdata06.sqm

[2010/03/19 19:24:42 | 000,000,232 | -H-- | M] () -- C:\sqmdata07.sqm

[2008/02/10 23:14:47 | 000,000,232 | -H-- | M] () -- C:\sqmdata08.sqm

[2008/02/11 21:36:54 | 000,000,232 | -H-- | M] () -- C:\sqmdata09.sqm

[2008/02/12 04:14:46 | 000,000,232 | -H-- | M] () -- C:\sqmdata10.sqm

[2008/02/12 12:58:16 | 000,000,232 | -H-- | M] () -- C:\sqmdata11.sqm

[2008/02/15 16:47:56 | 000,000,232 | -H-- | M] () -- C:\sqmdata12.sqm

[2008/02/15 16:56:53 | 000,000,232 | -H-- | M] () -- C:\sqmdata13.sqm

[2008/02/15 17:48:33 | 000,000,232 | -H-- | M] () -- C:\sqmdata14.sqm

[2008/02/15 18:03:41 | 000,000,232 | -H-- | M] () -- C:\sqmdata15.sqm

[2008/02/17 06:36:31 | 000,000,232 | -H-- | M] () -- C:\sqmdata16.sqm

[2008/02/20 08:43:42 | 000,000,232 | -H-- | M] () -- C:\sqmdata17.sqm

[2008/02/22 15:57:34 | 000,000,232 | -H-- | M] () -- C:\sqmdata18.sqm

[2008/02/22 16:00:06 | 000,000,232 | -H-- | M] () -- C:\sqmdata19.sqm

[2008/02/24 17:28:54 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt00.sqm

[2008/03/03 02:57:39 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt01.sqm

[2008/03/03 11:34:22 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt02.sqm

[2009/09/29 02:01:14 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt03.sqm

[2009/11/04 03:15:57 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt04.sqm

[2010/01/13 03:21:31 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt05.sqm

[2010/01/22 03:22:08 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt06.sqm

[2010/03/19 19:24:42 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt07.sqm

[2008/02/10 23:14:47 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt08.sqm

[2008/02/11 21:36:54 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt09.sqm

[2008/02/12 04:14:46 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt10.sqm

[2008/02/12 12:58:16 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt11.sqm

[2008/02/15 16:47:56 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt12.sqm

[2008/02/15 16:56:53 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt13.sqm

[2008/02/15 17:48:32 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt14.sqm

[2008/02/15 18:03:41 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt15.sqm

[2008/02/17 06:36:31 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt16.sqm

[2008/02/20 08:43:42 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt17.sqm

[2008/02/22 15:57:33 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt18.sqm

[2008/02/22 16:00:06 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt19.sqm

[2010/11/23 01:32:54 | 000,038,386 | ---- | M] () -- C:\TDSSKiller.2.4.8.0_23.11.2010_01.31.02_log.txt

[2008/04/30 15:32:00 | 000,107,596 | ---- | M] () -- C:\toolkit_widget.gif

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

[2010/10/03 16:42:34 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav

[2010/10/03 16:42:34 | 001,089,536 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav

[2010/10/03 16:42:34 | 000,905,216 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-11-11 10:03:21

< End of report >

OTL Extras logfile created on: 11/23/2010 12:05:12 PM - Run 1

OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Jim\Desktop

Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 72.00% Memory free

7.00 Gb Paging File | 7.00 Gb Available in Paging File | 90.00% Paging File free

Paging file location(s): C:\pagefile.sys 4546 6092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 931.50 Gb Total Space | 729.47 Gb Free Space | 78.31% Space Free | Partition Type: NTFS

Computer Name: DESK | User Name: Jim | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: All users | Quick Scan

Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

batfile [open] -- "%1" %*

cmdfile [open] -- "%1" %*

comfile [open] -- "%1" %*

exefile [open] -- "%1" %*

htafile [open] -- "%1" %*

piffile [open] -- "%1" %*

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- "%1"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)

scrfile [open] -- "%1" /S

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()

Directory [bridge] -- C:\Program Files\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()

Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)

Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"FirstRunDisabled" = 1

"AntiVirusDisableNotify" = 0

"FirewallDisableNotify" = 0

"UpdatesDisableNotify" = 0

"AntiVirusOverride" = 0

"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]

"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]

"Start" = 4

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]

"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004

"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005

"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001

"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

"EnableFirewall" = 0

"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007

"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004

"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005

"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001

"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL Connectivity Service Dialer -- (AOL LLC)

"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL Connectivity Service -- (AOL LLC)

"C:\Program Files\AOL 9.0b\waol.exe" = C:\Program Files\AOL 9.0b\waol.exe:*:Enabled:AOL -- (AOL, LLC.)

"C:\Program Files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe" = C:\Program Files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe:*:Enabled:AOL TopSpeed -- (AOL LLC)

"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader -- (America Online, Inc.)

"C:\Program Files\Common Files\AOL\System Information\sinf.exe" = C:\Program Files\Common Files\AOL\System Information\sinf.exe:*:Enabled:AOL System Information -- (AOL LLC)

"C:\Program Files\yDecode\yDecode.exe" = C:\Program Files\yDecode\yDecode.exe:*:Enabled:yDecode -- ()

"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:

Link to post
Share on other sites

Additional Information - this comes from watching Norton's History Monitor. This morning, it's been blocking repeated intrusion attempts from a risk name HTTP Misleading Application Detection. The firewall continues to block hundreds of attempts calling them "Rule Default Blocked Microsoft Windows 2000 SMB blocked (xxx.xxx.xxx.xxx, Port xxx)). Inbound TCP connection."

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.