Jump to content

Infection remains after Attempted Removal


Recommended Posts

To Whomever,

My desktop got infected with the "Google Redirect" problem. Attempting a fix given by a friend who has had multiple successes didn't work. Redirection occurs, with a Malwarebytes message about blocking an outbound IP address. Ran DDS, and the following are the two files that were created.

DDS.txt

--------

.

DDS (Ver_2011-08-26.01) - NTFSx86

Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_23

Run by Owner at 15:08:39 on 2011-10-17

Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1278.592 [GMT -7:00]

.

AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}

AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}

.

============== Running Processes ===============

.

C:\WINNT\system32\svchost -k DcomLaunch

svchost.exe

c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe

C:\WINNT\System32\svchost.exe -k netsvcs

svchost.exe

svchost.exe

C:\WINNT\Explorer.EXE

C:\WINNT\system32\spoolsv.exe

C:\Program Files\Winamp\Winampa.exe

C:\WINNT\System32\igfxtray.exe

C:\WINNT\System32\hkcmd.exe

C:\WINNT\system32\SK9910DM.EXE

C:\WINNT\GWMDMMSG.exe

C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe

C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

C:\Program Files\HP\hpcoretech\hpcmpmgr.exe

C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe

C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe

C:\Program Files\Common Files\Java\Java Update\jusched.exe

C:\Program Files\Microsoft Security Client\msseces.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe

svchost.exe

C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE

C:\WINNT\system32\ctfmon.exe

C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe

C:\WINNT\System32\drivers\CDAC11BA.EXE

C:\PROGRA~1\Borland\INTERB~1\Bin\IBGuard.EXE

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

C:\Corel\Suite8\Programs\DAD8.EXE

C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe

C:\WINNT\system32\PSIService.exe

C:\Program Files\CyberLink\Shared Files\RichVideo.exe

C:\WINNT\System32\svchost.exe -k imgsvc

C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

C:\WINNT\System32\TSIRCSRV.EXE

C:\Program Files\Common Files\Java\Java Update\jucheck.exe

C:\PROGRA~1\Borland\INTERB~1\Bin\ibserver.exe

C:\WINNT\System32\HPZipm12.exe

C:\WINNT\System32\svchost.exe -k HTTPFilter

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Program Files\Outlook Express\msimn.exe

C:\Program Files\Messenger\msmsgs.exe

.

============== Pseudo HJT Report ===============

.

uStart Page = hxxp://www.examiner-enterprise.com/

mWinlogon: Userinit=c:\winnt\system32\userinit.exe,c:\winnt\tsi32\tsircusr.exe,

BHO: {0e253a3a-66a3-4ba7-add7-52e0b872d27c} - c:\documents and settings\owner\local settings\application data\NetworkSys32.dll

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll

BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File

BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll

BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll

TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll

TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File

TB: {C7768536-96F8-4001-B1A2-90EE21279187} - No File

EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File

uRun: [MoneyAgent] "c:\program files\microsoft money\system\Money Express.exe"

uRun: [Microsoft Works Update Detection] ???\WkDetect.exe

uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\WCESCOMM.EXE"

uRun: [ctfmon.exe] c:\winnt\system32\ctfmon.exe

uRun: [updateMgr] "c:\program files\adobe\acrobat 7.0\reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1

uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden

mRun: [WinampAgent] "c:\program files\winamp\Winampa.exe"

mRun: [Keyboard Preload Check] c:\oemdrvrs\keyb\Preload.exe /DEVID: /CLASS:Keyboard /RunValue:"Keyboard Preload Check"

mRun: [igfxTray] c:\winnt\system32\igfxtray.exe

mRun: [HotKeysCmds] c:\winnt\system32\hkcmd.exe

mRun: [Hot Key Kbd 9910 Daemon] SK9910DM.EXE

mRun: [GWMDMpi] c:\winnt\GWMDMpi.exe

mRun: [GWMDMMSG] GWMDMMSG.exe

mRun: [AdaptecDirectCD] "c:\program files\adaptec\easy cd creator 5\directcd\DirectCD.exe"

mRun: [HP Software Update] "c:\program files\hp\hp software update\HPWuSchd2.exe"

mRun: [HP Component Manager] "c:\program files\hp\hpcoretech\hpcmpmgr.exe"

mRun: [QuickFinder Scheduler] "c:\program files\wordperfect office x3\programs\QFSCHD130.EXE"

mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"

mRun: [LanguageShortcut] "c:\program files\cyberlink\powerdvd\language\Language.exe"

mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime

mRun: [symantec PIF AlertEng] "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\pifsvc.exe" /a /m "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\AlertEng.dll"

mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"

mRun: [Adobe Acrobat Speed Launcher] "c:\program files\adobe\acrobat 9.0\acrobat\Acrobat_sl.exe"

mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 9.0\acrobat\Acrotray.exe"

mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"

mRun: [sunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"

mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey

mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray

mRun: [WinPatrol] g:\cleanup\4\winpatrol.exe -expressboot

dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t

StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\coreld~1.lnk - c:\corel\suite8\programs\DAD8.EXE

StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe

StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpimag~1.lnk - c:\program files\hp\digital imaging\bin\hpqthb08.exe

IE: &Add animation to IncrediMail Style Box - c:\progra~1\incred~1\bin\resources\WebMenuImg.htm

IE: Append Link Target to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

IE: Append to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppend.html

IE: Convert Link Target to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

IE: Convert to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html

IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000

IE: Open with WordPerfect - c:\program files\wordperfect office x3\programs\WPLauncher.hta

IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}

IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe

IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe

IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\program files\microsoft activesync\INETREPL.DLL

IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\program files\microsoft activesync\INETREPL.DLL

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL

Trusted Zone: aol.com\free

Trusted Zone: intuit.com\ttlc

Trusted Zone: turbotax.com

DPF: Microsoft XML Parser for Java - file://c:\winnt\java\classes\xmldso.cab

DPF: Sametime Meeting Toolkit ST25 - file://c:\docume~1\owner\locals~1\temp\STMeeting25.cab

DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file:///C:/Program%20Files/SCRABBLE/Images/stg_drm.ocx

DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - hxxp://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab

DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} - hxxps://www-secure.symantec.com/techsupp/asa/ctrl/SymAData.cab

DPF: {41F17733-B041-4099-A042-B518BB6A408C} - hxxp://a1540.g.akamai.net/7/1540/52/20020713/qtinstall.info.apple.com/samantha/us/win/QuickTimeInstaller.exe

DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} - hxxps://www-secure.symantec.com/techsupp/asa/ctrl/tgctlsi.cab

DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} - hxxps://www-secure.symantec.com/techsupp/asa/ctrl/tgctlsr.cab

DPF: {4CCA4E80-9259-11D9-AC6E-444553544200} - hxxp://h30155.www3.hp.com/ediags/dd/install/HPInstallMgr_v01_4.cab

DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - hxxp://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab

DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1167756557062

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab

DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab

DPF: {CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/1.3.1/jinstall-131_02-win.cab

DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab

DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} - file:///C:/Program%20Files/SCRABBLE/Images/armhelper.ocx

DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - hxxp://www.symantec.com/techsupp/asa/ctrl/SymAData.cab

DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -

TCP: DhcpNameServer = 68.116.46.115 24.205.192.61 24.205.224.36

TCP: Interfaces\{C23AC5B2-2867-4F1B-8D88-E1E608D9C037} : DhcpNameServer = 68.116.46.115 24.205.192.61 24.205.224.36

Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll

Handler: lbxfile - {56831180-F115-11d2-B6AA-00104B2B9943} - c:\program files\libronix dls\system\FileProt.dll

Handler: lbxres - {24508F1B-9E94-40EE-9759-9AF5795ADF52} - c:\program files\libronix dls\system\ResProt.dll

Handler: mctp - {d7b95390-b1c5-11d0-b111-0080c712fe82} - c:\program files\microsoft activesync\AATP.DLL

WinCE Filter: image/bmp - {86F59FAE-FB3A-11D1-AA72-00C04FAE2D4B} - c:\program files\microsoft activesync\CENETFLT.DLL

WinCE Filter: image/gif - {86F59FAE-FB3A-11D1-AA72-00C04FAE2D4B} - c:\program files\microsoft activesync\CENETFLT.DLL

WinCE Filter: image/jpeg - {86F59FAE-FB3A-11D1-AA72-00C04FAE2D4B} - c:\program files\microsoft activesync\CENETFLT.DLL

WinCE Filter: image/xbm - {86F59FAE-FB3A-11D1-AA72-00C04FAE2D4B} - c:\program files\microsoft activesync\CENETFLT.DLL

WinCE Filter: text/asp - {6C5C3074-FFAB-11d1-8EC4-00C04F98D57A} - c:\program files\microsoft activesync\CENETFLT.DLL

WinCE Filter: text/html - {6C5C3074-FFAB-11d1-8EC4-00C04F98D57A} - c:\program files\microsoft activesync\CENETFLT.DLL

Notify: igfxcui - igfxsrvc.dll

SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\winnt\system32\WPDShServiceObj.dll

SEH: {A213B520-C6C2-11d0-AF9D-008029E1027E} - No File

SEH: Quick View Plus - ShellExecute Hook: {0cab0400-7395-11d0-a5e5-0020afe2fdd9} - qvphook.dll

.

================= FIREFOX ===================

.

FF - ProfilePath - c:\documents and settings\owner\application data\mozilla\firefox\profiles\kzarc8u3.default\

FF - prefs.js: browser.search.selectedEngine - Google

FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/

FF - plugin: c:\documents and settings\owner\application data\move networks\plugins\npqmp071505000011.dll

FF - plugin: c:\program files\adobe\acrobat 9.0\acrobat\air\nppdf32.dll

FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll

FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll

FF - plugin: c:\program files\mozilla firefox\plugins\NPTURNMED.dll

FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll

FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}

FF - Ext: XUL Cache: {77e0db38-36fa-4529-8bc8-0ed29bd76027} - %profile%\extensions\{77e0db38-36fa-4529-8bc8-0ed29bd76027}

FF - Ext: XUL Cache: {5428796a-0b6d-4991-b121-9d41eeba65a2} - %profile%\extensions\{5428796a-0b6d-4991-b121-9d41eeba65a2}

FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}

FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\winnt\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension

FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\java\jre6\lib\deploy\jqs\ff

FF - Ext: Move Media Player: moveplayer@movenetworks.com - c:\documents and settings\owner\application data\Move Networks

.

============= SERVICES / DRIVERS ===============

.

R1 MpFilter;Microsoft Malware Protection Driver;c:\winnt\system32\drivers\MpFilter.sys [2009-12-2 165648]

R1 MpKsl02a19044;MpKsl02a19044;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{7092a0bb-7243-4c11-b746-0bedee0d5526}\MpKsl02a19044.sys [2011-10-17 28752]

R1 tsircmir;LapLink Mirror Driver Miniport;c:\winnt\system32\drivers\tsircmir.sys [2005-4-6 2816]

R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2010-3-26 366152]

R2 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2006-7-30 1251720]

R2 TSISER;TSISER;c:\winnt\system32\drivers\tsiser.sys [2005-4-6 42560]

R2 TSISTRMX;Traveling Software Stream Driver;c:\winnt\system32\drivers\TSISTRMX.SYS [2005-4-6 5120]

R3 MBAMProtector;MBAMProtector;c:\winnt\system32\drivers\mbam.sys [2010-3-26 22216]

R3 TotRec7;Total Recorder WDM audio driver;c:\winnt\system32\drivers\TotRec7.sys [2010-6-17 131152]

R3 TotRec8;Total Recorder WDM audio filter driver;c:\winnt\system32\drivers\TotRec8.sys [2010-6-17 91216]

R3 TSIKBF5;Traveling Software Keyboard Filter Driver;c:\winnt\system32\drivers\TSIKBF5.sys [2005-4-6 9728]

R3 TSIMSF5;Traveling Software Mouse Filter Driver;c:\winnt\system32\drivers\TSIMSF5.sys [2005-4-6 5632]

RUnknown SASKUTIL;SASKUTIL; [x]

S1 MpKsl0e4661b5;MpKsl0e4661b5;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{9ec077ed-d02c-4469-839c-ae009ff3a140}\mpksl0e4661b5.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{9ec077ed-d02c-4469-839c-ae009ff3a140}\MpKsl0e4661b5.sys [?]

S1 MpKsl36a56b80;MpKsl36a56b80;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{880c1d19-c5b1-4cb2-8c5a-5b5638c95ac8}\mpksl36a56b80.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{880c1d19-c5b1-4cb2-8c5a-5b5638c95ac8}\MpKsl36a56b80.sys [?]

S1 MpKsled1cb117;MpKsled1cb117;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{e927418d-049c-476e-99e6-c63009f75d94}\mpksled1cb117.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{e927418d-049c-476e-99e6-c63009f75d94}\MpKsled1cb117.sys [?]

S1 TSIRCINK;Traveling Software Install Driver;c:\winnt\system32\drivers\TSIRCINK.SYS [2005-4-6 9216]

S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\logmein\x86\LMIGuardianSvc.exe [2010-10-14 374152]

S3 BW2NDIS5;BW2NDIS5;c:\winnt\system32\drivers\bw2ndis5.sys --> c:\winnt\system32\drivers\BW2NDIS5.sys [?]

S3 iscFlash;iscFlash;\??\c:\winnt\system32\drivers\iscflash.sys --> c:\winnt\system32\drivers\iscflash.sys [?]

S3 LLUSBFLT;LLUSBFLT;c:\winnt\system32\drivers\NcBulk.SYS [2005-4-6 23628]

S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\winnt\system32\drivers\mbamswissarmy.sys --> c:\winnt\system32\drivers\mbamswissarmy.sys [?]

S3 NCBULK;NCBULK;c:\winnt\system32\drivers\NcBulk.SYS [2005-4-6 23628]

S3 NET1080;LapLink Inc. USB Cable Network Adapter;c:\winnt\system32\drivers\nettc.sys [2002-6-18 12536]

S3 PCDRDRV;Pcdr Helper Driver;\??\c:\atf\qctest\pcdoc\pcdrdrv.sys --> c:\atf\qctest\pcdoc\PCDRDRV.sys [?]

S3 RTL819xp;Realtek RTL8190\RTL8192E 802.11n Wireless LAN (Mini-)PCI NIC NT Driver;c:\winnt\system32\drivers\rtl819xp.sys [2010-11-4 519168]

S3 USBTC;USBTC;c:\winnt\system32\drivers\usbtc.sys [2002-6-18 13672]

.

=============== Created Last 30 ================

.

2011-10-17 11:53:16 28752 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{7092a0bb-7243-4c11-b746-0bedee0d5526}\MpKsl02a19044.sys

2011-10-17 11:45:06 56200 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{7092a0bb-7243-4c11-b746-0bedee0d5526}\offreg.dll

2011-10-17 08:50:31 -------- d-----w- c:\documents and settings\owner\application data\WinPatrol

2011-10-17 01:44:23 -------- d-----w- c:\documents and settings\all users\application data\Spybot - Search & Destroy

2011-10-16 22:41:44 7269712 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{7092a0bb-7243-4c11-b746-0bedee0d5526}\mpengine.dll

2011-10-16 22:29:14 -------- d-----w- c:\program files\SUPERAntiSpyware

2011-10-16 19:59:02 -------- d-----w- c:\documents and settings\all users\application data\SUPERAntiSpyware.com

.

==================== Find3M ====================

.

2011-10-03 11:40:14 404640 ----a-w- c:\winnt\system32\FlashPlayerCPLApp.cpl

2011-09-26 18:41:20 611328 ----a-w- c:\winnt\system32\uiautomationcore.dll

2011-09-26 18:41:20 220160 ----a-w- c:\winnt\system32\oleacc.dll

2011-09-26 18:41:14 20480 ----a-w- c:\winnt\system32\oleaccrc.dll

2011-09-19 21:58:27 1734 --sha-w- c:\winnt\system32\KGyGaAvL.sys

2011-09-09 09:12:13 599040 ----a-w- c:\winnt\system32\crypt32.dll

2011-09-06 13:20:51 1858944 ----a-w- c:\winnt\system32\win32k.sys

2011-09-01 00:00:50 22216 ----a-w- c:\winnt\system32\drivers\mbam.sys

2011-08-30 00:27:05 8892928 ----a-w- c:\documents and settings\all users\application data\atscie.msi

2011-08-17 21:32:17 832512 ----a-w- c:\winnt\system32\wininet.dll

2011-08-17 21:32:16 78336 ----a-w- c:\winnt\system32\ieencode.dll

2011-08-17 21:32:16 1830912 ----a-w- c:\winnt\system32\inetcpl.cpl

2011-08-17 21:32:15 17408 ------w- c:\winnt\system32\corpol.dll

2011-08-17 13:49:54 138496 ----a-w- c:\winnt\system32\drivers\afd.sys

2011-08-17 12:22:23 389120 ----a-w- c:\winnt\system32\html.iec

2011-08-12 20:51:26 26488 ----a-w- c:\winnt\system32\spupdsvc.exe

.

============= FINISH: 15:10:07.20 ===============

Attach.txt (sorry, don't know how to zip)

-------

DDS (Ver_2011-08-26.01)

.

Microsoft Windows XP Home Edition

Boot Device: \Device\HarddiskVolume1

Install Date: 14-Jun-2002 12:49:48

System Uptime: 17-Oct-2011 4:43:53 (11 hours ago)

.

Motherboard: Intel Corporation | | D845GRG

Processor: Intel® Pentium® 4 CPU 2.00GHz | X1 | 2000/100mhz

.

==== Disk Partitions =========================

.

A: is Removable

C: is FIXED (NTFS) - 75 GiB total, 20.235 GiB free.

D: is CDROM ()

E: is CDROM ()

.

==== Disabled Device Manager Items =============

.

Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}

Description: Realtek RTL8190 802.11n Wireless LAN (Mini-)PCI NIC

Device ID: PCI\VEN_10EC&DEV_8190&SUBSYS_819010EC&REV_00\4&2AF9ED5&0&00F0

Manufacturer: Realtek Semiconductor Corp.

Name: Realtek RTL8190 802.11n Wireless LAN (Mini-)PCI NIC

PNP Device ID: PCI\VEN_10EC&DEV_8190&SUBSYS_819010EC&REV_00\4&2AF9ED5&0&00F0

Service: RTL819xp

.

==== System Restore Points ===================

.

RP2701: 19-Jul-2011 16:21:09 - Software Distribution Service 3.0

RP2702: 20-Jul-2011 16:21:36 - Software Distribution Service 3.0

RP2703: 21-Jul-2011 15:32:19 - Software Distribution Service 3.0

RP2704: 22-Jul-2011 16:11:01 - System Checkpoint

RP2705: 22-Jul-2011 16:30:22 - Software Distribution Service 3.0

RP2706: 23-Jul-2011 16:08:47 - Software Distribution Service 3.0

RP2707: 24-Jul-2011 15:42:34 - Software Distribution Service 3.0

RP2708: 25-Jul-2011 16:05:35 - Software Distribution Service 3.0

RP2709: 26-Jul-2011 15:51:26 - Software Distribution Service 3.0

RP2710: 27-Jul-2011 16:09:26 - Software Distribution Service 3.0

RP2711: 28-Jul-2011 16:05:58 - Software Distribution Service 3.0

RP2712: 29-Jul-2011 15:38:04 - Software Distribution Service 3.0

RP2713: 30-Jul-2011 16:03:09 - System Checkpoint

RP2714: 30-Jul-2011 16:07:39 - Software Distribution Service 3.0

RP2715: 31-Jul-2011 15:34:15 - Software Distribution Service 3.0

RP2716: 01-Aug-2011 15:34:29 - Software Distribution Service 3.0

RP2717: 02-Aug-2011 16:27:26 - Software Distribution Service 3.0

RP2718: 03-Aug-2011 16:24:38 - Software Distribution Service 3.0

RP2719: 04-Aug-2011 16:22:38 - Software Distribution Service 3.0

RP2720: 05-Aug-2011 16:27:54 - Software Distribution Service 3.0

RP2721: 06-Aug-2011 19:20:22 - Software Distribution Service 3.0

RP2722: 07-Aug-2011 16:15:52 - Software Distribution Service 3.0

RP2723: 08-Aug-2011 15:34:42 - Software Distribution Service 3.0

RP2724: 09-Aug-2011 4:23:10 - Software Distribution Service 3.0

RP2725: 09-Aug-2011 16:26:24 - Software Distribution Service 3.0

RP2726: 10-Aug-2011 16:08:14 - Software Distribution Service 3.0

RP2727: 11-Aug-2011 4:19:48 - Software Distribution Service 3.0

RP2728: 11-Aug-2011 15:44:44 - Software Distribution Service 3.0

RP2729: 12-Aug-2011 15:48:34 - Software Distribution Service 3.0

RP2730: 13-Aug-2011 16:15:36 - Software Distribution Service 3.0

RP2731: 14-Aug-2011 16:05:07 - Software Distribution Service 3.0

RP2732: 15-Aug-2011 16:24:09 - Software Distribution Service 3.0

RP2733: 16-Aug-2011 16:27:17 - Software Distribution Service 3.0

RP2734: 17-Aug-2011 15:59:09 - Software Distribution Service 3.0

RP2735: 18-Aug-2011 15:55:06 - Software Distribution Service 3.0

RP2736: 19-Aug-2011 15:52:47 - Software Distribution Service 3.0

RP2737: 19-Aug-2011 17:35:22 - Installed Sibelius Scorch (Firefox, Opera, Netscape only)

RP2738: 20-Aug-2011 15:41:08 - Software Distribution Service 3.0

RP2739: 21-Aug-2011 15:44:57 - Software Distribution Service 3.0

RP2740: 22-Aug-2011 16:02:56 - Software Distribution Service 3.0

RP2741: 23-Aug-2011 16:10:30 - Software Distribution Service 3.0

RP2742: 24-Aug-2011 17:00:27 - System Checkpoint

RP2743: 25-Aug-2011 4:42:46 - Software Distribution Service 3.0

RP2744: 25-Aug-2011 9:23:09 - Software Distribution Service 3.0

RP2745: 25-Aug-2011 16:00:13 - Software Distribution Service 3.0

RP2746: 26-Aug-2011 16:32:52 - System Checkpoint

RP2747: 27-Aug-2011 4:21:36 - Software Distribution Service 3.0

RP2748: 27-Aug-2011 15:36:52 - Software Distribution Service 3.0

RP2749: 28-Aug-2011 15:50:09 - Software Distribution Service 3.0

RP2750: 29-Aug-2011 15:48:13 - Software Distribution Service 3.0

RP2751: 29-Aug-2011 17:28:00 - Printer Driver WebEx Document Loader Installed

RP2752: 30-Aug-2011 15:40:05 - Software Distribution Service 3.0

RP2753: 30-Aug-2011 17:12:08 - Removed Cisco Network Magic

RP2754: 30-Aug-2011 17:13:03 - Removed Pure Networks Platform

RP2755: 31-Aug-2011 16:06:25 - Software Distribution Service 3.0

RP2756: 01-Sep-2011 16:28:13 - Software Distribution Service 3.0

RP2757: 02-Sep-2011 15:38:52 - Software Distribution Service 3.0

RP2758: 03-Sep-2011 15:33:34 - Software Distribution Service 3.0

RP2759: 04-Sep-2011 15:35:34 - System Checkpoint

RP2760: 04-Sep-2011 15:50:12 - Software Distribution Service 3.0

RP2761: 05-Sep-2011 15:52:31 - Software Distribution Service 3.0

RP2762: 07-Sep-2011 13:39:18 - Software Distribution Service 3.0

RP2763: 07-Sep-2011 15:34:36 - Software Distribution Service 3.0

RP2764: 07-Sep-2011 17:00:18 - Software Distribution Service 3.0

RP2765: 08-Sep-2011 16:03:53 - Software Distribution Service 3.0

RP2766: 09-Sep-2011 16:14:24 - Software Distribution Service 3.0

RP2767: 10-Sep-2011 16:10:38 - Software Distribution Service 3.0

RP2768: 11-Sep-2011 16:32:04 - Software Distribution Service 3.0

RP2769: 12-Sep-2011 15:59:15 - Software Distribution Service 3.0

RP2770: 13-Sep-2011 15:52:50 - Software Distribution Service 3.0

RP2771: 14-Sep-2011 3:41:57 - Software Distribution Service 3.0

RP2772: 14-Sep-2011 16:01:09 - Software Distribution Service 3.0

RP2773: 15-Sep-2011 15:37:16 - Software Distribution Service 3.0

RP2774: 16-Sep-2011 15:50:39 - System Checkpoint

RP2775: 16-Sep-2011 16:22:10 - Software Distribution Service 3.0

RP2776: 17-Sep-2011 16:30:39 - Software Distribution Service 3.0

RP2777: 18-Sep-2011 16:10:16 - Software Distribution Service 3.0

RP2778: 19-Sep-2011 16:07:30 - Software Distribution Service 3.0

RP2779: 20-Sep-2011 15:55:56 - Software Distribution Service 3.0

RP2780: 21-Sep-2011 16:26:06 - Software Distribution Service 3.0

RP2781: 22-Sep-2011 16:14:27 - Software Distribution Service 3.0

RP2782: 23-Sep-2011 15:57:18 - Software Distribution Service 3.0

RP2783: 24-Sep-2011 16:01:17 - System Checkpoint

RP2784: 24-Sep-2011 16:27:57 - Software Distribution Service 3.0

RP2785: 25-Sep-2011 16:12:52 - Software Distribution Service 3.0

RP2786: 26-Sep-2011 15:44:24 - Software Distribution Service 3.0

RP2787: 27-Sep-2011 15:47:07 - Software Distribution Service 3.0

RP2788: 28-Sep-2011 4:38:17 - Software Distribution Service 3.0

RP2789: 28-Sep-2011 15:41:14 - Software Distribution Service 3.0

RP2790: 29-Sep-2011 16:11:33 - Software Distribution Service 3.0

RP2791: 30-Sep-2011 16:12:03 - Software Distribution Service 3.0

RP2792: 01-Oct-2011 16:13:16 - Software Distribution Service 3.0

RP2793: 02-Oct-2011 16:29:48 - Software Distribution Service 3.0

RP2794: 03-Oct-2011 16:16:28 - Software Distribution Service 3.0

RP2795: 04-Oct-2011 16:01:22 - Software Distribution Service 3.0

RP2796: 05-Oct-2011 15:46:39 - Software Distribution Service 3.0

RP2797: 06-Oct-2011 15:34:28 - Software Distribution Service 3.0

RP2798: 07-Oct-2011 15:40:50 - System Checkpoint

RP2799: 07-Oct-2011 16:04:46 - Software Distribution Service 3.0

RP2800: 08-Oct-2011 18:06:56 - Software Distribution Service 3.0

RP2801: 09-Oct-2011 16:29:32 - Software Distribution Service 3.0

RP2802: 10-Oct-2011 16:31:25 - Software Distribution Service 3.0

RP2803: 11-Oct-2011 15:38:07 - Software Distribution Service 3.0

RP2804: 12-Oct-2011 16:39:39 - Software Distribution Service 3.0

RP2805: 12-Oct-2011 17:03:22 - Software Distribution Service 3.0

RP2806: 13-Oct-2011 16:02:31 - Software Distribution Service 3.0

RP2807: 14-Oct-2011 16:09:44 - Software Distribution Service 3.0

RP2808: 15-Oct-2011 15:41:45 - Software Distribution Service 3.0

RP2809: 16-Oct-2011 15:41:21 - Software Distribution Service 3.0

.

==== Installed Programs ======================

.

4200

4200_Help

4200Tour

4200Trb

Adobe Acrobat 9 Pro

Adobe Acrobat 9.4.6 - CPSID_83708

Adobe AIR

Adobe Flash Player 10 ActiveX

Adobe Flash Player 10 Plugin

Adobe Reader 9.4.6

Advanced Office Password Recovery

AiO_Scan

AiOSoftware

Amazing Slow Downer (remove only)

Amazon MP3 Downloader 1.0.3

AnswerWorks 4.0 Runtime - English

Apple Application Support

Apple Software Update

Audacity 1.2.6

Batch Update

Bible Data Type System Files

BMET Study Guide 1.03

BufferChm

CadStd

Common System Files

Compatibility Pack for the 2007 Office system

Copy

Corel WordPerfect Suite 8

CreativeProjects

CreativeProjectsTemplates

Critical Update for Windows Media Player 11 (KB959772)

CueTour

CutePDF Writer 2.7

Destinations

Director

DocProc

DocumentViewer

DVD Player

e-Sword

Easy CD Creator 5 Basic

ESBUnitConv v6.0.1

Fax

Finale 2000

Finale Reader 2011

FLV Player 2.0 (build 25)

Free Convert M4A to MP3 AMR OGG AAC Converter 5.8

FreeRIP v3.09

GMAT POWERPREP

Graphical Query Editor

GTW V.92 Voicemodem

HelpSpot

High Definition Audio Driver Package - KB835221

honestech VHS to DVD 3.0 Deluxe

Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)

Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)

Hotfix for Windows Internet Explorer 7 (KB947864)

Hotfix for Windows Media Format 11 SDK (KB929399)

Hotfix for Windows Media Player 11 (KB939683)

Hotfix for Windows XP (KB2158563)

Hotfix for Windows XP (KB2443685)

Hotfix for Windows XP (KB2570791)

Hotfix for Windows XP (KB952287)

Hotfix for Windows XP (KB954550-v5)

Hotfix for Windows XP (KB961118)

Hotfix for Windows XP (KB970653-v3)

Hotfix for Windows XP (KB976098-v2)

Hotfix for Windows XP (KB979306)

Hotfix for Windows XP (KB981793)

HP Diagnostic Assistant

HP Driver Diagnostics

HP Image Zone 4.2

HP PSC & OfficeJet 4.2

HP Software Update

HPSystemDiagnostics

InstantShare

Intel® 845G Chipset Graphics Driver Software

Intel® PRO Ethernet Adapter and Software

iTunes

Japanese Fonts Support For Adobe Reader 9

Java 2 Runtime Environment Standard Edition v1.3.1_02

Java 2 Runtime Environment, SE v1.4.1_02

Java Auto Updater

Java Web Start

Java 6 Update 23

K-Lite Codec Pack 4.0.0 (Full)

LapLink Gold 11.5

Libronix Digital Library System

Libronix DLS Application

Libronix DLS Shortcuts

LibronixUpdate

LiveUpdate 3.0 (Symantec Corporation)

LiveUpdate Notice (Symantec Corporation)

LLS Resource Driver

Magellan Tools

Malwarebytes' Anti-Malware version 1.51.2.1300

Microsoft .NET Framework 1.1

Microsoft .NET Framework 1.1 Security Update (KB2572067)

Microsoft .NET Framework 1.1 Security Update (KB979906)

Microsoft .NET Framework 2.0 Service Pack 2

Microsoft .NET Framework 3.0 Service Pack 2

Microsoft .NET Framework 3.5 SP1

Microsoft ActiveSync 3.7

Microsoft Antimalware

Microsoft Application Error Reporting

Microsoft Base Smart Card Cryptographic Service Provider Package

Microsoft Compression Client Pack 1.0 for Windows XP

Microsoft Internationalized Domain Names Mitigation APIs

Microsoft National Language Support Downlevel APIs

Microsoft Office File Validation Add-In

Microsoft Office Professional Edition 2003

Microsoft Picture It! Photo 2002

Microsoft PowerPoint Viewer 97

Microsoft Security Client

Microsoft Security Essentials

Microsoft User-Mode Driver Framework Feature Pack 1.0

Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148

Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161

Microsoft Works 2002 Setup Launcher

Move Media Player

Mozilla Firefox (3.6.13)

MSN Music Assistant

MSXML 4.0 SP2 (KB927978)

MSXML 4.0 SP2 (KB936181)

MSXML 4.0 SP2 (KB954430)

MSXML 4.0 SP2 (KB973688)

MUSICMATCH Jukebox

neroxml

Netscape (7.1)

OEB Resource Driver

Overland

Paint Shop Pro 7

PC-Doctor for Windows

PDF Password Cracker Pro v3.2

PDF Resource Driver

PDFCreator

pdfsam

PhotoGallery

PolderbitS Sound Recorder and Editor

PowerDVD

PowerProducer

PrintScreen

ProductContext

PS/2 Millennium Keyboard

QFolder

Quick View Plus

QuickProjects

QuickTime

Readme

SafeCast Shared Components

Scan

SecurDisc Viewer

Security Update for CAPICOM (KB931906)

Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)

Security Update for Microsoft Windows (KB2564958)

Security Update for Step By Step Interactive Training (KB898458)

Security Update for Step By Step Interactive Training (KB923723)

Security Update for Windows Internet Explorer 7 (KB2183461)

Security Update for Windows Internet Explorer 7 (KB2360131)

Security Update for Windows Internet Explorer 7 (KB2416400)

Security Update for Windows Internet Explorer 7 (KB2482017)

Security Update for Windows Internet Explorer 7 (KB2497640)

Security Update for Windows Internet Explorer 7 (KB2530548)

Security Update for Windows Internet Explorer 7 (KB2544521)

Security Update for Windows Internet Explorer 7 (KB2559049)

Security Update for Windows Internet Explorer 7 (KB2586448)

Security Update for Windows Internet Explorer 7 (KB928090)

Security Update for Windows Internet Explorer 7 (KB929969)

Security Update for Windows Internet Explorer 7 (KB931768)

Security Update for Windows Internet Explorer 7 (KB933566)

Security Update for Windows Internet Explorer 7 (KB937143)

Security Update for Windows Internet Explorer 7 (KB938127)

Security Update for Windows Internet Explorer 7 (KB939653)

Security Update for Windows Internet Explorer 7 (KB942615)

Security Update for Windows Internet Explorer 7 (KB944533)

Security Update for Windows Internet Explorer 7 (KB950759)

Security Update for Windows Internet Explorer 7 (KB953838)

Security Update for Windows Internet Explorer 7 (KB956390)

Security Update for Windows Internet Explorer 7 (KB958215)

Security Update for Windows Internet Explorer 7 (KB960714)

Security Update for Windows Internet Explorer 7 (KB961260)

Security Update for Windows Internet Explorer 7 (KB963027)

Security Update for Windows Internet Explorer 7 (KB969897)

Security Update for Windows Internet Explorer 7 (KB972260)

Security Update for Windows Internet Explorer 7 (KB974455)

Security Update for Windows Internet Explorer 7 (KB976325)

Security Update for Windows Internet Explorer 7 (KB978207)

Security Update for Windows Internet Explorer 7 (KB982381)

Security Update for Windows Media Player (KB2378111)

Security Update for Windows Media Player (KB911564)

Security Update for Windows Media Player (KB952069)

Security Update for Windows Media Player (KB954155)

Security Update for Windows Media Player (KB968816)

Security Update for Windows Media Player (KB973540)

Security Update for Windows Media Player (KB975558)

Security Update for Windows Media Player (KB978695)

Security Update for Windows Media Player 10 (KB917734)

Security Update for Windows Media Player 11 (KB936782)

Security Update for Windows Media Player 11 (KB954154)

Security Update for Windows Media Player 6.4 (KB925398)

Security Update for Windows XP (KB2079403)

Security Update for Windows XP (KB2115168)

Security Update for Windows XP (KB2121546)

Security Update for Windows XP (KB2160329)

Security Update for Windows XP (KB2229593)

Security Update for Windows XP (KB2259922)

Security Update for Windows XP (KB2279986)

Security Update for Windows XP (KB2286198)

Security Update for Windows XP (KB2296011)

Security Update for Windows XP (KB2296199)

Security Update for Windows XP (KB2347290)

Security Update for Windows XP (KB2360937)

Security Update for Windows XP (KB2387149)

Security Update for Windows XP (KB2393802)

Security Update for Windows XP (KB2412687)

Security Update for Windows XP (KB2419632)

Security Update for Windows XP (KB2423089)

Security Update for Windows XP (KB2436673)

Security Update for Windows XP (KB2440591)

Security Update for Windows XP (KB2443105)

Security Update for Windows XP (KB2476490)

Security Update for Windows XP (KB2476687)

Security Update for Windows XP (KB2478960)

Security Update for Windows XP (KB2478971)

Security Update for Windows XP (KB2479628)

Security Update for Windows XP (KB2479943)

Security Update for Windows XP (KB2481109)

Security Update for Windows XP (KB2483185)

Security Update for Windows XP (KB2485376)

Security Update for Windows XP (KB2485663)

Security Update for Windows XP (KB2503658)

Security Update for Windows XP (KB2503665)

Security Update for Windows XP (KB2506212)

Security Update for Windows XP (KB2506223)

Security Update for Windows XP (KB2507618)

Security Update for Windows XP (KB2507938)

Security Update for Windows XP (KB2508272)

Security Update for Windows XP (KB2508429)

Security Update for Windows XP (KB2509553)

Security Update for Windows XP (KB2510581)

Security Update for Windows XP (KB2511455)

Security Update for Windows XP (KB2524375)

Security Update for Windows XP (KB2535512)

Security Update for Windows XP (KB2536276-v2)

Security Update for Windows XP (KB2536276)

Security Update for Windows XP (KB2544893)

Security Update for Windows XP (KB2555917)

Security Update for Windows XP (KB2562937)

Security Update for Windows XP (KB2566454)

Security Update for Windows XP (KB2567053)

Security Update for Windows XP (KB2567680)

Security Update for Windows XP (KB2570222)

Security Update for Windows XP (KB2570947)

Security Update for Windows XP (KB2592799)

Security Update for Windows XP (KB923561)

Security Update for Windows XP (KB923689)

Security Update for Windows XP (KB938464)

Security Update for Windows XP (KB941569)

Security Update for Windows XP (KB946648)

Security Update for Windows XP (KB950760)

Security Update for Windows XP (KB950762)

Security Update for Windows XP (KB950974)

Security Update for Windows XP (KB951066)

Security Update for Windows XP (KB951376-v2)

Security Update for Windows XP (KB951376)

Security Update for Windows XP (KB951698)

Security Update for Windows XP (KB951748)

Security Update for Windows XP (KB952004)

Security Update for Windows XP (KB952954)

Security Update for Windows XP (KB953839)

Security Update for Windows XP (KB954211)

Security Update for Windows XP (KB954459)

Security Update for Windows XP (KB954600)

Security Update for Windows XP (KB955069)

Security Update for Windows XP (KB956391)

Security Update for Windows XP (KB956572)

Security Update for Windows XP (KB956744)

Security Update for Windows XP (KB956802)

Security Update for Windows XP (KB956803)

Security Update for Windows XP (KB956841)

Security Update for Windows XP (KB956844)

Security Update for Windows XP (KB957095)

Security Update for Windows XP (KB957097)

Security Update for Windows XP (KB958644)

Security Update for Windows XP (KB958687)

Security Update for Windows XP (KB958690)

Security Update for Windows XP (KB958869)

Security Update for Windows XP (KB959426)

Security Update for Windows XP (KB960225)

Security Update for Windows XP (KB960715)

Security Update for Windows XP (KB960803)

Security Update for Windows XP (KB960859)

Security Update for Windows XP (KB961371)

Security Update for Windows XP (KB961373)

Security Update for Windows XP (KB961501)

Security Update for Windows XP (KB968537)

Security Update for Windows XP (KB969059)

Security Update for Windows XP (KB969898)

Security Update for Windows XP (KB969947)

Security Update for Windows XP (KB970238)

Security Update for Windows XP (KB970430)

Security Update for Windows XP (KB971468)

Security Update for Windows XP (KB971486)

Security Update for Windows XP (KB971557)

Security Update for Windows XP (KB971633)

Security Update for Windows XP (KB971657)

Security Update for Windows XP (KB971961)

Security Update for Windows XP (KB972270)

Security Update for Windows XP (KB973346)

Security Update for Windows XP (KB973354)

Security Update for Windows XP (KB973507)

Security Update for Windows XP (KB973525)

Security Update for Windows XP (KB973869)

Security Update for Windows XP (KB973904)

Security Update for Windows XP (KB974112)

Security Update for Windows XP (KB974318)

Security Update for Windows XP (KB974392)

Security Update for Windows XP (KB974571)

Security Update for Windows XP (KB975025)

Security Update for Windows XP (KB975467)

Security Update for Windows XP (KB975560)

Security Update for Windows XP (KB975561)

Security Update for Windows XP (KB975562)

Security Update for Windows XP (KB975713)

Security Update for Windows XP (KB977165-v2)

Security Update for Windows XP (KB977816)

Security Update for Windows XP (KB977914)

Security Update for Windows XP (KB978037)

Security Update for Windows XP (KB978251)

Security Update for Windows XP (KB978262)

Security Update for Windows XP (KB978338)

Security Update for Windows XP (KB978542)

Security Update for Windows XP (KB978601)

Security Update for Windows XP (KB978706)

Security Update for Windows XP (KB979309)

Security Update for Windows XP (KB979482)

Security Update for Windows XP (KB979559)

Security Update for Windows XP (KB979683)

Security Update for Windows XP (KB979687)

Security Update for Windows XP (KB980195)

Security Update for Windows XP (KB980218)

Security Update for Windows XP (KB980232)

Security Update for Windows XP (KB980436)

Security Update for Windows XP (KB981322)

Security Update for Windows XP (KB981349)

Security Update for Windows XP (KB981852)

Security Update for Windows XP (KB981957)

Security Update for Windows XP (KB981997)

Security Update for Windows XP (KB982132)

Security Update for Windows XP (KB982214)

Security Update for Windows XP (KB982665)

Security Update for Windows XP (KB982802)

Sentence Diagramming

Shockwave

Sibelius Scorch (Firefox, Opera, Netscape only)

SigmaTel Audio

SkinsHP1

SkinsHP2

Symantec KB-DocID:2003093015493306

TBS WMP Plug-in

Total Recorder 8.1

TrayApp

Unload

Update for Microsoft .NET Framework 3.5 SP1 (KB963707)

Update for Windows Internet Explorer 7 (KB976749)

Update for Windows Internet Explorer 7 (KB980182)

Update for Windows XP (KB2141007)

Update for Windows XP (KB2345886)

Update for Windows XP (KB2467659)

Update for Windows XP (KB2541763)

Update for Windows XP (KB2607712)

Update for Windows XP (KB2616676)

Update for Windows XP (KB951072-v2)

Update for Windows XP (KB951978)

Update for Windows XP (KB955759)

Update for Windows XP (KB955839)

Update for Windows XP (KB967715)

Update for Windows XP (KB968389)

Update for Windows XP (KB971029)

Update for Windows XP (KB971737)

Update for Windows XP (KB973687)

Update for Windows XP (KB973815)

USB2.0 VIDBOX NW03

V41

Video Resource Driver

Viewpoint Media Player (Remove Only)

Visual FoxPro ODBC Driver

Volo View Express

WebEx Support Manager for Internet Explorer

WebFldrs XP

WebReg

Welch Allyn TechView System

White Estate Software

Winamp (remove only)

Windows Driver Package - eMPIA Technology (USB28xxBGA) Media (06/22/2007 6.22.0116.0)

Windows Genuine Advantage Notifications (KB905474)

Windows Genuine Advantage Validation Tool (KB892130)

Windows Internet Explorer 7

Windows Live Messenger

Windows Media Format 11 runtime

Windows Media Format SDK Hotfix - KB891122

Windows Media Player 11

Windows Rights Management Client Backwards Compatibility SP2

Windows Rights Management Client with Service Pack 2

Windows XP Service Pack 3

WordPerfect Office X3

Works Suite OS Pack

Works Synchronization

.

==== Event Viewer Messages From Past Week ========

.

17-Oct-2011 4:49:45, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the IMAPI CD-Burning COM Service service to connect.

17-Oct-2011 4:49:45, error: Service Control Manager [7000] - The IMAPI CD-Burning COM Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.

16-Oct-2011 15:22:41, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

16-Oct-2011 15:22:09, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD Fips intelppm IPSec MpFilter MRxSmb NetBIOS NetBT RasAcd Rdbss SASDIFSV SASKUTIL Tcpip

16-Oct-2011 15:22:09, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD Networking Support Environment service which failed to start because of the following error: A device attached to the system is not functioning.

16-Oct-2011 15:22:09, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.

16-Oct-2011 15:22:09, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.

16-Oct-2011 15:22:09, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBT service which failed to start because of the following error: A device attached to the system is not functioning.

16-Oct-2011 15:21:51, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

16-Oct-2011 12:56:05, error: SideBySide [59] - Resolve Partial Assembly failed for Microsoft.VC80.MFCLOC. Reference error message: The referenced assembly is not installed on your system. .

16-Oct-2011 12:56:05, error: SideBySide [59] - Generate Activation Context failed for C:\WINNT\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\MFC80U.DLL. Reference error message: The operation completed successfully. .

16-Oct-2011 12:56:05, error: SideBySide [32] - Dependent Assembly Microsoft.VC80.MFCLOC could not be found and Last Error was The referenced assembly is not installed on your system.

14-Oct-2011 4:01:59, error: Service Control Manager [7022] - The Terminal Services service hung on starting.

14-Oct-2011 4:01:59, error: Service Control Manager [7001] - The Fast User Switching Compatibility service depends on the Terminal Services service which failed to start because of the following error: After starting, the service hung in a start-pending state.

12-Oct-2011 18:03:48, error: System Error [1003] - Error code 000000ea, parameter1 8a4c27c8, parameter2 8a26c168, parameter3 8a21f358, parameter4 00000001.

12-Oct-2011 18:02:10, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: adpu160m agp440 IntelIde ultra ViaIde

12-Oct-2011 15:04:43, error: Service Control Manager [7000] - The MBAMSwissArmy service failed to start due to the following error: The system cannot find the file specified.

12-Oct-2011 14:42:18, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the LMIGuardianSvc service to connect.

12-Oct-2011 14:42:18, error: Service Control Manager [7000] - The LMIGuardianSvc service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.

12-Oct-2011 13:57:50, error: ialm [108] - The driver ialmrnt5 for the display device \Device\Video0 got stuck in an infinite loop. This usually indicates a problem with the device itself or with the device driver programming the hardware incorrectly. Please check with your hardware device vendor for any driver updates.

.

==== End Of File ===========================

Link to post
Share on other sites

  • Staff

Hi and welcome to Malwarebytes.

  • Download the file TDSSKiller.zip and extract it into a folder on the infected PC.
  • Execute the file TDSSKiller.exe by double-clicking on it.
  • Wait for the scan and disinfection process to be over.
  • When its work is over, the utility prompts for a reboot to complete the disinfection.

By default, the utility outputs runtime log into the system disk root directory (the disk where the operating system is installed, C:\ as a rule).

The log is like UtilityName.Version_Date_Time_log.txt.

for example, C:\TDSSKiller.2.2.0_20.12.2009_15.31.43_log.txt.

Please post that log here.

Please update MBAM, run a Quick Scan, and post its log.

Next, please visit this webpage for instructions for running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

  • When the tool is finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt along with a new DDS log so we may continue cleaning the system.

-screen317

Link to post
Share on other sites

Thanks for your note. I tried attaching the requested files, but one of them was extremely long, and when I hit the Post button, I got a note saying my post was too long. I put everything into the attached NotePad file, which I'm hoping will make it through without any problems.

Thanks again for your assistance. I'll be awaiting your next instructions.

BTW, I assume you know that ComboFix only fixed a few items; the program has to be purchased for the complete cleaning to take place.

Logs 23Oct.txt

Link to post
Share on other sites

Hi,

Just in case my last attempt at posting this same message didn't go through.

Can't post a screen shot of the ComboFix I used; after having it come up each morning for the next three or four days teling me I needed to buy it, I removed it from my computer. I had clicked on the link you provided; could it be that the redirect virus I have redirected me when I clicked on that link?

That said, the log of what I ran today follows. First though, I have a question or two. In the course of running the test, the program had me download something from Microsoft. Then when I got done, it appeared that my default browser had all of a sudden become IE instead of Firefox. Is that normal? Then, after I pasted the log text and clicked on Post Reply, the IE died, saying it couldn't establish connection. I closed it and opened Firefox back up to see if it was still listed as my default browser, and I came back to where I had been in this thread. So I decided to redo my reply in case it hadn't made it with the IE burp. Again, is this normal?

Now, the log text from ComboFix.

ComboFix 11-10-29.06 - Owner 0-Oct-2011 6:58.1.1 - x86

Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1278.659 [GMT -7:00]

Running from: c:\documents and settings\Owner\My Documents\Downloads\ComboFix.exe

AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}

AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\documents and settings\All Users\Application Data\DirectCDUserNameE.txt

c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\kzarc8u3.default\extensions\{5428796a-0b6d-4991-b121-9d41eeba65a2}

c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\kzarc8u3.default\extensions\{5428796a-0b6d-4991-b121-9d41eeba65a2}\chrome.manifest

c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\kzarc8u3.default\extensions\{5428796a-0b6d-4991-b121-9d41eeba65a2}\chrome\xulcache.jar

c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\kzarc8u3.default\extensions\{5428796a-0b6d-4991-b121-9d41eeba65a2}\defaults\preferences\xulcache.js

c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\kzarc8u3.default\extensions\{5428796a-0b6d-4991-b121-9d41eeba65a2}\install.rdf

c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\kzarc8u3.default\extensions\{77e0db38-36fa-4529-8bc8-0ed29bd76027}

c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\kzarc8u3.default\extensions\{77e0db38-36fa-4529-8bc8-0ed29bd76027}\chrome.manifest

c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\kzarc8u3.default\extensions\{77e0db38-36fa-4529-8bc8-0ed29bd76027}\chrome\xulcache.jar

c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\kzarc8u3.default\extensions\{77e0db38-36fa-4529-8bc8-0ed29bd76027}\defaults\preferences\xulcache.js

c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\kzarc8u3.default\extensions\{77e0db38-36fa-4529-8bc8-0ed29bd76027}\install.rdf

c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\s8iykgld.Marty\extensions\{5428796a-0b6d-4991-b121-9d41eeba65a2}

c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\s8iykgld.Marty\extensions\{5428796a-0b6d-4991-b121-9d41eeba65a2}\chrome.manifest

c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\s8iykgld.Marty\extensions\{5428796a-0b6d-4991-b121-9d41eeba65a2}\chrome\xulcache.jar

c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\s8iykgld.Marty\extensions\{5428796a-0b6d-4991-b121-9d41eeba65a2}\defaults\preferences\xulcache.js

c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\s8iykgld.Marty\extensions\{5428796a-0b6d-4991-b121-9d41eeba65a2}\install.rdf

c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\s8iykgld.Marty\extensions\{77e0db38-36fa-4529-8bc8-0ed29bd76027}

c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\s8iykgld.Marty\extensions\{77e0db38-36fa-4529-8bc8-0ed29bd76027}\chrome.manifest

c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\s8iykgld.Marty\extensions\{77e0db38-36fa-4529-8bc8-0ed29bd76027}\chrome\xulcache.jar

c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\s8iykgld.Marty\extensions\{77e0db38-36fa-4529-8bc8-0ed29bd76027}\defaults\preferences\xulcache.js

c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\s8iykgld.Marty\extensions\{77e0db38-36fa-4529-8bc8-0ed29bd76027}\install.rdf

c:\documents and settings\Owner\My Documents\DPE.DUS

c:\documents and settings\Owner\System

c:\documents and settings\Owner\System\win_qs.jqx

c:\documents and settings\Owner\WINDOWS

c:\program files\messenger\msmsgsin.exe

c:\program files\msn\msncorefiles\copymar.exe

c:\program files\msn\msncorefiles\custdial.dll

c:\program files\msn\msncorefiles\logonmgr.dll

c:\program files\Open

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0001

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0002

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0003

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0004

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0005

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0006

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0007

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0008

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0009

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0010

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0011

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0012

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0013

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0014

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0015

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0016

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0017

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0018

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0019

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0020

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0021

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0022

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0023

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0024

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0025

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0026

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0027

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0028

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0029

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0030

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0031

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0032

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0033

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0034

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0035

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0036

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0037

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0038

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0039

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0040

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0041

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0042

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0043

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0044

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0045

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0046

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0047

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0048

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0049

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0050

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0051

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0052

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0053

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0054

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0055

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0056

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0057

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0058

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0059

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0060

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0061

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0062

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0063

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0064

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0065

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0066

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0067

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0068

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0069

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0070

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0071

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0072

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0073

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0074

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0075

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0076

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0077

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0078

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0079

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0080

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0081

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0082

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0083

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0084

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0085

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0086

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0087

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0088

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0089

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0090

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0091

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0092

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0093

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0094

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0095

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0096

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0097

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0098

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0099

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0100

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0101

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0102

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0103

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0104

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0105

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0106

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0107

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0108

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0109

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0110

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0111

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0112

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0113

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0114

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0115

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0116

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0117

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0118

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0119

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0120

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0121

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0122

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0123

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0124

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0125

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0126

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0127

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0128

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0129

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0130

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0131

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0132

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0133

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0134

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0135

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0136

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0137

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0138

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0139

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0140

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0141

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0142

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0143

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0144

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0145

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0146

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0147

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0148

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0149

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0150

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0151

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0152

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0153

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0154

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0155

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0156

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0157

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0158

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0159

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0160

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0161

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0162

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0163

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0164

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0165

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0166

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0167

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0168

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0169

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0170

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0171

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0172

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0173

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0174

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0175

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0176

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0177

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0178

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0179

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0180

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0181

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0182

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0183

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0184

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0185

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0186

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0187

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0188

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0189

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0190

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0191

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0192

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0193

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0194

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0195

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0196

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0197

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0198

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0199

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0200

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0201

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0202

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0203

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0204

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0205

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0206

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0207

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0208

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0209

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0210

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0211

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0212

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0213

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0214

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0215

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0216

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0217

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0218

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0219

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0220

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0221

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0222

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0223

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0224

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0225

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0226

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0227

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0228

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0229

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0230

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0231

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0232

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0233

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0234

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0235

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0236

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0237

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0238

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0239

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0240

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0241

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0242

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0243

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0244

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0245

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0246

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0247

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0248

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0249

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0250

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0251

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0252

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0253

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0254

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0255

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0256

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0257

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0258

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0259

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0260

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0261

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0262

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0263

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0264

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0265

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0266

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0267

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0268

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0269

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0270

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0271

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0272

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0273

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0274

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0275

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0276

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0277

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0278

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0279

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0280

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0281

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0282

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0283

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0284

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0285

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0286

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0287

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0288

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0289

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0290

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0291

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0292

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0293

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0294

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0295

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0296

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0297

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0298

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0299

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0300

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0301

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0302

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0303

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0304

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0305

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0306

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0307

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0308

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0309

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0310

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0311

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0312

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0313

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0314

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0315

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0316

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0317

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0318

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0319

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0320

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0321

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0322

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0323

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0324

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0325

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0326

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0327

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0328

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0329

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0330

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0331

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0332

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0333

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0334

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0335

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0336

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0337

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0338

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0339

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0340

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0341

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0342

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0343

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0344

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0345

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0346

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0347

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0348

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0349

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0350

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0351

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0352

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0353

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0354

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0355

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0356

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0357

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0358

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0359

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0360

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0361

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0362

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0363

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0364

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0365

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0366

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0367

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0368

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0369

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0370

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0371

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0372

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0373

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0374

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0375

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0376

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0377

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0378

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0379

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0380

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0381

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0382

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0383

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0384

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0385

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0386

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0387

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0388

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0389

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0390

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0391

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0392

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0393

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0394

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0395

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0396

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0397

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0398

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0399

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0400

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0401

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0402

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0403

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0404

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0405

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0406

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f_0407

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_001

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_002

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_003

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_004

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_005

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_006

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_007

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_008

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_009

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_010

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_011

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_012

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_013

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_014

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_015

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_016

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_017

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_018

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_019

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_020

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_021

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_022

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_023

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_024

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_025

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_026

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_027

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_028

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_029

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_030

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_031

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_032

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_033

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_034

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_035

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_036

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_037

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_038

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_039

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_040

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_041

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_042

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_043

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_044

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_045

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_046

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_047

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_048

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_049

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_050

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_051

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_052

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_053

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_054

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_055

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_056

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_057

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_058

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_059

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_060

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_061

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_062

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_063

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_064

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_065

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_066

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_067

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_068

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_069

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_070

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_071

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_072

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_073

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_074

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_075

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_076

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_077

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_078

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_079

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_080

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_081

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_082

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_083

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_084

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_085

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_086

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_087

c:\program files\Open\OOo_1.1.2_Win32Intel_install\f0_088

c:\program files\Open\OOo_1.1.2_Win32Intel_install\license.html

c:\program files\Open\OOo_1.1.2_Win32Intel_install\license.txt

c:\program files\Open\OOo_1.1.2_Win32Intel_install\readme.html

c:\program files\Open\OOo_1.1.2_Win32Intel_install\readme.txt

c:\program files\Open\OOo_1.1.2_Win32Intel_install\setup.exe

c:\program files\Open\OOo_1.1.2_Win32Intel_install\setup.inf

c:\program files\Open\OOo_1.1.2_Win32Intel_install\SETUP_GUIDE.pdf

c:\program files\Open\OOo_1.1.2_Win32Intel_install\THIRDPARTYLICENSEREADME.html

c:\winnt\CDAC13BA.EXE

c:\winnt\CDAC14BA.DLL

c:\winnt\dasetup.log

c:\winnt\Debug\dcpromo.log

c:\winnt\Downloaded Program Files\RdxIE.dll

c:\winnt\ehome\snchk.exe

c:\winnt\help\tours\htmltour\unlock_playing.htm

c:\winnt\help\wmplayer.bak

c:\winnt\Readme.txt

c:\winnt\system32\rnaph.dll

c:\winnt\tsoc.log

c:\winnt\winhelp.ini

.

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

-------\Legacy_USNJSVC

-------\Service_usnjsvc

.

.

((((((((((((((((((((((((( Files Created from 2011-09-28 to 2011-10-30 )))))))))))))))))))))))))))))))

.

.

2011-10-30 14:12 . 2011-10-30 14:12 56200 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{1FCB07B1-FFD8-4516-A5B5-83578C396A7B}\offreg.dll

2011-10-29 23:24 . 2011-10-07 03:48 6668624 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{1FCB07B1-FFD8-4516-A5B5-83578C396A7B}\mpengine.dll

2011-10-23 16:06 . 2011-10-25 11:47 -------- d-----w- c:\documents and settings\Owner\Application Data\Sammsoft

2011-10-17 08:50 . 2011-10-17 08:50 -------- d-----w- c:\documents and settings\Owner\Application Data\WinPatrol

2011-10-17 01:44 . 2011-10-17 08:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy

2011-10-16 22:29 . 2011-10-17 21:56 -------- d-----w- c:\program files\SUPERAntiSpyware

2011-10-16 22:20 . 2011-10-16 22:20 -------- d-----w- c:\documents and settings\Administrator

2011-10-16 19:59 . 2011-10-16 19:59 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2011-10-24 10:53 . 2011-05-17 12:32 414368 ----a-w- c:\winnt\system32\FlashPlayerCPLApp.cpl

2011-10-07 03:48 . 2010-05-28 21:15 6668624 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll

2011-09-26 18:41 . 2008-07-30 00:59 611328 ----a-w- c:\winnt\system32\uiautomationcore.dll

2011-09-26 18:41 . 1980-01-01 05:00 220160 ----a-w- c:\winnt\system32\oleacc.dll

2011-09-26 18:41 . 1980-01-01 05:00 20480 ----a-w- c:\winnt\system32\oleaccrc.dll

2011-09-09 09:12 . 2003-01-25 19:45 599040 ----a-w- c:\winnt\system32\crypt32.dll

2011-09-06 13:20 . 1980-01-01 05:00 1858944 ----a-w- c:\winnt\system32\win32k.sys

2011-09-01 00:00 . 2010-03-26 17:14 22216 ----a-w- c:\winnt\system32\drivers\mbam.sys

2011-08-30 00:27 . 2011-08-30 00:27 8892928 ----a-w- c:\documents and settings\All Users\Application Data\atscie.msi

2011-08-17 21:32 . 2006-04-28 15:58 832512 ----a-w- c:\winnt\system32\wininet.dll

2011-08-17 21:32 . 2004-08-04 07:56 78336 ----a-w- c:\winnt\system32\ieencode.dll

2011-08-17 21:32 . 2003-01-25 19:57 1830912 ----a-w- c:\winnt\system32\inetcpl.cpl

2011-08-17 21:32 . 1980-01-01 05:00 17408 ------w- c:\winnt\system32\corpol.dll

2011-08-17 13:49 . 1980-01-01 05:00 138496 ----a-w- c:\winnt\system32\drivers\afd.sys

2011-08-17 12:22 . 2004-08-04 05:59 389120 ----a-w- c:\winnt\system32\html.iec

2011-08-12 20:51 . 2006-06-13 17:03 26488 ----a-w- c:\winnt\system32\spupdsvc.exe

2010-03-31 17:09 . 2010-03-31 17:09 10437264 ----a-w- c:\program files\mozilla firefox\plugins\PDFNetC.dll

2010-04-08 19:36 . 2010-04-08 19:36 107760 ----a-w- c:\program files\mozilla firefox\plugins\ScorchPDFWrapper.dll

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Microsoft Works Update Detection"="???\WkDetect.exe" [?]

"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\WCESCOMM.EXE" [2004-02-03 401491]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"WinampAgent"="c:\program files\Winamp\Winampa.exe" [2002-04-26 12288]

"IgfxTray"="c:\winnt\System32\igfxtray.exe" [2002-03-26 155648]

"HotKeysCmds"="c:\winnt\System32\hkcmd.exe" [2002-03-26 106496]

"Hot Key Kbd 9910 Daemon"="SK9910DM.EXE" [2001-01-03 66048]

"GWMDMpi"="c:\winnt\GWMDMpi.exe" [2002-08-06 53248]

"GWMDMMSG"="GWMDMMSG.exe" [2002-08-06 90112]

"AdaptecDirectCD"="c:\program files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-02-28 675840]

"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2004-02-12 49152]

"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]

"QuickFinder Scheduler"="c:\program files\WordPerfect Office X3\Programs\QFSCHD130.EXE" [2006-07-05 77892]

"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 56928]

"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-06 54832]

"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696]

"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]

"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2011-09-07 40376]

"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2010-09-23 640440]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296]

"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]

"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]

"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-09-01 449608]

.

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]

.

c:\documents and settings\All Users\Start Menu\Programs\Startup\

Corel Desktop Application Director 8.LNK - c:\corel\Suite8\Programs\DAD8.EXE [2002-6-18 93184]

HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-5-28 241664]

HP Image Zone Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2004-5-28 53248]

.

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{0cab0400-7395-11d0-a5e5-0020afe2fdd9}"= "qvphook.dll" [2000-05-26 45056]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"mixer"=DrvTrNTm.dll

"wave"=DrvTrNTm.dll

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

@="Service"

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\Microsoft ActiveSync\\WCESCOMM.EXE"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Program Files\\LapLink Gold\\laplink.exe"=

"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=

"c:\\Program Files\\MSN Messenger\\livecall.exe"=

"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"1542:TCP"= 1542:TCP:Realtek WPS TCP Prot

"1542:UDP"= 1542:UDP:Realtek WPS UDP Prot

"53:UDP"= 53:UDP:Realtek AP UDP Prot

.

R1 tsircmir;LapLink Mirror Driver Miniport;c:\winnt\system32\drivers\tsircmir.sys [06-Apr-2005 15:33 2816]

R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [26-Mar-2010 10:15 366152]

R2 TSISER;TSISER;c:\winnt\system32\drivers\tsiser.sys [06-Apr-2005 15:33 42560]

R2 TSISTRMX;Traveling Software Stream Driver;c:\winnt\system32\drivers\TSISTRMX.SYS [06-Apr-2005 15:33 5120]

R3 MBAMProtector;MBAMProtector;c:\winnt\system32\drivers\mbam.sys [26-Mar-2010 10:14 22216]

R3 TotRec7;Total Recorder WDM audio driver;c:\winnt\system32\drivers\TotRec7.sys [17-Jun-2010 10:49 131152]

R3 TotRec8;Total Recorder WDM audio filter driver;c:\winnt\system32\drivers\TotRec8.sys [17-Jun-2010 10:49 91216]

R3 TSIKBF5;Traveling Software Keyboard Filter Driver;c:\winnt\system32\drivers\TSIKBF5.sys [06-Apr-2005 15:33 9728]

R3 TSIMSF5;Traveling Software Mouse Filter Driver;c:\winnt\system32\drivers\TSIMSF5.sys [06-Apr-2005 15:33 5632]

S1 MpKsl0e4661b5;MpKsl0e4661b5;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{9EC077ED-D02C-4469-839C-AE009FF3A140}\MpKsl0e4661b5.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{9EC077ED-D02C-4469-839C-AE009FF3A140}\MpKsl0e4661b5.sys [?]

S1 MpKsl28565489;MpKsl28565489;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{1FCB07B1-FFD8-4516-A5B5-83578C396A7B}\MpKsl28565489.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{1FCB07B1-FFD8-4516-A5B5-83578C396A7B}\MpKsl28565489.sys [?]

S1 MpKsl36a56b80;MpKsl36a56b80;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{880C1D19-C5B1-4CB2-8C5A-5B5638C95AC8}\MpKsl36a56b80.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{880C1D19-C5B1-4CB2-8C5A-5B5638C95AC8}\MpKsl36a56b80.sys [?]

S1 MpKsled1cb117;MpKsled1cb117;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E927418D-049C-476E-99E6-C63009F75D94}\MpKsled1cb117.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E927418D-049C-476E-99E6-C63009F75D94}\MpKsled1cb117.sys [?]

S1 TSIRCINK;Traveling Software Install Driver;c:\winnt\system32\drivers\TSIRCINK.SYS [06-Apr-2005 15:33 9216]

S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\LogMeIn\x86\LMIGuardianSvc.exe [14-Oct-2010 19:02 374152]

S3 BW2NDIS5;BW2NDIS5;c:\winnt\system32\Drivers\BW2NDIS5.sys --> c:\winnt\system32\Drivers\BW2NDIS5.sys [?]

S3 iscFlash;iscFlash;\??\c:\winnt\SYSTEM32\DRIVERS\iscflash.sys --> c:\winnt\SYSTEM32\DRIVERS\iscflash.sys [?]

S3 LLUSBFLT;LLUSBFLT;c:\winnt\system32\drivers\NcBulk.SYS [06-Apr-2005 15:33 23628]

S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\winnt\system32\drivers\mbamswissarmy.sys --> c:\winnt\system32\drivers\mbamswissarmy.sys [?]

S3 NCBULK;NCBULK;c:\winnt\system32\drivers\NcBulk.SYS [06-Apr-2005 15:33 23628]

S3 NET1080;LapLink Inc. USB Cable Network Adapter;c:\winnt\system32\drivers\nettc.sys [18-Jun-2002 16:49 12536]

S3 PCDRDRV;Pcdr Helper Driver;\??\c:\atf\Qctest\PCDoc\PCDRDRV.sys --> c:\atf\Qctest\PCDoc\PCDRDRV.sys [?]

S3 RTL819xp;Realtek RTL8190\RTL8192E 802.11n Wireless LAN (Mini-)PCI NIC NT Driver;c:\winnt\system32\drivers\rtl819xp.sys [04-Nov-2010 18:12 519168]

S3 USBTC;USBTC;c:\winnt\system32\drivers\usbtc.sys [18-Jun-2002 16:49 13672]

.

Contents of the 'Scheduled Tasks' folder

.

2011-10-30 c:\winnt\Tasks\MP Scheduled Scan.job

- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 22:39]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.examiner-enterprise.com/

IE: &Add animation to IncrediMail Style Box - c:\progra~1\INCRED~1\bin\resources\WebMenuImg.htm

IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html

IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html

IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000

IE: Open with WordPerfect - c:\program files\WordPerfect Office X3\Programs\WPLauncher.hta

Trusted Zone: aol.com\free

Trusted Zone: intuit.com\ttlc

Trusted Zone: turbotax.com

TCP: DhcpNameServer = 68.116.46.115 24.205.192.61 24.205.224.36

DPF: Microsoft XML Parser for Java - file://c:\winnt\Java\classes\xmldso.cab

DPF: Sametime Meeting Toolkit ST25 - file://c:\docume~1\Owner\LOCALS~1\Temp\STMeeting25.cab

FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\kzarc8u3.default\

FF - prefs.js: browser.search.selectedEngine - Google

FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/

FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}

FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}

FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\winnt\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension

FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff

FF - Ext: Move Media Player: moveplayer@movenetworks.com - c:\documents and settings\Owner\Application Data\Move Networks

.

- - - - ORPHANS REMOVED - - - -

.

BHO-{0E253A3A-66A3-4BA7-ADD7-52E0B872D27c} - c:\documents and settings\Owner\Local Settings\Application Data\NetworkSys32.dll

HKCU-Run-MoneyAgent - c:\program files\Microsoft Money\System\Money Express.exe

HKCU-Run-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe

HKCU-Run-LightScribe Control Panel - c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe

HKLM-Run-Keyboard Preload Check - c:\oemdrvrs\KEYB\Preload.exe

HKLM-Run-WinPatrol - g:\cleanup\4\winpatrol.exe

ShellExecuteHooks-{A213B520-C6C2-11d0-AF9D-008029E1027E} - (no file)

AddRemove-CdaC13Ba - c:\winnt\CDAC13BA.EXE

AddRemove-ESBUnitConv4_is1 - f:\esbunitconv\unins000.exe

AddRemove-Works2002Setup - c:\program files\Microsoft Works Suite 2002\Setup\Launcher.exe

.

.

.

**************************************************************************

.

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2011-10-30 07:12

Windows 5.1.2600 Service Pack 3 NTFS

.

scanning hidden processes ...

.

scanning hidden autostart entries ...

.

scanning hidden files ...

.

scan completed successfully

hidden files: 0

.

**************************************************************************

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_USERS\S-1-5-21-1316817595-487357192-516116760-1003\Software\Microsoft\SystemCertificates\AddressBook*]

@Allowed: (Read) (RestrictedCode)

@Allowed: (Read) (RestrictedCode)

.

--------------------- DLLs Loaded Under Running Processes ---------------------

.

- - - - - - - > 'explorer.exe'(1200)

c:\winnt\system32\WININET.dll

c:\winnt\system32\ieframe.dll

c:\winnt\system32\WPDShServiceObj.dll

c:\winnt\system32\PortableDeviceTypes.dll

c:\winnt\system32\PortableDeviceApi.dll

.

------------------------ Other Running Processes ------------------------

.

c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe

c:\program files\Symantec\LiveUpdate\ALUSchedulerSvc.exe

c:\winnt\System32\drivers\CDAC11BA.EXE

c:\progra~1\Borland\INTERB~1\Bin\IBGuard.EXE

c:\program files\Java\jre6\bin\jqs.exe

c:\winnt\system32\PSIService.exe

c:\program files\CyberLink\Shared Files\RichVideo.exe

c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

c:\winnt\System32\TSIRCSRV.EXE

c:\progra~1\Borland\INTERB~1\Bin\ibserver.exe

c:\winnt\system32\wscntfy.exe

c:\winnt\system32\SK9910DM.EXE

c:\winnt\GWMDMMSG.exe

c:\program files\HP\Digital Imaging\bin\hpqgalry.exe

c:\winnt\System32\HPZipm12.exe

c:\program files\Symantec\LiveUpdate\AUpdate.exe

c:\progra~1\Symantec\LIVEUP~1\LUCOMS~2.EXE

.

**************************************************************************

.

Completion time: 2011-10-30 07:20:15 - machine was rebooted

ComboFix-quarantined-files.txt 2011-10-30 14:20

.

Pre-Run: 21,764,173,824 bytes free

Post-Run: 21,973,757,952 bytes free

.

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINNT

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

UnsupportedDebug="do not select this" /debug

multi(0)disk(0)rdisk(0)partition(1)\WINNT="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

.

- - End Of File - - D2CB5B328629C3519A30E589D5D21FB6

Link to post
Share on other sites

Some more information for you after this morning's post. After running the ComboFix with the browser setting change, we noticed that the computer was running EXTREMELY slow. I ran a full scan of Microsoft Security Essentials, which found and removed one item -- Exploit:Java/CVE-2010-0840.LO. After that completed, I did a full MalwareBytes scan, which came up with no problems found. After that the computer seemed to be back to normal speed. I tried some searches with Google and Yahoo, and they seem to be working at this moment.

What other information would help you out?

Ken

Link to post
Share on other sites

  • Staff

Hi,

Yes that is normal for the default browser to change.

Update MBAM, run a Quick Scan, and post its log.

Next, please run a free online scan with the ESET Online Scanner

Note: You will need to use Internet Explorer for this scan.

  1. Tick the box next to YES, I accept the Terms of Use.
  2. Click Start
  3. When asked, allow the ActiveX control to install
  4. Click Start
  5. Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  6. Click Scan
    Wait for the scan to finish
  7. Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  8. Copy and paste that log as a reply to this topic

Next, download my Security Check from here or here.

  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

Let me know how things are running now and what issues remain.

-screen317

Link to post
Share on other sites

Ran both programs per your instructions. The first one took a loooong time. At this point, redirect seems to have been eliminated. Guess somewhere in the process it was fixed. Is there anything else that needs to be done? Log info is pasted below.

Ken

ESETSmartInstaller@High as CAB hook log:

OnlineScanner.ocx - registred OK

# version=7

# iexplore.exe=7.00.6000.17103 (vista_gdr.110816-1000)

# OnlineScanner.ocx=1.0.0.6583

# api_version=3.0.2

# EOSSerial=228c9d11ea08d24dab70e10ccd6b4024

# end=finished

# remove_checked=true

# archives_checked=false

# unwanted_checked=true

# unsafe_checked=false

# antistealth_checked=true

# utc_time=2011-11-04 08:25:28

# local_time=2011-11-04 01:25:28 (-0800, Pacific Daylight Time)

# country="United States"

# lang=9

# osver=5.1.2600 NT Service Pack 3

# compatibility_mode=256 16777215 100 0 0 0 0 0

# compatibility_mode=3584 16777215 100 0 0 0 0 0

# compatibility_mode=5891 16776533 42 87 0 17187175 0 0

# compatibility_mode=8192 67108863 100 0 0 0 0 0

# scanned=107802

# found=11

# cleaned=11

# scan_time=6825

C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Default\bmibhinnlhjmdmoolhlnmloghjlfddjo\contentscript.js Win32/TrojanDownloader.Tracur.F trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\Qoobox\Quarantine\C\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\kzarc8u3.default\extensions\{5428796a-0b6d-4991-b121-9d41eeba65a2}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\Qoobox\Quarantine\C\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\kzarc8u3.default\extensions\{77e0db38-36fa-4529-8bc8-0ed29bd76027}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\Qoobox\Quarantine\C\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\s8iykgld.Marty\extensions\{5428796a-0b6d-4991-b121-9d41eeba65a2}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\Qoobox\Quarantine\C\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\s8iykgld.Marty\extensions\{77e0db38-36fa-4529-8bc8-0ed29bd76027}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP2803\A0308391.manifest Win32/TrojanDownloader.Tracur.F trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP2803\A0308392.manifest Win32/TrojanDownloader.Tracur.F trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP2827\A0320756.manifest Win32/TrojanDownloader.Tracur.F trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP2827\A0320757.manifest Win32/TrojanDownloader.Tracur.F trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP2827\A0320758.manifest Win32/TrojanDownloader.Tracur.F trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP2827\A0320759.manifest Win32/TrojanDownloader.Tracur.F trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

-------------------------------------------------

Security Check Log/Info

Results of screen317's Security Check version 0.99.24

Windows XP Service Pack 3 x86

Internet Explorer 7 Out of date!

``````````````````````````````

Antivirus/Firewall Check:

Microsoft Security Essentials

```````````````````````````````

Anti-malware/Other Utilities Check:

Malwarebytes' Anti-Malware

Java Web Start

Java 2 Runtime Environment Standard Edition v1.3.1_02

Java 6 Update 23

Java 2 Runtime Environment, SE v1.4.1_02

Out of date Java installed!

Adobe Flash Player 11.0.1.152

Mozilla Firefox (Firefox, Opera, Netscape only..)

````````````````````````````````

Process Check:

objlist.exe by Laurent

Windows Defender MSMpEng.exe

Malwarebytes' Anti-Malware mbamservice.exe

Malwarebytes' Anti-Malware mbamgui.exe

Microsoft Security Essentials msseces.exe

Microsoft Security Client Antimalware MsMpEng.exe

``````````End of Log````````````

Link to post
Share on other sites

  • Staff

Hi,

Run TFC by OldTimer to clear temporary files:

  • Please download TFC from here and save it to your desktop.
  • Close any open programs and Internet browsers.
  • Double click TFC.exe to run it and once it opens click on the Start button on the lower left of the program to allow it to begin cleaning.
  • Please be patient as clearing out temp files may take a while.
  • Once it completes you may be prompted to restart your computer, please do so.
  • Once it's finished you may delete TFC.exe from your Desktop or save it for later use for the cleaning of temporary files.

Navigate to Start --> Run, and type Combofix /uninstall in the box that appears. Click OK afterward. Notice the space between the X and the /uninstall

This uninstalls all of ComboFix's components.

Delete SecurityCheck.

After that, navigate to Start --> Control Panel --> Add or Remove Programs, and uninstall the following program (if present):

ESET Online Scanner v3

Java Web Start

Java 2 Runtime Environment Standard Edition v1.3.1_02

Java™ 6 Update 23

Java 2 Runtime Environment, SE v1.4.1_02

Adobe Reader 8.0

Restart your computer.

Get the latest version of Java and Adobe Reader

Let me know what issues remain.

Link to post
Share on other sites

  • 2 weeks later...
  • Staff

Great!

I highly recommend the PRO version of MBAM; with it, it's likely that this issue would have been prevented in the first place.

Now that your computer seems to be in proper working order, please take the following steps to help prevent reinfection:

1) Download and install Javacool's SpywareBlaster, which will prevent malware from being installed on your computer. A tutorial on it can be found here.

2) Go to Windows Update frequently to get all of the latest updates (security or otherwise) for Windows.

3) Make sure your programs are up to date! Older versions may contain security risks. To find out what programs need to be updated, please run Secunia's Software Inspector.

4) WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:

  • Green to go
  • Yellow for caution
  • Red to stop

WOT has an addon available for both Firefox and IE.

5) Be sure to update your Antivirus and Antispyware programs often!

Finally, please also take the time to read Tony Klein's excellent article on: So How Did I Get Infected in the First Place?

Safe surfing,

-screen317

Link to post
Share on other sites

  • 2 weeks later...
  • Staff

Glad we could help. :)

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.