Jump to content

ping.exe, svchost.exe, iexplore.exe, forced proxy and site spams


Tsiphon
 Share

Recommended Posts

I noticed sometime last week that my computer was slow, so I opened task manager and saw PING.EXE from my SysWow64 folder was running high (which it shouldn't be running anyways). It restarted when I closed the process and all that so I knew I had a virus. I got Malwarebytes and the active protection pops up if the ethernet cable is plugged in, saying that either ping.exe, iexplore.exe, svchost.exe and sometimes firefox or avp.exe (kaspersky, which I have turned off while using malwarebytes) come up as trying to access random ip addresses under ports generally around 49000-55000.

Looking in the process explorer, one of the svchosts under my Creative Audio Service has many weird IP and url entries in the TCP/IP section. Sometimes it's blackhole.com or 007agent.com or other weird sites. There are other culprit svchosts directing to these sites, as well as ping.exe, and both of these will open many many iexplorer.exe (maybe iexplore.exe i can't remember), which increases the attempts.

I can give additional information, but for now, here's my DDS. (note, due to my keyboard on my infected desktop not working, I am transferring log files via thumbdrive to my laptop which has updated defenses as well as Comodo firewall, Malwarebytes, and WinPatrol.)

.

DDS (Ver_2011-08-26.01) - NTFSAMD64

Internet Explorer: 8.0.6001.19088 BrowserJavaVersion: 1.6.0_29

Run by Tsiphon at 17:08:45 on 2011-10-31

Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1252.1.1033.18.4094.1844 [GMT -5:00]

.

AV: Kaspersky Anti-Virus *Disabled/Updated* {56547CC9-C9B2-849D-8FEF-A496150D6A06}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

SP: Kaspersky Anti-Virus *Disabled/Updated* {ED359D2D-EF88-8B13-B55F-9FE46E8A20BB}

SP: COMODO Defense+ *Enabled/Updated* {CE351521-78FA-2048-BB22-B68A4A5CA7EC}

FW: COMODO Firewall *Enabled* {4D6F75E0-14AF-2E9E-AACD-24CDCF08AA2A}

.

============== Running Processes ===============

.

C:\Windows\system32\wininit.exe

C:\Windows\system32\lsm.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\nvvsvc.exe

C:\Windows\system32\svchost.exe -k rpcss

C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe

C:\Windows\system32\svchost.exe -k NetworkService

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k netsvcs

C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe

C:\Windows\system32\svchost.exe -k GPSvcGroup

C:\Windows\system32\SLsvc.exe

C:\Windows\system32\svchost.exe -k LocalService

C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe

C:\Windows\system32\nvvsvc.exe

C:\Windows\System32\spoolsv.exe

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

C:\Windows\system32\svchost.exe -k apphost

C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\Windows\system32\mqsvc.exe

C:\Windows\system32\taskeng.exe

C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedul2.exe

C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

C:\Windows\system32\svchost.exe -k imgsvc

C:\Program Files\Tablet\Pen\Pen_Tablet.exe

C:\Windows\system32\svchost.exe -k iissvcs

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

C:\Windows\system32\SearchIndexer.exe

C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

C:\Windows\system32\taskeng.exe

C:\Program Files\Tablet\Pen\Pen_TabletUser.exe

C:\Program Files\Tablet\Pen\Pen_Tablet.exe

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Windows\system32\conime.exe

C:\Windows\WindowsMobile\wmdc.exe

C:\Windows\RAVCpl64.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedhlp.exe

C:\Windows\ehome\ehtray.exe

C:\Windows\system32\wbem\unsecapp.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Program Files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe

C:\Program Files (x86)\Seagate\DiscWizard\TimounterMonitor.exe

C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe

C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe

C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

C:\Windows\ehome\ehmsas.exe

C:\Windows\system32\svchost.exe -k WindowsMobile

C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe

C:\Program Files\Windows Media Player\wmpnetwk.exe

C:\Windows\SysWoW64\svchost.exe

C:\Windows\system32\svchost.exe -k SDRSVC

C:\Windows\System32\osk.exe

C:\Program Files (x86)\Mozilla Firefox\firefox.exe

C:\Windows\system32\SearchProtocolHost.exe

C:\Windows\system32\SearchFilterHost.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Windows\SysWOW64\cmd.exe

C:\Windows\SysWOW64\cscript.exe

.

============== Pseudo HJT Report ===============

.

uStart Page = hxxp://www.yahoo.com/

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll

BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\ievkbd.dll

BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll

BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll

uRun: [ehTray.exe] C:\Windows\ehome\ehTray.exe

mRun: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe

mRun: [DiscWizardMonitor.exe] C:\Program Files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe

mRun: [AcronisTimounterMonitor] C:\Program Files (x86)\Seagate\DiscWizard\TimounterMonitor.exe

mRun: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe"

mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime Alternative\QTTask.exe" -atboottime

mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray

mRun: [WinPatrol] "C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe" -expressboot

mRun: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

dRun: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden

mPolicies-system: EnableLUA = 0 (0x0)

mPolicies-system: EnableUIADesktopToggle = 0 (0x0)

mPolicies-system: EnableLinkedConnections = 1 (0x1)

IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000

IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll

IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll

IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll

IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL

IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll

IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll

DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab

DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab

DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab

DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://l.yimg.com/jh/games/web_games/popcap/bejeweled2/popcaploader_v6.cab

DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://www.creative.com/softwareupdate/su2/ocx/15103/CTPID.cab

TCP: DhcpNameServer = 192.168.1.1

TCP: Interfaces\{B2707B3A-F1B2-4360-8B02-F14850833270} : DhcpNameServer = 192.168.1.1

Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll

AppInit_DLLs: C:\PROGRA~2\KASPER~1\KASPER~2\mzvkbd3.dll C:\Windows\SysWOW64\guard32.dll

SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll

mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"

BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

BHO-X64: AcroIEHelperStub - No File

BHO-X64: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll

BHO-X64: IEVkbdBHO Class: {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\ievkbd.dll

BHO-X64: IEVkbdBHO - No File

BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll

BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

BHO-X64: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

BHO-X64: FilterBHO Class: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll

BHO-X64: link filter bho - No File

mRun-x64: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe

mRun-x64: [DiscWizardMonitor.exe] C:\Program Files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe

mRun-x64: [AcronisTimounterMonitor] C:\Program Files (x86)\Seagate\DiscWizard\TimounterMonitor.exe

mRun-x64: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe"

mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime Alternative\QTTask.exe" -atboottime

mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray

mRun-x64: [WinPatrol] "C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe" -expressboot

mRun-x64: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

AppInit_DLLs-X64: C:\PROGRA~2\KASPER~1\KASPER~2\mzvkbd3.dll C:\Windows\SysWOW64\guard32.dll

SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll

.

================= FIREFOX ===================

.

FF - ProfilePath - C:\Users\Tsiphon\AppData\Roaming\Mozilla\Firefox\Profiles\h8pjtgv2.default\

FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/

FF - prefs.js: keyword.URL - hxxp://dts.search-results.com/sr?src=ffb&appid=0&systemid=410&q=

FF - prefs.js: network.proxy.http - 127.0.0.1

FF - prefs.js: network.proxy.http_port - 53960

FF - prefs.js: network.proxy.type - 0

FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll

FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll

FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll

FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrlui.dll

FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll

FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npmusicn.dll

FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll

FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll

FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll

FF - plugin: C:\Program Files (x86)\Photosynth\npPhotosynthMozilla.dll

FF - plugin: C:\Program Files (x86)\QuickTime Alternative\Plugins\npqtplugin.dll

FF - plugin: C:\Program Files (x86)\QuickTime Alternative\Plugins\npqtplugin2.dll

FF - plugin: C:\Program Files (x86)\QuickTime Alternative\Plugins\npqtplugin3.dll

FF - plugin: C:\Program Files (x86)\QuickTime Alternative\Plugins\npqtplugin4.dll

FF - plugin: C:\Program Files (x86)\QuickTime Alternative\Plugins\npqtplugin5.dll

FF - plugin: C:\Program Files (x86)\QuickTime Alternative\Plugins\npqtplugin6.dll

FF - plugin: C:\Program Files (x86)\QuickTime Alternative\Plugins\npqtplugin7.dll

FF - plugin: C:\Program Files (x86)\TabletPlugins\npwacom.dll

FF - plugin: C:\Users\Tsiphon\AppData\Roaming\Mozilla\Firefox\Profiles\h8pjtgv2.default\extensions\DeviceDetection@logitech.com\plugins\npLogitechDeviceDetection.dll

FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll

.

============= SERVICES / DRIVERS ===============

.

R0 BtHidBus;Bluetooth HID Bus Service;C:\Windows\system32\Drivers\BtHidBus.sys --> C:\Windows\system32\Drivers\BtHidBus.sys [?]

R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys --> C:\Windows\system32\Drivers\PxHlpa64.sys [?]

R1 cmdGuard;COMODO Internet Security Sandbox Driver;C:\Windows\system32\DRIVERS\cmdguard.sys --> C:\Windows\system32\DRIVERS\cmdguard.sys [?]

R1 cmdHlp;COMODO Internet Security Helper Driver;C:\Windows\system32\DRIVERS\cmdhlp.sys --> C:\Windows\system32\DRIVERS\cmdhlp.sys [?]

R1 kl2;kl2;C:\Windows\system32\DRIVERS\kl2.sys --> C:\Windows\system32\DRIVERS\kl2.sys [?]

R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\system32\DRIVERS\klim6.sys --> C:\Windows\system32\DRIVERS\klim6.sys [?]

R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-6-6 64952]

R2 cpuz135;cpuz135;\??\C:\Windows\system32\drivers\cpuz135_x64.sys --> C:\Windows\system32\drivers\cpuz135_x64.sys [?]

R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-10-26 366152]

R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2010-5-4 1153368]

R2 SgtSch2Svc;Seagate Scheduler2 Service;C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedul2.exe [2008-6-24 605464]

R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-10-16 369256]

R2 TabletServicePen;TabletServicePen;C:\Program Files\Tablet\Pen\Pen_Tablet.exe [2011-5-26 5790064]

R3 btnetBUs;Bluetooth PAN Bus Service;C:\Windows\system32\Drivers\btnetBus.sys --> C:\Windows\system32\Drivers\btnetBus.sys [?]

R3 CT20XUT.SYS;CT20XUT.SYS;C:\Windows\system32\drivers\CT20XUT.SYS --> C:\Windows\system32\drivers\CT20XUT.SYS [?]

R3 CTEXFIFX.SYS;CTEXFIFX.SYS;C:\Windows\system32\drivers\CTEXFIFX.SYS --> C:\Windows\system32\drivers\CTEXFIFX.SYS [?]

R3 CTHWIUT.SYS;CTHWIUT.SYS;C:\Windows\system32\drivers\CTHWIUT.SYS --> C:\Windows\system32\drivers\CTHWIUT.SYS [?]

R3 IvtBtBUs;IVT Bluetooth Bus Service;C:\Windows\system32\Drivers\IvtBtBus.sys --> C:\Windows\system32\Drivers\IvtBtBus.sys [?]

R3 klmouflt;Kaspersky Lab KLMOUFLT;C:\Windows\system32\DRIVERS\klmouflt.sys --> C:\Windows\system32\DRIVERS\klmouflt.sys [?]

R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]

R3 ScreamBAudioSvc;ScreamBee Audio;C:\Windows\system32\drivers\ScreamingBAudio64.sys --> C:\Windows\system32\drivers\ScreamingBAudio64.sys [?]

R3 VCSVADHWSer;Avnex Virtual Audio Device (WDM);C:\Windows\system32\DRIVERS\vcsvad.sys --> C:\Windows\system32\DRIVERS\vcsvad.sys [?]

S2 AVP;Kaspersky Anti-Virus Service;C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe [2010-7-1 352976]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]

S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]

S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-1-27 135664]

S3 AdobeActiveFileMonitor8.0;Adobe Active File Monitor V8;C:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe [2009-10-9 169312]

S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2008-8-6 79360]

S3 CT20XUT;CT20XUT;C:\Windows\system32\drivers\CT20XUT.SYS --> C:\Windows\system32\drivers\CT20XUT.SYS [?]

S3 CTEXFIFX;CTEXFIFX;C:\Windows\system32\drivers\CTEXFIFX.SYS --> C:\Windows\system32\drivers\CTEXFIFX.SYS [?]

S3 CTHWIUT;CTHWIUT;C:\Windows\system32\drivers\CTHWIUT.SYS --> C:\Windows\system32\drivers\CTHWIUT.SYS [?]

S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-1-27 135664]

S3 PerfHost;Performance Counter DLL Host;C:\Windows\SysWOW64\perfhost.exe [2008-7-22 19968]

S3 PSSDK42;PSSDK42;\??\C:\Windows\system32\Drivers\pssdk42.sys --> C:\Windows\system32\Drivers\pssdk42.sys [?]

S3 RivaTuner64;RivaTuner64;C:\Program Files (x86)\RivaTuner v2.09\RivaTuner64.sys [2008-4-28 19952]

S3 scramby_out;Scramby Output;C:\Windows\system32\drivers\scramby_out.sys --> C:\Windows\system32\drivers\scramby_out.sys [?]

S3 TouchServicePen;Wacom Consumer Touch Service;C:\Program Files\Tablet\Pen\Pen_TouchService.exe [2011-5-26 487280]

S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]

S3 wacmoumonitor;Wacom Mode Helper;C:\Windows\system32\DRIVERS\wacmoumonitor.sys --> C:\Windows\system32\DRIVERS\wacmoumonitor.sys [?]

S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-3-18 1020768]

S4 BsMobileCS;BsMobileCS;C:\Program Files (x86)\IVT Corporation\BlueSoleil\BsMobileCS.exe [2010-3-9 143467]

S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2009-3-24 93184]

S4 MSSQL$SOLARWINDS_ORION;SQL Server (SOLARWINDS_ORION); [x]

S4 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe [2010-3-25 490280]

S4 PRTG7CoreService;PRTG 8 Core Server Service; [x]

S4 PRTG7ProbeService;PRTG 8 Probe Service; [x]

S4 TomTomHOMEService;TomTomHOMEService;C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe [2009-11-13 92008]

.

=============== File Associations ===============

.

JSEFile=C:\Windows\SysWOW64\WScript.exe "%1" %*

.

=============== Created Last 30 ================

.

2011-10-31 18:23:41 -------- d-----w- C:\$RECYCLE.BIN

2011-10-31 07:06:56 0 ----a-w- C:\Windows\SysWow64\drivers\SET88DE.tmp

2011-10-31 07:06:45 0 ----a-w- C:\Windows\SysWow64\drivers\SET5C67.tmp

2011-10-31 07:06:44 0 ----a-w- C:\Windows\SysWow64\drivers\SET5AA1.tmp

2011-10-31 07:06:44 0 ----a-w- C:\Windows\SysWow64\drivers\SET584F.tmp

2011-10-31 07:06:23 0 ----a-w- C:\Windows\SysWow64\drivers\SET771.tmp

2011-10-31 07:06:22 0 ----a-w- C:\Windows\SysWow64\drivers\SET4E1.tmp

2011-10-31 07:06:07 309320 ----a-w- C:\Windows\SysWow64\drivers\TrufosAlt.sys

2011-10-31 07:06:07 0 ----a-w- C:\Windows\SysWow64\drivers\SETC86D.tmp

2011-10-31 07:05:21 0 ----a-w- C:\Windows\SysWow64\drivers\SET1747.tmp

2011-10-31 07:04:26 0 ----a-w- C:\Windows\SysWow64\drivers\SET3E2B.tmp

2011-10-31 07:04:25 0 ----a-w- C:\Windows\SysWow64\drivers\SET3C94.tmp

2011-10-31 07:04:25 0 ----a-w- C:\Windows\SysWow64\drivers\SET39E5.tmp

2011-10-31 07:04:23 0 ----a-w- C:\Windows\SysWow64\drivers\SET334F.tmp

2011-10-31 07:04:00 0 ----a-w- C:\Windows\SysWow64\drivers\SETDA09.tmp

2011-10-31 07:03:22 0 ----a-w- C:\Windows\SysWow64\drivers\SET432B.tmp

2011-10-31 07:03:21 0 ----a-w- C:\Windows\SysWow64\drivers\SET400F.tmp

2011-10-31 07:02:46 0 ----a-w- C:\Windows\SysWow64\drivers\SETB971.tmp

2011-10-31 07:02:46 0 ----a-w- C:\Windows\SysWow64\drivers\SETB6A2.tmp

2011-10-31 07:02:44 0 ----a-w- C:\Windows\SysWow64\drivers\SETAFBE.tmp

2011-10-31 06:58:23 0 ----a-w- C:\Windows\SysWow64\drivers\SETB450.tmp

2011-10-31 04:21:13 -------- d-----w- C:\Users\Tsiphon\AppData\Roaming\WinPatrol

2011-10-31 04:21:03 -------- d-----w- C:\ProgramData\InstallMate

2011-10-31 04:21:03 -------- d-----w- C:\Program Files (x86)\BillP Studios

2011-10-31 04:18:21 -------- d-----w- C:\ProgramData\Comodo

2011-10-31 04:18:17 -------- d-----w- C:\Program Files\COMODO

2011-10-31 04:17:25 -------- d-----w- C:\ProgramData\Comodo Downloader

2011-10-28 22:54:51 -------- d-----w- C:\Program Files (x86)\Eusing Free Registry Cleaner

2011-10-26 21:59:25 -------- d-----w- C:\Users\Tsiphon\AppData\Roaming\Malwarebytes

2011-10-26 21:59:20 -------- d-----w- C:\ProgramData\Malwarebytes

2011-10-26 21:59:16 25416 ----a-w- C:\Windows\System32\drivers\mbam.sys

2011-10-26 21:59:16 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware

2011-10-26 21:56:52 -------- d-----w- C:\Users\Tsiphon\AppData\Roaming\WTablet

2011-10-21 14:14:24 8570192 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FDC2EED1-71B5-48C1-ADD4-7D759D933147}\mpengine.dll

2011-10-13 22:18:09 -------- d-----w- C:\Program Files\iPod

2011-10-13 22:18:07 -------- d-----w- C:\Program Files\iTunes

2011-10-10 00:12:07 21992 ----a-w- C:\Windows\System32\drivers\cpuz135_x64.sys

2011-10-10 00:12:07 -------- d-----w- C:\Program Files\CPUID

2011-10-07 23:47:50 42224 ----a-w- C:\Windows\System32\drivers\cmdhlp.sys

2011-10-07 23:47:48 574216 ----a-w- C:\Windows\System32\drivers\cmdGuard.sys

2011-10-07 23:47:48 16528 ----a-w- C:\Windows\System32\drivers\cmderd.sys

2011-10-07 23:47:14 41200 ----a-w- C:\Windows\System32\cmdcsr.dll

2011-10-07 23:47:12 300200 ----a-w- C:\Windows\SysWow64\guard32.dll

2011-10-07 23:47:10 388280 ----a-w- C:\Windows\System32\guard64.dll

.

==================== Find3M ====================

.

2011-10-12 05:59:28 414368 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl

2011-10-03 10:06:03 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll

2011-08-31 04:05:32 96104 ----a-w- C:\Windows\System32\dns-sd.exe

2011-08-31 04:05:32 85864 ----a-w- C:\Windows\System32\dnssd.dll

2011-08-31 04:05:04 83816 ----a-w- C:\Windows\SysWow64\dns-sd.exe

2011-08-31 04:05:04 73064 ----a-w- C:\Windows\SysWow64\dnssd.dll

.

============= FINISH: 17:10:05.34 ===============

I forgot to mention that my browser is being forced into a proxy, local address and weird port, i think in an attempt to not let my programs update idk.

I went over what was required on the "I'm infected now what" sticky, but I figured i should include a HJT log as well. As follows. (Seeing all the missing Windows files, i ran sfc /scannow in the cmd prompt. It found corruption and will fix on my reboot.

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 1:57:03 PM, on 11/1/2011

Platform: Windows Vista SP1 (WinNT 6.00.1905)

MSIE: Internet Explorer v8.00 (8.00.6001.19088)

Boot mode: Normal

Running processes:

C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedhlp.exe

C:\Program Files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe

C:\Program Files (x86)\Seagate\DiscWizard\TimounterMonitor.exe

C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe

C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe

C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

C:\Users\Tsiphon\Desktop\ProcessExplorer\procexp.exe

C:\Program Files (x86)\Trend Micro\HijackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll

O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\ievkbd.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll

O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll

O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe

O4 - HKLM\..\Run: [DiscWizardMonitor.exe] C:\Program Files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe

O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files (x86)\Seagate\DiscWizard\TimounterMonitor.exe

O4 - HKLM\..\Run: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe"

O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime Alternative\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray

O4 - HKLM\..\Run: [WinPatrol] "C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe" -expressboot

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe

O4 - HKUS\S-1-5-18\..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden (User 'Default user')

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll

O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll

O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll

O9 - Extra button: &Virtual Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll

O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab

O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} (Java Plug-in 1.6.0_13) -

O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://l.yimg.com/jh/games/web_games/popcap/bejeweled2/popcaploader_v6.cab

O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/softwareupdate/su2/ocx/15103/CTPID.cab

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll

O20 - AppInit_DLLs: C:\PROGRA~2\KASPER~1\KASPER~2\mzvkbd3.dll C:\Windows\SysWOW64\guard32.dll

O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll

O23 - Service: Adobe Active File Monitor V8 (AdobeActiveFileMonitor8.0) - Adobe Systems Incorporated - C:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe

O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

O23 - Service: Kaspersky Anti-Virus Service (AVP) - Kaspersky Lab ZAO - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe

O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe

O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe

O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe

O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)

O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe

O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)

O23 - Service: @mqutil.dll,-6102 (MSMQ) - Unknown owner - C:\Windows\system32\mqsvc.exe (file missing)

O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: NVIDIA Driver Helper Service (NVSvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)

O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe

O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe

O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)

O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe

O23 - Service: ServiceLayer - Nokia. - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe

O23 - Service: Seagate Scheduler2 Service (SgtSch2Svc) - Seagate - C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedul2.exe

O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)

O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)

O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

O23 - Service: TabletServicePen - Wacom Technology, Corp. - C:\Program Files\Tablet\Pen\Pen_Tablet.exe

O23 - Service: Wacom Consumer Touch Service (TouchServicePen) - Wacom Technology, Corp. - C:\Program Files\Tablet\Pen\Pen_TouchService.exe

O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)

O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)

O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)

O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)

O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--

End of file - 11404 bytes

Link to post
Share on other sites

  • Replies 57
  • Created
  • Last Reply

Top Posters In This Topic

Top Posters In This Topic

Posted Images

A couple of addition details that might help identify anything.

I can visit anti-virus related sites, but my windows defender/firewall reports errors when trying to turn them on or off. Firefox and IE will often start, and show up in Process Explorer (and malwarebytes reports the browsers trying to connect to different ips,) but most of the time the browser window is never opened to me. Looking at the command line in process explorer, sometimes the svchosts have commands to connect to weird sites, I think one was about realtors.

Also, occasionally my google searches will redirect to random "search" sites, like search.this.com/somethinghere. That hasn't happened recently.

When I have been troubleshooting I have kept the computer unplugged from the internet.

I can open any anti-virus software I have tried.

The following anti-virus's produce "no threats found":

Malwarebytes

Spybot Search & Destroy

Kaspersky

TDSSkiller

GMER

and maybe a few others.

There are no weird non-microsoft processes running that I can tell, and the services behind the rogue microsoft programs seem to be standard ones, ntdll.dll and the like.

Basically I can't find any process or service that would point to a clear virus from my standpoint. I've tried working on this alot and search around for similar problems but I'm at a loss.

Link to post
Share on other sites

I get a bluescreen, system error ATAPORT.SYS when trying to scan. I tried twice, once regular, and once as administrator. I simply opened the program and clicked 'No' to "do you want to download AVAST virus definitions" and then clicked scan. I will post a DDS log in an hour or so.

Link to post
Share on other sites

Yes, I disabled all security, and tried in Safe mode. Same result with the blue screen and ATAPORT.SYS error.

Here is my new DDS log.

.

DDS (Ver_2011-08-26.01) - NTFSAMD64

Internet Explorer: 8.0.6001.19088 BrowserJavaVersion: 1.6.0_29

Run by Tsiphon at 19:31:09 on 2011-11-05

Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1252.1.1033.18.4094.2642 [GMT -5:00]

.

AV: Kaspersky Anti-Virus *Disabled/Outdated* {56547CC9-C9B2-849D-8FEF-A496150D6A06}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

SP: Kaspersky Anti-Virus *Disabled/Updated* {ED359D2D-EF88-8B13-B55F-9FE46E8A20BB}

SP: COMODO Defense+ *Enabled/Updated* {CE351521-78FA-2048-BB22-B68A4A5CA7EC}

FW: COMODO Firewall *Enabled* {4D6F75E0-14AF-2E9E-AACD-24CDCF08AA2A}

.

============== Running Processes ===============

.

C:\Windows\system32\wininit.exe

C:\Windows\system32\lsm.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\nvvsvc.exe

C:\Windows\system32\svchost.exe -k rpcss

C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe

C:\Windows\system32\svchost.exe -k NetworkService

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k netsvcs

C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe

C:\Windows\system32\svchost.exe -k GPSvcGroup

C:\Windows\system32\SLsvc.exe

C:\Windows\system32\svchost.exe -k LocalService

C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe

C:\Windows\system32\nvvsvc.exe

C:\Windows\System32\spoolsv.exe

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

C:\Windows\system32\svchost.exe -k apphost

C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

C:\Windows\SysWoW64\svchost.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt

C:\Windows\system32\mqsvc.exe

C:\Windows\System32\svchost.exe -k HPZ12

C:\Windows\System32\svchost.exe -k HPZ12

C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedul2.exe

C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

C:\Windows\system32\taskeng.exe

C:\Windows\system32\svchost.exe -k imgsvc

C:\Program Files\Tablet\Pen\Pen_Tablet.exe

C:\Windows\system32\svchost.exe -k iissvcs

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

C:\Windows\system32\SearchIndexer.exe

C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe

C:\Windows\system32\taskeng.exe

C:\Program Files\Tablet\Pen\Pen_TabletUser.exe

C:\Windows\Explorer.EXE

C:\Windows\system32\Dwm.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

C:\Program Files\Tablet\Pen\Pen_Tablet.exe

C:\Windows\System32\WerFault.exe

C:\Windows\WindowsMobile\wmdc.exe

C:\Windows\RAVCpl64.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedhlp.exe

C:\Windows\ehome\ehtray.exe

C:\Windows\ehome\ehmsas.exe

C:\Windows\system32\wbem\unsecapp.exe

C:\Program Files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe

C:\Program Files (x86)\Seagate\DiscWizard\TimounterMonitor.exe

C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe

C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Windows\system32\svchost.exe -k WindowsMobile

C:\Windows\system32\wbem\wmiprvse.exe

C:\Windows\SysWOW64\cmd.exe

C:\Windows\SysWOW64\conime.exe

C:\Windows\SysWOW64\cscript.exe

.

============== Pseudo HJT Report ===============

.

uStart Page = hxxp://www.yahoo.com/

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll

BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\ievkbd.dll

BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll

BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll

uRun: [ehTray.exe] C:\Windows\ehome\ehTray.exe

mRun: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe

mRun: [DiscWizardMonitor.exe] C:\Program Files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe

mRun: [AcronisTimounterMonitor] C:\Program Files (x86)\Seagate\DiscWizard\TimounterMonitor.exe

mRun: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe"

mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime Alternative\QTTask.exe" -atboottime

mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray

mRun: [WinPatrol] "C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe" -expressboot

mRun: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

dRun: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden

mPolicies-system: EnableLUA = 0 (0x0)

mPolicies-system: EnableUIADesktopToggle = 0 (0x0)

mPolicies-system: EnableLinkedConnections = 1 (0x1)

IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000

IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll

IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll

IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll

IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL

IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll

IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll

DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab

DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab

DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab

DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://l.yimg.com/jh/games/web_games/popcap/bejeweled2/popcaploader_v6.cab

DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://www.creative.com/softwareupdate/su2/ocx/15103/CTPID.cab

TCP: DhcpNameServer = 192.168.1.1

TCP: Interfaces\{B2707B3A-F1B2-4360-8B02-F14850833270} : DhcpNameServer = 192.168.1.1

Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll

AppInit_DLLs: C:\PROGRA~2\KASPER~1\KASPER~2\mzvkbd3.dll C:\Windows\SysWOW64\guard32.dll

SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll

mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"

BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

BHO-X64: AcroIEHelperStub - No File

BHO-X64: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll

BHO-X64: IEVkbdBHO Class: {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\ievkbd.dll

BHO-X64: IEVkbdBHO - No File

BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll

BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

BHO-X64: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

BHO-X64: FilterBHO Class: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll

BHO-X64: link filter bho - No File

mRun-x64: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe

mRun-x64: [DiscWizardMonitor.exe] C:\Program Files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe

mRun-x64: [AcronisTimounterMonitor] C:\Program Files (x86)\Seagate\DiscWizard\TimounterMonitor.exe

mRun-x64: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe"

mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime Alternative\QTTask.exe" -atboottime

mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray

mRun-x64: [WinPatrol] "C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe" -expressboot

mRun-x64: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

AppInit_DLLs-X64: C:\PROGRA~2\KASPER~1\KASPER~2\mzvkbd3.dll C:\Windows\SysWOW64\guard32.dll

SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll

.

================= FIREFOX ===================

.

FF - ProfilePath - C:\Users\Tsiphon\AppData\Roaming\Mozilla\Firefox\Profiles\h8pjtgv2.default\

FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/

FF - prefs.js: keyword.URL - hxxp://dts.search-results.com/sr?src=ffb&appid=0&systemid=410&q=

FF - prefs.js: network.proxy.http - 127.0.0.1

FF - prefs.js: network.proxy.http_port - 53960

FF - prefs.js: network.proxy.type - 1

FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll

FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll

FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll

FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrlui.dll

FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll

FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npmusicn.dll

FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll

FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll

FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll

FF - plugin: C:\Program Files (x86)\Photosynth\npPhotosynthMozilla.dll

FF - plugin: C:\Program Files (x86)\QuickTime Alternative\Plugins\npqtplugin.dll

FF - plugin: C:\Program Files (x86)\QuickTime Alternative\Plugins\npqtplugin2.dll

FF - plugin: C:\Program Files (x86)\QuickTime Alternative\Plugins\npqtplugin3.dll

FF - plugin: C:\Program Files (x86)\QuickTime Alternative\Plugins\npqtplugin4.dll

FF - plugin: C:\Program Files (x86)\QuickTime Alternative\Plugins\npqtplugin5.dll

FF - plugin: C:\Program Files (x86)\QuickTime Alternative\Plugins\npqtplugin6.dll

FF - plugin: C:\Program Files (x86)\QuickTime Alternative\Plugins\npqtplugin7.dll

FF - plugin: C:\Program Files (x86)\TabletPlugins\npwacom.dll

FF - plugin: C:\Users\Tsiphon\AppData\Roaming\Mozilla\Firefox\Profiles\h8pjtgv2.default\extensions\DeviceDetection@logitech.com\plugins\npLogitechDeviceDetection.dll

FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll

.

============= SERVICES / DRIVERS ===============

.

R0 BtHidBus;Bluetooth HID Bus Service;C:\Windows\system32\Drivers\BtHidBus.sys --> C:\Windows\system32\Drivers\BtHidBus.sys [?]

R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys --> C:\Windows\system32\Drivers\PxHlpa64.sys [?]

R1 cmdGuard;COMODO Internet Security Sandbox Driver;C:\Windows\system32\DRIVERS\cmdguard.sys --> C:\Windows\system32\DRIVERS\cmdguard.sys [?]

R1 cmdHlp;COMODO Internet Security Helper Driver;C:\Windows\system32\DRIVERS\cmdhlp.sys --> C:\Windows\system32\DRIVERS\cmdhlp.sys [?]

R1 kl2;kl2;C:\Windows\system32\DRIVERS\kl2.sys --> C:\Windows\system32\DRIVERS\kl2.sys [?]

R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\system32\DRIVERS\klim6.sys --> C:\Windows\system32\DRIVERS\klim6.sys [?]

R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-6-6 64952]

R2 cpuz135;cpuz135;\??\C:\Windows\system32\drivers\cpuz135_x64.sys --> C:\Windows\system32\drivers\cpuz135_x64.sys [?]

R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2010-5-4 1153368]

R2 SgtSch2Svc;Seagate Scheduler2 Service;C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedul2.exe [2008-6-24 605464]

R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-10-16 369256]

R2 TabletServicePen;TabletServicePen;C:\Program Files\Tablet\Pen\Pen_Tablet.exe [2011-5-26 5790064]

R3 btnetBUs;Bluetooth PAN Bus Service;C:\Windows\system32\Drivers\btnetBus.sys --> C:\Windows\system32\Drivers\btnetBus.sys [?]

R3 CT20XUT.SYS;CT20XUT.SYS;C:\Windows\system32\drivers\CT20XUT.SYS --> C:\Windows\system32\drivers\CT20XUT.SYS [?]

R3 CTEXFIFX.SYS;CTEXFIFX.SYS;C:\Windows\system32\drivers\CTEXFIFX.SYS --> C:\Windows\system32\drivers\CTEXFIFX.SYS [?]

R3 CTHWIUT.SYS;CTHWIUT.SYS;C:\Windows\system32\drivers\CTHWIUT.SYS --> C:\Windows\system32\drivers\CTHWIUT.SYS [?]

R3 IvtBtBUs;IVT Bluetooth Bus Service;C:\Windows\system32\Drivers\IvtBtBus.sys --> C:\Windows\system32\Drivers\IvtBtBus.sys [?]

R3 klmouflt;Kaspersky Lab KLMOUFLT;C:\Windows\system32\DRIVERS\klmouflt.sys --> C:\Windows\system32\DRIVERS\klmouflt.sys [?]

R3 ScreamBAudioSvc;ScreamBee Audio;C:\Windows\system32\drivers\ScreamingBAudio64.sys --> C:\Windows\system32\drivers\ScreamingBAudio64.sys [?]

R3 VCSVADHWSer;Avnex Virtual Audio Device (WDM);C:\Windows\system32\DRIVERS\vcsvad.sys --> C:\Windows\system32\DRIVERS\vcsvad.sys [?]

S2 AVP;Kaspersky Anti-Virus Service;C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe [2010-7-1 352976]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]

S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]

S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-1-27 135664]

S2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-10-26 366152]

S3 AdobeActiveFileMonitor8.0;Adobe Active File Monitor V8;C:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe [2009-10-9 169312]

S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2008-8-6 79360]

S3 CT20XUT;CT20XUT;C:\Windows\system32\drivers\CT20XUT.SYS --> C:\Windows\system32\drivers\CT20XUT.SYS [?]

S3 CTEXFIFX;CTEXFIFX;C:\Windows\system32\drivers\CTEXFIFX.SYS --> C:\Windows\system32\drivers\CTEXFIFX.SYS [?]

S3 CTHWIUT;CTHWIUT;C:\Windows\system32\drivers\CTHWIUT.SYS --> C:\Windows\system32\drivers\CTHWIUT.SYS [?]

S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-1-27 135664]

S3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]

S3 MEMSWEEP2;MEMSWEEP2;\??\C:\Windows\system32\B85.tmp --> C:\Windows\system32\B85.tmp [?]

S3 PerfHost;Performance Counter DLL Host;C:\Windows\SysWOW64\perfhost.exe [2008-7-22 19968]

S3 PSSDK42;PSSDK42;\??\C:\Windows\system32\Drivers\pssdk42.sys --> C:\Windows\system32\Drivers\pssdk42.sys [?]

S3 RivaTuner64;RivaTuner64;C:\Program Files (x86)\RivaTuner v2.09\RivaTuner64.sys [2008-4-28 19952]

S3 scramby_out;Scramby Output;C:\Windows\system32\drivers\scramby_out.sys --> C:\Windows\system32\drivers\scramby_out.sys [?]

S3 TouchServicePen;Wacom Consumer Touch Service;C:\Program Files\Tablet\Pen\Pen_TouchService.exe [2011-5-26 487280]

S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]

S3 wacmoumonitor;Wacom Mode Helper;C:\Windows\system32\DRIVERS\wacmoumonitor.sys --> C:\Windows\system32\DRIVERS\wacmoumonitor.sys [?]

S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-3-18 1020768]

S4 BsMobileCS;BsMobileCS;C:\Program Files (x86)\IVT Corporation\BlueSoleil\BsMobileCS.exe [2010-3-9 143467]

S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2009-3-24 93184]

S4 MSSQL$SOLARWINDS_ORION;SQL Server (SOLARWINDS_ORION); [x]

S4 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe [2010-3-25 490280]

S4 TomTomHOMEService;TomTomHOMEService;C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe [2009-11-13 92008]

.

=============== File Associations ===============

.

JSEFile=C:\Windows\SysWOW64\WScript.exe "%1" %*

.

=============== Created Last 30 ================

.

2011-11-02 23:46:30 6144 ------w- C:\Windows\System32\B85.tmp

2011-11-02 23:40:23 6144 ------w- C:\Windows\System32\7213.tmp

2011-11-02 23:30:25 6144 ------w- C:\Windows\System32\5060.tmp

2011-11-02 23:22:41 6144 ------w- C:\Windows\System32\1AC0.tmp

2011-11-02 23:16:36 6144 ------w- C:\Windows\System32\88FD.tmp

2011-11-02 23:11:45 6144 ------w- C:\Windows\System32\1821.tmp

2011-11-02 23:11:14 -------- d-----w- C:\Program Files (x86)\Sophos

2011-11-02 22:09:25 834 ----a-w- C:\ProgramData\vmpxaaa.tmp

2011-11-01 18:56:45 388096 ----a-r- C:\Users\Tsiphon\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe

2011-10-31 18:23:41 -------- d-----w- C:\$RECYCLE.BIN

2011-10-31 07:06:56 0 ----a-w- C:\Windows\SysWow64\drivers\SET88DE.tmp

2011-10-31 07:06:45 0 ----a-w- C:\Windows\SysWow64\drivers\SET5C67.tmp

2011-10-31 07:06:44 0 ----a-w- C:\Windows\SysWow64\drivers\SET5AA1.tmp

2011-10-31 07:06:44 0 ----a-w- C:\Windows\SysWow64\drivers\SET584F.tmp

2011-10-31 07:06:23 0 ----a-w- C:\Windows\SysWow64\drivers\SET771.tmp

2011-10-31 07:06:22 0 ----a-w- C:\Windows\SysWow64\drivers\SET4E1.tmp

2011-10-31 07:06:07 309320 ----a-w- C:\Windows\SysWow64\drivers\TrufosAlt.sys

2011-10-31 07:06:07 0 ----a-w- C:\Windows\SysWow64\drivers\SETC86D.tmp

2011-10-31 07:05:21 0 ----a-w- C:\Windows\SysWow64\drivers\SET1747.tmp

2011-10-31 07:04:26 0 ----a-w- C:\Windows\SysWow64\drivers\SET3E2B.tmp

2011-10-31 07:04:25 0 ----a-w- C:\Windows\SysWow64\drivers\SET3C94.tmp

2011-10-31 07:04:25 0 ----a-w- C:\Windows\SysWow64\drivers\SET39E5.tmp

2011-10-31 07:04:23 0 ----a-w- C:\Windows\SysWow64\drivers\SET334F.tmp

2011-10-31 07:04:00 0 ----a-w- C:\Windows\SysWow64\drivers\SETDA09.tmp

2011-10-31 07:03:22 0 ----a-w- C:\Windows\SysWow64\drivers\SET432B.tmp

2011-10-31 07:03:21 0 ----a-w- C:\Windows\SysWow64\drivers\SET400F.tmp

2011-10-31 07:02:46 0 ----a-w- C:\Windows\SysWow64\drivers\SETB971.tmp

2011-10-31 07:02:46 0 ----a-w- C:\Windows\SysWow64\drivers\SETB6A2.tmp

2011-10-31 07:02:44 0 ----a-w- C:\Windows\SysWow64\drivers\SETAFBE.tmp

2011-10-31 06:58:23 0 ----a-w- C:\Windows\SysWow64\drivers\SETB450.tmp

2011-10-31 04:21:13 -------- d-----w- C:\Users\Tsiphon\AppData\Roaming\WinPatrol

2011-10-31 04:21:03 -------- d-----w- C:\ProgramData\InstallMate

2011-10-31 04:21:03 -------- d-----w- C:\Program Files (x86)\BillP Studios

2011-10-31 04:18:21 -------- d-----w- C:\ProgramData\Comodo

2011-10-31 04:18:17 -------- d-----w- C:\Program Files\COMODO

2011-10-31 04:17:25 -------- d-----w- C:\ProgramData\Comodo Downloader

2011-10-28 22:54:51 -------- d-----w- C:\Program Files (x86)\Eusing Free Registry Cleaner

2011-10-26 21:59:25 -------- d-----w- C:\Users\Tsiphon\AppData\Roaming\Malwarebytes

2011-10-26 21:59:20 -------- d-----w- C:\ProgramData\Malwarebytes

2011-10-26 21:59:16 25416 ----a-w- C:\Windows\System32\drivers\mbam.sys

2011-10-26 21:59:16 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware

2011-10-26 21:56:52 -------- d-----w- C:\Users\Tsiphon\AppData\Roaming\WTablet

2011-10-21 14:14:24 8570192 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FDC2EED1-71B5-48C1-ADD4-7D759D933147}\mpengine.dll

2011-10-13 22:18:09 -------- d-----w- C:\Program Files\iPod

2011-10-13 22:18:07 -------- d-----w- C:\Program Files\iTunes

2011-10-10 00:12:07 21992 ----a-w- C:\Windows\System32\drivers\cpuz135_x64.sys

2011-10-10 00:12:07 -------- d-----w- C:\Program Files\CPUID

2011-10-07 23:47:50 42224 ----a-w- C:\Windows\System32\drivers\cmdhlp.sys

2011-10-07 23:47:48 574216 ----a-w- C:\Windows\System32\drivers\cmdGuard.sys

2011-10-07 23:47:48 16528 ----a-w- C:\Windows\System32\drivers\cmderd.sys

2011-10-07 23:47:14 41200 ----a-w- C:\Windows\System32\cmdcsr.dll

2011-10-07 23:47:12 300200 ----a-w- C:\Windows\SysWow64\guard32.dll

2011-10-07 23:47:10 388280 ----a-w- C:\Windows\System32\guard64.dll

.

==================== Find3M ====================

.

2011-10-12 05:59:28 414368 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl

2011-10-03 10:06:03 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll

2011-08-31 04:05:32 96104 ----a-w- C:\Windows\System32\dns-sd.exe

2011-08-31 04:05:32 85864 ----a-w- C:\Windows\System32\dnssd.dll

2011-08-31 04:05:04 83816 ----a-w- C:\Windows\SysWow64\dns-sd.exe

2011-08-31 04:05:04 73064 ----a-w- C:\Windows\SysWow64\dnssd.dll

.

============= FINISH: 19:33:08.39 ===============

Link to post
Share on other sites

Hi

Please visit this webpage for download links, and instructions for running ComboFix tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Please ensure you read this guide carefully first.

Please continue as follows:

  1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix, link
    Remember to re-enable them afterwards.
  2. Click Yes to allow ComboFix to continue scanning for malware.

When the tool is finished, it will produce a report for you.

Please include the following reports for further review, and so we may continue cleansing the system:

C:\ComboFix.txt

New dds log.

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix. This tool is not a toy and not for everyday use.

Link to post
Share on other sites

ComboFix 11-11-06.02 - Tsiphon 11/06/2011 13:23:37.3.4 - x64

Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1252.1.1033.18.4094.1944 [GMT -6:00]

Running from: c:\users\Tsiphon\Desktop\ComboFix.exe

AV: Kaspersky Anti-Virus *Disabled/Outdated* {56547CC9-C9B2-849D-8FEF-A496150D6A06}

FW: COMODO Firewall *Enabled* {4D6F75E0-14AF-2E9E-AACD-24CDCF08AA2A}

SP: COMODO Defense+ *Enabled/Updated* {CE351521-78FA-2048-BB22-B68A4A5CA7EC}

SP: Kaspersky Anti-Virus *Disabled/Updated* {ED359D2D-EF88-8B13-B55F-9FE46E8A20BB}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

* Created a new restore point

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\programdata\vmpxaaa.tmp

.

.

((((((((((((((((((((((((( Files Created from 2011-10-06 to 2011-11-06 )))))))))))))))))))))))))))))))

.

.

2011-11-06 19:42 . 2011-11-06 19:42 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\temp

2011-11-06 19:42 . 2011-11-06 19:42 -------- d-----w- c:\users\Mcx1\AppData\Local\temp

2011-11-06 19:42 . 2011-11-06 19:42 -------- d-----w- c:\users\Guest\AppData\Local\temp

2011-11-06 19:42 . 2011-11-06 19:42 -------- d-----w- c:\users\Default\AppData\Local\temp

2011-11-02 23:46 . 2011-05-12 19:03 6144 ------w- c:\windows\system32\B85.tmp

2011-11-02 23:40 . 2011-05-12 19:03 6144 ------w- c:\windows\system32\7213.tmp

2011-11-02 23:30 . 2011-05-12 19:03 6144 ------w- c:\windows\system32\5060.tmp

2011-11-02 23:22 . 2011-05-12 19:03 6144 ------w- c:\windows\system32\1AC0.tmp

2011-11-02 23:16 . 2011-05-12 19:03 6144 ------w- c:\windows\system32\88FD.tmp

2011-11-02 23:11 . 2011-05-12 19:03 6144 ------w- c:\windows\system32\1821.tmp

2011-11-02 23:11 . 2011-11-02 23:11 -------- d-----w- c:\program files (x86)\Sophos

2011-11-01 18:56 . 2011-11-01 18:56 388096 ----a-r- c:\users\Tsiphon\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe

2011-10-31 07:06 . 2011-10-31 07:06 0 ----a-w- c:\windows\SysWow64\drivers\SET88DE.tmp

2011-10-31 07:06 . 2011-10-31 07:06 0 ----a-w- c:\windows\SysWow64\drivers\SET5C67.tmp

2011-10-31 07:06 . 2011-10-31 07:06 0 ----a-w- c:\windows\SysWow64\drivers\SET5AA1.tmp

2011-10-31 07:06 . 2011-10-31 07:06 0 ----a-w- c:\windows\SysWow64\drivers\SET584F.tmp

2011-10-31 07:06 . 2011-10-31 07:06 0 ----a-w- c:\windows\SysWow64\drivers\SET771.tmp

2011-10-31 07:06 . 2011-10-31 07:06 0 ----a-w- c:\windows\SysWow64\drivers\SET4E1.tmp

2011-10-31 07:06 . 2011-10-31 07:07 309320 ----a-w- c:\windows\SysWow64\drivers\TrufosAlt.sys

2011-10-31 07:06 . 2011-10-31 07:06 0 ----a-w- c:\windows\SysWow64\drivers\SETC86D.tmp

2011-10-31 07:05 . 2011-10-31 07:05 0 ----a-w- c:\windows\SysWow64\drivers\SET1747.tmp

2011-10-31 07:04 . 2011-10-31 07:04 0 ----a-w- c:\windows\SysWow64\drivers\SET3E2B.tmp

2011-10-31 07:04 . 2011-10-31 07:04 0 ----a-w- c:\windows\SysWow64\drivers\SET3C94.tmp

2011-10-31 07:04 . 2011-10-31 07:04 0 ----a-w- c:\windows\SysWow64\drivers\SET39E5.tmp

2011-10-31 07:04 . 2011-10-31 07:04 0 ----a-w- c:\windows\SysWow64\drivers\SET334F.tmp

2011-10-31 07:04 . 2011-10-31 07:04 0 ----a-w- c:\windows\SysWow64\drivers\SETDA09.tmp

2011-10-31 07:03 . 2011-10-31 07:03 0 ----a-w- c:\windows\SysWow64\drivers\SET432B.tmp

2011-10-31 07:03 . 2011-10-31 07:03 0 ----a-w- c:\windows\SysWow64\drivers\SET400F.tmp

2011-10-31 07:02 . 2011-10-31 07:02 0 ----a-w- c:\windows\SysWow64\drivers\SETB971.tmp

2011-10-31 07:02 . 2011-10-31 07:02 0 ----a-w- c:\windows\SysWow64\drivers\SETB6A2.tmp

2011-10-31 07:02 . 2011-10-31 07:02 0 ----a-w- c:\windows\SysWow64\drivers\SETAFBE.tmp

2011-10-31 06:58 . 2011-10-31 06:58 0 ----a-w- c:\windows\SysWow64\drivers\SETB450.tmp

2011-10-31 04:21 . 2011-10-31 04:21 -------- d-----w- c:\users\Tsiphon\AppData\Roaming\WinPatrol

2011-10-31 04:21 . 2011-10-31 04:21 -------- d-----w- c:\programdata\InstallMate

2011-10-31 04:21 . 2011-10-31 04:21 -------- d-----w- c:\program files (x86)\BillP Studios

2011-10-31 04:18 . 2011-11-02 08:48 -------- d-----w- c:\programdata\Comodo

2011-10-31 04:18 . 2011-10-31 04:18 -------- d-----w- c:\program files\COMODO

2011-10-31 04:17 . 2011-10-31 04:18 -------- d-----w- c:\programdata\Comodo Downloader

2011-10-29 08:24 . 2011-10-29 10:15 -------- d-----w- c:\users\Tsiphon\AppData\Roaming\Winamp

2011-10-28 22:54 . 2011-10-28 23:09 -------- d-----w- c:\program files (x86)\Eusing Free Registry Cleaner

2011-10-26 21:59 . 2011-10-26 21:59 -------- d-----w- c:\users\Tsiphon\AppData\Roaming\Malwarebytes

2011-10-26 21:59 . 2011-10-26 21:59 -------- d-----w- c:\programdata\Malwarebytes

2011-10-26 21:59 . 2011-10-27 02:50 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware

2011-10-26 21:59 . 2011-08-31 22:00 25416 ----a-w- c:\windows\system32\drivers\mbam.sys

2011-10-26 21:56 . 2011-10-26 21:56 -------- d-----w- c:\users\Tsiphon\AppData\Roaming\WTablet

2011-10-21 14:14 . 2011-10-07 04:16 8570192 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{FDC2EED1-71B5-48C1-ADD4-7D759D933147}\mpengine.dll

2011-10-13 22:18 . 2011-10-13 22:18 -------- d-----w- c:\program files\iPod

2011-10-13 22:18 . 2011-10-13 22:19 -------- d-----w- c:\program files\iTunes

2011-10-10 00:12 . 2011-10-10 00:12 -------- d-----w- c:\program files\CPUID

2011-10-10 00:12 . 2010-11-09 20:35 21992 ----a-w- c:\windows\system32\drivers\cpuz135_x64.sys

2011-10-07 23:47 . 2011-10-07 23:47 93200 ----a-w- c:\windows\system32\drivers\inspect.sys

2011-10-07 23:47 . 2011-10-07 23:47 42224 ----a-w- c:\windows\system32\drivers\cmdhlp.sys

2011-10-07 23:47 . 2011-10-07 23:47 574216 ----a-w- c:\windows\system32\drivers\cmdGuard.sys

2011-10-07 23:47 . 2011-10-07 23:47 16528 ----a-w- c:\windows\system32\drivers\cmderd.sys

2011-10-07 23:47 . 2011-10-07 23:47 41200 ----a-w- c:\windows\system32\cmdcsr.dll

2011-10-07 23:47 . 2011-10-07 23:47 300200 ----a-w- c:\windows\SysWow64\guard32.dll

2011-10-07 23:47 . 2011-10-07 23:47 388280 ----a-w- c:\windows\system32\guard64.dll

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2011-10-12 05:59 . 2011-05-28 03:51 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2011-10-03 10:06 . 2010-04-30 21:21 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll

2011-08-31 04:05 . 2011-08-31 04:05 96104 ----a-w- c:\windows\system32\dns-sd.exe

2011-08-31 04:05 . 2011-08-31 04:05 85864 ----a-w- c:\windows\system32\dnssd.dll

2011-08-31 04:05 . 2011-08-31 04:05 83816 ----a-w- c:\windows\SysWow64\dns-sd.exe

2011-08-31 04:05 . 2011-08-31 04:05 73064 ----a-w- c:\windows\SysWow64\dnssd.dll

.

.

------- Sigcheck -------

Note: Unsigned files aren't necessarily malware.

.

[7] 2008-07-19 . 437C1C0CB2A42EA20083F21E9CAEF461 . 646656 . . [6.0.6000.20537] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.20537_none_32359eb27623cc22\user32.dll

[7] 2008-07-19 . 296BA70E2A302E639CBD9E2A32DC65C4 . 646656 . . [6.0.6000.16438] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.16438_none_31ad02315d0545af\user32.dll

[-] 2008-01-19 . BC8872C0B1B4599D60857B9E6BB66E44 . 672256 . . [6.0.6001.18000] .. c:\windows\SysWOW64\user32.dll

[7] 2008-01-19 . 3D691030DBD3BD75DE1501BE54F0D425 . 648192 . . [6.0.6001.18000] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_33abb2175a1ab263\user32.dll

[7] 2006-11-02 . 00B53DCA0408CCD8F6BAF13994F6E3A0 . 646656 . . [6.0.6000.16386] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.16386_none_3174f01b5d2fa18f\user32.dll

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 138240]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"AppleSyncNotifier"="c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-09-27 59240]

"DiscWizardMonitor.exe"="c:\program files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe" [2008-06-25 1325848]

"AcronisTimounterMonitor"="c:\program files (x86)\Seagate\DiscWizard\TimounterMonitor.exe" [2008-06-25 904768]

"AVP"="c:\program files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe" [2011-05-27 352976]

"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]

"QuickTime Task"="c:\program files (x86)\QuickTime Alternative\QTTask.exe" [2011-07-05 421888]

"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]

"WinPatrol"="c:\program files (x86)\BillP Studios\WinPatrol\winpatrol.exe" [2011-05-15 325512]

"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]

.

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"LightScribe Control Panel"="c:\program files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe" [2009-06-17 2363392]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"EnableLUA"= 0 (0x0)

"EnableUIADesktopToggle"= 0 (0x0)

"EnableLinkedConnections"= 1 (0x1)

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]

"AppInit_DLLs"=c:\progra~2\KASPER~1\KASPER~2\mzvkbd3.dll c:\windows\SysWOW64\guard32.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]

"aux8"=wdmaud.drv

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]

"LogitechQuickCamRibbon"="c:\program files (x86)\Logitech\QuickCam\Quickcam.exe" /hide

"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe"

"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]

"DisableMonitoring"=dword:00000001

.

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]

R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-27 135664]

R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-08-31 366152]

R2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]

R3 AdobeActiveFileMonitor8.0;Adobe Active File Monitor V8;c:\program files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe [2009-10-09 169312]

R3 CamDrL64;Logitech QuickCam Pro 3000(PID_08B0); [x]

R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2008-08-06 79360]

R3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.SYS [x]

R3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.SYS [x]

R3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.SYS [x]

R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-27 135664]

R3 LVcKap64;Logitech AEC Driver; [x]

R3 LVPr2M64;Logitech LVPr2M64 Driver; [x]

R3 LVUSBS64;Logitech USB Monitor Filter; [x]

R3 MEMSWEEP2;MEMSWEEP2;c:\windows\system32\B85.tmp [x]

R3 PSSDK42;PSSDK42;c:\windows\system32\Drivers\pssdk42.sys [x]

R3 RivaTuner64;RivaTuner64;c:\program files (x86)\RivaTuner v2.09\RivaTuner64.sys [2008-07-19 19952]

R3 rt61x64;Ralink RT61 Wireless Driver for Windows Vista; [x]

R3 scramby_out;Scramby Output;c:\windows\system32\drivers\scramby_out.sys [x]

R3 TouchServicePen;Wacom Consumer Touch Service;c:\program files\Tablet\Pen\Pen_TouchService.exe [2010-10-13 487280]

R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]

R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\DRIVERS\wacmoumonitor.sys [x]

R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 1020768]

R3 X6va003;X6va003;c:\users\Tsiphon\AppData\Local\Temp\003F29A.tmp [x]

R4 BsMobileCS;BsMobileCS;c:\program files (x86)\IVT Corporation\BlueSoleil\BsMobileCS.exe [2010-03-09 143467]

R4 MSSQL$SOLARWINDS_ORION;SQL Server (SOLARWINDS_ORION); [x]

R4 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2010-03-25 490280]

R4 TomTomHOMEService;TomTomHOMEService;c:\program files (x86)\TomTom HOME 2\TomTomHOMEService.exe [2009-11-13 92008]

S0 BtHidBus;Bluetooth HID Bus Service;c:\windows\System32\Drivers\BtHidBus.sys [x]

S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]

S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [x]

S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [x]

S1 kl2;kl2;c:\windows\system32\DRIVERS\kl2.sys [x]

S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [x]

S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]

S2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x64.sys [x]

S2 SgtSch2Svc;Seagate Scheduler2 Service;c:\program files (x86)\Common Files\Seagate\Schedule2\schedul2.exe [2008-06-25 605464]

S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-10-16 369256]

S2 TabletServicePen;TabletServicePen;c:\program files\Tablet\Pen\Pen_Tablet.exe [2010-10-13 5790064]

S3 btnetBUs;Bluetooth PAN Bus Service;c:\windows\system32\Drivers\btnetBus.sys [x]

S3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\System32\drivers\CT20XUT.SYS [x]

S3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\System32\drivers\CTEXFIFX.SYS [x]

S3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\System32\drivers\CTHWIUT.SYS [x]

S3 IvtBtBUs;IVT Bluetooth Bus Service;c:\windows\system32\Drivers\IvtBtBus.sys [x]

S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys [x]

S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]

S3 ScreamBAudioSvc;ScreamBee Audio;c:\windows\system32\drivers\ScreamingBAudio64.sys [x]

S3 VCSVADHWSer;Avnex Virtual Audio Device (WDM);c:\windows\system32\DRIVERS\vcsvad.sys [x]

.

.

--- Other Services/Drivers In Memory ---

.

*Deregistered* - PROCEXP141

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]

hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

iissvcs REG_MULTI_SZ w3svc was

apphost REG_MULTI_SZ apphostsvc

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]

2009-06-17 17:11 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe

.

Contents of the 'Scheduled Tasks' folder

.

2011-11-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-27 12:40]

.

2011-11-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-27 12:40]

.

2011-11-06 c:\windows\Tasks\User_Feed_Synchronization-{5FE47A93-B92C-4E46-AFD8-FF5094CD66E8}.job

- c:\windows\system32\msfeedssync.exe [2011-06-16 04:32]

.

.

--------- x86-64 -----------

.

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 660360]

"RtHDVCpl"="RAVCpl64.exe" [2008-02-13 5684736]

"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdSync.exe" [2006-11-02 225792]

"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-19 170496]

"Seagate Scheduler2 Service"="c:\program files (x86)\Common Files\Seagate\Schedule2\schedhlp.exe" [2008-06-25 136472]

"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2011-10-20 9264456]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

"LoadAppInit_DLLs"=0x1

"AppInit_DLLs"=c:\windows\System32\guard64.dll

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.yahoo.com/

IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000

TCP: DhcpNameServer = 192.168.1.1

CLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\browseui.dll

FF - ProfilePath - c:\users\Tsiphon\AppData\Roaming\Mozilla\Firefox\Profiles\h8pjtgv2.default\

FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/

FF - prefs.js: keyword.URL - hxxp://dts.search-results.com/sr?src=ffb&appid=0&systemid=410&q=

FF - prefs.js: network.proxy.http - 127.0.0.1

FF - prefs.js: network.proxy.http_port - 53960

FF - prefs.js: network.proxy.type - 1

.

- - - - ORPHANS REMOVED - - - -

.

Toolbar-10 - (no file)

Notify-klogon - (no file)

Notify-WgaLogon - (no file)

AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe

.

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Solarwinds Trap Service]

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\SolarWinds: Collector DataProcessor]

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Solarwinds: Job Broker]

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Solarwinds: Job Engine]

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Solarwinds: Job Engine v2]

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Solarwinds: Job Scheduler]

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Solarwinds: Job Scheduler v2]

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Solarwinds: Worker Process]

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Solarwinds: Worker Process v2]

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\MEMSWEEP2]

"ImagePath"="\??\c:\windows\system32\B85.tmp"

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\X6va003]

"ImagePath"="\??\c:\users\Tsiphon\AppData\Local\Temp\003F29A.tmp"

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]

@Denied: (2) (LocalSystem)

"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,

d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,9c,a2,f1,d4,15,82,c2,48,99,43,46,\

"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,

d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,9c,a2,f1,d4,15,82,c2,48,99,43,46,\

.

[HKEY_USERS\S-1-5-21-4111605854-636613554-1496609690-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]

@Allowed: (Read) (RestrictedCode)

"??"=hex:b0,24,0d,0e,50,c2,6b,70,02,29,1d,b9,9b,f3,6b,2f,2b,5d,22,b8,72,f1,89,

77,30,39,6a,87,2c,80,fe,83,ab,a8,68,9b,31,cd,34,b5,2e,58,6d,51,6f,3c,e1,3f,\

"??"=hex:de,c2,f1,00,6b,13,52,1e,8d,7b,f0,04,df,b8,e0,7f

.

[HKEY_USERS\S-1-5-21-4111605854-636613554-1496609690-1000\Software\SecuROM\License information*]

"datasecu"=hex:fa,84,73,12,ef,d2,44,36,38,4d,80,39,fc,50,df,aa,cd,eb,4b,10,d6,

0d,5b,f9,da,79,e0,3f,89,9a,b4,3c,4a,db,10,1e,e8,20,fd,88,02,da,16,3a,7a,b7,\

"rkeysecu"=hex:d0,71,9f,d7,18,0a,c6,cb,3e,d1,09,7e,f3,81,c3,2a

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10b.exe,-101"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\LocalServer32]

@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10b.exe"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10b.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

@="0"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

@="ShockwaveFlash.ShockwaveFlash.10"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10b.ocx, 1"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="ShockwaveFlash.ShockwaveFlash"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10b.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

@="FlashFactory.FlashFactory.1"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10b.ocx, 1"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="FlashFactory.FlashFactory"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}]

@Denied: (A 2) (Everyone)

@="IFlashBroker2"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\ProxyStubClsid]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]

@Denied: (A 2) (Everyone)

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]

@="Shockwave Flash"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]

@Denied: (A 2) (Everyone)

@=""

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]

@="FlashBroker"

.

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows CE Services]

"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,

00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\

"CurrentPartnershipProtocol"=dword:00000003

"MinimumPartnershipProtocol"=dword:00000002

@=""

"EulaRequired"=dword:06010000

"DTPTNetworkType"="{0}"

"Dual-Home"=dword:00000001

"DisableCredentialSave"=dword:00000000

"RasTimeoutResponseWait"=dword:00000032

"RasTimeoutPause"=dword:00000005

"ConnectTypesAllowed"=dword:0000000a

"CheckPasswordTimeoutSeconds"=dword:00000014

"WaitV2TimeoutSeconds"=dword:00000004

"SerialPort"="Bluetooth"

"HasUsbDevice"=dword:00000000

"SerialBaudRate"=dword:0001c200

"DeviceType"=""

"DeviceOemInfo"=""

"DeviceVersion"=dword:04401504

"DeviceProcessorType"=dword:00000000

"DeviceProcessor"=""

"DisableIr"=dword:00000000

"GuestOnly"=dword:00000000

"MajorVersion"=dword:00000006

"MinorVersion"=dword:00000000

"InstalledDir"="c:\\Windows\\WindowsMobile"

.

[HKEY_LOCAL_MACHINE\software\Wow6432Node\Classes]

"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,

00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\

.

Completion time: 2011-11-06 14:01:36

ComboFix-quarantined-files.txt 2011-11-06 20:01

ComboFix2.txt 2011-10-31 18:34

.

Pre-Run: 26,910,330,880 bytes free

Post-Run: 26,859,597,824 bytes free

.

- - End Of File - - 0E7863022534C44BCFBF449286F1E456

Link to post
Share on other sites

.

DDS (Ver_2011-08-26.01) - NTFSAMD64

Internet Explorer: 8.0.6001.19088 BrowserJavaVersion: 1.6.0_29

Run by Tsiphon at 14:06:58 on 2011-11-06

Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1252.1.1033.18.4094.1925 [GMT -6:00]

.

AV: Kaspersky Anti-Virus *Disabled/Outdated* {56547CC9-C9B2-849D-8FEF-A496150D6A06}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

SP: Kaspersky Anti-Virus *Disabled/Updated* {ED359D2D-EF88-8B13-B55F-9FE46E8A20BB}

SP: COMODO Defense+ *Enabled/Updated* {CE351521-78FA-2048-BB22-B68A4A5CA7EC}

FW: COMODO Firewall *Enabled* {4D6F75E0-14AF-2E9E-AACD-24CDCF08AA2A}

.

============== Running Processes ===============

.

C:\Windows\system32\wininit.exe

C:\Windows\system32\lsm.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\nvvsvc.exe

C:\Windows\system32\svchost.exe -k rpcss

C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe

C:\Windows\system32\svchost.exe -k NetworkService

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k netsvcs

C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe

C:\Windows\system32\svchost.exe -k GPSvcGroup

C:\Windows\system32\SLsvc.exe

C:\Windows\system32\svchost.exe -k LocalService

C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe

C:\Windows\system32\nvvsvc.exe

C:\Windows\System32\spoolsv.exe

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

C:\Windows\system32\svchost.exe -k apphost

C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\Windows\system32\mqsvc.exe

C:\Windows\System32\svchost.exe -k HPZ12

C:\Windows\System32\svchost.exe -k HPZ12

C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedul2.exe

C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

C:\Windows\system32\svchost.exe -k imgsvc

C:\Program Files\Tablet\Pen\Pen_Tablet.exe

C:\Windows\system32\svchost.exe -k iissvcs

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

C:\Windows\system32\SearchIndexer.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Windows\system32\taskeng.exe

C:\Program Files\Tablet\Pen\Pen_TabletUser.exe

C:\Program Files\Tablet\Pen\Pen_Tablet.exe

C:\Windows\WindowsMobile\wmdc.exe

C:\Windows\RAVCpl64.exe

C:\Windows\ehome\ehtray.exe

C:\Windows\system32\wbem\unsecapp.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Program Files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe

C:\Program Files (x86)\Seagate\DiscWizard\TimounterMonitor.exe

C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedhlp.exe

C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

C:\Windows\ehome\ehmsas.exe

C:\Windows\system32\svchost.exe -k WindowsMobile

C:\Program Files\Windows Media Player\wmpnetwk.exe

C:\Windows\system32\conime.exe

C:\Windows\System32\osk.exe

C:\Windows\SysWoW64\svchost.exe

C:\Windows\system32\taskeng.exe

C:\Windows\SysWOW64\cmd.exe

C:\Windows\SysWOW64\cscript.exe

C:\Windows\system32\wbem\wmiprvse.exe

.

============== Pseudo HJT Report ===============

.

uStart Page = hxxp://www.yahoo.com/

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll

BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\ievkbd.dll

BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll

BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll

uRun: [ehTray.exe] C:\Windows\ehome\ehTray.exe

mRun: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe

mRun: [DiscWizardMonitor.exe] C:\Program Files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe

mRun: [AcronisTimounterMonitor] C:\Program Files (x86)\Seagate\DiscWizard\TimounterMonitor.exe

mRun: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe"

mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime Alternative\QTTask.exe" -atboottime

mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray

mRun: [WinPatrol] "C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe" -expressboot

mRun: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

dRun: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden

mPolicies-system: EnableLUA = 0 (0x0)

mPolicies-system: EnableUIADesktopToggle = 0 (0x0)

mPolicies-system: EnableLinkedConnections = 1 (0x1)

IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000

IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll

IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll

IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll

IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL

IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll

IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll

DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab

DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab

DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab

DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://l.yimg.com/jh/games/web_games/popcap/bejeweled2/popcaploader_v6.cab

DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://www.creative.com/softwareupdate/su2/ocx/15103/CTPID.cab

TCP: DhcpNameServer = 192.168.1.1

TCP: Interfaces\{B2707B3A-F1B2-4360-8B02-F14850833270} : DhcpNameServer = 192.168.1.1

Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll

AppInit_DLLs: C:\PROGRA~2\KASPER~1\KASPER~2\mzvkbd3.dll C:\Windows\SysWOW64\guard32.dll

SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll

mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"

BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

BHO-X64: AcroIEHelperStub - No File

BHO-X64: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll

BHO-X64: IEVkbdBHO Class: {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\ievkbd.dll

BHO-X64: IEVkbdBHO - No File

BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll

BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

BHO-X64: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

BHO-X64: FilterBHO Class: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll

BHO-X64: link filter bho - No File

mRun-x64: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe

mRun-x64: [DiscWizardMonitor.exe] C:\Program Files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe

mRun-x64: [AcronisTimounterMonitor] C:\Program Files (x86)\Seagate\DiscWizard\TimounterMonitor.exe

mRun-x64: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe"

mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime Alternative\QTTask.exe" -atboottime

mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray

mRun-x64: [WinPatrol] "C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe" -expressboot

mRun-x64: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

AppInit_DLLs-X64: C:\PROGRA~2\KASPER~1\KASPER~2\mzvkbd3.dll C:\Windows\SysWOW64\guard32.dll

SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll

.

================= FIREFOX ===================

.

FF - ProfilePath - C:\Users\Tsiphon\AppData\Roaming\Mozilla\Firefox\Profiles\h8pjtgv2.default\

FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/

FF - prefs.js: keyword.URL - hxxp://dts.search-results.com/sr?src=ffb&appid=0&systemid=410&q=

FF - prefs.js: network.proxy.http - 127.0.0.1

FF - prefs.js: network.proxy.http_port - 53960

FF - prefs.js: network.proxy.type - 1

.

============= SERVICES / DRIVERS ===============

.

R0 BtHidBus;Bluetooth HID Bus Service;C:\Windows\system32\Drivers\BtHidBus.sys --> C:\Windows\system32\Drivers\BtHidBus.sys [?]

R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys --> C:\Windows\system32\Drivers\PxHlpa64.sys [?]

R1 cmdGuard;COMODO Internet Security Sandbox Driver;C:\Windows\system32\DRIVERS\cmdguard.sys --> C:\Windows\system32\DRIVERS\cmdguard.sys [?]

R1 cmdHlp;COMODO Internet Security Helper Driver;C:\Windows\system32\DRIVERS\cmdhlp.sys --> C:\Windows\system32\DRIVERS\cmdhlp.sys [?]

R1 kl2;kl2;C:\Windows\system32\DRIVERS\kl2.sys --> C:\Windows\system32\DRIVERS\kl2.sys [?]

R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\system32\DRIVERS\klim6.sys --> C:\Windows\system32\DRIVERS\klim6.sys [?]

R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-6-6 64952]

R2 cpuz135;cpuz135;\??\C:\Windows\system32\drivers\cpuz135_x64.sys --> C:\Windows\system32\drivers\cpuz135_x64.sys [?]

R2 SgtSch2Svc;Seagate Scheduler2 Service;C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedul2.exe [2008-6-24 605464]

R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-10-16 369256]

R2 TabletServicePen;TabletServicePen;C:\Program Files\Tablet\Pen\Pen_Tablet.exe [2011-5-25 5790064]

R3 btnetBUs;Bluetooth PAN Bus Service;C:\Windows\system32\Drivers\btnetBus.sys --> C:\Windows\system32\Drivers\btnetBus.sys [?]

R3 CT20XUT.SYS;CT20XUT.SYS;C:\Windows\system32\drivers\CT20XUT.SYS --> C:\Windows\system32\drivers\CT20XUT.SYS [?]

R3 CTEXFIFX.SYS;CTEXFIFX.SYS;C:\Windows\system32\drivers\CTEXFIFX.SYS --> C:\Windows\system32\drivers\CTEXFIFX.SYS [?]

R3 CTHWIUT.SYS;CTHWIUT.SYS;C:\Windows\system32\drivers\CTHWIUT.SYS --> C:\Windows\system32\drivers\CTHWIUT.SYS [?]

R3 IvtBtBUs;IVT Bluetooth Bus Service;C:\Windows\system32\Drivers\IvtBtBus.sys --> C:\Windows\system32\Drivers\IvtBtBus.sys [?]

R3 klmouflt;Kaspersky Lab KLMOUFLT;C:\Windows\system32\DRIVERS\klmouflt.sys --> C:\Windows\system32\DRIVERS\klmouflt.sys [?]

R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]

R3 ScreamBAudioSvc;ScreamBee Audio;C:\Windows\system32\drivers\ScreamingBAudio64.sys --> C:\Windows\system32\drivers\ScreamingBAudio64.sys [?]

R3 VCSVADHWSer;Avnex Virtual Audio Device (WDM);C:\Windows\system32\DRIVERS\vcsvad.sys --> C:\Windows\system32\DRIVERS\vcsvad.sys [?]

S2 AVP;Kaspersky Anti-Virus Service;C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe [2010-7-1 352976]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]

S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]

S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-1-27 135664]

S2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-10-26 366152]

S2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2010-5-4 1153368]

S3 AdobeActiveFileMonitor8.0;Adobe Active File Monitor V8;C:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe [2009-10-9 169312]

S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2008-8-6 79360]

S3 CT20XUT;CT20XUT;C:\Windows\system32\drivers\CT20XUT.SYS --> C:\Windows\system32\drivers\CT20XUT.SYS [?]

S3 CTEXFIFX;CTEXFIFX;C:\Windows\system32\drivers\CTEXFIFX.SYS --> C:\Windows\system32\drivers\CTEXFIFX.SYS [?]

S3 CTHWIUT;CTHWIUT;C:\Windows\system32\drivers\CTHWIUT.SYS --> C:\Windows\system32\drivers\CTHWIUT.SYS [?]

S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-1-27 135664]

S3 MEMSWEEP2;MEMSWEEP2;\??\C:\Windows\system32\B85.tmp --> C:\Windows\system32\B85.tmp [?]

S3 PerfHost;Performance Counter DLL Host;C:\Windows\SysWOW64\perfhost.exe [2008-7-22 19968]

S3 PSSDK42;PSSDK42;\??\C:\Windows\system32\Drivers\pssdk42.sys --> C:\Windows\system32\Drivers\pssdk42.sys [?]

S3 RivaTuner64;RivaTuner64;C:\Program Files (x86)\RivaTuner v2.09\RivaTuner64.sys [2008-4-28 19952]

S3 scramby_out;Scramby Output;C:\Windows\system32\drivers\scramby_out.sys --> C:\Windows\system32\drivers\scramby_out.sys [?]

S3 TouchServicePen;Wacom Consumer Touch Service;C:\Program Files\Tablet\Pen\Pen_TouchService.exe [2011-5-25 487280]

S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]

S3 wacmoumonitor;Wacom Mode Helper;C:\Windows\system32\DRIVERS\wacmoumonitor.sys --> C:\Windows\system32\DRIVERS\wacmoumonitor.sys [?]

S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-3-18 1020768]

S4 BsMobileCS;BsMobileCS;C:\Program Files (x86)\IVT Corporation\BlueSoleil\BsMobileCS.exe [2010-3-9 143467]

S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2009-3-24 93184]

S4 MSSQL$SOLARWINDS_ORION;SQL Server (SOLARWINDS_ORION); [x]

S4 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe [2010-3-25 490280]

S4 TomTomHOMEService;TomTomHOMEService;C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe [2009-11-13 92008]

.

=============== File Associations ===============

.

JSEFile=C:\Windows\SysWOW64\WScript.exe "%1" %*

.

=============== Created Last 30 ================

.

2011-11-06 19:03:56 98816 ----a-w- C:\Windows\sed.exe

2011-11-06 19:03:56 518144 ----a-w- C:\Windows\SWREG.exe

2011-11-06 19:03:56 256000 ----a-w- C:\Windows\PEV.exe

2011-11-06 19:03:56 208896 ----a-w- C:\Windows\MBR.exe

2011-11-02 23:46:30 6144 ------w- C:\Windows\System32\B85.tmp

2011-11-02 23:40:23 6144 ------w- C:\Windows\System32\7213.tmp

2011-11-02 23:30:25 6144 ------w- C:\Windows\System32\5060.tmp

2011-11-02 23:22:41 6144 ------w- C:\Windows\System32\1AC0.tmp

2011-11-02 23:16:36 6144 ------w- C:\Windows\System32\88FD.tmp

2011-11-02 23:11:45 6144 ------w- C:\Windows\System32\1821.tmp

2011-11-02 23:11:14 -------- d-----w- C:\Program Files (x86)\Sophos

2011-11-01 18:56:45 388096 ----a-r- C:\Users\Tsiphon\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe

2011-10-31 07:06:56 0 ----a-w- C:\Windows\SysWow64\drivers\SET88DE.tmp

2011-10-31 07:06:45 0 ----a-w- C:\Windows\SysWow64\drivers\SET5C67.tmp

2011-10-31 07:06:44 0 ----a-w- C:\Windows\SysWow64\drivers\SET5AA1.tmp

2011-10-31 07:06:44 0 ----a-w- C:\Windows\SysWow64\drivers\SET584F.tmp

2011-10-31 07:06:23 0 ----a-w- C:\Windows\SysWow64\drivers\SET771.tmp

2011-10-31 07:06:22 0 ----a-w- C:\Windows\SysWow64\drivers\SET4E1.tmp

2011-10-31 07:06:07 309320 ----a-w- C:\Windows\SysWow64\drivers\TrufosAlt.sys

2011-10-31 07:06:07 0 ----a-w- C:\Windows\SysWow64\drivers\SETC86D.tmp

2011-10-31 07:05:21 0 ----a-w- C:\Windows\SysWow64\drivers\SET1747.tmp

2011-10-31 07:04:26 0 ----a-w- C:\Windows\SysWow64\drivers\SET3E2B.tmp

2011-10-31 07:04:25 0 ----a-w- C:\Windows\SysWow64\drivers\SET3C94.tmp

2011-10-31 07:04:25 0 ----a-w- C:\Windows\SysWow64\drivers\SET39E5.tmp

2011-10-31 07:04:23 0 ----a-w- C:\Windows\SysWow64\drivers\SET334F.tmp

2011-10-31 07:04:00 0 ----a-w- C:\Windows\SysWow64\drivers\SETDA09.tmp

2011-10-31 07:03:22 0 ----a-w- C:\Windows\SysWow64\drivers\SET432B.tmp

2011-10-31 07:03:21 0 ----a-w- C:\Windows\SysWow64\drivers\SET400F.tmp

2011-10-31 07:02:46 0 ----a-w- C:\Windows\SysWow64\drivers\SETB971.tmp

2011-10-31 07:02:46 0 ----a-w- C:\Windows\SysWow64\drivers\SETB6A2.tmp

2011-10-31 07:02:44 0 ----a-w- C:\Windows\SysWow64\drivers\SETAFBE.tmp

2011-10-31 06:58:23 0 ----a-w- C:\Windows\SysWow64\drivers\SETB450.tmp

2011-10-31 04:21:13 -------- d-----w- C:\Users\Tsiphon\AppData\Roaming\WinPatrol

2011-10-31 04:21:03 -------- d-----w- C:\ProgramData\InstallMate

2011-10-31 04:21:03 -------- d-----w- C:\Program Files (x86)\BillP Studios

2011-10-31 04:18:21 -------- d-----w- C:\ProgramData\Comodo

2011-10-31 04:18:17 -------- d-----w- C:\Program Files\COMODO

2011-10-31 04:17:25 -------- d-----w- C:\ProgramData\Comodo Downloader

2011-10-28 22:54:51 -------- d-----w- C:\Program Files (x86)\Eusing Free Registry Cleaner

2011-10-26 21:59:25 -------- d-----w- C:\Users\Tsiphon\AppData\Roaming\Malwarebytes

2011-10-26 21:59:20 -------- d-----w- C:\ProgramData\Malwarebytes

2011-10-26 21:59:16 25416 ----a-w- C:\Windows\System32\drivers\mbam.sys

2011-10-26 21:59:16 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware

2011-10-26 21:56:52 -------- d-----w- C:\Users\Tsiphon\AppData\Roaming\WTablet

2011-10-21 14:14:24 8570192 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FDC2EED1-71B5-48C1-ADD4-7D759D933147}\mpengine.dll

2011-10-13 22:18:09 -------- d-----w- C:\Program Files\iPod

2011-10-13 22:18:07 -------- d-----w- C:\Program Files\iTunes

2011-10-10 00:12:07 21992 ----a-w- C:\Windows\System32\drivers\cpuz135_x64.sys

2011-10-10 00:12:07 -------- d-----w- C:\Program Files\CPUID

2011-10-07 23:47:50 42224 ----a-w- C:\Windows\System32\drivers\cmdhlp.sys

2011-10-07 23:47:48 574216 ----a-w- C:\Windows\System32\drivers\cmdGuard.sys

2011-10-07 23:47:48 16528 ----a-w- C:\Windows\System32\drivers\cmderd.sys

2011-10-07 23:47:14 41200 ----a-w- C:\Windows\System32\cmdcsr.dll

2011-10-07 23:47:12 300200 ----a-w- C:\Windows\SysWow64\guard32.dll

2011-10-07 23:47:10 388280 ----a-w- C:\Windows\System32\guard64.dll

.

==================== Find3M ====================

.

2011-10-12 05:59:28 414368 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl

2011-10-03 10:06:03 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll

2011-08-31 04:05:32 96104 ----a-w- C:\Windows\System32\dns-sd.exe

2011-08-31 04:05:32 85864 ----a-w- C:\Windows\System32\dnssd.dll

2011-08-31 04:05:04 83816 ----a-w- C:\Windows\SysWow64\dns-sd.exe

2011-08-31 04:05:04 73064 ----a-w- C:\Windows\SysWow64\dnssd.dll

.

============= FINISH: 14:08:05.75 ===============

Attach.txt

Link to post
Share on other sites

Hi again,

Open notepad and copy/paste the text in the quotebox below into it:


Firefox::
FF - ProfilePath - c:\users\Tsiphon\AppData\Roaming\Mozilla\Firefox\Profiles\h8pjtgv2.default\
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 53960
FF - prefs.js: network.proxy.type - 1

Save this as

CFScript

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine. This tool is not a toy and not for everyday use.

CFScriptB-4.gif

Close all browser windows and refering to the picture above, drag CFScript into ComboFix.exe (let the tool to update itself if prompted).

Then post the resultant log.

Uninstall vulnerable Flash versions by following instructions here. Fresh version can be obtained here.

Uninstall these old Javas:

Java 6 Update 4

Java 6 Update 7

* Go here to run an online scanner from ESET.

  • Note: You will need to use Internet explorer for this scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is UNchecked and the option Scan unwanted applications is checkmarked.
  • Click Scan
  • Wait for the scan to finish.

Post back its report, a fresh dds.txt log and above mentioned ComboFix resultant log. How's the system running?

Link to post
Share on other sites

Here's the logs, I think I created them before uninstalling java and flash, and definitely before reinstalling them.

My flash installation hung at 100% Finish because it tries to load the "Congradulations you now have flash" webpage, and my firefox was refusing to open still. I am still getting Malwarebytes alerts for potentially malicious website IPs from svchost.exe and firefox.exe (if I try to open it).

A side note, I remember that I had the Windows Feature SNMP (WMI provider host) enabled, as I was trying to monitor network bandwidth usage. I'm in the middle of turning that feature off, as I don't wish to monitor activity anymore, and because there's no reason for it to be running. (That's where the SolarWind orphans come from).

So, no differerence yet. Firefox is still not visible, and the SVCHOST is still trying to ping sites. Looking now there are 3 major culprits, being a svchost running the extra command line -k LocalService, which is using FDResPub, W32Time, and SSDPSRV to ping weird ports. (if that matters)

ComboFix 11-11-06.02 - Tsiphon 11/07/2011 21:00:45.4.4 - x64

Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1252.1.1033.18.4094.1532 [GMT -6:00]

Running from: c:\users\Tsiphon\Desktop\ComboFix.exe

Command switches used :: c:\users\Tsiphon\Desktop\CFScript.txt

AV: Kaspersky Anti-Virus *Disabled/Outdated* {56547CC9-C9B2-849D-8FEF-A496150D6A06}

FW: COMODO Firewall *Enabled* {4D6F75E0-14AF-2E9E-AACD-24CDCF08AA2A}

SP: COMODO Defense+ *Enabled/Updated* {CE351521-78FA-2048-BB22-B68A4A5CA7EC}

SP: Kaspersky Anti-Virus *Disabled/Updated* {ED359D2D-EF88-8B13-B55F-9FE46E8A20BB}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

* Created a new restore point

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\windows\SysWow64\kernel32.dll . . . is infected!!

.

.

((((((((((((((((((((((((( Files Created from 2011-10-08 to 2011-11-08 )))))))))))))))))))))))))))))))

.

.

2011-11-08 03:29 . 2011-11-08 03:29 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\temp

2011-11-08 03:29 . 2011-11-08 03:29 -------- d-----w- c:\users\Mcx1\AppData\Local\temp

2011-11-08 03:29 . 2011-11-08 03:29 -------- d-----w- c:\users\Guest\AppData\Local\temp

2011-11-08 03:29 . 2011-11-08 03:29 -------- d-----w- c:\users\Default\AppData\Local\temp

2011-11-02 23:46 . 2011-05-12 19:03 6144 ------w- c:\windows\system32\B85.tmp

2011-11-02 23:40 . 2011-05-12 19:03 6144 ------w- c:\windows\system32\7213.tmp

2011-11-02 23:30 . 2011-05-12 19:03 6144 ------w- c:\windows\system32\5060.tmp

2011-11-02 23:22 . 2011-05-12 19:03 6144 ------w- c:\windows\system32\1AC0.tmp

2011-11-02 23:16 . 2011-05-12 19:03 6144 ------w- c:\windows\system32\88FD.tmp

2011-11-02 23:11 . 2011-05-12 19:03 6144 ------w- c:\windows\system32\1821.tmp

2011-11-02 23:11 . 2011-11-02 23:11 -------- d-----w- c:\program files (x86)\Sophos

2011-11-01 18:56 . 2011-11-01 18:56 388096 ----a-r- c:\users\Tsiphon\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe

2011-10-31 07:06 . 2011-10-31 07:06 0 ----a-w- c:\windows\SysWow64\drivers\SET88DE.tmp

2011-10-31 07:06 . 2011-10-31 07:06 0 ----a-w- c:\windows\SysWow64\drivers\SET5C67.tmp

2011-10-31 07:06 . 2011-10-31 07:06 0 ----a-w- c:\windows\SysWow64\drivers\SET5AA1.tmp

2011-10-31 07:06 . 2011-10-31 07:06 0 ----a-w- c:\windows\SysWow64\drivers\SET584F.tmp

2011-10-31 07:06 . 2011-10-31 07:06 0 ----a-w- c:\windows\SysWow64\drivers\SET771.tmp

2011-10-31 07:06 . 2011-10-31 07:06 0 ----a-w- c:\windows\SysWow64\drivers\SET4E1.tmp

2011-10-31 07:06 . 2011-10-31 07:07 309320 ----a-w- c:\windows\SysWow64\drivers\TrufosAlt.sys

2011-10-31 07:06 . 2011-10-31 07:06 0 ----a-w- c:\windows\SysWow64\drivers\SETC86D.tmp

2011-10-31 07:05 . 2011-10-31 07:05 0 ----a-w- c:\windows\SysWow64\drivers\SET1747.tmp

2011-10-31 07:04 . 2011-10-31 07:04 0 ----a-w- c:\windows\SysWow64\drivers\SET3E2B.tmp

2011-10-31 07:04 . 2011-10-31 07:04 0 ----a-w- c:\windows\SysWow64\drivers\SET3C94.tmp

2011-10-31 07:04 . 2011-10-31 07:04 0 ----a-w- c:\windows\SysWow64\drivers\SET39E5.tmp

2011-10-31 07:04 . 2011-10-31 07:04 0 ----a-w- c:\windows\SysWow64\drivers\SET334F.tmp

2011-10-31 07:04 . 2011-10-31 07:04 0 ----a-w- c:\windows\SysWow64\drivers\SETDA09.tmp

2011-10-31 07:03 . 2011-10-31 07:03 0 ----a-w- c:\windows\SysWow64\drivers\SET432B.tmp

2011-10-31 07:03 . 2011-10-31 07:03 0 ----a-w- c:\windows\SysWow64\drivers\SET400F.tmp

2011-10-31 07:02 . 2011-10-31 07:02 0 ----a-w- c:\windows\SysWow64\drivers\SETB971.tmp

2011-10-31 07:02 . 2011-10-31 07:02 0 ----a-w- c:\windows\SysWow64\drivers\SETB6A2.tmp

2011-10-31 07:02 . 2011-10-31 07:02 0 ----a-w- c:\windows\SysWow64\drivers\SETAFBE.tmp

2011-10-31 06:58 . 2011-10-31 06:58 0 ----a-w- c:\windows\SysWow64\drivers\SETB450.tmp

2011-10-31 04:21 . 2011-10-31 04:21 -------- d-----w- c:\users\Tsiphon\AppData\Roaming\WinPatrol

2011-10-31 04:21 . 2011-10-31 04:21 -------- d-----w- c:\programdata\InstallMate

2011-10-31 04:21 . 2011-10-31 04:21 -------- d-----w- c:\program files (x86)\BillP Studios

2011-10-31 04:18 . 2011-11-02 08:48 -------- d-----w- c:\programdata\Comodo

2011-10-31 04:18 . 2011-10-31 04:18 -------- d-----w- c:\program files\COMODO

2011-10-31 04:17 . 2011-10-31 04:18 -------- d-----w- c:\programdata\Comodo Downloader

2011-10-29 08:24 . 2011-10-29 10:15 -------- d-----w- c:\users\Tsiphon\AppData\Roaming\Winamp

2011-10-28 22:54 . 2011-10-28 23:09 -------- d-----w- c:\program files (x86)\Eusing Free Registry Cleaner

2011-10-26 21:59 . 2011-10-26 21:59 -------- d-----w- c:\users\Tsiphon\AppData\Roaming\Malwarebytes

2011-10-26 21:59 . 2011-10-26 21:59 -------- d-----w- c:\programdata\Malwarebytes

2011-10-26 21:59 . 2011-10-27 02:50 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware

2011-10-26 21:59 . 2011-08-31 22:00 25416 ----a-w- c:\windows\system32\drivers\mbam.sys

2011-10-26 21:56 . 2011-10-26 21:56 -------- d-----w- c:\users\Tsiphon\AppData\Roaming\WTablet

2011-10-21 14:14 . 2011-10-07 04:16 8570192 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{FDC2EED1-71B5-48C1-ADD4-7D759D933147}\mpengine.dll

2011-10-13 22:18 . 2011-10-13 22:18 -------- d-----w- c:\program files\iPod

2011-10-13 22:18 . 2011-10-13 22:19 -------- d-----w- c:\program files\iTunes

2011-10-10 00:12 . 2011-10-10 00:12 -------- d-----w- c:\program files\CPUID

2011-10-10 00:12 . 2010-11-09 20:35 21992 ----a-w- c:\windows\system32\drivers\cpuz135_x64.sys

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2011-10-12 05:59 . 2011-05-28 03:51 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2011-10-07 23:47 . 2011-10-07 23:47 93200 ----a-w- c:\windows\system32\drivers\inspect.sys

2011-10-07 23:47 . 2011-10-07 23:47 42224 ----a-w- c:\windows\system32\drivers\cmdhlp.sys

2011-10-07 23:47 . 2011-10-07 23:47 574216 ----a-w- c:\windows\system32\drivers\cmdGuard.sys

2011-10-07 23:47 . 2011-10-07 23:47 16528 ----a-w- c:\windows\system32\drivers\cmderd.sys

2011-10-07 23:47 . 2011-10-07 23:47 41200 ----a-w- c:\windows\system32\cmdcsr.dll

2011-10-07 23:47 . 2011-10-07 23:47 300200 ----a-w- c:\windows\SysWow64\guard32.dll

2011-10-07 23:47 . 2011-10-07 23:47 388280 ----a-w- c:\windows\system32\guard64.dll

2011-10-03 10:06 . 2010-04-30 21:21 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll

2011-08-31 04:05 . 2011-08-31 04:05 96104 ----a-w- c:\windows\system32\dns-sd.exe

2011-08-31 04:05 . 2011-08-31 04:05 85864 ----a-w- c:\windows\system32\dnssd.dll

2011-08-31 04:05 . 2011-08-31 04:05 83816 ----a-w- c:\windows\SysWow64\dns-sd.exe

2011-08-31 04:05 . 2011-08-31 04:05 73064 ----a-w- c:\windows\SysWow64\dnssd.dll

.

.

------- Sigcheck -------

Note: Unsigned files aren't necessarily malware.

.

[7] 2008-07-19 . 437C1C0CB2A42EA20083F21E9CAEF461 . 646656 . . [6.0.6000.20537] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.20537_none_32359eb27623cc22\user32.dll

[7] 2008-07-19 . 296BA70E2A302E639CBD9E2A32DC65C4 . 646656 . . [6.0.6000.16438] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.16438_none_31ad02315d0545af\user32.dll

[-] 2008-01-19 . BC8872C0B1B4599D60857B9E6BB66E44 . 672256 . . [6.0.6001.18000] .. c:\windows\SysWOW64\user32.dll

[7] 2008-01-19 . 3D691030DBD3BD75DE1501BE54F0D425 . 648192 . . [6.0.6001.18000] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_33abb2175a1ab263\user32.dll

[7] 2006-11-02 . 00B53DCA0408CCD8F6BAF13994F6E3A0 . 646656 . . [6.0.6000.16386] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.16386_none_3174f01b5d2fa18f\user32.dll

.

((((((((((((((((((((((((((((( SnapShot@2011-11-06_19.43.21 )))))))))))))))))))))))))))))))))))))))))

.

+ 2008-07-19 06:58 . 2011-11-06 23:06 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2008-07-19 06:58 . 2011-11-06 00:38 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2008-07-19 06:58 . 2011-11-06 00:38 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

+ 2008-07-19 06:58 . 2011-11-06 23:06 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

+ 2008-07-19 06:58 . 2011-11-06 23:06 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

- 2008-07-19 06:58 . 2011-11-06 00:38 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2010-09-28 04:39 . 2011-11-06 23:06 16384 c:\windows\system32\%APPDATA%\Microsoft\Windows\IETldCache\index.dat

- 2010-09-28 04:39 . 2011-11-04 04:57 16384 c:\windows\system32\%APPDATA%\Microsoft\Windows\IETldCache\index.dat

+ 2009-01-17 21:40 . 2011-11-07 15:49 760208 c:\windows\system32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 138240]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"AppleSyncNotifier"="c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-09-27 59240]

"DiscWizardMonitor.exe"="c:\program files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe" [2008-06-25 1325848]

"AcronisTimounterMonitor"="c:\program files (x86)\Seagate\DiscWizard\TimounterMonitor.exe" [2008-06-25 904768]

"AVP"="c:\program files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe" [2011-05-27 352976]

"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]

"QuickTime Task"="c:\program files (x86)\QuickTime Alternative\QTTask.exe" [2011-07-05 421888]

"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]

"WinPatrol"="c:\program files (x86)\BillP Studios\WinPatrol\winpatrol.exe" [2011-05-15 325512]

"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]

.

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"LightScribe Control Panel"="c:\program files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe" [2009-06-17 2363392]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"EnableLUA"= 0 (0x0)

"EnableUIADesktopToggle"= 0 (0x0)

"EnableLinkedConnections"= 1 (0x1)

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\klogon]

[bU]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WgaLogon]

[bU]

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]

"AppInit_DLLs"=c:\progra~2\KASPER~1\KASPER~2\mzvkbd3.dll c:\windows\SysWOW64\guard32.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]

"aux8"=wdmaud.drv

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]

"LogitechQuickCamRibbon"="c:\program files (x86)\Logitech\QuickCam\Quickcam.exe" /hide

"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe"

"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]

"DisableMonitoring"=dword:00000001

.

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]

R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-27 135664]

R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-08-31 366152]

R2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]

R3 AdobeActiveFileMonitor8.0;Adobe Active File Monitor V8;c:\program files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe [2009-10-09 169312]

R3 CamDrL64;Logitech QuickCam Pro 3000(PID_08B0); [x]

R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2008-08-06 79360]

R3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.SYS [x]

R3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.SYS [x]

R3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.SYS [x]

R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-27 135664]

R3 LVcKap64;Logitech AEC Driver; [x]

R3 LVPr2M64;Logitech LVPr2M64 Driver; [x]

R3 LVUSBS64;Logitech USB Monitor Filter; [x]

R3 MEMSWEEP2;MEMSWEEP2;c:\windows\system32\B85.tmp [x]

R3 PSSDK42;PSSDK42;c:\windows\system32\Drivers\pssdk42.sys [x]

R3 RivaTuner64;RivaTuner64;c:\program files (x86)\RivaTuner v2.09\RivaTuner64.sys [2008-07-19 19952]

R3 rt61x64;Ralink RT61 Wireless Driver for Windows Vista; [x]

R3 scramby_out;Scramby Output;c:\windows\system32\drivers\scramby_out.sys [x]

R3 TouchServicePen;Wacom Consumer Touch Service;c:\program files\Tablet\Pen\Pen_TouchService.exe [2010-10-13 487280]

R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]

R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\DRIVERS\wacmoumonitor.sys [x]

R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 1020768]

R3 X6va003;X6va003;c:\users\Tsiphon\AppData\Local\Temp\003F29A.tmp [x]

R4 BsMobileCS;BsMobileCS;c:\program files (x86)\IVT Corporation\BlueSoleil\BsMobileCS.exe [2010-03-09 143467]

R4 MSSQL$SOLARWINDS_ORION;SQL Server (SOLARWINDS_ORION); [x]

R4 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2010-03-25 490280]

R4 TomTomHOMEService;TomTomHOMEService;c:\program files (x86)\TomTom HOME 2\TomTomHOMEService.exe [2009-11-13 92008]

S0 BtHidBus;Bluetooth HID Bus Service;c:\windows\System32\Drivers\BtHidBus.sys [x]

S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]

S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [x]

S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [x]

S1 kl2;kl2;c:\windows\system32\DRIVERS\kl2.sys [x]

S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [x]

S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]

S2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x64.sys [x]

S2 SgtSch2Svc;Seagate Scheduler2 Service;c:\program files (x86)\Common Files\Seagate\Schedule2\schedul2.exe [2008-06-25 605464]

S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-10-16 369256]

S2 TabletServicePen;TabletServicePen;c:\program files\Tablet\Pen\Pen_Tablet.exe [2010-10-13 5790064]

S3 btnetBUs;Bluetooth PAN Bus Service;c:\windows\system32\Drivers\btnetBus.sys [x]

S3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\System32\drivers\CT20XUT.SYS [x]

S3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\System32\drivers\CTEXFIFX.SYS [x]

S3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\System32\drivers\CTHWIUT.SYS [x]

S3 IvtBtBUs;IVT Bluetooth Bus Service;c:\windows\system32\Drivers\IvtBtBus.sys [x]

S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys [x]

S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]

S3 ScreamBAudioSvc;ScreamBee Audio;c:\windows\system32\drivers\ScreamingBAudio64.sys [x]

S3 VCSVADHWSer;Avnex Virtual Audio Device (WDM);c:\windows\system32\DRIVERS\vcsvad.sys [x]

.

.

--- Other Services/Drivers In Memory ---

.

*Deregistered* - PROCEXP141

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]

hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

iissvcs REG_MULTI_SZ w3svc was

apphost REG_MULTI_SZ apphostsvc

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]

2009-06-17 17:11 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe

.

Contents of the 'Scheduled Tasks' folder

.

2011-11-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-27 12:40]

.

2011-11-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-27 12:40]

.

2011-11-08 c:\windows\Tasks\User_Feed_Synchronization-{5FE47A93-B92C-4E46-AFD8-FF5094CD66E8}.job

- c:\windows\system32\msfeedssync.exe [2011-06-16 04:32]

.

.

--------- x86-64 -----------

.

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 660360]

"RtHDVCpl"="RAVCpl64.exe" [2008-02-13 5684736]

"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdSync.exe" [2006-11-02 225792]

"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-19 170496]

"Seagate Scheduler2 Service"="c:\program files (x86)\Common Files\Seagate\Schedule2\schedhlp.exe" [2008-06-25 136472]

"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2011-10-20 9264456]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

"AppInit_DLLs"=c:\windows\System32\guard64.dll

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.yahoo.com/

IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000

TCP: DhcpNameServer = 192.168.1.1

CLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\browseui.dll

FF - ProfilePath - c:\users\Tsiphon\AppData\Roaming\Mozilla\Firefox\Profiles\h8pjtgv2.default\

FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/

FF - prefs.js: keyword.URL - hxxp://dts.search-results.com/sr?src=ffb&appid=0&systemid=410&q=

.

- - - - ORPHANS REMOVED - - - -

.

Toolbar-10 - (no file)

.

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Solarwinds Trap Service]

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\SolarWinds: Collector DataProcessor]

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Solarwinds: Job Broker]

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Solarwinds: Job Engine]

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Solarwinds: Job Engine v2]

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Solarwinds: Job Scheduler]

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Solarwinds: Job Scheduler v2]

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Solarwinds: Worker Process]

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Solarwinds: Worker Process v2]

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\MEMSWEEP2]

"ImagePath"="\??\c:\windows\system32\B85.tmp"

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\X6va003]

"ImagePath"="\??\c:\users\Tsiphon\AppData\Local\Temp\003F29A.tmp"

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]

@Denied: (2) (LocalSystem)

"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,

d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,9c,a2,f1,d4,15,82,c2,48,99,43,46,\

"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,

d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,9c,a2,f1,d4,15,82,c2,48,99,43,46,\

.

[HKEY_USERS\S-1-5-21-4111605854-636613554-1496609690-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]

@Allowed: (Read) (RestrictedCode)

"??"=hex:b0,24,0d,0e,50,c2,6b,70,02,29,1d,b9,9b,f3,6b,2f,2b,5d,22,b8,72,f1,89,

77,30,39,6a,87,2c,80,fe,83,ab,a8,68,9b,31,cd,34,b5,2e,58,6d,51,6f,3c,e1,3f,\

"??"=hex:de,c2,f1,00,6b,13,52,1e,8d,7b,f0,04,df,b8,e0,7f

.

[HKEY_USERS\S-1-5-21-4111605854-636613554-1496609690-1000\Software\SecuROM\License information*]

"datasecu"=hex:fa,84,73,12,ef,d2,44,36,38,4d,80,39,fc,50,df,aa,cd,eb,4b,10,d6,

0d,5b,f9,da,79,e0,3f,89,9a,b4,3c,4a,db,10,1e,e8,20,fd,88,02,da,16,3a,7a,b7,\

"rkeysecu"=hex:d0,71,9f,d7,18,0a,c6,cb,3e,d1,09,7e,f3,81,c3,2a

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10b.exe,-101"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\LocalServer32]

@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10b.exe"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10b.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

@="0"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

@="ShockwaveFlash.ShockwaveFlash.10"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10b.ocx, 1"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="ShockwaveFlash.ShockwaveFlash"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10b.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

@="FlashFactory.FlashFactory.1"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10b.ocx, 1"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="FlashFactory.FlashFactory"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}]

@Denied: (A 2) (Everyone)

@="IFlashBroker2"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\ProxyStubClsid]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]

@Denied: (A 2) (Everyone)

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]

@="Shockwave Flash"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]

@Denied: (A 2) (Everyone)

@=""

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]

@="FlashBroker"

.

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows CE Services]

"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,

00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\

"CurrentPartnershipProtocol"=dword:00000003

"MinimumPartnershipProtocol"=dword:00000002

@=""

"EulaRequired"=dword:06010000

"DTPTNetworkType"="{0}"

"Dual-Home"=dword:00000001

"DisableCredentialSave"=dword:00000000

"RasTimeoutResponseWait"=dword:00000032

"RasTimeoutPause"=dword:00000005

"ConnectTypesAllowed"=dword:0000000a

"CheckPasswordTimeoutSeconds"=dword:00000014

"WaitV2TimeoutSeconds"=dword:00000004

"SerialPort"="Bluetooth"

"HasUsbDevice"=dword:00000000

"SerialBaudRate"=dword:0001c200

"DeviceType"=""

"DeviceOemInfo"=""

"DeviceVersion"=dword:04401504

"DeviceProcessorType"=dword:00000000

"DeviceProcessor"=""

"DisableIr"=dword:00000000

"GuestOnly"=dword:00000000

"MajorVersion"=dword:00000006

"MinorVersion"=dword:00000000

"InstalledDir"="c:\\Windows\\WindowsMobile"

.

[HKEY_LOCAL_MACHINE\software\Wow6432Node\Classes]

"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,

00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\

.

Completion time: 2011-11-07 21:33:03

ComboFix-quarantined-files.txt 2011-11-08 03:33

ComboFix2.txt 2011-11-06 20:01

ComboFix3.txt 2011-10-31 18:34

.

Pre-Run: 26,925,674,496 bytes free

Post-Run: 26,857,705,472 bytes free

.

- - End Of File - - 486ABD1BA30BFB3E4F0DC8DE5FEFC88F

Link to post
Share on other sites

Yeah just noticed what firefox is trying to connect to when i start it and it says Firefox is trying to connect to potentially malicious websites (and when I can't see firefox).

It spams ports in consecutive order like 50017-50050, trying to connect to blackhole.cz.cc/http

here's the dds log.

.

DDS (Ver_2011-08-26.01) - NTFSAMD64

Internet Explorer: 8.0.6001.19088

Run by Tsiphon at 13:53:03 on 2011-11-08

Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1252.1.1033.18.4094.2221 [GMT -6:00]

.

AV: Kaspersky Anti-Virus *Disabled/Outdated* {56547CC9-C9B2-849D-8FEF-A496150D6A06}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

SP: Kaspersky Anti-Virus *Disabled/Updated* {ED359D2D-EF88-8B13-B55F-9FE46E8A20BB}

SP: COMODO Defense+ *Enabled/Updated* {CE351521-78FA-2048-BB22-B68A4A5CA7EC}

FW: COMODO Firewall *Enabled* {4D6F75E0-14AF-2E9E-AACD-24CDCF08AA2A}

.

============== Running Processes ===============

.

C:\Windows\system32\wininit.exe

C:\Windows\system32\lsm.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\nvvsvc.exe

C:\Windows\system32\svchost.exe -k rpcss

C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe

C:\Windows\system32\svchost.exe -k NetworkService

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k netsvcs

C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe

C:\Windows\system32\svchost.exe -k GPSvcGroup

C:\Windows\system32\SLsvc.exe

C:\Windows\system32\svchost.exe -k LocalService

C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe

C:\Windows\system32\nvvsvc.exe

C:\Windows\System32\spoolsv.exe

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

C:\Windows\system32\svchost.exe -k apphost

C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt

C:\Windows\SysWoW64\svchost.exe

C:\Windows\system32\mqsvc.exe

C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedul2.exe

C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

C:\Windows\system32\svchost.exe -k imgsvc

C:\Program Files\Tablet\Pen\Pen_Tablet.exe

C:\Windows\system32\taskeng.exe

C:\Windows\SysWoW64\svchost.exe

C:\Windows\system32\svchost.exe -k iissvcs

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

C:\Windows\system32\SearchIndexer.exe

C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Windows\system32\taskeng.exe

C:\Windows\WindowsMobile\wmdc.exe

C:\Windows\RAVCpl64.exe

C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedhlp.exe

C:\Windows\ehome\ehtray.exe

C:\Windows\ehome\ehmsas.exe

C:\Program Files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe

C:\Program Files (x86)\Seagate\DiscWizard\TimounterMonitor.exe

C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe

C:\Program Files\Tablet\Pen\Pen_TabletUser.exe

C:\Program Files\Tablet\Pen\Pen_Tablet.exe

C:\Windows\system32\wbem\unsecapp.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Windows\system32\svchost.exe -k WindowsMobile

C:\Program Files (x86)\Mozilla Firefox\firefox.exe

C:\Program Files (x86)\Internet Explorer\iexplore.exe

C:\Program Files (x86)\Internet Explorer\iexplore.exe

C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe

C:\Program Files\Windows Media Player\wmpnetwk.exe

C:\Program Files (x86)\Mozilla Firefox\firefox.exe

C:\Windows\servicing\TrustedInstaller.exe

C:\Windows\System32\osk.exe

C:\Windows\system32\SearchProtocolHost.exe

C:\Windows\system32\SearchFilterHost.exe

C:\Windows\SysWOW64\cmd.exe

C:\Windows\SysWOW64\conime.exe

C:\Windows\SysWOW64\cscript.exe

C:\Windows\system32\wbem\wmiprvse.exe

.

============== Pseudo HJT Report ===============

.

uStart Page = hxxp://www.yahoo.com/

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll

BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\ievkbd.dll

BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll

BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll

uRun: [ehTray.exe] C:\Windows\ehome\ehTray.exe

mRun: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe

mRun: [DiscWizardMonitor.exe] C:\Program Files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe

mRun: [AcronisTimounterMonitor] C:\Program Files (x86)\Seagate\DiscWizard\TimounterMonitor.exe

mRun: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe"

mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime Alternative\QTTask.exe" -atboottime

mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray

mRun: [WinPatrol] "C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe" -expressboot

dRun: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden

mPolicies-system: EnableLUA = 0 (0x0)

mPolicies-system: EnableUIADesktopToggle = 0 (0x0)

mPolicies-system: EnableLinkedConnections = 1 (0x1)

IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000

IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll

IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll

IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll

IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL

IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll

IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll

DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab

DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab

DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://l.yimg.com/jh/games/web_games/popcap/bejeweled2/popcaploader_v6.cab

DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://www.creative.com/softwareupdate/su2/ocx/15103/CTPID.cab

TCP: DhcpNameServer = 192.168.1.1

TCP: Interfaces\{B2707B3A-F1B2-4360-8B02-F14850833270} : DhcpNameServer = 192.168.1.1

Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll

AppInit_DLLs: C:\PROGRA~2\KASPER~1\KASPER~2\mzvkbd3.dll C:\Windows\SysWOW64\guard32.dll

SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll

mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"

BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

BHO-X64: AcroIEHelperStub - No File

BHO-X64: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll

BHO-X64: IEVkbdBHO Class: {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\ievkbd.dll

BHO-X64: IEVkbdBHO - No File

BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll

BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

BHO-X64: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

BHO-X64: FilterBHO Class: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll

BHO-X64: link filter bho - No File

mRun-x64: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe

mRun-x64: [DiscWizardMonitor.exe] C:\Program Files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe

mRun-x64: [AcronisTimounterMonitor] C:\Program Files (x86)\Seagate\DiscWizard\TimounterMonitor.exe

mRun-x64: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe"

mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime Alternative\QTTask.exe" -atboottime

mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray

mRun-x64: [WinPatrol] "C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe" -expressboot

AppInit_DLLs-X64: C:\PROGRA~2\KASPER~1\KASPER~2\mzvkbd3.dll C:\Windows\SysWOW64\guard32.dll

SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll

.

================= FIREFOX ===================

.

FF - ProfilePath - C:\Users\Tsiphon\AppData\Roaming\Mozilla\Firefox\Profiles\h8pjtgv2.default\

FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/

FF - prefs.js: keyword.URL - hxxp://dts.search-results.com/sr?src=ffb&appid=0&systemid=410&q=

FF - prefs.js: network.proxy.http - 127.0.0.1

FF - prefs.js: network.proxy.http_port - 53960

FF - prefs.js: network.proxy.type - 1

FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll

FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll

FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrlui.dll

FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll

FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npmusicn.dll

FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll

FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll

FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll

FF - plugin: C:\Program Files (x86)\Photosynth\npPhotosynthMozilla.dll

FF - plugin: C:\Program Files (x86)\QuickTime Alternative\Plugins\npqtplugin.dll

FF - plugin: C:\Program Files (x86)\QuickTime Alternative\Plugins\npqtplugin2.dll

FF - plugin: C:\Program Files (x86)\QuickTime Alternative\Plugins\npqtplugin3.dll

FF - plugin: C:\Program Files (x86)\QuickTime Alternative\Plugins\npqtplugin4.dll

FF - plugin: C:\Program Files (x86)\QuickTime Alternative\Plugins\npqtplugin5.dll

FF - plugin: C:\Program Files (x86)\QuickTime Alternative\Plugins\npqtplugin6.dll

FF - plugin: C:\Program Files (x86)\QuickTime Alternative\Plugins\npqtplugin7.dll

FF - plugin: C:\Program Files (x86)\TabletPlugins\npwacom.dll

FF - plugin: C:\Users\Tsiphon\AppData\Roaming\Mozilla\Firefox\Profiles\h8pjtgv2.default\extensions\DeviceDetection@logitech.com\plugins\npLogitechDeviceDetection.dll

.

============= SERVICES / DRIVERS ===============

.

R0 BtHidBus;Bluetooth HID Bus Service;C:\Windows\system32\Drivers\BtHidBus.sys --> C:\Windows\system32\Drivers\BtHidBus.sys [?]

R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys --> C:\Windows\system32\Drivers\PxHlpa64.sys [?]

R1 cmdGuard;COMODO Internet Security Sandbox Driver;C:\Windows\system32\DRIVERS\cmdguard.sys --> C:\Windows\system32\DRIVERS\cmdguard.sys [?]

R1 cmdHlp;COMODO Internet Security Helper Driver;C:\Windows\system32\DRIVERS\cmdhlp.sys --> C:\Windows\system32\DRIVERS\cmdhlp.sys [?]

R1 kl2;kl2;C:\Windows\system32\DRIVERS\kl2.sys --> C:\Windows\system32\DRIVERS\kl2.sys [?]

R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\system32\DRIVERS\klim6.sys --> C:\Windows\system32\DRIVERS\klim6.sys [?]

R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-6-6 64952]

R2 cpuz135;cpuz135;\??\C:\Windows\system32\drivers\cpuz135_x64.sys --> C:\Windows\system32\drivers\cpuz135_x64.sys [?]

R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-10-26 366152]

R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2010-5-4 1153368]

R2 SgtSch2Svc;Seagate Scheduler2 Service;C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedul2.exe [2008-6-24 605464]

R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-10-16 369256]

R2 TabletServicePen;TabletServicePen;C:\Program Files\Tablet\Pen\Pen_Tablet.exe [2011-5-25 5790064]

R3 btnetBUs;Bluetooth PAN Bus Service;C:\Windows\system32\Drivers\btnetBus.sys --> C:\Windows\system32\Drivers\btnetBus.sys [?]

R3 CT20XUT.SYS;CT20XUT.SYS;C:\Windows\system32\drivers\CT20XUT.SYS --> C:\Windows\system32\drivers\CT20XUT.SYS [?]

R3 CTEXFIFX.SYS;CTEXFIFX.SYS;C:\Windows\system32\drivers\CTEXFIFX.SYS --> C:\Windows\system32\drivers\CTEXFIFX.SYS [?]

R3 CTHWIUT.SYS;CTHWIUT.SYS;C:\Windows\system32\drivers\CTHWIUT.SYS --> C:\Windows\system32\drivers\CTHWIUT.SYS [?]

R3 IvtBtBUs;IVT Bluetooth Bus Service;C:\Windows\system32\Drivers\IvtBtBus.sys --> C:\Windows\system32\Drivers\IvtBtBus.sys [?]

R3 klmouflt;Kaspersky Lab KLMOUFLT;C:\Windows\system32\DRIVERS\klmouflt.sys --> C:\Windows\system32\DRIVERS\klmouflt.sys [?]

R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]

R3 ScreamBAudioSvc;ScreamBee Audio;C:\Windows\system32\drivers\ScreamingBAudio64.sys --> C:\Windows\system32\drivers\ScreamingBAudio64.sys [?]

R3 VCSVADHWSer;Avnex Virtual Audio Device (WDM);C:\Windows\system32\DRIVERS\vcsvad.sys --> C:\Windows\system32\DRIVERS\vcsvad.sys [?]

S2 AVP;Kaspersky Anti-Virus Service;C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe [2010-7-1 352976]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]

S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]

S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-1-27 135664]

S3 AdobeActiveFileMonitor8.0;Adobe Active File Monitor V8;C:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe [2009-10-9 169312]

S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2008-8-6 79360]

S3 CT20XUT;CT20XUT;C:\Windows\system32\drivers\CT20XUT.SYS --> C:\Windows\system32\drivers\CT20XUT.SYS [?]

S3 CTEXFIFX;CTEXFIFX;C:\Windows\system32\drivers\CTEXFIFX.SYS --> C:\Windows\system32\drivers\CTEXFIFX.SYS [?]

S3 CTHWIUT;CTHWIUT;C:\Windows\system32\drivers\CTHWIUT.SYS --> C:\Windows\system32\drivers\CTHWIUT.SYS [?]

S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-1-27 135664]

S3 MEMSWEEP2;MEMSWEEP2;\??\C:\Windows\system32\B85.tmp --> C:\Windows\system32\B85.tmp [?]

S3 PerfHost;Performance Counter DLL Host;C:\Windows\SysWOW64\perfhost.exe [2008-7-22 19968]

S3 PSSDK42;PSSDK42;\??\C:\Windows\system32\Drivers\pssdk42.sys --> C:\Windows\system32\Drivers\pssdk42.sys [?]

S3 RivaTuner64;RivaTuner64;C:\Program Files (x86)\RivaTuner v2.09\RivaTuner64.sys [2008-4-28 19952]

S3 scramby_out;Scramby Output;C:\Windows\system32\drivers\scramby_out.sys --> C:\Windows\system32\drivers\scramby_out.sys [?]

S3 TouchServicePen;Wacom Consumer Touch Service;C:\Program Files\Tablet\Pen\Pen_TouchService.exe [2011-5-25 487280]

S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]

S3 wacmoumonitor;Wacom Mode Helper;C:\Windows\system32\DRIVERS\wacmoumonitor.sys --> C:\Windows\system32\DRIVERS\wacmoumonitor.sys [?]

S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-3-18 1020768]

S4 BsMobileCS;BsMobileCS;C:\Program Files (x86)\IVT Corporation\BlueSoleil\BsMobileCS.exe [2010-3-9 143467]

S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2009-3-24 93184]

S4 MSSQL$SOLARWINDS_ORION;SQL Server (SOLARWINDS_ORION); [x]

S4 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe [2010-3-25 490280]

S4 TomTomHOMEService;TomTomHOMEService;C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe [2009-11-13 92008]

.

=============== File Associations ===============

.

JSEFile=C:\Windows\SysWOW64\WScript.exe "%1" %*

.

=============== Created Last 30 ================

.

2011-11-08 03:47:19 -------- d-sh--w- C:\$RECYCLE.BIN

2011-11-06 19:03:56 98816 ----a-w- C:\Windows\sed.exe

2011-11-06 19:03:56 518144 ----a-w- C:\Windows\SWREG.exe

2011-11-06 19:03:56 256000 ----a-w- C:\Windows\PEV.exe

2011-11-06 19:03:56 208896 ----a-w- C:\Windows\MBR.exe

2011-11-02 23:46:30 6144 ------w- C:\Windows\System32\B85.tmp

2011-11-02 23:40:23 6144 ------w- C:\Windows\System32\7213.tmp

2011-11-02 23:30:25 6144 ------w- C:\Windows\System32\5060.tmp

2011-11-02 23:22:41 6144 ------w- C:\Windows\System32\1AC0.tmp

2011-11-02 23:16:36 6144 ------w- C:\Windows\System32\88FD.tmp

2011-11-02 23:11:45 6144 ------w- C:\Windows\System32\1821.tmp

2011-11-02 23:11:14 -------- d-----w- C:\Program Files (x86)\Sophos

2011-11-01 18:56:45 388096 ----a-r- C:\Users\Tsiphon\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe

2011-10-31 07:06:56 0 ----a-w- C:\Windows\SysWow64\drivers\SET88DE.tmp

2011-10-31 07:06:45 0 ----a-w- C:\Windows\SysWow64\drivers\SET5C67.tmp

2011-10-31 07:06:44 0 ----a-w- C:\Windows\SysWow64\drivers\SET5AA1.tmp

2011-10-31 07:06:44 0 ----a-w- C:\Windows\SysWow64\drivers\SET584F.tmp

2011-10-31 07:06:23 0 ----a-w- C:\Windows\SysWow64\drivers\SET771.tmp

2011-10-31 07:06:22 0 ----a-w- C:\Windows\SysWow64\drivers\SET4E1.tmp

2011-10-31 07:06:07 309320 ----a-w- C:\Windows\SysWow64\drivers\TrufosAlt.sys

2011-10-31 07:06:07 0 ----a-w- C:\Windows\SysWow64\drivers\SETC86D.tmp

2011-10-31 07:05:21 0 ----a-w- C:\Windows\SysWow64\drivers\SET1747.tmp

2011-10-31 07:04:26 0 ----a-w- C:\Windows\SysWow64\drivers\SET3E2B.tmp

2011-10-31 07:04:25 0 ----a-w- C:\Windows\SysWow64\drivers\SET3C94.tmp

2011-10-31 07:04:25 0 ----a-w- C:\Windows\SysWow64\drivers\SET39E5.tmp

2011-10-31 07:04:23 0 ----a-w- C:\Windows\SysWow64\drivers\SET334F.tmp

2011-10-31 07:04:00 0 ----a-w- C:\Windows\SysWow64\drivers\SETDA09.tmp

2011-10-31 07:03:22 0 ----a-w- C:\Windows\SysWow64\drivers\SET432B.tmp

2011-10-31 07:03:21 0 ----a-w- C:\Windows\SysWow64\drivers\SET400F.tmp

2011-10-31 07:02:46 0 ----a-w- C:\Windows\SysWow64\drivers\SETB971.tmp

2011-10-31 07:02:46 0 ----a-w- C:\Windows\SysWow64\drivers\SETB6A2.tmp

2011-10-31 07:02:44 0 ----a-w- C:\Windows\SysWow64\drivers\SETAFBE.tmp

2011-10-31 06:58:23 0 ----a-w- C:\Windows\SysWow64\drivers\SETB450.tmp

2011-10-31 04:21:13 -------- d-----w- C:\Users\Tsiphon\AppData\Roaming\WinPatrol

2011-10-31 04:21:03 -------- d-----w- C:\ProgramData\InstallMate

2011-10-31 04:21:03 -------- d-----w- C:\Program Files (x86)\BillP Studios

2011-10-31 04:18:21 -------- d-----w- C:\ProgramData\Comodo

2011-10-31 04:18:17 -------- d-----w- C:\Program Files\COMODO

2011-10-31 04:17:25 -------- d-----w- C:\ProgramData\Comodo Downloader

2011-10-28 22:54:51 -------- d-----w- C:\Program Files (x86)\Eusing Free Registry Cleaner

2011-10-26 21:59:25 -------- d-----w- C:\Users\Tsiphon\AppData\Roaming\Malwarebytes

2011-10-26 21:59:20 -------- d-----w- C:\ProgramData\Malwarebytes

2011-10-26 21:59:16 25416 ----a-w- C:\Windows\System32\drivers\mbam.sys

2011-10-26 21:59:16 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware

2011-10-26 21:56:52 -------- d-----w- C:\Users\Tsiphon\AppData\Roaming\WTablet

2011-10-21 14:14:24 8570192 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FDC2EED1-71B5-48C1-ADD4-7D759D933147}\mpengine.dll

2011-10-13 22:18:09 -------- d-----w- C:\Program Files\iPod

2011-10-13 22:18:07 -------- d-----w- C:\Program Files\iTunes

2011-10-10 00:12:07 21992 ----a-w- C:\Windows\System32\drivers\cpuz135_x64.sys

2011-10-10 00:12:07 -------- d-----w- C:\Program Files\CPUID

.

==================== Find3M ====================

.

2011-10-07 23:47:50 42224 ----a-w- C:\Windows\System32\drivers\cmdhlp.sys

2011-10-07 23:47:48 574216 ----a-w- C:\Windows\System32\drivers\cmdGuard.sys

2011-10-07 23:47:48 16528 ----a-w- C:\Windows\System32\drivers\cmderd.sys

2011-10-07 23:47:14 41200 ----a-w- C:\Windows\System32\cmdcsr.dll

2011-10-07 23:47:12 300200 ----a-w- C:\Windows\SysWow64\guard32.dll

2011-10-07 23:47:10 388280 ----a-w- C:\Windows\System32\guard64.dll

2011-10-03 10:06:03 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll

2011-08-31 04:05:32 96104 ----a-w- C:\Windows\System32\dns-sd.exe

2011-08-31 04:05:32 85864 ----a-w- C:\Windows\System32\dnssd.dll

2011-08-31 04:05:04 83816 ----a-w- C:\Windows\SysWow64\dns-sd.exe

2011-08-31 04:05:04 73064 ----a-w- C:\Windows\SysWow64\dnssd.dll

.

============= FINISH: 13:54:20.33 ===============

Link to post
Share on other sites

Hi,

Upload c:\windows\SysWow64\kernel32.dll file to http://www.virustotal.com (reanalyse if prompted) and post back a link to the results.

Open notepad and copy/paste the text in the quotebox below into it:


Firefox::
FF - ProfilePath - c:\users\Tsiphon\AppData\Roaming\Mozilla\Firefox\Profiles\h8pjtgv2.default\
FF - prefs.js: keyword.URL - hxxp://dts.search-results.com/sr?src=ffb&appid=0&systemid=410&q=
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 53960
FF - prefs.js: network.proxy.type - 1

Save this as

CFScript

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine. This tool is not a toy and not for everyday use.

CFScriptB-4.gif

Close all browser windows and refering to the picture above, drag CFScript into ComboFix.exe (let the tool to update itself if prompted).

Then post the resultant log.

Did you run ESET online scanner yet?

Link to post
Share on other sites

Ran the script, comp still running weird.

I have figured out that if my computer isn't plugged into the internet, I can open and see Firefox, and it pops up saying i can't connect because of proxy settings. If I plug in the ethernet cable to my modem, firefox will freeze. I used to be able to open firefox and browse after changing the proxy settings, earlier on when i had this virus.

I had to put kernel32 on a usb and upload it via my laptop, but virustotal.com times out during the upload. I therefore emailed it to them, and the scan came back all "found nothing".

If it helps at all I did a google search for the blackhole.cz.cc and a bunch of stuff came up talking about a "Blackhole exploit toolkit", with symptoms like mine.

Due to my desktop not letting me look at firefox while it runs (it loads, and makes connections, but I can't view it), I am unable to directly use virustotal.com or the ESET scan. As of now I can't do anything with browsers.

Thanks for your help by the way, it's frustrating to me and I'm sure it's lame to be on the 'trying to help' end and not have all the resources you need from me.

The Combofix log:

ComboFix 11-11-06.02 - Tsiphon 11/09/2011 0:25.5.4 - x64

Running from: c:\users\Tsiphon\Desktop\ComboFix.exe

Command switches used :: c:\users\Tsiphon\Desktop\CFScript.txt

AV: Kaspersky Anti-Virus *Disabled/Outdated* {56547CC9-C9B2-849D-8FEF-A496150D6A06}

FW: COMODO Firewall *Enabled* {4D6F75E0-14AF-2E9E-AACD-24CDCF08AA2A}

SP: COMODO Defense+ *Disabled/Updated* {CE351521-78FA-2048-BB22-B68A4A5CA7EC}

SP: Kaspersky Anti-Virus *Disabled/Updated* {ED359D2D-EF88-8B13-B55F-9FE46E8A20BB}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

.

((((((((((((((((((((((((( Files Created from 2011-10-09 to 2011-11-09 )))))))))))))))))))))))))))))))

.

.

2011-11-09 07:10 . 2011-11-09 07:10 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\temp

2011-11-09 07:10 . 2011-11-09 07:10 -------- d-----w- c:\users\Mcx1\AppData\Local\temp

2011-11-09 07:10 . 2011-11-09 07:10 -------- d-----w- c:\users\Guest\AppData\Local\temp

2011-11-09 07:10 . 2011-11-09 07:10 -------- d-----w- c:\users\Default\AppData\Local\temp

2011-11-08 20:10 . 2011-11-08 20:10 -------- d-----w- c:\program files (x86)\Common Files\Java

2011-11-08 20:09 . 2011-11-08 20:09 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2011-11-08 19:57 . 2011-11-08 20:06 -------- d-----w- c:\users\Tsiphon\AppData\Local\Solid State Networks

2011-11-08 03:40 . 2011-11-08 03:40 -------- d-----w- c:\windows\system32\Macromed

2011-11-02 23:46 . 2011-05-12 19:03 6144 ------w- c:\windows\system32\B85.tmp

2011-11-02 23:40 . 2011-05-12 19:03 6144 ------w- c:\windows\system32\7213.tmp

2011-11-02 23:30 . 2011-05-12 19:03 6144 ------w- c:\windows\system32\5060.tmp

2011-11-02 23:22 . 2011-05-12 19:03 6144 ------w- c:\windows\system32\1AC0.tmp

2011-11-02 23:16 . 2011-05-12 19:03 6144 ------w- c:\windows\system32\88FD.tmp

2011-11-02 23:11 . 2011-05-12 19:03 6144 ------w- c:\windows\system32\1821.tmp

2011-11-02 23:11 . 2011-11-02 23:11 -------- d-----w- c:\program files (x86)\Sophos

2011-11-01 18:56 . 2011-11-01 18:56 388096 ----a-r- c:\users\Tsiphon\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe

2011-10-31 07:06 . 2011-10-31 07:06 0 ----a-w- c:\windows\SysWow64\drivers\SET88DE.tmp

2011-10-31 07:06 . 2011-10-31 07:06 0 ----a-w- c:\windows\SysWow64\drivers\SET5C67.tmp

2011-10-31 07:06 . 2011-10-31 07:06 0 ----a-w- c:\windows\SysWow64\drivers\SET5AA1.tmp

2011-10-31 07:06 . 2011-10-31 07:06 0 ----a-w- c:\windows\SysWow64\drivers\SET584F.tmp

2011-10-31 07:06 . 2011-10-31 07:06 0 ----a-w- c:\windows\SysWow64\drivers\SET771.tmp

2011-10-31 07:06 . 2011-10-31 07:06 0 ----a-w- c:\windows\SysWow64\drivers\SET4E1.tmp

2011-10-31 07:06 . 2011-10-31 07:07 309320 ----a-w- c:\windows\SysWow64\drivers\TrufosAlt.sys

2011-10-31 07:06 . 2011-10-31 07:06 0 ----a-w- c:\windows\SysWow64\drivers\SETC86D.tmp

2011-10-31 07:05 . 2011-10-31 07:05 0 ----a-w- c:\windows\SysWow64\drivers\SET1747.tmp

2011-10-31 07:04 . 2011-10-31 07:04 0 ----a-w- c:\windows\SysWow64\drivers\SET3E2B.tmp

2011-10-31 07:04 . 2011-10-31 07:04 0 ----a-w- c:\windows\SysWow64\drivers\SET3C94.tmp

2011-10-31 07:04 . 2011-10-31 07:04 0 ----a-w- c:\windows\SysWow64\drivers\SET39E5.tmp

2011-10-31 07:04 . 2011-10-31 07:04 0 ----a-w- c:\windows\SysWow64\drivers\SET334F.tmp

2011-10-31 07:04 . 2011-10-31 07:04 0 ----a-w- c:\windows\SysWow64\drivers\SETDA09.tmp

2011-10-31 07:03 . 2011-10-31 07:03 0 ----a-w- c:\windows\SysWow64\drivers\SET432B.tmp

2011-10-31 07:03 . 2011-10-31 07:03 0 ----a-w- c:\windows\SysWow64\drivers\SET400F.tmp

2011-10-31 07:02 . 2011-10-31 07:02 0 ----a-w- c:\windows\SysWow64\drivers\SETB971.tmp

2011-10-31 07:02 . 2011-10-31 07:02 0 ----a-w- c:\windows\SysWow64\drivers\SETB6A2.tmp

2011-10-31 07:02 . 2011-10-31 07:02 0 ----a-w- c:\windows\SysWow64\drivers\SETAFBE.tmp

2011-10-31 06:58 . 2011-10-31 06:58 0 ----a-w- c:\windows\SysWow64\drivers\SETB450.tmp

2011-10-31 04:21 . 2011-10-31 04:21 -------- d-----w- c:\users\Tsiphon\AppData\Roaming\WinPatrol

2011-10-31 04:21 . 2011-10-31 04:21 -------- d-----w- c:\programdata\InstallMate

2011-10-31 04:21 . 2011-10-31 04:21 -------- d-----w- c:\program files (x86)\BillP Studios

2011-10-31 04:18 . 2011-11-02 08:48 -------- d-----w- c:\programdata\Comodo

2011-10-31 04:18 . 2011-10-31 04:18 -------- d-----w- c:\program files\COMODO

2011-10-31 04:17 . 2011-10-31 04:18 -------- d-----w- c:\programdata\Comodo Downloader

2011-10-29 08:24 . 2011-10-29 10:15 -------- d-----w- c:\users\Tsiphon\AppData\Roaming\Winamp

2011-10-28 22:54 . 2011-10-28 23:09 -------- d-----w- c:\program files (x86)\Eusing Free Registry Cleaner

2011-10-26 21:59 . 2011-10-26 21:59 -------- d-----w- c:\users\Tsiphon\AppData\Roaming\Malwarebytes

2011-10-26 21:59 . 2011-10-26 21:59 -------- d-----w- c:\programdata\Malwarebytes

2011-10-26 21:59 . 2011-10-27 02:50 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware

2011-10-26 21:59 . 2011-08-31 22:00 25416 ----a-w- c:\windows\system32\drivers\mbam.sys

2011-10-26 21:56 . 2011-10-26 21:56 -------- d-----w- c:\users\Tsiphon\AppData\Roaming\WTablet

2011-10-21 14:14 . 2011-10-07 04:16 8570192 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{FDC2EED1-71B5-48C1-ADD4-7D759D933147}\mpengine.dll

2011-10-13 22:18 . 2011-10-13 22:18 -------- d-----w- c:\program files\iPod

2011-10-13 22:18 . 2011-10-13 22:19 -------- d-----w- c:\program files\iTunes

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2011-11-08 20:10 . 2010-04-30 21:21 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll

2011-10-07 23:47 . 2011-10-07 23:47 93200 ----a-w- c:\windows\system32\drivers\inspect.sys

2011-10-07 23:47 . 2011-10-07 23:47 42224 ----a-w- c:\windows\system32\drivers\cmdhlp.sys

2011-10-07 23:47 . 2011-10-07 23:47 574216 ----a-w- c:\windows\system32\drivers\cmdGuard.sys

2011-10-07 23:47 . 2011-10-07 23:47 16528 ----a-w- c:\windows\system32\drivers\cmderd.sys

2011-10-07 23:47 . 2011-10-07 23:47 41200 ----a-w- c:\windows\system32\cmdcsr.dll

2011-10-07 23:47 . 2011-10-07 23:47 300200 ----a-w- c:\windows\SysWow64\guard32.dll

2011-10-07 23:47 . 2011-10-07 23:47 388280 ----a-w- c:\windows\system32\guard64.dll

2011-08-31 04:05 . 2011-08-31 04:05 96104 ----a-w- c:\windows\system32\dns-sd.exe

2011-08-31 04:05 . 2011-08-31 04:05 85864 ----a-w- c:\windows\system32\dnssd.dll

2011-08-31 04:05 . 2011-08-31 04:05 83816 ----a-w- c:\windows\SysWow64\dns-sd.exe

2011-08-31 04:05 . 2011-08-31 04:05 73064 ----a-w- c:\windows\SysWow64\dnssd.dll

.

.

------- Sigcheck -------

Note: Unsigned files aren't necessarily malware.

.

Cryptography Services Error !!

.

((((((((((((((((((((((((((((( SnapShot@2011-11-06_19.43.21 )))))))))))))))))))))))))))))))))))))))))

.

+ 2008-07-19 07:24 . 2011-11-08 20:09 30314 c:\windows\system32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-4111605854-636613554-1496609690-1000_UserData.bin

- 2011-06-10 04:10 . 2011-11-06 00:38 62078 c:\windows\system32\config\systemprofile\AppData\Roaming\WTablet\Pen_Tablet.dat

+ 2011-06-10 04:10 . 2011-11-08 20:04 62078 c:\windows\system32\config\systemprofile\AppData\Roaming\WTablet\Pen_Tablet.dat

+ 2008-07-19 06:58 . 2011-11-09 00:49 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2008-07-19 06:58 . 2011-11-06 00:38 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2008-07-19 06:58 . 2011-11-06 00:38 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

+ 2008-07-19 06:58 . 2011-11-09 00:49 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

+ 2008-07-19 06:58 . 2011-11-09 00:49 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

- 2008-07-19 06:58 . 2011-11-06 00:38 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2010-09-28 04:39 . 2011-11-08 20:11 16384 c:\windows\system32\%APPDATA%\Microsoft\Windows\IETldCache\index.dat

- 2010-09-28 04:39 . 2011-11-04 04:57 16384 c:\windows\system32\%APPDATA%\Microsoft\Windows\IETldCache\index.dat

+ 2009-05-20 06:17 . 2011-11-08 20:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2009-05-20 06:17 . 2011-11-06 00:44 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2009-05-20 06:17 . 2011-11-08 20:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

- 2009-05-20 06:17 . 2011-11-06 00:44 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2011-11-08 20:03 . 2011-11-08 20:03 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

- 2011-11-06 00:20 . 2011-11-06 00:38 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

+ 2011-11-08 20:03 . 2011-11-08 20:03 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

- 2011-11-06 00:20 . 2011-11-06 00:38 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

+ 2011-11-08 20:09 . 2011-11-08 20:09 247968 c:\windows\SysWOW64\Macromed\Flash\FlashUtil11c_Plugin.exe

- 2011-10-12 05:59 . 2011-10-12 05:59 247968 c:\windows\SysWOW64\Macromed\Flash\FlashUtil11c_Plugin.exe

+ 2011-11-08 20:10 . 2011-11-08 20:10 157472 c:\windows\SysWOW64\javaws.exe

- 2011-10-31 17:22 . 2011-10-03 10:06 157472 c:\windows\SysWOW64\javaws.exe

- 2011-10-31 17:22 . 2011-10-03 10:06 145184 c:\windows\SysWOW64\javaw.exe

+ 2011-11-08 20:10 . 2011-11-08 20:10 145184 c:\windows\SysWOW64\javaw.exe

- 2011-10-31 17:22 . 2011-10-03 10:06 145184 c:\windows\SysWOW64\java.exe

+ 2011-11-08 20:10 . 2011-11-08 20:10 145184 c:\windows\SysWOW64\java.exe

+ 2009-01-17 21:40 . 2011-11-08 19:46 760864 c:\windows\system32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin

+ 2008-07-19 07:24 . 2011-11-08 20:09 106476 c:\windows\system32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin

+ 2006-11-02 15:44 . 2011-11-08 20:09 141908 c:\windows\system32\WDI\BootPerformanceDiagnostics_SystemData.bin

+ 2008-08-26 08:08 . 2011-11-08 20:10 493170 c:\windows\system32\perfh011.dat

- 2008-08-26 08:08 . 2011-10-31 04:19 493170 c:\windows\system32\perfh011.dat

- 2006-11-02 12:46 . 2011-10-31 04:19 753588 c:\windows\system32\perfh009.dat

+ 2006-11-02 12:46 . 2011-11-08 20:10 753588 c:\windows\system32\perfh009.dat

- 2008-08-26 08:08 . 2011-10-31 04:19 162694 c:\windows\system32\perfc011.dat

+ 2008-08-26 08:08 . 2011-11-08 20:10 162694 c:\windows\system32\perfc011.dat

+ 2006-11-02 12:46 . 2011-11-08 20:10 162694 c:\windows\system32\perfc009.dat

- 2006-11-02 12:46 . 2011-10-31 04:19 162694 c:\windows\system32\perfc009.dat

+ 2011-11-08 20:09 . 2011-11-08 20:09 461984 c:\windows\system32\Macromed\Flash\FlashUtil64_11_0_1_Plugin.exe

- 2009-05-15 06:07 . 2011-11-06 00:38 262144 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat

+ 2009-05-15 06:07 . 2011-11-08 20:03 262144 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat

+ 2011-11-08 20:10 . 2011-11-08 20:10 203776 c:\windows\Installer\6d3dd.msi

+ 2011-11-08 20:10 . 2011-11-08 20:10 901120 c:\windows\Installer\6d3d6.msi

+ 2011-11-08 20:09 . 2011-11-08 20:09 8522400 c:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll

- 2009-02-03 02:15 . 2011-10-12 05:59 8522400 c:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll

+ 2006-11-02 15:21 . 2011-11-08 20:31 2929146 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareLicensing\tokens.dat

- 2006-11-02 15:21 . 2011-06-11 09:32 2929146 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareLicensing\tokens.dat

- 2011-06-11 06:21 . 2011-11-06 00:38 4194304 c:\windows\Debug\msmqlog.bin

+ 2011-06-11 06:21 . 2011-11-08 20:04 4194304 c:\windows\Debug\msmqlog.bin

- 2006-11-02 12:33 . 2011-11-01 19:55 11010048 c:\windows\system32\SMI\Store\Machine\schema.dat

+ 2006-11-02 12:33 . 2011-11-08 20:31 11010048 c:\windows\system32\SMI\Store\Machine\schema.dat

+ 2011-11-08 20:09 . 2011-11-08 20:09 11328672 c:\windows\system32\Macromed\Flash\NPSWF64_11_0_1.dll

+ 2011-11-09 06:22 . 2011-11-09 06:22 10887168 c:\windows\ERDNT\Hiv-backup\schema.dat

.

-- Snapshot reset to current date --

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 138240]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"AppleSyncNotifier"="c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-09-27 59240]

"DiscWizardMonitor.exe"="c:\program files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe" [2008-06-25 1325848]

"AcronisTimounterMonitor"="c:\program files (x86)\Seagate\DiscWizard\TimounterMonitor.exe" [2008-06-25 904768]

"AVP"="c:\program files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe" [2011-05-27 352976]

"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]

"QuickTime Task"="c:\program files (x86)\QuickTime Alternative\QTTask.exe" [2011-07-05 421888]

"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]

"WinPatrol"="c:\program files (x86)\BillP Studios\WinPatrol\winpatrol.exe" [2011-05-15 325512]

"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]

.

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"LightScribe Control Panel"="c:\program files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe" [2009-06-17 2363392]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"EnableLUA"= 0 (0x0)

"EnableUIADesktopToggle"= 0 (0x0)

"EnableLinkedConnections"= 1 (0x1)

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\klogon]

[bU]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WgaLogon]

[bU]

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]

"AppInit_DLLs"=c:\progra~2\KASPER~1\KASPER~2\mzvkbd3.dll c:\windows\SysWOW64\guard32.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]

"aux8"=wdmaud.drv

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]

"LogitechQuickCamRibbon"="c:\program files (x86)\Logitech\QuickCam\Quickcam.exe" /hide

"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe"

"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]

"DisableMonitoring"=dword:00000001

.

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]

R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-27 135664]

R3 AdobeActiveFileMonitor8.0;Adobe Active File Monitor V8;c:\program files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe [2009-10-09 169312]

R3 CamDrL64;Logitech QuickCam Pro 3000(PID_08B0); [x]

R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2008-08-06 79360]

R3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.SYS [x]

R3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.SYS [x]

R3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.SYS [x]

R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-27 135664]

R3 LVcKap64;Logitech AEC Driver; [x]

R3 LVPr2M64;Logitech LVPr2M64 Driver; [x]

R3 LVUSBS64;Logitech USB Monitor Filter; [x]

R3 MEMSWEEP2;MEMSWEEP2;c:\windows\system32\B85.tmp [x]

R3 PSSDK42;PSSDK42;c:\windows\system32\Drivers\pssdk42.sys [x]

R3 RivaTuner64;RivaTuner64;c:\program files (x86)\RivaTuner v2.09\RivaTuner64.sys [2008-07-19 19952]

R3 rt61x64;Ralink RT61 Wireless Driver for Windows Vista; [x]

R3 scramby_out;Scramby Output;c:\windows\system32\drivers\scramby_out.sys [x]

R3 TouchServicePen;Wacom Consumer Touch Service;c:\program files\Tablet\Pen\Pen_TouchService.exe [2010-10-13 487280]

R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]

R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\DRIVERS\wacmoumonitor.sys [x]

R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 1020768]

R3 X6va003;X6va003;c:\users\Tsiphon\AppData\Local\Temp\003F29A.tmp [x]

R4 BsMobileCS;BsMobileCS;c:\program files (x86)\IVT Corporation\BlueSoleil\BsMobileCS.exe [2010-03-09 143467]

R4 MSSQL$SOLARWINDS_ORION;SQL Server (SOLARWINDS_ORION); [x]

R4 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2010-03-25 490280]

R4 TomTomHOMEService;TomTomHOMEService;c:\program files (x86)\TomTom HOME 2\TomTomHOMEService.exe [2009-11-13 92008]

S0 BtHidBus;Bluetooth HID Bus Service;c:\windows\System32\Drivers\BtHidBus.sys [x]

S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]

S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [x]

S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [x]

S1 kl2;kl2;c:\windows\system32\DRIVERS\kl2.sys [x]

S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [x]

S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]

S2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x64.sys [x]

S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-08-31 366152]

S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]

S2 SgtSch2Svc;Seagate Scheduler2 Service;c:\program files (x86)\Common Files\Seagate\Schedule2\schedul2.exe [2008-06-25 605464]

S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-10-16 369256]

S2 TabletServicePen;TabletServicePen;c:\program files\Tablet\Pen\Pen_Tablet.exe [2010-10-13 5790064]

S3 btnetBUs;Bluetooth PAN Bus Service;c:\windows\system32\Drivers\btnetBus.sys [x]

S3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\System32\drivers\CT20XUT.SYS [x]

S3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\System32\drivers\CTEXFIFX.SYS [x]

S3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\System32\drivers\CTHWIUT.SYS [x]

S3 IvtBtBUs;IVT Bluetooth Bus Service;c:\windows\system32\Drivers\IvtBtBus.sys [x]

S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys [x]

S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]

S3 ScreamBAudioSvc;ScreamBee Audio;c:\windows\system32\drivers\ScreamingBAudio64.sys [x]

S3 VCSVADHWSer;Avnex Virtual Audio Device (WDM);c:\windows\system32\DRIVERS\vcsvad.sys [x]

.

.

--- Other Services/Drivers In Memory ---

.

*Deregistered* - PROCEXP141

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]

hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

iissvcs REG_MULTI_SZ w3svc was

apphost REG_MULTI_SZ apphostsvc

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]

2009-06-17 17:11 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe

.

Contents of the 'Scheduled Tasks' folder

.

2011-11-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-27 12:40]

.

2011-11-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-27 12:40]

.

2011-11-09 c:\windows\Tasks\User_Feed_Synchronization-{5FE47A93-B92C-4E46-AFD8-FF5094CD66E8}.job

- c:\windows\system32\msfeedssync.exe [2011-06-16 04:32]

.

.

--------- x86-64 -----------

.

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 660360]

"RtHDVCpl"="RAVCpl64.exe" [2008-02-13 5684736]

"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdSync.exe" [2006-11-02 225792]

"Seagate Scheduler2 Service"="c:\program files (x86)\Common Files\Seagate\Schedule2\schedhlp.exe" [2008-06-25 136472]

"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2011-10-20 9264456]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

"AppInit_DLLs"=c:\windows\System32\guard64.dll

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.yahoo.com/

IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000

TCP: DhcpNameServer = 192.168.1.1

CLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\browseui.dll

FF - ProfilePath - c:\users\Tsiphon\AppData\Roaming\Mozilla\Firefox\Profiles\h8pjtgv2.default\

FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/

.

- - - - ORPHANS REMOVED - - - -

.

Toolbar-10 - (no file)

.

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Solarwinds Trap Service]

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\SolarWinds: Collector DataProcessor]

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Solarwinds: Job Broker]

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Solarwinds: Job Engine]

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Solarwinds: Job Engine v2]

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Solarwinds: Job Scheduler]

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Solarwinds: Job Scheduler v2]

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Solarwinds: Worker Process]

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Solarwinds: Worker Process v2]

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\MEMSWEEP2]

"ImagePath"="\??\c:\windows\system32\B85.tmp"

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\X6va003]

"ImagePath"="\??\c:\users\Tsiphon\AppData\Local\Temp\003F29A.tmp"

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]

@Denied: (2) (LocalSystem)

"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,

d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,9c,a2,f1,d4,15,82,c2,48,99,43,46,\

"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,

d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,9c,a2,f1,d4,15,82,c2,48,99,43,46,\

.

[HKEY_USERS\S-1-5-21-4111605854-636613554-1496609690-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]

@Allowed: (Read) (RestrictedCode)

"??"=hex:b0,24,0d,0e,50,c2,6b,70,02,29,1d,b9,9b,f3,6b,2f,2b,5d,22,b8,72,f1,89,

77,30,39,6a,87,2c,80,fe,83,ab,a8,68,9b,31,cd,34,b5,2e,58,6d,51,6f,3c,e1,3f,\

"??"=hex:de,c2,f1,00,6b,13,52,1e,8d,7b,f0,04,df,b8,e0,7f

.

[HKEY_USERS\S-1-5-21-4111605854-636613554-1496609690-1000\Software\SecuROM\License information*]

"datasecu"=hex:fa,84,73,12,ef,d2,44,36,38,4d,80,39,fc,50,df,aa,cd,eb,4b,10,d6,

0d,5b,f9,da,79,e0,3f,89,9a,b4,3c,4a,db,10,1e,e8,20,fd,88,02,da,16,3a,7a,b7,\

"rkeysecu"=hex:d0,71,9f,d7,18,0a,c6,cb,3e,d1,09,7e,f3,81,c3,2a

.

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows CE Services]

"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,

00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\

"CurrentPartnershipProtocol"=dword:00000003

"MinimumPartnershipProtocol"=dword:00000002

@=""

"EulaRequired"=dword:06010000

"DTPTNetworkType"="{0}"

"Dual-Home"=dword:00000001

"DisableCredentialSave"=dword:00000000

"RasTimeoutResponseWait"=dword:00000032

"RasTimeoutPause"=dword:00000005

"ConnectTypesAllowed"=dword:0000000a

"CheckPasswordTimeoutSeconds"=dword:00000014

"WaitV2TimeoutSeconds"=dword:00000004

"SerialPort"="Bluetooth"

"HasUsbDevice"=dword:00000000

"SerialBaudRate"=dword:0001c200

"DeviceType"=""

"DeviceOemInfo"=""

"DeviceVersion"=dword:04401504

"DeviceProcessorType"=dword:00000000

"DeviceProcessor"=""

"DisableIr"=dword:00000000

"GuestOnly"=dword:00000000

"MajorVersion"=dword:00000006

"MinorVersion"=dword:00000000

"InstalledDir"="c:\\Windows\\WindowsMobile"

.

[HKEY_LOCAL_MACHINE\software\Wow6432Node\Classes]

"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,

00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\

.

Completion time: 2011-11-09 01:16:56

ComboFix-quarantined-files.txt 2011-11-09 07:16

ComboFix2.txt 2011-11-08 03:33

ComboFix3.txt 2011-11-06 20:01

ComboFix4.txt 2011-10-31 18:34

.

Pre-Run: 34,040,606,720 bytes free

Post-Run: 33,988,587,520 bytes free

.

- - End Of File - - B774A7865F3C714FF5D82C2664706EE4

Link to post
Share on other sites

Yes, the only time I can open and see either of them is when the ethernet cable is unplugged. As soon as I plug the cable in, the browsers freeze, act like they are loading (loading cursor), then say they aren't responding. During this time, malwarebytes immediately says the respective browser is trying to ping malicious sites. If i close the browser process, svchost takes over on the malicious pings.

Everytime I look at firefox with the cable unplugged, it says a proxy is preventing the internet (well, it did this when it would load with the cable plugged in a few weeks ago, i don't know why i can't browse the internet suddenly).

Link to post
Share on other sites

Hi,

Run ComboFix again and let it update itself. Post back its log + fresh DDS logs. Are there any other systems connected to same device(s) like this system with symptoms? If so are those other systems having similar issues?

Link to post
Share on other sites

Just to note I'm reading with interest, having this same problem--ping.exe, browser (didn't realilze svhost.exe was doing it too). IE8 is looking corrupted, with black areas in the tool bars. Event log seems to show attempts to increase bandwith and TCP concurrent connections limit being hit. Infected on 11/7/11.

Link to post
Share on other sites

Just to note I'm reading with interest, having this same problem--ping.exe, browser (didn't realilze svhost.exe was doing it too). IE8 is looking corrupted, with black areas in the tool bars. Event log seems to show attempts to increase bandwith and TCP concurrent connections limit being hit. Infected on 11/7/11.

Hi,

It's recommended to create own topic for your issue if you believe it's malware related. Instructions given in this topic are meant for the topic owner only.

Link to post
Share on other sites

Hi,

It's recommended to create own topic for your issue if you believe it's malware related. Instructions given in this topic are meant for the topic owner only.

Understood. I'm curious to know, though, if this thing has or will have a name. Trying to research it on line, I don't see any recognition of it by, say Symantec (and my McAfee missed it, as did SpyBot S&D and Malwarebytes). What is this? Do you have some system of reporting it somewhere?

If you don't mind, I'm just watching (and will shut up now) to see how things go here. I will then indeed open my own topic and ask for help, assuming I don't find some other solution, which doesn't look likely at this point.

Link to post
Share on other sites

New logs with updated Combofix:

ComboFix 11-11-11.06 - Tsiphon 11/11/2011 15:14:32.6.4 - x64

Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1252.1.1033.18.4094.2078 [GMT -6:00]

Running from: c:\users\Tsiphon\Desktop\ComboFix.exe

AV: Kaspersky Anti-Virus *Disabled/Updated* {56547CC9-C9B2-849D-8FEF-A496150D6A06}

FW: COMODO Firewall *Enabled* {4D6F75E0-14AF-2E9E-AACD-24CDCF08AA2A}

SP: COMODO Defense+ *Disabled/Updated* {CE351521-78FA-2048-BB22-B68A4A5CA7EC}

SP: Kaspersky Anti-Virus *Disabled/Updated* {ED359D2D-EF88-8B13-B55F-9FE46E8A20BB}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\programdata\zeicbaa.tmp

.

.

((((((((((((((((((((((((( Files Created from 2011-10-11 to 2011-11-11 )))))))))))))))))))))))))))))))

.

.

2011-11-11 21:38 . 2011-11-11 21:38 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\temp

2011-11-11 21:38 . 2011-11-11 21:38 -------- d-----w- c:\users\Mcx1\AppData\Local\temp

2011-11-11 21:38 . 2011-11-11 21:38 -------- d-----w- c:\users\Guest\AppData\Local\temp

2011-11-11 21:38 . 2011-11-11 21:38 -------- d-----w- c:\users\Default\AppData\Local\temp

2011-11-08 20:10 . 2011-11-08 20:10 -------- d-----w- c:\program files (x86)\Common Files\Java

2011-11-08 20:09 . 2011-11-08 20:09 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2011-11-08 19:57 . 2011-11-08 20:06 -------- d-----w- c:\users\Tsiphon\AppData\Local\Solid State Networks

2011-11-08 03:40 . 2011-11-08 03:40 -------- d-----w- c:\windows\system32\Macromed

2011-11-02 23:46 . 2011-05-12 19:03 6144 ------w- c:\windows\system32\B85.tmp

2011-11-02 23:40 . 2011-05-12 19:03 6144 ------w- c:\windows\system32\7213.tmp

2011-11-02 23:30 . 2011-05-12 19:03 6144 ------w- c:\windows\system32\5060.tmp

2011-11-02 23:22 . 2011-05-12 19:03 6144 ------w- c:\windows\system32\1AC0.tmp

2011-11-02 23:16 . 2011-05-12 19:03 6144 ------w- c:\windows\system32\88FD.tmp

2011-11-02 23:11 . 2011-05-12 19:03 6144 ------w- c:\windows\system32\1821.tmp

2011-11-02 23:11 . 2011-11-02 23:11 -------- d-----w- c:\program files (x86)\Sophos

2011-11-01 18:56 . 2011-11-01 18:56 388096 ----a-r- c:\users\Tsiphon\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe

2011-10-31 07:06 . 2011-10-31 07:06 0 ----a-w- c:\windows\SysWow64\drivers\SET88DE.tmp

2011-10-31 07:06 . 2011-10-31 07:06 0 ----a-w- c:\windows\SysWow64\drivers\SET5C67.tmp

2011-10-31 07:06 . 2011-10-31 07:06 0 ----a-w- c:\windows\SysWow64\drivers\SET5AA1.tmp

2011-10-31 07:06 . 2011-10-31 07:06 0 ----a-w- c:\windows\SysWow64\drivers\SET584F.tmp

2011-10-31 07:06 . 2011-10-31 07:06 0 ----a-w- c:\windows\SysWow64\drivers\SET771.tmp

2011-10-31 07:06 . 2011-10-31 07:06 0 ----a-w- c:\windows\SysWow64\drivers\SET4E1.tmp

2011-10-31 07:06 . 2011-10-31 07:07 309320 ----a-w- c:\windows\SysWow64\drivers\TrufosAlt.sys

2011-10-31 07:06 . 2011-10-31 07:06 0 ----a-w- c:\windows\SysWow64\drivers\SETC86D.tmp

2011-10-31 07:05 . 2011-10-31 07:05 0 ----a-w- c:\windows\SysWow64\drivers\SET1747.tmp

2011-10-31 07:04 . 2011-10-31 07:04 0 ----a-w- c:\windows\SysWow64\drivers\SET3E2B.tmp

2011-10-31 07:04 . 2011-10-31 07:04 0 ----a-w- c:\windows\SysWow64\drivers\SET3C94.tmp

2011-10-31 07:04 . 2011-10-31 07:04 0 ----a-w- c:\windows\SysWow64\drivers\SET39E5.tmp

2011-10-31 07:04 . 2011-10-31 07:04 0 ----a-w- c:\windows\SysWow64\drivers\SET334F.tmp

2011-10-31 07:04 . 2011-10-31 07:04 0 ----a-w- c:\windows\SysWow64\drivers\SETDA09.tmp

2011-10-31 07:03 . 2011-10-31 07:03 0 ----a-w- c:\windows\SysWow64\drivers\SET432B.tmp

2011-10-31 07:03 . 2011-10-31 07:03 0 ----a-w- c:\windows\SysWow64\drivers\SET400F.tmp

2011-10-31 07:02 . 2011-10-31 07:02 0 ----a-w- c:\windows\SysWow64\drivers\SETB971.tmp

2011-10-31 07:02 . 2011-10-31 07:02 0 ----a-w- c:\windows\SysWow64\drivers\SETB6A2.tmp

2011-10-31 07:02 . 2011-10-31 07:02 0 ----a-w- c:\windows\SysWow64\drivers\SETAFBE.tmp

2011-10-31 06:58 . 2011-10-31 06:58 0 ----a-w- c:\windows\SysWow64\drivers\SETB450.tmp

2011-10-31 04:21 . 2011-10-31 04:21 -------- d-----w- c:\users\Tsiphon\AppData\Roaming\WinPatrol

2011-10-31 04:21 . 2011-10-31 04:21 -------- d-----w- c:\programdata\InstallMate

2011-10-31 04:21 . 2011-10-31 04:21 -------- d-----w- c:\program files (x86)\BillP Studios

2011-10-31 04:18 . 2011-11-02 08:48 -------- d-----w- c:\programdata\Comodo

2011-10-31 04:18 . 2011-10-31 04:18 -------- d-----w- c:\program files\COMODO

2011-10-31 04:17 . 2011-10-31 04:18 -------- d-----w- c:\programdata\Comodo Downloader

2011-10-29 08:24 . 2011-10-29 10:15 -------- d-----w- c:\users\Tsiphon\AppData\Roaming\Winamp

2011-10-28 22:54 . 2011-10-28 23:09 -------- d-----w- c:\program files (x86)\Eusing Free Registry Cleaner

2011-10-26 21:59 . 2011-10-26 21:59 -------- d-----w- c:\users\Tsiphon\AppData\Roaming\Malwarebytes

2011-10-26 21:59 . 2011-10-26 21:59 -------- d-----w- c:\programdata\Malwarebytes

2011-10-26 21:59 . 2011-10-27 02:50 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware

2011-10-26 21:59 . 2011-08-31 22:00 25416 ----a-w- c:\windows\system32\drivers\mbam.sys

2011-10-26 21:56 . 2011-10-26 21:56 -------- d-----w- c:\users\Tsiphon\AppData\Roaming\WTablet

2011-10-21 14:14 . 2011-10-07 04:16 8570192 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{FDC2EED1-71B5-48C1-ADD4-7D759D933147}\mpengine.dll

2011-10-13 22:18 . 2011-10-13 22:18 -------- d-----w- c:\program files\iPod

2011-10-13 22:18 . 2011-10-13 22:19 -------- d-----w- c:\program files\iTunes

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2011-11-08 20:10 . 2010-04-30 21:21 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll

2011-10-07 23:47 . 2011-10-07 23:47 93200 ----a-w- c:\windows\system32\drivers\inspect.sys

2011-10-07 23:47 . 2011-10-07 23:47 42224 ----a-w- c:\windows\system32\drivers\cmdhlp.sys

2011-10-07 23:47 . 2011-10-07 23:47 574216 ----a-w- c:\windows\system32\drivers\cmdGuard.sys

2011-10-07 23:47 . 2011-10-07 23:47 16528 ----a-w- c:\windows\system32\drivers\cmderd.sys

2011-10-07 23:47 . 2011-10-07 23:47 41200 ----a-w- c:\windows\system32\cmdcsr.dll

2011-10-07 23:47 . 2011-10-07 23:47 300200 ----a-w- c:\windows\SysWow64\guard32.dll

2011-10-07 23:47 . 2011-10-07 23:47 388280 ----a-w- c:\windows\system32\guard64.dll

2011-08-31 04:05 . 2011-08-31 04:05 96104 ----a-w- c:\windows\system32\dns-sd.exe

2011-08-31 04:05 . 2011-08-31 04:05 85864 ----a-w- c:\windows\system32\dnssd.dll

2011-08-31 04:05 . 2011-08-31 04:05 83816 ----a-w- c:\windows\SysWow64\dns-sd.exe

2011-08-31 04:05 . 2011-08-31 04:05 73064 ----a-w- c:\windows\SysWow64\dnssd.dll

.

.

------- Sigcheck -------

Note: Unsigned files aren't necessarily malware.

.

[7] 2008-07-19 . 437C1C0CB2A42EA20083F21E9CAEF461 . 646656 . . [6.0.6000.20537] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.20537_none_32359eb27623cc22\user32.dll

[7] 2008-07-19 . 296BA70E2A302E639CBD9E2A32DC65C4 . 646656 . . [6.0.6000.16438] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.16438_none_31ad02315d0545af\user32.dll

[-] 2008-01-19 . BC8872C0B1B4599D60857B9E6BB66E44 . 672256 . . [6.0.6001.18000] .. c:\windows\SysWOW64\user32.dll

[7] 2008-01-19 . 3D691030DBD3BD75DE1501BE54F0D425 . 648192 . . [6.0.6001.18000] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_33abb2175a1ab263\user32.dll

[7] 2006-11-02 . 00B53DCA0408CCD8F6BAF13994F6E3A0 . 646656 . . [6.0.6000.16386] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.16386_none_3174f01b5d2fa18f\user32.dll

.

((((((((((((((((((((((((((((( SnapShot_2011-11-09_07.10.30 )))))))))))))))))))))))))))))))))))))))))

.

+ 2009-05-15 06:45 . 2011-11-11 20:51 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat

- 2009-05-15 06:45 . 2011-11-02 22:11 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat

- 2010-09-28 04:48 . 2011-11-02 22:11 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Feeds Cache\index.dat

+ 2010-09-28 04:48 . 2011-11-11 20:51 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Feeds Cache\index.dat

+ 2008-07-19 07:24 . 2011-11-11 21:03 30354 c:\windows\system32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-4111605854-636613554-1496609690-1000_UserData.bin

- 2011-06-10 04:10 . 2011-11-08 20:04 62078 c:\windows\system32\config\systemprofile\AppData\Roaming\WTablet\Pen_Tablet.dat

+ 2011-06-10 04:10 . 2011-11-10 03:09 62078 c:\windows\system32\config\systemprofile\AppData\Roaming\WTablet\Pen_Tablet.dat

- 2008-07-19 06:58 . 2011-11-09 00:49 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2008-07-19 06:58 . 2011-11-11 20:59 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2008-07-19 06:58 . 2011-11-09 00:49 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

+ 2008-07-19 06:58 . 2011-11-11 20:59 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

- 2008-07-19 06:58 . 2011-11-09 00:49 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2008-07-19 06:58 . 2011-11-11 20:59 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2009-05-20 06:17 . 2011-11-11 21:04 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2009-05-20 06:17 . 2011-11-08 20:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2009-05-20 06:17 . 2011-11-11 21:04 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

- 2009-05-20 06:17 . 2011-11-08 20:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2011-11-11 20:51 . 2011-11-11 20:51 5120 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{E0F3F081-0CA6-11E1-B172-001D7D0BF8E1}.dat

+ 2011-11-11 20:51 . 2011-11-11 20:51 4608 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{E9396173-0CA6-11E1-B172-001D7D0BF8E1}.dat

+ 2011-11-11 20:51 . 2011-11-11 20:51 5632 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{E0F3F085-0CA6-11E1-B172-001D7D0BF8E1}.dat

+ 2011-11-11 20:51 . 2011-11-11 20:51 5632 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{E0F3F083-0CA6-11E1-B172-001D7D0BF8E1}.dat

+ 2011-11-11 20:51 . 2011-11-11 20:51 4608 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{E0F3F082-0CA6-11E1-B172-001D7D0BF8E1}.dat

- 2011-11-08 20:03 . 2011-11-08 20:03 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

+ 2011-11-08 20:03 . 2011-11-11 20:59 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

- 2011-11-08 20:03 . 2011-11-08 20:03 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

+ 2011-11-08 20:03 . 2011-11-11 20:59 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

+ 2011-10-26 01:38 . 2011-11-11 20:51 507904 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\PrivacIE\index.dat

- 2011-10-26 01:38 . 2011-11-02 22:11 507904 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\PrivacIE\index.dat

+ 2008-07-22 10:21 . 2011-11-11 20:51 360448 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2006-11-02 15:44 . 2011-11-11 21:03 142228 c:\windows\system32\WDI\BootPerformanceDiagnostics_SystemData.bin

- 2008-08-26 08:08 . 2011-11-08 20:10 493170 c:\windows\system32\perfh011.dat

+ 2008-08-26 08:08 . 2011-11-11 21:05 493170 c:\windows\system32\perfh011.dat

- 2006-11-02 12:46 . 2011-11-08 20:10 753588 c:\windows\system32\perfh009.dat

+ 2006-11-02 12:46 . 2011-11-11 21:05 753588 c:\windows\system32\perfh009.dat

- 2008-08-26 08:08 . 2011-11-08 20:10 162694 c:\windows\system32\perfc011.dat

+ 2008-08-26 08:08 . 2011-11-11 21:05 162694 c:\windows\system32\perfc011.dat

+ 2006-11-02 12:46 . 2011-11-11 21:05 162694 c:\windows\system32\perfc009.dat

- 2006-11-02 12:46 . 2011-11-08 20:10 162694 c:\windows\system32\perfc009.dat

- 2009-05-15 06:07 . 2011-11-08 20:03 262144 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat

+ 2009-05-15 06:07 . 2011-11-11 20:59 262144 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat

- 2008-07-22 10:21 . 2011-11-04 23:50 2473984 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

+ 2008-07-22 10:21 . 2011-11-11 20:51 2473984 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

- 2008-07-22 10:21 . 2011-11-04 23:50 1212416 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2008-07-22 10:21 . 2011-11-11 20:51 1212416 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

- 2011-06-11 06:21 . 2011-11-08 20:04 4194304 c:\windows\Debug\msmqlog.bin

+ 2011-06-11 06:21 . 2011-11-11 20:59 4194304 c:\windows\Debug\msmqlog.bin

+ 2006-11-02 12:35 . 2011-11-11 20:53 52174280 c:\windows\system32\mrt.exe

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 138240]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"AppleSyncNotifier"="c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-09-27 59240]

"DiscWizardMonitor.exe"="c:\program files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe" [2008-06-25 1325848]

"AcronisTimounterMonitor"="c:\program files (x86)\Seagate\DiscWizard\TimounterMonitor.exe" [2008-06-25 904768]

"AVP"="c:\program files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe" [2011-05-27 352976]

"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]

"QuickTime Task"="c:\program files (x86)\QuickTime Alternative\QTTask.exe" [2011-07-05 421888]

"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]

"WinPatrol"="c:\program files (x86)\BillP Studios\WinPatrol\winpatrol.exe" [2011-05-15 325512]

"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]

.

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"LightScribe Control Panel"="c:\program files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe" [2009-06-17 2363392]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"EnableLUA"= 0 (0x0)

"EnableUIADesktopToggle"= 0 (0x0)

"EnableLinkedConnections"= 1 (0x1)

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\klogon]

[bU]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WgaLogon]

[bU]

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]

"AppInit_DLLs"=c:\progra~2\KASPER~1\KASPER~2\mzvkbd3.dll c:\windows\SysWOW64\guard32.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]

"aux8"=wdmaud.drv

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]

"LogitechQuickCamRibbon"="c:\program files (x86)\Logitech\QuickCam\Quickcam.exe" /hide

"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe"

"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]

"DisableMonitoring"=dword:00000001

.

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]

R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-27 135664]

R3 AdobeActiveFileMonitor8.0;Adobe Active File Monitor V8;c:\program files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe [2009-10-09 169312]

R3 CamDrL64;Logitech QuickCam Pro 3000(PID_08B0); [x]

R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2008-08-06 79360]

R3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.SYS [x]

R3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.SYS [x]

R3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.SYS [x]

R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-27 135664]

R3 LVcKap64;Logitech AEC Driver; [x]

R3 LVPr2M64;Logitech LVPr2M64 Driver; [x]

R3 LVUSBS64;Logitech USB Monitor Filter; [x]

R3 MEMSWEEP2;MEMSWEEP2;c:\windows\system32\B85.tmp [x]

R3 PSSDK42;PSSDK42;c:\windows\system32\Drivers\pssdk42.sys [x]

R3 RivaTuner64;RivaTuner64;c:\program files (x86)\RivaTuner v2.09\RivaTuner64.sys [2008-07-19 19952]

R3 rt61x64;Ralink RT61 Wireless Driver for Windows Vista; [x]

R3 scramby_out;Scramby Output;c:\windows\system32\drivers\scramby_out.sys [x]

R3 TouchServicePen;Wacom Consumer Touch Service;c:\program files\Tablet\Pen\Pen_TouchService.exe [2010-10-13 487280]

R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]

R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\DRIVERS\wacmoumonitor.sys [x]

R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 1020768]

R3 X6va003;X6va003;c:\users\Tsiphon\AppData\Local\Temp\003F29A.tmp [x]

R4 BsMobileCS;BsMobileCS;c:\program files (x86)\IVT Corporation\BlueSoleil\BsMobileCS.exe [2010-03-09 143467]

R4 MSSQL$SOLARWINDS_ORION;SQL Server (SOLARWINDS_ORION); [x]

R4 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2010-03-25 490280]

R4 TomTomHOMEService;TomTomHOMEService;c:\program files (x86)\TomTom HOME 2\TomTomHOMEService.exe [2009-11-13 92008]

S0 BtHidBus;Bluetooth HID Bus Service;c:\windows\System32\Drivers\BtHidBus.sys [x]

S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]

S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [x]

S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [x]

S1 kl2;kl2;c:\windows\system32\DRIVERS\kl2.sys [x]

S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [x]

S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]

S2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x64.sys [x]

S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-08-31 366152]

S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]

S2 SgtSch2Svc;Seagate Scheduler2 Service;c:\program files (x86)\Common Files\Seagate\Schedule2\schedul2.exe [2008-06-25 605464]

S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-10-16 369256]

S2 TabletServicePen;TabletServicePen;c:\program files\Tablet\Pen\Pen_Tablet.exe [2010-10-13 5790064]

S3 btnetBUs;Bluetooth PAN Bus Service;c:\windows\system32\Drivers\btnetBus.sys [x]

S3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\System32\drivers\CT20XUT.SYS [x]

S3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\System32\drivers\CTEXFIFX.SYS [x]

S3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\System32\drivers\CTHWIUT.SYS [x]

S3 IvtBtBUs;IVT Bluetooth Bus Service;c:\windows\system32\Drivers\IvtBtBus.sys [x]

S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys [x]

S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]

S3 ScreamBAudioSvc;ScreamBee Audio;c:\windows\system32\drivers\ScreamingBAudio64.sys [x]

S3 VCSVADHWSer;Avnex Virtual Audio Device (WDM);c:\windows\system32\DRIVERS\vcsvad.sys [x]

.

.

--- Other Services/Drivers In Memory ---

.

*Deregistered* - PROCEXP141

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]

hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

iissvcs REG_MULTI_SZ w3svc was

apphost REG_MULTI_SZ apphostsvc

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]

2009-06-17 17:11 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe

.

Contents of the 'Scheduled Tasks' folder

.

2011-11-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-27 12:40]

.

2011-11-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-27 12:40]

.

.

--------- x86-64 -----------

.

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 660360]

"RtHDVCpl"="RAVCpl64.exe" [2008-02-13 5684736]

"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdSync.exe" [2006-11-02 225792]

"Seagate Scheduler2 Service"="c:\program files (x86)\Common Files\Seagate\Schedule2\schedhlp.exe" [2008-06-25 136472]

"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2011-10-20 9264456]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

"AppInit_DLLs"=c:\windows\System32\guard64.dll

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.yahoo.com/

IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000

TCP: DhcpNameServer = 192.168.1.1

CLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\browseui.dll

FF - ProfilePath - c:\users\Tsiphon\AppData\Roaming\Mozilla\Firefox\Profiles\h8pjtgv2.default\

FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/

FF - prefs.js: network.proxy.http - 127.0.0.1

FF - prefs.js: network.proxy.http_port - 53960

FF - prefs.js: network.proxy.type - 0

.

- - - - ORPHANS REMOVED - - - -

.

Toolbar-10 - (no file)

.

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Solarwinds Trap Service]

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\SolarWinds: Collector DataProcessor]

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Solarwinds: Job Broker]

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Solarwinds: Job Engine]

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Solarwinds: Job Engine v2]

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Solarwinds: Job Scheduler]

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Solarwinds: Job Scheduler v2]

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Solarwinds: Worker Process]

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Solarwinds: Worker Process v2]

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\MEMSWEEP2]

"ImagePath"="\??\c:\windows\system32\B85.tmp"

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\X6va003]

"ImagePath"="\??\c:\users\Tsiphon\AppData\Local\Temp\003F29A.tmp"

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]

@Denied: (2) (LocalSystem)

"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,

d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,9c,a2,f1,d4,15,82,c2,48,99,43,46,\

"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,

d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,9c,a2,f1,d4,15,82,c2,48,99,43,46,\

.

[HKEY_USERS\S-1-5-21-4111605854-636613554-1496609690-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]

@Allowed: (Read) (RestrictedCode)

"??"=hex:b0,24,0d,0e,50,c2,6b,70,02,29,1d,b9,9b,f3,6b,2f,2b,5d,22,b8,72,f1,89,

77,30,39,6a,87,2c,80,fe,83,ab,a8,68,9b,31,cd,34,b5,2e,58,6d,51,6f,3c,e1,3f,\

"??"=hex:de,c2,f1,00,6b,13,52,1e,8d,7b,f0,04,df,b8,e0,7f

.

[HKEY_USERS\S-1-5-21-4111605854-636613554-1496609690-1000\Software\SecuROM\License information*]

"datasecu"=hex:fa,84,73,12,ef,d2,44,36,38,4d,80,39,fc,50,df,aa,cd,eb,4b,10,d6,

0d,5b,f9,da,79,e0,3f,89,9a,b4,3c,4a,db,10,1e,e8,20,fd,88,02,da,16,3a,7a,b7,\

"rkeysecu"=hex:d0,71,9f,d7,18,0a,c6,cb,3e,d1,09,7e,f3,81,c3,2a

.

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows CE Services]

"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,

00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\

"CurrentPartnershipProtocol"=dword:00000003

"MinimumPartnershipProtocol"=dword:00000002

@=""

"EulaRequired"=dword:06010000

"DTPTNetworkType"="{0}"

"Dual-Home"=dword:00000001

"DisableCredentialSave"=dword:00000000

"RasTimeoutResponseWait"=dword:00000032

"RasTimeoutPause"=dword:00000005

"ConnectTypesAllowed"=dword:0000000a

"CheckPasswordTimeoutSeconds"=dword:00000014

"WaitV2TimeoutSeconds"=dword:00000004

"SerialPort"="Bluetooth"

"HasUsbDevice"=dword:00000000

"SerialBaudRate"=dword:0001c200

"DeviceType"=""

"DeviceOemInfo"=""

"DeviceVersion"=dword:04401504

"DeviceProcessorType"=dword:00000000

"DeviceProcessor"=""

"DisableIr"=dword:00000000

"GuestOnly"=dword:00000000

"MajorVersion"=dword:00000006

"MinorVersion"=dword:00000000

"InstalledDir"="c:\\Windows\\WindowsMobile"

.

[HKEY_LOCAL_MACHINE\software\Wow6432Node\Classes]

"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,

00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\

.

Completion time: 2011-11-11 15:53:26

ComboFix-quarantined-files.txt 2011-11-11 21:53

ComboFix2.txt 2011-11-09 07:16

ComboFix3.txt 2011-11-08 03:33

ComboFix4.txt 2011-11-06 20:01

ComboFix5.txt 2011-11-11 21:11

.

Pre-Run: 34,024,357,888 bytes free

Post-Run: 33,957,621,760 bytes free

.

- - End Of File - - 8DB6BC48EA183FA40962D8C560B3D33D

Link to post
Share on other sites

.

DDS (Ver_2011-08-26.01) - NTFSAMD64

Internet Explorer: 8.0.6001.19088 BrowserJavaVersion: 1.6.0_29

Run by Tsiphon at 15:54:01 on 2011-11-11

Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1252.1.1033.18.4094.1792 [GMT -6:00]

.

AV: Kaspersky Anti-Virus *Disabled/Updated* {56547CC9-C9B2-849D-8FEF-A496150D6A06}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

SP: Kaspersky Anti-Virus *Disabled/Updated* {ED359D2D-EF88-8B13-B55F-9FE46E8A20BB}

SP: COMODO Defense+ *Disabled/Updated* {CE351521-78FA-2048-BB22-B68A4A5CA7EC}

FW: COMODO Firewall *Enabled* {4D6F75E0-14AF-2E9E-AACD-24CDCF08AA2A}

.

============== Running Processes ===============

.

C:\Windows\system32\wininit.exe

C:\Windows\system32\lsm.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\nvvsvc.exe

C:\Windows\system32\svchost.exe -k rpcss

C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe

C:\Windows\system32\svchost.exe -k NetworkService

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k netsvcs

C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe

C:\Windows\system32\svchost.exe -k GPSvcGroup

C:\Windows\system32\SLsvc.exe

C:\Windows\system32\svchost.exe -k LocalService

C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe

C:\Windows\system32\nvvsvc.exe

C:\Windows\System32\spoolsv.exe

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

C:\Windows\system32\svchost.exe -k apphost

C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

C:\Windows\system32\taskeng.exe

C:\Windows\system32\Dwm.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\Windows\Explorer.EXE

C:\Windows\system32\mqsvc.exe

C:\Windows\System32\svchost.exe -k HPZ12

C:\Windows\System32\svchost.exe -k HPZ12

C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedul2.exe

C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

C:\Windows\system32\svchost.exe -k imgsvc

C:\Program Files\Tablet\Pen\Pen_Tablet.exe

C:\Program Files\Tablet\Pen\Pen_TabletUser.exe

C:\Windows\system32\svchost.exe -k iissvcs

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

C:\Windows\system32\SearchIndexer.exe

C:\Program Files\Tablet\Pen\Pen_Tablet.exe

C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe

C:\Windows\WindowsMobile\wmdc.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

C:\Windows\RAVCpl64.exe

C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedhlp.exe

C:\Windows\ehome\ehtray.exe

C:\Program Files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe

C:\Program Files (x86)\Seagate\DiscWizard\TimounterMonitor.exe

C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe

C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

C:\Windows\system32\wbem\unsecapp.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Windows\ehome\ehmsas.exe

C:\Windows\system32\svchost.exe -k WindowsMobile

C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe

C:\Program Files\Windows Media Player\wmpnetwk.exe

C:\Windows\SysWoW64\svchost.exe

C:\Windows\system32\conime.exe

C:\Windows\system32\SearchProtocolHost.exe

C:\Windows\system32\SearchFilterHost.exe

C:\Windows\SysWOW64\cmd.exe

C:\Windows\SysWOW64\cscript.exe

C:\Windows\system32\wbem\wmiprvse.exe

.

============== Pseudo HJT Report ===============

.

uStart Page = hxxp://www.yahoo.com/

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll

BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\ievkbd.dll

BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll

BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll

uRun: [ehTray.exe] C:\Windows\ehome\ehTray.exe

mRun: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe

mRun: [DiscWizardMonitor.exe] C:\Program Files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe

mRun: [AcronisTimounterMonitor] C:\Program Files (x86)\Seagate\DiscWizard\TimounterMonitor.exe

mRun: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe"

mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime Alternative\QTTask.exe" -atboottime

mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray

mRun: [WinPatrol] "C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe" -expressboot

mRun: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

dRun: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden

mPolicies-system: EnableLUA = 0 (0x0)

mPolicies-system: EnableUIADesktopToggle = 0 (0x0)

mPolicies-system: EnableLinkedConnections = 1 (0x1)

IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000

IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll

IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll

IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll

IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL

IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll

IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll

DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab

DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab

DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab

DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://l.yimg.com/jh/games/web_games/popcap/bejeweled2/popcaploader_v6.cab

DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://www.creative.com/softwareupdate/su2/ocx/15103/CTPID.cab

TCP: DhcpNameServer = 192.168.1.1

TCP: Interfaces\{B2707B3A-F1B2-4360-8B02-F14850833270} : DhcpNameServer = 192.168.1.1

Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll

AppInit_DLLs: C:\PROGRA~2\KASPER~1\KASPER~2\mzvkbd3.dll C:\Windows\SysWOW64\guard32.dll

SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll

mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"

BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

BHO-X64: AcroIEHelperStub - No File

BHO-X64: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll

BHO-X64: IEVkbdBHO Class: {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\ievkbd.dll

BHO-X64: IEVkbdBHO - No File

BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll

BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

BHO-X64: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

BHO-X64: FilterBHO Class: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll

BHO-X64: link filter bho - No File

mRun-x64: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe

mRun-x64: [DiscWizardMonitor.exe] C:\Program Files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe

mRun-x64: [AcronisTimounterMonitor] C:\Program Files (x86)\Seagate\DiscWizard\TimounterMonitor.exe

mRun-x64: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe"

mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime Alternative\QTTask.exe" -atboottime

mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray

mRun-x64: [WinPatrol] "C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe" -expressboot

mRun-x64: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

AppInit_DLLs-X64: C:\PROGRA~2\KASPER~1\KASPER~2\mzvkbd3.dll C:\Windows\SysWOW64\guard32.dll

SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll

.

================= FIREFOX ===================

.

FF - ProfilePath - C:\Users\Tsiphon\AppData\Roaming\Mozilla\Firefox\Profiles\h8pjtgv2.default\

FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/

FF - prefs.js: network.proxy.http - 127.0.0.1

FF - prefs.js: network.proxy.http_port - 53960

FF - prefs.js: network.proxy.type - 0

.

============= SERVICES / DRIVERS ===============

.

R0 BtHidBus;Bluetooth HID Bus Service;C:\Windows\system32\Drivers\BtHidBus.sys --> C:\Windows\system32\Drivers\BtHidBus.sys [?]

R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys --> C:\Windows\system32\Drivers\PxHlpa64.sys [?]

R1 cmdGuard;COMODO Internet Security Sandbox Driver;C:\Windows\system32\DRIVERS\cmdguard.sys --> C:\Windows\system32\DRIVERS\cmdguard.sys [?]

R1 cmdHlp;COMODO Internet Security Helper Driver;C:\Windows\system32\DRIVERS\cmdhlp.sys --> C:\Windows\system32\DRIVERS\cmdhlp.sys [?]

R1 kl2;kl2;C:\Windows\system32\DRIVERS\kl2.sys --> C:\Windows\system32\DRIVERS\kl2.sys [?]

R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\system32\DRIVERS\klim6.sys --> C:\Windows\system32\DRIVERS\klim6.sys [?]

R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-6-6 64952]

R2 cpuz135;cpuz135;\??\C:\Windows\system32\drivers\cpuz135_x64.sys --> C:\Windows\system32\drivers\cpuz135_x64.sys [?]

R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-10-26 366152]

R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2010-5-4 1153368]

R2 SgtSch2Svc;Seagate Scheduler2 Service;C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedul2.exe [2008-6-24 605464]

R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-10-16 369256]

R2 TabletServicePen;TabletServicePen;C:\Program Files\Tablet\Pen\Pen_Tablet.exe [2011-5-25 5790064]

R3 btnetBUs;Bluetooth PAN Bus Service;C:\Windows\system32\Drivers\btnetBus.sys --> C:\Windows\system32\Drivers\btnetBus.sys [?]

R3 CT20XUT.SYS;CT20XUT.SYS;C:\Windows\system32\drivers\CT20XUT.SYS --> C:\Windows\system32\drivers\CT20XUT.SYS [?]

R3 CTEXFIFX.SYS;CTEXFIFX.SYS;C:\Windows\system32\drivers\CTEXFIFX.SYS --> C:\Windows\system32\drivers\CTEXFIFX.SYS [?]

R3 CTHWIUT.SYS;CTHWIUT.SYS;C:\Windows\system32\drivers\CTHWIUT.SYS --> C:\Windows\system32\drivers\CTHWIUT.SYS [?]

R3 IvtBtBUs;IVT Bluetooth Bus Service;C:\Windows\system32\Drivers\IvtBtBus.sys --> C:\Windows\system32\Drivers\IvtBtBus.sys [?]

R3 klmouflt;Kaspersky Lab KLMOUFLT;C:\Windows\system32\DRIVERS\klmouflt.sys --> C:\Windows\system32\DRIVERS\klmouflt.sys [?]

R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]

R3 ScreamBAudioSvc;ScreamBee Audio;C:\Windows\system32\drivers\ScreamingBAudio64.sys --> C:\Windows\system32\drivers\ScreamingBAudio64.sys [?]

R3 VCSVADHWSer;Avnex Virtual Audio Device (WDM);C:\Windows\system32\DRIVERS\vcsvad.sys --> C:\Windows\system32\DRIVERS\vcsvad.sys [?]

S2 AVP;Kaspersky Anti-Virus Service;C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe [2010-7-1 352976]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]

S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]

S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-1-27 135664]

S3 AdobeActiveFileMonitor8.0;Adobe Active File Monitor V8;C:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe [2009-10-9 169312]

S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2008-8-6 79360]

S3 CT20XUT;CT20XUT;C:\Windows\system32\drivers\CT20XUT.SYS --> C:\Windows\system32\drivers\CT20XUT.SYS [?]

S3 CTEXFIFX;CTEXFIFX;C:\Windows\system32\drivers\CTEXFIFX.SYS --> C:\Windows\system32\drivers\CTEXFIFX.SYS [?]

S3 CTHWIUT;CTHWIUT;C:\Windows\system32\drivers\CTHWIUT.SYS --> C:\Windows\system32\drivers\CTHWIUT.SYS [?]

S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-1-27 135664]

S3 MEMSWEEP2;MEMSWEEP2;\??\C:\Windows\system32\B85.tmp --> C:\Windows\system32\B85.tmp [?]

S3 PerfHost;Performance Counter DLL Host;C:\Windows\SysWOW64\perfhost.exe [2008-7-22 19968]

S3 PSSDK42;PSSDK42;\??\C:\Windows\system32\Drivers\pssdk42.sys --> C:\Windows\system32\Drivers\pssdk42.sys [?]

S3 RivaTuner64;RivaTuner64;C:\Program Files (x86)\RivaTuner v2.09\RivaTuner64.sys [2008-4-28 19952]

S3 scramby_out;Scramby Output;C:\Windows\system32\drivers\scramby_out.sys --> C:\Windows\system32\drivers\scramby_out.sys [?]

S3 TouchServicePen;Wacom Consumer Touch Service;C:\Program Files\Tablet\Pen\Pen_TouchService.exe [2011-5-25 487280]

S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]

S3 wacmoumonitor;Wacom Mode Helper;C:\Windows\system32\DRIVERS\wacmoumonitor.sys --> C:\Windows\system32\DRIVERS\wacmoumonitor.sys [?]

S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-3-18 1020768]

S4 BsMobileCS;BsMobileCS;C:\Program Files (x86)\IVT Corporation\BlueSoleil\BsMobileCS.exe [2010-3-9 143467]

S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2009-3-24 93184]

S4 MSSQL$SOLARWINDS_ORION;SQL Server (SOLARWINDS_ORION); [x]

S4 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe [2010-3-25 490280]

S4 TomTomHOMEService;TomTomHOMEService;C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe [2009-11-13 92008]

.

=============== File Associations ===============

.

JSEFile=C:\Windows\SysWOW64\WScript.exe "%1" %*

.

=============== Created Last 30 ================

.

2011-11-11 21:11:18 -------- d-----w- C:\ComboFix

2011-11-08 20:09:20 414368 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl

2011-11-08 19:57:55 -------- d-----w- C:\Users\Tsiphon\AppData\Local\Solid State Networks

2011-11-06 19:03:56 98816 ----a-w- C:\Windows\sed.exe

2011-11-06 19:03:56 518144 ----a-w- C:\Windows\SWREG.exe

2011-11-06 19:03:56 256000 ----a-w- C:\Windows\PEV.exe

2011-11-06 19:03:56 208896 ----a-w- C:\Windows\MBR.exe

2011-11-02 23:46:30 6144 ------w- C:\Windows\System32\B85.tmp

2011-11-02 23:40:23 6144 ------w- C:\Windows\System32\7213.tmp

2011-11-02 23:30:25 6144 ------w- C:\Windows\System32\5060.tmp

2011-11-02 23:22:41 6144 ------w- C:\Windows\System32\1AC0.tmp

2011-11-02 23:16:36 6144 ------w- C:\Windows\System32\88FD.tmp

2011-11-02 23:11:45 6144 ------w- C:\Windows\System32\1821.tmp

2011-11-02 23:11:14 -------- d-----w- C:\Program Files (x86)\Sophos

2011-11-01 18:56:45 388096 ----a-r- C:\Users\Tsiphon\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe

2011-10-31 07:06:56 0 ----a-w- C:\Windows\SysWow64\drivers\SET88DE.tmp

2011-10-31 07:06:45 0 ----a-w- C:\Windows\SysWow64\drivers\SET5C67.tmp

2011-10-31 07:06:44 0 ----a-w- C:\Windows\SysWow64\drivers\SET5AA1.tmp

2011-10-31 07:06:44 0 ----a-w- C:\Windows\SysWow64\drivers\SET584F.tmp

2011-10-31 07:06:23 0 ----a-w- C:\Windows\SysWow64\drivers\SET771.tmp

2011-10-31 07:06:22 0 ----a-w- C:\Windows\SysWow64\drivers\SET4E1.tmp

2011-10-31 07:06:07 309320 ----a-w- C:\Windows\SysWow64\drivers\TrufosAlt.sys

2011-10-31 07:06:07 0 ----a-w- C:\Windows\SysWow64\drivers\SETC86D.tmp

2011-10-31 07:05:21 0 ----a-w- C:\Windows\SysWow64\drivers\SET1747.tmp

2011-10-31 07:04:26 0 ----a-w- C:\Windows\SysWow64\drivers\SET3E2B.tmp

2011-10-31 07:04:25 0 ----a-w- C:\Windows\SysWow64\drivers\SET3C94.tmp

2011-10-31 07:04:25 0 ----a-w- C:\Windows\SysWow64\drivers\SET39E5.tmp

2011-10-31 07:04:23 0 ----a-w- C:\Windows\SysWow64\drivers\SET334F.tmp

2011-10-31 07:04:00 0 ----a-w- C:\Windows\SysWow64\drivers\SETDA09.tmp

2011-10-31 07:03:22 0 ----a-w- C:\Windows\SysWow64\drivers\SET432B.tmp

2011-10-31 07:03:21 0 ----a-w- C:\Windows\SysWow64\drivers\SET400F.tmp

2011-10-31 07:02:46 0 ----a-w- C:\Windows\SysWow64\drivers\SETB971.tmp

2011-10-31 07:02:46 0 ----a-w- C:\Windows\SysWow64\drivers\SETB6A2.tmp

2011-10-31 07:02:44 0 ----a-w- C:\Windows\SysWow64\drivers\SETAFBE.tmp

2011-10-31 06:58:23 0 ----a-w- C:\Windows\SysWow64\drivers\SETB450.tmp

2011-10-31 04:21:13 -------- d-----w- C:\Users\Tsiphon\AppData\Roaming\WinPatrol

2011-10-31 04:21:03 -------- d-----w- C:\ProgramData\InstallMate

2011-10-31 04:21:03 -------- d-----w- C:\Program Files (x86)\BillP Studios

2011-10-31 04:18:21 -------- d-----w- C:\ProgramData\Comodo

2011-10-31 04:18:17 -------- d-----w- C:\Program Files\COMODO

2011-10-31 04:17:25 -------- d-----w- C:\ProgramData\Comodo Downloader

2011-10-28 22:54:51 -------- d-----w- C:\Program Files (x86)\Eusing Free Registry Cleaner

2011-10-26 21:59:25 -------- d-----w- C:\Users\Tsiphon\AppData\Roaming\Malwarebytes

2011-10-26 21:59:20 -------- d-----w- C:\ProgramData\Malwarebytes

2011-10-26 21:59:16 25416 ----a-w- C:\Windows\System32\drivers\mbam.sys

2011-10-26 21:59:16 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware

2011-10-26 21:56:52 -------- d-----w- C:\Users\Tsiphon\AppData\Roaming\WTablet

2011-10-21 14:14:24 8570192 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FDC2EED1-71B5-48C1-ADD4-7D759D933147}\mpengine.dll

2011-10-13 22:18:09 -------- d-----w- C:\Program Files\iPod

2011-10-13 22:18:07 -------- d-----w- C:\Program Files\iTunes

.

==================== Find3M ====================

.

2011-11-08 20:10:35 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll

2011-10-07 23:47:50 42224 ----a-w- C:\Windows\System32\drivers\cmdhlp.sys

2011-10-07 23:47:48 574216 ----a-w- C:\Windows\System32\drivers\cmdGuard.sys

2011-10-07 23:47:48 16528 ----a-w- C:\Windows\System32\drivers\cmderd.sys

2011-10-07 23:47:14 41200 ----a-w- C:\Windows\System32\cmdcsr.dll

2011-10-07 23:47:12 300200 ----a-w- C:\Windows\SysWow64\guard32.dll

2011-10-07 23:47:10 388280 ----a-w- C:\Windows\System32\guard64.dll

2011-08-31 04:05:32 96104 ----a-w- C:\Windows\System32\dns-sd.exe

2011-08-31 04:05:32 85864 ----a-w- C:\Windows\System32\dnssd.dll

2011-08-31 04:05:04 83816 ----a-w- C:\Windows\SysWow64\dns-sd.exe

2011-08-31 04:05:04 73064 ----a-w- C:\Windows\SysWow64\dnssd.dll

.

============= FINISH: 15:55:09.85 ===============

Link to post
Share on other sites

Please download MiniToolBox, save it to your desktop and run it.

Checkmark the following checkboxes:

  • Flush DNS
  • Report IE Proxy Settings
  • Reset IE Proxy Settings
  • Report FF Proxy Settings
  • Reset FF Proxy Settings
  • List content of Hosts
  • List IP configuration
  • List Winsock Entries
  • List last 10 Event Viewer log
  • List Users, Partitions and Memory size.

Click Go and post the result (Result.txt). A copy of Result.txt will be saved in the same directory the tool is run.

Note: When using "Reset FF Proxy Settings" option Firefox should be closed.

Link to post
Share on other sites

The first run without the ethernet plugged in is below. Attached is the second run with the ethernet plugged in, since I noticed the programs log said it was trying to ping sites.

MiniToolBox by Farbar

Ran by Tsiphon (administrator) on 12-11-2011 at 16:06:42

Windows Vista Ultimate Service Pack 1 (X64)

***************************************************************************

========================= Flush DNS: ===================================

Windows IP Configuration

Could not flush the DNS Resolver Cache: Function failed during execution.

========================= IE Proxy Settings: ==============================

Proxy is not enabled.

No Proxy Server is set.

"Reset IE Proxy Settings": IE Proxy Settings were reset.

========================= FF Proxy Settings: ==============================

"network.proxy.http", "127.0.0.1"

"network.proxy.http_port", 53960

"network.proxy.no_proxies_on", ""

"network.proxy.type", 1

"Reset FF Proxy Settings": Firefox Proxy settings were reset.

========================= Hosts content: =================================

127.0.0.1 localhost

========================= IP Configuration: ================================

# ----------------------------------

# IPv4 Configuration

# ----------------------------------

pushd interface ipv4

reset

set global

popd

# End of IPv4 configuration

Windows IP Configuration

Host Name . . . . . . . . . . . . : Tsiphon-PC

Primary Dns Suffix . . . . . . . :

Node Type . . . . . . . . . . . . : Broadcast

IP Routing Enabled. . . . . . . . : No

WINS Proxy Enabled. . . . . . . . : No

Ethernet adapter Local Area Connection 2:

Media State . . . . . . . . . . . : Media disconnected

Connection-specific DNS Suffix . :

Description . . . . . . . . . . . : Realtek RTL8168B/8111B Family PCI-E Gigabit Ethernet NIC (NDIS 6.0) #2

Physical Address. . . . . . . . . : 00-1D-7D-0B-F9-00

DHCP Enabled. . . . . . . . . . . : Yes

Autoconfiguration Enabled . . . . : Yes

Ethernet adapter Local Area Connection:

Media State . . . . . . . . . . . : Media disconnected

Connection-specific DNS Suffix . :

Description . . . . . . . . . . . : Realtek RTL8168B/8111B Family PCI-E Gigabit Ethernet NIC (NDIS 6.0)

Physical Address. . . . . . . . . : 00-1D-7D-0B-F8-E1

DHCP Enabled. . . . . . . . . . . : Yes

Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Local Area Connection* 6:

Media State . . . . . . . . . . . : Media disconnected

Connection-specific DNS Suffix . :

Description . . . . . . . . . . . : isatap.{09CF76A3-2DCA-454D-89DF-76F42DD0BA58}

Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0

DHCP Enabled. . . . . . . . . . . : No

Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Local Area Connection* 9:

Media State . . . . . . . . . . . : Media disconnected

Connection-specific DNS Suffix . :

Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface

Physical Address. . . . . . . . . : 02-00-54-55-4E-01

DHCP Enabled. . . . . . . . . . . : No

Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Local Area Connection* 15:

Media State . . . . . . . . . . . : Media disconnected

Connection-specific DNS Suffix . :

Description . . . . . . . . . . . : 6TO4 Adapter

Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0

DHCP Enabled. . . . . . . . . . . : No

Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Local Area Connection* 19:

Media State . . . . . . . . . . . : Media disconnected

Connection-specific DNS Suffix . :

Description . . . . . . . . . . . : isatap.{B2707B3A-F1B2-4360-8B02-F14850833270}

Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0

DHCP Enabled. . . . . . . . . . . : No

Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Local Area Connection* 22:

Media State . . . . . . . . . . . : Media disconnected

Connection-specific DNS Suffix . :

Description . . . . . . . . . . . : 6TO4 Adapter

Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0

DHCP Enabled. . . . . . . . . . . : No

Autoconfiguration Enabled . . . . : Yes

Server: UnKnown

Address: 127.0.0.1

Ping request could not find host google.com. Please check the name and try again.

Server: UnKnown

Address: 127.0.0.1

Ping request could not find host yahoo.com. Please check the name and try again.

Pinging 127.0.0.1 with 32 bytes of data:

Reply from 127.0.0.1: bytes=32 time=2ms TTL=128

Reply from 127.0.0.1: bytes=32 time=1ms TTL=128

Ping statistics for 127.0.0.1:

Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

Minimum = 1ms, Maximum = 2ms, Average = 1ms

===========================================================================

Interface List

9 ...00 1d 7d 0b f9 00 ...... Realtek RTL8168B/8111B Family PCI-E Gigabit Ethernet NIC (NDIS 6.0) #2

8 ...00 1d 7d 0b f8 e1 ...... Realtek RTL8168B/8111B Family PCI-E Gigabit Ethernet NIC (NDIS 6.0)

1 ........................... Software Loopback Interface 1

31 ...00 00 00 00 00 00 00 e0 isatap.{09CF76A3-2DCA-454D-89DF-76F42DD0BA58}

10 ...02 00 54 55 4e 01 ...... Teredo Tunneling Pseudo-Interface

20 ...00 00 00 00 00 00 00 e0 6TO4 Adapter

32 ...00 00 00 00 00 00 00 e0 isatap.{B2707B3A-F1B2-4360-8B02-F14850833270}

33 ...00 00 00 00 00 00 00 e0 6TO4 Adapter

===========================================================================

IPv4 Route Table

===========================================================================

Active Routes:

Network Destination Netmask Gateway Interface Metric

127.0.0.0 255.0.0.0 On-link 127.0.0.1 306

127.0.0.1 255.255.255.255 On-link 127.0.0.1 306

127.255.255.255 255.255.255.255 On-link 127.0.0.1 306

224.0.0.0 240.0.0.0 On-link 127.0.0.1 306

255.255.255.255 255.255.255.255 On-link 127.0.0.1 306

===========================================================================

Persistent Routes:

None

IPv6 Route Table

===========================================================================

Active Routes:

If Metric Network Destination Gateway

1 306 ::1/128 On-link

1 306 ff00::/8 On-link

===========================================================================

Persistent Routes:

None

========================= Winsock entries =====================================

Catalog5 01 C:\Windows\SysWOW64\mswsock.dll [223232] (Microsoft Corporation)

Catalog5 02 C:\Windows\SysWOW64\napinsp.dll [50176] (Microsoft Corporation)

Catalog5 03 C:\Windows\SysWOW64\pnrpnsp.dll [62464] (Microsoft Corporation)

Catalog5 04 C:\Windows\SysWOW64\pnrpnsp.dll [62464] (Microsoft Corporation)

Catalog5 05 C:\Windows\SysWOW64\mswsock.dll [223232] (Microsoft Corporation)

Catalog5 06 C:\Windows\SysWOW64\winrnr.dll [19968] (Microsoft Corporation)

Catalog5 07 C:\Windows\SysWOW64\wshbth.dll [34304] (Microsoft Corporation)

Catalog5 08 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)

Catalog9 01 C:\Windows\SysWOW64\mswsock.dll [223232] (Microsoft Corporation)

Catalog9 02 C:\Windows\SysWOW64\mswsock.dll [223232] (Microsoft Corporation)

Catalog9 03 C:\Windows\SysWOW64\mswsock.dll [223232] (Microsoft Corporation)

Catalog9 04 C:\Windows\SysWOW64\mswsock.dll [223232] (Microsoft Corporation)

Catalog9 05 C:\Windows\SysWOW64\mswsock.dll [223232] (Microsoft Corporation)

Catalog9 06 C:\Windows\SysWOW64\mswsock.dll [223232] (Microsoft Corporation)

Catalog9 07 C:\Windows\SysWOW64\mswsock.dll [223232] (Microsoft Corporation)

Catalog9 08 C:\Windows\SysWOW64\mswsock.dll [223232] (Microsoft Corporation)

Catalog9 09 C:\Windows\SysWOW64\mswsock.dll [223232] (Microsoft Corporation)

Catalog9 10 C:\Windows\SysWOW64\mswsock.dll [223232] (Microsoft Corporation)

Catalog9 11 C:\Windows\SysWOW64\mswsock.dll [223232] (Microsoft Corporation)

x64-Catalog5 01 mswsock.dll [File Not found] ()

x64-Catalog5 02 C:\Windows\System32\napinsp.dll [62976] (Microsoft Corporation)

x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [78848] (Microsoft Corporation)

x64-Catalog5 04 C:\Windows\System32\pnrpnsp.dll [78848] (Microsoft Corporation)

x64-Catalog5 05 mswsock.dll [File Not found] ()

x64-Catalog5 06 C:\Windows\System32\winrnr.dll [27648] (Microsoft Corporation)

x64-Catalog5 07 C:\Windows\System32\wshbth.dll [42496] (Microsoft Corporation)

x64-Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [132968] (Apple Inc.)

x64-Catalog9 01 mswsock.dll [File Not found] ()

x64-Catalog9 02 mswsock.dll [File Not found] ()

x64-Catalog9 03 mswsock.dll [File Not found] ()

x64-Catalog9 04 mswsock.dll [File Not found] ()

x64-Catalog9 05 mswsock.dll [File Not found] ()

x64-Catalog9 06 mswsock.dll [File Not found] ()

x64-Catalog9 07 mswsock.dll [File Not found] ()

x64-Catalog9 08 mswsock.dll [File Not found] ()

x64-Catalog9 09 mswsock.dll [File Not found] ()

x64-Catalog9 10 mswsock.dll [File Not found] ()

x64-Catalog9 11 mswsock.dll [File Not found] ()

========================= Event log errors: ===============================

Application errors:

==================

Error: (11/12/2011 03:59:24 PM) (Source: MSMQ) (User: )

Description: Message Queuing failed to bind to port 1801. The port may already be bound to another process. Make sure that the port is free and try to start Message Queuing again. If this problem arises during setup, you must free the port and run setup again.

Error: (11/12/2011 03:59:24 PM) (Source: MSMQ) (User: )

Description: Message Queuing failed to bind to port 1801. The port may already be bound to another process. Make sure that the port is free and try to start Message Queuing again. If this problem arises during setup, you must free the port and run setup again.

Error: (11/11/2011 05:31:46 PM) (Source: MSMQ) (User: )

Description: Message Queuing failed to bind to port 1801. The port may already be bound to another process. Make sure that the port is free and try to start Message Queuing again. If this problem arises during setup, you must free the port and run setup again.

Error: (11/11/2011 05:31:46 PM) (Source: MSMQ) (User: )

Description: Message Queuing failed to bind to port 1801. The port may already be bound to another process. Make sure that the port is free and try to start Message Queuing again. If this problem arises during setup, you must free the port and run setup again.

Error: (11/11/2011 03:04:03 PM) (Source: Windows Search Service) (User: )

Description: The entry <C:\USERS\TSIPHON\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\H8PJTGV2.DEFAULT\CACHE\9> in the hash map cannot be updated.

Context: Application, SystemIndex Catalog

Details:

A device attached to the system is not functioning. (0x8007001f)

Error: (11/11/2011 03:04:03 PM) (Source: Windows Search Service) (User: )

Description: The entry <C:\USERS\TSIPHON\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\H8PJTGV2.DEFAULT\CACHE\9> in the hash map cannot be updated.

Context: Application, SystemIndex Catalog

Details:

A device attached to the system is not functioning. (0x8007001f)

Error: (11/11/2011 03:04:03 PM) (Source: Windows Search Service) (User: )

Description: The entry <C:\USERS\TSIPHON\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\H8PJTGV2.DEFAULT\CACHE\8> in the hash map cannot be updated.

Context: Application, SystemIndex Catalog

Details:

A device attached to the system is not functioning. (0x8007001f)

Error: (11/11/2011 03:04:03 PM) (Source: Windows Search Service) (User: )

Description: The entry <C:\USERS\TSIPHON\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\H8PJTGV2.DEFAULT\CACHE\8> in the hash map cannot be updated.

Context: Application, SystemIndex Catalog

Details:

A device attached to the system is not functioning. (0x8007001f)

Error: (11/11/2011 03:04:03 PM) (Source: Windows Search Service) (User: )

Description: The entry <C:\USERS\TSIPHON\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\H8PJTGV2.DEFAULT\CACHE\7> in the hash map cannot be updated.

Context: Application, SystemIndex Catalog

Details:

A device attached to the system is not functioning. (0x8007001f)

Error: (11/11/2011 03:04:03 PM) (Source: Windows Search Service) (User: )

Description: The entry <C:\USERS\TSIPHON\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\H8PJTGV2.DEFAULT\CACHE\7> in the hash map cannot be updated.

Context: Application, SystemIndex Catalog

Details:

A device attached to the system is not functioning. (0x8007001f)

System errors:

=============

Error: (11/12/2011 04:03:08 PM) (Source: Service Control Manager) (User: )

Description: Beep

i8042prt

speedfan

Error: (11/12/2011 04:03:08 PM) (Source: Service Control Manager) (User: )

Description: Diagnostic Service Host

Error: (11/12/2011 03:59:48 PM) (Source: Service Control Manager) (User: )

Description: Internet Connection Sharing (ICS)Remote Access Connection Manager%%1058

Error: (11/12/2011 03:59:48 PM) (Source: Service Control Manager) (User: )

Description: Computer BrowserServer%%1058

Error: (11/12/2011 03:59:25 PM) (Source: Print) (User: SYSTEM)

Description: The print spooler failed to share printer HP Photosmart C3100 series with shared resource name HP Photosmart C3100 series. Error 2114. The printer cannot be used by others on the network.

Error: (11/12/2011 03:59:09 PM) (Source: HTTP) (User: )

Description: \Device\Http\ReqQueueKerberos

Error: (11/11/2011 05:35:43 PM) (Source: Service Control Manager) (User: )

Description: Beep

i8042prt

speedfan

Error: (11/11/2011 05:35:43 PM) (Source: Service Control Manager) (User: )

Description: Diagnostic Service Host

Error: (11/11/2011 05:32:40 PM) (Source: Service Control Manager) (User: )

Description: 30000Mcx2Svc

Error: (11/11/2011 05:32:04 PM) (Source: Service Control Manager) (User: )

Description: Internet Connection Sharing (ICS)Remote Access Connection Manager%%1058

Microsoft Office Sessions:

=========================

Error: (11/09/2009 08:12:16 AM) (Source: Microsoft Office 12 Sessions)(User: )

Description: ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.6500.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 3 seconds with 0 seconds of active time. This session ended with a crash.

Error: (07/12/2009 02:03:08 AM) (Source: Microsoft Office 12 Sessions)(User: )

Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6504.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 4 seconds with 0 seconds of active time. This session ended with a crash.

Error: (07/04/2009 02:09:17 AM) (Source: Microsoft Office 12 Sessions)(User: )

Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6504.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 1 seconds with 0 seconds of active time. This session ended with a crash.

Error: (07/04/2009 02:05:55 AM) (Source: Microsoft Office 12 Sessions)(User: )

Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6504.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 160 seconds with 0 seconds of active time. This session ended with a crash.

Error: (07/04/2009 02:03:09 AM) (Source: Microsoft Office 12 Sessions)(User: )

Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6504.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 117 seconds with 0 seconds of active time. This session ended with a crash.

Error: (07/04/2009 01:10:53 AM) (Source: Microsoft Office 12 Sessions)(User: )

Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6504.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 8 seconds with 0 seconds of active time. This session ended with a crash.

Error: (05/15/2009 01:45:32 PM) (Source: Microsoft Office 12 Sessions)(User: )

Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6423.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 4 seconds with 0 seconds of active time. This session ended with a crash.

========================= Memory info: ===================================

Percentage of memory in use: 45%

Total physical RAM: 4093.58 MB

Available physical RAM: 2231.01 MB

Total Pagefile: 8376.26 MB

Available Pagefile: 6392.98 MB

Total Virtual: 4095.88 MB

Available Virtual: 4007.1 MB

========================= Partitions: =====================================

2 Drive c: () (Fixed) (Total:465.76 GB) (Free:31.72 GB) NTFS

3 Drive d: (PRESARIO) (Fixed) (Total:149.05 GB) (Free:0.87 GB) NTFS

5 Drive f: (Second Disk) (Fixed) (Total:465.76 GB) (Free:2.19 GB) NTFS

6 Drive h: (JEROD DRIVE) (Removable) (Total:3.73 GB) (Free:1.41 GB) FAT32

========================= Users: ========================================

User accounts for \\TSIPHON-PC

Administrator Guest Mcx1

Tsiphon

**** End of log ****

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
 Share

  • Recently Browsing   0 members

    • No registered users viewing this page.

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.