1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Inactive avast keeps reporting pws:win32/zbot.r

Discussion in 'Malware and Virus Removal Archive' started by dogtag, 2010/01/09.

  1. 2010/01/09
    dogtag

    dogtag Inactive Thread Starter

    Joined:
    2008/08/17
    Messages:
    31
    Likes Received:
    0
    [Inactive] avast keeps reporting pws:win32/zbot.r

    Hi I have a problem with constantly poping up malware detections from avast and windows securtiy centre reporting malware. Those programs however are unable to remove the infected files. This is my little brothers laptop and I have instantly deinstalled P2P software and urged him not to use it in the future.

    I hope someone can help me.
    Here are the HiJackthis log and panda active scan log:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 16:45:23, on 09/01/2010
    Platform: Windows Vista (WinNT 6.00.1904)
    MSIE: Internet Explorer v7.00 (7.00.6000.16945)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Alwil Software\Avast4\ashDisp.exe
    C:\Program Files\Microsoft Security Essentials\msseces.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Windows\system32\wuauclt.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
    C:\Program Files\iTunes\iTunes.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceHelper.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\distnoted.exe
    C:\Users\Allan\Downloads\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: iPhone OS 3 Toolbar - {74714d77-1695-4e73-a98e-25cb374f46b4} - C:\Program Files\iPhone_OS_3\tbiPho.dll
    F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe,userinit.exe,
    O1 - Hosts: ::1 localhost
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL
    O2 - BHO: iPhone OS 3 Toolbar - {74714d77-1695-4e73-a98e-25cb374f46b4} - C:\Program Files\iPhone_OS_3\tbiPho.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL
    O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
    O3 - Toolbar: iPhone OS 3 Toolbar - {74714d77-1695-4e73-a98e-25cb374f46b4} - C:\Program Files\iPhone_OS_3\tbiPho.dll
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [MSSE] "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKUS\S-1-5-18\..\Run: [RegistryMonitor1] "C:\Windows\TEMP\acxc.tmp\svchost.exe" (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [RegistryMonitor1] "C:\Windows\TEMP\acxc.tmp\svchost.exe" (User 'Default user')
    O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
    O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
    O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
    O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office14\EXCEL.EXE/3000
    O8 - Extra context menu item: Se&nd to OneNote - res:///105
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
    O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
    O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O13 - Gopher Prefix:
    O16 - DPF: {40F576AD-8680-4F9E-9490-99D069CD665F} (System Requirements Lab Class) - http://srtest-cdn.systemrequirementslab.com.s3.amazonaws.com/bin/sysreqlabdetect.cab
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Windows\System32\TuneUpDefragService.exe
    O23 - Service: @%SystemRoot%\System32\TUProgSt.exe,-1 (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\Windows\System32\TUProgSt.exe

    --
    End of file - 7348 bytes


    ;***********************************************************************************************************************************************************************************
    ANALYSIS: 2010-01-09 16:42:20
    PROTECTIONS: 2
    MALWARE: 2
    SUSPECTS: 1
    ;***********************************************************************************************************************************************************************************
    PROTECTIONS
    Description Version Active Updated
    ;===================================================================================================================================================================================
    Microsoft Security Essentials 2.0.6212.0 Yes Yes
    avast! antivirus 4.8.1368 [VPS 100108-1] 4.8.1368 Yes Yes
    ;===================================================================================================================================================================================
    MALWARE
    Id Description Type Active Severity Disinfectable Disinfected Location
    ;===================================================================================================================================================================================
    04779562 trj/sinowal.wos Virus/Trojan No 1 Yes No c:\windows\system32\lowsec
    05821561 Trj/Sinowal.DW Virus/Trojan No 1 Yes No c:\windows\temp\rrnt.tmp\svchost.exe
    ;===================================================================================================================================================================================
    SUSPECTS
    Sent Location
    ;===================================================================================================================================================================================
    No c:\downloads\software\flvtomp4converter_setup.exe
    ;===================================================================================================================================================================================
    VULNERABILITIES
    Id Severity Description
    ;===================================================================================================================================================================================
    ;===================================================================================================================================================================================


    Thanks in advance!!!
     
  2. 2010/01/09
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Please read this as indicated at the head of the forum and post the logs requested in this thread.
     

  3. to hide this advert.

  4. 2010/01/09
    dogtag

    dogtag Inactive Thread Starter

    Joined:
    2008/08/17
    Messages:
    31
    Likes Received:
    0
    Thx :)

    DDS (Ver_09-12-01.01) - NTFSx86
    Run by Allan at 17:45:46.20 on 09/01/2010
    Internet Explorer: 7.0.6000.16945
    Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.44.1033.18.1917.543 [GMT 0:00]

    AV: Microsoft Security Essentials *On-access scanning enabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
    AV: avast! antivirus 4.8.1368 [VPS 100109-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
    SP: Microsoft Security Essentials *enabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDE}
    SP: Spybot - Search and Destroy *enabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
    SP: Lavasoft Ad-Watch Live! *enabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
    SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
    SP: avast! antivirus 4.8.1368 [VPS 100109-0] *enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

    ============== Running Processes ===============

    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k rpcss
    c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
    C:\Windows\system32\Ati2evxx.exe
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\SLsvc.exe
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\Ati2evxx.exe
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Google\Update\GoogleUpdate.exe
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Windows\System32\TUProgSt.exe
    C:\Windows\System32\svchost.exe -k WerSvcGroup
    C:\Windows\system32\SearchIndexer.exe
    C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Alwil Software\Avast4\ashDisp.exe
    C:\Program Files\Microsoft Security Essentials\msseces.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\iTunes\iTunes.exe
    C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceHelper.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\distnoted.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\MDCrashReportTool.exe
    C:\Windows\system32\wuauclt.exe
    C:\Windows\system32\vssvc.exe
    C:\Windows\System32\svchost.exe -k swprv
    C:\Windows\system32\WUDFHost.exe
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Windows\system32\conime.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Users\Allan\Downloads\dds.scr
    C:\Windows\system32\wbem\wmiprvse.exe

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://www.google.co.uk/
    uInternet Settings,ProxyOverride = *.local
    uURLSearchHooks: iPhone OS 3 Toolbar: {74714d77-1695-4e73-a98e-25cb374f46b4} - c:\program files\iphone_os_3\tbiPho.dll
    mURLSearchHooks: iPhone OS 3 Toolbar: {74714d77-1695-4e73-a98e-25cb374f46b4} - c:\program files\iphone_os_3\tbiPho.dll
    mWinlogon: Userinit=c:\windows\system32\userinit.exe,userinit.exe,
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
    BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~3\office14\GROOVEEX.DLL
    BHO: iPhone OS 3 Toolbar: {74714d77-1695-4e73-a98e-25cb374f46b4} - c:\program files\iphone_os_3\tbiPho.dll
    BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~3\office14\URLREDIR.DLL
    BHO: FDMIECookiesBHO Class: {cc59e0f9-7e43-44fa-9faa-8377850bf205} - c:\program files\free download manager\iefdm2.dll
    TB: iPhone OS 3 Toolbar: {74714d77-1695-4e73-a98e-25cb374f46b4} - c:\program files\iphone_os_3\tbiPho.dll
    uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
    mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
    mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide
    dRun: [RegistryMonitor1] "c:\windows\temp\acxc.tmp\svchost.exe "
    IE: Download all with Free Download Manager - file://c:\program files\free download manager\dlall.htm
    IE: Download selected with Free Download Manager - file://c:\program files\free download manager\dlselected.htm
    IE: Download video with Free Download Manager - file://c:\program files\free download manager\dlfvideo.htm
    IE: Download with Free Download Manager - file://c:\program files\free download manager\dllink.htm
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office14\EXCEL.EXE/3000
    IE: Se&nd to OneNote - /105
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
    IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office11\REFIEBAR.DLL
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
    DPF: {40F576AD-8680-4F9E-9490-99D069CD665F} - hxxp://srtest-cdn.systemrequirementslab.com.s3.amazonaws.com/bin/sysreqlabdetect.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
    SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~3\office14\GROOVEEX.DLL

    ================= FIREFOX ===================

    FF - ProfilePath - c:\users\allan\appdata\roaming\mozilla\firefox\profiles\eev4jn5m.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
    FF - plugin: c:\progra~1\micros~3\office14\NPAUTHZ.DLL
    FF - plugin: c:\progra~1\micros~3\office14\NPSPWRAP.DLL
    FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
    FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll
    FF - plugin: c:\users\allan\appdata\roaming\gadu-gadu 10\_userdata\npgg.2.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

    ---- FIREFOX POLICIES ----
    FF - user.js: network.http.max-persistent-connections-per-server - 4
    FF - user.js: nglayout.initialpaint.delay - 600
    FF - user.js: content.notify.interval - 600000
    FF - user.js: content.max.tokenizing.time - 1800000
    FF - user.js: content.switch.threshold - 600000
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref( "security.ssl3.rsa_seed_sha ", true);

    ============= SERVICES / DRIVERS ===============

    R? gupdate;Google Update Service (gupdate)
    R? Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service
    R? MpNWMon;Microsoft Malware Protection Network Driver
    R? osppsvc;Office Software Protection Platform
    S? aswFsBlk;aswFsBlk
    S? aswMonFlt;aswMonFlt
    S? aswSP;avast! Self Protection
    S? avast! Antivirus;avast! Antivirus
    S? avast! Mail Scanner;avast! Mail Scanner
    S? avast! Web Scanner;avast! Web Scanner
    S? Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service
    S? Lbd;Lbd
    S? MpFilter;Microsoft Malware Protection Driver
    S? pavboot;pavboot
    S? SBSDWSCService;SBSD Security Center Service

    =============== Created Last 30 ================

    2010-01-09 14:50:58 15880 ----a-w- c:\windows\system32\lsdelete.exe
    2010-01-09 12:35:17 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
    2010-01-09 12:28:40 0 dc-h--w- c:\programdata\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}
    2010-01-09 12:26:50 0 d-----w- c:\programdata\Lavasoft
    2010-01-09 12:26:50 0 d-----w- c:\program files\Lavasoft
    2010-01-08 19:06:28 0 d-----w- c:\program files\CCleaner
    2010-01-08 18:47:33 28552 ----a-w- c:\windows\system32\drivers\pavboot.sys
    2010-01-08 18:46:58 0 d-----w- c:\program files\Panda Security
    2010-01-08 18:43:37 0 d-----w- c:\programdata\Spybot - Search & Destroy
    2010-01-08 18:43:37 0 d-----w- c:\program files\Spybot - Search & Destroy
    2010-01-07 22:06:28 0 d-----w- c:\windows\pss
    2010-01-07 17:54:55 0 d-----w- c:\program files\Microsoft Security Essentials
    2010-01-03 15:13:16 0 d-----w- c:\program files\DoremiSoft
    2010-01-03 09:40:20 0 d-----w- c:\program files\YouTube Downloader
    2010-01-03 09:37:08 0 d-----w- c:\users\allan\appdata\roaming\Apowersoft
    2010-01-03 09:36:56 0 d-----w- c:\program files\Apowersoft
    2010-01-02 22:29:42 0 d-----w- c:\program files\Conduit
    2010-01-02 22:29:41 0 d-----w- c:\program files\iPhone_OS_3
    2010-01-02 12:39:25 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
    2010-01-02 12:39:25 107368 ----a-w- c:\windows\system32\GEARAspi.dll
    2010-01-02 12:38:48 0 d-----w- c:\program files\iPod
    2010-01-02 12:38:37 0 d-----w- c:\programdata\{755AC846-7372-4AC8-8550-C52491DAA8BD}
    2010-01-02 12:38:37 0 d-----w- c:\program files\iTunes
    2010-01-02 12:37:56 0 d-----w- c:\program files\Bonjour
    2010-01-02 12:37:11 0 d-----w- c:\programdata\Apple Computer
    2010-01-02 12:35:15 0 d-----w- c:\programdata\Apple
    2010-01-02 11:26:30 0 d-----w- c:\program files\FLV to MP4 Converter
    2010-01-02 01:03:34 0 dc----w- c:\programdata\{7D4B3D1D-104E-4507-9123-568BC721B7E2}
    2010-01-01 18:32:59 0 d-sh--w- c:\users\allan\appdata\roaming\lowsec
    2009-12-17 17:28:45 0 d-sh--w- c:\windows\system32\lowsec
    2009-12-16 21:50:51 0 d-----w- c:\users\allan\appdata\roaming\DMCache
    2009-12-16 21:32:53 0 d-----w- c:\program files\Mozilla ActiveX Control v1.7.12
    2009-12-15 07:21:03 229888 ----a-w- c:\windows\system32\msshsq.dll
    2009-12-15 07:20:59 494592 ----a-w- c:\windows\system32\kerberos.dll
    2009-12-15 07:20:58 272384 ----a-w- c:\windows\system32\schannel.dll
    2009-12-14 19:40:11 0 d-----w- c:\users\allan\.gstreamer-0.10
    2009-12-13 23:14:47 0 d-----w- c:\programdata\OpenFM
    2009-12-13 23:14:46 0 d-----w- c:\users\allan\appdata\roaming\OpenFM
    2009-12-12 22:00:20 0 d-----w- c:\program files\Microsoft SQL Server
    2009-12-11 16:55:13 0 d-----w- c:\programdata\D25E
    2009-12-11 07:14:45 65536 --sha-w- c:\users\allan\NTUSER.DAT{b9758d4b-e624-11de-8ddc-001d09370315}.TM.blf
    2009-12-11 07:14:45 524288 --sha-w- c:\users\allan\NTUSER.DAT{b9758d4b-e624-11de-8ddc-001d09370315}.TMContainer00000000000000000002.regtrans-ms
    2009-12-11 07:14:45 524288 --sha-w- c:\users\allan\NTUSER.DAT{b9758d4b-e624-11de-8ddc-001d09370315}.TMContainer00000000000000000001.regtrans-ms

    ==================== Find3M ====================

    2010-01-08 18:18:43 86016 ----a-w- c:\windows\inf\infstrng.dat
    2010-01-08 18:18:43 51200 ----a-w- c:\windows\inf\infpub.dat
    2010-01-08 18:18:42 86016 ----a-w- c:\windows\inf\infstor.dat
    2010-01-03 18:25:34 21560 ----a-w- c:\windows\system32\drivers\atapi.sys
    2009-12-10 17:22:10 72704 ----a-w- c:\windows\system32\admparse.dll
    2009-12-10 17:22:08 832512 ----a-w- c:\windows\system32\wininet.dll
    2009-12-10 17:22:04 78336 ----a-w- c:\windows\system32\ieencode.dll
    2009-12-10 17:22:04 48128 ----a-w- c:\windows\system32\mshtmler.dll
    2009-12-10 17:21:57 26624 ----a-w- c:\windows\system32\ieUnatt.exe
    2009-12-10 17:21:54 56320 ----a-w- c:\windows\system32\iesetup.dll
    2009-12-10 17:19:08 396800 ----a-w- c:\windows\system32\drivers\http.sys
    2009-12-10 17:19:08 31232 ----a-w- c:\windows\system32\httpapi.dll
    2009-12-10 17:19:07 24064 ----a-w- c:\windows\system32\nshhttp.dll
    2009-12-10 17:13:47 274432 ----a-w- c:\windows\system32\raschap.dll
    2009-12-10 17:13:46 232960 ----a-w- c:\windows\system32\rastls.dll
    2009-12-06 14:54:37 279712 ----a-w- c:\windows\system32\drivers\atksgt.sys
    2009-12-06 14:54:35 25888 ----a-w- c:\windows\system32\drivers\lirsgt.sys
    2009-12-06 04:34:17 665600 ----a-w- c:\windows\inf\drvindex.dat
    2009-12-06 04:15:44 268800 ----a-w- c:\windows\system32\es.dll
    2009-12-06 04:13:57 8704 ----a-w- c:\windows\system32\hcrstco.dll
    2009-12-06 04:13:57 8704 ----a-w- c:\windows\system32\hccoin.dll
    2009-12-06 04:13:57 5888 ----a-w- c:\windows\system32\drivers\usbd.sys
    2009-12-06 04:13:57 38400 ----a-w- c:\windows\system32\drivers\usbehci.sys
    2009-12-06 04:13:57 224768 ----a-w- c:\windows\system32\drivers\usbport.sys
    2009-12-06 04:13:57 19456 ----a-w- c:\windows\system32\drivers\usbohci.sys
    2009-12-06 04:13:57 192000 ----a-w- c:\windows\system32\drivers\usbhub.sys
    2009-12-06 04:13:56 73216 ----a-w- c:\windows\system32\drivers\usbccgp.sys
    2009-12-06 04:11:59 7042560 ----a-w- c:\windows\system32\NlsLexicons081a.dll
    2009-12-06 04:07:48 61440 ----a-w- c:\windows\system32\ntprint.exe
    2009-12-06 04:07:48 220160 ----a-w- c:\windows\system32\ntprint.dll
    2009-12-06 04:07:42 10240 ----a-w- c:\windows\system32\dhcpcmonitor.dll
    2009-12-06 04:07:41 120320 ----a-w- c:\windows\system32\dhcpcsvc6.dll
    2009-12-06 04:07:40 1984512 ----a-w- c:\windows\system32\authui.dll
    2009-12-06 04:07:37 69632 ----a-w- c:\windows\system32\sendmail.dll
    2009-12-06 04:07:36 8138240 ----a-w- c:\windows\system32\ssBranded.scr
    2009-12-06 04:02:47 97800 ----a-w- c:\windows\system32\infocardapi.dll
    2009-12-06 04:02:47 622080 ----a-w- c:\windows\system32\icardagt.exe
    2009-12-06 04:02:47 11264 ----a-w- c:\windows\system32\icardres.dll
    2009-12-06 04:02:44 105016 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
    2009-12-06 04:02:43 781344 ----a-w- c:\windows\system32\PresentationNative_v0300.dll
    2009-12-06 04:02:43 43544 ----a-w- c:\windows\system32\PresentationHostProxy.dll
    2009-12-06 04:02:43 326160 ----a-w- c:\windows\system32\PresentationHost.exe
    2009-12-06 03:26:57 96760 ----a-w- c:\windows\system32\dfshim.dll
    2009-12-06 03:26:56 41984 ----a-w- c:\windows\system32\netfxperf.dll
    2009-12-06 03:26:55 282112 ----a-w- c:\windows\system32\mscoree.dll
    2009-12-06 03:26:55 158720 ----a-w- c:\windows\system32\mscorier.dll
    2009-12-06 03:26:54 83968 ----a-w- c:\windows\system32\mscories.dll
    2009-12-05 19:02:43 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
    2009-12-03 19:21:22 174 --sha-w- c:\program files\desktop.ini
    2009-12-03 19:15:48 87040 ----a-w- c:\windows\system32\msoert2.dll
    2009-12-03 19:15:48 39424 ----a-w- c:\windows\system32\ACCTRES.dll
    2009-12-03 19:15:48 205824 ----a-w- c:\windows\system32\msoeacct.dll
    2009-12-03 19:13:16 704000 ----a-w- c:\windows\system32\PhotoScreensaver.scr
    2009-12-03 19:13:16 356352 ----a-w- c:\windows\system32\wbem\wbemcomn.dll
    2009-12-03 19:13:15 24064 ----a-w- c:\windows\system32\wtsapi32.dll
    2009-12-03 19:13:14 258232 ----a-w- c:\windows\system32\drivers\acpi.sys
    2009-12-03 19:13:14 20920 ----a-w- c:\windows\system32\drivers\compbatt.sys
    2009-12-03 19:13:14 11264 ----a-w- c:\windows\system32\drivers\wmiacpi.sys
    2009-12-03 19:13:13 28344 ----a-w- c:\windows\system32\drivers\battc.sys
    2009-12-03 19:13:13 14208 ----a-w- c:\windows\system32\drivers\CmBatt.sys
    2009-12-03 19:13:12 542720 ----a-w- c:\windows\system32\sysmain.dll
    2009-12-03 19:12:19 123904 ----a-w- c:\windows\system32\L2SecHC.dll
    2009-12-03 19:12:18 67584 ----a-w- c:\windows\system32\wlanhlp.dll
    2009-12-03 19:12:18 502272 ----a-w- c:\windows\system32\wlansvc.dll
    2009-12-03 19:12:18 47104 ----a-w- c:\windows\system32\wlanapi.dll
    2009-12-03 19:12:18 297984 ----a-w- c:\windows\system32\wlansec.dll
    2009-12-03 19:12:18 290816 ----a-w- c:\windows\system32\wlanmsm.dll
    2009-12-03 19:11:19 7680 ----a-w- c:\windows\system32\lsass.exe
    2009-12-03 19:11:19 72704 ----a-w- c:\windows\system32\secur32.dll
    2009-12-03 19:11:19 408136 ----a-w- c:\windows\system32\drivers\ksecdd.sys
    2009-12-03 19:11:19 216576 ----a-w- c:\windows\system32\msv1_0.dll
    2009-12-03 19:11:19 175104 ----a-w- c:\windows\system32\wdigest.dll
    2009-12-03 19:11:19 1233920 ----a-w- c:\windows\system32\lsasrv.dll
    2009-12-03 19:10:23 98816 ----a-w- c:\windows\system32\mfps.dll
    2009-12-03 19:10:23 52736 ----a-w- c:\windows\system32\rrinstaller.exe
    2009-12-03 19:10:23 2855424 ----a-w- c:\windows\system32\mf.dll
    2009-12-03 19:10:23 2048 ----a-w- c:\windows\system32\mferror.dll
    2009-12-03 19:10:22 24576 ----a-w- c:\windows\system32\mfpmp.exe
    2009-12-03 19:09:19 2048 ----a-w- c:\windows\system32\tzres.dll
    2009-12-03 19:03:43 3502152 ----a-w- c:\windows\system32\ntkrnlpa.exe
    2009-12-03 19:03:43 3467864 ----a-w- c:\windows\system32\ntoskrnl.exe
    2009-12-03 19:03:05 356864 ----a-w- c:\windows\system32\MediaMetadataHandler.dll
    2009-12-03 19:02:18 1244672 ----a-w- c:\windows\system32\mcmde.dll
    2009-12-03 19:02:17 428032 ----a-w- c:\windows\system32\EncDec.dll
    2009-12-03 19:02:17 292352 ----a-w- c:\windows\system32\psisdecd.dll
    2009-12-03 19:00:03 45112 ----a-w- c:\windows\system32\drivers\pciidex.sys
    2009-12-03 19:00:03 15928 ----a-w- c:\windows\system32\drivers\pciide.sys
    2009-12-03 19:00:03 109624 ----a-w- c:\windows\system32\drivers\ataport.sys
    2009-12-03 19:00:02 211000 ----a-w- c:\windows\system32\drivers\volsnap.sys
    2009-12-03 19:00:02 154624 ----a-w- c:\windows\system32\drivers\nwifi.sys
    2009-12-03 18:55:27 1585664 ----a-w- c:\windows\system32\setupapi.dll
    2009-12-03 18:52:51 549888 ----a-w- c:\windows\system32\rpcss.dll
    2009-12-03 18:52:49 24576 ----a-w- c:\windows\system32\printfilterpipelineprxy.dll
    2009-12-03 18:52:48 654336 ----a-w- c:\windows\system32\printfilterpipelinesvc.exe
    2009-12-03 18:52:48 614912 ----a-w- c:\windows\system32\wbem\fastprox.dll
    2009-12-03 18:52:48 501760 ----a-w- c:\windows\system32\wbem\WmiPrvSD.dll
    2009-12-03 18:52:48 247296 ----a-w- c:\windows\system32\wbem\WmiPrvSE.exe
    2009-12-03 18:52:48 130560 ----a-w- c:\windows\system32\wbem\WmiDcPrv.dll
    2009-12-03 18:52:46 97280 ----a-w- c:\windows\system32\iasrecst.dll
    2009-12-03 18:52:46 53248 ----a-w- c:\windows\system32\iasads.dll
    2007-02-21 19:49:52 8192 --sha-w- c:\windows\users\default\NTUSER.DAT

    ============= FINISH: 17:47:23.80 ===============
     
  5. 2010/01/09
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    And the Attach.txt please - copy/paste the contents here.
     
  6. 2010/01/09
    dogtag

    dogtag Inactive Thread Starter

    Joined:
    2008/08/17
    Messages:
    31
    Likes Received:
    0
    there was no attack.txt ??
    i ran it twice and this was the only text file
     
  7. 2010/01/09
    dogtag

    dogtag Inactive Thread Starter

    Joined:
    2008/08/17
    Messages:
    31
    Likes Received:
    0
    Thanks
    i ran it again and i now have two log files


    DDS (Ver_09-12-01.01) - NTFSx86
    Run by Allan at 23:08:02.34 on 09/01/2010
    Internet Explorer: 7.0.6000.16945
    Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.44.1033.18.1917.901 [GMT 0:00]

    AV: Microsoft Security Essentials *On-access scanning enabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
    AV: avast! antivirus 4.8.1368 [VPS 100109-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
    SP: Microsoft Security Essentials *enabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDE}
    SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
    SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
    SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
    SP: avast! antivirus 4.8.1368 [VPS 100109-0] *enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

    ============== Running Processes ===============

    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k rpcss
    c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
    C:\Windows\system32\Ati2evxx.exe
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\SLsvc.exe
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\Ati2evxx.exe
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Google\Update\GoogleUpdate.exe
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Windows\System32\TUProgSt.exe
    C:\Windows\System32\svchost.exe -k WerSvcGroup
    C:\Windows\system32\SearchIndexer.exe
    C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Alwil Software\Avast4\ashDisp.exe
    C:\Program Files\Microsoft Security Essentials\msseces.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files\iTunes\iTunes.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceHelper.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\distnoted.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\MDCrashReportTool.exe
    C:\Windows\system32\wuauclt.exe
    C:\Windows\system32\vssvc.exe
    C:\Windows\System32\svchost.exe -k swprv
    C:\Windows\system32\conime.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Windows\System32\mobsync.exe
    C:\Program Files\Windows Media Player\wmplayer.exe
    c:\Program Files\Microsoft Security Essentials\MpCmdRun.exe
    C:\Users\Allan\Downloads\dds.scr
    C:\Windows\system32\WUDFHost.exe
    C:\Windows\system32\wbem\wmiprvse.exe

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://www.google.co.uk/
    uInternet Settings,ProxyOverride = *.local
    uURLSearchHooks: iPhone OS 3 Toolbar: {74714d77-1695-4e73-a98e-25cb374f46b4} - c:\program files\iphone_os_3\tbiPho.dll
    mURLSearchHooks: iPhone OS 3 Toolbar: {74714d77-1695-4e73-a98e-25cb374f46b4} - c:\program files\iphone_os_3\tbiPho.dll
    mWinlogon: Userinit=c:\windows\system32\userinit.exe,userinit.exe,
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
    BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~3\office14\GROOVEEX.DLL
    BHO: iPhone OS 3 Toolbar: {74714d77-1695-4e73-a98e-25cb374f46b4} - c:\program files\iphone_os_3\tbiPho.dll
    BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~3\office14\URLREDIR.DLL
    BHO: FDMIECookiesBHO Class: {cc59e0f9-7e43-44fa-9faa-8377850bf205} - c:\program files\free download manager\iefdm2.dll
    TB: iPhone OS 3 Toolbar: {74714d77-1695-4e73-a98e-25cb374f46b4} - c:\program files\iphone_os_3\tbiPho.dll
    uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
    mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
    mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide
    dRun: [RegistryMonitor1] "c:\windows\temp\acxc.tmp\svchost.exe "
    IE: Download all with Free Download Manager - file://c:\program files\free download manager\dlall.htm
    IE: Download selected with Free Download Manager - file://c:\program files\free download manager\dlselected.htm
    IE: Download video with Free Download Manager - file://c:\program files\free download manager\dlfvideo.htm
    IE: Download with Free Download Manager - file://c:\program files\free download manager\dllink.htm
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office14\EXCEL.EXE/3000
    IE: Se&nd to OneNote - /105
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
    IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office11\REFIEBAR.DLL
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
    DPF: {40F576AD-8680-4F9E-9490-99D069CD665F} - hxxp://srtest-cdn.systemrequirementslab.com.s3.amazonaws.com/bin/sysreqlabdetect.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
    SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~3\office14\GROOVEEX.DLL

    ================= FIREFOX ===================

    FF - ProfilePath - c:\users\allan\appdata\roaming\mozilla\firefox\profiles\eev4jn5m.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
    FF - plugin: c:\progra~1\micros~3\office14\NPAUTHZ.DLL
    FF - plugin: c:\progra~1\micros~3\office14\NPSPWRAP.DLL
    FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
    FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll
    FF - plugin: c:\users\allan\appdata\roaming\gadu-gadu 10\_userdata\npgg.2.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

    ---- FIREFOX POLICIES ----
    FF - user.js: network.http.max-persistent-connections-per-server - 4
    FF - user.js: nglayout.initialpaint.delay - 600
    FF - user.js: content.notify.interval - 600000
    FF - user.js: content.max.tokenizing.time - 1800000
    FF - user.js: content.switch.threshold - 600000
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref( "security.ssl3.rsa_seed_sha ", true);

    ============= SERVICES / DRIVERS ===============

    R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-1-9 64288]
    R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2010-1-8 28552]
    R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-12-9 114768]
    R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2009-6-18 142832]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-12-9 20560]
    R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2009-12-9 53328]
    S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2009-6-18 42480]

    =============== Created Last 30 ================

    2010-01-09 14:50:58 15880 ----a-w- c:\windows\system32\lsdelete.exe
    2010-01-09 12:35:17 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
    2010-01-09 12:28:40 0 dc-h--w- c:\programdata\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}
    2010-01-09 12:26:50 0 d-----w- c:\programdata\Lavasoft
    2010-01-09 12:26:50 0 d-----w- c:\program files\Lavasoft
    2010-01-08 19:06:28 0 d-----w- c:\program files\CCleaner
    2010-01-08 18:47:33 28552 ----a-w- c:\windows\system32\drivers\pavboot.sys
    2010-01-08 18:46:58 0 d-----w- c:\program files\Panda Security
    2010-01-08 18:43:37 0 d-----w- c:\programdata\Spybot - Search & Destroy
    2010-01-08 18:43:37 0 d-----w- c:\program files\Spybot - Search & Destroy
    2010-01-07 22:06:28 0 d-----w- c:\windows\pss
    2010-01-07 17:54:55 0 d-----w- c:\program files\Microsoft Security Essentials
    2010-01-03 15:13:16 0 d-----w- c:\program files\DoremiSoft
    2010-01-03 09:40:20 0 d-----w- c:\program files\YouTube Downloader
    2010-01-03 09:37:08 0 d-----w- c:\users\allan\appdata\roaming\Apowersoft
    2010-01-03 09:36:56 0 d-----w- c:\program files\Apowersoft
    2010-01-02 22:29:42 0 d-----w- c:\program files\Conduit
    2010-01-02 22:29:41 0 d-----w- c:\program files\iPhone_OS_3
    2010-01-02 12:39:25 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
    2010-01-02 12:39:25 107368 ----a-w- c:\windows\system32\GEARAspi.dll
    2010-01-02 12:38:48 0 d-----w- c:\program files\iPod
    2010-01-02 12:38:37 0 d-----w- c:\programdata\{755AC846-7372-4AC8-8550-C52491DAA8BD}
    2010-01-02 12:38:37 0 d-----w- c:\program files\iTunes
    2010-01-02 12:37:56 0 d-----w- c:\program files\Bonjour
    2010-01-02 12:37:11 0 d-----w- c:\programdata\Apple Computer
    2010-01-02 12:35:15 0 d-----w- c:\programdata\Apple
    2010-01-02 11:26:30 0 d-----w- c:\program files\FLV to MP4 Converter
    2010-01-02 01:03:34 0 dc----w- c:\programdata\{7D4B3D1D-104E-4507-9123-568BC721B7E2}
    2010-01-01 18:32:59 0 d-sh--w- c:\users\allan\appdata\roaming\lowsec
    2009-12-17 17:28:45 0 d-sh--w- c:\windows\system32\lowsec
    2009-12-16 21:50:51 0 d-----w- c:\users\allan\appdata\roaming\DMCache
    2009-12-16 21:32:53 0 d-----w- c:\program files\Mozilla ActiveX Control v1.7.12
    2009-12-15 07:21:03 229888 ----a-w- c:\windows\system32\msshsq.dll
    2009-12-15 07:20:59 494592 ----a-w- c:\windows\system32\kerberos.dll
    2009-12-15 07:20:58 272384 ----a-w- c:\windows\system32\schannel.dll
    2009-12-14 19:40:11 0 d-----w- c:\users\allan\.gstreamer-0.10
    2009-12-13 23:14:47 0 d-----w- c:\programdata\OpenFM
    2009-12-13 23:14:46 0 d-----w- c:\users\allan\appdata\roaming\OpenFM
    2009-12-12 22:00:20 0 d-----w- c:\program files\Microsoft SQL Server
    2009-12-11 16:55:13 0 d-----w- c:\programdata\D25E
    2009-12-11 07:14:45 65536 --sha-w- c:\users\allan\NTUSER.DAT{b9758d4b-e624-11de-8ddc-001d09370315}.TM.blf
    2009-12-11 07:14:45 524288 --sha-w- c:\users\allan\NTUSER.DAT{b9758d4b-e624-11de-8ddc-001d09370315}.TMContainer00000000000000000002.regtrans-ms
    2009-12-11 07:14:45 524288 --sha-w- c:\users\allan\NTUSER.DAT{b9758d4b-e624-11de-8ddc-001d09370315}.TMContainer00000000000000000001.regtrans-ms

    ==================== Find3M ====================

    2010-01-08 18:18:43 86016 ----a-w- c:\windows\inf\infstrng.dat
    2010-01-08 18:18:43 51200 ----a-w- c:\windows\inf\infpub.dat
    2010-01-08 18:18:42 86016 ----a-w- c:\windows\inf\infstor.dat
    2010-01-03 18:25:34 21560 ----a-w- c:\windows\system32\drivers\atapi.sys
    2009-12-10 17:22:10 72704 ----a-w- c:\windows\system32\admparse.dll
    2009-12-10 17:22:08 832512 ----a-w- c:\windows\system32\wininet.dll
    2009-12-10 17:22:04 78336 ----a-w- c:\windows\system32\ieencode.dll
    2009-12-10 17:22:04 48128 ----a-w- c:\windows\system32\mshtmler.dll
    2009-12-10 17:21:57 26624 ----a-w- c:\windows\system32\ieUnatt.exe
    2009-12-10 17:21:54 56320 ----a-w- c:\windows\system32\iesetup.dll
    2009-12-10 17:19:08 396800 ----a-w- c:\windows\system32\drivers\http.sys
    2009-12-10 17:19:08 31232 ----a-w- c:\windows\system32\httpapi.dll
    2009-12-10 17:19:07 24064 ----a-w- c:\windows\system32\nshhttp.dll
    2009-12-10 17:13:47 274432 ----a-w- c:\windows\system32\raschap.dll
    2009-12-10 17:13:46 232960 ----a-w- c:\windows\system32\rastls.dll
    2009-12-06 14:54:37 279712 ----a-w- c:\windows\system32\drivers\atksgt.sys
    2009-12-06 14:54:35 25888 ----a-w- c:\windows\system32\drivers\lirsgt.sys
    2009-12-06 04:34:17 665600 ----a-w- c:\windows\inf\drvindex.dat
    2009-12-06 04:15:44 268800 ----a-w- c:\windows\system32\es.dll
    2009-12-06 04:13:57 8704 ----a-w- c:\windows\system32\hcrstco.dll
    2009-12-06 04:13:57 8704 ----a-w- c:\windows\system32\hccoin.dll
    2009-12-06 04:13:57 5888 ----a-w- c:\windows\system32\drivers\usbd.sys
    2009-12-06 04:13:57 38400 ----a-w- c:\windows\system32\drivers\usbehci.sys
    2009-12-06 04:13:57 224768 ----a-w- c:\windows\system32\drivers\usbport.sys
    2009-12-06 04:13:57 19456 ----a-w- c:\windows\system32\drivers\usbohci.sys
    2009-12-06 04:13:57 192000 ----a-w- c:\windows\system32\drivers\usbhub.sys
    2009-12-06 04:13:56 73216 ----a-w- c:\windows\system32\drivers\usbccgp.sys
    2009-12-06 04:11:59 7042560 ----a-w- c:\windows\system32\NlsLexicons081a.dll
    2009-12-06 04:07:48 61440 ----a-w- c:\windows\system32\ntprint.exe
    2009-12-06 04:07:48 220160 ----a-w- c:\windows\system32\ntprint.dll
    2009-12-06 04:07:42 10240 ----a-w- c:\windows\system32\dhcpcmonitor.dll
    2009-12-06 04:07:41 120320 ----a-w- c:\windows\system32\dhcpcsvc6.dll
    2009-12-06 04:07:40 1984512 ----a-w- c:\windows\system32\authui.dll
    2009-12-06 04:07:37 69632 ----a-w- c:\windows\system32\sendmail.dll
    2009-12-06 04:07:36 8138240 ----a-w- c:\windows\system32\ssBranded.scr
    2009-12-06 04:02:47 97800 ----a-w- c:\windows\system32\infocardapi.dll
    2009-12-06 04:02:47 622080 ----a-w- c:\windows\system32\icardagt.exe
    2009-12-06 04:02:47 11264 ----a-w- c:\windows\system32\icardres.dll
    2009-12-06 04:02:44 105016 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
    2009-12-06 04:02:43 781344 ----a-w- c:\windows\system32\PresentationNative_v0300.dll
    2009-12-06 04:02:43 43544 ----a-w- c:\windows\system32\PresentationHostProxy.dll
    2009-12-06 04:02:43 326160 ----a-w- c:\windows\system32\PresentationHost.exe
    2009-12-06 03:26:57 96760 ----a-w- c:\windows\system32\dfshim.dll
    2009-12-06 03:26:56 41984 ----a-w- c:\windows\system32\netfxperf.dll
    2009-12-06 03:26:55 282112 ----a-w- c:\windows\system32\mscoree.dll
    2009-12-06 03:26:55 158720 ----a-w- c:\windows\system32\mscorier.dll
    2009-12-06 03:26:54 83968 ----a-w- c:\windows\system32\mscories.dll
    2009-12-05 19:02:43 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
    2009-12-03 19:21:22 174 --sha-w- c:\program files\desktop.ini
    2009-12-03 19:15:48 87040 ----a-w- c:\windows\system32\msoert2.dll
    2009-12-03 19:15:48 39424 ----a-w- c:\windows\system32\ACCTRES.dll
    2009-12-03 19:15:48 205824 ----a-w- c:\windows\system32\msoeacct.dll
    2009-12-03 19:13:16 704000 ----a-w- c:\windows\system32\PhotoScreensaver.scr
    2009-12-03 19:13:16 356352 ----a-w- c:\windows\system32\wbem\wbemcomn.dll
    2009-12-03 19:13:15 24064 ----a-w- c:\windows\system32\wtsapi32.dll
    2009-12-03 19:13:14 258232 ----a-w- c:\windows\system32\drivers\acpi.sys
    2009-12-03 19:13:14 20920 ----a-w- c:\windows\system32\drivers\compbatt.sys
    2009-12-03 19:13:14 11264 ----a-w- c:\windows\system32\drivers\wmiacpi.sys
    2009-12-03 19:13:13 28344 ----a-w- c:\windows\system32\drivers\battc.sys
    2009-12-03 19:13:13 14208 ----a-w- c:\windows\system32\drivers\CmBatt.sys
    2009-12-03 19:13:12 542720 ----a-w- c:\windows\system32\sysmain.dll
    2009-12-03 19:12:19 123904 ----a-w- c:\windows\system32\L2SecHC.dll
    2009-12-03 19:12:18 67584 ----a-w- c:\windows\system32\wlanhlp.dll
    2009-12-03 19:12:18 502272 ----a-w- c:\windows\system32\wlansvc.dll
    2009-12-03 19:12:18 47104 ----a-w- c:\windows\system32\wlanapi.dll
    2009-12-03 19:12:18 297984 ----a-w- c:\windows\system32\wlansec.dll
    2009-12-03 19:12:18 290816 ----a-w- c:\windows\system32\wlanmsm.dll
    2009-12-03 19:11:19 7680 ----a-w- c:\windows\system32\lsass.exe
    2009-12-03 19:11:19 72704 ----a-w- c:\windows\system32\secur32.dll
    2009-12-03 19:11:19 408136 ----a-w- c:\windows\system32\drivers\ksecdd.sys
    2009-12-03 19:11:19 216576 ----a-w- c:\windows\system32\msv1_0.dll
    2009-12-03 19:11:19 175104 ----a-w- c:\windows\system32\wdigest.dll
    2009-12-03 19:11:19 1233920 ----a-w- c:\windows\system32\lsasrv.dll
    2009-12-03 19:10:23 98816 ----a-w- c:\windows\system32\mfps.dll
    2009-12-03 19:10:23 52736 ----a-w- c:\windows\system32\rrinstaller.exe
    2009-12-03 19:10:23 2855424 ----a-w- c:\windows\system32\mf.dll
    2009-12-03 19:10:23 2048 ----a-w- c:\windows\system32\mferror.dll
    2009-12-03 19:10:22 24576 ----a-w- c:\windows\system32\mfpmp.exe
    2009-12-03 19:09:19 2048 ----a-w- c:\windows\system32\tzres.dll
    2009-12-03 19:03:43 3502152 ----a-w- c:\windows\system32\ntkrnlpa.exe
    2009-12-03 19:03:43 3467864 ----a-w- c:\windows\system32\ntoskrnl.exe
    2009-12-03 19:03:05 356864 ----a-w- c:\windows\system32\MediaMetadataHandler.dll
    2009-12-03 19:02:18 1244672 ----a-w- c:\windows\system32\mcmde.dll
    2009-12-03 19:02:17 428032 ----a-w- c:\windows\system32\EncDec.dll
    2009-12-03 19:02:17 292352 ----a-w- c:\windows\system32\psisdecd.dll
    2009-12-03 19:00:03 45112 ----a-w- c:\windows\system32\drivers\pciidex.sys
    2009-12-03 19:00:03 15928 ----a-w- c:\windows\system32\drivers\pciide.sys
    2009-12-03 19:00:03 109624 ----a-w- c:\windows\system32\drivers\ataport.sys
    2009-12-03 19:00:02 211000 ----a-w- c:\windows\system32\drivers\volsnap.sys
    2009-12-03 19:00:02 154624 ----a-w- c:\windows\system32\drivers\nwifi.sys
    2009-12-03 18:55:27 1585664 ----a-w- c:\windows\system32\setupapi.dll
    2009-12-03 18:52:51 549888 ----a-w- c:\windows\system32\rpcss.dll
    2009-12-03 18:52:49 24576 ----a-w- c:\windows\system32\printfilterpipelineprxy.dll
    2009-12-03 18:52:48 654336 ----a-w- c:\windows\system32\printfilterpipelinesvc.exe
    2009-12-03 18:52:48 614912 ----a-w- c:\windows\system32\wbem\fastprox.dll
    2009-12-03 18:52:48 501760 ----a-w- c:\windows\system32\wbem\WmiPrvSD.dll
    2009-12-03 18:52:48 247296 ----a-w- c:\windows\system32\wbem\WmiPrvSE.exe
    2009-12-03 18:52:48 130560 ----a-w- c:\windows\system32\wbem\WmiDcPrv.dll
    2009-12-03 18:52:46 97280 ----a-w- c:\windows\system32\iasrecst.dll
    2009-12-03 18:52:46 53248 ----a-w- c:\windows\system32\iasads.dll
    2007-02-21 19:49:52 8192 --sha-w- c:\windows\users\default\NTUSER.DAT

    ============= FINISH: 23:09:09.64 ===============
     
  8. 2010/01/09
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    You're running two AV programs, Avast and MSE. One of them has to go. Your choice.
    When done....

    Print these instructions out.

    NOTE. If any of the programs listed below refuse to run, try renaming executive file to something else; for instance, rename hijackthis.exe to scanner.exe

    ***VERY IMPORTANT! Make sure, you update Superantispyware, and Malwarebytes before running the scans.***

    STEP 1. Download SUPERAntiSpyware Free for Home Users:
    http://www.superantispyware.com/

    * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
    * An icon will be created on your desktop. Double-click that icon to launch the program.
    * If asked to update the program definitions, click "Yes ". If not, update the definitions before scanning by selecting "Check for Updates ". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
    * Close SUPERAntiSpyware.

    PHYSICALLY DISCONNECT FROM THE INTERNET

    Restart computer in Safe Mode.
    To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

    * Open SUPERAntiSpyware.
    * Click Scan your Computer... button.
    * Click Scanning Preferences/Control Center... button.
    * Under General and Startup tab, make sure, Start SUPERAntiSpyware when Windows starts option is UN-checked.
    * Click the Scanning Control tab.
    * Under Scanner Options make sure the following are checked (leave all others unchecked):
    • Close browsers before scanning.
    • Terminate memory threats before quarantining.
    * Click the Close button to leave the control center screen.
    * On the left, make sure you check C:\Fixed Drive.
    * On the right, choose Perform Complete Scan.
    * Click Next to start the scan. Please be patient while it scans your computer.
    * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click OK.
    * Make sure everything has a checkmark next to it and click Next.
    * A notification will appear that Quarantine and Removal is Complete. Click OK and then click the Finish button to return to the main menu.
    * If asked if you want to reboot, click Yes.
    * To retrieve the removal information after reboot, launch SUPERAntispyware again.
    • Click Preferences, then click the Statistics/Logs tab.
    • Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    • If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    • Please copy and paste the Scan Log results in your next reply.
    * Click Close to exit the program.
    Post SUPERAntiSpyware log.

    RECONNECT TO THE INTERNET

    RESTART COMPUTER!

    STEP 2. Download Malwarebytes' Anti-Malware: http://www.malwarebytes.org/mbam.php to your desktop.
    (Malwarebytes is free to use as a manual scanner. Payment is only required if you wish to have it run and update automatically which is not necessary for our purposes)

    * Double-click mbam-setup.exe and follow the prompts to install the program.
    * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select Perform full scan, then click Scan.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Be sure that everything is checked, and click Remove Selected.
    * When completed, a log will open in Notepad.
    * Post the log back here.

    The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
    Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

    RESTART COMPUTER!

    STEP 3. Download GMER: http://www.gmer.net/files.php, by clicking on Download EXE button.
    Alternative downloads:
    - http://majorgeeks.com/GMER_d5198.html
    - http://www.softpedia.com/get/Interne...ers/GMER.shtml
    Double click on downloaded .exe file, select Rootkit tab and click the Scan button.
    When scan is completed, click Save button, and save the results as gmer.log
    Warning ! Please, do not select the "Show all" checkbox during the scan.
    Post the log to your next reply.

    RESTART COMPUTER

    STEP 4. Download HijackThis:
    http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download
    by clicking on Installer under Version 2.0.2
    [DO NOT download version 2.0.3 (beta)]
    Install, and run it.
    Post HijackThis log.
    NOTE. If you're using Vista, or 7, right click on HijackThis, and click Run as Administrator
    Do NOT attempt to "fix" anything!


    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
     
  9. 2010/01/09
    dogtag

    dogtag Inactive Thread Starter

    Joined:
    2008/08/17
    Messages:
    31
    Likes Received:
    0
    sorry for being this slow :( and thanks for your help

    1st part of the attach.txt

    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_09-12-01.01)

    Microsoft® Windows Vista™ Home Premium
    Boot Device: \Device\HarddiskVolume1
    Install Date: 30/11/2009 17:48:48
    System Uptime: 01/09/2010 16:54:37 (-5633 hours ago)

    Motherboard: Dell Inc. | | 0WP019
    Processor: AMD Turion(tm) 64 X2 Mobile Technology TL-60 | Microprocessor | 2000/100mhz

    ==== Disk Partitions =========================

    C: is FIXED (NTFS) - 298 GiB total, 139.904 GiB free.
    D: is CDROM (CDFS)
    E: is CDROM ()
    F: is CDROM ()

    ==== Disabled Device Manager Items =============

    Class GUID:
    Description: Base System Device
    Device ID: PCI\VEN_1180&DEV_0843&SUBSYS_02301028&REV_12\4&35E69562&0&4AA4
    Manufacturer:
    Name: Base System Device
    PNP Device ID: PCI\VEN_1180&DEV_0843&SUBSYS_02301028&REV_12\4&35E69562&0&4AA4
    Service:

    Class GUID:
    Description: Base System Device
    Device ID: PCI\VEN_1180&DEV_0592&SUBSYS_02301028&REV_12\4&35E69562&0&4BA4
    Manufacturer:
    Name: Base System Device
    PNP Device ID: PCI\VEN_1180&DEV_0592&SUBSYS_02301028&REV_12\4&35E69562&0&4BA4
    Service:

    ==== System Restore Points ===================

    RP37: 12/12/2009 21:59:31 - Installed Microsoft SQL Server PowerPivot for Excel
    RP38: 15/12/2009 07:21:08 - Windows Update
    RP39: 15/12/2009 17:22:54 - Windows Update
    RP40: 15/12/2009 19:11:25 - Windows Update

    ==== Installed Programs ======================

    Ad-Aware
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Reader 9.2
    Apple Application Support
    Apple Mobile Device Support
    Apple Software Update
    Ares 3.1.5.3038
    ATI Catalyst Install Manager
    avast! Antivirus
    Bonjour
    Catalyst Control Center - Branding
    Catalyst Control Center Core Implementation
    Catalyst Control Center Graphics Full Existing
    Catalyst Control Center Graphics Full New
    Catalyst Control Center Graphics Light
    Catalyst Control Center Graphics Previews Common
    Catalyst Control Center Graphics Previews Vista
    Catalyst Control Center InstallProxy
    ccc-core-static
    ccc-utility
    CCC Help English
    CCleaner
    Dell Driver Download Manager
    DoremiSoft AVI to MP4 Converter 1.0
    Episode Downloader V2.3.4
    FLV to MP4 Converter 2009.2.20
    Free Download Manager 3.0
    Gadu-Gadu 10
    Google Earth
    Google Update Helper
    Guitar Pro 5.2
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    iPhone_OS_3 Toolbar
    iTunes
    Laptop Integrated Webcam Driver (1.04.01.1011)
    Magic FLAC to MP3 Converter 3.72
    Microsoft .NET Framework 3.5 SP1
    Microsoft Antimalware
    Microsoft Application Error Reporting
    Microsoft Choice Guard
    Microsoft Office Access MUI (English) 2010 (Beta)
    Microsoft Office Access Setup Metadata MUI (English) 2010 (Beta)
    Microsoft Office Excel MUI (English) 2010 (Beta)
    Microsoft Office Groove MUI (English) 2010 (Beta)
    Microsoft Office InfoPath MUI (English) 2010 (Beta)
    Microsoft Office OneNote MUI (English) 2010 (Beta)
    Microsoft Office Outlook MUI (English) 2010 (Beta)
    Microsoft Office PowerPoint MUI (English) 2010 (Beta)
    Microsoft Office Professional Edition 2003
    Microsoft Office Professional Plus 2010
    Microsoft Office Professional Plus 2010 (Beta)
    Microsoft Office Proof (English) 2010 (Beta)
    Microsoft Office Proof (French) 2010 (Beta)
    Microsoft Office Proof (Spanish) 2010 (Beta)
    Microsoft Office Proofing (English) 2010 (Beta)
    Microsoft Office Publisher MUI (English) 2010 (Beta)
    Microsoft Office Send-a-Smile
    Microsoft Office Shared MUI (English) 2010 (Beta)
    Microsoft Office Shared Setup Metadata MUI (English) 2010 (Beta)
    Microsoft Office Word MUI (English) 2010 (Beta)
    Microsoft Outlook Hotmail Connector 32-bit (Beta)
    Microsoft Security Essentials
    Microsoft Silverlight
    Microsoft SQL Server PowerPivot for Excel
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    Microsoft Visual C++ 2005 Redistributable
    Mozilla Firefox (3.5.6)
    MSVCRT
    Ogg Codecs 0.81.15562
    Panda ActiveScan 2.0
    QuickTime
    Security Update for Microsoft Office 2010 File Validation - Beta (KB976133)
    Skins
    Spybot - Search & Destroy
    System Requirements Lab
    The Witcher Enhanced Edition
    TuneUp Utilities 2009
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    VLC media player 1.0.3
    Winamp
    Windows Live Call
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live Messenger
    Windows Live Sign-in Assistant
    Windows Live Upload Tool
    WinRAR archiver
    YouTube Downloader 2.5.3

    ==== Event Viewer Messages From Past Week ========

    09/01/2010 18:06:20, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
    09/01/2010 17:58:01, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
    09/01/2010 17:52:27, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
    09/01/2010 17:47:44, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
    09/01/2010 17:42:25, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
    09/01/2010 17:41:15, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
    09/01/2010 17:32:10, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
    09/01/2010 17:21:53, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
    09/01/2010 17:16:48, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
    09/01/2010 17:11:44, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
    09/01/2010 17:06:35, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
     
  10. 2010/01/09
    dogtag

    dogtag Inactive Thread Starter

    Joined:
    2008/08/17
    Messages:
    31
    Likes Received:
    0
    2nd part

    09/01/2010 16:55:58, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
    09/01/2010 16:52:31, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
    09/01/2010 16:37:36, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
    09/01/2010 15:51:50, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
    09/01/2010 15:40:26, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
    09/01/2010 15:32:33, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: NT AUTHORITY\SYSTEM Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
    09/01/2010 15:17:21, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
    09/01/2010 15:12:05, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
    09/01/2010 15:06:58, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
    09/01/2010 15:01:52, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
    09/01/2010 14:56:41, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
    09/01/2010 14:51:26, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
    09/01/2010 14:38:52, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
    09/01/2010 14:16:03, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
    09/01/2010 13:59:03, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
    09/01/2010 13:40:40, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
    09/01/2010 13:35:11, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
    09/01/2010 13:31:19, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
    09/01/2010 13:31:18, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
    09/01/2010 13:14:08, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
    09/01/2010 13:08:56, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
    09/01/2010 12:58:34, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
    09/01/2010 12:50:10, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
    09/01/2010 12:41:57, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
    09/01/2010 12:35:24, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
    09/01/2010 12:32:20, Error: Service Control Manager [7030] - The Lavasoft Ad-Aware Service service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
    09/01/2010 12:28:11, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
    09/01/2010 12:23:03, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
    09/01/2010 12:12:40, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
    09/01/2010 12:03:49, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
    09/01/2010 11:58:46, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
    09/01/2010 11:48:26, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
    09/01/2010 11:08:36, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
    08/01/2010 19:15:39, Error: EventLog [6008] - The previous system shutdown at 19:13:25 on 08/01/2010 was unexpected.
    08/01/2010 19:10:38, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
    08/01/2010 19:05:27, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
    08/01/2010 19:00:16, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
    08/01/2010 18:55:03, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
    08/01/2010 18:49:55, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
    08/01/2010 18:44:39, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
    08/01/2010 18:35:15, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
    08/01/2010 18:31:36, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1914.0, AS: 1.71.1914.0 Engine Version: 1.1.5302.0
    08/01/2010 18:21:09, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1885.0, AS: 1.71.1885.0 Engine Version: 1.1.5302.0
    08/01/2010 18:11:16, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
    08/01/2010 18:08:55, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1885.0, AS: 1.71.1885.0 Engine Version: 1.1.5302.0
    08/01/2010 18:03:47, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1885.0, AS: 1.71.1885.0 Engine Version: 1.1.5302.0
    08/01/2010 17:58:41, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1885.0, AS: 1.71.1885.0 Engine Version: 1.1.5302.0
    08/01/2010 17:53:34, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1885.0, AS: 1.71.1885.0 Engine Version: 1.1.5302.0
    08/01/2010 17:48:30, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1885.0, AS: 1.71.1885.0 Engine Version: 1.1.5302.0
    08/01/2010 17:38:20, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1885.0, AS: 1.71.1885.0 Engine Version: 1.1.5302.0
    08/01/2010 17:32:59, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1885.0, AS: 1.71.1885.0 Engine Version: 1.1.5302.0
    08/01/2010 17:27:56, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1885.0, AS: 1.71.1885.0 Engine Version: 1.1.5302.0
    08/01/2010 17:18:52, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1885.0, AS: 1.71.1885.0 Engine Version: 1.1.5302.0
    08/01/2010 17:13:43, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1885.0, AS: 1.71.1885.0 Engine Version: 1.1.5302.0
     
  11. 2010/01/09
    dogtag

    dogtag Inactive Thread Starter

    Joined:
    2008/08/17
    Messages:
    31
    Likes Received:
    0
    last part

    08/01/2010 17:08:37, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1885.0, AS: 1.71.1885.0 Engine Version: 1.1.5302.0
    08/01/2010 16:37:07, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
    08/01/2010 09:12:40, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
    07/01/2010 22:15:34, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
    07/01/2010 21:59:41, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the WLAN AutoConfig service, but this action failed with the following error: An instance of the service is already running.
    07/01/2010 21:58:40, Error: Service Control Manager [7034] - The Microsoft Antimalware Service service terminated unexpectedly. It has done this 3 time(s).
    07/01/2010 21:58:30, Error: Service Control Manager [7031] - The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
    07/01/2010 21:57:41, Error: Service Control Manager [7031] - The WLAN AutoConfig service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
    07/01/2010 21:57:41, Error: Service Control Manager [7031] - The Windows Driver Foundation - User-mode Driver Framework service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
    07/01/2010 21:57:41, Error: Service Control Manager [7031] - The Windows Audio Endpoint Builder service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    07/01/2010 21:57:41, Error: Service Control Manager [7031] - The Superfetch service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    07/01/2010 21:57:41, Error: Service Control Manager [7031] - The ReadyBoost service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    07/01/2010 21:57:41, Error: Service Control Manager [7031] - The Program Compatibility Assistant Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    07/01/2010 21:57:41, Error: Service Control Manager [7031] - The Portable Device Enumerator Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
    07/01/2010 21:57:41, Error: Service Control Manager [7031] - The Network Connections service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service.
    07/01/2010 21:57:41, Error: Service Control Manager [7031] - The Distributed Link Tracking Client service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
    07/01/2010 21:57:41, Error: Service Control Manager [7031] - The Desktop Window Manager Session Manager service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
    07/01/2010 21:57:11, Error: Service Control Manager [7024] - The Windows Firewall service terminated with service-specific error 2150760449 (0x80320001).
    07/01/2010 21:56:48, Error: Service Control Manager [7031] - The Terminal Services service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    07/01/2010 21:56:48, Error: Service Control Manager [7031] - The Telephony service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
    07/01/2010 21:56:48, Error: Service Control Manager [7031] - The Network Location Awareness service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service.
    07/01/2010 21:56:48, Error: Service Control Manager [7031] - The KtmRm for Distributed Transaction Coordinator service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 1000 milliseconds: Restart the service.
    07/01/2010 21:56:48, Error: Service Control Manager [7031] - The DNS Client service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
    07/01/2010 21:56:48, Error: Service Control Manager [7031] - The Cryptographic Services service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    07/01/2010 21:56:28, Error: Service Control Manager [7031] - The Software Licensing service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
    07/01/2010 21:54:44, Error: Service Control Manager [7031] - The Print Spooler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    07/01/2010 21:54:31, Error: Service Control Manager [7034] - The TuneUp Program Statistics Service service terminated unexpectedly. It has done this 1 time(s).
    07/01/2010 21:54:24, Error: Service Control Manager [7034] - The Bonjour Service service terminated unexpectedly. It has done this 1 time(s).
    07/01/2010 21:54:05, Error: Service Control Manager [7034] - The Ati External Event Utility service terminated unexpectedly. It has done this 1 time(s).
    07/01/2010 21:53:26, Error: Service Control Manager [7031] - The Microsoft Antimalware Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 15000 milliseconds: Restart the service.
    07/01/2010 21:49:37, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
    07/01/2010 21:32:36, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
    07/01/2010 20:30:48, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
    07/01/2010 19:49:55, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
    07/01/2010 19:28:16, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1885.0, AS: 1.71.1885.0 Engine Version: 1.1.5302.0
    07/01/2010 19:27:58, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1885.0, AS: 1.71.1885.0 Engine Version: 1.1.5302.0
    07/01/2010 18:55:39, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1885.0, AS: 1.71.1885.0 Engine Version: 1.1.5302.0
    07/01/2010 18:55:21, Error: Microsoft-Windows-WPD-MTPClassDriver [15300] - MTP WPD Driver has failed to start. Error 0x80070005.
    07/01/2010 18:40:45, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1885.0, AS: 1.71.1885.0 Engine Version: 1.1.5302.0
    07/01/2010 18:34:05, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1885.0, AS: 1.71.1885.0 Engine Version: 1.1.5302.0
    07/01/2010 18:29:04, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1885.0, AS: 1.71.1885.0 Engine Version: 1.1.5302.0
    07/01/2010 18:04:20, Error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Zbot.gen!R&threatid=2147618509 User: Allan-PC\Allan Name: PWS:Win32/Zbot.gen!R ID: 2147618509 Severity: Severe Category: Password Stealer Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.71.1885.0, AS: 1.71.1885.0 Engine Version: 1.1.5302.0
    07/01/2010 16:34:30, Error: EventLog [6008] - The previous system shutdown at 07:32:07 on 07/01/2010 was unexpected.
    06/01/2010 18:08:12, Error: EventLog [6008] - The previous system shutdown at 07:30:22 on 06/01/2010 was unexpected.
    06/01/2010 07:02:41, Error: EventLog [6008] - The previous system shutdown at 22:25:01 on 05/01/2010 was unexpected.
    04/01/2010 19:05:52, Error: EventLog [6008] - The previous system shutdown at 19:04:27 on 04/01/2010 was unexpected.
    04/01/2010 18:04:16, Error: Microsoft-Windows-Firewall [6400] - An attempt to programmatically disable the Windows Firewall using a call to INetFwProfile.FirewallEnabled(FALSE) interface was rejected because this API is not supported on Windows Vista. This has most likely occurred due to an application which is incompatible with Windows Vista. Please contact the application's vendor to make sure you have a Windows Vista compatible application version. Error Code: E_NOTIMPL Caller Process Name: C:\Windows\system32\svchost.exe Process Id: 880 Publisher: Microsoft Corporation
    03/01/2010 08:52:14, Error: Service Control Manager [7034] - The iPod Service service terminated unexpectedly. It has done this 1 time(s).
    02/01/2010 21:26:29, Error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    02/01/2010 10:52:16, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Reboot the machine) after the unexpected termination of the DCOM Server Process Launcher service, but this action failed with the following error: A system shutdown has already been scheduled.
    02/01/2010 10:52:16, Error: Service Control Manager [7031] - The Plug and Play service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Reboot the machine.
    02/01/2010 10:52:16, Error: Service Control Manager [7031] - The DCOM Server Process Launcher service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Reboot the machine.
    02/01/2010 09:43:55, Error: Service Control Manager [7034] - The Google Update Service (gupdate) service terminated unexpectedly. It has done this 1 time(s).
    02/01/2010 09:41:57, Error: ACPI [6] - IRQARB: ACPI BIOS does not contain an IRQ for the device in PCI slot 6, function 0. Please contact your system vendor for technical assistance.
    02/01/2010 09:41:57, Error: ACPI [6] - IRQARB: ACPI BIOS does not contain an IRQ for the device in PCI slot 5, function 0. Please contact your system vendor for technical assistance.
    02/01/2010 00:11:08, Error: Service Control Manager [7034] - The TuneUp Drive Defrag Service service terminated unexpectedly. It has done this 1 time(s).
    02/01/2010 00:02:35, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the ncvbads service to connect.
    02/01/2010 00:02:35, Error: Service Control Manager [7000] - The Parallel port driver service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
    02/01/2010 00:01:17, Error: EventLog [6008] - The previous system shutdown at 23:58:27 on 01/01/2010 was unexpected.

    ==== End Of File ===========================
     
  12. 2010/01/09
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Good.
    Go ahead with my previous instructions.
     
  13. 2010/01/10
    dogtag

    dogtag Inactive Thread Starter

    Joined:
    2008/08/17
    Messages:
    31
    Likes Received:
    0
    The SuperAntiSpyware.log

    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 01/10/2010 at 00:20 AM

    Application Version : 4.33.1000

    Core Rules Database Version : 4462
    Trace Rules Database Version: 2283

    Scan type : Complete Scan
    Total Scan Time : 00:26:22

    Memory items scanned : 303
    Memory threats detected : 0
    Registry items scanned : 6380
    Registry threats detected : 0
    File items scanned : 22846
    File threats detected : 1

    Trojan.Agent/Gen
    C:\Windows\system32\lowsec
     
  14. 2010/01/10
    dogtag

    dogtag Inactive Thread Starter

    Joined:
    2008/08/17
    Messages:
    31
    Likes Received:
    0
    Malware Bytes log

    Malwarebytes' Anti-Malware 1.44
    Database version: 3533
    Windows 6.0.6000
    Internet Explorer 7.0.6000.16945

    10/01/2010 12:05:38
    mbam-log-2010-01-10 (12-05-38).txt

    Scan type: Full Scan (C:\|)
    Objects scanned: 215575
    Time elapsed: 1 hour(s), 0 minute(s), 56 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 5
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> Quarantined and deleted successfully.
    HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> Quarantined and deleted successfully.
    HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully.
    HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> Quarantined and deleted successfully.
    HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully.

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)
     
  15. 2010/01/10
    dogtag

    dogtag Inactive Thread Starter

    Joined:
    2008/08/17
    Messages:
    31
    Likes Received:
    0
    Hey
    i ran the gmer.exe a few times and after running for about half an hour my laptop shuts down. I renamed the file to scan.exe but it's still not working??
    Thx
     
  16. 2010/01/10
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    OK.

    Please download ComboFix from [color= "Red"]Here[/color] or [color= "#FF0000"]Here[/color] to your Desktop.


    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    • Please, never rename Combofix unless instructed.
    • Close any open browsers.
    • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results ".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
    NOTE. If Combofix asks you to install Recovery Console, please allow it.

    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    • Double click on combofix.exe & follow the prompts.
    • When finished, it will produce a report for you.
    • Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review.
    **Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

    Make sure, you re-enable your security programs, when you're done with Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
     
  17. 2010/01/10
    dogtag

    dogtag Inactive Thread Starter

    Joined:
    2008/08/17
    Messages:
    31
    Likes Received:
    0
    Thanks
    running combofix now
     
  18. 2010/01/10
    dogtag

    dogtag Inactive Thread Starter

    Joined:
    2008/08/17
    Messages:
    31
    Likes Received:
    0
    ComboFix 10-01-04.01 - Allan 10/01/2010 21:42:14.2.2 - x86
    Microsoft® Windows Vistaâ„¢ Home Premium 6.0.6000.0.1252.44.1033.18.1917.1169 [GMT 0:00]
    Running from: c:\users\Allan\Desktop\ComboFix.exe
    AV: Microsoft Security Essentials *On-access scanning enabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
    SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
    SP: Microsoft Security Essentials *enabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDE}
    SP: Spybot - Search and Destroy *enabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
    SP: SUPERAntiSpyware *enabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
    SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\$recycle.bin\S-1-5-21-2152478756-3922319563-605102323-500

    .
    ((((((((((((((((((((((((( Files Created from 2009-12-10 to 2010-01-10 )))))))))))))))))))))))))))))))
    .

    2010-01-10 21:52 . 2010-01-10 21:53 -------- d-----w- c:\users\Allan\AppData\Local\temp
    2010-01-10 21:52 . 2010-01-10 21:52 -------- d-----w- c:\users\Default\AppData\Local\temp
    2010-01-10 21:33 . 2010-01-10 21:35 -------- d-----w- C:\32788R22FWJFW
    2010-01-10 09:21 . 2010-01-10 09:21 -------- d-----w- c:\users\Allan\AppData\Roaming\Malwarebytes
    2010-01-10 09:20 . 2010-01-07 16:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-01-10 09:20 . 2010-01-10 09:20 -------- d-----w- c:\programdata\Malwarebytes
    2010-01-10 09:20 . 2010-01-10 09:21 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2010-01-10 09:20 . 2010-01-07 16:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-01-09 23:29 . 2010-01-09 23:29 52224 ----a-w- c:\users\Allan\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
    2010-01-09 23:29 . 2010-01-09 23:29 117760 ----a-w- c:\users\Allan\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
    2010-01-09 23:27 . 2010-01-09 23:27 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
    2010-01-09 23:27 . 2010-01-09 23:27 -------- d-----w- c:\program files\SUPERAntiSpyware
    2010-01-09 23:27 . 2010-01-09 23:27 -------- d-----w- c:\users\Allan\AppData\Roaming\SUPERAntiSpyware.com
    2010-01-09 23:26 . 2010-01-09 23:26 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
    2010-01-09 14:50 . 2009-12-02 13:19 15880 ----a-w- c:\windows\system32\lsdelete.exe
    2010-01-09 12:35 . 2009-12-02 13:19 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
    2010-01-09 12:34 . 2010-01-09 12:34 862040 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\threatwork.exe
    2010-01-09 12:34 . 2010-01-09 12:34 206944 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\lavamessage.dll
    2010-01-09 12:34 . 2010-01-09 12:34 390288 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\lavalicense.dll
    2010-01-09 12:34 . 2010-01-09 12:34 537576 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\aawapi.dll
    2010-01-09 12:34 . 2010-01-09 12:34 370744 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\UpdateManager.dll
    2010-01-09 12:34 . 2010-01-09 12:34 194104 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Savapibridge.dll
    2010-01-09 12:33 . 2010-01-09 12:33 6296864 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Resources.dll
    2010-01-09 12:33 . 2010-01-09 12:33 933120 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\CEAPI.dll
    2010-01-09 12:33 . 2010-01-09 12:33 816272 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
    2010-01-09 12:33 . 2010-01-09 12:33 822904 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
    2010-01-09 12:33 . 2010-01-09 12:33 1643272 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
    2010-01-09 12:33 . 2010-01-09 12:33 788880 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\AAWTray.exe
    2010-01-09 12:33 . 2010-01-09 12:33 1181328 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\AAWService.exe
    2010-01-09 12:30 . 2009-08-24 12:47 378368 ----a-w- c:\windows\system32\winhttp.dll
    2010-01-09 12:28 . 2010-01-09 12:28 -------- dc-h--w- c:\programdata\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}
    2010-01-09 12:28 . 2009-12-07 14:10 2953352 -c--a-w- c:\programdata\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}\Ad-AwareInstallation.exe
    2010-01-09 12:26 . 2010-01-09 12:35 -------- d-----w- c:\programdata\Lavasoft
    2010-01-09 12:26 . 2010-01-09 12:26 -------- d-----w- c:\program files\Lavasoft
    2010-01-08 19:06 . 2010-01-08 19:06 -------- d-----w- c:\program files\CCleaner
    2010-01-08 18:47 . 2009-06-30 09:37 28552 ----a-w- c:\windows\system32\drivers\pavboot.sys
    2010-01-08 18:46 . 2010-01-08 18:46 -------- d-----w- c:\program files\Panda Security
    2010-01-08 18:43 . 2010-01-08 19:12 -------- d-----w- c:\program files\Spybot - Search & Destroy
    2010-01-08 18:43 . 2010-01-08 19:10 -------- d-----w- c:\programdata\Spybot - Search & Destroy
    2010-01-08 18:19 . 2010-01-08 18:19 -------- d-----w- c:\program files\Microsoft Silverlight
    2010-01-08 17:38 . 2010-01-09 23:40 -------- d-----w- c:\users\Allan\AppData\Roaming\vlc
    2010-01-07 17:54 . 2010-01-07 17:55 -------- d-----w- c:\program files\Microsoft Security Essentials
    2010-01-03 15:13 . 2010-01-03 15:13 -------- d-----w- c:\program files\DoremiSoft
    2010-01-03 09:40 . 2010-01-03 09:40 -------- d-----w- c:\program files\YouTube Downloader
    2010-01-03 09:37 . 2010-01-03 09:37 -------- d-----w- c:\users\Allan\AppData\Roaming\Apowersoft
    2010-01-03 09:36 . 2010-01-03 09:36 -------- d-----w- c:\program files\Apowersoft
    2010-01-02 22:29 . 2010-01-02 22:29 -------- d-----w- c:\program files\Conduit
    2010-01-02 22:29 . 2010-01-02 22:29 -------- d-----w- c:\program files\iPhone_OS_3
    2010-01-02 12:39 . 2010-01-09 23:43 -------- d-----w- c:\users\Allan\AppData\Local\Apple Computer
    2010-01-02 12:39 . 2010-01-02 17:30 -------- d-----w- c:\users\Allan\AppData\Roaming\Apple Computer
    2010-01-02 12:39 . 2009-05-18 14:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
    2010-01-02 12:39 . 2008-04-17 13:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
    2010-01-02 12:39 . 2010-01-09 12:35 -------- dc----w- c:\windows\system32\DRVSTORE
    2010-01-02 12:38 . 2010-01-02 12:38 -------- d-----w- c:\program files\iPod
    2010-01-02 12:38 . 2010-01-02 12:39 -------- d-----w- c:\programdata\{755AC846-7372-4AC8-8550-C52491DAA8BD}
    2010-01-02 12:38 . 2010-01-02 12:39 -------- d-----w- c:\program files\iTunes
    2010-01-02 12:37 . 2010-01-09 12:17 -------- d-----w- c:\program files\Bonjour
    2010-01-02 12:37 . 2010-01-02 12:37 -------- d-----w- c:\program files\QuickTime
    2010-01-02 12:37 . 2010-01-02 12:38 -------- d-----w- c:\programdata\Apple Computer
    2010-01-02 12:36 . 2010-01-02 12:36 -------- d-----w- c:\users\Allan\AppData\Local\Apple
    2010-01-02 12:36 . 2010-01-02 12:36 -------- d-----w- c:\program files\Apple Software Update
    2010-01-02 12:35 . 2010-01-02 17:24 -------- d-----w- c:\programdata\Apple
    2010-01-02 12:35 . 2010-01-02 12:38 -------- d-----w- c:\program files\Common Files\Apple
    2010-01-02 11:26 . 2010-01-02 11:26 -------- d-----w- c:\program files\FLV to MP4 Converter
    2010-01-02 01:03 . 2010-01-02 01:03 -------- dc----w- c:\programdata\{7D4B3D1D-104E-4507-9123-568BC721B7E2}
    2010-01-01 18:32 . 2010-01-01 23:59 -------- d-sh--w- c:\users\Allan\AppData\Roaming\lowsec
    2009-12-16 21:50 . 2010-01-03 09:45 -------- d-----w- c:\users\Allan\AppData\Roaming\DMCache
    2009-12-16 21:32 . 2009-12-16 21:32 -------- d-----w- c:\program files\Mozilla ActiveX Control v1.7.12
    2009-12-15 07:21 . 2006-12-20 06:03 229888 ----a-w- c:\windows\system32\msshsq.dll
    2009-12-15 07:20 . 2009-06-15 15:23 494592 ----a-w- c:\windows\system32\kerberos.dll
    2009-12-15 07:20 . 2009-06-15 15:28 272384 ----a-w- c:\windows\system32\schannel.dll
    2009-12-14 19:40 . 2009-12-14 19:40 -------- d-----w- c:\users\Allan\.gstreamer-0.10
    2009-12-13 23:14 . 2010-01-02 10:30 -------- d-----w- c:\programdata\OpenFM
    2009-12-13 23:14 . 2009-12-13 23:14 -------- d-----w- c:\users\Allan\AppData\Roaming\OpenFM
    2009-12-13 19:16 . 2009-12-13 19:16 -------- d-----w- c:\users\Allan\AppData\Local\assembly
    2009-12-12 22:00 . 2009-12-12 22:00 -------- d-----w- c:\program files\Microsoft SQL Server

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-01-10 12:07 . 2009-12-03 19:00 21560 ----a-w- c:\windows\system32\drivers\atapi.sys
    2010-01-08 18:40 . 2009-11-30 21:06 -------- d-----w- c:\program files\Google
    2010-01-08 18:29 . 2009-11-30 17:55 1356 ----a-w- c:\users\Allan\AppData\Local\d3d9caps.dat
    2010-01-07 18:26 . 2009-11-30 20:11 -------- d-sh--r- c:\program files\Common Files\tysarekb
    2010-01-03 19:59 . 2009-11-30 20:31 -------- d-----w- c:\users\Allan\AppData\Roaming\Free Download Manager
    2009-12-17 23:43 . 2009-11-30 17:55 100656 ----a-w- c:\users\Allan\AppData\Local\GDIPFONTCACHEV1.DAT
    2009-12-17 20:23 . 2009-12-05 16:05 -------- d-----w- c:\programdata\Microsoft Help
    2009-12-12 22:00 . 2009-12-05 15:21 -------- d-----w- c:\program files\Microsoft.NET
    2009-12-12 22:00 . 2009-12-05 16:06 -------- d-----w- c:\program files\Microsoft Analysis Services
    2009-12-11 16:55 . 2009-12-11 16:55 -------- d-----w- c:\programdata\D25E
    2009-12-10 18:47 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
    2009-12-10 17:22 . 2009-12-10 17:22 72704 ----a-w- c:\windows\system32\admparse.dll
    2009-12-10 17:22 . 2009-12-10 17:22 52736 ----a-w- c:\windows\AppPatch\iebrshim.dll
    2009-12-10 17:22 . 2009-12-10 17:22 832512 ----a-w- c:\windows\system32\wininet.dll
    2009-12-10 17:22 . 2009-12-10 17:22 78336 ----a-w- c:\windows\system32\ieencode.dll
    2009-12-10 17:22 . 2009-12-10 17:22 48128 ----a-w- c:\windows\system32\mshtmler.dll
    2009-12-10 17:21 . 2009-12-10 17:21 26624 ----a-w- c:\windows\system32\ieUnatt.exe
    2009-12-10 17:21 . 2009-12-10 17:21 56320 ----a-w- c:\windows\system32\iesetup.dll
    2009-12-10 17:19 . 2009-12-10 17:19 396800 ----a-w- c:\windows\system32\drivers\http.sys
    2009-12-10 17:19 . 2009-12-10 17:19 31232 ----a-w- c:\windows\system32\httpapi.dll
    2009-12-10 17:19 . 2009-12-10 17:19 24064 ----a-w- c:\windows\system32\nshhttp.dll
    2009-12-10 17:13 . 2009-12-10 17:13 274432 ----a-w- c:\windows\system32\raschap.dll
    2009-12-10 17:13 . 2009-12-10 17:13 232960 ----a-w- c:\windows\system32\rastls.dll
    2009-12-09 22:17 . 2009-12-09 17:27 -------- d-----w- c:\users\Allan\AppData\Roaming\Gadu-Gadu 10
    2009-12-09 20:47 . 2009-12-09 20:47 -------- d-----w- c:\program files\Ares
    2009-12-09 17:30 . 2009-12-09 17:30 -------- d-----w- c:\program files\Alwil Software
    2009-12-09 17:27 . 2009-12-09 17:27 -------- d-----w- c:\program files\Gadu-Gadu 10
    2009-12-06 16:04 . 2009-12-06 14:13 -------- d-----w- c:\program files\The Witcher Enhanced Edition
    2009-12-06 14:54 . 2009-12-06 14:54 279712 ----a-w- c:\windows\system32\drivers\atksgt.sys
    2009-12-06 14:54 . 2009-12-06 14:54 25888 ----a-w- c:\windows\system32\drivers\lirsgt.sys
    2009-12-06 14:14 . 2009-12-06 14:14 -------- d--h--w- c:\program files\InstallShield Installation Information
    2009-12-06 14:12 . 2009-12-05 18:59 -------- d-----w- c:\users\Allan\AppData\Roaming\DAEMON Tools Lite
    2009-12-06 04:35 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
    2009-12-06 04:34 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
    2009-12-06 04:15 . 2009-12-06 04:15 268800 ----a-w- c:\windows\system32\es.dll
    2009-12-06 04:13 . 2009-12-06 04:13 8704 ----a-w- c:\windows\system32\hcrstco.dll
    2009-12-06 04:13 . 2009-12-06 04:13 8704 ----a-w- c:\windows\system32\hccoin.dll
    2009-12-06 04:13 . 2009-12-06 04:13 5888 ----a-w- c:\windows\system32\drivers\usbd.sys
    2009-12-06 04:13 . 2009-12-06 04:13 38400 ----a-w- c:\windows\system32\drivers\usbehci.sys
    2009-12-06 04:13 . 2009-12-06 04:13 224768 ----a-w- c:\windows\system32\drivers\usbport.sys
    2009-12-06 04:13 . 2009-12-06 04:13 19456 ----a-w- c:\windows\system32\drivers\usbohci.sys
    2009-12-06 04:13 . 2009-12-06 04:13 192000 ----a-w- c:\windows\system32\drivers\usbhub.sys
    2009-12-06 04:13 . 2009-12-06 04:13 73216 ----a-w- c:\windows\system32\drivers\usbccgp.sys
    2009-12-06 04:11 . 2009-12-06 04:11 7042560 ----a-w- c:\windows\system32\NlsLexicons081a.dll
    2009-12-06 04:07 . 2009-12-06 04:07 61440 ----a-w- c:\windows\system32\ntprint.exe
    2009-12-06 04:07 . 2009-12-06 04:07 220160 ----a-w- c:\windows\system32\ntprint.dll
    2009-12-06 04:07 . 2009-12-06 04:07 10240 ----a-w- c:\windows\system32\dhcpcmonitor.dll
    2009-12-06 04:07 . 2009-12-06 04:07 120320 ----a-w- c:\windows\system32\dhcpcsvc6.dll
    2009-12-06 04:07 . 2009-12-06 04:07 1984512 ----a-w- c:\windows\system32\authui.dll
    2009-12-06 04:07 . 2009-12-06 04:07 69632 ----a-w- c:\windows\system32\sendmail.dll
    2009-12-06 04:07 . 2009-12-06 04:07 8138240 ----a-w- c:\windows\system32\ssBranded.scr
    2009-12-06 04:02 . 2009-12-06 04:02 97800 ----a-w- c:\windows\system32\infocardapi.dll
    2009-12-06 04:02 . 2009-12-06 04:02 622080 ----a-w- c:\windows\system32\icardagt.exe
    2009-12-06 04:02 . 2009-12-06 04:02 11264 ----a-w- c:\windows\system32\icardres.dll
    2009-12-06 04:02 . 2009-12-06 04:02 105016 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
    2009-12-06 04:02 . 2009-12-06 04:02 781344 ----a-w- c:\windows\system32\PresentationNative_v0300.dll
    2009-12-06 04:02 . 2009-12-06 04:02 43544 ----a-w- c:\windows\system32\PresentationHostProxy.dll
    2009-12-06 04:02 . 2009-12-06 04:02 326160 ----a-w- c:\windows\system32\PresentationHost.exe
    2009-12-06 03:26 . 2009-12-06 03:26 96760 ----a-w- c:\windows\system32\dfshim.dll
    2009-12-06 03:26 . 2009-12-06 03:26 41984 ----a-w- c:\windows\system32\netfxperf.dll
    2009-12-06 03:26 . 2009-12-06 03:26 282112 ----a-w- c:\windows\system32\mscoree.dll
    2009-12-06 03:26 . 2009-12-06 03:26 158720 ----a-w- c:\windows\system32\mscorier.dll
    2009-12-06 03:26 . 2009-12-06 03:26 83968 ----a-w- c:\windows\system32\mscories.dll
    2009-12-05 19:25 . 2009-12-05 19:24 -------- d-----w- c:\program files\Winamp
    2009-12-05 19:24 . 2009-12-05 19:24 -------- d-----w- c:\users\Allan\AppData\Roaming\Winamp
    2009-12-05 19:23 . 2009-12-05 19:23 -------- d-----w- c:\program files\Xiph.Org
    2009-12-05 19:02 . 2009-12-05 18:59 -------- d-----w- c:\program files\DAEMON Tools Lite
    2009-12-05 19:02 . 2009-12-05 19:02 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
    2009-12-05 18:59 . 2009-12-05 18:59 -------- d-----w- c:\programdata\DAEMON Tools Lite
    2009-12-05 18:47 . 2009-12-05 18:47 -------- d-----w- c:\program files\VideoLAN
    2009-12-05 17:50 . 2009-12-05 17:49 -------- d-----w- c:\program files\Common Files\Adobe
    2009-12-05 16:11 . 2006-11-02 12:37 -------- d-----w- c:\program files\MSBuild
    2009-12-05 16:10 . 2009-12-05 16:10 -------- d-----w- c:\program files\Microsoft Sync Framework
    2009-12-05 16:07 . 2009-12-05 16:07 -------- d-----w- c:\program files\Microsoft Visual Studio 8
    2009-12-05 15:55 . 2009-12-05 15:31 -------- d-----w- c:\users\Allan\AppData\Roaming\Download Manager
    2009-12-05 15:23 . 2009-12-05 15:23 -------- d-----w- c:\program files\Microsoft ActiveSync
    2009-12-05 13:54 . 2009-12-05 13:54 -------- d-----w- c:\program files\Guitar Pro 5
    2009-12-03 19:17 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
    2009-12-03 19:15 . 2009-12-03 19:15 87040 ----a-w- c:\windows\system32\msoert2.dll
    2009-12-03 19:15 . 2009-12-03 19:15 39424 ----a-w- c:\windows\system32\ACCTRES.dll
    2009-12-03 19:15 . 2009-12-03 19:15 205824 ----a-w- c:\windows\system32\msoeacct.dll
    2009-12-03 19:13 . 2009-12-03 19:13 704000 ----a-w- c:\windows\system32\PhotoScreensaver.scr
    2009-12-03 19:13 . 2009-12-03 19:13 356352 ----a-w- c:\windows\system32\wbem\wbemcomn.dll
    2009-12-03 19:13 . 2009-12-03 19:13 24064 ----a-w- c:\windows\system32\wtsapi32.dll
    2009-12-03 19:13 . 2009-12-03 19:13 258232 ----a-w- c:\windows\system32\drivers\acpi.sys
    2009-12-03 19:13 . 2009-12-03 19:13 20920 ----a-w- c:\windows\system32\drivers\compbatt.sys
    2009-12-03 19:13 . 2009-12-03 19:13 11264 ----a-w- c:\windows\system32\drivers\wmiacpi.sys
    2009-12-03 19:13 . 2009-12-03 19:13 28344 ----a-w- c:\windows\system32\drivers\battc.sys
    2009-12-03 19:13 . 2009-12-03 19:13 14208 ----a-w- c:\windows\system32\drivers\CmBatt.sys
    2009-12-03 19:13 . 2009-12-03 19:13 542720 ----a-w- c:\windows\system32\sysmain.dll
    2009-12-03 19:12 . 2009-12-03 19:12 123904 ----a-w- c:\windows\system32\L2SecHC.dll
    2009-12-03 19:12 . 2009-12-03 19:12 67584 ----a-w- c:\windows\system32\wlanhlp.dll
    2009-12-03 19:12 . 2009-12-03 19:12 502272 ----a-w- c:\windows\system32\wlansvc.dll
    2009-12-03 19:12 . 2009-12-03 19:12 47104 ----a-w- c:\windows\system32\wlanapi.dll
    2009-12-03 19:12 . 2009-12-03 19:12 297984 ----a-w- c:\windows\system32\wlansec.dll
    2009-12-03 19:12 . 2009-12-03 19:12 290816 ----a-w- c:\windows\system32\wlanmsm.dll
    2009-12-03 19:11 . 2009-12-03 19:11 7680 ----a-w- c:\windows\system32\lsass.exe
    2009-12-03 19:11 . 2009-12-03 19:11 72704 ----a-w- c:\windows\system32\secur32.dll
    2009-12-03 19:11 . 2009-12-03 19:11 408136 ----a-w- c:\windows\system32\drivers\ksecdd.sys
    2009-12-03 19:11 . 2009-12-03 19:11 216576 ----a-w- c:\windows\system32\msv1_0.dll
    2007-02-21 19:49 . 2007-02-21 19:49 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{74714d77-1695-4e73-a98e-25cb374f46b4} "= "c:\program files\iPhone_OS_3\tbiPho.dll" [2009-11-09 2331672]

    [HKEY_CLASSES_ROOT\clsid\{74714d77-1695-4e73-a98e-25cb374f46b4}]

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{74714d77-1695-4e73-a98e-25cb374f46b4}]
    2009-11-09 18:38 2331672 ----a-w- c:\program files\iPhone_OS_3\tbiPho.dll

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
    2009-11-03 21:12 556432 ----a-w- c:\progra~1\MICROS~3\Office14\URLREDIR.DLL

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{74714d77-1695-4e73-a98e-25cb374f46b4} "= "c:\program files\iPhone_OS_3\tbiPho.dll" [2009-11-09 2331672]

    [HKEY_CLASSES_ROOT\clsid\{74714d77-1695-4e73-a98e-25cb374f46b4}]

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
    "{74714D77-1695-4E73-A98E-25CB374F46B4} "= "c:\program files\iPhone_OS_3\tbiPho.dll" [2009-11-09 2331672]

    [HKEY_CLASSES_ROOT\clsid\{74714d77-1695-4e73-a98e-25cb374f46b4}]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SpybotSD TeaTimer "= "c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
    "DAEMON Tools Lite "= "c:\program files\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Windows Defender "= "c:\program files\Windows Defender\MSASCui.exe" [2009-12-03 1006264]
    "MSSE "= "c:\program files\Microsoft Security Essentials\msseces.exe" [2009-09-13 1048392]

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} "= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    2009-09-03 14:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "aux1 "=wdmaud.drv

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
    BootExecute REG_MULTI_SZ autocheck autochk *\0lsdelete\0aswBoot.exe /M:4070ad29d

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
    @= "Service "

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
    @= "Service "

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
    @= "Service "

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
    2009-11-12 16:33 141600 ----a-w- c:\program files\iTunes\iTunesHelper.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    2009-11-10 23:08 417792 ----a-w- c:\program files\QuickTime\QTTask.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
    "ares "= "c:\program files\Ares\Ares.exe" -h
    "DAEMON Tools Lite "= "c:\program files\DAEMON Tools Lite\DTLite.exe" -autorun
    "msnmsgr "= "c:\program files\Windows Live\Messenger\msnmsgr.exe" /background

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
    "OEM02Mon.exe "=c:\windows\OEM02Mon.exe
    "Adobe Reader Speed Launcher "= "c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe "
    "Adobe ARM "= "c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe "
    "StartCCC "= "c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

    R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [09/01/2010 12:35 64288]
    R0 pavboot;pavboot;c:\windows\System32\drivers\pavboot.sys [08/01/2010 18:47 28552]
    R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [05/01/2010 07:56 9968]
    R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [05/01/2010 07:56 74480]
    R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [02/12/2009 13:19 1181328]
    R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [08/01/2010 18:44 1153368]
    S0 sptd;sptd;c:\windows\System32\drivers\sptd.sys [05/12/2009 19:02 691696]
    S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [30/11/2009 21:06 135664]
    S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [29/10/2009 10:22 30603640]
    S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\System32\drivers\MpNWMon.sys [18/06/2009 18:48 42480]
    S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [26/09/2009 04:28 4639136]
    S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [05/01/2010 07:56 7408]

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
    UxTuneUp
    .
    Contents of the 'Scheduled Tasks' folder

    2010-01-10 c:\windows\Tasks\1-Click Maintenance.job
    - c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-11-20 16:28]

    2010-01-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-11-30 21:06]

    2010-01-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-11-30 21:06]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.google.co.uk/
    uInternet Settings,ProxyOverride = *.local
    IE: Download all with Free Download Manager - file://c:\program files\Free Download Manager\dlall.htm
    IE: Download selected with Free Download Manager - file://c:\program files\Free Download Manager\dlselected.htm
    IE: Download video with Free Download Manager - file://c:\program files\Free Download Manager\dlfvideo.htm
    IE: Download with Free Download Manager - file://c:\program files\Free Download Manager\dllink.htm
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office14\EXCEL.EXE/3000
    IE: Se&nd to OneNote - /105
    Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
    FF - ProfilePath - c:\users\Allan\AppData\Roaming\Mozilla\Firefox\Profiles\eev4jn5m.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
    FF - plugin: c:\progra~1\MICROS~3\Office14\NPAUTHZ.DLL
    FF - plugin: c:\progra~1\MICROS~3\Office14\NPSPWRAP.DLL
    FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
    FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
    FF - plugin: c:\users\Allan\AppData\Roaming\Gadu-Gadu 10\_userdata\npgg.2.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

    ---- FIREFOX POLICIES ----
    FF - user.js: network.http.max-persistent-connections-per-server - 4
    FF - user.js: nglayout.initialpaint.delay - 600
    FF - user.js: content.notify.interval - 600000
    FF - user.js: content.max.tokenizing.time - 1800000
    FF - user.js: content.switch.threshold - 600000
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2010-01-10 21:53
    Windows 6.0.6000 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************

    Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

    device: opened successfully
    user: MBR read successfully
    called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll >>UNKNOWN [0x83D77618]<<
    kernel: MBR read successfully
    detected MBR rootkit hooks:
    \Driver\Disk -> CLASSPNP.SYS @ 0x879e4d1f
    \Driver\ACPI -> acpi.sys @ 0x802329d6
    \Driver\atapi -> ataport.SYS @ 0x807de9c6
    IoDeviceObjectType ->\Device\Harddisk0\DR0 ->user & kernel MBR OK

    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial "=dword:00000000
    .
    Completion time: 2010-01-10 21:57:20
    ComboFix-quarantined-files.txt 2010-01-10 21:57

    Pre-Run: 148,189,253,632 bytes free
    Post-Run: 148,169,457,664 bytes free

    - - End Of File - - DD4DA43F1C5AED83047FB63C18D2C6A6
     
  19. 2010/01/10
    dogtag

    dogtag Inactive Thread Starter

    Joined:
    2008/08/17
    Messages:
    31
    Likes Received:
    0
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 22:02:48, on 10/01/2010
    Platform: Windows Vista (WinNT 6.00.1904)
    MSIE: Internet Explorer v7.00 (7.00.6000.16945)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
    C:\Windows\system32\conime.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Windows\explorer.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\iTunes\iTunes.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceHelper.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\distnoted.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\SyncServer.exe
    C:\Windows\system32\taskeng.exe
    C:\Users\Allan\Downloads\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: iPhone OS 3 Toolbar - {74714d77-1695-4e73-a98e-25cb374f46b4} - C:\Program Files\iPhone_OS_3\tbiPho.dll
    O1 - Hosts: ::1 localhost
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL
    O2 - BHO: iPhone OS 3 Toolbar - {74714d77-1695-4e73-a98e-25cb374f46b4} - C:\Program Files\iPhone_OS_3\tbiPho.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL
    O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
    O3 - Toolbar: iPhone OS 3 Toolbar - {74714d77-1695-4e73-a98e-25cb374f46b4} - C:\Program Files\iPhone_OS_3\tbiPho.dll
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [MSSE] "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
    O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
    O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
    O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
    O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office14\EXCEL.EXE/3000
    O8 - Extra context menu item: Se&nd to OneNote - res:///105
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
    O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
    O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O16 - DPF: {40F576AD-8680-4F9E-9490-99D069CD665F} (System Requirements Lab Class) - http://srtest-cdn.systemrequirementslab.com.s3.amazonaws.com/bin/sysreqlabdetect.cab
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Windows\System32\TuneUpDefragService.exe
    O23 - Service: @%SystemRoot%\System32\TUProgSt.exe,-1 (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\Windows\System32\TUProgSt.exe

    --
    End of file - 6446 bytes
     
  20. 2010/01/10
    dogtag

    dogtag Inactive Thread Starter

    Joined:
    2008/08/17
    Messages:
    31
    Likes Received:
    0
    Thanks for your help
     
  21. 2010/01/10
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Please download [color= "#CC0000"]The Avenger[/color] by Swandog46 to your Desktop.
    - Right click on the Avenger.zip folder and select Extract All...
    - Follow the prompts and extract the avenger folder to your desktop

    Double click on avenger.exe.
    Click OK in pop-up window.

    Avenger window will open.

    Click on Execute button.
    Click OK in two consecutive pop-up windows.

    Your computer will re-boot now.

    Upon re-boot, Notepad window will open.
    Select all text, copy it, and paste it into next reply.

    NOTE. If the log doesn't open on reboot, open Avenger again, and go File>Open Log File.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.