1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved No access to anti-virus sites

Discussion in 'Malware and Virus Removal Archive' started by doflamingo, 2010/12/13.

  1. 2010/12/13
    doflamingo

    doflamingo Inactive Thread Starter

    Joined:
    2010/12/13
    Messages:
    29
    Likes Received:
    0
    [Resolved] No access to anti-virus sites

    hello everyone.
    i am using Microsoft XP Professional Version 2002 Service Pack 2.
    I think a virus have infected it. The virus stop my avira guard, and it won't allow me to access all anti virus sites, such as avira, avg, bitdefender, and kaspersky. I uninstalled the Avira, and when i tried to re-install it, it failed. The virus also disabled my System Restore, it is said that my System Restore is disabled by Group Policy.

    When i open the folder options and unmark the "Hide protected operating system files (Recommended)" there is no warning, but when i mark it, a warning pop up, and it is said "You have chosen to display protected operating system (files labeled system and hidden) in Windows explorer "

    I scan my computer with an Anti virus in my country, and it found 126 registry infected, so i chose to fix them all. when i re-scan it, it found 126 registry key infected again.

    in the rule of this forum, it asked me to post a log from malwarebytes (MBAM), but i cannot download it, the virus won't allow me to open that site.

    please, help me :(
     
  2. 2010/12/13
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Welcome aboard :)

    Please, read this post, then post the requested log(s).

    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running tools or applying updates other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.
     

  3. to hide this advert.

  4. 2010/12/14
    doflamingo

    doflamingo Inactive Thread Starter

    Joined:
    2010/12/13
    Messages:
    29
    Likes Received:
    0
    Hi again :D

    after i run the TFC, suddenly my computer can access the anti virus sites, so i download kaspersky, and had it to full scan my computer. :D

    right now my computer are perform better than before, but maybe the virus still infect it.
    by the way, here's the log ( oh yeah, i'm sorry for my bad english )

    ===MBAM===

    Malwarebytes' Anti-Malware 1.50
    www.malwarebytes.org

    Database version: 5309

    Windows 5.1.2600 Service Pack 2
    Internet Explorer 6.0.2900.2180

    12/14/2010 10:34:29 AM
    mbam-log-2010-12-14 (10-34-29).txt

    Scan type: Quick scan
    Objects scanned: 128688
    Time elapsed: 3 minute(s), 35 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 4
    Registry Values Infected: 0
    Registry Data Items Infected: 2
    Folders Infected: 0
    Files Infected: 3

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MRXCLS (Rootkit.TmpHider) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MRXNET (Rootkit.TmpHider) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MRxCls (Rootkit.TmpHider) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MRxNet (Rootkit.TmpHider) -> Quarantined and deleted successfully.

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    c:\WINDOWS\inf\mdmcpq3.PNF (Rootkit.TmpHider) -> Quarantined and deleted successfully.
    c:\WINDOWS\inf\mdmeric3.PNF (Rootkit.TmpHider) -> Quarantined and deleted successfully.
    c:\WINDOWS\inf\oem6C.PNF (Rootkit.TmpHider) -> Quarantined and deleted successfully.

    ===End of MBAM===
     
  5. 2010/12/14
    doflamingo

    doflamingo Inactive Thread Starter

    Joined:
    2010/12/13
    Messages:
    29
    Likes Received:
    0
    ===GMER Log (Part 1)===

    GMER 1.0.15.15530 - http://www.gmer.net
    Rootkit scan 2010-12-14 12:25:57
    Windows 5.1.2600 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 FUJITSU_MJA2160BH_G2 rev.8919
    Running: gmer.exe; Driver: C:\DOCUME~1\nika\LOCALS~1\Temp\ugtcrpod.sys


    ---- System - GMER 1.0.15 ----

    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwAdjustPrivilegesToken [0xA9C2E5FA]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwClose [0xA9C2EEFE]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwConnectPort [0xA9C2FD32]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateEvent [0xA9C3027C]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateFile [0xA9C2F1DA]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateKey [0xA9C2D46A]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateMutant [0xA9C30162]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateNamedPipeFile [0xA9C2E1E8]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreatePort [0xA9C30036]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateSection [0xA9C2E390]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateSemaphore [0xA9C3039C]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateThread [0xA9C2EB86]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateWaitablePort [0xA9C300CC]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDebugActiveProcess [0xA9C31A84]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDeleteKey [0xA9C2DA74]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDeleteValueKey [0xA9C2DE28]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDeviceIoControlFile [0xA9C2F65C]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDuplicateObject [0xA9C32C90]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwEnumerateKey [0xA9C2DF74]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwEnumerateValueKey [0xA9C2E00C]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwFsControlFile [0xA9C2F46A]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwLoadDriver [0xA9C31B76]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwLoadKey [0xA9C2D446]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwLoadKey2 [0xA9C2D458]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwMapViewOfSection [0xA9C322DE]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwNotifyChangeKey [0xA9C2E138]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenEvent [0xA9C30312]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenFile [0xA9C2EF80]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenKey [0xA9C2D62A]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenMutant [0xA9C301F2]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenProcess [0xA9C2E836]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenSection [0xA9C32078]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenSemaphore [0xA9C30432]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenThread [0xA9C2E728]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueryKey [0xA9C2E0A4]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueryMultipleValueKey [0xA9C2DCDC]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQuerySection [0xA9C32618]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueryValueKey [0xA9C2D906]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueueApcThread [0xA9C31F0A]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwRenameKey [0xA9C2DB96]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwReplaceKey [0xA9C2CE80]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwReplyPort [0xA9C30796]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwReplyWaitReceivePort [0xA9C3065C]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwRequestWaitReplyPort [0xA9C3181E]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwRestoreKey [0xA9C2D1F8]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwResumeThread [0xA9C32B32]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSaveKey [0xA9C2CE18]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSecureConnectPort [0xA9C2FA78]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetContextThread [0xA9C2EDA2]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetInformationToken [0xA9C310BE]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetSecurityObject [0xA9C31D14]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetSystemInformation [0xA9C32768]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetValueKey [0xA9C2D780]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSuspendProcess [0xA9C3285A]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSuspendThread [0xA9C32994]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSystemDebugControl [0xA9C319A8]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwTerminateProcess [0xA9C2E9D2]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwTerminateThread [0xA9C2E932]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwUnmapViewOfSection [0xA9C324BC]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwWriteVirtualMemory [0xA9C2EABC]

    INT 0x62 ? 865D7BF8
    INT 0x63 ? 865D7BF8
    INT 0x63 ? 865D7BF8
    INT 0x63 ? 86395BF8
    INT 0x63 ? 86395BF8
    INT 0x63 ? 865D7BF8
    INT 0x73 ? 86395BF8
    INT 0x73 ? 86395BF8
    INT 0x82 ? 865D7BF8
    INT 0x84 ? 86395BF8
    INT 0x94 ? 86395BF8
    INT 0xA4 ? 86395BF8

    Code \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) FsRtlCheckLockForReadAccess
    Code \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) IoIsOperationSynchronous

    ---- Kernel code sections - GMER 1.0.15 ----

    .text ntkrnlpa.exe!FsRtlCheckLockForReadAccess 804EAE40 5 Bytes JMP A9C20FEC \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)
    .text ntkrnlpa.exe!IoIsOperationSynchronous 804EF634 5 Bytes JMP A9C213C8 \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)
    .text ntkrnlpa.exe!ZwCallbackReturn + 2CB8 805038B8 12 Bytes [76, 1B, C3, A9, 46, D4, C2, ...]
    .text ntkrnlpa.exe!ZwCallbackReturn + 2D1C 8050391C 4 Bytes CALL 3F60E2E3
    .text ntkrnlpa.exe!ZwCallbackReturn + 2E34 80503A34 16 Bytes [96, DB, C2, A9, 80, CE, C2, ...] {XCHG ESI, EAX; FCMOVNB ST, ST(2); TEST EAX, 0xa9c2ce80; XCHG ESI, EAX; POP ES; RET ; TEST EAX, 0xa9c3065c}
    .text ntkrnlpa.exe!ZwCallbackReturn + 2F38 80503B38 8 Bytes JMP 6982E4FF
    .text ntkrnlpa.exe!ZwCallbackReturn + 2F88 80503B88 4 Bytes JMP 3DBCA9C2
    ? lhec.sys The system cannot find the file specified. !
    ? spiz.sys The system cannot find the file specified. !
    .text USBPORT.SYS!DllUnload F650162C 5 Bytes JMP 863951D8
    .text a1nen24q.SYS F5FBA386 35 Bytes [00, 00, 00, 00, 00, 00, 20, ...]
    .text a1nen24q.SYS F5FBA3AA 24 Bytes [00, 00, 00, 00, 00, 00, 00, ...]
    .text a1nen24q.SYS F5FBA3C4 3 Bytes [00, 70, 02] {ADD [EAX+0x2], DH}
    .text a1nen24q.SYS F5FBA3C9 1 Byte [2E]
    .text a1nen24q.SYS F5FBA3C9 11 Bytes [2E, 00, 00, 00, 5C, 02, 00, ...] {ADD CS:[EAX], AL; ADD [EDX+EAX+0x0], BL; ADD [EAX], AL; ADD [EAX], AL}
    .text ...
    pnidata C:\WINDOWS\system32\DRIVERS\secdrv.sys unknown last section [0xA8EA5F00, 0x24000, 0x48000000]

    ---- User code sections - GMER 1.0.15 ----

    ? C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] C:\WINDOWS\system32\ntdll.dll time/date stamp mismatch;
    ? C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] C:\WINDOWS\system32\kernel32.dll time/date stamp mismatch;
    .text C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] USER32.dll!VRipOutput + FFFA5010 77D42A78 4 Bytes [E0, 13, 48, 6C] {LOOPNZ 0x15; DEC EAX; INSB }
    ? C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] C:\WINDOWS\system32\ntdll.dll time/date stamp mismatch;
    ? C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] C:\WINDOWS\system32\kernel32.dll time/date stamp mismatch;
    .text C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] USER32.dll!VRipOutput + FFFA5010 77D42A78 4 Bytes [E0, 13, 48, 6C] {LOOPNZ 0x15; DEC EAX; INSB }

    ---- Kernel IAT/EAT - GMER 1.0.15 ----

    IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F72A7040] spiz.sys
    IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F72A713C] spiz.sys
    IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F72A70BE] spiz.sys
    IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F72A77FC] spiz.sys
    IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F72A76D2] spiz.sys
    IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F72B7048] spiz.sys
    IAT \SystemRoot\System32\Drivers\a1nen24q.SYS[HAL.dll!KfAcquireSpinLock] 8A000002
    IAT \SystemRoot\System32\Drivers\a1nen24q.SYS[HAL.dll!READ_PORT_UCHAR] 83880846
    IAT \SystemRoot\System32\Drivers\a1nen24q.SYS[HAL.dll!KeGetCurrentIrql] 000001C0
    IAT \SystemRoot\System32\Drivers\a1nen24q.SYS[HAL.dll!KfRaiseIrql] 2C4EB70F
    IAT \SystemRoot\System32\Drivers\a1nen24q.SYS[HAL.dll!KfLowerIrql] 8303C183
    IAT \SystemRoot\System32\Drivers\a1nen24q.SYS[HAL.dll!HalGetInterruptVector] D103FCE1
    IAT \SystemRoot\System32\Drivers\a1nen24q.SYS[HAL.dll!HalTranslateBusAddress] 2E7E8366
    IAT \SystemRoot\System32\Drivers\a1nen24q.SYS[HAL.dll!KeStallExecutionProcessor] 8D1C7400
    IAT \SystemRoot\System32\Drivers\a1nen24q.SYS[HAL.dll!KfReleaseSpinLock] 83893204
    IAT \SystemRoot\System32\Drivers\a1nen24q.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] 00000218
    IAT \SystemRoot\System32\Drivers\a1nen24q.SYS[HAL.dll!READ_PORT_USHORT] 2E4EB70F
    IAT \SystemRoot\System32\Drivers\a1nen24q.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 021C8B89
    IAT \SystemRoot\System32\Drivers\a1nen24q.SYS[HAL.dll!WRITE_PORT_UCHAR] B70F0000
    IAT \SystemRoot\System32\Drivers\a1nen24q.SYS[WMILIB.SYS!WmiSystemControl] 03D00304
    IAT \SystemRoot\System32\Drivers\a1nen24q.SYS[WMILIB.SYS!WmiCompleteRequest] 0CB389F2
    IAT \SystemRoot\system32\DRIVERS\tcpip.sys[TDI.SYS!TdiRegisterDeviceObject] [F6BF4D50] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab ZAO)
    IAT \SystemRoot\system32\DRIVERS\netbt.sys[TDI.SYS!TdiRegisterDeviceObject] [F6BF4D50] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab ZAO)

    ===End of GMER part1===
     
  6. 2010/12/14
    doflamingo

    doflamingo Inactive Thread Starter

    Joined:
    2010/12/13
    Messages:
    29
    Likes Received:
    0
    ===GMER Part 2===

    ---- User IAT/EAT - GMER 1.0.15 ----

    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!RtlAllocateHeap] 00EC0240
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!RtlFreeHeap] 00EC02B0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!RtlSizeHeap] 00EC0320
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!RtlReAllocateHeap] 00EC0390
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!SetErrorMode] 010E04E0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 010E0550
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!GetProcAddress] 010E05C0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!FreeLibrary] 010E0630
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!GetModuleHandleA] 010E06A0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!HeapDestroy] 00EC0940
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!HeapCreate] 00EC09B0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!VirtualFree] 00EC0A20
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!VirtualAlloc] 00EC0A90
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateThread] 00EC0B70
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\ADVAPI32.dll [ntdll.dll!RtlFreeHeap] 00EC0CC0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\ADVAPI32.dll [ntdll.dll!RtlAllocateHeap] 00EC0D30
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\ADVAPI32.dll [ntdll.dll!RtlReAllocateHeap] 00EC0DA0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!SetErrorMode] 010E08D0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!CreateThread] 00EC0E10
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetModuleHandleW] 010E0940
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 010E09B0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetModuleHandleA] 010E0A20
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!FreeLibrary] 010E0A90
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] 010E0B00
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!VirtualAlloc] 00EC0F60
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!VirtualFree] 7C9B0400
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\RPCRT4.dll [ntdll.dll!RtlFreeHeap] 7C9B0470
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\RPCRT4.dll [ntdll.dll!RtlAllocateHeap] 7C9B04E0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!VirtualFree] 7C9B05C0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] 010E0B70
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!FreeLibrary] 010E0BE0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 010E0C50
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateThread] 7C9B06A0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!GetModuleHandleW] 010E0CC0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!VirtualAlloc] 7C9B0710
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!FreeLibrary] 010E0D30
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] 010E0DA0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 010E0E10
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!CreateThread] 7C9B0780
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetModuleHandleA] 010E0E80
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\USER32.dll [ntdll.dll!RtlAllocateHeap] 7C9B07F0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\USER32.dll [ntdll.dll!RtlFreeHeap] 7C9B0860
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetModuleHandleW] 010E0EF0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateThread] 7C9B08D0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!VirtualFree] 7C9B0A20
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetModuleHandleA] 010E0F60
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 7D1E02B0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetProcAddress] 7D1E0320
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!FreeLibrary] 7D1E0390
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\GDI32.dll [ntdll.dll!RtlAllocateHeap] 7C9B0B70
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\GDI32.dll [ntdll.dll!RtlFreeHeap] 7C9B0BE0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 7D1E0400
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!FreeLibrary] 7D1E0470
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] 7D1E04E0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\userenv.dll [ntdll.dll!RtlFreeHeap] 00ED02B0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\userenv.dll [KERNEL32.dll!SetErrorMode] 7D1E0B70
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\userenv.dll [KERNEL32.dll!CreateThread] 00ED0320
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\userenv.dll [KERNEL32.dll!GetProcAddress] 7D1E0BE0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\userenv.dll [KERNEL32.dll!FreeLibrary] 7D1E0C50
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\userenv.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 7D1E0CC0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\secur32.dll [ntdll.dll!RtlFreeHeap] 00ED0400
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\secur32.dll [ntdll.dll!RtlAllocateHeap] 00ED0470
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\secur32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 7D1E0EF0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\secur32.dll [KERNEL32.dll!GetModuleHandleW] 7D1E0F60
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\secur32.dll [KERNEL32.dll!GetProcAddress] 010F0010
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\secur32.dll [KERNEL32.dll!FreeLibrary] 010F0080
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\netapi32.dll [ntdll.dll!RtlAllocateHeap] 00ED04E0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\netapi32.dll [ntdll.dll!RtlFreeHeap] 00ED0550
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\netapi32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 010F00F0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\netapi32.dll [KERNEL32.dll!FreeLibrary] 010F0160
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\netapi32.dll [KERNEL32.dll!GetProcAddress] 010F01D0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\netapi32.dll [KERNEL32.dll!CreateThread] 00ED06A0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 010F0710
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!SetErrorMode] 010F0780
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetModuleHandleA] 010F07F0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetModuleHandleW] 010F0860
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!FreeLibrary] 010F08D0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateThread] 00ED0A90
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!HeapDestroy] 00ED0B00
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!HeapCreate] 00ED0BE0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] 010F0940
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\ole32.dll [ntdll.dll!RtlFreeHeap] 00ED0D30
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetProcAddress] 010F0A20
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!FreeLibrary] 010F0A90
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetModuleHandleW] 010F0B00
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateThread] 00ED0F60
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!VirtualAlloc] 00EE0010
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 010F0B70
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\SHELL32.dll [ntdll.dll!RtlFreeHeap] 00EE01D0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!VirtualAlloc] 00EE0240
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetModuleHandleA] 010F0C50
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!HeapCreate] 00EE02B0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!VirtualFree] 00EE0320
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!HeapDestroy] 00EE04E0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 010F0CC0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetModuleHandleW] 010F0D30
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!SetErrorMode] 010F0DA0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] 010F0E10
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateThread] 00EE0550
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!FreeLibrary] 010F0E80
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!FreeLibrary] 01100B70
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!GetProcAddress] 01100BE0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[380] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!SetUnhandledExceptionFilter] 01100C50
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!RtlAllocateHeap] 00BF0240
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!RtlFreeHeap] 00BF02B0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!RtlSizeHeap] 00BF0320
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!RtlReAllocateHeap] 00BF0390
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!SetErrorMode] 00EC04E0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 00EC0550
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!GetProcAddress] 00EC05C0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!FreeLibrary] 00EC0630
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!GetModuleHandleA] 00EC06A0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!HeapDestroy] 00BF0940
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!HeapCreate] 00BF09B0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!VirtualFree] 00BF0A20
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!VirtualAlloc] 00BF0A90
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateThread] 00BF0B70
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\ADVAPI32.dll [ntdll.dll!RtlFreeHeap] 00BF0CC0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\ADVAPI32.dll [ntdll.dll!RtlAllocateHeap] 00BF0D30
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\ADVAPI32.dll [ntdll.dll!RtlReAllocateHeap] 00BF0DA0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!SetErrorMode] 00EC08D0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!CreateThread] 00BF0E10
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetModuleHandleW] 00EC0940
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 00EC09B0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetModuleHandleA] 00EC0A20
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!FreeLibrary] 00EC0A90
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] 00EC0B00
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!VirtualAlloc] 00BF0F60
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!VirtualFree] 7C9B0400
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\RPCRT4.dll [ntdll.dll!RtlFreeHeap] 7C9B0470
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\RPCRT4.dll [ntdll.dll!RtlAllocateHeap] 7C9B04E0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!VirtualFree] 7C9B05C0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] 00EC0B70
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!FreeLibrary] 00EC0BE0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 00EC0C50
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateThread] 7C9B06A0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!GetModuleHandleW] 00EC0CC0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!VirtualAlloc] 7C9B0710
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!FreeLibrary] 00EC0D30
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] 00EC0DA0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 00EC0E10
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!CreateThread] 7C9B0780
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetModuleHandleA] 00EC0E80
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\USER32.dll [ntdll.dll!RtlAllocateHeap] 7C9B07F0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\USER32.dll [ntdll.dll!RtlFreeHeap] 7C9B0860
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetModuleHandleW] 00EC0EF0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateThread] 7C9B08D0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!VirtualFree] 7C9B0A20
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetModuleHandleA] 00EC0F60
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 7D1E02B0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetProcAddress] 7D1E0320
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!FreeLibrary] 7D1E0390
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\GDI32.dll [ntdll.dll!RtlAllocateHeap] 7C9B0B70
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\GDI32.dll [ntdll.dll!RtlFreeHeap] 7C9B0BE0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 7D1E0400
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!FreeLibrary] 7D1E0470
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] 7D1E04E0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\userenv.dll [ntdll.dll!RtlFreeHeap] 00C002B0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\userenv.dll [KERNEL32.dll!SetErrorMode] 7D1E0B70
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\userenv.dll [KERNEL32.dll!CreateThread] 00C00320
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\userenv.dll [KERNEL32.dll!GetProcAddress] 7D1E0BE0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\userenv.dll [KERNEL32.dll!FreeLibrary] 7D1E0C50
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\userenv.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 7D1E0CC0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\secur32.dll [ntdll.dll!RtlFreeHeap] 00C00400
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\secur32.dll [ntdll.dll!RtlAllocateHeap] 00C00470
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\secur32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 7D1E0EF0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\secur32.dll [KERNEL32.dll!GetModuleHandleW] 7D1E0F60
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\secur32.dll [KERNEL32.dll!GetProcAddress] 00ED0010
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\secur32.dll [KERNEL32.dll!FreeLibrary] 00ED0080
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\netapi32.dll [ntdll.dll!RtlAllocateHeap] 00C004E0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\netapi32.dll [ntdll.dll!RtlFreeHeap] 00C00550
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\netapi32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 00ED00F0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\netapi32.dll [KERNEL32.dll!FreeLibrary] 00ED0160
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\netapi32.dll [KERNEL32.dll!GetProcAddress] 00ED01D0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\netapi32.dll [KERNEL32.dll!CreateThread] 00C006A0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 00ED0710
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!SetErrorMode] 00ED0780
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetModuleHandleA] 00ED07F0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetModuleHandleW] 00ED0860
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!FreeLibrary] 00ED08D0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateThread] 00C00A90
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!HeapDestroy] 00C00B00
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!HeapCreate] 00C00BE0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] 00ED0940
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\ole32.dll [ntdll.dll!RtlFreeHeap] 00C00D30
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetProcAddress] 00ED0A20
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!FreeLibrary] 00ED0A90
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetModuleHandleW] 00ED0B00
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateThread] 00C00F60
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!VirtualAlloc] 00C10010
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 00ED0B70
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\SHELL32.dll [ntdll.dll!RtlFreeHeap] 00C101D0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!VirtualAlloc] 00C10240
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetModuleHandleA] 00ED0C50
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!HeapCreate] 00C102B0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!VirtualFree] 00C10320
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!HeapDestroy] 00C104E0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 00ED0CC0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetModuleHandleW] 00ED0D30
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!SetErrorMode] 00ED0DA0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] 00ED0E10
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateThread] 00C10550
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!FreeLibrary] 00ED0E80
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!FreeLibrary] 00EE07F0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!GetProcAddress] 00EE0860
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe[616] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!SetUnhandledExceptionFilter] 00EE08D0
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3204] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [610E9B95] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3204] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [610E9AC7] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3204] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [610E93C2] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3204] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [610E9B07] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3204] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [610E9B95] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3204] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [610E9AC7] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3204] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [610E93C2] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3204] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [610E9B07] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3204] @ C:\WINDOWS\system32\USER32.dll [GDI32.dll!GetStockObject] [610E89AA] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3204] @ C:\WINDOWS\system32\SHELL32.dll [GDI32.dll!GetStockObject] [610E89AA] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3204] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!AnimateWindow] [610E89E8] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3204] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TrackPopupMenuEx] [610E8922] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3204] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DefWindowProcA] [610E8FD9] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3204] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetSysColor] [610E8960] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3204] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DefWindowProcW] [610E8FD9] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3204] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetSysColorBrush] [610E89B0] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3204] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TrackPopupMenu] [610E88E4] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3204] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [610E9AC7] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3204] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [610E9B07] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3204] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [610E93C2] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3204] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [610E9B95] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3204] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [610E9B47] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3204] @ C:\WINDOWS\system32\SHLWAPI.dll [GDI32.dll!GetStockObject] [610E89AA] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3204] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [610E9B47] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3204] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [610E9B95] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3204] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [610E9B07] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3204] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [610E9AC7] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3204] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [610E93C2] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3204] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DefWindowProcA] [610E8FD9] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3204] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DefWindowProcW] [610E8FD9] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3204] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetSysColor] [610E8960] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3204] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TrackPopupMenu] [610E88E4] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3204] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TrackPopupMenuEx] [610E8922] C:\Program Files\Yahoo!\Messenger\yui.dll

    ===End of GMER part 2===
     
    Last edited: 2010/12/14
  7. 2010/12/14
    doflamingo

    doflamingo Inactive Thread Starter

    Joined:
    2010/12/13
    Messages:
    29
    Likes Received:
    0
    ===GMER part 3===

    ---- Devices - GMER 1.0.15 ----

    Device \FileSystem\Ntfs \Ntfs 865D61F8

    AttachedDevice \Driver\Tcpip \Device\Ip kl1.sys (Kaspersky Unified Driver/Kaspersky Lab ZAO)
    AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 wdf01000.sys (WDF Dynamic/Microsoft Corporation)

    Device \Driver\NetBT \Device\NetBT_Tcpip_{DD04A4D1-6EAE-445D-AD24-EF242FCFA502} 830211F8

    AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 wdf01000.sys (WDF Dynamic/Microsoft Corporation)

    Device \Driver\usbuhci \Device\USBPDO-0 863561F8
    Device \Driver\dmio \Device\DmControl\DmIoDaemon 865671F8
    Device \Driver\dmio \Device\DmControl\DmConfig 865671F8
    Device \Driver\dmio \Device\DmControl\DmPnP 865671F8
    Device \Driver\dmio \Device\DmControl\DmInfo 865671F8
    Device \Driver\usbuhci \Device\USBPDO-1 863561F8
    Device \Driver\usbehci \Device\USBPDO-2 863721F8
    Device \Driver\usbuhci \Device\USBPDO-3 863561F8
    Device \Driver\usbuhci \Device\USBPDO-4 863561F8

    AttachedDevice \Driver\Tcpip \Device\Tcp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab ZAO)

    Device \Driver\usbehci \Device\USBPDO-5 863721F8
    Device \Driver\usbuhci \Device\USBPDO-6 863561F8
    Device \Driver\Ftdisk \Device\HarddiskVolume1 865D81F8
    Device \Driver\usbuhci \Device\USBPDO-7 863561F8
    Device \Driver\Ftdisk \Device\HarddiskVolume2 865D81F8
    Device \Driver\Cdrom \Device\CdRom0 862DD1F8
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 865D71F8
    Device \Driver\atapi \Device\Ide\IdePort0 865D71F8
    Device \Driver\atapi \Device\Ide\IdePort1 865D71F8
    Device \Driver\atapi \Device\Ide\IdePort2 865D71F8
    Device \Driver\atapi \Device\Ide\IdePort3 865D71F8
    Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-12 865D71F8
    Device \Driver\PCI_PNP2922 \Device\00000069 spiz.sys
    Device \Driver\sptd \Device\93971672 spiz.sys
    Device \Driver\NetBT \Device\NetBt_Wins_Export 830211F8
    Device \Driver\NetBT \Device\NetbiosSmb 830211F8

    AttachedDevice \Driver\Tcpip \Device\Udp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab ZAO)
    AttachedDevice \Driver\Tcpip \Device\RawIp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab ZAO)

    Device \Driver\usbuhci \Device\USBFDO-0 863561F8
    Device \Driver\usbuhci \Device\USBFDO-1 863561F8
    Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 82FDC1F8
    Device \Driver\usbuhci \Device\USBFDO-2 863561F8
    Device \FileSystem\MRxSmb \Device\LanmanRedirector 82FDC1F8
    Device \Driver\usbehci \Device\USBFDO-3 863721F8
    Device \Driver\NetBT \Device\NetBT_Tcpip_{9DA36829-AB9D-4B0E-9712-1649FA28B32B} 830211F8
    Device \Driver\usbuhci \Device\USBFDO-4 863561F8
    Device \Driver\Ftdisk \Device\FtControl 865D81F8
    Device \Driver\usbuhci \Device\USBFDO-5 863561F8
    Device \Driver\usbuhci \Device\USBFDO-6 863561F8
    Device \Driver\usbehci \Device\USBFDO-7 863721F8
    Device \Driver\a1nen24q \Device\Scsi\a1nen24q1 862C5500
    Device \FileSystem\Cdfs \Cdfs 862A2500
    ---- Processes - GMER 1.0.15 ----

    Library C:\Program (*** hidden *** ) @ C:\Program [1932] 0x00400000

    ---- Registry - GMER 1.0.15 ----

    Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
    Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xFE 0x2A 0x04 0xBB ...
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x2D 0x9B 0xAE 0x55 ...
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x48 0xD6 0x34 0xE7 ...
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xD3 0xD1 0x8E 0xC4 ...
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x2D 0x9B 0xAE 0x55 ...
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x48 0xD6 0x34 0xE7 ...
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xD3 0xD1 0x8E 0xC4 ...

    ---- EOF - GMER 1.0.15 ----

    ===End of GMER part 3===
     
  8. 2010/12/14
    doflamingo

    doflamingo Inactive Thread Starter

    Joined:
    2010/12/13
    Messages:
    29
    Likes Received:
    0
    ===MBR Check===

    MBRCheck, version 1.2.3
    (c) 2010, AD

    Command-line:
    Windows Version: Windows XP Professional
    Windows Information: Service Pack 2 (build 2600)
    Logical Drives Mask: 0x0000001c

    Kernel Drivers (total 137):
    0x804D7000 \WINDOWS\system32\ntkrnlpa.exe
    0x806E2000 \WINDOWS\system32\hal.dll
    0xF79A6000 \WINDOWS\system32\KDCOM.DLL
    0xF78B6000 \WINDOWS\system32\BOOTVID.dll
    0xF72A5000 spon.sys
    0xF79A8000 \WINDOWS\System32\Drivers\WMILIB.SYS
    0xF728D000 \WINDOWS\System32\Drivers\SCSIPORT.SYS
    0xF725F000 ACPI.sys
    0xF724E000 pci.sys
    0xF74A6000 isapnp.sys
    0xF78BA000 compbatt.sys
    0xF78BE000 \WINDOWS\system32\DRIVERS\BATTC.SYS
    0xF7A6E000 pciide.sys
    0xF7726000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
    0xF74B6000 MountMgr.sys
    0xF722F000 ftdisk.sys
    0xF79AA000 dmload.sys
    0xF7209000 dmio.sys
    0xF78C2000 ACPIEC.sys
    0xF7A6F000 \WINDOWS\system32\DRIVERS\OPRGHDLR.SYS
    0xF772E000 PartMgr.sys
    0xF74C6000 VolSnap.sys
    0xF71F1000 atapi.sys
    0xF74D6000 disk.sys
    0xF74E6000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
    0xF71D2000 fltMgr.sys
    0xF71C0000 sr.sys
    0xF74F6000 PxHelp20.sys
    0xF71A9000 KSecDD.sys
    0xF711C000 Ntfs.sys
    0xF70EF000 NDIS.sys
    0xF7506000 sfaudio.sys
    0xF70D4000 Mup.sys
    0xF6BB2000 kl1.sys
    0xF7736000 hpdskflt.sys
    0xF75B6000 \SystemRoot\system32\DRIVERS\intelppm.sys
    0xF6520000 \SystemRoot\system32\DRIVERS\igxpmp32.sys
    0xF650C000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
    0xF77C6000 \SystemRoot\system32\DRIVERS\usbuhci.sys
    0xF64E9000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
    0xF77CE000 \SystemRoot\system32\DRIVERS\usbehci.sys
    0xF64C4000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
    0xF60C2000 \SystemRoot\system32\DRIVERS\NETw5x32.sys
    0xF75C6000 \SystemRoot\system32\DRIVERS\i8042prt.sys
    0xF77D6000 \SystemRoot\system32\DRIVERS\HpqKbFiltr.sys
    0xF75D6000 \SystemRoot\system32\DRIVERS\WDFLDR.SYS
    0xF6046000 \SystemRoot\System32\Drivers\wdf01000.sys
    0xF77DE000 \SystemRoot\system32\DRIVERS\kbdclass.sys
    0xF6013000 \SystemRoot\system32\DRIVERS\SynTP.sys
    0xF79C0000 \SystemRoot\system32\DRIVERS\USBD.SYS
    0xF75E6000 \SystemRoot\system32\DRIVERS\klmouflt.sys
    0xF77EE000 \SystemRoot\system32\DRIVERS\mouclass.sys
    0xF75F6000 \SystemRoot\system32\DRIVERS\imapi.sys
    0xF77F6000 \SystemRoot\system32\drivers\Afc.sys
    0xF7606000 \SystemRoot\system32\DRIVERS\cdrom.sys
    0xF7616000 \SystemRoot\system32\DRIVERS\redbook.sys
    0xF5FF0000 \SystemRoot\system32\DRIVERS\ks.sys
    0xF5FBA000 \SystemRoot\System32\Drivers\a7xue0i8.SYS
    0xF7856000 \SystemRoot\system32\DRIVERS\Accelerometer.sys
    0xF7992000 \SystemRoot\system32\DRIVERS\CmBatt.sys
    0xF7996000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
    0xF5EC9000 \SystemRoot\system32\DRIVERS\btkrnl.sys
    0xF799A000 \SystemRoot\system32\DRIVERS\ArcSoftVirtualCapture.sys
    0xF7646000 \SystemRoot\system32\DRIVERS\STREAM.SYS
    0xF7656000 \SystemRoot\system32\DRIVERS\klim5.sys
    0xF7B5A000 \SystemRoot\system32\DRIVERS\audstub.sys
    0xF7666000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
    0xF6B7E000 \SystemRoot\system32\DRIVERS\ndistapi.sys
    0xF5EB2000 \SystemRoot\system32\DRIVERS\ndiswan.sys
    0xF7676000 \SystemRoot\system32\DRIVERS\raspppoe.sys
    0xF7686000 \SystemRoot\system32\DRIVERS\raspptp.sys
    0xF7866000 \SystemRoot\system32\DRIVERS\TDI.SYS
    0xF5DD9000 \SystemRoot\system32\DRIVERS\psched.sys
    0xF7696000 \SystemRoot\system32\DRIVERS\msgpc.sys
    0xF786E000 \SystemRoot\system32\DRIVERS\ptilink.sys
    0xF7876000 \SystemRoot\system32\DRIVERS\raspti.sys
    0xF5DA8000 \SystemRoot\system32\DRIVERS\rdpdr.sys
    0xF76A6000 \SystemRoot\system32\DRIVERS\termdd.sys
    0xF79D2000 \SystemRoot\system32\DRIVERS\swenum.sys
    0xF5D74000 \SystemRoot\system32\DRIVERS\update.sys
    0xF6B6A000 \SystemRoot\system32\DRIVERS\mssmbios.sys
    0xF76B6000 \SystemRoot\system32\DRIVERS\cledx.sys
    0xF787E000 \SystemRoot\system32\DRIVERS\btport.sys
    0xF76C6000 \SystemRoot\System32\Drivers\NDProxy.SYS
    0xF76E6000 \SystemRoot\system32\DRIVERS\usbhub.sys
    0xA9DA7000 \SystemRoot\system32\drivers\ADIHdAud.sys
    0xA9D85000 \SystemRoot\system32\drivers\portcls.sys
    0xF76F6000 \SystemRoot\system32\drivers\drmk.sys
    0xA9D69000 \SystemRoot\system32\drivers\AEAudio.sys
    0xA9D49000 \SystemRoot\system32\drivers\IntcHdmi.sys
    0xA9CA2000 \SystemRoot\system32\DRIVERS\klif.sys
    0xF79EC000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
    0xF7BD6000 \SystemRoot\System32\Drivers\Null.SYS
    0xF79EE000 \SystemRoot\System32\Drivers\Beep.SYS
    0xF7786000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
    0xF778E000 \SystemRoot\System32\drivers\vga.sys
    0xF79F2000 \SystemRoot\System32\Drivers\mnmdd.SYS
    0xF7626000 \SystemRoot\System32\Drivers\btwusb.sys
    0xA9C64000 \SystemRoot\system32\DRIVERS\btwdndis.sys
    0xA9BE3000 \SystemRoot\system32\drivers\btaudio.sys
    0xF79F4000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
    0xF77A6000 \SystemRoot\System32\Drivers\Msfs.SYS
    0xF77AE000 \SystemRoot\System32\Drivers\Npfs.SYS
    0xF5DF6000 \SystemRoot\system32\DRIVERS\rasacd.sys
    0xF77B6000 \SystemRoot\system32\DRIVERS\kl2.sys
    0xA9BA8000 \SystemRoot\system32\DRIVERS\ipsec.sys
    0xA9B50000 \SystemRoot\system32\DRIVERS\tcpip.sys
    0xA9B28000 \SystemRoot\system32\DRIVERS\netbt.sys
    0xA9B07000 \SystemRoot\system32\DRIVERS\ipnat.sys
    0xA9AE5000 \SystemRoot\System32\drivers\afd.sys
    0xF5EA2000 \SystemRoot\system32\DRIVERS\netbios.sys
    0xF5E92000 \SystemRoot\system32\DRIVERS\wanarp.sys
    0xA9A19000 \SystemRoot\system32\DRIVERS\rdbss.sys
    0xA9982000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
    0xF5E82000 \SystemRoot\System32\Drivers\Fips.SYS
    0xF5E62000 \SystemRoot\System32\Drivers\Cdfs.SYS
    0xA996A000 \SystemRoot\System32\Drivers\dump_atapi.sys
    0xF79FC000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS
    0xBF800000 \SystemRoot\System32\win32k.sys
    0xF782E000 \SystemRoot\System32\watchdog.sys
    0xA9D21000 \SystemRoot\System32\drivers\Dxapi.sys
    0xBF000000 \SystemRoot\System32\drivers\dxg.sys
    0xF7B39000 \SystemRoot\System32\drivers\dxgthk.sys
    0xBF024000 \SystemRoot\System32\igxpgd32.dll
    0xBF012000 \SystemRoot\System32\igxprd32.dll
    0xBF05F000 \SystemRoot\System32\igxpdv32.DLL
    0xBF324000 \SystemRoot\System32\igxpdx32.DLL
    0xBFFA0000 \SystemRoot\System32\ATMFD.DLL
    0xA986E000 \SystemRoot\system32\DRIVERS\ndisuio.sys
    0xA95E5000 \SystemRoot\system32\drivers\wdmaud.sys
    0xA98B2000 \SystemRoot\system32\drivers\sysaudio.sys
    0xA9125000 \SystemRoot\system32\DRIVERS\mrxdav.sys
    0xA8FBA000 \SystemRoot\system32\DRIVERS\srv.sys
    0xA8EA2000 \SystemRoot\system32\DRIVERS\secdrv.sys
    0xA877F000 \SystemRoot\System32\Drivers\HTTP.sys
    0x7C900000 \WINDOWS\system32\ntdll.dll
    0x10000000 \Program Files\DAEMON Tools\daemon.dll

    Processes (total 59):
    0 System Idle Process
    4 System
    1084 C:\WINDOWS\system32\smss.exe
    1164 csrss.exe
    1188 C:\WINDOWS\system32\winlogon.exe
    1232 C:\WINDOWS\system32\services.exe
    1244 C:\WINDOWS\system32\lsass.exe
    1412 C:\WINDOWS\system32\svchost.exe
    1456 svchost.exe
    1496 C:\WINDOWS\system32\svchost.exe
    1624 svchost.exe
    1660 svchost.exe
    1676 C:\WINDOWS\system32\svchost.exe
    1984 C:\WINDOWS\system32\svchost.exe
    2036 C:\WINDOWS\system32\spoolsv.exe
    820 C:\WINDOWS\explorer.exe
    672 C:\WINDOWS\system32\hkcmd.exe
    1056 C:\WINDOWS\system32\igfxpers.exe
    1076 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    1136 C:\WINDOWS\system32\igfxsrvc.exe
    668 C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe
    1520 C:\Program Files\Analog Devices\Core\smax4pnp.exe
    1580 C:\WINDOWS\system32\accelerometerST.exe
    1596 C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
    1768 C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
    1792 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    1824 C:\Program Files\Smadav\SM
    1860 C:\Program Files\Common Files\Java\Java Update\jusched.exe
    1876 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
    1936 C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe
    1948 C:\WINDOWS\system32\ctfmon.exe
    316 C:\Program Files\DAEMON Tools\daemon.exe
    380 C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
    448 C:\Program Files\LSI SoftModem\agrsmsvc.exe
    468 C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe
    532 C:\Program Files\Java\jre6\bin\jqs.exe
    584 C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
    612 C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
    644 C:\Program Files\HP\Button Manager\BM.exe
    796 C:\Program Files\ArcSoft\Magic-i 3\Magic-i.exe
    900 C:\Program Files\ArcSoft\Magic-i 3\uMgiSvr.exe
    960 C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
    996 C:\WINDOWS\system32\svchost.exe
    244 C:\Program Files\Modem AC2726 UI\bin\MonServiceUDisk.exe
    1752 wdfmgr.exe
    2064 C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
    2548 C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    2556 C:\WINDOWS\system32\wuauclt.exe
    2728 wmiprvse.exe
    2988 C:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe
    3256 C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
    3660 wmiprvse.exe
    3756 alg.exe
    952 C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
    3980 C:\Program Files\Mozilla Firefox\firefox.exe
    712 C:\WINDOWS\system32\wuauclt.exe
    1600 C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtblfs.exe
    1704 C:\Program Files\Mozilla Firefox\plugin-container.exe
    928 C:\Documents and Settings\nika\My Documents\Downloads\MBRCheck.exe

    \\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)
    \\.\D: --> \\.\PhysicalDrive0 at offset 0x0000000f`6151bc00 (NTFS)

    PhysicalDrive0 Model Number: FUJITSUMJA2160BHG2, Rev: 8919

    Size Device Name MBR Status
    --------------------------------------------
    149 GB \\.\PhysicalDrive0 Windows XP MBR code detected
    SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A


    Done!

    ===End of MBR Check===

    ===DDS===


    DDS (Ver_10-12-12.02) - NTFSx86
    Run by nika at 12:34:36.28 on Tue 12/14/2010
    Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_20
    Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.952.424 [GMT 7:00]

    AV: Kaspersky Anti-Virus *Disabled/Updated* {2C4D4BC6-0793-4956-A9F9-E252435469C0}

    ============== Running Processes ===============

    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    svchost.exe
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k yksvcs
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\igfxpers.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\WINDOWS\system32\igfxsrvc.exe
    C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
    C:\Program Files\Analog Devices\Core\smax4pnp.exe
    C:\WINDOWS\System32\accelerometerST.exe
    C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
    C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\DAEMON Tools\daemon.exe
    C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
    C:\Program Files\LSI SoftModem\agrsmsvc.exe
    C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
    C:\Program Files\HP\Button Manager\BM.exe
    C:\Program Files\ArcSoft\Magic-i 3\Magic-i.exe
    C:\Program Files\ArcSoft\Magic-i 3\uMgiSvr.exe
    C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\Program Files\Modem AC2726 UI\bin\MonServiceUDisk.exe
    C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
    C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
    C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
    C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtblfs.exe
    C:\Program Files\Mozilla Firefox\plugin-container.exe
    C:\Documents and Settings\nika\Desktop\dds.scr

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://www.daemon-search.com/default
    uInternet Connection Wizard,ShellNext = hxxp://ultra1/ultrasurf.htm
    uInternet Settings,ProxyOverride = local
    BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
    BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files\kaspersky lab\kaspersky anti-virus 2011\ievkbd.dll
    BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - c:\program files\kaspersky lab\kaspersky anti-virus 2011\klwtbbho.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
    TB: {32099AAC-C132-4136-9E9A-4E364A424E17} - No File
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    uRun: [Messenger (Yahoo!)] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
    uRun: [DAEMON Tools Lite] "c:\program files\daemon tools\daemon.exe" -autorun
    mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
    mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
    mRun: [Persistence] c:\windows\system32\igfxpers.exe
    mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
    mRun: [QlbCtrl.exe] c:\program files\hewlett-packard\hp quick launch buttons\QlbCtrl.exe /Start
    mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
    mRun: [SoundMAX] c:\program files\analog devices\soundmax\Smax4.exe /tray
    mRun: [AccelerometerSysTrayApplet] c:\windows\system32\accelerometerST.exe
    mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe "
    mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe
    mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe "
    mRun: [SM?RT-Protection] c:\program files\smadav\SM?RTP.exe rtp
    mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe "
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe "
    mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
    mRun: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    mRun: [conime] conime.exe
    mRun: [AVP] "c:\program files\kaspersky lab\kaspersky anti-virus 2011\avp.exe "
    StartupFolder: c:\docume~1\nika\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
    StartupFolder: c:\documents and settings\nika\start menu\programs\startup\OneNote Table Of Contents.onetoc2
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpbutt~1.lnk - c:\program files\hp\button manager\BM.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\magic-i.lnk - c:\program files\arcsoft\magic-i 3\Magic-i.exe
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
    IE: Send to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
    IE: Send To Bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
    IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
    IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - c:\program files\kaspersky lab\kaspersky anti-virus 2011\klwtbbho.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
    IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - c:\program files\kaspersky lab\kaspersky anti-virus 2011\klwtbbho.dll
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
    TCP: {9DA36829-AB9D-4B0E-9712-1649FA28B32B} = 64.125.136.20,63.146.122.11
    Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~2\office12\GR99D3~1.DLL
    Notify: igfxcui - igfxdev.dll
    Notify: klogon - c:\windows\system32\klogon.dll
    AppInit_DLLs: c:\progra~1\kasper~1\kasper~1\mzvkbd3.dll
    SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL

    ================= FIREFOX ===================

    FF - ProfilePath - c:\docume~1\nika\applic~1\mozilla\firefox\profiles\yvh2rbka.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.id/
    FF - component: c:\documents and settings\nika\application data\mozilla\firefox\profiles\yvh2rbka.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}\components\FFExternalAlert.dll
    FF - component: c:\documents and settings\nika\application data\mozilla\firefox\profiles\yvh2rbka.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}\components\RadioWMPCore.dll
    FF - component: c:\documents and settings\nika\application data\mozilla\firefox\profiles\yvh2rbka.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\qscanff.dll
    FF - component: c:\program files\mozilla firefox\extensions\linkfilter@kaspersky.ru\components\kavlinkfilter.dll
    FF - plugin: c:\documents and settings\nika\application data\facebook\npfbplugin_1_0_3.dll
    FF - plugin: c:\documents and settings\nika\application data\mozilla\firefox\profiles\yvh2rbka.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
    FF - plugin: c:\documents and settings\nika\local settings\application data\yahoo!\browserplus\2.8.1\plugins\npybrowserplus_2.8.1.dll
    FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
    FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nppl3260.dll
    FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nprpjplug.dll
    FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll
    FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
    FF - Ext: Kaspersky URL Advisor: linkfilter@kaspersky.ru - c:\program files\mozilla firefox\extensions\linkfilter@kaspersky.ru
    FF - Ext: XfireXO Toolbar: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - %profile%\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}
    FF - Ext: FoxTab: {ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a} - %profile%\extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}
    FF - Ext: Browser Backgrounds: {3e0c7f3a-3f50-4730-beb5-4a9a10e2831c} - %profile%\extensions\{3e0c7f3a-3f50-4730-beb5-4a9a10e2831c}
    FF - Ext: DownloadHelper: {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - %profile%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
    FF - Ext: BitDefender QuickScan: {e001c731-5e37-4538-a5cb-8168736a2360} - %profile%\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
    FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\java\jre6\lib\deploy\jqs\ff

    ============= SERVICES / DRIVERS ===============

    R0 KL1;kl1;c:\windows\system32\drivers\kl1.sys [2010-6-9 132184]
    R0 SFAUDIO;Sonic Focus DSP Driver;c:\windows\system32\drivers\sfaudio.sys [2008-3-28 24064]
    R1 kl2;kl2;c:\windows\system32\drivers\kl2.sys [2010-6-9 11352]
    R1 KLIF;Kaspersky Lab Driver;c:\windows\system32\drivers\klif.sys [2010-12-14 475736]
    R2 AVP;Kaspersky Anti-Virus Service;c:\program files\kaspersky lab\kaspersky anti-virus 2011\avp.exe [2010-11-2 365336]
    R2 UDisk Monitor;UDisk Monitor;c:\program files\modem ac2726 ui\bin\MonServiceUDisk.exe [2010-2-26 262144]
    R2 yksvc;Marvell Yukon Service;c:\windows\system32\svchost.exe -k yksvcs [2006-2-28 14336]
    R3 CLEDX;Team H2O CLEDX service;c:\windows\system32\drivers\cledx.sys [2010-4-25 33792]
    R3 Com4QLBEx;Com4QLBEx;c:\program files\hewlett-packard\hp quick launch buttons\Com4QLBEx.exe [2010-1-19 228408]
    R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [2010-1-19 109568]
    R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2010-5-7 32856]
    R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2009-11-2 19472]
    S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\drivers\ewusbnet.sys --> c:\windows\system32\drivers\ewusbnet.sys [?]
    S3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\drivers\ewusbdev.sys --> c:\windows\system32\drivers\ewusbdev.sys [?]
    S3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\drivers\ewusbfake.sys --> c:\windows\system32\drivers\ewusbfake.sys [?]
    S3 massfilter;ZTE Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys --> c:\windows\system32\drivers\massfilter.sys [?]
    S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service --> c:\windows\system32\GameMon.des -service [?]
    S3 PTDCWWAN;PANTECH PC Card WWAN Controller device driver;c:\windows\system32\drivers\PTDCWWAN.sys [2010-3-12 58240]
    S3 wirelessusbser;Wireless USB Device for Legacy Serial Communication;c:\windows\system32\drivers\3GDatausbser.sys [2010-12-9 102656]
    S3 ztemtusbser;ZTEMT Legacy Serial Communication;c:\windows\system32\drivers\CT_ZTEMT_U_USBSER.sys [2010-2-26 104704]
    S3 ZTEusbnet;ZTE USB-NDIS miniport;c:\windows\system32\drivers\zteusbnet.sys --> c:\windows\system32\drivers\ZTEusbnet.sys [?]

    =============== Created Last 30 ================

    2010-12-14 03:41:12 -------- d-----w- C:\gmer
    2010-12-14 03:26:56 -------- d-----w- c:\docume~1\nika\applic~1\Malwarebytes
    2010-12-14 03:26:40 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-12-14 03:26:39 -------- d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
    2010-12-14 03:26:35 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-12-14 03:26:34 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2010-12-14 01:32:07 150200 ----a-w- c:\program files\mozilla firefox\extensions\linkfilter@kaspersky.ru\components\kavlinkfilter.dll
    2010-12-14 01:31:55 97859 ----a-w- c:\windows\system32\drivers\klick.dat
    2010-12-14 01:31:55 114243 ----a-w- c:\windows\system32\drivers\klin.dat
    2010-12-14 01:30:27 -------- d-----w- c:\program files\Kaspersky Lab
    2010-12-14 01:30:26 -------- d-----w- c:\docume~1\alluse~1\applic~1\Kaspersky Lab
    2010-12-14 01:28:09 -------- d-----w- c:\docume~1\alluse~1\applic~1\Kaspersky Lab Setup Files
    2010-12-14 00:18:32 -------- d-----w- c:\docume~1\nika\applic~1\QuickScan
    2010-12-13 03:07:37 -------- d-----w- c:\program files\CCleaner
    2010-12-11 13:45:45 -------- d-----w- c:\docume~1\nika\applic~1\Smith Micro
    2010-12-09 01:50:13 102656 ----a-w- c:\windows\system32\drivers\3GDatausbser.sys
    2010-12-01 01:34:10 -------- d-----w- c:\windows\system32\CatRoot_bak
    2010-11-30 11:30:45 -------- d-----w- c:\program files\IObit
    2010-11-30 11:30:45 -------- d-----w- c:\docume~1\alluse~1\applic~1\IObit
    2010-11-30 09:53:21 -------- d-----w- c:\docume~1\alluse~1\applic~1\KONAMI
    2010-11-30 03:46:51 -------- d-----w- c:\program files\MSXML 6.0
    2010-11-29 23:22:29 -------- d-----w- c:\windows\system32\PreInstall
    2010-11-29 10:42:51 -------- d-----w- c:\windows\system32\SoftwareDistribution
    2010-11-28 13:51:09 14848 -c--a-w- c:\windows\system32\dllcache\kbdhid.sys
    2010-11-28 13:51:09 14848 ----a-w- c:\windows\system32\drivers\kbdhid.sys

    ==================== Find3M ====================

    2010-10-05 13:27:04 228024 ----a-w- c:\windows\system32\klogon.dll

    ============= FINISH: 12:35:01.81 ===============

    ===End of DDS===
     
  9. 2010/12/14
    doflamingo

    doflamingo Inactive Thread Starter

    Joined:
    2010/12/13
    Messages:
    29
    Likes Received:
    0
    ===DDS Attach===


    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_10-12-12.02)

    Microsoft Windows XP Professional
    Boot Device: \Device\HarddiskVolume1
    Install Date: 1/19/2010 8:46:32 AM
    System Uptime: 12/14/2010 12:28:16 PM (0 hours ago)

    Motherboard: Hewlett-Packard | | 3072
    Processor: Intel(R) Core(TM)2 Duo CPU T5870 @ 2.00GHz | Intel(R) Genuine processor | 1995/200mhz
    Processor: Intel(R) Core(TM)2 Duo CPU T5870 @ 2.00GHz | Intel(R) Genuine processor | 1994/200mhz

    ==== Disk Partitions =========================

    C: is FIXED (NTFS) - 62 GiB total, 45.551 GiB free.
    D: is FIXED (NTFS) - 88 GiB total, 59.065 GiB free.
    E: is CDROM ()

    ==== Disabled Device Manager Items =============

    Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
    Description: Marvell Yukon 88E8072 PCI-E Gigabit Ethernet Controller
    Device ID: PCI\VEN_11AB&DEV_436C&SUBSYS_3072103C&REV_10\4&384C4504&0&00E5
    Manufacturer: Marvell
    Name: Marvell Yukon 88E8072 PCI-E Gigabit Ethernet Controller
    PNP Device ID: PCI\VEN_11AB&DEV_436C&SUBSYS_3072103C&REV_10\4&384C4504&0&00E5
    Service: yukonwxp

    ==== System Restore Points ===================

    RP201: 12/1/2010 9:57:19 AM - Removed Join Air

    ==== Installed Programs ======================

    3GP Video Converter 3
    Access Manager
    Actual Spy 3.0
    Adobe Flash Player 10 Plugin
    Adobe Photoshop CS
    Adobe Reader 8.1.1
    Adobe Shockwave Player 11.5
    Agere Systems HDA Modem
    Apple Application Support
    Apple Software Update
    ArcSoft Magic-i 3
    ArcSoft VideoImpression 2
    ArcSoft WebCam Companion 2
    CCleaner
    Cheating-Death 4.32.0
    Counter-Strike 1.6
    Crayon Physics Deluxe - release 51
    Facebook Plug-In
    FLV Player 2.0 (build 25)
    Game Booster
    Hero Editor V0.96
    HP 3D DriveGuard
    HP Button Manager
    HP Integrated Module with Bluetooth wireless technology
    HP Quick Launch Buttons
    HP Webcam User’s Guide
    Intel(R) Graphics Media Accelerator Driver
    Java Auto Updater
    Java(TM) 6 Update 20
    K-Lite Mega Codec Pack 3.9.0
    Kaspersky Anti-Virus 2011
    Kid-Key-Lock 1.7.0.0
    Malwarebytes' Anti-Malware
    Marvell Miniport Driver
    Microsoft .NET Framework 2.0
    Microsoft .NET Framework 3.0
    Microsoft Games for Windows - LIVE
    Microsoft Games for Windows - LIVE Redistributable
    Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
    Microsoft Office Access MUI (English) 2007
    Microsoft Office Access Setup Metadata MUI (English) 2007
    Microsoft Office Enterprise 2007
    Microsoft Office Excel MUI (English) 2007
    Microsoft Office Groove MUI (English) 2007
    Microsoft Office Groove Setup Metadata MUI (English) 2007
    Microsoft Office InfoPath MUI (English) 2007
    Microsoft Office OneNote MUI (English) 2007
    Microsoft Office Outlook MUI (English) 2007
    Microsoft Office PowerPoint MUI (English) 2007
    Microsoft Office Proof (English) 2007
    Microsoft Office Proof (French) 2007
    Microsoft Office Proof (Spanish) 2007
    Microsoft Office Proofing (English) 2007
    Microsoft Office Publisher MUI (English) 2007
    Microsoft Office Shared MUI (English) 2007
    Microsoft Office Shared Setup Metadata MUI (English) 2007
    Microsoft Office Word MUI (English) 2007
    Microsoft Save as PDF Add-in for 2007 Microsoft Office programs
    Microsoft Silverlight
    Microsoft Software Update for Web Folders (English) 12
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Minilyrics(remove only)
    Mobile Partner
    Modem AC2726 UI
    Mozilla Firefox (3.6.13)
    MSXML 6 Service Pack 2 (KB954459)
    PANTECH PC Card Software
    PHStat2 version 2.7
    PowerDVD
    Pro Evolution Soccer 2011
    QLBCASL
    QuickTime
    Security Update for Windows XP (KB923561)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB978601)
    Security Update for Windows XP (KB979309)
    Smart Bro
    SoundMAX
    Synaptics Pointing Device Driver
    Syncrosoft's License Control
    SyncroSoft Emu (Remove only)
    Update for Windows XP (KB898461)
    Update for Windows XP (KB911164)
    Update for Windows XP (KB973687)
    WebFldrs XP
    Winamp
    Winamp Detector Plug-in
    Winamp Essentials Pack
    Windows Communication Foundation
    Windows Imaging Component
    Windows Installer 3.1 (KB893803)
    Windows Media Format Runtime
    Windows Presentation Foundation
    Windows Workflow Foundation
    WinRAR archiver
    XML Paper Specification Shared Components Pack 1.0
    Yahoo! BrowserPlus 2.8.1
    Yahoo! Messenger

    ==== Event Viewer Messages From Past Week ========

    12/9/2010 6:29:07 AM, error: Service Control Manager [7023] - The Server Support service terminated with the following error: A dynamic link library (DLL) initialization routine failed.
    12/8/2010 6:40:24 AM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
    12/8/2010 5:06:43 PM, error: MRxSmb [8003] - The master browser has received a server announcement from the computer ADRY-29CC35AC that believes that it is the master browser for the domain on transport NetBT_Tcpip_{9DA36829-AB9D-. The master browser is stopping or an election is being forced.
    12/8/2010 10:57:57 AM, error: NetBT [4321] - The name "MSHOME :1d" could not be registered on the Interface with IP address 192.168.4.183. The machine with the IP address 192.168.4.1 did not allow the name to be claimed by this machine.
    12/7/2010 5:10:50 AM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments " " in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
    12/14/2010 7:07:05 AM, error: Service Control Manager [7023] - The Server Support service terminated with the following error: The specified procedure could not be found.
    12/14/2010 7:04:45 AM, error: Service Control Manager [7031] - The Bluetooth Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    12/14/2010 7:04:44 AM, error: Service Control Manager [7034] - The UDisk Monitor service terminated unexpectedly. It has done this 1 time(s).
    12/14/2010 7:04:44 AM, error: Service Control Manager [7034] - The MgiSvr service terminated unexpectedly. It has done this 1 time(s).
    12/14/2010 7:04:44 AM, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s).
    12/14/2010 7:04:44 AM, error: Service Control Manager [7034] - The hpqwmiex service terminated unexpectedly. It has done this 1 time(s).
    12/14/2010 7:04:44 AM, error: Service Control Manager [7034] - The Com4QLBEx service terminated unexpectedly. It has done this 1 time(s).
    12/14/2010 7:04:44 AM, error: Service Control Manager [7034] - The ArcSoft Connect Daemon service terminated unexpectedly. It has done this 1 time(s).
    12/14/2010 7:04:44 AM, error: Service Control Manager [7034] - The Agere Modem Call Progress Audio service terminated unexpectedly. It has done this 1 time(s).
    12/14/2010 12:26:31 PM, error: Service Control Manager [7023] - The Windows Firewall/Internet Connection Sharing (ICS) service terminated with the following error: Access is denied.
    12/14/2010 12:25:58 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the stisvc service.
    12/14/2010 11:21:10 AM, error: NetBT [4321] - The name "MSHOME :1d" could not be registered on the Interface with IP address 192.168.4.183. The machine with the IP address 192.168.4.31 did not allow the name to be claimed by this machine.
    12/14/2010 10:47:05 AM, error: atapi [9] - The device, \Device\Ide\IdePort0, did not respond within the timeout period.
    12/13/2010 8:36:18 AM, error: Tcpip [4199] - The system detected an address conflict for IP address 192.168.4.183 with the system having network hardware address 2C:A8:35:D3:09:87. Network operations on this system may be disrupted as a result.
    12/13/2010 8:34:13 AM, error: MRxSmb [8003] - The master browser has received a server announcement from the computer ALI that believes that it is the master browser for the domain on transport NetBT_Tcpip_{9DA36829-AB9D-4B0E-9712. The master browser is stopping or an election is being forced.
    12/12/2010 8:43:36 AM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service BITS with arguments " " in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}
    12/12/2010 10:59:36 AM, error: SideBySide [59] - Resolve Partial Assembly failed for Microsoft.Windows.Common-Controls. Reference error message: Insufficient system resources exist to complete the requested service. .
    12/12/2010 10:59:36 AM, error: SideBySide [59] - Generate Activation Context failed for C:\WINDOWS\system32\CRYPTUI.dll. Reference error message: The operation completed successfully. .
    12/11/2010 8:44:34 PM, error: PlugPlayManager [12] - The device 'PANTECH PC Card WWAN Controller #2' (USB\VID_106c&PID_3702&MI_02\6&26d1234d&0&8515) disappeared from the system without first being prepared for removal.
    12/11/2010 10:18:10 PM, error: PlugPlayManager [12] - The device 'PANTECH PC Card WWAN Controller #4' (USB\VID_106c&PID_3702&MI_02\6&5c5a782&0&8515) disappeared from the system without first being prepared for removal.

    ==== End Of File ===========================
     
  10. 2010/12/14
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I'm glad to see your computer running better :)
    We'll keep checking...

    Please download ComboFix from [color= "Red"]Here[/color] or [color= "#FF0000"]Here[/color] to your Desktop.

    [color= "Blue"]**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**[/color]
    1. Please, never rename Combofix unless instructed.
    2. Close any open browsers.
    3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results ".
      • Click on [color= "Red"]this link[/color] to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
      NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
      • Close any open browsers.
      • [color= "Red"]WARNING:[/color] Combofix will disconnect your machine from the Internet as soon as it starts
      • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
      • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    4. Double click on combofix.exe & follow the prompts.
    5. When finished, it will produce a report for you.
    6. Please post the "C:\ComboFix.txt"
    **Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
    **Note 2 for AVG users: ComboFix will not run until AVG is uninstalled as a protective measure against the anti-virus. This is because AVG "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results ". Since AVG cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG first.
    Use AVG Remover to uninstall it: http://www.avg.com/us-en/download-tools
    We can reinstall it when we're done with CF.
    **Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion ", restart computer to fix the issue.



    Make sure, you re-enable your security programs, when you're done with Combofix.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    NOTE.
    If, for some reason, Combofix refuses to run, try one of the following:

    1. Run Combofix from Safe Mode.

    2. Delete Combofix file, download fresh one, but rename combofix.exe to your_name.exe BEFORE saving it to your desktop.
    Do NOT run it yet.

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click Rkill and choose Run as Administrator

    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    Rkill.com
    Rkill.scr
    Rkill.pif
    Rkill.exe

    • Double-click on the Rkill desktop icon to run the tool.
    • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    • If not, delete the file, then download and use the one provided in Link 2.
    • If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
    • Do not reboot until instructed.
    • If the tool does not run from any of the links provided, please let me know.

    Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

    If normal mode still doesn't work, run BOTH tools from safe mode.

    In case #2, please post BOTH logs, rKill and Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
     
  11. 2010/12/14
    doflamingo

    doflamingo Inactive Thread Starter

    Joined:
    2010/12/13
    Messages:
    29
    Likes Received:
    0
    Thanks for your help broni :)

    here's the log.. oh yeah, by the way, after combo box finished checking my computer, i restarted my computer, after that, my touch pad cannot scroll up and down.. have any idea how to fix it?

    ComboFix 10-12-14.01 - nika 12/15/2010 9:48.1.2 - x86
    Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.952.517 [GMT 7:00]
    Running from: c:\documents and settings\nika\Desktop\ComboFix.exe
    AV: Kaspersky Anti-Virus *Disabled/Updated* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
    * Created a new restore point
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\documents and settings\All Users\Documents\DAEMON Tools Images\Desktop_1.ini
    c:\documents and settings\All Users\Documents\microsoft\Desktop_1.ini
    c:\documents and settings\All Users\Documents\microsoft\IdentityCRL\Desktop_1.ini
    c:\documents and settings\All Users\Documents\microsoft\IdentityCRL\production\Desktop_1.ini
    c:\documents and settings\All Users\Documents\My Music\Desktop_1.ini
    c:\documents and settings\All Users\Documents\My Music\My Playlists\Desktop_1.ini
    c:\documents and settings\All Users\Documents\My Music\Sample Music\Desktop_1.ini
    c:\documents and settings\All Users\Documents\My Music\Sample Playlists\000AEF60\Desktop_1.ini
    c:\documents and settings\All Users\Documents\My Music\Sample Playlists\Desktop_1.ini
    c:\documents and settings\All Users\Documents\My Pictures\Desktop_1.ini
    c:\documents and settings\All Users\Documents\My Pictures\Sample Pictures\Desktop_1.ini
    c:\documents and settings\All Users\Documents\My Videos\Desktop_1.ini

    Infected copy of c:\windows\system32\userinit.exe was found and disinfected
    Restored copy from - c:\windows\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\backup\userinit.exe

    .
    ((((((((((((((((((((((((( Files Created from 2010-11-15 to 2010-12-15 )))))))))))))))))))))))))))))))
    .

    2010-12-14 03:41 . 2010-12-14 03:41 -------- d-----w- C:\gmer
    2010-12-14 03:26 . 2010-12-14 03:26 -------- d-----w- c:\documents and settings\nika\Application Data\Malwarebytes
    2010-12-14 03:26 . 2010-11-29 10:42 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-12-14 03:26 . 2010-12-14 03:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
    2010-12-14 03:26 . 2010-11-29 10:42 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-12-14 03:26 . 2010-12-14 03:26 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2010-12-14 01:32 . 2010-10-05 13:27 150200 ----a-w- c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\components\kavlinkfilter.dll
    2010-12-14 01:31 . 2010-12-14 02:10 97859 ----a-w- c:\windows\system32\drivers\klick.dat
    2010-12-14 01:31 . 2010-12-14 02:10 114243 ----a-w- c:\windows\system32\drivers\klin.dat
    2010-12-14 01:30 . 2010-12-14 01:30 -------- d-----w- c:\program files\Kaspersky Lab
    2010-12-14 01:30 . 2010-12-15 02:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
    2010-12-14 01:28 . 2010-12-14 01:28 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
    2010-12-14 00:18 . 2010-12-14 00:18 -------- d-----w- c:\documents and settings\nika\Application Data\QuickScan
    2010-12-13 03:07 . 2010-12-13 03:07 -------- d-----w- c:\program files\CCleaner
    2010-12-11 13:45 . 2010-12-11 13:45 -------- d-----w- c:\documents and settings\nika\Application Data\Smith Micro
    2010-12-09 01:50 . 2010-01-15 03:24 102656 ----a-w- c:\windows\system32\drivers\3GDatausbser.sys
    2010-12-01 01:34 . 2010-12-13 03:59 -------- d-----w- c:\windows\system32\CatRoot_bak
    2010-11-30 11:30 . 2010-11-30 11:30 -------- d-----w- c:\program files\IObit
    2010-11-30 11:30 . 2010-11-30 11:30 -------- d-----w- c:\documents and settings\All Users\Application Data\IObit
    2010-11-30 09:53 . 2010-11-30 09:53 -------- d-----w- c:\documents and settings\All Users\Application Data\KONAMI
    2010-11-30 03:46 . 2010-11-30 03:46 -------- d-----w- c:\program files\MSXML 6.0
    2010-11-28 13:51 . 2004-08-03 15:58 14848 -c--a-w- c:\windows\system32\dllcache\kbdhid.sys
    2010-11-28 13:51 . 2004-08-03 15:58 14848 ----a-w- c:\windows\system32\drivers\kbdhid.sys

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-10-05 13:27 . 2010-10-05 13:27 228024 ----a-w- c:\windows\system32\klogon.dll
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Messenger (Yahoo!) "= "c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2008-05-27 4269296]
    "DAEMON Tools Lite "= "c:\program files\DAEMON Tools\daemon.exe" [2008-12-29 687560]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SM?RT-Protection "= "c:\program files\Smadav\SM?RTP.exe" [?]
    "IgfxTray "= "c:\windows\system32\igfxtray.exe" [2009-03-13 141336]
    "HotKeysCmds "= "c:\windows\system32\hkcmd.exe" [2009-03-13 173592]
    "Persistence "= "c:\windows\system32\igfxpers.exe" [2009-03-13 142872]
    "QlbCtrl.exe "= "c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2009-07-27 288312]
    "SoundMAXPnP "= "c:\program files\Analog Devices\Core\smax4pnp.exe" [2009-07-20 1044480]
    "AccelerometerSysTrayApplet "= "c:\windows\System32\accelerometerST.exe" [2009-01-22 82488]
    "GrooveMonitor "= "c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
    "ArcSoft Connection Service "= "c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2008-04-17 98616]
    "RemoteControl "= "c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-12-08 32768]
    "SunJavaUpdateSched "= "c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
    "Adobe Reader Speed Launcher "= "c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 39792]
    "QuickTime Task "= "c:\program files\QuickTime\QTTask.exe" [2010-09-08 421888]
    "conime "= "conime.exe" [2006-02-28 27648]
    "AVP "= "c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe" [2010-11-02 365336]

    c:\documents and settings\nika\Start Menu\Programs\Startup\
    OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
    OneNote Table Of Contents.onetoc2 [2010-11-11 3656]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2010-3-10 113664]
    Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-12-11 604776]
    HP Button Manager.lnk - c:\program files\HP\Button Manager\BM.exe [2010-1-29 249856]
    Magic-i.lnk - c:\program files\ArcSoft\Magic-i 3\Magic-i.exe [2010-1-29 530944]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
    2010-07-12 16:32 74752 ----a-w- c:\program files\Winamp\winampa.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusOverride "=dword:00000001
    "FirewallOverride "=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
    "DisableMonitoring "=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall "= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe "=
    "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE "=
    "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE "=
    "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE "=
    "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe "=
    "c:\\Program Files\\Counter-Strike 1.6\\hl.exe "=
    "c:\\Program Files\\Left 4 Dead\\left4dead.exe "=
    "d:\\game\\Need for Speed Underground 2\\speed2.exe "=
    "d:\\game\\PES2011\\pes2011.exe "=
    "c:\\Program Files\\Mozilla Firefox\\firefox.exe "=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "6088:TCP "= 6088:TCP:wdjftt

    R0 SFAUDIO;Sonic Focus DSP Driver;c:\windows\system32\drivers\sfaudio.sys [3/28/2008 11:14 AM 24064]
    R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [3/2/2010 10:07 AM 717296]
    R1 kl2;kl2;c:\windows\system32\drivers\kl2.sys [6/9/2010 4:43 PM 11352]
    R2 UDisk Monitor;UDisk Monitor;c:\program files\Modem AC2726 UI\bin\MonServiceUDisk.exe [2/26/2010 10:32 AM 262144]
    R2 yksvc;Marvell Yukon Service;c:\windows\System32\svchost.exe -k yksvcs [2/28/2006 7:00 PM 14336]
    R3 CLEDX;Team H2O CLEDX service;c:\windows\system32\drivers\cledx.sys [4/25/2010 9:37 AM 33792]
    R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [1/19/2010 8:55 AM 228408]
    R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [1/19/2010 9:39 AM 109568]
    R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [5/7/2010 11:06 AM 32856]
    R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [11/2/2009 7:27 PM 19472]
    S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys --> c:\windows\system32\DRIVERS\ewusbnet.sys [?]
    S3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys --> c:\windows\system32\DRIVERS\ewusbdev.sys [?]
    S3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\DRIVERS\ewusbfake.sys --> c:\windows\system32\DRIVERS\ewusbfake.sys [?]
    S3 massfilter;ZTE Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys --> c:\windows\system32\drivers\massfilter.sys [?]
    S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
    S3 PTDCWWAN;PANTECH PC Card WWAN Controller device driver;c:\windows\system32\drivers\PTDCWWAN.sys [3/12/2010 10:50 PM 58240]
    S3 wirelessusbser;Wireless USB Device for Legacy Serial Communication;c:\windows\system32\drivers\3GDatausbser.sys [12/9/2010 8:50 AM 102656]
    S3 ztemtusbser;ZTEMT Legacy Serial Communication;c:\windows\system32\drivers\CT_ZTEMT_U_USBSER.sys [2/26/2010 10:32 AM 104704]
    S3 ZTEusbnet;ZTE USB-NDIS miniport;c:\windows\system32\DRIVERS\ZTEusbnet.sys --> c:\windows\system32\DRIVERS\ZTEusbnet.sys [?]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    yksvcs REG_MULTI_SZ yksvc
    .
    Contents of the 'Scheduled Tasks' folder

    2010-11-26 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 05:34]

    2010-12-15 c:\windows\Tasks\Game_Booster_Startup.job
    - c:\program files\IObit\Game Booster\GameBox.exe [2010-11-30 12:08]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.daemon-search.com/default
    uInternet Connection Wizard,ShellNext = hxxp://ultra1/ultrasurf.htm
    uInternet Settings,ProxyOverride = local
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
    IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    TCP: {9DA36829-AB9D-4B0E-9712-1649FA28B32B} = 64.125.136.20,63.146.122.11
    FF - ProfilePath - c:\documents and settings\nika\Application Data\Mozilla\Firefox\Profiles\yvh2rbka.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.id/
    FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
    FF - Ext: Kaspersky URL Advisor: linkfilter@kaspersky.ru - c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru
    FF - Ext: XfireXO Toolbar: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - %profile%\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}
    FF - Ext: FoxTab: {ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a} - %profile%\extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}
    FF - Ext: Browser Backgrounds: {3e0c7f3a-3f50-4730-beb5-4a9a10e2831c} - %profile%\extensions\{3e0c7f3a-3f50-4730-beb5-4a9a10e2831c}
    FF - Ext: DownloadHelper: {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - %profile%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
    FF - Ext: BitDefender QuickScan: {e001c731-5e37-4538-a5cb-8168736a2360} - %profile%\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
    FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
    .
    - - - - ORPHANS REMOVED - - - -

    Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
    HKLM-Run-SynTPEnh - %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
    AddRemove-Agere Systems Soft Modem - c:\windows\agrsmdel



    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2010-12-15 09:59
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************

    [HKEY_LOCAL_MACHINE\System\ControlSet002\Services\npggsvc]
    "ImagePath "= "c:\windows\system32\GameMon.des -service "
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'explorer.exe'(764)
    c:\windows\system32\msi.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
    c:\program files\LSI SoftModem\agrsmsvc.exe
    c:\program files\Java\jre6\bin\jqs.exe
    c:\windows\system32\igfxsrvc.exe
    c:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
    c:\program files\Synaptics\SynTP\SynTPEnh.exe
    c:\program files\ArcSoft\Magic-i 3\uMgiSvr.exe
    c:\program files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
    c:\windows\system32\wdfmgr.exe
    c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    c:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
    c:\program files\Yahoo!\Messenger\ymsgr_tray.exe
    c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
    .
    **************************************************************************
    .
    Completion time: 2010-12-15 10:04:27 - machine was rebooted
    ComboFix-quarantined-files.txt 2010-12-15 03:04

    Pre-Run: 48,687,853,568 bytes free
    Post-Run: 48,619,499,520 bytes free

    WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT= "Microsoft Windows Recovery Console" /cmdcons
    UnsupportedDebug= "do not select this" /debug
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS= "Microsoft Windows XP Professional" /noexecute=optin /fastdetect

    - - End Of File - - C8858E45AB3D6D115F194EA5037BF1FD
     
  12. 2010/12/14
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I don't see Combofix touching anything related to your touchpad.
    Try to restart again, possibly reinstall touchpad driver.
    When cleaning infected computer, some side effects may happen.

    =================================================================

    1. Please open Notepad
    • Click Start , then Run
    • Type notepad .exe in the Run Box.

    2. Now copy/paste the entire content of the codebox below into the Notepad window:

    Code:
    Registry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
     "SM?RT-Protection "=-
    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
     "AntiVirusOverride "=dword:00000000
     "FirewallOverride "=dword:00000000
    
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
     "DisableMonitoring "=dword:00000000
    
    

    3. Save the above as CFScript.txt

    4. Close/disable all anti virus and anti malware programs again, so they do not interfere with the running of ComboFix.

    5. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

    [​IMG]


    6. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
    • Combofix.txt
     
  13. 2010/12/14
    doflamingo

    doflamingo Inactive Thread Starter

    Joined:
    2010/12/13
    Messages:
    29
    Likes Received:
    0
    Okay, i'll re-install my driver later :D

    here's the second log

    ComboFix 10-12-14.01 - nika 12/15/2010 10:57:57.2.2 - x86
    Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.952.574 [GMT 7:00]
    Running from: c:\documents and settings\nika\Desktop\ComboFix.exe
    Command switches used :: c:\documents and settings\nika\Desktop\CFScript.txt
    AV: Kaspersky Anti-Virus *Disabled/Updated* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
    .

    ((((((((((((((((((((((((( Files Created from 2010-11-15 to 2010-12-15 )))))))))))))))))))))))))))))))
    .

    2010-12-14 03:41 . 2010-12-14 03:41 -------- d-----w- C:\gmer
    2010-12-14 03:26 . 2010-12-14 03:26 -------- d-----w- c:\documents and settings\nika\Application Data\Malwarebytes
    2010-12-14 03:26 . 2010-11-29 10:42 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-12-14 03:26 . 2010-12-14 03:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
    2010-12-14 03:26 . 2010-11-29 10:42 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-12-14 03:26 . 2010-12-14 03:26 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2010-12-14 01:32 . 2010-10-05 13:27 150200 ----a-w- c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\components\kavlinkfilter.dll
    2010-12-14 01:31 . 2010-12-14 02:10 97859 ----a-w- c:\windows\system32\drivers\klick.dat
    2010-12-14 01:31 . 2010-12-14 02:10 114243 ----a-w- c:\windows\system32\drivers\klin.dat
    2010-12-14 01:30 . 2010-12-14 01:30 -------- d-----w- c:\program files\Kaspersky Lab
    2010-12-14 01:30 . 2010-12-15 03:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
    2010-12-14 01:28 . 2010-12-14 01:28 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
    2010-12-14 00:18 . 2010-12-14 00:18 -------- d-----w- c:\documents and settings\nika\Application Data\QuickScan
    2010-12-13 03:07 . 2010-12-13 03:07 -------- d-----w- c:\program files\CCleaner
    2010-12-11 13:45 . 2010-12-11 13:45 -------- d-----w- c:\documents and settings\nika\Application Data\Smith Micro
    2010-12-09 01:50 . 2010-01-15 03:24 102656 ----a-w- c:\windows\system32\drivers\3GDatausbser.sys
    2010-12-01 01:34 . 2010-12-13 03:59 -------- d-----w- c:\windows\system32\CatRoot_bak
    2010-11-30 11:30 . 2010-11-30 11:30 -------- d-----w- c:\program files\IObit
    2010-11-30 11:30 . 2010-11-30 11:30 -------- d-----w- c:\documents and settings\All Users\Application Data\IObit
    2010-11-30 09:53 . 2010-11-30 09:53 -------- d-----w- c:\documents and settings\All Users\Application Data\KONAMI
    2010-11-30 03:46 . 2010-11-30 03:46 -------- d-----w- c:\program files\MSXML 6.0
    2010-11-28 13:51 . 2004-08-03 15:58 14848 -c--a-w- c:\windows\system32\dllcache\kbdhid.sys
    2010-11-28 13:51 . 2004-08-03 15:58 14848 ----a-w- c:\windows\system32\drivers\kbdhid.sys

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-10-05 13:27 . 2010-10-05 13:27 228024 ----a-w- c:\windows\system32\klogon.dll
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Messenger (Yahoo!) "= "c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2008-05-27 4269296]
    "DAEMON Tools Lite "= "c:\program files\DAEMON Tools\daemon.exe" [2008-12-29 687560]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SM?RT-Protection "= "c:\program files\Smadav\SM?RTP.exe" [?]
    "IgfxTray "= "c:\windows\system32\igfxtray.exe" [2009-03-13 141336]
    "HotKeysCmds "= "c:\windows\system32\hkcmd.exe" [2009-03-13 173592]
    "Persistence "= "c:\windows\system32\igfxpers.exe" [2009-03-13 142872]
    "QlbCtrl.exe "= "c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2009-07-27 288312]
    "SoundMAXPnP "= "c:\program files\Analog Devices\Core\smax4pnp.exe" [2009-07-20 1044480]
    "AccelerometerSysTrayApplet "= "c:\windows\System32\accelerometerST.exe" [2009-01-22 82488]
    "GrooveMonitor "= "c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
    "ArcSoft Connection Service "= "c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2008-04-17 98616]
    "RemoteControl "= "c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-12-08 32768]
    "SunJavaUpdateSched "= "c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
    "Adobe Reader Speed Launcher "= "c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 39792]
    "QuickTime Task "= "c:\program files\QuickTime\QTTask.exe" [2010-09-08 421888]
    "conime "= "conime.exe" [2006-02-28 27648]
    "AVP "= "c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe" [2010-11-02 365336]

    c:\documents and settings\nika\Start Menu\Programs\Startup\
    OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
    OneNote Table Of Contents.onetoc2 [2010-11-11 3656]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2010-3-10 113664]
    Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-12-11 604776]
    HP Button Manager.lnk - c:\program files\HP\Button Manager\BM.exe [2010-1-29 249856]
    Magic-i.lnk - c:\program files\ArcSoft\Magic-i 3\Magic-i.exe [2010-1-29 530944]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
    2010-07-12 16:32 74752 ----a-w- c:\program files\Winamp\winampa.exe

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall "= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe "=
    "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE "=
    "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE "=
    "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE "=
    "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe "=
    "c:\\Program Files\\Counter-Strike 1.6\\hl.exe "=
    "c:\\Program Files\\Left 4 Dead\\left4dead.exe "=
    "d:\\game\\Need for Speed Underground 2\\speed2.exe "=
    "d:\\game\\PES2011\\pes2011.exe "=
    "c:\\Program Files\\Mozilla Firefox\\firefox.exe "=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "6088:TCP "= 6088:TCP:wdjftt

    R0 SFAUDIO;Sonic Focus DSP Driver;c:\windows\system32\drivers\sfaudio.sys [3/28/2008 11:14 AM 24064]
    R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [3/2/2010 10:07 AM 717296]
    R1 kl2;kl2;c:\windows\system32\drivers\kl2.sys [6/9/2010 4:43 PM 11352]
    R2 yksvc;Marvell Yukon Service;c:\windows\System32\svchost.exe -k yksvcs [2/28/2006 7:00 PM 14336]
    R3 CLEDX;Team H2O CLEDX service;c:\windows\system32\drivers\cledx.sys [4/25/2010 9:37 AM 33792]
    R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [1/19/2010 8:55 AM 228408]
    R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [1/19/2010 9:39 AM 109568]
    R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [5/7/2010 11:06 AM 32856]
    R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [11/2/2009 7:27 PM 19472]
    S2 UDisk Monitor;UDisk Monitor;c:\program files\Modem AC2726 UI\bin\MonServiceUDisk.exe [2/26/2010 10:32 AM 262144]
    S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys --> c:\windows\system32\DRIVERS\ewusbnet.sys [?]
    S3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys --> c:\windows\system32\DRIVERS\ewusbdev.sys [?]
    S3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\DRIVERS\ewusbfake.sys --> c:\windows\system32\DRIVERS\ewusbfake.sys [?]
    S3 massfilter;ZTE Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys --> c:\windows\system32\drivers\massfilter.sys [?]
    S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
    S3 PTDCWWAN;PANTECH PC Card WWAN Controller device driver;c:\windows\system32\drivers\PTDCWWAN.sys [3/12/2010 10:50 PM 58240]
    S3 wirelessusbser;Wireless USB Device for Legacy Serial Communication;c:\windows\system32\drivers\3GDatausbser.sys [12/9/2010 8:50 AM 102656]
    S3 ztemtusbser;ZTEMT Legacy Serial Communication;c:\windows\system32\drivers\CT_ZTEMT_U_USBSER.sys [2/26/2010 10:32 AM 104704]
    S3 ZTEusbnet;ZTE USB-NDIS miniport;c:\windows\system32\DRIVERS\ZTEusbnet.sys --> c:\windows\system32\DRIVERS\ZTEusbnet.sys [?]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    yksvcs REG_MULTI_SZ yksvc
    .
    Contents of the 'Scheduled Tasks' folder

    2010-11-26 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 05:34]

    2010-12-15 c:\windows\Tasks\Game_Booster_Startup.job
    - c:\program files\IObit\Game Booster\GameBox.exe [2010-11-30 12:08]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.daemon-search.com/default
    uInternet Connection Wizard,ShellNext = hxxp://ultra1/ultrasurf.htm
    uInternet Settings,ProxyOverride = local
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
    IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    TCP: {9DA36829-AB9D-4B0E-9712-1649FA28B32B} = 64.125.136.20,63.146.122.11
    FF - ProfilePath - c:\documents and settings\nika\Application Data\Mozilla\Firefox\Profiles\yvh2rbka.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.id/
    FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
    FF - Ext: Kaspersky URL Advisor: linkfilter@kaspersky.ru - c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru
    FF - Ext: XfireXO Toolbar: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - %profile%\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}
    FF - Ext: FoxTab: {ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a} - %profile%\extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}
    FF - Ext: Browser Backgrounds: {3e0c7f3a-3f50-4730-beb5-4a9a10e2831c} - %profile%\extensions\{3e0c7f3a-3f50-4730-beb5-4a9a10e2831c}
    FF - Ext: DownloadHelper: {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - %profile%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
    FF - Ext: BitDefender QuickScan: {e001c731-5e37-4538-a5cb-8168736a2360} - %profile%\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
    FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2010-12-15 11:03
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************

    [HKEY_LOCAL_MACHINE\System\ControlSet002\Services\npggsvc]
    "ImagePath "= "c:\windows\system32\GameMon.des -service "
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(1200)
    c:\windows\system32\igfxdev.dll

    - - - - - - - > 'explorer.exe'(616)
    c:\windows\system32\msi.dll
    .
    Completion time: 2010-12-15 11:04:45
    ComboFix-quarantined-files.txt 2010-12-15 04:04
    ComboFix2.txt 2010-12-15 03:04

    Pre-Run: 48,637,378,560 bytes free
    Post-Run: 48,611,577,856 bytes free

    - - End Of File - - BA03D10B9FB1D1063AFE551EE835F346
     
  14. 2010/12/14
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Looks good :)

    How is computer doing?

    Download OTL to your Desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Under the Custom Scan box paste this in:


    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    %systemroot%\system32\winlog\*.*
    %systemroot%\system32\Language\*.*
    %systemroot%\system32\Settings\*.*
    %systemroot%\system32\*.quo
    %SYSTEMROOT%\AppPatch\*.exe
    %SYSTEMROOT%\inf\*.exe
    %SYSTEMROOT%\Installer\*.exe
    %systemroot%\system32\config\*.bak2
    %systemroot%\system32\Computers\*.*
    %SystemRoot%\system32\Sound\*.*
    %SystemRoot%\system32\SpecialImg\*.*
    %SystemRoot%\system32\code\*.*
    %SystemRoot%\system32\draft\*.*
    %SystemRoot%\system32\MSSSys\*.*
    %ProgramFiles%\Javascript\*.*
    %systemroot%\pchealth\helpctr\System\*.exe /s
    %systemroot%\Web\*.exe
    %systemroot%\system32\msn\*.*
    %systemroot%\system32\*.tro
    %AppData%\Microsoft\Installer\msupdates\*.*
    %ProgramFiles%\Messenger\*.*
    %systemroot%\system32\systhem32\*.*
    %systemroot%\system\*.exe
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    /md5start
    /md5stop


    • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.
     
  15. 2010/12/14
    doflamingo

    doflamingo Inactive Thread Starter

    Joined:
    2010/12/13
    Messages:
    29
    Likes Received:
    0
    my computer doing goods :D
    thanks for all your help broni :)

    here's the OTL

    OTL logfile created on: 12/15/2010 12:29:36 PM - Run 1
    OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\nika\My Documents\Downloads
    Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 6.0.2900.2180)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    952.00 Mb Total Physical Memory | 528.00 Mb Available Physical Memory | 55.00% Memory free
    2.00 Gb Paging File | 2.00 Gb Available in Paging File | 83.00% Paging File free
    Paging file location(s): C:\pagefile.sys 1428 2856 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 61.52 Gb Total Space | 45.30 Gb Free Space | 73.64% Space Free | Partition Type: NTFS
    Drive D: | 87.53 Gb Total Space | 59.06 Gb Free Space | 67.48% Space Free | Partition Type: NTFS

    Computer Name: DOFLAMINGO | User Name: nika | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: Current user | Quick Scan
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Processes (SafeList) ==========

    PRC - [2010/12/15 12:25:52 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\nika\My Documents\Downloads\OTL.exe
    PRC - [2010/11/02 22:06:06 | 000,365,336 | ---- | M] (Kaspersky Lab ZAO) -- C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe
    PRC - [2010/10/12 08:27:24 | 001,478,690 | ---- | M] (Smadsoft) -- C:\Program Files\Smadav\SMΔRTP.exe
    PRC - [2009/07/20 14:35:20 | 001,044,480 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\Core\smax4pnp.exe
    PRC - [2009/05/21 19:44:56 | 000,262,144 | ---- | M] () -- C:\Program Files\Modem AC2726 UI\bin\MonServiceUDisk.exe
    PRC - [2009/01/22 17:14:06 | 000,082,488 | ---- | M] (Hewlett-Packard Corporation) -- C:\WINDOWS\system32\accelerometerST.exe
    PRC - [2008/12/29 17:40:30 | 000,687,560 | ---- | M] (DT Soft Ltd) -- C:\Program Files\DAEMON Tools\daemon.exe
    PRC - [2008/12/11 14:23:08 | 001,456,768 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
    PRC - [2008/12/11 14:23:08 | 000,604,776 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
    PRC - [2008/08/26 14:02:24 | 000,014,336 | ---- | M] (Agere Systems) -- C:\Program Files\LSI SoftModem\agrsmsvc.exe
    PRC - [2008/06/17 19:04:42 | 000,249,856 | ---- | M] () -- C:\Program Files\HP\Button Manager\BM.exe
    PRC - [2008/05/21 13:33:32 | 000,530,944 | ---- | M] (ArcSoft, Inc.) -- C:\Program Files\ArcSoft\Magic-i 3\Magic-i.exe
    PRC - [2008/04/17 14:14:00 | 000,102,712 | ---- | M] (ArcSoft Inc.) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
    PRC - [2008/04/17 14:14:00 | 000,098,616 | ---- | M] (ArcSoft Inc.) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
    PRC - [2008/04/17 14:11:00 | 000,221,496 | ---- | M] (ArcSoft Inc.) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
    PRC - [2006/11/13 14:02:08 | 000,076,544 | ---- | M] (ArcSoft, Inc.) -- C:\Program Files\ArcSoft\Magic-i 3\uMgiSvr.exe
    PRC - [2006/02/28 19:00:00 | 001,032,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe


    ========== Modules (SafeList) ==========

    MOD - [2010/12/15 12:25:52 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\nika\My Documents\Downloads\OTL.exe
    MOD - [2008/12/11 14:22:02 | 000,094,273 | ---- | M] (Broadcom Corporation.) -- C:\WINDOWS\system32\BtMmHook.dll
    MOD - [2008/12/11 14:20:20 | 000,069,697 | ---- | M] () -- C:\Program Files\WIDCOMM\Bluetooth Software\BTKeyInd.dll
    MOD - [2006/02/28 19:00:00 | 001,050,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll


    ========== Win32 Services (SafeList) ==========

    SRV - File not found [Disabled | Stopped] -- C:\WINDOWS\System32\hidserv.dll -- (HidServ)
    SRV - [2010/11/02 22:06:06 | 000,365,336 | ---- | M] (Kaspersky Lab ZAO) [Auto | Running] -- C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe -- (AVP)
    SRV - [2010/03/08 23:26:00 | 003,519,560 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\WINDOWS\System32\GameMon.des -- (npggsvc)
    SRV - [2009/07/17 15:10:00 | 000,282,624 | ---- | M] (Marvell) [Auto | Running] -- C:\WINDOWS\system32\yk51x86.dll -- (yksvc)
    SRV - [2009/05/21 19:44:56 | 000,262,144 | ---- | M] () [Auto | Running] -- C:\Program Files\Modem AC2726 UI\bin\MonServiceUDisk.exe -- (UDisk Monitor)
    SRV - [2008/08/26 14:02:24 | 000,014,336 | ---- | M] (Agere Systems) [Auto | Running] -- C:\Program Files\LSI SoftModem\agrsmsvc.exe -- (AgereModemAudio)
    SRV - [2008/04/17 14:14:00 | 000,102,712 | ---- | M] (ArcSoft Inc.) [Auto | Running] -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe -- (ACDaemon)
    SRV - [2006/11/13 14:02:08 | 000,076,544 | ---- | M] (ArcSoft, Inc.) [Auto | Running] -- C:\Program Files\ArcSoft\Magic-i 3\uMgiSvr.exe -- (MgiSvr)


    ========== Driver Services (SafeList) ==========

    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\ZTEusbser6k.sys -- (ZTEusbser6k)
    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\ZTEusbnmea.sys -- (ZTEusbnmea)
    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\ZTEusbnet.sys -- (ZTEusbnet)
    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\ZTEusbmdm6k.sys -- (ZTEusbmdm6k)
    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\massfilter.sys -- (massfilter)
    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\ewusbfake.sys -- (hwusbfake)
    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\ewusbdev.sys -- (hwusbdev)
    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\ewusbmdm.sys -- (hwdatacard)
    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\ewusbnet.sys -- (ewusbnet)
    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\Drivers\dtscsi.sys -- (dtscsi)
    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\nika\LOCALS~1\Temp\catchme.sys -- (catchme)
    DRV - [2010/12/14 08:30:13 | 000,475,736 | ---- | M] (Kaspersky Lab) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\klif.sys -- (KLIF)
    DRV - [2010/06/09 16:43:52 | 000,011,352 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\kl2.sys -- (kl2)
    DRV - [2010/06/09 16:43:50 | 000,132,184 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\kl1.sys -- (KL1)
    DRV - [2010/05/07 11:06:26 | 000,032,856 | ---- | M] (Kaspersky Lab ZAO) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\klim5.sys -- (klim5)
    DRV - [2010/03/02 10:07:33 | 000,717,296 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
    DRV - [2010/01/15 10:24:28 | 000,102,656 | ---- | M] (QUALCOMM Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\3GDatausbser.sys -- (wirelessusbser)
    DRV - [2009/11/02 19:27:24 | 000,019,472 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\klmouflt.sys -- (klmouflt)
    DRV - [2009/07/29 16:33:04 | 000,213,680 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SynTP.sys -- (SynTP)
    DRV - [2009/07/20 14:39:04 | 000,339,456 | ---- | M] (Analog Devices, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ADIHdAud.sys -- (ADIHdAudAddService)
    DRV - [2009/07/17 15:10:00 | 000,297,728 | ---- | M] (Marvell) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\yk51x86.sys -- (yukonwxp)
    DRV - [2009/05/21 18:57:28 | 000,104,704 | ---- | M] (ZTEMT Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\CT_ZTEMT_U_USBSER.sys -- (ztemtusbser)
    DRV - [2009/03/05 12:59:50 | 006,312,928 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\igxpmp32.sys -- (ialm)
    DRV - [2009/03/04 10:31:00 | 004,202,496 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NETw5x32.sys -- (NETw5x32) Intel(R)
    DRV - [2009/01/14 15:16:20 | 000,156,816 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btwdndis.sys -- (BTWDNDIS)
    DRV - [2009/01/14 15:16:20 | 000,047,272 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btwusb.sys -- (BTWUSB)
    DRV - [2009/01/14 15:16:18 | 000,991,656 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btkrnl.sys -- (BTKRNL)
    DRV - [2009/01/14 15:16:18 | 000,534,568 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btaudio.sys -- (btaudio)
    DRV - [2009/01/14 15:16:18 | 000,037,160 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btport.sys -- (BTDriver)
    DRV - [2008/10/29 15:43:44 | 001,204,128 | ---- | M] (Agere Systems) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem)
    DRV - [2008/09/22 06:40:46 | 000,109,568 | R--- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\IntcHdmi.sys -- (IntcHdmiAddService) Intel(R)
    DRV - [2008/05/23 12:51:02 | 000,024,624 | ---- | M] (Hewlett-Packard Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\hpdskflt.sys -- (hpdskflt)
    DRV - [2008/05/23 12:50:16 | 000,028,592 | ---- | M] (Hewlett-Packard Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Accelerometer.sys -- (Accelerometer)
    DRV - [2008/03/28 11:14:02 | 000,024,064 | ---- | M] (Sonic Focus, Inc) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sfaudio.sys -- (SFAUDIO)
    DRV - [2007/07/02 15:08:08 | 000,015,616 | ---- | M] (ArcSoft, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ArcSoftVirtualCapture.sys -- (ARCSOFTVIRTUALCAPTURE)
    DRV - [2007/06/18 17:12:04 | 000,016,768 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HpqKbFiltr.sys -- (HpqKbFiltr)
    DRV - [2007/05/01 07:30:14 | 000,058,240 | ---- | M] (DEVGURU Co,LTD.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PTDCWWAN.sys -- (PTDCWWAN)
    DRV - [2007/04/01 17:45:30 | 000,039,808 | ---- | M] (DEVGURU Co,LTD.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PTDCVsp.sys -- (PTDCVsp) PANTECH PC Card Diagnostic Serial Port (UDP)
    DRV - [2007/04/01 17:45:26 | 000,041,728 | ---- | M] (DEVGURU Co,LTD.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PTDCMdm.sys -- (PTDCMdm) PANTECH PC Card Drivers (UDP)
    DRV - [2007/04/01 17:45:22 | 000,027,520 | ---- | M] (DEVGURU Co,LTD.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PTDCBus.sys -- (PTDCBus) PANTECH PC Card Composite Device Driver (UDP)
    DRV - [2006/11/10 15:05:00 | 000,018,688 | ---- | M] (Arcsoft, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\afc.sys -- (Afc)
    DRV - [2005/05/09 20:08:40 | 000,033,792 | ---- | M] (Team H2O) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\cledx.sys -- (CLEDX)
    DRV - [2005/01/07 17:07:18 | 000,138,752 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Hdaudbus.sys -- (HDAudBus)
    DRV - [2004/08/03 23:07:56 | 000,059,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\USBAUDIO.sys -- (usbaudio) USB Audio Driver (WDM)
    DRV - [2002/11/26 13:54:58 | 000,016,936 | ---- | M] (Smith Micro Software, Inc.) [Kernel | On_Demand | Stopped] -- C:\Program Files\Access Manager\SMNDIS5.sys -- (SMNDIS5)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/default
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = local

    ========== FireFox ==========

    FF - prefs.js..browser.startup.homepage: "http://www.google.co.id/ "
    FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
    FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
    FF - prefs.js..extensions.enabledItems: {5e5ab302-7f65-44cd-8211-c1d4caaccea3}:2.5.8.6
    FF - prefs.js..extensions.enabledItems: {ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}:1.3
    FF - prefs.js..extensions.enabledItems: {3e0c7f3a-3f50-4730-beb5-4a9a10e2831c}:0.8
    FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.1
    FF - prefs.js..extensions.enabledItems: {e001c731-5e37-4538-a5cb-8168736a2360}:0.9.9.52
    FF - prefs.js..extensions.enabledItems: linkfilter@kaspersky.ru:11.0.2.556

    FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/12/11 13:58:55 | 000,000,000 | ---D | M]
    FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/12/11 13:58:55 | 000,000,000 | ---D | M]

    [2010/01/20 02:36:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\nika\Application Data\Mozilla\Extensions
    [2010/12/15 11:32:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\nika\Application Data\Mozilla\Firefox\Profiles\yvh2rbka.default\extensions
    [2010/10/12 14:42:48 | 000,000,000 | ---D | M] (Browser Backgrounds) -- C:\Documents and Settings\nika\Application Data\Mozilla\Firefox\Profiles\yvh2rbka.default\extensions\{3e0c7f3a-3f50-4730-beb5-4a9a10e2831c}
    [2010/03/25 13:54:52 | 000,000,000 | ---D | M] (XfireXO Toolbar) -- C:\Documents and Settings\nika\Application Data\Mozilla\Firefox\Profiles\yvh2rbka.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}
    [2010/11/08 14:57:50 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Documents and Settings\nika\Application Data\Mozilla\Firefox\Profiles\yvh2rbka.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
    [2010/12/14 07:18:19 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\nika\Application Data\Mozilla\Firefox\Profiles\yvh2rbka.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
    [2010/10/12 06:23:19 | 000,000,000 | ---D | M] (FoxTab) -- C:\Documents and Settings\nika\Application Data\Mozilla\Firefox\Profiles\yvh2rbka.default\extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}
    [2010/03/02 10:09:19 | 000,002,921 | ---- | M] () -- C:\Documents and Settings\nika\Application Data\Mozilla\Firefox\Profiles\yvh2rbka.default\searchplugins\daemon-search.xml
    [2010/12/15 11:32:44 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
    [2010/04/25 11:59:46 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
    [2010/12/14 08:32:07 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru
    [2010/04/25 11:59:26 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
    [2010/07/12 23:33:56 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npwachk.dll

    O1 HOSTS File: ([2010/12/15 09:57:26 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
    O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\ievkbd.dll (Kaspersky Lab ZAO)
    O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll (Kaspersky Lab ZAO)
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
    O4 - HKLM..\Run: [AccelerometerSysTrayApplet] C:\WINDOWS\system32\accelerometerST.exe (Hewlett-Packard Corporation)
    O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
    O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
    O4 - HKLM..\Run: [AVP] C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe (Kaspersky Lab ZAO)
    O4 - HKLM..\Run: [conime] C:\WINDOWS\System32\conime.exe (Microsoft Corporation)
    O4 - HKLM..\Run: [SMΔRT-Protection] C:\Program Files\Smadav\SMΔRTP.exe (Smadsoft)
    O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
    O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools\daemon.exe (DT Soft Ltd)
    O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
    O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
    O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
    O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Button Manager.lnk = C:\Program Files\HP\Button Manager\BM.exe ()
    O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Magic-i.lnk = C:\Program Files\ArcSoft\Magic-i 3\Magic-i.exe (ArcSoft, Inc.)
    O4 - Startup: C:\Documents and Settings\nika\Start Menu\Programs\Startup\OneNote Table Of Contents.onetoc2 ()
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
    O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
    O9 - Extra Button: &Virtual Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll (Kaspersky Lab ZAO)
    O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
    O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
    O9 - Extra Button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll (Kaspersky Lab ZAO)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
    O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.4.1 180.131.144.144 180.131.144.145
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
    O20 - Winlogon\Notify\klogon: DllName - C:\WINDOWS\system32\klogon.dll - C:\WINDOWS\system32\klogon.dll (Kaspersky Lab ZAO)
    O24 - Desktop WallPaper: C:\Documents and Settings\nika\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
    O24 - Desktop BackupWallPaper: C:\Documents and Settings\nika\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2010/01/19 08:44:09 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
    O34 - HKLM BootExecute: (autocheck autochk *) - File not found
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37 - HKLM\...com [@ = ComFile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*

    NetSvcs: 6to4 - File not found
    NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
    NetSvcs: Ias - File not found
    NetSvcs: Iprip - File not found
    NetSvcs: Irmon - File not found
    NetSvcs: NWCWorkstation - File not found
    NetSvcs: Nwsapagent - File not found
    NetSvcs: WmdmPmSp - File not found

    Drivers32: msacm.ac3acm - C:\WINDOWS\System32\ac3acm.acm (fccHandler)
    Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
    Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
    Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (http://www.mp3dev.org/)
    Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
    Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
    Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
    Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
    Drivers32: VIDC.DIVX - C:\WINDOWS\System32\divx.dll (DivX, Inc.)
    Drivers32: VIDC.FFDS - C:\WINDOWS\System32\ff_vfw.dll ()
    Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
    Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
    Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
    Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
    Drivers32: VIDC.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
    Drivers32: VIDC.YV12 - C:\WINDOWS\System32\yv12vfw.dll (www.helixcommunity.org)

    CREATERESTOREPOINT
    Restore point Set: OTL Restore Point (54619756233228288)

    ========== Files/Folders - Created Within 30 Days ==========

    [2010/12/15 09:47:11 | 000,000,000 | RHSD | C] -- C:\cmdcons
    [2010/12/15 09:44:18 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
    [2010/12/15 09:44:18 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
    [2010/12/15 09:44:18 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
    [2010/12/15 09:44:18 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
    [2010/12/15 09:40:59 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
    [2010/12/15 09:40:33 | 000,000,000 | ---D | C] -- C:\Qoobox
    [2010/12/14 19:06:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\nika\My Documents\Proyek Proyek
    [2010/12/14 10:41:12 | 000,000,000 | ---D | C] -- C:\gmer
    [2010/12/14 10:26:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\nika\Application Data\Malwarebytes
    [2010/12/14 10:26:40 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
    [2010/12/14 10:26:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    [2010/12/14 10:26:35 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
    [2010/12/14 10:26:34 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
    [2010/12/14 08:30:27 | 000,000,000 | ---D | C] -- C:\Program Files\Kaspersky Lab
    [2010/12/14 08:30:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
    [2010/12/14 08:30:13 | 000,475,736 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\klif.sys
    [2010/12/14 08:28:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
    [2010/12/14 07:18:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\nika\Application Data\QuickScan
    [2010/12/13 10:07:37 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
    [2010/12/11 21:40:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\nika\My Documents\jam_files
    [2010/12/11 21:35:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\nika\My Documents\viewtopic.php_files
    [2010/12/11 20:45:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\nika\Application Data\Smith Micro
    [2010/12/09 08:50:13 | 000,102,656 | ---- | C] (QUALCOMM Incorporated) -- C:\WINDOWS\System32\drivers\3GDatausbser.sys
    [2010/12/01 08:34:10 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot_bak
    [2010/11/30 18:30:45 | 000,000,000 | ---D | C] -- C:\Program Files\IObit
    [2010/11/30 18:30:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\IObit
    [2010/11/30 17:11:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\nika\My Documents\KONAMI
    [2010/11/30 16:53:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\KONAMI
    [2010/11/30 10:46:51 | 000,000,000 | ---D | C] -- C:\Program Files\MSXML 6.0
    [2010/11/30 06:22:29 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\PreInstall
    [2010/11/29 17:42:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\SoftwareDistribution

    ========== Files - Modified Within 30 Days ==========

    [2010/12/15 12:31:01 | 000,000,244 | -HS- | M] () -- C:\WINDOWS\KLIF.spi
    [2010/12/15 11:11:16 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
    [2010/12/15 10:02:18 | 000,000,248 | ---- | M] () -- C:\WINDOWS\tasks\Game_Booster_Startup.job
    [2010/12/15 09:57:26 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
    [2010/12/15 09:47:16 | 000,000,327 | RHS- | M] () -- C:\boot.ini
    [2010/12/15 09:43:35 | 003,989,579 | R--- | M] () -- C:\Documents and Settings\nika\Desktop\ComboFix.exe
    [2010/12/14 10:38:55 | 000,000,808 | ---- | M] () -- C:\Documents and Settings\nika\Desktop\Kaspersky Anti-Virus 2011.lnk
    [2010/12/14 10:26:40 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
    [2010/12/14 09:10:21 | 000,114,243 | ---- | M] () -- C:\WINDOWS\System32\drivers\klin.dat
    [2010/12/14 09:10:21 | 000,097,859 | ---- | M] () -- C:\WINDOWS\System32\drivers\klick.dat
    [2010/12/14 08:30:13 | 000,475,736 | ---- | M] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\klif.sys
    [2010/12/14 06:59:56 | 000,624,128 | ---- | M] () -- C:\Documents and Settings\nika\Desktop\dds.scr
    [2010/12/13 12:16:34 | 000,000,471 | ---- | M] () -- C:\WINDOWS\System32\Datei4
    [2010/12/13 12:16:34 | 000,000,471 | ---- | M] () -- C:\WINDOWS\System32\Datei2
    [2010/12/13 12:16:34 | 000,000,470 | ---- | M] () -- C:\WINDOWS\System32\Datei3
    [2010/12/13 12:16:34 | 000,000,470 | ---- | M] () -- C:\WINDOWS\System32\Datei1
    [2010/12/13 12:16:34 | 000,000,469 | ---- | M] () -- C:\WINDOWS\System32\Datei7
    [2010/12/13 12:16:34 | 000,000,469 | ---- | M] () -- C:\WINDOWS\System32\Datei5
    [2010/12/13 12:16:34 | 000,000,468 | ---- | M] () -- C:\WINDOWS\System32\Datei0
    [2010/12/13 12:16:34 | 000,000,467 | ---- | M] () -- C:\WINDOWS\System32\Datei9
    [2010/12/13 12:16:34 | 000,000,467 | ---- | M] () -- C:\WINDOWS\System32\Datei8
    [2010/12/13 12:16:34 | 000,000,467 | ---- | M] () -- C:\WINDOWS\System32\Datei10
    [2010/12/13 12:16:34 | 000,000,465 | ---- | M] () -- C:\WINDOWS\System32\Datei6
    [2010/12/11 21:40:21 | 000,029,940 | ---- | M] () -- C:\Documents and Settings\nika\My Documents\jam.htm
    [2010/12/11 21:40:00 | 000,067,478 | ---- | M] () -- C:\Documents and Settings\nika\My Documents\viewtopic.php.htm
    [2010/12/09 12:41:47 | 000,012,425 | ---- | M] () -- C:\Documents and Settings\nika\My Documents\Ayu Sandra Desi.docx
    [2010/12/06 11:22:10 | 000,009,878 | ---- | M] () -- C:\Documents and Settings\nika\My Documents\Nocan Inside gan.xlsx
    [2010/12/03 07:32:30 | 000,303,624 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
    [2010/12/01 14:54:32 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
    [2010/11/30 18:30:49 | 000,000,755 | ---- | M] () -- C:\Documents and Settings\nika\Application Data\Microsoft\Internet Explorer\Quick Launch\Game Booster.lnk
    [2010/11/30 18:30:48 | 000,000,737 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Game Booster.lnk
    [2010/11/30 17:09:39 | 000,001,537 | ---- | M] () -- C:\Documents and Settings\nika\Desktop\Pro Evolution Soccer 2011.lnk
    [2010/11/30 10:45:57 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
    [2010/11/29 18:43:01 | 000,017,408 | ---- | M] () -- C:\Documents and Settings\nika\My Documents\My IPK.xlsx
    [2010/11/29 17:42:18 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
    [2010/11/29 17:42:06 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
    [2010/11/28 20:59:41 | 000,000,044 | ---- | M] () -- C:\WINDOWS\SMWizard.INI
    [2010/11/26 16:46:02 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
    [2010/11/22 20:39:00 | 000,135,680 | ---- | M] () -- C:\Documents and Settings\nika\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

    ========== Files Created - No Company Name ==========

    [2010/12/15 11:27:45 | 000,000,244 | -HS- | C] () -- C:\WINDOWS\KLIF.spi
    [2010/12/15 09:47:16 | 000,000,211 | ---- | C] () -- C:\Boot.bak
    [2010/12/15 09:47:13 | 000,260,272 | RHS- | C] () -- C:\cmldr
    [2010/12/15 09:44:18 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
    [2010/12/15 09:44:18 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
    [2010/12/15 09:44:18 | 000,089,088 | ---- | C] () -- C:\WINDOWS\MBR.exe
    [2010/12/15 09:44:18 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
    [2010/12/15 09:44:18 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
    [2010/12/15 09:25:48 | 003,989,579 | R--- | C] () -- C:\Documents and Settings\nika\Desktop\ComboFix.exe
    [2010/12/14 10:38:55 | 000,000,808 | ---- | C] () -- C:\Documents and Settings\nika\Desktop\Kaspersky Anti-Virus 2011.lnk
    [2010/12/14 10:26:40 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
    [2010/12/14 08:31:55 | 000,114,243 | ---- | C] () -- C:\WINDOWS\System32\drivers\klin.dat
    [2010/12/14 08:31:55 | 000,097,859 | ---- | C] () -- C:\WINDOWS\System32\drivers\klick.dat
    [2010/12/14 06:59:43 | 000,624,128 | ---- | C] () -- C:\Documents and Settings\nika\Desktop\dds.scr
    [2010/12/11 21:40:20 | 000,029,940 | ---- | C] () -- C:\Documents and Settings\nika\My Documents\jam.htm
    [2010/12/11 21:38:15 | 000,067,478 | ---- | C] () -- C:\Documents and Settings\nika\My Documents\viewtopic.php.htm
    [2010/12/09 12:41:47 | 000,012,425 | ---- | C] () -- C:\Documents and Settings\nika\My Documents\Ayu Sandra Desi.docx
    [2010/12/06 11:22:09 | 000,009,878 | ---- | C] () -- C:\Documents and Settings\nika\My Documents\Nocan Inside gan.xlsx
    [2010/11/30 18:31:01 | 000,000,248 | ---- | C] () -- C:\WINDOWS\tasks\Game_Booster_Startup.job
    [2010/11/30 17:09:39 | 000,001,537 | ---- | C] () -- C:\Documents and Settings\nika\Desktop\Pro Evolution Soccer 2011.lnk
    [2010/11/28 20:59:28 | 000,000,044 | ---- | C] () -- C:\WINDOWS\SMWizard.INI
    [2010/07/23 14:21:18 | 000,000,307 | ---- | C] () -- C:\WINDOWS\game.ini
    [2010/04/04 08:38:04 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\nika\Local Settings\Application Data\FnF4.txt
    [2010/03/18 20:07:38 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Pool.INI
    [2010/03/16 05:15:10 | 000,159,192 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
    [2010/03/15 12:01:23 | 000,000,048 | ---- | C] () -- C:\WINDOWS\scmate.ini
    [2010/03/02 10:07:33 | 000,717,296 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
    [2010/02/26 11:22:28 | 000,135,680 | ---- | C] () -- C:\Documents and Settings\nika\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2010/02/26 10:30:15 | 000,164,352 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
    [2010/02/26 10:30:11 | 000,755,027 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
    [2010/02/26 10:30:10 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
    [2010/02/26 10:30:10 | 000,159,839 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
    [2010/02/26 10:30:08 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
    [2010/01/19 15:33:37 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
    [2010/01/19 08:58:29 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\nika\Local Settings\Application Data\QSwitch.txt
    [2010/01/19 08:58:29 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\nika\Local Settings\Application Data\DSwitch.txt
    [2010/01/19 08:58:29 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\nika\Local Settings\Application Data\AtStart.txt
    [2009/04/22 00:19:06 | 000,172,173 | ---- | C] () -- C:\WINDOWS\System32\xlive.dll.cat
    [2008/12/11 14:22:10 | 002,854,976 | ---- | C] () -- C:\WINDOWS\System32\btwicons.dll
    [2006/02/28 19:00:00 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\ieencode.dll
    [2001/11/14 12:56:00 | 001,802,240 | ---- | C] () -- C:\WINDOWS\System32\lcppn21.dll

    ========== LOP Check ==========

    [2010/03/30 07:17:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9
    [2010/03/02 10:09:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
    [2010/03/22 12:03:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Fugazo
    [2010/11/30 18:30:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\IObit
    [2010/11/30 16:53:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\KONAMI
    [2010/05/23 16:09:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
    [2010/06/01 10:22:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\nika\Application Data\Crayon Physics Deluxe
    [2010/03/02 10:10:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\nika\Application Data\DAEMON Tools
    [2010/07/18 07:14:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\nika\Application Data\DAEMON Tools Lite
    [2010/03/02 10:10:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\nika\Application Data\DAEMON Tools Pro
    [2010/05/26 21:06:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\nika\Application Data\Facebook
    [2010/04/29 05:57:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\nika\Application Data\FALCOM
    [2010/10/23 14:59:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\nika\Application Data\fltk.org
    [2010/12/14 07:18:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\nika\Application Data\QuickScan
    [2010/12/11 20:45:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\nika\Application Data\Smith Micro
    [2010/04/25 09:47:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\nika\Application Data\Steinberg
    [2010/05/24 18:59:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\nika\Application Data\Thinstall
    [2010/02/26 10:38:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\nika\Application Data\ZTEMTUI
    [2010/12/15 10:02:18 | 000,000,248 | ---- | M] () -- C:\WINDOWS\Tasks\Game_Booster_Startup.job

    ========== Purity Check ==========



    ========== Custom Scans ==========


    < %SYSTEMDRIVE%\*.* >
    [2010/01/19 08:44:09 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
    [2010/04/17 16:51:47 | 000,000,211 | ---- | M] () -- C:\Boot.bak
    [2010/12/15 09:47:16 | 000,000,327 | RHS- | M] () -- C:\boot.ini
    [2004/08/03 23:00:00 | 000,260,272 | RHS- | M] () -- C:\cmldr
    [2010/12/15 11:04:46 | 000,012,116 | ---- | M] () -- C:\ComboFix.txt
    [2010/01/19 08:44:09 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
    [2010/02/28 18:30:47 | 000,000,721 | ---- | M] () -- C:\deltaStartup.log
    [2010/01/19 08:44:09 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
    [2010/01/19 08:44:09 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
    [2010/05/26 08:28:54 | 000,001,090 | ---- | M] () -- C:\NetworkCfg.xml
    [2006/02/28 19:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
    [2006/02/28 19:00:00 | 000,250,032 | RHS- | M] () -- C:\ntldr
    [2010/12/15 11:11:11 | 1497,366,528 | -HS- | M] () -- C:\pagefile.sys

    < %systemroot%\Fonts\*.com >
    [2006/04/19 20:21:28 | 000,026,040 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
    [2006/07/02 22:37:10 | 000,026,489 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
    [2006/04/19 20:21:28 | 000,029,779 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
    [2006/07/02 22:37:12 | 000,030,808 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

    < %systemroot%\Fonts\*.dll >

    < %systemroot%\Fonts\*.ini >
    [2010/01/19 08:43:48 | 000,000,067 | -HS- | M] () -- C:\WINDOWS\Fonts\desktop.ini

    < %systemroot%\Fonts\*.ini2 >

    < %systemroot%\Fonts\*.exe >

    < %systemroot%\system32\spool\prtprocs\w32x86\*.* >
    [2006/10/14 16:43:18 | 000,027,648 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
    [2006/10/26 19:58:12 | 000,030,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
    [2006/10/26 19:56:12 | 000,033,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
    [2006/10/14 16:44:44 | 000,671,744 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\PrintFilterPipelineSvc.exe

    < %systemroot%\REPAIR\*.bak1 >

    < %systemroot%\REPAIR\*.ini >

    < %systemroot%\system32\*.jpg >

    < %systemroot%\*.jpg >

    < %systemroot%\*.png >

    < %systemroot%\*.scr >

    < %systemroot%\*._sy >

    < %APPDATA%\Adobe\Update\*.* >

    < %ALLUSERSPROFILE%\Favorites\*.* >

    < %APPDATA%\Microsoft\*.* >
    [2010/03/24 13:37:06 | 000,001,562 | -H-- | M] () -- C:\Documents and Settings\nika\Application Data\Microsoft\LastFlashConfig.WFC

    < %PROGRAMFILES%\*.* >

    < %APPDATA%\Update\*.* >

    < %systemroot%\*. /mp /s >

    < %systemroot%\System32\config\*.sav >
    [2010/01/19 15:31:41 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
    [2010/01/19 15:31:41 | 000,659,456 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
    [2010/01/19 15:31:41 | 000,917,504 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav

    < %PROGRAMFILES%\bak. /s >

    < %systemroot%\system32\bak. /s >

    < %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
    [2010/01/19 08:44:15 | 000,000,294 | -HS- | M] () -- C:\Documents and Settings\All Users\Start Menu\desktop.ini

    < %systemroot%\system32\config\systemprofile\*.dat /x >

    < %systemroot%\*.config >

    < %systemroot%\system32\*.db >

    < %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
    [2010/01/19 08:49:00 | 000,000,119 | -HS- | M] () -- C:\Documents and Settings\nika\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
    [2010/01/19 08:48:59 | 000,000,079 | ---- | M] () -- C:\Documents and Settings\nika\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

    < %USERPROFILE%\Desktop\*.exe >
    [2010/12/15 09:43:35 | 003,989,579 | R--- | M] () -- C:\Documents and Settings\nika\Desktop\ComboFix.exe

    < %PROGRAMFILES%\Common Files\*.* >

    < %systemroot%\*.src >

    < %systemroot%\install\*.* >

    < %systemroot%\system32\DLL\*.* >

    < %systemroot%\system32\HelpFiles\*.* >

    < %systemroot%\system32\rundll\*.* >

    < %systemroot%\winn32\*.* >

    < %systemroot%\Java\*.* >

    < %systemroot%\system32\test\*.* >

    < %systemroot%\system32\Rundll32\*.* >

    < %systemroot%\AppPatch\Custom\*.* >

    < %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

    < %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

    < %PROGRAMFILES%\Internet Explorer\*.tmp >

    < %PROGRAMFILES%\Internet Explorer\*.dat >

    < %USERPROFILE%\My Documents\*.exe >

    < %USERPROFILE%\*.exe >

    < %systemroot%\ADDINS\*.* >

    < %systemroot%\assembly\*.bak2 >

    < %systemroot%\Config\*.* >

    < %systemroot%\REPAIR\*.bak2 >

    < %systemroot%\SECURITY\Database\*.sdb /x >

    < %systemroot%\SYSTEM\*.bak2 >

    < %systemroot%\Web\*.bak2 >

    < %systemroot%\Driver Cache\*.* >

    < %PROGRAMFILES%\Mozilla Firefox\0*.exe >

    < %ProgramFiles%\Microsoft Common\*.* >

    < %ProgramFiles%\TinyProxy. >

    < %USERPROFILE%\Favorites\*.url /x >
    [2010/01/19 08:48:59 | 000,000,122 | -HS- | M] () -- C:\Documents and Settings\nika\Favorites\Desktop.ini

    < %systemroot%\system32\*.bk >

    < %systemroot%\*.te >

    < %systemroot%\system32\system32\*.* >

    < %ALLUSERSPROFILE%\*.dat /x >
    [2010/01/19 08:52:43 | 000,000,440 | RHS- | M] () -- C:\Documents and Settings\All Users\ntuser.pol

    < %systemroot%\system32\drivers\*.rmv >

    < dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

    < dir /b "%systemroot%\*.exe" | find /i " " /c >

    < %PROGRAMFILES%\Microsoft\*.* >

    < %systemroot%\System32\Wbem\proquota.exe >

    < %PROGRAMFILES%\Mozilla Firefox\*.dat >

    < %USERPROFILE%\Cookies\*.txt /x >
    [2010/12/15 12:21:48 | 000,032,768 | ---- | M] () -- C:\Documents and Settings\nika\Cookies\index.dat

    < %SystemRoot%\system32\fonts\*.* >

    < %systemroot%\system32\winlog\*.* >

    < %systemroot%\system32\Language\*.* >

    < %systemroot%\system32\Settings\*.* >

    < %systemroot%\system32\*.quo >

    < %SYSTEMROOT%\AppPatch\*.exe >

    < %SYSTEMROOT%\inf\*.exe >
    [2006/02/28 19:00:00 | 000,208,896 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\inf\unregmp2.exe

    < %SYSTEMROOT%\Installer\*.exe >

    < %systemroot%\system32\config\*.bak2 >

    < %systemroot%\system32\Computers\*.* >

    < %SystemRoot%\system32\Sound\*.* >

    < %SystemRoot%\system32\SpecialImg\*.* >

    < %SystemRoot%\system32\code\*.* >

    < %SystemRoot%\system32\draft\*.* >

    < %SystemRoot%\system32\MSSSys\*.* >

    < %ProgramFiles%\Javascript\*.* >

    < %systemroot%\pchealth\helpctr\System\*.exe /s >

    < %systemroot%\Web\*.exe >

    < %systemroot%\system32\msn\*.* >

    < %systemroot%\system32\*.tro >

    < %AppData%\Microsoft\Installer\msupdates\*.* >

    < %ProgramFiles%\Messenger\*.* >
    [2006/02/28 19:00:00 | 000,028,672 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\custsat.dll
    [2004/08/04 01:06:34 | 000,004,821 | ---- | M] () -- C:\Program Files\Messenger\logowin.gif
    [2004/08/04 01:06:34 | 000,007,047 | ---- | M] () -- C:\Program Files\Messenger\lvback.gif
    [2004/08/04 01:06:34 | 000,082,944 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msgsc.dll
    [2004/08/04 01:06:34 | 000,180,224 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msgslang.dll
    [2004/08/04 01:06:34 | 001,667,584 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msmsgs.exe
    [2006/02/28 19:00:00 | 000,009,306 | ---- | M] () -- C:\Program Files\Messenger\newalert.wav
    [2006/02/28 19:00:00 | 000,018,052 | ---- | M] () -- C:\Program Files\Messenger\newemail.wav
    [2006/02/28 19:00:00 | 000,009,306 | ---- | M] () -- C:\Program Files\Messenger\online.wav
    [2004/08/04 01:06:36 | 000,004,454 | ---- | M] () -- C:\Program Files\Messenger\type.wav
    [2004/08/04 01:06:36 | 000,115,981 | ---- | M] () -- C:\Program Files\Messenger\xpmsgr.chm

    < %systemroot%\system32\systhem32\*.* >

    < %systemroot%\system\*.exe >

    < HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

    < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs >


    ========== Files - Unicode (All) ==========
    [2010/10/12 08:27:25 | 000,000,439 | ---- | M] ()(C:\Documents and Settings\All Users\Desktop\SMAD?V.lnk) -- C:\Documents and Settings\All Users\Desktop\SMADΔV.lnk
    [2010/03/01 19:31:35 | 000,000,439 | ---- | C] ()(C:\Documents and Settings\All Users\Desktop\SMAD?V.lnk) -- C:\Documents and Settings\All Users\Desktop\SMADΔV.lnk

    ========== Alternate Data Streams ==========

    @Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9857FAE3

    < End of report >
     
  16. 2010/12/14
    doflamingo

    doflamingo Inactive Thread Starter

    Joined:
    2010/12/13
    Messages:
    29
    Likes Received:
    0
    Here's the Extras

    OTL Extras logfile created on: 12/15/2010 12:29:36 PM - Run 1
    OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\nika\My Documents\Downloads
    Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 6.0.2900.2180)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    952.00 Mb Total Physical Memory | 528.00 Mb Available Physical Memory | 55.00% Memory free
    2.00 Gb Paging File | 2.00 Gb Available in Paging File | 83.00% Paging File free
    Paging file location(s): C:\pagefile.sys 1428 2856 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 61.52 Gb Total Space | 45.30 Gb Free Space | 73.64% Space Free | Partition Type: NTFS
    Drive D: | 87.53 Gb Total Space | 59.06 Gb Free Space | 67.48% Space Free | Partition Type: NTFS

    Computer Name: DOFLAMINGO | User Name: nika | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: Current user | Quick Scan
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Extra Registry (SafeList) ==========


    ========== File Associations ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

    [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
    .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

    ========== Shell Spawning ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    exefile [open] -- "%1" %*
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1 "
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
    Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
    Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
    Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
    Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    ========== Security Center Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "FirstRunDisabled" = 1
    "AntiVirusDisableNotify" = 0
    "FirewallDisableNotify" = 0
    "UpdatesDisableNotify" = 0
    "AntiVirusOverride" = 0
    "FirewallOverride" = 0

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
    "DisableMonitoring" = 0

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

    ========== System Restore Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
    "DisableSR" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
    "Start" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
    "Start" = 2

    ========== Firewall Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
    "139:TCP" = 139:TCP:*:Enabled:mad:xpsp2res.dll,-22004
    "445:TCP" = 445:TCP:*:Enabled:mad:xpsp2res.dll,-22005
    "137:UDP" = 137:UDP:*:Enabled:mad:xpsp2res.dll,-22001
    "138:UDP" = 138:UDP:*:Enabled:mad:xpsp2res.dll,-22002

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "EnableFirewall" = 1
    "DoNotAllowExceptions" = 0
    "DisableNotifications" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
    "1900:UDP" = 1900:UDP:LocalSubNet:Disabled:mad:xpsp2res.dll,-22007
    "2869:TCP" = 2869:TCP:LocalSubNet:Disabled:mad:xpsp2res.dll,-22008
    "139:TCP" = 139:TCP:LocalSubNet:Enabled:mad:xpsp2res.dll,-22004
    "445:TCP" = 445:TCP:LocalSubNet:Enabled:mad:xpsp2res.dll,-22005
    "137:UDP" = 137:UDP:LocalSubNet:Enabled:mad:xpsp2res.dll,-22001
    "138:UDP" = 138:UDP:LocalSubNet:Enabled:mad:xpsp2res.dll,-22002
    "6088:TCP" = 6088:TCP:*:Enabled:wdjftt

    ========== Authorized Applications List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
    "C:\WINDOWS\system32\igfxmvp32.exe" = C:\WINDOWS\system32\igfxmvp32.exe:*:Enabled:WLAN Device -- File not found

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger -- (Yahoo! Inc.)
    "C:\Program Files\Counter-Strike 1.6\hl.exe" = C:\Program Files\Counter-Strike 1.6\hl.exe:*:Enabled:Half-Life Launcher -- (Valve)
    "C:\Program Files\Left 4 Dead\left4dead.exe" = C:\Program Files\Left 4 Dead\left4dead.exe:*:Enabled:left4dead -- ()
    "D:\game\Need for Speed Underground 2\speed2.exe" = D:\game\Need for Speed Underground 2\speed2.exe:*:Enabled:speed2 -- ()
    "D:\game\PES2011\pes2011.exe" = D:\game\PES2011\pes2011.exe:*:Enabled:pro Evolution Soccer 2011 -- (Konami Digital Entertainment Co., Ltd.)
    "C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Mozilla Firefox -- (Mozilla Corporation)


    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{05B49229-22A2-4F88-842A-BBC2EBE1CCF6}" = Microsoft Games for Windows - LIVE Redistributable
    "{0CCCD5BF-FDDD-4D31-8E3F-CEA3FD196B26}" = HP 3D DriveGuard
    "{15095BF3-A3D7-4DDF-B193-3A496881E003}" = Microsoft .NET Framework 3.0
    "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    "{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java(TM) 6 Update 20
    "{2BB67266-D1A3-4CCC-8EB2-16770AB1FB76}" = ArcSoft WebCam Companion 2
    "{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons
    "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
    "{491DD792-AD81-429C-9EB4-86DD3D22E333}" = Windows Communication Foundation
    "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
    "{4D243BA7-9AC4-46D1-90E5-EEB88974F501}" = Microsoft Games for Windows - LIVE
    "{66F1F013-008F-4875-B283-5A814B820347}" = Kaspersky Anti-Virus 2011
    "{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
    "{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
    "{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
    "{719842F9-FF69-4BA6-A6FE-52244575E0B3}" = ArcSoft VideoImpression 2
    "{786C5694-F5C0-4215-92B7-EE77A4E7319C}" = PHStat2 version 2.7
    "{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}" = Windows Workflow Foundation
    "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
    "{84814E6B-2581-46EC-926A-823BD1C670F6}" = HP Integrated Module with Bluetooth wireless technology
    "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
    "{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
    "{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
    "{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
    "{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
    "{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
    "{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
    "{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
    "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
    "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
    "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
    "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
    "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
    "{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
    "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
    "{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
    "{90120000-00B0-0409-0000-0000000FF1CE}" = Microsoft Save as PDF Add-in for 2007 Microsoft Office programs
    "{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
    "{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
    "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
    "{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
    "{9773450C-E2F3-46C3-9464-1D7EDE5EFB63}" = Pro Evolution Soccer 2011
    "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    "{AC76BA86-7AD7-1033-7B44-A81100000003}" = Adobe Reader 8.1.1
    "{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
    "{CA634931-0CC3-4067-ABCC-7182E1DC23B7}" = HP Button Manager
    "{D31612BB-C6D7-4142-96AE-16DB062354CF}" = HP Webcam User’s Guide
    "{DAEAFD68-BB4A-4507-A241-C8804D2EA66D}" = Apple Application Support
    "{DB6F07FF-A436-453a-B685-F6C1F4F09D22}" = PANTECH PC Card Software
    "{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
    "{EFB21DE7-8C19-4A88-BB28-A766E16493BC}" = Adobe Photoshop CS
    "{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
    "{F1D7AC58-554A-4A58-B784-B61558B1449A}" = QLBCASL
    "{FAB046D7-C187-4648-A1A9-FC875F7E3FCE}" = ArcSoft Magic-i 3
    "3GP Video Converter 3" = 3GP Video Converter 3
    "Access Manager" = Access Manager
    "Actual Spy_is1" = Actual Spy 3.0
    "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
    "Adobe Shockwave Player" = Adobe Shockwave Player 11.5
    "CCleaner" = CCleaner
    "Cheating-Death" = Cheating-Death 4.32.0
    "Counter-Strike 1.6_is1" = Counter-Strike 1.6
    "Crayon Physics Deluxe_is1" = Crayon Physics Deluxe - release 51
    "ENTERPRISE" = Microsoft Office Enterprise 2007
    "FLV Player" = FLV Player 2.0 (build 25)
    "Game Booster_is1" = Game Booster
    "HDMI" = Intel(R) Graphics Media Accelerator Driver
    "InstallWIX_{66F1F013-008F-4875-B283-5A814B820347}" = Kaspersky Anti-Virus 2011
    "Kid-Key-Lock_is1" = Kid-Key-Lock 1.7.0.0
    "KLiteCodecPack_is1" = K-Lite Mega Codec Pack 3.9.0
    "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
    "Marvell Miniport Driver" = Marvell Miniport Driver
    "Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
    "Microsoft .NET Framework 3.0" = Microsoft .NET Framework 3.0
    "MiniLyrics" = Minilyrics(remove only)
    "Mobile Partner" = Mobile Partner
    "Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13)
    "Smart Bro" = Smart Bro
    "ST6UNST #1" = Hero Editor V0.96
    "SyncroSoft Emu" = SyncroSoft Emu (Remove only)
    "Syncrosoft's License Control" = Syncrosoft's License Control
    "SynTPDeinstKey" = Synaptics Pointing Device Driver
    "Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
    "WIC" = Windows Imaging Component
    "Winamp" = Winamp
    "Winamp Essentials Pack" = Winamp Essentials Pack
    "Windows Media Format Runtime" = Windows Media Format Runtime
    "WinRAR archiver" = WinRAR archiver
    "XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
    "Yahoo! Messenger" = Yahoo! Messenger
    "ZTEWireless-101_is1" = Modem AC2726 UI

    ========== HKEY_CURRENT_USER Uninstall List ==========

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "Facebook Plug-In" = Facebook Plug-In
    "Winamp Detect" = Winamp Detector Plug-in
    "Yahoo! BrowserPlus" = Yahoo! BrowserPlus 2.8.1

    ========== Last 10 Event Log Errors ==========

    [ Application Events ]
    Error - 12/11/2010 11:39:41 AM | Computer Name = DOFLAMINGO | Source = Application Hang | ID = 1002
    Description = Hanging application Access Manager.exe, version 6.7.1.2035, hang module
    hungapp, version 0.0.0.0, hang address 0x00000000.

    Error - 12/11/2010 11:40:33 AM | Computer Name = DOFLAMINGO | Source = Application Hang | ID = 1002
    Description = Hanging application Access Manager.exe, version 6.7.1.2035, hang module
    hungapp, version 0.0.0.0, hang address 0x00000000.

    Error - 12/11/2010 11:40:44 AM | Computer Name = DOFLAMINGO | Source = Application Hang | ID = 1002
    Description = Hanging application Access Manager.exe, version 6.7.1.2035, hang module
    hungapp, version 0.0.0.0, hang address 0x00000000.

    Error - 12/11/2010 9:43:37 PM | Computer Name = DOFLAMINGO | Source = Application Error | ID = 1000
    Description = Faulting application jaucheck.exe, version 2.0.2.1, faulting module
    jaucheck.exe, version 2.0.2.1, fault address 0x0000c940.

    Error - 12/13/2010 2:22:54 AM | Computer Name = DOFLAMINGO | Source = crypt32 | ID = 131080
    Description = Failed auto update retrieval of third-party root list sequence number
    from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
    with error: The server name or address could not be resolved

    Error - 12/13/2010 2:22:55 AM | Computer Name = DOFLAMINGO | Source = crypt32 | ID = 131080
    Description = Failed auto update retrieval of third-party root list sequence number
    from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
    with error: This network connection does not exist.

    Error - 12/14/2010 12:22:43 AM | Computer Name = DOFLAMINGO | Source = Application Error | ID = 1000
    Description = Faulting application , version 0.0.0.0, faulting module unknown, version
    0.0.0.0, fault address 0x00000000.

    Error - 12/14/2010 1:38:58 AM | Computer Name = DOFLAMINGO | Source = Application Error | ID = 1000
    Description = Faulting application , version 0.0.0.0, faulting module unknown, version
    0.0.0.0, fault address 0x00000000.

    Error - 12/14/2010 7:26:49 AM | Computer Name = DOFLAMINGO | Source = Application Hang | ID = 1002
    Description = Hanging application firefox.exe, version 1.9.2.3989, hang module hungapp,
    version 0.0.0.0, hang address 0x00000000.

    Error - 12/14/2010 10:30:50 PM | Computer Name = DOFLAMINGO | Source = Application Error | ID = 1000
    Description = Faulting application , version 0.0.0.0, faulting module unknown, version
    0.0.0.0, fault address 0x00000000.

    [ OSession Events ]
    Error - 5/29/2010 12:12:57 AM | Computer Name = DOFLAMINGO | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
    Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session
    lasted 5 seconds with 0 seconds of active time. This session ended with a crash.

    Error - 6/16/2010 6:18:07 AM | Computer Name = DOFLAMINGO | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 2, Application Name: Microsoft Office Access, Application Version:
    12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 183
    seconds with 180 seconds of active time. This session ended with a crash.

    Error - 7/15/2010 7:01:54 AM | Computer Name = DOFLAMINGO | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 2, Application Name: Microsoft Office Access, Application Version:
    12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 40
    seconds with 0 seconds of active time. This session ended with a crash.

    Error - 7/15/2010 7:02:02 AM | Computer Name = DOFLAMINGO | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 2, Application Name: Microsoft Office Access, Application Version:
    12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 0
    seconds with 0 seconds of active time. This session ended with a crash.

    Error - 11/10/2010 7:49:36 PM | Computer Name = DOFLAMINGO | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
    Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session
    lasted 1 seconds with 0 seconds of active time. This session ended with a crash.

    Error - 11/10/2010 7:50:00 PM | Computer Name = DOFLAMINGO | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
    Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session
    lasted 14 seconds with 0 seconds of active time. This session ended with a crash.

    Error - 11/10/2010 7:50:17 PM | Computer Name = DOFLAMINGO | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
    Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session
    lasted 11 seconds with 0 seconds of active time. This session ended with a crash.

    Error - 11/10/2010 7:51:00 PM | Computer Name = DOFLAMINGO | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
    Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session
    lasted 24 seconds with 0 seconds of active time. This session ended with a crash.

    Error - 11/10/2010 7:52:44 PM | Computer Name = DOFLAMINGO | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
    Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session
    lasted 59 seconds with 0 seconds of active time. This session ended with a crash.

    Error - 11/10/2010 7:54:43 PM | Computer Name = DOFLAMINGO | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
    Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session
    lasted 117 seconds with 60 seconds of active time. This session ended with a crash.

    [ System Events ]
    Error - 12/14/2010 1:25:58 AM | Computer Name = DOFLAMINGO | Source = Service Control Manager | ID = 7011
    Description = Timeout (30000 milliseconds) waiting for a transaction response from
    the stisvc service.

    Error - 12/14/2010 1:26:31 AM | Computer Name = DOFLAMINGO | Source = Service Control Manager | ID = 7023
    Description = The Windows Firewall/Internet Connection Sharing (ICS) service terminated
    with the following error: %%5

    Error - 12/14/2010 1:42:09 AM | Computer Name = DOFLAMINGO | Source = Service Control Manager | ID = 7032
    Description = The Service Control Manager tried to take a corrective action (Restart
    the service) after the unexpected termination of the Windows Management Instrumentation
    service, but this action failed with the following error: %%1056

    Error - 12/14/2010 1:52:26 AM | Computer Name = DOFLAMINGO | Source = Service Control Manager | ID = 7011
    Description = Timeout (30000 milliseconds) waiting for a transaction response from
    the stisvc service.

    Error - 12/14/2010 4:36:46 AM | Computer Name = DOFLAMINGO | Source = Service Control Manager | ID = 7016
    Description = The MgiSvr service has reported an invalid current state 32.

    Error - 12/14/2010 6:18:50 AM | Computer Name = DOFLAMINGO | Source = MRxSmb | ID = 8003
    Description = The master browser has received a server announcement from the computer
    BADJINGANCYCLE that believes that it is the master browser for the domain on transport
    NetBT_Tcpip_{9DA36829-AB9D. The master browser is stopping or an election is being
    forced.

    Error - 12/14/2010 10:48:11 PM | Computer Name = DOFLAMINGO | Source = Service Control Manager | ID = 7034
    Description = The UDisk Monitor service terminated unexpectedly. It has done this
    1 time(s).

    Error - 12/14/2010 11:57:41 PM | Computer Name = DOFLAMINGO | Source = Service Control Manager | ID = 7034
    Description = The UDisk Monitor service terminated unexpectedly. It has done this
    1 time(s).

    Error - 12/15/2010 1:22:08 AM | Computer Name = DOFLAMINGO | Source = MRxSmb | ID = 8003
    Description = The master browser has received a server announcement from the computer
    HP-738BCD076912 that believes that it is the master browser for the domain on transport
    NetBT_Tcpip_{9DA36829-AB9. The master browser is stopping or an election is being
    forced.

    Error - 12/15/2010 1:23:51 AM | Computer Name = DOFLAMINGO | Source = NetBT | ID = 4321
    Description = The name "MSHOME :1d" could not be registered on the Interface
    with IP address 192.168.4.183. The machine with the IP address 192.168.4.15 did
    not allow the name to be claimed by this machine.


    < End of report >
     
  17. 2010/12/15
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Good news :)

    Update your Java version here: http://www.java.com/en/download/installed.jsp

    Note 1: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

    Note 2: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. If you don't want to run another extra service, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.

    Now, we need to remove old Java version and its remnants...

    Download JavaRa to your desktop and unzip it to its own folder
    • Run JavaRa.exe (Vista users! Right click on JavaRa.exe, click Run As Administrator), pick the language of your choice and click Select. Then click Remove Older Versions.
    • Accept any prompts.

    ===============================================================

    Run OTL
    • Under the [color= "#0000FF"]Custom Scans/Fixes[/color] box at the bottom, paste in the following

      Code:
      :OTL
      O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
      O4 - HKLM..\Run: [SMΔRT-Protection] C:\Program Files\Smadav\SMΔRTP.exe (Smadsoft)
      [2010/03/30 07:17:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9
      @Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9857FAE3
      [2010/10/12 08:27:25 | 000,000,439 | ---- | M] ()(C:\Documents and Settings\All Users\Desktop\SMAD?V.lnk) -- C:\Documents and Settings\All Users\Desktop\SMADΔV.lnk
      [2010/03/01 19:31:35 | 000,000,439 | ---- | C] ()(C:\Documents and Settings\All Users\Desktop\SMAD?V.lnk) -- C:\Documents and Settings\All Users\Desktop\SMADΔV.lnk
      
      
      :Services
      
      :Reg
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
       "DisableMonitoring" =-
      
      
      :Files
      C:\Program Files\Smadav
      
      
      :Commands
      [purity]
      [emptytemp]
      [emptyflash]
      [Reboot]
      
    • Then click the [color= "#FF0000"]Run Fix[/color] button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • You will get a log that shows the results of the fix. Please post it.

    ===============================================================

    Last scans....

    1. Download Security Check from HERE, and save it to your Desktop.
    • Double-click SecurityCheck.exe
    • Follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

      NOTE SecurityCheck may produce some false warning(s), so leave the results reading to me.


    2. Download Temp File Cleaner (TFC)
    • Double click on TFC.exe to run the program.
    • Click on Start button to begin cleaning process.
    • TFC will close all running programs, and it may ask you to restart computer.


    3. Please run a free online scan with the ESET Online Scanner

    • Disable your antivirus program
    • Tick the box next to YES, I accept the Terms of Use
    • Click Start
    • IMPORTANT! UN-check Remove found threats
    • Accept any security warnings from your browser.
    • Check Scan archives
    • Click Start
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, push List of found threats
    • Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    • NOTE. If Eset won't find any threats, it won't produce any log.
     
  18. 2010/12/15
    doflamingo

    doflamingo Inactive Thread Starter

    Joined:
    2010/12/13
    Messages:
    29
    Likes Received:
    0
    Wow, i'm surprised that eset found viruses in my computer :eek:

    here's the log :)

    All processes killed
    ========== OTL ==========
    Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{32099AAC-C132-4136-9E9A-4E364A424E17} deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}\ not found.
    Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\SMΔRT-Protection deleted successfully.
    C:\Program Files\Smadav\SMΔRTP.exe moved successfully.
    C:\Documents and Settings\All Users\Application Data\avg9\Temp folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\avg9\Log folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\avg9 folder moved successfully.
    ADS C:\Documents and Settings\All Users\Application Data\TEMP:9857FAE3 deleted successfully.
    C:\Documents and Settings\All Users\Desktop\SMADΔV.lnk moved successfully.
    File C:\Documents and Settings\All Users\Desktop\SMADΔV.lnk not found.
    ========== SERVICES/DRIVERS ==========
    ========== REGISTRY ==========
    Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus\\DisableMonitoring deleted successfully.
    ========== FILES ==========
    C:\Program Files\Smadav folder moved successfully.
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: LocalService
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 32902 bytes

    User: NetworkService
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 33103 bytes

    User: nika
    ->Temp folder emptied: 10550726 bytes
    ->Temporary Internet Files folder emptied: 108700 bytes
    ->Java cache emptied: 2027 bytes
    ->FireFox cache emptied: 100162132 bytes
    ->Flash cache emptied: 2184 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\dllcache .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 215248 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 106.00 mb


    [EMPTYFLASH]

    User: All Users

    User: Default User

    User: LocalService

    User: NetworkService

    User: nika
    ->Flash cache emptied: 0 bytes

    Total Flash Files Cleaned = 0.00 mb


    OTL by OldTimer - Version 3.2.17.3 log created on 12152010_155234

    Files\Folders moved on Reboot...
    File\Folder C:\WINDOWS\temp\kls947D.tmp not found!
    C:\WINDOWS\temp\Perflib_Perfdata_a40.dat moved successfully.

    Registry entries deleted on Reboot...
     
  19. 2010/12/15
    doflamingo

    doflamingo Inactive Thread Starter

    Joined:
    2010/12/13
    Messages:
    29
    Likes Received:
    0
    Here's the checkup

    Results of screen317's Security Check version 0.99.5
    Windows XP Service Pack 2
    Out of date service pack!!
    Internet Explorer 6 Out of date!
    ``````````````````````````````
    Antivirus/Firewall Check:

    Windows Firewall Enabled!
    Kaspersky Anti-Virus 2011
    Antivirus up to date!
    ```````````````````````````````
    Anti-malware/Other Utilities Check:

    Malwarebytes' Anti-Malware
    CCleaner
    Java(TM) 6 Update 23
    Out of date Java installed!
    Adobe Flash Player 10.1.102.64
    Adobe Reader 8.1.1
    Out of date Adobe Reader installed!
    Mozilla Firefox (3.6.13) Firefox Out of Date!
    ````````````````````````````````
    Process Check:
    objlist.exe by Laurent

    Kaspersky Lab Kaspersky Anti-Virus 2011 avp.exe
    ````````````````````````````````
    DNS Vulnerability Check:

    GREAT! (Not vulnerable to DNS cache poisoning)

    ``````````End of Log````````````
     
  20. 2010/12/15
    doflamingo

    doflamingo Inactive Thread Starter

    Joined:
    2010/12/13
    Messages:
    29
    Likes Received:
    0
    ANd finally, here's the eset's log :)

    C:\Documents and Settings\All Users\Start Menu\Programs\Actual Spy\ActualSpy.exe probably a variant of Win32/Agent.DNARYPE trojan
    C:\Documents and Settings\NetworkService\tyrla.exe a variant of Win32/Kryptik.HOU trojan
    C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\KXC58X0D\24[1].exe a variant of Win32/Kryptik.HPD trojan
    C:\System Volume Information\_restore{FFEBD83F-D6B4-4D8F-AE8B-1EFD1A4BBC8F}\RP201\A0090479.exe Win32/Stuxnet.A worm
    C:\System Volume Information\_restore{FFEBD83F-D6B4-4D8F-AE8B-1EFD1A4BBC8F}\RP201\A0090480.PNF Win32/Stuxnet.A worm
    C:\WINDOWS\system32\igfxdsr32.exe a variant of Win32/Kryptik.HPD trojan
    D:\Mentahan\Trial.Resetter.CyberAff.NonStopFunZone.Com.rar Win32/HackTool.Kiser.OK trojan
    D:\Study\Semester 2\Macroeconomics\ENDRI\autorun.inf INF/Autorun.C.Gen virus
     
  21. 2010/12/15
    doflamingo

    doflamingo Inactive Thread Starter

    Joined:
    2010/12/13
    Messages:
    29
    Likes Received:
    0
    oh yeah, by the way, after i ran the OTL, in my D:\ , a folder named _OTL suddenly appear, and it had a folder named "Movedfile" on it. may i delete it?
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.