1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved ran combofix myself now windows wont boot

Discussion in 'Malware and Virus Removal Archive' started by JusticeNY, 2010/12/27.

  1. 2010/12/28
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Let me try to post OTL log...

    OTL logfile created on: 2010-12-28 4:07:14 PM - Run 1
    OTL by OldTimer - Version 3.2.18.0 Folder = C:\Documents and Settings\family\Desktop
    Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 6.0.2900.2180)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: yyyy-MM-dd

    1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 67.00% Memory free
    3.00 Gb Paging File | 3.00 Gb Available in Paging File | 88.00% Paging File free
    Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 70.93 Gb Total Space | 1.49 Gb Free Space | 2.09% Space Free | Partition Type: NTFS

    Computer Name: FAM | User Name: Family | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: Current user | Quick Scan
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Processes (SafeList) ==========

    PRC - [2010-12-28 16:05:00 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\family\Desktop\OTL.exe
    PRC - [2010-12-19 11:33:21 | 000,267,944 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    PRC - [2010-12-10 15:32:26 | 000,910,808 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
    PRC - [2010-08-02 16:10:02 | 000,135,336 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
    PRC - [2010-08-02 16:09:56 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
    PRC - [2010-05-20 17:11:48 | 002,437,176 | ---- | M] (Check Point Software Technologies LTD) -- C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
    PRC - [2010-05-20 17:10:18 | 001,043,968 | ---- | M] (Check Point Software Technologies LTD) -- C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    PRC - [2010-05-18 09:01:36 | 000,493,032 | ---- | M] (Check Point Software Technologies) -- C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe
    PRC - [2010-05-18 09:01:32 | 000,730,600 | ---- | M] (Check Point Software Technologies) -- C:\Program Files\CheckPoint\ZAForceField\ForceField.exe
    PRC - [2010-01-14 22:11:02 | 000,076,968 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
    PRC - [2008-11-09 15:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
    PRC - [2007-04-04 16:41:28 | 000,177,672 | R--- | M] (Authentium, Inc.) -- C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
    PRC - [2004-08-12 08:19:07 | 001,032,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe


    ========== Modules (SafeList) ==========

    MOD - [2010-12-28 16:05:00 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\family\Desktop\OTL.exe
    MOD - [2010-08-23 11:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
    MOD - [2010-05-18 09:01:40 | 000,640,488 | ---- | M] (Check Point Software Technologies) -- C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
    MOD - [2009-07-12 01:12:06 | 000,632,656 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll
    MOD - [2009-07-12 01:09:20 | 000,554,832 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcp80.dll


    ========== Win32 Services (SafeList) ==========

    SRV - File not found [Auto | Stopped] -- C:\Program Files\Viewpoint\Common\ViewpointService.exe -- (Viewpoint Manager Service)
    SRV - File not found [On_Demand | Stopped] -- -- (VideoAcceleratorEngine)
    SRV - File not found [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe -- (McComponentHostService)
    SRV - File not found [Disabled | Stopped] -- C:\WINDOWS\System32\hidserv.dll -- (HidServ)
    SRV - [2010-12-19 11:33:21 | 000,267,944 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
    SRV - [2010-11-29 10:41:26 | 000,058,944 | ---- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- C:\Program Files\NOS\bin\getPlus_Helper_3004.dll -- (nosGetPlusHelper) getPlus(R)
    SRV - [2010-08-02 16:10:02 | 000,135,336 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
    SRV - [2010-05-20 17:11:48 | 002,437,176 | ---- | M] (Check Point Software Technologies LTD) [Auto | Running] -- C:\WINDOWS\System32\ZoneLabs\vsmon.exe -- (vsmon)
    SRV - [2010-05-18 09:01:36 | 000,493,032 | ---- | M] (Check Point Software Technologies) [Auto | Running] -- C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe -- (IswSvc)
    SRV - [2010-05-14 11:00:26 | 000,249,136 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -- (SeaPort)
    SRV - [2009-09-24 23:48:41 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
    SRV - [2008-11-09 15:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
    SRV - [2008-03-17 17:59:36 | 000,099,056 | ---- | M] (Radialpoint Inc.) [On_Demand | Stopped] -- C:\Program Files\verizon\PC Security Checkup\rpsupdaterR.exe -- (RPSUpdaterR)
    SRV - [2007-04-04 16:41:28 | 000,177,672 | R--- | M] (Authentium, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe -- (dvpapi)
    SRV - [2004-07-01 15:45:46 | 000,421,888 | ---- | M] (Dell) [On_Demand | Stopped] -- C:\WINDOWS\System32\dlbucoms.exe -- (dlbu_device)


    ========== Driver Services (SafeList) ==========

    DRV - File not found [Kernel | Auto | Stopped] -- C:\Program Files\Verizon Games on Demand Player\X4HSX32.Sys -- (X4HSX32)
    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\vinyl97.sys -- (VIAudio) Vinyl AC'97 Audio Controller (WDM)
    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\PeerGuardian2\pgfilter.sys -- (pgfilter)
    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\EagleNT.sys -- (EagleNT)
    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\family\LOCALS~1\Temp\catchme.sys -- (catchme)
    DRV - [2010-12-25 12:19:32 | 000,135,096 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\avipbb.sys -- (avipbb)
    DRV - [2010-12-19 11:33:23 | 000,061,960 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\avgntflt.sys -- (avgntflt)
    DRV - [2010-06-24 12:52:08 | 000,028,256 | ---- | M] (Jaksta LLC) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\JakNDis.sys -- (JakNDisMP)
    DRV - [2010-06-24 12:52:08 | 000,028,256 | ---- | M] (Jaksta LLC) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\JakNDis.sys -- (JakNDis)
    DRV - [2010-06-17 15:27:24 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\ssmdrv.sys -- (ssmdrv)
    DRV - [2010-06-17 15:27:14 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys -- (avgio)
    DRV - [2010-05-18 09:01:28 | 000,026,352 | ---- | M] (Check Point Software Technologies) [Kernel | Auto | Running] -- C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys -- (ISWKL)
    DRV - [2010-05-13 17:05:40 | 000,032,768 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\taphss.sys -- (taphss)
    DRV - [2010-05-13 09:02:32 | 000,532,224 | ---- | M] (Check Point Software Technologies LTD) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\vsdatant.sys -- (vsdatant)
    DRV - [2009-12-30 11:20:54 | 000,027,064 | ---- | M] (VS Revo Group) [File_System | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\revoflt.sys -- (Revoflt)
    DRV - [2009-07-02 20:14:33 | 000,137,888 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\PnkBstrK.sys -- (PnkBstrK)
    DRV - [2008-12-15 17:23:42 | 000,102,664 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\tmcomm.sys -- (tmcomm)
    DRV - [2008-12-10 01:39:33 | 000,717,296 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\sptd.sys -- (sptd)
    DRV - [2008-01-14 05:06:32 | 000,021,632 | ---- | M] (ManyCam LLC.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\ManyCam.sys -- (ManyCam)
    DRV - [2007-09-28 13:30:57 | 000,019,345 | ---- | M] (Motive, Inc.) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Motive\MREMPR5.sys -- (MREMPR5)
    DRV - [2007-09-28 13:30:49 | 000,018,003 | ---- | M] (Motive, Inc.) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Motive\MRENDIS5.sys -- (MRENDIS5)
    DRV - [2007-06-07 18:32:33 | 000,017,480 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\hamachi.sys -- (hamachi)
    DRV - [2007-06-03 21:07:27 | 000,223,128 | ---- | M] (Alcohol Soft Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\Drivers\vaxscsi.sys -- (vaxscsi)
    DRV - [2007-04-04 16:15:02 | 000,839,880 | ---- | M] (Authentium, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\Css-Dvp.sys -- (CSS DVP)
    DRV - [2006-10-19 10:11:40 | 000,010,664 | ---- | M] (Applied Networking Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\gan_adapter.sys -- (hamachi_oem)
    DRV - [2005-11-03 09:40:07 | 000,063,488 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfvfs02.sys -- (sfvfs02) StarForce Protection VFS Driver (version 2.x)
    DRV - [2005-08-10 07:44:04 | 000,050,688 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfdrv01.sys -- (sfdrv01) StarForce Protection Environment Driver (version 1.x)
    DRV - [2005-05-16 08:20:39 | 000,006,656 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfhlp02.sys -- (sfhlp02) StarForce Protection Helper Driver (version 2.x)
    DRV - [2005-01-03 19:43:08 | 000,004,682 | ---- | M] (INCA Internet Co., Ltd.) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\npptNT2.sys -- (NPPTNT2)
    DRV - [2004-08-25 14:28:46 | 000,787,456 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\ati2mtag.sys -- (ati2mtag)
    DRV - [2004-08-12 08:31:27 | 000,036,736 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\ultra.sys -- (ultra)
    DRV - [2004-08-12 08:30:27 | 000,030,688 | ---- | M] (LSI Logic) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\sym_u3.sys -- (sym_u3)
    DRV - [2004-08-12 08:30:27 | 000,028,384 | ---- | M] (LSI Logic) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\sym_hi.sys -- (sym_hi)
    DRV - [2004-08-12 08:30:26 | 000,032,640 | ---- | M] (LSI Logic) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\symc8xx.sys -- (symc8xx)
    DRV - [2004-08-12 08:30:26 | 000,016,256 | ---- | M] (Symbios Logic Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\symc810.sys -- (symc810)
    DRV - [2004-08-12 08:29:29 | 000,019,072 | ---- | M] (Adaptec, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\sparrow.sys -- (Sparrow)
    DRV - [2004-08-12 08:26:47 | 000,049,024 | ---- | M] (QLogic Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\ql1280.sys -- (ql1280)
    DRV - [2004-08-12 08:26:47 | 000,045,312 | ---- | M] (QLogic Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\ql12160.sys -- (ql12160)
    DRV - [2004-08-12 08:26:46 | 000,040,320 | ---- | M] (QLogic Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\ql1080.sys -- (ql1080)
    DRV - [2004-08-12 08:25:23 | 000,088,448 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\nwlnkipx.sys -- (NwlnkIpx)
    DRV - [2004-08-12 08:25:23 | 000,063,232 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\nwlnknb.sys -- (NwlnkNb)
    DRV - [2004-08-12 08:25:23 | 000,055,936 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\nwlnkspx.sys -- (NwlnkSpx)
    DRV - [2004-08-12 08:22:31 | 000,017,280 | ---- | M] (American Megatrends Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\mraid35x.sys -- (mraid35x)
    DRV - [2004-08-12 08:18:51 | 000,011,648 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\scsiprnt.sys -- (scsiprnt)
    DRV - [2004-08-12 08:18:30 | 000,179,584 | ---- | M] (Mylex Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\dac2w2k.sys -- (dac2w2k)
    DRV - [2004-08-12 08:17:45 | 000,006,656 | ---- | M] (CMD Technology, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\cmdide.sys -- (CmdIde)
    DRV - [2004-08-12 08:17:24 | 000,026,496 | ---- | M] (Advanced System Products, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\asc.sys -- (asc)
    DRV - [2004-08-12 08:17:24 | 000,014,848 | ---- | M] (Advanced System Products, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\asc3550.sys -- (asc3550)
    DRV - [2004-08-12 08:17:21 | 000,005,248 | ---- | M] (Acer Laboratories Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\aliide.sys -- (AliIde)
    DRV - [2004-08-03 23:29:56 | 001,897,408 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\NV4_MINI.SYS -- (nv)
    DRV - [2004-08-03 23:07:44 | 000,043,008 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\amdagp.sys -- (amdagp)
    DRV - [2004-08-03 23:07:44 | 000,041,088 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\sisagp.sys -- (sisagp)
    DRV - [2004-04-01 16:30:46 | 000,010,368 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\pfc.sys -- (pfc)
    DRV - [2003-11-17 16:59:20 | 000,212,224 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\HSFHWBS2.sys -- (HSFHWBS2)
    DRV - [2003-11-17 16:58:02 | 000,680,704 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\HSF_CNXT.sys -- (winachsf)
    DRV - [2003-11-17 16:56:26 | 001,042,432 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\HSF_DP.sys -- (HSF_DP)
    DRV - [2002-11-08 14:45:06 | 000,017,217 | ---- | M] (Dell Computer Corporation) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys -- (omci)
    DRV - [2002-01-12 16:30:34 | 000,003,567 | ---- | M] (Beyond Logic http://www.beyondlogic.org) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\PortTalk.sys -- (PortTalk)
    DRV - [2001-01-09 16:49:28 | 000,027,088 | ---- | M] (Primax Electronics Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\PELMOUSE.SYS -- (pelmouse)
    DRV - [2001-01-08 21:02:54 | 000,012,816 | ---- | M] (Primax Electronics Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\pelusblf.sys -- (pelusblf)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
    IE - HKCU\..\URLSearchHook: {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - C:\Program Files\ZoneAlarm\tbZone.dll (Conduit Ltd.)
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    ========== FireFox ==========

    FF - prefs.js..browser.startup.homepage: "http://www.google.com/ "
    FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
    FF - prefs.js..extensions.enabledItems: anycolor.pavlos256@gmail.com:0.3.3
    FF - prefs.js..extensions.enabledItems: {2ac337b3-fc9c-4d51-bed1-1ac1c48c63ea}:3.2.3.3
    FF - prefs.js..extensions.enabledItems: {0545b830-f0aa-4d7e-8820-50a4629a56fe}:4.6.5
    FF - prefs.js..extensions.enabledItems: engine@conduit.com:3.2.5.2
    FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.1
    FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20100408.6
    FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
    FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
    FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.0.8.1
    FF - prefs.js..extensions.enabledItems: {02450954-cdd9-410f-b1da-db804e18c671}:0.96.3


    FF - HKLM\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\TrustChecker [2010-11-12 15:01:12 | 000,000,000 | ---D | M]
    FF - HKLM\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2010-12-01 03:01:02 | 000,000,000 | ---D | M]
    FF - HKLM\software\mozilla\Mozilla Firefox 3.5.16\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010-12-20 19:53:35 | 000,000,000 | ---D | M]
    FF - HKLM\software\mozilla\Mozilla Firefox 3.5.16\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010-12-10 15:32:35 | 000,000,000 | ---D | M]
    FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird

    [2010-11-09 02:37:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\Mozilla\Extensions
    [2010-12-28 03:41:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\Mozilla\Firefox\Profiles\h0sglesq.default\extensions
    [2010-11-09 04:15:14 | 000,000,000 | ---D | M] (Screengrab) -- C:\Documents and Settings\family\Application Data\Mozilla\Firefox\Profiles\h0sglesq.default\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
    [2010-12-25 19:46:28 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\family\Application Data\Mozilla\Firefox\Profiles\h0sglesq.default\extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe}
    [2010-12-24 15:46:46 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\family\Application Data\Mozilla\Firefox\Profiles\h0sglesq.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
    [2010-11-09 17:53:02 | 000,000,000 | ---D | M] (BlackBar Community Toolbar) -- C:\Documents and Settings\family\Application Data\Mozilla\Firefox\Profiles\h0sglesq.default\extensions\{2ac337b3-fc9c-4d51-bed1-1ac1c48c63ea}
    [2010-12-24 15:46:43 | 000,000,000 | ---D | M] (NoScript) -- C:\Documents and Settings\family\Application Data\Mozilla\Firefox\Profiles\h0sglesq.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
    [2010-12-09 00:59:26 | 000,000,000 | ---D | M] (HyperCam Toolbar) -- C:\Documents and Settings\family\Application Data\Mozilla\Firefox\Profiles\h0sglesq.default\extensions\{75656794-AB59-4712-BFBC-5D816D56F3BC}
    [2010-11-09 04:15:12 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Documents and Settings\family\Application Data\Mozilla\Firefox\Profiles\h0sglesq.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
    [2010-12-24 15:46:45 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Documents and Settings\family\Application Data\Mozilla\Firefox\Profiles\h0sglesq.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
    [2010-11-17 22:05:58 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Documents and Settings\family\Application Data\Mozilla\Firefox\Profiles\h0sglesq.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
    [2010-11-09 04:15:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\Mozilla\Firefox\Profiles\h0sglesq.default\extensions\anycolor.pavlos256@gmail.com
    [2010-12-24 15:46:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\Mozilla\Firefox\Profiles\h0sglesq.default\extensions\engine@conduit.com
    [2010-12-28 03:41:24 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
    [2010-11-29 17:25:39 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
    [2009-11-19 17:16:28 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
    [2010-11-29 17:25:11 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
    [2009-11-19 17:16:29 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll

    O1 HOSTS File: ([2010-12-28 15:06:07 | 000,000,027 | ---- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Black III\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
    O2 - BHO: (ZoneAlarm Toolbar) - {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - C:\Program Files\ZoneAlarm\tbZone.dll (Conduit Ltd.)
    O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
    O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
    O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
    O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
    O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll (Google Inc.)
    O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
    O2 - BHO: (MSN Toolbar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN Toolbar\Platform\4.0.0401.0\npwinext.dll (Microsoft Corporation)
    O2 - BHO: (SMTTB2009 Class) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\HyperCam Toolbar\tbcore3.dll ()
    O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
    O3 - HKLM\..\Toolbar: (ZoneAlarm Toolbar) - {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - C:\Program Files\ZoneAlarm\tbZone.dll (Conduit Ltd.)
    O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
    O3 - HKLM\..\Toolbar: (MSN Toolbar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\MSN Toolbar\Platform\4.0.0401.0\npwinext.dll (Microsoft Corporation)
    O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
    O3 - HKCU\..\Toolbar\ShellBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
    O3 - HKCU\..\Toolbar\WebBrowser: (Verizon Broadband Toolbar) - {4E7BD74F-2B8D-469E-8CB0-AB60BB9AAE22} - C:\PROGRA~1\VOL_TO~1\VOL_TO~1.DLL File not found
    O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Toolbar) - {66F2E20D-0DA8-4C11-A9C8-DD8477B88ACD} - C:\Program Files\ZoneAlarm\tbZone.dll (Conduit Ltd.)
    O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
    O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
    O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
    O4 - HKLM..\Run: [ISW] C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
    O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
    O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O8 - Extra context menu item: &Download by Orbit - C:\Black III\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
    O8 - Extra context menu item: &Grab video by Orbit - C:\Black III\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
    O8 - Extra context menu item: Do&wnload selected by Orbit - C:\Black III\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
    O8 - Extra context menu item: Down&load all by Orbit - C:\Black III\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
    O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
    O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\WINDOWS\SYSTEM32\nwprovau.dll (Microsoft Corporation)
    O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} https://activatemyfios.verizon.net/sdcCommon/download/FIOS/Verizon FiOS Installer.cab (Support.com Configuration Class)
    O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/FacebookPhotoUploader5.cab (Facebook Photo Uploader 5)
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/downl...-4505-8fb8-d0d2d160e512/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool)
    O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
    O16 - DPF: {3D3DBC64-0D21-4EA4-94EE-86D6D9B31C0C} http://www.worldwinner.com/games/v45/moneylist/moneylist.cab (MoneyList Control)
    O16 - DPF: {42FDC231-A411-45F8-B8B6-3B5026111DA8} http://www.worldwinner.com/games/v47/solitairerush/solitairerush.cab (SolitaireRush Control)
    O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.1.cab (DLM Control)
    O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control)
    O16 - DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} http://www.worldwinner.com/games/v63/bjattack/bja.cab (BJA Control)
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (DivXBrowserPlugin Object)
    O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} http://verizon.exent.com/vzfamily/classes/ExentCtl.ocx (ExentInf Class)
    O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} http://www.nick.com/common/groove/gx/GrooveAX27.cab (Reg Error: Key error.)
    O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} http://www.worldwinner.com/games/shared/wwlaunch.cab (Wwlaunch Control)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
    O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
    O16 - DPF: {97438FE9-D361-4279-BA82-98CC0877A717} http://www.worldwinner.com/games/v57/cubis/cubis.cab (Cubis Control)
    O16 - DPF: {A021A215-6CDC-44B4-8C16-90491CED9605} http://www.worldwinner.com/games/v59/clue/clue.cab (Clue Control)
    O16 - DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} http://www.worldwinner.com/games/v57/wof/wof.cab (WoF Control)
    O16 - DPF: {AC2881FD-5760-46DB-83AE-20A5C6432A7E} http://www.worldwinner.com/games/v67/swapit/swapit.cab (SwapIt Control)
    O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab (IWinAmpActiveX Class)
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab (MSN Games - Installer)
    O16 - DPF: {BA94245D-2AA0-4953-9D9F-B0EE4CC02C43} http://www.worldwinner.com/games/v42/tilecity/tilecity.cab (Tilecity Control)
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class)
    O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
    O16 - DPF: {CF969D51-F764-4FBF-9E90-475248601C8A} http://www.worldwinner.com/games/v47/familyfeud/familyfeud.cab (FamilyFeud Control)
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
    O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
    O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
    O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
    O20 - Winlogon\Notify\winabi32: DllName - winabi32.dll - C:\WINDOWS\System32\winabi32.dll ()
    O24 - Desktop WallPaper: C:\Documents and Settings\family\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
    O24 - Desktop BackupWallPaper: C:\Documents and Settings\family\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2004-08-11 18:15:00 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
    O34 - HKLM BootExecute: (autocheck autochk *) - File not found
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37 - HKLM\...com [@ = ComFile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*

    NetSvcs: 6to4 - File not found
    NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
    NetSvcs: Ias - File not found
    NetSvcs: Iprip - File not found
    NetSvcs: Irmon - File not found
    NetSvcs: Nwsapagent - File not found
    NetSvcs: WmdmPmSp - File not found
    NetSvcs: winmgmt - C:\WINDOWS\SYSTEM32\WBEM\WINMGMT.EXE (Microsoft Corporation)

    Drivers32: msacm.ac3acm - C:\WINDOWS\System32\ac3acm.acm (fccHandler)
    Drivers32: msacm.ac3filter - C:\WINDOWS\System32\ac3filter.acm ()
    Drivers32: msacm.iac2 - C:\WINDOWS\SYSTEM32\iac25_32.ax (Intel Corporation)
    Drivers32: msacm.l3acm - C:\WINDOWS\SYSTEM32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
    Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (http://www.mp3dev.org/)
    Drivers32: msacm.lhacm - C:\WINDOWS\System32\lhacm.acm (Microsoft Corporation)
    Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
    Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
    Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
    Drivers32: vidc.avrn - C:\WINDOWS\System32\AvidAVICodec.dll (Avid Technology, Inc)
    Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
    Drivers32: VIDC.FFDS - C:\WINDOWS\System32\ff_vfw.dll ()
    Drivers32: VIDC.HFYU - C:\WINDOWS\System32\huffyuv.dll (Disappearing Inc.)
    Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
    Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
    Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
    Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
    Drivers32: vidc.tscc - C:\WINDOWS\System32\tsccvid.dll (TechSmith Corporation)
    Drivers32: VIDC.VP70 - C:\WINDOWS\System32\vp7vfw.dll (On2.com)
    Drivers32: VIDC.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
    Drivers32: VIDC.YV12 - C:\WINDOWS\System32\yv12vfw.dll (www.helixcommunity.org)
    Drivers32: wave - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)
    Drivers32: wave2 - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)
    Drivers32: wave3 - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)
    Drivers32: wave4 - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)
     
  2. 2010/12/28
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    CREATERESTOREPOINT
    Restore point Set: OTL Restore Point (66160230278365184)

    ========== Files/Folders - Created Within 30 Days ==========

    [2010-12-28 16:04:59 | 000,602,624 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\family\Desktop\OTL.exe
    [2010-12-28 03:46:38 | 000,000,000 | ---D | C] -- C:\9c1c213a8b65e850fa7c8b95a8
    [2010-12-28 01:31:23 | 000,000,000 | ---D | C] -- C:\Adobe
    [2010-12-28 01:31:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Sun
    [2010-12-27 22:31:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
    [2010-12-27 22:06:39 | 000,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia330.dll
    [2010-12-27 22:06:39 | 000,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia001.dll
    [2010-12-27 22:06:39 | 000,026,624 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rw330ext.dll
    [2010-12-27 22:06:23 | 000,281,088 | ---- | C] (Cinematronics) -- C:\WINDOWS\System32\dllcache\pinball.exe
    [2010-12-27 22:04:12 | 000,054,528 | ---- | C] (Philips Semiconductors GmbH) -- C:\WINDOWS\System32\dllcache\cap7146.sys
    [2010-12-27 18:50:22 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
    [2010-12-27 18:50:22 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
    [2010-12-27 18:50:22 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
    [2010-12-27 18:48:42 | 000,000,000 | ---D | C] -- C:\Qoobox
    [2010-12-27 16:04:49 | 000,000,000 | ---D | C] -- C:\WINDOWS\msapps
    [2010-12-27 16:04:49 | 000,000,000 | ---D | C] -- C:\WINDOWS\dell
    [2010-12-11 22:57:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\family\Application Data\Avira
    [2010-12-11 22:46:24 | 000,135,096 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys
    [2010-12-11 22:46:23 | 000,061,960 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys
    [2010-12-11 22:46:23 | 000,045,416 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntdd.sys
    [2010-12-11 22:46:23 | 000,022,360 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntmgr.sys
    [2010-12-11 22:46:19 | 000,000,000 | ---D | C] -- C:\Program Files\Avira
    [2010-12-11 22:46:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Avira
    [2010-12-09 00:59:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\family\Application Data\Toolbar4
    [2010-12-09 00:59:21 | 000,000,000 | ---D | C] -- C:\Program Files\HyperCam Toolbar
    [2010-12-05 00:48:05 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Software Update Utility
    [2010-11-29 17:28:30 | 000,000,000 | ---D | C] -- C:\Program Files\MSN Toolbar
    [2010-11-29 17:27:01 | 000,000,000 | ---D | C] -- C:\Program Files\MSN Toolbar Installer
    [2010-11-29 17:26:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sun
    [2006-08-24 22:51:30 | 000,032,768 | ---- | C] ( ) -- C:\WINDOWS\System32\ShellLnkSSE.dll
    [2004-08-25 15:22:08 | 000,151,552 | ---- | C] ( ) -- C:\WINDOWS\System32\ATIDEMGR.dll
    [6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
    [2 C:\Documents and Settings\family\My Documents\*.tmp files -> C:\Documents and Settings\family\My Documents\*.tmp -> ]

    ========== Files - Modified Within 30 Days ==========

    [2010-12-28 16:05:00 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\family\Desktop\OTL.exe
    [2010-12-28 15:51:24 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\WPA.DBL
    [2010-12-28 15:51:23 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
    [2010-12-28 15:49:51 | 000,002,048 | --S- | M] () -- C:\WINDOWS\BOOTSTAT.DAT
    [2010-12-28 15:49:48 | 1608,667,136 | -HS- | M] () -- C:\hiberfil.sys
    [2010-12-28 15:28:14 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
    [2010-12-28 15:06:07 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\ETC\hosts
    [2010-12-28 14:42:02 | 003,998,686 | R--- | M] () -- C:\Documents and Settings\family\Desktop\ComboFix.exe
    [2010-12-28 14:39:40 | 000,000,654 | ---- | M] () -- C:\Documents and Settings\family\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk
    [2010-12-28 14:39:39 | 000,000,636 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Opera.lnk
    [2010-12-28 14:34:00 | 000,000,982 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2271019165-553755714-499774489-1005UA.job
    [2010-12-28 12:46:01 | 000,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
    [2010-12-28 12:46:01 | 000,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
    [2010-12-28 04:41:53 | 000,000,782 | ---- | M] () -- C:\Documents and Settings\family\Desktop\Windows Media Player.lnk
    [2010-12-28 04:37:48 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
    [2010-12-28 04:32:56 | 000,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx
    [2010-12-28 01:31:04 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
    [2010-12-28 01:20:11 | 1608,593,408 | ---- | M] () -- C:\WINDOWS\MEMORY.DMP
    [2010-12-27 23:13:57 | 002,641,632 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
    [2010-12-27 22:48:41 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
    [2010-12-27 22:14:01 | 000,000,288 | ---- | M] () -- C:\WINDOWS\System32\$winnt$.inf
    [2010-12-27 22:02:00 | 000,004,161 | ---- | M] () -- C:\WINDOWS\ODBCINST.INI
    [2010-12-27 21:39:50 | 000,000,282 | -HS- | M] () -- C:\boot.ini
    [2010-12-27 21:23:21 | 000,004,128 | ---- | M] () -- C:\INFCACHE.1
    [2010-12-27 21:22:28 | 000,442,894 | ---- | M] () -- C:\WINDOWS\System32\PERFH009.DAT
    [2010-12-27 21:22:28 | 000,072,160 | ---- | M] () -- C:\WINDOWS\System32\PERFC009.DAT
    [2010-12-27 18:22:15 | 000,107,520 | ---- | M] () -- C:\WINDOWS\System32\winabi32.dll
    [2010-12-27 18:02:10 | 000,138,752 | ---- | M] () -- C:\Documents and Settings\family\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2010-12-27 14:14:31 | 000,055,160 | ---- | M] () -- C:\WINDOWS\System32\ativvaxx.cap
    [2010-12-26 19:34:30 | 000,021,090 | ---- | M] () -- C:\Documents and Settings\family\My Documents\Renee's College Supplement Essays.docx
    [2010-12-26 06:34:00 | 000,000,930 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2271019165-553755714-499774489-1005Core.job
    [2010-12-25 12:19:32 | 000,135,096 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys
    [2010-12-24 14:55:07 | 000,032,076 | ---- | M] () -- C:\Documents and Settings\family\My Documents\Renee Black USC Essays.docx
    [2010-12-24 14:55:03 | 000,013,498 | ---- | M] () -- C:\Documents and Settings\family\My Documents\Renee's College Essay.docx
    [2010-12-23 02:39:03 | 000,029,031 | ---- | M] () -- C:\Documents and Settings\family\Desktop\NAZI-CHRISTMAS-PARTY.jpg
    [2010-12-20 18:09:00 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
    [2010-12-20 18:08:40 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
    [2010-12-20 07:11:47 | 000,013,647 | ---- | M] () -- C:\Documents and Settings\family\My Documents\Marketting Plan .docx
    [2010-12-20 05:52:41 | 000,012,628 | ---- | M] () -- C:\Documents and Settings\family\My Documents\Marketin assingment 1.docx
    [2010-12-19 22:14:36 | 000,013,226 | ---- | M] () -- C:\Documents and Settings\family\My Documents\college supple ment essays.docx
    [2010-12-19 11:33:23 | 000,061,960 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys
    [2010-12-14 13:38:00 | 000,596,801 | ---- | M] () -- C:\WINDOWS\setupapi.old
    [2010-12-11 22:46:57 | 000,001,707 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Avira AntiVir Control Center.lnk
    [2010-12-11 22:27:01 | 000,002,577 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
    [2010-12-11 16:43:43 | 004,890,505 | ---- | M] () -- C:\Documents and Settings\family\Desktop\madx.gif
    [2010-12-09 23:29:45 | 000,002,137 | ---- | M] () -- C:\Documents and Settings\family\Desktop\iTunes.lnk
    [2010-12-09 06:59:56 | 000,025,056 | ---- | M] () -- C:\Documents and Settings\family\Desktop\Rex Ryan Buries Game Ball From Monday Night Loss_1291895983888.jpg
    [2010-12-05 00:49:21 | 000,002,657 | -H-- | M] () -- C:\IPH.PH
    [2010-12-05 00:48:33 | 000,001,605 | ---- | M] () -- C:\Documents and Settings\family\Application Data\Microsoft\Internet Explorer\Quick Launch\AIM.lnk
    [2010-12-05 00:48:33 | 000,001,587 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AIM.lnk
    [2010-12-02 03:02:01 | 000,002,099 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Jaksta Streaming Media Recorder and Converter.lnk
    [2010-12-01 22:07:58 | 000,726,016 | ---- | M] () -- C:\Documents and Settings\family\My Documents\AXA Scholarship Form.doc
    [6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
    [2 C:\Documents and Settings\family\My Documents\*.tmp files -> C:\Documents and Settings\family\My Documents\*.tmp -> ]

    ========== Files Created - No Company Name ==========

    [2010-12-28 14:41:57 | 003,998,686 | R--- | C] () -- C:\Documents and Settings\family\Desktop\ComboFix.exe
    [2010-12-27 22:05:30 | 001,158,818 | ---- | C] () -- C:\WINDOWS\System32\dllcache\korwbrkr.lex
    [2010-12-27 22:05:17 | 000,059,392 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imscinst.exe
    [2010-12-27 22:05:13 | 000,134,339 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imekr.lex
    [2010-12-27 22:04:59 | 013,463,552 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hwxjpn.dll
    [2010-12-27 22:04:51 | 000,108,827 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hanja.lex
    [2010-12-27 22:04:43 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\dllcache\fpencode.dll
    [2010-12-27 22:04:16 | 000,173,568 | ---- | C] () -- C:\WINDOWS\System32\dllcache\chtskf.dll
    [2010-12-27 21:21:53 | 000,141,702 | ---- | C] () -- C:\WINDOWS\System32\dllcache\netfx.cat
    [2010-12-27 21:21:53 | 000,110,116 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tabletpc.cat
    [2010-12-27 21:21:53 | 000,037,484 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MW770.CAT
    [2010-12-27 21:21:53 | 000,031,965 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mediactr.cat
    [2010-12-27 21:21:53 | 000,024,209 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msn7.cat
    [2010-12-27 21:21:53 | 000,013,753 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IMS.CAT
    [2010-12-27 21:21:53 | 000,013,472 | ---- | C] () -- C:\WINDOWS\System32\dllcache\HPCRDP.CAT
    [2010-12-27 21:21:53 | 000,011,651 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msn9.cat
    [2010-12-27 21:21:53 | 000,009,581 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MSMSGS.CAT
    [2010-12-27 21:21:53 | 000,008,574 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IASNT4.CAT
    [2010-12-27 21:21:53 | 000,007,710 | ---- | C] () -- C:\WINDOWS\System32\dllcache\OEMBIOS.CAT
    [2010-12-27 21:21:53 | 000,007,334 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmerrenu.cat
    [2010-12-27 21:21:53 | 000,007,245 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MSTSWEB.CAT
    [2010-12-27 21:21:52 | 002,012,670 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5.CAT
    [2010-12-27 21:21:52 | 001,042,903 | ---- | C] () -- C:\WINDOWS\System32\dllcache\SP2.CAT
    [2010-12-27 21:21:52 | 000,797,189 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5IIS.CAT
    [2010-12-27 21:21:52 | 000,502,724 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5INF.CAT
    [2010-12-27 21:21:52 | 000,399,645 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MAPIMIG.CAT
    [2010-12-27 21:21:52 | 000,031,281 | ---- | C] () -- C:\WINDOWS\System32\dllcache\FP4.CAT
    [2010-12-27 18:50:23 | 000,089,088 | ---- | C] () -- C:\WINDOWS\MBR.exe
    [2010-12-27 18:50:22 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
    [2010-12-27 18:50:22 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
    [2010-12-27 18:50:22 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
    [2010-12-27 18:50:22 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
    [2010-12-27 18:22:15 | 000,107,520 | ---- | C] () -- C:\WINDOWS\System32\winabi32.dll
    [2010-12-23 02:39:01 | 000,029,031 | ---- | C] () -- C:\Documents and Settings\family\Desktop\NAZI-CHRISTMAS-PARTY.jpg
    [2010-12-22 00:03:11 | 000,021,090 | ---- | C] () -- C:\Documents and Settings\family\My Documents\Renee's College Supplement Essays.docx
    [2010-12-20 07:11:47 | 000,013,647 | ---- | C] () -- C:\Documents and Settings\family\My Documents\Marketting Plan .docx
    [2010-12-20 05:52:40 | 000,012,628 | ---- | C] () -- C:\Documents and Settings\family\My Documents\Marketin assingment 1.docx
    [2010-12-11 22:46:57 | 000,001,707 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Avira AntiVir Control Center.lnk
    [2010-12-11 16:43:38 | 004,890,505 | ---- | C] () -- C:\Documents and Settings\family\Desktop\madx.gif
    [2010-12-09 06:59:55 | 000,025,056 | ---- | C] () -- C:\Documents and Settings\family\Desktop\Rex Ryan Buries Game Ball From Monday Night Loss_1291895983888.jpg
    [2010-11-30 22:16:16 | 000,032,076 | ---- | C] () -- C:\Documents and Settings\family\My Documents\Renee Black USC Essays.docx
    [2010-11-18 22:22:19 | 000,000,126 | ---- | C] () -- C:\WINDOWS\replay_telecorder_skype.INI
    [2010-08-21 05:18:47 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini
    [2010-08-21 05:18:40 | 000,790,528 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
    [2010-08-21 05:18:40 | 000,134,144 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
    [2010-08-21 05:18:39 | 000,108,032 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
    [2010-08-04 15:07:13 | 000,165,376 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
    [2010-04-12 20:54:15 | 000,002,418 | -HS- | C] () -- C:\Documents and Settings\family\Local Settings\Application Data\aB6G3tn
    [2010-04-12 20:54:15 | 000,002,418 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\aB6G3tn
    [2010-04-05 00:06:06 | 000,006,856 | -HS- | C] () -- C:\Documents and Settings\family\Local Settings\Application Data\VHx0W
    [2010-04-05 00:06:06 | 000,006,856 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\VHx0W
    [2009-12-24 22:28:22 | 000,001,182 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\jaksta.smr.lic
    [2009-11-28 23:57:44 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\rmc_rtspdl.dll
    [2009-10-08 00:32:04 | 000,000,130 | ---- | C] () -- C:\WINDOWS\cfplogvw.INI
    [2009-07-02 19:49:48 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\leverage.drm.log
    [2009-06-26 16:40:04 | 000,131,072 | ---- | C] () -- C:\WINDOWS\System32\imgproc.dll
    [2009-06-13 22:36:29 | 000,941,784 | ---- | C] () -- C:\WINDOWS\System32\drivers\CAMTHWDM.sys
    [2008-10-20 16:18:58 | 000,000,067 | ---- | C] () -- C:\WINDOWS\Apollo Audio DVD Creator.INI
    [2008-04-12 13:34:58 | 000,000,067 | ---- | C] () -- C:\WINDOWS\Easy Video to DVD.INI
    [2007-11-16 15:01:42 | 000,139,152 | ---- | C] () -- C:\Documents and Settings\family\Application Data\PnkBstrK.sys
    [2007-10-19 11:58:29 | 000,000,319 | ---- | C] () -- C:\WINDOWS\game.ini
    [2007-10-05 23:56:43 | 002,255,360 | ---- | C] () -- C:\WINDOWS\System32\libavcodec.dll
    [2007-10-05 23:56:43 | 000,395,776 | ---- | C] () -- C:\WINDOWS\System32\libmplayer.dll
    [2007-10-05 23:56:43 | 000,262,144 | ---- | C] () -- C:\WINDOWS\System32\TomsMoComp_ff.dll
    [2007-10-05 23:56:43 | 000,112,640 | ---- | C] () -- C:\WINDOWS\System32\libmpeg2_ff.dll
    [2007-06-18 14:29:14 | 000,027,648 | ---- | C] () -- C:\WINDOWS\System32\AVSredirect.dll
    [2007-06-18 14:29:13 | 000,471,552 | ---- | C] () -- C:\WINDOWS\System32\Smab.dll
    [2007-03-15 23:28:12 | 000,137,888 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
    [2007-01-21 18:57:40 | 000,000,092 | ---- | C] () -- C:\WINDOWS\WB.ini
    [2007-01-21 18:36:47 | 000,005,267 | ---- | C] () -- C:\WINDOWS\langorig.ini
    [2007-01-21 18:35:52 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\wbload.dll
    [2006-11-25 18:10:19 | 000,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll
    [2006-09-14 10:07:19 | 000,132,096 | ---- | C] () -- C:\WINDOWS\System32\gc.dll
    [2006-08-24 22:51:30 | 000,044,544 | ---- | C] () -- C:\WINDOWS\System32\Gif89.dll
    [2006-06-27 15:07:53 | 000,002,149 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
    [2006-06-21 15:34:44 | 000,000,067 | ---- | C] () -- C:\WINDOWS\IDMan.INI
    [2006-05-04 18:47:45 | 000,000,049 | ---- | C] () -- C:\WINDOWS\winzipme.ini
    [2006-04-10 07:12:34 | 000,000,305 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\addr_file.html
    [2006-03-13 17:30:35 | 000,000,096 | ---- | C] () -- C:\WINDOWS\SysUtil.ini
    [2006-02-11 20:41:47 | 000,034,308 | ---- | C] () -- C:\WINDOWS\System32\BASSMOD.dll
    [2006-02-11 11:16:13 | 000,000,021 | ---- | C] () -- C:\WINDOWS\atid.ini
    [2006-01-22 19:24:21 | 000,000,026 | ---- | C] () -- C:\WINDOWS\dvdSanta.INI
    [2006-01-21 22:32:38 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\cygz.dll
    [2006-01-16 19:30:54 | 000,000,192 | ---- | C] () -- C:\WINDOWS\winamp.ini
    [2005-12-31 13:40:12 | 000,000,299 | ---- | C] () -- C:\WINDOWS\etrup.dll
    [2005-12-07 19:58:42 | 000,000,129 | ---- | C] () -- C:\Documents and Settings\family\Local Settings\Application Data\fusioncache.dat
    [2005-11-19 15:23:29 | 000,000,125 | ---- | C] () -- C:\WINDOWS\mix-fx.ini
    [2005-11-04 14:34:42 | 000,000,518 | ---- | C] () -- C:\Program Files\Shortcut to Internet Explorer.lnk
    [2005-11-04 14:10:28 | 000,004,272 | R--- | C] () -- C:\WINDOWS\System32\drivers\bvrp_pci.sys
    [2005-09-18 11:03:38 | 000,860,211 | --S- | C] () -- C:\WINDOWS\System32\XSIFtk-3.6.2.1.dll
    [2005-08-27 09:30:08 | 000,001,848 | ---- | C] () -- C:\WINDOWS\VIEWER.INI
    [2005-08-27 09:30:08 | 000,000,830 | ---- | C] () -- C:\WINDOWS\BTW.INI
    [2005-08-09 17:13:31 | 000,831,488 | ---- | C] () -- C:\WINDOWS\System32\libeay32.dll
    [2005-08-09 17:13:31 | 000,159,744 | ---- | C] () -- C:\WINDOWS\System32\ssleay32.dll
    [2005-07-10 19:29:31 | 000,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
    [2005-07-02 18:27:07 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
    [2005-05-07 18:59:34 | 000,000,138 | ---- | C] () -- C:\WINDOWS\iPlayer.INI
    [2005-01-22 15:48:50 | 000,000,867 | ---- | C] () -- C:\WINDOWS\hegames.ini
    [2005-01-02 18:08:26 | 000,025,193 | ---- | C] () -- C:\WINDOWS\cdPlayer.ini
    [2004-12-31 18:40:48 | 000,000,026 | ---- | C] () -- C:\WINDOWS\wb04d2se.INI
    [2004-12-20 14:13:07 | 000,000,620 | ---- | C] () -- C:\WINDOWS\ODBC.INI
    [2004-12-01 07:45:26 | 000,000,954 | ---- | C] () -- C:\WINDOWS\dellstat.ini
    [2004-12-01 07:28:03 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\dlbuvs.dll
    [2004-12-01 07:28:01 | 000,114,688 | ---- | C] () -- C:\WINDOWS\System32\dlbucur.dll
    [2004-12-01 07:28:01 | 000,069,632 | ---- | C] () -- C:\WINDOWS\System32\dlbucu.dll
    [2004-12-01 07:27:58 | 000,557,056 | ---- | C] () -- C:\WINDOWS\System32\dlbujswr.dll
    [2004-12-01 07:27:53 | 000,401,408 | ---- | C] () -- C:\WINDOWS\System32\dlbuutil.dll
    [2004-11-30 18:24:06 | 000,143,360 | R--- | C] () -- C:\WINDOWS\System32\dlbucoin.dll
    [2004-11-30 18:24:06 | 000,131,072 | R--- | C] () -- C:\WINDOWS\System32\dlbusnls.dll
    [2004-11-29 21:46:17 | 000,003,218 | ---- | C] () -- C:\WINDOWS\System32\Setup2k.ini
    [2004-11-29 21:46:17 | 000,000,193 | ---- | C] () -- C:\WINDOWS\System32\presetup.ini
    [2004-11-26 04:45:35 | 000,138,752 | ---- | C] () -- C:\Documents and Settings\family\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2004-11-25 16:49:17 | 000,000,000 | ---- | C] () -- C:\WINDOWS\MADCCS.INI
    [2004-11-25 16:49:16 | 000,000,000 | ---- | C] () -- C:\WINDOWS\MADCCF.INI
    [2004-11-23 23:11:44 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Textart.INI
    [2004-11-23 18:27:33 | 000,061,678 | ---- | C] () -- C:\Documents and Settings\family\Application Data\PFP120JPR.{PB
    [2004-11-23 18:27:33 | 000,012,358 | ---- | C] () -- C:\Documents and Settings\family\Application Data\PFP120JCM.{PB
    [2004-11-23 17:49:40 | 000,000,643 | ---- | C] () -- C:\WINDOWS\lexstat.ini
    [2004-11-17 23:40:58 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
    [2004-11-17 23:39:18 | 000,000,297 | ---- | C] () -- C:\WINDOWS\wininit.ini
    [2004-08-25 14:27:00 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\ati2evxx.dll
    [2004-08-12 08:27:58 | 000,027,440 | ---- | C] () -- C:\WINDOWS\System32\drivers\secdrv.sys
    [2004-08-12 08:19:54 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\ieencode.dll
    [2004-08-11 18:25:56 | 000,000,884 | ---- | C] () -- C:\WINDOWS\ORUN32.INI
    [2004-08-11 18:14:38 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
    [2002-03-26 14:18:28 | 000,091,136 | ---- | C] () -- C:\WINDOWS\System32\mp4fil32.dll
    [2002-01-20 07:26:36 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\SimpleResize.dll
    [2001-08-29 18:57:40 | 000,155,648 | ---- | C] () -- C:\WINDOWS\System32\addurl41.DLL
    [2001-07-10 13:43:16 | 000,018,432 | ---- | C] () -- C:\WINDOWS\System32\winwatch.DLL
    [1996-11-21 00:00:00 | 000,022,016 | ---- | C] () -- C:\WINDOWS\System32\ODBCSTF.DLL
    [1996-11-21 00:00:00 | 000,022,016 | ---- | C] () -- C:\WINDOWS\System32\DOCOBJ.DLL
    [1980-01-01 01:00:00 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\e100bmsg.dll

    ========== LOP Check ==========

    [2009-07-02 19:52:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AA3DeployClient
    [2008-11-15 22:55:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\acccore
    [2009-05-31 16:28:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AIM
    [2010-05-29 13:01:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
    [2009-07-01 03:22:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\America's Army Deploy Client
    [2008-12-10 22:07:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ashampoo
    [2007-06-01 18:23:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Azureus
    [2010-07-11 16:23:06 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonBJ
    [2010-08-20 20:33:26 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonIJFax
    [2008-11-19 20:35:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DriverScanner
    [2008-07-24 10:08:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\eBay
    [2007-09-14 23:15:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Escape From Paradise
    [2009-04-06 02:21:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ESET
    [2008-11-06 01:12:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\GeoVid
    [2008-03-23 16:12:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\HipSoft
    [2010-07-16 01:49:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Innovative Solutions
    [2008-03-23 16:10:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\iWin Games
    [2004-11-25 03:51:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Kazaa
    [2008-03-30 21:06:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ludia
    [2008-12-15 01:54:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MailFrontier
    [2008-11-15 19:37:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
    [2008-07-28 12:10:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NexonUS
    [2008-06-03 13:41:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\OBJOWNSTEAMWMA
    [2008-03-23 15:34:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PlayFirst
    [2006-11-19 16:06:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\RoboForm
    [2010-04-12 22:36:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Rosetta Stone
    [2008-07-22 12:00:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Soulseek
    [2010-08-21 06:33:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TechSmith
    [2008-12-25 14:14:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
    [2010-08-07 18:41:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Tencent
    [2006-02-11 20:40:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TuneUp Software
    [2007-05-04 20:41:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ulead Systems
    [2008-07-14 17:20:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
    [2010-08-06 06:26:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\VistaCodecs
    [2008-05-23 00:21:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
    [2010-03-20 06:46:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
    [2009-07-10 14:30:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
    [2006-08-01 14:07:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\acccore
    [2005-02-21 22:59:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\Aim
    [2010-01-03 09:20:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\AnvSoft
    [2009-12-09 06:02:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\Any Video Converter
    [2008-12-10 22:07:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\Ashampoo
    [2006-11-25 18:09:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\Atari
    [2009-08-23 23:24:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\avidemux
    [2008-07-22 12:54:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\Azureus
    [2007-06-01 00:08:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\BitTorrent
    [2009-12-25 06:07:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\Camfrog
    [2010-05-27 23:43:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\CheckPoint
    [2007-09-17 22:35:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\CoreFTP
    [2008-07-14 17:33:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\COWON
    [2008-12-10 01:39:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\DAEMON Tools
    [2006-06-21 21:14:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\DMCache
    [2004-11-27 12:00:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\Earthlink
    [2008-12-07 21:04:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\eBookPro6
    [2009-04-06 02:22:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\ESET
    [2007-01-27 11:20:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\ExitBlah
    [2010-03-09 07:20:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\Foxit
    [2010-03-30 16:23:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\Foxit Software
    [2009-12-31 07:02:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\FreeFLVConverter
    [2008-04-23 21:53:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\FrostWire
    [2008-06-20 12:29:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\GARMIN
    [2007-06-18 16:34:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\GeoVid
    [2007-12-11 10:37:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\GetRightToGo
    [2010-03-01 02:02:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\GrabPro
    [2007-05-10 15:44:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\Greyfirst
    [2010-04-23 05:55:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\gtk-2.0
    [2007-07-20 15:19:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\gtopala
    [2006-04-22 09:44:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\Internet Download Accelerator
    [2007-09-08 22:45:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\iWin
    [2008-03-23 16:11:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\iWinArcade
    [2010-10-12 14:41:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\Jaksta
    [2008-12-18 15:37:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\kantaris
    [2004-11-25 03:47:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\Kazaa Lite
    [2004-11-25 21:37:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\Leadertech
    [2010-08-02 19:29:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\ManyCam
    [2008-07-17 10:40:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\MP3Rocket
    [2009-01-10 15:03:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\MSNInstaller
    [2008-06-15 00:53:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\MxBoost
    [2009-09-23 23:20:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\NavNet Solutions
    [2006-07-29 01:44:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\NCH Swift Sound
    [2006-03-18 19:06:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\NetMedia Providers
    [2006-07-29 01:46:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\Netscape
    [2007-09-10 13:10:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\Nvu
    [2009-12-28 03:24:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\ooVoo Details
    [2010-06-10 17:59:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\oovooinstaller
    [2009-06-08 18:21:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\Opera
    [2010-12-17 20:28:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\Orbit
    [2008-03-23 15:34:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\PlayFirst
    [2006-03-18 19:06:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\Publish Providers
    [2007-10-17 17:30:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\QQ Games
    [2008-05-29 17:38:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\QQ Games Plugin
    [2006-07-28 19:49:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\RecordPad
    [2007-03-14 20:11:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\SecondLife
    [2008-04-22 14:27:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\Shareaza
    [2010-01-24 14:06:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\Softland
    [2008-03-17 00:31:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\Sony
    [2009-11-18 02:45:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\Styler
    [2008-10-29 13:36:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\SystemRequirementsLab
    [2008-11-15 22:57:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\Tencent
    [2007-09-29 15:09:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\Thunderbird
    [2010-12-09 00:59:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\Toolbar4
    [2009-09-15 16:23:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\Trillian
    [2006-02-11 20:41:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\TuneUp Software
    [2010-01-24 13:57:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\UDC Profiles
    [2005-12-28 19:50:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\Ulead Systems
    [2008-11-19 20:35:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\Uniblue
    [2007-08-25 19:52:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\UseNeXT
    [2008-03-17 00:47:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\Viewpoint
    [2008-03-17 14:09:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\vol_toolbar
    [2005-07-09 11:18:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\WeatherBug
    [2009-06-13 22:39:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\Webcammax
    [2006-08-22 11:35:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\WNR
    [2009-06-07 16:02:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\Xilisoft Corporation

    ========== Purity Check ==========



    ========== Custom Scans ==========


    < %SYSTEMDRIVE%\*.* >
    [2004-08-11 18:15:00 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
    [2009-04-14 20:27:29 | 000,000,281 | -HS- | M] () -- C:\Boot.bak
    [2010-12-27 21:39:50 | 000,000,282 | -HS- | M] () -- C:\boot.ini
    [2004-08-03 22:00:00 | 000,260,272 | ---- | M] () -- C:\cmldr
    [2010-12-28 15:09:42 | 000,019,593 | ---- | M] () -- C:\ComboFix.txt
    [2009-09-24 23:32:20 | 000,000,000 | ---- | M] () -- C:\config.ini
    [2004-08-11 18:15:00 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
    [2005-03-08 05:58:02 | 000,007,576 | ---- | M] () -- C:\dbc.nfo
    [2004-11-17 23:11:02 | 000,004,710 | RH-- | M] () -- C:\DELL.SDR
    [2004-12-01 07:29:27 | 000,000,502 | ---- | M] () -- C:\dlbu.log
    [2005-02-19 17:45:24 | 000,004,717 | -HS- | M] () -- C:\ffastun.ffa
    [2005-02-19 17:45:24 | 000,286,720 | -HS- | M] () -- C:\ffastun.ffl
    [2005-02-19 17:45:24 | 000,135,168 | -H-- | M] () -- C:\ffastun.ffo
    [2005-02-19 17:45:24 | 001,482,752 | -HS- | M] () -- C:\ffastun0.ffx
    [2005-02-19 23:06:00 | 000,286,720 | ---- | M] () -- C:\ffastunT.ffl
    [2005-03-08 05:54:06 | 000,000,310 | ---- | M] () -- C:\FILE_ID.DIZ
    [2010-12-28 15:49:48 | 1608,667,136 | -HS- | M] () -- C:\hiberfil.sys
    [2010-12-27 21:23:21 | 000,004,128 | ---- | M] () -- C:\INFCACHE.1
    [2008-10-18 21:45:29 | 000,000,118 | ---- | M] () -- C:\InstallHelper.log
    [2004-08-11 18:15:00 | 000,000,000 | -H-- | M] () -- C:\IO.SYS
    [2010-12-05 00:49:21 | 000,002,657 | -H-- | M] () -- C:\IPH.PH
    [2008-09-09 20:23:53 | 000,000,065 | ---- | M] () -- C:\jetscan.log
    [2010-04-05 00:49:50 | 000,000,109 | ---- | M] () -- C:\mbam-error.txt
    [2008-08-29 16:51:27 | 000,000,333 | ---- | M] () -- C:\moduleName.txt
    [2005-02-14 23:56:06 | 000,041,984 | ---- | M] () -- C:\MOUNTAINSIDE.doc
    [2004-08-11 18:15:00 | 000,000,000 | -H-- | M] () -- C:\MSDOS.SYS
    [2003-03-19 03:14:52 | 000,499,712 | ---- | M] (Microsoft Corporation) -- C:\MSVCP71.DLL
    [2008-10-17 16:46:35 | 000,001,142 | ---- | M] () -- C:\NTDClient.log
    [2004-08-04 06:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
    [2008-09-01 22:22:59 | 000,250,048 | RHS- | M] () -- C:\NTLDR
    [2010-12-28 15:49:47 | 2145,386,496 | -HS- | M] () -- C:\pagefile.sys
    [2005-04-26 06:13:30 | 000,007,646 | ---- | M] () -- C:\release.nfo
    [2006-05-01 15:43:09 | 000,000,016 | ---- | M] () -- C:\s1eo
    [2006-07-13 12:57:51 | 000,000,016 | ---- | M] () -- C:\s268
    [2006-07-20 18:55:37 | 000,000,016 | ---- | M] () -- C:\s2qk
    [2006-06-28 19:52:37 | 000,000,016 | ---- | M] () -- C:\s2u0
    [2006-06-22 14:17:40 | 000,000,016 | ---- | M] () -- C:\s3e0
    [2006-06-22 18:58:50 | 000,000,016 | ---- | M] () -- C:\s3gs
    [2006-06-27 14:51:15 | 000,000,016 | ---- | M] () -- C:\s3kg
    [2006-12-30 08:16:41 | 000,000,016 | ---- | M] () -- C:\s49k
    [2004-11-17 23:33:10 | 000,000,087 | ---- | M] () -- C:\SystemInfo.ini
    [2010-12-28 03:26:32 | 000,054,142 | ---- | M] () -- C:\TDSSKiller.2.4.12.0_28.12.2010_03.25.45_log.txt
    [2006-11-14 20:39:43 | 000,000,000 | ---- | M] () -- C:\wizard.txt

    < %systemroot%\Fonts\*.com >
    [2006-06-29 14:58:52 | 000,030,808 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
    [2006-04-18 15:39:28 | 000,029,779 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
    [2006-06-29 14:53:56 | 000,026,489 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
    [2006-04-18 15:39:28 | 000,026,040 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont

    < %systemroot%\Fonts\*.dll >

    < %systemroot%\Fonts\*.ini >
    [2010-12-27 22:02:37 | 000,000,067 | -HS- | M] () -- C:\WINDOWS\Fonts\DESKTOP.INI

    < %systemroot%\Fonts\*.ini2 >

    < %systemroot%\Fonts\*.exe >

    < %systemroot%\system32\spool\prtprocs\w32x86\*.* >
    [2009-04-25 04:00:00 | 000,027,136 | ---- | M] (CANON INC.) -- C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\CNMPD9N.DLL
    [2009-04-25 04:00:00 | 000,069,632 | ---- | M] (CANON INC.) -- C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\CNMPP9N.DLL
    [2004-07-26 16:11:56 | 000,075,264 | ---- | M] () -- C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\DLBUPP5C.DLL
    [2008-07-06 07:06:10 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\filterpipelineprintproc.dll
    [2001-04-02 18:04:10 | 000,058,880 | ---- | M] (Lexmark International) -- C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\LXATPP.DLL
    [2007-04-09 12:23:54 | 000,028,552 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\mdippr.dll
    [2008-07-06 05:50:03 | 000,597,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\printfilterpipelinesvc.exe

    < %systemroot%\REPAIR\*.bak1 >

    < %systemroot%\REPAIR\*.ini >

    < %systemroot%\system32\*.jpg >

    < %systemroot%\*.jpg >

    < %systemroot%\*.png >

    < %systemroot%\*.scr >
    [2005-08-02 19:50:07 | 000,232,784 | ---- | M] (MacSourcery) -- C:\WINDOWS\Matrix Code.scr

    < %systemroot%\*._sy >

    < %APPDATA%\Adobe\Update\*.* >

    < %ALLUSERSPROFILE%\Favorites\*.* >

    < %APPDATA%\Microsoft\*.* >
    [2005-10-28 06:14:12 | 000,007,168 | ---- | M] () -- C:\Documents and Settings\family\Application Data\Microsoft\ArtGalry.cag
    [2005-11-19 14:06:54 | 000,002,464 | ---- | M] () -- C:\Documents and Settings\family\Application Data\Microsoft\INSTALL.LOG
    [2004-07-30 08:06:30 | 000,003,183 | ---- | M] () -- C:\Documents and Settings\family\Application Data\Microsoft\readme.txt
    [2004-07-30 08:03:08 | 000,038,053 | ---- | M] () -- C:\Documents and Settings\family\Application Data\Microsoft\toolbox.chm

    < %PROGRAMFILES%\*.* >
    [2005-11-04 14:34:42 | 000,000,518 | ---- | M] () -- C:\Program Files\Shortcut to Internet Explorer.lnk

    < %APPDATA%\Update\*.* >

    < %systemroot%\*. /mp /s >

    < %systemroot%\System32\config\*.sav >
    [2010-12-27 16:16:11 | 001,048,576 | ---- | M] () -- C:\WINDOWS\SYSTEM32\CONFIG\default.sav
    [2010-12-27 19:17:59 | 000,479,232 | ---- | M] () -- C:\WINDOWS\SYSTEM32\CONFIG\security.sav
    [2010-12-27 16:16:11 | 046,661,632 | ---- | M] () -- C:\WINDOWS\SYSTEM32\CONFIG\software.sav
    [2010-12-27 16:16:11 | 013,631,488 | ---- | M] () -- C:\WINDOWS\SYSTEM32\CONFIG\system.sav

    < %PROGRAMFILES%\bak. /s >

    < %systemroot%\system32\bak. /s >

    < %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
    [2010-12-27 22:02:50 | 000,000,294 | -HS- | M] () -- C:\Documents and Settings\All Users\Start Menu\DESKTOP.INI

    < %systemroot%\system32\config\systemprofile\*.dat /x >
    [2004-11-17 23:27:07 | 000,000,310 | ---- | M] () -- C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\convert.log

    < %systemroot%\*.config >

    < %systemroot%\system32\*.db >

    < %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
    [2004-11-22 20:28:47 | 000,000,119 | -HS- | M] () -- C:\Documents and Settings\family\Application Data\Microsoft\Internet Explorer\Quick Launch\DESKTOP.INI
    [2004-08-11 18:20:42 | 000,000,079 | ---- | M] () -- C:\Documents and Settings\family\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

    < %USERPROFILE%\Desktop\*.exe >
    [2010-12-28 14:42:02 | 003,998,686 | R--- | M] () -- C:\Documents and Settings\family\Desktop\ComboFix.exe
    [2008-06-23 04:20:52 | 000,625,664 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\family\Desktop\iexplore.exe
    [2010-06-21 21:52:36 | 000,437,248 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\family\Desktop\Microsoft Paint.exe
    [2010-12-28 16:05:00 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\family\Desktop\OTL.exe
    [2009-12-09 16:32:46 | 000,692,224 | ---- | M] (binaerkombinat) -- C:\Documents and Settings\family\Desktop\SkypeLauncher.exe

    < %PROGRAMFILES%\Common Files\*.* >

    < %systemroot%\*.src >

    < %systemroot%\install\*.* >

    < %systemroot%\system32\DLL\*.* >

    < %systemroot%\system32\HelpFiles\*.* >

    < %systemroot%\system32\rundll\*.* >

    < %systemroot%\winn32\*.* >

    < %systemroot%\Java\*.* >

    < %systemroot%\system32\test\*.* >

    < %systemroot%\system32\Rundll32\*.* >

    < %systemroot%\AppPatch\Custom\*.* >

    < %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

    < %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

    < %PROGRAMFILES%\Internet Explorer\*.tmp >

    < %PROGRAMFILES%\Internet Explorer\*.dat >

    < %USERPROFILE%\My Documents\*.exe >
    [2005-06-20 20:43:06 | 000,337,672 | ---- | M] (Microsoft® Corporation) -- C:\Documents and Settings\family\My Documents\GenuineCheck.exe
    [2004-12-04 22:49:47 | 004,465,296 | ---- | M] () -- C:\Documents and Settings\family\My Documents\Install_AIM.exe
    [2 C:\Documents and Settings\family\My Documents\*.tmp files -> C:\Documents and Settings\family\My Documents\*.tmp -> ]

    < %USERPROFILE%\*.exe >
    [2007-06-27 22:12:19 | 000,389,120 | ---- | M] (Citrix Online) -- C:\Documents and Settings\family\GoToAssist_phone__268_en.exe
    [2007-01-24 11:06:35 | 000,439,296 | ---- | M] (Citrix Online) -- C:\Documents and Settings\family\GoToAssist_phone__317_en.exe
    [2006-11-14 22:20:33 | 000,439,296 | ---- | M] (Citrix Online) -- C:\Documents and Settings\family\remote.exe

    < %systemroot%\ADDINS\*.* >

    < %systemroot%\assembly\*.bak2 >

    < %systemroot%\Config\*.* >

    < %systemroot%\REPAIR\*.bak2 >

    < %systemroot%\SECURITY\Database\*.sdb /x >

    < %systemroot%\SYSTEM\*.bak2 >

    < %systemroot%\Web\*.bak2 >

    < %systemroot%\Driver Cache\*.* >

    < %PROGRAMFILES%\Mozilla Firefox\0*.exe >

    < %ProgramFiles%\Microsoft Common\*.* >

    < %ProgramFiles%\TinyProxy. >

    < %USERPROFILE%\Favorites\*.url /x >
    [2004-11-22 20:28:47 | 000,000,122 | -HS- | M] () -- C:\Documents and Settings\family\Favorites\Desktop.ini
    [2004-12-20 14:45:12 | 000,000,406 | ---- | M] () -- C:\Documents and Settings\family\Favorites\My Documents.lnk
    [2008-03-17 13:55:43 | 000,001,680 | ---- | M] () -- C:\Documents and Settings\family\Favorites\Verizon Central

    < %systemroot%\system32\*.bk >

    < %systemroot%\*.te >

    < %systemroot%\system32\system32\*.* >

    < %ALLUSERSPROFILE%\*.dat /x >
    [2008-09-15 14:16:32 | 000,000,406 | RHS- | M] () -- C:\Documents and Settings\All Users\ntuser.pol

    < %systemroot%\system32\drivers\*.rmv >

    < dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

    < dir /b "%systemroot%\*.exe" | find /i " " /c >
    Matrix Code.exe

    < %PROGRAMFILES%\Microsoft\*.* >

    < %systemroot%\System32\Wbem\proquota.exe >

    < %PROGRAMFILES%\Mozilla Firefox\*.dat >

    < %USERPROFILE%\Cookies\*.txt /x >
    [2010-12-26 06:35:25 | 000,000,067 | -HS- | M] () -- C:\Documents and Settings\family\Cookies\desktop.ini
    [2010-12-28 16:12:02 | 000,131,072 | -HS- | M] () -- C:\Documents and Settings\family\Cookies\index.dat

    < %SystemRoot%\system32\fonts\*.* >

    < %systemroot%\system32\winlog\*.* >

    < %systemroot%\system32\Language\*.* >

    < %systemroot%\system32\Settings\*.* >

    < %systemroot%\system32\*.quo >

    < %SYSTEMROOT%\AppPatch\*.exe >

    < %SYSTEMROOT%\inf\*.exe >
    [2009-01-30 17:40:22 | 000,317,440 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\INF\unregmp2.exe

    < %SYSTEMROOT%\Installer\*.exe >

    < %systemroot%\system32\config\*.bak2 >

    < %systemroot%\system32\Computers\*.* >

    < %SystemRoot%\system32\Sound\*.* >

    < %SystemRoot%\system32\SpecialImg\*.* >

    < %SystemRoot%\system32\code\*.* >

    < %SystemRoot%\system32\draft\*.* >

    < %SystemRoot%\system32\MSSSys\*.* >

    < %ProgramFiles%\Javascript\*.* >

    < %systemroot%\pchealth\helpctr\System\*.exe /s >

    < %systemroot%\Web\*.exe >

    < %systemroot%\system32\msn\*.* >

    < %systemroot%\system32\*.tro >

    < %AppData%\Microsoft\Installer\msupdates\*.* >

    < %ProgramFiles%\Messenger\*.* >
    [2008-04-13 19:11:51 | 000,033,792 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\custsat.dll
    [2004-08-04 02:06:34 | 000,004,821 | ---- | M] () -- C:\Program Files\Messenger\LOGOWIN.GIF
    [2004-08-04 02:06:34 | 000,007,047 | ---- | M] () -- C:\Program Files\Messenger\LVBACK.GIF
    [2008-05-02 09:01:49 | 000,083,968 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msgsc.dll
    [2008-04-13 12:30:28 | 000,180,224 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msgslang.dll
    [2008-04-13 19:12:28 | 001,695,232 | -HS- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msmsgs.exe
    [2004-08-04 02:06:36 | 000,002,882 | ---- | M] () -- C:\Program Files\Messenger\NEWALERT.WAV
    [2004-08-04 02:06:36 | 000,006,156 | ---- | M] () -- C:\Program Files\Messenger\NEWEMAIL.WAV
    [2004-08-04 02:06:36 | 000,006,160 | ---- | M] () -- C:\Program Files\Messenger\ONLINE.WAV
    [2004-08-04 02:06:36 | 000,004,454 | ---- | M] () -- C:\Program Files\Messenger\TYPE.WAV
    [2004-08-04 02:06:36 | 000,115,981 | ---- | M] () -- C:\Program Files\Messenger\XPMSGR.CHM

    < %systemroot%\system32\systhem32\*.* >

    < %systemroot%\system\*.exe >
    [1993-03-21 23:00:00 | 000,286,704 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SYSTEM\MVIEWER2.EXE

    < HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

    < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs >


    ========== Alternate Data Streams ==========

    @Alternate Data Stream - 99 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0F8F5844
    @Alternate Data Stream - 153 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:522EA216
    @Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7E22C00F
    @Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:172EB9B5
    @Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:75EFCFC2
    @Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5B3E9221
    @Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DD874E14
    @Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D9F6664C
    @Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E71141D2
    @Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
    @Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:60C47453
    @Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1D6686D8
    @Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8643C5BE
    @Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:52D71461
    @Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3B00070D
    @Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C8591AF9
    @Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D56DDC33
    @Alternate Data Stream - 101 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E0E19514

    < End of report >
     

  3. to hide this advert.

  4. 2010/12/28
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    You're running dangerously low on C drive free space:
    You must start moving some stuff out, or your computer may refuse to boot one day.

    =================================================================

    Update your Java version here: http://www.java.com/en/download/installed.jsp

    Note 1: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

    Note 2: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. If you don't want to run another extra service, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.

    Now, we need to remove old Java version and its remnants...

    Download JavaRa to your desktop and unzip it to its own folder
    • Run JavaRa.exe (Vista users! Right click on JavaRa.exe, click Run As Administrator), pick the language of your choice and click Select. Then click Remove Older Versions.
    • Accept any prompts.

    ===============================================================

    Run OTL
    • Under the [color= "#0000FF"]Custom Scans/Fixes[/color] box at the bottom, paste in the following

      Code:
      :OTL
      PRC - [2007-04-04 16:41:28 | 000,177,672 | R--- | M] (Authentium, Inc.) -- C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
      SRV - File not found [Auto | Stopped] -- C:\Program Files\Viewpoint\Common\ViewpointService.exe -- (Viewpoint Manager Service)
      SRV - File not found [On_Demand | Stopped] -- -- (VideoAcceleratorEngine)
      SRV - File not found [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe -- (McComponentHostService)
      SRV - [2008-03-17 17:59:36 | 000,099,056 | ---- | M] (Radialpoint Inc.) [On_Demand | Stopped] -- C:\Program Files\verizon\PC Security Checkup\rpsupdaterR.exe -- (RPSUpdaterR)
      SRV - [2007-04-04 16:41:28 | 000,177,672 | R--- | M] (Authentium, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe -- (dvpapi)
      DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\EagleNT.sys -- (EagleNT)
      DRV - [2008-12-15 17:23:42 | 000,102,664 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\tmcomm.sys -- (tmcomm)
      DRV - [2007-04-04 16:15:02 | 000,839,880 | ---- | M] (Authentium, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\Css-Dvp.sys -- (CSS DVP)
      FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
      O3 - HKCU\..\Toolbar\WebBrowser: (Verizon Broadband Toolbar) - {4E7BD74F-2B8D-469E-8CB0-AB60BB9AAE22} - C:\PROGRA~1\VOL_TO~1\VOL_TO~1.DLL File not found
      O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} http://www.nick.com/common/groove/gx/GrooveAX27.cab (Reg Error: Key error.)
      O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get.../ultrashim.cab (Reg Error: Key error.)
      O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Reg Error: Key error.)
      O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
      O20 - Winlogon\Notify\winabi32: DllName - winabi32.dll - C:\WINDOWS\System32\winabi32.dll ()
      [6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
      [2 C:\Documents and Settings\family\My Documents\*.tmp files -> C:\Documents and Settings\family\My Documents\*.tmp -> ]
      [2010-04-12 20:54:15 | 000,002,418 | -HS- | C] () -- C:\Documents and Settings\family\Local Settings\Application Data\aB6G3tn
      [2010-04-12 20:54:15 | 000,002,418 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\aB6G3tn
      [2010-04-05 00:06:06 | 000,006,856 | -HS- | C] () -- C:\Documents and Settings\family\Local Settings\Application Data\VHx0W
      [2010-04-05 00:06:06 | 000,006,856 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\VHx0W
      [2008-07-14 17:20:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
      [2008-11-19 20:35:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\family\Application Data\Uniblue
      @Alternate Data Stream - 99 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0F8F5844
      @Alternate Data Stream - 153 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:522EA216
      @Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7E22C00F
      @Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:172EB9B5
      @Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:75EFCFC2
      @Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5B3E9221
      @Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DD874E14
      @Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D9F6664C
      @Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E71141D2
      @Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
      @Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:60C47453
      @Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1D6686D8
      @Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8643C5BE
      @Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:52D71461
      @Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3B00070D
      @Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C8591AF9
      @Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D56DDC33
      @Alternate Data Stream - 101 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E0E19514
      
      
      :Services
      
      :Reg
      
      :Files
      C:\Program Files\Common Files\Authentium
      C:\WINDOWS\System32\winabi32.dll 
      
      :Commands
      [purity]
      [emptytemp]
      [emptyflash]
      [Reboot]
      
    • Then click the [color= "#FF0000"]Run Fix[/color] button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • You will get a log that shows the results of the fix. Please post it.

    ===============================================================

    Last scans...

    1. Download Security Check from HERE, and save it to your Desktop.
    • Double-click SecurityCheck.exe
    • Follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

      NOTE SecurityCheck may produce some false warning(s), so leave the results reading to me.


    2. Download Temp File Cleaner (TFC)
    • Double click on TFC.exe to run the program.
    • Click on Start button to begin cleaning process.
    • TFC will close all running programs, and it may ask you to restart computer.


    3. Please run a free online scan with the ESET Online Scanner

    • Disable your antivirus program
    • Tick the box next to YES, I accept the Terms of Use
    • Click Start
    • IMPORTANT! UN-check Remove found threats
    • Accept any security warnings from your browser.
    • Check Scan archives
    • Click Start
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, push List of found threats
    • Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    • NOTE. If Eset won't find any threats, it won't produce any log.
     
  5. 2010/12/28
    JusticeNY

    JusticeNY Well-Known Member Thread Starter

    Joined:
    2008/12/14
    Messages:
    160
    Likes Received:
    0
    ran otl program worked then asked me to reboot

    when i reboot the program is gone from my desktop and no log was produced
     
  6. 2010/12/28
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Re-download OTL and run the fix again.
     
  7. 2010/12/28
    JusticeNY

    JusticeNY Well-Known Member Thread Starter

    Joined:
    2008/12/14
    Messages:
    160
    Likes Received:
    0
    Results of screen317's Security Check version 0.99.7
    Windows XP Service Pack 2
    Out of date service pack!!
    Internet Explorer 6 Out of date!
    ``````````````````````````````
    Antivirus/Firewall Check:

    Windows Security Center service is not running! This report may not be accurate!
    Avira AntiVir Personal - Free Antivirus
    Authentium AntiVirus SDK - 2
    McAfee Shredder
    ZoneAlarm
    ZoneAlarm Toolbar
    WMI entry may not exist for antivirus; attempting automatic update.
    Avira successfully updated!
    ```````````````````````````````
    Anti-malware/Other Utilities Check:

    Malwarebytes' Anti-Malware
    HijackThis 2.0.2
    EasyCleaner
    Java(TM) 6 Update 23
    Out of date Java installed!
    Adobe Flash Player 10.0.45.2
    Mozilla Firefox (3.5.16) Firefox Out of Date!
    ````````````````````````````````
    Process Check:
    objlist.exe by Laurent

    ``````````End of Log````````````
     
  8. 2010/12/28
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    .....
     
  9. 2010/12/28
    JusticeNY

    JusticeNY Well-Known Member Thread Starter

    Joined:
    2008/12/14
    Messages:
    160
    Likes Received:
    0
    when i re-downloaded otf as soon as i clicked on it produced the log that was lost

    All processes killed
    ========== OTL ==========
    No active process named dvpapi.exe was found!
    Service Viewpoint Manager Service stopped successfully!
    Service Viewpoint Manager Service deleted successfully!
    File C:\Program Files\Viewpoint\Common\ViewpointService.exe not found.
    Service VideoAcceleratorEngine stopped successfully!
    Service VideoAcceleratorEngine deleted successfully!
    Service McComponentHostService stopped successfully!
    Service McComponentHostService deleted successfully!
    File C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe not found.
    Service RPSUpdaterR stopped successfully!
    Service RPSUpdaterR deleted successfully!
    C:\Program Files\verizon\PC Security Checkup\rpsupdaterR.exe moved successfully.
    Service dvpapi stopped successfully!
    Service dvpapi deleted successfully!
    C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe moved successfully.
    Service EagleNT stopped successfully!
    Service EagleNT deleted successfully!
    File C:\WINDOWS\System32\drivers\EagleNT.sys not found.
    Service tmcomm stopped successfully!
    Service tmcomm deleted successfully!
    C:\WINDOWS\SYSTEM32\DRIVERS\tmcomm.sys moved successfully.
    Service CSS DVP stopped successfully!
    Service CSS DVP deleted successfully!
    C:\WINDOWS\SYSTEM32\DRIVERS\Css-Dvp.sys moved successfully.
    Registry value HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com deleted successfully.
    File C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird not found.
    Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{4E7BD74F-2B8D-469E-8CB0-AB60BB9AAE22} deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4E7BD74F-2B8D-469E-8CB0-AB60BB9AAE22}\ deleted successfully.
    Starting removal of ActiveX control {77E32299-629F-43C6-AB77-6A1E6D7663F6}
    Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{77E32299-629F-43C6-AB77-6A1E6D7663F6}\DownloadInformation\\INF .
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{77E32299-629F-43C6-AB77-6A1E6D7663F6}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{77E32299-629F-43C6-AB77-6A1E6D7663F6}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{77E32299-629F-43C6-AB77-6A1E6D7663F6}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{77E32299-629F-43C6-AB77-6A1E6D7663F6}\ not found.
    Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
    C:\WINDOWS\Downloaded Program Files\erma.inf moved successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
    Starting removal of ActiveX control {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}\ not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}\ not found.
    File oft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab not found.
    Starting removal of ActiveX control Microsoft XML Parser for Java
    Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java\DownloadInformation\\INF .
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\Microsoft XML Parser for Java\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winabi32\ deleted successfully.
    C:\WINDOWS\SYSTEM32\winabi32.dll moved successfully.
    C:\WINDOWS\System32\SET50.tmp deleted successfully.
    C:\WINDOWS\System32\SET54.tmp deleted successfully.
    C:\WINDOWS\System32\SET5C.tmp deleted successfully.
    C:\WINDOWS\System32\SET6D.tmp deleted successfully.
    C:\WINDOWS\System32\SET6F.tmp deleted successfully.
    C:\WINDOWS\System32\SET7E.tmp deleted successfully.
    C:\Documents and Settings\family\My Documents\~WRL1145.tmp deleted successfully.
    C:\Documents and Settings\family\My Documents\~WRL3034.tmp deleted successfully.
    C:\Documents and Settings\family\Local Settings\Application Data\aB6G3tn moved successfully.
    C:\Documents and Settings\All Users\Application Data\aB6G3tn moved successfully.
    C:\Documents and Settings\family\Local Settings\Application Data\VHx0W moved successfully.
    C:\Documents and Settings\All Users\Application Data\VHx0W moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Toolbar\3.8.0\ThemesV3\Windows\features\Weather\includes folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Toolbar\3.8.0\ThemesV3\Windows\features\Weather\graphics folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Toolbar\3.8.0\ThemesV3\Windows\features\Weather\core folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Toolbar\3.8.0\ThemesV3\Windows\features\Weather folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Toolbar\3.8.0\ThemesV3\Windows\features\ThemeCustomizer\images folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Toolbar\3.8.0\ThemesV3\Windows\features\ThemeCustomizer folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Toolbar\3.8.0\ThemesV3\Windows\features\options\images folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Toolbar\3.8.0\ThemesV3\Windows\features\options folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Toolbar\3.8.0\ThemesV3\Windows\features\Amazon\graphics folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Toolbar\3.8.0\ThemesV3\Windows\features\Amazon\core folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Toolbar\3.8.0\ThemesV3\Windows\features\Amazon folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Toolbar\3.8.0\ThemesV3\Windows\features folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Toolbar\3.8.0\ThemesV3\Windows\assets\graphics\Includes folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Toolbar\3.8.0\ThemesV3\Windows\assets\graphics\barintro_images folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Toolbar\3.8.0\ThemesV3\Windows\assets\graphics folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Toolbar\3.8.0\ThemesV3\Windows\assets\colorSchemes\backgrounds folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Toolbar\3.8.0\ThemesV3\Windows\assets\colorSchemes folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Toolbar\3.8.0\ThemesV3\Windows\assets folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Toolbar\3.8.0\ThemesV3\Windows folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Toolbar\3.8.0\ThemesV3\Default\production\automationScripts folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Toolbar\3.8.0\ThemesV3\Default\production folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Toolbar\3.8.0\ThemesV3\Default\features\Weather\includes folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Toolbar\3.8.0\ThemesV3\Default\features\Weather\graphics folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Toolbar\3.8.0\ThemesV3\Default\features\Weather\core folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Toolbar\3.8.0\ThemesV3\Default\features\Weather folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Toolbar\3.8.0\ThemesV3\Default\features\ThemeCustomizer\images folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Toolbar\3.8.0\ThemesV3\Default\features\ThemeCustomizer folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Toolbar\3.8.0\ThemesV3\Default\features\Amazon\includes folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Toolbar\3.8.0\ThemesV3\Default\features\Amazon\graphics folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Toolbar\3.8.0\ThemesV3\Default\features\Amazon\core folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Toolbar\3.8.0\ThemesV3\Default\features\Amazon folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Toolbar\3.8.0\ThemesV3\Default\features folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Toolbar\3.8.0\ThemesV3\Default\assets\graphics\tellafriend_offline\images folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Toolbar\3.8.0\ThemesV3\Default\assets\graphics\tellafriend_offline folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Toolbar\3.8.0\ThemesV3\Default\assets\graphics folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Toolbar\3.8.0\ThemesV3\Default\assets\colorSchemes\backgrounds folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Toolbar\3.8.0\ThemesV3\Default\assets\colorSchemes folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Toolbar\3.8.0\ThemesV3\Default\assets folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Toolbar\3.8.0\ThemesV3\Default folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Toolbar\3.8.0\ThemesV3 folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Toolbar\3.8.0 folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Toolbar folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\ThemeTemplates\Default folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\ThemeTemplates folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\features\SkinChooser folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\features\SelectorEditor folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\features\search\graphics folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\features\search folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\features\popups\graphics folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\features\popups folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\features\photoviewVista\includes folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\features\photoviewVista\graphics folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\features\photoviewVista\core folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\features\photoviewVista folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\features\photoview2\graphics folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\features\photoview2 folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\features\photoview\wizard\tests folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\features\photoview\wizard\html\images folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\features\photoview\wizard\html folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\features\photoview\wizard folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\features\photoview\offline\images folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\features\photoview\offline folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\features\photoview\graphics folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\features\photoview\frame_template folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\features\photoview\frames\Sports folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\features\photoview\frames\New Years folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\features\photoview\frames\New Baby folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\features\photoview\frames\Halloween folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\features\photoview\frames\Christmas folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\features\photoview\frames\Chanukah folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\features\photoview\frames\Birthday folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\features\photoview\frames\Autumn folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\features\photoview\frames folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\features\photoview folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\features\options\images folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\features\options folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\features\GeneralOptions\graphics folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\features\GeneralOptions folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\features\bookmarks\graphics folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\features\bookmarks folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\features\alerts\graphics folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\features\alerts folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\features\AdvancedOptions folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\features folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\core\UI_elements\tray_scroller folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\core\UI_elements\shared_graphics folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\core\UI_elements\selectors folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\core\UI_elements\searchWidget folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\core\UI_elements\scrollbar folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\core\UI_elements\preview folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\core\UI_elements\options_menu_button\graphics folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\core\UI_elements\options_menu_button folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\core\UI_elements\notification folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\core\UI_elements\listMenu folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\core\UI_elements\list folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\core\UI_elements\htmldialog folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\core\UI_elements\dropdowns folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\core\UI_elements\dialogs folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\core\UI_elements\buttons folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\core\UI_elements folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\core\tellafriend\offline\images folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\core\tellafriend\offline folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\core\tellafriend folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\core\options\images folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\core\options folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine\core folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0\SkinEngine folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime\3.8.0 folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\Toolbar Runtime folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint\AxMetaStream_Win folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\Viewpoint folder moved successfully.
    C:\Documents and Settings\family\Application Data\Uniblue folder moved successfully.
    ADS C:\Documents and Settings\All Users\Application Data\TEMP:0F8F5844 deleted successfully.
    ADS C:\Documents and Settings\All Users\Application Data\TEMP:522EA216 deleted successfully.
    ADS C:\Documents and Settings\All Users\Application Data\TEMP:7E22C00F deleted successfully.
    ADS C:\Documents and Settings\All Users\Application Data\TEMP:172EB9B5 deleted successfully.
    ADS C:\Documents and Settings\All Users\Application Data\TEMP:75EFCFC2 deleted successfully.
    ADS C:\Documents and Settings\All Users\Application Data\TEMP:5B3E9221 deleted successfully.
    ADS C:\Documents and Settings\All Users\Application Data\TEMP:DD874E14 deleted successfully.
    ADS C:\Documents and Settings\All Users\Application Data\TEMP:D9F6664C deleted successfully.
    ADS C:\Documents and Settings\All Users\Application Data\TEMP:E71141D2 deleted successfully.
    ADS C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2 deleted successfully.
    ADS C:\Documents and Settings\All Users\Application Data\TEMP:60C47453 deleted successfully.
    ADS C:\Documents and Settings\All Users\Application Data\TEMP:1D6686D8 deleted successfully.
    ADS C:\Documents and Settings\All Users\Application Data\TEMP:8643C5BE deleted successfully.
    ADS C:\Documents and Settings\All Users\Application Data\TEMP:52D71461 deleted successfully.
    ADS C:\Documents and Settings\All Users\Application Data\TEMP:3B00070D deleted successfully.
    ADS C:\Documents and Settings\All Users\Application Data\TEMP:C8591AF9 deleted successfully.
    ADS C:\Documents and Settings\All Users\Application Data\TEMP:D56DDC33 deleted successfully.
    ADS C:\Documents and Settings\All Users\Application Data\TEMP:E0E19514 deleted successfully.
    ========== SERVICES/DRIVERS ==========
    ========== REGISTRY ==========
    ========== FILES ==========
    C:\Program Files\Common Files\Authentium\AntiVirus folder moved successfully.
    C:\Program Files\Common Files\Authentium folder moved successfully.
    File\Folder C:\WINDOWS\System32\winabi32.dll not found.
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: Administrator
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: All Users

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes

    User: family
    ->Temp folder emptied: 10546108 bytes
    ->Temporary Internet Files folder emptied: 2324203 bytes
    ->Java cache emptied: 6333 bytes
    ->FireFox cache emptied: 178573456 bytes
    ->Apple Safari cache emptied: 0 bytes
    ->Opera cache emptied: 0 bytes
    ->Flash cache emptied: 7648 bytes

    User: LocalService
    ->Temp folder emptied: 983736 bytes
    ->Temporary Internet Files folder emptied: 72096822 bytes
    ->FireFox cache emptied: 0 bytes
    ->Flash cache emptied: 881 bytes

    User: NetworkService
    ->Temp folder emptied: 983736 bytes
    ->Temporary Internet Files folder emptied: 2855602 bytes
    ->Java cache emptied: 12 bytes
    ->Flash cache emptied: 787 bytes

    User: New Folder

    User: the fam
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->FireFox cache emptied: 0 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\dllcache .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 56737788 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 310.00 mb


    [EMPTYFLASH]

    User: Administrator

    User: All Users

    User: Default User

    User: family
    ->Flash cache emptied: 0 bytes

    User: LocalService
    ->Flash cache emptied: 0 bytes

    User: NetworkService
    ->Flash cache emptied: 0 bytes

    User: New Folder

    User: the fam

    Total Flash Files Cleaned = 0.00 mb


    OTL by OldTimer - Version 3.2.18.0 log created on 12282010_182333

    Files\Folders moved on Reboot...
    C:\Documents and Settings\family\Local Settings\Temp\~DF55A4.tmp moved successfully.
    C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\WDUBW9EN\101223-114830_ig[1].htm moved successfully.
    File\Folder C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\WDUBW9EN\default[1].htm not found!
    File\Folder C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\WDUBW9EN\default[2].htm not found!
    C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\WDUBW9EN\DocumentDotWrite[1].js moved successfully.
    File\Folder C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\WDUBW9EN\key[1].htm not found!
    File\Folder C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\WDUBW9EN\key[2].htm not found!
    C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\WDUBW9EN\quant[1].js moved successfully.
    File\Folder C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\WDUBW9EN\result[1].htm not found!
    File\Folder C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\WDUBW9EN\result[2].htm not found!
    File\Folder C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\WDUBW9EN\search[1].htm not found!
    C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\S9MBC1UV\101223-114830_ig-min[1].js moved successfully.
    C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\S9MBC1UV\sync-min[1].html moved successfully.
    C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\89238HMV\1527783898892882944[1].htm moved successfully.
    C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\89238HMV\fw-nonplayer-banner[1].php moved successfully.
    C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\89238HMV\fw-nonplayer-banner[2].php moved successfully.
    C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\89238HMV\gamesweaseltv.mevio[1] moved successfully.
    C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\89238HMV\login_status[1].php moved successfully.
    C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\89238HMV\nat[1] moved successfully.
    File\Folder C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\89238HMV\result[1].htm not found!
    C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\89238HMV\search[1].txt moved successfully.
    C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\89238HMV\sync-min[1].htm moved successfully.
    C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\89238HMV\top5countdown.mevio[1] moved successfully.
    C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\89238HMV\xd_receiver[1].php moved successfully.
    C:\WINDOWS\temp\IswTmp\Logs\ISWSHEX.swl moved successfully.
    C:\WINDOWS\temp\ZLT07dbf.TMP moved successfully.

    Registry entries deleted on Reboot...
     
  10. 2010/12/28
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Very good :)

    Update Firefox to the current, 3.6.13 version.

    I'll wait for Eset results before I ask you to update IE and install Service Pack 3.
     
  11. 2010/12/28
    JusticeNY

    JusticeNY Well-Known Member Thread Starter

    Joined:
    2008/12/14
    Messages:
    160
    Likes Received:
    0
    C:\Documents and Settings\All Users\Application Data\AOL Downloads\SUD4131\setup.exe probably a variant of Win32/Agent.HZHBURL trojan
    C:\Documents and Settings\family\My Documents\Install_AIM.exe Win32/Adware.WBug.A application
    C:\WINDOWS\dbplugin.ocx probably a variant of Win32/Adware.Agent.MCARLOM application
    C:\_OTL\MovedFiles\12282010_182333\C_WINDOWS\SYSTEM32\winabi32.dll a variant of Win32/Nebuler.BZ trojan
     
  12. 2010/12/28
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Run OTL
    • Under the [color= "#0000FF"]Custom Scans/Fixes[/color] box at the bottom, paste in the following

      Code:
      :OTL
      
      :Services
      
      :Reg
      
      :Files
      C:\Documents and Settings\All Users\Application Data\AOL Downloads\SUD4131\setup.exe 
      C:\Documents and Settings\family\My Documents\Install_AIM.exe 
      C:\WINDOWS\dbplugin.ocx
      
      :Commands
      [purity]
      [emptytemp]
      [emptyflash]
      [Reboot]
      
    • Then click the [color= "#FF0000"]Run Fix[/color] button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • You will get a log that shows the results of the fix. Please post it.

    ===============================================================

    You need to update Internet Explorer to at least version 7.
    Version 6 is obsolete and thus dangerous.

    ===============================================================

    Your computer is clean :)

    1. We need to reset system restore to prevent your computer from being accidentally reinfected by using some old restore point(s). We'll create fresh, clean restore point, using following OTL script:

    Run OTL

    • Under the Custom Scans/Fixes box at the bottom, paste in the following:

    Code:
    :OTL
    :Commands
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [CLEARALLRESTOREPOINTS]
    [Reboot]
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • Post resulting log.

    2. Now, we'll remove all tools, we used during our cleaning process

    Clean up with OTL:

    • Double-click OTL.exe to start the program.
    • Close all other programs apart from OTL as this step will require a reboot
    • On the OTL main screen, press the CLEANUP button
    • Say Yes to the prompt and then allow the program to reboot your computer.

    If you still have any tools or logs leftover on your computer you can go ahead and delete those off of your computer now.

    3. Make sure, Windows Updates are current (including Service Pack 3 installation and updating IE!)

    4. If any Trojan was listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

    5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

    6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

    7. Run Temporary File Cleaner (TFC) weekly.

    8. Download and install Secunia Personal Software Inspector (PSI): http://secunia.com/vulnerability_scanning/personal/. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

    9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
    The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

    10. Run defrag at your convenience.

    11. Read How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html

    12. Please, let me know, how your computer is doing.
     
  13. 2010/12/28
    JusticeNY

    JusticeNY Well-Known Member Thread Starter

    Joined:
    2008/12/14
    Messages:
    160
    Likes Received:
    0
    All processes killed
    ========== OTL ==========
    ========== SERVICES/DRIVERS ==========
    ========== REGISTRY ==========
    ========== FILES ==========
    C:\Documents and Settings\All Users\Application Data\AOL Downloads\SUD4131\setup.exe moved successfully.
    C:\Documents and Settings\family\My Documents\Install_AIM.exe moved successfully.
    C:\WINDOWS\dbplugin.ocx moved successfully.
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: Administrator
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: All Users

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: family
    ->Temp folder emptied: 1155536 bytes
    ->Temporary Internet Files folder emptied: 231737 bytes
    ->Java cache emptied: 0 bytes
    ->FireFox cache emptied: 128003789 bytes
    ->Apple Safari cache emptied: 0 bytes
    ->Opera cache emptied: 0 bytes
    ->Flash cache emptied: 1606 bytes

    User: LocalService
    ->Temp folder emptied: 983736 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes
    ->FireFox cache emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: NetworkService
    ->Temp folder emptied: 983736 bytes
    ->Temporary Internet Files folder emptied: 11343087 bytes
    ->Java cache emptied: 0 bytes
    ->Flash cache emptied: 758 bytes

    User: New Folder

    User: the fam
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->FireFox cache emptied: 0 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\dllcache .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 1009499 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 137.00 mb


    [EMPTYFLASH]

    User: Administrator

    User: All Users

    User: Default User

    User: family
    ->Flash cache emptied: 0 bytes

    User: LocalService
    ->Flash cache emptied: 0 bytes

    User: NetworkService
    ->Flash cache emptied: 0 bytes

    User: New Folder

    User: the fam

    Total Flash Files Cleaned = 0.00 mb


    OTL by OldTimer - Version 3.2.18.0 log created on 12282010_220824

    Files\Folders moved on Reboot...
    C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\IBKBYFMD\CAGX6F05.htm moved successfully.
    File\Folder C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\IBKBYFMD\dallasdui[1] not found!
    File\Folder C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\IBKBYFMD\like[1].php not found!
    C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\IBKBYFMD\meviomen.mevio[1] moved successfully.
    C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\IBKBYFMD\radontheweb.mevio[1] moved successfully.
    File\Folder C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\IBKBYFMD\search[1].htm not found!
    File\Folder C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\IBKBYFMD\search[1].php not found!
    C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\IBKBYFMD\viewid=33833254[1].htm moved successfully.
    File\Folder C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\CDEFGPEN\CA4HGR07.3198061 not found!
    File\Folder C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\CDEFGPEN\like[1].php not found!
    File\Folder C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\CDEFGPEN\NK-XVT6bZ0B[1].js not found!
    C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\24UO0HQB\cs[1] moved successfully.
    C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\24UO0HQB\debt[1].htm moved successfully.
    C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\24UO0HQB\empty[1].html moved successfully.
    C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\24UO0HQB\jump2[1] moved successfully.
    C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\24UO0HQB\media[2].php%3Fw%3D728%26h%3D90%26fwcsid%3DDistributedMvBlog%26btype%3D1 moved successfully.
    File\Folder C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\24UO0HQB\meviomen.mevio[1] not found!
    File\Folder C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\24UO0HQB\meviomen.mevio[2] not found!
    C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\24UO0HQB\viewid=33833254[1].htm moved successfully.
    C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\1PP389AH\CA98G7T9.htm moved successfully.
    File\Folder C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\1PP389AH\fw-nonplayer-banner[1].php not found!
    File\Folder C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\1PP389AH\fw-nonplayer-banner[2].php not found!
    C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\1PP389AH\sync-min[1].htm moved successfully.
    C:\WINDOWS\temp\IswTmp\Logs\ISWSHEX.swl moved successfully.

    Registry entries deleted on Reboot...
     
  14. 2010/12/28
    JusticeNY

    JusticeNY Well-Known Member Thread Starter

    Joined:
    2008/12/14
    Messages:
    160
    Likes Received:
    0
    still getting just in time debugger popup after a few mins on the cpu
     
  15. 2010/12/28
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Really?

    Please download ComboFix from [color= "Red"]Here[/color] or [color= "#FF0000"]Here[/color] to your Desktop.

    [color= "Blue"]**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**[/color]
    1. Please, never rename Combofix unless instructed.
    2. Close any open browsers.
    3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results ".
      • Click on [color= "Red"]this link[/color] to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
      NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
      • Close any open browsers.
      • [color= "Red"]WARNING:[/color] Combofix will disconnect your machine from the Internet as soon as it starts
      • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
      • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    4. Double click on combofix.exe & follow the prompts.
    5. When finished, it will produce a report for you.
    6. Please post the "C:\ComboFix.txt"
    **Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
    **Note 2 for AVG users: ComboFix will not run until AVG is uninstalled as a protective measure against the anti-virus. This is because AVG "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results ". Since AVG cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG first.
    Use AppRemover to uninstall it: http://www.appremover.com/
    We can reinstall it when we're done with CF.
    **Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion ", restart computer to fix the issue.



    Make sure, you re-enable your security programs, when you're done with Combofix.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    NOTE.
    If, for some reason, Combofix refuses to run, try one of the following:

    1. Run Combofix from Safe Mode.

    2. Delete Combofix file, download fresh one, but rename combofix.exe to your_name.exe BEFORE saving it to your desktop.
    Do NOT run it yet.

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click Rkill and choose Run as Administrator

    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    Rkill.com
    Rkill.scr
    Rkill.pif
    Rkill.exe

    • Double-click on the Rkill desktop icon to run the tool.
    • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    • If not, delete the file, then download and use the one provided in Link 2.
    • If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
    • Do not reboot until instructed.
    • If the tool does not run from any of the links provided, please let me know.

    Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

    If normal mode still doesn't work, run BOTH tools from safe mode.

    In case #2, please post BOTH logs, rKill and Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
     
  16. 2010/12/28
    JusticeNY

    JusticeNY Well-Known Member Thread Starter

    Joined:
    2008/12/14
    Messages:
    160
    Likes Received:
    0
    ComboFix 10-12-28.02 - Family 2010-12-29 0:18.10.2 - x86
    Running from: c:\documents and settings\family\Desktop\ComboFix.exe
    .

    ((((((((((((((((((((((((( Files Created from 2010-11-28 to 2010-12-29 )))))))))))))))))))))))))))))))
    .

    2010-12-29 04:23 . 2010-12-29 04:23 -------- d-----w- c:\windows\system32\msmq
    2010-12-29 04:23 . 2010-12-29 04:23 -------- d-----w- C:\Inetpub
    2010-12-29 04:08 . 2010-12-29 04:08 -------- d-s---w- c:\documents and settings\NetworkService\UserData
    2010-12-29 03:43 . 2010-12-29 03:43 -------- d-----w- c:\documents and settings\family\Local Settings\Application Data\Secunia PSI
    2010-12-29 03:43 . 2010-12-29 03:43 -------- d-----w- c:\program files\Secunia
    2010-12-28 23:57 . 2010-12-28 23:57 -------- d-----w- c:\program files\ESET
    2010-12-28 23:23 . 2010-12-28 23:23 -------- d-----w- C:\_OTL
    2010-12-28 08:46 . 2010-12-28 09:28 -------- d-----w- C:\9c1c213a8b65e850fa7c8b95a8
    2010-12-28 06:31 . 2010-12-28 06:31 -------- d-----w- C:\Adobe
    2010-12-28 03:08 . 2004-08-12 13:36 13894 -c--a-w- c:\windows\system32\dllcache\zonelibm.dll
    2010-12-28 03:08 . 2004-08-12 13:36 113222 -c--a-w- c:\windows\system32\dllcache\zoneclim.dll
    2010-12-28 03:08 . 2004-08-12 13:36 4677 -c--a-w- c:\windows\system32\dllcache\zeeverm.dll
    2010-12-28 03:08 . 2004-08-12 13:36 29760 -c--a-w- c:\windows\system32\dllcache\znetm.dll
    2010-12-28 03:08 . 2004-08-12 13:36 41029 -c--a-w- c:\windows\system32\dllcache\zcorem.dll
    2010-12-28 03:08 . 2004-08-12 13:36 36937 -c--a-w- c:\windows\system32\dllcache\zclientm.exe
    2010-12-28 03:08 . 2004-08-12 13:34 5632 -c--a-w- c:\windows\system32\dllcache\write.exe
    2010-12-28 03:06 . 2004-08-12 13:29 538624 -c--a-w- c:\windows\system32\dllcache\spider.exe
    2010-12-28 03:05 . 2004-08-12 13:20 98304 -c--a-w- c:\windows\system32\dllcache\msir3jp.dll
    2010-12-28 03:04 . 2004-08-12 13:20 13463552 -c--a-w- c:\windows\system32\dllcache\hwxjpn.dll
    2010-12-28 03:03 . 2004-08-12 13:17 9216 -c--a-w- c:\windows\system32\dllcache\authfilt.dll
    2010-12-28 03:02 . 2003-03-24 21:52 20540 -c--a-w- c:\windows\system32\dllcache\admin.dll
    2010-12-28 02:22 . 2004-08-12 13:29 24661 -c--a-w- c:\windows\system32\dllcache\spxcoins.dll
    2010-12-28 02:22 . 2004-08-12 13:29 24661 ----a-w- c:\windows\system32\spxcoins.dll
    2010-12-28 02:22 . 2004-08-12 13:20 13312 -c--a-w- c:\windows\system32\dllcache\irclass.dll
    2010-12-28 02:22 . 2004-08-12 13:20 13312 ----a-w- c:\windows\system32\irclass.dll
    2010-12-27 21:04 . 2010-12-27 21:04 -------- d-----w- c:\windows\msapps
    2010-12-27 21:04 . 2010-12-27 21:04 -------- d-----w- c:\windows\dell
    2010-12-12 03:57 . 2010-12-12 03:57 -------- d-----w- c:\documents and settings\family\Application Data\Avira
    2010-12-12 03:46 . 2010-12-25 17:19 135096 ----a-w- c:\windows\system32\drivers\avipbb.sys
    2010-12-12 03:46 . 2010-12-19 16:33 61960 ----a-w- c:\windows\system32\drivers\avgntflt.sys
    2010-12-12 03:46 . 2010-06-17 20:27 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
    2010-12-12 03:46 . 2010-06-17 20:27 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
    2010-12-12 03:46 . 2010-12-12 03:46 -------- d-----w- c:\program files\Avira
    2010-12-12 03:46 . 2010-12-12 03:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
    2010-12-09 05:59 . 2010-12-09 05:59 -------- d-----w- c:\documents and settings\family\Application Data\Toolbar4
    2010-12-09 05:59 . 2010-12-09 05:59 -------- d-----w- c:\program files\HyperCam Toolbar
    2010-12-05 05:48 . 2010-12-05 05:48 -------- d-----w- c:\program files\Common Files\Software Update Utility
    2010-11-29 22:28 . 2010-11-29 22:28 -------- d-----w- c:\program files\MSN Toolbar
    2010-11-29 22:27 . 2010-11-29 22:28 -------- d-----w- c:\program files\MSN Toolbar Installer
    2010-11-29 22:25 . 2010-11-12 23:53 472808 ----a-w- c:\windows\system32\deployJava1.dll
    2010-11-29 22:25 . 2010-11-12 23:53 472808 ----a-w- c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-12-20 23:09 . 2009-07-27 05:45 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-12-20 23:08 . 2009-07-27 05:45 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-11-29 23:07 . 2009-08-18 16:30 564632 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\wlidui.dll
    2010-11-29 23:07 . 2009-08-18 16:24 17816 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
    2010-11-12 21:34 . 2008-04-24 02:40 73728 ----a-w- c:\windows\system32\javacpl.cpl
    2010-11-10 04:55 . 2009-05-06 21:35 398744 ----a-r- c:\windows\system32\cpnprt2.cid
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{66f2e20d-0da8-4c11-a9c8-dd8477b88acd} "= "c:\program files\ZoneAlarm\tbZone.dll" [2010-05-09 2517088]

    [HKEY_CLASSES_ROOT\clsid\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]
    2010-05-09 15:50 2517088 ----a-w- c:\program files\ZoneAlarm\tbZone.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{66f2e20d-0da8-4c11-a9c8-dd8477b88acd} "= "c:\program files\ZoneAlarm\tbZone.dll" [2010-05-09 2517088]

    [HKEY_CLASSES_ROOT\clsid\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
    "{66F2E20D-0DA8-4C11-A9C8-DD8477B88ACD} "= "c:\program files\ZoneAlarm\tbZone.dll" [2010-05-09 2517088]

    [HKEY_CLASSES_ROOT\clsid\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ZoneAlarm Client "= "c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2010-05-20 1043968]
    "ISW "= "c:\program files\CheckPoint\ZAForceField\ForceField.exe" [2010-05-18 730600]
    "QuickTime Task "= "c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]
    "avgnt "= "c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-08-02 281768]
    "SunJavaUpdateSched "= "c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Secunia PSI Tray.lnk - c:\program files\Secunia\PSI\psi_tray.exe [2010-12-21 291896]

    [HKLM\~\startupfolder\C:^Documents and Settings^family^Start Menu^Programs^Startup^Styler.lnk]
    path=c:\documents and settings\family\Start Menu\Programs\Startup\Styler.lnk
    backup=c:\windows\pss\Styler.lnkStartup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
    2009-07-07 01:07 1848648 ----a-w- c:\program files\Canon\MyPrinter\BJMYPRT.EXE

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
    2010-03-02 06:09 135664 ----atw- c:\documents and settings\family\Local Settings\Application Data\Google\Update\GoogleUpdate.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
    2006-10-27 05:47 31016 -c--a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
    2004-05-06 21:48 118784 -c--a-w- c:\windows\SYSTEM32\hkcmd.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
    2004-05-06 21:52 155648 -c--a-w- c:\windows\SYSTEM32\igfxtray.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
    2010-02-15 22:07 141608 -c--a-w- c:\program files\iTunes\iTunesHelper.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Default Manager]
    2009-07-17 16:12 288080 ----a-w- c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Mouse Suite 98 Daemon]
    2001-01-12 21:36 73728 -c--a-w- c:\windows\SYSTEM32\PELMICED.EXE

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSN Toolbar]
    2010-02-12 16:02 240992 ----a-w- c:\program files\MSN Toolbar\Platform\4.0.0401.0\mswinext.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    2009-11-11 03:08 417792 ----a-w- c:\program files\QuickTime\QTTask.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\replay_telecorder_skype]
    2010-11-07 04:16 39408 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
    2010-05-14 16:44 248552 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
    2010-11-07 04:16 39408 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "iPod Service "=3 (0x3)
    "PnkBstrB "=2 (0x2)
    "PnkBstrA "=2 (0x2)
    "ATI Smart "=2 (0x2)
    "Ati HotKey Poller "=2 (0x2)
    "Apple Mobile Device "=2 (0x2)
    "SeaPort "=2 (0x2)

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
    "DisableMonitoring "=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
    "DisableMonitoring "=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall "= 0 (0x0)
    "DisableNotifications "= 1 (0x1)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe "=
    "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe "=
    "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE "=
    "c:\\Program Files\\AIM7\\aim.exe "=
    "c:\\Program Files\\Opera 10 Beta\\opera.exe "=
    "c:\\Program Files\\Google\\Google Talk\\googletalk.exe "=
    "c:\\Documents and Settings\\family\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll "=
    "c:\\Documents and Settings\\family\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe "=
    "c:\\Program Files\\iTunes\\iTunes.exe "=
    "c:\\Black III\\Orbitdownloader\\orbitdm.exe "=
    "c:\\Black III\\Orbitdownloader\\orbitnet.exe "=
    "c:\\WINDOWS\\SYSTEM32\\ZoneLabs\\vsmon.exe "=
    "c:\\Program Files\\Tencent\\QQ Games\\QQGames.exe "=
    "c:\\Program Files\\Tencent\\QQ Games\\QQGamesD.exe "=
    "c:\\Program Files\\Tencent\\QQ Games\\Update\\Update.exe "=
    "c:\\Program Files\\Skype\\Phone\\Skype.exe "=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "443:TCP "= 443:TCP:*:Disabled:eek:oVoo TCP port 443
    "443:UDP "= 443:UDP:*:Disabled:eek:oVoo UDP port 443
    "37674:TCP "= 37674:TCP:*:Disabled:eek:oVoo TCP port 37674
    "37674:UDP "= 37674:UDP:*:Disabled:eek:oVoo UDP port 37674
    "37675:UDP "= 37675:UDP:*:Disabled:eek:oVoo UDP port 37675

    R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-11-07 136176]
    R2 sbbotdi;sbbotdi; [x]
    R3 hamachi_oem;PlayLinc Adapter;c:\windows\system32\DRIVERS\gan_adapter.sys [2006-10-19 10664]
    R3 JakNDis;Jaksta Service;c:\windows\system32\DRIVERS\JakNDis.sys [2010-06-24 28256]
    R3 nosGetPlusHelper;getPlus(R) Helper 3004;c:\windows\System32\svchost.exe [2004-08-12 14336]
    R3 NTProcDrv;Process creation detector for NT.; [x]
    R3 PortTalk;PortTalk;c:\windows\system32\Drivers\PortTalk.sys [2002-01-12 3567]
    R3 Revoflt;Revoflt;c:\windows\system32\DRIVERS\revoflt.sys [2009-12-30 27064]
    R3 scsiprnt;Microsoft SCSI/1394 Generic Printer Class;c:\windows\system32\DRIVERS\scsiprnt.sys [2004-08-12 11648]
    R3 vaxscsi;vaxscsi;c:\windows\System32\Drivers\vaxscsi.sys [2007-06-04 223128]
    R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2008-12-10 717296]
    S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2010-08-02 135336]
    S2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [2010-05-18 26352]
    S2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\CheckPoint\ZAForceField\IswSvc.exe [2010-05-18 493032]
    S2 Secunia PSI Agent;Secunia PSI Agent;c:\program files\Secunia\PSI\PSIA.exe [2010-12-21 987704]
    S2 Secunia Update Agent;Secunia Update Agent;c:\program files\Secunia\PSI\sua.exe [2010-12-21 399416]
    S3 JakNDisMP;JakNDisMP;c:\windows\system32\DRIVERS\JakNDis.sys [2010-06-24 28256]
    S3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\DRIVERS\ManyCam.sys [2008-01-14 21632]
    S3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [2010-09-01 15544]


    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
    .
    Contents of the 'Scheduled Tasks' folder

    2010-10-25 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 16:34]

    2010-12-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-11-07 04:17]

    2010-12-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-11-07 04:17]

    2010-12-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2271019165-553755714-499774489-1005Core.job
    - c:\documents and settings\family\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-03-02 06:09]

    2010-12-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2271019165-553755714-499774489-1005UA.job
    - c:\documents and settings\family\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-03-02 06:09]
    .
    .
    ------- Supplementary Scan -------
    .
    uInternet Connection Wizard,ShellNext = iexplore
    uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
    IE: &Download by Orbit - c:\black iii\Orbitdownloader\orbitmxt.dll/201
    IE: &Grab video by Orbit - c:\black iii\Orbitdownloader\orbitmxt.dll/204
    IE: Do&wnload selected by Orbit - c:\black iii\Orbitdownloader\orbitmxt.dll/203
    IE: Down&load all by Orbit - c:\black iii\Orbitdownloader\orbitmxt.dll/202
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
    FF - ProfilePath - c:\documents and settings\family\Application Data\Mozilla\Firefox\Profiles\h0sglesq.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
    FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
    FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
    FF - Ext: AnyColor: anycolor.pavlos256@gmail.com - %profile%\extensions\anycolor.pavlos256@gmail.com
    FF - Ext: Screengrab: {02450954-cdd9-410f-b1da-db804e18c671} - %profile%\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
    FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
    FF - Ext: NoScript: {73a6fe31-595d-460b-a920-fcc0f8843232} - %profile%\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
    FF - Ext: DownloadHelper: {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - %profile%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
    FF - Ext: BlackBar Community Toolbar: {2ac337b3-fc9c-4d51-bed1-1ac1c48c63ea} - %profile%\extensions\{2ac337b3-fc9c-4d51-bed1-1ac1c48c63ea}
    FF - Ext: Conduit Engine : engine@conduit.com - %profile%\extensions\engine@conduit.com
    FF - Ext: Greasemonkey: {e4a8a97b-f2ed-450b-b12d-ee082ba24781} - %profile%\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
    FF - Ext: ColorfulTabs: {0545b830-f0aa-4d7e-8820-50a4629a56fe} - %profile%\extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe}
    FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false
    .
    - - - - ORPHANS REMOVED - - - -

    Notify-winabi32 - winabi32.dll



    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2010-12-29 00:33
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************

    Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
    Windows 5.1.2600 Disk: ST380013AS rev.8.05 -> Harddisk0\DR0 -> \Device\Ide\IdePort1 P1T0L0-e

    device: opened successfully
    user: MBR read successfully

    Disk trace:
    called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8A3B9555]<<
    _asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x8a3bf7b0]; MOV EAX, [0x8a3bf82c]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
    1 nt!IofCallDriver[0x804E19BC] -> \Device\Harddisk0\DR0[0x8A3F5030]
    3 CLASSPNP[0xF76B805B] -> nt!IofCallDriver[0x804E19BC] -> [0x8A376520]
    \Driver\atapi[0x8A3EDA50] -> IRP_MJ_CREATE -> 0x8A3B9555
    kernel: MBR read successfully
    _asm { CLI ; MOV AX, 0x0; MOV SS, AX; MOV SP, 0x7c00; STI ; MOV DS, AX; CLD ; MOV CX, 0x80; MOV SI, SP; MOV DI, 0x600; MOV ES, AX; REP MOVSD ; JMP FAR 0x0:0x62f; }
    detected disk devices:
    \Device\Ide\IdeDeviceP1T0L0-e -> \??\IDE#DiskST380013AS______________________________8.05____#4a35465647565839202020202020202020202020#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
    detected hooks:
    \Driver\atapi DriverStartIo -> 0x8A3B939B
    user & kernel MBR OK
    Warning: possible TDL3 rootkit infection !

    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_USERS\S-1-5-21-2271019165-553755714-499774489-1005\¬ ³*]
    @Allowed: (Read) (RestrictedCode)
    "verticalChoices "= "weatherV "
    "firstLaunch "= "false "
    DUMPHIVE0.003 (REGF)

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    @Denied: (A 2) (Everyone)
    @= "FlashBroker "
    "LocalizedString "= "@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101 "

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
    "Enabled "=dword:00000001

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
    @= "c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe "

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
    @= "{FAB3E735-69C7-453B-A446-B6823C6DF1C9} "

    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
    @Denied: (A 2) (Everyone)
    @= "IFlashBroker4 "

    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
    @= "{00020424-0000-0000-C000-000000000046} "

    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
    @= "{FAB3E735-69C7-453B-A446-B6823C6DF1C9} "
    "Version "= "1.0 "
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(1640)
    c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll

    - - - - - - - > 'lsass.exe'(1728)
    c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
    .
    Completion time: 2010-12-29 00:42:12
    ComboFix-quarantined-files.txt 2010-12-29 05:41

    Pre-Run: 1,668,407,296 bytes free
    Post-Run: 1,648,168,960 bytes free

    Current=3 Default=3 Failed=0 LastKnownGood=5 Sets=1,2,3,4,5
    - - End Of File - - 56797B5E437E79A83609E57AD1EDDB74
     
  17. 2010/12/29
    JusticeNY

    JusticeNY Well-Known Member Thread Starter

    Joined:
    2008/12/14
    Messages:
    160
    Likes Received:
    0
    also is it possible that a virus renamed svchost.exe so its undetectable i think that happened to me b4 a few years back cause i see svchost having high memory usage sometimes since i got this malware
     
  18. 2010/12/29
    JusticeNY

    JusticeNY Well-Known Member Thread Starter

    Joined:
    2008/12/14
    Messages:
    160
    Likes Received:
    0
  19. 2010/12/29
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    It looks like a rootkit is back...

    Download TDSSKiller and save it to your desktop.
    • Extract (unzip) its contents to your desktop.
    • Open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
    • If an infected file is detected, the default action will be Cure, click on Continue.
    • If a suspicious file is detected, the default action will be Skip, click on Continue.
    • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
    • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
    • If a reboot is required, the report can also be found in your root directory (usually C:\ folder) in the form of TDSSKiller_xxxx_log.txt. Please copy and paste the contents of that file here.
     
  20. 2010/12/29
    JusticeNY

    JusticeNY Well-Known Member Thread Starter

    Joined:
    2008/12/14
    Messages:
    160
    Likes Received:
    0
    2010/12/29 17:27:41.0046 TDSS rootkit removing tool 2.4.12.0 Dec 16 2010 09:46:46
    2010/12/29 17:27:41.0046 ================================================================================
    2010/12/29 17:27:41.0046 SystemInfo:
    2010/12/29 17:27:41.0046
    2010/12/29 17:27:41.0046 OS Version: 5.1.2600 ServicePack: 2.0
    2010/12/29 17:27:41.0046 Product type: Workstation
    2010/12/29 17:27:41.0046 ComputerName: FAM
    2010/12/29 17:27:41.0046 UserName: Family
    2010/12/29 17:27:41.0046 Windows directory: C:\WINDOWS
    2010/12/29 17:27:41.0046 System windows directory: C:\WINDOWS
    2010/12/29 17:27:41.0046 Processor architecture: Intel x86
    2010/12/29 17:27:41.0046 Number of processors: 2
    2010/12/29 17:27:41.0046 Page size: 0x1000
    2010/12/29 17:27:41.0046 Boot type: Normal boot
    2010/12/29 17:27:41.0046 ================================================================================
    2010/12/29 17:27:41.0375 Initialize success
    2010/12/29 17:28:06.0609 ================================================================================
    2010/12/29 17:28:06.0609 Scan started
    2010/12/29 17:28:06.0609 Mode: Manual;
    2010/12/29 17:28:06.0609 ================================================================================
    2010/12/29 17:28:07.0109 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS
    2010/12/29 17:28:07.0187 ACPI (a10c7534f7223f4a73a948967d00e69b) C:\WINDOWS\system32\DRIVERS\ACPI.sys
    2010/12/29 17:28:07.0265 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
    2010/12/29 17:28:07.0359 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys
    2010/12/29 17:28:07.0437 aeaudio (11c04b17ed2abbb4833694bcd644ac90) C:\WINDOWS\system32\drivers\aeaudio.sys
    2010/12/29 17:28:07.0500 aec (841f385c6cfaf66b58fbd898722bb4f0) C:\WINDOWS\system32\drivers\aec.sys
    2010/12/29 17:28:07.0625 AFD (5ac495f4cb807b2b98ad2ad591e6d92e) C:\WINDOWS\System32\drivers\afd.sys
    2010/12/29 17:28:07.0718 agp440 (2c428fa0c3e3a01ed93c9b2a27d8d4bb) C:\WINDOWS\system32\DRIVERS\agp440.sys
    2010/12/29 17:28:07.0796 agpCPQ (67288b07d6aba6c1267b626e67bc56fd) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
    2010/12/29 17:28:07.0875 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys
    2010/12/29 17:28:08.0000 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys
    2010/12/29 17:28:08.0093 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys
    2010/12/29 17:28:08.0156 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys
    2010/12/29 17:28:08.0218 alim1541 (f312b7cef21eff52fa23056b9d815fad) C:\WINDOWS\system32\DRIVERS\alim1541.sys
    2010/12/29 17:28:08.0281 amdagp (675c16a3c1f8482f85ee4a97fc0dde3d) C:\WINDOWS\system32\DRIVERS\amdagp.sys
    2010/12/29 17:28:08.0343 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys
    2010/12/29 17:28:08.0453 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys
    2010/12/29 17:28:08.0546 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys
    2010/12/29 17:28:08.0625 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys
    2010/12/29 17:28:08.0750 AsyncMac (02000abf34af4c218c35d257024807d6) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
    2010/12/29 17:28:08.0812 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\WINDOWS\system32\DRIVERS\atapi.sys
    2010/12/29 17:28:09.0000 ati2mtag (f0d0b0cdec0be32d775f404cac2604bf) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
    2010/12/29 17:28:09.0093 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
    2010/12/29 17:28:09.0156 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
    2010/12/29 17:28:09.0265 avgio (0b497c79824f8e1bf22fa6aacd3de3a0) C:\Program Files\Avira\AntiVir Desktop\avgio.sys
    2010/12/29 17:28:09.0375 avgntflt (47b879406246ffdced59e18d331a0e7d) C:\WINDOWS\system32\DRIVERS\avgntflt.sys
    2010/12/29 17:28:09.0484 avipbb (da39805e2bad99d37fce9477dd94e7f2) C:\WINDOWS\system32\DRIVERS\avipbb.sys
    2010/12/29 17:28:09.0578 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
    2010/12/29 17:28:09.0859 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys
    2010/12/29 17:28:09.0906 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
    2010/12/29 17:28:09.0984 CCDECODE (6163ed60b684bab19d3352ab22fc48b2) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
    2010/12/29 17:28:10.0031 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys
    2010/12/29 17:28:10.0109 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
    2010/12/29 17:28:10.0171 Cdfs (cd7d5152df32b47f4e36f710b35aae02) C:\WINDOWS\system32\drivers\Cdfs.sys
    2010/12/29 17:28:10.0265 Cdrom (af9c19b3100fe010496b1a27181fbf72) C:\WINDOWS\system32\DRIVERS\cdrom.sys
    2010/12/29 17:28:10.0375 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys
    2010/12/29 17:28:10.0468 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys
    2010/12/29 17:28:10.0562 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys
    2010/12/29 17:28:10.0656 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys
    2010/12/29 17:28:10.0734 Disk (00ca44e4534865f8a3b64f7c0984bff0) C:\WINDOWS\system32\DRIVERS\disk.sys
    2010/12/29 17:28:10.0906 dmboot (c0fbb516e06e243f0cf31f597e7ebf7d) C:\WINDOWS\system32\drivers\dmboot.sys
    2010/12/29 17:28:11.0062 dmio (f5e7b358a732d09f4bcf2824b88b9e28) C:\WINDOWS\system32\DRIVERS\dmio.sys
    2010/12/29 17:28:11.0171 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
    2010/12/29 17:28:11.0250 DMusic (a6f881284ac1150e37d9ae47ff601267) C:\WINDOWS\system32\drivers\DMusic.sys
    2010/12/29 17:28:11.0375 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys
    2010/12/29 17:28:11.0468 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\WINDOWS\system32\drivers\drmkaud.sys
    2010/12/29 17:28:11.0640 E100B (7d91dc6342248369f94d6eba0cf42e99) C:\WINDOWS\system32\DRIVERS\e100b325.sys
    2010/12/29 17:28:11.0828 Fastfat (3117f595e9615e04f05a54fc15a03b20) C:\WINDOWS\system32\drivers\Fastfat.sys
    2010/12/29 17:28:11.0937 Fdc (ced2e8396a8838e59d8fd529c680e02c) C:\WINDOWS\system32\DRIVERS\fdc.sys
    2010/12/29 17:28:12.0078 Fips (e153ab8a11de5452bcf5ac7652dbf3ed) C:\WINDOWS\system32\drivers\Fips.sys
    2010/12/29 17:28:12.0171 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
    2010/12/29 17:28:12.0281 FltMgr (157754f0df355a9e0a6f54721914f9c6) C:\WINDOWS\system32\drivers\fltmgr.sys
    2010/12/29 17:28:12.0421 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
    2010/12/29 17:28:12.0562 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
    2010/12/29 17:28:12.0671 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys
    2010/12/29 17:28:12.0921 Gpc (c0f1d4a21de5a415df8170616703debf) C:\WINDOWS\system32\DRIVERS\msgpc.sys
    2010/12/29 17:28:13.0093 hamachi (d30b31375c40309425c21efe75db90bb) C:\WINDOWS\system32\DRIVERS\hamachi.sys
    2010/12/29 17:28:13.0234 hamachi_oem (c25c70fd4d49391091d9eb8c747f19e6) C:\WINDOWS\system32\DRIVERS\gan_adapter.sys
    2010/12/29 17:28:13.0328 HidUsb (1de6783b918f540149aa69943bdfeba8) C:\WINDOWS\system32\DRIVERS\hidusb.sys
    2010/12/29 17:28:13.0437 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys
    2010/12/29 17:28:13.0515 HSFHWBS2 (77e4ff0b73bc0aeaaf39bf0c8104231f) C:\WINDOWS\system32\DRIVERS\HSFHWBS2.sys
    2010/12/29 17:28:13.0593 HSF_DP (60e1604729a15ef4a3b05f298427b3b1) C:\WINDOWS\system32\DRIVERS\HSF_DP.sys
    2010/12/29 17:28:13.0796 HTTP (c19b522a9ae0bbc3293397f3055e80a1) C:\WINDOWS\system32\Drivers\HTTP.sys
    2010/12/29 17:28:13.0906 i2omgmt (8f09f91b5c91363b77bcd15599570f2c) C:\WINDOWS\system32\drivers\i2omgmt.sys
    2010/12/29 17:28:14.0000 i2omp (ed6bf9e441fdea13292a6d30a64a24c3) C:\WINDOWS\system32\DRIVERS\i2omp.sys
    2010/12/29 17:28:14.0109 i8042prt (5502b58eef7486ee6f93f3f164dcb808) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
    2010/12/29 17:28:14.0250 ialm (6d4b680d5bf352cd0951aadd4de119ef) C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
    2010/12/29 17:28:14.0421 Imapi (f8aa320c6a0409c0380e5d8a99d76ec6) C:\WINDOWS\system32\DRIVERS\imapi.sys
    2010/12/29 17:28:14.0500 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys
    2010/12/29 17:28:14.0562 IntelIde (2d722b2b54ab55b2fa475eb58d7b2aad) C:\WINDOWS\system32\DRIVERS\intelide.sys
    2010/12/29 17:28:14.0671 intelppm (279fb78702454dff2bb445f238c048d2) C:\WINDOWS\system32\DRIVERS\intelppm.sys
    2010/12/29 17:28:14.0750 Ip6Fw (4448006b6bc60e6c027932cfc38d6855) C:\WINDOWS\system32\drivers\ip6fw.sys
    2010/12/29 17:28:14.0828 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
    2010/12/29 17:28:14.0906 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) C:\WINDOWS\system32\DRIVERS\ipinip.sys
    2010/12/29 17:28:14.0968 IpNat (b5a8e215ac29d24d60b4d1250ef05ace) C:\WINDOWS\system32\DRIVERS\ipnat.sys
    2010/12/29 17:28:15.0078 IPSec (64537aa5c003a6afeee1df819062d0d1) C:\WINDOWS\system32\DRIVERS\ipsec.sys
    2010/12/29 17:28:15.0187 IRENUM (50708daa1b1cbb7d6ac1cf8f56a24410) C:\WINDOWS\system32\DRIVERS\irenum.sys
    2010/12/29 17:28:15.0281 isapnp (e504f706ccb699c2596e9a3da1596e87) C:\WINDOWS\system32\DRIVERS\isapnp.sys
    2010/12/29 17:28:15.0406 ISWKL (4122f5208ae8380ccbacc5870d2567c7) C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys
    2010/12/29 17:28:15.0531 JakNDis (fcfe5f566e01264643a3175beb4c8280) C:\WINDOWS\system32\DRIVERS\JakNDis.sys
    2010/12/29 17:28:15.0546 JakNDisMP (fcfe5f566e01264643a3175beb4c8280) C:\WINDOWS\system32\DRIVERS\JakNDis.sys
    2010/12/29 17:28:15.0828 Kbdclass (ebdee8a2ee5393890a1acee971c4c246) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
    2010/12/29 17:28:15.0921 kmixer (d93cad07c5683db066b0b2d2d3790ead) C:\WINDOWS\system32\drivers\kmixer.sys
    2010/12/29 17:28:16.0031 KSecDD (eb7ffe87fd367ea8fca0506f74a87fbb) C:\WINDOWS\system32\drivers\KSecDD.sys
    2010/12/29 17:28:16.0203 ManyCam (c6d085c7045200143528136a43a65fde) C:\WINDOWS\system32\DRIVERS\ManyCam.sys
    2010/12/29 17:28:16.0281 mdmxsdk (eeaea6514ba7c9d273b5e87c4e1aab30) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys
    2010/12/29 17:28:16.0375 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
    2010/12/29 17:28:16.0468 Modem (6fc6f9d7acc36dca9b914565a3aeda05) C:\WINDOWS\system32\drivers\Modem.sys
    2010/12/29 17:28:16.0531 MODEMCSA (1992e0d143b09653ab0f9c5e04b0fd65) C:\WINDOWS\system32\drivers\MODEMCSA.sys
    2010/12/29 17:28:16.0718 Mouclass (34e1f0031153e491910e12551400192c) C:\WINDOWS\system32\DRIVERS\mouclass.sys
    2010/12/29 17:28:16.0953 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
    2010/12/29 17:28:17.0234 MountMgr (65653f3b4477f3c63e68a9659f85ee2e) C:\WINDOWS\system32\drivers\MountMgr.sys
    2010/12/29 17:28:17.0515 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys
    2010/12/29 17:28:17.0640 MREMPR5 (2bc9e43f55de8c30fc817ed56d0ee907) C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS
    2010/12/29 17:28:17.0703 MRENDIS5 (594b9d8194e3f4ecbf0325bd10bbeb05) C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS
    2010/12/29 17:28:17.0843 MRxDAV (46edcc8f2db2f322c24f48785cb46366) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
    2010/12/29 17:28:18.0015 MRxSmb (1fd607fc67f7f7c633c3da65bfc53d18) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
    2010/12/29 17:28:18.0171 Msfs (561b3a4333ca2dbdba28b5b956822519) C:\WINDOWS\system32\drivers\Msfs.sys
    2010/12/29 17:28:18.0328 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) C:\WINDOWS\system32\drivers\MSKSSRV.sys
    2010/12/29 17:28:18.0421 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
    2010/12/29 17:28:18.0468 MSPQM (1988a33ff19242576c3d0ef9ce785da7) C:\WINDOWS\system32\drivers\MSPQM.sys
    2010/12/29 17:28:18.0515 mssmbios (469541f8bfd2b32659d5d463a6714bce) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
    2010/12/29 17:28:18.0593 MSTEE (bf13612142995096ab084f2db7f40f77) C:\WINDOWS\system32\drivers\MSTEE.sys
    2010/12/29 17:28:18.0718 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) C:\WINDOWS\system32\drivers\Mup.sys
    2010/12/29 17:28:18.0828 NABTSFEC (5c8dc6429c43dc6177c1fa5b76290d1a) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
    2010/12/29 17:28:18.0984 NDIS (558635d3af1c7546d26067d5d9b6959e) C:\WINDOWS\system32\drivers\NDIS.sys
    2010/12/29 17:28:19.0078 NdisIP (520ce427a8b298f54112857bcf6bde15) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
    2010/12/29 17:28:19.0156 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
    2010/12/29 17:28:19.0250 Ndisuio (34d6cd56409da9a7ed573e1c90a308bf) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
    2010/12/29 17:28:19.0312 NdisWan (0b90e255a9490166ab368cd55a529893) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
    2010/12/29 17:28:19.0359 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\WINDOWS\system32\drivers\NDProxy.sys
    2010/12/29 17:28:19.0453 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) C:\WINDOWS\system32\DRIVERS\netbios.sys
    2010/12/29 17:28:19.0562 NetBT (0c80e410cd2f47134407ee7dd19cc86b) C:\WINDOWS\system32\DRIVERS\netbt.sys
    2010/12/29 17:28:19.0718 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) C:\WINDOWS\system32\drivers\Npfs.sys
    2010/12/29 17:28:19.0796 NPPTNT2 (9131fe60adfab595c8da53ad6a06aa31) C:\WINDOWS\system32\npptNT2.sys
    2010/12/29 17:28:19.0984 Ntfs (b78be402c3f63dd55521f73876951cdd) C:\WINDOWS\system32\drivers\Ntfs.sys
    2010/12/29 17:28:20.0125 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
    2010/12/29 17:28:20.0265 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
    2010/12/29 17:28:20.0437 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
    2010/12/29 17:28:20.0484 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
    2010/12/29 17:28:20.0593 NwlnkIpx (79ea3fcda7067977625b3363a2657c80) C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys
    2010/12/29 17:28:20.0703 NwlnkNb (56d34a67c05e94e16377c60609741ff8) C:\WINDOWS\system32\DRIVERS\nwlnknb.sys
    2010/12/29 17:28:20.0781 NwlnkSpx (c0bb7d1615e1acbdc99757f6ceaf8cf0) C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys
    2010/12/29 17:28:20.0906 NWRDR (03373a79440473062c6f3aedec6a49c8) C:\WINDOWS\system32\DRIVERS\nwrdr.sys
    2010/12/29 17:28:21.0000 omci (53d5f1278d9edb21689bbbcecc09108d) C:\WINDOWS\system32\DRIVERS\omci.sys
    2010/12/29 17:28:21.0093 Parport (29744eb4ce659dfe3b4122deb45bc478) C:\WINDOWS\system32\DRIVERS\parport.sys
    2010/12/29 17:28:21.0171 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\WINDOWS\system32\drivers\PartMgr.sys
    2010/12/29 17:28:21.0250 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
    2010/12/29 17:28:21.0312 PCI (8086d9979234b603ad5bc2f5d890b234) C:\WINDOWS\system32\DRIVERS\pci.sys
    2010/12/29 17:28:21.0390 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
    2010/12/29 17:28:21.0484 Pcmcia (82a087207decec8456fbe8537947d579) C:\WINDOWS\system32\drivers\Pcmcia.sys
    2010/12/29 17:28:21.0750 pelmouse (03f37bebd1f699b12304c4aeeedc0fae) C:\WINDOWS\system32\DRIVERS\pelmouse.sys
    2010/12/29 17:28:21.0828 pelusblf (a448e46c8fcb8f7f4ee0c64c97fe86ce) C:\WINDOWS\system32\DRIVERS\pelusblf.sys
    2010/12/29 17:28:21.0906 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys
    2010/12/29 17:28:21.0953 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys
    2010/12/29 17:28:22.0062 pfc (444f122e68db44c0589227781f3c8b3f) C:\WINDOWS\system32\drivers\pfc.sys
    2010/12/29 17:28:22.0187 PnkBstrK (58a25c6a67f53bdf5d899768a15b849c) C:\WINDOWS\system32\drivers\PnkBstrK.sys
    2010/12/29 17:28:22.0328 PortTalk (7d5a2d755b6c6579f63657b527d6ff1b) C:\WINDOWS\system32\Drivers\PortTalk.sys
    2010/12/29 17:28:22.0406 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) C:\WINDOWS\system32\DRIVERS\raspptp.sys
    2010/12/29 17:28:22.0468 PSched (48671f327553dcf1d27f6197f622a668) C:\WINDOWS\system32\DRIVERS\psched.sys
    2010/12/29 17:28:22.0531 PSI (d24dfd16a1e2a76034df5aa18125c35d) C:\WINDOWS\system32\DRIVERS\psi_mf.sys
    2010/12/29 17:28:22.0687 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
    2010/12/29 17:28:22.0765 PxHelp20 (153d02480a0a2f45785522e814c634b6) C:\WINDOWS\system32\Drivers\PxHelp20.sys
    2010/12/29 17:28:22.0843 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys
    2010/12/29 17:28:22.0906 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys
    2010/12/29 17:28:22.0968 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys
    2010/12/29 17:28:23.0046 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys
    2010/12/29 17:28:23.0109 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys
    2010/12/29 17:28:23.0171 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
    2010/12/29 17:28:23.0281 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
    2010/12/29 17:28:23.0390 RasPppoe (7306eeed8895454cbed4669be9f79faa) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
    2010/12/29 17:28:23.0468 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
    2010/12/29 17:28:23.0671 Rdbss (29d66245adba878fff574cd66abd2884) C:\WINDOWS\system32\DRIVERS\rdbss.sys
    2010/12/29 17:28:23.0781 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
    2010/12/29 17:28:23.0859 rdpdr (a2cae2c60bc37e0751ef9dda7ceaf4ad) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
    2010/12/29 17:28:23.0984 RDPWD (d4f5643d7714ef499ae9527fdcd50894) C:\WINDOWS\system32\drivers\RDPWD.sys
    2010/12/29 17:28:24.0125 redbook (b31b4588e4086d8d84adbf9845c2402b) C:\WINDOWS\system32\DRIVERS\redbook.sys
    2010/12/29 17:28:24.0218 Revoflt (8b5b8a11306190c6963d3473f052d3c8) C:\WINDOWS\system32\DRIVERS\revoflt.sys
    2010/12/29 17:28:24.0359 scsiprnt (74d69a3393a1f491d013db711641dd2d) C:\WINDOWS\system32\DRIVERS\scsiprnt.sys
    2010/12/29 17:28:24.0453 Secdrv (d26e26ea516450af9d072635c60387f4) C:\WINDOWS\system32\DRIVERS\secdrv.sys
    2010/12/29 17:28:24.0562 serenum (a2d868aeeff612e70e213c451a70cafb) C:\WINDOWS\system32\DRIVERS\serenum.sys
    2010/12/29 17:28:24.0640 Serial (cd9404d115a00d249f70a371b46d5a26) C:\WINDOWS\system32\DRIVERS\serial.sys
    2010/12/29 17:28:24.0843 sfdrv01 (4c0d673281178cb496011a2e28571fc8) C:\WINDOWS\system32\drivers\sfdrv01.sys
    2010/12/29 17:28:24.0921 sfhlp02 (15be2b5e4dc5b8623cf167720682abc9) C:\WINDOWS\system32\drivers\sfhlp02.sys
    2010/12/29 17:28:25.0000 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) C:\WINDOWS\system32\drivers\Sfloppy.sys
    2010/12/29 17:28:25.0078 sfvfs02 (d5a7e09d2c6a702809e49190d52adc9f) C:\WINDOWS\system32\drivers\sfvfs02.sys
    2010/12/29 17:28:25.0187 sisagp (732d859b286da692119f286b21a2a114) C:\WINDOWS\system32\DRIVERS\sisagp.sys
    2010/12/29 17:28:25.0296 SLIP (5caeed86821fa2c6139e32e9e05ccdc9) C:\WINDOWS\system32\DRIVERS\SLIP.sys
    2010/12/29 17:28:25.0359 smwdm (4aa922332433cdeb8b82c072c212e32e) C:\WINDOWS\system32\drivers\smwdm.sys
    2010/12/29 17:28:25.0468 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys
    2010/12/29 17:28:25.0546 splitter (8e186b8f23295d1e42c573b82b80d548) C:\WINDOWS\system32\drivers\splitter.sys
    2010/12/29 17:28:25.0656 sptd (71e276f6d189413266ea22171806597b) C:\WINDOWS\system32\Drivers\sptd.sys
    2010/12/29 17:28:25.0843 sr (e41b6d037d6cd08461470af04500dc24) C:\WINDOWS\system32\DRIVERS\sr.sys
    2010/12/29 17:28:25.0937 Srv (20b7e396720353e4117d64d9dcb926ca) C:\WINDOWS\system32\DRIVERS\srv.sys
    2010/12/29 17:28:26.0015 ssmdrv (a36ee93698802cd899f98bfd553d8185) C:\WINDOWS\system32\DRIVERS\ssmdrv.sys
    2010/12/29 17:28:26.0109 StillCam (a9573045baa16eab9b1085205b82f1ed) C:\WINDOWS\system32\DRIVERS\serscan.sys
    2010/12/29 17:28:26.0187 streamip (284c57df5dc7abca656bc2b96a667afb) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
    2010/12/29 17:28:26.0250 swenum (03c1bae4766e2450219d20b993d6e046) C:\WINDOWS\system32\DRIVERS\swenum.sys
    2010/12/29 17:28:26.0343 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WINDOWS\system32\drivers\swmidi.sys
    2010/12/29 17:28:26.0453 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys
    2010/12/29 17:28:26.0546 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys
    2010/12/29 17:28:26.0625 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys
    2010/12/29 17:28:26.0718 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys
    2010/12/29 17:28:26.0796 sysaudio (650ad082d46bac0e64c9c0e0928492fd) C:\WINDOWS\system32\drivers\sysaudio.sys
    2010/12/29 17:28:26.0890 taphss (0c3b2a9c4bd2dd9a6c2e4084314dd719) C:\WINDOWS\system32\DRIVERS\taphss.sys
    2010/12/29 17:28:27.0015 Tcpip (9f4b36614a0fc234525ba224957de55c) C:\WINDOWS\system32\DRIVERS\tcpip.sys
    2010/12/29 17:28:27.0125 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) C:\WINDOWS\system32\drivers\TDPIPE.sys
    2010/12/29 17:28:27.0171 TDTCP (ed0580af02502d00ad8c4c066b156be9) C:\WINDOWS\system32\drivers\TDTCP.sys
    2010/12/29 17:28:27.0265 TermDD (a540a99c281d933f3d69d55e48727f47) C:\WINDOWS\system32\DRIVERS\termdd.sys
    2010/12/29 17:28:27.0343 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys
    2010/12/29 17:28:27.0453 Udfs (12f70256f140cd7d52c58c7048fde657) C:\WINDOWS\system32\drivers\Udfs.sys
    2010/12/29 17:28:27.0531 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys
    2010/12/29 17:28:27.0640 Update (aff2e5045961bbc0a602bb6f95eb1345) C:\WINDOWS\system32\DRIVERS\update.sys
    2010/12/29 17:28:27.0750 USBAAPL (60a68a5ea173a97971ee9f1ff49eb2b3) C:\WINDOWS\system32\Drivers\usbaapl.sys
    2010/12/29 17:28:27.0812 usbccgp (bffd9f120cc63bcbaa3d840f3eef9f79) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
    2010/12/29 17:28:27.0890 usbehci (15e993ba2f6946b2bfbbfcd30398621e) C:\WINDOWS\system32\DRIVERS\usbehci.sys
    2010/12/29 17:28:27.0968 usbhub (c72f40947f92cea56a8fb532edf025f1) C:\WINDOWS\system32\DRIVERS\usbhub.sys
    2010/12/29 17:28:28.0046 usbprint (a42369b7cd8886cd7c70f33da6fcbcf5) C:\WINDOWS\system32\DRIVERS\usbprint.sys
    2010/12/29 17:28:28.0093 usbscan (a6bc71402f4f7dd5b77fd7f4a8ddba85) C:\WINDOWS\system32\DRIVERS\usbscan.sys
    2010/12/29 17:28:28.0171 USBSTOR (6cd7b22193718f1d17a47a1cd6d37e75) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
    2010/12/29 17:28:28.0250 usbuhci (f8fd1400092e23c8f2f31406ef06167b) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
    2010/12/29 17:28:28.0359 vaxscsi (92cebc2bc7be2c8d49391b365569f306) C:\WINDOWS\System32\Drivers\vaxscsi.sys
    2010/12/29 17:28:28.0484 VgaSave (8a60edd72b4ea5aea8202daf0e427925) C:\WINDOWS\System32\drivers\vga.sys
    2010/12/29 17:28:28.0562 viaagp (d92e7c8a30cfd14d8e15b5f7f032151b) C:\WINDOWS\system32\DRIVERS\viaagp.sys
    2010/12/29 17:28:28.0609 ViaIde (59cb1338ad3654417bea49636457f65d) C:\WINDOWS\system32\DRIVERS\viaide.sys
    2010/12/29 17:28:28.0765 VolSnap (ee4660083deba849ff6c485d944b379b) C:\WINDOWS\system32\drivers\VolSnap.sys
    2010/12/29 17:28:28.0859 vsdatant (050c38ebb22512122e54b47dc278bccd) C:\WINDOWS\system32\vsdatant.sys
    2010/12/29 17:28:29.0046 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) C:\WINDOWS\system32\DRIVERS\wanarp.sys
    2010/12/29 17:28:29.0187 wdmaud (2797f33ebf50466020c430ee4f037933) C:\WINDOWS\system32\drivers\wdmaud.sys
    2010/12/29 17:28:29.0281 winachsf (f59ed5a43b988a18ef582bb07b2327a7) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys
    2010/12/29 17:28:29.0484 WpdUsb (c60dc16d4e406810fad54b98dc92d5ec) C:\WINDOWS\system32\Drivers\wpdusb.sys
    2010/12/29 17:28:29.0562 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
    2010/12/29 17:28:29.0671 WSTCODEC (d5842484f05e12121c511aa93f6439ec) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
    2010/12/29 17:28:29.0781 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
    2010/12/29 17:28:29.0859 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
    2010/12/29 17:28:29.0968 \HardDisk0 - detected Rootkit.Win32.TDSS.tdl4 (0)
    2010/12/29 17:28:29.0984 ================================================================================
    2010/12/29 17:28:29.0984 Scan finished
    2010/12/29 17:28:29.0984 ================================================================================
    2010/12/29 17:28:30.0000 Detected object count: 1
    2010/12/29 17:28:38.0343 \HardDisk0 - will be cured after reboot
    2010/12/29 17:28:38.0343 Rootkit.Win32.TDSS.tdl4(\HardDisk0) - User select action: Cure
    2010/12/29 17:28:43.0046 Deinitialize success
     
  21. 2010/12/29
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Good :)

    Delete your Combofix file, download fresh one and post new log.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.