1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved Google Redirect Virus

Discussion in 'Malware and Virus Removal Archive' started by insaniity, 2009/11/28.

  1. 2009/11/28
    insaniity

    insaniity Inactive Thread Starter

    Joined:
    2009/11/28
    Messages:
    13
    Likes Received:
    0
    [Resolved] Google Redirect Virus

    I have gotten a Google redirect virus. I have tried everything to remove it but nothing seems to work.If its any help, it first goes to AmusementFacility then jumps to another website. Any help would be appreciated.

    Logs from DDS
    DDS (Ver_09-11-29.01) - NTFSx86
    Run by Luka at 18:19:17.83 on 28/11/2009
    Internet Explorer: 8.0.6001.18828 BrowserJavaVersion: 1.6.0_15
    Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.2.1033.18.1918.593 [GMT -5:00]

    SP: Spybot - Search and Destroy *enabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}

    ============== Running Processes ===============

    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\nvvsvc.exe
    C:\Windows\system32\svchost.exe -k rpcss
    C:\Windows\System32\svchost.exe -k secsvcs
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\AUDIODG.EXE
    C:\Windows\system32\svchost.exe -k GPSvcGroup
    C:\Windows\system32\SLsvc.exe
    C:\Windows\system32\nvvsvc.exe
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\ESET\ESET Smart Security\ekrn.exe
    C:\Program Files\ISP Monitor\ISPMonitorSrv.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
    C:\Program Files\CDBurnerXP\NMSAccessU.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\PnkBstrA.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\system32\PnkBstrB.exe
    C:\Windows\Explorer.EXE
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    C:\WINDOWS\RtHDVCpl.exe
    C:\Program Files\Winamp\winampa.exe
    C:\Program Files\ESET\ESET Smart Security\egui.exe
    C:\Program Files\DAEMON Tools Lite\daemon.exe
    C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\Codebox\BitMeter\BitMeter2.exe
    C:\Windows\system32\svchost.exe -k netsvc
    C:\Users\Luka\Downloads\Programs\Rainmeter\Rainmeter.exe
    c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    C:\Users\Luka\Downloads\Programs\Alcohol 120\StarWind\StarWindService.exe
    C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Windows\System32\TUProgSt.exe
    C:\Windows\System32\svchost.exe -k WerSvcGroup
    C:\Windows\system32\SearchIndexer.exe
    C:\Windows\system32\WUDFHost.exe
    C:\Windows\system32\DRIVERS\xaudio.exe
    C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
    C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    C:\Windows\system32\LogonUI.exe
    C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\ehome\mcupdate.EXE
    C:\Users\Luka\Downloads\Programs\Firefox\firefox.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Windows Live\Contacts\wlcomm.exe
    C:\Users\Luka\Downloads\dds.scr
    C:\Windows\system32\wbem\wmiprvse.exe

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://google.ca/
    uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_CA&c=71&bd=Pavilion&pf=desktop
    uWindow Title =
    mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_CA&c=71&bd=Pavilion&pf=desktop
    mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_CA&c=71&bd=Pavilion&pf=desktop
    mWindow Title =
    TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
    uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\daemon.exe" -autorun
    uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
    uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
    uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
    mRun: [RtHDVCpl] RtHDVCpl.exe
    mRun: [<NO NAME>]
    mRun: [amd_dc_opt] c:\program files\amd\dual-core optimizer\amd_dc_opt.exe
    mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
    mRun: [WinampAgent] "c:\program files\winamp\winampa.exe "
    mRun: [SpybotSnD] "c:\program files\spybot - search & destroy\SpybotSD.exe" /autocheck
    mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
    mRun: [egui] "c:\program files\eset\eset smart security\egui.exe" /hide /waitservice
    StartupFolder: c:\users\luka\appdata\roaming\micros~1\windows\startm~1\programs\startup\rainme~1.lnk - c:\users\luka\downloads\programs\rainmeter\Rainmeter.exe
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\bitmet~1.lnk - c:\program files\codebox\bitmeter\BitMeter2.exe
    mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
    mPolicies-explorer: NoChangeAnimation = 0 (0x0)
    mPolicies-explorer: NoStrCmpLogical = 0 (0x0)
    mPolicies-system: ConsentPromptBehaviorUser = 2 (0x2)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    mPolicies-system: RunStartupScriptSync = 1 (0x1)
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
    IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
    DPF: {D1278801-B2C0-4332-BD3E-2F64D2204EDF} - hxxps://www.mesh.com/0.9.4014.13/TSWeb.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    TCP: {10AA17A2-D126-48AA-83FE-D0C879DD6E86} = 192.168.2.1
    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
    Notify: MCPClient - c:\progra~1\common~1\stardock\mcpstub.dll
    SSODL: 0aMCPClient - {F5DF91F9-15E9-416B-A7C3-7519B11ECBFC} - c:\progra~1\common~1\stardock\MCPCore.dll
    mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe "
    mASetup: {6301493A-4A41-F704-18F6-554AEC18DBA5} - c:\program files\windows\windll.exe s
    IFEO: image file execution options - svchost.exe
    IFEO: brastk.exe - svchost.exe
    Hosts: 74.125.45.100 safebrowsing-cache.google.com
    Hosts: 74.125.45.100 urs.microsoft.com
    Hosts: 74.125.45.100 protected.maxisoftwaremart.com
    Hosts: 89.248.168.187 google.ae
    Hosts: 89.248.168.187 google.as

    Note: multiple HOSTS entries found. Please refer to Attach.txt

    ================= FIREFOX ===================

    FF - ProfilePath - c:\users\luka\appdata\roaming\mozilla\firefox\profiles\pxn860zz.default\
    FF - prefs.js: browser.startup.homepage - www.google.ca
    FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
    FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll
    FF - plugin: c:\program files\microsoft\office live\npOLW.dll
    FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
    FF - plugin: c:\users\luka\downloads\programs\vlc\npvlc.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

    ============= SERVICES / DRIVERS ===============

    R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2009-11-16 108792]
    R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-7-8 214664]
    R2 epfwwfp;epfwwfp;c:\windows\system32\drivers\epfwwfp.sys [2009-11-16 38240]
    R2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-15 34064]
    R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2009-10-23 19160]
    S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2009-11-10 54632]
    S3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2009-9-27 79816]
    S3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2009-9-27 35272]
    S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2009-9-27 34248]
    S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2009-9-27 40552]

    =============== Created Last 30 ================

    2009-11-28 16:57:23 0 d-----w- c:\users\luka\appdata\roaming\ESET
    2009-11-28 16:53:42 0 d-----w- c:\programdata\ESET
    2009-11-28 16:53:42 0 d-----w- c:\program files\ESET
    2009-11-28 15:32:53 19805 ----a-w- c:\windows\system32\drivers\usbio.sys
    2009-11-28 11:20:59 0 d-----w- c:\programdata\SP
    2009-11-28 00:48:56 195456 ------w- c:\windows\system32\MpSigStub.exe
    2009-11-25 03:59:01 2048 ----a-w- c:\windows\system32\tzres.dll
    2009-11-25 03:53:37 1401856 ----a-w- c:\windows\system32\msxml6.dll
    2009-11-25 03:53:36 1248768 ----a-w- c:\windows\system32\msxml3.dll
    2009-11-25 03:53:31 714240 ----a-w- c:\windows\system32\timedate.cpl
    2009-11-24 20:46:46 26266 ----a-w- c:\windows\system32\TuneUpDefragService_20091124-204646.dmp
    2009-11-23 15:06:33 0 d-----w- c:\program files\WinPcap
    2009-11-23 14:50:10 190 --s-a-w- c:\windows\system32\3272900702.dat
    2009-11-23 01:57:25 0 d-----w- c:\programdata\Macrovision
    2009-11-23 01:56:39 57344 ------w- c:\windows\system32\mfc70enu.dll
    2009-11-23 01:56:32 0 d-----w- c:\program files\common files\Macromedia Shared
    2009-11-22 18:06:39 0 d-sh--w- C:\found.003
    2009-11-22 12:09:33 0 d-sh--w- C:\found.002
    2009-11-22 04:06:41 0 d-----w- c:\programdata\Macromedia
    2009-11-22 04:06:21 0 d-----w- c:\program files\common files\Macromedia
    2009-11-22 04:04:46 0 d-----w- c:\windows\Downloaded Installations
    2009-11-21 00:05:49 0 d-----w- c:\users\luka\appdata\roaming\Rainmeter
    2009-11-17 11:49:03 0 d-----w- c:\program files\Windows Portable Devices
    2009-11-17 11:47:52 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
    2009-11-17 03:29:46 92672 ----a-w- c:\windows\system32\UIAnimation.dll
    2009-11-17 03:29:43 3023360 ----a-w- c:\windows\system32\UIRibbon.dll
    2009-11-17 03:29:43 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
    2009-11-17 03:29:06 369664 ----a-w- c:\windows\system32\WMPhoto.dll
    2009-11-17 03:29:06 258048 ----a-w- c:\windows\system32\winspool.drv
    2009-11-17 03:29:03 634880 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
    2009-11-17 03:29:03 37888 ----a-w- c:\windows\system32\cdd.dll
    2009-11-17 03:26:56 4096 ----a-w- c:\windows\system32\oleaccrc.dll
    2009-11-17 03:26:54 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
    2009-11-17 03:26:54 234496 ----a-w- c:\windows\system32\oleacc.dll
    2009-11-16 14:06:50 38240 ----a-w- c:\windows\system32\drivers\epfwwfp.sys
    2009-11-16 14:06:44 135048 ----a-w- c:\windows\system32\drivers\epfw.sys
    2009-11-16 14:03:36 108792 ----a-w- c:\windows\system32\drivers\ehdrv.sys
    2009-11-16 13:56:12 116520 ----a-w- c:\windows\system32\drivers\eamon.sys
    2009-11-14 16:38:29 0 d-----w- c:\programdata\Age of Empires 3
    2009-11-14 15:18:54 335 ----a-w- c:\windows\is-051EA.lst
    2009-11-14 15:18:54 21031 ----a-w- c:\windows\is-051EA.msg
    2009-11-14 15:18:54 1547264 ----a-w- c:\windows\is-051EA.exe
    2009-11-12 01:55:08 116736 ----a-w- c:\windows\system32\drivers\mcdbus.sys
    2009-11-11 08:05:25 118 ----a-w- c:\windows\system32\MRT.INI
    2009-11-11 08:00:55 0 d-sh--w- c:\windows\system32\%APPDATA%
    2009-11-11 01:58:31 2036736 ----a-w- c:\windows\system32\win32k.sys
    2009-11-11 01:57:51 355328 ----a-w- c:\windows\system32\WSDApi.dll
    2009-11-11 01:54:03 0 d-----w- c:\programdata\Age of Empires 3 XPack Trial
    2009-11-11 01:46:48 0 d-----w- c:\program files\common files\Microsoft Games
    2009-11-11 01:13:10 0 d-----w- c:\program files\Auto Mouse Click
    2009-11-10 21:03:26 54632 ----a-w- c:\windows\system32\drivers\fssfltr.sys
    2009-11-10 03:11:59 0 d-----w- c:\programdata\SkiniTunes
    2009-11-10 02:46:38 0 d-----w- c:\users\luka\appdata\roaming\CD Art Display
    2009-11-10 02:46:34 94208 ----a-w- c:\windows\system32\wmpuice.dll
    2009-11-10 02:46:34 69632 ----a-w- c:\windows\cadSSaver.scr
    2009-11-10 02:46:31 0 d-----w- c:\program files\CD Art Display
    2009-11-10 01:47:40 0 d-----w- c:\program files\TuneUp Utilities 2009
    2009-11-08 17:03:34 0 d-----w- c:\programdata\LightScribe
    2009-11-08 16:35:12 0 d-----w- c:\program files\EA GAMES
    2009-11-08 14:43:26 0 d-----w- c:\program files\GameSpy Arcade
    2009-11-08 14:38:10 0 d-----w- c:\program files\Sierra
    2009-11-08 14:35:25 45 ----a-w- c:\windows\system32\initdebug.nfo
    2009-11-07 03:05:22 98304 ----a-w- c:\windows\system32\CmdLineExt.dll
    2009-11-06 23:28:45 27672 ----a-w- c:\windows\system32\drivers\Entech.sys
    2009-11-06 23:28:45 0 d-----w- c:\windows\system32\Futuremark
    2009-11-06 23:28:44 0 d-----w- c:\program files\common files\Futuremark Shared
    2009-11-06 21:00:34 0 d-----w- c:\users\luka\appdata\roaming\PeerNetworking
    2009-11-05 01:41:45 0 d-----w- c:\program files\uTorrent
    2009-11-04 23:02:19 0 d-----w- c:\users\luka\appdata\roaming\Bitmeter2
    2009-11-04 23:02:19 0 d-----w- c:\programdata\Bitmeter2
    2009-11-04 23:02:18 0 d-----w- c:\program files\Codebox
    2009-11-04 22:54:52 0 d-----w- c:\users\luka\appdata\roaming\Rokario
    2009-11-04 21:59:17 5120 ----a-w- c:\windows\system32\BReWErS.dll
    2009-11-04 08:40:18 1638912 ----a-w- c:\windows\system32\mshtml.tlb
    2009-11-04 04:41:33 0 d-----w- c:\users\luka\appdata\roaming\ISP Monitor
    2009-11-04 04:41:16 737280 ----a-w- c:\windows\iun6002.exe
    2009-11-04 04:41:15 0 d-----w- c:\program files\ISP Monitor
    2009-11-03 23:46:47 75 ----a-w- c:\programdata\nvUnsupRes.dat
    2009-11-02 21:36:51 0 d-----w- c:\program files\Activision
    2009-11-01 14:43:47 22328 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
    2009-11-01 14:43:46 22328 ----a-w- c:\users\luka\appdata\roaming\PnkBstrK.sys
    2009-11-01 13:49:17 0 d-sh--w- c:\windows\ftpcache
    2009-10-31 03:32:51 335 ----a-w- c:\windows\is-49ORC.lst
    2009-10-31 03:32:51 21031 ----a-w- c:\windows\is-49ORC.msg
    2009-10-31 03:32:51 1547264 ----a-w- c:\windows\is-49ORC.exe
    2009-10-31 02:55:31 0 d-----w- c:\users\luka\appdata\roaming\LimeWire

    ==================== Find3M ====================

    2009-11-28 21:53:04 79248 ----a-w- c:\programdata\nvModes.dat
    2009-11-28 16:54:40 51200 ----a-w- c:\windows\inf\infpub.dat
    2009-11-28 16:54:40 143360 ----a-w- c:\windows\inf\infstrng.dat
    2009-11-28 16:54:38 86016 ----a-w- c:\windows\inf\infstor.dat
    2009-11-17 11:48:41 665600 ----a-w- c:\windows\inf\drvindex.dat
    2009-11-10 01:48:54 604488 ----a-w- c:\windows\system32\TUProgSt.exe
    2009-11-10 01:48:42 361288 ----a-w- c:\windows\system32\TuneUpDefragService.exe
    2009-11-05 00:25:07 103736 ----a-w- c:\windows\system32\PnkBstrB.exe
    2009-11-05 00:24:57 66872 ----a-w- c:\windows\system32\PnkBstrA.exe
    2009-10-31 16:29:51 127016 ----a-w- c:\windows\fonts\ZAPFCHA3.TTF
    2009-10-26 19:44:58 1510 ----a-w- c:\windows\Sketchpad Preferences.dat
    2009-10-26 12:24:30 2149888 ----a-w- c:\windows\system32\python26.dll
    2009-10-25 20:59:51 274133 ----a-w- c:\windows\Icon Converter Plus Uninstaller.exe
    2009-10-25 16:19:56 7852 ----a-w- c:\windows\system32\mcdmsg7.dll
    2009-10-24 14:55:49 615424 ----a-w- c:\windows\system32\themeui.dll
    2009-10-24 14:55:49 240128 ----a-w- c:\windows\system32\uxtheme.dll
    2009-10-18 16:16:49 2560 ----a-w- c:\windows\_MSRSTRT.EXE
    2009-10-18 02:33:14 147940 ---ha-w- c:\windows\system32\mlfcache.dat
    2009-10-13 00:18:30 174 --sha-w- c:\program files\desktop.ini
    2009-10-02 22:13:25 9040 ----a-w- c:\windows\system32\drivers\rdpdispm.sys
    2009-10-02 22:13:25 118736 ----a-w- c:\windows\system32\rdpdispd.dll
    2009-10-01 01:02:17 2537472 ----a-w- c:\windows\system32\wpdshext.dll
    2009-10-01 01:02:05 30208 ----a-w- c:\windows\system32\WPDShextAutoplay.exe
    2009-10-01 01:02:04 334848 ----a-w- c:\windows\system32\PortableDeviceApi.dll
    2009-10-01 01:02:02 87552 ----a-w- c:\windows\system32\WPDShServiceObj.dll
    2009-10-01 01:02:00 31232 ----a-w- c:\windows\system32\BthMtpContextHandler.dll
    2009-10-01 01:01:59 546816 ----a-w- c:\windows\system32\wpd_ci.dll
    2009-10-01 01:01:59 160256 ----a-w- c:\windows\system32\PortableDeviceTypes.dll
    2009-10-01 01:01:56 60928 ----a-w- c:\windows\system32\PortableDeviceConnectApi.dll
    2009-10-01 01:01:56 350208 ----a-w- c:\windows\system32\WPDSp.dll
    2009-10-01 01:01:56 196608 ----a-w- c:\windows\system32\PortableDeviceWMDRM.dll
    2009-10-01 01:01:56 100864 ----a-w- c:\windows\system32\PortableDeviceClassExtension.dll
    2009-10-01 01:01:54 81920 ----a-w- c:\windows\system32\wpdbusenum.dll
    2009-09-27 22:47:00 92776 ----a-w- c:\windows\system32\nvmctray.dll
    2009-09-27 22:47:00 805480 ----a-w- c:\windows\system32\nvsvc.dll
    2009-09-27 22:47:00 4033128 ----a-w- c:\windows\system32\nvvitvs.dll
    2009-09-27 22:47:00 3553896 ----a-w- c:\windows\system32\nvgames.dll
    2009-09-27 22:47:00 3172968 ----a-w- c:\windows\system32\nvwss.dll
    2009-09-27 22:47:00 215656 ----a-w- c:\windows\system32\nvvsvc.exe
    2009-09-27 22:47:00 195176 ----a-w- c:\windows\system32\nvmccss.dll
    2009-09-27 22:47:00 1309288 ----a-w- c:\windows\system32\nvsvs.dll
    2009-09-27 22:47:00 1292904 ----a-w- c:\windows\system32\nvmobls.dll
    2009-09-27 22:46:00 4942440 ----a-w- c:\windows\system32\nvdisps.dll
    2009-09-27 22:46:00 13949544 ----a-w- c:\windows\system32\nvcpl.dll
    2009-09-27 21:47:30 2173544 ----a-w- c:\windows\system32\nvcplui.exe
    2009-09-27 20:12:22 7614056 ----a-w- c:\windows\system32\nvd3dum.dll
    2009-09-27 20:12:22 490088 ----a-w- c:\windows\system32\nvudisp.exe
    2009-09-27 20:12:22 2169448 ----a-w- c:\windows\system32\nvcuvid.dll
    2009-09-27 20:12:22 1997416 ----a-w- c:\windows\system32\nvcuda.dll
    2009-09-27 20:12:22 1714792 ----a-w- c:\windows\system32\nvcuvenc.dll
    2009-09-27 20:12:22 170600 ----a-w- c:\windows\system32\nvcod167.dll
    2009-09-27 20:12:22 170600 ----a-w- c:\windows\system32\nvcod.dll
    2009-09-27 20:12:22 11197032 ----a-w- c:\windows\system32\nvoglv32.dll
    2009-09-27 20:12:22 1074280 ----a-w- c:\windows\system32\nvapi.dll
    2009-09-25 16:41:28 90112 ----a-w- c:\windows\system32\dpl100.dll
    2009-09-25 16:41:26 856064 ----a-w- c:\windows\system32\divx_xx0c.dll
    2009-09-25 16:41:26 856064 ----a-w- c:\windows\system32\divx_xx07.dll
    2009-09-25 16:41:26 847872 ----a-w- c:\windows\system32\divx_xx0a.dll
    2009-09-25 16:41:26 843776 ----a-w- c:\windows\system32\divx_xx16.dll
    2009-09-25 16:41:26 839680 ----a-w- c:\windows\system32\divx_xx11.dll
    2009-09-25 16:41:26 696320 ----a-w- c:\windows\system32\DivX.dll
    2009-09-25 02:10:10 974848 ----a-w- c:\windows\system32\WindowsCodecs.dll
    2009-09-25 02:07:08 189440 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
    2009-09-25 02:04:32 321024 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
    2009-09-25 01:49:22 1554432 ----a-w- c:\windows\system32\xpsservices.dll
    2009-09-25 01:48:08 351232 ----a-w- c:\windows\system32\XpsPrint.dll
    2009-09-25 01:38:29 847360 ----a-w- c:\windows\system32\OpcServices.dll
    2009-09-25 01:36:13 280064 ----a-w- c:\windows\system32\XpsGdiConverter.dll
    2009-09-25 01:35:31 135680 ----a-w- c:\windows\system32\XpsRasterService.dll
    2009-09-25 01:33:25 195584 ----a-w- c:\windows\system32\dxdiagn.dll
    2009-09-25 01:33:15 829440 ----a-w- c:\windows\system32\d3d10warp.dll
    2009-09-25 01:32:59 252928 ----a-w- c:\windows\system32\dxdiag.exe
    2009-09-25 01:31:53 519680 ----a-w- c:\windows\system32\d3d11.dll
    2009-09-25 01:31:26 486912 ----a-w- c:\windows\system32\d3d10level9.dll
    2009-09-25 01:31:21 161280 ----a-w- c:\windows\system32\d3d10_1.dll
    2009-09-25 01:31:19 218112 ----a-w- c:\windows\system32\d3d10_1core.dll
    2009-09-25 01:31:16 1030144 ----a-w- c:\windows\system32\d3d10.dll
    2009-09-25 01:31:15 828928 ----a-w- c:\windows\system32\d2d1.dll
    2009-09-25 01:30:23 481792 ----a-w- c:\windows\system32\dxgi.dll
    2009-09-25 01:30:23 190464 ----a-w- c:\windows\system32\d3d10core.dll
    2009-09-25 01:27:04 793088 ----a-w- c:\windows\system32\FntCache.dll
    2009-09-25 01:27:04 1064448 ----a-w- c:\windows\system32\DWrite.dll
    2009-09-24 22:54:53 667648 ----a-w- c:\windows\system32\printfilterpipelinesvc.exe
    2009-09-24 22:54:52 26112 ----a-w- c:\windows\system32\printfilterpipelineprxy.dll
    2009-09-24 13:24:18 490088 ----a-w- c:\windows\system32\nvuninst.exe
    2009-09-10 16:48:01 218624 ----a-w- c:\windows\system32\msv1_0.dll
    2009-09-10 14:59:26 8147456 ----a-w- c:\windows\system32\wmploc.DLL
    2009-09-10 14:58:28 310784 ----a-w- c:\windows\system32\unregmp2.exe
    2009-09-04 21:44:40 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll
    2009-09-04 21:44:40 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
    2009-09-04 21:44:40 238936 ----a-w- c:\windows\system32\xactengine3_5.dll
    2009-09-04 21:29:34 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
    2009-09-04 21:29:34 235344 ----a-w- c:\windows\system32\d3dx11_42.dll
    2009-09-04 21:29:32 5501792 ----a-w- c:\windows\system32\d3dcsx_42.dll
    2009-09-04 21:29:32 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll
    2009-09-04 21:29:30 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
    2009-09-04 11:41:59 60928 ----a-w- c:\windows\system32\msasn1.dll
    2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
    2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
    2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat

    ============= FINISH: 18:29:00.03 ===============


    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_09-11-29.01)

    Microsoft® Windows Vista™ Home Premium
    Boot Device: \Device\HarddiskVolume1
    Install Date: 15/07/2009 11:39:05 PM
    System Uptime: 28/11/2009 4:50:59 PM (2 hours ago)

    Motherboard: ASUSTek Computer INC. | | NODUSM3
    Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 3800+ | Socket AM2 | 2000/200mhz

    ==== Disk Partitions =========================

    C: is FIXED (NTFS) - 227 GiB total, 130.077 GiB free.
    D: is FIXED (NTFS) - 6 GiB total, 1.563 GiB free.
    E: is CDROM ()
    F: is CDROM ()
    G: is Removable
    H: is Removable
    I: is Removable
    J: is Removable
    L: is CDROM ()

    ==== Disabled Device Manager Items =============

    Class GUID: {4d36e96c-e325-11ce-bfc1-08002be10318}
    Description: Dazzle DVC100 Audio Device
    Device ID: ROOT\MEDIA\0000
    Manufacturer: Pinnacle Systems
    Name: Dazzle DVC100 Audio Device
    PNP Device ID: ROOT\MEDIA\0000
    Service: emAudio

    ==== System Restore Points ===================


    ==== Hosts File Hijack ======================

    Hosts: 74.125.45.100 safebrowsing-cache.google.com
    Hosts: 74.125.45.100 urs.microsoft.com
    Hosts: 74.125.45.100 protected.maxisoftwaremart.com
    Hosts: 89.248.168.187 google.ae
    Hosts: 89.248.168.187 google.as
    Hosts: 89.248.168.187 google.at
    Hosts: 89.248.168.187 google.az
    Hosts: 89.248.168.187 google.ba
    Hosts: 89.248.168.187 google.be
    Hosts: 89.248.168.187 google.bg
    Hosts: 89.248.168.187 google.bs
    Hosts: 89.248.168.187 google.ca
    Hosts: 89.248.168.187 google.cd
    Hosts: 89.248.168.187 google.com.gh
    Hosts: 89.248.168.187 google.com.hk
    Hosts: 89.248.168.187 google.com.jm
    Hosts: 89.248.168.187 google.com.mx
    Hosts: 89.248.168.187 google.com.my
    Hosts: 89.248.168.187 google.com.na
    Hosts: 89.248.168.187 google.com.nf
    Hosts: 89.248.168.187 google.com.ng
    Hosts: 89.248.168.187 google.ch
    Hosts: 89.248.168.187 google.com.np
    Hosts: 89.248.168.187 google.com.pr
    Hosts: 89.248.168.187 google.com.qa
    Hosts: 89.248.168.187 google.com.sg
    Hosts: 89.248.168.187 google.com.tj
    Hosts: 89.248.168.187 google.com.tw
    Hosts: 89.248.168.187 google.dj
    Hosts: 89.248.168.187 google.de
    Hosts: 89.248.168.187 google.dk
    Hosts: 89.248.168.187 google.dm
    Hosts: 89.248.168.187 google.ee
    Hosts: 89.248.168.187 google.fi
    Hosts: 89.248.168.187 google.fm
    Hosts: 89.248.168.187 google.fr
    Hosts: 89.248.168.187 google.ge
    Hosts: 89.248.168.187 google.gg
    Hosts: 89.248.168.187 google.gm
    Hosts: 89.248.168.187 google.gr
    Hosts: 89.248.168.187 google.ht
    Hosts: 89.248.168.187 google.ie
    Hosts: 89.248.168.187 google.im
    Hosts: 89.248.168.187 google.in
    Hosts: 89.248.168.187 google.it
    Hosts: 89.248.168.187 google.ki
    Hosts: 89.248.168.187 google.la
    Hosts: 89.248.168.187 google.li
    Hosts: 89.248.168.187 google.lv
    Hosts: 89.248.168.187 google.ma
    Hosts: 89.248.168.187 google.ms
    Hosts: 89.248.168.187 google.mu
    Hosts: 89.248.168.187 google.mw
    Hosts: 89.248.168.187 google.nl
    Hosts: 89.248.168.187 google.no
    Hosts: 89.248.168.187 google.nr
    Hosts: 89.248.168.187 google.nu
    Hosts: 89.248.168.187 google.pl
    Hosts: 89.248.168.187 google.pn
    Hosts: 89.248.168.187 google.pt
    Hosts: 89.248.168.187 google.ro
    Hosts: 89.248.168.187 google.ru
    Hosts: 89.248.168.187 google.rw
    Hosts: 89.248.168.187 google.sc
    Hosts: 89.248.168.187 google.se
    Hosts: 89.248.168.187 google.sh
    Hosts: 89.248.168.187 google.si
    Hosts: 89.248.168.187 google.sm
    Hosts: 89.248.168.187 google.sn
    Hosts: 89.248.168.187 google.st
    Hosts: 89.248.168.187 google.tl
    Hosts: 89.248.168.187 google.tm
    Hosts: 89.248.168.187 google.tt
    Hosts: 89.248.168.187 google.us
    Hosts: 89.248.168.187 google.vu
    Hosts: 89.248.168.187 google.ws
    Hosts: 89.248.168.187 google.co.ck
    Hosts: 89.248.168.187 google.co.id
    Hosts: 89.248.168.187 google.co.il
    Hosts: 89.248.168.187 google.co.in
    Hosts: 89.248.168.187 google.co.jp
    Hosts: 89.248.168.187 google.co.kr
    Hosts: 89.248.168.187 google.co.ls
    Hosts: 89.248.168.187 google.co.ma
    Hosts: 89.248.168.187 google.co.nz
    Hosts: 89.248.168.187 google.co.tz
    Hosts: 89.248.168.187 google.co.ug
    Hosts: 89.248.168.187 google.co.uk
    Hosts: 89.248.168.187 google.co.za
    Hosts: 89.248.168.187 google.co.zm
    Hosts: 89.248.168.187 google.com
    Hosts: 89.248.168.187 google.com.af
    Hosts: 89.248.168.187 google.com.ag
    Hosts: 89.248.168.187 google.com.ar
    Hosts: 89.248.168.187 google.com.au
    Hosts: 89.248.168.187 google.com.bn
    Hosts: 89.248.168.187 google.com.br
    Hosts: 89.248.168.187 google.com.by
    Hosts: 89.248.168.187 google.com.bz
    Hosts: 89.248.168.187 google.com.cu
    Hosts: 89.248.168.187 google.com.ec
    Hosts: 89.248.168.187 google.com.fj
    Hosts: 89.248.168.187 www.google.ae
    Hosts: 89.248.168.187 www.google.as
    Hosts: 89.248.168.187 www.google.at
    Hosts: 89.248.168.187 www.google.az
    Hosts: 89.248.168.187 www.google.ba
    Hosts: 89.248.168.187 www.google.be
    Hosts: 89.248.168.187 www.google.bg
    Hosts: 89.248.168.187 www.google.bs
    Hosts: 89.248.168.187 www.google.ca
    Hosts: 89.248.168.187 www.google.cd
    Hosts: 89.248.168.187 www.google.com.gh
    Hosts: 89.248.168.187 www.google.com.hk
    Hosts: 89.248.168.187 www.google.com.jm
    Hosts: 89.248.168.187 www.google.com.mx
    Hosts: 89.248.168.187 www.google.com.my
    Hosts: 89.248.168.187 www.google.com.na
    Hosts: 89.248.168.187 www.google.com.nf
    Hosts: 89.248.168.187 www.google.com.ng
    Hosts: 89.248.168.187 www.google.ch
    Hosts: 89.248.168.187 www.google.com.np
    Hosts: 89.248.168.187 www.google.com.pr
    Hosts: 89.248.168.187 www.google.com.qa
    Hosts: 89.248.168.187 www.google.com.sg
    Hosts: 89.248.168.187 www.google.com.tj
    Hosts: 89.248.168.187 www.google.com.tw
    Hosts: 89.248.168.187 www.google.dj
    Hosts: 89.248.168.187 www.google.de
    Hosts: 89.248.168.187 www.google.dk
    Hosts: 89.248.168.187 www.google.dm
    Hosts: 89.248.168.187 www.google.ee
    Hosts: 89.248.168.187 www.google.fi
    Hosts: 89.248.168.187 www.google.fm
    Hosts: 89.248.168.187 www.google.fr
    Hosts: 89.248.168.187 www.google.ge
    Hosts: 89.248.168.187 www.google.gg
    Hosts: 89.248.168.187 www.google.gm
    Hosts: 89.248.168.187 www.google.gr
    Hosts: 89.248.168.187 www.google.ht
    Hosts: 89.248.168.187 www.google.ie
    Hosts: 89.248.168.187 www.google.im
    Hosts: 89.248.168.187 www.google.in
    Hosts: 89.248.168.187 www.google.it
    Hosts: 89.248.168.187 www.google.ki
    Hosts: 89.248.168.187 www.google.la
    Hosts: 89.248.168.187 www.google.li
    Hosts: 89.248.168.187 www.google.lv
    Hosts: 89.248.168.187 www.google.ma
    Hosts: 89.248.168.187 www.google.ms
    Hosts: 89.248.168.187 www.google.mu
    Hosts: 89.248.168.187 www.google.mw
    Hosts: 89.248.168.187 www.google.nl
    Hosts: 89.248.168.187 www.google.no
    Hosts: 89.248.168.187 www.google.nr
    Hosts: 89.248.168.187 www.google.nu
    Hosts: 89.248.168.187 www.google.pl
    Hosts: 89.248.168.187 www.google.pn
    Hosts: 89.248.168.187 www.google.pt
    Hosts: 89.248.168.187 www.google.ro
    Hosts: 89.248.168.187 www.google.ru
    Hosts: 89.248.168.187 www.google.rw
    Hosts: 89.248.168.187 www.google.sc
    Hosts: 89.248.168.187 www.google.se
    Hosts: 89.248.168.187 www.google.sh
    Hosts: 89.248.168.187 www.google.si
    Hosts: 89.248.168.187 www.google.sm
    Hosts: 89.248.168.187 www.google.sn
    Hosts: 89.248.168.187 www.google.st
    Hosts: 89.248.168.187 www.google.tl
    Hosts: 89.248.168.187 www.google.tm
    Hosts: 89.248.168.187 www.google.tt
    Hosts: 89.248.168.187 www.google.us
    Hosts: 89.248.168.187 www.google.vu
    Hosts: 89.248.168.187 www.google.ws
    Hosts: 89.248.168.187 www.google.co.ck
    Hosts: 89.248.168.187 www.google.co.id
    Hosts: 89.248.168.187 www.google.co.il
    Hosts: 89.248.168.187 www.google.co.in
    Hosts: 89.248.168.187 www.google.co.jp
    Hosts: 89.248.168.187 www.google.co.kr
    Hosts: 89.248.168.187 www.google.co.ls
    Hosts: 89.248.168.187 www.google.co.ma
    Hosts: 89.248.168.187 www.google.co.nz
    Hosts: 89.248.168.187 www.google.co.tz
    Hosts: 89.248.168.187 www.google.co.ug
    Hosts: 89.248.168.187 www.google.co.za
    Hosts: 89.248.168.187 www.google.co.zm
    Hosts: 89.248.168.187 www.google.com.af
    Hosts: 89.248.168.187 www.google.com.ag
    Hosts: 89.248.168.187 www.google.com.ar
    Hosts: 89.248.168.187 www.google.com.au
    Hosts: 89.248.168.187 www.google.com.bn
    Hosts: 89.248.168.187 www.google.com.br
    Hosts: 89.248.168.187 www.google.com.by
    Hosts: 89.248.168.187 www.google.com.bz
    Hosts: 89.248.168.187 www.google.com.cu
    Hosts: 89.248.168.187 www.google.com.ec
    Hosts: 89.248.168.187 www.google.com.fj
    Hosts: 89.248.168.187 google.com
    Hosts: 89.248.168.187 bing.com
    Hosts: 89.248.168.187 www.bing.com
    Hosts: 89.248.168.187 search.yahoo.com
    Hosts: 89.248.168.187 www.search.yahoo.com
    Hosts: 89.248.168.187 search.live.com
    Hosts: 89.248.168.187 search.msn.com

    ==== Installed Programs ======================

    AC3Filter (remove only)
    Action Replay Code Manager
    ActiveCheck component for HP Active Support Library
    Adobe After Effects CS4
    Adobe After Effects CS4 Presets
    Adobe After Effects CS4 Third Party Content
    Adobe AIR
    Adobe Anchor Service CS3
    Adobe Anchor Service CS4
    Adobe Asset Services CS3
    Adobe Bridge CS3
    Adobe Bridge CS4
    Adobe Bridge Start Meeting
    Adobe Camera Raw 4.0
    Adobe CMaps CS4
    Adobe Color - Photoshop Specific
    Adobe Color EU Extra Settings CS4
    Adobe Color JA Extra Settings CS4
    Adobe Color NA Recommended Settings CS4
    Adobe Color Video Profiles AE CS4
    Adobe CSI CS4
    Adobe Default Language CS4
    Adobe Device Central CS3
    Adobe Device Central CS4
    Adobe Drive CS4
    Adobe Dynamiclink Support
    Adobe ExtendScript Toolkit 2
    Adobe ExtendScript Toolkit CS4
    Adobe Extension Manager CS4
    Adobe Flash CS4
    Adobe Flash CS4 Extension - Flash Lite STI en
    Adobe Flash CS4 Professional
    Adobe Flash CS4 STI-en
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Fonts All
    Adobe Help Viewer CS3
    Adobe Linguistics CS3
    Adobe Linguistics CS4
    Adobe Media Encoder CS4
    Adobe Media Encoder CS4 Additional Exporter
    Adobe Media Player
    Adobe MotionPicture Color Files CS4
    Adobe Output Module
    Adobe PDF Library Files CS4
    Adobe Photoshop CS3
    Adobe Premiere Pro CS3 Third Party Content
    Adobe Reader 7.0.8
    Adobe Search for Help
    Adobe Service Manager Extension
    Adobe Setup
    Adobe Stock Photos CS3
    Adobe Type Support CS4
    Adobe Update Manager CS3
    Adobe Update Manager CS4
    Adobe Version Cue CS3 Client
    Adobe WinSoft Linguistics Plugin
    Adobe XMP Panels CS3
    Adobe XMP Panels CS4
    AdobeColorCommonSetCMYK
    AdobeColorCommonSetRGB
    Age of Empires III
    Age of Empires III - The WarChiefs Trial
    Apple Application Support
    Apple Mobile Device Support
    Apple Software Update
    µTorrent
    Auto Mouse Click v1.1
    BannedStory
    Battlefield 2(TM)
    BitMeter
    Bonjour
    Call of Duty(R) 4 - Modern Warfare(TM) 1.4 Patch
    Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch
    Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch
    CCleaner (remove only)
    CD Art Display 2.0.1
    CDBurnerXP
    Coby Media Manager
    Connect
    CursorFX
    DivX Codec
    DivX Converter
    DivX Player
    DivX Plus DirectShow Filters
    DivX Web Player
    Dual-Core Optimizer
    EasyBCD 1.7.2
    Enhanced Multimedia Keyboard Solution
    ESET Smart Security
    EVEREST Home Edition v2.20
    EVEREST Ultimate Edition v5.30
    Express Burn
    FEARCombat
    Futuremark SystemInfo
    Google Earth
    Google Update Helper
    HijackThis 2.0.2
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    HP Active Support Library
    HP Connections (remove only)
    HP Customer Experience Enhancements
    HP Customer Feedback
    HP Easy Setup - Core
    HP Easy Setup - Frontend
    HP Picasso Media Center Add-In
    HP Total Care Advisor
    HP Update
    HPAsset component for HP Active Support Library
    Icon Converter Plus
    ISO Image Burner 1.1
    ISP Monitor
    iTunes
    Java(TM) 6 Update 15
    Junk Mail filter update
    kuler
    LightScribe System Software
    LimeWire 5.2.13
    LiveUpdate Notice (Symantec Corporation)
    Macromedia Extension Manager
    Macromedia Fireworks MX 2004
    Macromedia Flash 8
    Macromedia Flash 8 Video Encoder
    Magic ISO Maker v5.5 (build 0276)
    MagicDisc 2.7.106
    Malwarebytes' Anti-Malware
    MapleStory
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Security Update (KB953297)
    Microsoft .NET Framework 3.5 SP1
    Microsoft Application Error Reporting
    Microsoft Choice Guard
    Microsoft Office Excel MUI (English) 2007
    Microsoft Office Home and Student 2007
    Microsoft Office Home and Student 2007 Trial
    Microsoft Office Live Add-in 1.3
    Microsoft Office OneNote MUI (English) 2007
    Microsoft Office PowerPoint MUI (English) 2007
    Microsoft Office Proof (English) 2007
    Microsoft Office Proof (French) 2007
    Microsoft Office Proof (Spanish) 2007
    Microsoft Office Proofing (English) 2007
    Microsoft Office Shared MUI (English) 2007
    Microsoft Office Shared Setup Metadata MUI (English) 2007
    Microsoft Office Word MUI (English) 2007
    Microsoft Search Enhancement Pack
    Microsoft Silverlight
    Microsoft SQL Server 2005 Compact Edition [ENU]
    Microsoft SQL Server 2008
    Microsoft SQL Server 2008 Browser
    Microsoft SQL Server 2008 Common Files
    Microsoft SQL Server 2008 Database Engine Services
    Microsoft SQL Server 2008 Database Engine Shared
    Microsoft SQL Server 2008 Management Objects
    Microsoft SQL Server 2008 Native Client
    Microsoft SQL Server 2008 RsFx Driver
    Microsoft SQL Server 2008 Setup Support Files
    Microsoft SQL Server VSS Writer
    Microsoft Sync Framework Runtime Native v1.0 (x86)
    Microsoft Sync Framework Services Native v1.0 (x86)
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    Microsoft Windows SDK for Visual Studio 2008 Headers and Libraries
    Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for .NET Framework - enu
    Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for Win32
    Microsoft Works
    Mozilla Firefox (3.0.15)
    MSVCRT
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    MSXML 4.0 SP2 Parser and SDK
    muvee autoProducer 5.0
    My HP Games
    MyDefrag v4.2.1
    NVIDIA Drivers
    NVIDIA Stereoscopic 3D Driver
    ObjectDock
    OcxSetup
    OGA Notifier 2.0.0048.0
    Opera 10.01
    Pando Media Booster
    PDF Settings CS4
    Photoshop Camera Raw
    Pinnacle Instant DVD Recorder
    Pixel Bender Toolkit
    Prism Video Converter
    Python 2.4.3
    Python 2.5.1
    Python 2.6.4
    QuickBooks EasyStart Edition
    QuickBooks EasyStart Free Starter Edition
    QuickTime
    Rainmeter (remove only)
    Readiris Pro 10
    Realtek High Definition Audio Driver
    Roxio Creator Audio
    Roxio Creator Basic v9
    Roxio Creator Copy
    Roxio Creator Data
    Roxio Creator EasyArchive
    Roxio Creator Tools
    Roxio Express Labeler 3
    Safari
    SAMSUNG Dr. Printer
    Security Update for CAPICOM (KB931906)
    SkiniTunes
    Skype web features
    Skype™ 4.1
    SmarThru 4
    SmarThru PC Fax
    SpeedFan (remove only)
    Spybot - Search & Destroy
    Sql Server Customer Experience Improvement Program
    SQL Server System CLR Types
    Suite Shared Configuration CS4
    SupportSoft Assisted Service
    TuneUp Utilities 2009
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    VC80CRTRedist - 8.0.50727.4053
    Vegas Movie Studio Platinum 9.0
    Vista Shortcut Manager
    VLC media player 0.9.8a
    Winamp
    Windows Live Call
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live Family Safety
    Windows Live Mail
    Windows Live Messenger
    Windows Live Movie Maker
    Windows Live Photo Gallery
    Windows Live Sign-in Assistant
    Windows Live Sync
    Windows Live Toolbar
    Windows Live Upload Tool
    Windows Live Writer
    Windows Media Player Firefox Plugin
    WinRAR archiver
    YouTube Downloader 2.5.2

    ==== End Of File ===========================


    Again, thanks in advance
     
  2. 2009/11/28
    Admin.

    Admin. Administrator Administrator Staff

    Joined:
    2001/12/30
    Messages:
    6,687
    Likes Received:
    107
    I see you have P2P software ( Limewire, BitTorrent uTorrent etc… ) installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It may be contributing to your current situation. This page will give you further information.

    Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares and their infections.

    References for the risk of these programs are here, and here.

    I would strongly recommend that you uninstall them,

    Note: Please be advised that continued use of these programs after being warned of the danger of infections from them, may result in the discontinued help of future cleaning of your system here at WindowsBBS Malware and Virus removal.

    A Malware expert will have a look at your log in due course.
     

  3. to hide this advert.

  4. 2009/11/28
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Which browser is getting redirected?

    Download HostsXpert ( http://www.majorgeeks.com/Hoster_d4626.html ) and then follow the steps below:

    * Unzip HostsXpert.zip
    * It will create a folder named HostsXpert in whatever folder you extract it to.
    * Run HostsXpert.exe by double clicking on it.
    * click Restore MS Hosts File and then click OK.
    * Click the X to exit the program

    Restart computer.
     
  5. 2009/11/28
    insaniity

    insaniity Inactive Thread Starter

    Joined:
    2009/11/28
    Messages:
    13
    Likes Received:
    0
    Each time i choose to restore the hosts file it gives me an error message "ERROR: cannot create file C:\Windows\System32\drivers\etc\hosts" i may think the problem causing this is Spybot S&D the IE Tweaks because its checked off to "lock hosts file from hijackers ". but each time i uncheck it when i go to another area it gets rechecked

    PS:I have uninstalled all P2P clients,and Opera,Firefox and Internet Explorer are being redirected
     
    Last edited: 2009/11/28
  6. 2009/11/28
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Disable TeaTimer, as it'll interfere with the cleaning process:
    Right click Spybot's TeaTimer System Tray Icon.
    Click Exit Spybot-S&D Resident.
    TeaTimer closes.
    NOTE. If on re-boot, Spybot inquires about registry change(s), allow it.

    Right click on HostsXpert.exe, click "Run as Administrator ".

     
  7. 2009/11/28
    insaniity

    insaniity Inactive Thread Starter

    Joined:
    2009/11/28
    Messages:
    13
    Likes Received:
    0
    i did all that but still no luck. Same error shows up

    Browsers that are getting redirected are opera firefox and internet explorer
     
  8. 2009/11/28
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Restart in Safe Mode and try again.
     
  9. 2009/11/28
    insaniity

    insaniity Inactive Thread Starter

    Joined:
    2009/11/28
    Messages:
    13
    Likes Received:
    0
    I am in safe mode, i did repeat the process, but still nothing different.
     
  10. 2009/11/28
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Restart in normal mode.

    Please download ComboFix from [color= "Red"]Here[/color] or [color= "#FF0000"]Here[/color] to your Desktop.

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    • Please, never rename Combofix unless instructed.
    • Close any open browsers.
    • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results ".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
    NOTE. If Combofix asks you to install Recovery Console, please allow it.
    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    • Double click on combofix.exe & follow the prompts.
    • When finished, it will produce a report for you.
    • Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review.
    **Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

    Make sure, you re-enable your security programs, when you're done with Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!


    Download HijackThis:
    http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download
    by clicking on Download HijackThis Installer
    Install, and run it.
    Post HijackTHis log.
    Do NOT attempt to fix anything!

    NOTE. If you're using Vista, right click on HijackThis, and click Run as Administrator
     
  11. 2009/11/29
    insaniity

    insaniity Inactive Thread Starter

    Joined:
    2009/11/28
    Messages:
    13
    Likes Received:
    0
    ComboFix Logfile:
    ComboFix 09-11-28.03 - Luka 29/11/2009 9:47.1.2 - x86
    Microsoft® Windows Vistaâ„¢ Home Premium 6.0.6002.2.1252.2.1033.18.1918.1144 [GMT -5:00]
    Running from: c:\users\Luka\Desktop\ComboFix.exe
    SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
    * Resident AV is active

    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\$recycle.bin\S-1-5-21-2152478756-3922319563-605102323-500
    c:\$recycle.bin\S-1-5-21-4084801008-541973896-1260924502-500
    c:\$recycle.bin\S-1-5-21-4247689957-3568266116-3149608587-1000
    c:\program files\WinPCap
    c:\program files\WinPCap\rpcapd.exe
    c:\windows\system32\3272900702.dat
    c:\windows\system32\BReWErS.dll
    c:\windows\system32\drivers\npf.sys
    c:\windows\system32\Packet.dll
    c:\windows\system32\pthreadVC.dll
    c:\windows\system32\twain_32.dll
    c:\windows\system32\wpcap.dll
    D:\resycled
    d:\resycled\Desktop.ini
    d:\resycled\Protect.ed

    Infected copy of c:\windows\System32\drivers\atapi.sys was found and disinfected
    Restored copy from - Kitty ate it :p
    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Legacy_NPF
    -------\Service_npf


    ((((((((((((((((((((((((( Files Created from 2009-10-28 to 2009-11-29 )))))))))))))))))))))))))))))))
    .

    2009-11-29 15:06 . 2009-11-29 15:10 -------- d-----w- c:\users\Luka\AppData\Local\temp
    2009-11-29 15:06 . 2009-11-29 15:06 -------- d-----w- c:\users\Temp\AppData\Local\temp
    2009-11-29 15:06 . 2009-11-29 15:06 -------- d-----w- c:\users\Default\AppData\Local\temp
    2009-11-28 23:56 . 2009-11-28 23:56 -------- d-----w- c:\users\Luka\dwhelper
    2009-11-28 21:19 . 2009-11-28 21:19 -------- d-----w- c:\users\Luka\AppData\Local\Frameworkx.com
    2009-11-28 21:17 . 2009-11-28 21:17 284147 ----a-r- c:\users\Luka\AppData\Roaming\Microsoft\Installer\{47609E69-4C5E-48B1-A889-24C6B82B5C04}\_93A0BD079836122C39D406.exe
    2009-11-28 21:17 . 2009-11-28 21:17 284147 ----a-r- c:\users\Luka\AppData\Roaming\Microsoft\Installer\{47609E69-4C5E-48B1-A889-24C6B82B5C04}\_6FEFF9B68218417F98F549.exe
    2009-11-28 21:17 . 2009-11-28 21:17 284147 ----a-r- c:\users\Luka\AppData\Roaming\Microsoft\Installer\{47609E69-4C5E-48B1-A889-24C6B82B5C04}\_3207B59E601B5F75D71B21.exe
    2009-11-28 16:53 . 2009-11-28 16:53 -------- d-----w- c:\program files\ESET
    2009-11-28 16:45 . 2009-11-28 16:45 92 ----a-w- c:\users\Luka\AppData\Local\fusioncache.dat
    2009-11-28 15:32 . 2001-05-07 10:56 19805 ----a-w- c:\windows\system32\drivers\usbio.sys
    2009-11-28 11:20 . 2009-11-28 11:20 57344 ----a-w- c:\programdata\SP\sp.DLL
    2009-11-28 11:20 . 2009-11-28 11:20 -------- d-----w- c:\programdata\SP
    2009-11-28 00:48 . 2009-11-03 01:42 195456 ------w- c:\windows\system32\MpSigStub.exe
    2009-11-25 03:59 . 2009-10-29 09:17 2048 ----a-w- c:\windows\system32\tzres.dll
    2009-11-25 03:53 . 2009-08-11 16:44 1401856 ----a-w- c:\windows\system32\msxml6.dll
    2009-11-25 03:53 . 2009-08-11 16:44 1248768 ----a-w- c:\windows\system32\msxml3.dll
    2009-11-24 04:46 . 2009-11-24 04:46 -------- d-----w- c:\users\Temp\AppData\Roaming\TuneUp Software
    2009-11-23 01:57 . 2009-11-23 01:57 -------- d-----w- c:\programdata\Macrovision
    2009-11-23 01:56 . 2002-01-05 12:10 57344 ------w- c:\windows\system32\mfc70enu.dll
    2009-11-23 01:56 . 2009-11-23 01:56 -------- d-----w- c:\program files\Common Files\Macromedia Shared
    2009-11-22 18:06 . 2009-11-22 18:06 -------- d-----w- C:\found.003
    2009-11-22 15:32 . 2009-11-22 15:32 96096 ----a-w- c:\users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT
    2009-11-22 15:31 . 2009-11-22 15:31 -------- d-----w- c:\users\Administrator\AppData\Local\ApplicationHistory
    2009-11-22 15:31 . 2009-11-22 15:31 -------- d-----w- c:\users\Administrator\AppData\Roaming\Malwarebytes
    2009-11-22 14:26 . 2009-11-22 14:27 -------- d-----w- c:\users\Luka\AppData\Local\VirtualStore
    2009-11-22 12:09 . 2009-11-22 12:09 -------- d-----w- C:\found.002
    2009-11-22 05:02 . 2009-11-22 05:02 9 ----a-w- c:\users\Luka\AppData\Roaming\Microsoft\Windows\Recent\ANTIGEN.exe
    2009-11-22 04:54 . 2009-11-22 04:54 6 ----a-w- c:\users\Luka\AppData\Roaming\Microsoft\Windows\Recent\SICKBOY.drv
    2009-11-22 04:54 . 2009-11-22 04:54 6 ----a-w- c:\users\Luka\AppData\Roaming\Microsoft\Windows\Recent\PE.dll
    2009-11-22 04:54 . 2009-11-22 04:54 50 ----a-w- c:\users\Luka\AppData\Roaming\Microsoft\Windows\Recent\PE.sys
    2009-11-22 04:54 . 2009-11-22 04:54 46 ----a-w- c:\users\Luka\AppData\Roaming\Microsoft\Windows\Recent\tempdoc.exe
    2009-11-22 04:54 . 2009-11-22 04:54 15 ----a-w- c:\users\Luka\AppData\Roaming\Microsoft\Windows\Recent\sld.dll
    2009-11-22 04:54 . 2009-11-22 04:54 68 ----a-w- c:\users\Luka\AppData\Roaming\Microsoft\Windows\Recent\eb.drv
    2009-11-22 04:53 . 2009-11-22 04:53 48 ----a-w- c:\users\Luka\AppData\Roaming\Microsoft\Windows\Recent\ppal.sys
    2009-11-22 04:53 . 2009-11-22 04:53 30 ----a-w- c:\users\Luka\AppData\Roaming\Microsoft\Windows\Recent\exec.sys
    2009-11-22 04:53 . 2009-11-22 04:53 20 ----a-w- c:\users\Luka\AppData\Roaming\Microsoft\Windows\Recent\snl2w.exe
    2009-11-22 04:53 . 2009-11-22 04:53 17 ----a-w- c:\users\Luka\AppData\Roaming\Microsoft\Windows\Recent\tjd.sys
    2009-11-22 04:53 . 2009-11-22 04:53 72 ----a-w- c:\users\Luka\AppData\Roaming\Microsoft\Windows\Recent\delfile.drv
    2009-11-22 04:27 . 2009-11-22 04:27 -------- d-----w- c:\users\Luka\AppData\Local\Macromedia
    2009-11-22 04:06 . 2009-11-23 01:56 -------- d-----w- c:\program files\Common Files\Macromedia
    2009-11-22 04:04 . 2009-11-22 04:04 -------- d-----w- c:\windows\Downloaded Installations
    2009-11-21 00:05 . 2009-11-21 02:58 -------- d-----w- c:\users\Luka\AppData\Roaming\Rainmeter
    2009-11-20 02:47 . 2009-11-20 02:52 4096 d-----w- c:\users\Luka\AppData\Roaming\Winamp
    2009-11-17 11:49 . 2009-11-17 11:49 -------- d-----w- c:\program files\Windows Portable Devices
    2009-11-17 03:29 . 2009-09-10 02:00 92672 ----a-w- c:\windows\system32\UIAnimation.dll
    2009-11-17 03:29 . 2009-09-10 02:01 3023360 ----a-w- c:\windows\system32\UIRibbon.dll
    2009-11-17 03:29 . 2009-09-10 02:00 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
    2009-11-17 03:29 . 2009-09-25 01:33 369664 ----a-w- c:\windows\system32\WMPhoto.dll
    2009-11-17 03:29 . 2009-09-24 22:54 258048 ----a-w- c:\windows\system32\winspool.drv
    2009-11-17 03:29 . 2009-09-25 01:27 634880 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
    2009-11-17 03:29 . 2009-09-25 01:27 37888 ----a-w- c:\windows\system32\cdd.dll
    2009-11-17 03:26 . 2009-10-08 21:07 4096 ----a-w- c:\windows\system32\oleaccrc.dll
    2009-11-17 03:26 . 2009-10-08 21:08 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
    2009-11-17 03:26 . 2009-10-08 21:08 234496 ----a-w- c:\windows\system32\oleacc.dll
    2009-11-16 14:06 . 2009-11-16 14:06 38240 ----a-w- c:\windows\system32\drivers\epfwwfp.sys
    2009-11-16 14:06 . 2009-11-16 14:06 135048 ----a-w- c:\windows\system32\drivers\epfw.sys
    2009-11-16 14:03 . 2009-11-16 14:03 108792 ----a-w- c:\windows\system32\drivers\ehdrv.sys
    2009-11-16 13:56 . 2009-11-16 13:56 116520 ----a-w- c:\windows\system32\drivers\eamon.sys
    2009-11-14 16:38 . 2009-11-14 16:38 -------- d-----w- c:\programdata\Age of Empires 3
    2009-11-14 15:18 . 2009-11-14 15:18 1547264 ----a-w- c:\windows\is-051EA.exe
    2009-11-12 01:55 . 2009-02-24 23:42 116736 ----a-w- c:\windows\system32\drivers\mcdbus.sys
    2009-11-11 23:29 . 2009-11-11 23:29 -------- d-----w- c:\users\Luka\AppData\Roaming\AdobeUM
    2009-11-11 08:00 . 2009-11-11 08:00 -------- d-sh--w- c:\windows\system32\%APPDATA%
    2009-11-11 01:58 . 2009-08-14 13:27 2036736 ----a-w- c:\windows\system32\win32k.sys
    2009-11-11 01:57 . 2009-08-10 12:35 355328 ----a-w- c:\windows\system32\WSDApi.dll
    2009-11-11 01:54 . 2009-11-11 01:54 -------- d-----w- c:\programdata\Age of Empires 3 XPack Trial
    2009-11-11 01:46 . 2009-11-11 01:46 -------- d-----w- c:\program files\Common Files\Microsoft Games
    2009-11-11 01:13 . 2009-11-11 01:13 4096 d-----w- c:\program files\Auto Mouse Click
    2009-11-11 00:24 . 2009-11-11 00:24 -------- d-----w- c:\users\Luka\AppData\Roaming\InstallShield
    2009-11-10 21:03 . 2009-08-06 03:48 54632 ----a-w- c:\windows\system32\drivers\fssfltr.sys
    2009-11-10 03:12 . 2009-11-10 03:12 285478 ----a-r- c:\users\Luka\AppData\Roaming\Microsoft\Installer\{0298D87A-9095-4F05-BE2F-51C2D11E2435}\_F1DC7CF6DFDABC527C8FED.exe
    2009-11-10 03:12 . 2009-11-10 03:12 285478 ----a-r- c:\users\Luka\AppData\Roaming\Microsoft\Installer\{0298D87A-9095-4F05-BE2F-51C2D11E2435}\_6FEFF9B68218417F98F549.exe
    2009-11-10 03:12 . 2009-11-10 03:12 285478 ----a-r- c:\users\Luka\AppData\Roaming\Microsoft\Installer\{0298D87A-9095-4F05-BE2F-51C2D11E2435}\_2395B77B6C903FD39C6BC7.exe
    2009-11-10 03:12 . 2009-11-10 03:12 285478 ----a-r- c:\users\Luka\AppData\Roaming\Microsoft\Installer\{0298D87A-9095-4F05-BE2F-51C2D11E2435}\_21F3885A18D238E15AAE81.exe
    2009-11-10 03:11 . 2009-11-10 03:12 -------- d-----w- c:\programdata\SkiniTunes
    2009-11-10 02:46 . 2009-11-10 03:00 -------- d-----w- c:\users\Luka\AppData\Roaming\CD Art Display
    2009-11-10 02:46 . 2009-09-06 01:28 69632 ----a-w- c:\windows\cadSSaver.scr
    2009-11-10 02:46 . 2003-01-27 19:27 94208 ----a-w- c:\windows\system32\wmpuice.dll
    2009-11-10 02:46 . 2009-11-10 02:46 4096 d-----w- c:\program files\CD Art Display
    2009-11-10 01:47 . 2009-11-10 01:48 49152 d-----w- c:\program files\TuneUp Utilities 2009
    2009-11-08 17:03 . 2009-11-08 17:03 -------- d-----w- c:\programdata\LightScribe
    2009-11-08 16:35 . 2009-11-08 16:35 -------- d-----w- c:\program files\EA GAMES
    2009-11-08 16:10 . 2009-11-08 16:10 -------- d-----w- c:\users\Luka\AppData\Local\MicroVision Applications
    2009-11-08 14:43 . 2009-11-08 14:43 -------- d-----w- c:\program files\GameSpy Arcade
    2009-11-08 14:38 . 2009-11-08 14:38 -------- d-----w- c:\program files\Sierra
    2009-11-07 03:05 . 2009-11-07 03:05 98304 ----a-w- c:\windows\system32\CmdLineExt.dll
    2009-11-06 23:28 . 2009-11-06 23:28 -------- d-----w- c:\windows\system32\Futuremark
    2009-11-06 23:28 . 2007-08-20 16:05 27672 ----a-w- c:\windows\system32\drivers\Entech.sys
    2009-11-06 23:28 . 2009-11-06 23:28 -------- d-----w- c:\program files\Common Files\Futuremark Shared
    2009-11-06 21:00 . 2009-11-06 21:00 -------- d-----w- c:\users\Luka\AppData\Roaming\PeerNetworking
    2009-11-05 22:37 . 2009-11-11 00:03 -------- d-----w- c:\users\Temp\AppData\Roaming\BitMeter2
    2009-11-05 01:41 . 2009-11-05 01:41 -------- d-----w- c:\program files\uTorrent
    2009-11-04 23:02 . 2009-11-28 16:45 -------- d-----w- c:\users\Luka\AppData\Local\ApplicationHistory
    2009-11-04 23:02 . 2009-11-29 14:40 -------- d-----w- c:\programdata\Bitmeter2
    2009-11-04 23:02 . 2009-11-05 08:15 -------- d-----w- c:\users\Luka\AppData\Roaming\Bitmeter2
    2009-11-04 23:02 . 2009-11-04 23:02 -------- d-----w- c:\program files\Codebox
    2009-11-04 22:54 . 2009-11-04 22:54 -------- d-----w- c:\users\Luka\AppData\Roaming\Rokario
    2009-11-04 04:41 . 2009-11-04 04:43 -------- d-----w- c:\users\Luka\AppData\Roaming\ISP Monitor
    2009-11-04 04:41 . 2009-11-04 04:41 737280 ----a-w- c:\windows\iun6002.exe
    2009-11-04 04:41 . 2009-11-04 11:56 4096 d-----w- c:\program files\ISP Monitor
    2009-11-03 02:35 . 2009-11-03 02:34 816456 ----a-w- c:\programdata\Intuit\QuickBooks 2008\Components\DownloadQB17\Patch\qbpatch2.exe
    2009-11-02 21:36 . 2009-11-02 21:36 -------- d-----w- c:\program files\Activision
    2009-11-01 14:43 . 2009-11-05 00:25 22328 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
    2009-11-01 14:43 . 2009-11-05 00:25 22328 ----a-w- c:\users\Luka\AppData\Roaming\PnkBstrK.sys
    2009-11-01 13:49 . 2009-11-01 13:49 -------- d-sh--w- c:\windows\ftpcache
    2009-10-31 03:32 . 2009-10-31 03:32 1547264 ----a-w- c:\windows\is-49ORC.exe

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-11-29 15:10 . 2009-10-10 21:37 79248 ----a-w- c:\programdata\nvModes.dat
    2009-11-29 15:09 . 2009-07-16 04:26 4096 d-----w- c:\programdata\NVIDIA
    2009-11-29 03:15 . 2009-10-15 21:10 1356 ----a-w- c:\users\Luka\AppData\Local\d3d9caps.dat
    2009-11-28 22:04 . 2009-10-16 11:33 -------- d-----w- c:\program files\NCH Swift Sound
    2009-11-28 21:49 . 2009-09-27 20:45 4096 d-----w- c:\program files\McAfee
    2009-11-27 12:39 . 2009-10-24 12:31 4096 d-----w- c:\programdata\Spybot - Search & Destroy
    2009-11-25 18:57 . 2009-10-13 23:51 24576 d-----w- c:\users\Luka\AppData\Roaming\uTorrent
    2009-11-24 21:03 . 2009-10-24 12:31 8192 d-----w- c:\program files\Spybot - Search & Destroy
    2009-11-23 01:56 . 2006-12-28 19:41 8192 d--h--w- c:\program files\InstallShield Installation Information
    2009-11-22 04:07 . 2009-08-14 20:50 8192 d-----w- c:\users\Temp\AppData\Roaming\LimeWire
    2009-11-21 13:07 . 2009-08-02 22:26 96096 ----a-w- c:\users\Temp\AppData\Local\GDIPFONTCACHEV1.DAT
    2009-11-21 02:27 . 2009-10-11 22:51 96096 ----a-w- c:\users\Luka\AppData\Local\GDIPFONTCACHEV1.DAT
    2009-11-19 02:20 . 2009-10-12 16:30 -------- d-----w- c:\program files\Common Files\Stardock
    2009-11-17 11:48 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
    2009-11-17 11:47 . 2009-11-17 11:47 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
    2009-11-15 13:11 . 2009-10-07 00:07 16384 d-----w- c:\program files\CDBurnerXP
    2009-11-12 04:14 . 2006-12-28 19:48 8192 d-----w- c:\program files\Common Files\Adobe
    2009-11-12 03:50 . 2009-10-22 01:23 4096 d-----w- c:\users\Luka\AppData\Roaming\Download Manager
    2009-11-11 08:21 . 2006-11-02 11:18 4096 d-----w- c:\program files\Windows Mail
    2009-11-11 08:06 . 2009-07-16 16:55 12288 d-----w- c:\programdata\Microsoft Help
    2009-11-10 21:03 . 2009-07-16 04:42 -------- d-----w- c:\program files\Microsoft
    2009-11-10 21:02 . 2009-07-16 04:41 4096 d-----w- c:\program files\Windows Live
    2009-11-10 02:56 . 2009-10-12 16:42 4096 d-----w- c:\users\Luka\AppData\Roaming\Apple Computer
    2009-11-10 01:48 . 2009-10-25 16:46 604488 ----a-w- c:\windows\system32\TUProgSt.exe
    2009-11-10 01:48 . 2009-10-25 16:46 361288 ----a-w- c:\windows\system32\TuneUpDefragService.exe
    2009-11-09 04:03 . 2009-08-06 04:28 2445 ----a-w- c:\programdata\Intuit\QuickBooks 2008\qbbackup.sys
    2009-11-08 16:58 . 2009-09-11 23:21 4096 d-----w- c:\program files\Opera
    2009-11-08 16:42 . 2006-12-28 19:47 8192 d---a-w- c:\program files\Common Files\LightScribe
    2009-11-05 00:25 . 2009-10-11 11:37 103736 ----a-w- c:\windows\system32\PnkBstrB.exe
    2009-11-05 00:24 . 2009-10-11 11:35 66872 ----a-w- c:\windows\system32\PnkBstrA.exe
    2009-11-03 23:46 . 2009-11-03 23:46 75 ----a-w- c:\programdata\nvUnsupRes.dat
    2009-11-03 23:32 . 2009-10-31 02:55 4096 d-----w- c:\users\Luka\AppData\Roaming\LimeWire
    2009-11-03 00:29 . 2009-10-27 22:07 4096 d-----w- c:\program files\Adobe Media Player
    2009-10-31 05:30 . 2009-07-16 19:14 4096 d-----w- c:\program files\QuickTime
    2009-10-29 20:59 . 2009-10-29 20:59 -------- d-----w- c:\program files\Common Files\Adobe AIR
    2009-10-29 20:59 . 2009-11-22 15:29 38208 ----a-w- c:\users\Administrator\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
    2009-10-29 20:59 . 2009-10-29 20:59 38208 ----a-w- c:\users\Default\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
    2009-10-29 20:59 . 2009-10-29 20:50 38208 ----a-w- c:\users\Luka\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
    2009-10-29 20:55 . 2009-10-29 20:53 4096 d-----w- c:\program files\BannedStory
    2009-10-29 20:14 . 2009-10-29 20:14 94208 ----a-r- c:\users\Luka\AppData\Roaming\Microsoft\Installer\{31800004-6386-4999-A519-518F2D78D8F0}\python_icon.exe
    2009-10-27 22:25 . 2009-09-16 19:42 -------- d-----w- c:\programdata\FLEXnet
    2009-10-26 21:08 . 2009-10-26 21:08 -------- d-----w- c:\users\Temp\AppData\Roaming\vlc
    2009-10-26 19:44 . 2009-10-26 19:30 1510 ----a-w- c:\windows\Sketchpad Preferences.dat
    2009-10-26 12:24 . 2009-10-26 12:24 2149888 ----a-w- c:\windows\system32\python26.dll
    2009-10-25 22:39 . 2009-10-25 22:39 -------- d-----w- c:\users\Luka\AppData\Roaming\vlc
    2009-10-25 20:59 . 2009-10-25 20:59 274133 ----a-w- c:\windows\Icon Converter Plus Uninstaller.exe
    2009-10-25 20:58 . 2009-10-25 20:56 4096 d-----w- c:\program files\Common Files\Program4Pc
    2009-10-25 16:46 . 2009-10-25 16:46 -------- d-----w- c:\users\Luka\AppData\Roaming\TuneUp Software
    2009-10-25 16:45 . 2009-10-25 16:45 -------- d-----w- c:\programdata\TuneUp Software
    2009-10-25 16:45 . 2009-10-25 16:45 -------- d-sh--w- c:\programdata\{55A29068-F2CE-456C-9148-C869879E2357}
    2009-10-25 16:19 . 2009-10-25 16:19 7852 ----a-w- c:\windows\system32\mcdmsg7.dll
    2009-10-24 23:22 . 2009-10-24 17:28 -------- d-----w- c:\users\Luka\AppData\Roaming\DivX
    2009-10-24 22:52 . 2009-10-24 22:52 4096 d-----w- c:\program files\AC3Filter
    2009-10-24 22:42 . 2009-10-22 01:48 8192 d-----w- c:\program files\DivX
    2009-10-24 22:42 . 2009-09-27 03:58 4096 d-----w- c:\program files\Common Files\DivX Shared
    2009-10-24 14:55 . 2009-10-24 14:55 240128 ----a-w- c:\windows\system32\uxtheme.dll
    2009-10-24 14:55 . 2009-08-09 20:01 615424 ----a-w- c:\windows\system32\themeui.dll
    2009-10-24 02:30 . 2009-10-17 14:35 -------- d-----w- c:\program files\Lavalys
    2009-10-24 00:16 . 2009-10-24 00:16 -------- d-----w- c:\users\Luka\AppData\Roaming\Malwarebytes
    2009-10-23 23:57 . 2009-10-23 23:57 -------- d-----w- c:\users\Temp\AppData\Roaming\Malwarebytes
    2009-10-23 23:57 . 2009-10-23 23:57 4096 d-----w- c:\program files\Malwarebytes' Anti-Malware
    2009-10-23 23:57 . 2009-10-23 23:57 -------- d-----w- c:\programdata\Malwarebytes
    2009-10-22 01:49 . 2009-07-30 06:28 4096 d-----w- c:\program files\Common Files\PX Storage Engine
    2009-10-22 01:15 . 2009-10-22 01:09 -------- d-----w- c:\users\Luka\AppData\Roaming\Sony
    2009-10-22 01:11 . 2009-09-10 23:57 -------- d-----w- c:\program files\Sony
    2009-10-22 01:10 . 2009-10-22 01:10 -------- d-----w- c:\users\Luka\AppData\Roaming\Publish Providers
    2009-10-21 12:37 . 2009-10-21 12:37 -------- d-----w- c:\users\Luka\AppData\Roaming\SmarThru4
    2009-10-18 16:16 . 2009-10-18 16:16 2560 ----a-w- c:\windows\_MSRSTRT.EXE
    2009-10-18 14:23 . 2009-09-26 18:04 -------- d-----w- c:\programdata\Roxio
    2009-10-18 13:25 . 2009-10-18 13:23 4096 d-----w- c:\users\Luka\AppData\Roaming\muvee Technologies
    2009-10-18 13:23 . 2009-10-18 13:23 -------- d-----w- c:\programdata\muvee Technologies
    2009-10-18 13:22 . 2009-10-18 13:21 -------- d-----w- c:\users\Luka\AppData\Roaming\Roxio
    2009-10-18 02:33 . 2009-10-18 02:33 147940 ---ha-w- c:\windows\system32\mlfcache.dat
    2009-10-17 22:26 . 2009-10-17 22:26 -------- d-----w- c:\program files\Common Files\EasyInfo
    2009-10-17 20:43 . 2009-10-17 20:43 -------- d-----w- c:\program files\AMD
    2009-10-17 17:07 . 2009-10-16 11:54 -------- d-----w- c:\programdata\NCH Swift Sound
    2009-10-16 22:55 . 2009-10-16 22:55 -------- d-----w- c:\users\Luka\AppData\Roaming\Canneverbe_Limited
    2009-10-16 11:35 . 2009-10-16 11:31 -------- d-----w- c:\program files\NCH Software
    2009-10-16 11:33 . 2009-10-16 11:33 -------- d-----w- c:\programdata\NCH Software
    2009-10-16 11:33 . 2009-10-16 11:33 -------- d-----w- c:\users\Luka\AppData\Roaming\NCH Swift Sound
    2009-10-14 19:51 . 2006-12-28 19:49 28672 d-----w- c:\program files\Microsoft Works
    2009-10-14 19:38 . 2009-10-13 20:26 -------- d-----w- c:\users\Luka\AppData\Roaming\DAEMON Tools Lite
    2009-10-14 00:54 . 2009-10-14 00:39 4096 d-----w- c:\users\Luka\AppData\Roaming\GetRightToGo
    2009-10-14 00:38 . 2009-10-14 00:36 -------- d-----w- c:\program files\Pinnacle
    2009-10-14 00:36 . 2009-10-14 00:36 -------- d-----w- c:\programdata\Pinnacle
    2009-10-13 23:23 . 2009-10-13 23:22 4096 d-----w- c:\program files\DAEMON Tools Lite
    2009-10-13 23:20 . 2009-10-10 16:33 -------- d-----w- c:\programdata\DriverScanner
    2009-10-13 01:50 . 2009-10-12 17:48 4096 d-----w- c:\program files\iTunes
    2009-10-12 17:49 . 2009-10-12 17:48 -------- d-----w- c:\programdata\{755AC846-7372-4AC8-8550-C52491DAA8BD}
    2009-10-12 17:48 . 2009-10-12 17:48 -------- d-----w- c:\program files\iPod
    2009-10-12 17:48 . 2009-07-16 18:58 -------- d-----w- c:\program files\Common Files\Apple
    2009-10-12 17:27 . 2009-10-12 17:27 79144 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.0.1.8\SetupAdmin.exe
    2009-10-12 17:06 . 2009-10-12 17:06 -------- d-----w- c:\program files\temp
    2009-10-12 03:36 . 2009-10-12 03:36 -------- d-----w- c:\program files\QS
    2009-10-12 03:36 . 2009-10-12 03:36 -------- d-----w- c:\users\Luka\AppData\Roaming\TeamViewer
    2009-10-12 01:03 . 2009-10-12 01:00 4096 d-----w- c:\users\Luka\AppData\Roaming\Notepad++
    2009-10-12 01:03 . 2009-10-10 21:27 4096 d-----w- c:\program files\Notepad++
    2009-10-11 22:53 . 2009-10-11 22:53 -------- d-----w- c:\users\Luka\AppData\Roaming\Hewlett-Packard
    2009-10-11 14:20 . 2009-10-03 00:39 4096 d-----w- c:\program files\FL Studio
    2009-10-11 14:19 . 2009-09-27 15:57 4096 d-----w- c:\users\Temp\AppData\Roaming\Any Video Converter
    .

    ------- Sigcheck -------

    [-] 2009-10-24 . 690D53BD10A804BB6D0A772D1C0E6907 . 247296 . . [6.0.6000.16386] . . c:\windows\System32\shsvcs.dll
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\sp]
    @= "{96AFBE69-C3B0-4b00-8578-D933D2896EE2} "
    [HKEY_CLASSES_ROOT\CLSID\{96AFBE69-C3B0-4b00-8578-D933D2896EE2}]
    2009-11-28 11:20 57344 ----a-w- c:\programdata\SP\sp.DLL

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "DAEMON Tools Lite "= "c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
    "LightScribe Control Panel "= "c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2009-10-16 2363392]
    "WMPNSCFG "= "c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "amd_dc_opt "= "c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2007-07-23 77824]
    "Malwarebytes Anti-Malware (reboot) "= "c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
    "WinampAgent "= "c:\program files\Winamp\winampa.exe" [2009-07-01 37888]
    "SpybotSnD "= "c:\program files\Spybot - Search & Destroy\SpybotSD.exe" [2009-01-26 5365592]
    "Malwarebytes' Anti-Malware "= "c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2009-09-10 420176]
    "egui "= "c:\program files\ESET\ESET Smart Security\egui.exe" [2009-11-16 2054360]
    "RtHDVCpl "= "RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-01-15 4874240]

    c:\users\Temp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    OneNote 2007 Screen Clipper and Launcher.lnk.disabled [2009-10-9 1073]

    c:\users\Luka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    Rainmeter - Shortcut.lnk - c:\users\Luka\Downloads\Programs\Rainmeter\Rainmeter.exe [2009-11-1 119296]

    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    Bitmeter2.lnk - c:\program files\Codebox\BitMeter\BitMeter2.exe [2009-6-21 1462272]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorUser "= 2 (0x2)
    "EnableUIADesktopToggle "= 0 (0x0)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
    "NoChangeAnimation "= 0 (0x0)
    "NoStrCmpLogical "= 0 (0x0)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\MCPClient]
    2005-01-31 19:13 49152 ----a-w- c:\progra~1\COMMON~1\Stardock\MCPStub.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "mixer1 "=wdmaud.drv

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
    @= "Service "

    [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Connections.lnk]
    path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Connections.lnk
    backup=c:\windows\pss\HP Connections.lnk.CommonStartup
    backupExtension=.CommonStartup

    [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
    path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
    backup=c:\windows\pss\QuickBooks Update Agent.lnk.CommonStartup
    backupExtension=.CommonStartup

    [HKLM\~\startupfolder\C:^Users^Luka^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Client Default.lnk]
    path=c:\users\Luka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Client Default.lnk
    backup=c:\windows\pss\Client Default.lnk.Startup
    backupExtension=.Startup

    [HKLM\~\startupfolder\C:^Users^Luka^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
    path=c:\users\Luka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LimeWire On Startup.lnk
    backup=c:\windows\pss\LimeWire On Startup.lnk.Startup
    backupExtension=.Startup

    [HKLM\~\startupfolder\C:^Users^Luka^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Stardock ObjectDock.lnk]
    path=c:\users\Luka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Stardock ObjectDock.lnk
    backup=c:\windows\pss\Stardock ObjectDock.lnk.Startup
    backupExtension=.Startup

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
    "Sidebar "=c:\program files\Windows Sidebar\sidebar.exe /autoRun

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
    "iTunesHelper "= "c:\program files\iTunes\iTunesHelper.exe "
    "QuickTime Task "= "c:\program files\QuickTime\QTTask.exe" -atboottime
    "HP Health Check Scheduler "=c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring "=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring "=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring "=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
    "VistaSp2 "=hex(b):72,57,4d,7c,56,1b,ca,01

    R1 ehdrv;ehdrv;c:\windows\System32\drivers\ehdrv.sys [16/11/2009 9:03 AM 108792]
    R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [16/11/2009 9:04 AM 735960]
    R2 epfwwfp;epfwwfp;c:\windows\System32\drivers\epfwwfp.sys [16/11/2009 9:06 AM 38240]
    R2 ISPMonitorSrv;ISP Monitor;c:\program files\ISP Monitor\ISPMonitorSrv.exe [22/08/2007 6:55 PM 36864]
    R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [23/10/2009 6:57 PM 269648]
    R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [24/10/2009 7:32 AM 1153368]
    R2 SPService;SPService;c:\windows\system32\svchost.exe -k netsvc [18/07/2009 12:22 PM 21504]
    R2 SSPORT;SSPORT;c:\windows\System32\drivers\SSPORT.sys [03/02/2009 1:47 PM 5120]
    R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [17/08/2009 12:32 AM 239648]
    R3 MBAMProtector;MBAMProtector;c:\windows\System32\drivers\mbam.sys [23/10/2009 6:57 PM 19160]
    S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [09/10/2009 5:33 PM 133104]
    S2 Serv;Serv; "c:\krbgix.exe" --> c:\kRBgix.exe [?]
    S2 WinRM Licensing Service;Windows Remote Management (WS-Management) WinRM Licensing Service;c:\windows\system32\aaclientr.exe srv --> c:\windows\system32\aaclientr.exe srv [?]
    S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [18/07/2009 12:22 PM 21504]
    S3 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [10/11/2009 4:03 PM 54632]
    S3 fsssvc;Windows Live Family Safety Service;c:\program files\Windows Live\Family Safety\fsssvc.exe [05/08/2009 10:48 PM 704864]
    S3 RDPDISPM;RDPDISPM;c:\windows\System32\drivers\rdpdispm.sys [02/10/2009 5:13 PM 9040]
    S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\sqladhlp.exe [10/07/2008 7:28 PM 47128]
    S4 RsFx0102;RsFx0102 Driver;c:\windows\System32\drivers\RsFx0102.sys [10/07/2008 1:49 AM 242712]
    S4 sptd;sptd;c:\windows\System32\drivers\sptd.sys [26/09/2009 9:44 AM 721904]
    S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [30/03/2009 2:23 AM 366936]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
    netsvc REG_MULTI_SZ SPService 2

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
    UxTuneUp

    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
    "c:\program files\Common Files\LightScribe\LSRunOnce.exe "

    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6301493A-4A41-F704-18F6-554AEC18DBA5}]
    c:\program files\Windows\windll.exe s
    .
    Contents of the 'Scheduled Tasks' folder

    2009-11-29 c:\windows\Tasks\1-Click Maintenance.job
    - c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2009-07-16 15:54]

    2009-11-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-10-09 22:32]

    2009-11-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-10-09 22:32]

    2009-11-29 c:\windows\Tasks\Malwarebytes' Scheduled Scan for Luka.job
    - c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2009-10-23 18:53]

    2009-11-29 c:\windows\Tasks\Malwarebytes' Scheduled Update for Luka.job
    - c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2009-10-23 18:53]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://google.ca/
    mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_CA&c=71&bd=Pavilion&pf=desktop
    mWindow Title =
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
    TCP: {10AA17A2-D126-48AA-83FE-D0C879DD6E86} = 192.168.2.1
    DPF: {D1278801-B2C0-4332-BD3E-2F64D2204EDF} - hxxps://www.mesh.com/0.9.4014.13/TSWeb.cab
    FF - ProfilePath - c:\users\Luka\AppData\Roaming\Mozilla\Firefox\Profiles\pxn860zz.default\
    FF - prefs.js: browser.startup.homepage - www.google.ca
    FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
    FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
    FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
    FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
    FF - plugin: c:\users\Luka\Downloads\Programs\VLC\npvlc.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
    .
    - - - - ORPHANS REMOVED - - - -

    SafeBoot-mcmscsvc
    SafeBoot-MCODS
    AddRemove-HijackThis - c:\users\Luka\Downloads\HijackThis.exe
    AddRemove-NVIDIA Drivers - c:\windows\system32\nvuninst.exe UninstallGUI
    AddRemove-CursorFX - c:\users\Luka\AppData\Local\{DE032019-B933-4DF4-9174-48C52613DA13}\CursorFX_setup.exe REMOVE=TRUE MODIFY=FALSE



    **************************************************************************
    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files:

    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial "=dword:00000000
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'Explorer.exe'(3856)
    c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\windows\system32\nvvsvc.exe
    c:\windows\system32\nvvsvc.exe
    c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    c:\program files\Bonjour\mDNSResponder.exe
    c:\program files\Common Files\LightScribe\LSSrvc.exe
    c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
    c:\program files\CDBurnerXP\NMSAccessU.exe
    c:\windows\system32\PnkBstrA.exe
    c:\windows\system32\PnkBstrB.exe
    c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    c:\users\Luka\Downloads\Programs\Alcohol 120\StarWind\StarWindService.exe
    c:\windows\System32\TUProgSt.exe
    c:\windows\system32\DRIVERS\xaudio.exe
    c:\windows\system32\WUDFHost.exe
    c:\program files\Windows Media Player\wmpnetwk.exe
    c:\program files\Hewlett-Packard\HP Health Check\hphc_service.exe
    .
    **************************************************************************
    .
    Completion time: 2009-11-29 10:25 - machine was rebooted
    ComboFix-quarantined-files.txt 2009-11-29 15:25

    Pre-Run: 138,665,644,032 bytes free
    Post-Run: 146,645,532,672 bytes free

    - - End Of File - - 0606D16FC48910D5FFDE515F18688D99

    HJT Logfile
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 10:32:16 AM, on 29/11/2009
    Platform: Windows Vista SP2 (WinNT 6.00.1906)
    MSIE: Internet Explorer v8.00 (8.00.6001.18828)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\system32\taskeng.exe
    C:\WINDOWS\RtHDVCpl.exe
    C:\Program Files\ESET\ESET Smart Security\egui.exe
    C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\Codebox\BitMeter\BitMeter2.exe
    C:\Windows\Explorer.exe
    C:\Windows\system32\notepad.exe
    C:\Users\Luka\Downloads\Programs\Firefox\firefox.exe
    C:\Users\Luka\Downloads\Programs\Rainmeter\Rainmeter.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Users\Luka\Downloads\Programs\HJThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.ca/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_CA&c=71&bd=Pavilion&pf=desktop
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
    O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
    O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe "
    O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
    O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
    O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
    O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
    O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - Startup: Rainmeter - Shortcut.lnk = Luka\Downloads\Programs\Rainmeter\Rainmeter.exe
    O4 - Global Startup: Bitmeter2.lnk = C:\Program Files\Codebox\BitMeter\BitMeter2.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
    O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
    O16 - DPF: {D1278801-B2C0-4332-BD3E-2F64D2204EDF} (Windows Live Mesh Upload Tool) - https://www.mesh.com/0.9.4014.13/TSWeb.cab
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{10AA17A2-D126-48AA-83FE-D0C879DD6E86}: NameServer = 192.168.2.1
    O17 - HKLM\System\CS1\Services\Tcpip\..\{10AA17A2-D126-48AA-83FE-D0C879DD6E86}: NameServer = 192.168.2.1
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
    O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
    O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
    O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: ISP Monitor (ISPMonitorSrv) - How2 Studios - C:\Program Files\ISP Monitor\ISPMonitorSrv.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
    O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
    O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
    O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
    O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
    O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
    O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    O23 - Service: Serv - Unknown owner - C:\kRBgix.exe (file missing)
    O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Users\Luka\Downloads\Programs\Alcohol 120\StarWind\StarWindService.exe
    O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
    O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
    O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Windows\System32\TuneUpDefragService.exe
    O23 - Service: @%SystemRoot%\System32\TUProgSt.exe,-1 (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\Windows\System32\TUProgSt.exe
    O23 - Service: Windows Remote Management (WS-Management) WinRM Licensing Service (WinRM Licensing Service) - Unknown owner - C:\Windows\system32\aaclientr.exe (file missing)
    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

    --
    End of file - 7903 bytes
     
  12. 2009/11/29
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    1. Please open Notepad
    • Click Start , then Run
    • Type notepad .exe in the Run Box.

    2. Now copy/paste the entire content of the codebox below into the Notepad window:

    Code:
    File::
    c:\programdata\SP\sp.DLL
    c:\users\Luka\AppData\Roaming\Microsoft\Windows\Recent\ANTIGEN.exe
    c:\users\Luka\AppData\Roaming\Microsoft\Windows\Recent\SICKBOY.drv
    c:\users\Luka\AppData\Roaming\Microsoft\Windows\Recent\PE.dll
    c:\users\Luka\AppData\Roaming\Microsoft\Windows\Recent\PE.sys
    c:\users\Luka\AppData\Roaming\Microsoft\Windows\Recent\tempdoc.exe
    c:\users\Luka\AppData\Roaming\Microsoft\Windows\Recent\sld.dll
    c:\users\Luka\AppData\Roaming\Microsoft\Windows\Recent\eb.drv
    c:\users\Luka\AppData\Roaming\Microsoft\Windows\Recent\ppal.sys
    c:\users\Luka\AppData\Roaming\Microsoft\Windows\Recent\exec.sys
    c:\users\Luka\AppData\Roaming\Microsoft\Windows\Recent\snl2w.exe
    c:\users\Luka\AppData\Roaming\Microsoft\Windows\Recent\tjd.sys
    c:\users\Luka\AppData\Roaming\Microsoft\Windows\Recent\delfile.drv
    c:\windows\is-051EA.exe
    c:\windows\cadSSaver.scr
    c:\windows\iun6002.exe
    c:\windows\is-49ORC.exe
    c:\kRBgix.exe
    c:\windows\system32\aaclientr.exe
    c:\program files\Windows\windll.exe
    
    
    Folder::
    c:\programdata\SP
    c:\program files\McAfee
    
    
    Driver::
    Serv
    WinRM Licensing Service
    
    Registry::
    [-HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6301493A-4A41-F704-18F6-554AEC18DBA5}]
    
    RegLockDel::
    
    

    3. Save the above as CFScript.txt

    4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

    [​IMG]


    5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
    • Combofix.txt
    • A new HijackThis log.
     
  13. 2009/11/29
    insaniity

    insaniity Inactive Thread Starter

    Joined:
    2009/11/28
    Messages:
    13
    Likes Received:
    0
    ComboFix
    ComboFix 09-11-29.01 - Luka 29/11/2009 13:24.2.2 - x86
    Microsoft® Windows Vistaâ„¢ Home Premium 6.0.6002.2.1252.2.1033.18.1918.1045 [GMT -5:00]
    Running from: c:\users\Luka\Downloads\ComboFix.exe
    Command switches used :: c:\users\Luka\Desktop\CFScript.txt
    SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
    * Resident AV is active


    FILE ::
    "c:\kRBgix.exe "
    "c:\program files\Windows\windll.exe "
    "c:\programdata\SP\sp.DLL "
    "c:\users\Luka\AppData\Roaming\Microsoft\Windows\Recent\ANTIGEN.exe "
    "c:\users\Luka\AppData\Roaming\Microsoft\Windows\Recent\delfile.drv "
    "c:\users\Luka\AppData\Roaming\Microsoft\Windows\Recent\eb.drv "
    "c:\users\Luka\AppData\Roaming\Microsoft\Windows\Recent\exec.sys "
    "c:\users\Luka\AppData\Roaming\Microsoft\Windows\Recent\PE.dll "
    "c:\users\Luka\AppData\Roaming\Microsoft\Windows\Recent\PE.sys "
    "c:\users\Luka\AppData\Roaming\Microsoft\Windows\Recent\ppal.sys "
    "c:\users\Luka\AppData\Roaming\Microsoft\Windows\Recent\SICKBOY.drv "
    "c:\users\Luka\AppData\Roaming\Microsoft\Windows\Recent\sld.dll "
    "c:\users\Luka\AppData\Roaming\Microsoft\Windows\Recent\snl2w.exe "
    "c:\users\Luka\AppData\Roaming\Microsoft\Windows\Recent\tempdoc.exe "
    "c:\users\Luka\AppData\Roaming\Microsoft\Windows\Recent\tjd.sys "
    "c:\windows\cadSSaver.scr "
    "c:\windows\is-051EA.exe "
    "c:\windows\is-49ORC.exe "
    "c:\windows\iun6002.exe "
    "c:\windows\system32\aaclientr.exe "
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\program files\McAfee
    c:\program files\McAfee\MBK\ArbusComLib.dll
    c:\program files\McAfee\MBK\mback.chm
    c:\program files\McAfee\MBK\MBKAlert.dll
    c:\program files\McAfee\MBK\MBKLaunch.exe
    c:\program files\McAfee\MBK\MBKProv.dll
    c:\program files\McAfee\MBK\MBKRegister.exe
    c:\program files\McAfee\MBK\mbksbt.inf
    c:\program files\McAfee\MBK\Readme.htm
    c:\program files\McAfee\MHN\mhnsbt.inf
    c:\program files\McAfee\MHN\subst.inf
    c:\program files\McAfee\MPF\1033\instLD.inf
    c:\program files\McAfee\MPF\1033\L10N.dll
    c:\program files\McAfee\MPF\1033\mpfHelp.inf
    c:\program files\McAfee\MPF\1033\mpfloc.inf
    c:\program files\McAfee\MPF\1033\Readme.htm
    c:\program files\McAfee\MPF\1033\subst.inf
    c:\program files\McAfee\MPF\data\1033\ids.xml
    c:\program files\McAfee\MPF\data\1033\inbound.xml
    c:\program files\McAfee\MPF\data\1033\outbound.xml
    c:\program files\McAfee\MPF\data\1033\twerp.dat
    c:\program files\McAfee\MPF\data\1033\twerp.idx
    c:\program files\McAfee\MPF\data\mvtx\settings.idx
    c:\program files\McAfee\MPF\mpfsbt.inf
    c:\program files\McAfee\MPF\mpfuc.dll
    c:\program files\McAfee\MPF\mpfuc.inf
    c:\program files\McAfee\MPF\mpfui.inf
    c:\program files\McAfee\MPS\mpsli.inf
    c:\program files\McAfee\MPS\mpssbt.inf
    c:\program files\McAfee\MPS\mpsuc.dll
    c:\program files\McAfee\MPS\mpsuc.inf
    c:\program files\McAfee\MPS\mpsui.inf
    c:\program files\McAfee\MPS\substli.inf
    c:\program files\McAfee\MQC\MRU.bak
    c:\program files\McAfee\MQC\qcconf.bak
    c:\program files\McAfee\MSC\1033\Help\FWBlock.htm
    c:\program files\McAfee\MSC\1033\Help\mpf.chm
    c:\program files\McAfee\MSC\1033\Help\msk.chm
    c:\program files\McAfee\MSC\1033\Help\nmc.chm
    c:\program files\McAfee\MSC\1033\Help\vs.chm
    c:\program files\McAfee\MSC\1033\instLDNMC.inf
    c:\program files\McAfee\MSC\1033\McNDCoR.dll
    c:\program files\McAfee\MSC\1033\McNDLor.dll
    c:\program files\McAfee\MSC\1033\McNmcCoR.dll
    c:\program files\McAfee\MSC\1033\McNmcLoR.dll
    c:\program files\McAfee\MSC\1033\ndLD.inf
    c:\program files\McAfee\MSC\1033\nmchelp.inf
    c:\program files\McAfee\MSC\1033\nmclang.inf
    c:\program files\McAfee\MSC\1033\nmcoem.inf
    c:\program files\McAfee\MSC\1033\nmcpstld.inf
    c:\program files\McAfee\MSC\Help\mbk.chm
    c:\program files\McAfee\MSC\langmap.dat
    c:\program files\McAfee\MSC\langsel.exe
    c:\program files\McAfee\MSC\mcactwiz.dll
    c:\program files\McAfee\MSC\mcactwiz.ini
    c:\program files\McAfee\MSC\McNDSv.dll
    c:\program files\McAfee\MSC\mcoemmap.ini
    c:\program files\McAfee\MSC\mcoemmgr.exe
    c:\program files\McAfee\MSC\NMC\nmcsubst.inf
    c:\program files\McAfee\MSC\NMC\readme.htm
    c:\program files\McAfee\MSC\nmcLD.inf
    c:\program files\McAfee\MSC\nmcuicfg.dat
    c:\program files\McAfee\MSC\oem\0-906\mcactui.dll
    c:\program files\McAfee\MSC\oem\0-906\mcactwiz_ld.dll
    c:\program files\McAfee\MSC\oem\0-906\mccobres.dll
    c:\program files\McAfee\MSC\oem\0-906\oemcfg.dat
    c:\program files\McAfee\MSC\oeminfo\{ba6fdfe0-6d8b-4dee-8059-c21b5f674e5e}\en-US\regurl.inf
    c:\program files\McAfee\MSC\oeminfo\MBK\en-US\0-906\mbkoem.inf
    c:\program files\McAfee\MSC\oeminfo\MBK\en-US\0-906\mbkreg.cab
    c:\program files\McAfee\MSC\oeminfo\MBK\en-US\0-906\mbkrgw.inf
    c:\program files\McAfee\MSC\oeminfo\MBK\en-US\0-906\mbksbt.cab
    c:\program files\McAfee\MSC\oeminfo\MHN\en-US\0-906\mhnfs.inf
    c:\program files\McAfee\MSC\oeminfo\MHN\en-US\0-906\mhnoem.inf
    c:\program files\McAfee\MSC\oeminfo\MHN\en-US\0-906\mhnreg.cab
    c:\program files\McAfee\MSC\oeminfo\MHN\en-US\0-906\mhnrgw.inf
    c:\program files\McAfee\MSC\oeminfo\MHN\en-US\0-906\mhnsbt.cab
    c:\program files\McAfee\MSC\oeminfo\MHN\en-US\0-906\mhnub.inf
    c:\program files\McAfee\MSC\oeminfo\MHN\en-US\0-906\mhnus.inf
    c:\program files\McAfee\MSC\oeminfo\MHN\en-US\0-906\subst.cab
    c:\program files\McAfee\MSC\oeminfo\MPF\en-US\0-906\mpfdis.cab
    c:\program files\McAfee\MSC\oeminfo\MPF\en-US\0-906\mpfena.cab
    c:\program files\McAfee\MSC\oeminfo\MPF\en-US\0-906\mpffc.cab
    c:\program files\McAfee\MSC\oeminfo\MPF\en-US\0-906\mpffs.inf
    c:\program files\McAfee\MSC\oeminfo\MPF\en-US\0-906\mpflang.cab
    c:\program files\McAfee\MSC\oeminfo\MPF\en-US\0-906\mpfoem.inf
    c:\program files\McAfee\MSC\oeminfo\MPF\en-US\0-906\mpfreg.cab
    c:\program files\McAfee\MSC\oeminfo\MPF\en-US\0-906\mpfrgw.inf
    c:\program files\McAfee\MSC\oeminfo\MPF\en-US\0-906\mpfsbt.cab
    c:\program files\McAfee\MSC\oeminfo\MPF\en-US\0-906\mpfub.inf
    c:\program files\McAfee\MSC\oeminfo\MPF\en-US\0-906\mpfuc.cab
    c:\program files\McAfee\MSC\oeminfo\MPF\en-US\0-906\mpfui.cab
    c:\program files\McAfee\MSC\oeminfo\MPF\en-US\0-906\mpfus.inf
    c:\program files\McAfee\MSC\oeminfo\MPF\en-US\0-906\subst.cab
    c:\program files\McAfee\MSC\oeminfo\MPS\en-US\0-906\mpsdis.cab
    c:\program files\McAfee\MSC\oeminfo\MPS\en-US\0-906\mpsena.cab
    c:\program files\McAfee\MSC\oeminfo\MPS\en-US\0-906\mpsfc.cab
    c:\program files\McAfee\MSC\oeminfo\MPS\en-US\0-906\mpsfs.inf
    c:\program files\McAfee\MSC\oeminfo\MPS\en-US\0-906\mpslang.cab
    c:\program files\McAfee\MSC\oeminfo\MPS\en-US\0-906\mpsoem.inf
    c:\program files\McAfee\MSC\oeminfo\MPS\en-US\0-906\mpsreg.cab
    c:\program files\McAfee\MSC\oeminfo\MPS\en-US\0-906\mpsrgw.inf
    c:\program files\McAfee\MSC\oeminfo\MPS\en-US\0-906\mpsrmv.inf
    c:\program files\McAfee\MSC\oeminfo\MPS\en-US\0-906\mpssbt.cab
    c:\program files\McAfee\MSC\oeminfo\MPS\en-US\0-906\mpsub.inf
    c:\program files\McAfee\MSC\oeminfo\MPS\en-US\0-906\mpsuc.cab
    c:\program files\McAfee\MSC\oeminfo\MPS\en-US\0-906\mpsui.cab
    c:\program files\McAfee\MSC\oeminfo\MPS\en-US\0-906\mpsus.inf
    c:\program files\McAfee\MSC\oeminfo\MPS\en-US\0-906\subst.cab
    c:\program files\McAfee\MSC\oeminfo\MSAD\en-US\0-906\msadfs.inf
    c:\program files\McAfee\MSC\oeminfo\MSAD\en-US\0-906\msadoem.inf
    c:\program files\McAfee\MSC\oeminfo\MSAD\en-US\0-906\msadreg.cab
    c:\program files\McAfee\MSC\oeminfo\MSAD\en-US\0-906\msadrgw.inf
    c:\program files\McAfee\MSC\oeminfo\MSAD\en-US\0-906\msadub.inf
    c:\program files\McAfee\MSC\oeminfo\MSAD\en-US\0-906\msaduc.cab
    c:\program files\McAfee\MSC\oeminfo\MSAD\en-US\0-906\msadus.inf
    c:\program files\McAfee\MSC\oeminfo\MSC\en-US\0-906\mcactui.cab
    c:\program files\McAfee\MSC\oeminfo\MSC\en-US\0-906\mcawlang.cab
    c:\program files\McAfee\MSC\oeminfo\MSC\en-US\0-906\mnadis.cab
    c:\program files\McAfee\MSC\oeminfo\MSC\en-US\0-906\mnaena.cab
    c:\program files\McAfee\MSC\oeminfo\MSC\en-US\0-906\mscdis.cab
    c:\program files\McAfee\MSC\oeminfo\MSC\en-US\0-906\mscena.cab
    c:\program files\McAfee\MSC\oeminfo\MSC\en-US\0-906\mscoem.inf
    c:\program files\McAfee\MSC\oeminfo\MSC\en-US\0-906\mscoemf.inf
    c:\program files\McAfee\MSC\oeminfo\MSC\en-US\0-906\mscoemu.inf
    c:\program files\McAfee\MSC\oeminfo\MSC\en-US\0-906\mscpostu.inf
    c:\program files\McAfee\MSC\oeminfo\MSC\en-US\0-906\mscsbt.cab
    c:\program files\McAfee\MSC\oeminfo\MSC\en-US\0-906\nmcsubst.cab
    c:\program files\McAfee\MSC\oeminfo\MSC\en-US\0-906\oemcfg.cab
    c:\program files\McAfee\MSC\oeminfo\MSC\en-US\0-906\qclan.inf
    c:\program files\McAfee\MSC\oeminfo\MSC\en-US\0-906\subst.cab
    c:\program files\McAfee\MSC\oeminfo\MSK\en-US\0-906\mskdis.cab
    c:\program files\McAfee\MSC\oeminfo\MSK\en-US\0-906\mskena.cab
    c:\program files\McAfee\MSC\oeminfo\MSK\en-US\0-906\mskfc.cab
    c:\program files\McAfee\MSC\oeminfo\MSK\en-US\0-906\mskfs.inf
    c:\program files\McAfee\MSC\oeminfo\MSK\en-US\0-906\msklang.cab
    c:\program files\McAfee\MSC\oeminfo\MSK\en-US\0-906\mskoem.inf
    c:\program files\McAfee\MSC\oeminfo\MSK\en-US\0-906\mskreg.cab
    c:\program files\McAfee\MSC\oeminfo\MSK\en-US\0-906\mskrgw.inf
    c:\program files\McAfee\MSC\oeminfo\MSK\en-US\0-906\msksbt.cab
    c:\program files\McAfee\MSC\oeminfo\MSK\en-US\0-906\mskub.inf
    c:\program files\McAfee\MSC\oeminfo\MSK\en-US\0-906\mskuc.cab
    c:\program files\McAfee\MSC\oeminfo\MSK\en-US\0-906\mskui.cab
    c:\program files\McAfee\MSC\oeminfo\MSK\en-US\0-906\mskus.inf
    c:\program files\McAfee\MSC\oeminfo\MSK\en-US\0-906\subst.cab
    c:\program files\McAfee\MSC\oeminfo\VSO\en-US\0-906\subst.cab
    c:\program files\McAfee\MSC\oeminfo\VSO\en-US\0-906\vsodis.cab
    c:\program files\McAfee\MSC\oeminfo\VSO\en-US\0-906\vsoena.cab
    c:\program files\McAfee\MSC\oeminfo\VSO\en-US\0-906\vsofc.cab
    c:\program files\McAfee\MSC\oeminfo\VSO\en-US\0-906\vsofs.inf
    c:\program files\McAfee\MSC\oeminfo\VSO\en-US\0-906\vsooem.inf
    c:\program files\McAfee\MSC\oeminfo\VSO\en-US\0-906\vsoreg.cab
    c:\program files\McAfee\MSC\oeminfo\VSO\en-US\0-906\vsorgw.inf
    c:\program files\McAfee\MSC\oeminfo\VSO\en-US\0-906\vsosbt.cab
    c:\program files\McAfee\MSC\oeminfo\VSO\en-US\0-906\vsoub.inf
    c:\program files\McAfee\MSC\oeminfo\VSO\en-US\0-906\vsouc.cab
    c:\program files\McAfee\MSC\oeminfo\VSO\en-US\0-906\vsoui.cab
    c:\program files\McAfee\MSC\oeminfo\VSO\en-US\0-906\vsous.inf
    c:\program files\McAfee\MSC\subst.inf
    c:\program files\McAfee\MSK\1033\instLD.inf
    c:\program files\McAfee\MSK\1033\mskhlp.inf
    c:\program files\McAfee\MSK\1033\mskres.dll
    c:\program files\McAfee\MSK\1033\mskres.inf
    c:\program files\McAfee\MSK\1033\mskui.dll
    c:\program files\McAfee\MSK\1033\mskuicfg.dat
    c:\program files\McAfee\MSK\1033\mskupd.xml
    c:\program files\McAfee\MSK\1033\mskwm.xml
    c:\program files\McAfee\MSK\1033\ReadMe.htm
    c:\program files\McAfee\MSK\1033\subst.inf
    c:\program files\McAfee\MSK\apf\apf
    c:\program files\McAfee\MSK\Config\core\3416\config.lua
    c:\program files\McAfee\MSK\Config\core\3416\core.lua
    c:\program files\McAfee\MSK\Config\core\3416\core.rgx
    c:\program files\McAfee\MSK\Config\core\3416\custom.lua
    c:\program files\McAfee\MSK\Config\core\3416\dometa.lua
    c:\program files\McAfee\MSK\Config\core\3416\filter.lua
    c:\program files\McAfee\MSK\Config\core\3416\main.lua
    c:\program files\McAfee\MSK\Config\core\3416\manifest
    c:\program files\McAfee\MSK\Config\core\3416\overrides.lua
    c:\program files\McAfee\MSK\Config\core\3416\phish.lua
    c:\program files\McAfee\MSK\Config\core\3416\received.lua
    c:\program files\McAfee\MSK\Config\core\3416\tlds.lua
    c:\program files\McAfee\MSK\Config\core\3416\utils.lua
    c:\program files\McAfee\MSK\Config\cstreams\75288\cstreams.lua
    c:\program files\McAfee\MSK\Config\cstreams\75288\cstreams.rgx
    c:\program files\McAfee\MSK\Config\cstreams\75288\manifest
    c:\program files\McAfee\MSK\Config\mas_ui_0
    c:\program files\McAfee\MSK\Config\rbl\5\manifest
    c:\program files\McAfee\MSK\Config\rbl\5\rbl.lua
    c:\program files\McAfee\MSK\Config\sentag\25088\manifest
    c:\program files\McAfee\MSK\Config\sentag\25088\sentag.lua
    c:\program files\McAfee\MSK\Config\sentag\25088\sentence.lut
    c:\program files\McAfee\MSK\Config\sentag\25088\tags.lut
    c:\program files\McAfee\MSK\msksbt.inf
    c:\program files\McAfee\MSK\mskuc.dll
    c:\program files\McAfee\MSK\mskuc.inf
    c:\program files\McAfee\SiteAdvisor\apengine.dll
    c:\program files\McAfee\SiteAdvisor\cntscan.dll
    c:\program files\McAfee\SiteAdvisor\content.dat
    c:\program files\McAfee\SiteAdvisor\elist.dat
    c:\program files\McAfee\SiteAdvisor\mcfrmwk.dll
    c:\program files\McAfee\SiteAdvisor\McSACore.exe
    c:\program files\McAfee\SiteAdvisor\McSACorePS.dll
    c:\program files\McAfee\SiteAdvisor\Oem.txt
    c:\program files\McAfee\SiteAdvisor\sacore.dll
    c:\program files\McAfee\SiteAdvisor\sacore.inf
    c:\program files\McAfee\SiteAdvisor\saset.dll
    c:\program files\McAfee\SiteAdvisor\saupkeep.dll
    c:\program files\McAfee\SiteAdvisor\Scripts\locale\hr-hr\FF\safe.css
    c:\program files\McAfee\SiteAdvisor\Scripts\locale\hr-hr\IE\safe.css
    c:\program files\McAfee\SiteAdvisor\Scripts\locale\sr-sr\FF\safe.css
    c:\program files\McAfee\SiteAdvisor\Scripts\locale\sr-sr\IE\safe.css
    c:\program files\McAfee\SiteAdvisor\Scripts\safesearch.dat
    c:\program files\McAfee\SiteAdvisor\Scripts\safesearch.js
    c:\programdata\SP
    c:\programdata\SP\sp.DLL
    c:\users\Luka\AppData\Roaming\Microsoft\Windows\Recent\ANTIGEN.exe
    c:\users\Luka\AppData\Roaming\Microsoft\Windows\Recent\delfile.drv
    c:\users\Luka\AppData\Roaming\Microsoft\Windows\Recent\eb.drv
    c:\users\Luka\AppData\Roaming\Microsoft\Windows\Recent\exec.sys
    c:\users\Luka\AppData\Roaming\Microsoft\Windows\Recent\PE.dll
    c:\users\Luka\AppData\Roaming\Microsoft\Windows\Recent\PE.sys
    c:\users\Luka\AppData\Roaming\Microsoft\Windows\Recent\ppal.sys
    c:\users\Luka\AppData\Roaming\Microsoft\Windows\Recent\SICKBOY.drv
    c:\users\Luka\AppData\Roaming\Microsoft\Windows\Recent\sld.dll
    c:\users\Luka\AppData\Roaming\Microsoft\Windows\Recent\snl2w.exe
    c:\users\Luka\AppData\Roaming\Microsoft\Windows\Recent\tempdoc.exe
    c:\users\Luka\AppData\Roaming\Microsoft\Windows\Recent\tjd.sys
    c:\windows\cadSSaver.scr
    c:\windows\is-051EA.exe
    c:\windows\is-49ORC.exe
    c:\windows\iun6002.exe

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Service_Serv
    -------\Service_WinRM Licensing Service
    -------\Service_SPService


    ((((((((((((((((((((((((( Files Created from 2009-10-28 to 2009-11-29 )))))))))))))))))))))))))))))))
    .

    2009-11-29 18:45 . 2009-11-29 18:50 -------- d-----w- c:\users\Luka\AppData\Local\temp
    2009-11-29 18:45 . 2009-11-29 18:45 -------- d-----w- c:\users\Temp\AppData\Local\temp
    2009-11-29 18:45 . 2009-11-29 18:45 -------- d-----w- c:\users\Public\AppData\Local\temp
    2009-11-29 18:45 . 2009-11-29 18:45 -------- d-----w- c:\users\Default\AppData\Local\temp
    2009-11-29 18:45 . 2009-11-29 18:45 -------- d-----w- c:\users\Administrator\AppData\Local\temp
    2009-11-29 14:47 . 2009-11-29 14:47 -------- d-----w- c:\users\Luka\AppData\Local\ESET
    2009-11-28 23:56 . 2009-11-28 23:56 -------- d-----w- c:\users\Luka\dwhelper
    2009-11-28 21:19 . 2009-11-28 21:19 -------- d-----w- c:\users\Luka\AppData\Local\Frameworkx.com
    2009-11-28 21:17 . 2009-11-28 21:17 284147 ----a-r- c:\users\Luka\AppData\Roaming\Microsoft\Installer\{47609E69-4C5E-48B1-A889-24C6B82B5C04}\_93A0BD079836122C39D406.exe
    2009-11-28 21:17 . 2009-11-28 21:17 284147 ----a-r- c:\users\Luka\AppData\Roaming\Microsoft\Installer\{47609E69-4C5E-48B1-A889-24C6B82B5C04}\_6FEFF9B68218417F98F549.exe
    2009-11-28 21:17 . 2009-11-28 21:17 284147 ----a-r- c:\users\Luka\AppData\Roaming\Microsoft\Installer\{47609E69-4C5E-48B1-A889-24C6B82B5C04}\_3207B59E601B5F75D71B21.exe
    2009-11-28 16:53 . 2009-11-28 16:53 -------- d-----w- c:\program files\ESET
    2009-11-28 16:45 . 2009-11-28 16:45 92 ----a-w- c:\users\Luka\AppData\Local\fusioncache.dat
    2009-11-28 15:32 . 2001-05-07 10:56 19805 ----a-w- c:\windows\system32\drivers\usbio.sys
    2009-11-28 00:48 . 2009-11-03 01:42 195456 ------w- c:\windows\system32\MpSigStub.exe
    2009-11-25 03:59 . 2009-10-29 09:17 2048 ----a-w- c:\windows\system32\tzres.dll
    2009-11-25 03:53 . 2009-08-11 16:44 1401856 ----a-w- c:\windows\system32\msxml6.dll
    2009-11-25 03:53 . 2009-08-11 16:44 1248768 ----a-w- c:\windows\system32\msxml3.dll
    2009-11-24 04:46 . 2009-11-24 04:46 -------- d-----w- c:\users\Temp\AppData\Roaming\TuneUp Software
    2009-11-23 01:57 . 2009-11-23 01:57 -------- d-----w- c:\programdata\Macrovision
    2009-11-23 01:56 . 2002-01-05 12:10 57344 ------w- c:\windows\system32\mfc70enu.dll
    2009-11-23 01:56 . 2009-11-23 01:56 -------- d-----w- c:\program files\Common Files\Macromedia Shared
    2009-11-22 18:06 . 2009-11-22 18:06 -------- d-----w- C:\found.003
    2009-11-22 15:32 . 2009-11-22 15:32 96096 ----a-w- c:\users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT
    2009-11-22 15:31 . 2009-11-22 15:31 -------- d-----w- c:\users\Administrator\AppData\Local\ApplicationHistory
    2009-11-22 15:31 . 2009-11-22 15:31 -------- d-----w- c:\users\Administrator\AppData\Roaming\Malwarebytes
    2009-11-22 14:26 . 2009-11-22 14:27 -------- d-----w- c:\users\Luka\AppData\Local\VirtualStore
    2009-11-22 12:09 . 2009-11-22 12:09 -------- d-----w- C:\found.002
    2009-11-22 04:27 . 2009-11-22 04:27 -------- d-----w- c:\users\Luka\AppData\Local\Macromedia
    2009-11-22 04:06 . 2009-11-23 01:56 -------- d-----w- c:\program files\Common Files\Macromedia
    2009-11-22 04:04 . 2009-11-22 04:04 -------- d-----w- c:\windows\Downloaded Installations
    2009-11-21 00:05 . 2009-11-21 02:58 -------- d-----w- c:\users\Luka\AppData\Roaming\Rainmeter
    2009-11-20 02:47 . 2009-11-20 02:52 4096 d-----w- c:\users\Luka\AppData\Roaming\Winamp
    2009-11-17 11:49 . 2009-11-17 11:49 -------- d-----w- c:\program files\Windows Portable Devices
    2009-11-17 03:29 . 2009-09-10 02:00 92672 ----a-w- c:\windows\system32\UIAnimation.dll
    2009-11-17 03:29 . 2009-09-10 02:01 3023360 ----a-w- c:\windows\system32\UIRibbon.dll
    2009-11-17 03:29 . 2009-09-10 02:00 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
    2009-11-17 03:29 . 2009-09-25 01:33 369664 ----a-w- c:\windows\system32\WMPhoto.dll
    2009-11-17 03:29 . 2009-09-24 22:54 258048 ----a-w- c:\windows\system32\winspool.drv
    2009-11-17 03:29 . 2009-09-25 01:27 634880 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
    2009-11-17 03:29 . 2009-09-25 01:27 37888 ----a-w- c:\windows\system32\cdd.dll
    2009-11-17 03:26 . 2009-10-08 21:07 4096 ----a-w- c:\windows\system32\oleaccrc.dll
    2009-11-17 03:26 . 2009-10-08 21:08 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
    2009-11-17 03:26 . 2009-10-08 21:08 234496 ----a-w- c:\windows\system32\oleacc.dll
    2009-11-16 14:06 . 2009-11-16 14:06 38240 ----a-w- c:\windows\system32\drivers\epfwwfp.sys
    2009-11-16 14:06 . 2009-11-16 14:06 135048 ----a-w- c:\windows\system32\drivers\epfw.sys
    2009-11-16 14:03 . 2009-11-16 14:03 108792 ----a-w- c:\windows\system32\drivers\ehdrv.sys
    2009-11-16 13:56 . 2009-11-16 13:56 116520 ----a-w- c:\windows\system32\drivers\eamon.sys
    2009-11-14 16:38 . 2009-11-14 16:38 -------- d-----w- c:\programdata\Age of Empires 3
    2009-11-12 01:55 . 2009-02-24 23:42 116736 ----a-w- c:\windows\system32\drivers\mcdbus.sys
    2009-11-11 23:29 . 2009-11-11 23:29 -------- d-----w- c:\users\Luka\AppData\Roaming\AdobeUM
    2009-11-11 08:00 . 2009-11-11 08:00 -------- d-sh--w- c:\windows\system32\%APPDATA%
    2009-11-11 01:58 . 2009-08-14 13:27 2036736 ----a-w- c:\windows\system32\win32k.sys
    2009-11-11 01:57 . 2009-08-10 12:35 355328 ----a-w- c:\windows\system32\WSDApi.dll
    2009-11-11 01:54 . 2009-11-11 01:54 -------- d-----w- c:\programdata\Age of Empires 3 XPack Trial
    2009-11-11 01:46 . 2009-11-11 01:46 -------- d-----w- c:\program files\Common Files\Microsoft Games
    2009-11-11 01:13 . 2009-11-11 01:13 4096 d-----w- c:\program files\Auto Mouse Click
    2009-11-11 00:24 . 2009-11-11 00:24 -------- d-----w- c:\users\Luka\AppData\Roaming\InstallShield
    2009-11-10 21:03 . 2009-08-06 03:48 54632 ----a-w- c:\windows\system32\drivers\fssfltr.sys
    2009-11-10 03:12 . 2009-11-10 03:12 285478 ----a-r- c:\users\Luka\AppData\Roaming\Microsoft\Installer\{0298D87A-9095-4F05-BE2F-51C2D11E2435}\_F1DC7CF6DFDABC527C8FED.exe
    2009-11-10 03:12 . 2009-11-10 03:12 285478 ----a-r- c:\users\Luka\AppData\Roaming\Microsoft\Installer\{0298D87A-9095-4F05-BE2F-51C2D11E2435}\_6FEFF9B68218417F98F549.exe
    2009-11-10 03:12 . 2009-11-10 03:12 285478 ----a-r- c:\users\Luka\AppData\Roaming\Microsoft\Installer\{0298D87A-9095-4F05-BE2F-51C2D11E2435}\_2395B77B6C903FD39C6BC7.exe
    2009-11-10 03:12 . 2009-11-10 03:12 285478 ----a-r- c:\users\Luka\AppData\Roaming\Microsoft\Installer\{0298D87A-9095-4F05-BE2F-51C2D11E2435}\_21F3885A18D238E15AAE81.exe
    2009-11-10 03:11 . 2009-11-10 03:12 -------- d-----w- c:\programdata\SkiniTunes
    2009-11-10 02:46 . 2009-11-10 03:00 -------- d-----w- c:\users\Luka\AppData\Roaming\CD Art Display
    2009-11-10 02:46 . 2003-01-27 19:27 94208 ----a-w- c:\windows\system32\wmpuice.dll
    2009-11-10 02:46 . 2009-11-10 02:46 4096 d-----w- c:\program files\CD Art Display
    2009-11-10 01:47 . 2009-11-10 01:48 49152 d-----w- c:\program files\TuneUp Utilities 2009
    2009-11-08 17:03 . 2009-11-08 17:03 -------- d-----w- c:\programdata\LightScribe
    2009-11-08 16:35 . 2009-11-08 16:35 -------- d-----w- c:\program files\EA GAMES
    2009-11-08 16:10 . 2009-11-08 16:10 -------- d-----w- c:\users\Luka\AppData\Local\MicroVision Applications
    2009-11-08 14:43 . 2009-11-08 14:43 -------- d-----w- c:\program files\GameSpy Arcade
    2009-11-08 14:38 . 2009-11-08 14:38 -------- d-----w- c:\program files\Sierra
    2009-11-07 03:05 . 2009-11-07 03:05 98304 ----a-w- c:\windows\system32\CmdLineExt.dll
    2009-11-06 23:28 . 2009-11-06 23:28 -------- d-----w- c:\windows\system32\Futuremark
    2009-11-06 23:28 . 2007-08-20 16:05 27672 ----a-w- c:\windows\system32\drivers\Entech.sys
    2009-11-06 23:28 . 2009-11-06 23:28 -------- d-----w- c:\program files\Common Files\Futuremark Shared
    2009-11-06 21:00 . 2009-11-06 21:00 -------- d-----w- c:\users\Luka\AppData\Roaming\PeerNetworking
    2009-11-05 22:37 . 2009-11-11 00:03 -------- d-----w- c:\users\Temp\AppData\Roaming\BitMeter2
    2009-11-05 01:41 . 2009-11-05 01:41 -------- d-----w- c:\program files\uTorrent
    2009-11-04 23:02 . 2009-11-28 16:45 4096 d-----w- c:\users\Luka\AppData\Local\ApplicationHistory
    2009-11-04 23:02 . 2009-11-29 18:46 -------- d-----w- c:\programdata\Bitmeter2
    2009-11-04 23:02 . 2009-11-05 08:15 -------- d-----w- c:\users\Luka\AppData\Roaming\Bitmeter2
    2009-11-04 23:02 . 2009-11-04 23:02 -------- d-----w- c:\program files\Codebox
    2009-11-04 22:54 . 2009-11-04 22:54 -------- d-----w- c:\users\Luka\AppData\Roaming\Rokario
    2009-11-04 04:41 . 2009-11-04 04:43 -------- d-----w- c:\users\Luka\AppData\Roaming\ISP Monitor
    2009-11-04 04:41 . 2009-11-04 11:56 4096 d-----w- c:\program files\ISP Monitor
    2009-11-03 02:35 . 2009-11-03 02:34 816456 ----a-w- c:\programdata\Intuit\QuickBooks 2008\Components\DownloadQB17\Patch\qbpatch2.exe
    2009-11-02 21:36 . 2009-11-02 21:36 -------- d-----w- c:\program files\Activision
    2009-11-01 14:43 . 2009-11-05 00:25 22328 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
    2009-11-01 14:43 . 2009-11-05 00:25 22328 ----a-w- c:\users\Luka\AppData\Roaming\PnkBstrK.sys
    2009-11-01 13:49 . 2009-11-01 13:49 -------- d-sh--w- c:\windows\ftpcache

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-11-29 18:48 . 2009-10-10 21:37 79248 ----a-w- c:\programdata\nvModes.dat
    2009-11-29 18:47 . 2009-07-16 04:26 4096 d-----w- c:\programdata\NVIDIA
    2009-11-29 03:15 . 2009-10-15 21:10 1356 ----a-w- c:\users\Luka\AppData\Local\d3d9caps.dat
    2009-11-28 22:04 . 2009-10-16 11:33 -------- d-----w- c:\program files\NCH Swift Sound
    2009-11-27 12:39 . 2009-10-24 12:31 4096 d-----w- c:\programdata\Spybot - Search & Destroy
    2009-11-25 18:57 . 2009-10-13 23:51 24576 d-----w- c:\users\Luka\AppData\Roaming\uTorrent
    2009-11-24 21:03 . 2009-10-24 12:31 8192 d-----w- c:\program files\Spybot - Search & Destroy
    2009-11-23 01:56 . 2006-12-28 19:41 8192 d--h--w- c:\program files\InstallShield Installation Information
    2009-11-22 04:07 . 2009-08-14 20:50 8192 d-----w- c:\users\Temp\AppData\Roaming\LimeWire
    2009-11-21 13:07 . 2009-08-02 22:26 96096 ----a-w- c:\users\Temp\AppData\Local\GDIPFONTCACHEV1.DAT
    2009-11-21 02:27 . 2009-10-11 22:51 96096 ----a-w- c:\users\Luka\AppData\Local\GDIPFONTCACHEV1.DAT
    2009-11-19 02:20 . 2009-10-12 16:30 -------- d-----w- c:\program files\Common Files\Stardock
    2009-11-17 11:48 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
    2009-11-17 11:47 . 2009-11-17 11:47 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
    2009-11-15 13:11 . 2009-10-07 00:07 16384 d-----w- c:\program files\CDBurnerXP
    2009-11-12 04:14 . 2006-12-28 19:48 8192 d-----w- c:\program files\Common Files\Adobe
    2009-11-12 03:50 . 2009-10-22 01:23 4096 d-----w- c:\users\Luka\AppData\Roaming\Download Manager
    2009-11-11 08:21 . 2006-11-02 11:18 4096 d-----w- c:\program files\Windows Mail
    2009-11-11 08:06 . 2009-07-16 16:55 12288 d-----w- c:\programdata\Microsoft Help
    2009-11-10 21:03 . 2009-07-16 04:42 -------- d-----w- c:\program files\Microsoft
    2009-11-10 21:02 . 2009-07-16 04:41 4096 d-----w- c:\program files\Windows Live
    2009-11-10 02:56 . 2009-10-12 16:42 4096 d-----w- c:\users\Luka\AppData\Roaming\Apple Computer
    2009-11-10 01:48 . 2009-10-25 16:46 604488 ----a-w- c:\windows\system32\TUProgSt.exe
    2009-11-10 01:48 . 2009-10-25 16:46 361288 ----a-w- c:\windows\system32\TuneUpDefragService.exe
    2009-11-09 04:03 . 2009-08-06 04:28 2445 ----a-w- c:\programdata\Intuit\QuickBooks 2008\qbbackup.sys
    2009-11-08 16:58 . 2009-09-11 23:21 4096 d-----w- c:\program files\Opera
    2009-11-08 16:42 . 2006-12-28 19:47 8192 d---a-w- c:\program files\Common Files\LightScribe
    2009-11-05 00:25 . 2009-10-11 11:37 103736 ----a-w- c:\windows\system32\PnkBstrB.exe
    2009-11-05 00:24 . 2009-10-11 11:35 66872 ----a-w- c:\windows\system32\PnkBstrA.exe
    2009-11-03 23:46 . 2009-11-03 23:46 75 ----a-w- c:\programdata\nvUnsupRes.dat
    2009-11-03 23:32 . 2009-10-31 02:55 4096 d-----w- c:\users\Luka\AppData\Roaming\LimeWire
    2009-11-03 00:29 . 2009-10-27 22:07 4096 d-----w- c:\program files\Adobe Media Player
    2009-10-31 05:30 . 2009-07-16 19:14 4096 d-----w- c:\program files\QuickTime
    2009-10-29 20:59 . 2009-10-29 20:59 -------- d-----w- c:\program files\Common Files\Adobe AIR
    2009-10-29 20:59 . 2009-11-22 15:29 38208 ----a-w- c:\users\Administrator\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
    2009-10-29 20:59 . 2009-10-29 20:59 38208 ----a-w- c:\users\Default\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
    2009-10-29 20:59 . 2009-10-29 20:50 38208 ----a-w- c:\users\Luka\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
    2009-10-29 20:55 . 2009-10-29 20:53 4096 d-----w- c:\program files\BannedStory
    2009-10-29 20:14 . 2009-10-29 20:14 94208 ----a-r- c:\users\Luka\AppData\Roaming\Microsoft\Installer\{31800004-6386-4999-A519-518F2D78D8F0}\python_icon.exe
    2009-10-27 22:25 . 2009-09-16 19:42 -------- d-----w- c:\programdata\FLEXnet
    2009-10-26 21:08 . 2009-10-26 21:08 -------- d-----w- c:\users\Temp\AppData\Roaming\vlc
    2009-10-26 19:44 . 2009-10-26 19:30 1510 ----a-w- c:\windows\Sketchpad Preferences.dat
    2009-10-26 12:24 . 2009-10-26 12:24 2149888 ----a-w- c:\windows\system32\python26.dll
    2009-10-25 22:39 . 2009-10-25 22:39 -------- d-----w- c:\users\Luka\AppData\Roaming\vlc
    2009-10-25 20:59 . 2009-10-25 20:59 274133 ----a-w- c:\windows\Icon Converter Plus Uninstaller.exe
    2009-10-25 20:58 . 2009-10-25 20:56 4096 d-----w- c:\program files\Common Files\Program4Pc
    2009-10-25 16:46 . 2009-10-25 16:46 -------- d-----w- c:\users\Luka\AppData\Roaming\TuneUp Software
    2009-10-25 16:45 . 2009-10-25 16:45 -------- d-----w- c:\programdata\TuneUp Software
    2009-10-25 16:45 . 2009-10-25 16:45 -------- d-sh--w- c:\programdata\{55A29068-F2CE-456C-9148-C869879E2357}
    2009-10-25 16:19 . 2009-10-25 16:19 7852 ----a-w- c:\windows\system32\mcdmsg7.dll
    2009-10-24 23:22 . 2009-10-24 17:28 -------- d-----w- c:\users\Luka\AppData\Roaming\DivX
    2009-10-24 22:52 . 2009-10-24 22:52 4096 d-----w- c:\program files\AC3Filter
    2009-10-24 22:42 . 2009-10-22 01:48 8192 d-----w- c:\program files\DivX
    2009-10-24 22:42 . 2009-09-27 03:58 4096 d-----w- c:\program files\Common Files\DivX Shared
    2009-10-24 14:55 . 2009-10-24 14:55 240128 ----a-w- c:\windows\system32\uxtheme.dll
    2009-10-24 14:55 . 2009-08-09 20:01 615424 ----a-w- c:\windows\system32\themeui.dll
    2009-10-24 02:30 . 2009-10-17 14:35 -------- d-----w- c:\program files\Lavalys
    2009-10-24 00:16 . 2009-10-24 00:16 -------- d-----w- c:\users\Luka\AppData\Roaming\Malwarebytes
    2009-10-23 23:57 . 2009-10-23 23:57 -------- d-----w- c:\users\Temp\AppData\Roaming\Malwarebytes
    2009-10-23 23:57 . 2009-10-23 23:57 4096 d-----w- c:\program files\Malwarebytes' Anti-Malware
    2009-10-23 23:57 . 2009-10-23 23:57 -------- d-----w- c:\programdata\Malwarebytes
    2009-10-22 01:49 . 2009-07-30 06:28 4096 d-----w- c:\program files\Common Files\PX Storage Engine
    2009-10-22 01:15 . 2009-10-22 01:09 -------- d-----w- c:\users\Luka\AppData\Roaming\Sony
    2009-10-22 01:11 . 2009-09-10 23:57 -------- d-----w- c:\program files\Sony
    2009-10-22 01:10 . 2009-10-22 01:10 -------- d-----w- c:\users\Luka\AppData\Roaming\Publish Providers
    2009-10-21 12:37 . 2009-10-21 12:37 -------- d-----w- c:\users\Luka\AppData\Roaming\SmarThru4
    2009-10-18 16:16 . 2009-10-18 16:16 2560 ----a-w- c:\windows\_MSRSTRT.EXE
    2009-10-18 14:23 . 2009-09-26 18:04 -------- d-----w- c:\programdata\Roxio
    2009-10-18 13:25 . 2009-10-18 13:23 4096 d-----w- c:\users\Luka\AppData\Roaming\muvee Technologies
    2009-10-18 13:23 . 2009-10-18 13:23 -------- d-----w- c:\programdata\muvee Technologies
    2009-10-18 13:22 . 2009-10-18 13:21 -------- d-----w- c:\users\Luka\AppData\Roaming\Roxio
    2009-10-18 02:33 . 2009-10-18 02:33 147940 ---ha-w- c:\windows\system32\mlfcache.dat
    2009-10-17 22:26 . 2009-10-17 22:26 -------- d-----w- c:\program files\Common Files\EasyInfo
    2009-10-17 20:43 . 2009-10-17 20:43 -------- d-----w- c:\program files\AMD
    2009-10-17 17:07 . 2009-10-16 11:54 -------- d-----w- c:\programdata\NCH Swift Sound
    2009-10-16 22:55 . 2009-10-16 22:55 -------- d-----w- c:\users\Luka\AppData\Roaming\Canneverbe_Limited
    2009-10-16 11:35 . 2009-10-16 11:31 -------- d-----w- c:\program files\NCH Software
    2009-10-16 11:33 . 2009-10-16 11:33 -------- d-----w- c:\programdata\NCH Software
    2009-10-16 11:33 . 2009-10-16 11:33 -------- d-----w- c:\users\Luka\AppData\Roaming\NCH Swift Sound
    2009-10-14 19:51 . 2006-12-28 19:49 28672 d-----w- c:\program files\Microsoft Works
    2009-10-14 19:38 . 2009-10-13 20:26 -------- d-----w- c:\users\Luka\AppData\Roaming\DAEMON Tools Lite
    2009-10-14 00:54 . 2009-10-14 00:39 4096 d-----w- c:\users\Luka\AppData\Roaming\GetRightToGo
    2009-10-14 00:38 . 2009-10-14 00:36 -------- d-----w- c:\program files\Pinnacle
    2009-10-14 00:36 . 2009-10-14 00:36 -------- d-----w- c:\programdata\Pinnacle
    2009-10-13 23:23 . 2009-10-13 23:22 4096 d-----w- c:\program files\DAEMON Tools Lite
    2009-10-13 23:20 . 2009-10-10 16:33 -------- d-----w- c:\programdata\DriverScanner
    2009-10-13 01:50 . 2009-10-12 17:48 4096 d-----w- c:\program files\iTunes
    2009-10-12 17:49 . 2009-10-12 17:48 -------- d-----w- c:\programdata\{755AC846-7372-4AC8-8550-C52491DAA8BD}
    2009-10-12 17:48 . 2009-10-12 17:48 -------- d-----w- c:\program files\iPod
    2009-10-12 17:48 . 2009-07-16 18:58 -------- d-----w- c:\program files\Common Files\Apple
    2009-10-12 17:27 . 2009-10-12 17:27 79144 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.0.1.8\SetupAdmin.exe
    2009-10-12 17:06 . 2009-10-12 17:06 -------- d-----w- c:\program files\temp
    2009-10-12 03:36 . 2009-10-12 03:36 -------- d-----w- c:\program files\QS
    2009-10-12 03:36 . 2009-10-12 03:36 -------- d-----w- c:\users\Luka\AppData\Roaming\TeamViewer
    2009-10-12 01:03 . 2009-10-12 01:00 4096 d-----w- c:\users\Luka\AppData\Roaming\Notepad++
    2009-10-12 01:03 . 2009-10-10 21:27 4096 d-----w- c:\program files\Notepad++
    2009-10-11 22:53 . 2009-10-11 22:53 -------- d-----w- c:\users\Luka\AppData\Roaming\Hewlett-Packard
    2009-10-11 14:20 . 2009-10-03 00:39 4096 d-----w- c:\program files\FL Studio
    2009-10-11 14:19 . 2009-09-27 15:57 4096 d-----w- c:\users\Temp\AppData\Roaming\Any Video Converter
    2009-10-11 14:08 . 2009-10-10 14:31 8192 d-----w- c:\program files\Game Accelerator
    .

    ------- Sigcheck -------

    [-] 2009-10-24 . 690D53BD10A804BB6D0A772D1C0E6907 . 247296 . . [6.0.6000.16386] . . c:\windows\System32\shsvcs.dll
    .
    ((((((((((((((((((((((((((((( SnapShot@2009-11-29_15.10.54 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2006-12-28 19:39 . 2009-11-29 16:29 63068 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
    + 2006-11-02 13:05 . 2009-11-29 18:50 72600 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
    - 2009-07-16 03:46 . 2009-11-29 03:39 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2009-07-16 03:46 . 2009-11-29 16:06 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    - 2009-07-16 03:46 . 2009-11-29 03:39 98304 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    + 2009-07-16 03:46 . 2009-11-29 16:06 98304 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    + 2009-07-16 03:46 . 2009-11-29 16:06 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    - 2009-07-16 03:46 . 2009-11-29 03:39 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    - 2009-10-09 14:40 . 2009-11-29 03:23 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2009-10-09 14:40 . 2009-11-29 17:02 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2009-10-09 14:40 . 2009-11-29 17:02 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    - 2009-10-09 14:40 . 2009-11-29 03:23 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    - 2009-10-09 14:40 . 2009-11-29 03:23 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2009-10-09 14:40 . 2009-11-29 17:02 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    - 2009-07-16 05:47 . 2009-11-28 21:43 2718 c:\windows\System32\WDI\ERCQueuedResolutions.dat
    + 2009-07-16 05:47 . 2009-11-29 18:46 2718 c:\windows\System32\WDI\ERCQueuedResolutions.dat
    + 2009-10-15 10:55 . 2009-11-29 16:29 6010 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-4247689957-3568266116-3149608587-1009_UserData.bin
    - 2009-11-29 15:09 . 2009-11-29 15:09 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
    + 2009-11-29 18:47 . 2009-11-29 18:47 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
    - 2009-11-29 15:09 . 2009-11-29 15:09 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
    + 2009-11-29 18:47 . 2009-11-29 18:47 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
    + 2006-11-02 10:33 . 2009-11-29 18:54 673582 c:\windows\System32\perfh009.dat
    - 2006-11-02 10:33 . 2009-11-29 15:16 673582 c:\windows\System32\perfh009.dat
    - 2006-11-02 10:33 . 2009-11-29 15:16 133540 c:\windows\System32\perfc009.dat
    + 2006-11-02 10:33 . 2009-11-29 18:54 133540 c:\windows\System32\perfc009.dat
    - 2009-09-19 18:01 . 2009-11-29 03:38 245760 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
    + 2009-09-19 18:01 . 2009-11-29 16:06 245760 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "DAEMON Tools Lite "= "c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
    "LightScribe Control Panel "= "c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2009-10-16 2363392]
    "WMPNSCFG "= "c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
    "AdobeUpdater "= "c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2009-09-16 2356088]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "amd_dc_opt "= "c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2007-07-23 77824]
    "Malwarebytes Anti-Malware (reboot) "= "c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
    "WinampAgent "= "c:\program files\Winamp\winampa.exe" [2009-07-01 37888]
    "SpybotSnD "= "c:\program files\Spybot - Search & Destroy\SpybotSD.exe" [2009-01-26 5365592]
    "Malwarebytes' Anti-Malware "= "c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2009-09-10 420176]
    "egui "= "c:\program files\ESET\ESET Smart Security\egui.exe" [2009-11-16 2054360]
    "RtHDVCpl "= "RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-01-15 4874240]

    c:\users\Temp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    OneNote 2007 Screen Clipper and Launcher.lnk.disabled [2009-10-9 1073]

    c:\users\Luka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    Rainmeter - Shortcut.lnk - c:\users\Luka\Downloads\Programs\Rainmeter\Rainmeter.exe [2009-11-1 119296]

    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    Bitmeter2.lnk - c:\program files\Codebox\BitMeter\BitMeter2.exe [2009-6-21 1462272]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorUser "= 2 (0x2)
    "EnableUIADesktopToggle "= 0 (0x0)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
    "NoChangeAnimation "= 0 (0x0)
    "NoStrCmpLogical "= 0 (0x0)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\MCPClient]
    2005-01-31 19:13 49152 ----a-w- c:\progra~1\COMMON~1\Stardock\MCPStub.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "mixer1 "=wdmaud.drv

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
    @= "Service "

    [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Connections.lnk]
    path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Connections.lnk
    backup=c:\windows\pss\HP Connections.lnk.CommonStartup
    backupExtension=.CommonStartup

    [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
    path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
    backup=c:\windows\pss\QuickBooks Update Agent.lnk.CommonStartup
    backupExtension=.CommonStartup

    [HKLM\~\startupfolder\C:^Users^Luka^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Client Default.lnk]
    path=c:\users\Luka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Client Default.lnk
    backup=c:\windows\pss\Client Default.lnk.Startup
    backupExtension=.Startup

    [HKLM\~\startupfolder\C:^Users^Luka^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
    path=c:\users\Luka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LimeWire On Startup.lnk
    backup=c:\windows\pss\LimeWire On Startup.lnk.Startup
    backupExtension=.Startup

    [HKLM\~\startupfolder\C:^Users^Luka^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Stardock ObjectDock.lnk]
    path=c:\users\Luka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Stardock ObjectDock.lnk
    backup=c:\windows\pss\Stardock ObjectDock.lnk.Startup
    backupExtension=.Startup

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
    "Sidebar "=c:\program files\Windows Sidebar\sidebar.exe /autoRun

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
    "iTunesHelper "= "c:\program files\iTunes\iTunesHelper.exe "
    "QuickTime Task "= "c:\program files\QuickTime\QTTask.exe" -atboottime
    "HP Health Check Scheduler "=c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring "=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring "=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring "=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
    "VistaSp2 "=hex(b):72,57,4d,7c,56,1b,ca,01

    R1 ehdrv;ehdrv;c:\windows\System32\drivers\ehdrv.sys [16/11/2009 9:03 AM 108792]
    R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [16/11/2009 9:04 AM 735960]
    R2 epfwwfp;epfwwfp;c:\windows\System32\drivers\epfwwfp.sys [16/11/2009 9:06 AM 38240]
    R2 ISPMonitorSrv;ISP Monitor;c:\program files\ISP Monitor\ISPMonitorSrv.exe [22/08/2007 6:55 PM 36864]
    R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [23/10/2009 6:57 PM 269648]
    R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [24/10/2009 7:32 AM 1153368]
    R2 SSPORT;SSPORT;c:\windows\System32\drivers\SSPORT.sys [03/02/2009 1:47 PM 5120]
    R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [17/08/2009 12:32 AM 239648]
    R3 MBAMProtector;MBAMProtector;c:\windows\System32\drivers\mbam.sys [23/10/2009 6:57 PM 19160]
    S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [09/10/2009 5:33 PM 133104]
    S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [18/07/2009 12:22 PM 21504]
    S3 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [10/11/2009 4:03 PM 54632]
    S3 fsssvc;Windows Live Family Safety Service;c:\program files\Windows Live\Family Safety\fsssvc.exe [05/08/2009 10:48 PM 704864]
    S3 RDPDISPM;RDPDISPM;c:\windows\System32\drivers\rdpdispm.sys [02/10/2009 5:13 PM 9040]
    S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\sqladhlp.exe [10/07/2008 7:28 PM 47128]
    S4 RsFx0102;RsFx0102 Driver;c:\windows\System32\drivers\RsFx0102.sys [10/07/2008 1:49 AM 242712]
    S4 sptd;sptd;c:\windows\System32\drivers\sptd.sys [26/09/2009 9:44 AM 721904]
    S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [30/03/2009 2:23 AM 366936]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
    netsvc REG_MULTI_SZ SPService "š

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
    UxTuneUp

    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
    "c:\program files\Common Files\LightScribe\LSRunOnce.exe "
    .
    Contents of the 'Scheduled Tasks' folder

    2009-11-29 c:\windows\Tasks\1-Click Maintenance.job
    - c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2009-07-16 15:54]

    2009-11-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-10-09 22:32]

    2009-11-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-10-09 22:32]

    2009-11-29 c:\windows\Tasks\Malwarebytes' Scheduled Scan for Luka.job
    - c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2009-10-23 18:53]

    2009-11-29 c:\windows\Tasks\Malwarebytes' Scheduled Update for Luka.job
    - c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2009-10-23 18:53]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://google.ca/
    mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_CA&c=71&bd=Pavilion&pf=desktop
    mWindow Title =
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
    TCP: {10AA17A2-D126-48AA-83FE-D0C879DD6E86} = 192.168.2.1
    DPF: {D1278801-B2C0-4332-BD3E-2F64D2204EDF} - hxxps://www.mesh.com/0.9.4014.13/TSWeb.cab
    FF - ProfilePath - c:\users\Luka\AppData\Roaming\Mozilla\Firefox\Profiles\pxn860zz.default\
    FF - prefs.js: browser.startup.homepage - www.google.ca
    FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
    FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
    FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
    FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
    FF - plugin: c:\users\Luka\Downloads\Programs\VLC\npvlc.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
    .
    - - - - ORPHANS REMOVED - - - -

    ShellIconOverlayIdentifiers-{96AFBE69-C3B0-4b00-8578-D933D2896EE2} - c:\programdata\sp\sp.dll
    AddRemove-ISPMonitor - c:\windows\iun6002.exe



    **************************************************************************
    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files:

    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial "=dword:00000000
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\windows\system32\nvvsvc.exe
    c:\windows\system32\nvvsvc.exe
    c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    c:\program files\Bonjour\mDNSResponder.exe
    c:\program files\Common Files\LightScribe\LSSrvc.exe
    c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
    c:\program files\CDBurnerXP\NMSAccessU.exe
    c:\windows\system32\PnkBstrA.exe
    c:\windows\system32\PnkBstrB.exe
    c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    c:\users\Luka\Downloads\Programs\Alcohol 120\StarWind\StarWindService.exe
    c:\windows\System32\TUProgSt.exe
    c:\windows\system32\DRIVERS\xaudio.exe
    c:\windows\system32\WUDFHost.exe
    c:\program files\Windows Media Player\wmpnetwk.exe
    c:\program files\Hewlett-Packard\HP Health Check\hphc_service.exe
    .
    **************************************************************************
    .
    Completion time: 2009-11-29 13:59 - machine was rebooted
    ComboFix-quarantined-files.txt 2009-11-29 18:59
    ComboFix2.txt 2009-11-29 15:25

    Pre-Run: 146,073,477,120 bytes free
    Post-Run: 146,125,598,720 bytes free

    - - End Of File - - BB8F02304EB3F85E52385C76862E8C71
     
  14. 2009/11/29
    insaniity

    insaniity Inactive Thread Starter

    Joined:
    2009/11/28
    Messages:
    13
    Likes Received:
    0
    HJT:
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 2:08:10 PM, on 29/11/2009
    Platform: Windows Vista SP2 (WinNT 6.00.1906)
    MSIE: Internet Explorer v8.00 (8.00.6001.18828)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\system32\taskeng.exe
    C:\WINDOWS\RtHDVCpl.exe
    C:\Program Files\ESET\ESET Smart Security\egui.exe
    C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
    C:\Program Files\Codebox\BitMeter\BitMeter2.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Windows\Explorer.exe
    C:\Users\Luka\Downloads\Programs\HJThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.ca/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_CA&c=71&bd=Pavilion&pf=desktop
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
    O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
    O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe "
    O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
    O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
    O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
    O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
    O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - HKCU\..\Run: [AdobeUpdater] "C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe "
    O4 - Startup: Rainmeter - Shortcut.lnk = Luka\Downloads\Programs\Rainmeter\Rainmeter.exe
    O4 - Global Startup: Bitmeter2.lnk = C:\Program Files\Codebox\BitMeter\BitMeter2.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
    O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
    O16 - DPF: {D1278801-B2C0-4332-BD3E-2F64D2204EDF} (Windows Live Mesh Upload Tool) - https://www.mesh.com/0.9.4014.13/TSWeb.cab
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{10AA17A2-D126-48AA-83FE-D0C879DD6E86}: NameServer = 192.168.2.1
    O17 - HKLM\System\CS1\Services\Tcpip\..\{10AA17A2-D126-48AA-83FE-D0C879DD6E86}: NameServer = 192.168.2.1
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
    O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
    O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
    O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: ISP Monitor (ISPMonitorSrv) - How2 Studios - C:\Program Files\ISP Monitor\ISPMonitorSrv.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
    O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
    O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
    O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
    O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
    O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
    O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Users\Luka\Downloads\Programs\Alcohol 120\StarWind\StarWindService.exe
    O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
    O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
    O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Windows\System32\TuneUpDefragService.exe
    O23 - Service: @%SystemRoot%\System32\TUProgSt.exe,-1 (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\Windows\System32\TUProgSt.exe
    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

    --
    End of file - 7570 bytes
     
  15. 2009/11/29
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    How is redirections issue?

    =============================================================

    Uninstall Combofix:
    Go Start > Run [Vista users, go Start> "Start search"]
    Type in:
    Combofix /Uninstall
    Note the space between the "Combofix" and the "/Uninstall "
    Restart computer.

    =============================================================

    Download and run Norton Removal Tool: http://service1.symantec.com/Support/tsgeninfo.nsf/docid/2005033108162039

    ================================================================

    Print these instructions out.

    NOTE. If any of the programs listed below refuse to run, try renaming executive file to something else; for instance, rename hijackthis.exe to scanner.exe

    ***VERY IMPORTANT! Make sure, you update Superantispyware, and Malwarebytes before running the scans.***

    STEP 1. Download SUPERAntiSpyware Free for Home Users:
    http://www.superantispyware.com/

    * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
    * An icon will be created on your desktop. Double-click that icon to launch the program.
    * If asked to update the program definitions, click "Yes ". If not, update the definitions before scanning by selecting "Check for Updates ". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
    * Close SUPERAntiSpyware.

    PHYSICALLY DISCONNECT FROM THE INTERNET

    Restart computer in Safe Mode.
    To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

    * Open SUPERAntiSpyware.
    * Click Scan your Computer... button.
    * Click Scanning Preferences/Control Center... button.
    * Under General and Startup tab, make sure, Start SUPERAntiSpyware when Windows starts option is UN-checked.
    * Click the Scanning Control tab.
    * Under Scanner Options make sure the following are checked (leave all others unchecked):
    • Close browsers before scanning.
    • Terminate memory threats before quarantining.
    * Click the Close button to leave the control center screen.
    * On the left, make sure you check C:\Fixed Drive.
    * On the right, choose Perform Complete Scan.
    * Click Next to start the scan. Please be patient while it scans your computer.
    * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click OK.
    * Make sure everything has a checkmark next to it and click Next.
    * A notification will appear that Quarantine and Removal is Complete. Click OK and then click the Finish button to return to the main menu.
    * If asked if you want to reboot, click Yes.
    * To retrieve the removal information after reboot, launch SUPERAntispyware again.
    • Click Preferences, then click the Statistics/Logs tab.
    • Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    • If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    • Please copy and paste the Scan Log results in your next reply.
    * Click Close to exit the program.
    Post SUPERAntiSpyware log.

    RECONNECT TO THE INTERNET

    RESTART COMPUTER!

    STEP 2. Download Malwarebytes' Anti-Malware: http://www.malwarebytes.org/mbam.php to your desktop.
    (Malwarebytes is free to use as a manual scanner. Payment is only required if you wish to have it run and update automatically which is not necessary for our purposes)

    ******************************************************************************************
    Due to a bug in Malwarebytes, you may see in MBAM's log following entries:
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\atapi (Rootkit)
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\atapi (Rootkit)
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\atapi (Rootkit)

    DO NOT remove those entries!
    If you do, your computer will become UN-bootable.
    The issue has been fixed in the latest MBAM update, so, it's EXTREMELY important, you update MBAM before you run it.
    ****************************************************************************************

    * Double-click mbam-setup.exe and follow the prompts to install the program.
    * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select Perform full scan, then click Scan.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Be sure that everything is checked, and click Remove Selected.
    * When completed, a log will open in Notepad.
    * Post the log back here.

    The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
    Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

    RESTART COMPUTER!


    STEP 3.
    Post fresh HijackThis log.
    NOTE. If you're using Vista, right click on HijackThis, and click Run as Administrator
    Do NOT attempt to "fix" anything!


    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
     
  16. 2009/11/29
    insaniity

    insaniity Inactive Thread Starter

    Joined:
    2009/11/28
    Messages:
    13
    Likes Received:
    0
    No, it's not redirecting. As for SUPERAntiSpyware, I'm scanning right now. Mind you, I'm using another computer to do this seeing as i have no internet access from the scanning one. Will it be a problem if i uninstalled Spybot S&D thinking that they'll be problems with 2 anti-spyware programs?
     
  17. 2009/11/29
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    At what point did you lose internet connection?

    Uninstalling Spybot is a good thing, because it's not 1st class tool anymore.
     
  18. 2009/11/29
    insaniity

    insaniity Inactive Thread Starter

    Joined:
    2009/11/28
    Messages:
    13
    Likes Received:
    0
    i lost internet connection about 40 minutes ago (around), because i had to check out the post, follow insructions etc. Why?
     
  19. 2009/11/29
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    No, I'm asking rather about a certain step after which you lost internet connection.
     
  20. 2009/11/29
    insaniity

    insaniity Inactive Thread Starter

    Joined:
    2009/11/28
    Messages:
    13
    Likes Received:
    0
    Oh, i lost internet connection before i had to go restart computer into safe mode to start scanning SUPERAntispyware
     
  21. 2009/11/29
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Oh, so it's not really lost.
    I misread you :)
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.