Unsolved

This post is more than 5 years old

20 Posts

4035

October 24th, 2010 08:00

may i have some help, please, sincerely brian

good morning

symptoms such as my avg being turned of

or automatic updates turned off

have not had pop ups or pop unders

just keep seeing the progress bar on microsoft update, it does not continue on, however i am up to date according to Belarc.

i used security templates but then i set them back to the default installations type

i did try using sytem restore but that kept getting turned off.

I just wanted the system drive monitored.

i did turn on data execution prevention.

windows firewall has been on.

i have cable that goes through a router.

 

 

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:37:30 AM, on 10/24/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\PROGRA~1\AVG\AVG10\avgchsvx.exe
C:\PROGRA~1\AVG\AVG10\avgrsx.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVG\AVG10\avgwdsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\WINDOWS\system32\tcpsvcs.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\AVG\AVG10\avgtray.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\WINDOWS\System32\dmadmin.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
O2 - BHO: IEPlugin Class - {11222041-111B-46E3-BD29-EFB2449479B1} - C:\PROGRA~1\ArcSoft\VIDEOD~1\ArcURLRecord.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: ToolbarBHO Class - {9519AF7E-638D-4933-BAD6-D33D23C79FE5} - C:\PROGRA~1\ArcSoft\RAWTHU~1\EXIFToolBar.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O2 - BHO: SnapFlash Class - {A44CBB0B-C77D-4BF5-87CC-B4EE79AD1B7E} - C:\Program Files\Common Files\Justdo\Jd2002.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SMTTB2009 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\Splitcam Toolbar\tbcore3.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O3 - Toolbar: RAW Thumbnail Viewer - {F301665A-12F8-4331-804A-5BCBD379668C} - C:\PROGRA~1\ArcSoft\RAWTHU~1\EXIFToolBar.dll
O3 - Toolbar: Splitcam Toolbar - {338B4DFE-2E2C-4338-9E41-E176D497299E} - C:\Program Files\Splitcam Toolbar\tbcore3.dll
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\system32\msconfig.exe /auto
O4 - HKLM\..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\RunServices: [] C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" (User 'Default user')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: Read EXIF - C:\Program Files\ArcSoft\RAW Thumbnail Viewer\ArcEXIFM.htm
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Flash with Flash Catcher - res://C:\Program Files\Common Files\Justdo\IECatcher.DLL/FlashCatcher.htm
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Flash Catcher - {90BAE0EF-F4BF-4FAC-B2EC-2C725C34AF12} - C:\Program Files\Common Files\Justdo\IECatcher.DLL
O9 - Extra 'Tools' menuitem: Flash Catcher - {90BAE0EF-F4BF-4FAC-B2EC-2C725C34AF12} - C:\Program Files\Common Files\Justdo\IECatcher.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra 'Tools' menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} (WMI Class) - https://support.dell.com/systemprofiler/SysProExe.CAB
O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} (DellSystemLite.Scanner) - http://support.dell.com/systemprofiler/DellSystemLite.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwareupdate/su2/ocx/15112/CTPID.cab
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe

--
End of file - 9789 bytes

2 Intern

 • 

1.5K Posts

November 7th, 2010 02:00

Hi brianboru2,

 

Welcome to Dell Community Malware Removal Forums,

Sorry for the delay in getting to you, I'm K27 and i will be reviewing your log for you.

Please DO NOT run any scans/tools/fixes on your own as this will conflict with the tools we are going to use.

Please Print or Save to Notepad all instructions and please follow them carefully and if there's something you don't understand or that will not work please let me know and we will go through it together.

Please DO NOT use this system for anything apart from visiting this forum and other sites I direct you too, as this will only make the cleanup process all the more diffecult.

Failure to reply in three (3) days will result in this topic being closed and I will remove it from my notifications, If you require more time then that is fine but please let me know.

 

If you still require assistance, please post a fresh HJT log.

 

Thanks.

20 Posts

November 7th, 2010 13:00

all okay but could you take a look at the log anyway, please, thanks, Brian

 

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:20:47 PM, on 11/7/2010
Platform: Windows XP SP3, v.5857 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\mmc.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Trend Micro\HijackThis\brian5028fagan.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O1 - Hosts: ::1 localhost # IPv6
O1 - Hosts: ::1 localhost # IPv6
O1 - Hosts: ::1 localhost # IPv6
O2 - BHO: (no name) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - (no file)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {31B27F2D-6BC6-451B-B3D2-4EAB36B2FC3B} - (no file)
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - (no file)
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SnapFlash Class - {A44CBB0B-C77D-4BF5-87CC-B4EE79AD1B7E} - C:\Program Files\Common Files\Justdo\Jd2002.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: (no name) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - (no file)
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: (no name) - {FF6C3CF0-4B15-11D1-ABED-709549C10000} - (no file)
O2 - BHO: (no name) - {FF7C3CF0-4B15-11D1-ABED-709549C10000} - (no file)
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Flash Catcher - {90BAE0EF-F4BF-4FAC-B2EC-2C725C34AF12} - C:\Program Files\Common Files\Justdo\IECatcher.DLL
O9 - Extra 'Tools' menuitem: Flash Catcher - {90BAE0EF-F4BF-4FAC-B2EC-2C725C34AF12} - C:\Program Files\Common Files\Justdo\IECatcher.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra 'Tools' menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {362C56AA-6E4F-40C7-A0B5-85501DBDAD77} (Scanner.SysScanner) - http://i.dell.com/images/global/js/scanner/SysProExe.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) -
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} -
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) -
O16 - DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} (Java Plug-in 1.6.0_04) -
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} (Java Plug-in 1.6.0_14) -
O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} (SysInfo Class) - http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.3.11.0.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} -
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) -
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

--
End of file - 8125 bytes

2 Intern

 • 

1.5K Posts

November 8th, 2010 11:00

Hi,

Please do not alter the text of the replies. It makes it very difficult to read.

 

I need to see some additional information about what is happening in your machine.
Please perform the following scan:

  • Download DDS by sUBs from one of the following links. Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool.
  • When done, DDS will open two (2) logs
    1. DDS.txt
    2. Attach.txt
  • Save both reports to your desktop.
  • The instructions here ask you to attach the Attach.txt.
    DDS.jpg
  • Instead of attaching, please copy/past both logs into your next reply.

Please note: You may have to disable any script protection running if the scan fails to run.
After downloading the tool, disconnect from the internet and disable all antivirus protection.
Run the scan, enable your A/V and reconnect to the internet.
Information on A/V control here

 

YOU MUST DISABLE ALL REAL TIME PROTECTION BEFORE RUNNING THE NEXT TOOL,

Next, download this Antirootkit Program to a folder that you create such as C:\ARK, by choosing the "Download EXE" button on the webpage.

Please Disable all Anti-virus/Anti-Spyware/FireWall on your machine(instructions via links below)

 

Next, please perform a rootkit scan:

  • Double-click the randomly name EXE located in the C:\ARK folder that you just downloaded to launch it
  • When the program opens, it will automatically initiate a very fast scan of common rootkit hiding places.
  • When the "quick" scan is finished (a few seconds), click the Rootkit/Malware tab,and then select the Scan button.
  • Leave your system completely idle while this longer scan is in progress.
  • When the scan is done, save the scan log to the Windows clipboard
  • Open Notepad or a similar text editor
  • Paste the clipboard contents into a text file by clicking Edit | Paste or Ctl V
  • Exit the Program
  • Save the Scan log as ARK.txt and post it in your next reply.
  • Now, re-enable the active protection component of any antivirus/antimalware programs you disabled before performing the scan.

.
If the ARK tool crashes your machine or causes a Blue Screen error, please post the log results from the first inital quick scan,this can be saved in the same way as the full scan in the above instructions.

 

Please COPY/PASTE BOTH DDS logs and the ARK log back to this thread,
Thanks
K27

20 Posts

November 9th, 2010 02:00

thanks, here is attach text. and the other DDS text is below. try as i did i could not get gmer to run.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-09-29.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 12/14/2007 10:40:40 PM
System Uptime: 11/9/2010 4:18:10 AM (0 hours ago)

Motherboard: Dell Computer Corp. |  | 0WF887
Processor:                 Intel(R) Celeron(R) CPU 2.53GHz | Microprocessor | 2527/533mhz

==== Disk Partitions =========================

A: is Removable
C: is FIXED (NTFS) - 48 GiB total, 24.116 GiB free.
D: is FIXED (NTFS) - 63 GiB total, 9.894 GiB free.
E: is CDROM ()

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP1: 11/7/2010 4:15:36 AM - System Checkpoint
RP2: 11/7/2010 4:50:50 AM - Removed Microsoft Baseline Security Analyzer 2.2
RP3: 11/7/2010 5:20:53 PM - I
RP4: 11/8/2010 4:12:21 PM - Installed Windows Media Player 11 KB954154.
RP5: 11/8/2010 4:13:11 PM - Installed Windows XP KB923561.

==== Installed Programs ======================


Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 8.1.1
Adobe Shockwave Player
Advanced Registry Optimizer
Advanced Video FX Engine
AI RoboForm (All Users)
Apple Application Support
Apple Software Update
ATI - Software Uninstall Utility
ATI AVIVO Codecs
ATI Catalyst Control Center
ATI Display Driver
AutoUpdate
Belarc Advisor 8.1
BugOff 1.10
Canon MP Navigator EX 1.0
Canon MP470 series
Canon MP470 series User Registration
Canon My Printer
Canon Utilities Easy-PhotoPrint EX
Canon Utilities Solution Menu
Catalyst Control Center - Branding
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Common
Catalyst Control Center HydraVision Full
Catalyst Control Center Localization All
ccc-core-preinstall
ccc-core-static
ccc-utility
CCC Help Chinese Standard
CCC Help English
CCC Help French
CCC Help German
CCC Help Spanish
Creative Audio Console
Creative Live! Cam Center
Creative Live! Cam Voice Driver (1.02.08.0710)
Data Lifeguard Tools
Digital Line Detect
DIGOpt
DivX Codec
DivX Converter
DivX Player
DivX Web Player
EASEUS Partition Master 6.5.1 Home Edition
Flash Catcher
FLV Player 2.0 (build 25)
GoodSync
Google Earth
Google Video Player
Graboid Video 1.65
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows XP (KB942288-v3)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB954708)
Intel(R) Extreme Graphics 2 Driver
Intel(R) Network Connections 14.0.40.0
Intel(R) PRO Network Adapters and Drivers
IsoBuster 2.4
Java Auto Updater
Java DB 10.5.3.0
Java(TM) 6 Update 22
Java(TM) SE Development Kit 6 Update 22
Joost (tm) Beta 1.1.4
Little Registry Cleaner
LiveReg (Symantec Corporation)
LiveUpdate (Symantec Corporation)
LiveUpdate 1.80 (Symantec Corporation)
Malwarebytes' Anti-Malware
Microsoft .NET Framework (English)
Microsoft .NET Framework (English) v1.0.3705
Microsoft .NET Framework 1.0 Hotfix (KB928367)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2416447)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Digital Image Library 9 - Blocker
Microsoft Digital Image Standard 2006 Editor
Microsoft Digital Image Standard 2006 Library
Microsoft Digital Image Standard 2006 Update
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft USB Flash Drive Manager
Microsoft Visual C++ 2005 Redistributable
Microsoft Windows XP Video Decoder Checkup Utility
Modem Helper
Modem On Hold
Mozilla Firefox (3.6.12)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 and SOAP Toolkit 3.0
MSXML 6.0 Parser (KB933579)
Netscape Navigator (9.0.0.6)
nLite 1.4.8
Norton Ghost
NTREGOPT 1.1j
OpenOffice.org 2.4
PaltalkScene
PixiePack Codec Pack
PowerDVD 5.9
QuickTime
RealMedia (remove only)
RealPlayer
Rhapsody
Rhapsody Player Engine
Roxio DLA
Roxio MyDVD LE
Roxio RecordNow Audio
Roxio RecordNow Copy
Roxio RecordNow Data
ScanSoft OmniPage SE 4
Security Update for CAPICOM (KB931906)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB974455)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB972187)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 9 (KB936782)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371-v2)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Skins
Sonic Update Manager
SoundMAX
Spybot - Search & Destroy
SpywareBlaster 4.4
SyncToy 2.0 Beta
System Requirements Lab for Intel
Tweak UI
Update for Windows Internet Explorer 7 (KB928089)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB973815)
VC 9.0 Runtime
Veoh Web Player
VeohTV BETA
VLC media player 1.1.4
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Imaging Component
Windows Installer Clean Up
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Media Format 11 runtime
Windows Media Format SDK Hotfix - KB891122
Windows Media Player 11
Windows Media Player Firefox Plugin
Windows Presentation Foundation
Windows XP Hotfix (SP1) [See Q282784 for more information]
Windows XP Service Pack 3
XML Paper Specification Shared Components Pack 1.0
XPS Essentials Pack
XPS Essentials Pack 1.0

==== Event Viewer Messages From Past Week ========

11/9/2010 3:50:48 AM, error: DCOM [10005]  - DCOM got error "%1084" attempting to start the service EventSystem with

arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
11/9/2010 3:43:07 AM, error: Service Control Manager [7026]  - The following boot-start or system-start driver(s) failed to

load:  AFD BANTExt Fips intelppm IPSec NetBT RasAcd Tcpip WS2IFSL
11/9/2010 3:43:07 AM, error: Service Control Manager [7001]  - The IPSEC Services service depends on the IPSEC driver service

which failed to start because of the following error:  A device attached to the system is not functioning.
11/9/2010 3:43:07 AM, error: Service Control Manager [7001]  - The DHCP Client service depends on the NetBT service which

failed to start because of the following error:  A device attached to the system is not functioning.
11/9/2010 3:36:11 AM, error: Service Control Manager [7034]  - The Application Layer Gateway Service service terminated

unexpectedly.  It has done this 1 time(s).
11/9/2010 3:02:21 AM, error: Service Control Manager [7023]  - The IPSEC Services service terminated with the following

error:  The authentication service is unknown.
11/9/2010 3:02:21 AM, error: Service Control Manager [7000]  - The ScreenCamera HR service failed to start due to the

following error:  The service cannot be started, either because it is disabled or because it has no enabled devices

associated with it.
11/9/2010 3:02:21 AM, error: Service Control Manager [7000]  - The MCSTRM service failed to start due to the following error:

 The system cannot find the file specified.
11/9/2010 3:02:18 AM, error: DCOM [10016]  - The application-specific permission settings do not grant Local Launch

permission for the COM Server application with CLSID  {DCBCA92E-7DBE-4EDA-8B7B-3AAEA4DD412B}  to the user NT AUTHORITY\SYSTEM

SID (S-1-5-18).  This security permission can be modified using the Component Services administrative tool.

==== End Of File ===========================

DDS (Ver_09-09-29.01) - NTFSx86 
Run by brian at  4:22:16.17 on Tue 11/09/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_22
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.2046.1508 [GMT -8:00]


============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Paltalk Messenger\paltalk.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\brian\My Documents\Downloads\dds.com

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
BHO: {00C6482D-C502-44C8-8409-FCE54AD9C208} - No File
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common

files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program

files\real\realplayer\rpbrowserrecordplugin.dll
BHO: {31B27F2D-6BC6-451B-B3D2-4EAB36B2FC3B} - No File
BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - No File
BHO: RoboForm: {724d43a9-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll
BHO: SnapFlash Class: {a44cbb0b-c77d-4bf5-87cc-b4ee79ad1b7e} - c:\program files\common files\justdo\Jd2002.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - No File
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program

files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: {FF6C3CF0-4B15-11D1-ABED-709549C10000} - No File
BHO: {FF7C3CF0-4B15-11D1-ABED-709549C10000} - No File
TB: &RoboForm: {724d43a0-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll
TB: Veoh Browser Plug-in: {d0943516-5076-4020-a3b5-aefaf26ab263} - c:\program files\veoh

networks\veoh\plugins\reg\VeohToolbar.dll
TB: Veoh Web Player Video Finder: {0fbb9689-d3d7-4f7a-a2e2-585b10099bfc} - c:\program files\veoh

networks\veohwebplayer\VeohIEToolbar.dll
uRun: [RoboForm] "c:\program files\siber systems\ai roboform\RoboTaskBarIcon.exe"
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE
mRun: [MSConfig] c:\windows\pchealth\helpctr\binaries\MSCONFIG.EXE /auto
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mPolicies-explorer: NoFileAssociate = 1 (0x1)
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - c:\program files\siber systems\ai roboform\RoboFormComFillForms.html
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - c:\program files\siber systems\ai roboform\RoboFormComSavePass.html
IE: {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - c:\program files\paltalk messenger\Paltalk.exe
IE: {724d43aa-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html
IE: {90BAE0EF-F4BF-4FAC-B2EC-2C725C34AF12} - res://c:\program files\common files\justdo\IECatcher.DLL/FlashCatcher.htm
IE: {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - c:\program files\common files\sourcetec\swf catcher\InternetExplorer.htm
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {362C56AA-6E4F-40C7-A0B5-85501DBDAD77} - hxxp://i.dell.com/images/global/js/scanner/SysProExe.cab
DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - hxxp://www.eset.eu/buxus/docs/OnlineScanner.cab
DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4}
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F}
DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} -

hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.3.11.0.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6}
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
LSA: Notification Packages = scecli konazuki.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\brian\applic~1\mozilla\firefox\profiles\et54xjm1.default\
FF - component: c:\program files\real\realplayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\documents and settings\administrator\application data\move networks\plugins\npqmp071505000011.dll
FF - plugin: c:\documents and settings\brianjohn\application data\move networks\plugins\npqmp071505000011.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npagent.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npJoostPlugin.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npmozax.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npRACtrl.dll
FF - plugin: c:\program files\veoh networks\veoh\plugins\noreg\NPVeohVersion.dll
FF - plugin: c:\program files\veoh networks\veohwebplayer\npWebPlayerVideoPluginATL.dll
FF - plugin: c:\windows\system32\superadblocker.com\npsabffx.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla

firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla

firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla

firefox\extensions\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla

firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency",   1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true);  // Traditional
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true);  // Simplified
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type",                  5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size",  4096);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug",            false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight",       2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize",       1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight",   25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight",     5);
c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js -

pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation",  false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name",

"chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js -

pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R1 kbfilter;Keyboard Filter Driver;c:\windows\system32\drivers\kbfilter.sys [2008-1-1 14624]
S2 SCRCAMHRDRV;ScreenCamera HR;c:\windows\system32\drivers\SCRCAMHRDRV.sys [2009-11-22 234304]
S3 BENDER;Pinnacle DV/AV Capture;c:\windows\system32\drivers\bender.sys [2005-8-13 203264]
S3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\system32\drivers\commonfx.sys --> c:\windows\system32\drivers\COMMONFX.SYS [?]
S3 COMMONFX;COMMONFX;c:\windows\system32\drivers\commonfx.sys --> c:\windows\system32\drivers\COMMONFX.SYS [?]
S3 cpudrv;cpudrv;c:\program files\systemrequirementslab\cpudrv.sys [2009-12-18 11336]
S3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\system32\drivers\ctaudfx.sys --> c:\windows\system32\drivers\CTAUDFX.SYS [?]
S3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\ctaudfx.sys --> c:\windows\system32\drivers\CTAUDFX.SYS [?]
S3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\system32\drivers\cterfxfx.sys --> c:\windows\system32\drivers\CTERFXFX.SYS [?]
S3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\cterfxfx.sys --> c:\windows\system32\drivers\CTERFXFX.SYS [?]
S3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\system32\drivers\ctsblfx.sys --> c:\windows\system32\drivers\CTSBLFX.SYS [?]
S3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\ctsblfx.sys --> c:\windows\system32\drivers\CTSBLFX.SYS [?]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2010-11-1 13192]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2010-11-1 8456]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\e.tmp --> c:\windows\system32\E.tmp [?]
S3 P1370Aud;Creative WebCam Audio Control;c:\windows\system32\drivers\P1370Aud.sys [2009-12-16 93056]
S3 P1370Aul;PD1370 Lower Filter Driver;c:\windows\system32\drivers\P1370Aul.sys [2009-12-16 4992]
S3 P1370Vfx;P1370Vfx;c:\windows\system32\drivers\P1370Vfx.sys [2009-12-16 6272]
S3 P1370VID;Live! Cam Voice;c:\windows\system32\drivers\P1370Vid.sys [2009-12-16 297792]
S3 ptiusbf;PTI USB Filter;c:\windows\system32\drivers\ptiusbf.sys [2001-4-13 22474]
S3 rootrepeal;rootrepeal;\??\c:\windows\system32\drivers\rootrepeal.sys --> c:\windows\system32\drivers\rootrepeal.sys [?]
S3 utm1mzay;AVZ Kernel Driver;c:\windows\system32\drivers\utm1mzay.sys [2010-11-1 7168]
S3 WsAudio_DeviceS(1);WsAudio_DeviceS(1);c:\windows\system32\drivers\WsAudio_DeviceS(1).sys [2009-11-11 25704]
S3 WsAudio_DeviceS(2);WsAudio_DeviceS(2);c:\windows\system32\drivers\WsAudio_DeviceS(2).sys [2009-11-11 25704]
S3 WsAudio_DeviceS(3);WsAudio_DeviceS(3);c:\windows\system32\drivers\WsAudio_DeviceS(3).sys [2009-11-11 25704]
S3 WsAudio_DeviceS(4);WsAudio_DeviceS(4);c:\windows\system32\drivers\WsAudio_DeviceS(4).sys [2009-11-11 25704]
S3 WsAudio_DeviceS(5);WsAudio_DeviceS(5);c:\windows\system32\drivers\WsAudio_DeviceS(5).sys [2009-11-11 25704]
S4 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\common files\creative

labs shared\service\CTAELicensing.exe [2010-2-6 79360]
S4 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;c:\windows\system32\dllhost.exe [2004-8-4 5120]

=============== Created Last 30 ================

2010-11-09 04:20   

    --d-----    c:\docume~1\brian\applic~1\Paltalk
2010-11-08 16:09        --d-----    c:\program files\MSXML 4.0
2010-11-07 17:23        --d-----    c:\program files\common files\Little Registry Cleaner
2010-11-07 17:20        --d-----    c:\program files\Little Registry Cleaner
2010-11-02 22:43        --dsh---    C:\found.000
2010-11-02 14:36    118,784    a-------    c:\windows\system32\Prounstl.exe
2010-11-02 14:31        --d-----    c:\program files\SystemRequirementsLab
2010-11-02 12:36    1,904    --------    c:\windows\system32\SetupBD.din
2010-11-02 12:36    24,064    a-------    c:\windows\system32\IntelNic.dll
2010-11-02 12:36    12,288    a-------    c:\windows\system32\e100bmsg.dll
2010-11-02 12:36    5,110    a-------    c:\windows\system32\e100b325.din
2010-11-02 12:32        --dsh---    c:\documents and settings\brian\PrivacIE
2010-11-02 12:14        --dsh---    c:\documents and settings\brian\IECompatCache
2010-11-02 09:36        --dsh---    c:\documents and settings\brian\IETldCache
2010-11-02 01:51        -cd-h---    c:\windows\ie8
2010-11-01 16:15    7,168    a-------    c:\windows\system32\drivers\utm1mzay.sys
2010-11-01 12:09    315,408    a-------    c:\windows\system32\drivers\7755189.sys
2010-11-01 05:34    2,217,088    a-------    c:\windows\system32\BootMan.exe
2010-11-01 05:34    86,408    a-------    c:\windows\system32\setupempdrv03.exe
2010-11-01 05:34    14,848    a-------    c:\windows\system32\EuEpmGdi.dll
2010-11-01 05:34    13,192    a-------    c:\windows\system32\epmntdrv.sys
2010-11-01 05:34    8,456    a-------    c:\windows\system32\EuGdiDrv.sys
2010-11-01 05:34        --d-----    c:\program files\EASEUS
2010-11-01 05:03    472,808    a-------    c:\windows\system32\deployJava1.dll
2010-10-31 18:36    3,840    a-------    c:\windows\system32\drivers\BANTExt.sys
2010-10-31 07:55    361    a-------    c:\windows\NYCODE7A.INI
2010-10-31 07:55        --d-----    C:\NYCODE7A
2010-10-28 23:34        --d-----    c:\program files\common files\ATI Technologies
2010-10-28 23:33    52,096    ac------    c:\windows\system32\dllcache\msdv.sys
2010-10-28 23:33    15,104    ac------    c:\windows\system32\dllcache\mpe.sys
2010-10-28 23:33    11,392    ac------    c:\windows\system32\dllcache\bdasup.sys
2010-10-28 23:33    52,096    a-------    c:\windows\system32\drivers\msdv.sys
2010-10-28 23:33    15,104    a-------    c:\windows\system32\drivers\mpe.sys
2010-10-28 23:33    11,392    a-------    c:\windows\system32\drivers\bdasup.sys
2010-10-28 23:33    16,896    ac------    c:\windows\system32\dllcache\bdaplgin.ax
2010-10-28 23:33    16,896    a-------    c:\windows\system32\bdaplgin.ax
2010-10-28 23:32    12,288    a-------    c:\windows\system32\ksolay.ax
2010-10-28 23:32    46,592    a-------    c:\windows\system32\dxdllreg.exe
2010-10-28 23:31    593,920    --------    c:\windows\system32\ati2sgag.exe
2010-10-28 23:30        --d-----    c:\program files\ATI Technologies
2010-10-28 21:18    0    a-------    c:\windows\ativpsrm.bin
2010-10-28 21:18    307,200    a----r--    c:\windows\system32\atiiiexx.dll
2010-10-28 21:18    15,577    a----r--    c:\windows\atiogl.xml
2010-10-28 21:18    442,368    a----r--    c:\windows\system32\ATIDEMGX.dll
2010-10-28 21:18    7,167    a----r--    c:\windows\system32\atifglpf.xml
2010-10-28 21:18    887,724    a----r--    c:\windows\system32\ativva6x.dat
2010-10-28 21:18    3,107,788    a----r--    c:\windows\system32\ativva5x.dat
2010-10-28 21:18    189,051    a----r--    c:\windows\system32\atiicdxx.dat
2010-10-28 21:15    20,992    ac------    c:\windows\system32\dllcache\dshowext.ax
2010-10-28 21:15    20,992    a-------    c:\windows\system32\dshowext.ax

==================== Find3M  ====================

2010-10-19 12:51    222,080    --------    c:\windows\system32\MpSigStub.exe
2009-11-14 20:09    1,802,784    a--sh---    c:\windows\system32\drivers\fidbox.dat
2009-11-14 20:09    26,656    a--sh---    c:\windows\system32\drivers\fidbox2.dat

============= FINISH:  4:22:42.70 ===============

2 Intern

 • 

1.5K Posts

November 9th, 2010 14:00

Hi,

Sorry, that is an old version of DDS, please delete the version you have saved by right clicking the desktop icon and clicking delete. Then please download a fresh version from HERE, run it, and post the logs.

 

Please try this Anti-Rootkit tool:

 

Please Disable all Anti-virus/Anti-Spyware/FireWall on your machine(instructions via links below)

  • Please download Rootkit Unhooker and save it to your desktop.
  • Double-click RKUnhookerLE.exe to run it.
  • Click the Report tab, then click Scan
  • Check Drivers, Stealth Code, Files, and Code Hooks
  • Uncheck the rest, then click OK
  • When prompted to Select Disks for Scan, make sure C:\ is checked and click OK
  • Wait till the scanner has finished then go File > Save Report
  • Save the report somewhere you can find it. Click Close
  • This log may be very large so use multiple posts if need be.

 

Note** you may get the following warning. It is ok, just ignore it.

"Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?
"

 

Please post back both the fresh DDS logs, and the RKUhooker log.

Thanks.

20 Posts

November 10th, 2010 12:00

okay, i will do as you say, however i got GMER to run.  it is running at the moment.

I will wait for it to run its' course unless you tell me otherwise.

20 Posts

November 10th, 2010 13:00

Hi, gmer just finished running.

thanks

 

 

GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2010-11-10 16:16:02
Windows 5.1.2600 Service Pack 3, v.5973 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 WDC_WD1200JB-75CRA0 rev.16.06V16
Running: 3ti0kr9u.exe; Driver: C:\DOCUME~1\brian\LOCALS~1\Temp\pxrcyfow.sys


---- System - GMER 1.0.15 ----

SSDT            \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. )  ZwOpenProcess [0xB9EAC6C0]
SSDT            \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. )  ZwTerminateProcess [0xB9EAC770]
SSDT            \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. )  ZwTerminateThread [0xB9EAC810]
SSDT            \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. )  ZwWriteVirtualMemory [0xB9EAC8B0]

---- Kernel code sections - GMER 1.0.15 ----

.text           ntoskrnl.exe!_abnormal_termination + 450                                                                                    804E2ABC 8 Bytes  JMP EAC810B9
.text           C:\WINDOWS\system32\DRIVERS\ati2mtag.sys                                                                                    section is writeable [0xB95C8000, 0x1C5D38, 0xE8000020]
init            C:\WINDOWS\system32\drivers\senfilt.sys                                                                                     entry point in "init" section [0xB94D7F80]

---- User code sections - GMER 1.0.15 ----

.text           C:\Program Files\Mozilla Firefox\plugin-container.exe[2236] USER32.dll!TrackPopupMenu                                       7E465316 5 Bytes  JMP 10405CF5 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text           C:\Program Files\Mozilla Firefox\firefox.exe[2948] ntdll.dll!LdrLoadDll                                                     7C9163C3 5 Bytes  JMP 004013F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)

---- Devices - GMER 1.0.15 ----

Device                                                                                                                                      Ntfs.sys (NT File System Driver/Microsoft Corporation)
Device                                                                                                                                      Fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)

AttachedDevice  \Driver\Tcpip \Device\Ip                                                                                                    avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice  \Driver\Tcpip \Device\Tcp                                                                                                   avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device                                                                                                                                      ftdisk.sys (FT Disk Driver/Microsoft Corporation)

AttachedDevice                                                                                                                              symsnap.sys (StorageCraft Volume Snap-Shot/StorageCraft)
AttachedDevice                                                                                                                              sisidex.sys (SISIDEX Driver/Windows (R) 2000 DDK provider)
AttachedDevice  \Driver\Tcpip \Device\Udp                                                                                                   avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice  \Driver\Tcpip \Device\RawIp                                                                                                 avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device          \FileSystem\Cdfs \Cdfs                                                                                                      DLAIFS_M.SYS (Drive Letter Access Component/Sonic Solutions)

---- Registry - GMER 1.0.15 ----

Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\DS@ParameterMessageFile                                                %SystemRoot%\System32\MsObjs.dll
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\DS\ObjectNames (not active ControlSet)                                
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\DS\ObjectNames@Directory Service Object                                7680
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\LSA@ParameterMessageFile                                               %SystemRoot%\System32\MsObjs.dll
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\LSA\ObjectNames (not active ControlSet)                               
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\LSA\ObjectNames@PolicyObject                                           5632
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\LSA\ObjectNames@SecretObject                                           5648
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\LSA\ObjectNames@TrustedDomainObject                                    5664
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\LSA\ObjectNames@UserAccountObject                                      5680
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\NetDDE Object@ParameterMessageFile                                     %SystemRoot%\System32\MsObjs.dll
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\NetDDE Object\ObjectNames (not active ControlSet)                     
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\NetDDE Object\ObjectNames@DDE Share                                    7424
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\SC Manager@ParameterMessageFile                                        %SystemRoot%\System32\MsObjs.dll
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\SC Manager\ObjectNames (not active ControlSet)                        
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\SC Manager\ObjectNames@SC_MANAGER Object                               7168
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\SC Manager\ObjectNames@SERVICE Object                                  7184
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\Security@CategoryCount                                                 9
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\Security@CategoryMessageFile                                           %SystemRoot%\System32\MsAuditE.dll
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\Security@GuidMessageFile                                               %SystemRoot%\System32\NtMarta.dll
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\Security@EventMessageFile                                              %SystemRoot%\System32\MsAuditE.dll;%SystemRoot%\System32\xpsp2res.dll;%SystemRoot%\System32\xpsp3res.dll
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\Security@ParameterMessageFile                                          %SystemRoot%\System32\MsObjs.dll
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\Security@TypesSupported                                                28
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\Security\ObjectNames (not active ControlSet)                          
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\Security\ObjectNames@Channel                                           5120
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\Security\ObjectNames@Desktop                                           6672
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\Security\ObjectNames@Device                                            4352
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\Security\ObjectNames@Directory                                         4368
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\Security\ObjectNames@Event                                             4384
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\Security\ObjectNames@EventPair                                         4400
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\Security\ObjectNames@File                                              4416
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\Security\ObjectNames@IoCompletion                                      4864
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\Security\ObjectNames@Job                                               5136
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\Security\ObjectNames@Key                                               4432
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\Security\ObjectNames@MailSlot                                          4416
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\Security\ObjectNames@Mutant                                            4448
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\Security\ObjectNames@NamedPipe                                         4416
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\Security\ObjectNames@Port                                              4464
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\Security\ObjectNames@Process                                           4480
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\Security\ObjectNames@Profile                                           4496
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\Security\ObjectNames@Section                                           4512
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\Security\ObjectNames@Semaphore                                         4528
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\Security\ObjectNames@SymbolicLink                                      4544
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\Security\ObjectNames@Thread                                            4560
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\Security\ObjectNames@Timer                                             4576
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\Security\ObjectNames@Token                                             4592
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\Security\ObjectNames@Type                                              4608
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\Security\ObjectNames@WaitablePort                                      4464
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\Security\ObjectNames@WindowStation                                     6656
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\Security Account Manager@ParameterMessageFile                          %SystemRoot%\System32\MsObjs.dll
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\Security Account Manager\ObjectNames (not active ControlSet)          
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\Security Account Manager\ObjectNames@SAM_ALIAS                         5424
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\Security Account Manager\ObjectNames@SAM_DOMAIN                        5392
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\Security Account Manager\ObjectNames@SAM_GROUP                         5408
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\Security Account Manager\ObjectNames@SAM_SERVER                        5376
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\Security Account Manager\ObjectNames@SAM_USER                          5440
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\ServiceModel 3.0.0.0@TypesSupported                                    31
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\ServiceModel 3.0.0.0@CategoryMessageFile                               %SystemRoot%\System32\MsAuditE.dll
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\ServiceModel 3.0.0.0@CategoryCount                                     3
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\ServiceModel 3.0.0.0@ParameterMessageFile                              c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll.mui
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\ServiceModel 3.0.0.0@EventMessageFile                                  c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll.mui
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\ServiceModel 3.0.0.0@EventSourceFlags                                  1
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\Spooler@ParameterMessageFile                                           %SystemRoot%\System32\MsObjs.dll
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\Spooler\ObjectNames (not active ControlSet)                           
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\Spooler\ObjectNames@Document                                           6944
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\Spooler\ObjectNames@Printer                                            6928
Reg             HKLM\SYSTEM\ControlSet001\Services\Eventlog\Security\Spooler\ObjectNames@Server                                             6912
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\DS@ParameterMessageFile                                                %SystemRoot%\System32\MsObjs.dll
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\DS\ObjectNames (not active ControlSet)                                
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\DS\ObjectNames@Directory Service Object                                7680
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\LSA@ParameterMessageFile                                               %SystemRoot%\System32\MsObjs.dll
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\LSA\ObjectNames (not active ControlSet)                               
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\LSA\ObjectNames@PolicyObject                                           5632
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\LSA\ObjectNames@SecretObject                                           5648
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\LSA\ObjectNames@TrustedDomainObject                                    5664
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\LSA\ObjectNames@UserAccountObject                                      5680
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\NetDDE Object@ParameterMessageFile                                     %SystemRoot%\System32\MsObjs.dll
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\NetDDE Object\ObjectNames (not active ControlSet)                     
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\NetDDE Object\ObjectNames@DDE Share                                    7424
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\SC Manager@ParameterMessageFile                                        %SystemRoot%\System32\MsObjs.dll
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\SC Manager\ObjectNames (not active ControlSet)                        
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\SC Manager\ObjectNames@SC_MANAGER Object                               7168
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\SC Manager\ObjectNames@SERVICE Object                                  7184
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\Security@CategoryCount                                                 9
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\Security@CategoryMessageFile                                           %SystemRoot%\System32\MsAuditE.dll
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\Security@GuidMessageFile                                               %SystemRoot%\System32\NtMarta.dll
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\Security@EventMessageFile                                              %SystemRoot%\System32\MsAuditE.dll;%SystemRoot%\System32\xpsp2res.dll;%SystemRoot%\System32\xpsp3res.dll
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\Security@ParameterMessageFile                                          %SystemRoot%\System32\MsObjs.dll
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\Security@TypesSupported                                                28
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\Security\ObjectNames (not active ControlSet)                          
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\Security\ObjectNames@Channel                                           5120
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\Security\ObjectNames@Desktop                                           6672
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\Security\ObjectNames@Device                                            4352
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\Security\ObjectNames@Directory                                         4368
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\Security\ObjectNames@Event                                             4384
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\Security\ObjectNames@EventPair                                         4400
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\Security\ObjectNames@File                                              4416
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\Security\ObjectNames@IoCompletion                                      4864
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\Security\ObjectNames@Job                                               5136
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\Security\ObjectNames@Key                                               4432
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\Security\ObjectNames@MailSlot                                          4416
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\Security\ObjectNames@Mutant                                            4448
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\Security\ObjectNames@NamedPipe                                         4416
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\Security\ObjectNames@Port                                              4464
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\Security\ObjectNames@Process                                           4480
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\Security\ObjectNames@Profile                                           4496
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\Security\ObjectNames@Section                                           4512
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\Security\ObjectNames@Semaphore                                         4528
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\Security\ObjectNames@SymbolicLink                                      4544
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\Security\ObjectNames@Thread                                            4560
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\Security\ObjectNames@Timer                                             4576
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\Security\ObjectNames@Token                                             4592
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\Security\ObjectNames@Type                                              4608
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\Security\ObjectNames@WaitablePort                                      4464
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\Security\ObjectNames@WindowStation                                     6656
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\Security Account Manager@ParameterMessageFile                          %SystemRoot%\System32\MsObjs.dll
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\Security Account Manager\ObjectNames (not active ControlSet)          
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\Security Account Manager\ObjectNames@SAM_ALIAS                         5424
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\Security Account Manager\ObjectNames@SAM_DOMAIN                        5392
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\Security Account Manager\ObjectNames@SAM_GROUP                         5408
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\Security Account Manager\ObjectNames@SAM_SERVER                        5376
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\Security Account Manager\ObjectNames@SAM_USER                          5440
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\ServiceModel 3.0.0.0@TypesSupported                                    31
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\ServiceModel 3.0.0.0@CategoryMessageFile                               %SystemRoot%\System32\MsAuditE.dll
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\ServiceModel 3.0.0.0@CategoryCount                                     3
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\ServiceModel 3.0.0.0@ParameterMessageFile                              c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll.mui
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\ServiceModel 3.0.0.0@EventMessageFile                                  c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll.mui
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\ServiceModel 3.0.0.0@EventSourceFlags                                  1
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\Spooler@ParameterMessageFile                                           %SystemRoot%\System32\MsObjs.dll
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\Spooler\ObjectNames (not active ControlSet)                           
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\Spooler\ObjectNames@Document                                           6944
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\Spooler\ObjectNames@Printer                                            6928
Reg             HKLM\SYSTEM\ControlSet003\Services\Eventlog\Security\Spooler\ObjectNames@Server                                             6912
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\DS@ParameterMessageFile                                            %SystemRoot%\System32\MsObjs.dll
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\DS\ObjectNames                                                    
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\DS\ObjectNames@Directory Service Object                            7680
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\LSA@ParameterMessageFile                                           %SystemRoot%\System32\MsObjs.dll
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\LSA\ObjectNames                                                   
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\LSA\ObjectNames@PolicyObject                                       5632
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\LSA\ObjectNames@SecretObject                                       5648
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\LSA\ObjectNames@TrustedDomainObject                                5664
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\LSA\ObjectNames@UserAccountObject                                  5680
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\NetDDE Object@ParameterMessageFile                                 %SystemRoot%\System32\MsObjs.dll
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\NetDDE Object\ObjectNames                                         
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\NetDDE Object\ObjectNames@DDE Share                                7424
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\SC Manager@ParameterMessageFile                                    %SystemRoot%\System32\MsObjs.dll
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\SC Manager\ObjectNames                                            
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\SC Manager\ObjectNames@SC_MANAGER Object                           7168
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\SC Manager\ObjectNames@SERVICE Object                              7184
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security@CategoryCount                                             9
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security@CategoryMessageFile                                       %SystemRoot%\System32\MsAuditE.dll
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security@GuidMessageFile                                           %SystemRoot%\System32\NtMarta.dll
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security@EventMessageFile                                          %SystemRoot%\System32\MsAuditE.dll;%SystemRoot%\System32\xpsp2res.dll;%SystemRoot%\System32\xpsp3res.dll
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security@ParameterMessageFile                                      %SystemRoot%\System32\MsObjs.dll
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security@TypesSupported                                            28
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames                                              
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@Channel                                       5120
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@Desktop                                       6672
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@Device                                        4352
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@Directory                                     4368
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@Event                                         4384
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@EventPair                                     4400
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@File                                          4416
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@IoCompletion                                  4864
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@Job                                           5136
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@Key                                           4432
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@MailSlot                                      4416
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@Mutant                                        4448
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@NamedPipe                                     4416
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@Port                                          4464
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@Process                                       4480
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@Profile                                       4496
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@Section                                       4512
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@Semaphore                                     4528
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@SymbolicLink                                  4544
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@Thread                                        4560
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@Timer                                         4576
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@Token                                         4592
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@Type                                          4608
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@WaitablePort                                  4464
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@WindowStation                                 6656
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security Account Manager@ParameterMessageFile                      %SystemRoot%\System32\MsObjs.dll
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security Account Manager\ObjectNames                              
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security Account Manager\ObjectNames@SAM_ALIAS                     5424
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security Account Manager\ObjectNames@SAM_DOMAIN                    5392
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security Account Manager\ObjectNames@SAM_GROUP                     5408
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security Account Manager\ObjectNames@SAM_SERVER                    5376
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security Account Manager\ObjectNames@SAM_USER                      5440
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\ServiceModel 3.0.0.0@TypesSupported                                31
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\ServiceModel 3.0.0.0@CategoryMessageFile                           %SystemRoot%\System32\MsAuditE.dll
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\ServiceModel 3.0.0.0@CategoryCount                                 3
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\ServiceModel 3.0.0.0@ParameterMessageFile                          c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll.mui
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\ServiceModel 3.0.0.0@EventMessageFile                              c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll.mui
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\ServiceModel 3.0.0.0@EventSourceFlags                              1
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Spooler@ParameterMessageFile                                       %SystemRoot%\System32\MsObjs.dll
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Spooler\ObjectNames                                               
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Spooler\ObjectNames@Document                                       6944
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Spooler\ObjectNames@Printer                                        6928
Reg             HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Spooler\ObjectNames@Server                                         6912

---- EOF - GMER 1.0.15 ----

20 Posts

November 10th, 2010 14:00


DDS (Ver_10-11-10.01) - NTFSx86 
Run by brian at 17:07:06.53 on Wed 11/10/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_22
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.2046.1233 [GMT -8:00]

AV: AVG Anti-Virus Free Edition 2011 *On-access scanning disabled* (Updated)   {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\PROGRA~1\AVG\AVG10\avgchsvx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG10\avgwdsvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\AVG\AVG10\avgnsx.exe
C:\Program Files\AVG\AVG10\avgemcx.exe
C:\PROGRA~1\AVG\AVG10\avgrsx.exe
C:\Program Files\AVG\AVG10\avgcsrvx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\AVG\AVG10\avgtray.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\rundll32.exe
C:\DOCUME~1\brian\MYDOCU~1\DOWNLO~1\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
BHO: {00C6482D-C502-44C8-8409-FCE54AD9C208} - No File
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common

files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program

files\real\realplayer\rpbrowserrecordplugin.dll
BHO: {31B27F2D-6BC6-451B-B3D2-4EAB36B2FC3B} - No File
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg10\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search &

destroy\SDHelper.dll
BHO: {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - No File
BHO: RoboForm: {724d43a9-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll
BHO: SnapFlash Class: {a44cbb0b-c77d-4bf5-87cc-b4ee79ad1b7e} - c:\program files\common files\justdo\Jd2002.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - No File
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program

files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: {FF6C3CF0-4B15-11D1-ABED-709549C10000} - No File
BHO: {FF7C3CF0-4B15-11D1-ABED-709549C10000} - No File
TB: &RoboForm: {724d43a0-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll
TB: Veoh Browser Plug-in: {d0943516-5076-4020-a3b5-aefaf26ab263} - c:\program files\veoh

networks\veoh\plugins\reg\VeohToolbar.dll
TB: Veoh Web Player Video Finder: {0fbb9689-d3d7-4f7a-a2e2-585b10099bfc} - c:\program files\veoh

networks\veohwebplayer\VeohIEToolbar.dll
uRun: [RoboForm] "c:\program files\siber systems\ai roboform\RoboTaskBarIcon.exe"
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE
mRun: [Malwarebytes Anti-Malware (rootkit-scan)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [AVG_TRAY] c:\program files\avg\avg10\avgtray.exe
mPolicies-explorer: NoFileAssociate = 1 (0x1)
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - c:\program files\siber systems\ai roboform\RoboFormComFillForms.html
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - c:\program files\siber systems\ai roboform\RoboFormComSavePass.html
IE: {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - c:\program files\paltalk messenger\Paltalk.exe
IE: {724d43aa-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html
IE: {90BAE0EF-F4BF-4FAC-B2EC-2C725C34AF12} - res://c:\program files\common files\justdo\IECatcher.DLL/FlashCatcher.htm
IE: {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - c:\program files\common files\sourcetec\swf catcher\InternetExplorer.htm
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search &

destroy\SDHelper.dll
DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE}
DPF: {362C56AA-6E4F-40C7-A0B5-85501DBDAD77}
DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - hxxp://www.eset.eu/buxus/docs/OnlineScanner.cab
DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4}
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F}
DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} -

hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.3.11.0.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6}
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg10\avgpp.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
LSA: Notification Packages = scecli konazuki.dll
mASetup: {9C450606-ED24-4958-92BA-B8940C99D441} - c:\program files\pixiepack codec pack\InstallerHelper.exe

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\brian\applic~1\mozilla\firefox\profiles\et54xjm1.default\
FF - component: c:\program files\avg\avg10\firefox\components\avgssff.dll
FF - component: c:\program files\real\realplayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\documents and settings\administrator\application data\move networks\plugins\npqmp071505000011.dll
FF - plugin: c:\documents and settings\brianjohn\application data\move networks\plugins\npqmp071505000011.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npagent.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npJoostPlugin.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npmozax.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npRACtrl.dll
FF - plugin: c:\program files\veoh networks\veoh\plugins\noreg\NPVeohVersion.dll
FF - plugin: c:\program files\veoh networks\veohwebplayer\npWebPlayerVideoPluginATL.dll
FF - plugin: c:\windows\system32\superadblocker.com\npsabffx.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} -

c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla

firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla

firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla

firefox\extensions\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla

firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true);  // Traditional
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true);  // Simplified

============= SERVICES / DRIVERS ===============

R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2010-9-13 25680]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2010-9-7 26064]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2010-9-7 249424]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2010-9-7 34384]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2010-9-7 298448]
R1 kbfilter;Keyboard Filter Driver;c:\windows\system32\drivers\kbfilter.sys [2008-1-1 14624]
R2 avgwd;AVG WatchDog;c:\program files\avg\avg10\avgwdsvc.exe [2010-9-10 265400]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2010-8-19 123472]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2010-8-19 30288]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2010-8-19 26192]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN

v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 SCRCAMHRDRV;ScreenCamera HR;c:\windows\system32\drivers\SCRCAMHRDRV.sys [2009-11-22 234304]
S3 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg10\identity protection\agent\bin\AVGIDSAgent.exe [2010-10-11 6104656]
S3 BENDER;Pinnacle DV/AV Capture;c:\windows\system32\drivers\bender.sys [2005-8-13 203264]
S3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\system32\drivers\commonfx.sys --> c:\windows\system32\drivers\COMMONFX.SYS [?]
S3 COMMONFX;COMMONFX;c:\windows\system32\drivers\commonfx.sys --> c:\windows\system32\drivers\COMMONFX.SYS [?]
S3 cpudrv;cpudrv;c:\program files\systemrequirementslab\cpudrv.sys [2009-12-18 11336]
S3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\system32\drivers\ctaudfx.sys --> c:\windows\system32\drivers\CTAUDFX.SYS [?]
S3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\ctaudfx.sys --> c:\windows\system32\drivers\CTAUDFX.SYS [?]
S3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\system32\drivers\cterfxfx.sys --> c:\windows\system32\drivers\CTERFXFX.SYS [?]
S3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\cterfxfx.sys --> c:\windows\system32\drivers\CTERFXFX.SYS [?]
S3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\system32\drivers\ctsblfx.sys --> c:\windows\system32\drivers\CTSBLFX.SYS [?]
S3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\ctsblfx.sys --> c:\windows\system32\drivers\CTSBLFX.SYS [?]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2010-11-1 13192]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2010-11-1 8456]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\31.tmp --> c:\windows\system32\31.tmp [?]
S3 P1370Aud;Creative WebCam Audio Control;c:\windows\system32\drivers\P1370Aud.sys [2009-12-16 93056]
S3 P1370Aul;PD1370 Lower Filter Driver;c:\windows\system32\drivers\P1370Aul.sys [2009-12-16 4992]
S3 P1370Vfx;P1370Vfx;c:\windows\system32\drivers\P1370Vfx.sys [2009-12-16 6272]
S3 P1370VID;Live! Cam Voice;c:\windows\system32\drivers\P1370Vid.sys [2009-12-16 297792]
S3 ptiusbf;PTI USB Filter;c:\windows\system32\drivers\ptiusbf.sys [2001-4-13 22474]
S3 rootrepeal;rootrepeal;\??\c:\windows\system32\drivers\rootrepeal.sys --> c:\windows\system32\drivers\rootrepeal.sys [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache

4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S3 WsAudio_DeviceS(1);WsAudio_DeviceS(1);c:\windows\system32\drivers\WsAudio_DeviceS(1).sys [2009-11-11 25704]
S3 WsAudio_DeviceS(2);WsAudio_DeviceS(2);c:\windows\system32\drivers\WsAudio_DeviceS(2).sys [2009-11-11 25704]
S3 WsAudio_DeviceS(3);WsAudio_DeviceS(3);c:\windows\system32\drivers\WsAudio_DeviceS(3).sys [2009-11-11 25704]
S3 WsAudio_DeviceS(4);WsAudio_DeviceS(4);c:\windows\system32\drivers\WsAudio_DeviceS(4).sys [2009-11-11 25704]
S3 WsAudio_DeviceS(5);WsAudio_DeviceS(5);c:\windows\system32\drivers\WsAudio_DeviceS(5).sys [2009-11-11 25704]
S4 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\common files\creative

labs shared\service\CTAELicensing.exe [2010-2-6 79360]
S4 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-11-9 136176]
S4 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;c:\windows\system32\dllhost.exe [2004-8-4 5120]

=============== Created Last 30 ================

2010-11-10 20:01:34    --------    d--h--w-    C:\$AVG
2010-11-10 19:28:34    --------    d-----w-    c:\docume~1\brian\applic~1\AVG10
2010-11-10 19:27:18    --------    d--h--w-    c:\docume~1\alluse~1\applic~1\Common Files
2010-11-10 19:26:27    --------    d-----w-    c:\windows\system32\drivers\AVG
2010-11-10 19:26:27    --------    d-----w-    c:\docume~1\alluse~1\applic~1\AVG10
2010-11-10 19:25:57    --------    d-----w-    c:\program files\AVG
2010-11-10 19:22:43    --------    d-----w-    c:\docume~1\alluse~1\applic~1\MFAData
2010-11-10 18:24:02    --------    d-----w-    c:\windows\ie8updates
2010-11-10 18:21:24    247808    -c----w-    c:\windows\system32\dllcache\ieproxy.dll
2010-11-10 18:21:24    12800    -c----w-    c:\windows\system32\dllcache\xpshims.dll
2010-11-10 18:21:23    743424    -c----w-    c:\windows\system32\dllcache\iedvtool.dll
2010-11-10 18:07:02    --------    d-----w-    c:\docume~1\brian\locals~1\applic~1\Help
2010-11-10 15:00:34    --------    d-----w-    c:\docume~1\alluse~1\applic~1\Norton
2010-11-10 15:00:30    --------    d-----w-    c:\docume~1\alluse~1\applic~1\NortonInstaller
2010-11-10 11:57:03    --------    d-----w-    c:\program files\Safer Networking
2010-11-10 06:57:01    --------    d-----w-    c:\docume~1\brian\locals~1\applic~1\BVRP Software
2010-11-10 06:39:10    --------    d-----w-    c:\docume~1\brian\applic~1\Malwarebytes
2010-11-10 01:31:22    --------    d-----w-    c:\docume~1\brian\locals~1\applic~1\Temp
2010-11-10 01:30:51    --------    d-----w-    c:\docume~1\brian\locals~1\applic~1\Google
2010-11-09 12:20:32    --------    d-----w-    c:\docume~1\brian\applic~1\Paltalk
2010-11-09 00:09:55    --------    d-----w-    c:\program files\MSXML 4.0
2010-11-08 01:23:23    --------    d-----w-    c:\program files\common files\Little Registry Cleaner
2010-11-08 01:20:53    --------    d-----w-    c:\program files\Little Registry Cleaner
2010-11-03 06:43:12    --------    d-----w-    C:\found.000
2010-11-02 22:36:36    118784    ----a-w-    c:\windows\system32\Prounstl.exe
2010-11-02 22:31:30    --------    d-----w-    c:\program files\SystemRequirementsLab
2010-11-02 20:36:17    24064    ----a-w-    c:\windows\system32\IntelNic.dll
2010-11-02 20:36:17    12288    ----a-w-    c:\windows\system32\e100bmsg.dll
2010-11-02 20:32:54    --------    d-sh--w-    c:\documents and settings\brian\PrivacIE
2010-11-02 20:14:49    --------    d-sh--w-    c:\documents and settings\brian\IECompatCache
2010-11-02 17:36:04    --------    d-----w-    c:\docume~1\brian\locals~1\applic~1\ATI
2010-11-02 17:36:00    --------    d-sh--w-    c:\documents and settings\brian\IETldCache
2010-11-02 09:51:35    --------    dc-h--w-    c:\windows\ie8
2010-11-01 20:09:17    315408    ----a-w-    c:\windows\system32\drivers\7755189.sys
2010-11-01 13:34:53    86408    ----a-w-    c:\windows\system32\setupempdrv03.exe
2010-11-01 13:34:53    8456    ----a-w-    c:\windows\system32\EuGdiDrv.sys
2010-11-01 13:34:53    2217088    ----a-w-    c:\windows\system32\BootMan.exe
2010-11-01 13:34:53    14848    ----a-w-    c:\windows\system32\EuEpmGdi.dll
2010-11-01 13:34:53    13192    ----a-w-    c:\windows\system32\epmntdrv.sys
2010-11-01 13:34:46    --------    d-----w-    c:\program files\EASEUS
2010-11-01 13:03:55    472808    ----a-w-    c:\windows\system32\deployJava1.dll
2010-11-01 13:03:55    472808    ----a-w-    c:\program files\mozilla firefox\plugins\npdeployJava1.dll
2010-11-01 02:36:19    3840    ----a-w-    c:\windows\system32\drivers\BANTExt.sys
2010-10-31 15:55:01    --------    d-----w-    C:\NYCODE7A
2010-10-29 07:34:17    --------    d-----w-    c:\program files\common files\ATI Technologies
2010-10-29 07:33:02    52096    -c--a-w-    c:\windows\system32\dllcache\msdv.sys
2010-10-29 07:33:02    52096    ----a-w-    c:\windows\system32\drivers\msdv.sys
2010-10-29 07:33:02    15104    -c--a-w-    c:\windows\system32\dllcache\mpe.sys
2010-10-29 07:33:02    15104    ----a-w-    c:\windows\system32\drivers\mpe.sys
2010-10-29 07:33:02    11392    -c--a-w-    c:\windows\system32\dllcache\bdasup.sys
2010-10-29 07:33:02    11392    ----a-w-    c:\windows\system32\drivers\bdasup.sys
2010-10-29 07:33:01    16896    ----a-w-    c:\windows\system32\bdaplgin.ax
2010-10-29 07:32:59    12288    ----a-w-    c:\windows\system32\ksolay.ax
2010-10-29 07:32:54    46592    ----a-w-    c:\windows\system32\dxdllreg.exe
2010-10-29 07:31:56    593920    ------w-    c:\windows\system32\ati2sgag.exe
2010-10-29 07:30:55    --------    d-----w-    c:\program files\ATI Technologies
2010-10-29 05:18:30    0    ----a-w-    c:\windows\ativpsrm.bin
2010-10-29 05:18:09    307200    ----a-r-    c:\windows\system32\atiiiexx.dll
2010-10-29 05:18:04    442368    ----a-r-    c:\windows\system32\ATIDEMGX.dll
2010-10-29 05:15:27    20992    ----a-w-    c:\windows\system32\dshowext.ax

==================== Find3M  ====================

2010-11-01 13:03:45    73728    ----a-w-    c:\windows\system32\javacpl.cpl
2010-10-19 20:51:33    222080    ------w-    c:\windows\system32\MpSigStub.exe
2010-09-18 20:23:26    974848    ----a-w-    c:\windows\system32\mfc42u.dll
2010-09-18 06:53:25    974848    ----a-w-    c:\windows\system32\mfc42.dll
2010-09-18 06:53:25    954368    ----a-w-    c:\windows\system32\mfc40.dll
2010-09-18 06:53:25    953856    ------w-    c:\windows\system32\mfc40u.dll
2010-09-10 05:58:08    916480    ----a-w-    c:\windows\system32\wininet.dll
2010-09-10 05:58:06    43520    ----a-w-    c:\windows\system32\licmgr10.dll
2010-09-10 05:58:06    1469440    ----a-w-    c:\windows\system32\inetcpl.cpl
2010-09-01 11:51:14    285824    ----a-w-    c:\windows\system32\atmfd.dll
2010-08-31 13:42:52    1852800    ----a-w-    c:\windows\system32\win32k.sys
2010-08-27 08:02:29    119808    ----a-w-    c:\windows\system32\t2embed.dll
2010-08-27 05:57:43    99840    ----a-w-    c:\windows\system32\srvsvc.dll
2010-08-26 12:52:45    5120    ----a-w-    c:\windows\system32\xpsp4res.dll
2010-08-23 16:12:04    617472    ------w-    c:\windows\system32\comctl32.dll
2010-08-17 13:17:06    58880    ----a-w-    c:\windows\system32\spoolsv.exe
2010-08-16 08:45:00    590848    ----a-w-    c:\windows\system32\rpcrt4.dll

============= FINISH: 17:07:31.17 ===============

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_10-11-10.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 12/14/2007 10:40:40 PM
System Uptime: 11/10/2010 1:45:40 PM (4 hours ago)

Motherboard: Dell Computer Corp. |  | 0WF887
Processor:                 Intel(R) Celeron(R) CPU 2.53GHz | Microprocessor | 2527/533mhz

==== Disk Partitions =========================

A: is Removable
C: is FIXED (NTFS) - 48 GiB total, 23.094 GiB free.
D: is FIXED (NTFS) - 63 GiB total, 9.894 GiB free.
E: is CDROM ()
F: is Removable

==== Disabled Device Manager Items =============

==== System Restore Points ===================

No restore point in system.

==== Installed Programs ======================


Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 8.1.1
Adobe Shockwave Player
Advanced Registry Optimizer
Advanced Video FX Engine
AI RoboForm (All Users)
Apple Application Support
Apple Software Update
ATI - Software Uninstall Utility
ATI AVIVO Codecs
ATI Catalyst Control Center
ATI Display Driver
AutoUpdate
AVG 2011
Belarc Advisor 8.1
BugOff 1.10
Canon MP Navigator EX 1.0
Canon MP470 series
Canon MP470 series User Registration
Canon My Printer
Canon Utilities Easy-PhotoPrint EX
Canon Utilities Solution Menu
Catalyst Control Center - Branding
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Common
Catalyst Control Center HydraVision Full
Catalyst Control Center Localization All
ccc-core-preinstall
ccc-core-static
ccc-utility
CCC Help Chinese Standard
CCC Help English
CCC Help French
CCC Help German
CCC Help Spanish
Creative Audio Console
Creative Live! Cam Center
Creative Live! Cam Voice Driver (1.02.08.0710)
Data Lifeguard Tools
Digital Line Detect
DIGOpt
DivX Codec
DivX Converter
DivX Player
DivX Web Player
EASEUS Partition Master 6.5.1 Home Edition
Flash Catcher
FLV Player 2.0 (build 25)
GoodSync
Google Earth
Google Earth Plug-in
Google Update Helper
Google Video Player
Graboid Video 1.65
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows XP (KB2158563)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Intel(R) Extreme Graphics 2 Driver
Intel(R) Network Connections 14.0.40.0
Intel(R) PRO Network Adapters and Drivers
IsoBuster 2.4
Java Auto Updater
Java DB 10.5.3.0
Java(TM) 6 Update 22
Java(TM) SE Development Kit 6 Update 22
Joost (tm) Beta 1.1.4
Little Registry Cleaner
LiveReg (Symantec Corporation)
LiveUpdate (Symantec Corporation)
LiveUpdate 1.80 (Symantec Corporation)
Malwarebytes' Anti-Malware
Microsoft .NET Framework (English)
Microsoft .NET Framework (English) v1.0.3705
Microsoft .NET Framework 1.0 Hotfix (KB928367)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2416447)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft Application Error Reporting
Microsoft Digital Image Library 9 - Blocker
Microsoft Digital Image Standard 2006 Editor
Microsoft Digital Image Standard 2006 Library
Microsoft Digital Image Standard 2006 Update
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft USB Flash Drive Manager
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Windows XP Video Decoder Checkup Utility
Modem Helper
Modem On Hold
Mozilla Firefox (3.6.12)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP2 and SOAP Toolkit 3.0
MSXML 6.0 Parser (KB933579)
Netscape Navigator (9.0.0.6)
nLite 1.4.8
Norton Ghost
NTREGOPT 1.1j
OpenOffice.org 2.4
PaltalkScene
PixiePack Codec Pack
PowerDVD 5.9
QuickTime
RealMedia (remove only)
RealPlayer
Rhapsody
Rhapsody Player Engine
Roxio DLA
Roxio MyDVD LE
Roxio RecordNow Audio
Roxio RecordNow Copy
Roxio RecordNow Data
RunAlyzer
ScanSoft OmniPage SE 4
Security Update for CAPICOM (KB931906)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft .NET Framework 4 Extended (KB2416472)
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB974455)
Security Update for Windows Internet Explorer 8 (KB2360131)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Media Player (KB2378111)
Security Update for Windows Media Player (KB975558)
Security Update for Windows Media Player (KB978695)
Security Update for Windows XP (KB2079403)
Security Update for Windows XP (KB2115168)
Security Update for Windows XP (KB2121546)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2259922)
Security Update for Windows XP (KB2279986)
Security Update for Windows XP (KB2286198)
Security Update for Windows XP (KB2296011)
Security Update for Windows XP (KB2347290)
Security Update for Windows XP (KB2360937)
Security Update for Windows XP (KB2387149)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979687)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB980436)
Security Update for Windows XP (KB981322)
Security Update for Windows XP (KB981852)
Security Update for Windows XP (KB981957)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982132)
Security Update for Windows XP (KB982214)
Security Update for Windows XP (KB982665)
Skins
Sonic Update Manager
SoundMAX
Spybot - Search & Destroy
SpywareBlaster 4.4
SyncToy 2.0 Beta
System Requirements Lab for Intel
Tweak UI
Update for Microsoft Windows (KB971513)
Update for Windows Internet Explorer 7 (KB928089)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows XP (KB2141007)
Update for Windows XP (KB2345886)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
VC 9.0 Runtime
Veoh Web Player
VeohTV BETA
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Installer Clean Up
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player Firefox Plugin
Windows Presentation Foundation
Windows XP Hotfix (SP1) [See Q282784 for more information]
WinRAR archiver
XML Paper Specification Shared Components Pack 1.0
XPS Essentials Pack

==== Event Viewer Messages From Past Week ========

11/9/2010 6:54:56 PM, error: Service Control Manager [7034]  - The Print Spooler service terminated unexpectedly.  It has done this 1 time(s).
11/9/2010 6:40:33 PM, error: Service Control Manager [7026]  - The following boot-start or system-start driver(s) failed to load:  BANTExt Fips intelppm
11/9/2010 11:29:05 PM, error: Service Control Manager [7000]  - The ScreenCamera HR service failed to start due to the following error:  The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
11/9/2010 11:29:05 PM, error: Service Control Manager [7000]  - The MCSTRM service failed to start due to the following error:  The system cannot find the file specified.
11/9/2010 11:29:03 PM, error: DCOM [10016]  - The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID  {DCBCA92E-7DBE-4EDA-8B7B-3AAEA4DD412B}  to the user NT AUTHORITY\SYSTEM SID (S-1-5-18).  This security permission can be modified using the Component Services administrative tool.
11/9/2010 11:11:58 PM, error: Service Control Manager [7034]  - The Application Layer Gateway Service service terminated unexpectedly.  It has done this 1 time(s).
11/9/2010 11:05:06 PM, error: Service Control Manager [7023]  - The IPSEC Services service terminated with the following error:  The authentication service is unknown.
11/9/2010 10:57:10 PM, error: Service Control Manager [7026]  - The following boot-start or system-start driver(s) failed to load:  AFD BANTExt Fips intelppm IPSec NetBT RasAcd Tcpip WS2IFSL
11/9/2010 10:57:10 PM, error: Service Control Manager [7001]  - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error:  A device attached to the system is not functioning.
11/9/2010 10:57:10 PM, error: Service Control Manager [7001]  - The DHCP Client service depends on the NetBT service which failed to start because of the following error:  A device attached to the system is not functioning.
11/9/2010 10:57:06 PM, error: DCOM [10005]  - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
11/9/2010 10:56:43 PM, error: DCOM [10005]  - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
11/10/2010 1:23:39 PM, error: Service Control Manager [7026]  - The following boot-start or system-start driver(s) failed to load:  AFD Avgldx86 Avgmfx86 Avgtdix BANTExt Fips intelppm IPSec NetBT RasAcd Tcpip WS2IFSL

==== End Of File ===========================
RkUnhooker report generator v0.7
==============================================
Rootkit Unhooker kernel version: 3.7.300.509
==============================================
Windows Major Version: 5
Windows Minor Version: 1
Windows Build Number: 2600
==============================================
>Drivers
Driver: C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
Address: 0xB95C7000
Size: 3891200 bytes

Driver: C:\WINDOWS\System32\ati3duag.dll
Address: 0xBF1CD000
Size: 3821568 bytes

Driver: C:\WINDOWS\System32\ativvaxx.dll
Address: 0xBF572000
Size: 2670592 bytes

Driver: C:\WINDOWS\system32\ntoskrnl.exe
Address: 0x804D7000
Size: 2189952 bytes

Driver: PnpManager
Address: 0x804D7000
Size: 2189952 bytes

Driver: RAW
Address: 0x804D7000
Size: 2189952 bytes

Driver: WMIxWDM
Address: 0x804D7000
Size: 2189952 bytes

Driver: Win32k
Address: 0xBF800000
Size: 1855488 bytes

Driver: C:\WINDOWS\System32\win32k.sys
Address: 0xBF800000
Size: 1855488 bytes

Driver: C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
Address: 0xB99B5000
Size: 1302528 bytes

Driver: C:\WINDOWS\System32\ialmdd5.DLL
Address: 0xBFA2A000
Size: 925696 bytes

Driver: C:\WINDOWS\system32\drivers\senfilt.sys
Address: 0xB9453000
Size: 733184 bytes

Driver: C:\WINDOWS\System32\ati2cqag.dll
Address: 0xBF065000
Size: 626688 bytes

Driver: Ntfs.sys
Address: 0xF7B52000
Size: 577536 bytes

Driver: C:\WINDOWS\System32\atikvmag.dll
Address: 0xBF0FE000
Size: 540672 bytes

Driver: C:\WINDOWS\system32\DRIVERS\tcpip.sys
Address: 0xA5004000
Size: 364544 bytes

Driver: C:\WINDOWS\system32\DRIVERS\update.sys
Address: 0xB93CA000
Size: 364544 bytes

Driver: C:\WINDOWS\System32\ati2dvag.dll
Address: 0xBF012000
Size: 339968 bytes

Driver: C:\WINDOWS\System32\atiok3x2.dll
Address: 0xBF182000
Size: 307200 bytes

Driver: C:\WINDOWS\system32\DRIVERS\avgtdix.sys
Address: 0xA4FBC000
Size: 294912 bytes

Driver: C:\WINDOWS\System32\ATMFD.DLL
Address: 0xBFFA0000
Size: 286720 bytes

Driver: C:\WINDOWS\system32\drivers\smwdm.sys
Address: 0xB952A000
Size: 262144 bytes

Driver: C:\WINDOWS\system32\DRIVERS\avgldx86.sys
Address: 0xA4F10000
Size: 245760 bytes

Driver: C:\WINDOWS\System32\ialmdev5.DLL
Address: 0xBF9F5000
Size: 217088 bytes

Driver: C:\WINDOWS\system32\DRIVERS\rdpdr.sys
Address: 0xB9423000
Size: 196608 bytes

Driver: ACPI.sys
Address: 0xF75A8000
Size: 188416 bytes

Driver: NDIS.sys
Address: 0xF795A000
Size: 184320 bytes

Driver: C:\WINDOWS\system32\drivers\tmcomm.sys
Address: 0xA2850000
Size: 180224 bytes

Driver: C:\WINDOWS\system32\DRIVERS\AVGIDSDriver.Sys
Address: 0xA27B0000
Size: 163840 bytes

Driver: C:\WINDOWS\system32\DRIVERS\netbt.sys
Address: 0xA4F6E000
Size: 163840 bytes

Driver: dmio.sys
Address: 0xF74B2000
Size: 155648 bytes

Driver: C:\WINDOWS\system32\DRIVERS\e100b325.sys
Address: 0xB95A1000
Size: 155648 bytes

Driver: C:\WINDOWS\system32\DRIVERS\ipnat.sys
Address: 0xA4F96000
Size: 155648 bytes

Driver: C:\WINDOWS\System32\Drivers\Fastfat.SYS
Address: 0xA25FC000
Size: 147456 bytes

Driver: C:\WINDOWS\system32\drivers\portcls.sys
Address: 0xB9506000
Size: 147456 bytes

Driver: C:\WINDOWS\system32\DRIVERS\USBPORT.SYS
Address: 0xB997D000
Size: 147456 bytes

Driver: C:\WINDOWS\system32\DRIVERS\ks.sys
Address: 0xB956A000
Size: 143360 bytes

Driver: C:\WINDOWS\System32\drivers\afd.sys
Address: 0xA4F4C000
Size: 139264 bytes

Driver: C:\WINDOWS\System32\ialmdnt5.dll
Address: 0xBF9D3000
Size: 139264 bytes

Driver: ACPI_HAL
Address: 0x806EE000
Size: 131840 bytes

Driver: C:\WINDOWS\system32\hal.dll
Address: 0x806EE000
Size: 131840 bytes

Driver: fltmgr.sys
Address: 0xF747A000
Size: 131072 bytes

Driver: symsnap.sys
Address: 0xF7867000
Size: 131072 bytes

Driver: ftdisk.sys
Address: 0xF74D8000
Size: 126976 bytes

Driver: C:\WINDOWS\System32\Drivers\usbvideo.sys
Address: 0xA5085000
Size: 122880 bytes

Driver: Mup.sys
Address: 0xF7836000
Size: 106496 bytes

Driver: atapi.sys
Address: 0xF749A000
Size: 98304 bytes

Driver: C:\WINDOWS\System32\DLA\DLAUDFAM.SYS
Address: 0xA2B02000
Size: 98304 bytes

Driver: C:\WINDOWS\system32\DRIVERS\nbf.sys
Address: 0xA2A84000
Size: 98304 bytes

Driver: C:\DOCUME~1\brian\LOCALS~1\Temp\pxrcyfow.sys
Address: 0xA1D45000
Size: 98304 bytes

Driver: KSecDD.sys
Address: 0xF7850000
Size: 94208 bytes

Driver: C:\WINDOWS\System32\DLA\DLAIFS_M.SYS
Address: 0xA2B1A000
Size: 90112 bytes

Driver: C:\WINDOWS\System32\DLA\DLAUDF_M.SYS
Address: 0xA2AEC000
Size: 90112 bytes

Driver: DRVMCDB.SYS
Address: 0xF7464000
Size: 90112 bytes

Driver: C:\WINDOWS\system32\drivers\wdmaud.sys
Address: 0xA21FF000
Size: 86016 bytes

Driver: C:\WINDOWS\system32\DRIVERS\parport.sys
Address: 0xB958D000
Size: 81920 bytes

Driver: C:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYS
Address: 0xB99A1000
Size: 81920 bytes

Driver: C:\WINDOWS\system32\DRIVERS\ipsec.sys
Address: 0xA50A3000
Size: 77824 bytes

Driver: C:\WINDOWS\System32\drivers\dxg.sys
Address: 0xBF000000
Size: 73728 bytes

Driver: pci.sys
Address: 0xF7597000
Size: 69632 bytes

Driver: C:\WINDOWS\System32\Drivers\Cdfs.SYS
Address: 0xF7404000
Size: 65536 bytes

Driver: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Address: 0xF76F7000
Size: 65536 bytes

Driver: C:\WINDOWS\system32\DRIVERS\serial.sys
Address: 0xF76D7000
Size: 65536 bytes

Driver: C:\WINDOWS\system32\drivers\drmk.sys
Address: 0xF7577000
Size: 61440 bytes

Driver: ohci1394.sys
Address: 0xF7607000
Size: 61440 bytes

Driver: C:\WINDOWS\system32\DRIVERS\redbook.sys
Address: 0xF7587000
Size: 61440 bytes

Driver: C:\WINDOWS\system32\drivers\sysaudio.sys
Address: 0xA22FC000
Size: 61440 bytes

Driver: C:\WINDOWS\system32\drivers\usbaudio.sys
Address: 0xF7454000
Size: 61440 bytes

Driver: C:\WINDOWS\system32\DRIVERS\usbhub.sys
Address: 0xF7557000
Size: 61440 bytes

Driver: C:\WINDOWS\system32\DRIVERS\1394BUS.SYS
Address: 0xF7617000
Size: 57344 bytes

Driver: C:\WINDOWS\System32\ialmrnt5.dll
Address: 0xBF9C5000
Size: 57344 bytes

Driver: C:\WINDOWS\system32\DRIVERS\CLASSPNP.SYS
Address: 0xF7657000
Size: 53248 bytes

Driver: VolSnap.sys
Address: 0xF7637000
Size: 53248 bytes

Driver: C:\WINDOWS\system32\DRIVERS\avgmfx86.sys
Address: 0xF7517000
Size: 49152 bytes

Driver: sisidex.sys
Address: 0xF7687000
Size: 49152 bytes

Driver: C:\WINDOWS\System32\Drivers\Fips.SYS
Address: 0xF7434000
Size: 45056 bytes

Driver: C:\WINDOWS\system32\DRIVERS\imapi.sys
Address: 0xF76E7000
Size: 45056 bytes

Driver: MountMgr.sys
Address: 0xF7627000
Size: 45056 bytes

Driver: sbp2port.sys
Address: 0xF7697000
Size: 45056 bytes

Driver: uagp35.sys
Address: 0xF7677000
Size: 45056 bytes

Driver: C:\WINDOWS\system32\DRIVERS\AVGIDSFilter.Sys
Address: 0xA2C60000
Size: 40960 bytes

Driver: C:\WINDOWS\system32\DRIVERS\AVGIDSShim.Sys
Address: 0xB9EAA000
Size: 40960 bytes

Driver: C:\WINDOWS\System32\Drivers\DRVNDDM.SYS
Address: 0xB9F2A000
Size: 40960 bytes

Driver: isapnp.sys
Address: 0xF75F7000
Size: 40960 bytes

Driver: PxHelp20.sys
Address: 0xF7667000
Size: 40960 bytes

Driver: C:\WINDOWS\system32\DRIVERS\termdd.sys
Address: 0xF7567000
Size: 40960 bytes

Driver: AVGIDSEH.Sys
Address: 0xF76A7000
Size: 36864 bytes

Driver: disk.sys
Address: 0xF7647000
Size: 36864 bytes

Driver: C:\WINDOWS\system32\DRIVERS\HIDCLASS.SYS
Address: 0xF7444000
Size: 36864 bytes

Driver: C:\WINDOWS\system32\DRIVERS\intelppm.sys
Address: 0xB9E9A000
Size: 36864 bytes

Driver: C:\WINDOWS\system32\DRIVERS\msgpc.sys
Address: 0xF74F7000
Size: 36864 bytes

Driver: C:\WINDOWS\System32\Drivers\Npfs.SYS
Address: 0xF777F000
Size: 32768 bytes

Driver: C:\WINDOWS\system32\DRIVERS\usbccgp.sys
Address: 0xF774F000
Size: 32768 bytes

Driver: C:\WINDOWS\system32\DRIVERS\usbehci.sys
Address: 0xF7817000
Size: 32768 bytes

Driver: C:\WINDOWS\system32\DRIVERS\v2imount.sys
Address: 0xF77E7000
Size: 32768 bytes

Driver: C:\WINDOWS\System32\DLA\DLABOIOM.SYS
Address: 0xF77CF000
Size: 28672 bytes

Driver: C:\WINDOWS\system32\DRIVERS\fdc.sys
Address: 0xF781F000
Size: 28672 bytes

Driver: C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
Address: 0xF772F000
Size: 28672 bytes

Driver: C:\WINDOWS\system32\DRIVERS\HIDPARSE.SYS
Address: 0xF7767000
Size: 28672 bytes

Driver: C:\WINDOWS\system32\DRIVERS\PCIIDEX.SYS
Address: 0xF7707000
Size: 28672 bytes

Driver: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
Address: 0xA2464000
Size: 28672 bytes

Driver: C:\WINDOWS\System32\Drivers\DLARTL_N.SYS
Address: 0xF775F000
Size: 24576 bytes

Driver: C:\WINDOWS\system32\DRIVERS\kbdclass.sys
Address: 0xF7737000
Size: 24576 bytes

Driver: C:\WINDOWS\system32\DRIVERS\mouclass.sys
Address: 0xF773F000
Size: 24576 bytes

Driver: C:\WINDOWS\System32\Drivers\rkhdrv40.SYS
Address: 0xA244C000
Size: 24576 bytes

Driver: C:\WINDOWS\system32\DRIVERS\usbuhci.sys
Address: 0xF780F000
Size: 24576 bytes

Driver: C:\WINDOWS\System32\drivers\vga.sys
Address: 0xF776F000
Size: 24576 bytes

Driver: avgrkx86.sys
Address: 0xF7717000
Size: 20480 bytes

Driver: C:\WINDOWS\system32\DRIVERS\flpydisk.sys
Address: 0xF7747000
Size: 20480 bytes

Driver: C:\WINDOWS\System32\Drivers\Msfs.SYS
Address: 0xF7777000
Size: 20480 bytes

Driver: PartMgr.sys
Address: 0xF770F000
Size: 20480 bytes

Driver: C:\WINDOWS\system32\DRIVERS\TDI.SYS
Address: 0xF7787000
Size: 20480 bytes

Driver: C:\WINDOWS\System32\watchdog.sys
Address: 0xF77AF000
Size: 20480 bytes

Driver: C:\WINDOWS\System32\DLA\DLAOPIOM.SYS
Address: 0xA2BC4000
Size: 16384 bytes

Driver: C:\WINDOWS\system32\DRIVERS\kbdhid.sys
Address: 0xF7933000
Size: 16384 bytes

Driver: C:\WINDOWS\system32\DRIVERS\mssmbios.sys
Address: 0xBA7C0000
Size: 16384 bytes

Driver: C:\WINDOWS\system32\DRIVERS\ndisuio.sys
Address: 0xA2B78000
Size: 16384 bytes

Driver: C:\WINDOWS\system32\DRIVERS\serenum.sys
Address: 0xBA7D8000
Size: 16384 bytes

Driver: C:\WINDOWS\system32\BOOTVID.dll
Address: 0xF7897000
Size: 12288 bytes

Driver: C:\WINDOWS\System32\drivers\Dxapi.sys
Address: 0xA4EFC000
Size: 12288 bytes

Driver: C:\WINDOWS\system32\DRIVERS\hidusb.sys
Address: 0xF792B000
Size: 12288 bytes

Driver: C:\WINDOWS\System32\Drivers\kbfilter.SYS
Address: 0xF793F000
Size: 12288 bytes

Driver: C:\WINDOWS\system32\DRIVERS\mouhid.sys
Address: 0xF7937000
Size: 12288 bytes

Driver: C:\WINDOWS\system32\DRIVERS\rasacd.sys
Address: 0xBA787000
Size: 12288 bytes

Driver: sisperf.sys
Address: 0xF789B000
Size: 12288 bytes

Driver: C:\WINDOWS\System32\drivers\ws2ifsl.sys
Address: 0xF793B000
Size: 12288 bytes

Driver: C:\WINDOWS\System32\Drivers\Beep.SYS
Address: 0xF79B5000
Size: 8192 bytes

Driver: C:\WINDOWS\System32\Drivers\DLACDBHM.SYS
Address: 0xF79AD000
Size: 8192 bytes

Driver: C:\WINDOWS\System32\DLA\DLAPoolM.SYS
Address: 0xF79C1000
Size: 8192 bytes

Driver: dmload.sys
Address: 0xF798D000
Size: 8192 bytes

Driver: C:\WINDOWS\System32\Drivers\Fs_Rec.SYS
Address: 0xF79B3000
Size: 8192 bytes

Driver: intelide.sys
Address: 0xF798B000
Size: 8192 bytes

Driver: C:\WINDOWS\system32\KDCOM.DLL
Address: 0xF7987000
Size: 8192 bytes

Driver: C:\WINDOWS\System32\Drivers\mnmdd.SYS
Address: 0xF79B7000
Size: 8192 bytes

Driver: C:\WINDOWS\System32\Drivers\ParVdm.SYS
Address: 0xF79CD000
Size: 8192 bytes

Driver: C:\WINDOWS\System32\DRIVERS\RDPCDD.sys
Address: 0xF79B9000
Size: 8192 bytes

Driver: C:\WINDOWS\system32\DRIVERS\swenum.sys
Address: 0xF79AF000
Size: 8192 bytes

Driver: C:\WINDOWS\system32\DRIVERS\USBD.SYS
Address: 0xF79B1000
Size: 8192 bytes

Driver: C:\WINDOWS\system32\DRIVERS\WMILIB.SYS
Address: 0xF7989000
Size: 8192 bytes

Driver: C:\WINDOWS\system32\DRIVERS\audstub.sys
Address: 0xB9DCE000
Size: 4096 bytes

Driver: C:\WINDOWS\System32\Drivers\BANTExt.sys
Address: 0xB9224000
Size: 4096 bytes

Driver: C:\WINDOWS\System32\DLA\DLADResN.SYS
Address: 0xF7AAD000
Size: 4096 bytes

Driver: C:\WINDOWS\System32\drivers\dxgthk.sys
Address: 0xF7A95000
Size: 4096 bytes

Driver: C:\WINDOWS\System32\Drivers\Null.SYS
Address: 0xB9249000
Size: 4096 bytes

Driver: pciide.sys
Address: 0xF7A4F000
Size: 4096 bytes

Driver: siside.sys
Address: 0xF7A50000
Size: 4096 bytes

==============================================
>Stealth
==============================================
>Files

Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\03041974d01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\03B37B61d01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\05F65918d01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\09AC8FF8d01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\09E2E8EDd01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\0F057768d01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\11337BFCd01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\135B4DFAd01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\156BBF18d01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\1710B1D2d01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\17B04E70d01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\2361504Ed01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\23733B32d01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\2719EA39d01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\28399E4Ad01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\291CB5C2d01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\2BD5B65Dd01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\32AB8D0Ad01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\3371113Fd01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\3B3F76D9d01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\498F7E22d01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\4B4A9B91d01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\4F0B24B0d01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\635AC26Ad01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\69EA2AEEd01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\6ABF502Cd01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\6CCA1BE7d01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\714A5A7Dd01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\79C51A6Fd01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\803E1511d01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\835C037Fd01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\937CF67Fd01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\95DD201Cd01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\9E23E22Fd01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\A78DBCD3d01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\A90EA6DCd01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\B46B6B1Bd01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\BD15C5F4d01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\C471BD49d01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\C93A5482d01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\D258F0B5d01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\E1AA3CDDd01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\E3FAD433d01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\E4CE6FF2d01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\EA0EEED5d01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\EC1EA346d01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\EF06BBDFd01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\F8ED8726d01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\F92E8770d01 Status: Hidden


Suspect File: C:\Documents and Settings\brian\Local Settings\Application Data\Mozilla\Firefox\Profiles\et54xjm1.default\Cache\FCF6FE2Bd01 Status: Hidden


Suspect File: C:\RECYCLER\S-1-5-21-1123561945-1383384898-1417001333-1003\Dc5.scr Status: Hidden


Suspect File: C:\RECYCLER\S-1-5-21-1123561945-1383384898-1417001333-1003\Dc5.scr Status: Hidden


Suspect File: C:\RECYCLER\S-1-5-21-1123561945-1383384898-1417001333-1003\Dc5.scr Status: Hidden


Suspect File: C:\RECYCLER\S-1-5-21-1123561945-1383384898-1417001333-1003\Dc5.scr Status: Hidden

==============================================
>Hooks

ntoskrnl.exe+0x00004AA2, Type: Inline - RelativeJump at address 0x804DBAA2 hook handler located in [ntoskrnl.exe]
ntoskrnl.exe+0x0000BABC, Type: Inline - RelativeJump at address 0x804E2ABC hook handler located in [ntoskrnl.exe]
ntoskrnl.exe-->KeFindConfigurationNextEntry, Type: Inline - RelativeJump at address 0x806AA85D hook handler located in [ntoskrnl.exe]
[2236]plugin-container.exe-->user32.dll-->TrackPopupMenu, Type: Inline - RelativeJump at address 0x7E465316 hook handler located in [xul.dll]
[2948]firefox.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump at address 0x7C9163C3 hook handler located in [firefox.exe]
[3080]explorer.exe-->kernel32.dll-->GetProcAddress, Type: IAT modification at address 0x01001268 hook handler located in [shimeng.dll]

2 Intern

 • 

1.5K Posts

November 10th, 2010 17:00

Hi,

 

Please download ComboFix.exe. Please visit THIS webpage for download links, and instructions for running the tool:

ComboFix MUST be saved to your desktop before running the tool

* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

When prompted to install the recovery console please make sure to do so as this is a VERY IMPORTANT backup of ComboFix (XP only, Vista/Windows 7 will NOT be propmted to install the recovery console)

You will need to be conected to the net to install the recovery console, if you can not install it DO NOT run ComboFix,
Post back and we will install it manually.

DO NOT mouse click when ComboFix is running as this will cause ComboFix to Stall and it will not work as it should

EXTRA NOTES:

  • If Combofix detects a Rootkit on the system it will give a warning and prompt for a reboot, please allow it to do so.
  • If Combofix reboot's due to a rootkit, the screen may stay black for a few minutes on reboot, this is normal
  • On some Vista machines, after running Combofix, you may receive a warning message about registry key's being listed for deletion, when trying to open certain programs. Please reboot the system and this will fix the issue (These certain items will not be deleted)

 

Please include the C:\ComboFix.txt in your next reply for further review.

Thanks,
K27.

20 Posts

November 11th, 2010 12:00

sorry could not do. combo would not run completely. in windows task manager took 99  100 percent of resources. the small box show but then zip. the greeen progress line would show.   it would not shut off, i had to manually show computer off.

2 Intern

 • 

1.5K Posts

November 12th, 2010 12:00

Hi,

You are using AVG, this is well known for interfering with Combofix. Please uninstall AVG via Add/Remove Programs in control panel.

Then please download and run the AVG Remover (32bit) from the AVG web site and then please reboot the system.

 

Once the system has rebooted, please re-run Combofix. You will be prompted for an update, please allow COmbofix to do so.

Post back the Combofix log if you are able to get one.

Thanks.

20 Posts

November 12th, 2010 18:00

i had already done that but since you said so i did so again and even uninstalled spybot search and destroy for good measure.

before i got your email i was looking at all the ghosted images of attached devices in device manager. there were a slew of them.

windows will put some back on reboot even if their drivers are deleted. windows must get the drivers from somewhere  besides the dll cache or cab files.

catch me ran fine after that. renamed it to something else because i saw that on the net.  catch me kept insisting that the avg scanner was active (which i could not find in task manager or in the files.

 

ComboFix 10-11-12.01 - brianjohn 11/12/2010  20:52:22.6.1 - x86
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.2046.1597 [GMT -5:00]
Running from: c:\documents and settings\brianjohn\Desktop\wehavenobanannas.exe
AV: AVG Anti-Virus Free Edition 2011 *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\Downloaded Program Files\ODCTOOLS
c:\windows\system32\drivers\etc\hosts1
c:\windows\system32\scvideo.dll

.
(((((((((((((((((((((((((   Files Created from 2010-10-13 to 2010-11-13  )))))))))))))))))))))))))))))))
.

2010-11-12 11:23 . 2010-11-12 11:23    --------    d-----w-    c:\documents and settings\brianjohn\Local Settings\Application Data\AVG Security Toolbar
2010-11-12 09:03 . 2010-11-12 23:56    --------    d-----w-    c:\program files\Spybot - Search & Destroy
2010-11-11 21:37 . 2010-11-11 21:37    --------    d-----w-    c:\documents and settings\brian\Local Settings\Application Data\ApplicationHistory
2010-11-11 18:50 . 2010-11-11 18:50    --------    d-----w-    c:\documents and settings\brian\Application Data\Apple Computer
2010-11-11 18:35 . 2010-11-11 18:35    --------    d-----w-    c:\documents and settings\brian\Local Settings\Application Data\Apple Computer
2010-11-11 08:30 . 2010-11-11 08:32    --------    d-----w-    c:\program files\TZEdit
2010-11-11 07:28 . 2010-11-11 07:28    --------    d-----w-    c:\documents and settings\brian\Application Data\ElevatedDiagnostics
2010-11-11 06:10 . 2010-11-11 06:10    --------    d-----w-    c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-11-10 20:01 . 2010-11-10 20:01    --------    d-----w-    C:\$AVG
2010-11-10 19:28 . 2010-11-10 19:28    --------    d-----w-    c:\documents and settings\brian\Application Data\AVG10
2010-11-10 19:27 . 2010-11-10 19:27    --------    d--h--w-    c:\documents and settings\All Users\Application Data\Common Files
2010-11-10 19:22 . 2010-11-10 19:26    --------    d-----w-    c:\documents and settings\All Users\Application Data\MFAData
2010-11-10 18:52 . 2010-11-10 18:52    --------    d-----w-    c:\program files\Microsoft.NET
2010-11-10 18:21 . 2010-09-10 05:58    12800    -c----w-    c:\windows\system32\dllcache\xpshims.dll
2010-11-10 18:21 . 2010-09-10 05:58    247808    -c----w-    c:\windows\system32\dllcache\ieproxy.dll
2010-11-10 18:21 . 2010-09-10 05:58    743424    -c----w-    c:\windows\system32\dllcache\iedvtool.dll
2010-11-10 18:07 . 2010-11-10 18:07    --------    d-----w-    c:\documents and settings\brian\Local Settings\Application Data\Help
2010-11-10 15:00 . 2010-11-10 15:12    --------    d-----w-    c:\documents and settings\All Users\Application Data\Norton
2010-11-10 11:57 . 2010-11-10 11:57    --------    d-----w-    c:\program files\Safer Networking
2010-11-10 07:44 . 2010-11-10 07:44    --------    d-----w-    c:\documents and settings\brian\Application Data\SystemRequirementsLab
2010-11-10 06:57 . 2010-11-10 06:57    --------    d-----w-    c:\documents and settings\brian\Local Settings\Application Data\BVRP Software
2010-11-10 06:39 . 2010-11-10 06:39    --------    d-----w-    c:\documents and settings\brian\Application Data\Malwarebytes
2010-11-10 06:19 . 2010-11-10 19:27    --------    d-sh--w-    c:\documents and settings\LocalService\IETldCache
2010-11-10 01:59 . 2010-11-10 01:59    --------    d-----w-    c:\documents and settings\brian\Application Data\Yahoo!
2010-11-10 01:36 . 2010-11-10 01:36    --------    d-----w-    c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2010-11-10 01:31 . 2010-11-10 01:31    --------    d-----w-    c:\documents and settings\brian\Local Settings\Application Data\Temp
2010-11-10 01:31 . 2010-11-10 01:31    --------    d-----w-    c:\documents and settings\LocalService\Local Settings\Application Data\Google
2010-11-10 01:30 . 2010-11-10 01:30    --------    d-----w-    c:\documents and settings\brian\Local Settings\Application Data\Google
2010-11-10 00:55 . 2010-11-11 18:33    --------    d-----w-    c:\documents and settings\brian\Application Data\OpenOffice.org2
2010-11-09 12:20 . 2010-11-10 03:44    --------    d-----w-    c:\documents and settings\brian\Application Data\Paltalk
2010-11-09 06:35 . 2010-11-09 06:35    --------    d-----w-    c:\documents and settings\brianjohn\Application Data\GoodSync
2010-11-09 00:09 . 2010-11-09 00:09    --------    d-----w-    c:\program files\MSXML 4.0
2010-11-08 23:49 . 2010-11-08 23:49    --------    d-----w-    c:\documents and settings\brianjohn\Local Settings\Application Data\Little_Apps_(http___www.l
2010-11-08 01:23 . 2010-11-08 01:23    --------    d-----w-    c:\program files\Common Files\Little Registry Cleaner
2010-11-08 01:20 . 2010-11-08 01:20    --------    d-----w-    c:\program files\Little Registry Cleaner
2010-11-07 07:01 . 2010-11-07 07:01    --------    d-----w-    c:\documents and settings\brianjohn\Local Settings\Application Data\WMTools Downloaded Files
2010-11-04 07:11 . 2010-11-07 06:21    --------    d-----w-    c:\documents and settings\brianjohn\Application Data\Paltalk
2010-11-04 05:14 . 2010-11-10 18:04    --------    d-sh--w-    c:\documents and settings\brianjohn\PrivacIE
2010-11-04 05:09 . 2010-11-04 05:09    --------    d-----w-    c:\documents and settings\brianjohn\Local Settings\Application Data\ATI
2010-11-04 05:09 . 2010-11-04 05:09    --------    d-----w-    c:\documents and settings\brianjohn\Application Data\ATI
2010-11-04 05:09 . 2010-11-12 06:57    --------    d-sh--w-    c:\documents and settings\brianjohn\IETldCache
2010-11-03 06:43 . 2010-11-10 15:57    --------    d-----w-    C:\found.000
2010-11-02 22:36 . 2003-11-21 23:26    118784    ----a-w-    c:\windows\system32\Prounstl.exe
2010-11-02 22:31 . 2010-11-10 07:44    --------    d-----w-    c:\program files\SystemRequirementsLab
2010-11-02 20:36 . 2004-02-19 01:40    12288    ----a-w-    c:\windows\system32\e100bmsg.dll
2010-11-02 20:36 . 2003-07-28 14:55    24064    ----a-w-    c:\windows\system32\IntelNic.dll
2010-11-02 20:32 . 2010-11-10 18:10    --------    d-sh--w-    c:\documents and settings\brian\PrivacIE
2010-11-02 20:14 . 2010-11-10 18:10    --------    d-sh--w-    c:\documents and settings\brian\IECompatCache
2010-11-02 17:36 . 2010-11-02 17:36    --------    d-----w-    c:\documents and settings\brian\Local Settings\Application Data\ATI
2010-11-02 17:36 . 2010-11-02 17:36    --------    d-----w-    c:\documents and settings\brian\Application Data\ATI
2010-11-02 17:36 . 2010-11-10 18:04    --------    d-sh--w-    c:\documents and settings\brian\IETldCache
2010-11-02 14:27 . 2010-11-04 05:07    --------    d-sh--w-    c:\documents and settings\Administrator\PrivacIE
2010-11-02 13:58 . 2010-11-04 05:07    --------    d-sh--w-    c:\documents and settings\Administrator\IETldCache
2010-11-02 09:51 . 2010-11-02 09:53    --------    dc-h--w-    c:\windows\ie8
2010-11-01 20:09 . 2009-10-10 06:31    315408    ----a-w-    c:\windows\system32\drivers\7755189.sys
2010-11-01 13:34 . 2010-10-28 20:23    2217088    ----a-w-    c:\windows\system32\BootMan.exe
2010-11-01 13:34 . 2010-07-15 16:44    86408    ----a-w-    c:\windows\system32\setupempdrv03.exe
2010-11-01 13:34 . 2010-07-15 16:44    8456    ----a-w-    c:\windows\system32\EuGdiDrv.sys
2010-11-01 13:34 . 2010-07-15 16:44    13192    ----a-w-    c:\windows\system32\epmntdrv.sys
2010-11-01 13:34 . 2010-07-15 16:44    14848    ----a-w-    c:\windows\system32\EuEpmGdi.dll
2010-11-01 13:34 . 2010-11-01 13:34    --------    d-----w-    c:\program files\EASEUS
2010-11-01 13:03 . 2010-11-01 13:03    472808    ----a-w-    c:\windows\system32\deployJava1.dll
2010-11-01 13:03 . 2010-11-01 13:03    472808    ----a-w-    c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
2010-11-01 02:36 . 2008-02-27 21:49    3840    ----a-w-    c:\windows\system32\drivers\BANTExt.sys
2010-10-31 15:55 . 2010-11-09 07:02    --------    d-----w-    C:\NYCODE7A
2010-10-29 12:21 . 2010-11-04 03:51    --------    d-----w-    c:\documents and settings\Administrator\Application Data\vlc
2010-10-29 07:58 . 2010-10-29 07:58    --------    d-----w-    c:\documents and settings\All Users\Application Data\ATI
2010-10-29 07:58 . 2010-10-29 07:58    --------    d-----w-    c:\documents and settings\Administrator\Local Settings\Application Data\ATI
2010-10-29 07:58 . 2010-10-29 07:58    --------    d-----w-    c:\documents and settings\Administrator\Application Data\ATI
2010-10-29 07:34 . 2010-10-29 07:34    --------    d-----w-    c:\program files\Common Files\ATI Technologies
2010-10-29 07:33 . 2004-07-09 12:26    52096    -c--a-w-    c:\windows\system32\dllcache\msdv.sys
2010-10-29 07:33 . 2004-07-09 12:26    52096    ----a-w-    c:\windows\system32\drivers\msdv.sys
2010-10-29 07:33 . 2004-07-09 12:26    15104    -c--a-w-    c:\windows\system32\dllcache\mpe.sys
2010-10-29 07:33 . 2004-07-09 12:26    15104    ----a-w-    c:\windows\system32\drivers\mpe.sys
2010-10-29 07:33 . 2004-07-09 12:26    11392    -c--a-w-    c:\windows\system32\dllcache\bdasup.sys
2010-10-29 07:33 . 2004-07-09 12:26    11392    ----a-w-    c:\windows\system32\drivers\bdasup.sys
2010-10-29 07:33 . 2004-07-09 12:26    16896    ----a-w-    c:\windows\system32\bdaplgin.ax
2010-10-29 07:32 . 2002-12-12 08:14    12288    ----a-w-    c:\windows\system32\ksolay.ax
2010-10-29 07:32 . 2002-12-12 08:14    46592    ----a-w-    c:\windows\system32\dxdllreg.exe
2010-10-29 07:31 . 2009-09-30 05:15    593920    ------w-    c:\windows\system32\ati2sgag.exe
2010-10-29 07:30 . 2010-10-29 07:36    --------    d-----w-    c:\program files\ATI Technologies
2010-10-29 05:18 . 2010-10-29 05:18    0    ----a-w-    c:\windows\ativpsrm.bin
2010-10-29 05:18 . 2010-01-20 05:38    307200    ----a-r-    c:\windows\system32\atiiiexx.dll
2010-10-29 05:18 . 2010-01-20 05:38    442368    ----a-r-    c:\windows\system32\ATIDEMGX.dll
2010-10-29 05:15 . 2007-12-01 08:27    20992    ----a-w-    c:\windows\system32\dshowext.ax

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-01 13:03 . 2010-11-01 13:03    472808    ----a-w-    c:\windows\system32\deployJava1.dll
2010-11-01 13:03 . 2009-12-07 03:31    73728    ----a-w-    c:\windows\system32\javacpl.cpl
2010-10-28 20:23 . 2010-11-01 13:34    2217088    ----a-w-    c:\windows\system32\BootMan.exe
2010-10-19 20:51 . 2009-12-06 07:40    222080    ------w-    c:\windows\system32\MpSigStub.exe
2010-09-18 20:23 . 2004-08-04 12:00    974848    ----a-w-    c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2004-08-04 12:00    974848    ----a-w-    c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2004-08-04 12:00    954368    ----a-w-    c:\windows\system32\mfc40.dll
2010-09-18 06:53 . 2004-08-04 12:00    953856    ------w-    c:\windows\system32\mfc40u.dll
2010-09-10 05:58 . 2004-08-04 12:00    916480    ----a-w-    c:\windows\system32\wininet.dll
2010-09-10 05:58 . 2004-08-04 12:00    43520    ----a-w-    c:\windows\system32\licmgr10.dll
2010-09-10 05:58 . 2004-08-04 12:00    1469440    ----a-w-    c:\windows\system32\inetcpl.cpl
2010-09-01 11:51 . 2004-08-04 12:00    285824    ----a-w-    c:\windows\system32\atmfd.dll
2010-08-31 13:42 . 2004-08-04 12:00    1852800    ----a-w-    c:\windows\system32\win32k.sys
2010-08-27 08:02 . 2004-08-04 12:00    119808    ----a-w-    c:\windows\system32\t2embed.dll
2010-08-27 05:57 . 2004-08-04 12:00    99840    ----a-w-    c:\windows\system32\srvsvc.dll
2010-08-26 13:39 . 2004-08-04 12:00    357248    ----a-w-    c:\windows\system32\drivers\srv.sys
2010-08-26 12:52 . 2009-12-03 01:40    5120    ----a-w-    c:\windows\system32\xpsp4res.dll
2010-08-23 16:12 . 2004-08-04 12:00    617472    ------w-    c:\windows\system32\comctl32.dll
2010-08-17 13:17 . 2004-08-04 12:00    58880    ----a-w-    c:\windows\system32\spoolsv.exe
2010-08-16 08:45 . 2004-08-04 12:00    590848    ----a-w-    c:\windows\system32\rpcrt4.dll
2006-10-12 22:17 . 2006-12-05 01:28    3072    ----a-w-    c:\program files\mozilla firefox\plugins\ractrlkeyhook.dll
2006-02-13 17:07 . 2006-12-05 01:28    245408    ----a-w-    c:\program files\mozilla firefox\plugins\unicows.dll
.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-11-07 122940]

c:\documents and settings\brian\Start Menu\Programs\Startup\
OpenOffice.org 2.4.lnk - c:\program files\OpenOffice.org 2.4\program\quickstart.exe [2008-1-21 393216]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoFileAssociate"= 1 (0x1)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVFX Engine]
2006-06-09 09:11    24576    ------w-    c:\program files\Creative\Creative Live! Cam\VideoFX\StartFX.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2007-12-01 05:26    15360    ------w-    c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTxfiHlp]
2007-04-09 20:32    19968    ----a-w-    c:\windows\system32\Ctxfihlp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (rootkit-scan)]
2010-04-29 23:39    1090952    ----a-w-    c:\program files\Malwarebytes' Anti-Malware\mbam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-11 07:08    417792    ----a-w-    c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoboForm]
2010-11-07 12:07    160328    ----a-w-    c:\program files\Siber Systems\AI RoboForm\robotaskbaricon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
2004-10-14 18:42    1404928    ----a-w-    c:\program files\Analog Devices\Core\smax4pnp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
2009-09-30 05:13    61440    ----a-w-    c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 19:44    248552    ----a-w-    c:\program files\Common Files\Java\Java Update\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2009-11-15 09:02    198160    ----a-w-    c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VeohPlugin]
2010-07-06 14:01    2634048    ----a-w-    c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2006-10-19 01:05    204288    ------w-    c:\program files\Windows Media Player\wmpnscfg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"FLEXnet Licensing Service"=3 (0x3)
"NetSvc"=3 (0x3)
"AVGEMS"=2 (0x2)
"Avg7UpdSvc"=2 (0x2)
"Avg7Alrt"=2 (0x2)
"SeaPort"=3 (0x3)
"YahooAUService"=2 (0x2)
"MsMpSvc"=2 (0x2)
"WudfSvc"=3 (0x3)
"WPFFontCache_v0400"=3 (0x3)
"Wmi"=3 (0x3)
"VSS"=3 (0x3)
"TrkWks"=3 (0x3)
"TlntSvr"=3 (0x3)
"SysmonLog"=3 (0x3)
"SwPrv"=3 (0x3)
"SSDPSRV"=3 (0x3)
"Schedule"=2 (0x2)
"RasAuto"=3 (0x3)
"PolicyAgent"=2 (0x2)
"NtmsSvc"=3 (0x3)
"NetTcpPortSharing"=3 (0x3)
"napagent"=3 (0x3)
"MSIServer"=2 (0x2)
"MSDTC"=3 (0x3)
"JavaQuickStarterService"=2 (0x2)
"ImapiService"=3 (0x3)
"idsvc"=3 (0x3)
"HTTPFilter"=3 (0x3)
"hkmsvc"=3 (0x3)
"gupdate"=2 (0x2)
"FontCache3.0.0.0"=3 (0x3)
"EapHost"=3 (0x3)
"Dot3svc"=3 (0x3)
"Dnscache"=3 (0x3)
"dmserver"=3 (0x3)
"dmadmin"=3 (0x3)
"Creative Audio Engine Licensing Service"=3 (0x3)
"COMSysApp"=3 (0x3)
"clr_optimization_v4.0.30319_32"=2 (0x2)
"aspnet_state"=3 (0x3)
"AppMgmt"=3 (0x3)
"ALG"=3 (0x3)
"CTAudSvcService"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\msiexec.exe"=
"c:\\Program Files\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"86:TCP"= 86:TCP:*:Disabled:BroadCam Video Streaming Server TCP/IP Port
"4100:UDP"= 4100:UDP:uPNP Router Control Port

R1 kbfilter;Keyboard Filter Driver;c:\windows\system32\drivers\kbfilter.sys [1/1/2008 10:04 AM 14624]
S1 SASDIFSV;SASDIFSV;\??\c:\program files\SUPERAntiSpyware\SASDIFSV.SYS --> c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [?]
S1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.SYS --> c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [?]
S2 SCRCAMHRDRV;ScreenCamera HR;c:\windows\system32\drivers\SCRCAMHRDRV.sys [11/22/2009 10:28 PM 234304]
S3 BENDER;Pinnacle DV/AV Capture;c:\windows\system32\drivers\bender.sys [8/13/2005 5:18 AM 203264]
S3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\system32\drivers\COMMONFX.SYS --> c:\windows\system32\drivers\COMMONFX.SYS [?]
S3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.SYS --> c:\windows\system32\drivers\COMMONFX.SYS [?]
S3 cpudrv;cpudrv;c:\program files\SystemRequirementsLab\cpudrv.sys [12/18/2009 2:58 PM 11336]
S3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\system32\drivers\CTAUDFX.SYS --> c:\windows\system32\drivers\CTAUDFX.SYS [?]
S3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.SYS --> c:\windows\system32\drivers\CTAUDFX.SYS [?]
S3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\system32\drivers\CTERFXFX.SYS --> c:\windows\system32\drivers\CTERFXFX.SYS [?]
S3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.SYS --> c:\windows\system32\drivers\CTERFXFX.SYS [?]
S3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\system32\drivers\CTSBLFX.SYS --> c:\windows\system32\drivers\CTSBLFX.SYS [?]
S3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.SYS --> c:\windows\system32\drivers\CTSBLFX.SYS [?]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [11/1/2010 8:34 AM 13192]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [11/1/2010 8:34 AM 8456]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\31.tmp --> c:\windows\system32\31.tmp [?]
S3 ptiusbf;PTI USB Filter;c:\windows\system32\drivers\ptiusbf.sys [4/14/2001 12:22 AM 22474]
S3 rkhdrv40;Rootkit Unhooker Driver;
S3 WsAudio_DeviceS(1);WsAudio_DeviceS(1);c:\windows\system32\drivers\WsAudio_DeviceS(1).sys [11/11/2009 1:22 PM 25704]
S3 WsAudio_DeviceS(2);WsAudio_DeviceS(2);c:\windows\system32\drivers\WsAudio_DeviceS(2).sys [11/11/2009 1:22 PM 25704]
S3 WsAudio_DeviceS(3);WsAudio_DeviceS(3);c:\windows\system32\drivers\WsAudio_DeviceS(3).sys [11/11/2009 1:23 PM 25704]
S3 WsAudio_DeviceS(4);WsAudio_DeviceS(4);c:\windows\system32\drivers\WsAudio_DeviceS(4).sys [11/11/2009 1:23 PM 25704]
S3 WsAudio_DeviceS(5);WsAudio_DeviceS(5);c:\windows\system32\drivers\WsAudio_DeviceS(5).sys [11/11/2009 1:23 PM 25704]
S4 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\AVGIDSDriver.Sys --> c:\windows\system32\DRIVERS\AVGIDSDriver.Sys [?]
S4 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys --> c:\windows\system32\DRIVERS\AVGIDSEH.Sys [?]
S4 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\AVGIDSFilter.Sys --> c:\windows\system32\DRIVERS\AVGIDSFilter.Sys [?]
S4 AVGIDSShim;AVGIDSShim;c:\windows\system32\DRIVERS\AVGIDSShim.Sys --> c:\windows\system32\DRIVERS\AVGIDSShim.Sys [?]
S4 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 4:16 PM 130384]
S4 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2/6/2010 3:29 PM 79360]
S4 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [11/9/2010 8:31 PM 136176]
S4 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;c:\windows\system32\dllhost.exe [8/4/2004 7:00 AM 5120]
S4 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 4:16 PM 753504]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - RDPNP

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9C450606-ED24-4958-92BA-B8940C99D441}]
2009-03-04 21:32    8192    ----a-w-    c:\program files\PixiePack Codec Pack\InstallerHelper.exe
.
Contents of the 'Scheduled Tasks' folder

2009-11-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]

2009-11-18 c:\windows\Tasks\Disk Cleanup.job
- c:\windows\system32\cleanmgr.exe [2004-08-04 05:26]

2007-12-25 c:\windows\Tasks\System Restore.job
- c:\windows\system32\Restore\rstrui.exe [2006-11-26 05:26]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4}
FF - ProfilePath - c:\documents and settings\brianjohn\Application Data\Mozilla\Firefox\Profiles\8c798w91.default\
FF - component: c:\program files\Real\RealPlayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll
FF - component: c:\program files\Siber Systems\AI RoboForm\Firefox\components\rfproxy_31.dll
FF - plugin: c:\documents and settings\Administrator\Application Data\Move Networks\plugins\npqmp071505000011.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npagent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npJoostPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npRACtrl.dll
FF - plugin: c:\program files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\npWebPlayerVideoPluginATL.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true);  // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true);  // Simplified
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -

BHO-{31B27F2D-6BC6-451B-B3D2-4EAB36B2FC3B} - (no file)
BHO-{FF6C3CF0-4B15-11D1-ABED-709549C10000} - (no file)
ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - (no file)
Notify-avgrsstarter - (no file)
MSConfigStartUp-AVG_TRAY - c:\program files\AVG\AVG10\avgtray.exe
MSConfigStartUp-CTHelper - CTHELPER.EXE
MSConfigStartUp-mmtask - c:\program files\MusicMatch\MusicMatch Jukebox\mmtask.exe
MSConfigStartUp-MMTray - c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
MSConfigStartUp-P1370Mon - c:\windows\P1370Mon.exe
MSConfigStartUp-SpybotSD TeaTimer - c:\program files\Spybot - Search & Destroy\TeaTimer.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-11-12 20:58
Windows 5.1.2600 Service Pack 3, v.5973 NTFS

scanning hidden processes ... 

scanning hidden autostart entries ...

scanning hidden files ... 

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet004\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\31.tmp"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(356)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(2036)
c:\windows\system32\WININET.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\msiexec.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2010-11-12  21:02:18 - machine was rebooted
ComboFix-quarantined-files.txt  2010-11-13 02:02

Pre-Run: 25,236,566,016 bytes free
Post-Run: 25,240,883,200 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="y" y
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
[spybotsd]
timeout.old=3

- - End Of File - - 454BB91F276D7F1AB5973E63831FAA01

2 Intern

 • 

1.5K Posts

November 14th, 2010 05:00

Hi,

Please re-download the AVG Removal Tool and run it again. Remember that you need the first one in the list.

Then please download the Norton Removal Tool, and then run the tool. If you exact product is not listed, choose the one that is named closest to yours.

 

 

PLEASE BE SURE TO DISABLE ALL PROTECTIVE SOFTWARE THAT IS RUNNING ON YOUR MACHINE BEFORE RUNNING COMBOFIX, SO THAT COMBOFIX IS NOT HINDERED IN ITS REMOVAL PROCESS

Please Disable all Anti-virus/Anti-Spyware/FireWall on your machine(instructions via links below)

 

Next we are going to run ComboFix in a slightly different way

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quote box below into it:

Quote:

http://en.community.dell.com/support-forums/virus-spyware/f/3521/p/19351080/19773784.aspx#19773784

Suspect::[108]
c:\windows\system32\e100bmsg.dll
c:\windows\system32\drivers\7755189.sys
c:\program files\SystemRequirementsLab\cpudrv.sys
c:\windows\system32\epmntdrv.sys
c:\windows\system32\EuGdiDrv.sys

DirLook::
C:\NYCODE7A









Save this as CFScript.txt, in the same location as ComboFix.exe

CFScriptB-4.gif

Refering to the picture above, drag CFScript into ComboFix.exe (NOTE: You may receive a message that there is a newer version of Combofix available, please allow Combofox to update if you get this message)

You are going to be prompted at the end of the Combofix scan that files need to be uploaded for analysis, please answer yes to this.

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

NOTE: If ComboFix does not reboot the system, please do so manually

 

 

Then please leave all active protection disabled before running the next Scan

 

Go here to run an online scannner from ESET.

  • Note: You will need to use Internet explorer for this scan
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic and also let me know how things are now.

 

Please copy/paste the new Combofix log and the ESET report back for review.

Thanks.

K27.

20 Posts

November 14th, 2010 18:00

my aplogies, but i cannot do this tonight, as i have an fever etc. perhaps tomorrow.

 

thanks

brian

2 Intern

 • 

1.5K Posts

November 16th, 2010 15:00

Hi,

Do you still require assistance?

Thanks.

No Events found!

Top