PDA

View Full Version : Malware/rootkit/something?



Cent1
2010-02-21, 07:37
I'm pretty sure I have adware/malware of some sort on my computer, and it may be related to a problem I had about a month and a half ago. (Log at end of post, if I shouldn't have done the description and you want to skip it)

First, this is the first time I've used the forum (last time I e-mailed), so I apologize if I'm not doing something right.

So, last month my computer became infected with a rootkit/malware (specifically the TDSS rootkit). My anti-virus (Norton) would not run, Malwarebytes couldn't run unless I changed the name, spybot wouldn't run unless I went in an alternate way, etc. I managed to get that resolved, or so I thought. About two weeks ago, on Tuesday or Wednesday, I turned off my computer for the first time in a few days. When I did so, I also installed updates (the Feb 9th updates). The next morning, when I turned on my computer, Norton said it was turned off and I wasn't able to figure out why. I didn't really think much of it. After a few days or so, I restarted my computer, and it then opened/ran fine, as far as I can tell. Just to make sure everything was fine, I scanned the system with Malwarebytes/Spybot/Norton and none of them found anything major. LiveUpdate still works for Norton. They also all opened fine, so I was pretty sure that nothing had happened.
However, more recently, there have been signs something is up. Sometimes my google searches are redirected when I click on the link (happens less often recently) and my norton is blocking "attempts to attack my computer". When I look at these, I get one message pretty frequently: the application path is \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\SVCHOST.EXE, and the attacking IP is the same (basically) in all cases. Also, the Risk Name is labeled HTTPS Tidserv Request 2 (which a google search implies is related to my earlier problem, but you would know more about that than I would. I'm also getting other messages, like C:\windows\explorer.exe trying to send a "Terminate Message" to various .exe files within C:\Program Files\Norton Internet Security . I assume that's something trying to shut down Norton (=bad, presumably). I also occasionally get a different attacking IP; this is labeled as a "Portscan". This IP is seems close or identical to my IP.
Finally, Google Chrome (the browser I normally use) doesn't appear to be working. I'm using Firefox for this; haven't tried IE.

It seems Norton has also been detecting "Trojan Horse" and "Trojan.Malscript!html". This looks more recent than the other alerts.
It seems (looking through my security history) as though after I cleared out the last malware, the first two major events are the quarantine of "Backdoor.Tidserv" and of "Packed.Generic.277", both of which were fully removed. Then there were a series of attempted Unauthorized Accesses to my norton .exe files (just the first day), but I can't tell whether they were blocked, or just "logged". After that, there was a period of about a month when nothing happened apart from the occasional explorer.exe trying to mess with Norton. On the 30th the Portscan IP starts "intrusion attempts" every 3 or so seconds. Two different IPs, actually. This stops on the 31st (largely). Then on the 10th of this month, as mentioned above, Intrusion Prevention has been disabled. Same with Browser Protection for IE and Firefox. Also, the terminate notices to my Norton .exe files began significantly before the malware a month and a half ago.

I downloaded and started HijackThis, and when it began and a prompt came up I selected "Run scan and save log" (or something like that). This log was taken earlier today, and it was taken with my external hard drive in, if that matters (I sometimes use it as a spot to download files, so there's a chance whatever I have could be there I guess. Again, you would know more than me, just giving info). Thanks for any help you can provide (and apologies if my description was way too long)!





Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:21:52 AM, on 2/20/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Anti-Blaxx\Anti-Blaxx.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Curse\CurseClient.exe
C:\program files\steam\steam.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
C:\Documents and Settings\Russell Klare\Local Settings\Application Data\Google\Update\1.2.183.13\GoogleCrashHandler.exe
C:\Program Files\Vongo\Tray.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Vongo\VongoService.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe
C:\PROGRA~1\HPQ\Shared\HPQTOA~1.EXE
C:\Program Files\Norton Internet Security\Engine\16.8.0.41\MCUI32.EXE
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\VideoLAN\VLC\vlc.exe
C:\Program Files\Norton Internet Security\Engine\16.8.0.41\mcui32.exe
C:\Program Files\SpybotSD\TeaTimer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Norton Internet Security\Engine\16.8.0.41\MCUI32.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\SpybotSD\SDHelper.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\IPSBHO.DLL
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O2 - BHO: (no name) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - (no file)
O2 - BHO: (no name) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\coIEPlg.dll
O3 - Toolbar: SciFinder Scholar Bar - {4e16a8fb-0521-46d1-aa2c-d0fc7abf6af9} - mscoree.dll (file missing)
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [Anti-Blaxx Manager] C:\Program Files\Anti-Blaxx\Anti-Blaxx.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\IGN\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Russell Klare\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\SpybotSD\TeaTimer.exe
O4 - HKCU\..\Run: [CurseClient] C:\Program Files\Curse\CurseClient.exe -silent
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - S-1-5-18 Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Registration Ghost Recon Advanced Warfighter.LNK = C:\Program Files\Ubisoft\Ghost Recon Advanced Warfighter\Support\Register\RegistrationReminder.exe
O4 - Startup: Vongo Tray.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\SpybotSD\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\SpybotSD\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
O16 - DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} (Hewlett-Packard Online Support Services) - http://h50203.www5.hp.com/HPISWeb/Customer/cabs/HPISDataManager.CAB
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{738B480C-1CAC-4004-863E-3ED776804BF9}: NameServer = 134.173.63.200,134.173.254.23
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\coIEPlg.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPBPRO.EXE
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton Internet Security - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Vongo Service - Starz Entertainment Group LLC - C:\Program Files\Vongo\VongoService.exe

--
End of file - 13160 bytes

ken545
2010-02-22, 19:02
Hello

Welcome to Safer Networking.

Please read Before You Post (http://forums.spybot.info/showthread.php?t=288)
While best efforts are made to assist in removing infections safely, unexpected stuff can happen. It is advisable that you back up your important data before starting any clean up procedure. Neither Safer Networking Forums nor the Analyst providing the advice may be held responsible for any loss.



Please download DeFogger (http://www.jpshortstuff.247fixes.com/Defogger.exe) to your desktop.

Double click DeFogger to run the tool.

The application window will appear
Click the Disable button to disable your CD Emulation drivers
Click Yes to continue
A 'Finished!' message will appear
Click OK
DeFogger will now ask to reboot the machine - click OK

IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

Do not re-enable these drivers until otherwise instructed.





Next:

Please download GMER from one of the following locations and save it to your desktop:
Main Mirror (http://gmer.net/download.php)
This version will download a randomly named file (Recommended)
Zipped Mirror (http://gmer.net/gmer.zip)
This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.

Disconnect from the Internet and close all running programs.
Temporarily disable any real-time active protection (http://forums.whatthetech.com/How_Disable_your_Security_Programs_t96260.html) so your security programs will not conflict with gmer's driver.
Double-click on the randomly named GMER file (i.e. n7gmo46c.exe) and allow the gmer.sys driver to load if asked.
Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then double-click on gmer.exe.

http://img.photobucket.com/albums/v666/sUBs/gmer_zip.gif

GMER will open to the Rootkit/Malware tab and perform an automatic quick scan when first run. (do not use the computer while the scan is in progress)
If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system...click NO.
Now click the Scan button. If you see a rootkit warning window, click OK.
When the scan is finished, click the Save... button to save the scan results to your Desktop. Save the file as gmer.log.
Click the Copy button and paste the results into your next reply.
Exit GMER and re-enable all active protection when done.




To re-enable your Emulation drivers, double click DeFogger to run the tool.

The application window will appear
Click the Re-enable button to re-enable your CD Emulation drivers
Click Yes to continue
A 'Finished!' message will appear
Click OK
DeFogger will now ask to reboot the machine - click OK

IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_enable which will appear on your desktop.

Your Emulation drivers are now re-enabled.





Please download Malwarebytes from Here (http://www.malwarebytes.org/mbam-download.php) or Here (http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html)

Double-click mbam-setup.exe and follow the prompts to install the program.
At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select Perform FULL scan, then click Scan.
Make sure you check all drives
http://forums.whatthetech.com/post_a4255_MBAM.PNG
When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click Remove Selected .
When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report and also a new HJT log please

Cent1
2010-02-25, 08:11
Alright, I turned off my internet/antivirus/emulation and ran the gmer scan shown below. I also got a error message titled Windows - Corrupt File with "The file or directory \System Volume Information\EfaData\SYMFEA.DB-journal is corrupt and unreadable. Please run the Chkdsk utility". After this I re-enabled my internet and anti-virus (but I still haven't re-enabled the emulation) and got the HijackThis log at the bottom of this post. I ran a Malwarebytes scan but it didn't find anything, so I didn't post the log. I can do another one and post that if you want though. UPDATE: The GMER post is too long to fit in this post, so it will be in the next one. Most of the length is a giant chunk of Civilization 4 stuff. That may go in its own post. I know the rules say not to post additional logs w/o a response but the character limit means I kind of have to.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:55:45 PM, on 2/24/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\Program Files\Anti-Blaxx\Anti-Blaxx.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Curse\CurseClient.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe
C:\Program Files\Vongo\Tray.exe
C:\Documents and Settings\Russell Klare\Local Settings\Application Data\Google\Update\1.2.183.13\GoogleCrashHandler.exe
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\PROGRA~1\HPQ\Shared\HPQTOA~1.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Vongo\VongoService.exe
C:\PROGRA~1\MICROS~4\OFFICE11\ois.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\HPZinw12.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SpybotSD\SDHelper.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\IPSBHO.DLL
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O2 - BHO: (no name) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - (no file)
O2 - BHO: (no name) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\coIEPlg.dll
O3 - Toolbar: SciFinder Scholar Bar - {4e16a8fb-0521-46d1-aa2c-d0fc7abf6af9} - mscoree.dll (file missing)
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - HKLM\..\Run: [Anti-Blaxx Manager] C:\Program Files\Anti-Blaxx\Anti-Blaxx.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\IGN\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Russell Klare\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [CurseClient] C:\Program Files\Curse\CurseClient.exe -silent
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - S-1-5-18 Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: Registration Ghost Recon Advanced Warfighter.LNK = C:\Program Files\Ubisoft\Ghost Recon Advanced Warfighter\Support\Register\RegistrationReminder.exe
O4 - Startup: Vongo Tray.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SpybotSD\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SpybotSD\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
O16 - DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} (Hewlett-Packard Online Support Services) - http://h50203.www5.hp.com/HPISWeb/Customer/cabs/HPISDataManager.CAB
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{738B480C-1CAC-4004-863E-3ED776804BF9}: NameServer = 134.173.63.200,134.173.254.23
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\coIEPlg.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPBPRO.EXE
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton Internet Security - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Vongo Service - Starz Entertainment Group LLC - C:\Program Files\Vongo\VongoService.exe

--
End of file - 12834 bytes

Cent1
2010-02-25, 08:14
The aforementioned GMER scan:



GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-02-24 10:27:42
Windows 5.1.2600 Service Pack 3
Running: 8xtdzj6s.exe; Driver: C:\DOCUME~1\RUSSEL~1\LOCALS~1\Temp\awtdauoc.sys


---- System - GMER 1.0.15 ----

SSDT 864F59F8 ZwAlertResumeThread
SSDT 864F8C00 ZwAlertThread
SSDT 857DC400 ZwAllocateVirtualMemory
SSDT 86278050 ZwAssignProcessToJobObject
SSDT 8653A500 ZwConnectPort
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwCreateKey [0xAE772130]
SSDT 857D8780 ZwCreateMutant
SSDT 8626EB38 ZwCreateSymbolicLinkObject
SSDT 863673A0 ZwCreateThread
SSDT 85778050 ZwDebugActiveProcess
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteKey [0xAE7723B0]
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xAE772910]
SSDT 857DC6D8 ZwDuplicateObject
SSDT 86276AF0 ZwFreeVirtualMemory
SSDT 863530B8 ZwImpersonateAnonymousToken
SSDT 863690B8 ZwImpersonateThread
SSDT 8657FF10 ZwLoadDriver
SSDT 86276950 ZwMapViewOfSection
SSDT 8577A050 ZwOpenEvent
SSDT 857DCAB8 ZwOpenProcess
SSDT 869EC718 ZwOpenProcessToken
SSDT 8627A050 ZwOpenSection
SSDT 857DC868 ZwOpenThread
SSDT 8626F6F0 ZwProtectVirtualMemory
SSDT 864F57F0 ZwResumeThread
SSDT 864CFB88 ZwSetContextThread
SSDT 86276638 ZwSetInformationProcess
SSDT 857DF050 ZwSetSystemInformation
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xAE772B60]
SSDT 857E0050 ZwSuspendProcess
SSDT 864AD728 ZwSuspendThread
SSDT 864FC9F8 ZwTerminateProcess
SSDT 864ECC08 ZwTerminateThread
SSDT 864CEEC0 ZwUnmapViewOfSection
SSDT 86276F00 ZwWriteVirtualMemory

---- Kernel code sections - GMER 1.0.15 ----

? C:\WINDOWS\system32\drivers\iaStor.sys The process cannot access the file because it is being used by another process.
? SYMEFA.SYS The system cannot find the file specified. !
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB6B77360, 0x33AACD, 0xE8000020]
init C:\WINDOWS\system32\drivers\tifm21.sys entry point in "init" section [0xB6B13EBF]
.text C:\WINDOWS\system32\DRIVERS\atksgt.sys section is writeable [0x9F587300, 0x3AF78, 0xE8000020]
.text C:\WINDOWS\system32\DRIVERS\lirsgt.sys section is writeable [0xB7186300, 0x1BCE, 0xE8000020]

---- User code sections - GMER 1.0.15 ----

.text C:\WINDOWS\System32\svchost.exe[1024] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 006D000A
.text C:\WINDOWS\System32\svchost.exe[1024] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 006E000A
.text C:\WINDOWS\System32\svchost.exe[1024] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 006C000C
.text C:\WINDOWS\System32\svchost.exe[1024] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 0188000A
.text C:\WINDOWS\Explorer.EXE[1436] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00B7000A
.text C:\WINDOWS\Explorer.EXE[1436] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00C1000A
.text C:\WINDOWS\Explorer.EXE[1436] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00B6000C
.text C:\WINDOWS\system32\wuauclt.exe[2352] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00C2000A
.text C:\WINDOWS\system32\wuauclt.exe[2352] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00C3000A
.text C:\WINDOWS\system32\wuauclt.exe[2352] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00C1000C

---- Devices - GMER 1.0.15 ----

Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
Device Fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)

AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 eabfiltr.sys (QLB PS/2 Keyboard filter driver/Hewlett-Packard Development Company, L.P.)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)

AttachedDevice fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xF4 0xB1 0xFB 0x09 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xB3 0x78 0x3A 0x56 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x86 0x28 0x29 0x41 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xF4 0xB1 0xFB 0x09 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xB3 0x78 0x3A 0x56 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x27 0xFB 0x36 0x5C ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xF4 0xB1 0xFB 0x09 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xB3 0x78 0x3A 0x56 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x0C 0xE1 0x07 0xD3 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xF4 0xB1 0xFB 0x09 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xB3 0x78 0x3A 0x56 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xF1 0x41 0x2F 0x06 ...
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xF4 0xB1 0xFB 0x09 ...
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xB3 0x78 0x3A 0x56 ...
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xC9 0x28 0x9D 0x67 ...
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xF4 0xB1 0xFB 0x09 ...
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xB3 0x78 0x3A 0x56 ...
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x26 0x66 0x38 0xF7 ...
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xF4 0xB1 0xFB 0x09 ...
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xB3 0x78 0x3A 0x56 ...
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x1C 0x46 0x31 0x29 ...
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xF4 0xB1 0xFB 0x09 ...
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xB3 0x78 0x3A 0x56 ...
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x6C 0x58 0xE0 0xC1 ...
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xF4 0xB1 0xFB 0x09 ...
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xB3 0x78 0x3A 0x56 ...
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xCF 0x8E 0x70 0x79 ...
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xF4 0xB1 0xFB 0x09 ...
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xB3 0x78 0x3A 0x56 ...
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x42 0x3F 0x12 0x6D ...
Reg HKLM\SYSTEM\ControlSet011\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet011\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet011\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xF4 0xB1 0xFB 0x09 ...
Reg HKLM\SYSTEM\ControlSet011\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet011\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet011\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet011\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xB3 0x78 0x3A 0x56 ...
Reg HKLM\SYSTEM\ControlSet011\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet011\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xA2 0xA5 0xE4 0x6E ...
Reg HKLM\SYSTEM\ControlSet012\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet012\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet012\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xF4 0xB1 0xFB 0x09 ...
Reg HKLM\SYSTEM\ControlSet012\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet012\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet012\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet012\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xB3 0x78 0x3A 0x56 ...
Reg HKLM\SYSTEM\ControlSet012\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet012\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x4C 0x75 0x82 0x63 ...
Reg HKLM\SYSTEM\ControlSet013\Services\H8SRTd.sys@start 1
Reg HKLM\SYSTEM\ControlSet013\Services\H8SRTd.sys@type 1
Reg HKLM\SYSTEM\ControlSet013\Services\H8SRTd.sys@imagepath \systemroot\system32\drivers\H8SRTywbuvbsmsa.sys
Reg HKLM\SYSTEM\ControlSet013\Services\H8SRTd.sys@group file system
Reg HKLM\SYSTEM\ControlSet013\Services\H8SRTd.sys\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet013\Services\H8SRTd.sys\modules@H8SRTd \\?\globalroot\systemroot\system32\drivers\H8SRTywbuvbsmsa.sys
Reg HKLM\SYSTEM\ControlSet013\Services\H8SRTd.sys\modules@H8SRTc \\?\globalroot\systemroot\system32\H8SRTcumeuebhdv.dll
Reg HKLM\SYSTEM\ControlSet013\Services\H8SRTd.sys\modules@H8SRTsrcr \\?\globalroot\systemroot\system32\H8SRTdttdobjkdp.dat
Reg HKLM\SYSTEM\ControlSet013\Services\H8SRTd.sys\modules@h8srtserf \\?\globalroot\systemroot\system32\H8SRTawvjaqcujk.dll
Reg HKLM\SYSTEM\ControlSet013\Services\H8SRTd.sys\modules@h8srtbbr \\?\globalroot\systemroot\system32\H8SRTlmaqlqtrji.dll
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xF4 0xB1 0xFB 0x09 ...
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xB3 0x78 0x3A 0x56 ...
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xBA 0x6E 0x0B 0xF8 ...
Reg HKLM\SYSTEM\ControlSet014\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet014\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet014\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xF4 0xB1 0xFB 0x09 ...
Reg HKLM\SYSTEM\ControlSet014\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet014\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet014\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet014\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xB3 0x78 0x3A 0x56 ...
Reg HKLM\SYSTEM\ControlSet014\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet014\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x98 0xEC 0x29 0xD8 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xF4 0xB1 0xFB 0x09 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xB3 0x78 0x3A 0x56 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xF3 0xD4 0x62 0x07 ...
Reg HKLM\SYSTEM\ControlSet016\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet016\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet016\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xF4 0xB1 0xFB 0x09 ...
Reg HKLM\SYSTEM\ControlSet016\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet016\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet016\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet016\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xB3 0x78 0x3A 0x56 ...
Reg HKLM\SYSTEM\ControlSet016\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet016\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xF3 0xD4 0x62 0x07 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{F64B1FF6-25E7-E014-BF0C-5D66ACA0DEC1}

---- Files - GMER 1.0.15 ----



As mentioned above, civ4 files must be put in a different reply due to the character limit. Those are the only files it lists.

Cent1
2010-02-25, 08:19
Here are the files it lists. Again, I apologize for the three posts, but I didn't see any way around it. NOTE that even this post was too long: I cut out the last third or so of the files. If you want them, let me know. It's pretty much the same type of stuff as these guys.




File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Structures\cities\Asian.nif 110770 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Structures\cities\asian_building.dds 174904 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Structures\cities\asian_building_shadow.dds 87536 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Structures\cities\Greco_Roman.nif 104539 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Structures\cities\Greco_Rome_building.dds 174904 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Structures\cities\Greco_Rome_shadow.dds 87536 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features 0 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark 0 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack 0 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice10_02.nif 6723 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice01_01.nif 4187 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice01_02.nif 3727 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice01_03.nif 4951 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice02_01.nif 5859 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice02_02.nif 3727 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice02_03.nif 4899 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice03_01.nif 5289 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice03_02.nif 5411 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice03_03.nif 5447 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice04_01.nif 3259 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice04_02.nif 3611 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice04_03.nif 3091 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice05_01.nif 7667 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice05_02.nif 6467 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice05_03.nif 6579 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice06_01.nif 9075 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice06_02.nif 5583 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice06_03.nif 5451 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice07_01.nif 7619 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice07_02.nif 7019 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice07_03.nif 7407 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice08_01.nif 3367 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice08_02.nif 3751 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice08_03.nif 3787 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice09_01.nif 5679 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice09_02.nif 5619 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice09_03.nif 5569 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice10_01.nif 9029 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice10_03.nif 6863 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice11_01.nif 6347 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice11_02.nif 6463 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice11_03.nif 6841 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice12_01.nif 5479 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice12_02.nif 5363 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice12_03.nif 5307 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice13_01.nif 7339 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice13_02.nif 7239 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice13_03.nif 7599 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice14_01.nif 7403 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice14_02.nif 7361 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice14_03.nif 7289 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice15_01.nif 7027 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice15_02.nif 7027 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice15_03.nif 7027 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice15_04.nif 7027 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice15_05.nif 7027 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice15_06.nif 6999 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice15_07.nif 7027 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\Ice15_08.nif 7027 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\IcePack\IcePack_1024.dds 524416 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees 0 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Evergreen12_01.nif 69293 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Leafy09_01.nif 97301 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Snowy04_01.nif 30146 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\EvergrCOMBOGrShad.dds 11064 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Evergreen01_01.nif 31097 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Evergreen02_01.nif 29755 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Evergreen03_01.nif 69539 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Evergreen04_01.nif 30157 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Evergreen05_01.nif 98547 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Evergreen06_01.nif 72317 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Evergreen07_01.nif 123241 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Evergreen08_01.nif 41021 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Evergreen09_01.nif 92034 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Evergreen10_01.nif 97935 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Evergreen11_01.nif 113606 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Leafy10_01.nif 127093 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Leafy11_01.nif 141256 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Leafy12_01.nif 100138 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Leafy13_01.nif 141521 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Leafy14_01.nif 152146 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Leafy15_01.nif 182473 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Snowy01_01.nif 31095 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Snowy02_01.nif 29744 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Snowy03_01.nif 69528 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Jungle01_01.nif 31574 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Jungle02_01.nif 37950 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Jungle03_01.nif 64605 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Jungle04_01.nif 40496 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Jungle05_01.nif 100180 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Jungle06_01.nif 77366 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Jungle07_01.nif 138124 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Jungle08_01.nif 34962 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Jungle09_01.nif 81998 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Jungle10_01.nif 106786 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Jungle11_01.nif 116450 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Jungle12_01.nif 76950 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Jungle13_01.nif 130616 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Jungle14_01.nif 133593 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Jungle15_01.nif 154506 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Leafy01_01.nif 45493 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Leafy02_01.nif 34657 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Leafy03_01.nif 90203 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Leafy04_01.nif 45601 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Leafy05_01.nif 126477 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Leafy06_01.nif 93901 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Leafy07_01.nif 152425 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Leafy08_01.nif 34857 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Snowy05_01.nif 98508 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Snowy06_01.nif 72317 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Snowy07_01.nif 123230 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Snowy08_01.nif 40982 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Snowy09_01.nif 92020 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Snowy10_01.nif 97924 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Snowy11_01.nif 112748 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Snowy12_01.nif 69274 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Snowy13_01.nif 111438 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Snowy14_01.nif 105386 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Snowy15_01.nif 132820 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Trees_1024.dds 349680 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Evergreen13_01.nif 111449 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Evergreen14_01.nif 105365 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Features\Dark\Trees\Evergreen15_01.nif 132831 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Lights 0 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Lights\SunLight.nif 771 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\PlotTextures 0 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\PlotTextures\BorderPlane.nif 8130 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\PlotTextures\TeamColor.bmp 72 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Resources 0 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Resources\cotton 0 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Resources\cotton\cotton.dds 43856 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Resources\cotton\cotton.nif 100253 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Resources\cotton\cotton_shadow.dds 5616 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Resources\Olives 0 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Resources\Olives\olives.dds 21992 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Resources\Olives\Olives.nif 90080 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Resources\Olives\olive_press.dds 22000 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Resources\Olives\Olive_press.kfm 130 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Resources\Olives\Olive_press.nif 24306 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Resources\Olives\Olive_press_freeze0000.nif 12399 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Resources\Olives\Olive_press_MD01_Worked.kf 1142 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Resources\Olives\olive_shadow.dds 11088 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Resources\tobacco 0 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Resources\tobacco\tobacco.dds 21992 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Resources\tobacco\tobacco.nif 53313 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Resources\tobacco\tobacco_shadow.dds 5616 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Textures 0 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Textures\Dark 0 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Textures\Dark\CoastBLEND.dds 699216 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Textures\Dark\CoastGRIDS.dds 699216 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Textures\Dark\DesertBLEND.dds 699216 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Textures\Dark\DesertGRIDS.dds 699216 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Textures\Dark\GrassBLEND.dds 699216 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Textures\Dark\GrassGRIDS.dds 699216 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Textures\Dark\HillBLEND.dds 1398256 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Textures\Dark\HillGRIDS.dds 1398256 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Textures\Dark\IceBLEND.dds 699216 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Textures\Dark\IceGRIDS.dds 699216 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Textures\Dark\OceanBLEND.dds 699216 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Textures\Dark\OceanGRIDS.dds 699216 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Textures\Dark\PeakBLEND.dds 1398256 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Textures\Dark\PeakGRIDS.dds 1398256 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Textures\Dark\PlainsBLEND.dds 699216 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Textures\Dark\PlainsGRIDS.dds 699216 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Textures\Dark\TundraBLEND.dds 699216 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Textures\Dark\TundraGRIDS.dds 699216 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Textures\Light 0 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Textures\Light\CoastBLEND.dds 699216 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Textures\Light\CoastGRIDS.dds 699216 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Textures\Light\GrassBLEND.dds 699216 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Textures\Light\GrassGRIDS.dds 699216 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Textures\Light\HillBLEND.dds 1398256 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Textures\Light\HillGRIDS.dds 1398256 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Textures\Light\OceanBLEND.dds 699216 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Textures\Light\OceanGRIDS.dds 699216 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Textures\Light\PeakBLEND.dds 1398256 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Textures\Light\PeakGRIDS.dds 1398256 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Textures\Light\PlainsBLEND.dds 699216 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Textures\Light\PlainsGRIDS.dds 699216 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Textures\Light\TundraBLEND.dds 699216 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Terrain\Textures\Light\TundraGRIDS.dds 699216 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Hwacha_Korean 0 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Hwacha_Korean\Hwacha_Pilot.dds 22000 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Hwacha_Korean\Hwacha.kfm 993 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Hwacha_Korean\Hwacha.nif 141574 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Hwacha_Korean\Hwacha_freeze1000.nif 67406 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Hwacha_Korean\Hwacha_freeze1031.nif 68465 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Hwacha_Korean\Hwacha_FX.nif 139894 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Hwacha_Korean\Hwacha_MD_Heal.kf 8984 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Hwacha_Korean\Hwacha_MD_HurtA.kf 10732 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Hwacha_Korean\Hwacha_MD_Idle.kf 21867 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Hwacha_Korean\Hwacha_MD_RangedDie.kf 13392 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Hwacha_Korean\Hwacha_MD_RangedDie_Fade.kf 5746 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Hwacha_Korean\Hwacha_MD_RangedFortify.kf 8466 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Hwacha_Korean\Hwacha_MD_RangedStrike.kf 8929 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Hwacha_Korean\Hwacha_MD_Ranged_Idle.kf 14764 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Hwacha_Korean\Hwacha_MD_Run.kf 12771 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Hwacha_Korean\Hwacha_Rocket.kfm 186 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Hwacha_Korean\Hwacha_Rocket.nif 20162 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Hwacha_Korean\Hwacha_Rocket_MD_Explode.kf 1090 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Hwacha_Korean\Hwacha_Rocket_MD_Run.kf 870 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Hwacha_Korean\Hwacha_w_ALPHA.dds 11064 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Hwacha_Korean\Hwacha_w_TC.dds 22000 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Spearman_Chinese 0 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Spearman_Chinese\Spearman_Chinese_MD_FortifyA.kf 8583 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Spearman_Chinese\Chinese_Spearman_128.dds 22000 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Spearman_Chinese\Chinese_Spearman_gloss.dds 5616 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Spearman_Chinese\Spearman_Chinese.kfm 3367 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Spearman_Chinese\Spearman_Chinese.nif 56130 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Spearman_Chinese\Spearman_Chinese_freeze1000.nif 20838 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Spearman_Chinese\Spearman_Chinese_freeze1021.nif 20838 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Spearman_Chinese\Spearman_Chinese_freeze2021.nif 20838 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Spearman_Chinese\Spearman_Chinese_FX.nif 54909 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Spearman_Chinese\Spearman_Chinese_MD_DieA.kf 12761 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Spearman_Chinese\Spearman_Chinese_MD_DieA_Fade.kf 4940 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Spearman_Chinese\Spearman_Chinese_MD_DieB.kf 12146 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Spearman_Chinese\Spearman_Chinese_MD_DieB_Fade.kf 4972 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Spearman_Chinese\Spearman_Chinese_MD_Fidget.kf 30772 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Spearman_Chinese\Spearman_Chinese_MD_FortifyA_Idle.kf 18295 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Spearman_Chinese\Spearman_Chinese_MD_FortifyB.kf 8569 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Spearman_Chinese\Spearman_Chinese_MD_FortifyB_Idle.kf 17671 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Spearman_Chinese\Spearman_Chinese_MD_Heal.kf 8972 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Spearman_Chinese\Spearman_Chinese_MD_HurtA.kf 8713 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Spearman_Chinese\Spearman_Chinese_MD_HurtB.kf 8309 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Spearman_Chinese\Spearman_Chinese_MD_Idle.kf 15846 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Spearman_Chinese\Spearman_Chinese_MD_Run.kf 8270 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Spearman_Chinese\Spearman_Chinese_MD_RunDie.kf 8702 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Spearman_Chinese\Spearman_Chinese_MD_RunDie_Fade.kf 4466 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Spearman_Chinese\Spearman_Chinese_MD_StrikeA.kf 8675 bytes
File C:\Program Files\Steam\steamapps\common\sid meier's civilization iv beyond the sword\Warlords\Assets\Art\Units\Spearman_Chinese\Spearman_Chinese_MD_StrikeB.kf 8899 bytes

ken545
2010-02-25, 10:22
Good Morning,

No problem on the replies, GMER is showing markers for a rootkit


Download Combofix from any of the links below. You must rename it before saving it. Save it to your desktop.

Link 1 (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
Link 2 (http://www.forospyware.com/sUBs/ComboFix.exe)


http://i266.photobucket.com/albums/ii277/sUBs_/combofix/CF_download_FF.gif


http://i266.photobucket.com/albums/ii277/sUBs_/combofix/CF_download_rename.gif

* IMPORTANT !!! Save ComboFix.exe to your Desktop


Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
See this Link (http://www.bleepingcomputer.com/forums/topic114351.html) for programs that need to be disabled and instruction on how to disable them.
Remember to re-enable them when we're done.


Double click on ComboFix.exe & follow the prompts.


As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.


Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.



http://img.photobucket.com/albums/v706/ried7/RC1.png


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

http://img.photobucket.com/albums/v706/ried7/RC2-1.png

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply along with a New Hijackthis log.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

Cent1
2010-02-26, 02:43
Here's the Combo-fix Log:

ComboFix 10-02-25.02 - Russell Klare 02/25/2010 13:10:30.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.523 [GMT -8:00]
Running from: c:\documents and settings\Russell Klare\Desktop\Combo-Fix.exe
AV: Norton Internet Security *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\srchasst\nls302en.lex

.
((((((((((((((((((((((((( Files Created from 2010-01-25 to 2010-02-25 )))))))))))))))))))))))))))))))
.

2010-02-23 07:04 . 2010-02-23 07:05 -------- d-----w- c:\program files\ERUNT
2010-02-20 02:22 . 2010-02-20 02:22 -------- d-----w- c:\program files\Trend Micro
2010-02-18 20:15 . 2010-02-18 20:15 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple Computer
2010-02-18 12:09 . 2010-02-18 12:09 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Apple Computer
2010-02-17 20:19 . 2010-02-17 20:19 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-02-17 06:23 . 2010-02-17 06:23 -------- d-----w- c:\documents and settings\Russell Klare\Local Settings\Application Data\Electronic Arts
2010-02-15 07:00 . 2010-02-15 07:00 -------- d-----w- c:\documents and settings\Russell Klare\Local Settings\Application Data\HotheadGames
2010-02-15 04:53 . 2010-02-18 19:05 -------- d-----w- c:\program files\Hothead Games
2010-02-10 04:27 . 2010-02-10 04:27 -------- d-----w- c:\program files\Norn
2010-02-05 22:29 . 2010-02-05 22:29 -------- d-----w- c:\program files\luchs
2010-02-03 23:01 . 2010-02-03 23:02 -------- d-----w- c:\documents and settings\Russell Klare\Application Data\.chimera
2010-02-03 02:48 . 2010-02-03 02:48 -------- d-----w- c:\program files\iPod
2010-02-03 02:48 . 2010-02-03 02:50 -------- d-----w- c:\program files\iTunes
2010-02-03 02:40 . 2010-02-03 02:41 -------- d-----w- c:\program files\QuickTime
2010-02-02 18:29 . 2010-02-02 18:34 -------- d-----w- c:\program files\Chimera
2010-02-02 18:29 . 2010-02-02 18:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Chimera
2010-01-31 21:29 . 2010-01-31 21:29 -------- d-----w- c:\documents and settings\Russell Klare\Application Data\BDL+D
2010-01-28 00:30 . 2010-02-15 08:50 -------- d-----w- c:\program files\SpinWorks_3

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-25 21:47 . 2009-05-25 06:35 -------- d-----w- c:\program files\Steam
2010-02-25 21:01 . 2007-11-08 04:20 -------- d-----w- c:\documents and settings\Russell Klare\Application Data\uTorrent
2010-02-25 20:49 . 2007-01-28 11:27 -------- d-----w- c:\documents and settings\Russell Klare\Application Data\vlc
2010-02-24 22:52 . 2010-01-04 23:41 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-23 20:41 . 2009-03-14 05:21 -------- d-----w- c:\documents and settings\Russell Klare\Application Data\dvdcss
2010-02-23 07:33 . 2010-01-05 21:15 -------- d-----w- c:\program files\SpybotSD
2010-02-18 20:15 . 2010-01-04 22:08 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2010-02-17 07:07 . 2010-01-22 03:47 -------- d-----w- c:\documents and settings\Russell Klare\Application Data\Waffle
2010-02-17 03:37 . 2006-08-18 01:36 -------- d-----w- c:\program files\Electronic Arts
2010-02-12 01:58 . 2006-05-10 07:51 111864 -c--a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-11 00:27 . 2009-04-01 03:18 -------- d-----w- c:\program files\Symantec
2010-02-03 02:48 . 2008-06-08 20:06 -------- d-----w- c:\program files\Common Files\Apple
2010-02-01 18:42 . 2006-05-10 05:44 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-25 23:27 . 2009-01-14 05:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Electronic Arts
2010-01-25 23:26 . 2010-01-25 23:26 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-01-25 22:51 . 2010-01-25 22:51 -------- d-----w- c:\program files\NEKOBOKU
2010-01-22 19:37 . 2009-03-19 18:09 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-08 18:16 . 2007-10-29 23:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-01-08 00:07 . 2010-01-04 23:41 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-08 00:07 . 2010-01-04 23:41 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-05 18:34 . 2009-01-30 09:51 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-01-05 08:36 . 2007-10-29 23:55 -------- d-----w- c:\program files\Spybot Old
2010-01-05 00:20 . 2010-01-05 00:20 -------- d-----w- c:\documents and settings\Russell Klare\Application Data\Malwarebytes
2010-01-05 00:06 . 2006-05-10 08:26 -------- d-----w- c:\program files\Google
2010-01-04 23:41 . 2010-01-04 23:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-31 16:50 . 2005-05-10 08:17 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:14 . 2004-08-04 21:00 916480 ----a-w- c:\windows\system32\wininet.dll
2009-12-16 18:43 . 2004-08-04 21:00 343040 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:08 . 2004-08-04 21:00 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-12-09 03:12 . 2009-12-09 03:12 279712 ----a-w- c:\windows\system32\drivers\atksgt.sys
2009-12-09 03:12 . 2009-12-09 03:12 25888 ----a-w- c:\windows\system32\drivers\lirsgt.sys
2009-12-08 19:26 . 2004-08-04 21:00 2145280 ------w- c:\windows\system32\ntoskrnl.exe
2009-12-08 18:43 . 2004-08-04 21:00 2023936 ------w- c:\windows\system32\ntkrnlpa.exe
2009-12-04 18:22 . 2005-01-19 12:26 455424 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2004-07-22 17:51 . 2004-07-22 17:51 3432656 ----a-w- c:\program files\ManagedDX.CAB
2004-07-20 05:58 . 2004-07-20 05:58 1156363 ----a-w- c:\program files\BDANT.cab
2004-07-20 05:53 . 2004-07-20 05:53 976020 ----a-w- c:\program files\BDAXP.cab
2004-07-09 21:17 . 2004-07-09 21:17 13265040 ----a-w- c:\program files\dxnt.cab
2004-07-09 16:13 . 2004-07-09 16:13 15493481 ----a-w- c:\program files\DirectX.cab
2004-07-09 16:13 . 2004-07-09 16:13 703080 ----a-w- c:\program files\BDA.cab
2004-07-09 11:08 . 2004-07-09 11:08 472576 ----a-w- c:\program files\dxsetup.exe
2004-07-09 11:08 . 2004-07-09 11:08 2242560 ----a-w- c:\program files\dsetup32.dll
2004-07-09 10:03 . 2004-07-09 10:03 62976 ----a-w- c:\program files\DSETUP.dll
2004-03-16 02:51 . 2004-03-16 02:51 114688 ----a-w- c:\program files\internet explorer\plugins\LV71ActiveXControl.dll
2008-06-30 17:44 . 2008-02-23 03:15 324976 ----a-w- c:\program files\mozilla firefox\components\coFFPlgn.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LDM"="c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2007-03-19 67128]
"igndlm.exe"="c:\program files\IGN\Download Manager\DLM.exe" [2007-03-05 1103480]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2010-01-08 289584]
"Google Update"="c:\documents and settings\Russell Klare\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-08 133104]
"CurseClient"="c:\program files\Curse\CurseClient.exe" [2010-01-22 1845248]
"Steam"="c:\program files\steam\steam.exe" [2010-02-23 1217872]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-02-15 454656]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-01-30 13594624]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-01-30 86016]
"nwiz"="nwiz.exe" [2009-01-30 1657376]
"MsmqIntCert"="mqrt.dll" [2008-04-14 177152]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-04-18 61952]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-04 761948]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2006-04-12 102400]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-03-21 213936]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-03-21 86960]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-03-07 131072]
"Cpqset"="c:\program files\HPQ\Default Settings\cpqset.exe" [2006-02-22 40960]
"RecGuard"="c:\windows\SMINST\RecGuard.exe" [2005-10-11 1187840]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-03-21 213936]
"Anti-Blaxx Manager"="c:\program files\Anti-Blaxx\Anti-Blaxx.exe" [2006-11-20 204800]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-04 44032]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-01-23 141608]

c:\documents and settings\Default User\Start Menu\Programs\Startup\
Vongo Tray.lnk - c:\program files\Vongo\Tray.exe [2006-12-11 73728]

c:\documents and settings\Administrator\Start Menu\Programs\Startup\
Vongo Tray.lnk - c:\program files\Vongo\Tray.exe [2006-12-11 73728]

c:\documents and settings\Russell Klare\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\Hp\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
HP Photosmart Premier Fast Start.lnk - c:\program files\Hp\Digital Imaging\bin\hpqthb08.exe [2006-2-10 73728]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-3-19 67128]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mqsvc.exe"=
"c:\\Program Files\\Electronic Arts\\The Battle for Middle-earth (tm) II\\game.dat"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Curse\\CurseClient.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\civilization iv colonization\\Colonization.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\sid meier's civilization iv\\Civilization4.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\sid meier's civilization iv warlords\\Warlords\\Civ4Warlords.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\sid meier's civilization iv warlords\\Warlords\\Civ4Warlords_PitBoss.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1008000.029\SymEFA.sys [2/2/2010 12:20 AM 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NIS\1008000.029\BHDrvx86.sys [2/2/2010 12:20 AM 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NIS\1008000.029\cchpx86.sys [2/2/2010 12:17 AM 482432]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100224.002\IDSXpx86.sys [2/25/2010 2:01 PM 329592]
R2 {09BB444F-B2E2-4009-BAF2-7B727681223E};BuddyVM;h:\s.t.a.l.k.e.r - shadow of chernobyl\Hitomi - My Stepsister\VMLaunch\BuddyVM.sys [10/5/2004 9:40 AM 15872]
R2 Norton Internet Security;Norton Internet Security;c:\program files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe [2/2/2010 12:18 AM 117640]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2/23/2010 8:06 AM 102448]
S0 nfehdbmt;nfehdbmt;c:\windows\system32\drivers\pgsbvj.sys --> c:\windows\system32\drivers\pgsbvj.sys [?]
S3 cmudau32;C-Media USB UDA Sound Interface;c:\windows\system32\drivers\cmudaxu.sys [8/24/2006 8:28 AM 1391040]
S3 jfdcd;jfdcd;\??\c:\docume~1\RUSSEL~1\LOCALS~1\Temp\jfdcd.sys --> c:\docume~1\RUSSEL~1\LOCALS~1\Temp\jfdcd.sys [?]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [9/26/2006 6:38 PM 643072]
.
Contents of the 'Scheduled Tasks' folder

2010-02-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]

2010-02-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-403753715-2283007472-2311900264-1005Core.job
- c:\documents and settings\Russell Klare\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-08 00:24]

2010-02-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-403753715-2283007472-2311900264-1005UA.job
- c:\documents and settings\Russell Klare\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-08 00:24]

2010-02-25 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 22:07]

2010-02-25 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-05-06 05:18]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Send To &Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
TCP: {738B480C-1CAC-4004-863E-3ED776804BF9} = 134.173.63.200,134.173.254.23
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
FF - ProfilePath - c:\documents and settings\Russell Klare\Application Data\Mozilla\Firefox\Profiles\wra9qko3.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\components\coFFPlgn.dll
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
FF - component: c:\documents and settings\Russell Klare\Application Data\Mozilla\Firefox\Profiles\wra9qko3.default\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}\platform\WINNT\components\FoxyTunes.dll
FF - plugin: c:\documents and settings\Russell Klare\Application Data\Mozilla\Firefox\Profiles\wra9qko3.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071102000004.dll
FF - plugin: c:\documents and settings\Russell Klare\Local Settings\Application Data\Google\Update\1.2.183.17\npGoogleOneClick8.dll
FF - plugin: c:\program files\CambridgeSoft\ChemOffice2008\Chem3D\npChem3DPlugin.dll
FF - plugin: c:\program files\CambridgeSoft\ChemOffice2008\ChemDraw\NPCDN32.DLL
FF - plugin: c:\program files\IGN\Download Manager\npfpdlm.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npSfAppM.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-EA Core - c:\program files\Electronic Arts\EADM\Core.exe
AddRemove-??????????~????~_is1 - c:\program files\?????\??????????~????~\unins000.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-25 13:49
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\program files\HPQ\Default Settings\cpqset.exe?????? ???@???????????????@? ???`|??????(?@???????@

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: error reading MBR
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x876A381A]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf75aef28
\Driver\ACPI -> ACPI.sys @ 0xf7421cb8
\Driver\atapi -> atapi.sys @ 0xf7395852
\Driver\iaStor -> iaStor.sys @ 0xf72cbb58
IoDeviceObjectType ->\Device\Harddisk0\DR0 ->NDIS: Intel(R) PRO/Wireless 3945ABG Network Connection -> SendCompleteHandler -> NDIS.sys @ 0xf717cbb0
PacketIndicateHandler -> NDIS.sys @ 0xf7189a21
SendHandler -> NDIS.sys @ 0xf716787b

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet015\Services\Norton Internet Security]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\program files\Norton Internet Security\Engine\16.8.0.41\diMaster.dll\" /prefetch:1"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-403753715-2283007472-2311900264-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1400)
c:\windows\system32\WININET.dll

- - - - - - - > 'lsass.exe'(1460)
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(1780)
c:\windows\system32\WININET.dll
c:\program files\iTunes\iTunesMiniPlayer.dll
c:\program files\iTunes\iTunesMiniPlayer.Resources\en.lproj\iTunesMiniPlayerLocalized.dll
c:\program files\iTunes\iTunesMiniPlayer.Resources\iTunesMiniPlayer.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\msdtc.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\nvsvc32.exe
c:\program files\Vongo\VongoService.exe
c:\windows\system32\mqsvc.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\windows\system32\mqtgsvc.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\RUNDLL32.EXE
c:\documents and settings\Russell Klare\Local Settings\Application Data\Google\Update\1.2.183.17\GoogleCrashHandler.exe
c:\program files\iPod\bin\iPodService.exe
c:\progra~1\HPQ\Shared\HPQTOA~1.EXE
c:\program files\HP\Digital Imaging\bin\hpqimzone.exe
c:\program files\HP\Digital Imaging\bin\hpqnrs08.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\windows\system32\HPZinw12.exe
.
**************************************************************************
.
Completion time: 2010-02-25 14:13:00 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-25 22:12
ComboFix2.txt 2010-01-08 20:40

Pre-Run: 629,186,560 bytes free
Post-Run: 3,542,724,608 bytes free

Current=15 Default=15 Failed=13 LastKnownGood=16 Sets=1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16
- - End Of File - - BE6008833B3FA724D27465C857564C4F







And here's the HijackThis log:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:39:15 PM, on 2/25/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Vongo\VongoService.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\Program Files\Anti-Blaxx\Anti-Blaxx.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Curse\CurseClient.exe
C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Vongo\Tray.exe
C:\Documents and Settings\Russell Klare\Local Settings\Application Data\Google\Update\1.2.183.17\GoogleCrashHandler.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\HPQ\Shared\HPQTOA~1.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Norton Internet Security\Engine\16.8.0.41\MCUI32.EXE
C:\Documents and Settings\Russell Klare\Desktop\Spybot Stuff\HijackThis.exe
C:\WINDOWS\system32\HPZinw12.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SpybotSD\SDHelper.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\IPSBHO.DLL
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O2 - BHO: (no name) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - (no file)
O2 - BHO: (no name) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\coIEPlg.dll
O3 - Toolbar: SciFinder Scholar Bar - {4e16a8fb-0521-46d1-aa2c-d0fc7abf6af9} - mscoree.dll (file missing)
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - HKLM\..\Run: [Anti-Blaxx Manager] C:\Program Files\Anti-Blaxx\Anti-Blaxx.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\IGN\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Russell Klare\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [CurseClient] C:\Program Files\Curse\CurseClient.exe -silent
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - S-1-5-18 Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: Registration Ghost Recon Advanced Warfighter.LNK = C:\Program Files\Ubisoft\Ghost Recon Advanced Warfighter\Support\Register\RegistrationReminder.exe
O4 - Startup: Vongo Tray.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SpybotSD\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SpybotSD\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
O16 - DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} (Hewlett-Packard Online Support Services) - http://h50203.www5.hp.com/HPISWeb/Customer/cabs/HPISDataManager.CAB
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{738B480C-1CAC-4004-863E-3ED776804BF9}: NameServer = 134.173.63.200,134.173.254.23
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\coIEPlg.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPBPRO.EXE
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton Internet Security - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Vongo Service - Starz Entertainment Group LLC - C:\Program Files\Vongo\VongoService.exe

--
End of file - 12559 bytes

ken545
2010-02-26, 03:04
Hi,

c:\program files\uTorrent If you continue to use File Sharing programs like this you will continue to get infected. Your downloading that file from and unknown source, its the latest way the the dirtbags that write this garbage can infect your computer. You would be doing your self a big favor by staying away from any form of file sharing, the torrents, Limewire. There all bad news.


You need to enable windows to show all files and folders, instructions Here (http://www.bleepingcomputer.com/tutorials/tutorial62.html)

Go to VirusTotal (http://www.virustotal.com/) and submit this file for analysis, just use the browse feature and then Send File, you will get a report back, post the report into this thread for me to see.

c:\windows\system32\drivers\pgsbvj.sys

If the site is busy you can try this one
http://virusscan.jotti.org/en




Please download ATF Cleaner (http://www.atribune.org/ccount/click.php?id=1) by Atribune to your desktop.

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.Your system may start up slower after running ATF Cleaner, this is expected but will be back to normal after the first or second boot up
Please note: If you use online banking or are registered online with any other organizations, ensure you have memorized password and other personal information as removing cookies will temporarily disable the auto-login facility.





Please download Malwarebytes from Here (http://www.malwarebytes.org/mbam-download.php) or Here (http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html)


Double-click mbam-setup.exe and follow the prompts to install the program.
At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select Perform quick scan, then click Scan.
http://forums.whatthetech.com/post_a4255_MBAM.PNG
When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click Remove Selected .
When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report and also a new HJT log please

Cent1
2010-02-26, 04:43
Alright. I had thought the torrent might be part of it, so I quit it and set it not to run on startup even before you mentioned anything. I'll strongly consider uninstalling it.

I don't see the pgsbvj.sys file, even with all the hidden folders and system operating folders visible, so I can't give that log.

Every 30 seconds or so I'm getting a little notice from my taskbar for "XP Antivirus Pro 2010", basically telling me to fix stuff. I'm not stupid, I know it's fake (still annoying), but I hadn't had that problem until earlier today, so something's changed. I think something might have switched my default internet to IE as well.


Malwarebytes doesn't appear to be starting anymore. Even when I changed the name it wouldn't open. This is also new (and bad).



HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:41:38 PM, on 2/25/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Vongo\VongoService.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\Program Files\Anti-Blaxx\Anti-Blaxx.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Curse\CurseClient.exe
C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Vongo\Tray.exe
C:\Documents and Settings\Russell Klare\Local Settings\Application Data\Google\Update\1.2.183.17\GoogleCrashHandler.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\HPQ\Shared\HPQTOA~1.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Norton Internet Security\Engine\16.8.0.41\MCUI32.EXE
C:\Program Files\VideoLAN\VLC\vlc.exe
C:\Program Files\Steam\steam.exe
C:\Documents and Settings\Russell Klare\Local Settings\Application Data\av.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\Russell Klare\Desktop\Spybot Stuff\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SpybotSD\SDHelper.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\IPSBHO.DLL
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O2 - BHO: (no name) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - (no file)
O2 - BHO: (no name) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\coIEPlg.dll
O3 - Toolbar: SciFinder Scholar Bar - {4e16a8fb-0521-46d1-aa2c-d0fc7abf6af9} - mscoree.dll (file missing)
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - HKLM\..\Run: [Anti-Blaxx Manager] C:\Program Files\Anti-Blaxx\Anti-Blaxx.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\IGN\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Russell Klare\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [CurseClient] C:\Program Files\Curse\CurseClient.exe -silent
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - S-1-5-18 Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: Registration Ghost Recon Advanced Warfighter.LNK = C:\Program Files\Ubisoft\Ghost Recon Advanced Warfighter\Support\Register\RegistrationReminder.exe
O4 - Startup: Vongo Tray.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SpybotSD\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SpybotSD\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
O16 - DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} (Hewlett-Packard Online Support Services) - http://h50203.www5.hp.com/HPISWeb/Customer/cabs/HPISDataManager.CAB
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{738B480C-1CAC-4004-863E-3ED776804BF9}: NameServer = 134.173.63.200,134.173.254.23
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\coIEPlg.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPBPRO.EXE
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton Internet Security - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Vongo Service - Starz Entertainment Group LLC - C:\Program Files\Vongo\VongoService.exe

--
End of file - 12600 bytes

Cent1
2010-02-26, 06:05
Update: I was able to run Spybot, which found 3 things. After I resolved those, I was able to do a Quick Scan with MalwareBytes. The log for that run is below (I'm about to reboot, to finish the scan):

Malwarebytes' Anti-Malware 1.44
Database version: 3787
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

2/25/2010 9:01:57 PM
mbam-log-2010-02-25 (21-01-57).txt

Scan type: Quick Scan
Objects scanned: 132703
Time elapsed: 16 minute(s), 25 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
C:\Documents and Settings\Russell Klare\Local Settings\Application Data\av.exe (ROGUE.Win7Antispyware2010) -> Failed to unload process.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\Russell Klare\Local Settings\Application Data\av.exe (ROGUE.Win7Antispyware2010) -> Delete on reboot.

ken545
2010-02-26, 14:15
Good Morning,

Open Notepad Go to Start> All Programs> Assessories> Notepad ( this will only work with Notepad )and copy all the text inside the Codebox by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above Rootkit::




File::
C:\Documents and Settings\Russell Klare\Local Settings\Application Data\av.exe


Save this as CFScript to your desktop.

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

http://i24.photobucket.com/albums/c30/ken545/CFScriptB-4.gif


This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.

Cent1
2010-02-26, 22:08
1. Before I forget, thanks for helping me, I really appreciate it.

2. I uninstalled uTorrent after all. Too much possible downside when crap like this happens.

3. Do you think/know if this current HTTP Tidserv thing is related to the TDSS guy that I had last month? A quick google search implies yes...but why would it suddenly comback?

3a. Do you think this is the exact same problem as I had last month (i.e. I never fully got rid of it and it lay dormant or something, and maybe the patch tuesday update triggered it?), or just closely related? All of the stuff I've read on TDSS from the various google links indicates it's as much of a pain in the ass as I think it is.

4. Do you care about the norton alerts (IE, the IP addresses where the attacks come from, the path) or should I just give you the logs asked for and not other info? On a related note, EVERY (or very nearly every) time I google search a little alert comes up that says c36996639.cn/(random stuff) tried to attack my computer.

5. Here's the combofix log (below is the HijackThis log). While running combofix I got an error about PEV.exe, which is in the Application Data\uTorrent\settings.dat.old being "corrupt and unreadable". Also, whenever I use combofix, I get a message saying Catchme.cfxxe is can't initialize because the system is shutting down.

ComboFix 10-02-25.02 - Russell Klare 02/26/2010 12:01:00.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.444 [GMT -8:00]
Running from: c:\documents and settings\Russell Klare\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\Russell Klare\Desktop\CFScript.txt
AV: Norton Internet Security *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}

FILE ::
"c:\documents and settings\Russell Klare\Local Settings\Application Data\av.exe"
.

((((((((((((((((((((((((( Files Created from 2010-01-26 to 2010-02-26 )))))))))))))))))))))))))))))))
.

2010-02-23 07:04 . 2010-02-23 07:05 -------- d-----w- c:\program files\ERUNT
2010-02-20 02:22 . 2010-02-20 02:22 -------- d-----w- c:\program files\Trend Micro
2010-02-18 20:15 . 2010-02-18 20:15 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple Computer
2010-02-18 12:09 . 2010-02-18 12:09 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Apple Computer
2010-02-17 20:19 . 2010-02-17 20:19 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-02-17 06:23 . 2010-02-17 06:23 -------- d-----w- c:\documents and settings\Russell Klare\Local Settings\Application Data\Electronic Arts
2010-02-15 07:00 . 2010-02-15 07:00 -------- d-----w- c:\documents and settings\Russell Klare\Local Settings\Application Data\HotheadGames
2010-02-15 04:53 . 2010-02-18 19:05 -------- d-----w- c:\program files\Hothead Games
2010-02-10 04:27 . 2010-02-10 04:27 -------- d-----w- c:\program files\Norn
2010-02-05 22:29 . 2010-02-05 22:29 -------- d-----w- c:\program files\luchs
2010-02-03 23:01 . 2010-02-03 23:02 -------- d-----w- c:\documents and settings\Russell Klare\Application Data\.chimera
2010-02-03 02:48 . 2010-02-03 02:48 -------- d-----w- c:\program files\iPod
2010-02-03 02:48 . 2010-02-03 02:50 -------- d-----w- c:\program files\iTunes
2010-02-03 02:40 . 2010-02-03 02:41 -------- d-----w- c:\program files\QuickTime
2010-02-02 18:29 . 2010-02-02 18:34 -------- d-----w- c:\program files\Chimera
2010-02-02 18:29 . 2010-02-02 18:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Chimera
2010-01-31 21:29 . 2010-01-31 21:29 -------- d-----w- c:\documents and settings\Russell Klare\Application Data\BDL+D
2010-01-28 00:30 . 2010-02-15 08:50 -------- d-----w- c:\program files\SpinWorks_3

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-26 19:52 . 2009-05-25 06:35 -------- d-----w- c:\program files\Steam
2010-02-26 19:22 . 2007-01-28 11:27 -------- d-----w- c:\documents and settings\Russell Klare\Application Data\vlc
2010-02-26 07:15 . 2006-10-30 09:30 -------- d-----w- c:\program files\DAEMON Tools
2010-02-26 05:23 . 2006-11-25 02:00 -------- d-----w- c:\program files\BitTorrent
2010-02-26 05:21 . 2007-11-08 04:21 -------- d-----w- c:\program files\uTorrent
2010-02-26 05:21 . 2007-11-08 04:20 -------- d-----w- c:\documents and settings\Russell Klare\Application Data\uTorrent
2010-02-26 03:40 . 2010-01-04 23:41 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-23 20:41 . 2009-03-14 05:21 -------- d-----w- c:\documents and settings\Russell Klare\Application Data\dvdcss
2010-02-23 07:33 . 2010-01-05 21:15 -------- d-----w- c:\program files\SpybotSD
2010-02-18 20:15 . 2010-01-04 22:08 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2010-02-17 07:07 . 2010-01-22 03:47 -------- d-----w- c:\documents and settings\Russell Klare\Application Data\Waffle
2010-02-17 03:37 . 2006-08-18 01:36 -------- d-----w- c:\program files\Electronic Arts
2010-02-12 01:58 . 2006-05-10 07:51 111864 -c--a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-11 00:27 . 2009-04-01 03:18 -------- d-----w- c:\program files\Symantec
2010-02-03 02:48 . 2008-06-08 20:06 -------- d-----w- c:\program files\Common Files\Apple
2010-02-01 18:42 . 2006-05-10 05:44 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-25 23:27 . 2009-01-14 05:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Electronic Arts
2010-01-25 23:26 . 2010-01-25 23:26 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-01-25 22:51 . 2010-01-25 22:51 -------- d-----w- c:\program files\NEKOBOKU
2010-01-22 19:37 . 2009-03-19 18:09 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-08 18:16 . 2007-10-29 23:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-01-08 00:07 . 2010-01-04 23:41 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-08 00:07 . 2010-01-04 23:41 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-05 18:34 . 2009-01-30 09:51 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-01-05 08:36 . 2007-10-29 23:55 -------- d-----w- c:\program files\Spybot Old
2010-01-05 00:20 . 2010-01-05 00:20 -------- d-----w- c:\documents and settings\Russell Klare\Application Data\Malwarebytes
2010-01-05 00:06 . 2006-05-10 08:26 -------- d-----w- c:\program files\Google
2010-01-04 23:41 . 2010-01-04 23:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-31 16:50 . 2005-05-10 08:17 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:14 . 2004-08-04 21:00 916480 ------w- c:\windows\system32\wininet.dll
2009-12-16 18:43 . 2004-08-04 21:00 343040 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:08 . 2004-08-04 21:00 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-12-09 03:12 . 2009-12-09 03:12 279712 ----a-w- c:\windows\system32\drivers\atksgt.sys
2009-12-09 03:12 . 2009-12-09 03:12 25888 ----a-w- c:\windows\system32\drivers\lirsgt.sys
2009-12-08 19:26 . 2004-08-04 21:00 2145280 ------w- c:\windows\system32\ntoskrnl.exe
2009-12-08 18:43 . 2004-08-04 21:00 2023936 ------w- c:\windows\system32\ntkrnlpa.exe
2009-12-04 18:22 . 2005-01-19 12:26 455424 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2004-07-22 17:51 . 2004-07-22 17:51 3432656 ----a-w- c:\program files\ManagedDX.CAB
2004-07-20 05:58 . 2004-07-20 05:58 1156363 ----a-w- c:\program files\BDANT.cab
2004-07-20 05:53 . 2004-07-20 05:53 976020 ----a-w- c:\program files\BDAXP.cab
2004-07-09 21:17 . 2004-07-09 21:17 13265040 ----a-w- c:\program files\dxnt.cab
2004-07-09 16:13 . 2004-07-09 16:13 15493481 ----a-w- c:\program files\DirectX.cab
2004-07-09 16:13 . 2004-07-09 16:13 703080 ----a-w- c:\program files\BDA.cab
2004-07-09 11:08 . 2004-07-09 11:08 472576 ----a-w- c:\program files\dxsetup.exe
2004-07-09 11:08 . 2004-07-09 11:08 2242560 ----a-w- c:\program files\dsetup32.dll
2004-07-09 10:03 . 2004-07-09 10:03 62976 ----a-w- c:\program files\DSETUP.dll
2004-03-16 02:51 . 2004-03-16 02:51 114688 ----a-w- c:\program files\internet explorer\plugins\LV71ActiveXControl.dll
2008-06-30 17:44 . 2008-02-23 03:15 324976 ----a-w- c:\program files\mozilla firefox\components\coFFPlgn.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LDM"="c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2007-03-19 67128]
"igndlm.exe"="c:\program files\IGN\Download Manager\DLM.exe" [2007-03-05 1103480]
"Google Update"="c:\documents and settings\Russell Klare\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-08 133104]
"CurseClient"="c:\program files\Curse\CurseClient.exe" [2010-01-22 1845248]
"Steam"="c:\program files\steam\steam.exe" [2010-02-23 1217872]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-02-15 454656]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-01-30 13594624]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-01-30 86016]
"nwiz"="nwiz.exe" [2009-01-30 1657376]
"MsmqIntCert"="mqrt.dll" [2008-04-14 177152]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-04-18 61952]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-04 761948]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2006-04-12 102400]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-03-21 213936]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-03-21 86960]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-03-07 131072]
"Cpqset"="c:\program files\HPQ\Default Settings\cpqset.exe" [2006-02-22 40960]
"RecGuard"="c:\windows\SMINST\RecGuard.exe" [2005-10-11 1187840]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-03-21 213936]
"Anti-Blaxx Manager"="c:\program files\Anti-Blaxx\Anti-Blaxx.exe" [2006-11-20 204800]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-04 44032]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-01-23 141608]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2005-12-10 133016]

c:\documents and settings\Default User\Start Menu\Programs\Startup\
Vongo Tray.lnk - c:\program files\Vongo\Tray.exe [2006-12-11 73728]

c:\documents and settings\Administrator\Start Menu\Programs\Startup\
Vongo Tray.lnk - c:\program files\Vongo\Tray.exe [2006-12-11 73728]

c:\documents and settings\Russell Klare\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\Hp\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
HP Photosmart Premier Fast Start.lnk - c:\program files\Hp\Digital Imaging\bin\hpqthb08.exe [2006-2-10 73728]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-3-19 67128]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mqsvc.exe"=
"c:\\Program Files\\Electronic Arts\\The Battle for Middle-earth (tm) II\\game.dat"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Curse\\CurseClient.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\civilization iv colonization\\Colonization.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\sid meier's civilization iv\\Civilization4.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\sid meier's civilization iv warlords\\Warlords\\Civ4Warlords.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\sid meier's civilization iv warlords\\Warlords\\Civ4Warlords_PitBoss.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1008000.029\SymEFA.sys [2/2/2010 12:20 AM 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NIS\1008000.029\BHDrvx86.sys [2/2/2010 12:20 AM 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NIS\1008000.029\cchpx86.sys [2/2/2010 12:17 AM 482432]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100224.002\IDSXpx86.sys [2/25/2010 2:01 PM 329592]
R2 {09BB444F-B2E2-4009-BAF2-7B727681223E};BuddyVM;h:\s.t.a.l.k.e.r - shadow of chernobyl\Hitomi - My Stepsister\VMLaunch\BuddyVM.sys [10/5/2004 9:40 AM 15872]
R2 Norton Internet Security;Norton Internet Security;c:\program files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe [2/2/2010 12:18 AM 117640]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2/23/2010 8:06 AM 102448]
S0 nfehdbmt;nfehdbmt;c:\windows\system32\drivers\pgsbvj.sys --> c:\windows\system32\drivers\pgsbvj.sys [?]
S3 cmudau32;C-Media USB UDA Sound Interface;c:\windows\system32\drivers\cmudaxu.sys [8/24/2006 8:28 AM 1391040]
S3 jfdcd;jfdcd;\??\c:\docume~1\RUSSEL~1\LOCALS~1\Temp\jfdcd.sys --> c:\docume~1\RUSSEL~1\LOCALS~1\Temp\jfdcd.sys [?]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [9/26/2006 6:38 PM 643072]
.
Contents of the 'Scheduled Tasks' folder

2010-02-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]

2010-02-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-403753715-2283007472-2311900264-1005Core.job
- c:\documents and settings\Russell Klare\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-08 00:24]

2010-02-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-403753715-2283007472-2311900264-1005UA.job
- c:\documents and settings\Russell Klare\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-08 00:24]

2010-02-26 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 22:07]

2010-02-26 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-05-06 05:18]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Send To &Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
TCP: {738B480C-1CAC-4004-863E-3ED776804BF9} = 134.173.63.200,134.173.254.23
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
FF - ProfilePath - c:\documents and settings\Russell Klare\Application Data\Mozilla\Firefox\Profiles\wra9qko3.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\components\coFFPlgn.dll
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
FF - component: c:\documents and settings\Russell Klare\Application Data\Mozilla\Firefox\Profiles\wra9qko3.default\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}\platform\WINNT\components\FoxyTunes.dll
FF - plugin: c:\documents and settings\Russell Klare\Application Data\Mozilla\Firefox\Profiles\wra9qko3.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071102000004.dll
FF - plugin: c:\documents and settings\Russell Klare\Local Settings\Application Data\Google\Update\1.2.183.17\npGoogleOneClick8.dll
FF - plugin: c:\program files\CambridgeSoft\ChemOffice2008\Chem3D\npChem3DPlugin.dll
FF - plugin: c:\program files\CambridgeSoft\ChemOffice2008\ChemDraw\NPCDN32.DLL
FF - plugin: c:\program files\IGN\Download Manager\npfpdlm.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npSfAppM.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

AddRemove-??????????~????~_is1 - c:\program files\?????\??????????~????~\unins000.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-26 12:26
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\program files\HPQ\Default Settings\cpqset.exe?????? ???@???????????????@? ???`|??????(?@???????@

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: error reading MBR
called modules: ntkrnlpa.exe catchme.sys CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x876C881A]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf75aef28
\Driver\ACPI -> ACPI.sys @ 0xf7421cb8
\Driver\atapi -> atapi.sys @ 0xf7395852
\Driver\iaStor -> iaStor.sys @ 0xf72cbb58
IoDeviceObjectType ->\Device\Harddisk0\DR0 ->NDIS: Intel(R) PRO/Wireless 3945ABG Network Connection -> SendCompleteHandler -> NDIS.sys @ 0xf717cbb0
PacketIndicateHandler -> NDIS.sys @ 0xf7189a21
SendHandler -> NDIS.sys @ 0xf716787b

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet015\Services\Norton Internet Security]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\program files\Norton Internet Security\Engine\16.8.0.41\diMaster.dll\" /prefetch:1"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-403753715-2283007472-2311900264-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1388)
c:\windows\system32\WININET.dll

- - - - - - - > 'lsass.exe'(1448)
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(740)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-02-26 12:42:17
ComboFix-quarantined-files.txt 2010-02-26 20:42
ComboFix2.txt 2010-02-25 22:13
ComboFix3.txt 2010-01-08 20:40

Pre-Run: 3,397,054,464 bytes free
Post-Run: 3,424,997,376 bytes free

Current=15 Default=15 Failed=13 LastKnownGood=16 Sets=1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16
- - End Of File - - F88D268FA20E982C2B736983C2D1DCCD






Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:56:58 PM, on 2/26/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\Program Files\Anti-Blaxx\Anti-Blaxx.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\program files\steam\steam.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Vongo\Tray.exe
C:\Documents and Settings\Russell Klare\Local Settings\Application Data\Google\Update\1.2.183.17\GoogleCrashHandler.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Vongo\VongoService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\HPQ\Shared\HPQTOA~1.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\Russell Klare\Desktop\Spybot Stuff\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SpybotSD\SDHelper.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\IPSBHO.DLL
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O2 - BHO: (no name) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - (no file)
O2 - BHO: (no name) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\coIEPlg.dll
O3 - Toolbar: SciFinder Scholar Bar - {4e16a8fb-0521-46d1-aa2c-d0fc7abf6af9} - mscoree.dll (file missing)
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - HKLM\..\Run: [Anti-Blaxx Manager] C:\Program Files\Anti-Blaxx\Anti-Blaxx.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\IGN\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Russell Klare\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [CurseClient] C:\Program Files\Curse\CurseClient.exe -silent
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - S-1-5-18 Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: Registration Ghost Recon Advanced Warfighter.LNK = C:\Program Files\Ubisoft\Ghost Recon Advanced Warfighter\Support\Register\RegistrationReminder.exe
O4 - Startup: Vongo Tray.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SpybotSD\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SpybotSD\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
O16 - DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} (Hewlett-Packard Online Support Services) - http://h50203.www5.hp.com/HPISWeb/Customer/cabs/HPISDataManager.CAB
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{738B480C-1CAC-4004-863E-3ED776804BF9}: NameServer = 134.173.63.200,134.173.254.23
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\coIEPlg.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPBPRO.EXE
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton Internet Security - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Vongo Service - Starz Entertainment Group LLC - C:\Program Files\Vongo\VongoService.exe

--
End of file - 12380 bytes

ken545
2010-02-27, 01:03
Hi,

Keep in mind that this forum is read by people from all over and all ages so please refrain from any fowl language please.

Whatever you had before may have not been fully removed.


Open Notepad Go to Start> All Programs> Assessories> Notepad ( this will only work with Notepad )and copy all the text inside the Codebox by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above Driver::




Driver::
nfehdbmt
pgsbvj.sys

File::
c:\windows\system32\drivers\pgsbvj.sys
c:\docume~1\RUSSEL~1\LOCALS~1\Temp\jfdcd.sys

FixCSet::
S0 nfehdbmt;nfehdbmt;c:\windows\system32\drivers\pgsbvj.sys --> c:\windows\system32\drivers\pgsbvj.sys [?]
S3 jfdcd;jfdcd;\??\c:\docume~1\RUSSEL~1\LOCALS~1\Temp\jfdcd.sys --> c:\docume~1\RUSSEL~1\LOCALS~1\Temp\jfdcd.sys [?]


Save this as CFScript to your desktop.

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

http://i24.photobucket.com/albums/c30/ken545/CFScriptB-4.gif


This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.





Please download Maxhandle by Noahdfear (http://noahdfear.net/downloads/maxhandle.exe) to your

desktop

Double click and run the application
An active internet connection is required so that maxhandle.exe may download a tool from SysInternals
If Max++ is present the log will open automatically.
If Max++ is not found Nothing found! is echoed to the screen - no log is produced.
Log is saved to c:\maxhandle.txt

Please post the results for my review

Cent1
2010-02-27, 05:35
Maxhandle found nothing, the other two logs are below:

ComboFix 10-02-26.01 - Russell Klare 02/26/2010 19:26:43.4.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.543 [GMT -8:00]
Running from: c:\documents and settings\Russell Klare\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\Russell Klare\Desktop\CFScript.txt
AV: Norton Internet Security *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}

FILE ::
"c:\docume~1\RUSSEL~1\LOCALS~1\Temp\jfdcd.sys"
"c:\windows\system32\drivers\pgsbvj.sys"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_nfehdbmt


((((((((((((((((((((((((( Files Created from 2010-01-27 to 2010-02-27 )))))))))))))))))))))))))))))))
.

2010-02-23 07:04 . 2010-02-23 07:05 -------- d-----w- c:\program files\ERUNT
2010-02-20 02:22 . 2010-02-20 02:22 -------- d-----w- c:\program files\Trend Micro
2010-02-18 20:15 . 2010-02-18 20:15 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple Computer
2010-02-18 12:09 . 2010-02-18 12:09 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Apple Computer
2010-02-17 20:19 . 2010-02-17 20:19 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-02-17 06:23 . 2010-02-17 06:23 -------- d-----w- c:\documents and settings\Russell Klare\Local Settings\Application Data\Electronic Arts
2010-02-15 07:00 . 2010-02-15 07:00 -------- d-----w- c:\documents and settings\Russell Klare\Local Settings\Application Data\HotheadGames
2010-02-15 04:53 . 2010-02-18 19:05 -------- d-----w- c:\program files\Hothead Games
2010-02-10 04:27 . 2010-02-10 04:27 -------- d-----w- c:\program files\Norn
2010-02-05 22:29 . 2010-02-05 22:29 -------- d-----w- c:\program files\luchs
2010-02-03 23:01 . 2010-02-03 23:02 -------- d-----w- c:\documents and settings\Russell Klare\Application Data\.chimera
2010-02-03 02:48 . 2010-02-03 02:48 -------- d-----w- c:\program files\iPod
2010-02-03 02:48 . 2010-02-03 02:50 -------- d-----w- c:\program files\iTunes
2010-02-03 02:40 . 2010-02-03 02:41 -------- d-----w- c:\program files\QuickTime
2010-02-02 18:29 . 2010-02-02 18:34 -------- d-----w- c:\program files\Chimera
2010-02-02 18:29 . 2010-02-02 18:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Chimera
2010-01-31 21:29 . 2010-01-31 21:29 -------- d-----w- c:\documents and settings\Russell Klare\Application Data\BDL+D

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-27 04:01 . 2009-05-25 06:35 -------- d-----w- c:\program files\Steam
2010-02-27 03:06 . 2007-01-28 11:27 -------- d-----w- c:\documents and settings\Russell Klare\Application Data\vlc
2010-02-26 07:15 . 2006-10-30 09:30 -------- d-----w- c:\program files\DAEMON Tools
2010-02-26 05:23 . 2006-11-25 02:00 -------- d-----w- c:\program files\BitTorrent
2010-02-26 05:21 . 2007-11-08 04:21 -------- d-----w- c:\program files\uTorrent
2010-02-26 05:21 . 2007-11-08 04:20 -------- d-----w- c:\documents and settings\Russell Klare\Application Data\uTorrent
2010-02-26 03:40 . 2010-01-04 23:41 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-23 20:41 . 2009-03-14 05:21 -------- d-----w- c:\documents and settings\Russell Klare\Application Data\dvdcss
2010-02-23 07:33 . 2010-01-05 21:15 -------- d-----w- c:\program files\SpybotSD
2010-02-18 20:15 . 2010-01-04 22:08 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2010-02-17 07:07 . 2010-01-22 03:47 -------- d-----w- c:\documents and settings\Russell Klare\Application Data\Waffle
2010-02-17 03:37 . 2006-08-18 01:36 -------- d-----w- c:\program files\Electronic Arts
2010-02-15 08:50 . 2010-01-28 00:30 -------- d-----w- c:\program files\SpinWorks_3
2010-02-12 01:58 . 2006-05-10 07:51 111864 -c--a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-11 00:27 . 2009-04-01 03:18 -------- d-----w- c:\program files\Symantec
2010-02-03 02:48 . 2008-06-08 20:06 -------- d-----w- c:\program files\Common Files\Apple
2010-02-01 18:42 . 2006-05-10 05:44 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-25 23:27 . 2009-01-14 05:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Electronic Arts
2010-01-25 23:26 . 2010-01-25 23:26 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-01-25 22:51 . 2010-01-25 22:51 -------- d-----w- c:\program files\NEKOBOKU
2010-01-22 19:37 . 2009-03-19 18:09 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-08 18:16 . 2007-10-29 23:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-01-08 00:07 . 2010-01-04 23:41 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-08 00:07 . 2010-01-04 23:41 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-05 18:34 . 2009-01-30 09:51 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-01-05 08:36 . 2007-10-29 23:55 -------- d-----w- c:\program files\Spybot Old
2010-01-05 00:20 . 2010-01-05 00:20 -------- d-----w- c:\documents and settings\Russell Klare\Application Data\Malwarebytes
2010-01-05 00:06 . 2006-05-10 08:26 -------- d-----w- c:\program files\Google
2010-01-04 23:41 . 2010-01-04 23:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-31 16:50 . 2005-05-10 08:17 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:14 . 2004-08-04 21:00 916480 ------w- c:\windows\system32\wininet.dll
2009-12-16 18:43 . 2004-08-04 21:00 343040 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:08 . 2004-08-04 21:00 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-12-09 03:12 . 2009-12-09 03:12 279712 ----a-w- c:\windows\system32\drivers\atksgt.sys
2009-12-09 03:12 . 2009-12-09 03:12 25888 ----a-w- c:\windows\system32\drivers\lirsgt.sys
2009-12-08 19:26 . 2004-08-04 21:00 2145280 ------w- c:\windows\system32\ntoskrnl.exe
2009-12-08 18:43 . 2004-08-04 21:00 2023936 ------w- c:\windows\system32\ntkrnlpa.exe
2009-12-04 18:22 . 2005-01-19 12:26 455424 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2004-07-22 17:51 . 2004-07-22 17:51 3432656 ----a-w- c:\program files\ManagedDX.CAB
2004-07-20 05:58 . 2004-07-20 05:58 1156363 ----a-w- c:\program files\BDANT.cab
2004-07-20 05:53 . 2004-07-20 05:53 976020 ----a-w- c:\program files\BDAXP.cab
2004-07-09 21:17 . 2004-07-09 21:17 13265040 ----a-w- c:\program files\dxnt.cab
2004-07-09 16:13 . 2004-07-09 16:13 15493481 ----a-w- c:\program files\DirectX.cab
2004-07-09 16:13 . 2004-07-09 16:13 703080 ----a-w- c:\program files\BDA.cab
2004-07-09 11:08 . 2004-07-09 11:08 472576 ----a-w- c:\program files\dxsetup.exe
2004-07-09 11:08 . 2004-07-09 11:08 2242560 ----a-w- c:\program files\dsetup32.dll
2004-07-09 10:03 . 2004-07-09 10:03 62976 ----a-w- c:\program files\DSETUP.dll
2004-03-16 02:51 . 2004-03-16 02:51 114688 ----a-w- c:\program files\internet explorer\plugins\LV71ActiveXControl.dll
2008-06-30 17:44 . 2008-02-23 03:15 324976 ----a-w- c:\program files\mozilla firefox\components\coFFPlgn.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LDM"="c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2007-03-19 67128]
"igndlm.exe"="c:\program files\IGN\Download Manager\DLM.exe" [2007-03-05 1103480]
"Google Update"="c:\documents and settings\Russell Klare\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-08 133104]
"CurseClient"="c:\program files\Curse\CurseClient.exe" [2010-01-22 1845248]
"Steam"="c:\program files\steam\steam.exe" [2010-02-23 1217872]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-02-15 454656]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-01-30 13594624]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-01-30 86016]
"nwiz"="nwiz.exe" [2009-01-30 1657376]
"MsmqIntCert"="mqrt.dll" [2008-04-14 177152]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-04-18 61952]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-04 761948]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2006-04-12 102400]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-03-21 213936]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-03-21 86960]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-03-07 131072]
"Cpqset"="c:\program files\HPQ\Default Settings\cpqset.exe" [2006-02-22 40960]
"RecGuard"="c:\windows\SMINST\RecGuard.exe" [2005-10-11 1187840]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-03-21 213936]
"Anti-Blaxx Manager"="c:\program files\Anti-Blaxx\Anti-Blaxx.exe" [2006-11-20 204800]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-04 44032]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-01-23 141608]

c:\documents and settings\Default User\Start Menu\Programs\Startup\
Vongo Tray.lnk - c:\program files\Vongo\Tray.exe [2006-12-11 73728]

c:\documents and settings\Administrator\Start Menu\Programs\Startup\
Vongo Tray.lnk - c:\program files\Vongo\Tray.exe [2006-12-11 73728]

c:\documents and settings\Russell Klare\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\Hp\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
HP Photosmart Premier Fast Start.lnk - c:\program files\Hp\Digital Imaging\bin\hpqthb08.exe [2006-2-10 73728]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-3-19 67128]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mqsvc.exe"=
"c:\\Program Files\\Electronic Arts\\The Battle for Middle-earth (tm) II\\game.dat"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Curse\\CurseClient.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\civilization iv colonization\\Colonization.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\sid meier's civilization iv\\Civilization4.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\sid meier's civilization iv warlords\\Warlords\\Civ4Warlords.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\sid meier's civilization iv warlords\\Warlords\\Civ4Warlords_PitBoss.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1008000.029\SymEFA.sys [2/2/2010 12:20 AM 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NIS\1008000.029\BHDrvx86.sys [2/2/2010 12:20 AM 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NIS\1008000.029\cchpx86.sys [2/2/2010 12:17 AM 482432]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100224.002\IDSXpx86.sys [2/25/2010 2:01 PM 329592]
R2 Norton Internet Security;Norton Internet Security;c:\program files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe [2/2/2010 12:18 AM 117640]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2/23/2010 8:06 AM 102448]
S2 {09BB444F-B2E2-4009-BAF2-7B727681223E};BuddyVM;\??\h:\s.t.a.l.k.e.r - shadow of chernobyl\Hitomi - My Stepsister\VMLaunch\BuddyVM.sys --> h:\s.t.a.l.k.e.r - shadow of chernobyl\Hitomi - My Stepsister\VMLaunch\BuddyVM.sys [?]
S3 cmudau32;C-Media USB UDA Sound Interface;c:\windows\system32\drivers\cmudaxu.sys [8/24/2006 8:28 AM 1391040]
S3 jfdcd;jfdcd;\??\c:\docume~1\RUSSEL~1\LOCALS~1\Temp\jfdcd.sys --> c:\docume~1\RUSSEL~1\LOCALS~1\Temp\jfdcd.sys [?]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [9/26/2006 6:38 PM 643072]
.
Contents of the 'Scheduled Tasks' folder

2010-02-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]

2010-02-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-403753715-2283007472-2311900264-1005Core.job
- c:\documents and settings\Russell Klare\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-08 00:24]

2010-02-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-403753715-2283007472-2311900264-1005UA.job
- c:\documents and settings\Russell Klare\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-08 00:24]

2010-02-27 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 22:07]

2010-02-27 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-05-06 05:18]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Send To &Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
TCP: {738B480C-1CAC-4004-863E-3ED776804BF9} = 134.173.63.200,134.173.254.23
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
FF - ProfilePath - c:\documents and settings\Russell Klare\Application Data\Mozilla\Firefox\Profiles\wra9qko3.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\components\coFFPlgn.dll
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
FF - component: c:\documents and settings\Russell Klare\Application Data\Mozilla\Firefox\Profiles\wra9qko3.default\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}\platform\WINNT\components\FoxyTunes.dll
FF - plugin: c:\documents and settings\Russell Klare\Application Data\Mozilla\Firefox\Profiles\wra9qko3.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071102000004.dll
FF - plugin: c:\documents and settings\Russell Klare\Local Settings\Application Data\Google\Update\1.2.183.17\npGoogleOneClick8.dll
FF - plugin: c:\program files\CambridgeSoft\ChemOffice2008\Chem3D\npChem3DPlugin.dll
FF - plugin: c:\program files\CambridgeSoft\ChemOffice2008\ChemDraw\NPCDN32.DLL
FF - plugin: c:\program files\IGN\Download Manager\npfpdlm.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npSfAppM.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

AddRemove-amaenbo_is1 - h:\s.t.a.l.k.e.r - shadow of chernobyl\Perverted Summer Vacation\amaenbo\unins000.exe
AddRemove-B5WIN - h:\s.t.a.l.k.e.r - shadow of chernobyl\huge sailor boobs\B5WIN\UNINST.EXE
AddRemove-??????????~????~_is1 - c:\program files\?????\??????????~????~\unins000.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-26 20:01
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\program files\HPQ\Default Settings\cpqset.exe?????? ???@???????????????@? ???`|??????(?@???????@

scanning hidden files ...


c:\docume~1\RUSSEL~1\LOCALS~1\Temp\RGI8.tmp

scan completed successfully
hidden files: 1

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x876B681A]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf75ebf28
\Driver\ACPI -> ACPI.sys @ 0xf745ecb8
\Driver\atapi -> atapi.sys @ 0xf73d2852
\Driver\iaStor -> iaStor.sys @ 0xf7308b58
IoDeviceObjectType -> SecurityProcedure -> ntkrnlpa.exe @ 0x80583d4a
\Device\Harddisk0\DR0 -> SecurityProcedure -> ntkrnlpa.exe @ 0x80583d4a
NDIS: Intel(R) PRO/Wireless 3945ABG Network Connection -> SendCompleteHandler -> NDIS.sys @ 0xf71b9bb0
PacketIndicateHandler -> NDIS.sys @ 0xf71c6a21
SendHandler -> NDIS.sys @ 0xf71a487b
user & kernel MBR OK

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet015\Services\Norton Internet Security]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\program files\Norton Internet Security\Engine\16.8.0.41\diMaster.dll\" /prefetch:1"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-403753715-2283007472-2311900264-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1412)
c:\windows\system32\WININET.dll

- - - - - - - > 'lsass.exe'(1476)
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(3660)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\msdtc.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\nvsvc32.exe
c:\program files\Vongo\VongoService.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\windows\system32\RUNDLL32.EXE
c:\documents and settings\Russell Klare\Local Settings\Application Data\Google\Update\1.2.183.17\GoogleCrashHandler.exe
c:\progra~1\HPQ\Shared\HPQTOA~1.EXE
c:\program files\iPod\bin\iPodService.exe
c:\program files\HP\Digital Imaging\bin\hpqimzone.exe
c:\program files\HP\Digital Imaging\bin\hpqnrs08.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\windows\system32\HPZinw12.exe
.
**************************************************************************
.
Completion time: 2010-02-26 20:27:53 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-27 04:27
ComboFix2.txt 2010-02-26 20:42
ComboFix3.txt 2010-02-25 22:13
ComboFix4.txt 2010-01-08 20:40

Pre-Run: 3,421,212,672 bytes free
Post-Run: 3,393,601,536 bytes free

- - End Of File - - F5C72E5DA74878E101679431F36C44CE





Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:32:21 PM, on 2/26/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Vongo\VongoService.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\Program Files\Anti-Blaxx\Anti-Blaxx.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Curse\CurseClient.exe
C:\program files\steam\steam.exe
C:\Documents and Settings\Russell Klare\Local Settings\Application Data\Google\Update\1.2.183.17\GoogleCrashHandler.exe
C:\Program Files\Vongo\Tray.exe
C:\PROGRA~1\HPQ\Shared\HPQTOA~1.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\HPZinw12.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\Russell Klare\Desktop\Spybot Stuff\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SpybotSD\SDHelper.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\IPSBHO.DLL
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O2 - BHO: (no name) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - (no file)
O2 - BHO: (no name) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\coIEPlg.dll
O3 - Toolbar: SciFinder Scholar Bar - {4e16a8fb-0521-46d1-aa2c-d0fc7abf6af9} - mscoree.dll (file missing)
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - HKLM\..\Run: [Anti-Blaxx Manager] C:\Program Files\Anti-Blaxx\Anti-Blaxx.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\IGN\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Russell Klare\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [CurseClient] C:\Program Files\Curse\CurseClient.exe -silent
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - S-1-5-18 Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: Registration Ghost Recon Advanced Warfighter.LNK = C:\Program Files\Ubisoft\Ghost Recon Advanced Warfighter\Support\Register\RegistrationReminder.exe
O4 - Startup: Vongo Tray.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SpybotSD\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SpybotSD\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
O16 - DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} (Hewlett-Packard Online Support Services) - http://h50203.www5.hp.com/HPISWeb/Customer/cabs/HPISDataManager.CAB
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{738B480C-1CAC-4004-863E-3ED776804BF9}: NameServer = 134.173.63.200,134.173.254.23
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\coIEPlg.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPBPRO.EXE
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton Internet Security - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Vongo Service - Starz Entertainment Group LLC - C:\Program Files\Vongo\VongoService.exe

--
End of file - 12247 bytes

ken545
2010-02-27, 13:43
c:\documents and settings\Russell Klare\Local Settings\temp <--Delete all the contents of the temp folder but not the temp folder itself


Open Notepad Go to Start> All Programs> Assessories> Notepad ( this will only work with Notepad )and copy all the text inside the Codebox by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above File::




File::
c:\documents and settings\Russell Klare\Local Settings\temp\jfdcd.sys
c:\documents and settings\Russell Klare\Local Settings\temp\RGI8.tmp


Save this as CFScript to your desktop.

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

http://i24.photobucket.com/albums/c30/ken545/CFScriptB-4.gif


This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.

Cent1
2010-02-28, 01:04
When I first deleted the stuff in the Temp folder (noon or so my time), there were about 4 or 5 files that I couldn't delete because it was claimed they were in use by another person or program. After about three hours of browsing the internet, there were another 4 or 5 very similar files (this was after I closed firefox), so there were around 8 or so files in the Temp folder when Combofix ran. The two logs are below:



ComboFix 10-02-26.01 - Russell Klare 02/27/2010 15:25:20.5.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.592 [GMT -8:00]
Running from: c:\documents and settings\Russell Klare\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\Russell Klare\Desktop\CFScript.txt
AV: Norton Internet Security *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}

FILE ::
"c:\documents and settings\Russell Klare\Local Settings\temp\jfdcd.sys"
"c:\documents and settings\Russell Klare\Local Settings\temp\RGI8.tmp"
.
PEV Error: TemplatesFile
PEV Error: TemplatesFolder

((((((((((((((((((((((((( Files Created from 2010-01-27 to 2010-02-27 )))))))))))))))))))))))))))))))
.

2010-02-27 23:18 . 2010-02-13 01:41 558448 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\components\coFFPlgn.dll
2010-02-27 23:18 . 2010-02-02 03:20 165240 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
2010-02-27 16:25 . 2010-02-03 09:00 84912 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100227.007\NAVENG.SYS
2010-02-27 16:25 . 2010-02-03 09:00 1324720 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100227.007\NAVEX15.SYS
2010-02-27 16:25 . 2009-08-25 08:00 177520 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100227.007\NAVENG32.DLL
2010-02-27 16:25 . 2009-08-25 08:00 1647984 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100227.007\NAVEX32A.DLL
2010-02-27 16:25 . 2009-12-09 09:00 2747440 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100227.007\CCERASER.DLL
2010-02-27 16:25 . 2009-09-22 08:00 259440 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100227.007\ECMSVR32.DLL
2010-02-27 16:25 . 2009-08-26 08:00 371248 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100227.007\EECTRL.SYS
2010-02-27 16:25 . 2009-08-26 08:00 102448 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100227.007\ERASER.SYS
2010-02-27 04:31 . 2008-11-18 21:15 417136 ----a-w- c:\windows\handle.exe
2010-02-25 22:01 . 2009-10-28 22:37 811896 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100224.002\Scxpx86.dll
2010-02-25 22:01 . 2009-10-28 22:37 329592 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100224.002\IDSXpx86.sys
2010-02-25 22:01 . 2009-10-28 22:37 343088 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100224.002\IDSvix86.sys
2010-02-25 22:01 . 2009-10-28 22:37 488312 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100224.002\IDSxpx86.dll
2010-02-25 22:01 . 2009-10-28 22:37 466992 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100224.002\IDSviA64.sys
2010-02-24 22:52 . 2010-02-24 22:52 5115824 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-02-23 07:04 . 2010-02-23 07:05 -------- d-----w- c:\program files\ERUNT
2010-02-20 02:22 . 2010-02-20 02:22 -------- d-----w- c:\program files\Trend Micro
2010-02-19 21:54 . 2009-10-28 22:37 811896 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100218.001\Scxpx86.dll
2010-02-19 21:54 . 2009-10-28 22:37 329592 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100218.001\IDSXpx86.sys
2010-02-19 21:54 . 2009-10-28 22:37 488312 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100218.001\IDSxpx86.dll
2010-02-19 21:54 . 2009-10-28 22:37 343088 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100218.001\IDSvix86.sys
2010-02-19 21:54 . 2009-10-28 22:37 466992 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100218.001\IDSviA64.sys
2010-02-18 20:15 . 2010-02-18 20:15 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple Computer
2010-02-18 12:09 . 2010-02-18 12:09 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Apple Computer
2010-02-17 20:19 . 2010-02-17 20:19 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-02-17 06:23 . 2010-02-17 06:23 -------- d-----w- c:\documents and settings\Russell Klare\Local Settings\Application Data\Electronic Arts
2010-02-15 07:00 . 2010-02-15 07:00 -------- d-----w- c:\documents and settings\Russell Klare\Local Settings\Application Data\HotheadGames
2010-02-15 04:53 . 2010-02-18 19:05 -------- d-----w- c:\program files\Hothead Games
2010-02-10 04:27 . 2010-02-10 04:27 -------- d-----w- c:\program files\Norn
2010-02-05 22:29 . 2010-02-05 22:29 -------- d-----w- c:\program files\luchs
2010-02-03 23:01 . 2010-02-03 23:02 -------- d-----w- c:\documents and settings\Russell Klare\Application Data\.chimera
2010-02-03 02:48 . 2010-02-03 02:48 -------- d-----w- c:\program files\iPod
2010-02-03 02:48 . 2010-02-03 02:50 -------- d-----w- c:\program files\iTunes
2010-02-03 02:40 . 2010-02-03 02:41 -------- d-----w- c:\program files\QuickTime
2010-02-03 02:34 . 2010-02-03 02:34 72488 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
2010-02-02 18:29 . 2010-02-02 18:34 -------- d-----w- c:\program files\Chimera
2010-02-02 18:29 . 2010-02-02 18:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Chimera
2010-01-31 21:29 . 2010-01-31 21:44 16 --sha-w- c:\documents and settings\Russell Klare\Application Data\BDL+D\GYUT.TO\2727\____.sys
2010-01-31 21:29 . 2010-01-31 21:29 -------- d-----w- c:\documents and settings\Russell Klare\Application Data\BDL+D

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-27 23:02 . 2007-01-28 11:27 -------- d-----w- c:\documents and settings\Russell Klare\Application Data\vlc
2010-02-27 20:11 . 2009-05-25 06:35 -------- d-----w- c:\program files\Steam
2010-02-26 07:15 . 2006-10-30 09:30 -------- d-----w- c:\program files\DAEMON Tools
2010-02-26 05:23 . 2006-11-25 02:00 -------- d-----w- c:\program files\BitTorrent
2010-02-26 05:21 . 2007-11-08 04:21 -------- d-----w- c:\program files\uTorrent
2010-02-26 05:21 . 2007-11-08 04:20 -------- d-----w- c:\documents and settings\Russell Klare\Application Data\uTorrent
2010-02-26 03:40 . 2010-01-04 23:41 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-23 20:41 . 2009-03-14 05:21 -------- d-----w- c:\documents and settings\Russell Klare\Application Data\dvdcss
2010-02-23 18:12 . 2009-11-11 05:10 79488 ----a-w- c:\documents and settings\Russell Klare\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-02-23 07:33 . 2010-01-05 21:15 -------- d-----w- c:\program files\SpybotSD
2010-02-18 20:15 . 2010-01-04 22:08 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2010-02-17 07:07 . 2010-01-22 03:47 -------- d-----w- c:\documents and settings\Russell Klare\Application Data\Waffle
2010-02-17 03:37 . 2006-08-18 01:36 -------- d-----w- c:\program files\Electronic Arts
2010-02-15 08:50 . 2010-01-28 00:30 -------- d-----w- c:\program files\SpinWorks_3
2010-02-12 01:58 . 2006-05-10 07:51 111864 -c--a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-11 00:27 . 2009-04-01 03:18 -------- d-----w- c:\program files\Symantec
2010-02-03 02:48 . 2008-06-08 20:06 -------- d-----w- c:\program files\Common Files\Apple
2010-02-01 18:42 . 2006-05-10 05:44 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-25 23:27 . 2009-01-14 05:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Electronic Arts
2010-01-25 23:26 . 2010-01-25 23:26 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-01-25 23:25 . 2008-09-14 22:15 38784 ----a-w- c:\documents and settings\Russell Klare\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-01-25 22:51 . 2010-01-25 22:51 -------- d-----w- c:\program files\NEKOBOKU
2010-01-22 19:37 . 2009-03-19 18:09 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-08 18:16 . 2007-10-29 23:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-01-08 00:07 . 2010-01-04 23:41 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-08 00:07 . 2010-01-04 23:41 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-05 18:34 . 2009-01-30 09:51 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-01-05 08:36 . 2007-10-29 23:55 -------- d-----w- c:\program files\Spybot Old
2010-01-05 00:20 . 2010-01-05 00:20 -------- d-----w- c:\documents and settings\Russell Klare\Application Data\Malwarebytes
2010-01-05 00:06 . 2006-05-10 08:26 -------- d-----w- c:\program files\Google
2010-01-04 23:41 . 2010-01-04 23:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-31 16:50 . 2005-05-10 08:17 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:14 . 2004-08-04 21:00 916480 ------w- c:\windows\system32\wininet.dll
2009-12-16 18:43 . 2004-08-04 21:00 343040 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:08 . 2004-08-04 21:00 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-12-09 09:00 . 2010-01-08 18:29 2747440 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100108.002\CCERASER.DLL
2009-12-09 03:12 . 2009-12-09 03:12 279712 ----a-w- c:\windows\system32\drivers\atksgt.sys
2009-12-09 03:12 . 2009-12-09 03:12 25888 ----a-w- c:\windows\system32\drivers\lirsgt.sys
2009-12-08 19:26 . 2004-08-04 21:00 2145280 ------w- c:\windows\system32\ntoskrnl.exe
2009-12-08 18:43 . 2004-08-04 21:00 2023936 ------w- c:\windows\system32\ntkrnlpa.exe
2009-12-04 18:22 . 2005-01-19 12:26 455424 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2004-07-22 17:51 . 2004-07-22 17:51 3432656 ----a-w- c:\program files\ManagedDX.CAB
2004-07-20 05:58 . 2004-07-20 05:58 1156363 ----a-w- c:\program files\BDANT.cab
2004-07-20 05:53 . 2004-07-20 05:53 976020 ----a-w- c:\program files\BDAXP.cab
2004-07-09 21:17 . 2004-07-09 21:17 13265040 ----a-w- c:\program files\dxnt.cab
2004-07-09 16:13 . 2004-07-09 16:13 15493481 ----a-w- c:\program files\DirectX.cab
2004-07-09 16:13 . 2004-07-09 16:13 703080 ----a-w- c:\program files\BDA.cab
2004-07-09 11:08 . 2004-07-09 11:08 472576 ----a-w- c:\program files\dxsetup.exe
2004-07-09 11:08 . 2004-07-09 11:08 2242560 ----a-w- c:\program files\dsetup32.dll
2004-07-09 10:03 . 2004-07-09 10:03 62976 ----a-w- c:\program files\DSETUP.dll
2004-03-16 02:51 . 2004-03-16 02:51 114688 ----a-w- c:\program files\internet explorer\plugins\LV71ActiveXControl.dll
2008-06-30 17:44 . 2008-02-23 03:15 324976 ----a-w- c:\program files\mozilla firefox\components\coFFPlgn.dll
.

((((((((((((((((((((((((((((( SnapShot@2010-02-26_20.27.13 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-02-27 23:17 . 2010-02-27 23:17 16384 c:\windows\temp\Perflib_Perfdata_714.dat
+ 2010-02-27 23:20 . 2010-02-27 23:20 16384 c:\windows\temp\Perflib_Perfdata_350.dat
+ 2010-02-27 20:12 . 2010-02-27 20:12 344064 c:\windows\ERDNT\AutoBackup\2-27-2010\Users\00000002\UsrClass.dat
+ 2010-02-27 20:12 . 2005-10-20 20:02 163328 c:\windows\ERDNT\AutoBackup\2-27-2010\ERDNT.EXE
+ 2010-02-27 20:12 . 2010-02-27 20:12 14540800 c:\windows\ERDNT\AutoBackup\2-27-2010\Users\00000001\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LDM"="c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2007-03-19 67128]
"igndlm.exe"="c:\program files\IGN\Download Manager\DLM.exe" [2007-03-05 1103480]
"Google Update"="c:\documents and settings\Russell Klare\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-08 133104]
"CurseClient"="c:\program files\Curse\CurseClient.exe" [2010-01-22 1845248]
"Steam"="c:\program files\steam\steam.exe" [2010-02-23 1217872]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-02-15 454656]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-01-30 13594624]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-01-30 86016]
"nwiz"="nwiz.exe" [2009-01-30 1657376]
"MsmqIntCert"="mqrt.dll" [2008-04-14 177152]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-04-18 61952]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-04 761948]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2006-04-12 102400]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-03-21 213936]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-03-21 86960]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-03-07 131072]
"Cpqset"="c:\program files\HPQ\Default Settings\cpqset.exe" [2006-02-22 40960]
"RecGuard"="c:\windows\SMINST\RecGuard.exe" [2005-10-11 1187840]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-03-21 213936]
"Anti-Blaxx Manager"="c:\program files\Anti-Blaxx\Anti-Blaxx.exe" [2006-11-20 204800]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-04 44032]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-01-23 141608]

c:\documents and settings\Default User\Start Menu\Programs\Startup\
Vongo Tray.lnk - c:\program files\Vongo\Tray.exe [2006-12-11 73728]

c:\documents and settings\Administrator\Start Menu\Programs\Startup\
Vongo Tray.lnk - c:\program files\Vongo\Tray.exe [2006-12-11 73728]

c:\documents and settings\Russell Klare\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\Hp\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
HP Photosmart Premier Fast Start.lnk - c:\program files\Hp\Digital Imaging\bin\hpqthb08.exe [2006-2-10 73728]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-3-19 67128]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mqsvc.exe"=
"c:\\Program Files\\Electronic Arts\\The Battle for Middle-earth (tm) II\\game.dat"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Curse\\CurseClient.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\civilization iv colonization\\Colonization.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\sid meier's civilization iv\\Civilization4.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\sid meier's civilization iv warlords\\Warlords\\Civ4Warlords.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\sid meier's civilization iv warlords\\Warlords\\Civ4Warlords_PitBoss.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1008000.029\SymEFA.sys [2/2/2010 12:20 AM 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NIS\1008000.029\BHDrvx86.sys [2/2/2010 12:20 AM 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NIS\1008000.029\cchpx86.sys [2/2/2010 12:17 AM 482432]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100224.002\IDSXpx86.sys [2/25/2010 2:01 PM 329592]
R2 Norton Internet Security;Norton Internet Security;c:\program files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe [2/2/2010 12:18 AM 117640]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2/23/2010 8:06 AM 102448]
S2 {09BB444F-B2E2-4009-BAF2-7B727681223E};BuddyVM;\??\h:\s.t.a.l.k.e.r - shadow of chernobyl\Hitomi - My Stepsister\VMLaunch\BuddyVM.sys --> h:\s.t.a.l.k.e.r - shadow of chernobyl\Hitomi - My Stepsister\VMLaunch\BuddyVM.sys [?]
S3 cmudau32;C-Media USB UDA Sound Interface;c:\windows\system32\drivers\cmudaxu.sys [8/24/2006 8:28 AM 1391040]
S3 jfdcd;jfdcd;\??\c:\docume~1\RUSSEL~1\LOCALS~1\Temp\jfdcd.sys --> c:\docume~1\RUSSEL~1\LOCALS~1\Temp\jfdcd.sys [?]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [9/26/2006 6:38 PM 643072]
.
Contents of the 'Scheduled Tasks' folder

2010-02-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]

2010-02-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-403753715-2283007472-2311900264-1005Core.job
- c:\documents and settings\Russell Klare\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-08 00:24]

2010-02-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-403753715-2283007472-2311900264-1005UA.job
- c:\documents and settings\Russell Klare\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-08 00:24]

2010-02-27 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 22:07]

2010-02-27 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-05-06 05:18]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Send To &Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
TCP: {738B480C-1CAC-4004-863E-3ED776804BF9} = 134.173.63.200,134.173.254.23
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
FF - ProfilePath - c:\documents and settings\Russell Klare\Application Data\Mozilla\Firefox\Profiles\wra9qko3.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\components\coFFPlgn.dll
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
FF - component: c:\documents and settings\Russell Klare\Application Data\Mozilla\Firefox\Profiles\wra9qko3.default\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}\platform\WINNT\components\FoxyTunes.dll
FF - plugin: c:\documents and settings\Russell Klare\Application Data\Mozilla\Firefox\Profiles\wra9qko3.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071102000004.dll
FF - plugin: c:\documents and settings\Russell Klare\Local Settings\Application Data\Google\Update\1.2.183.17\npGoogleOneClick8.dll
FF - plugin: c:\program files\CambridgeSoft\ChemOffice2008\Chem3D\npChem3DPlugin.dll
FF - plugin: c:\program files\CambridgeSoft\ChemOffice2008\ChemDraw\NPCDN32.DLL
FF - plugin: c:\program files\IGN\Download Manager\npfpdlm.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npSfAppM.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

AddRemove-??????????~????~_is1 - c:\program files\?????\??????????~????~\unins000.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-27 15:48
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\program files\HPQ\Default Settings\cpqset.exe?????? ???@???????????????@? ???`|??????(?@???????@

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe catchme.sys CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x876CB81A]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf75aef28
\Driver\ACPI -> ACPI.sys @ 0xf7421cb8
\Driver\atapi -> atapi.sys @ 0xf7395852
\Driver\iaStor -> iaStor.sys @ 0xf72cbb58
IoDeviceObjectType -> SecurityProcedure -> ntkrnlpa.exe @ 0x80583d4a
\Device\Harddisk0\DR0 -> SecurityProcedure -> ntkrnlpa.exe @ 0x80583d4a
NDIS: Intel(R) PRO/Wireless 3945ABG Network Connection -> SendCompleteHandler -> NDIS.sys @ 0xf717cbb0
PacketIndicateHandler -> NDIS.sys @ 0xf7189a21
SendHandler -> NDIS.sys @ 0xf716787b
user & kernel MBR OK

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet015\Services\Norton Internet Security]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\program files\Norton Internet Security\Engine\16.8.0.41\diMaster.dll\" /prefetch:1"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-403753715-2283007472-2311900264-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1392)
c:\windows\system32\WININET.dll

- - - - - - - > 'lsass.exe'(1456)
c:\windows\system32\WININET.dll
.
Completion time: 2010-02-27 15:55:17
ComboFix-quarantined-files.txt 2010-02-27 23:55
ComboFix2.txt 2010-02-27 04:27
ComboFix3.txt 2010-02-26 20:42
ComboFix4.txt 2010-02-25 22:13
ComboFix5.txt 2010-02-27 23:07

Pre-Run: 3,357,069,312 bytes free
Post-Run: 3,304,988,672 bytes free

- - End Of File - - 3B1EEE1AA9E86582D3E0B8B424196655







Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:57:59 PM, on 2/27/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Vongo\VongoService.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Russell Klare\Desktop\Spybot Stuff\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SpybotSD\SDHelper.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\IPSBHO.DLL
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O2 - BHO: (no name) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - (no file)
O2 - BHO: (no name) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\coIEPlg.dll
O3 - Toolbar: SciFinder Scholar Bar - {4e16a8fb-0521-46d1-aa2c-d0fc7abf6af9} - mscoree.dll (file missing)
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - HKLM\..\Run: [Anti-Blaxx Manager] C:\Program Files\Anti-Blaxx\Anti-Blaxx.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\IGN\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Russell Klare\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [CurseClient] C:\Program Files\Curse\CurseClient.exe -silent
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - S-1-5-18 Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: Registration Ghost Recon Advanced Warfighter.LNK = C:\Program Files\Ubisoft\Ghost Recon Advanced Warfighter\Support\Register\RegistrationReminder.exe
O4 - Startup: Vongo Tray.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SpybotSD\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SpybotSD\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
O16 - DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} (Hewlett-Packard Online Support Services) - http://h50203.www5.hp.com/HPISWeb/Customer/cabs/HPISDataManager.CAB
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{738B480C-1CAC-4004-863E-3ED776804BF9}: NameServer = 134.173.63.200,134.173.254.23
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\coIEPlg.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPBPRO.EXE
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton Internet Security - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Vongo Service - Starz Entertainment Group LLC - C:\Program Files\Vongo\VongoService.exe

--
End of file - 11224 bytes

ken545
2010-02-28, 02:24
Download OTL (http://oldtimer.geekstogo.com/OTL.exe) to your desktop.
Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
When the window appears, underneath Output at the top change it to Minimal Output.
Check the boxes beside LOP Check and Purity Check.
Under the Custom Scan box paste this in


netsvcs
%SYSTEMDRIVE%\*.exe
/md5start
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
sceclt.dll
ntelogon.dll
logevent.dll
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
nvrd32.sys
symmpi.sys
adp3132.sys
mv61xx.sys
/md5stop
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav



Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.

Cent1
2010-02-28, 06:06
OTL.txt (extras.txt is next post)


OTL logfile created on: 2/27/2010 8:35:41 PM - Run 1
OTL by OldTimer - Version 3.1.30.3 Folder = C:\Documents and Settings\Russell Klare\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,022.00 Mb Total Physical Memory | 465.00 Mb Available Physical Memory | 45.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 73.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 101.18 Gb Total Space | 3.10 Gb Free Space | 3.07% Space Free | Partition Type: NTFS
Drive D: | 9.58 Gb Total Space | 1.38 Gb Free Space | 14.37% Space Free | Partition Type: FAT32
Drive E: | 4.16 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: RUSSKLARELAPTOP
Current User Name: Russell Klare
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Russell Klare\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Vongo\VongoService.exe (Starz Entertainment Group LLC)
PRC - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)
PRC - C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Russell Klare\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\asOEHook.dll (Symantec Corporation)


========== Win32 Services (SafeList) ==========

SRV - (iPod Service) -- C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (Norton Internet Security) -- C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe (Symantec Corporation)
SRV - (Apple Mobile Device) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (JavaQuickStarterService) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (NVSvc) -- C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (Bonjour Service) -- C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (getPlus(R) Helper) getPlus(R) -- C:\Program Files\NOS\bin\getPlus_HelperSvc.exe (NOS Microsystems Ltd.)
SRV - (MSMQTriggers) -- C:\WINDOWS\system32\mqtgsvc.exe (Microsoft Corporation)
SRV - (MSMQ) -- C:\WINDOWS\system32\mqsvc.exe (Microsoft Corporation)
SRV - (Adobe LM Service) -- C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe (Adobe Systems)
SRV - (Vongo Service) -- C:\Program Files\Vongo\VongoService.exe (Starz Entertainment Group LLC)
SRV - (hpqwmiex) -- C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe (Hewlett-Packard Development Company, L.P.)
SRV - (Pml Driver HPZ12) -- C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (btwdins) -- C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)
SRV - (LightScribeService) -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (HP Port Resolver) -- C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE (Hewlett-Packard Company)
SRV - (IDriverT) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (ose) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (catchme) -- File not found
DRV - (NAVEX15) -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100227.025\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100227.025\NAVENG.SYS (Symantec Corporation)
DRV - (ccHP) -- C:\WINDOWS\System32\Drivers\NIS\1008000.029\ccHPx86.sys (Symantec Corporation)
DRV - (atksgt) -- C:\WINDOWS\system32\drivers\atksgt.sys ()
DRV - (lirsgt) -- C:\WINDOWS\system32\drivers\lirsgt.sys ()
DRV - (IDSxpx86) -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100224.002\IDSXpx86.sys (Symantec Corporation)
DRV - (SymEvent) -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (eeCtrl) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SymEFA) -- C:\WINDOWS\system32\drivers\NIS\1008000.029\SYMEFA.SYS (Symantec Corporation)
DRV - (SRTSP) -- C:\WINDOWS\System32\Drivers\NIS\1008000.029\SRTSP.SYS (Symantec Corporation)
DRV - (BHDrvx86) -- C:\WINDOWS\System32\Drivers\NIS\1008000.029\BHDrvx86.sys (Symantec Corporation)
DRV - (SYMTDI) -- C:\WINDOWS\System32\Drivers\NIS\1008000.029\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMFW) -- C:\WINDOWS\System32\Drivers\NIS\1008000.029\SYMFW.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) -- C:\WINDOWS\system32\drivers\NIS\1008000.029\SRTSPX.SYS (Symantec Corporation)
DRV - (SYMNDIS) -- C:\WINDOWS\System32\Drivers\NIS\1008000.029\SYMNDIS.SYS (Symantec Corporation)
DRV - (SYMIDS) -- C:\WINDOWS\System32\Drivers\NIS\1008000.029\SYMIDS.SYS (Symantec Corporation)
DRV - (SymIMMP) -- C:\WINDOWS\system32\drivers\SymIM.sys (Symantec Corporation)
DRV - (SymIM) -- C:\WINDOWS\system32\drivers\SymIM.sys (Symantec Corporation)
DRV - (GEARAspiWDM) -- C:\WINDOWS\system32\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (nv) -- C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (RMCAST) -- C:\WINDOWS\system32\drivers\rmcast.sys (Microsoft Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) -- C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (MQAC) -- C:\WINDOWS\system32\drivers\mqac.sys (Microsoft Corporation)
DRV - (amdagp) -- C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) -- C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (HDAudBus) -- C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows (R) Server 2003 DDK provider)
DRV - (USBAAPL) -- C:\WINDOWS\system32\drivers\usbaapl.sys (Apple, Inc.)
DRV - (Secdrv) -- C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (dtscsi) -- C:\WINDOWS\System32\Drivers\dtscsi.sys (DT Soft Ltd.)
DRV - (sptd) -- C:\WINDOWS\system32\drivers\sptd.sys (Duplex Secure Ltd.)
DRV - (HdAudAddService) -- C:\WINDOWS\system32\drivers\CHDAud.sys (Conexant Systems Inc.)
DRV - (w39n51) Intel(R) -- C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
DRV - (SynTP) -- C:\WINDOWS\system32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (btaudio) -- C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.)
DRV - (BTKRNL) -- C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.)
DRV - (BTDriver) -- C:\WINDOWS\system32\drivers\btport.sys (Broadcom Corporation.)
DRV - (BTWUSB) -- C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (BTWDNDIS) -- C:\WINDOWS\system32\drivers\btwdndis.sys (Broadcom Corporation.)
DRV - (btwhid) -- C:\WINDOWS\system32\drivers\btwhid.sys (Broadcom Corporation.)
DRV - (mdmxsdk) -- C:\WINDOWS\system32\drivers\mdmxsdk.sys (Conexant)
DRV - (cmudau32) -- C:\WINDOWS\system32\drivers\cmudaxu.sys (C-Media Inc)
DRV - (HPZipr12) -- C:\WINDOWS\system32\drivers\HPZipr12.sys (HP)
DRV - (HPZid412) -- C:\WINDOWS\system32\drivers\HPZid412.sys (HP)
DRV - (HPZius12) -- C:\WINDOWS\system32\drivers\HPZius12.sys (HP)
DRV - (E100B) Intel(R) -- C:\WINDOWS\system32\drivers\e100b325.sys (Intel Corporation)
DRV - (iaStor) -- C:\WINDOWS\system32\DRIVERS\iaStor.sys ()
DRV - (tifm21) -- C:\WINDOWS\system32\drivers\tifm21.sys (Texas Instruments)
DRV - (eabusb) -- C:\WINDOWS\system32\drivers\EabUsb.sys (Hewlett-Packard Development Company, L.P.)
DRV - (HBtnKey) -- C:\WINDOWS\system32\drivers\CPQBttn.sys (Hewlett-Packard Development Company, L.P.)
DRV - (eabfiltr) -- C:\WINDOWS\system32\drivers\eabfiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (HSF_DPV) -- C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) -- C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (PxHelp20) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (ENTECH) -- C:\WINDOWS\system32\drivers\Entech.sys (EnTech Taiwan)
DRV - (Ptilink) -- C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (FsVga) -- C:\WINDOWS\system32\drivers\fsvga.sys (Microsoft Corporation)
DRV - (rtl8139) Realtek RTL8139(A/B/C) -- C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (Sparrow) -- C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) -- C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) -- C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) -- C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) -- C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (ultra) -- C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) -- C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) -- C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) -- C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) -- C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) -- C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) -- C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) -- C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) -- C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) -- C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (StillCam) -- C:\WINDOWS\system32\drivers\serscan.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..extensions.enabledItems: moveplayer@movenetworks.com:1.0.0.071102000004
FF - prefs.js..extensions.enabledItems: personas@christopher.beard:1.5.1
FF - prefs.js..extensions.enabledItems: {888d99e7-e8b5-46a3-851e-1ec45da1e644}:3.6.2
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: redshift_V2@shift-themes.com:3.0

FF - HKLM\software\mozilla\Firefox\extensions\\{7BA52691-1876-45ce-9EE6-54BCB3B04BBC}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\ [2010/02/27 15:18:53 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/02/18 17:40:07 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/02/25 21:23:45 | 000,000,000 | ---D | M]

[2008/06/18 17:02:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Russell Klare\Application Data\Mozilla\Extensions
[2010/02/27 15:58:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Russell Klare\Application Data\Mozilla\Firefox\Profiles\wra9qko3.default\extensions
[2008/01/25 13:22:23 | 000,000,000 | ---D | M] (Adblock) -- C:\Documents and Settings\Russell Klare\Application Data\Mozilla\Firefox\Profiles\wra9qko3.default\extensions\{34274bf4-1d97-a289-e984-17e546307e4f}
[2009/11/16 18:32:21 | 000,000,000 | ---D | M] (FoxyTunes) -- C:\Documents and Settings\Russell Klare\Application Data\Mozilla\Firefox\Profiles\wra9qko3.default\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}
[2010/02/20 19:36:21 | 000,000,000 | ---D | M] (ReloadEvery) -- C:\Documents and Settings\Russell Klare\Application Data\Mozilla\Firefox\Profiles\wra9qko3.default\extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}
[2008/11/01 11:07:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Russell Klare\Application Data\Mozilla\Firefox\Profiles\wra9qko3.default\extensions\moveplayer@movenetworks.com
[2010/02/20 19:36:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Russell Klare\Application Data\Mozilla\Firefox\Profiles\wra9qko3.default\extensions\personas@christopher.beard
[2009/09/16 17:50:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Russell Klare\Application Data\Mozilla\Firefox\Profiles\wra9qko3.default\extensions\redshift_V2@shift-themes.com
[2010/02/27 15:58:51 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2008/06/30 09:44:08 | 000,324,976 | ---- | M] (Symantec Corporation) -- C:\Program Files\Mozilla Firefox\components\coFFPlgn.dll
[2007/05/16 10:30:04 | 000,036,864 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\npSfAppM.dll

O1 HOSTS File: ([2010/02/26 19:59:51 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\SpybotSD\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - No CLSID value found.
O2 - BHO: (no name) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - No CLSID value found.
O2 - BHO: (no name) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - No CLSID value found.
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\CoIEPlg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\CoIEPlg.dll (Symantec Corporation)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Anti-Blaxx Manager] C:\Program Files\Anti-Blaxx\Anti-Blaxx.exe (MB-Soft, HAANDI)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\Cpqset.exe ()
O4 - HKLM..\Run: [High Definition Audio Property Page Shortcut] C:\WINDOWS\System32\CHDAudPropShortcut.exe (Windows (R) Server 2003 DDK provider)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpWirelessAssistant] C:\Program Files\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\imekrmig.exe (Microsoft Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [ISUSPM] C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe (Macrovision Corporation)
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe (Macrovision Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Macrovision Corporation)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [MsmqIntCert] C:\WINDOWS\System32\mqrt.dll (Microsoft Corporation)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [QlbCtrl] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe ( Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [QPService] C:\Program Files\HP\QuickPlay\QPService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
O4 - HKLM..\Run: [RecGuard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKCU..\Run: [CurseClient] C:\Program Files\Curse\CurseClient.exe ()
O4 - HKCU..\Run: [Google Update] C:\Documents and Settings\Russell Klare\Local Settings\Application Data\Google\Update\GoogleUpdate.exe (Google Inc.)
O4 - HKCU..\Run: [igndlm.exe] C:\Program Files\IGN\Download Manager\DLM.exe (IGN Entertainment)
O4 - HKCU..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe (Logitech Inc.)
O4 - HKCU..\Run: [Steam] c:\program files\steam\steam.exe (Valve Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\StartUp\HP Digital Imaging Monitor.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Development Company, L.P.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\StartUp\HP Photosmart Premier Fast Start.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Development Company, L.P.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\StartUp\Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe (Logitech Inc.)
O4 - Startup: C:\Documents and Settings\Russell Klare\Start Menu\Programs\StartUp\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\Russell Klare\Start Menu\Programs\StartUp\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O4 - Startup: C:\Documents and Settings\Russell Klare\Start Menu\Programs\StartUp\Registration Ghost Recon Advanced Warfighter.LNK = C:\Program Files\Ubisoft\Ghost Recon Advanced Warfighter\Support\Register\RegistrationReminder.exe File not found
O4 - Startup: C:\Documents and Settings\Russell Klare\Start Menu\Programs\StartUp\Vongo Tray.lnk = C:\Documents and Settings\Russell Klare\Application Data\Microsoft\Installer\{DB7E00C9-6DEF-489A-8112-D8F81614F45A}\NewShortcut2_DB7E00C96DEF489A8112D8F81614F45A.exe (Macrovision Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\SpybotSD\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} http://h50203.www5.hp.com/HPISWeb/Customer/cabs/HPISDataManager.CAB (Hewlett-Packard Online Support Services)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab (get_atlcom Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 134.173.254.23 134.173.53.8
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
O18 - Protocol\Handler\symres {AA1061FE-6C41-421f-9344-69640C9732AB} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\CoIEPlg.dll (Symantec Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Russell Klare\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Russell Klare\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2001/07/27 22:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT -- [ FAT32 ]
O32 - AutoRun File - [2005/11/21 09:26:21 | 000,000,057 | R--- | M] () - E:\autorun.inf -- [ UDF ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] -- "%1" %*
O35 - exefile [open] -- "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2006/05/09 21:44:53 | 000,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

========== Files/Folders - Created Within 30 Days ==========

[2010/02/27 19:32:13 | 000,549,888 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Russell Klare\Desktop\OTL.exe
[2010/02/26 20:31:44 | 000,417,136 | ---- | C] (Sysinternals) -- C:\WINDOWS\handle.exe
[2010/02/25 19:25:39 | 000,050,688 | ---- | C] (Atribune.org) -- C:\Documents and Settings\Russell Klare\Desktop\ATF-Cleaner.exe
[2010/02/22 23:04:42 | 000,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2010/02/19 18:22:04 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2010/02/18 12:15:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple Computer
[2010/02/18 11:11:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2010/02/18 04:09:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Apple Computer
[2010/02/18 04:08:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Sun
[2010/02/17 16:01:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2010/02/17 12:37:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Macromedia
[2010/02/17 12:37:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Adobe
[2010/02/17 12:19:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Application Data\Sun
[2010/02/17 12:19:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2010/02/17 12:19:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/02/17 10:51:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/02/16 22:23:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Russell Klare\Local Settings\Application Data\Electronic Arts
[2010/02/16 19:37:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Russell Klare\My Documents\Electronic Arts
[2010/02/14 23:00:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Russell Klare\Local Settings\Application Data\HotheadGames
[2010/02/14 20:53:22 | 000,000,000 | ---D | C] -- C:\Program Files\Hothead Games
[2010/02/10 16:18:54 | 094,152,744 | ---- | C] (Symantec Corporation) -- C:\Documents and Settings\Russell Klare\Desktop\NIS-ESD-17-5-0-127-EN.exe
[2010/02/09 20:27:40 | 000,000,000 | ---D | C] -- C:\Program Files\Norn
[2010/02/05 14:29:54 | 000,000,000 | ---D | C] -- C:\Program Files\luchs
[2010/02/03 15:01:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Russell Klare\Application Data\.chimera
[2010/02/02 18:48:44 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2010/02/02 18:48:22 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2010/02/02 18:40:24 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2010/02/02 10:29:05 | 000,000,000 | ---D | C] -- C:\Program Files\Chimera
[2010/02/02 10:29:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Chimera
[2010/01/31 13:29:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Russell Klare\Application Data\BDL+D
[2008/10/17 14:41:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Xfire
[2008/06/27 11:28:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2007/08/11 13:07:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Application Data\Xfire
[2006/11/30 23:26:28 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
[2006/05/09 23:50:13 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2006/02/18 23:28:56 | 000,012,288 | ---- | C] (Hewlett-Packard Development Company, L.P.) -- C:\WINDOWS\Fonts\RandFont.dll
[2004/07/09 03:08:36 | 000,472,576 | ---- | C] (Microsoft Corporation) -- C:\Program Files\dxsetup.exe
[2004/07/09 03:08:34 | 002,242,560 | ---- | C] (Microsoft Corporation) -- C:\Program Files\dsetup32.dll
[2004/07/09 02:03:10 | 000,062,976 | ---- | C] (Microsoft Corporation) -- C:\Program Files\DSETUP.dll
[7 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[106 C:\Documents and Settings\Russell Klare\My Documents\*.tmp files -> C:\Documents and Settings\Russell Klare\My Documents\*.tmp -> ]
[1 C:\Documents and Settings\Russell Klare\*.tmp files -> C:\Documents and Settings\Russell Klare\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/02/27 20:06:03 | 000,001,010 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-403753715-2283007472-2311900264-1005UA.job
[2010/02/27 19:32:19 | 000,549,888 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Russell Klare\Desktop\OTL.exe
[2010/02/27 15:55:20 | 000,000,260 | ---- | M] () -- C:\WINDOWS\tasks\WGASetup.job
[2010/02/27 15:55:20 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/02/27 15:49:14 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010/02/27 15:20:21 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/02/27 15:18:18 | 000,000,236 | ---- | M] () -- C:\WINDOWS\tasks\OGALogon.job
[2010/02/27 15:17:05 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/02/27 15:16:28 | 000,695,558 | ---- | M] () -- C:\WINDOWS\System32\drivers\NIS\1008000.029\Cat.DB
[2010/02/27 15:15:15 | 014,680,064 | -H-- | M] () -- C:\Documents and Settings\Russell Klare\NTUSER.DAT
[2010/02/27 15:15:15 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\Russell Klare\ntuser.ini
[2010/02/27 12:13:02 | 000,001,515 | ---- | M] () -- C:\hpqp.ini
[2010/02/27 12:10:17 | 000,002,317 | ---- | M] () -- C:\Documents and Settings\Russell Klare\Start Menu\Programs\StartUp\Vongo Tray.lnk
[2010/02/27 12:09:52 | 000,000,039 | ---- | M] () -- C:\XP_TV.ini
[2010/02/27 12:09:43 | 000,194,401 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2010/02/26 23:06:01 | 000,000,958 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-403753715-2283007472-2311900264-1005Core.job
[2010/02/26 22:09:57 | 000,000,162 | -H-- | M] () -- C:\Documents and Settings\Russell Klare\Desktop\~$oblem Set 5_2010.doc
[2010/02/26 19:59:51 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010/02/26 19:10:58 | 003,873,931 | R--- | M] () -- C:\Documents and Settings\Russell Klare\Desktop\Combo-Fix.exe
[2010/02/26 13:49:26 | 000,000,140 | ---- | M] () -- C:\Documents and Settings\Russell Klare\defogger_reenable
[2010/02/26 12:13:03 | 000,140,559 | ---- | M] () -- C:\Documents and Settings\Russell Klare\Desktop\comboprob.JPG
[2010/02/26 00:07:41 | 000,002,344 | ---- | M] () -- C:\Documents and Settings\Russell Klare\Desktop\Google Chrome.lnk
[2010/02/25 23:23:24 | 000,033,280 | ---- | M] () -- C:\Documents and Settings\Russell Klare\Desktop\Problem Set 5_2010.doc
[2010/02/25 20:12:21 | 000,011,946 | -HS- | M] () -- C:\Documents and Settings\Russell Klare\Local Settings\Application Data\rQVN4I4g
[2010/02/25 19:25:40 | 000,050,688 | ---- | M] (Atribune.org) -- C:\Documents and Settings\Russell Klare\Desktop\ATF-Cleaner.exe
[2010/02/25 19:04:31 | 000,002,193 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Steam.lnk
[2010/02/24 10:30:55 | 000,174,551 | ---- | M] () -- C:\Documents and Settings\Russell Klare\Desktop\gmer problem.JPG
[2010/02/23 18:31:05 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/02/23 10:46:35 | 000,293,376 | ---- | M] () -- C:\Documents and Settings\Russell Klare\Desktop\8xtdzj6s.exe
[2010/02/23 09:56:12 | 000,050,477 | ---- | M] () -- C:\Documents and Settings\Russell Klare\Desktop\Defogger.exe
[2010/02/22 23:05:07 | 000,000,767 | ---- | M] () -- C:\Documents and Settings\Russell Klare\Start Menu\Programs\StartUp\ERUNT AutoBackup.lnk
[2010/02/22 23:04:49 | 000,000,592 | ---- | M] () -- C:\Documents and Settings\Russell Klare\Desktop\ERUNT.lnk
[2010/02/21 23:59:48 | 000,030,720 | ---- | M] () -- C:\Documents and Settings\Russell Klare\My Documents\Locke and or Hobbes state of nature.doc
[2010/02/21 19:02:23 | 000,012,752 | ---- | M] () -- C:\Documents and Settings\Russell Klare\My Documents\Guidelines for exploratory writing and first paper.pdf
[2010/02/19 18:22:05 | 000,001,734 | ---- | M] () -- C:\Documents and Settings\Russell Klare\Desktop\HijackThis.lnk
[2010/02/19 16:39:05 | 000,000,315 | RHS- | M] () -- C:\boot.ini
[2010/02/19 14:48:58 | 000,032,768 | ---- | M] () -- C:\Documents and Settings\Russell Klare\My Documents\yay polygamy.doc
[2010/02/19 13:36:12 | 000,045,056 | ---- | M] () -- C:\Documents and Settings\Russell Klare\My Documents\Resume Russell Klare seminar.doc
[2010/02/18 12:15:07 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/02/17 15:57:20 | 000,000,840 | ---- | M] () -- C:\Documents and Settings\Russell Klare\Desktop\‚Ђ܂í‚胖‹u‘‡•a‰@‚ւ悤‚±‚».LNK
[2010/02/16 20:11:28 | 000,001,794 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Dead Space™.lnk
[2010/02/15 19:45:57 | 000,039,295 | ---- | M] () -- C:\Documents and Settings\Russell Klare\My Documents\Dead_Space.4466027.TPB.torrent
[2010/02/15 10:45:05 | 000,000,611 | ---- | M] () -- C:\prob set 3 what the fuck
[2010/02/14 17:50:58 | 000,019,317 | ---- | M] () -- C:\Documents and Settings\Russell Klare\My Documents\Penny.Arcade.Adventures.On.the.Rain-Slick.Precipice.of.Darkness..4200936.TPB.torrent
[2010/02/14 16:16:44 | 000,000,097 | ---- | M] () -- C:\WINDOWS\amaenbo.ini
[2010/02/13 01:13:55 | 000,000,113 | ---- | M] () -- C:\WINDOWS\WININIT.INI
[2010/02/12 19:47:32 | 000,222,720 | ---- | M] () -- C:\Documents and Settings\Russell Klare\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/02/11 17:55:30 | 000,382,424 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/02/11 12:23:52 | 000,056,832 | ---- | M] () -- C:\Documents and Settings\Russell Klare\My Documents\porphyrin.xls
[2010/02/10 16:19:14 | 094,152,744 | ---- | M] (Symantec Corporation) -- C:\Documents and Settings\Russell Klare\Desktop\NIS-ESD-17-5-0-127-EN.exe
[2010/02/10 00:52:13 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010/02/10 00:47:32 | 002,005,876 | ---- | M] () -- C:\WINDOWS\iis6.BAK
[2010/02/08 18:25:24 | 000,001,973 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Norton Internet Security.lnk
[2010/02/08 18:22:21 | 003,174,326 | -H-- | M] () -- C:\Documents and Settings\Russell Klare\Local Settings\Application Data\IconCache.db
[2010/02/08 16:13:57 | 000,001,792 | ---- | M] () -- C:\isoscr.5
[2010/02/07 23:22:52 | 000,000,654 | ---- | M] () -- C:\prob set 2 sim
[2010/02/07 22:42:34 | 000,002,261 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\SpinWorks 3.lnk
[2010/02/03 18:25:32 | 000,011,632 | ---- | M] () -- C:\Documents and Settings\Russell Klare\My Documents\biochem 1.cdx
[2010/02/02 18:50:53 | 000,001,804 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/02/02 10:34:05 | 000,000,764 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Chimera.lnk
[2010/02/02 00:17:23 | 000,482,432 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NIS\1008000.029\cchpx86.sys
[2010/02/02 00:17:17 | 000,000,172 | ---- | M] () -- C:\WINDOWS\System32\drivers\NIS\1008000.029\isolate.ini
[2010/01/31 21:27:19 | 000,000,224 | ---- | M] () -- C:\WINDOWS\Hitoduma2.ini
[7 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[106 C:\Documents and Settings\Russell Klare\My Documents\*.tmp files -> C:\Documents and Settings\Russell Klare\My Documents\*.tmp -> ]
[1 C:\Documents and Settings\Russell Klare\*.tmp files -> C:\Documents and Settings\Russell Klare\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/02/26 22:09:57 | 000,000,162 | -H-- | C] () -- C:\Documents and Settings\Russell Klare\Desktop\~$oblem Set 5_2010.doc
[2010/02/26 13:49:25 | 000,000,140 | ---- | C] () -- C:\Documents and Settings\Russell Klare\defogger_reenable
[2010/02/26 12:13:02 | 000,140,559 | ---- | C] () -- C:\Documents and Settings\Russell Klare\Desktop\comboprob.JPG
[2010/02/25 23:23:21 | 000,033,280 | ---- | C] () -- C:\Documents and Settings\Russell Klare\Desktop\Problem Set 5_2010.doc
[2010/02/25 19:11:22 | 000,011,946 | -HS- | C] () -- C:\Documents and Settings\Russell Klare\Local Settings\Application Data\rQVN4I4g
[2010/02/25 12:49:08 | 003,873,931 | R--- | C] () -- C:\Documents and Settings\Russell Klare\Desktop\Combo-Fix.exe
[2010/02/24 10:30:55 | 000,174,551 | ---- | C] () -- C:\Documents and Settings\Russell Klare\Desktop\gmer problem.JPG
[2010/02/23 10:46:34 | 000,293,376 | ---- | C] () -- C:\Documents and Settings\Russell Klare\Desktop\8xtdzj6s.exe
[2010/02/23 09:56:10 | 000,050,477 | ---- | C] () -- C:\Documents and Settings\Russell Klare\Desktop\Defogger.exe
[2010/02/22 23:05:07 | 000,000,767 | ---- | C] () -- C:\Documents and Settings\Russell Klare\Start Menu\Programs\StartUp\ERUNT AutoBackup.lnk
[2010/02/22 23:04:49 | 000,000,592 | ---- | C] () -- C:\Documents and Settings\Russell Klare\Desktop\ERUNT.lnk
[2010/02/21 23:40:55 | 000,030,720 | ---- | C] () -- C:\Documents and Settings\Russell Klare\My Documents\Locke and or Hobbes state of nature.doc
[2010/02/21 19:02:15 | 000,012,752 | ---- | C] () -- C:\Documents and Settings\Russell Klare\My Documents\Guidelines for exploratory writing and first paper.pdf
[2010/02/19 18:22:05 | 000,001,734 | ---- | C] () -- C:\Documents and Settings\Russell Klare\Desktop\HijackThis.lnk
[2010/02/19 01:40:46 | 000,032,768 | ---- | C] () -- C:\Documents and Settings\Russell Klare\My Documents\yay polygamy.doc
[2010/02/17 15:57:20 | 000,000,840 | ---- | C] () -- C:\Documents and Settings\Russell Klare\Desktop\‚Ђ܂í‚胖‹u‘‡•a‰@‚ւ悤‚±‚».LNK
[2010/02/16 20:11:28 | 000,001,794 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Dead Space™.lnk
[2010/02/15 19:45:57 | 000,039,295 | ---- | C] () -- C:\Documents and Settings\Russell Klare\My Documents\Dead_Space.4466027.TPB.torrent
[2010/02/15 00:52:40 | 000,000,611 | ---- | C] () -- C:\prob set 3 what the fuck
[2010/02/14 17:50:58 | 000,019,317 | ---- | C] () -- C:\Documents and Settings\Russell Klare\My Documents\Penny.Arcade.Adventures.On.the.Rain-Slick.Precipice.of.Darkness..4200936.TPB.torrent
[2010/02/14 16:16:44 | 000,000,097 | ---- | C] () -- C:\WINDOWS\amaenbo.ini
[2010/02/11 12:23:52 | 000,056,832 | ---- | C] () -- C:\Documents and Settings\Russell Klare\My Documents\porphyrin.xls
[2010/02/08 18:25:23 | 000,001,973 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Norton Internet Security.lnk
[2010/02/08 16:13:07 | 000,001,792 | ---- | C] () -- C:\isoscr.5
[2010/02/07 23:22:52 | 000,000,654 | ---- | C] () -- C:\prob set 2 sim
[2010/02/03 18:18:36 | 000,011,632 | ---- | C] () -- C:\Documents and Settings\Russell Klare\My Documents\biochem 1.cdx
[2010/02/02 18:50:53 | 000,001,804 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/02/02 10:34:03 | 000,000,764 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Chimera.lnk
[2010/01/31 21:27:19 | 000,000,224 | ---- | C] () -- C:\WINDOWS\Hitoduma2.ini
[2010/01/10 21:57:14 | 000,000,132 | ---- | C] () -- C:\WINDOWS\sailor_tuma.ini
[2010/01/10 13:11:33 | 000,000,081 | ---- | C] () -- C:\WINDOWS\Oumetokkai_Chiemi.ini
[2010/01/09 12:47:29 | 000,000,148 | ---- | C] () -- C:\WINDOWS\Oumetokkai_reiko.ini
[2009/12/08 19:12:47 | 000,279,712 | ---- | C] () -- C:\WINDOWS\System32\drivers\atksgt.sys
[2009/12/08 19:12:45 | 000,025,888 | ---- | C] () -- C:\WINDOWS\System32\drivers\lirsgt.sys
[2009/12/03 16:43:43 | 000,004,488 | ---- | C] () -- C:\Documents and Settings\Russell Klare\Local Settings\Application Data\gcs.pref
[2009/08/03 14:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2009/07/23 17:57:06 | 000,041,872 | ---- | C] () -- C:\WINDOWS\System32\xfcodec.dll
[2009/06/27 15:50:20 | 000,000,162 | ---- | C] () -- C:\WINDOWS\System32\AddPort.ini
[2009/06/27 15:49:59 | 000,000,687 | ---- | C] () -- C:\WINDOWS\hpntwksetup.ini
[2009/06/26 13:04:52 | 000,000,058 | ---- | C] () -- C:\WINDOWS\OSA.INI
[2009/06/04 23:01:06 | 009,214,464 | ---- | C] () -- C:\WINDOWS\avcodec-52.dll
[2009/06/04 23:01:06 | 000,745,984 | ---- | C] () -- C:\WINDOWS\avformat-52.dll
[2009/06/04 23:01:06 | 000,218,624 | ---- | C] () -- C:\WINDOWS\swscale-0.dll
[2009/06/04 23:01:06 | 000,070,144 | ---- | C] () -- C:\WINDOWS\avutil-50.dll
[2009/05/10 08:18:42 | 000,060,416 | ---- | C] () -- C:\WINDOWS\zlib1.dll
[2009/05/10 08:17:16 | 000,162,304 | ---- | C] () -- C:\WINDOWS\libpng13.dll
[2009/05/09 11:57:14 | 000,122,368 | ---- | C] () -- C:\WINDOWS\lua5.1.dll
[2009/02/17 21:22:24 | 000,142,336 | ---- | C] () -- C:\WINDOWS\System32\libcl.dll
[2008/10/07 08:13:30 | 000,197,912 | ---- | C] () -- C:\WINDOWS\System32\physxcudart_20.dll
[2008/10/07 08:13:22 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 08:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008/10/07 08:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008/10/07 08:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 08:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008/10/07 08:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll
[2008/10/07 08:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008/10/07 08:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll
[2008/10/07 08:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll
[2008/09/30 16:25:52 | 000,000,324 | ---- | C] () -- C:\WINDOWS\cafej.ini
[2008/09/25 20:59:45 | 000,000,297 | ---- | C] () -- C:\WINDOWS\mrsj.ini
[2008/02/17 19:15:31 | 000,000,309 | ---- | C] () -- C:\WINDOWS\milkj.ini
[2008/02/17 19:12:43 | 000,000,316 | ---- | C] () -- C:\WINDOWS\milkj3.ini
[2008/02/17 19:08:16 | 000,000,316 | ---- | C] () -- C:\WINDOWS\milkj2.ini
[2008/02/08 18:21:19 | 000,126,464 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll
[2008/01/31 13:42:59 | 000,000,157 | ---- | C] () -- C:\WINDOWS\matlab.ini
[2008/01/14 15:47:06 | 000,099,712 | ---- | C] () -- C:\WINDOWS\HPBroker.dll
[2007/11/26 20:56:28 | 000,151,415 | ---- | C] () -- C:\WINDOWS\System32\xlive.dll.cat
[2007/02/13 12:26:32 | 000,000,248 | ---- | C] () -- C:\WINDOWS\RomeTW.ini
[2007/01/29 23:38:44 | 000,000,708 | ---- | C] () -- C:\WINDOWS\KGOleSrv.INI
[2006/12/17 11:27:20 | 000,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll
[2006/11/14 17:10:25 | 000,001,360 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/11/03 23:07:11 | 000,000,023 | ---- | C] () -- C:\WINDOWS\BlendSettings.ini
[2006/09/22 14:46:21 | 000,003,972 | ---- | C] () -- C:\WINDOWS\System32\drivers\PciBus.sys
[2006/09/08 21:23:05 | 000,761,856 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2006/09/08 21:23:04 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2006/08/24 09:18:04 | 000,077,824 | R--- | C] () -- C:\WINDOWS\System32\HPZIDS01.dll
[2006/08/24 08:28:03 | 000,045,056 | R--- | C] () -- C:\WINDOWS\System32\cmdrvrmu.dll
[2006/08/24 08:27:41 | 000,004,952 | R--- | C] () -- C:\WINDOWS\Cmudau.ini
[2006/08/18 03:17:51 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Russell Klare\Application Data\wklnhst.dat
[2006/08/17 15:30:17 | 000,000,136 | ---- | C] () -- C:\Documents and Settings\Russell Klare\Local Settings\Application Data\fusioncache.dat
[2006/08/17 15:30:17 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Russell Klare\Local Settings\Application Data\DSwitch.txt
[2006/08/17 15:30:17 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Russell Klare\Local Settings\Application Data\AtStart.txt
[2006/08/17 15:30:16 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Russell Klare\Local Settings\Application Data\QSwitch.txt
[2006/08/17 09:20:18 | 000,222,720 | ---- | C] () -- C:\Documents and Settings\Russell Klare\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/05/10 00:29:47 | 000,000,174 | ---- | C] () -- C:\WINDOWS\QUICKEN.INI
[2006/05/10 00:27:06 | 000,000,698 | ---- | C] () -- C:\WINDOWS\NSSetDefaultBrowser.ini
[2006/05/10 00:07:52 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/05/10 00:04:35 | 000,028,836 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2006/05/09 21:45:42 | 001,724,416 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2006/05/09 21:45:42 | 001,101,824 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2006/05/09 21:45:41 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2006/05/09 21:45:40 | 001,507,328 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2006/03/27 08:54:36 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006/03/27 08:23:14 | 000,004,589 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2006/03/27 08:18:52 | 000,000,113 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2006/03/27 08:15:14 | 000,000,791 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2006/02/27 12:51:36 | 000,090,112 | ---- | C] () -- C:\WINDOWS\System32\btprn2k.dll
[2005/12/02 10:09:10 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2005/10/12 17:07:12 | 000,874,240 | ---- | C] () -- C:\WINDOWS\System32\drivers\iaStor.sys
[2004/07/22 09:51:34 | 003,432,656 | ---- | C] () -- C:\Program Files\ManagedDX.CAB
[2004/07/19 21:58:36 | 001,156,363 | ---- | C] () -- C:\Program Files\BDANT.cab
[2004/07/19 21:53:26 | 000,976,020 | ---- | C] () -- C:\Program Files\BDAXP.cab
[2004/07/09 13:17:16 | 013,265,040 | ---- | C] () -- C:\Program Files\dxnt.cab
[2004/07/09 08:13:48 | 015,493,481 | ---- | C] () -- C:\Program Files\DirectX.cab
[2004/07/09 08:13:46 | 000,703,080 | ---- | C] () -- C:\Program Files\BDA.cab
[2004/02/20 12:36:34 | 000,416,256 | ---- | C] () -- C:\WINDOWS\exchndl.dll
[2004/01/13 11:46:34 | 000,172,032 | ---- | C] () -- C:\WINDOWS\System32\tifmicon.dll
[2003/01/07 14:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2002/05/15 18:29:04 | 000,000,607 | ---- | C] () -- C:\WINDOWS\System32\BTNeighborhood.dll.manifest
[2001/11/23 13:18:00 | 000,000,597 | ---- | C] () -- C:\WINDOWS\System32\btcss.dll.manifest
[2001/11/14 08:56:00 | 001,802,240 | ---- | C] () -- C:\WINDOWS\System32\lcppn21.dll
[2001/07/07 02:00:00 | 000,003,399 | ---- | C] () -- C:\WINDOWS\System32\hptcpmon.ini

========== LOP Check ==========

[2009/12/26 11:47:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BioWare
[2008/01/24 16:58:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CambridgeSoft
[2010/02/02 10:29:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Chimera
[2009/06/19 12:47:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ElectricSheep
[2010/01/25 15:27:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Electronic Arts
[2008/11/01 12:57:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Fallout3
[2009/03/31 19:01:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PCSettings
[2008/09/01 19:53:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2008/05/09 17:54:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ubisoft
[2009/03/17 14:52:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2009/09/15 18:54:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/04/07 17:39:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2010/02/03 15:02:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Russell Klare\Application Data\.chimera
[2010/01/31 13:29:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Russell Klare\Application Data\BDL+D
[2007/11/07 13:23:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Russell Klare\Application Data\BitTorrent
[2008/09/14 14:17:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Russell Klare\Application Data\com.directv.supercast.AA1ECC8BBAFE4E1BBF2D418DC006AF207FACE6CA.1
[2009/03/27 20:01:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Russell Klare\Application Data\FOG Downloader
[2006/09/04 22:40:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Russell Klare\Application Data\funkitron
[2006/09/10 21:13:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Russell Klare\Application Data\G-Force
[2007/02/16 23:54:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Russell Klare\Application Data\GetRightToGo
[2006/12/08 18:18:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Russell Klare\Application Data\Leadertech
[2006/09/04 15:47:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Russell Klare\Application Data\Mind Control Software
[2006/08/20 16:21:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Russell Klare\Application Data\My Battle for Middle-earth(tm) II Files
[2006/12/09 16:37:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Russell Klare\Application Data\My Games
[2007/11/15 20:25:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Russell Klare\Application Data\Opera
[2008/12/05 22:12:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Russell Klare\Application Data\Planetside Software
[2006/09/04 15:48:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Russell Klare\Application Data\PlayFirst
[2009/07/06 12:44:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Russell Klare\Application Data\SPORE
[2008/06/23 18:35:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Russell Klare\Application Data\SPORE Creature Creator
[2006/10/09 13:20:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Russell Klare\Application Data\System Requirements Lab
[2008/05/08 20:41:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Russell Klare\Application Data\SystemRequirementsLab
[2007/03/14 14:19:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Russell Klare\Application Data\Turbine
[2008/05/09 17:54:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Russell Klare\Application Data\Ubisoft
[2007/01/26 01:22:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Russell Klare\Application Data\uk.co.planetside
[2010/02/25 21:21:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Russell Klare\Application Data\uTorrent
[2010/02/16 23:07:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Russell Klare\Application Data\Waffle
[2010/02/27 15:18:18 | 000,000,236 | ---- | M] () -- C:\WINDOWS\Tasks\OGALogon.job
[2010/02/27 15:55:20 | 000,000,260 | ---- | M] () -- C:\WINDOWS\Tasks\WGASetup.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2004/08/04 05:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\I386\sp2.cab:AGP440.sys
[2004/08/04 13:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/09/21 15:39:30 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008/09/21 15:39:30 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 10:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ERDNT\cache\agp440.sys
[2008/04/13 10:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 10:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
[2004/08/04 07:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\$NtServicePackUninstall$\agp440.sys

< MD5 for: ATAPI.SYS >
[2004/08/04 05:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\I386\sp2.cab:atapi.sys
[2004/08/04 13:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/09/21 15:39:30 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008/09/21 15:39:30 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 10:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ERDNT\cache\atapi.sys
[2008/04/13 10:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 10:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/03 21:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2004/08/04 06:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0011\DriverFiles\i386\atapi.sys

< MD5 for: EVENTLOG.DLL >
[1999/10/02 09:24:46 | 000,017,408 | ---- | M] () MD5=1363337A5301619F00F8033835EF30E9 -- C:\MATLAB\R2007a\sys\perl\win32\site\lib\auto\Win32\EventLog\EventLog.dll
[2008/04/13 16:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ERDNT\cache\eventlog.dll
[2008/04/13 16:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 16:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\eventlog.dll
[2004/08/04 13:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: IASTOR.SYS >
[2005/10/13 01:07:12 | 000,874,240 | ---- | M] (Intel Corporation) MD5=309C4D86D989FB1FCF64BD30DC81C51B -- C:\SWSETUP\HDD\iastor.sys
[2005/10/13 01:07:12 | 000,874,240 | ---- | M] ()[b] Unable to obtain MD5 -- C:\WINDOWS\system32\drivers\iaStor.sys

< MD5 for: NETLOGON.DLL >
[2008/04/13 16:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ERDNT\cache\netlogon.dll
[2008/04/13 16:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 16:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\netlogon.dll
[2004/08/04 13:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004/08/04 13:00:00 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 16:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ERDNT\cache\scecli.dll
[2008/04/13 16:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 16:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2009/03/08 00:31:44 | 000,348,160 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\dxtmsft.dll
[2009/03/08 00:31:38 | 000,216,064 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\dxtrans.dll
[2009/12/21 11:14:03 | 000,184,320 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\iepeers.dll
[7 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2005/10/13 01:07:12 | 000,874,240 | ---- | M] () Unable to obtain MD5 -- C:\WINDOWS\system32\drivers\iaStor.sys

< %systemroot%\System32\config\*.sav >
[2006/03/26 23:47:52 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2006/03/26 23:47:52 | 000,659,456 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav

========== Files - Unicode (All) ==========
[2010/01/25 15:01:08 | 000,000,276 | ---- | M] ()(C:\WINDOWS\System32\??????~?!~?????????~(DL?).ini) -- C:\WINDOWS\System32\乳ちちちちち~ッ!~ミルクまみれカフェ~(DL版).ini
[2010/01/25 15:01:08 | 000,000,276 | ---- | C] ()(C:\WINDOWS\System32\??????~?!~?????????~(DL?).ini) -- C:\WINDOWS\System32\乳ちちちちち~ッ!~ミルクまみれカフェ~(DL版).ini

========== Alternate Data Streams ==========

@Alternate Data Stream - 60 bytes -> C:\64 bits:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\32 bits:AFP_AfpInfo
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:466F9D5D
< End of report >

Cent1
2010-02-28, 06:07
Extras:



OTL Extras logfile created on: 2/27/2010 8:35:41 PM - Run 1
OTL by OldTimer - Version 3.1.30.3 Folder = C:\Documents and Settings\Russell Klare\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,022.00 Mb Total Physical Memory | 465.00 Mb Available Physical Memory | 45.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 73.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 101.18 Gb Total Space | 3.10 Gb Free Space | 3.07% Space Free | Partition Type: NTFS
Drive D: | 9.58 Gb Total Space | 1.38 Gb Free Space | 14.37% Space Free | Partition Type: FAT32
Drive E: | 4.16 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: RUSSKLARELAPTOP
Current User Name: Russell Klare
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.exe [@ = exefile] -- Reg Error: Key error. File not found
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "%programfiles%\internet explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"" =
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\WINDOWS\system32\mqsvc.exe" = C:\WINDOWS\system32\mqsvc.exe:*:Enabled:Message Queuing -- (Microsoft Corporation)
"" =
"C:\Program Files\Vongo\VongoService.exe" = C:\Program Files\Vongo\VongoService.exe:*:enabled:VongoService -- (Starz Entertainment Group LLC)
"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger -- (Logitech Inc.)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\WINDOWS\system32\mqsvc.exe" = C:\WINDOWS\system32\mqsvc.exe:*:Enabled:Message Queuing -- (Microsoft Corporation)
"C:\Program Files\Electronic Arts\The Battle for Middle-earth (tm) II\game.dat" = C:\Program Files\Electronic Arts\The Battle for Middle-earth (tm) II\game.dat:*:Enabled:The Battle for Middle-earth(tm) II -- (Electronic Arts Inc.)
"C:\Program Files\Xfire\Xfire.exe" = C:\Program Files\Xfire\Xfire.exe:*:Enabled:Xfire -- (Xfire Inc.)
"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger -- (Logitech Inc.)
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour -- (Apple Inc.)
"C:\Program Files\Curse\CurseClient.exe" = C:\Program Files\Curse\CurseClient.exe:*:Enabled:Curse Client -- ()
"C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe" = C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe -- (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\Hp\Digital Imaging\bin\hpqste08.exe" = C:\Program Files\Hp\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe -- (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\Hp\Digital Imaging\bin\hpofxm08.exe" = C:\Program Files\Hp\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe -- (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\Hp\Digital Imaging\bin\hposfx08.exe" = C:\Program Files\Hp\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe -- (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\Hp\Digital Imaging\bin\hposid01.exe" = C:\Program Files\Hp\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe -- (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\Hp\Digital Imaging\bin\hpqscnvw.exe" = C:\Program Files\Hp\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe -- ()
"C:\Program Files\Hp\Digital Imaging\bin\hpqkygrp.exe" = C:\Program Files\Hp\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe -- (Hewlett-Packard)
"C:\Program Files\Hp\Digital Imaging\bin\hpqCopy.exe" = C:\Program Files\Hp\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe -- (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\Hp\Digital Imaging\bin\hpfccopy.exe" = C:\Program Files\Hp\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe -- (Hewlett-Packard)
"C:\Program Files\Hp\Digital Imaging\bin\hpzwiz01.exe" = C:\Program Files\Hp\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe -- (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\Hp\Digital Imaging\Unload\HpqPhUnl.exe" = C:\Program Files\Hp\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe -- (Hewlett-Packard)
"C:\Program Files\Hp\Digital Imaging\Unload\HpqDIA.exe" = C:\Program Files\Hp\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe -- ( )
"C:\Program Files\Hp\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\Hp\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe -- (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\Hp\Digital Imaging\bin\hpqnrs08.exe" = C:\Program Files\Hp\Digital Imaging\bin\hpqnrs08.exe:*:Enabled:hpqnrs08.exe -- (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\Steam\steamapps\common\civilization iv colonization\Colonization.exe" = C:\Program Files\Steam\steamapps\common\civilization iv colonization\Colonization.exe:*:Enabled:Sid Meier's Civilization IV: Colonization -- (Firaxis Games)
"C:\Program Files\Steam\steamapps\common\sid meier's civilization iv\Civilization4.exe" = C:\Program Files\Steam\steamapps\common\sid meier's civilization iv\Civilization4.exe:*:Enabled:Sid Meier's Civilization IV -- (Firaxis Games)
"C:\Program Files\Steam\steamapps\common\sid meier's civilization iv warlords\Warlords\Civ4Warlords.exe" = C:\Program Files\Steam\steamapps\common\sid meier's civilization iv warlords\Warlords\Civ4Warlords.exe:*:Enabled:Sid Meier's Civilization IV: Warlords -- (Firaxis Games)
"C:\Program Files\Steam\steamapps\common\sid meier's civilization iv warlords\Warlords\Civ4Warlords_PitBoss.exe" = C:\Program Files\Steam\steamapps\common\sid meier's civilization iv warlords\Warlords\Civ4Warlords_PitBoss.exe:*:Enabled:Sid Meier's Civilization IV: Warlords -- (Firaxis Games)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic Data Module
"{09D8492A-C8E2-421E-927D-46800FB327A3}" = Wireless Home Network Setup
"{0A65A3BD-54B5-4d0d-B084-7688507813F5}" = SlideShow
"{1170D24F-42B7-40CF-AA1B-6395CE562354}" = Gears of War
"{12377A05-0062-47F9-9CB9-AAAF8C22D645}" = SciFinder Scholar 2007
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{15C0AF59-4877-49B6-B8C6-A61CE54515F5}" = cp_OnlineProjectsConfig
"{15C13906-1280-45F7-9460-A5861E79056C}" = CambridgeSoft ChemDraw Std 11.0
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD Plus
"{23012310-3E05-46A5-88A9-C6CBCABCAC79}" = Customer Experience Enhancement
"{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"{2376813B-2E5A-4641-B7B3-A0D5ADB55229}" = HPPhotoSmartExpress
"{23B35809-5E4A-4F14-8332-1CDEDDFAC089}" = CP_Package_Variety2
"{23D683DD-93C6-48E6-B84E-78B57778F126}" = Oblivion - Construction Set
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java(TM) 6 Update 13
"{2818095F-FB6C-42C8-827E-0A406CC9AFF5}" = Quicken 2006
"{286F29AF-0BE2-4D5F-AB17-B7631A810553}" = muvee autoProducer 4.5
"{2A9A40C7-6670-4D5F-8F41-D12E2E08B48B}" = Star Wars®: Knights of the Old Republic (TM)
"{2A9F95AB-65A3-432c-8631-B8BC5BF7477A}" = The Battle for Middle-earth (tm) II
"{2F58D60D-2BFD-4467-9B4D-64E7355C329D}" = Sonic_PrimoSDK
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java(TM) SE Runtime Environment 6 Update 1
"{33BF0960-DBA3-4187-B6CC-C969FCFA2D25}" = SkinsHP1
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.00 E2
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35CB6715-41F8-4F99-8881-6FC75BF054B0}" = Oblivion
"{363790D2-DA98-41DD-9C9F-69FA36B169DE}" = PanoStandAlone
"{36D620AD-EEBA-4973-BA86-0C9AE6396620}" = OptionalContentQFolder
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
"{3875B963-E867-44B9-8637-54ACA5C713DF}" = PlasmaVis
"{394BE3D9-7F57-4638-A8D1-1D88671913B7}" = Microsoft AppLocale
"{3AC54383-31D1-4907-961B-B12CBB1D0AE8}" = MobileMe Control Panel
"{3F4EC965-28EF-45C3-B063-04B25D4E9679}" = HP Integrated Module with Bluetooth wireless technology
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works
"{41E776A5-9B12-416D-9A12-B4F7B044EBED}" = CP_Package_Basic1
"{4302B2DD-D958-40E3-BAF3-B07FFE1978CE}" = HP Wireless Assistant 2.00 E1
"{455F9ACD-4967-446B-9174-8C87EA895F2A}" = SciFinder Scholar Toolbar
"{45B8A76B-57EC-4242-B019-066400CD8428}" = BufferChm
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP QuickPlay 2.1
"{47D2103B-FD51-4017-9C20-DD408B17D726}" = Office 2003 Trial Assistant
"{4D87DC92-C328-46EC-A7B4-9C88129DC696}" = Dead Space™
"{4DA4012B-39AF-48c2-B23B-A4D570D233A6}" = cp_LightScribeConfig
"{4DDAF49F-500E-404F-9894-D5F005B8FA4E}" = SpinWorks_3
"{4EA684E9-5C81-4033-A696-3019EC57AC3A}" = HPProductAssistant
"{518930BE-7875-4547-B026-20B92F695781}" = NI LabVIEW Run-Time Engine 7.1
"{522D1D79-9C0A-4361-91F8-2AFF8EC6C2E1}" = CP_Package_Variety1
"{629F65FB-7F3C-4D66-A1C0-20722744B7B6}" = Star Wars(R) Knights of the Old Republic(R) II: The Sith Lords(TM)
"{62D77FB3-32E3-4D37-AB96-0941DE80C9CA}" = Magic The Gathering Online Tutorial
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Sonic Express Labeler
"{66910000-8B30-4973-A159-6371345AFFA5}" = WebReg
"{6696D9A4-28A8-4F5A-8E9A-2E8974C8C39C}" = RandMap
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6815FCDD-401D-481E-BA88-31B4754C2B46}" = Macromedia Flash Player 8
"{68763C27-235D-4165-A961-FDEA228CE504}" = AiOSoftwareNPI
"{6909F917-5499-482e-9AA1-FAD06A99F231}" = Toolbox
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6994491D-D491-48F1-AE1F-E179C1FFFC2F}" = HP Photosmart Essential
"{6B976ADF-8AE8-434E-B282-A06C7F624D2F}" = Python 2.5.2
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{736C803C-DD3B-4015-BC51-AFB9E67B9076}" = Readme
"{75E71ADD-042C-4F30-BFAC-A9EC42351313}" = Python 2.4.3
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{786C5747-1033-0000-B58E-000000000001}" = Adobe Stock Photos 1.0
"{7B6CF9EB-CB2B-4A1A-81A9-BE1A9044690A}" = TIPCI
"{7C03270C-4FAB-4F5C-B10D-52FEDA190790}" = DocumentViewerQFolder
"{7E7B7865-6C80-4373-8BC1-C2EB9431F9DE}" = ProductContextNPI
"{80AE27BA-B0ED-4288-A8B9-D8194BCF4115}" = cp_UpdateProjectsConfig
"{8105684D-8CA6-440D-8F58-7E5FD67A499D}" = Easy Internet Sign-up
"{8331C3EA-0C91-43AA-A4D4-27221C631139}" = Status
"{863F58EF-467F-4BCC-A40B-D2304630DEA1}" = CambridgeSoft Activation Client
"{876A4C7A-412A-40b8-9DCF-B04D2339B73E}" = c7100_Help
"{8795CBED-55E2-4693-9F14-84EC446935BE}" = SpeechRedist
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A4CE7FD-9657-4B06-9943-E1819F3D5D67}" = DocProc
"{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}" = Unload
"{8CFA9151-6404-409A-AF22-4632D04582FD}" = Assassin's Creed
"{8DAE4336-2B71-11D4-9A6C-006067325E47}" = Baldur's Gate(TM) II - Shadows of Amn(TM)
"{8EDBA74D-0686-4C99-BFDD-F894678E5B39}" = Adobe Common File Installer
"{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}" = Logitech Desktop Messenger
"{91110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{929CE49F-1CA7-4CF3-A9A1-6D757443C63F}" = Microsoft Games for Windows - LIVE Redistributable
"{974C4B12-4D02-4879-85E0-61C95CC63E9E}" = Fallout 3
"{977C5080-EA08-435D-8901-233A506E1651}}_is1" = VLC Skin Editor
"{996512CF-F35B-48DE-9291-557FA5316967}" = ScannerCopy
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BF36062-6E39-46CF-9823-9FB8C700D682}" = Terragen 2 Technology Preview
"{A01FC76F-CC09-4658-9E37-5C2F635EE708}" = TourSetup
"{A29800BA-0BF1-4E63-9F31-DF05A87F4104}" = InstantShareDevices
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A5181519-9F3D-4372-ABC6-C333C2F3A816}_is1" = RunAlyzer
"{A59BB15D-51B7-F12B-4548-8C0368243441}" = EA Download Manager UI
"{A642BB6B-CA1D-4142-8DD4-318C3F3DC834}" = Rome - Total War(TM)
"{A7B279F4-E9B0-470F-A6A0-54C31C340DBC}" = C7100
"{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}" = HP Help and Support
"{A9F5421F-DA70-4C77-BB97-8D77EC33ED5E}" = HP Photosmart and Deskjet 7.0.A
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Sonic Audio Module
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1.3
"{AEF7A12C-CD9B-4773-8AD1-6916138CA7EA}" = SmartAudio
"{B11E71BA-498C-42D4-9F1A-9D7A89D9DA61}" = CP_AtenaShokunin1Config
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Sonic Copy Module
"{B1494C3E-687F-4E4D-8038-D57154338D9D}" = Wolfram Mathematica 6
"{B2157760-AA3C-4E2E-BFE6-D20BC52495D9}" = cp_PosterPrintConfig
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B57F2FF0-5A25-4332-B503-4592B370C02F}" = CP_Package_Variety3
"{B6286A44-7505-471A-A72B-04EC2DB2F442}" = CueTour
"{B69CFE29-FD03-4E0A-87A7-6ED97F98E5B3}" = CP_Panorama1Config
"{B74D4E10-1033-0000-0000-000000000001}" = Adobe Bridge 1.0
"{B8C3B479-1716-11D5-968A-0050BA84F5F7}" = Baldur's Gate(TM) II - Throne of Bhaal (TM)
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BC96BBA7-C634-460E-AD18-A0A994213F80}" = HP User Guides--System Recovery
"{BDBE2F3E-42DB-4d4a-8CB1-19BA765DBC6C}" = HP Photosmart, Officejet and Deskjet 7.0.A
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C1C6767D-B395-43CB-BF99-051B58B86DA6}" = PhotoGallery
"{C3C9EB3D-24FA-4462-B784-0EC6AAFCD2DD}" = Fable - The Lost Chapters
"{C7F54CF8-D6FB-4E0A-93A3-E68AE0D6C476}" = SolutionCenter
"{C8753E28-2680-49BF-BD48-DD38FD086EFE}" = AiO_Scan_CDA
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CCEB53A5-A252-4CF3-8602-429AB06BF0AE}" = Terragen
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7}" = getPlus(R) for Adobe
"{D6E4E5D6-7693-4BB4-95BA-21F38FAFEE90}" = Safari
"{D755C7A3-C03E-4460-8C00-AC6E55505FB5}" = LightScribe 1.4.74.1
"{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" = HpSdpAppCoreApp
"{DB7E00C9-6DEF-489A-8112-D8F81614F45A}" = Vongo
"{DBC20735-34E6-4E97-A9E5-2066B66B243D}" = TrayApp
"{DD1865F0-AD73-40FB-B23E-1822E02396FF}" = NVIDIA PhysX
"{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb" = Microsoft Windows Application Compatibility Database
"{E1B80DEE-A795-4258-8445-074C06AE3AB8}" = MarketResearch
"{E74E3D81-773B-4DCF-B706-50236F80BD81}" = HP User Guides 0019
"{E9787678-1033-0000-8E67-000000000001}" = Adobe Help Center 1.0
"{EC43DDFD-99BA-43DA-9B7D-58328C36637E}" = Kaleidagraph
"{ED2C557E-9C18-41FF-B58E-A05EEF0B3B5F}" = CP_CalendarTemplates1
"{F157460F-720E-482f-8625-AD7843891E5F}" = InstantShareDevicesMFC
"{F3760724-B29D-465B-BC53-E5D72095BCC4}" = Scan
"{F439D7AF-03F3-4F8E-AEC4-571BFE977C61}" = iTunes
"{F6076EF9-08E1-442F-B6A2-BFB61B295A14}" = Fax_CDA
"{F9335A34-A982-E441-CF26-4DF7B9CFF8AF}" = Supercast
"{F9B2E82F-B10A-454E-B19B-735CFF6A5DD2}" = Wolfram Notebook Indexer 2.0
"{FA54AFB1-5745-4389-B8C1-9F7509672ED1}" = iPhone Configuration Utility
"{FB15E224-67C3-491F-9F5C-F257BC418412}" = Destinations
"{FBB980B0-63F8-4B48-8D65-90F1D9F81D9F}" = NewCopy_CDA
"{FC10C290-6E4D-4C6B-A8B3-33700C21F9E6}" = Mathematica 5.2 for Students
"{FE57DE70-95DE-4B64-9266-84DA811053DB}" = HP Update
"{FE7E1DD7-EBCE-4696-ADE2-22BDBF2372DA}" = DocumentViewer
"0E5266B4-9069-401A-93AE-5FF9F1712016" = Insaniquarium Deluxe from Hewlett-Packard Laptops (remove only)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Anti-Blaxx_is1" = Anti-Blaxx 1.15
"Apophysis 2.0" = Apophysis 2.0
"Chimera_is1" = UCSF Chimera 1.4_b29530
"CNXT_HDAUDIO" = Conexant HD Audio
"CNXT_MODEM_HDAUDIO_CPL30A5m" = HDAUDIO Soft Data Fax Modem with SmartCP
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"com.directv.supercast.AA1ECC8BBAFE4E1BBF2D418DC006AF207FACE6CA.1" = DIRECTV SUPERCAST
"com.ea.Vault.919CACB699904AC5D41B606703500DD39747C02D.1" = EA Download Manager UI
"CurseClient" = Curse Client
"E76A7EFF-7758-49EE-B3FA-9699830A2D6B" = Mah Jong Quest from Hewlett-Packard Laptops (remove only)
"EA Download Manager" = EA Download Manager
"Electricsheep Screensaver" = Electricsheep Screensaver 2.7b17
"ERUNT_is1" = ERUNT 1.1j
"F2566CC2-D4C4-44ED-A838-3F8288D8D3FE" = Flip Words from Hewlett-Packard Laptops (remove only)
"FoxyTunesForFirefox" = FoxyTunes for Firefox
"GameSpy Arcade" = GameSpy Arcade
"Generic USB Sound" = USB Audio
"G-Force" = G-Force
"GRE POWERPREP" = GRE POWERPREP
"HijackThis" = HijackThis 2.0.2
"HP Document Viewer" = HP Document Viewer 7.0
"HP Game Console" = HP Game Console and games
"HP Imaging Device Functions" = HP Imaging Device Functions 7.0
"HP Photo & Imaging" = HP Photosmart Premier Software 6.5
"HP Rhapsody" = HP Rhapsody
"HP Solution Center & Imaging Support Tools" = HP Solution Center 7.0
"HPExtendedCapabilities" = HP Customer Participation Program 7.0
"HPOCR" = OCR Software by I.R.I.S 7.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"IGN Download Manager" = IGN Download Manager 2.2.2
"InstallShield_{1170D24F-42B7-40CF-AA1B-6395CE562354}" = Gears of War
"InstallShield_{15C13906-1280-45F7-9460-A5861E79056C}" = CambridgeSoft ChemDraw Std 11.0
"InstallShield_{23012310-3E05-46A5-88A9-C6CBCABCAC79}" = Customer Experience Enhancement
"InstallShield_{7B6CF9EB-CB2B-4A1A-81A9-BE1A9044690A}" = Texas Instruments PCIxx21/x515/xx12 drivers.
"InstallShield_{8105684D-8CA6-440D-8F58-7E5FD67A499D}" = Easy Internet Sign-up
"InstallShield_{A642BB6B-CA1D-4142-8DD4-318C3F3DC834}" = Rome - Total War(TM)
"InstallShield_{C3C9EB3D-24FA-4462-B784-0EC6AAFCD2DD}" = Fable - The Lost Chapters
"InstallShield_{FC10C290-6E4D-4C6B-A8B3-33700C21F9E6}" = Mathematica 5.2 for Students
"IrfanView" = IrfanView (remove only)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MatlabR2007a" = MATLAB R2007a
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MojoWorld3.1 Demo_is1" = MojoWorld3.1 Demo
"Money2006b" = Microsoft Money 2006
"Mozilla Firefox (3.5.8)" = Mozilla Firefox (3.5.8)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MTG Forge_is1" = MTG Forge
"Netscape Browser" = Netscape Browser (remove only)
"NI Uninstaller" = National Instruments Software
"NIS" = Norton Internet Security
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"Oblivion mod manager_is1" = Oblivion mod manager 1.1.9
"oggcodecs" = oggcodecs 0.71.0946
"Operation Optimization_is1" = Operation Optimization v1.1.1
"PFConfig" = PFConfig 1.0.163
"PROSet" = Intel(R) PRO Network Connections Drivers
"QuteMol" = QuteMol 0.4.1
"ST5UNST #1" = CyclicVoltSim
"Starcraft" = Starcraft
"Steam App 16810" = Sid Meier's Civilization IV: Colonization
"Steam App 3900" = Sid Meier's Civilization IV
"Steam App 3990" = Sid Meier's Civilization IV: Warlords
"Steam App 8800" = Sid Meier's Civilization IV: Beyond the Sword
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"System Requirements Lab" = System Requirements Lab
"u‚l‚h‚k‚jEƒWƒƒƒ“ƒL[‚Qv@(c)BLUEGALE" = u‚l‚h‚k‚jEƒWƒƒƒ“ƒL[‚Qv@(c)BLUEGALE
"u‚l‚h‚k‚jEƒWƒƒƒ“ƒL[‚Rv@(c)BLUEGALE" = u‚l‚h‚k‚jEƒWƒƒƒ“ƒL[‚Rv@(c)BLUEGALE
"u‚l‚h‚k‚jEƒWƒƒƒ“ƒL[v(c)BLUEGALE" = u‚l‚h‚k‚jEƒWƒƒƒ“ƒL[v(c)BLUEGALE
"uƒ~ƒZƒXEƒWƒƒƒ“ƒL[v(c)BLUEGALE" = uƒ~ƒZƒXEƒWƒƒƒ“ƒL[v(c)BLUEGALE
"uƒJƒtƒFEƒWƒƒƒ“ƒL[v@(c)ÌÞÙ¹Þ ON DEMAND" = uƒJƒtƒFEƒWƒƒƒ“ƒL[v@(c)ÌÞÙ¹Þ ON DEM
"Unofficial Oblivion Patch_is1" = Unofficial Oblivion Patch v3.0.0
"VLC media player" = VLC media player 1.0.1
"VPython for Python 2.4_is1" = VPython 3.2.9
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"World Machine1.25" = World Machine 1.25 Basic Edition (remove only)
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"wxPython2.8-ansi-py25_is1" = wxPython 2.8.7.1 (ansi) for Python 2.5
"Xfire" = Xfire (remove only)
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"XviD_is1" = XviD 1.1 final uninstall
"もしも透明人間になれるなら" = もしも透明人間になれたなら
"乳辱アナウンサー静香~乳揉み編~_is1" = 乳辱アナウンサー静香~乳揉み編~

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer
"Octoshape add-in for Adobe Flash Player" = Octoshape add-in for Adobe Flash Player

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/24/2010 4:57:15 PM | Computer Name = RUSSKLARELAPTOP | Source = Google Update | ID = 20
Description =

Error - 2/24/2010 5:01:21 PM | Computer Name = RUSSKLARELAPTOP | Source = Google Update | ID = 20
Description =

Error - 2/24/2010 6:01:06 PM | Computer Name = RUSSKLARELAPTOP | Source = Google Update | ID = 20
Description =

[ Application Events ]
Error - 2/24/2010 4:57:15 PM | Computer Name = RUSSKLARELAPTOP | Source = Google Update | ID = 20
Description =

Error - 2/24/2010 5:01:21 PM | Computer Name = RUSSKLARELAPTOP | Source = Google Update | ID = 20
Description =

Error - 2/24/2010 6:01:06 PM | Computer Name = RUSSKLARELAPTOP | Source = Google Update | ID = 20
Description =

[ System Events ]
Error - 2/24/2010 4:53:40 PM | Computer Name = RUSSKLARELAPTOP | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume C:.

Error - 2/24/2010 4:53:40 PM | Computer Name = RUSSKLARELAPTOP | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.

Error - 2/24/2010 4:53:40 PM | Computer Name = RUSSKLARELAPTOP | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.

Error - 2/24/2010 4:56:08 PM | Computer Name = RUSSKLARELAPTOP | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
SCDEmu

Error - 2/27/2010 1:16:58 PM | Computer Name = RUSSKLARELAPTOP | Source = NetBT | ID = 4321
Description = The name "MUDD :1d" could not be registered on the Interface
with IP address 134.173.56.115. The machine with the IP address 134.173.56.115 did
not allow the name to be claimed by this machine.


< End of report >

ken545
2010-02-28, 14:48
Nothing earth shattering


Please run this free online virus scanner from ESET (http://www.eset.com/onlinescan/)

Note: You will need to use Internet explorer for this scan
Tick the box next to YES, I accept the Terms of Use.
Click Start
When asked, allow the activex control to install
Click Start
Make sure that the option Remove found threats is ticked, and the option Scan unwanted applications is checked
Click Scan
Wait for the scan to finish
Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
Copy and paste that log as a reply to this topic

Cent1
2010-02-28, 22:57
Alright, I tried to run it but it claimed it was "done" after scanning 0 files and running for 0 seconds (and, obviously, it didn't find anything). Should I turn off Norton and try it again?

ken545
2010-02-28, 23:02
Please do , you need to temporarily disable your onboard Anti Virus.

If it still wont run then try this one.




Please do a scan with Kaspersky Online Scanner (http://www.kaspersky.com/kos/eng/partner/default/kavwebscan.html) or from Here. (http://www.kaspersky.com/virusscanner)

Click on the Accept button and install any components it needs.
The program will install and then begin downloading the latest definition files.
After the files have been downloaded on the left side of the page in the Scan section select My Computer.
This will start the program and scan your system.
The scan will take a while, so be patient and let it run. (At times it may appear to stall)
Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.

Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.


Once the scan is complete, click on View scan report To obtain the report:
Click on: Save Report As
Next, in the Save as prompt, Save in area, select: Desktop
In the File name area, use KScan, or something similar In Save as type, click the drop arrow and select: Text file [*.txt]
Then, click: Save
Please post the Kaspersky Online Scanner Report in your reply.



http://i275.photobucket.com/albums/jj285/Bleeping/KAS/KAS9.gif

Cent1
2010-03-01, 19:41
Alright, I ran the first scan without my anti-virus running and it scanned, but it didn't find anything. I haven't scanned with Kaspersky yet. Should I?

ken545
2010-03-01, 19:46
I would, it cant hurt.

How is your system behaving now ?

Cent1
2010-03-01, 22:11
(Haven't run the Kaspersky scan yet, because I need my computer and it makes more sense to run it overnight or sometime when that's all that's going on)

It still gets "attacked" (HTTP Tidserv request, says Norton) by c36996639.cn/ whenever I search something in Google (application path goes through Firefox.exe). Every so often (20, 30 minutes) a new tab opens, ads, searches or something, I'm not really sure because I try to close them as soon as they open. When the tab displays the URL (at least initially) it tends to have my last google search in there somewhere. For example, the last one I have is (if my last google search was "this is a test") (brackets aren't really there; [random numbers] is actually a67990067, in this example):

/?url=http://[random numbers].cn/[more random stuff]ref=http://bulkputty.org/key/[still more random stuff]=this+is+a+test

Sorry for if the description isn't clear, but that's what I mean by having the search in there.

Haven't tried Chrome, but I doubt it'll work.

I suspect the malware is using something with svchost, just because
1). some of the attacks are going through \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\SVCHOST.EXE
2). There are times when task manager has Svchost using half my CPU or more (though it's relatively uncommon) and
3). Maybe once or twice every few days (if I've left my comp running on overnight, an error message pops up saying there was an error in svchost.exe (don't know the exact message). If I hit Okay, to close the process, my computer becomes unresponsive, generally. I can still scroll web pages, for example, or close tabs, but I can't close or minimize Firefox, can't click the start menu or anything on the bottom bar, task manager doesn't really respond, etc.

In general, something is clearly "wrong" with it, but it's not crippling.

I have no idea if any of that helps.

ken545
2010-03-01, 23:24
Hold off on Kaspersky for the moment.

Run this tool

Download TDSSKiller and save it to your Desktop.
http://support.kaspersky.com/downloads/utils/tdsskiller.zip

Extract the file and run it.
Once completed it will create a log in your C:\ drive
Please post the contents of that log

Cent1
2010-03-02, 04:41
Alright, I used that and it found three things, then it asked to restart my computer, so I did. When my computer next started up it ran the CHKDSK scan and deleted a few files (mostly old uTorrent stuff I think). Then, when it tried to re-start, it very briefly displayed a blue screen of death type and would keep going through the initial startup until I ran it under "Last known good configuration", after which it worked fine.

Norton doesn't show any attacks since I booted, nor when I do google searches. Chrome appears to work fine. I'm cautiously optimistic that the rootkit is gone.

If it is (or even if it isn't), thanks a bunch for helping me here.



Here's the log:

18:45:24:218 5640 TDSS rootkit removing tool 2.2.7.1 Feb 27 2010 13:29:25
18:45:24:218 5640 ================================================================================
18:45:24:218 5640 SystemInfo:

18:45:24:218 5640 OS Version: 5.1.2600 ServicePack: 3.0
18:45:24:218 5640 Product type: Workstation
18:45:24:218 5640 ComputerName: RUSSKLARELAPTOP
18:45:24:218 5640 UserName: Russell Klare
18:45:24:218 5640 Windows directory: C:\WINDOWS
18:45:24:218 5640 Processor architecture: Intel x86
18:45:24:218 5640 Number of processors: 2
18:45:24:218 5640 Page size: 0x1000
18:45:24:218 5640 Boot type: Normal boot
18:45:24:218 5640 ================================================================================
18:45:25:000 5640 UnloadDriverW: NtUnloadDriver error 2
18:45:25:000 5640 ForceUnloadDriverW: UnloadDriverW(klmd21) error 2
18:45:26:125 5640 Initialize success
18:45:26:125 5640
18:45:26:125 5640 Scanning Services ...
18:45:26:125 5640 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\system
18:45:26:125 5640 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
18:45:26:125 5640 wfopen_ex: Trying to KLMD file open
18:45:26:125 5640 wfopen_ex: File opened ok (Flags 2)
18:45:26:125 5640 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\software
18:45:26:125 5640 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
18:45:26:125 5640 wfopen_ex: Trying to KLMD file open
18:45:26:125 5640 wfopen_ex: File opened ok (Flags 2)
18:45:26:843 5640 GetAdvancedServicesInfo: Raw services enum returned 390 services
18:45:26:843 5640 fclose_ex: Trying to close file C:\WINDOWS\system32\config\system
18:45:26:859 5640 fclose_ex: Trying to close file C:\WINDOWS\system32\config\software
18:45:26:859 5640
18:45:26:859 5640 Scanning Kernel memory ...
18:45:26:859 5640 Devices to scan: 4
18:45:26:859 5640
18:45:26:859 5640 Driver Name: Disk
18:45:26:859 5640 IRP_MJ_CREATE : F75B0BB0
18:45:26:859 5640 IRP_MJ_CREATE_NAMED_PIPE : 804F4562
18:45:26:859 5640 IRP_MJ_CLOSE : F75B0BB0
18:45:26:859 5640 IRP_MJ_READ : F75AAD1F
18:45:26:859 5640 IRP_MJ_WRITE : F75AAD1F
18:45:26:859 5640 IRP_MJ_QUERY_INFORMATION : 804F4562
18:45:26:859 5640 IRP_MJ_SET_INFORMATION : 804F4562
18:45:26:859 5640 IRP_MJ_QUERY_EA : 804F4562
18:45:26:859 5640 IRP_MJ_SET_EA : 804F4562
18:45:26:859 5640 IRP_MJ_FLUSH_BUFFERS : F75AB2E2
18:45:26:859 5640 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4562
18:45:26:859 5640 IRP_MJ_SET_VOLUME_INFORMATION : 804F4562
18:45:26:859 5640 IRP_MJ_DIRECTORY_CONTROL : 804F4562
18:45:26:859 5640 IRP_MJ_FILE_SYSTEM_CONTROL : 804F4562
18:45:26:859 5640 IRP_MJ_DEVICE_CONTROL : F75AB3BB
18:45:26:859 5640 IRP_MJ_INTERNAL_DEVICE_CONTROL : F75AEF28
18:45:26:859 5640 IRP_MJ_SHUTDOWN : F75AB2E2
18:45:26:859 5640 IRP_MJ_LOCK_CONTROL : 804F4562
18:45:26:859 5640 IRP_MJ_CLEANUP : 804F4562
18:45:26:859 5640 IRP_MJ_CREATE_MAILSLOT : 804F4562
18:45:26:859 5640 IRP_MJ_QUERY_SECURITY : 804F4562
18:45:26:859 5640 IRP_MJ_SET_SECURITY : 804F4562
18:45:26:859 5640 IRP_MJ_POWER : F75ACC82
18:45:26:859 5640 IRP_MJ_SYSTEM_CONTROL : F75B199E
18:45:26:859 5640 IRP_MJ_DEVICE_CHANGE : 804F4562
18:45:26:859 5640 IRP_MJ_QUERY_QUOTA : 804F4562
18:45:26:859 5640 IRP_MJ_SET_QUOTA : 804F4562
18:45:26:875 5640 TDL3_StartIoLastChanceHookDetect: Unable to dump StartIo handler code
18:45:26:875 5640 sion
18:45:26:875 5640 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
18:45:26:875 5640
18:45:26:875 5640 Driver Name: Disk
18:45:26:875 5640 IRP_MJ_CREATE : F75B0BB0
18:45:26:875 5640 IRP_MJ_CREATE_NAMED_PIPE : 804F4562
18:45:26:875 5640 IRP_MJ_CLOSE : F75B0BB0
18:45:26:875 5640 IRP_MJ_READ : F75AAD1F
18:45:26:875 5640 IRP_MJ_WRITE : F75AAD1F
18:45:26:875 5640 IRP_MJ_QUERY_INFORMATION : 804F4562
18:45:26:875 5640 IRP_MJ_SET_INFORMATION : 804F4562
18:45:26:875 5640 IRP_MJ_QUERY_EA : 804F4562
18:45:26:875 5640 IRP_MJ_SET_EA : 804F4562
18:45:26:875 5640 IRP_MJ_FLUSH_BUFFERS : F75AB2E2
18:45:26:875 5640 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4562
18:45:26:875 5640 IRP_MJ_SET_VOLUME_INFORMATION : 804F4562
18:45:26:875 5640 IRP_MJ_DIRECTORY_CONTROL : 804F4562
18:45:26:875 5640 IRP_MJ_FILE_SYSTEM_CONTROL : 804F4562
18:45:26:875 5640 IRP_MJ_DEVICE_CONTROL : F75AB3BB
18:45:26:875 5640 IRP_MJ_INTERNAL_DEVICE_CONTROL : F75AEF28
18:45:26:875 5640 IRP_MJ_SHUTDOWN : F75AB2E2
18:45:26:875 5640 IRP_MJ_LOCK_CONTROL : 804F4562
18:45:26:875 5640 IRP_MJ_CLEANUP : 804F4562
18:45:26:875 5640 IRP_MJ_CREATE_MAILSLOT : 804F4562
18:45:26:875 5640 IRP_MJ_QUERY_SECURITY : 804F4562
18:45:26:875 5640 IRP_MJ_SET_SECURITY : 804F4562
18:45:26:875 5640 IRP_MJ_POWER : F75ACC82
18:45:26:875 5640 IRP_MJ_SYSTEM_CONTROL : F75B199E
18:45:26:875 5640 IRP_MJ_DEVICE_CHANGE : 804F4562
18:45:26:875 5640 IRP_MJ_QUERY_QUOTA : 804F4562
18:45:26:875 5640 IRP_MJ_SET_QUOTA : 804F4562
18:45:26:875 5640 TDL3_StartIoLastChanceHookDetect: Unable to dump StartIo handler code
18:45:26:875 5640 sion
18:45:26:875 5640 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
18:45:26:875 5640
18:45:26:875 5640 Driver Name: Disk
18:45:26:875 5640 IRP_MJ_CREATE : F75B0BB0
18:45:26:875 5640 IRP_MJ_CREATE_NAMED_PIPE : 804F4562
18:45:26:875 5640 IRP_MJ_CLOSE : F75B0BB0
18:45:26:875 5640 IRP_MJ_READ : F75AAD1F
18:45:26:875 5640 IRP_MJ_WRITE : F75AAD1F
18:45:26:875 5640 IRP_MJ_QUERY_INFORMATION : 804F4562
18:45:26:875 5640 IRP_MJ_SET_INFORMATION : 804F4562
18:45:26:875 5640 IRP_MJ_QUERY_EA : 804F4562
18:45:26:875 5640 IRP_MJ_SET_EA : 804F4562
18:45:26:875 5640 IRP_MJ_FLUSH_BUFFERS : F75AB2E2
18:45:26:875 5640 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4562
18:45:26:875 5640 IRP_MJ_SET_VOLUME_INFORMATION : 804F4562
18:45:26:875 5640 IRP_MJ_DIRECTORY_CONTROL : 804F4562
18:45:26:875 5640 IRP_MJ_FILE_SYSTEM_CONTROL : 804F4562
18:45:26:875 5640 IRP_MJ_DEVICE_CONTROL : F75AB3BB
18:45:26:875 5640 IRP_MJ_INTERNAL_DEVICE_CONTROL : F75AEF28
18:45:26:875 5640 IRP_MJ_SHUTDOWN : F75AB2E2
18:45:26:875 5640 IRP_MJ_LOCK_CONTROL : 804F4562
18:45:26:875 5640 IRP_MJ_CLEANUP : 804F4562
18:45:26:875 5640 IRP_MJ_CREATE_MAILSLOT : 804F4562
18:45:26:875 5640 IRP_MJ_QUERY_SECURITY : 804F4562
18:45:26:875 5640 IRP_MJ_SET_SECURITY : 804F4562
18:45:26:875 5640 IRP_MJ_POWER : F75ACC82
18:45:26:875 5640 IRP_MJ_SYSTEM_CONTROL : F75B199E
18:45:26:875 5640 IRP_MJ_DEVICE_CHANGE : 804F4562
18:45:26:875 5640 IRP_MJ_QUERY_QUOTA : 804F4562
18:45:26:875 5640 IRP_MJ_SET_QUOTA : 804F4562
18:45:26:875 5640 TDL3_StartIoLastChanceHookDetect: Unable to dump StartIo handler code
18:45:26:875 5640 sion
18:45:26:890 5640 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
18:45:26:890 5640
18:45:26:890 5640 Driver Name: iaStor
18:45:26:890 5640 IRP_MJ_CREATE : 876B981A
18:45:26:890 5640 IRP_MJ_CREATE_NAMED_PIPE : 876B981A
18:45:26:890 5640 IRP_MJ_CLOSE : 876B981A
18:45:26:890 5640 IRP_MJ_READ : 876B981A
18:45:26:890 5640 IRP_MJ_WRITE : 876B981A
18:45:26:890 5640 IRP_MJ_QUERY_INFORMATION : 876B981A
18:45:26:890 5640 IRP_MJ_SET_INFORMATION : 876B981A
18:45:26:890 5640 IRP_MJ_QUERY_EA : 876B981A
18:45:26:890 5640 IRP_MJ_SET_EA : 876B981A
18:45:26:890 5640 IRP_MJ_FLUSH_BUFFERS : 876B981A
18:45:26:890 5640 IRP_MJ_QUERY_VOLUME_INFORMATION : 876B981A
18:45:26:890 5640 IRP_MJ_SET_VOLUME_INFORMATION : 876B981A
18:45:26:890 5640 IRP_MJ_DIRECTORY_CONTROL : 876B981A
18:45:26:890 5640 IRP_MJ_FILE_SYSTEM_CONTROL : 876B981A
18:45:26:890 5640 IRP_MJ_DEVICE_CONTROL : 876B981A
18:45:26:890 5640 IRP_MJ_INTERNAL_DEVICE_CONTROL : 876B981A
18:45:26:890 5640 IRP_MJ_SHUTDOWN : 876B981A
18:45:26:890 5640 IRP_MJ_LOCK_CONTROL : 876B981A
18:45:26:890 5640 IRP_MJ_CLEANUP : 876B981A
18:45:26:890 5640 IRP_MJ_CREATE_MAILSLOT : 876B981A
18:45:26:890 5640 IRP_MJ_QUERY_SECURITY : 876B981A
18:45:26:890 5640 IRP_MJ_SET_SECURITY : 876B981A
18:45:26:890 5640 IRP_MJ_POWER : 876B981A
18:45:26:890 5640 IRP_MJ_SYSTEM_CONTROL : 876B981A
18:45:26:890 5640 IRP_MJ_DEVICE_CHANGE : 876B981A
18:45:26:890 5640 IRP_MJ_QUERY_QUOTA : 876B981A
18:45:26:890 5640 IRP_MJ_SET_QUOTA : 876B981A
18:45:26:890 5640 ihd: 4, FFDF0308, 333, 121, 3, 109, 1
18:45:26:890 5640 Driver "iaStor" Irp handler infected by TDSS rootkit ... 18:45:26:890 5640 cured
18:45:26:890 5640 siohd: 1
18:45:26:890 5640 Driver "iaStor" StartIo handler infected by TDSS rootkit ... 18:45:26:890 5640 cured
18:45:26:921 5640 C:\WINDOWS\system32\DRIVERS\iaStor.sys - Verdict: Infected
18:45:26:921 5640 File C:\WINDOWS\system32\DRIVERS\iaStor.sys infected by TDSS rootkit ... 18:45:26:921 5640 Processing driver file: C:\WINDOWS\system32\DRIVERS\iaStor.sys
18:45:26:921 5640 ProcessDirEnumEx: FindFirstFile(C:\WINDOWS\system32\DriverStore\FileRepository\*) error 3
18:45:27:265 5640 ProcessDirEnumEx: FindFirstFile(C:\WINDOWS\OemDir\*) error 3
18:45:27:906 5640 !fdfb7
18:45:28:031 5640 vfvi6
18:45:28:296 5640 !dsvbh1
18:45:31:187 5640 dsvbh2
18:45:31:187 5640 Backup copy2 found, using it..
18:45:31:375 5640 will be cured on next reboot
18:45:31:375 5640 Reboot required for cure complete..
18:45:31:671 5640 Cure on reboot scheduled successfully
18:45:31:671 5640
18:45:31:671 5640 Completed
18:45:31:671 5640
18:45:31:671 5640 Results:
18:45:31:671 5640 Memory objects infected / cured / cured on reboot: 2 / 2 / 0
18:45:31:671 5640 Registry objects infected / cured / cured on reboot: 0 / 0 / 0
18:45:31:671 5640 File objects infected / cured / cured on reboot: 1 / 0 / 1
18:45:31:671 5640
18:45:31:671 5640 UnloadDriverW: NtUnloadDriver error 1
18:45:31:671 5640 KLMD_Unload: UnloadDriverW(klmd21) error 1
18:45:31:671 5640 KLMD(ARK) unloaded successfully

ken545
2010-03-02, 10:27
HI,

iaStor.sys <-- This is a Intel Accelerator driver, I somewhat expected this to be infected and it was and it looks like its cured.

Why don't you just use your computer for a few days and post back and let me know if your still having problems, it seems you may be out of the woods.

Ken :)