PDA

View Full Version : Malware Infection, keep coming back



MrBugger
2010-07-19, 19:46
Hi,

One of my computers showning a lot of malware, need removal help

Br

DDS (Ver_10-03-17.01) - NTFSx86
Run by Olsson at 18:33:41,39 on 2010-07-19
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.46.1053.18.2046.1086 [GMT 2:00]


============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program\Delade filer\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\WINDOWS\ATKKBService.exe
C:\Program\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
C:\Program\Bonjour\mDNSResponder.exe
svchost.exe
C:\Program\F-Secure\Anti-Virus\fsgk32st.exe
C:\Program\F-Secure\Anti-Virus\FSGK32.EXE
C:\Program\Windows Live\Family Safety\fsssvc.exe
C:\Program\F-Secure\Anti-Virus\fssm32.exe
C:\Program\F-Secure\BackWeb\7681197\Program\BackWeb-7681197.exe
C:\Program\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program\F-Secure\Common\FSMA32.EXE
C:\Program\F-Secure\Common\FSMB32.EXE
C:\Program\F-Secure\Common\FCH32.EXE
C:\WINDOWS\Explorer.EXE
C:\Program\F-Secure\Common\FAMEH32.EXE
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program\D-Tools\daemon.exe
C:\WINDOWS\vsnpstd.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program\F-Secure\Common\FSM32.EXE
C:\Program\Windows Live\Family Safety\fsui.exe
C:\Program\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program\Spybot - Search & Destroy\TeaTimer.exe
C:\Program\Messenger\msmsgs.exe
C:\Program\F-Secure\Common\FNRB32.EXE
C:\Program\Skype\Phone\Skype.exe
C:\Program\F-Secure\Common\FIH32.EXE
C:\Program\F-Secure\Anti-Virus\fsav32.exe
C:\Program\iPod\bin\iPodService.exe
C:\Program\Internet Explorer\iexplore.exe
C:\Program\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program\Java\jre6\bin\java.exe
C:\Program\Spotify\spotify.exe
C:\Program\Internet Explorer\iexplore.exe
C:\Documents and Settings\Olsson\Skrivbord\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://bilddagboken.se/p/frontpage.html#0
uWindow Title = Pappa Johan äger!!!
uInternet Settings,ProxyOverride = *.local
mWinlogon: Taskman=c:\recycler\s-1-5-21-9735241404-2918741587-970478018-9969\yv8g67.exe
uWinlogon: Shell=c:\recycler\s-1-5-21-9735241404-2918741587-970478018-9969\yv8g67.exe,explorer.exe,c:\documents and settings\olsson\application data\ebzbg.exe
BHO: Windows Live Family Safety Browser Helper Class: {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - c:\program\windows live\family safety\fssbho.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program\spybot~1\SDHelper.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live inloggningshjälpen: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program\delade filer\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - No File
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program\windows live\toolbar\wltcore.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program\windows live\toolbar\wltcore.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [SpybotSD TeaTimer] c:\program\spybot - search & destroy\TeaTimer.exe
uRun: [MSMSGS] "c:\program\messenger\msmsgs.exe" /background
uRun: [Skype] "c:\program\skype\phone\Skype.exe" /nosplash /minimized
uRun: [xtoe8] c:\windows\system32\hii6e1v2.exe
uRun: [zaawwh2] c:\windows\system32\k95iyzaqq9.exe
uRun: [tje6a] c:\windows\system32\dze8a1hr.exe
uRun: [fbcnt] c:\windows\system32\c8ijeflbc.exe
uRun: [toe9a] c:\windows\system32\2lbcdyu.exe
uRun: [msooz8] c:\windows\system32\hs6t15va.exe
uRun: [djagl] c:\windows\system32\xss70e1a3.exe
uRun: [jaglw] c:\windows\system32\xss70e1a3cn.exe
uRun: [wxdyua] c:\windows\system32\izplr2siej.exe
uRun: [aammi1e] c:\windows\system32\xnejkaw3.exe
uRun: [qwbm9] c:\windows\system32\ukal2xc3e1.exe
uRun: [ghityfq] c:\windows\system32\lgbss9euavg.exe
uRun: [euvlm] c:\windows\system32\p9r0ii9jall.exe
uRun: [ezqlmcx] c:\windows\system32\kvr0ii9ja.exe
uRun: [dopkq] c:\windows\system32\c1yefk9g.exe
uRun: [qrcinj] c:\windows\system32\r4xoepq73s9.exe
uRun: [sxtoo6] c:\windows\system32\d6avrrnd6.exe
uRun: [pvvmmxd] c:\windows\system32\0jeuglw.exe
uRun: [uqwrst] c:\windows\system32\yjffbrsi.exe
uRun: [qbmxt] c:\windows\system32\ntef2rm9sy.exe
uRun: [vbmxtoj] c:\windows\system32\nyjffbrsit.exe
uRun: [pggbs] c:\windows\system32\nytpk1gc71d.exe
uRun: [aqrmm6] c:\windows\system32\0eezqbw.exe
uRun: [vbxtjp] c:\windows\system32\e7plq6sxi.exe
uRun: [pabbxnn] c:\windows\system32\vrm674pqgg.exe
uRun: [mrinjea] c:\windows\system32\zugmhddz.exe
uRun: [wsnjjaq] c:\windows\system32\zugmhddza.exe
uRun: [zplghc] c:\windows\system32\rhd3eu1q.exe
uRun: [ghc3o] c:\windows\system32\2u1q3x7.exe
uRun: [xdtjzq] c:\windows\system32\aagmcs9u.exe
uRun: [ppqb8n] c:\windows\system32\rrd27p0l.exe
uRun: [cnjj7] c:\windows\system32\0mrs9jp.exe
uRun: [stez0v] c:\windows\system32\0riy0uu.exe
uRun: [yezaqg] c:\windows\system32\0iy0uup.exe
uRun: [rnno3] c:\windows\system32\9msnokk.exe
uRun: [whty3a] c:\windows\system32\pfqb60c4o0.exe
uRun: [neezq] c:\windows\system32\xoojaavm.exe
uRun: [qqlcc] c:\windows\system32\zuu6gg6ss.exe
uRun: [kabrsd] c:\windows\system32\tzpgmrnt.exe
uRun: [wmcctup] c:\windows\system32\cs1uzalrhso.exe
uRun: [wsndo9v] c:\windows\system32\78x5oj6.exe
uRun: [ekvqmh] c:\windows\system32\dj625b66.exe
uRun: [mdi3u] c:\windows\system32\5hsdzkf.exe
uRun: [bmcxio] c:\windows\system32\fqwrc870.exe
uRun: [mccy1o] c:\windows\system32\c1sty86k.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [DAEMON Tools-1033] "c:\program\d-tools\daemon.exe" -lang 1033
mRun: [snpstd] c:\windows\vsnpstd.exe
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [SunJavaUpdateSched] "c:\program\java\jre6\bin\jusched.exe"
mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
mRun: [F-Secure Manager] "c:\program\f-secure\common\FSM32.EXE" /splash
mRun: [fssui] "c:\program\windows live\family safety\fsui.exe" -autorun
mRun: [QuickTime Task] "c:\program\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program\itunes\iTunesHelper.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\documents and settings\olsson\start-meny\program\autostart\0ofalhn.exe
StartupFolder: c:\documents and settings\olsson\start-meny\program\autostart\3ggbsst.exe
StartupFolder: c:\documents and settings\olsson\start-meny\program\autostart\vvmc6n0t.exe
StartupFolder: c:\docume~1\alluse~1\start-~1\program\autost~1\micros~1.lnk - c:\program\microsoft office\office\OSA9.EXE
IE: {d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\jenny\start-meny\program\imvu\Run IMVU.lnk
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program\windows live\writer\WriterBrowserExtension.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program\spybot~1\SDHelper.dll
DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} - hxxp://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1194543042140
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program\delade~1\skype\SKYPE4~1.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program\windows desktop search\MSNLNamespaceMgr.dll
Hosts: 127.0.0.1 www.spywareinfo.com (http://www.spywareinfo.com)

============= SERVICES / DRIVERS ===============

R0 d347bus;d347bus;c:\windows\system32\drivers\d347bus.sys [2007-11-25 155136]
R0 d347prt;d347prt;c:\windows\system32\drivers\d347prt.sys [2007-11-25 5248]
R2 BackWeb Client - 7681197;F-Secure BackWeb;c:\program\f-secure\backweb\7681197\program\SERVIC~1.EXE [2009-9-13 16384]
R2 F-Secure Filter;F-Secure File System Filter;c:\program\f-secure\anti-virus\win2k\FSfilter.sys [2009-9-13 47280]
R2 F-Secure Gatekeeper Handler Starter;F-Secure Gatekeeper Handler Starter;c:\program\f-secure\anti-virus\fsgk32st.exe [2009-9-13 45056]
R2 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program\f-secure\anti-virus\win2k\fsgk.sys [2009-9-13 37456]
R2 F-Secure Recognizer;F-Secure File System Recognizer;c:\program\f-secure\anti-virus\win2k\FSrec.sys [2009-9-13 15984]
R2 FSpm;F-Secure Policy Manager;c:\program\f-secure\common\FSpm.sys [2009-9-13 65328]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-9-20 54752]
R2 fsssvc;Tjänsten Windows Live Family Safety;c:\program\windows live\family safety\fsssvc.exe [2009-8-5 704864]
R3 F-Secure Network Request Broker;F-Secure Network Request Broker;c:\program\f-secure\common\FNRB32.exe [2009-9-13 110668]
R3 VCSVADHWSer;Avnex Virtual Audio Device (WDM);c:\windows\system32\drivers\vcsvad.sys [2010-1-27 17792]
S2 gupdate;Google Update Service (gupdate);c:\program\google\update\GoogleUpdate.exe [2010-5-13 136176]
S3 F-Secure BackWeb LAN Access;F-Secure BackWeb LAN Access;c:\program\f-secure\backweb\7681197\program\fsbwlan.exe [2009-9-13 39936]
S3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys [2009-12-1 34384]
S3 XDva317;XDva317;\??\c:\windows\system32\xdva317.sys --> c:\windows\system32\XDva317.sys [?]
S3 XDva321;XDva321;\??\c:\windows\system32\xdva321.sys --> c:\windows\system32\XDva321.sys [?]
S3 XDva323;XDva323;\??\c:\windows\system32\xdva323.sys --> c:\windows\system32\XDva323.sys [?]
S3 XDva326;XDva326;\??\c:\windows\system32\xdva326.sys --> c:\windows\system32\XDva326.sys [?]
S3 XDva327;XDva327;\??\c:\windows\system32\xdva327.sys --> c:\windows\system32\XDva327.sys [?]
S3 XDva336;XDva336;\??\c:\windows\system32\xdva336.sys --> c:\windows\system32\XDva336.sys [?]
S3 XDva337;XDva337;\??\c:\windows\system32\xdva337.sys --> c:\windows\system32\XDva337.sys [?]
S3 XDva341;XDva341;\??\c:\windows\system32\xdva341.sys --> c:\windows\system32\XDva341.sys [?]
S3 XDva342;XDva342;\??\c:\windows\system32\xdva342.sys --> c:\windows\system32\XDva342.sys [?]
S3 XDva345;XDva345;\??\c:\windows\system32\xdva345.sys --> c:\windows\system32\XDva345.sys [?]
S3 XDva346;XDva346;\??\c:\windows\system32\xdva346.sys --> c:\windows\system32\XDva346.sys [?]
S3 XDva347;XDva347;\??\c:\windows\system32\xdva347.sys --> c:\windows\system32\XDva347.sys [?]
S3 XDva348;XDva348;\??\c:\windows\system32\xdva348.sys --> c:\windows\system32\XDva348.sys [?]
S3 XDva349;XDva349;\??\c:\windows\system32\xdva349.sys --> c:\windows\system32\XDva349.sys [?]

=============== Created Last 30 ================

2010-07-14 15:14:33 0 d-----w- c:\docume~1\alluse~1\applic~1\F-Secure
2010-07-14 13:52:53 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2010-06-26 17:45:36 14720 ---ha-w- c:\windows\system32\mlfcache.dat
2010-06-26 15:05:09 0 d-----w- c:\program\iPod
2010-06-26 14:51:28 0 d-----w- c:\program\Bonjour
2010-06-19 17:14:46 0 d-----w- c:\docume~1\alluse~1\applic~1\Blizzard

==================== Find3M ====================

2010-06-22 19:15:04 87766 ----a-w- c:\windows\system32\perfc01D.dat
2010-06-22 19:15:04 454926 ----a-w- c:\windows\system32\perfh01D.dat
2010-05-18 14:35:16 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-05-18 14:35:16 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-05-13 11:43:23 321328 ----a-w- c:\program\utorrent.exe
2010-05-13 11:36:24 562864 ----a-w- c:\program\GoogleEarthPluginSetup.exe
2010-05-13 11:18:48 97547048 ----a-w- c:\program\iTunesSetup.exe
2010-05-06 10:36:51 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-02 08:10:15 1851264 ----a-w- c:\windows\system32\win32k.sys
2009-12-28 19:48:53 1971 ----a-w- c:\program\Harry Potter(TM) och Fången från Azkaban.lnk
2008-05-16 18:03:20 32768 --sha-w- c:\windows\system32\config\systemprofile\lokala inställningar\tidigare\history.ie5\mshist012008051620080517\index.dat

============= FINISH: 18:34:28,87 ===============

http://forums.spybot.info/showthread.php?p=378016#post378016

ken545
2010-07-23, 16:27
:snwelcome:


Please read Before You Post (http://forums.spybot.info/showthread.php?t=288)
While best efforts are made to assist in removing infections safely, unexpected stuff can happen. It is advisable that you back up your important data before starting any clean up procedure. Neither Safer Networking Forums nor the Analyst providing the advice may be held responsible for any loss.


Yep, you have a lot going on.


Please download Malwarebytes from Here (http://www.malwarebytes.org/mbam-download.php) or Here (http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html)


Double-click mbam-setup.exe and follow the prompts to install the program.
At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select Perform quick scan, then click Scan.
http://i24.photobucket.com/albums/c30/ken545/MBAMCapture.jpg
When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click Remove Selected .
When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report please

MrBugger
2010-07-23, 16:37
Hi Ken!

Thanks for helping me, you guys do a great job

Just to be sure, i have made 2 post because 2 of my computers is infekted and now you want me do run Malwarebytes on the first one?

Br

ken545
2010-07-23, 16:45
MB,

Run Malwarebytes on the computer that you posted in this forum for, the one that you posted the DDS log for.

DDS (Ver_10-03-17.01) - NTFSx86
Run by Olsson at 18:33:41,39 on 2010-07-19
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.46.1053.18.2046.1086 [GMT 2:00]

DO NOT RUN ANY SCANS OR POST ANY LOGS FROM ANY OTHER COMPUTERS, WHEN WE'RE DONE WITH THIS ONE THIS THREAD WILL BE CLOSED AND YOU CAN START A NEW THREAD AND POST FOR THE OTHER ONE.

MrBugger
2010-07-23, 17:22
Hi Ken!

Just wanted to be 100% sure. Anyway here is the report from Malwarebytes

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Databasversion: 4340

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

2010-07-23 16:09:08
mbam-log-2010-07-23 (16-09-08).txt

Skanningstyp: Snabbskanning
Antal skannade objekt: 137975
Förfluten tid: 12 minut(er), 8 sekund(er)

Infekterade minnesprocesser: 0
Infekterade minnesmoduler: 0
Infekterade registernycklar: 0
Infekterade registervärden: 2
Infekterade registerdataposter: 1
Infekterade mappar: 0
Infekterade filer: 67

Infekterade minnesprocesser:
(Inga illasinnade poster hittades)

Infekterade minnesmoduler:
(Inga illasinnade poster hittades)

Infekterade registernycklar:
(Inga illasinnade poster hittades)

Infekterade registervärden:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\shell (Worm.AutoRun) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\taskman (Trojan.Agent) -> Quarantined and deleted successfully.

Infekterade registerdataposter:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell) -> Bad: (C:\RECYCLER\S-1-5-21-9735241404-2918741587-970478018-9969\yv8g67.exe,explorer.exe,C:\Documents and Settings\Olsson\Application Data\ebzbg.exe) Good: (Explorer.exe) -> Quarantined and deleted successfully.

Infekterade mappar:
(Inga illasinnade poster hittades)

Infekterade filer:
C:\RECYCLER\S-1-5-21-9735241404-2918741587-970478018-9969\yv8g67.exe (Trojan.Proxy) -> Delete on reboot.
C:\Documents and Settings\Olsson\Start-meny\Program\Autostart\0ofalhn.exe (Trojan.Refroso) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Start-meny\Program\Autostart\3ggbsst.exe (Trojan.DDox) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Start-meny\Program\Autostart\6ioo69a.exe (Trojan.DDox) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Start-meny\Program\Autostart\hi3y3aa9gm.exe (Trojan.DDox) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Start-meny\Program\Autostart\nio5u1lhxi.exe (Trojan.Refroso) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Start-meny\Program\Autostart\vvmc6n0t.exe (Trojan.Refroso) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Start-meny\Program\Autostart\xteo75lg.exe (Trojan.Refroso) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\461.exe (BackDoor.Refroso) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\463.exe (Trojan.DDox) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\488.exe (Trojan.Refroso) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\529.exe (Trojan.Refroso) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\583.exe (Trojan.Refroso) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\595.exe (Trojan.Refroso) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\608.exe (Trojan.DDox) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\613.exe (Trojan.DDox) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\628.exe (Trojan.DDox) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\646.exe (Trojan.DDox) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\667.exe (Trojan.Refroso) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\687.exe (Trojan.DDox) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\708.exe (Trojan.DDox) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\727.exe (Trojan.Refroso) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\748.exe (Trojan.Refroso) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\789.exe (Trojan.Refroso) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\797.exe (Trojan.DDox) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\820.exe (Trojan.DDox) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\821.exe (Trojan.Refroso) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\822.exe (Trojan.Refroso) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\837.exe (BackDoor.Refroso) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\853.exe (Trojan.DDox) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\884.exe (BackDoor.Refroso) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\912.exe (Trojan.Refroso) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\926.exe (BackDoor.Refroso) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\948.exe (Trojan.Refroso) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\954.exe (Trojan.Refroso) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\963.exe (Trojan.Refroso) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\977.exe (Trojan.Refroso) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\458.exe (Trojan.DDox) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\010.exe (Trojan.Refroso) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\054.exe (Trojan.Refroso) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\064.exe (Trojan.Refroso) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\088.exe (Trojan.Refroso) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\094.exe (Trojan.Refroso) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\102.exe (Trojan.Renos) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\104.exe (Trojan.Refroso) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\106.exe (Trojan.Refroso) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\119.exe (Trojan.Refroso) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\141.exe (Trojan.Refroso) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\148.exe (Trojan.Refroso) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\151.exe (Trojan.Refroso) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\166.exe (Trojan.DDox) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\184.exe (Trojan.Refroso) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\191.exe (Trojan.Refroso) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\251.exe (Trojan.DDox) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\258.exe (Trojan.DDox) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\259.exe (Trojan.Refroso) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\264.exe (Trojan.Refroso) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\280.exe (BackDoor.Refroso) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\289.exe (Trojan.Refroso) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\292.exe (Trojan.DDox) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\339.exe (Trojan.Refroso) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\356.exe (Trojan.Refroso) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\375.exe (Trojan.DDox) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\401.exe (Trojan.Refroso) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\404.exe (Trojan.Refroso) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\447.exe (Trojan.Refroso) -> Quarantined and deleted successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temp\452.exe (Trojan.DDox) -> Quarantined and deleted successfully.

ken545
2010-07-23, 17:52
Good ,

The reason we only do one computer at time, believe me I have tried in the past with a user posting logs from other computers while I was trying to clean the one they originally posted for and it can get very confusing, just keep the other one off line until we get this one fixed, then I will close this thread and you can start a new topic for the other one.


I am sure there is more to do.

Download TFC (http://oldtimer.geekstogo.com/TFC.exe) to your desktop

Close any open windows.
Double click the TFC icon to run the program
TFC will close all open programs itself in order to run,
Click the Start button to begin the process.
Allow TFC to run uninterrupted.
The program should not take long to finish it's job
Once its finished it should automatically reboot your machine,
if it doesn't, manually reboot to ensure a complete clean







Download ComboFix from one of these locations:

Link 1 (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
Link 2 (http://www.forospyware.com/sUBs/ComboFix.exe)


* IMPORTANT !!! Save ComboFix.exe to your Desktop


Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
See this Link (http://www.bleepingcomputer.com/forums/topic114351.html) for programs that need to be disabled and instruction on how to disable them.
Remember to re-enable them when we're done.


Double click on ComboFix.exe & follow the prompts.


As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.


Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.



http://img.photobucket.com/albums/v706/ried7/RC1.png


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

http://img.photobucket.com/albums/v706/ried7/RC2-1.png

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

MrBugger
2010-07-24, 01:33
Hi Ken!

I've been waiting 7 hours now for ComboFix to finish. It has been no changes since the screen that says "scanning for infected files"
Should i restars Combofix and try once more or wait?

Br

ken545
2010-07-24, 04:42
Lets give it a chance to finish, this is one heavily infected computer

MrBugger
2010-07-24, 11:10
Still the same screen. Have you experienced this kind of long serch? Is it possible to see if the program is working? For me it seems low activity on the harddrive lamp accordning to a search (it has been the same "pulsing" since start)

After we're done i think you have to help me set up better protection for my daughters PC

Br

ken545
2010-07-24, 12:02
Combofix doesn't usually take more than 20 min or so, go ahead and stop it, reboot and see if it left a report at C:\ComboFix.txt

MrBugger
2010-07-24, 12:33
Strange, i was not able to stop Combofix without using the power button. Due to that i didn't find any report. Should i try the Combofix once more?

Br

ken545
2010-07-24, 12:41
First run this this, lets see how much of this garbage we can remove before we give CF another run




Download OTL (http://oldtimer.geekstogo.com/OTL.exe) to your desktop.
Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
When the window appears, underneath Output at the top change it to Minimal Output.
Check the boxes beside LOP Check and Purity Check.
Under the Custom Scan box paste this in



netsvcs
%SYSTEMDRIVE%\*.exe
/md5start
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
sceclt.dll
ntelogon.dll
logevent.dll
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
nvrd32.sys
symmpi.sys
adp3132.sys
mv61xx.sys
/md5stop
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav



Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.

MrBugger
2010-07-24, 13:42
OTL.txt:

OTL logfile created on: 2010-07-24 12:22:02 - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\Olsson\Skrivbord
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 0000041D | Country: Sverige | Language: SVE | Date Format: yyyy-MM-dd

2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 71,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 88,00% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program
Drive C: | 74,52 Gb Total Space | 9,97 Gb Free Space | 13,37% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: JEOH1
Current User Name: Olsson
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Olsson\Skrivbord\OTL.exe (OldTimer Tools)
PRC - C:\Program\Delade filer\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program\F-Secure\BackWeb\7681197\Program\ServiceWrapper-7681197.exe ()
PRC - C:\Program\F-Secure\BackWeb\7681197\Program\backWeb-7681197.exe ()
PRC - C:\Program\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
PRC - C:\Program\Windows Live\Family Safety\fsui.exe (Microsoft Corporation)
PRC - C:\Program\Java\jre6\bin\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\ATKKBService.exe (ASUSTeK COMPUTER INC.)
PRC - C:\Program\D-Tools\daemon.exe (DAEMON'S HOME)
PRC - C:\WINDOWS\vsnpstd.exe ()
PRC - C:\Program\F-Secure\Common\FSMB32.exe (F-Secure Corporation)
PRC - C:\Program\F-Secure\Common\FNRB32.exe (F-Secure Corporation)
PRC - C:\Program\F-Secure\Common\FSM32.exe (F-Secure Corporation)
PRC - C:\Program\F-Secure\Common\FSMA32.exe (F-Secure Corporation)
PRC - C:\Program\F-Secure\Common\FIH32.exe (F-Secure Corporation)
PRC - C:\Program\F-Secure\Common\FAMEH32.exe (F-Secure Corporation)
PRC - C:\Program\F-Secure\Common\fch32.exe (F-Secure Corporation)
PRC - C:\Program\F-Secure\Anti-Virus\fssm32.exe (F-Secure Corp.)
PRC - C:\Program\F-Secure\Anti-Virus\fsgk32.exe (F-Secure Corp.)
PRC - C:\Program\F-Secure\Anti-Virus\fsav32.exe (F-Secure Corporation)
PRC - C:\Program\F-Secure\Anti-Virus\fsgk32st.exe (F-Secure Corp.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Olsson\Skrivbord\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\Temp\IadHide3.dll (BackWeb)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (getPlus(R) Helper) getPlus(R) -- C:\Program\NOS\bin\getPlus_HelperSvc.exe File not found
SRV - (Apple Mobile Device) -- C:\Program\Delade filer\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (F-Secure BackWeb LAN Access) -- C:\Program\F-Secure\BackWeb\7681197\Program\fsbwlan.exe ()
SRV - (BackWeb Client - 7681197) -- C:\Program\F-Secure\BackWeb\7681197\Program\ServiceWrapper-7681197.exe ()
SRV - (fsssvc) -- C:\Program\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (SeaPort) -- C:\Program\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (Adobe LM Service) -- C:\Program\Delade filer\Adobe Systems Shared\Service\Adobelmsvc.exe (Adobe Systems)
SRV - (ATKKeyboardService) -- C:\WINDOWS\ATKKBService.exe (ASUSTeK COMPUTER INC.)
SRV - (FSAA) -- C:\Program\F-Secure\Common\FSAA.EXE (F-Secure Corporation. All Rights Reserved.)
SRV - (F-Secure Network Request Broker) -- C:\Program\F-Secure\Common\FNRB32.EXE (F-Secure Corporation)
SRV - (FSMA) -- C:\Program\F-Secure\Common\FSMA32.EXE (F-Secure Corporation)
SRV - (F-Secure Gatekeeper Handler Starter) -- C:\Program\F-Secure\Anti-Virus\fsgk32st.exe (F-Secure Corp.)


========== Driver Services (SafeList) ==========

DRV - (XDva349) -- C:\WINDOWS\System32\XDva349.sys File not found
DRV - (XDva348) -- C:\WINDOWS\System32\XDva348.sys File not found
DRV - (XDva347) -- C:\WINDOWS\System32\XDva347.sys File not found
DRV - (XDva346) -- C:\WINDOWS\System32\XDva346.sys File not found
DRV - (XDva345) -- C:\WINDOWS\System32\XDva345.sys File not found
DRV - (XDva342) -- C:\WINDOWS\System32\XDva342.sys File not found
DRV - (XDva341) -- C:\WINDOWS\System32\XDva341.sys File not found
DRV - (XDva337) -- C:\WINDOWS\System32\XDva337.sys File not found
DRV - (XDva336) -- C:\WINDOWS\System32\XDva336.sys File not found
DRV - (XDva327) -- C:\WINDOWS\System32\XDva327.sys File not found
DRV - (XDva326) -- C:\WINDOWS\System32\XDva326.sys File not found
DRV - (XDva323) -- C:\WINDOWS\System32\XDva323.sys File not found
DRV - (XDva321) -- C:\WINDOWS\System32\XDva321.sys File not found
DRV - (XDva317) -- C:\WINDOWS\System32\XDva317.sys File not found
DRV - (npkcrypt) -- C:\Nexon\v55 Maplestory\npkcrypt.sys File not found
DRV - (GMSIPCI) -- D:\INSTALL\GMSIPCI.SYS File not found
DRV - (catchme) -- C:\DOCUME~1\Olsson\LOKALA~1\Temp\catchme.sys File not found
DRV - (SCREAMINGBDRIVER) -- C:\WINDOWS\system32\drivers\ScreamingBAudio.sys (Screaming Bee LLC)
DRV - (fssfltr) -- C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (VCSVADHWSer) Avnex Virtual Audio Device (WDM) -- C:\WINDOWS\system32\drivers\vcsvad.sys (Avnex)
DRV - (nv) -- C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (NwlnkIpx) -- C:\WINDOWS\system32\drivers\nwlnkipx.sys (Microsoft Corporation)
DRV - (HDAudBus) -- C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows (R) Server 2003 DDK provider)
DRV - (EIO) -- C:\WINDOWS\system32\drivers\EIO.sys (ASUSTeK Computer Inc.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\WINDOWS\system32\drivers\RtkHDAud.Sys (Realtek Semiconductor Corp.)
DRV - (asuskbnt) -- C:\WINDOWS\system32\drivers\atkkbnt.sys (ASUSTeK COMPUTER INC.)
DRV - (AmdK8) -- C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
DRV - (d347prt) -- C:\WINDOWS\System32\Drivers\d347prt.sys ( )
DRV - (d347bus) -- C:\WINDOWS\system32\DRIVERS\d347bus.sys ( )
DRV - (NwlnkNb) -- C:\WINDOWS\system32\drivers\nwlnknb.sys (Microsoft Corporation)
DRV - (NwlnkSpx) -- C:\WINDOWS\system32\drivers\nwlnkspx.sys (Microsoft Corporation)
DRV - (snpstd) USB PC Camera (SN9C102) -- C:\WINDOWS\system32\drivers\snpstd.sys ()
DRV - (FSpm) -- C:\Program\F-Secure\Common\FSpm.sys (F-Secure Corporation)
DRV - (F-Secure Gatekeeper) -- C:\Program\F-Secure\Anti-Virus\win2k\fsgk.sys ()
DRV - (F-Secure Filter) -- C:\Program\F-Secure\Anti-Virus\win2k\FSfilter.sys ()
DRV - (F-Secure Recognizer) -- C:\Program\F-Secure\Anti-Virus\win2k\FSrec.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://forums.spybot.info/index.php
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


[2010-03-10 21:30:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Olsson\Application Data\Mozilla\Extensions
[2010-03-10 21:30:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Olsson\Application Data\Mozilla\Extensions\mozswing@mozswing.org
[2010-02-27 20:11:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Olsson\Application Data\Mozilla\Firefox\extensions
[2010-02-27 20:11:38 | 000,000,000 | ---D | M] (XfireXO Toolbar) -- C:\Documents and Settings\Olsson\Application Data\Mozilla\Firefox\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}

O1 HOSTS File: ([2010-07-13 11:46:57 | 000,413,362 | R--- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 127.0.0.1 www.163ns.com
O1 - Hosts: 127.0.0.1 163ns.com
O1 - Hosts: 14285 more lines...
O2 - BHO: (Windows Live Family Safety Browser Helper Class) - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Windows Live inloggningshjälpen) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program\Delade filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (no name) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - No CLSID value found.
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [DAEMON Tools-1033] C:\Program\D-Tools\daemon.exe (DAEMON'S HOME)
O4 - HKLM..\Run: [F-Secure Manager] C:\Program\F-Secure\Common\FSM32.EXE (F-Secure Corporation)
O4 - HKLM..\Run: [fssui] C:\Program\Windows Live\Family Safety\fsui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe ()
O4 - HKCU..\Run: [aammi1e] C:\WINDOWS\System32\xnejkaw3.exe File not found
O4 - HKCU..\Run: [aqrmm6] C:\WINDOWS\System32\0eezqbw.exe File not found
O4 - HKCU..\Run: [bmcxio] C:\WINDOWS\System32\fqwrc870.exe File not found
O4 - HKCU..\Run: [cnjj7] C:\WINDOWS\System32\0mrs9jp.exe File not found
O4 - HKCU..\Run: [djagl] C:\WINDOWS\System32\xss70e1a3.exe File not found
O4 - HKCU..\Run: [dopkq] C:\WINDOWS\System32\c1yefk9g.exe File not found
O4 - HKCU..\Run: [ekvqmh] C:\WINDOWS\System32\dj625b66.exe File not found
O4 - HKCU..\Run: [euvlm] C:\WINDOWS\System32\p9r0ii9jall.exe File not found
O4 - HKCU..\Run: [ezqlmcx] C:\WINDOWS\System32\kvr0ii9ja.exe File not found
O4 - HKCU..\Run: [fbcnt] C:\WINDOWS\System32\c8ijeflbc.exe File not found
O4 - HKCU..\Run: [ghc3o] C:\WINDOWS\System32\2u1q3x7.exe File not found
O4 - HKCU..\Run: [ghityfq] C:\WINDOWS\System32\lgbss9euavg.exe File not found
O4 - HKCU..\Run: [jaglw] C:\WINDOWS\System32\xss70e1a3cn.exe File not found
O4 - HKCU..\Run: [kabrsd] C:\WINDOWS\System32\tzpgmrnt.exe File not found
O4 - HKCU..\Run: [mccy1o] C:\WINDOWS\System32\c1sty86k.exe File not found
O4 - HKCU..\Run: [mdi3u] C:\WINDOWS\System32\5hsdzkf.exe File not found
O4 - HKCU..\Run: [mrinjea] C:\WINDOWS\System32\zugmhddz.exe File not found
O4 - HKCU..\Run: [msooz8] C:\WINDOWS\System32\hs6t15va.exe File not found
O4 - HKCU..\Run: [neezq] C:\WINDOWS\System32\xoojaavm.exe File not found
O4 - HKCU..\Run: [pabbxnn] C:\WINDOWS\System32\vrm674pqgg.exe File not found
O4 - HKCU..\Run: [pggbs] C:\WINDOWS\System32\nytpk1gc71d.exe File not found
O4 - HKCU..\Run: [ppqb8n] C:\WINDOWS\System32\rrd27p0l.exe File not found
O4 - HKCU..\Run: [pvvmmxd] C:\WINDOWS\System32\0jeuglw.exe File not found
O4 - HKCU..\Run: [qbmxt] C:\WINDOWS\System32\ntef2rm9sy.exe File not found
O4 - HKCU..\Run: [qqlcc] C:\WINDOWS\System32\zuu6gg6ss.exe File not found
O4 - HKCU..\Run: [qrcinj] C:\WINDOWS\System32\r4xoepq73s9.exe File not found
O4 - HKCU..\Run: [qwbm9] C:\WINDOWS\System32\ukal2xc3e1.exe File not found
O4 - HKCU..\Run: [rnno3] C:\WINDOWS\System32\9msnokk.exe File not found
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [stez0v] C:\WINDOWS\System32\0riy0uu.exe File not found
O4 - HKCU..\Run: [sxtoo6] C:\WINDOWS\System32\d6avrrnd6.exe File not found
O4 - HKCU..\Run: [tje6a] C:\WINDOWS\System32\dze8a1hr.exe File not found
O4 - HKCU..\Run: [toe9a] C:\WINDOWS\System32\2lbcdyu.exe File not found
O4 - HKCU..\Run: [uqwrst] C:\WINDOWS\System32\yjffbrsi.exe File not found
O4 - HKCU..\Run: [vbmxtoj] C:\WINDOWS\System32\nyjffbrsit.exe File not found
O4 - HKCU..\Run: [vbxtjp] C:\WINDOWS\System32\e7plq6sxi.exe File not found
O4 - HKCU..\Run: [whty3a] C:\WINDOWS\System32\pfqb60c4o0.exe File not found
O4 - HKCU..\Run: [wmcctup] C:\WINDOWS\System32\cs1uzalrhso.exe File not found
O4 - HKCU..\Run: [wsndo9v] C:\WINDOWS\System32\78x5oj6.exe File not found
O4 - HKCU..\Run: [wsnjjaq] C:\WINDOWS\System32\zugmhddza.exe File not found
O4 - HKCU..\Run: [wxdyua] C:\WINDOWS\System32\izplr2siej.exe File not found
O4 - HKCU..\Run: [xdtjzq] C:\WINDOWS\System32\aagmcs9u.exe File not found
O4 - HKCU..\Run: [xtoe8] C:\WINDOWS\System32\hii6e1v2.exe File not found
O4 - HKCU..\Run: [yezaqg] C:\WINDOWS\System32\0iy0uup.exe File not found
O4 - HKCU..\Run: [zaawwh2] C:\WINDOWS\System32\k95iyzaqq9.exe File not found
O4 - HKCU..\Run: [zplghc] C:\WINDOWS\System32\rhd3eu1q.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Start-meny\Program\Autostart\Microsoft Office.lnk = C:\Program\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O9 - Extra Button: Blogga detta - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blogga detta i Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Jenny\Start-meny\Program\IMVU\Run IMVU.lnk ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Program\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab (CKAVWebScan Object)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1194543042140 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program\Delade filer\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program\Delade filer\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program\Delade filer\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program\Delade filer\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program\Delade filer\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program\Delade filer\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program\Delade filer\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program\Delade filer\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Min aktuella startsida) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Olsson\Lokala inställningar\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Olsson\Lokala inställningar\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007-11-07 11:20:52 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{9e7c23de-e8e7-11de-843d-001617b20fe8}\Shell\AutoRun\command - "" = F:\autorun.exe -- File not found
O33 - MountPoints2\{9e7c23de-e8e7-11de-843d-001617b20fe8}\Shell\explore\command - "" = F:\autorun.exe -- File not found
O33 - MountPoints2\{9e7c23de-e8e7-11de-843d-001617b20fe8}\Shell\open\command - "" = F:\autorun.exe -- File not found
O33 - MountPoints2\{cac0fb4d-8299-11df-851b-001617b20fe8}\Shell\AutoRun\command - "" = G:\autorun.exe -- File not found
O33 - MountPoints2\{cac0fb4d-8299-11df-851b-001617b20fe8}\Shell\explore\command - "" = G:\autorun.exe -- File not found
O33 - MountPoints2\{cac0fb4d-8299-11df-851b-001617b20fe8}\Shell\open\command - "" = G:\autorun.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

========== Files/Folders - Created Within 30 Days ==========

[2010-07-24 12:19:49 | 000,574,976 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Olsson\Skrivbord\OTL.exe
[2010-07-24 11:18:54 | 000,000,000 | --SD | C] -- C:\ComboFix
[2010-07-23 17:16:39 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010-07-23 17:11:09 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010-07-23 17:11:09 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010-07-23 17:11:09 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010-07-23 17:11:09 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010-07-23 17:11:02 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010-07-23 17:10:47 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010-07-23 16:54:10 | 000,446,464 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Olsson\Skrivbord\TFC.exe
[2010-07-23 15:54:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Olsson\Application Data\Malwarebytes
[2010-07-23 15:54:05 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010-07-23 15:54:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010-07-23 15:54:02 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010-07-23 15:54:02 | 000,000,000 | ---D | C] -- C:\Program\Malwarebytes' Anti-Malware
[2010-07-23 15:45:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Olsson\Skrivbord\DDS
[2010-07-14 17:14:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\F-Secure
[2010-07-14 15:52:53 | 000,744,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\helpsvc.exe
[2010-07-13 13:35:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Olsson\Mina dokument\blandat
[2010-06-28 14:55:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Olsson\Application Data\U3
[2010-06-26 17:05:09 | 000,000,000 | ---D | C] -- C:\Program\iPod
[2010-06-26 16:51:28 | 000,000,000 | ---D | C] -- C:\Program\Bonjour
[2010-06-26 16:48:43 | 000,000,000 | ---D | C] -- C:\Program\Safari
[2008-08-26 20:08:09 | 000,061,440 | ---- | C] ( ) -- C:\WINDOWS\System32\csnpstd.dll
[2008-08-26 20:08:09 | 000,040,960 | ---- | C] ( ) -- C:\WINDOWS\System32\rsnpstd.dll
[2008-08-26 20:08:09 | 000,036,864 | ---- | C] ( ) -- C:\WINDOWS\System32\vsnpstd.dll
[2007-11-25 11:38:46 | 000,155,136 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\d347bus.sys
[2007-11-25 11:38:46 | 000,005,248 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\d347prt.sys

========== Files - Modified Within 30 Days ==========

[2010-07-24 12:25:00 | 000,000,410 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{2C8DC5CE-1445-4847-B385-34C3AC51553E}.job
[2010-07-24 12:19:51 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Olsson\Skrivbord\OTL.exe
[2010-07-24 12:14:39 | 000,191,924 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2010-07-24 12:14:09 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010-07-24 12:14:00 | 000,000,922 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010-07-24 12:12:50 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010-07-24 12:12:41 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010-07-24 11:18:17 | 003,742,848 | R--- | M] () -- C:\Documents and Settings\Olsson\Skrivbord\ComboFix.exe
[2010-07-24 11:16:48 | 008,126,464 | -H-- | M] () -- C:\Documents and Settings\Olsson\NTUSER.DAT
[2010-07-24 11:14:01 | 000,000,412 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{C4030E41-5E64-40C0-B6D9-D952AC516761}.job
[2010-07-24 10:58:52 | 000,002,149 | ---- | M] () -- C:\Documents and Settings\All Users\Skrivbord\Safari.lnk
[2010-07-23 17:16:48 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2010-07-23 16:54:12 | 000,446,464 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Olsson\Skrivbord\TFC.exe
[2010-07-23 16:47:03 | 000,000,926 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010-07-23 16:41:17 | 000,000,137 | ---- | M] () -- C:\Documents and Settings\Olsson\Skrivbord\Teen got My Security Engine installed - Safer-Networking Forums.url
[2010-07-23 15:54:08 | 000,000,664 | ---- | M] () -- C:\Documents and Settings\All Users\Skrivbord\Malwarebytes' Anti-Malware.lnk
[2010-07-19 18:28:58 | 000,525,824 | ---- | M] () -- C:\Documents and Settings\Olsson\Skrivbord\dds.scr
[2010-07-19 18:14:16 | 000,002,111 | ---- | M] () -- C:\Documents and Settings\All Users\Skrivbord\iTunes.lnk
[2010-07-19 15:35:55 | 000,000,192 | -HS- | M] () -- C:\Documents and Settings\Olsson\ntuser.ini
[2010-07-14 19:00:00 | 000,000,262 | ---- | M] () -- C:\WINDOWS\tasks\Spybot - Search & Destroy.job
[2010-07-14 17:05:06 | 000,000,135 | ---- | M] () -- C:\Documents and Settings\All Users\Skrivbord\F-Secure Online Scanner.url
[2010-07-14 16:57:09 | 000,000,153 | ---- | M] () -- C:\Documents and Settings\All Users\Skrivbord\par...avwebscan.html.url
[2010-07-13 11:46:57 | 000,413,362 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010-06-26 19:45:36 | 000,014,720 | -H-- | M] () -- C:\WINDOWS\System32\mlfcache.dat
[2010-06-26 16:49:26 | 000,001,842 | ---- | M] () -- C:\Documents and Settings\Olsson\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk

========== Files Created - No Company Name ==========

[2010-07-23 17:16:48 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2010-07-23 17:16:44 | 000,260,784 | ---- | C] () -- C:\cmldr
[2010-07-23 17:11:09 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010-07-23 17:11:09 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010-07-23 17:11:09 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010-07-23 17:11:09 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010-07-23 17:11:09 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010-07-23 17:08:09 | 003,742,848 | R--- | C] () -- C:\Documents and Settings\Olsson\Skrivbord\ComboFix.exe
[2010-07-23 16:41:17 | 000,000,137 | ---- | C] () -- C:\Documents and Settings\Olsson\Skrivbord\Teen got My Security Engine installed - Safer-Networking Forums.url
[2010-07-23 15:54:08 | 000,000,664 | ---- | C] () -- C:\Documents and Settings\All Users\Skrivbord\Malwarebytes' Anti-Malware.lnk
[2010-07-19 18:28:57 | 000,525,824 | ---- | C] () -- C:\Documents and Settings\Olsson\Skrivbord\dds.scr
[2010-07-14 17:05:06 | 000,000,135 | ---- | C] () -- C:\Documents and Settings\All Users\Skrivbord\F-Secure Online Scanner.url
[2010-07-14 16:57:09 | 000,000,153 | ---- | C] () -- C:\Documents and Settings\All Users\Skrivbord\par...avwebscan.html.url
[2010-06-26 19:45:36 | 000,014,720 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2010-06-26 17:07:53 | 000,002,111 | ---- | C] () -- C:\Documents and Settings\All Users\Skrivbord\iTunes.lnk
[2010-06-26 16:49:26 | 000,002,149 | ---- | C] () -- C:\Documents and Settings\All Users\Skrivbord\Safari.lnk
[2010-06-26 16:49:26 | 000,001,842 | ---- | C] () -- C:\Documents and Settings\Olsson\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2009-12-28 15:49:49 | 000,132,096 | ---- | C] () -- C:\WINDOWS\System32\RashIcon.dll
[2009-12-28 15:49:49 | 000,041,472 | ---- | C] () -- C:\WINDOWS\System32\RashProp.dll
[2009-11-21 13:50:55 | 000,063,488 | ---- | C] () -- C:\WINDOWS\xobglu16.dll
[2009-11-21 13:50:55 | 000,023,552 | ---- | C] () -- C:\WINDOWS\xobglu32.dll
[2009-10-29 19:27:45 | 000,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll
[2009-09-15 14:22:32 | 002,332,160 | ---- | C] () -- C:\WINDOWS\System32\x264vfw.dll
[2009-09-13 18:03:10 | 000,000,256 | ---- | C] () -- C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2009-07-31 15:14:38 | 000,129,024 | ---- | C] () -- C:\WINDOWS\System32\AVERM.dll
[2009-07-31 15:14:38 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\AVEQT.dll
[2008-08-26 20:21:52 | 000,043,729 | ---- | C] () -- C:\WINDOWS\unvpeye.ini
[2008-08-26 20:08:14 | 000,015,541 | ---- | C] () -- C:\WINDOWS\snpstd.ini
[2008-08-26 20:08:13 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\dsnpstd.dll
[2008-08-26 20:08:11 | 000,301,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\snpstd.sys
[2008-07-21 21:27:51 | 000,765,952 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2008-07-21 21:27:50 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2008-05-27 00:10:02 | 000,014,772 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2008-05-27 00:10:00 | 000,022,298 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2008-05-27 00:09:58 | 000,014,614 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2008-01-18 16:23:27 | 000,047,104 | ---- | C] () -- C:\WINDOWS\System32\KMVIDC32.DLL
[2007-11-08 20:07:36 | 000,000,383 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2007-11-07 12:04:33 | 000,046,592 | ---- | C] () -- C:\WINDOWS\System32\asfrench.dll
[2007-11-07 12:04:33 | 000,046,080 | ---- | C] () -- C:\WINDOWS\System32\asrussian.dll
[2007-11-07 12:04:33 | 000,046,080 | ---- | C] () -- C:\WINDOWS\System32\asgerman.dll
[2007-11-07 12:04:33 | 000,046,080 | ---- | C] () -- C:\WINDOWS\System32\aseng.dll
[2007-11-07 12:04:33 | 000,045,568 | ---- | C] () -- C:\WINDOWS\System32\askorean.dll
[2007-11-07 12:04:33 | 000,045,568 | ---- | C] () -- C:\WINDOWS\System32\asjapan.dll
[2007-11-07 12:04:33 | 000,045,568 | ---- | C] () -- C:\WINDOWS\System32\aschs.dll
[2007-11-07 12:04:33 | 000,010,496 | ---- | C] () -- C:\WINDOWS\System32\ATKOSDMini.DLL
[2007-11-07 12:04:33 | 000,000,018 | ---- | C] () -- C:\WINDOWS\System32\atkid.ini
[2007-11-07 12:04:32 | 000,045,568 | ---- | C] () -- C:\WINDOWS\System32\ASCHT.dll
[2007-11-07 11:57:40 | 000,135,168 | R--- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2006-06-01 11:22:00 | 001,724,416 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2006-06-01 11:22:00 | 001,503,232 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2006-06-01 11:22:00 | 001,101,824 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2006-06-01 11:22:00 | 000,581,632 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2006-06-01 11:22:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2006-06-01 11:22:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2004-08-22 18:04:56 | 000,069,120 | ---- | C] () -- C:\WINDOWS\daemon.dll
[2002-05-28 03:52:36 | 000,106,496 | ---- | C] () -- C:\WINDOWS\japi.dll
[2001-06-24 11:32:44 | 000,172,032 | ---- | C] () -- C:\WINDOWS\japi2.dll
[1999-01-22 13:46:58 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL

========== LOP Check ==========

[2010-07-14 17:14:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\F-Secure
[2010-01-17 19:48:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\LogSys
[2008-07-21 21:19:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\River Past G5
[2010-05-13 13:34:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010-01-17 20:10:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Olsson\Application Data\Blueberry
[2010-01-17 19:48:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Olsson\Application Data\LogSys
[2009-11-21 20:37:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Olsson\Application Data\Nexon
[2008-07-21 21:05:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Olsson\Application Data\River Past G5
[2010-02-16 20:11:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Olsson\Application Data\Screaming Bee
[2010-07-19 23:12:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Olsson\Application Data\Spotify
[2010-01-02 13:48:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Olsson\Application Data\TweakNow PowerPack 2009
[2009-12-27 19:40:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Olsson\Application Data\Windows Desktop Search
[2009-12-31 17:05:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Olsson\Application Data\Windows Search
[2010-02-07 11:00:00 | 000,000,258 | ---- | M] () -- C:\WINDOWS\Tasks\defrag.job
[2010-02-06 11:00:00 | 000,000,310 | ---- | M] () -- C:\WINDOWS\Tasks\Genomsök alla lokala hårddiskar.job
[2010-07-24 12:25:00 | 000,000,410 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{2C8DC5CE-1445-4847-B385-34C3AC51553E}.job
[2010-07-24 11:14:01 | 000,000,412 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{C4030E41-5E64-40C0-B6D9-D952AC516761}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2004-08-04 14:00:00 | 018,778,343 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008-05-16 19:40:48 | 023,884,604 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008-05-16 19:40:48 | 023,884,604 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008-04-13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008-04-13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys

< MD5 for: ATAPI.SYS >
[2004-08-04 14:00:00 | 018,778,343 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008-05-16 19:40:48 | 023,884,604 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008-05-16 19:40:48 | 023,884,604 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008-04-13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\Qoobox\32788R22FWJFW\atapi.sys
[2008-04-13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008-04-13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004-08-04 14:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008-04-14 18:04:38 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=0A6DF967AE8E836D053DB46398F603E5 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008-04-14 18:04:38 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=0A6DF967AE8E836D053DB46398F603E5 -- C:\WINDOWS\system32\eventlog.dll
[2004-08-04 14:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=264DBC116901E89565B830B0CC20F922 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: NETLOGON.DLL >
[2008-04-14 18:04:44 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=4F4A16EAEB932AE413E48923E6A400E0 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008-04-14 18:04:44 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=4F4A16EAEB932AE413E48923E6A400E0 -- C:\WINDOWS\system32\netlogon.dll
[2004-08-04 14:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=A6FD3341EC1A98A31B044C6E0DAF8F26 -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004-08-04 14:00:00 | 000,183,808 | ---- | M] (Microsoft Corporation) MD5=24BADA1C3795CB877C67E0F2F8BBAD1F -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008-04-14 18:04:47 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=3B50B494647E60CE6AC516E3F5C82B25 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008-04-14 18:04:47 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=3B50B494647E60CE6AC516E3F5C82B25 -- C:\WINDOWS\system32\scecli.dll

< MD5 for: VIAMRAID.SYS >
[2005-11-23 04:12:24 | 000,092,672 | ---- | M] (VIA Technologies inc,.ltd) MD5=FBF18F9F5FB852C2976723587B44F346 -- C:\Qoobox\32788R22FWJFW\viamraid.sys
[2005-11-23 04:12:24 | 000,092,672 | ---- | M] (VIA Technologies inc,.ltd) MD5=FBF18F9F5FB852C2976723587B44F346 -- C:\WINDOWS\system32\drivers\viamraid.sys

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2007-11-07 12:00:26 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2007-11-07 12:00:26 | 000,659,456 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2007-11-07 12:00:26 | 000,442,368 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< End of report >

Extras.txt:

OTL Extras logfile created on: 2010-07-24 12:22:02 - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\Olsson\Skrivbord
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 0000041D | Country: Sverige | Language: SVE | Date Format: yyyy-MM-dd

2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 71,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 88,00% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program
Drive C: | 74,52 Gb Total Space | 9,97 Gb Free Space | 13,37% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: JEOH1
Current User Name: Olsson
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = SafariHTML] -- C:\Program\Safari\Safari.exe (Apple Inc.)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Program\Microsoft Office\Office\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program\Microsoft Office\Office\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"3389:TCP" = 3389:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22009
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program\MSN Messenger\livecall.exe" = C:\Program\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) -- File not found
"C:\Program\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync -- (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program\Winamp Remote\bin\Orb.exe" = C:\Program\Winamp Remote\bin\Orb.exe:*:Enabled:Orb -- File not found
"C:\Program\Winamp Remote\bin\OrbTray.exe" = C:\Program\Winamp Remote\bin\OrbTray.exe:*:Enabled:OrbTray -- File not found
"C:\Program\Winamp Remote\bin\OrbStreamerClient.exe" = C:\Program\Winamp Remote\bin\OrbStreamerClient.exe:*:Enabled:Orb Stream Client -- File not found
"C:\Program\SpacialAudio\SAMBC\SAMBC.exe" = C:\Program\SpacialAudio\SAMBC\SAMBC.exe:*:Enabled:SAMBC -- File not found
"C:\EA Games\Command & Conquer The First Decade\Command & Conquer Red Alert(tm) II\RA2\mph.exe" = C:\EA Games\Command & Conquer The First Decade\Command & Conquer Red Alert(tm) II\RA2\mph.exe:*:Enabled:mph -- ()
"C:\EA Games\Command & Conquer The First Decade\Command & Conquer Red Alert(tm) II\RA2\game.exe" = C:\EA Games\Command & Conquer The First Decade\Command & Conquer Red Alert(tm) II\RA2\game.exe:*:Enabled:game -- (Westwood Studios)
"C:\Program\MSN Messenger\livecall.exe" = C:\Program\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) -- File not found
"C:\Program\River Past\Screen Recorder Pro\ScreenRecorderPro.exe" = C:\Program\River Past\Screen Recorder Pro\ScreenRecorderPro.exe:*:Enabled:River Past Screen Recorder Pro -- File not found
"C:\Spel\Hasbro Interactive\RollerCoaster Tycoon\rct.exe" = C:\Spel\Hasbro Interactive\RollerCoaster Tycoon\rct.exe:*:Enabled:rct -- File not found
"C:\Documents and Settings\Olsson\Skrivbord\rctrec1.exe" = C:\Documents and Settings\Olsson\Skrivbord\rctrec1.exe:*:Enabled:rctrec1 -- File not found
"C:\Mohaa\Mohaa\MOHAA.exe" = C:\Mohaa\Mohaa\MOHAA.exe:*:Enabled:Medal of Honor Allied Assault -- (Electronic Arts Inc.)
"C:\Program\Ventrilo\Ventrilo.exe" = C:\Program\Ventrilo\Ventrilo.exe:*:Enabled:Ventrilo.exe -- (Flagship Industries, Inc.)
"C:\Program\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync -- (Microsoft Corporation)
"C:\Team17\Worms Armageddon\WA.exe" = C:\Team17\Worms Armageddon\WA.exe:*:Enabled:Worms Armageddon -- (Team17 Software Ltd)
"C:\Program\Spotify\spotify.exe" = C:\Program\Spotify\spotify.exe:*:Enabled:Spotify -- (Spotify Ltd)
"C:\WINDOWS\pchealth\helpctr\binaries\helpctr.exe" = C:\WINDOWS\pchealth\helpctr\binaries\helpctr.exe:*:Enabled:Fjärrhjälp - Windows Messenger och tal -- (Microsoft Corporation)
"C:\Program\Xfire\Xfire.exe" = C:\Program\Xfire\Xfire.exe:*:Enabled:Xfire -- File not found
"C:\Program\LimeWire\LimeWire.exe" = C:\Program\LimeWire\LimeWire.exe:*:Enabled:LimeWire -- File not found
"C:\Program\iTunes\iTunes.exe" = C:\Program\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.)
"C:\Program\Java\jre6\bin\java.exe" = C:\Program\Java\jre6\bin\java.exe:*:Disabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001041D-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 SR-1 Professional
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{01521746-02A6-4A72-00BD-A285DF6B80C6}" = The Sims 2 Studentliv
"{08A247F5-E34F-4D17-8731-0906DF56947E}" = Windows Live Sync
"{0CB9668D-F979-4F31-B8B8-67FE90F929F8}" = Bonjour
"{0EE11800-A1BD-11D3-BFEB-005004AF2D32}" = Risk II
"{14FB2C18-CFC1-4DF4-A9CF-BAD3CCB5AAFD}" = Windows Live Toolbar
"{1A8BAA46-1179-4743-B00E-51B794A018B0}" = Windows Live Writer
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{236BB7C4-4419-42FD-041D-1E257A25E34D}" = Adobe Photoshop CS2
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java(TM) 6 Update 15
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{315ACD04-BCEB-478B-9B1D-5431D0E6CB11}" = ASUS Enhanced Display Driver
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java(TM) 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java(TM) 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java(TM) 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7
"{350C941d-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3DED3A72-61A8-4B87-98A5-EF0BC8038AA0}" = DAEMON Tools
"{4817189D-1785-4627-A33C-39FD90919300}" = The Sims™ 2 Djurliv
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{57383270-6F61-4DC8-A9B8-C1745FC29F38}" = USB PC Camera (SN9C102)
"{5A70922D-9365-43CC-ADA9-CB84E4A54E4E}" = Windows Live Essentials
"{5C648FDB-0138-4619-B66E-230EF53E8E2C}" = The Sims™ 2 Tonårsprylar Prylpaket
"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.8
"{65F6D25C-2B2B-4673-A81D-E7D7D72B29E4}" = Windows Live Family Safety
"{66D6F3BD-CA23-41A4-9FA3-96B26B32528C}" = Command & Conquer The First Decade
"{6B30FB1E-9F4A-49BA-9D74-174F1ECEB59D}" = Windows Live inloggningsassistenten
"{6E7DD182-9FC6-4651-0095-2E666CC6AF35}" = The Sims 2
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{72DF62BD-FF36-424E-AA5F-D89BAFF2C249}" = RollerCoaster Tycoon 2
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{786C5747-1437-443D-B06E-79A00FE45110}" = Adobe Stock Photos 1.0
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{7AB3A249-FB81-416B-917A-A2A10E74C503}" = iTunes
"{7B3577F5-1D82-4C9B-008B-69D026FD8BCA}" = The Sims 2 Arbetsliv
"{84DDE556-43EF-43ed-B2DF-37AF9E5DDD75}" = The Sims™ 2 H&M® Fashion Prylpaket
"{85991ED2-010C-4930-96FA-52F43C2CE98A}" = Apple Mobile Device Support
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8EDBA74D-0686-4C99-BFDD-F894678E5102}" = Adobe Common File Installer
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{961034C0-58DF-11DF-97FD-005056806466}" = Google Earth Plug-in
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BBE7AA1-AFA8-4D76-8FC2-1FDFD9BD3371}" = Windows Live Mail
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AFAC914D-9E83-4A89-8ABE-427521C82CCF}" = Safari
"{B2D328BE-45AD-4D92-96F9-2151490A203E}" = Apple Application Support
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B74D4E10-6884-0000-0000-000000000101}" = Adobe Bridge 1.0
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C3FE3DD5-92E1-4EC3-BD6B-822DD99E8991}" = Windows Live Photo Gallery
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D7D50E0C-27DD-4999-BC05-E026B580F93A}" = Electronic Arts Product Registration
"{DFEF49D9-FC95-4301-99B9-2FB91C6ABA06}" = The Sims™ 2 Året runt
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E9787678-551D-4478-9682-DBB587257110}" = Adobe Help Center 1.0
"{EC928237-A3BD-4640-ABD0-E49E758F2315}" = Windows Live Messenger
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop CS2 - {236BB7C4-4419-42FD-041D-1E257A25E34D}" = Adobe Photoshop CS2
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Cross Fire_is1" = Cross Fire En
"F-Secure Anti-Virus" = F-Secure Anti-Virus
"F-Secure BackWeb" = F-Secure BackWeb
"F-Secure Management Agent" = F-Secure Management Agent
"Hospital" = Theme Hospital
"HospitalTycoon" = Hospital Tycoon
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platform Device Manager
"InstallShield_{D7D50E0C-27DD-4999-BC05-E026B580F93A}" = Electronic Arts Product Registration
"Kaspersky Online Scanner" = Kaspersky Online Scanner
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"RoadRash" = RoadRash
"Spotify" = Spotify
"Spybot - Search & Destroy_is1" = Spybot - Search & Destroy 1.4
"SystemRequirementsLab" = System Requirements Lab
"Teamspeak 2 RC2_is1" = TeamSpeak 2 RC2
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"TweakNow PowerPack 2009_is1" = TweakNow PowerPack 2009
"Ultra MP4 Video Converter_is1" = Ultra MP4 Video Converter 5.2.0603
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"Virtual Villagers_is1" = Virtual Villagers
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Worms Armageddon" = Worms Armageddon
"Worms Pinball" = Worms Pinball
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XCC Game Spy" = XCC Game Spy 1.0.8
"Xvid_is1" = Xvid 1.1.2 final uninstall
"Zoo Tycoon 1.0" = Microsoft Zoo Tycoon

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"World of Warcraft Trial" = World of Warcraft Trial

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2010-07-24 06:34:50 | Computer Name = JEOH1 | Source = F-Secure Anti-Virus | ID = 103
Description = 45 2010-07-24 12:34:50+02:00 jeoh1 JEOH1\Olsson F-Secure Anti-Virus

An error occurred while scanning C:\WINDOWS\SYSTEM32\WOW32.DLL.

Error - 2010-07-24 06:34:50 | Computer Name = JEOH1 | Source = F-Secure Anti-Virus | ID = 103
Description = 46 2010-07-24 12:34:50+02:00 jeoh1 JEOH1\Olsson F-Secure Anti-Virus

An error occurred while scanning C:\WINDOWS\SYSTEM32\WOW32.DLL.

Error - 2010-07-24 06:34:50 | Computer Name = JEOH1 | Source = F-Secure Anti-Virus | ID = 103
Description = 47 2010-07-24 12:34:50+02:00 jeoh1 JEOH1\Olsson F-Secure Anti-Virus

An error occurred while scanning C:\WINDOWS\SYSTEM32\WOW32.DLL.

Error - 2010-07-24 06:34:50 | Computer Name = JEOH1 | Source = F-Secure Anti-Virus | ID = 103
Description = 48 2010-07-24 12:34:50+02:00 jeoh1 JEOH1\Olsson F-Secure Anti-Virus

An error occurred while scanning C:\WINDOWS\SYSTEM32\WOW32.DLL.

Error - 2010-07-24 06:34:50 | Computer Name = JEOH1 | Source = F-Secure Anti-Virus | ID = 103
Description = 49 2010-07-24 12:34:50+02:00 jeoh1 JEOH1\Olsson F-Secure Anti-Virus

An error occurred while scanning C:\WINDOWS\SYSTEM32\WOW32.DLL.

Error - 2010-07-24 06:34:50 | Computer Name = JEOH1 | Source = F-Secure Anti-Virus | ID = 103
Description = 50 2010-07-24 12:34:50+02:00 jeoh1 JEOH1\Olsson F-Secure Anti-Virus

An error occurred while scanning C:\WINDOWS\SYSTEM32\WOW32.DLL.

Error - 2010-07-24 06:34:50 | Computer Name = JEOH1 | Source = F-Secure Anti-Virus | ID = 103
Description = 51 2010-07-24 12:34:50+02:00 jeoh1 JEOH1\Olsson F-Secure Anti-Virus

An error occurred while scanning C:\WINDOWS\SYSTEM32\WOW32.DLL.

Error - 2010-07-24 06:34:50 | Computer Name = JEOH1 | Source = F-Secure Anti-Virus | ID = 103
Description = 52 2010-07-24 12:34:50+02:00 jeoh1 JEOH1\Olsson F-Secure Anti-Virus

An error occurred while scanning C:\WINDOWS\SYSTEM32\WOW32.DLL.

Error - 2010-07-24 06:34:50 | Computer Name = JEOH1 | Source = F-Secure Anti-Virus | ID = 103
Description = 53 2010-07-24 12:34:50+02:00 jeoh1 JEOH1\Olsson F-Secure Anti-Virus

An error occurred while scanning C:\WINDOWS\SYSTEM32\WOW32.DLL.

Error - 2010-07-24 06:34:50 | Computer Name = JEOH1 | Source = F-Secure Anti-Virus | ID = 103
Description = 54 2010-07-24 12:34:50+02:00 jeoh1 JEOH1\Olsson F-Secure Anti-Virus

An error occurred while scanning C:\WINDOWS\SYSTEM32\WOW32.DLL.

[ System Events ]
Error - 2010-07-23 11:01:48 | Computer Name = JEOH1 | Source = Dhcp | ID = 1002
Description = IP-adresslånet 192.168.0.25 för det nätverkskort som har nätverksadressen
001617B20FE8 har nekats av DHCP-servern 192.168.0.1 (DHCP-servern skickade ett DHCPNACK-meddelande).

Error - 2010-07-23 11:02:28 | Computer Name = JEOH1 | Source = Service Control Manager | ID = 7000
Description = Tjänsten npkcrypt kunde inte startas på grund av följande fel: %%3

Error - 2010-07-23 11:18:22 | Computer Name = JEOH1 | Source = Service Control Manager | ID = 7034
Description = Tjänsten F-Secure BackWeb avslutades oväntat. Detta har skett 1 gånger.

Error - 2010-07-23 23:01:54 | Computer Name = JEOH1 | Source = Dhcp | ID = 1002
Description = IP-adresslånet 192.168.0.25 för det nätverkskort som har nätverksadressen
001617B20FE8 har nekats av DHCP-servern 192.168.0.1 (DHCP-servern skickade ett DHCPNACK-meddelande).

Error - 2010-07-24 05:12:22 | Computer Name = JEOH1 | Source = Service Control Manager | ID = 7023
Description = Tjänsten HID Input Service avbröts med följande fel: %%126

Error - 2010-07-24 05:12:22 | Computer Name = JEOH1 | Source = Service Control Manager | ID = 7000
Description = Tjänsten npkcrypt kunde inte startas på grund av följande fel: %%3

Error - 2010-07-24 05:23:03 | Computer Name = JEOH1 | Source = Service Control Manager | ID = 7034
Description = Tjänsten F-Secure BackWeb avslutades oväntat. Detta har skett 1 gånger.

Error - 2010-07-24 06:13:12 | Computer Name = JEOH1 | Source = Service Control Manager | ID = 7023
Description = Tjänsten HID Input Service avbröts med följande fel: %%126

Error - 2010-07-24 06:13:12 | Computer Name = JEOH1 | Source = Service Control Manager | ID = 7000
Description = Tjänsten npkcrypt kunde inte startas på grund av följande fel: %%3

Error - 2010-07-24 06:13:56 | Computer Name = JEOH1 | Source = Service Control Manager | ID = 7011
Description = En timeout (30000 ms) inträffade vid väntan på transaktionssvar från
tjänsten NVSvc.


< End of report >

ken545
2010-07-24, 15:24
Looks like CF may have removed the bad files


Run OTL

Under the Custom Scans/Fixes box at the bottom, paste in the following



:OTL
PRC - C:\Windows\Explorer.EXE (Microsoft Corporation)
DRV - (XDva349) -- C:\WINDOWS\System32\XDva349.sys File not found
DRV - (XDva348) -- C:\WINDOWS\System32\XDva348.sys File not found
DRV - (XDva347) -- C:\WINDOWS\System32\XDva347.sys File not found
DRV - (XDva346) -- C:\WINDOWS\System32\XDva346.sys File not found
DRV - (XDva345) -- C:\WINDOWS\System32\XDva345.sys File not found
DRV - (XDva342) -- C:\WINDOWS\System32\XDva342.sys File not found
DRV - (XDva341) -- C:\WINDOWS\System32\XDva341.sys File not found
DRV - (XDva337) -- C:\WINDOWS\System32\XDva337.sys File not found
DRV - (XDva336) -- C:\WINDOWS\System32\XDva336.sys File not found
DRV - (XDva327) -- C:\WINDOWS\System32\XDva327.sys File not found
DRV - (XDva326) -- C:\WINDOWS\System32\XDva326.sys File not found
DRV - (XDva323) -- C:\WINDOWS\System32\XDva323.sys File not found
DRV - (XDva321) -- C:\WINDOWS\System32\XDva321.sys File not found
DRV - (XDva317) -- C:\WINDOWS\System32\XDva317.sys File not found
O4 - HKCU..\Run: [aammi1e] C:\WINDOWS\System32\xnejkaw3.exe File not found
O4 - HKCU..\Run: [aqrmm6] C:\WINDOWS\System32\0eezqbw.exe File not found
O4 - HKCU..\Run: C:\WINDOWS\System32\fqwrc870.exe File not found
O4 - HKCU..\Run: [cnjj7] C:\WINDOWS\System32\0mrs9jp.exe File not found
O4 - HKCU..\Run: [djagl] C:\WINDOWS\System32\xss70e1a3.exe File not found
O4 - HKCU..\Run: [dopkq] C:\WINDOWS\System32\c1yefk9g.exe File not found
O4 - HKCU..\Run: [ekvqmh] C:\WINDOWS\System32\dj625b66.exe File not found
O4 - HKCU..\Run: [euvlm] C:\WINDOWS\System32\p9r0ii9jall.exe File not found
O4 - HKCU..\Run: [ezqlmcx] C:\WINDOWS\System32\kvr0ii9ja.exe File not found
O4 - HKCU..\Run: [fbcnt] C:\WINDOWS\System32\c8ijeflbc.exe File not found
O4 - HKCU..\Run: [ghc3o] C:\WINDOWS\System32\2u1q3x7.exe File not found
O4 - HKCU..\Run: [ghityfq] C:\WINDOWS\System32\lgbss9euavg.exe File not found
O4 - HKCU..\Run: [jaglw] C:\WINDOWS\System32\xss70e1a3cn.exe File not found
O4 - HKCU..\Run: [kabrsd] C:\WINDOWS\System32\tzpgmrnt.exe File not found
O4 - HKCU..\Run: [mccy1o] C:\WINDOWS\System32\c1sty86k.exe File not found
O4 - HKCU..\Run: [mdi3u] C:\WINDOWS\System32\5hsdzkf.exe File not found
O4 - HKCU..\Run: [mrinjea] C:\WINDOWS\System32\zugmhddz.exe File not found
O4 - HKCU..\Run: [msooz8] C:\WINDOWS\System32\hs6t15va.exe File not found
O4 - HKCU..\Run: [neezq] C:\WINDOWS\System32\xoojaavm.exe File not found
O4 - HKCU..\Run: [pabbxnn] C:\WINDOWS\System32\vrm674pqgg.exe File not found
O4 - HKCU..\Run: [pggbs] C:\WINDOWS\System32\nytpk1gc71d.exe File not found
O4 - HKCU..\Run: [ppqb8n] C:\WINDOWS\System32\rrd27p0l.exe File not found
O4 - HKCU..\Run: [pvvmmxd] C:\WINDOWS\System32\0jeuglw.exe File not found
O4 - HKCU..\Run: [qbmxt] C:\WINDOWS\System32\ntef2rm9sy.exe File not found
O4 - HKCU..\Run: [qqlcc] C:\WINDOWS\System32\zuu6gg6ss.exe File not found
O4 - HKCU..\Run: [qrcinj] C:\WINDOWS\System32\r4xoepq73s9.exe File not found
O4 - HKCU..\Run: [qwbm9] C:\WINDOWS\System32\ukal2xc3e1.exe File not found
O4 - HKCU..\Run: [rnno3] C:\WINDOWS\System32\9msnokk.exe File not found
O4 - HKCU..\Run: [stez0v] C:\WINDOWS\System32\0riy0uu.exe File not found
O4 - HKCU..\Run: [sxtoo6] C:\WINDOWS\System32\d6avrrnd6.exe File not found
O4 - HKCU..\Run: [tje6a] C:\WINDOWS\System32\dze8a1hr.exe File not found
O4 - HKCU..\Run: [toe9a] C:\WINDOWS\System32\2lbcdyu.exe File not found
O4 - HKCU..\Run: [uqwrst] C:\WINDOWS\System32\yjffbrsi.exe File not found
O4 - HKCU..\Run: [vbmxtoj] C:\WINDOWS\System32\nyjffbrsit.exe File not found
O4 - HKCU..\Run: [vbxtjp] C:\WINDOWS\System32\e7plq6sxi.exe File not found
O4 - HKCU..\Run: [whty3a] C:\WINDOWS\System32\pfqb60c4o0.exe File not found
O4 - HKCU..\Run: [wmcctup] C:\WINDOWS\System32\cs1uzalrhso.exe File not found
O4 - HKCU..\Run: [wsndo9v] C:\WINDOWS\System32\78x5oj6.exe File not found
O4 - HKCU..\Run: [wsnjjaq] C:\WINDOWS\System32\zugmhddza.exe File not found
O4 - HKCU..\Run: [wxdyua] C:\WINDOWS\System32\izplr2siej.exe File not found
O4 - HKCU..\Run: [xdtjzq] C:\WINDOWS\System32\aagmcs9u.exe File not found
O4 - HKCU..\Run: [xtoe8] C:\WINDOWS\System32\hii6e1v2.exe File not found
O4 - HKCU..\Run: [yezaqg] C:\WINDOWS\System32\0iy0uup.exe File not found
O4 - HKCU..\Run: [zaawwh2] C:\WINDOWS\System32\k95iyzaqq9.exe File not found
O4 - HKCU..\Run: [zplghc] C:\WINDOWS\System32\rhd3eu1q.exe File not found
O33 - MountPoints2\{9e7c23de-e8e7-11de-843d-001617b20fe8}\Shell\AutoRun\command - "" = F:\autorun.exe -- File not found
O33 - MountPoints2\{9e7c23de-e8e7-11de-843d-001617b20fe8}\Shell\explore\command - "" = F:\autorun.exe -- File not found
O33 - MountPoints2\{9e7c23de-e8e7-11de-843d-001617b20fe8}\Shell\open\command - "" = F:\autorun.exe -- File not found
O33 - MountPoints2\{cac0fb4d-8299-11df-851b-001617b20fe8}\Shell\AutoRun\command - "" = G:\autorun.exe -- File not found
O33 - MountPoints2\{cac0fb4d-8299-11df-851b-001617b20fe8}\Shell\explore\command - "" = G:\autorun.exe -- File not found
O33 - MountPoints2\{cac0fb4d-8299-11df-851b-001617b20fe8}\Shell\open\command - "" = G:\autorun.exe -- File not found

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

Then click the [b]Run Fix button at the top
Let the program run unhindered, reboot when it is done, post the log it created

MrBugger
2010-07-24, 16:04
All processes killed
========== OTL ==========
No active process named Explorer.EXE was found!
Service XDva349 stopped successfully!
Service XDva349 deleted successfully!
File C:\WINDOWS\System32\XDva349.sys File not found not found.
Service XDva348 stopped successfully!
Service XDva348 deleted successfully!
File C:\WINDOWS\System32\XDva348.sys File not found not found.
Service XDva347 stopped successfully!
Service XDva347 deleted successfully!
File C:\WINDOWS\System32\XDva347.sys File not found not found.
Service XDva346 stopped successfully!
Service XDva346 deleted successfully!
File C:\WINDOWS\System32\XDva346.sys File not found not found.
Service XDva345 stopped successfully!
Service XDva345 deleted successfully!
File C:\WINDOWS\System32\XDva345.sys File not found not found.
Service XDva342 stopped successfully!
Service XDva342 deleted successfully!
File C:\WINDOWS\System32\XDva342.sys File not found not found.
Service XDva341 stopped successfully!
Service XDva341 deleted successfully!
File C:\WINDOWS\System32\XDva341.sys File not found not found.
Service XDva337 stopped successfully!
Service XDva337 deleted successfully!
File C:\WINDOWS\System32\XDva337.sys File not found not found.
Service XDva336 stopped successfully!
Service XDva336 deleted successfully!
File C:\WINDOWS\System32\XDva336.sys File not found not found.
Service XDva327 stopped successfully!
Service XDva327 deleted successfully!
File C:\WINDOWS\System32\XDva327.sys File not found not found.
Service XDva326 stopped successfully!
Service XDva326 deleted successfully!
File C:\WINDOWS\System32\XDva326.sys File not found not found.
Service XDva323 stopped successfully!
Service XDva323 deleted successfully!
File C:\WINDOWS\System32\XDva323.sys File not found not found.
Service XDva321 stopped successfully!
Service XDva321 deleted successfully!
File C:\WINDOWS\System32\XDva321.sys File not found not found.
Service XDva317 stopped successfully!
Service XDva317 deleted successfully!
File C:\WINDOWS\System32\XDva317.sys File not found not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\aammi1e deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\aqrmm6 deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\bmcxio deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\cnjj7 deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\djagl deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\dopkq deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ekvqmh deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\euvlm deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ezqlmcx deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\fbcnt deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ghc3o deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ghityfq deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\jaglw deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\kabrsd deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\mccy1o deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\mdi3u deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\mrinjea deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\msooz8 deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\neezq deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\pabbxnn deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\pggbs deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ppqb8n deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\pvvmmxd deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\qbmxt deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\qqlcc deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\qrcinj deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\qwbm9 deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\rnno3 deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\stez0v deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\sxtoo6 deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\tje6a deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\toe9a deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\uqwrst deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\vbmxtoj deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\vbxtjp deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\whty3a deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\wmcctup deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\wsndo9v deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\wsnjjaq deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\wxdyua deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\xdtjzq deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\xtoe8 deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\yezaqg deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\zaawwh2 deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\zplghc deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9e7c23de-e8e7-11de-843d-001617b20fe8}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9e7c23de-e8e7-11de-843d-001617b20fe8}\ not found.
File F:\autorun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9e7c23de-e8e7-11de-843d-001617b20fe8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9e7c23de-e8e7-11de-843d-001617b20fe8}\ not found.
File F:\autorun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9e7c23de-e8e7-11de-843d-001617b20fe8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9e7c23de-e8e7-11de-843d-001617b20fe8}\ not found.
File F:\autorun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{cac0fb4d-8299-11df-851b-001617b20fe8}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{cac0fb4d-8299-11df-851b-001617b20fe8}\ not found.
File G:\autorun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{cac0fb4d-8299-11df-851b-001617b20fe8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{cac0fb4d-8299-11df-851b-001617b20fe8}\ not found.
File G:\autorun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{cac0fb4d-8299-11df-851b-001617b20fe8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{cac0fb4d-8299-11df-851b-001617b20fe8}\ not found.
File G:\autorun.exe not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Jenny
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->Apple Safari cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Olsson
->Temp folder emptied: 46453 bytes
->Temporary Internet Files folder emptied: 9807550 bytes
->Java cache emptied: 0 bytes
->Apple Safari cache emptied: 1863680 bytes
->Flash cache emptied: 689 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 57827 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 11,00 mb
So things look a little bit brighter now :)

OTL by OldTimer - Version 3.2.9.1 log created on 07242010_145554

Files\Folders moved on Reboot...
C:\Documents and Settings\Olsson\Lokala inställningar\Temporary Internet Files\Content.IE5\DHOBWFPC\showthread[1].htm moved successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully.
C:\Documents and Settings\Olsson\Lokala inställningar\Temporary Internet Files\SuggestedSites.dat moved successfully.
C:\WINDOWS\temp\IadHide3.dll moved successfully.

Registry entries deleted on Reboot...

ken545
2010-07-24, 17:31
I think that there was so much bad stuff clogging up your system that it bogged down Combofix, drag Combofix to the trash and download a fresh copy and run it please and post the report


Download ComboFix from one of these locations:

Link 1 (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
Link 2 (http://www.forospyware.com/sUBs/ComboFix.exe)


* IMPORTANT !!! Save ComboFix.exe to your Desktop


Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
See this Link (http://www.bleepingcomputer.com/forums/topic114351.html) for programs that need to be disabled and instruction on how to disable them.
Remember to re-enable them when we're done.


Double click on ComboFix.exe & follow the prompts.


As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.


Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.



http://img.photobucket.com/albums/v706/ried7/RC1.png


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

http://img.photobucket.com/albums/v706/ried7/RC2-1.png

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

MrBugger
2010-07-24, 19:46
Hi Ken!

Am i doing something wrong? It's been 2 hours now with CF and i still got "scanning for infected files" and minimal hd activity

I have stopped F-Secure and Spyboot. The infected computer is connected to internet, is that wrong thing to have?

Br

ken545
2010-07-24, 20:15
Ok, go ahead and shut it down, lets run this scan to see if there is any rootkit activity preventing CF from running


Download the GMER Rootkit Scanner (http://www.gmer.net/gmer.zip). Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double click GMER.exe.
http://img.photobucket.com/albums/v666/sUBs/gmer_zip.gif
If it gives you a warning about rootkit activity and asks if you want to run a full scan...click on NO, then use the following settings for a more complete scan..
In the right panel, you will see several boxes that have been checked. Ensure the following are UNCHECKED ...
IAT/EAT
Drives/Partition other than Systemdrive (typically C:\)
Show All (don't miss this one)
http://www.geekstogo.com/misc/guide_icons/GMER_thumb.jpg (http://www.geekstogo.com/misc/guide_icons/GMER_instructions.jpg)
Click the image to enlarge it

Then click the Scan button & wait for it to finish.
Once done click on the [Save..] button, and in the File name area, type in "ark.txt"
Save the log where you can easily find it, such as your desktop.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries
Please copy and paste the report into your Post.

MrBugger
2010-07-24, 20:50
Hi Ken!

Something is causing GMER from running after about 5 seconds. I get "gmer.exe har stött på ett problem och måste avslutas." Like " gmer.exe has encountered an error and has to be ended. Send a report to Microsoft?

I've tried this twice with a reboot, get the same message

I ended Spybot and F-Secure before starting gmer.exe

Br

ken545
2010-07-24, 22:38
Start Combofix and it if stalls bring up Task Manager using CTRL+ALT+DELETE. See if any of these processes are running ...Kill Process if they are

findstr
sed
grep.
nircmd.exe
nircmd.cfexe
swsc.cfexe
* .. or any other process that has the .cfexe extension except for CFxxx.cfexe

If ComboFix is still 'hung', then kill process on CFxxx.cfexe

MrBugger
2010-07-24, 23:59
Hi Ken!

I didn't se your edit on the post. I just followed the e-mail so i did the CF in safemode. Just tell me if you want we to do the way you edited.

ComboFix 10-07-23.04 - Olsson 2010-07-24 22:30:30.1.1 - x86 NETWORK
Microsoft Windows XP Professional 5.1.2600.3.1252.46.1053.18.2046.1789 [GMT 2:00]
Körs från: c:\documents and settings\Olsson\Skrivbord\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Andra raderingar ))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\daemon.dll

.
(((((((((((((((((((((((( Filer Skapade från 2010-06-24 till 2010-07-24 ))))))))))))))))))))))))))))))
.

2010-07-24 12:55 . 2010-07-24 12:55 -------- d-----w- C:\_OTL
2010-07-23 13:54 . 2010-07-23 13:54 -------- d-----w- c:\documents and settings\Olsson\Application Data\Malwarebytes
2010-07-23 13:54 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-23 13:54 . 2010-07-23 13:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-07-23 13:54 . 2010-07-23 13:54 -------- d-----w- c:\program\Malwarebytes' Anti-Malware
2010-07-23 13:54 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-07-14 15:14 . 2010-07-14 15:14 -------- d-----w- c:\documents and settings\All Users\Application Data\F-Secure
2010-07-14 13:52 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2010-06-28 12:55 . 2010-06-28 12:55 -------- d-----w- c:\documents and settings\Olsson\Application Data\U3
2010-06-26 17:45 . 2010-06-26 17:45 14720 ---ha-w- c:\windows\system32\mlfcache.dat
2010-06-26 15:05 . 2010-06-26 15:05 -------- d-----w- c:\program\iPod
2010-06-26 14:51 . 2010-06-26 14:51 -------- d-----w- c:\program\Bonjour
2010-06-26 14:49 . 2010-06-26 14:49 72504 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.2.0.61\SetupAdmin.exe
2010-06-26 14:48 . 2010-06-26 14:49 -------- d-----w- c:\program\Safari
2010-06-26 14:47 . 2010-06-26 14:47 71992 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.33.16.0\SetupAdmin.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-24 10:18 . 2010-01-30 10:57 -------- d-----w- c:\documents and settings\Olsson\Application Data\Skype
2010-07-24 09:15 . 2010-01-30 10:59 -------- d-----w- c:\documents and settings\Olsson\Application Data\skypePM
2010-07-19 21:12 . 2009-11-01 15:12 -------- d-----w- c:\documents and settings\Olsson\Application Data\Spotify
2010-07-15 09:58 . 2009-06-20 15:48 -------- d-----w- c:\program\Pando Networks
2010-06-29 21:05 . 2010-05-13 11:35 -------- d-----w- c:\documents and settings\Olsson\Application Data\Apple Computer
2010-06-26 15:52 . 2010-02-04 09:48 -------- d-----w- c:\program\World of Warcraft Trial
2010-06-26 15:07 . 2010-05-13 11:32 -------- d-----w- c:\program\iTunes
2010-06-26 15:04 . 2010-05-13 11:25 -------- d-----w- c:\program\Delade filer\Apple
2010-06-22 19:15 . 2004-08-04 12:00 87766 ----a-w- c:\windows\system32\perfc01D.dat
2010-06-22 19:15 . 2004-08-04 12:00 454926 ----a-w- c:\windows\system32\perfh01D.dat
2010-06-19 17:14 . 2010-06-19 17:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Blizzard
2010-06-18 19:06 . 2010-01-17 17:52 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-06-14 14:31 . 2007-11-07 09:18 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-05 10:47 . 2008-03-24 20:53 -------- d-----w- c:\program\Microsoft Silverlight
2010-05-29 09:10 . 2010-01-30 10:56 -------- d-----r- c:\program\Skype
2010-05-18 14:35 . 2010-05-18 14:35 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-05-18 14:35 . 2010-05-18 14:35 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-05-13 11:43 . 2010-05-13 11:43 321328 ----a-w- c:\program\utorrent.exe
2010-05-13 11:36 . 2010-05-13 11:36 562864 ----a-w- c:\program\GoogleEarthPluginSetup.exe
2010-05-13 11:18 . 2010-05-13 11:18 97547048 ----a-w- c:\program\iTunesSetup.exe
2010-05-06 10:36 . 2004-08-04 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-04 14:58 . 2010-05-04 14:58 282624 ----a-w- c:\documents and settings\Olsson\Application Data\Spotify\Gracenote\gnsdk_musicid_file.dll
2010-05-04 14:58 . 2010-05-04 14:58 655360 ----a-w- c:\documents and settings\Olsson\Application Data\Spotify\Gracenote\gnsdk_sdkmanager.dll
2010-05-04 14:58 . 2010-05-04 14:58 208896 ----a-w- c:\documents and settings\Olsson\Application Data\Spotify\Gracenote\gnsdk_dsp.dll
2010-05-02 08:10 . 2004-08-04 12:00 1851264 ----a-w- c:\windows\system32\win32k.sys
2009-12-28 19:48 . 2009-12-28 19:48 1971 ----a-w- c:\program\Harry Potter(TM) och Fången från Azkaban.lnk
.

(((((((((((((((((((((((((((((((((( Startpunkter i registret )))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Not* Tomma poster & legitima standardposter visas inte.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-17 13574144]
"DAEMON Tools-1033"="c:\program\D-Tools\daemon.exe" [2004-08-22 81920]
"snpstd"="c:\windows\vsnpstd.exe" [2003-12-31 40960]
"nwiz"="nwiz.exe" [2008-09-17 1657376]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-09-17 86016]
"SunJavaUpdateSched"="c:\program\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"F-Secure Manager"="c:\program\F-Secure\Common\FSM32.EXE" [2002-12-05 106571]
"fssui"="c:\program\Windows Live\Family Safety\fsui.exe" [2009-08-05 647520]
"QuickTime Task"="c:\program\QuickTime\qttask.exe" [2010-03-17 421888]
"iTunesHelper"="c:\program\iTunes\iTunesHelper.exe" [2010-06-15 141624]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users\Start-meny\Program\Autostart\
Microsoft Office.lnk - c:\program\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2005-05-03 10:43 69632 ------r- c:\windows\Alcmtr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2008-04-14 16:05 15360 ----a-w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2008-09-17 21:55 13574144 ----a-w- c:\windows\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2008-09-17 21:55 86016 ----a-w- c:\windows\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2008-09-17 21:55 1657376 ----a-w- c:\windows\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RaidTool]
2005-11-23 02:12 1060864 ----a-r- c:\program\VIA\RAID\raid_tool.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2006-04-17 07:34 16143872 ------r- c:\windows\RTHDCPL.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\Jenny\\Lokala inställningar\\Application Data\\Skype\\Phone\\Skype.exe"=
"c:\\EA Games\\Command & Conquer The First Decade\\Command & Conquer Red Alert(tm) II\\RA2\\mph.exe"=
"c:\\EA Games\\Command & Conquer The First Decade\\Command & Conquer Red Alert(tm) II\\RA2\\game.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Mohaa\\Mohaa\\MOHAA.exe"=
"c:\\Program\\Ventrilo\\Ventrilo.exe"=
"c:\\Program\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Team17\\Worms Armageddon\\WA.exe"=
"c:\\Program\\Spotify\\spotify.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\helpctr.exe"=
"c:\\Program\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program\\Bonjour\\mDNSResponder.exe"=
"c:\\Program\\iTunes\\iTunes.exe"=
"c:\\Program\\Java\\jre6\\bin\\java.exe"=
"c:\\Program\\Skype\\Phone\\Skype.exe"=

R0 d347bus;d347bus;c:\windows\system32\drivers\d347bus.sys [2007-11-25 155136]
R0 d347prt;d347prt;c:\windows\system32\drivers\d347prt.sys [2007-11-25 5248]
S2 BackWeb Client - 7681197;F-Secure BackWeb;c:\program\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE [2009-09-13 16384]
S2 F-Secure Filter;F-Secure File System Filter;c:\program\F-Secure\Anti-Virus\win2k\FSfilter.sys [2009-09-13 47280]
S2 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program\F-Secure\Anti-Virus\win2k\fsgk.sys [2009-09-13 37456]
S2 F-Secure Recognizer;F-Secure File System Recognizer;c:\program\F-Secure\Anti-Virus\win2k\FSrec.sys [2009-09-13 15984]
S2 FSpm;F-Secure Policy Manager;c:\program\F-Secure\Common\FSpm.sys [2009-09-13 65328]
S2 gupdate;Google Update Service (gupdate);c:\program\Google\Update\GoogleUpdate.exe [2010-05-13 136176]
S3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys [2009-12-01 34384]
S3 VCSVADHWSer;Avnex Virtual Audio Device (WDM);c:\windows\system32\drivers\vcsvad.sys [2010-01-27 17792]
.
Innehållet i mappen 'Schemalagda aktiviteter':

2010-05-13 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program\Apple Software Update\SoftwareUpdate.exe [2009-10-22 09:50]

2010-02-07 c:\windows\Tasks\defrag.job
- c:\windows\system32\defrag.exe [2004-08-04 16:05]

2010-02-06 c:\windows\Tasks\Genomsök alla lokala hårddiskar.job
- c:\program\F-Secure\ANTI-V~1\fsavstrt.exe [2009-09-13 15:44]

2010-07-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program\Google\Update\GoogleUpdate.exe [2010-05-13 11:36]

2010-07-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program\Google\Update\GoogleUpdate.exe [2010-05-13 11:36]

2010-07-14 c:\windows\Tasks\Spybot - Search & Destroy.job
- c:\program\SPYBOT~1\SpybotSD.exe [2007-11-08 13:31]

2010-07-24 c:\windows\Tasks\User_Feed_Synchronization-{2C8DC5CE-1445-4847-B385-34C3AC51553E}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 02:31]

2010-07-24 c:\windows\Tasks\User_Feed_Synchronization-{C4030E41-5E64-40C0-B6D9-D952AC516761}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 02:31]
.
.
------- Extra genomsökning -------
.
uStart Page = hxxp://forums.spybot.info/index.php
uInternet Settings,ProxyOverride = *.local
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\Jenny\Start-meny\Program\IMVU\Run IMVU.lnk
.
- - - - FÖRÄLDRALÖSA POSTER SOM TAGITS BORT - - - -

WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
AddRemove-Worms Pinball - c:\team17\Worms Pinball\Uninst.isu
AddRemove-{E2883E8F-472F-4fb0-9522-AC9BF37916A7} - c:\program\NOS\bin\getPlus_HelperSvc.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-24 22:39
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe catchme.sys CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8A4DD248]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf763bf28
\Driver\ACPI -> ACPI.sys @ 0xf7588cb8
\Driver\atapi -> 0x8a4dd248
IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805a0615
ParseProcedure -> ntoskrnl.exe @ 0x8056c3ac
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805a0615
ParseProcedure -> ntoskrnl.exe @ 0x8056c3ac
NDIS: VIA Rhine II Fast Ethernet Adapter -> SendCompleteHandler -> NDIS.sys @ 0xf7868bb0
PacketIndicateHandler -> NDIS.sys @ 0xf7875a21
SendHandler -> NDIS.sys @ 0xf785387b
Warning: possible MBR rootkit infection !
user & kernel MBR OK

**************************************************************************
.
--------------------- LÅSTA REGISTERNYCKLAR ---------------------

[HKEY_USERS\S-1-5-21-789336058-682003330-1775052-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{2420B5BB-416C-03FE-7DD8-043FEB80489B}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iaoihfhdedlcocinfl"=hex:69,61,61,6d,70,6c,6b,64,67,66,6b,67,6d,6c,61,64,70,62,
00,00
"haijbhbmoefjaaal"=hex:69,61,61,6d,70,6c,6b,64,67,66,6b,67,6d,6c,61,64,70,62,
00,00
"iackpenkdhejipclep"=hex:63,61,6e,6c,64,6d,00,7c

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Sluttid: 2010-07-24 22:43:02
ComboFix-quarantined-files.txt 2010-07-24 20:42

Före genomsökningen: 10*666*192*896 byte ledigt
Efter genomsökningen: 10*679*812*096 byte ledigt

- - End Of File - - C6E18B31B5F6C66BCD521593374C312A

ken545
2010-07-25, 00:13
No, thats fine, you got it to run, those instructions I posted in my edit where for incase CF stalled again.

See if you can run GMER in Safemode also

MrBugger
2010-07-25, 00:29
Hi Ken!

I get the same message running GMER in safemode. I forgot to inform you when running CF in safemode i got the message like "Detected rootkit, computer will reboot"

Br

ken545
2010-07-25, 00:34
Lets try this one

Please download RootRepeal from one of these locations and save it to your desktop
Here (http://ad13.geekstogo.com/RootRepeal.exe)
Here (http://download.bleepingcomputer.com/rootrepeal/RootRepeal.exe)
Here (http://rootrepeal.psikotick.com/RootRepeal.exe)

Open http://billy-oneal.com/forums/rootRepeal/rootRepealDesktopIcon.png on your desktop.
Click the http://billy-oneal.com/forums/rootRepeal/reportTab.png tab.
Click the http://billy-oneal.com/forums/rootRepeal/btnScan.png button.
Check just these boxes:
http://forums.whatthetech.com/uploads/monthly_08_2009/post-75503-1250480183.gif
Push Ok
Check the box for your main system drive (Usually C:, and press Ok.
Allow RootRepeal to run a scan of your system. This may take some time.
Once the scan completes, push the http://billy-oneal.com/forums/rootRepeal/saveReport.png button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt. Include this report in your post.

MrBugger
2010-07-25, 00:53
Hi Ken!

Push Ok (After this the report was made automatically so i couldn't proceed any steps after clicking OK)

Check the box for your main system drive (Usually C:, and press Ok.
Allow RootRepeal to run a scan of your system. This may take some time.
Once the scan completes, push the button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt. Include this report in your post.


ROOTREPEAL (c) AD, 2007-2009
==================================================
Scan Start Time: 2010/07/24 23:45
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================

Drivers
-------------------
Name:
Image Path:
Address: 0xB9EE5000 Size: 98304 File Visible: No Signed: -
Status: -

Name:
Image Path:
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -

Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xAD516000 Size: 98304 File Visible: No Signed: -
Status: -

Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xBA61C000 Size: 8192 File Visible: No Signed: -
Status: -

Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xAD07B000 Size: 49152 File Visible: No Signed: -
Status: -

SSDT
-------------------
#: 025 Function Name: NtClose
Status: Hooked by "d347bus.sys" at address 0xb9f8e818

#: 041 Function Name: NtCreateKey
Status: Hooked by "d347bus.sys" at address 0xb9f8e7d0

#: 045 Function Name: NtCreatePagingFile
Status: Hooked by "d347bus.sys" at address 0xb9f82a20

#: 071 Function Name: NtEnumerateKey
Status: Hooked by "d347bus.sys" at address 0xb9f832a8

#: 073 Function Name: NtEnumerateValueKey
Status: Hooked by "d347bus.sys" at address 0xb9f8e910

#: 119 Function Name: NtOpenKey
Status: Hooked by "d347bus.sys" at address 0xb9f8e794

#: 160 Function Name: NtQueryKey
Status: Hooked by "d347bus.sys" at address 0xb9f832c8

#: 177 Function Name: NtQueryValueKey
Status: Hooked by "d347bus.sys" at address 0xb9f8e866

#: 241 Function Name: NtSetSystemPowerState
Status: Hooked by "d347bus.sys" at address 0xb9f8e0b0

==EOF==

ken545
2010-07-25, 01:31
Download TDSSKiller (http://support.kaspersky.com/downloads/utils/tdsskiller.zip) and save it to your Desktop.

Extract the file and run it.

Once completed it will create a log in your C:\ drive called TDSSKiller_* (* denotes version & date)

Please post the content of the TDSSKiller log

MrBugger
2010-07-25, 10:50
Hi Ken!

Do you know why CF removed the .sys file for daemon tools?
Here's the log:

2010/07/25 09:44:37.0375 TDSS rootkit removing tool 2.4.0.0 Jul 22 2010 16:09:49
2010/07/25 09:44:37.0375 ================================================================================
2010/07/25 09:44:37.0375 SystemInfo:
2010/07/25 09:44:37.0375
2010/07/25 09:44:37.0375 OS Version: 5.1.2600 ServicePack: 3.0
2010/07/25 09:44:37.0375 Product type: Workstation
2010/07/25 09:44:37.0375 ComputerName: JEOH1
2010/07/25 09:44:37.0390 UserName: Olsson
2010/07/25 09:44:37.0390 Windows directory: C:\WINDOWS
2010/07/25 09:44:37.0390 System windows directory: C:\WINDOWS
2010/07/25 09:44:37.0390 Processor architecture: Intel x86
2010/07/25 09:44:37.0390 Number of processors: 1
2010/07/25 09:44:37.0390 Page size: 0x1000
2010/07/25 09:44:37.0390 Boot type: Normal boot
2010/07/25 09:44:37.0390 ================================================================================
2010/07/25 09:44:37.0640 Initialize success
2010/07/25 09:45:17.0781 ================================================================================
2010/07/25 09:45:17.0781 Scan started
2010/07/25 09:45:17.0781 Mode: Manual;
2010/07/25 09:45:17.0781 ================================================================================
2010/07/25 09:45:18.0734 ACPI (48547e29772befe3c554ff5e4855bf51) C:\WINDOWS\system32\DRIVERS\ACPI.sys
2010/07/25 09:45:18.0984 ACPIEC (decedc736cef3c0fff6e981b31e73a61) C:\WINDOWS\system32\drivers\ACPIEC.sys
2010/07/25 09:45:19.0453 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
2010/07/25 09:45:19.0953 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys
2010/07/25 09:45:21.0046 AmdK8 (59301936898ae62245a6f09c0aba9475) C:\WINDOWS\system32\DRIVERS\AmdK8.sys
2010/07/25 09:45:22.0093 asuskbnt (f5c2ccdb273a546e9c3a15250f1d9165) C:\WINDOWS\system32\drivers\atkkbnt.sys
2010/07/25 09:45:22.0328 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
2010/07/25 09:45:22.0609 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
2010/07/25 09:45:23.0046 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
2010/07/25 09:45:23.0312 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
2010/07/25 09:45:23.0546 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
2010/07/25 09:45:23.0781 BthEnum (b279426e3c0c344893ed78a613a73bde) C:\WINDOWS\system32\DRIVERS\BthEnum.sys
2010/07/25 09:45:24.0093 BTHPORT (5393b93cacf7f0f91ebacd014fe2b4c9) C:\WINDOWS\system32\Drivers\BTHport.sys
2010/07/25 09:45:24.0406 BTHUSB (61364cd71ef63b0f038b7e9df00f1efa) C:\WINDOWS\system32\Drivers\BTHUSB.sys
2010/07/25 09:45:24.0765 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
2010/07/25 09:45:24.0984 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
2010/07/25 09:45:25.0437 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
2010/07/25 09:45:25.0687 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
2010/07/25 09:45:25.0921 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
2010/07/25 09:45:26.0828 d347bus (5776322f93cdb91086111f5ffbfda2a0) C:\WINDOWS\system32\DRIVERS\d347bus.sys
2010/07/25 09:45:27.0046 d347prt (b49f79ace459763f4e0380071be9cb45) C:\WINDOWS\system32\Drivers\d347prt.sys
2010/07/25 09:45:27.0687 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
2010/07/25 09:45:28.0156 dmboot (80008bd0c19d97b0b3f4d1d9cbf190a8) C:\WINDOWS\system32\drivers\dmboot.sys
2010/07/25 09:45:28.0671 dmio (41862731f82be80f0cfba5d0da36b683) C:\WINDOWS\system32\drivers\dmio.sys
2010/07/25 09:45:28.0890 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
2010/07/25 09:45:29.0125 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
2010/07/25 09:45:29.0593 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
2010/07/25 09:45:29.0828 EIO (0daf3544804650526751c478aeccce63) C:\WINDOWS\system32\drivers\EIO.sys
2010/07/25 09:45:29.0921 F-Secure Filter (704cacd94794169efa2e43e913746591) C:\Program\F-Secure\Anti-Virus\Win2K\FSfilter.sys
2010/07/25 09:45:30.0000 F-Secure Gatekeeper (1658c72b6c96f3dcaa70d41bcf0b1b43) C:\Program\F-Secure\Anti-Virus\Win2K\FSgk.sys
2010/07/25 09:45:30.0078 F-Secure Recognizer (bb1daf5bcb2c6e4f22bb4be87e3f73aa) C:\Program\F-Secure\Anti-Virus\Win2K\FSrec.sys
2010/07/25 09:45:30.0375 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
2010/07/25 09:45:30.0656 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
2010/07/25 09:45:30.0906 FETNDIS (e9648254056bce81a85380c0c3647dc4) C:\WINDOWS\system32\DRIVERS\fetnd5.sys
2010/07/25 09:45:31.0156 FETNDISB (a583bc166495b07f704533754ce29cbd) C:\WINDOWS\system32\DRIVERS\fetnd5b.sys
2010/07/25 09:45:31.0406 Fips (b66ddb75642f6722468707840c67a394) C:\WINDOWS\system32\drivers\Fips.sys
2010/07/25 09:45:31.0656 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
2010/07/25 09:45:31.0937 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
2010/07/25 09:45:32.0281 FSpm (7f1c5075b89fcdd3cdc371f10ce15322) C:\Program\F-Secure\Common\FSPM.SYS
2010/07/25 09:45:32.0546 fssfltr (c6ee3a87fe609d3e1db9dbd072a248de) C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys
2010/07/25 09:45:32.0812 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
2010/07/25 09:45:33.0109 Ftdisk (45fc410cfe68ff036ad232a141e69c19) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
2010/07/25 09:45:33.0531 gagp30kx (3a74c423cf6bcca6982715878f450a3b) C:\WINDOWS\system32\DRIVERS\gagp30kx.sys
2010/07/25 09:45:33.0796 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
2010/07/25 09:45:34.0109 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
2010/07/25 09:45:34.0515 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
2010/07/25 09:45:34.0953 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
2010/07/25 09:45:35.0546 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
2010/07/25 09:45:36.0218 i8042prt (82e56cd09b2ce1edec3fba9111c7ee3a) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
2010/07/25 09:45:36.0484 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
2010/07/25 09:45:38.0218 IntcAzAudAddService (71ae838a88b07268d732f596fc17ced5) C:\WINDOWS\system32\drivers\RtkHDAud.sys
2010/07/25 09:45:38.0796 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
2010/07/25 09:45:39.0078 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
2010/07/25 09:45:39.0328 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
2010/07/25 09:45:39.0656 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
2010/07/25 09:45:39.0906 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
2010/07/25 09:45:40.0156 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
2010/07/25 09:45:40.0390 isapnp (48f97c77daf8811598cfae21368eacb6) C:\WINDOWS\system32\DRIVERS\isapnp.sys
2010/07/25 09:45:40.0625 Kbdclass (d655ca94c8e2e0223c1bc28bcd95723a) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
2010/07/25 09:45:40.0890 klmd24 (6485ad0a17a0d6286b4d44c652adabb2) C:\WINDOWS\system32\drivers\klmd.sys
2010/07/25 09:45:41.0171 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
2010/07/25 09:45:41.0484 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
2010/07/25 09:45:41.0937 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
2010/07/25 09:45:42.0203 Modem (42ce19726d9c410dff75d3ff1cc79db2) C:\WINDOWS\system32\drivers\Modem.sys
2010/07/25 09:45:42.0437 Mouclass (e0c4c36573bcf0c0d2a1578caa791f7d) C:\WINDOWS\system32\DRIVERS\mouclass.sys
2010/07/25 09:45:42.0703 mouhid (98e474ecf11f1db62fb072157a95ea83) C:\WINDOWS\system32\DRIVERS\mouhid.sys
2010/07/25 09:45:42.0937 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
2010/07/25 09:45:43.0406 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
2010/07/25 09:45:43.0781 MRxSmb (f3aefb11abc521122b67095044169e98) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
2010/07/25 09:45:44.0000 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
2010/07/25 09:45:44.0250 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
2010/07/25 09:45:44.0515 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2010/07/25 09:45:44.0734 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
2010/07/25 09:45:44.0968 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
2010/07/25 09:45:45.0187 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
2010/07/25 09:45:45.0453 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys
2010/07/25 09:45:45.0765 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
2010/07/25 09:45:46.0062 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
2010/07/25 09:45:46.0312 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
2010/07/25 09:45:46.0546 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
2010/07/25 09:45:46.0812 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
2010/07/25 09:45:47.0109 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
2010/07/25 09:45:47.0375 NDProxy (6215023940cfd3702b46abc304e1d45a) C:\WINDOWS\system32\drivers\NDProxy.sys
2010/07/25 09:45:47.0625 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
2010/07/25 09:45:47.0890 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
2010/07/25 09:45:48.0312 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
2010/07/25 09:45:48.0703 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
2010/07/25 09:45:48.0937 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
2010/07/25 09:45:51.0000 nv (70cb8915895ccb92ddf23ce890c4f5be) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
2010/07/25 09:45:53.0062 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
2010/07/25 09:45:53.0296 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
2010/07/25 09:45:53.0562 NwlnkIpx (8b8b1be2dba4025da6786c645f77f123) C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys
2010/07/25 09:45:53.0828 NwlnkNb (56d34a67c05e94e16377c60609741ff8) C:\WINDOWS\system32\DRIVERS\nwlnknb.sys
2010/07/25 09:45:54.0078 NwlnkSpx (c0bb7d1615e1acbdc99757f6ceaf8cf0) C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys
2010/07/25 09:45:54.0359 Parport (19e28ed86e7244d76fda792c2810188e) C:\WINDOWS\system32\DRIVERS\parport.sys
2010/07/25 09:45:54.0609 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
2010/07/25 09:45:54.0859 ParVdm (5cf71e14a108c492c1fb07543d579af5) C:\WINDOWS\system32\drivers\ParVdm.sys
2010/07/25 09:45:55.0109 PCI (8a185f0112cf5b42ff1aaff31b8b3091) C:\WINDOWS\system32\DRIVERS\pci.sys
2010/07/25 09:45:55.0765 Pcmcia (904053aa6e251c77cf85371ce644cfd7) C:\WINDOWS\system32\drivers\Pcmcia.sys
2010/07/25 09:45:57.0281 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
2010/07/25 09:45:57.0531 Processor (992e4b2a91e6a2f3d21de89b9273353a) C:\WINDOWS\system32\DRIVERS\processr.sys
2010/07/25 09:45:57.0796 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
2010/07/25 09:45:58.0046 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
2010/07/25 09:45:58.0281 PxHelp20 (d86b4a68565e444d76457f14172c875a) C:\WINDOWS\system32\Drivers\PxHelp20.sys
2010/07/25 09:45:59.0578 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
2010/07/25 09:45:59.0843 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
2010/07/25 09:46:00.0093 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
2010/07/25 09:46:00.0312 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
2010/07/25 09:46:00.0609 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
2010/07/25 09:46:00.0890 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
2010/07/25 09:46:01.0171 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
2010/07/25 09:46:01.0515 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
2010/07/25 09:46:01.0796 redbook (97130d37842819fa39fd5f1e90a5d676) C:\WINDOWS\system32\DRIVERS\redbook.sys
2010/07/25 09:46:02.0078 RFCOMM (851c30df2807fcfa21e4c681a7d6440e) C:\WINDOWS\system32\DRIVERS\rfcomm.sys
2010/07/25 09:46:02.0343 SCREAMINGBDRIVER (a643d6df1b7546256b11fb5d6b5d1375) C:\WINDOWS\system32\drivers\ScreamingBAudio.sys
2010/07/25 09:46:02.0609 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
2010/07/25 09:46:02.0859 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
2010/07/25 09:46:03.0109 Serial (f7d35464062edc08909e568bcd8ae77d) C:\WINDOWS\system32\DRIVERS\serial.sys
2010/07/25 09:46:03.0359 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
2010/07/25 09:46:03.0796 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
2010/07/25 09:46:04.0125 snpstd (7452187a8f1ac46ce4f21be616e8d5f3) C:\WINDOWS\system32\DRIVERS\snpstd.sys
2010/07/25 09:46:04.0656 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
2010/07/25 09:46:04.0906 sr (1193ef00869f6367367e6e7cb96be325) C:\WINDOWS\system32\DRIVERS\sr.sys
2010/07/25 09:46:05.0250 Srv (89220b427890aa1dffd1a02648ae51c3) C:\WINDOWS\system32\DRIVERS\srv.sys
2010/07/25 09:46:05.0531 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
2010/07/25 09:46:05.0765 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
2010/07/25 09:46:06.0000 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
2010/07/25 09:46:07.0093 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
2010/07/25 09:46:07.0468 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
2010/07/25 09:46:07.0796 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
2010/07/25 09:46:08.0031 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
2010/07/25 09:46:08.0281 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
2010/07/25 09:46:08.0750 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
2010/07/25 09:46:09.0312 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
2010/07/25 09:46:09.0703 USBAAPL (4b8a9c16b6d9258ed99c512aecb8c555) C:\WINDOWS\system32\Drivers\usbaapl.sys
2010/07/25 09:46:09.0968 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
2010/07/25 09:46:10.0234 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
2010/07/25 09:46:10.0484 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
2010/07/25 09:46:10.0750 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
2010/07/25 09:46:11.0015 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
2010/07/25 09:46:11.0250 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
2010/07/25 09:46:11.0500 VCSVADHWSer (b2abab4ca46bad182e27763dc19c780f) C:\WINDOWS\system32\DRIVERS\vcsvad.sys
2010/07/25 09:46:11.0734 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
2010/07/25 09:46:11.0968 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys
2010/07/25 09:46:12.0218 viamraid (fbf18f9f5fb852c2976723587b44f346) C:\WINDOWS\system32\DRIVERS\viamraid.sys
2010/07/25 09:46:12.0453 VolSnap (57187ec04878147e1f4f2d9224b12205) C:\WINDOWS\system32\drivers\VolSnap.sys
2010/07/25 09:46:12.0687 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
2010/07/25 09:46:13.0171 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
2010/07/25 09:46:13.0437 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
2010/07/25 09:46:13.0703 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
2010/07/25 09:46:13.0953 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
2010/07/25 09:46:14.0203 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
2010/07/25 09:46:14.0281 ================================================================================
2010/07/25 09:46:14.0281 Scan finished
2010/07/25 09:46:14.0281 ================================================================================
2010/07/25 09:46:58.0859 Deinitialize success

ken545
2010-07-25, 13:14
Really not sure on daemon.dll, it may have been infected, nowadays malware writers are infecting anything they can. Why don't you just redownload the program and install it.

How are things running now ?

MrBugger
2010-07-25, 13:31
I've the installed one on a other server so i will do that.

Things are alot better now thanks to you. But i still experince that the computer is kind of slow. Can i scan with any tool?

Br

ken545
2010-07-25, 14:34
Try running this cleaner again


Download TFC (http://oldtimer.geekstogo.com/TFC.exe) to your desktop

Close any open windows.
Double click the TFC icon to run the program
TFC will close all open programs itself in order to run,
Click the Start button to begin the process.
Allow TFC to run uninterrupted.
The program should not take long to finish it's job
Once its finished it should automatically reboot your machine,
if it doesn't, manually reboot to ensure a complete clean




We just do malware removal in this forum, why dont you post here at out sister site , tell them you posted here and we cleaned a lot of infections off your system but that your computer is slow and they can go through start up programs and such that may be slowing things down.

http://forums.whatthetech.com/index.php?showforum=119





Open OTL and click on the cleanup feature and it will remove all the tools we used to clean your machine





How did I get infected in the first place ?
Read these links and find out how to prevent getting infected again.
Tutorial for System Restore (http://www.bleepingcomputer.com/tutorials/tutorial56.html) <-- Do this first to prevent yourself from being reinfected.
WhattheTech (http://forums.whatthetech.com/So_how_did_I_get_infected_in_the_first_place_t57817.html)
Grinler BleepingComputer (http://www.bleepingcomputer.com/forums/topic2520.html)
GeeksTo Go (http://www.geekstogo.com/forum/index.php?autocom=custom&page=How_did_I)
Dslreports (http://www.dslreports.com/faq/10002)





Keep in mind if you install some of these programs. Only ONE Anti Virus and only ONE Firewall is recommended, more is overkill and can cause you problems. You can install all the Spyware programs I have listed without any problems. If you install Spyware Blaster and Spyware Guard, they will conflict with the TeaTimer in Spybot , you can still install Spybot Search and Destroy but do not enable the TeaTimer .


Here are some free programs to install, all free and highly regarded by the fine people in the Malware Removal Community

Spybot Search and Destroy 1.6 (http://www.safer-networking.org/en/download/)
Check for Updates/ Immunize and run a Full System Scan on a regular basis. If you install Spyware Blaster ( Recommended ) then do not enable the TeaTimer in Spybot Search and Destroy.

Spyware Blaster (http://www.javacoolsoftware.com/spywareblaster.html) It will prevent most spyware from ever being installed. No scan to run, just update about once a week and enable all protection.

Spyware Guard (http://www.javacoolsoftware.com/spywareguard.html) It offers realtime protection from spyware installation attempts, again, no scan to run, just install it and let it do its thing.

IE-Spyad (http://www.pcworld.com/downloads/file/fid,23332-order,1-page,1-c,antispywaretools/description.html)
IE-Spyad places over 6000 web sites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (cookies etc) from the sites listed, although you will still be able to connect to the sites.

Firefox 3 (http://www.mozilla.org/products/firefox/) It has more features and is a lot more secure than IE. It is a very easy and painless download and install, it will no way interfere with IE, you can use them both.



Safe Surfn
Ken

MrBugger
2010-07-25, 14:45
Hi Ken!

Before i start the removing phase i need your help how to scan USB sticks that my daughter has been using on the infected PC.

Also if you recommend which scanner to use to check my other machines för malware/virus

Br

ken545
2010-07-25, 15:33
We use this one


Please download Flash_Disinfector.exe (http://download.bleepingcomputer.com/sUBs/Flash_Disinfector.exe) by sUBs and save it to your desktop:


Double-click Flash_Disinfector.exe to run it.
Follow any prompts that may appear.
Wait until the program has finished scanning, then please exit the program.
The tool may ask you to insert your flash drive, or other removable drives. Please do so and allow the tool to clean it up as well.


Please restart your computer.



What I will do is close this thread and you can start a new topic for the other computer, be sure to post in the title that it is your second computer, if and when I see it I will pick it up , we have a fine staff so if I miss it someone else will get it. Start the topic by posting a DDS log

MrBugger
2010-07-25, 16:06
Thanks again for all the help. I'll post a new one asp

Br

ken545
2010-07-25, 16:22
Your most welcome :)