Page 2 of 4 FirstFirst 1234 LastLast
Results 11 to 20 of 35

Thread: Picked up a virus, can't run Spybot

  1. #11
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Good

    Looking over your log, it seems you don't have any evidence of an anti-virus software.

    Anti-virus software are programs that detect, cleanse, and erase harmful virus files on a computer, Web server, or network. Unchecked, virus files can unintentionally be forwarded to others, including trading partners and thereby spreading infection. Because new viruses regularly emerge, anti-virus software should be updated frequently. Anti-virus software can scan the computer memory and disk drives for malicious code. They can alert the user if a virus is present, and will clean, delete (or quarantine) infected files or directories. Please download a free anti-virus software from one these excellent vendors NOW:

    1) Antivir PersonalEdition Classic - Free anti-virus software for Windows. Free support.
    2) avast! 4 Home Edition - Anti-virus program for Windows. The home edition is freeware for noncommercial users.
    3) AVG Anti-Virus Free Edition - Free edition of the AVG anti-virus program for Windows.

    You should run only one antivirus program at a time. Having more than one antivirus program active in memory uses additional resources and results in program conflicts and false virus alerts.

    Please post a fresh hijackthis log afterwards.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  2. #12
    Junior Member
    Join Date
    Aug 2009
    Posts
    19

    Default

    Okay, Avast is installed. The scan it performed on reboot after I installed it didn't find any infected files.

    I didn't let Spybot fix any of them but I performed a scan in Spybot and it found several things. I have attached a screen shot:



    -Greg

    Hijackthis log follows:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 3:39:35 PM, on 8/12/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\msb.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\SearchIndexer.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://eeepc.asus.com/global
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/betapit/PCPitStop.CAB
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/micr...?1230231671609
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/micr...?1230231648859
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{C38A5413-F50B-4F03-BB3E-825B2A29DC47}: NameServer = 66.174.95.44 69.78.96.14
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = tabs.toshiba.com
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = tabs.toshiba.com
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe

    --
    End of file - 5677 bytes

  3. #13
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Please post entire spybot report
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  4. #14
    Junior Member
    Join Date
    Aug 2009
    Posts
    19

    Default

    Hi,

    Here's a bit of an update. I updated Avast and let it perform a full system scan. It scanned forever and found quite a few things this time. I've been letting Avast delete anything it finds, should I be sending them to the chest?

    I'll get that spybot log up shortly

    -Greg

    Avast warning.txt log follows:

    8/12/2009 6:48:51 PM 1250117331 Greg 616 Sign of "JS:Pdfka-MQ [Trj]" has been found in "C:\Documents and Settings\Greg\Local Settings\Temporary Internet Files\Content.IE5\Q6E6QCF0\README[1].pdf" file.
    8/12/2009 7:02:06 PM 1250118126 Greg 616 Sign of "JS:Pdfka-MQ [Trj]" has been found in "C:\Documents and Settings\Greg\Local Settings\Temporary Internet Files\Content.IE5\29ATOVMJ\howto[1].pdf" file.
    8/12/2009 8:04:04 PM 1250121844 Greg 616 Sign of "JS:Pdfka-MQ [Trj]" has been found in "C:\Documents and Settings\Greg\Local Settings\Temporary Internet Files\Content.IE5\Q6E6QCF0\README[2].pdf" file.
    8/12/2009 9:00:58 PM 1250125258 Greg 616 Sign of "JS:Pdfka-MQ [Trj]" has been found in "C:\Documents and Settings\Greg\Local Settings\Temporary Internet Files\Content.IE5\Q6E6QCF0\README[1].pdf" file.
    8/12/2009 9:22:57 PM 1250126577 Greg 216 Sign of "JS:Pdfka-MQ [Trj]" has been found in "C:\Documents and Settings\Greg\Local Settings\Temporary Internet Files\Content.IE5\29ATOVMJ\howto[1].pdf" file.
    8/12/2009 9:24:15 PM 1250126655 Greg 216 Sign of "JS:Pdfka-MQ [Trj]" has been found in "C:\Documents and Settings\Greg\Local Settings\Temporary Internet Files\Content.IE5\Q6E6QCF0\README[1].pdf" file.
    8/12/2009 10:15:07 PM 1250129707 Greg 216 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Qoobox\Quarantine\C\Documents and Settings\Greg\Start Menu\Programs\Startup\rncsys32.exe.vir" file.
    8/12/2009 10:15:11 PM 1250129711 Greg 216 Sign of "Win32:Alureon-CM [Rtk]" has been found in "C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\SKYNETxoqgriwq.sys.vir" file.
    8/12/2009 10:15:11 PM 1250129711 Greg 216 Sign of "Win32:Alureon-CJ [Rtk]" has been found in "C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\UACfqxdpbdvym.sys.vir" file.
    8/12/2009 10:15:11 PM 1250129711 Greg 216 Sign of "Win32:FakeAV-NP [Trj]" has been found in "C:\Qoobox\Quarantine\C\WINDOWS\system32\msxml71.dll.vir" file.
    8/12/2009 10:15:11 PM 1250129711 Greg 216 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Qoobox\Quarantine\C\WINDOWS\system32\net.net.vir" file.
    8/12/2009 10:15:11 PM 1250129711 Greg 216 Sign of "Win32:Alureon-CM [Rtk]" has been found in "C:\Qoobox\Quarantine\C\WINDOWS\system32\SKYNETqhwlxelh.dll.vir" file.
    8/12/2009 10:15:11 PM 1250129711 Greg 216 Sign of "Win32:Alureon-CM [Rtk]" has been found in "C:\Qoobox\Quarantine\C\WINDOWS\system32\SKYNETvmupjuyt.dll.vir" file.
    8/12/2009 10:15:12 PM 1250129712 Greg 216 Sign of "Win32:Fasec [Trj]" has been found in "C:\Qoobox\Quarantine\C\WINDOWS\system32\UACjgwnshhssq.dll.vir" file.
    8/12/2009 10:15:12 PM 1250129712 Greg 216 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Qoobox\Quarantine\C\WINDOWS\system32\UACkgxwjkvvwr.dll.vir" file.
    8/12/2009 10:15:12 PM 1250129712 Greg 216 Sign of "Win32:Fasec [Trj]" has been found in "C:\Qoobox\Quarantine\C\WINDOWS\system32\UACoboxhllilr.dll.vir" file.
    8/12/2009 10:15:12 PM 1250129712 Greg 216 Sign of "Win32:Fasec [Trj]" has been found in "C:\Qoobox\Quarantine\C\WINDOWS\system32\UACwwsppridmo.dll.vir" file.
    8/12/2009 10:15:15 PM 1250129715 Greg 216 Sign of "Win32:Alureon-CM [Rtk]" has been found in "C:\System Volume Information\_restore{70FD1DB3-E30F-48EC-ABEA-2DE81F03A8C6}\RP210\A0014643.sys" file.
    8/12/2009 10:15:15 PM 1250129715 Greg 216 Sign of "Win32:Alureon-CM [Rtk]" has been found in "C:\System Volume Information\_restore{70FD1DB3-E30F-48EC-ABEA-2DE81F03A8C6}\RP210\A0014644.dll" file.
    8/12/2009 10:15:15 PM 1250129715 Greg 216 Sign of "Win32:Alureon-CM [Rtk]" has been found in "C:\System Volume Information\_restore{70FD1DB3-E30F-48EC-ABEA-2DE81F03A8C6}\RP210\A0014645.dll" file.
    8/12/2009 10:15:15 PM 1250129715 Greg 216 Sign of "Win32:Alureon-CJ [Rtk]" has been found in "C:\System Volume Information\_restore{70FD1DB3-E30F-48EC-ABEA-2DE81F03A8C6}\RP210\A0014646.sys" file.
    8/12/2009 10:15:15 PM 1250129715 Greg 216 Sign of "Win32:Fasec [Trj]" has been found in "C:\System Volume Information\_restore{70FD1DB3-E30F-48EC-ABEA-2DE81F03A8C6}\RP210\A0014647.dll" file.
    8/12/2009 10:15:15 PM 1250129715 Greg 216 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{70FD1DB3-E30F-48EC-ABEA-2DE81F03A8C6}\RP210\A0014649.dll" file.
    8/12/2009 10:15:15 PM 1250129715 Greg 216 Sign of "Win32:Fasec [Trj]" has been found in "C:\System Volume Information\_restore{70FD1DB3-E30F-48EC-ABEA-2DE81F03A8C6}\RP210\A0014650.dll" file.
    8/12/2009 10:15:15 PM 1250129715 Greg 216 Sign of "Win32:Fasec [Trj]" has been found in "C:\System Volume Information\_restore{70FD1DB3-E30F-48EC-ABEA-2DE81F03A8C6}\RP210\A0014651.dll" file.
    8/12/2009 10:15:16 PM 1250129716 Greg 216 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{70FD1DB3-E30F-48EC-ABEA-2DE81F03A8C6}\RP211\A0014681.exe" file.
    8/12/2009 10:15:17 PM 1250129717 Greg 216 Sign of "Win32:FakeAV-NP [Trj]" has been found in "C:\System Volume Information\_restore{70FD1DB3-E30F-48EC-ABEA-2DE81F03A8C6}\RP211\A0014683.dll" file.
    8/12/2009 10:47:26 PM 1250131646 Greg 216 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\pss\rncsys32.exeStartup" file.
    8/13/2009 3:03:58 AM 1250147038 Greg 1912 Sign of "JS:Obfuscated-CV [Trj]" has been found in "C:\Documents and Settings\Greg\Local Settings\Temporary Internet Files\Content.IE5\TTF66952\in[1].htm" file.

  5. #15
    Junior Member
    Join Date
    Aug 2009
    Posts
    19

    Default

    and here's the Spybot report:


    --- Search result list ---
    Fraud.AVCare: [SBI $2A46F590] Settings (Registry key, nothing done)
    HKEY_LOCAL_MACHINE\Software\AV Care

    Fraud.AVCare: [SBI $6A389111] Executable (File, nothing done)
    C:\Program Files\AV Care\AVCare.exe
    Properties.size=1765376
    Properties.md5=1C0921380E8D9A1828CAB0708683A067
    Properties.filedate=1249310492
    Properties.filedatetext=2009-08-03 10:41:32

    Fraud.AVCare: [SBI $242142C8] Picture (File, nothing done)
    C:\Program Files\AV Care\avc.ico
    Properties.size=1150
    Properties.md5=51D3D99DDFACAFA55A4E8FC39D4AB409
    Properties.filedate=1246851840
    Properties.filedatetext=2009-07-05 23:44:00

    Fraud.AVCare: [SBI $5836260B] Data (File, nothing done)
    C:\Program Files\AV Care\AVCare.dat
    Properties.size=597
    Properties.md5=39DBF1F3B4EFB9C5A147975B88AA42F3
    Properties.filedate=1249869619
    Properties.filedatetext=2009-08-09 22:00:19

    Fraud.AVCare: [SBI $DB735B46] Configuration file (File, nothing done)
    C:\Program Files\AV Care\AVCare.ini
    Properties.size=119
    Properties.md5=4BFFC12DA6D4A492F5D9D20C021CCE71
    Properties.filedate=1249869910
    Properties.filedatetext=2009-08-09 22:05:10

    Fraud.AVCare: [SBI $F63F5B53] Executable (File, nothing done)
    C:\Program Files\AV Care\PP.exe
    Properties.size=229376
    Properties.md5=74B914E42999CB4E4464BDD899BD2F19
    Properties.filedate=1249308606
    Properties.filedatetext=2009-08-03 10:10:06

    Fraud.AVCare: [SBI $45EA1444] Executable (File, nothing done)
    C:\Program Files\AV Care\Uninstall.exe
    Properties.size=54140
    Properties.md5=9489815E2B9955DAD12D2929412192A4
    Properties.filedate=1249869588
    Properties.filedatetext=2009-08-09 21:59:48

    Fraud.AVCare: [SBI $11939BFB] Desktop link (File, nothing done)
    C:\Documents and Settings\Greg\Desktop\AV Care.lnk
    Properties.size=663
    Properties.md5=5D65D6D3ACE2C20AABBF37EF041993FC
    Properties.filedate=1249869588
    Properties.filedatetext=2009-08-09 21:59:47

    Fraud.AVCare: [SBI $DBABB708] Link (File, nothing done)
    C:\Documents and Settings\Greg\Start Menu\Programs\AV Care\AV Care.lnk
    Properties.size=675
    Properties.md5=8C10A77EE9B195088310BB3FA94A9CCF
    Properties.filedate=1249869588
    Properties.filedatetext=2009-08-09 21:59:47

    Fraud.AVCare: [SBI $B92E4C17] Program directory (Directory, nothing done)
    C:\Documents and Settings\Greg\Start Menu\Programs\AV Care\

    Fraud.AVCare: [SBI $BD3495D0] Program directory (Directory, nothing done)
    C:\Program Files\AV Care\

    Win32.FraudLoad.edt: [SBI $BBEEDD02] Data (File, nothing done)
    C:\WINDOWS\Tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job
    Properties.size=274
    Properties.md5=F94AB60D7136D1E81D91F2FB86453F40
    Properties.filedate=1250147957
    Properties.filedatetext=2009-08-13 03:19:17

    Win32.FraudLoad.edt: [SBI $E205C221] Data (File, nothing done)
    C:\WINDOWS\Tasks\{7B02EF0B-A410-4938-8480-9BA26420A627}.job
    Properties.size=238
    Properties.md5=87F055A3DBA003316D2E346F833DB4C6
    Properties.filedate=1250147986
    Properties.filedatetext=2009-08-13 03:19:46

    Right Media: Tracking cookie (Internet Explorer: Greg) (Cookie, nothing done)



    --- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---

    2009-01-26 blindman.exe (1.0.0.8)
    2009-01-26 SDFiles.exe (1.6.1.7)
    2009-01-26 SDMain.exe (1.0.0.6)
    2009-01-26 SDShred.exe (1.0.2.5)
    2009-01-26 SDUpdate.exe (1.6.0.12)
    2008-07-07 SDWinSec.exe (1.0.0.12)
    2009-01-26 SpybotSD.exe (1.6.2.46)
    2009-03-05 TeaTimer.exe (1.6.6.32)
    2009-04-07 unins000.exe (51.49.0.0)
    2009-01-26 Update.exe (1.6.0.7)
    2009-07-28 advcheck.dll (1.6.3.17)
    2007-04-02 aports.dll (2.1.0.0)
    2008-06-14 DelZip179.dll (1.79.11.1)
    2009-01-26 SDHelper.dll (1.6.2.14)
    2008-06-19 sqlite3.dll
    2009-01-26 Tools.dll (2.1.6.10)
    2009-01-16 UninsSrv.dll (1.0.0.0)
    2009-05-19 Includes\Adware.sbi (*)
    2009-07-30 Includes\AdwareC.sbi (*)
    2009-01-22 Includes\Cookies.sbi (*)
    2009-05-19 Includes\Dialer.sbi (*)
    2009-08-04 Includes\DialerC.sbi (*)
    2009-01-22 Includes\HeavyDuty.sbi (*)
    2009-05-26 Includes\Hijackers.sbi (*)
    2009-08-04 Includes\HijackersC.sbi (*)
    2009-06-23 Includes\Keyloggers.sbi (*)
    2009-07-30 Includes\KeyloggersC.sbi (*)
    2004-11-29 Includes\LSP.sbi (*)
    2009-08-11 Includes\Malware.sbi (*)
    2009-08-11 Includes\MalwareC.sbi (*)
    2009-03-25 Includes\PUPS.sbi (*)
    2009-08-06 Includes\PUPSC.sbi (*)
    2009-01-22 Includes\Revision.sbi (*)
    2009-01-13 Includes\Security.sbi (*)
    2009-07-30 Includes\SecurityC.sbi (*)
    2008-06-03 Includes\Spybots.sbi (*)
    2008-06-03 Includes\SpybotsC.sbi (*)
    2009-04-07 Includes\Spyware.sbi (*)
    2009-08-11 Includes\SpywareC.sbi (*)
    2009-06-08 Includes\Tracks.uti
    2009-08-11 Includes\Trojans.sbi (*)
    2009-08-12 Includes\TrojansC.sbi (*)
    2008-03-04 Plugins\Chai.dll
    2008-03-05 Plugins\Fennel.dll
    2008-02-26 Plugins\Mate.dll
    2007-12-24 Plugins\TCPIPAddress.dll



    --- System information ---
    Windows XP (Build: 2600) Service Pack 3 (5.1.2600)
    / .NETFramework / 1.1: Microsoft .NET Framework 1.1 Hotfix (KB928366)
    / .NETFramework / 1.1: Microsoft .NET Framework 1.1 Hotfix (KB929729)
    / .NETFramework / 1.1: Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
    / MSXML4SP2: Security update for MSXML4 SP2 (KB954430)
    / Windows / SP1: Microsoft Internationalized Domain Names Mitigation APIs
    / Windows / SP1: Microsoft National Language Support Downlevel APIs
    / Windows Media Format 11 SDK: Hotfix for Windows Media Format 11 SDK (KB929399)
    / Windows Media Player: Security Update for Windows Media Player (KB952069)
    / Windows Media Player: Security Update for Windows Media Player (KB973540)
    / Windows Media Player 11: Security Update for Windows Media Player 11 (KB936782)
    / Windows Media Player 11: Hotfix for Windows Media Player 11 (KB939683)
    / Windows Media Player 11: Security Update for Windows Media Player 11 (KB954154)
    / Windows Media Player 11: Critical Update for Windows Media Player 11 (KB959772)
    / Windows XP: Security Update for Windows XP (KB941569)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB938127-v2)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB956390)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB958215)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB960714)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB961260)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB963027)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB969897)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 8 (KB969897)
    / Windows XP / SP0: Update for Windows Internet Explorer 8 (KB971930)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 8 (KB972260)
    / Windows XP / SP10: Microsoft Compression Client Pack 1.0 for Windows XP
    / Windows XP / SP3: Update for Windows XP (KB898461)
    / Windows XP / SP4: Hotfix for Windows XP (KB915800-v4)
    / Windows XP / SP4: Security Update for Windows XP (KB923561)
    / Windows XP / SP4: Security Update for Windows XP (KB938464)
    / Windows XP / SP4: Update for Windows XP (KB942763)
    / Windows XP / SP4: Security Update for Windows XP (KB946648)
    / Windows XP / SP4: Security Update for Windows XP (KB950759)
    / Windows XP / SP4: Security Update for Windows XP (KB950760)
    / Windows XP / SP4: Security Update for Windows XP (KB950762)
    / Windows XP / SP4: Security Update for Windows XP (KB950974)
    / Windows XP / SP4: Security Update for Windows XP (KB951066)
    / Windows XP / SP4: Update for Windows XP (KB951072-v2)
    / Windows XP / SP4: Security Update for Windows XP (KB951376)
    / Windows XP / SP4: Security Update for Windows XP (KB951376-v2)
    / Windows XP / SP4: Update for Windows XP (KB951618-v2)
    / Windows XP / SP4: Security Update for Windows XP (KB951698)
    / Windows XP / SP4: Security Update for Windows XP (KB951748)
    / Windows XP / SP4: Update for Windows XP (KB951978)
    / Windows XP / SP4: Security Update for Windows XP (KB952004)
    / Windows XP / SP4: Hotfix for Windows XP (KB952287)
    / Windows XP / SP4: Security Update for Windows XP (KB952954)
    / Windows XP / SP4: Update for Windows XP (KB953356)
    / Windows XP / SP4: Security Update for Windows XP (KB953838)
    / Windows XP / SP4: Security Update for Windows XP (KB953839)
    / Windows XP / SP4: Security Update for Windows XP (KB954211)
    / Windows XP / SP4: Security Update for Windows XP (KB954459)
    / Windows XP / SP4: Hotfix for Windows XP (KB954550-v5)
    / Windows XP / SP4: Security Update for Windows XP (KB954600)
    / Windows XP / SP4: Security Update for Windows XP (KB955069)
    / Windows XP / SP4: Update for Windows XP (KB955839)
    / Windows XP / SP4: Security Update for Windows XP (KB956391)
    / Windows XP / SP4: Security Update for Windows XP (KB956572)
    / Windows XP / SP4: Security Update for Windows XP (KB956744)
    / Windows XP / SP4: Security Update for Windows XP (KB956802)
    / Windows XP / SP4: Security Update for Windows XP (KB956803)
    / Windows XP / SP4: Security Update for Windows XP (KB956841)
    / Windows XP / SP4: Security Update for Windows XP (KB957095)
    / Windows XP / SP4: Security Update for Windows XP (KB957097)
    / Windows XP / SP4: Security Update for Windows XP (KB958644)
    / Windows XP / SP4: Security Update for Windows XP (KB958687)
    / Windows XP / SP4: Security Update for Windows XP (KB958690)
    / Windows XP / SP4: Security Update for Windows XP (KB959426)
    / Windows XP / SP4: Security Update for Windows XP (KB960225)
    / Windows XP / SP4: Security Update for Windows XP (KB960715)
    / Windows XP / SP4: Security Update for Windows XP (KB960803)
    / Windows XP / SP4: Security Update for Windows XP (KB960859)
    / Windows XP / SP4: Hotfix for Windows XP (KB961118)
    / Windows XP / SP4: Security Update for Windows XP (KB961371)
    / Windows XP / SP4: Security Update for Windows XP (KB961373)
    / Windows XP / SP4: Security Update for Windows XP (KB961501)
    / Windows XP / SP4: Update for Windows XP (KB967715)
    / Windows XP / SP4: Security Update for Windows XP (KB968537)
    / Windows XP / SP4: Security Update for Windows XP (KB969898)
    / Windows XP / SP4: Security Update for Windows XP (KB970238)
    / Windows XP / SP4: Security Update for Windows XP (KB971557)
    / Windows XP / SP4: Security Update for Windows XP (KB971633)
    / Windows XP / SP4: Security Update for Windows XP (KB971657)
    / Windows XP / SP4: Security Update for Windows XP (KB973346)
    / Windows XP / SP4: Security Update for Windows XP (KB973354)
    / Windows XP / SP4: Security Update for Windows XP (KB973507)
    / Windows XP / SP4: Update for Windows XP (KB973815)
    / Windows XP / SP4: Security Update for Windows XP (KB973869)


    --- Startup entries list ---
    Located: HK_LM:Run, avast!
    command: C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    file: C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    size: 81000
    MD5: FC242DBD786557AC641726DC5C13F060

    Located: HK_CU:Run, ctfmon.exe
    where: S-1-5-21-371554582-1491889555-182000295-1006...
    command: C:\WINDOWS\system32\ctfmon.exe
    file: C:\WINDOWS\system32\ctfmon.exe
    size: 15360
    MD5: 5F1D5F88303D4A4DBC8E5F97BA967CC3

    Located: Startup (disabled), SuperHybridEngine (DISABLED)
    command: C:\PROGRA~1\ASUS\EeePC\SUPERH~1\SUPERH~1.EXE
    file: C:\PROGRA~1\ASUS\EeePC\SUPERH~1\SUPERH~1.EXE
    size: 311296
    MD5: 52ADDED5C967C963EE0A2A8DBD0EF4DA

    Located: Startup (disabled), VPN Client (DISABLED)
    command: C:\WINDOWS\Installer\{3E5562ED-69AB-4CEC-91E2-64E18EC5ACC6}\Icon3E5562ED7.ico -user_logon
    file: C:\WINDOWS\Installer\{3E5562ED-69AB-4CEC-91E2-64E18EC5ACC6}\Icon3E5562ED7.ico -user_logon
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: Startup (disabled), Windows Search (DISABLED)
    command: C:\PROGRA~1\WI459E~1\WINDOW~1.EXE /startup
    file: C:\PROGRA~1\WI459E~1\WINDOW~1.EXE
    size: 123904
    MD5: B5C9F63C01FCFEC3F64EC6A0940A1825

    Located: Startup (disabled), ERUNT AutoBackup (DISABLED)
    command: C:\PROGRA~1\ERUNT\AUTOBACK.EXE %SystemRoot%\ERDNT\AutoBackup\#Date# /noconfirmdelete /noprogresswindow
    file: C:\PROGRA~1\ERUNT\AUTOBACK.EXE
    size: 38912
    MD5: E00DE20F0F6BED5CD2160247DDC9443B

    Located: Startup (disabled), OpenOffice.org 3.0 (DISABLED)
    command: C:\PROGRA~1\OPENOF~1.ORG\program\QUICKS~1.EXE
    file: C:\PROGRA~1\OPENOF~1.ORG\program\QUICKS~1.EXE
    size: 384000
    MD5: B2901E0C109652046ED3C210C47DA318

    Located: Startup (disabled), rncsys32 (DISABLED)
    command: C:\Documents and Settings\Greg\Start Menu\Programs\Startup\rncsys32.exe
    file: C:\Documents and Settings\Greg\Start Menu\Programs\Startup\rncsys32.exe
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, crypt32chain
    command: crypt32.dll
    file: crypt32.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, cryptnet
    command: cryptnet.dll
    file: cryptnet.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, cscdll
    command: cscdll.dll
    file: cscdll.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, dimsntfy
    command: %SystemRoot%\System32\dimsntfy.dll
    file: %SystemRoot%\System32\dimsntfy.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, igfxcui
    command: igfxdev.dll
    file: igfxdev.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, ScCertProp
    command: wlnotify.dll
    file: wlnotify.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, Schedule
    command: wlnotify.dll
    file: wlnotify.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, sclgntfy
    command: sclgntfy.dll
    file: sclgntfy.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, SensLogn
    command: WlNotify.dll
    file: WlNotify.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, termsrv
    command: wlnotify.dll
    file: wlnotify.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, wlballoon
    command: wlnotify.dll
    file: wlnotify.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!



    --- Browser helper object list ---
    {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name:
    CLSID name: Adobe PDF Reader Link Helper
    description: Adobe Acrobat reader
    classification: Legitimate
    known filename: AcroIEhelper.ocx<br>AcroIEhelper.dll
    info link: http://www.adobe.com/products/acrobat/readstep2.html
    info source: TonyKlein
    Path: C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\
    Long name: AcroIEHelper.dll
    Short name: ACROIE~1.DLL
    Date (created): 10/23/2006 12:08:42 AM
    Date (last access): 8/13/2009 2:55:06 AM
    Date (last write): 10/23/2006 12:08:42 AM
    Filesize: 62080
    Attributes: archive
    MD5: C11F6A1F61481E24BE3FDC06EA6F7D2A
    CRC32: E388508F
    Version: 8.0.0.456

    {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name:
    CLSID name: Spybot-S&D IE Protection
    description: Spybot-S&D IE Browser plugin
    classification: Legitimate
    known filename: SDhelper.dll
    info link: http://spybot.eon.net.au/
    info source: Patrick M. Kolla
    Path: C:\PROGRA~1\SPYBOT~1\
    Long name: SDHelper.dll
    Short name:
    Date (created): 12/25/2008 3:54:36 PM
    Date (last access): 8/13/2009 2:55:06 AM
    Date (last write): 1/26/2009 3:31:02 PM
    Filesize: 1879896
    Attributes: archive
    MD5: 022C2F6DCCDFA0AD73024D254E62AFAC
    CRC32: 5BA24007
    Version: 1.6.2.14

    {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name:
    CLSID name: SSVHelper Class
    Path: C:\Program Files\Java\jre1.6.0_07\bin\
    Long name: ssv.dll
    Short name:
    Date (created): 12/25/2008 4:41:48 PM
    Date (last access): 8/13/2009 2:55:06 AM
    Date (last write): 6/10/2008 5:27:02 AM
    Filesize: 509328
    Attributes: archive
    MD5: F921D875A1CBD69A6A462BA2514BC831
    CRC32: 38AC9EE2
    Version: 6.0.70.6

    {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name:
    CLSID name:

    {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name:
    CLSID name: Windows Live Sign-in Helper
    Path: C:\Program Files\Common Files\Microsoft Shared\Windows Live\
    Long name: WindowsLiveLogin.dll
    Short name: WINDOW~1.DLL
    Date (created): 2/17/2009 5:11:04 PM
    Date (last access): 8/13/2009 2:55:06 AM
    Date (last write): 2/17/2009 5:11:04 PM
    Filesize: 408440
    Attributes: archive
    MD5: 1A82C1B9BB43385695EFC3A84F6756A2
    CRC32: 75E558CA
    Version: 5.0.818.6

    {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} (Windows Live Toolbar Helper)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name:
    CLSID name: Windows Live Toolbar Helper
    Path: C:\Program Files\Windows Live Toolbar\
    Long name: msntb.dll
    Short name:
    Date (created): 10/19/2007 2:20:48 PM
    Date (last access): 8/13/2009 2:55:06 AM
    Date (last write): 10/19/2007 2:20:48 PM
    Filesize: 546320
    Attributes: archive
    MD5: CEE1BE1DA21300208D07FBEAE9EA2B51
    CRC32: 12446524
    Version: 3.1.0.146



    --- ActiveX list ---
    {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility)
    DPF name:
    CLSID name: PCPitstop Utility
    Installer: C:\WINDOWS\Downloaded Program Files\PCPitstop.inf
    Codebase: http://www.pcpitstop.com/betapit/PCPitStop.CAB
    description: Gateway tools
    classification: Legitimate
    known filename: PCPITSTOP.DLL
    info link:
    info source: Patrick M. Kolla
    Path: C:\WINDOWS\Downloaded Program Files\
    Long name: PCPitstop.dll
    Short name: PCPITS~2.DLL
    Date (created): 11/24/2008 4:31:44 PM
    Date (last access): 8/13/2009 2:55:06 AM
    Date (last write): 1/7/2009 12:24:08 PM
    Filesize: 457432
    Attributes: archive
    MD5: 1F899500DE260CEA92101CA0CF94B019
    CRC32: 1546FC08
    Version: 1.0.0.198

    {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class)
    DPF name:
    CLSID name: WUWebControl Class
    Installer: C:\WINDOWS\Downloaded Program Files\wuweb.inf
    Codebase: http://www.update.microsoft.com/micr...?1230231671609
    description:
    classification: Legitimate
    known filename: wuweb.dll
    info link:
    info source: Safer Networking Ltd.
    Path: C:\WINDOWS\system32\
    Long name: wuweb.dll
    Short name:
    Date (created): 8/9/2008 10:47:48 AM
    Date (last access): 8/13/2009 2:55:06 AM
    Date (last write): 10/16/2008 3:12:24 PM
    Filesize: 202776
    Attributes: archive
    MD5: 0006DE8037F5A562F96B461B3C557C3C
    CRC32: 9B107DED
    Version: 7.2.6001.788

    {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class)
    DPF name:
    CLSID name: MUWebControl Class
    Installer: C:\WINDOWS\Downloaded Program Files\muweb.inf
    Codebase: http://www.update.microsoft.com/micr...?1230231648859
    description:
    classification: Legitimate
    known filename: muweb.dll
    info link:
    info source: Safer Networking Ltd.
    Path: C:\WINDOWS\system32\
    Long name: muweb.dll
    Short name:
    Date (created): 10/16/2008 3:07:48 PM
    Date (last access): 8/13/2009 2:55:06 AM
    Date (last write): 10/16/2008 3:07:48 PM
    Filesize: 208744
    Attributes: archive
    MD5: 90058C2AD9FC43A3B3D59F82FFC6AEA7
    CRC32: 7D5F90FA
    Version: 7.2.6001.788

    {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.1_02)
    DPF name: Java Runtime Environment 1.4.1_02
    CLSID name: Java Plug-in 1.6.0_07
    Installer:
    Codebase: http://java.sun.com/products/plugin/...ndows-i586.cab
    description: Sun Java
    classification: Legitimate
    known filename: %PROGRAM FILES%\JabaSoft\JRE\*\Bin\npjava131.dll
    info link:
    info source: Patrick M. Kolla
    Path: C:\Program Files\Java\jre1.6.0_07\bin\
    Long name: npjpi160_07.dll
    Short name: NPJPI1~1.DLL
    Date (created): 6/10/2008 3:32:34 AM
    Date (last access): 8/13/2009 2:55:06 AM
    Date (last write): 6/10/2008 5:27:02 AM
    Filesize: 132496
    Attributes: archive
    MD5: 7C83A2809E13950359189767AC9D5DB8
    CRC32: 925C2A88
    Version: 6.0.70.6

    {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_02)
    DPF name: Java Runtime Environment 1.4.1_02
    CLSID name:
    Installer:
    Codebase: http://java.sun.com/products/plugin/...ndows-i586.cab
    description:
    classification: Legitimate
    known filename: NPJPI141_02.dll
    info link:
    info source: Safer Networking Ltd.

    {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
    DPF name: Java Runtime Environment 1.6.0
    CLSID name: Java Plug-in 1.6.0_07
    Installer:
    Codebase: http://java.sun.com/update/1.6.0/jin...ndows-i586.cab
    Path: C:\Program Files\Java\jre1.6.0_07\bin\
    Long name: npjpi160_07.dll
    Short name: NPJPI1~1.DLL
    Date (created): 6/10/2008 3:32:34 AM
    Date (last access): 8/13/2009 2:55:06 AM
    Date (last write): 6/10/2008 5:27:02 AM
    Filesize: 132496
    Attributes: archive
    MD5: 7C83A2809E13950359189767AC9D5DB8
    CRC32: 925C2A88
    Version: 6.0.70.6

    {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
    DPF name: Java Runtime Environment 1.6.0
    CLSID name: Java Plug-in 1.6.0_07
    Installer:
    Codebase: http://java.sun.com/update/1.6.0/jin...ndows-i586.cab
    description:
    classification: Legitimate
    known filename: npjpi150_06.dll
    info link:
    info source: Safer Networking Ltd.
    Path: C:\Program Files\Java\jre1.6.0_07\bin\
    Long name: npjpi160_07.dll
    Short name: NPJPI1~1.DLL
    Date (created): 6/10/2008 3:32:34 AM
    Date (last access): 8/13/2009 2:55:06 AM
    Date (last write): 6/10/2008 5:27:02 AM
    Filesize: 132496
    Attributes: archive
    MD5: 7C83A2809E13950359189767AC9D5DB8
    CRC32: 925C2A88
    Version: 6.0.70.6

    {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object)
    DPF name:
    CLSID name: Shockwave Flash Object
    Installer: C:\WINDOWS\Downloaded Program Files\swflash.inf
    Codebase: http://fpdownload2.macromedia.com/ge...sh/swflash.cab
    description: Macromedia Shockwave Flash Player
    classification: Legitimate
    known filename:
    info link:
    info source: Patrick M. Kolla
    Path: C:\WINDOWS\system32\Macromed\Flash\
    Long name: Flash10a.ocx
    Short name:
    Date (created): 10/4/2008 11:16:26 PM
    Date (last access): 8/13/2009 2:48:54 AM
    Date (last write): 10/4/2008 11:16:26 PM
    Filesize: 3789728
    Attributes: readonly archive
    MD5: 466C1355934925768822E380DA6E6E4A
    CRC32: 48EC1E52
    Version: 10.0.12.36



    --- Process list ---
    PID: 0 ( 0) [System]
    PID: 604 ( 4) \SystemRoot\System32\smss.exe
    size: 50688
    PID: 1076 ( 604) \??\C:\WINDOWS\system32\csrss.exe
    size: 6144
    PID: 1100 ( 604) \??\C:\WINDOWS\system32\winlogon.exe
    size: 507904
    PID: 1144 (1100) C:\WINDOWS\system32\services.exe
    size: 110592
    MD5: 65DF52F5B8B6E9BBD183505225C37315
    PID: 1156 (1100) C:\WINDOWS\system32\lsass.exe
    size: 13312
    MD5: BF2466B3E18E970D8A976FB95FC1CA85
    PID: 1316 (1144) C:\WINDOWS\system32\svchost.exe
    size: 14336
    MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    PID: 1384 (1144) C:\WINDOWS\system32\svchost.exe
    size: 14336
    MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    PID: 1424 (1144) C:\WINDOWS\System32\svchost.exe
    size: 14336
    MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    PID: 1564 (1144) C:\WINDOWS\system32\svchost.exe
    size: 14336
    MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    PID: 1588 (1144) C:\WINDOWS\system32\svchost.exe
    size: 14336
    MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    PID: 1844 (1144) C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    size: 18752
    MD5: B4253776EE034F6770FCEE32C28490B0
    PID: 1916 (1144) C:\Program Files\Alwil Software\Avast4\ashServ.exe
    size: 138680
    MD5: 62889D40A3FB1A9012428E16FE0DC67A
    PID: 596 (1144) C:\WINDOWS\system32\spoolsv.exe
    size: 57856
    MD5: D8E14A61ACC1D4A6CD0D38AEBAC7FA3B
    PID: 848 ( 772) C:\WINDOWS\Explorer.EXE
    size: 1033728
    MD5: 12896823FB95BFB3DC9B46BCAEDC9923
    PID: 1740 (1144) C:\WINDOWS\system32\svchost.exe
    size: 14336
    MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    PID: 1788 (1144) C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    size: 1413184
    MD5: 58927917C241C22EEE9A5CCFF6E9177B
    PID: 1968 (1424) C:\WINDOWS\msb.exe
    size: 144896
    MD5: F135D218835CC92A069E34A2E04578C7
    PID: 236 (1144) C:\WINDOWS\system32\svchost.exe
    size: 14336
    MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    PID: 676 (1144) C:\WINDOWS\system32\SearchIndexer.exe
    size: 439808
    MD5: 7778BDFA3F6F6FBA0E75B9594098F737
    PID: 904 ( 848) C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    size: 81000
    MD5: FC242DBD786557AC641726DC5C13F060
    PID: 940 ( 848) C:\WINDOWS\system32\ctfmon.exe
    size: 15360
    MD5: 5F1D5F88303D4A4DBC8E5F97BA967CC3
    PID: 2160 (1144) C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    size: 254040
    MD5: F09461C8ECCACE33C271CC229F11E281
    PID: 2184 (1144) C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    size: 352920
    MD5: 23CA3E54474AE5FFDBC0F97B9E1815DB
    PID: 2496 (1144) C:\WINDOWS\System32\alg.exe
    size: 44544
    MD5: 8C515081584A38AA007909CD02020B3D
    PID: 3128 ( 848) C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
    size: 5365592
    MD5: 0477C2F9171599CA5BC3307FDFBA8D89
    PID: 3728 ( 848) C:\Program Files\Mozilla Firefox\firefox.exe
    size: 307704
    MD5: 457441B04089CF16784D698B4B4EA8AF
    PID: 3340 (1424) C:\WINDOWS\system32\wuauclt.exe
    size: 51224
    MD5: E654B78D2F1D791B30D0ED9A8195EC22
    PID: 4 ( 0) System


    --- Browser start & search pages list ---
    Spybot - Search & Destroy browser pages report, 8/13/2009 3:46:26 AM

    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page
    C:\WINDOWS\system32\blank.htm
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page
    http://www.microsoft.com/isapi/redir...ie&ar=iesearch
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
    http://www.google.com/
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
    http://www.google.com/ie
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl\@
    http://www.google.com/search?q=%s
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Local Page
    C:\WINDOWS\system32\blank.htm
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Page
    http://go.microsoft.com/fwlink/?LinkId=54896
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page
    http://go.microsoft.com/fwlink/?LinkId=69157
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
    http://go.microsoft.com/fwlink/?LinkId=69157
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
    http://go.microsoft.com/fwlink/?LinkId=54896
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\SearchAssistant
    http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\CustomizeSearch
    http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm


    --- Winsock Layered Service Provider list ---
    Protocol 0: MSAFD Tcpip [TCP/IP]
    GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP IP protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD Tcpip[*]

    Protocol 1: MSAFD Tcpip [UDP/IP]
    GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP IP protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD Tcpip[*]

    Protocol 2: MSAFD Tcpip [RAW/IP]
    GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP IP protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD Tcpip[*]

    Protocol 3: RSVP UDP Service Provider
    GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
    Filename: %SystemRoot%\system32\rsvpsp.dll
    Description: Microsoft Windows NT/2k/XP RVSP
    DB filename: %SystemRoot%\system32\rsvpsp.dll
    DB protocol: RSVP * Service Provider

    Protocol 4: RSVP TCP Service Provider
    GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
    Filename: %SystemRoot%\system32\rsvpsp.dll
    Description: Microsoft Windows NT/2k/XP RVSP
    DB filename: %SystemRoot%\system32\rsvpsp.dll
    DB protocol: RSVP * Service Provider

    Protocol 5: MSAFD NetBIOS [\Device\NetBT_Tcpip_{6E5576F7-C1D0-4CDB-9E31-3B757A82C364}] SEQPACKET 10
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 6: MSAFD NetBIOS [\Device\NetBT_Tcpip_{6E5576F7-C1D0-4CDB-9E31-3B757A82C364}] DATAGRAM 10
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 7: MSAFD NetBIOS [\Device\NetBT_Tcpip_{80B6C53A-2F1D-4952-832C-C3532F4EE7B5}] SEQPACKET 9
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 8: MSAFD NetBIOS [\Device\NetBT_Tcpip_{80B6C53A-2F1D-4952-832C-C3532F4EE7B5}] DATAGRAM 9
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 9: MSAFD NetBIOS [\Device\NetBT_Tcpip_{1FEE91F0-EC20-4BE2-BED4-8C122AC654CB}] SEQPACKET 6
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 10: MSAFD NetBIOS [\Device\NetBT_Tcpip_{1FEE91F0-EC20-4BE2-BED4-8C122AC654CB}] DATAGRAM 6
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 11: MSAFD NetBIOS [\Device\NetBT_Tcpip_{0A2F862E-0E2B-4337-826A-18C6A89F1F3E}] SEQPACKET 5
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 12: MSAFD NetBIOS [\Device\NetBT_Tcpip_{0A2F862E-0E2B-4337-826A-18C6A89F1F3E}] DATAGRAM 5
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 13: MSAFD NetBIOS [\Device\NetBT_Tcpip_{3BD7D72E-47A5-468A-AF25-B93E94A0707E}] SEQPACKET 3
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 14: MSAFD NetBIOS [\Device\NetBT_Tcpip_{3BD7D72E-47A5-468A-AF25-B93E94A0707E}] DATAGRAM 3
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 15: MSAFD NetBIOS [\Device\NetBT_Tcpip_{4CF69781-2339-42F6-899A-AF3DF7C8BB96}] SEQPACKET 4
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 16: MSAFD NetBIOS [\Device\NetBT_Tcpip_{4CF69781-2339-42F6-899A-AF3DF7C8BB96}] DATAGRAM 4
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 17: MSAFD NetBIOS [\Device\NetBT_Tcpip_{7FBD8EB4-3AC8-45C0-93A7-BDDE432F7CFB}] SEQPACKET 0
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 18: MSAFD NetBIOS [\Device\NetBT_Tcpip_{7FBD8EB4-3AC8-45C0-93A7-BDDE432F7CFB}] DATAGRAM 0
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 19: MSAFD NetBIOS [\Device\NetBT_Tcpip_{4520FF0C-3412-4946-BB34-35DA13C20E9A}] SEQPACKET 1
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 20: MSAFD NetBIOS [\Device\NetBT_Tcpip_{4520FF0C-3412-4946-BB34-35DA13C20E9A}] DATAGRAM 1
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 21: MSAFD NetBIOS [\Device\NetBT_Tcpip_{C55C027F-A8C4-499A-98A2-DBCD2502AADB}] SEQPACKET 2
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 22: MSAFD NetBIOS [\Device\NetBT_Tcpip_{C55C027F-A8C4-499A-98A2-DBCD2502AADB}] DATAGRAM 2
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 23: MSAFD NetBIOS [\Device\NetBT_Tcpip_{4A6FFFF5-A56D-43F7-B8BA-CA07A3DA3AA8}] SEQPACKET 7
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 24: MSAFD NetBIOS [\Device\NetBT_Tcpip_{4A6FFFF5-A56D-43F7-B8BA-CA07A3DA3AA8}] DATAGRAM 7
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 25: MSAFD NetBIOS [\Device\NetBT_Tcpip_{C38A5413-F50B-4F03-BB3E-825B2A29DC47}] SEQPACKET 8
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 26: MSAFD NetBIOS [\Device\NetBT_Tcpip_{C38A5413-F50B-4F03-BB3E-825B2A29DC47}] DATAGRAM 8
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Namespace Provider 0: Tcpip
    GUID: {22059D40-7E9E-11CF-AE5A-00AA00A7112B}
    Filename: %SystemRoot%\System32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP TCP/IP name space provider
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: TCP/IP

    Namespace Provider 1: NTDS
    GUID: {3B2637EE-E580-11CF-A555-00C04FD8D4AC}
    Filename: %SystemRoot%\System32\winrnr.dll
    Description: Microsoft Windows NT/2k/XP name space provider
    DB filename: %SystemRoot%\system32\winrnr.dll
    DB protocol: NTDS

    Namespace Provider 2: Network Location Awareness (NLA) Namespace
    GUID: {6642243A-3BA8-4AA6-BAA5-2E0BD71FDD83}
    Filename: %SystemRoot%\System32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP name space provider
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: NLA-Namespace

    Namespace Provider 3: mdnsNSP
    GUID: {B600E6E9-553B-4A19-8696-335E5C896153}
    Filename: C:\Program Files\Bonjour\mdnsNSP.dll
    Description: Apple Rendezvous protocol
    DB filename: %ProgramFiles%\Rendezvous\bin\mdnsNSP.dll
    DB protocol: mdnsNSP

  6. #16
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    You can let it delete what it finds.

    Please download Malwarebytes Anti-Malware and save it to your desktop.
    alternate download link 1
    alternate download link 2
    • Make sure you are connected to the Internet.
    • Double-click on mbam-setup.exe to install the application.
    • When the installation begins, follow the prompts and do not make any changes to default settings.
    • When installation has finished, make sure you leave both of these checked:
      • Update Malwarebytes' Anti-Malware
      • Launch Malwarebytes' Anti-Malware
    • Then click Finish.
    • MBAM will automatically start and you will be asked to update the program before performing a scan. If an update is found, the program will automatically update itself. Press the OK button to close that box and continue. If you encounter any problems while downloading the updates, manually download them from here and just double-click on mbam-rules.exe to install.
    • On the Scanner tab:
      • Make sure the "Perform Full Scan" option is selected.
      • Then click on the Scan button.
    • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
    • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
    • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
    • Click OK to close the message box and continue with the removal process.
    • Back at the main Scanner screen, click on the Show Results button to see a list of any malware that was found.
    • Make sure that everything is checked, and click Remove Selected.
    • When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
    • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
    • Copy and paste the contents of that report in your next reply and exit MBAM.
    Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  7. #17
    Junior Member
    Join Date
    Aug 2009
    Posts
    19

    Default

    Here's the MalwareBytes log:

    Malwarebytes' Anti-Malware 1.40
    Database version: 2615
    Windows 5.1.2600 Service Pack 3

    8/13/2009 8:21:45 AM
    mbam-log-2009-08-13 (08-21-45).txt

    Scan type: Full Scan (C:\|D:\|)
    Objects scanned: 196141
    Time elapsed: 53 minute(s), 9 second(s)

    Memory Processes Infected: 1
    Memory Modules Infected: 0
    Registry Keys Infected: 3
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 2
    Files Infected: 17

    Memory Processes Infected:
    C:\WINDOWS\msb.exe (Trojan.Downloader) -> Unloaded process successfully.

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\av care (Rogue.AVCare) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\NordBull (Malware.Trace) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\AV Care (Rogue.AVCare) -> Quarantined and deleted successfully.

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    C:\Program Files\AV Care (Rogue.AVCare) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Greg\Start Menu\Programs\AV Care (Rogue.AVCare) -> Quarantined and deleted successfully.

    Files Infected:
    C:\WINDOWS\msb.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\Program Files\AV Care\AVCare.exe (Rogue.AVCare) -> Quarantined and deleted successfully.
    C:\Program Files\AV Care\PP.exe (Rogue.AVCare) -> Quarantined and deleted successfully.
    C:\Program Files\AV Care\Uninstall.exe (Rogue.AVCare) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\DOCUME~1\ALLUSE~1\APPLIC~1\13715154\13715154.exe.vir (Rogue.SystemSecurity) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\msa.exe.vir (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\UACtdylkwoofj.dll.vir (Rogue.Agent) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{70FD1DB3-E30F-48EC-ABEA-2DE81F03A8C6}\RP210\A0014648.dll (Rogue.Agent) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{70FD1DB3-E30F-48EC-ABEA-2DE81F03A8C6}\RP211\A0014680.exe (Rogue.SystemSecurity) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{70FD1DB3-E30F-48EC-ABEA-2DE81F03A8C6}\RP211\A0014682.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\Program Files\AV Care\avc.ico (Rogue.AVCare) -> Quarantined and deleted successfully.
    C:\Program Files\AV Care\AVCare.dat (Rogue.AVCare) -> Quarantined and deleted successfully.
    C:\Program Files\AV Care\AVCare.ini (Rogue.AVCare) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Greg\Start Menu\Programs\AV Care\AV Care.lnk (Rogue.AVCare) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Greg\Desktop\AV Care.lnk (Rogue.AVCare) -> Quarantined and deleted successfully.
    C:\WINDOWS\Tasks\{7B02EF0B-A410-4938-8480-9BA26420A627}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\WINDOWS\Tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job (Trojan.Downloader) -> Quarantined and deleted successfully.

  8. #18
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Please rescan with spybot and let me know if it still finds something.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  9. #19
    Junior Member
    Join Date
    Aug 2009
    Posts
    19

    Default

    It found a single tracking cookie.

    -Greg

    Spybot log follows:


    --- Search result list ---
    Right Media: Tracking cookie (Internet Explorer: Greg) (Cookie, nothing done)



    --- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---

    2009-01-26 blindman.exe (1.0.0.8)
    2009-01-26 SDFiles.exe (1.6.1.7)
    2009-01-26 SDMain.exe (1.0.0.6)
    2009-01-26 SDShred.exe (1.0.2.5)
    2009-01-26 SDUpdate.exe (1.6.0.12)
    2008-07-07 SDWinSec.exe (1.0.0.12)
    2009-01-26 SpybotSD.exe (1.6.2.46)
    2009-03-05 TeaTimer.exe (1.6.6.32)
    2009-04-07 unins000.exe (51.49.0.0)
    2009-01-26 Update.exe (1.6.0.7)
    2009-07-28 advcheck.dll (1.6.3.17)
    2007-04-02 aports.dll (2.1.0.0)
    2008-06-14 DelZip179.dll (1.79.11.1)
    2009-01-26 SDHelper.dll (1.6.2.14)
    2008-06-19 sqlite3.dll
    2009-01-26 Tools.dll (2.1.6.10)
    2009-01-16 UninsSrv.dll (1.0.0.0)
    2009-05-19 Includes\Adware.sbi (*)
    2009-07-30 Includes\AdwareC.sbi (*)
    2009-01-22 Includes\Cookies.sbi (*)
    2009-05-19 Includes\Dialer.sbi (*)
    2009-08-04 Includes\DialerC.sbi (*)
    2009-01-22 Includes\HeavyDuty.sbi (*)
    2009-05-26 Includes\Hijackers.sbi (*)
    2009-08-04 Includes\HijackersC.sbi (*)
    2009-06-23 Includes\Keyloggers.sbi (*)
    2009-07-30 Includes\KeyloggersC.sbi (*)
    2004-11-29 Includes\LSP.sbi (*)
    2009-08-11 Includes\Malware.sbi (*)
    2009-08-11 Includes\MalwareC.sbi (*)
    2009-03-25 Includes\PUPS.sbi (*)
    2009-08-06 Includes\PUPSC.sbi (*)
    2009-01-22 Includes\Revision.sbi (*)
    2009-01-13 Includes\Security.sbi (*)
    2009-07-30 Includes\SecurityC.sbi (*)
    2008-06-03 Includes\Spybots.sbi (*)
    2008-06-03 Includes\SpybotsC.sbi (*)
    2009-04-07 Includes\Spyware.sbi (*)
    2009-08-11 Includes\SpywareC.sbi (*)
    2009-06-08 Includes\Tracks.uti
    2009-08-11 Includes\Trojans.sbi (*)
    2009-08-12 Includes\TrojansC.sbi (*)
    2008-03-04 Plugins\Chai.dll
    2008-03-05 Plugins\Fennel.dll
    2008-02-26 Plugins\Mate.dll
    2007-12-24 Plugins\TCPIPAddress.dll



    --- System information ---
    Windows XP (Build: 2600) Service Pack 3 (5.1.2600)
    / .NETFramework / 1.1: Microsoft .NET Framework 1.1 Hotfix (KB928366)
    / .NETFramework / 1.1: Microsoft .NET Framework 1.1 Hotfix (KB929729)
    / .NETFramework / 1.1: Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
    / MSXML4SP2: Security update for MSXML4 SP2 (KB954430)
    / Windows / SP1: Microsoft Internationalized Domain Names Mitigation APIs
    / Windows / SP1: Microsoft National Language Support Downlevel APIs
    / Windows Media Format 11 SDK: Hotfix for Windows Media Format 11 SDK (KB929399)
    / Windows Media Player: Security Update for Windows Media Player (KB952069)
    / Windows Media Player: Security Update for Windows Media Player (KB973540)
    / Windows Media Player 11: Security Update for Windows Media Player 11 (KB936782)
    / Windows Media Player 11: Hotfix for Windows Media Player 11 (KB939683)
    / Windows Media Player 11: Security Update for Windows Media Player 11 (KB954154)
    / Windows Media Player 11: Critical Update for Windows Media Player 11 (KB959772)
    / Windows XP: Security Update for Windows XP (KB941569)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB938127-v2)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB956390)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB958215)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB960714)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB961260)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB963027)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB969897)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 8 (KB969897)
    / Windows XP / SP0: Update for Windows Internet Explorer 8 (KB971930)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 8 (KB972260)
    / Windows XP / SP10: Microsoft Compression Client Pack 1.0 for Windows XP
    / Windows XP / SP3: Update for Windows XP (KB898461)
    / Windows XP / SP4: Hotfix for Windows XP (KB915800-v4)
    / Windows XP / SP4: Security Update for Windows XP (KB923561)
    / Windows XP / SP4: Security Update for Windows XP (KB938464)
    / Windows XP / SP4: Update for Windows XP (KB942763)
    / Windows XP / SP4: Security Update for Windows XP (KB946648)
    / Windows XP / SP4: Security Update for Windows XP (KB950759)
    / Windows XP / SP4: Security Update for Windows XP (KB950760)
    / Windows XP / SP4: Security Update for Windows XP (KB950762)
    / Windows XP / SP4: Security Update for Windows XP (KB950974)
    / Windows XP / SP4: Security Update for Windows XP (KB951066)
    / Windows XP / SP4: Update for Windows XP (KB951072-v2)
    / Windows XP / SP4: Security Update for Windows XP (KB951376)
    / Windows XP / SP4: Security Update for Windows XP (KB951376-v2)
    / Windows XP / SP4: Update for Windows XP (KB951618-v2)
    / Windows XP / SP4: Security Update for Windows XP (KB951698)
    / Windows XP / SP4: Security Update for Windows XP (KB951748)
    / Windows XP / SP4: Update for Windows XP (KB951978)
    / Windows XP / SP4: Security Update for Windows XP (KB952004)
    / Windows XP / SP4: Hotfix for Windows XP (KB952287)
    / Windows XP / SP4: Security Update for Windows XP (KB952954)
    / Windows XP / SP4: Update for Windows XP (KB953356)
    / Windows XP / SP4: Security Update for Windows XP (KB953838)
    / Windows XP / SP4: Security Update for Windows XP (KB953839)
    / Windows XP / SP4: Security Update for Windows XP (KB954211)
    / Windows XP / SP4: Security Update for Windows XP (KB954459)
    / Windows XP / SP4: Hotfix for Windows XP (KB954550-v5)
    / Windows XP / SP4: Security Update for Windows XP (KB954600)
    / Windows XP / SP4: Security Update for Windows XP (KB955069)
    / Windows XP / SP4: Update for Windows XP (KB955839)
    / Windows XP / SP4: Security Update for Windows XP (KB956391)
    / Windows XP / SP4: Security Update for Windows XP (KB956572)
    / Windows XP / SP4: Security Update for Windows XP (KB956744)
    / Windows XP / SP4: Security Update for Windows XP (KB956802)
    / Windows XP / SP4: Security Update for Windows XP (KB956803)
    / Windows XP / SP4: Security Update for Windows XP (KB956841)
    / Windows XP / SP4: Security Update for Windows XP (KB957095)
    / Windows XP / SP4: Security Update for Windows XP (KB957097)
    / Windows XP / SP4: Security Update for Windows XP (KB958644)
    / Windows XP / SP4: Security Update for Windows XP (KB958687)
    / Windows XP / SP4: Security Update for Windows XP (KB958690)
    / Windows XP / SP4: Security Update for Windows XP (KB959426)
    / Windows XP / SP4: Security Update for Windows XP (KB960225)
    / Windows XP / SP4: Security Update for Windows XP (KB960715)
    / Windows XP / SP4: Security Update for Windows XP (KB960803)
    / Windows XP / SP4: Security Update for Windows XP (KB960859)
    / Windows XP / SP4: Hotfix for Windows XP (KB961118)
    / Windows XP / SP4: Security Update for Windows XP (KB961371)
    / Windows XP / SP4: Security Update for Windows XP (KB961373)
    / Windows XP / SP4: Security Update for Windows XP (KB961501)
    / Windows XP / SP4: Update for Windows XP (KB967715)
    / Windows XP / SP4: Security Update for Windows XP (KB968537)
    / Windows XP / SP4: Security Update for Windows XP (KB969898)
    / Windows XP / SP4: Security Update for Windows XP (KB970238)
    / Windows XP / SP4: Security Update for Windows XP (KB971557)
    / Windows XP / SP4: Security Update for Windows XP (KB971633)
    / Windows XP / SP4: Security Update for Windows XP (KB971657)
    / Windows XP / SP4: Security Update for Windows XP (KB973346)
    / Windows XP / SP4: Security Update for Windows XP (KB973354)
    / Windows XP / SP4: Security Update for Windows XP (KB973507)
    / Windows XP / SP4: Update for Windows XP (KB973815)
    / Windows XP / SP4: Security Update for Windows XP (KB973869)


    --- Startup entries list ---
    Located: HK_LM:Run, avast!
    command: C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    file: C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    size: 81000
    MD5: FC242DBD786557AC641726DC5C13F060

    Located: HK_CU:Run, ctfmon.exe
    where: S-1-5-21-371554582-1491889555-182000295-1006...
    command: C:\WINDOWS\system32\ctfmon.exe
    file: C:\WINDOWS\system32\ctfmon.exe
    size: 15360
    MD5: 5F1D5F88303D4A4DBC8E5F97BA967CC3

    Located: Startup (disabled), SuperHybridEngine (DISABLED)
    command: C:\PROGRA~1\ASUS\EeePC\SUPERH~1\SUPERH~1.EXE
    file: C:\PROGRA~1\ASUS\EeePC\SUPERH~1\SUPERH~1.EXE
    size: 311296
    MD5: 52ADDED5C967C963EE0A2A8DBD0EF4DA

    Located: Startup (disabled), VPN Client (DISABLED)
    command: C:\WINDOWS\Installer\{3E5562ED-69AB-4CEC-91E2-64E18EC5ACC6}\Icon3E5562ED7.ico -user_logon
    file: C:\WINDOWS\Installer\{3E5562ED-69AB-4CEC-91E2-64E18EC5ACC6}\Icon3E5562ED7.ico -user_logon
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: Startup (disabled), Windows Search (DISABLED)
    command: C:\PROGRA~1\WI459E~1\WINDOW~1.EXE /startup
    file: C:\PROGRA~1\WI459E~1\WINDOW~1.EXE
    size: 123904
    MD5: B5C9F63C01FCFEC3F64EC6A0940A1825

    Located: Startup (disabled), ERUNT AutoBackup (DISABLED)
    command: C:\PROGRA~1\ERUNT\AUTOBACK.EXE %SystemRoot%\ERDNT\AutoBackup\#Date# /noconfirmdelete /noprogresswindow
    file: C:\PROGRA~1\ERUNT\AUTOBACK.EXE
    size: 38912
    MD5: E00DE20F0F6BED5CD2160247DDC9443B

    Located: Startup (disabled), OpenOffice.org 3.0 (DISABLED)
    command: C:\PROGRA~1\OPENOF~1.ORG\program\QUICKS~1.EXE
    file: C:\PROGRA~1\OPENOF~1.ORG\program\QUICKS~1.EXE
    size: 384000
    MD5: B2901E0C109652046ED3C210C47DA318

    Located: Startup (disabled), rncsys32 (DISABLED)
    command: C:\Documents and Settings\Greg\Start Menu\Programs\Startup\rncsys32.exe
    file: C:\Documents and Settings\Greg\Start Menu\Programs\Startup\rncsys32.exe
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, crypt32chain
    command: crypt32.dll
    file: crypt32.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, cryptnet
    command: cryptnet.dll
    file: cryptnet.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, cscdll
    command: cscdll.dll
    file: cscdll.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, dimsntfy
    command: %SystemRoot%\System32\dimsntfy.dll
    file: %SystemRoot%\System32\dimsntfy.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, igfxcui
    command: igfxdev.dll
    file: igfxdev.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, ScCertProp
    command: wlnotify.dll
    file: wlnotify.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, Schedule
    command: wlnotify.dll
    file: wlnotify.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, sclgntfy
    command: sclgntfy.dll
    file: sclgntfy.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, SensLogn
    command: WlNotify.dll
    file: WlNotify.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, termsrv
    command: wlnotify.dll
    file: wlnotify.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, wlballoon
    command: wlnotify.dll
    file: wlnotify.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!



    --- Browser helper object list ---
    {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name:
    CLSID name: Adobe PDF Reader Link Helper
    description: Adobe Acrobat reader
    classification: Legitimate
    known filename: AcroIEhelper.ocx<br>AcroIEhelper.dll
    info link: http://www.adobe.com/products/acrobat/readstep2.html
    info source: TonyKlein
    Path: C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\
    Long name: AcroIEHelper.dll
    Short name: ACROIE~1.DLL
    Date (created): 10/23/2006 12:08:42 AM
    Date (last access): 8/13/2009 4:54:52 PM
    Date (last write): 10/23/2006 12:08:42 AM
    Filesize: 62080
    Attributes: archive
    MD5: C11F6A1F61481E24BE3FDC06EA6F7D2A
    CRC32: E388508F
    Version: 8.0.0.456

    {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name:
    CLSID name: Spybot-S&D IE Protection
    description: Spybot-S&D IE Browser plugin
    classification: Legitimate
    known filename: SDhelper.dll
    info link: http://spybot.eon.net.au/
    info source: Patrick M. Kolla
    Path: C:\PROGRA~1\SPYBOT~1\
    Long name: SDHelper.dll
    Short name:
    Date (created): 12/25/2008 3:54:36 PM
    Date (last access): 8/13/2009 5:07:34 PM
    Date (last write): 1/26/2009 3:31:02 PM
    Filesize: 1879896
    Attributes: archive
    MD5: 022C2F6DCCDFA0AD73024D254E62AFAC
    CRC32: 5BA24007
    Version: 1.6.2.14

    {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name:
    CLSID name: SSVHelper Class
    Path: C:\Program Files\Java\jre1.6.0_07\bin\
    Long name: ssv.dll
    Short name:
    Date (created): 12/25/2008 4:41:48 PM
    Date (last access): 8/13/2009 5:02:02 PM
    Date (last write): 6/10/2008 5:27:02 AM
    Filesize: 509328
    Attributes: archive
    MD5: F921D875A1CBD69A6A462BA2514BC831
    CRC32: 38AC9EE2
    Version: 6.0.70.6

    {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name:
    CLSID name:

    {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name:
    CLSID name: Windows Live Sign-in Helper
    Path: C:\Program Files\Common Files\Microsoft Shared\Windows Live\
    Long name: WindowsLiveLogin.dll
    Short name: WINDOW~1.DLL
    Date (created): 2/17/2009 5:11:04 PM
    Date (last access): 8/13/2009 5:02:02 PM
    Date (last write): 2/17/2009 5:11:04 PM
    Filesize: 408440
    Attributes: archive
    MD5: 1A82C1B9BB43385695EFC3A84F6756A2
    CRC32: 75E558CA
    Version: 5.0.818.6

    {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} (Windows Live Toolbar Helper)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name:
    CLSID name: Windows Live Toolbar Helper
    Path: C:\Program Files\Windows Live Toolbar\
    Long name: msntb.dll
    Short name:
    Date (created): 10/19/2007 2:20:48 PM
    Date (last access): 8/13/2009 5:02:02 PM
    Date (last write): 10/19/2007 2:20:48 PM
    Filesize: 546320
    Attributes: archive
    MD5: CEE1BE1DA21300208D07FBEAE9EA2B51
    CRC32: 12446524
    Version: 3.1.0.146



    --- ActiveX list ---
    {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility)
    DPF name:
    CLSID name: PCPitstop Utility
    Installer: C:\WINDOWS\Downloaded Program Files\PCPitstop.inf
    Codebase: http://www.pcpitstop.com/betapit/PCPitStop.CAB
    description: Gateway tools
    classification: Legitimate
    known filename: PCPITSTOP.DLL
    info link:
    info source: Patrick M. Kolla
    Path: C:\WINDOWS\Downloaded Program Files\
    Long name: PCPitstop.dll
    Short name: PCPITS~2.DLL
    Date (created): 11/24/2008 4:31:44 PM
    Date (last access): 8/13/2009 7:59:24 AM
    Date (last write): 1/7/2009 12:24:08 PM
    Filesize: 457432
    Attributes: archive
    MD5: 1F899500DE260CEA92101CA0CF94B019
    CRC32: 1546FC08
    Version: 1.0.0.198

    {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class)
    DPF name:
    CLSID name: WUWebControl Class
    Installer: C:\WINDOWS\Downloaded Program Files\wuweb.inf
    Codebase: http://www.update.microsoft.com/micr...?1230231671609
    description:
    classification: Legitimate
    known filename: wuweb.dll
    info link:
    info source: Safer Networking Ltd.
    Path: C:\WINDOWS\system32\
    Long name: wuweb.dll
    Short name:
    Date (created): 8/9/2008 10:47:48 AM
    Date (last access): 8/13/2009 4:53:56 PM
    Date (last write): 10/16/2008 3:12:24 PM
    Filesize: 202776
    Attributes: archive
    MD5: 0006DE8037F5A562F96B461B3C557C3C
    CRC32: 9B107DED
    Version: 7.2.6001.788

    {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class)
    DPF name:
    CLSID name: MUWebControl Class
    Installer: C:\WINDOWS\Downloaded Program Files\muweb.inf
    Codebase: http://www.update.microsoft.com/micr...?1230231648859
    description:
    classification: Legitimate
    known filename: muweb.dll
    info link:
    info source: Safer Networking Ltd.
    Path: C:\WINDOWS\system32\
    Long name: muweb.dll
    Short name:
    Date (created): 10/16/2008 3:07:48 PM
    Date (last access): 8/13/2009 4:53:54 PM
    Date (last write): 10/16/2008 3:07:48 PM
    Filesize: 208744
    Attributes: archive
    MD5: 90058C2AD9FC43A3B3D59F82FFC6AEA7
    CRC32: 7D5F90FA
    Version: 7.2.6001.788

    {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.1_02)
    DPF name: Java Runtime Environment 1.4.1_02
    CLSID name: Java Plug-in 1.6.0_07
    Installer:
    Codebase: http://java.sun.com/products/plugin/...ndows-i586.cab
    description: Sun Java
    classification: Legitimate
    known filename: %PROGRAM FILES%\JabaSoft\JRE\*\Bin\npjava131.dll
    info link:
    info source: Patrick M. Kolla
    Path: C:\Program Files\Java\jre1.6.0_07\bin\
    Long name: npjpi160_07.dll
    Short name: NPJPI1~1.DLL
    Date (created): 6/10/2008 3:32:34 AM
    Date (last access): 8/13/2009 7:45:20 AM
    Date (last write): 6/10/2008 5:27:02 AM
    Filesize: 132496
    Attributes: archive
    MD5: 7C83A2809E13950359189767AC9D5DB8
    CRC32: 925C2A88
    Version: 6.0.70.6

    {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_02)
    DPF name: Java Runtime Environment 1.4.1_02
    CLSID name:
    Installer:
    Codebase: http://java.sun.com/products/plugin/...ndows-i586.cab
    description:
    classification: Legitimate
    known filename: NPJPI141_02.dll
    info link:
    info source: Safer Networking Ltd.

    {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
    DPF name: Java Runtime Environment 1.6.0
    CLSID name: Java Plug-in 1.6.0_07
    Installer:
    Codebase: http://java.sun.com/update/1.6.0/jin...ndows-i586.cab
    Path: C:\Program Files\Java\jre1.6.0_07\bin\
    Long name: npjpi160_07.dll
    Short name: NPJPI1~1.DLL
    Date (created): 6/10/2008 3:32:34 AM
    Date (last access): 8/13/2009 5:09:04 PM
    Date (last write): 6/10/2008 5:27:02 AM
    Filesize: 132496
    Attributes: archive
    MD5: 7C83A2809E13950359189767AC9D5DB8
    CRC32: 925C2A88
    Version: 6.0.70.6

    {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
    DPF name: Java Runtime Environment 1.6.0
    CLSID name: Java Plug-in 1.6.0_07
    Installer:
    Codebase: http://java.sun.com/update/1.6.0/jin...ndows-i586.cab
    description:
    classification: Legitimate
    known filename: npjpi150_06.dll
    info link:
    info source: Safer Networking Ltd.
    Path: C:\Program Files\Java\jre1.6.0_07\bin\
    Long name: npjpi160_07.dll
    Short name: NPJPI1~1.DLL
    Date (created): 6/10/2008 3:32:34 AM
    Date (last access): 8/13/2009 5:09:04 PM
    Date (last write): 6/10/2008 5:27:02 AM
    Filesize: 132496
    Attributes: archive
    MD5: 7C83A2809E13950359189767AC9D5DB8
    CRC32: 925C2A88
    Version: 6.0.70.6

    {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object)
    DPF name:
    CLSID name: Shockwave Flash Object
    Installer: C:\WINDOWS\Downloaded Program Files\swflash.inf
    Codebase: http://fpdownload2.macromedia.com/ge...sh/swflash.cab
    description: Macromedia Shockwave Flash Player
    classification: Legitimate
    known filename:
    info link:
    info source: Patrick M. Kolla
    Path: C:\WINDOWS\system32\Macromed\Flash\
    Long name: Flash10a.ocx
    Short name:
    Date (created): 10/4/2008 11:16:26 PM
    Date (last access): 8/13/2009 8:04:46 AM
    Date (last write): 10/4/2008 11:16:26 PM
    Filesize: 3789728
    Attributes: readonly archive
    MD5: 466C1355934925768822E380DA6E6E4A
    CRC32: 48EC1E52
    Version: 10.0.12.36



    --- Process list ---
    PID: 0 ( 0) [System]
    PID: 608 ( 4) \SystemRoot\System32\smss.exe
    size: 50688
    PID: 1368 ( 608) \??\C:\WINDOWS\system32\csrss.exe
    size: 6144
    PID: 1392 ( 608) \??\C:\WINDOWS\system32\winlogon.exe
    size: 507904
    PID: 1436 (1392) C:\WINDOWS\system32\services.exe
    size: 110592
    MD5: 65DF52F5B8B6E9BBD183505225C37315
    PID: 1448 (1392) C:\WINDOWS\system32\lsass.exe
    size: 13312
    MD5: BF2466B3E18E970D8A976FB95FC1CA85
    PID: 1604 (1436) C:\WINDOWS\system32\svchost.exe
    size: 14336
    MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    PID: 1652 (1436) C:\WINDOWS\system32\svchost.exe
    size: 14336
    MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    PID: 1692 (1436) C:\WINDOWS\System32\svchost.exe
    size: 14336
    MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    PID: 1872 (1436) C:\WINDOWS\system32\svchost.exe
    size: 14336
    MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    PID: 1908 (1436) C:\WINDOWS\system32\svchost.exe
    size: 14336
    MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    PID: 260 (1436) C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    size: 18752
    MD5: B4253776EE034F6770FCEE32C28490B0
    PID: 328 (1436) C:\Program Files\Alwil Software\Avast4\ashServ.exe
    size: 138680
    MD5: 62889D40A3FB1A9012428E16FE0DC67A
    PID: 832 (1436) C:\WINDOWS\system32\spoolsv.exe
    size: 57856
    MD5: D8E14A61ACC1D4A6CD0D38AEBAC7FA3B
    PID: 920 (1436) C:\WINDOWS\system32\svchost.exe
    size: 14336
    MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    PID: 1188 (1436) C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    size: 1413184
    MD5: 58927917C241C22EEE9A5CCFF6E9177B
    PID: 1224 (1096) C:\WINDOWS\Explorer.EXE
    size: 1033728
    MD5: 12896823FB95BFB3DC9B46BCAEDC9923
    PID: 1352 (1436) C:\WINDOWS\system32\svchost.exe
    size: 14336
    MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    PID: 1752 (1436) C:\WINDOWS\system32\SearchIndexer.exe
    size: 439808
    MD5: 7778BDFA3F6F6FBA0E75B9594098F737
    PID: 1108 (1224) C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    size: 81000
    MD5: FC242DBD786557AC641726DC5C13F060
    PID: 1124 (1224) C:\WINDOWS\system32\ctfmon.exe
    size: 15360
    MD5: 5F1D5F88303D4A4DBC8E5F97BA967CC3
    PID: 944 (1436) C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    size: 254040
    MD5: F09461C8ECCACE33C271CC229F11E281
    PID: 1256 (1436) C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    size: 352920
    MD5: 23CA3E54474AE5FFDBC0F97B9E1815DB
    PID: 1848 (1436) C:\WINDOWS\System32\alg.exe
    size: 44544
    MD5: 8C515081584A38AA007909CD02020B3D
    PID: 3768 (1224) C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe
    size: 1770800
    MD5: 363F37D00F57A7C0D39AE142267DF2D6
    PID: 1416 (1224) C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
    size: 5365592
    MD5: 0477C2F9171599CA5BC3307FDFBA8D89
    PID: 4 ( 0) System


    --- Browser start & search pages list ---
    Spybot - Search & Destroy browser pages report, 8/13/2009 5:09:04 PM

    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page
    C:\WINDOWS\system32\blank.htm
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page
    http://www.microsoft.com/isapi/redir...ie&ar=iesearch
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
    http://www.google.com/
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
    http://www.google.com/ie
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl\@
    http://www.google.com/search?q=%s
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Local Page
    C:\WINDOWS\system32\blank.htm
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Page
    http://go.microsoft.com/fwlink/?LinkId=54896
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page
    http://go.microsoft.com/fwlink/?LinkId=69157
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
    http://go.microsoft.com/fwlink/?LinkId=69157
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
    http://go.microsoft.com/fwlink/?LinkId=54896
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\SearchAssistant
    http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\CustomizeSearch
    http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm


    --- Winsock Layered Service Provider list ---
    Protocol 0: MSAFD Tcpip [TCP/IP]
    GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP IP protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD Tcpip[*]

    Protocol 1: MSAFD Tcpip [UDP/IP]
    GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP IP protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD Tcpip[*]

    Protocol 2: MSAFD Tcpip [RAW/IP]
    GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP IP protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD Tcpip[*]

    Protocol 3: RSVP UDP Service Provider
    GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
    Filename: %SystemRoot%\system32\rsvpsp.dll
    Description: Microsoft Windows NT/2k/XP RVSP
    DB filename: %SystemRoot%\system32\rsvpsp.dll
    DB protocol: RSVP * Service Provider

    Protocol 4: RSVP TCP Service Provider
    GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
    Filename: %SystemRoot%\system32\rsvpsp.dll
    Description: Microsoft Windows NT/2k/XP RVSP
    DB filename: %SystemRoot%\system32\rsvpsp.dll
    DB protocol: RSVP * Service Provider

    Protocol 5: MSAFD NetBIOS [\Device\NetBT_Tcpip_{6E5576F7-C1D0-4CDB-9E31-3B757A82C364}] SEQPACKET 10
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 6: MSAFD NetBIOS [\Device\NetBT_Tcpip_{6E5576F7-C1D0-4CDB-9E31-3B757A82C364}] DATAGRAM 10
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 7: MSAFD NetBIOS [\Device\NetBT_Tcpip_{80B6C53A-2F1D-4952-832C-C3532F4EE7B5}] SEQPACKET 9
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 8: MSAFD NetBIOS [\Device\NetBT_Tcpip_{80B6C53A-2F1D-4952-832C-C3532F4EE7B5}] DATAGRAM 9
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 9: MSAFD NetBIOS [\Device\NetBT_Tcpip_{1FEE91F0-EC20-4BE2-BED4-8C122AC654CB}] SEQPACKET 6
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 10: MSAFD NetBIOS [\Device\NetBT_Tcpip_{1FEE91F0-EC20-4BE2-BED4-8C122AC654CB}] DATAGRAM 6
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 11: MSAFD NetBIOS [\Device\NetBT_Tcpip_{0A2F862E-0E2B-4337-826A-18C6A89F1F3E}] SEQPACKET 5
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 12: MSAFD NetBIOS [\Device\NetBT_Tcpip_{0A2F862E-0E2B-4337-826A-18C6A89F1F3E}] DATAGRAM 5
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 13: MSAFD NetBIOS [\Device\NetBT_Tcpip_{3BD7D72E-47A5-468A-AF25-B93E94A0707E}] SEQPACKET 3
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 14: MSAFD NetBIOS [\Device\NetBT_Tcpip_{3BD7D72E-47A5-468A-AF25-B93E94A0707E}] DATAGRAM 3
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 15: MSAFD NetBIOS [\Device\NetBT_Tcpip_{4CF69781-2339-42F6-899A-AF3DF7C8BB96}] SEQPACKET 4
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 16: MSAFD NetBIOS [\Device\NetBT_Tcpip_{4CF69781-2339-42F6-899A-AF3DF7C8BB96}] DATAGRAM 4
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 17: MSAFD NetBIOS [\Device\NetBT_Tcpip_{7FBD8EB4-3AC8-45C0-93A7-BDDE432F7CFB}] SEQPACKET 0
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 18: MSAFD NetBIOS [\Device\NetBT_Tcpip_{7FBD8EB4-3AC8-45C0-93A7-BDDE432F7CFB}] DATAGRAM 0
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 19: MSAFD NetBIOS [\Device\NetBT_Tcpip_{4520FF0C-3412-4946-BB34-35DA13C20E9A}] SEQPACKET 1
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 20: MSAFD NetBIOS [\Device\NetBT_Tcpip_{4520FF0C-3412-4946-BB34-35DA13C20E9A}] DATAGRAM 1
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 21: MSAFD NetBIOS [\Device\NetBT_Tcpip_{C55C027F-A8C4-499A-98A2-DBCD2502AADB}] SEQPACKET 2
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 22: MSAFD NetBIOS [\Device\NetBT_Tcpip_{C55C027F-A8C4-499A-98A2-DBCD2502AADB}] DATAGRAM 2
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 23: MSAFD NetBIOS [\Device\NetBT_Tcpip_{4A6FFFF5-A56D-43F7-B8BA-CA07A3DA3AA8}] SEQPACKET 7
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 24: MSAFD NetBIOS [\Device\NetBT_Tcpip_{4A6FFFF5-A56D-43F7-B8BA-CA07A3DA3AA8}] DATAGRAM 7
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 25: MSAFD NetBIOS [\Device\NetBT_Tcpip_{C38A5413-F50B-4F03-BB3E-825B2A29DC47}] SEQPACKET 8
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 26: MSAFD NetBIOS [\Device\NetBT_Tcpip_{C38A5413-F50B-4F03-BB3E-825B2A29DC47}] DATAGRAM 8
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Namespace Provider 0: Tcpip
    GUID: {22059D40-7E9E-11CF-AE5A-00AA00A7112B}
    Filename: %SystemRoot%\System32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP TCP/IP name space provider
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: TCP/IP

    Namespace Provider 1: NTDS
    GUID: {3B2637EE-E580-11CF-A555-00C04FD8D4AC}
    Filename: %SystemRoot%\System32\winrnr.dll
    Description: Microsoft Windows NT/2k/XP name space provider
    DB filename: %SystemRoot%\system32\winrnr.dll
    DB protocol: NTDS

    Namespace Provider 2: Network Location Awareness (NLA) Namespace
    GUID: {6642243A-3BA8-4AA6-BAA5-2E0BD71FDD83}
    Filename: %SystemRoot%\System32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP name space provider
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: NLA-Namespace

    Namespace Provider 3: mdnsNSP
    GUID: {B600E6E9-553B-4A19-8696-335E5C896153}
    Filename: C:\Program Files\Bonjour\mdnsNSP.dll
    Description: Apple Rendezvous protocol
    DB filename: %ProgramFiles%\Rendezvous\bin\mdnsNSP.dll
    DB protocol: mdnsNSP

  10. #20
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    OK that is not dangerous.

    Please go to ESET Online Scanner - © ESET All Rights Reserved... to run an online scan.
    Note: You - will - need to use Internet Explorer for this scan!
    1. Check the box next to "YES, I accept the Terms of Use."
    2. Click "Start"
    3. Click Yes... at the run ActiveX prompt. Click Install... at the install ActiveX prompt.
      Once installed, the scanner will be initialized.
    4. Click "Start". Make sure that the options:
      • Remove found threats is UNCHECKED
      • Scan unwanted applications is CHECKED
    5. Click "Scan"
    6. Wait for the scan to finish... it may take a while... please be patient. When the scan is finished...
    7. Use Notepad to open the log file located at C:\Program Files\EsetOnlineScanner\log.txt
    8. Copy and paste the contents of log.txt in your next reply.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •