When i boot up i get a message about SUSP_IRP_MJ_CREATE that needs removing but mcafee carnt do it this trojan is apparently also infection other files that mcafee then quarantines and cleans up but then they just get reinfected which creates alot of clutter.
basically i think its the same as this http://forums.spybot.info/showthread.php?t=54991
but im not sure how to apply that fix to mine especially since i apparently have 51 instances of this trojan
and heres the DDS
DDS (Ver_10-03-17.01) - NTFSx86
Run by Owner at 17:56:33.70 on 18/09/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_21
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1134 [GMT 1:00]
AV: McAfee Anti-Virus and Anti-Spyware *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
============== Running Processes ===============
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
C:\WINDOWS\System32\svchost.exe -k eapsvcs
svchost.exe
C:\WINDOWS\System32\svchost.exe -k dot3svc
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\netdde.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\clipsrv.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\CTSvcCDA.EXE
C:\Program Files\DellSupport\brkrsvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Windows Live\Family Safety\fsssvc.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
C:\Program Files\Common Files\AOL\1211036978\ee\AOLSoftware.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
C:\Program Files\WinFast\WFDTV\WFWIZ.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Pando Networks\Media Booster\PMB.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\NETGEAR\WPN111 Configuration Utility\WPN111.exe
C:\WINDOWS\system32\imapi.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\runservice.exe
C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
C:\Program Files\McAfee Online Backup\MOBKbackup.exe
C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
svchost.exe
C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\dmadmin.exe
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\Program Files\AOL 9.1\waol.exe
C:\Program Files\AOL 9.1\shellmon.exe
C:\Program Files\Common Files\AOL\Topspeed\3.0\aoltpsd3.exe
c:\PROGRA~1\mcafee.com\agent\McUpdate.exe
C:\Documents and Settings\Stephen Shepherd\Local Settings\Temporary Internet Files\Content.IE5\1GYAHOWR\dds[1].scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.aol.co.uk
uSearch Bar = hxxp://mysearch.myway.com/jsp/dellsidebar.jsp?p=DK
uDefault_Page_URL = hxxp://www.dell.co.uk/myway
mSearch Bar =
uSearchAssistant =
uCustomizeSearch =
uSearchURL,(Default) = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=101668&gct=&gc=1&q=%s
uURLSearchHooks: H - No File
uURLSearchHooks: H - No File
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
uURLSearchHooks: H - No File
uURLSearchHooks: H - No File
mURLSearchHooks: H - No File
mURLSearchHooks: H - No File
mURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
mWinlogon: Userinit=c:\windows\system32\userinit.exe,c:\windows\system32\sdra64.exe,,c:\program files\microsoft\desktoplayer.exe
BHO: Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - No File
BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll
BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - j:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: {776a9d06-e178-4aa0-aee4-b4de3a64ad28} - No File
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\common files\mcafee\systemcore\ScriptSn.20100917144217.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: {ad708c09-d51b-45b3-9d28-4eba2681febf} - No File
BHO: MSN Search Toolbar Helper: {bdbd1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\msn toolbar suite\tb\02.05.0000.1082\en-gb\msntb.dll
BHO: FrostWire Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
{e4df440e-b53a-472d-95bb-3056e39c0ddf}
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: MSN Search Toolbar: {bdad1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\msn toolbar suite\tb\02.05.0000.1082\en-gb\msntb.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - No File
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: {e6ed7f95-e571-4f81-8757-5eb11252703d} - No File
TB: {ad708c09-d51b-45b3-9d28-4eba2681febf} - No File
TB: FrostWire Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [{B22B24D2-7D41-65FC-0108-8024D118F1B4}] "c:\documents and settings\stephen shepherd\application data\fahabi\vuezg.exe"
uRun: [Pando Media Booster] c:\program files\pando networks\media booster\PMB.exe
uRun: [Tyuvedakokoxevok] rundll32.exe "c:\windows\dmasip.dll",Startup
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRunOnce: [<NO NAME>] c:\program files\internet explorer\iexplore.exe http://www.symantec.com/techsupp/se...000001e.0000004a&d=00000082.00000045.0000011b
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [HostManager] c:\program files\common files\aol\1211036978\ee\AOLSoftware.exe
mRun: [mcui_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [WinFastDTV] c:\program files\winfast\wfdtv\DTVSchdl.exe
mRun: [WinFast Schedule] c:\program files\winfast\wfdtv\WFWIZ.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [nonep] c:\program files\riv87\oops.exe
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRunOnce: [SWHelper] "c:\windows\system32\macromed\shockwave 10\PostUpdate.exe" 1014020
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\netgea~1.lnk - c:\program files\netgear\wpn111 configuration utility\WPN111.exe
uPolicies-explorer: NoResolveTrack = 1 (0x1)
uPolicies-system: NoColorChoice = 0 (0x0)
uPolicies-system: NoSizeChoice = 0 (0x0)
uPolicies-system: NoVisualStyleChoice = 0 (0x0)
uPolicies-system: SetVisualStyle = c:\windows\resources\themes\Luna.theme
mPolicies-explorer: NoResolveTrack = 1 (0x1)
IE: &MSN Search - c:\program files\msn toolbar suite\tb\02.05.0000.1082\en-gb\msntb.dll/search.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office10\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - j:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: internet
Trusted Zone: mcafee.com
DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE}
TCP: NameServer = 93.188.162.81,93.188.161.221
TCP: {55F76BCA-0465-4E8D-811D-1CD9DA007B9D} = 93.188.162.81,93.188.161.221
TCP: {602F73AD-2D47-4888-986C-A71CCA91206B} = 93.188.162.81,93.188.161.221
TCP: {D3AEFB10-3EC4-4A1F-A53C-7738F8F2E287} = 93.188.162.81,93.188.161.221
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: WRNotifier - WRLogonNTF.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
LSA: Authentication Packages = msv1_0 c:\\windows\\system32\\vturo nwprovau
============= SERVICES / DRIVERS ===============
R0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-2-13 386712]
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [2010-2-23 84072]
R1 MOBKFilter;MOBKFilter;c:\windows\system32\drivers\MOBK.sys [2010-2-23 54776]
R2 CX88TS;WinFast BDA Transport Stream Capture (CX2388x);c:\windows\system32\drivers\cx88ts.sys [2006-1-20 13440]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-10-3 54752]
R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2010-2-23 55840]
R3 CXBDATUNE;WinFast CX2388x BDA DVB-T Tuner/Demod;c:\windows\system32\drivers\cxBDAtun.sys [2006-1-20 21376]
R3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;c:\windows\system32\DNINDIS5.sys [2006-1-20 17149]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2010-2-23 152992]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2010-2-23 52104]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2010-2-23 312904]
R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [2010-2-23 88544]
R3 WPN111;Wireless USB 2.0 Adapter with RangeMax Service;c:\windows\system32\drivers\WPN111.sys [2009-6-26 286720]
S3 ATHFMWDL;NETGEAR WPN111 Bootloader driver;c:\windows\system32\drivers\athwpn.sys [2009-6-26 43392]
S3 CDAVFS;CDAVFS;c:\windows\system32\drivers\CDAVFS.sys [2007-9-18 61440]
S3 cpuz132;cpuz132;\??\c:\docume~1\stephe~1\locals~1\temp\cpuz132\cpuz132_x32.sys --> c:\docume~1\stephe~1\locals~1\temp\cpuz132\cpuz132_x32.sys [?]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [2010-2-23 88544]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2010-2-23 84264]
S3 WFIOCTL;WFIOCTL;\??\c:\program files\winfast\wftvfm\wfioctl.sys --> c:\program files\winfast\wftvfm\WFIOCTL.SYS [?]
=============== Created Last 30 ================
2010-09-16 13:48:28 0 d-----w- c:\docume~1\stephe~1\applic~1\McAfee
2010-09-15 00:18:22 68 ----a-w- c:\windows\system32\XM
2010-09-14 12:12:04 0 d-----w- c:\program files\sys32
2010-09-14 12:11:52 0 d-----w- c:\program files\riv87
2010-09-10 20:45:46 0 d-----w- c:\docume~1\alluse~1\applic~1\PMB Files
2010-09-10 20:44:44 0 d-----w- c:\program files\Pando Networks
2010-09-10 20:43:44 1910144 ----a-w- C:\lotrohigh.exe
2010-09-05 20:44:29 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-09-05 20:23:22 0 d-----w- c:\program files\Ask.com
2010-09-03 13:48:24 292 ----a-w- c:\windows\vtmb.ini
2010-09-03 13:05:21 0 d-----w- c:\windows\system32\WinFast
2010-09-03 13:05:08 0 d-----w- c:\program files\WinFast
2010-09-02 17:51:20 0 d-----w- c:\program files\McAfee.com
2010-09-02 16:33:37 0 d-----w- C:\avrescue
2010-08-30 18:40:47 0 d-----w- c:\windows\system32\wbem\Repository
2010-08-20 22:22:09 3532 ----a-w- C:\drmHeader.bin
==================== Find3M ====================
2010-09-18 16:31:24 215552 ----a-w- c:\windows\system32\dllcache\wordpad.exe
2010-09-18 16:31:23 64000 ----a-w- c:\windows\system32\dllcache\wmplayer.exe
2010-09-18 16:31:23 243712 ----a-w- c:\windows\system32\dllcache\mpvis.dll
2010-09-18 16:31:22 991232 ----a-w- c:\windows\system32\dllcache\migrate.exe
2010-09-18 16:28:54 1315328 ----a-w- c:\windows\system32\dllcache\msoe.dll
2010-09-18 16:28:10 69632 ----a-w- c:\windows\system32\dllcache\wmm2ext.dll
2010-09-18 16:28:09 3558912 ----a-w- c:\windows\system32\dllcache\moviemk.exe
2010-09-01 02:02:29 6528 -csha-w- c:\windows\system32\KGyGaAvL.sys
2010-08-24 13:57:38 95600 ----a-w- c:\windows\system32\drivers\mfeapfk.sys
2010-08-24 13:57:38 9344 ----a-w- c:\windows\system32\drivers\mfeclnk.sys
2010-08-24 13:57:38 88544 ----a-w- c:\windows\system32\drivers\mfendisk.sys
2010-08-24 13:57:38 84264 ----a-w- c:\windows\system32\drivers\mferkdet.sys
2010-08-24 13:57:38 84072 ----a-w- c:\windows\system32\drivers\mfetdi2k.sys
2010-08-24 13:57:38 55840 ----a-w- c:\windows\system32\drivers\cfwids.sys
2010-08-24 13:57:38 52104 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2010-08-24 13:57:38 386712 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2010-08-24 13:57:38 312904 ----a-w- c:\windows\system32\drivers\mfefirek.sys
2010-08-24 13:57:38 152992 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2010-07-14 21:39:53 4197 ----a-w- c:\documents and settings\stephen shepherd\regfix.reg
2008-06-06 08:43:19 6190 ----a-w- c:\program files\install.log
2004-09-22 16:46:16 290816 -c--a-w- c:\program files\Interop.WMPLib.dll
2006-01-27 21:35:55 56 -csh--r- c:\windows\system32\E0DAEDED00.sys
2009-12-12 00:19:10 132096 --sha-r- c:\windows\system32\esentprfx.dll
2009-06-04 17:43:32 1457 --sha-w- c:\windows\system32\mmf(10)(2).sys
2009-06-04 17:40:27 1457 --sha-w- c:\windows\system32\mmf(11)(2).sys
2009-06-04 16:20:07 1457 --sha-w- c:\windows\system32\mmf(11)(3).sys
2009-06-06 11:48:05 1457 --sha-w- c:\windows\system32\mmf(2)(2)(2).sys
2009-06-04 16:29:57 1457 --sha-w- c:\windows\system32\mmf(2)(2).sys
2009-05-31 12:06:28 1457 --sha-w- c:\windows\system32\mmf(2)(3).sys
2009-06-04 16:17:46 1457 --sha-w- c:\windows\system32\mmf(2)(4).sys
2009-06-06 11:28:22 1457 --sha-w- c:\windows\system32\mmf(2)(5).sys
2009-06-04 16:17:46 1457 --sha-w- c:\windows\system32\mmf(2)(6).sys
2009-06-04 16:17:46 1457 --sha-w- c:\windows\system32\mmf(2)(7).sys
2009-05-28 11:43:25 1457 --sha-w- c:\windows\system32\mmf(2)(8).sys
2009-06-06 11:34:47 1457 --sha-w- c:\windows\system32\mmf(3)(2)(2).sys
2009-06-04 16:27:44 1457 --sha-w- c:\windows\system32\mmf(3)(2).sys
2009-06-04 14:27:39 1457 --sha-w- c:\windows\system32\mmf(3)(3).sys
2009-06-06 11:24:50 1457 --sha-w- c:\windows\system32\mmf(3)(4).sys
2009-06-04 14:27:39 1457 --sha-w- c:\windows\system32\mmf(3)(5).sys
2009-06-04 14:27:39 1457 --sha-w- c:\windows\system32\mmf(3)(6).sys
2009-05-27 12:18:40 1457 --sha-w- c:\windows\system32\mmf(3)(7).sys
2009-06-04 17:47:04 1457 --sha-w- c:\windows\system32\mmf(4)(2)(2).sys
2009-06-04 16:26:09 1457 --sha-w- c:\windows\system32\mmf(4)(2).sys
2009-06-03 09:35:22 1457 --sha-w- c:\windows\system32\mmf(4)(3).sys
2009-06-06 11:19:39 1457 --sha-w- c:\windows\system32\mmf(4)(4).sys
2009-06-03 09:35:22 1457 --sha-w- c:\windows\system32\mmf(4)(5).sys
2009-06-06 11:17:41 1457 --sha-w- c:\windows\system32\mmf(5)(2)(2).sys
2009-06-02 10:33:29 1457 --sha-w- c:\windows\system32\mmf(5)(2).sys
2009-06-02 10:33:29 1457 --sha-w- c:\windows\system32\mmf(5)(3).sys
2009-06-02 10:33:29 1457 --sha-w- c:\windows\system32\mmf(5)(4).sys
2009-06-06 11:15:16 1457 --sha-w- c:\windows\system32\mmf(6)(2).sys
2009-06-01 11:59:15 1457 --sha-w- c:\windows\system32\mmf(6)(3).sys
2009-06-05 15:47:48 1457 --sha-w- c:\windows\system32\mmf(7)(2).sys
2009-05-31 12:06:28 1457 --sha-w- c:\windows\system32\mmf(7)(3).sys
2009-06-05 15:42:08 1457 --sha-w- c:\windows\system32\mmf(8)(2).sys
2009-06-03 09:35:22 1457 --sha-w- c:\windows\system32\mmf(8)(3).sys
2009-05-30 10:59:32 1457 --sha-w- c:\windows\system32\mmf(8)(4).sys
2009-06-04 17:47:04 1457 --sha-w- c:\windows\system32\mmf(9)(2).sys
2009-05-29 11:16:23 1457 --sha-w- c:\windows\system32\mmf(9)(3).sys
2007-09-19 16:16:40 2039162 -csh--w- c:\windows\system32\orutv.bak2
2007-09-19 16:17:06 2038428 -csh--w- c:\windows\system32\orutv.ini2
============= FINISH: 18:08:47.12 ===============
basically i think its the same as this http://forums.spybot.info/showthread.php?t=54991
but im not sure how to apply that fix to mine especially since i apparently have 51 instances of this trojan
and heres the DDS
DDS (Ver_10-03-17.01) - NTFSx86
Run by Owner at 17:56:33.70 on 18/09/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_21
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1134 [GMT 1:00]
AV: McAfee Anti-Virus and Anti-Spyware *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
============== Running Processes ===============
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
C:\WINDOWS\System32\svchost.exe -k eapsvcs
svchost.exe
C:\WINDOWS\System32\svchost.exe -k dot3svc
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\netdde.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\clipsrv.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\CTSvcCDA.EXE
C:\Program Files\DellSupport\brkrsvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Windows Live\Family Safety\fsssvc.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
C:\Program Files\Common Files\AOL\1211036978\ee\AOLSoftware.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
C:\Program Files\WinFast\WFDTV\WFWIZ.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Pando Networks\Media Booster\PMB.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\NETGEAR\WPN111 Configuration Utility\WPN111.exe
C:\WINDOWS\system32\imapi.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\runservice.exe
C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
C:\Program Files\McAfee Online Backup\MOBKbackup.exe
C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
svchost.exe
C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\dmadmin.exe
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\Program Files\AOL 9.1\waol.exe
C:\Program Files\AOL 9.1\shellmon.exe
C:\Program Files\Common Files\AOL\Topspeed\3.0\aoltpsd3.exe
c:\PROGRA~1\mcafee.com\agent\McUpdate.exe
C:\Documents and Settings\Stephen Shepherd\Local Settings\Temporary Internet Files\Content.IE5\1GYAHOWR\dds[1].scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.aol.co.uk
uSearch Bar = hxxp://mysearch.myway.com/jsp/dellsidebar.jsp?p=DK
uDefault_Page_URL = hxxp://www.dell.co.uk/myway
mSearch Bar =
uSearchAssistant =
uCustomizeSearch =
uSearchURL,(Default) = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=101668&gct=&gc=1&q=%s
uURLSearchHooks: H - No File
uURLSearchHooks: H - No File
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
uURLSearchHooks: H - No File
uURLSearchHooks: H - No File
mURLSearchHooks: H - No File
mURLSearchHooks: H - No File
mURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
mWinlogon: Userinit=c:\windows\system32\userinit.exe,c:\windows\system32\sdra64.exe,,c:\program files\microsoft\desktoplayer.exe
BHO: Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - No File
BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll
BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - j:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: {776a9d06-e178-4aa0-aee4-b4de3a64ad28} - No File
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\common files\mcafee\systemcore\ScriptSn.20100917144217.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: {ad708c09-d51b-45b3-9d28-4eba2681febf} - No File
BHO: MSN Search Toolbar Helper: {bdbd1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\msn toolbar suite\tb\02.05.0000.1082\en-gb\msntb.dll
BHO: FrostWire Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
{e4df440e-b53a-472d-95bb-3056e39c0ddf}
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: MSN Search Toolbar: {bdad1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\msn toolbar suite\tb\02.05.0000.1082\en-gb\msntb.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - No File
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: {e6ed7f95-e571-4f81-8757-5eb11252703d} - No File
TB: {ad708c09-d51b-45b3-9d28-4eba2681febf} - No File
TB: FrostWire Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [{B22B24D2-7D41-65FC-0108-8024D118F1B4}] "c:\documents and settings\stephen shepherd\application data\fahabi\vuezg.exe"
uRun: [Pando Media Booster] c:\program files\pando networks\media booster\PMB.exe
uRun: [Tyuvedakokoxevok] rundll32.exe "c:\windows\dmasip.dll",Startup
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRunOnce: [<NO NAME>] c:\program files\internet explorer\iexplore.exe http://www.symantec.com/techsupp/se...000001e.0000004a&d=00000082.00000045.0000011b
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [HostManager] c:\program files\common files\aol\1211036978\ee\AOLSoftware.exe
mRun: [mcui_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [WinFastDTV] c:\program files\winfast\wfdtv\DTVSchdl.exe
mRun: [WinFast Schedule] c:\program files\winfast\wfdtv\WFWIZ.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [nonep] c:\program files\riv87\oops.exe
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRunOnce: [SWHelper] "c:\windows\system32\macromed\shockwave 10\PostUpdate.exe" 1014020
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\netgea~1.lnk - c:\program files\netgear\wpn111 configuration utility\WPN111.exe
uPolicies-explorer: NoResolveTrack = 1 (0x1)
uPolicies-system: NoColorChoice = 0 (0x0)
uPolicies-system: NoSizeChoice = 0 (0x0)
uPolicies-system: NoVisualStyleChoice = 0 (0x0)
uPolicies-system: SetVisualStyle = c:\windows\resources\themes\Luna.theme
mPolicies-explorer: NoResolveTrack = 1 (0x1)
IE: &MSN Search - c:\program files\msn toolbar suite\tb\02.05.0000.1082\en-gb\msntb.dll/search.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office10\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - j:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: internet
Trusted Zone: mcafee.com
DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE}
TCP: NameServer = 93.188.162.81,93.188.161.221
TCP: {55F76BCA-0465-4E8D-811D-1CD9DA007B9D} = 93.188.162.81,93.188.161.221
TCP: {602F73AD-2D47-4888-986C-A71CCA91206B} = 93.188.162.81,93.188.161.221
TCP: {D3AEFB10-3EC4-4A1F-A53C-7738F8F2E287} = 93.188.162.81,93.188.161.221
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: WRNotifier - WRLogonNTF.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
LSA: Authentication Packages = msv1_0 c:\\windows\\system32\\vturo nwprovau
============= SERVICES / DRIVERS ===============
R0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-2-13 386712]
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [2010-2-23 84072]
R1 MOBKFilter;MOBKFilter;c:\windows\system32\drivers\MOBK.sys [2010-2-23 54776]
R2 CX88TS;WinFast BDA Transport Stream Capture (CX2388x);c:\windows\system32\drivers\cx88ts.sys [2006-1-20 13440]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-10-3 54752]
R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2010-2-23 55840]
R3 CXBDATUNE;WinFast CX2388x BDA DVB-T Tuner/Demod;c:\windows\system32\drivers\cxBDAtun.sys [2006-1-20 21376]
R3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;c:\windows\system32\DNINDIS5.sys [2006-1-20 17149]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2010-2-23 152992]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2010-2-23 52104]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2010-2-23 312904]
R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [2010-2-23 88544]
R3 WPN111;Wireless USB 2.0 Adapter with RangeMax Service;c:\windows\system32\drivers\WPN111.sys [2009-6-26 286720]
S3 ATHFMWDL;NETGEAR WPN111 Bootloader driver;c:\windows\system32\drivers\athwpn.sys [2009-6-26 43392]
S3 CDAVFS;CDAVFS;c:\windows\system32\drivers\CDAVFS.sys [2007-9-18 61440]
S3 cpuz132;cpuz132;\??\c:\docume~1\stephe~1\locals~1\temp\cpuz132\cpuz132_x32.sys --> c:\docume~1\stephe~1\locals~1\temp\cpuz132\cpuz132_x32.sys [?]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [2010-2-23 88544]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2010-2-23 84264]
S3 WFIOCTL;WFIOCTL;\??\c:\program files\winfast\wftvfm\wfioctl.sys --> c:\program files\winfast\wftvfm\WFIOCTL.SYS [?]
=============== Created Last 30 ================
2010-09-16 13:48:28 0 d-----w- c:\docume~1\stephe~1\applic~1\McAfee
2010-09-15 00:18:22 68 ----a-w- c:\windows\system32\XM
2010-09-14 12:12:04 0 d-----w- c:\program files\sys32
2010-09-14 12:11:52 0 d-----w- c:\program files\riv87
2010-09-10 20:45:46 0 d-----w- c:\docume~1\alluse~1\applic~1\PMB Files
2010-09-10 20:44:44 0 d-----w- c:\program files\Pando Networks
2010-09-10 20:43:44 1910144 ----a-w- C:\lotrohigh.exe
2010-09-05 20:44:29 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-09-05 20:23:22 0 d-----w- c:\program files\Ask.com
2010-09-03 13:48:24 292 ----a-w- c:\windows\vtmb.ini
2010-09-03 13:05:21 0 d-----w- c:\windows\system32\WinFast
2010-09-03 13:05:08 0 d-----w- c:\program files\WinFast
2010-09-02 17:51:20 0 d-----w- c:\program files\McAfee.com
2010-09-02 16:33:37 0 d-----w- C:\avrescue
2010-08-30 18:40:47 0 d-----w- c:\windows\system32\wbem\Repository
2010-08-20 22:22:09 3532 ----a-w- C:\drmHeader.bin
==================== Find3M ====================
2010-09-18 16:31:24 215552 ----a-w- c:\windows\system32\dllcache\wordpad.exe
2010-09-18 16:31:23 64000 ----a-w- c:\windows\system32\dllcache\wmplayer.exe
2010-09-18 16:31:23 243712 ----a-w- c:\windows\system32\dllcache\mpvis.dll
2010-09-18 16:31:22 991232 ----a-w- c:\windows\system32\dllcache\migrate.exe
2010-09-18 16:28:54 1315328 ----a-w- c:\windows\system32\dllcache\msoe.dll
2010-09-18 16:28:10 69632 ----a-w- c:\windows\system32\dllcache\wmm2ext.dll
2010-09-18 16:28:09 3558912 ----a-w- c:\windows\system32\dllcache\moviemk.exe
2010-09-01 02:02:29 6528 -csha-w- c:\windows\system32\KGyGaAvL.sys
2010-08-24 13:57:38 95600 ----a-w- c:\windows\system32\drivers\mfeapfk.sys
2010-08-24 13:57:38 9344 ----a-w- c:\windows\system32\drivers\mfeclnk.sys
2010-08-24 13:57:38 88544 ----a-w- c:\windows\system32\drivers\mfendisk.sys
2010-08-24 13:57:38 84264 ----a-w- c:\windows\system32\drivers\mferkdet.sys
2010-08-24 13:57:38 84072 ----a-w- c:\windows\system32\drivers\mfetdi2k.sys
2010-08-24 13:57:38 55840 ----a-w- c:\windows\system32\drivers\cfwids.sys
2010-08-24 13:57:38 52104 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2010-08-24 13:57:38 386712 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2010-08-24 13:57:38 312904 ----a-w- c:\windows\system32\drivers\mfefirek.sys
2010-08-24 13:57:38 152992 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2010-07-14 21:39:53 4197 ----a-w- c:\documents and settings\stephen shepherd\regfix.reg
2008-06-06 08:43:19 6190 ----a-w- c:\program files\install.log
2004-09-22 16:46:16 290816 -c--a-w- c:\program files\Interop.WMPLib.dll
2006-01-27 21:35:55 56 -csh--r- c:\windows\system32\E0DAEDED00.sys
2009-12-12 00:19:10 132096 --sha-r- c:\windows\system32\esentprfx.dll
2009-06-04 17:43:32 1457 --sha-w- c:\windows\system32\mmf(10)(2).sys
2009-06-04 17:40:27 1457 --sha-w- c:\windows\system32\mmf(11)(2).sys
2009-06-04 16:20:07 1457 --sha-w- c:\windows\system32\mmf(11)(3).sys
2009-06-06 11:48:05 1457 --sha-w- c:\windows\system32\mmf(2)(2)(2).sys
2009-06-04 16:29:57 1457 --sha-w- c:\windows\system32\mmf(2)(2).sys
2009-05-31 12:06:28 1457 --sha-w- c:\windows\system32\mmf(2)(3).sys
2009-06-04 16:17:46 1457 --sha-w- c:\windows\system32\mmf(2)(4).sys
2009-06-06 11:28:22 1457 --sha-w- c:\windows\system32\mmf(2)(5).sys
2009-06-04 16:17:46 1457 --sha-w- c:\windows\system32\mmf(2)(6).sys
2009-06-04 16:17:46 1457 --sha-w- c:\windows\system32\mmf(2)(7).sys
2009-05-28 11:43:25 1457 --sha-w- c:\windows\system32\mmf(2)(8).sys
2009-06-06 11:34:47 1457 --sha-w- c:\windows\system32\mmf(3)(2)(2).sys
2009-06-04 16:27:44 1457 --sha-w- c:\windows\system32\mmf(3)(2).sys
2009-06-04 14:27:39 1457 --sha-w- c:\windows\system32\mmf(3)(3).sys
2009-06-06 11:24:50 1457 --sha-w- c:\windows\system32\mmf(3)(4).sys
2009-06-04 14:27:39 1457 --sha-w- c:\windows\system32\mmf(3)(5).sys
2009-06-04 14:27:39 1457 --sha-w- c:\windows\system32\mmf(3)(6).sys
2009-05-27 12:18:40 1457 --sha-w- c:\windows\system32\mmf(3)(7).sys
2009-06-04 17:47:04 1457 --sha-w- c:\windows\system32\mmf(4)(2)(2).sys
2009-06-04 16:26:09 1457 --sha-w- c:\windows\system32\mmf(4)(2).sys
2009-06-03 09:35:22 1457 --sha-w- c:\windows\system32\mmf(4)(3).sys
2009-06-06 11:19:39 1457 --sha-w- c:\windows\system32\mmf(4)(4).sys
2009-06-03 09:35:22 1457 --sha-w- c:\windows\system32\mmf(4)(5).sys
2009-06-06 11:17:41 1457 --sha-w- c:\windows\system32\mmf(5)(2)(2).sys
2009-06-02 10:33:29 1457 --sha-w- c:\windows\system32\mmf(5)(2).sys
2009-06-02 10:33:29 1457 --sha-w- c:\windows\system32\mmf(5)(3).sys
2009-06-02 10:33:29 1457 --sha-w- c:\windows\system32\mmf(5)(4).sys
2009-06-06 11:15:16 1457 --sha-w- c:\windows\system32\mmf(6)(2).sys
2009-06-01 11:59:15 1457 --sha-w- c:\windows\system32\mmf(6)(3).sys
2009-06-05 15:47:48 1457 --sha-w- c:\windows\system32\mmf(7)(2).sys
2009-05-31 12:06:28 1457 --sha-w- c:\windows\system32\mmf(7)(3).sys
2009-06-05 15:42:08 1457 --sha-w- c:\windows\system32\mmf(8)(2).sys
2009-06-03 09:35:22 1457 --sha-w- c:\windows\system32\mmf(8)(3).sys
2009-05-30 10:59:32 1457 --sha-w- c:\windows\system32\mmf(8)(4).sys
2009-06-04 17:47:04 1457 --sha-w- c:\windows\system32\mmf(9)(2).sys
2009-05-29 11:16:23 1457 --sha-w- c:\windows\system32\mmf(9)(3).sys
2007-09-19 16:16:40 2039162 -csh--w- c:\windows\system32\orutv.bak2
2007-09-19 16:17:06 2038428 -csh--w- c:\windows\system32\orutv.ini2
============= FINISH: 18:08:47.12 ===============