Trojan Symptoms - Can I Avoid Reformatting All Drives [Solved] |
Trojan Symptoms - Can I Avoid Reformatting All Drives [Solved] |
Apr 27 2009, 02:24 PM
Post
#1
|
|
|
Member ![]() ![]() Posts: 17 OS: XP Pro |
Hello,
I got ahead of myself, screwed up my original post and am putting this in its place. I will attempt to delete the original, posted yesterday 04/27/09 at 4:27 PM and 6:06 PM. There is probably no way to kill that on my end, but please do if an Admin can. I am not attempting abuse the forum, and do need help, which I have gotten at Geeks to Go before. Thanks for your consideration. I had a trojan a few months back, January I think, and one of your support guys here helped me get rid of it. It was one of the Codec variants and I had it on two machines. Both machines now seem to work fairly well, but it screwed up a few things which I am still unable to correct. One of the primary messages that it caused was a "network cable unplugged" message when in fact the cables were plugged in and working, although intermittently. Also, when I would try to download new malware software or data files, it would not let those particular files download. SuperAntiSpyware finally got it I think. Some of the symptoms that I am having are symptoms that trojans or rootkits cause, slow mouse response, slow page load times, various error messages popping up (same ones over and over). I suspect that at this point they are the result of files that got deleted, etc. when we were removing the trojan, but this is just a guess. So, I am going to reformat the C: drive on at least one of the machines, probably both. I used these machines in a music recording system, Steinberg Nuendo, and have multiple drives that have been used at different times, some via USB, some via SATA. This machine needs to run a Maximum capacity, with no glitches. For years I did not hook this machine up to the Internet, except in rare instances, but slowly got careless. I do have the OS on my C: drive, a very few Programs on the C:, and most of the software and all of the data on other drives (i.e. E:, F:, etc.). So my main question is (other than you looking at my logs to see whether you see anything suspicious): What are my odds of success (a clean machine) if I just reformat my C: drive and just uninstall and reinstall some necessary programs on the other drives. Or phrased another way, what are the odds that I might have a Rootkit or Trojan hiding on one of these other drives, that might resurface after I reformat the C: drive? I think I know the ugly answer to my question, but if it is possible to say at all, . I don't really want to have to reformat all of them right now (I am backed up on all however). I know there will not be any definitive answer, but any insight by an expert would be helpful. The second machine that was infected previously is a laptop and has the OS mixed with the programs. I know that on it I will have to reformat the whole thing, but it will be much easier, as I have only used one other USB drive with it. When I do reformat the laptop, I will probably put the OS on its own partition, planning for the future, which always comes eventually. So we are really just talking about the main machine, SonHouse, and it is the SonHouse logs that are posted below. I have scanned with all of your suggested tools many times, and continue to do so. Also, I have used a tool called UnHackMe to look for Rootkits, and in all cases both computers show as clean at this time. Maybe I should post a OTLI2 log just for you to look over. I went ahead and did all of the sequence per your instructions page. If I can get by without having to reformat all of my drives, I would be a very happy guy. But I do know that trojans and viruses can move, so I may be just wishing. Also, even if I do reformat the other drives, how do I clean the data? One other question, I know you say that a given computer should only have one Virus Scanner on it at a time. What about MalWare or Spyware Scanners? Can I have BitDefender (which I am using) and MalWareBytes (which I am also using) installed at the same time. Or do you mean just don't have them running at the same time. The new BitDefender has anti-spyware built in, so what is the effect of that. This would be a good article for someone, a little more depth about what can run, and cannot run simultaneously. Thanks in advance whatever the answers. Here are my OTListIt2 (I see your suggested tool change) and Rooter Logs from last evening. <-- Here is the OTListIt2 Log --> OTListIt logfile created on: 4/26/2009 2:21:59 PM - Run 1 OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\BigDaddy\Desktop Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.13) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 100.00% Memory free 4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free Paging file location(s): C:\pagefile.sys 1488 1488; %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 93.36 Gb Total Space | 63.01 Gb Free Space | 67.49% Space Free | Partition Type: NTFS D: Drive not present or media not loaded Drive E: | 189.92 Gb Total Space | 65.16 Gb Free Space | 34.31% Space Free | Partition Type: NTFS Drive F: | 698.64 Gb Total Space | 47.75 Gb Free Space | 6.83% Space Free | Partition Type: NTFS G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: sonhouse Current User Name: BigDaddy Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Output = Minimal File Age = 30 Days Company Name Whitelist: On ========== Processes (SafeList) ========== PRC - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe (BitDefender SRL) PRC - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe (BitDefender S. R. L.) PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.) PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.) PRC - C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company) PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corp.) PRC - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.) PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation) PRC - C:\WINDOWS\system32\digi96.exe (RME) PRC - C:\WINDOWS\System32\igfxtray.exe (Intel Corporation) PRC - C:\WINDOWS\System32\hkcmd.exe (Intel Corporation) PRC - C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.) PRC - C:\Program Files\Analog Devices\SoundMAX\smax4.exe (Analog Devices, Inc.) PRC - C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation) PRC - C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation) PRC - C:\Program Files\Ahead\ODD Toolkit\DVDTray.exe (Hewlett-Packard Company) PRC - C:\Program Files\SnapStream Media\Firefly\Firefly.exe (SnapStream Media) PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.) PRC - C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe (BitDefender S.R.L.) PRC - C:\Program Files\Brownie\BrstsWnd.exe (brother) PRC - C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe () PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.) PRC - C:\Program Files\DAEMON Tools Lite\daemon.exe (DT Soft Ltd) PRC - C:\Program Files\Common Files\SnapStream\Common\X10nets.exe (X10) PRC - C:\Program Files\SnapStream Media\Beyond TV\BTVAgent2.exe () PRC - C:\Program Files\SnapStream Media\Beyond TV\BTVSettingsService.exe (SnapStream Media) PRC - C:\Program Files\SnapStream Media\Beyond TV\BTVTaskManagerService.exe (SnapStream Media) PRC - C:\Program Files\SnapStream Media\Beyond TV\BTVLibraryService.exe (SnapStream Media) PRC - C:\Program Files\SnapStream Media\Beyond TV\BTVSchedulerService.exe (SnapStream Media) PRC - C:\Program Files\SnapStream Media\Beyond TV\BTVNetworkService.exe (SnapStream Media) PRC - C:\Program Files\SnapStream Media\Beyond TV\BTVNotifierService.exe (SnapStream Media) PRC - C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe (Microsoft Corp.) PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.) PRC - C:\Program Files\SnapStream Media\Beyond TV\BTVRecordingEngine.exe (SnapStream Media) PRC - C:\Documents and Settings\BigDaddy\Desktop\OTListIt2.exe (OldTimer Tools) ========== Win32 Services (SafeList) ========== SRV - (Apple Mobile Device [Auto | Running]) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.) SRV - (Arrakis3 [On_Demand | Stopped]) -- C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe (BitDefender S.R.L. http://www.bitdefender.com) SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation) SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation) SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation) SRV - (gusvc [On_Demand | Stopped]) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google) SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation) SRV - (idsvc [Unknown | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation) SRV - (iPod Service [On_Demand | Stopped]) -- C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.) SRV - (JavaQuickStarterService [Auto | Running]) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.) SRV - (LightScribeService [Auto | Running]) -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company) SRV - (LIVESRV [Auto | Running]) -- C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe (BitDefender SRL) SRV - (NetTcpPortSharing [Disabled | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation) SRV - (scan [On_Demand | Stopped]) -- C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\scan.dll (S.C. BitDefender S.R.L) SRV - (SeaPort [Auto | Running]) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corp.) SRV - (SoundMAX Agent Service (default) [Auto | Running]) -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.) SRV - (VSSERV [Auto | Running]) -- C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe (BitDefender S. R. L.) SRV - (WMPNetworkSvc [On_Demand | Stopped]) -- C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation) SRV - (x10nets [On_Demand | Running]) -- C:\Program Files\Common Files\SnapStream\Common\X10nets.exe (X10) ========== Driver Services (SafeList) ========== DRV - (aeaudio [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\aeaudio.sys (Andrea Electronics Corporation) DRV - (ATIDACXX [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\atidacxx.sys (ATI Technologies Inc.) DRV - (ATIDDCXX [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\atiddcxx.sys (ATI Technologies Inc.) DRV - (ATIDTUXX [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\atidtuxx.sys (ATI Technologies Inc.) DRV - (ATIDVCXX [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\atidvcxx.sys (ATI Technologies Inc.) DRV - (ATIDXBXX [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\atidxbxx.sys (ATI Technologies Inc.) DRV - (bdfm [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\bdfm.sys (BitDefender S.R.L. Bucharest, ROMANIA) DRV - (Bdfndisf [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\bdfndisf.sys (BitDefender LLC) DRV - (bdfsfltr [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\bdfsfltr.sys (BitDefender S.R.L. Bucharest, ROMANIA) DRV - (bdftdif [System | Running]) -- C:\Program Files\Common Files\BitDefender\BitDefender Firewall\bdftdif.sys (BitDefender LLC) DRV - (BDSelfPr [On_Demand | Running]) -- C:\Program Files\BitDefender\BitDefender 2009\bdselfpr.sys (BitDefender S.R.L.) DRV - (BDVEDISK [Auto | Running]) -- C:\Program Files\BitDefender\BitDefender 2009\BDVEDISK.sys (BitDefender S.R.L.) DRV - (BVRPMPR5 [On_Demand | Stopped]) -- C:\windows\system32\drivers\BVRPMPR5.SYS (Avanquest Software) DRV - (digi96 [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\digi96.sys (RME) DRV - (E100B [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\e100b325.sys (Intel Corporation) DRV - (GEARAspiWDM [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.) DRV - (ialm [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ialmnt5.sys (Intel Corporation) DRV - (MidiSyn [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\MidiSyn.sys (Analog Devices Inc) DRV - (MPE [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\MPE.sys (Microsoft Corporation) DRV - (Partizan [Boot | Stopped]) -- C:\WINDOWS\system32\drivers\Partizan.sys (Greatis Software) DRV - (pavboot [Boot | Running]) -- C:\WINDOWS\system32\drivers\pavboot.sys (Panda Security, S.L.) DRV - (Point32 [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\point32.sys (Microsoft Corporation) DRV - (Profos [On_Demand | Stopped]) -- C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\profos.sys () DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.) DRV - (PxHelp20 [Boot | Running]) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions) DRV - (SASDIFSV [System | Running]) -- C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com) DRV - (SASENUM [On_Demand | Stopped]) -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com) DRV - (SASKUTIL [System | Running]) -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com) DRV - (Secdrv [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) DRV - (senfilt [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\senfilt.sys (Sensaura) DRV - (sf [System | Running]) -- C:\WINDOWS\system32\drivers\sf.sys (Sonic Focus, Inc) DRV - (smwdm [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\smwdm.sys (Analog Devices, Inc.) DRV - (sptd [Boot | Running]) -- C:\WINDOWS\System32\Drivers\sptd.sys () DRV - (SynasUSB [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\SynasUSB.sys (SIA Syncrosoft) DRV - (Trufos [On_Demand | Stopped]) -- C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\trufos.sys (BitDefender S.R.L.) DRV - (USB22LDR [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\usb22ldr.sys (MIDIMAN) DRV - (USBMN2X2 [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\usbmn2x2.sys (Doug Fetter Software Wizardry) DRV - (XUIF [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\x10ufx2.sys (X10 Wireless Technology, Inc.) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "Live Search" FF - prefs.js..browser.search.defaulturl: "http://search.live.com/results.aspx?FORM=SOLTDF&q=" FF - prefs.js..browser.search.order.1: "Ask" FF - prefs.js..browser.search.selectedEngine: "Live Search" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "http://google.com" FF - prefs.js..extensions.enabledItems: FFToolbar@bitdefender.com:2.0 FF - prefs.js..extensions.enabledItems: {77b819fa-95ad-4f2c-ac7c-486b356188a9}:1.5.20090207 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13 FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0 FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.0 FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:1.9.1.6 FF - prefs.js..extensions.enabledItems: paypalfirefoxplugin@orbiscom:2.2.19.0 FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.9 FF - prefs.js..keyword.URL: "http://search.live.com/results.aspx?FORM=SOLTDF&q=" FF - HKLM\software\mozilla\Firefox\Extensions\\paypalfirefoxplugin@orbiscom: C:\PROGRAM FILES\PAYPAL\PAYPAL PLUG-IN FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\ [2009/02/20 08:30:43 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Firefox\Extensions\\FFToolbar@bitdefender.com: C:\PROGRAM FILES\BITDEFENDER\BITDEFENDER 2009\FFTOOLBAR\ [2009/02/20 21:37:59 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Firefox\Extensions\\jqs@sun.com: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/01/27 12:36:52 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.0.9\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/04/23 17:20:49 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.0.9\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/04/23 17:20:49 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Thunderbird\Extensions\\bdThunderbird@bitdefender.com: C:\PROGRAM FILES\BITDEFENDER\BITDEFENDER 2009\TBEXTENSION\ [2009/02/20 21:38:11 | 00,000,000 | ---D | M] [2008/09/09 00:38:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\BigDaddy\Application Data\mozilla\Extensions [2008/09/09 00:38:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\BigDaddy\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} [2009/04/26 14:17:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\BigDaddy\Application Data\mozilla\Firefox\Profiles\i9417xms.default\extensions [2009/04/03 09:55:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\BigDaddy\Application Data\mozilla\Firefox\Profiles\i9417xms.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232} [2009/03/04 21:36:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\BigDaddy\Application Data\mozilla\Firefox\Profiles\i9417xms.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9} [2008/06/19 20:40:26 | 00,002,921 | ---- | M] () -- C:\Documents and Settings\BigDaddy\Application Data\Mozilla\FireFox\Profiles\i9417xms.default\searchplugins\daemon-search.xml [2009/04/26 14:06:31 | 00,001,633 | ---- | M] () -- C:\Documents and Settings\BigDaddy\Application Data\Mozilla\FireFox\Profiles\i9417xms.default\searchplugins\live-search.xml [2009/04/24 16:23:16 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions [2007/04/08 23:23:38 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c} [2009/04/23 17:20:49 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2009/01/27 12:37:11 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} [2009/04/14 22:41:04 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} [2009/04/23 17:20:40 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll [2009/04/23 17:20:41 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll [2009/04/01 08:30:05 | 00,049,664 | ---- | M] () -- C:\Program Files\mozilla firefox\components\FFComm.dll [2008/09/09 00:38:41 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml [2008/09/09 00:38:41 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml [2008/09/09 00:38:41 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml [2008/11/16 20:44:21 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml [2008/09/09 00:38:41 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml [2008/09/09 00:38:41 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml [2008/09/09 00:38:41 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml O1 HOSTS File: (302468 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: 127.0.0.1 007guard.com O1 - Hosts: 127.0.0.1 www.007guard.com O1 - Hosts: 127.0.0.1 008i.com O1 - Hosts: 127.0.0.1 008k.com O1 - Hosts: 127.0.0.1 www.008k.com O1 - Hosts: 127.0.0.1 00hq.com O1 - Hosts: 127.0.0.1 www.00hq.com O1 - Hosts: 127.0.0.1 010402.com O1 - Hosts: 127.0.0.1 032439.com O1 - Hosts: 127.0.0.1 www.032439.com O1 - Hosts: 127.0.0.1 0scan.com O1 - Hosts: 127.0.0.1 www.0scan.com O1 - Hosts: 127.0.0.1 1-2005-search.com O1 - Hosts: 127.0.0.1 www.1-2005-search.com O1 - Hosts: 127.0.0.1 1-domains-registrations.com O1 - Hosts: 127.0.0.1 www.1-domains-registrations.com O1 - Hosts: 127.0.0.1 1000gratisproben.com O1 - Hosts: 127.0.0.1 www.1000gratisproben.com O1 - Hosts: 127.0.0.1 1001namen.com O1 - Hosts: 127.0.0.1 www.1001namen.com O1 - Hosts: 127.0.0.1 100888290cs.com O1 - Hosts: 127.0.0.1 www.100888290cs.com O1 - Hosts: 127.0.0.1 100sexlinks.com O1 - Hosts: 127.0.0.1 www.100sexlinks.com O1 - Hosts: 10427 more lines... O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll (Microsoft Corp.) O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.) O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.) O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.) O2 - BHO: (MSN Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll (Microsoft Corp.) O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.) O2 - BHO: (OToolbarHelper Class) - {EAD3A971-6A23-4246-8691-C9244E858967} - C:\Program Files\PayPal\PayPal Plug-In\PayPalHelper.dll () O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll (Microsoft Corp.) O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.) O3 - HKLM\..\Toolbar: (BitDefender Toolbar) - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll (Bitdefender) O3 - HKLM\..\Toolbar: (Veoh Browser Plug-in) - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll (Veoh Networks Inc) O3 - HKLM\..\Toolbar: (PayPal Plug-In) - {DC0F2F93-27FA-4f84-ACAA-9416F90B9511} - C:\Program Files\PayPal\PayPal Plug-In\OToolbar.dll () O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.) O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - Reg Error: Key error. File not found O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated) O4 - HKLM..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe" (BitDefender S.R.L.) O4 - HKLM..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe" (BitDefender) O4 - HKLM..\Run: [BrStsWnd] C:\Program Files\Brownie\BrstsWnd.exe Autorun (brother) O4 - HKLM..\Run: [DVDTray] C:\Program Files\Ahead\ODD Toolkit\DVDTray.exe (Hewlett-Packard Company) O4 - HKLM..\Run: [Firefly] C:\Program Files\SnapStream Media\Firefly\Firefly.exe (SnapStream Media) O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe (Intel Corporation) O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe (Intel Corporation) O4 - HKLM..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe" (Microsoft Corporation) O4 - HKLM..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe" (Microsoft Corporation) O4 - HKLM..\Run: [Microsoft Default Manager] "C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume (Microsoft Corp.) O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh) O4 - HKLM..\Run: [RMETray] digi96.exe (RME) O4 - HKLM..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\smax4.exe" /tray (Analog Devices, Inc.) O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.) O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.) O4 - HKLM..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc.) O4 - HKCU..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun (DT Soft Ltd) O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.) O4 - HKLM..\RunOnceEx: [Flags] Reg Error: Invalid data type. File not found O4 - HKLM..\RunOnceEx: [Title] UnHackMe Rootkit Check File not found O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Beyond TV.lnk = C:\Program Files\SnapStream Media\Beyond TV\BTVD3DShell.exe (SnapStream Media, Inc.) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk.disabled () O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 0 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0 O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [NWLink IPX/SPX/NetBIOS Compatible Transport Protocol] - C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation) O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll (InterTrust Technologies Corporation, Inc.) O15 - HKLM\..Trusted Domains: 48 domain(s) and sub-domain(s) not assigned to a zone. O15 - HKCU\..Trusted Domains: 48 domain(s) and sub-domain(s) not assigned to a zone. O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa...director/sw.cab (Shockwave ActiveX Control) O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/8/b...heckControl.cab (Windows Genuine Advantage Validation Tool) O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab (Trend Micro ActiveX Scan Agent 6.6) O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/...b?1170029355062 (WUWebControl Class) O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat...b?1170030100531 (MUWebControl Class) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13) O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash...r/ultrashim.cab (Reg Error: Key error.) O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} http://www.crucial.com/controls/cpcScanner.cab (Crucial cpcScan) O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock...ash/swflash.cab (Shockwave Flash Object) O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.) O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Interfaces\{E8FE347E-1C8A-49D6-955C-C45B56AF0BC8}\\NameServer = 192.168.0.1,192.168.0.2 O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Filter: - x-sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com) O24 - Desktop Components:0 (My Current Home Page) - About:Home O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation) O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com) O31 - SafeBoot: AlternateShell - cmd.exe O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (autocheck) - File not found O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation) O34 - HKLM BootExecute: (*) - File not found O34 - HKLM BootExecute: (Partizan) - C:\WINDOWS\System32\Partizan.exe (Greatis Software) O34 - HKLM BootExecute: (ootExecute) - File not found O34 - HKLM BootExecute: (settings...) - File not found O34 - HKLM BootExecute: (on\E) - File not found ========== Files/Folders - Created Within 30 Days ========== [2009/04/26 13:19:13 | 00,501,248 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\BigDaddy\Desktop\OTListIt2.exe [2009/04/26 13:01:08 | 00,267,612 | ---- | C] () -- C:\Documents and Settings\BigDaddy\Desktop\Rooter.exe [2009/04/26 13:00:22 | 00,000,000 | ---D | C] -- C:\Rooter$ [2009/04/21 19:27:49 | 00,000,000 | ---D | C] -- C:\Documents and Settings\BigDaddy\My Documents\Twitter Docs [2009/04/15 04:31:03 | 00,284,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pdh.dll [2009/04/15 04:31:02 | 00,473,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fastprox.dll [2009/04/15 04:31:02 | 00,401,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rpcss.dll [2009/04/15 04:31:02 | 00,110,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\services.exe [2009/04/15 04:31:01 | 00,729,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\lsasrv.dll [2009/04/15 04:31:01 | 00,453,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmiprvsd.dll [2009/04/15 04:31:01 | 00,227,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmiprvse.exe [2009/04/15 04:31:00 | 00,617,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\advapi32.dll [2009/04/15 04:30:59 | 00,714,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntdll.dll [2009/04/15 04:30:10 | 00,002,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xpsp4res.dll [2009/04/15 04:30:09 | 01,203,922 | ---- | C] () -- C:\WINDOWS\System32\dllcache\sysmain.sdb [2009/04/15 04:30:09 | 00,215,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wordpad.exe [2009/04/14 22:42:03 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft [2009/04/12 07:58:21 | 00,001,729 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk [2009/03/30 20:36:15 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\DVD Shrink [2009/03/30 20:36:14 | 00,000,670 | ---- | C] () -- C:\Documents and Settings\BigDaddy\Desktop\DVD Shrink 3.2.lnk [2009/03/30 20:36:12 | 00,000,000 | ---D | C] -- C:\Program Files\DVD Shrink [2009/03/07 11:27:51 | 00,000,146 | ---- | C] () -- C:\WINDOWS\BRVIDEO.INI [2009/03/07 11:27:51 | 00,000,000 | ---- | C] () -- C:\WINDOWS\brmx2001.ini [2009/03/07 11:26:46 | 00,000,114 | ---- | C] () -- C:\WINDOWS\System32\brlmw03a.ini [2009/03/07 11:26:45 | 00,009,853 | ---- | C] () -- C:\WINDOWS\HL-2170W.INI [2009/03/07 11:22:41 | 00,000,291 | ---- | C] () -- C:\WINDOWS\Brownie.ini [2009/02/23 13:00:29 | 00,000,121 | ---- | C] () -- C:\WINDOWS\bdagent.INI [2009/02/08 14:10:59 | 00,000,461 | ---- | C] () -- C:\WINDOWS\Jelly.ini [2008/10/09 16:31:54 | 00,192,512 | ---- | C] () -- C:\WINDOWS\System32\txmlutil.dll [2008/09/01 18:03:52 | 00,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI [2008/07/23 09:50:52 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll [2008/07/23 09:47:34 | 00,000,416 | ---- | C] () -- C:\WINDOWS\System32\dtu100.dll.manifest [2008/07/23 09:47:34 | 00,000,416 | ---- | C] () -- C:\WINDOWS\System32\dpl100.dll.manifest [2008/07/23 09:46:38 | 00,012,288 | ---- | C] () -- C:\WINDOWS\System32\DivXWMPExtType.dll [2008/06/19 20:30:06 | 00,717,296 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys [2008/05/12 22:42:27 | 00,000,426 | ---- | C] () -- C:\WINDOWS\BRWMARK.INI [2008/05/04 00:08:14 | 00,000,032 | ---- | C] () -- C:\WINDOWS\System32\msvcsv60.dll [2007/09/27 11:51:02 | 00,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini [2007/09/27 11:48:48 | 00,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini [2007/09/27 11:48:28 | 00,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini [2007/05/26 21:41:02 | 00,000,000 | ---- | C] () -- C:\WINDOWS\iplayer.INI [2007/04/19 22:51:52 | 00,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll [2007/04/19 22:51:51 | 00,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll [2007/04/19 22:51:51 | 00,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll [2007/04/19 22:51:51 | 00,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll [2007/04/19 22:51:51 | 00,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll [2007/04/19 22:51:51 | 00,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll [2007/01/31 14:50:32 | 00,913,408 | ---- | C] () -- C:\WINDOWS\System32\xreglib.dll [2005/11/24 09:42:51 | 00,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini [2005/11/24 09:15:01 | 00,000,000 | ---- | C] () -- C:\WINDOWS\ATIMMC.INI [2005/11/23 23:16:14 | 00,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll [2005/11/21 09:18:36 | 00,000,037 | ---- | C] () -- C:\WINDOWS\Acroread.ini [2005/05/08 09:56:00 | 00,055,808 | ---- | C] () -- C:\WINDOWS\System32\zlib1.dll [2002/08/29 05:00:00 | 00,000,664 | ---- | C] () -- C:\WINDOWS\win.ini [2002/08/29 05:00:00 | 00,000,227 | ---- | C] () -- C:\WINDOWS\system.ini ========== Files - Modified Within 30 Days ========== [1 C:\WINDOWS\System32\*.tmp files] [5 C:\WINDOWS\*.tmp files] [2009/04/26 14:19:27 | 00,501,248 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\BigDaddy\Desktop\OTListIt2.exe [2009/04/26 13:52:35 | 00,000,291 | ---- | M] () -- C:\WINDOWS\Brownie.ini [2009/04/26 13:51:53 | 00,012,598 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2009/04/26 13:51:01 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT [2009/04/26 13:50:48 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2009/04/26 13:49:15 | 00,081,984 | ---- | M] () -- C:\WINDOWS\System32\bdod.bin [2009/04/26 12:55:49 | 00,267,612 | ---- | M] () -- C:\Documents and Settings\BigDaddy\Desktop\Rooter.exe [2009/04/26 01:24:26 | 00,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini [2009/04/23 09:51:03 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job [2009/04/21 19:27:22 | 00,001,507 | ---- | M] () -- C:\Documents and Settings\BigDaddy\Desktop\Notepad.lnk [2009/04/21 15:47:00 | 00,000,276 | ---- | M] () -- C:\WINDOWS\tasks\Uniblue SpeedUpMyPC Nag.job [2009/04/16 08:53:57 | 00,551,164 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI [2009/04/16 08:53:57 | 00,462,168 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2009/04/16 08:53:57 | 00,078,114 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2009/04/16 03:10:50 | 00,000,340 | ---- | M] () -- C:\WINDOWS\System32\BDUpdateV1.xml [2009/04/12 07:58:21 | 00,001,729 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk [2009/04/06 07:57:24 | 24,921,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe [2009/04/01 08:29:44 | 00,104,328 | ---- | M] (BitDefender LLC) -- C:\WINDOWS\System32\drivers\bdfndisf.sys [2009/03/30 20:36:14 | 00,000,670 | ---- | M] () -- C:\Documents and Settings\BigDaddy\Desktop\DVD Shrink 3.2.lnk ========== Alternate Data Streams ========== @Alternate Data Stream - 1238 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:yoA9MubIGHKEzbUl @Alternate Data Stream - 1121 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:K9ty5unsT444tnWigkMVu8vJ @Alternate Data Stream - 1112 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:D0JejUiHUPX6bYcaXEcZv < End of report > <-- Here is the OTListIt2 Extra Log --> OTListIt Extras logfile created on: 4/26/2009 2:21:59 PM - Run 1 OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\BigDaddy\Desktop Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.13) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 100.00% Memory free 4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free Paging file location(s): C:\pagefile.sys 1488 1488; %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 93.36 Gb Total Space | 63.01 Gb Free Space | 67.49% Space Free | Partition Type: NTFS D: Drive not present or media not loaded Drive E: | 189.92 Gb Total Space | 65.16 Gb Free Space | 34.31% Space Free | Partition Type: NTFS Drive F: | 698.64 Gb Total Space | 47.75 Gb Free Space | 6.83% Space Free | Partition Type: NTFS G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: sonhouse Current User Name: BigDaddy Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Output = Minimal File Age = 30 Days Company Name Whitelist: On ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "AntiVirusDisableNotify" = 0 "FirewallDisableNotify" = 0 "UpdatesDisableNotify" = 0 "AntiVirusOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile "EnableFirewall" = 0 "DisableNotifications" = 0 "DoNotAllowExceptions" = 0 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007 "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008 "139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004 "445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005 "137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001 "138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] C:\Program Files\SnapStream Media\Beyond TV\BTVRegistrationService.exe:*:Enabled:TV Registration Service (SnapStream Media) C:\Program Files\SnapStream Media\Beyond TV\BTVLibraryService.exe:*:Enabled:TV Library Service (SnapStream Media) C:\Program Files\SnapStream Media\Beyond TV\BTVNetworkService.exe:*:Enabled:TV Network Service (SnapStream Media) C:\Program Files\SnapStream Media\Beyond TV\BTVNotifierService.exe:*:Enabled:TV Notifier Service (SnapStream Media) C:\Program Files\SnapStream Media\Beyond TV\BTVRecordingEngine.exe:*:Enabled:TV Recording Engine (SnapStream Media) C:\Program Files\SnapStream Media\Beyond TV\BTVGuideDataLoader.exe:*:Enabled:TV Guide Data Loader (SnapStream Media) C:\Program Files\SnapStream Media\Beyond TV\BTVSettingsService.exe:*:Enabled:TV Settings Service (SnapStream Media) C:\Program Files\SnapStream Media\Beyond TV\BTVTaskManagerService.exe:*:Enabled:TV Task Manager Service (SnapStream Media) C:\Program Files\SnapStream Media\Beyond TV\BTVD3DShell.exe:*:Enabled:TV ViewScape (SnapStream Media, Inc.) C:\Program Files\SnapStream Media\Beyond TV\SetupWizard.exe:*:Enabled:TV Setup Wizard (SnapStream Media, Inc.) C:\Program Files\Azureus\Azureus.exe:*:Enabled:Azureus (Vuze Inc.) C:\Program Files\Veoh Networks\Veoh\VeohClient.exe:*:Enabled:Veoh Client (Veoh Networks) C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe:*:Enabled:SUPERAntiSpyware Free Edition (SUPERAntiSpyware.com) C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe:*:Enabled:Malwarebytes' Anti-Malware (Malwarebytes Corporation) C:\Program Files\SUPERAntiSpyware\RUNSAS.EXE:*:Enabled:SUPERAntiSpyware Alternate Start () C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer (Microsoft Corporation) C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Mozilla Firefox (Mozilla Corporation) ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR "{0405E51E-9582-4207-8F38-AC44201D3808}" = VeohTV BETA "{0570669C-39D2-4074-863C-0925BF6E4A9B}" = HP f2105 Wide LCD Driver Software "{0E4BC542-9CFD-4E97-B586-9F1E5516E7B9}" = Microsoft IntelliPoint 6.1 "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer "{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate "{1B45DFED-2510-4053-ADEB-1DE66890EF98}" = FX Teleport "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer "{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 13 "{2CCBABCB-6427-4A55-B091-49864623C43F}" = Google Toolbar for Firefox "{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}" = Rhapsody Player Engine "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{37A89DF0-5DD6-48BB-BC34-0CEB2A9E6F63}" = LS_HSI "{3EDFFD11-B9AB-4296-9757-B5AF1F2B8E5C}" = Beyond TV DVD Burning Foundation "{422182E5-97A6-4E54-B5C2-07A349A411AC}" = Brother HL-2170W "{639858DD-4966-40F3-A706-7C838BCF3A2B}" = MaxBlast 4 "{647CC6E9-7F59-4CFB-8E23-F8FD7908FC30}" = BitDefender Definitions Update "{648C1BFD-6A70-46D8-B855-F84D95C2DC34}" = CSR "{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update "{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK "{73317C31-2B6E-4B88-9865-B97C1331A39D}" = PayPal Plug-In "{777AD08E-B32A-4456-AFE1-094DBECEB268}" = Intel® Network Connections 13.5.32.0 "{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver "{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player "{8B7AED24-E1A6-41E5-A2E8-18ED56144208}" = String Machine "{8DC42D05-680B-41B0-8878-6C14D24602DB}" = QuickTime "{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo XPack (Combo) "{976C2B2A-CE59-4AB3-83FB-BF895E28F2E6}" = Apple Mobile Device Support "{98177940-C048-4831-A279-F3888B1E2C7F}" = InstallMgr "{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}" = Microsoft Search Enhancement Pack "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2 "{A7E80619-A6CC-438C-92B3-708FFC004AFE}" = BitDefender Internet Security 2009 "{A8AC89BA-D8CB-4372-9743-1C54D23286B0}" = MSN Toolbar "{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1 "{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter "{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy "{B6EF6DCE-078E-4952-A7FA-352A9C349EB0}" = MSN Toolbar "{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player "{B7148D71-0A8F-4501-96B4-4E1CC67F874E}" = Microsoft Default Manager "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2 "{C29B13CC-F0C5-4973-8980-2BCDC7C44E39}" = Beyond TV DVD Burning Foundation "{C73A3AB4-99A4-45E5-B77F-09A3065E0D6A}" = Microsoft IntelliType Pro 6.1 "{C88E49AA-41C5-4420-A08D-BE1B6C5A3A74}" = DAO "{C894366E-51C4-4162-BA82-ECBEFC1C2C61}" = PayPal Plug-In "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1 "{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{D8C2C5B1-1A88-4B87-9116-59D082B1CE30}" = Visual Studio 2005 Redist Package "{DDDE0BE3-0CBE-4BF6-B75A-E3F69C947843}" = iTunes "{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series "{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX "7-Zip" = 7-Zip 4.57 "ActiveScan 2.0" = Panda ActiveScan 2.0 "Adobe Acrobat 5.0" = Adobe Acrobat 5.0 "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Adobe Shockwave Player" = Adobe Shockwave Player 11 "Beyond TV" = SnapStream Beyond TV 4.8.1 "BFD" = BFD "CCleaner" = CCleaner (remove only) "com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com "Combined Community Codec Pack_is1" = Combined Community Codec Pack 2008-09-21 16:18 "DIGI96" = RME DIGI32, DIGI96 and Hammerfall Series "DVD Shrink_is1" = DVD Shrink 3.2 "ERUNT_is1" = ERUNT 1.1j "Firefly" = Snapstream Firefly 1.2.1.916 "Firefly Mini" = SnapStream Firefly Mini 1.0.2 "Groove Monkee Blues" = Groove Monkee Blues "Groove Monkee Country" = Groove Monkee Country "Groove Monkee Electronic" = Groove Monkee Electronic "Groove Monkee Funk HH RB" = Groove Monkee Funk HH RB "Groove Monkee Jazz" = Groove Monkee Jazz "Groove Monkee Metal" = Groove Monkee Metal "Groove Monkee Rock" = Groove Monkee Rock "Groove Monkee World Beats" = Groove Monkee World Beats "HDSP" = Steinberg ST24/96 and Nuendo 96/52 "HijackThis" = HijackThis 2.0.2 "IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs "ie7" = Windows Internet Explorer 7 "InstallShield_{0405E51E-9582-4207-8F38-AC44201D3808}" = VeohTV BETA "InstallShield_{C88E49AA-41C5-4420-A08D-BE1B6C5A3A74}" = DAO "InterActual Player" = InterActual Player "JellyFish Light 3.5" = JellyFish Light 3.5 "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1 "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "MIDIsport2x2" = Midisport 2x2 1.0.1.0 "Mozilla Firefox (3.0.9)" = Mozilla Firefox (3.0.9) "MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP "NeroMultiInstaller!UninstallKey" = Nero Suite "NI Service Center" = NI Service Center "NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs "PeerGuardian_is1" = PeerGuardian 2.0 "Steinberg Nuendo 3" = Steinberg Nuendo 3 "SubtitleWorkshop" = Subtitle Workshop 2.51 "Syncrosoft's License Control" = Syncrosoft's License Control "The KMPlayer" = The KMPlayer (remove only) "UnHackMe_is1" = UnHackMe 5.00 release "VLC media player" = VLC media player 0.9.6 "VobSub" = VobSub v2.23 (Remove Only) "Vuze" = Vuze "Windows Media Encoder 9" = Windows Media Encoder 9 Series "Windows Media Format Runtime" = Windows Media Format 11 runtime "Windows Media Player" = Windows Media Player 11 "Windows XP Service Pack" = Windows XP Service Pack 3 "WinRAR archiver" = WinRAR archiver "WMFDist11" = Windows Media Format 11 runtime "wmp11" = Windows Media Player 11 "Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0 "Yahoo! Companion" = Yahoo! Toolbar "Yahoo! Toolbar" = Yahoo! Toolbar "Zipeg" = Zipeg ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Adobe ConnectNow" = Adobe ConnectNow ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 12/17/2008 1:04:09 PM | Computer Name = SONHOUSE | Source = Application Error | ID = 1000 Description = Faulting application vlc.exe, version 0.9.6.99, faulting module libvlccore.dll, version 0.9.6.99, fault address 0x00073f37. Error - 12/19/2008 11:10:18 AM | Computer Name = SONHOUSE | Source = Application Error | ID = 1000 Description = Faulting application vlc.exe, version 0.9.6.99, faulting module avcodec-51.dll, version 0.0.0.0, fault address 0x0007678d. Error - 12/19/2008 12:09:30 PM | Computer Name = SONHOUSE | Source = Application Error | ID = 1000 Description = Faulting application vlc.exe, version 0.9.6.99, faulting module avcodec-51.dll, version 0.0.0.0, fault address 0x0007678d. Error - 12/21/2008 2:15:48 AM | Computer Name = SONHOUSE | Source = Application Error | ID = 1000 Description = Faulting application vlc.exe, version 0.9.6.99, faulting module avcodec-51.dll, version 0.0.0.0, fault address 0x0007678d. Error - 12/24/2008 12:00:24 AM | Computer Name = SONHOUSE | Source = Application Error | ID = 1000 Description = Faulting application zplayer.exe, version 5.0.0.0, faulting module libavcodec.dll, version 0.0.0.0, fault address 0x001a598e. Error - 1/9/2009 4:07:19 AM | Computer Name = SONHOUSE | Source = crypt32 | ID = 131080 Description = Failed auto update retrieval of third-party root list sequence number from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: This operation returned because the timeout period expired. Error - 1/9/2009 4:07:19 AM | Computer Name = SONHOUSE | Source = crypt32 | ID = 131080 Description = Failed auto update retrieval of third-party root list sequence number from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: The specified server cannot perform the requested operation. Error - 1/11/2009 3:54:57 AM | Computer Name = SONHOUSE | Source = Application Error | ID = 1000 Description = Faulting application msiexec.exe, version 3.1.4001.5512, faulting module msi25.tmp, version 1.1.0.0, fault address 0x00011328. Error - 1/11/2009 3:55:09 AM | Computer Name = SONHOUSE | Source = Application Error | ID = 1000 Description = Faulting application msiexec.exe, version 3.1.4001.5512, faulting module msi34.tmp, version 1.1.0.0, fault address 0x00011328. Error - 1/11/2009 3:55:11 AM | Computer Name = SONHOUSE | Source = Application Error | ID = 1000 Description = Faulting application msiexec.exe, version 3.1.4001.5512, faulting module msi35.tmp, version 1.1.0.0, fault address 0x00011328. [ System Events ] Error - 3/30/2009 1:12:36 AM | Computer Name = sonhouse | Source = Cdrom | ID = 262155 Description = The driver detected a controller error on \Device\CdRom0. Error - 4/2/2009 12:55:45 AM | Computer Name = sonhouse | Source = Service Control Manager | ID = 7000 Description = The Nsynas32 service failed to start due to the following error: %%2 Error - 4/2/2009 12:59:23 AM | Computer Name = sonhouse | Source = Service Control Manager | ID = 7000 Description = The Nsynas32 service failed to start due to the following error: %%2 Error - 4/2/2009 1:02:49 AM | Computer Name = sonhouse | Source = Service Control Manager | ID = 7000 Description = The Nsynas32 service failed to start due to the following error: %%2 Error - 4/12/2009 12:31:49 PM | Computer Name = sonhouse | Source = Service Control Manager | ID = 7034 Description = The BitDefender Virus Shield service terminated unexpectedly. It has done this 1 time(s). Error - 4/12/2009 12:40:18 PM | Computer Name = sonhouse | Source = Service Control Manager | ID = 7000 Description = The Nsynas32 service failed to start due to the following error: %%2 Error - 4/12/2009 12:58:35 PM | Computer Name = sonhouse | Source = BROWSER | ID = 8032 Description = The browser service has failed to retrieve the backup list too many times on transport \Device\NetBT_Tcpip_{E8FE347E-1C8A-49D6-955C-C45B56AF0BC8}. The backup browser is stopping. Error - 4/15/2009 9:58:52 AM | Computer Name = sonhouse | Source = Service Control Manager | ID = 7000 Description = The Nsynas32 service failed to start due to the following error: %%2 Error - 4/16/2009 6:12:08 AM | Computer Name = sonhouse | Source = Service Control Manager | ID = 7000 Description = The Nsynas32 service failed to start due to the following error: %%2 Error - 4/26/2009 4:51:17 PM | Computer Name = sonhouse | Source = Service Control Manager | ID = 7000 Description = The Nsynas32 service failed to start due to the following error: %%2 < End of report > <--------- // Next begins the Rooter Log File 04/26/09 //---------> Microsoft Windows XP Professional (5.1.2600) Service Pack 3 A:\ [Removable] (Total:0 Mo/Free:0 Mo) C:\ [Fixed] - NTFS - (Total:95605 Mo/Free:3090 Mo) D:\ [CD-Rom] (Total:0 Mo/Free:0 Mo) E:\ [Fixed] - NTFS - (Total:194474 Mo/Free:1192 Mo) F:\ [Fixed] - NTFS - (Total:715402 Mo/Free:3785 Mo) G:\ [CD-Rom] (Total:0 Mo/Free:0 Mo) Sun 04/26/2009|17:54 ----------------------\\ Processes.. --Locked-- [System Process] ---------- ???"?? ---------- \SystemRoot\System32\smss.exe ---------- \??\C:\WINDOWS\system32\csrss.exe ---------- \??\C:\WINDOWS\system32\winlogon.exe ---------- C:\WINDOWS\system32\services.exe ---------- C:\WINDOWS\system32\lsass.exe ---------- C:\WINDOWS\system32\svchost.exe ---------- C:\WINDOWS\system32\svchost.exe --Locked-- ???"?"??? --Locked-- ???"?"??? ---------- C:\WINDOWS\System32\svchost.exe ---------- C:\WINDOWS\System32\svchost.exe ---------- C:\WINDOWS\system32\spoolsv.exe ---------- C:\WINDOWS\System32\svchost.exe ---------- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe ---------- C:\Program Files\Java\jre6\bin\jqs.exe ---------- C:\Program Files\Common Files\LightScribe\LSSrvc.exe ---------- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe ---------- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe ---------- C:\WINDOWS\system32\SearchIndexer.exe ---------- C:\WINDOWS\System32\alg.exe ---------- C:\WINDOWS\Explorer.EXE ---------- C:\WINDOWS\system32\digi96.exe ---------- C:\WINDOWS\System32\igfxtray.exe ---------- C:\WINDOWS\System32\hkcmd.exe ---------- C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe ---------- C:\Program Files\Analog Devices\SoundMAX\smax4.exe ---------- C:\Program Files\Microsoft IntelliPoint\ipoint.exe ---------- C:\Program Files\Microsoft IntelliType Pro\itype.exe ---------- C:\Program Files\Ahead\ODD Toolkit\DVDTray.exe ---------- C:\Program Files\SnapStream Media\Firefly\Firefly.exe ---------- C:\Program Files\Common Files\Real\Update_OB\realsched.exe --Locked-- ???"?"??? ---------- C:\Program Files\Brownie\BrstsWnd.exe --Locked-- ???"?"??? ---------- C:\Program Files\Java\jre6\bin\jusched.exe ---------- C:\WINDOWS\system32\ctfmon.exe ---------- C:\Program Files\DAEMON Tools Lite\daemon.exe ---------- C:\PROGRA~1\COMMON~1\SNAPST~1\Common\x10nets.exe ---------- C:\Program Files\SnapStream Media\Beyond TV\BTVAgent2.exe ---------- C:\Program Files\SnapStream Media\Beyond TV\BTVSettingsService.exe ---------- C:\Program Files\SnapStream Media\Beyond TV\BTVTaskManagerService.exe ---------- C:\Program Files\SnapStream Media\Beyond TV\BTVLibraryService.exe ---------- C:\Program Files\SnapStream Media\Beyond TV\BTVSchedulerService.exe ---------- C:\Program Files\SnapStream Media\Beyond TV\BTVNetworkService.exe ---------- C:\Program Files\SnapStream Media\Beyond TV\BTVNotifierService.exe ---------- C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe ---------- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe ---------- C:\Program Files\Mozilla Firefox\firefox.exe ---------- C:\Program Files\PayPal\PayPal Plug-In\RBroker.exe ---------- C:\WINDOWS\system32\NOTEPAD.EXE ---------- C:\Program Files\SnapStream Media\Beyond TV\BTVRecordingEngine.exe ---------- C:\WINDOWS\system32\wuauclt.exe ---------- C:\WINDOWS\system32\cmd.exe ---------- C:\Rooter$\RK.exe ----------------------\\ Search.. ----------------------\\ ROOTKIT !! 1 - "C:\Rooter$\Rooter_1.txt" - Sun 04/26/2009|13:03 2 - "C:\Rooter$\Rooter_2.txt" - Sun 04/26/2009|14:03 3 - "C:\Rooter$\Rooter_3.txt" - Sun 04/26/2009|15:01 4 - "C:\Rooter$\Rooter_4.txt" - Sun 04/26/2009|17:55 ----------------------\\ Scan completed at 17:55 |
|
|
![]() |
Apr 28 2009, 10:43 AM
Post
#2
|
|
![]() GeekU Moderator Posts: 8,651 From: Massachusetts OS: Windows XP Pro, Windows 7 Pro 64- and 32-bit; Virtual PC |
Hello, tniah, and welcome to GeeksToGo!
Please download ComboFix from Here or Here to your Desktop. **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall** |
|
|
Apr 28 2009, 05:23 PM
Post
#3
|
|
|
Member ![]() ![]() Posts: 17 OS: XP Pro |
Hi Handhfan,
Thanks for looking at my files. A couple of comments, I did disable my active virus scanning software, BitDefender 2009, but your comments did not say to disable the Firewall and Bitdefender kept popping up while ComboFix was scanning. I tried to close BD a couple of times and turned off the Firewall while ComboFix was running, so I hope this did not screw up the CF scan. So do you suspect that I have an infection still, and if so, what leads you to think that? Below are the new logs. Thanks Tniah <--------- Here is the ComboFix Log ----------> ComboFix 09-04-28.02 - BigDaddy 04/28/2009 15:48.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3727.3070 [GMT -7:00] Running from: c:\documents and settings\BigDaddy\Desktop\ComboFix.exe AV: BitDefender Antivirus *On-access scanning disabled* (Updated) FW: BitDefender Firewall *enabled* * Created a new restore point . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\system32\Agent.OMZ.Fix.exe c:\windows\system32\dumphive.exe c:\windows\system32\IEDFix.C.exe c:\windows\system32\IEDFix.exe c:\windows\system32\msvcsv60.dll c:\windows\system32\o4Patch.exe c:\windows\system32\Process.exe c:\windows\system32\SrchSTS.exe c:\windows\system32\tmp.reg c:\windows\system32\VACFix.exe c:\windows\system32\VCCLSID.exe c:\windows\system32\WS2Fix.exe . ((((((((((((((((((((((((( Files Created from 2009-05-28 to 2009-4-28 ))))))))))))))))))))))))))))))) . 2009-04-26 20:00 . 2009-04-27 00:55 -------- d-----w C:\Rooter$ 2009-04-15 11:31 . 2009-03-06 14:22 284160 -c----w c:\windows\system32\dllcache\pdh.dll 2009-04-15 11:31 . 2009-02-09 12:10 401408 -c----w c:\windows\system32\dllcache\rpcss.dll 2009-04-15 11:31 . 2009-02-06 11:11 110592 -c----w c:\windows\system32\dllcache\services.exe 2009-04-15 11:31 . 2009-02-09 12:10 473600 -c----w c:\windows\system32\dllcache\fastprox.dll 2009-04-15 11:31 . 2009-02-06 10:10 227840 -c----w c:\windows\system32\dllcache\wmiprvse.exe 2009-04-15 11:31 . 2009-02-09 12:10 453120 -c----w c:\windows\system32\dllcache\wmiprvsd.dll 2009-04-15 11:31 . 2009-02-09 12:10 729088 -c----w c:\windows\system32\dllcache\lsasrv.dll 2009-04-15 11:31 . 2009-02-09 12:10 617472 -c----w c:\windows\system32\dllcache\advapi32.dll 2009-04-15 11:30 . 2009-02-09 12:10 714752 -c----w c:\windows\system32\dllcache\ntdll.dll 2009-04-15 11:30 . 2008-05-03 11:55 2560 ------w c:\windows\system32\xpsp4res.dll 2009-04-15 11:30 . 2008-04-21 12:08 215552 -c----w c:\windows\system32\dllcache\wordpad.exe 2009-04-15 05:42 . 2009-04-15 05:42 -------- d-----w c:\program files\Microsoft 2009-03-31 03:36 . 2009-03-31 03:36 -------- d-----w c:\documents and settings\All Users\Application Data\DVD Shrink 2009-03-31 03:36 . 2009-03-31 03:36 -------- d-----w c:\program files\DVD Shrink . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-04-28 22:29 . 2009-02-21 04:47 81984 ----a-w c:\windows\system32\bdod.bin 2009-04-28 21:28 . 2009-01-30 07:25 -------- d-----w c:\program files\PeerGuardian2 2009-04-27 00:28 . 2009-01-12 18:57 -------- d-----w c:\program files\ERUNT 2009-04-17 15:03 . 2008-03-08 06:30 -------- d-----w c:\program files\Azureus 2009-04-15 05:40 . 2007-03-25 19:13 -------- d-----w c:\program files\Java 2009-04-12 16:30 . 2009-02-21 04:37 -------- d-----w c:\program files\BitDefender 2009-04-12 14:57 . 2005-11-21 16:18 -------- d-----w c:\program files\Common Files\Adobe 2009-04-01 15:29 . 2009-02-04 01:03 104328 ----a-w c:\windows\system32\drivers\bdfndisf.sys 2009-04-01 14:15 . 2007-04-09 06:23 -------- d-----w c:\program files\Google 2009-04-01 14:08 . 2007-05-30 21:18 -------- d-----w c:\program files\Spybot - Search & Destroy 2009-03-20 04:12 . 2008-05-04 07:08 32 ----a-w c:\windows\msocreg32.dat 2009-03-13 09:31 . 2009-03-07 04:27 -------- d-----w c:\program files\The KMPlayer 2009-03-10 18:45 . 2009-03-09 16:41 -------- d-----w c:\program files\UnHackMe 2009-03-09 16:43 . 2009-03-09 16:43 34760 ----a-w c:\windows\system32\drivers\Partizan.sys 2009-03-09 16:43 . 2009-03-09 16:43 32480 ----a-w c:\windows\system32\Partizan.exe 2009-03-09 16:42 . 2009-03-09 16:42 2 --shatr c:\windows\winstart.bat 2009-03-09 12:19 . 2009-01-27 19:37 410984 ----a-w c:\windows\system32\deploytk.dll 2009-03-07 18:26 . 2009-03-07 18:26 -------- d-----w c:\program files\Brownie 2009-03-07 18:26 . 2009-03-07 18:26 34 ----a-w c:\windows\system32\BD2170W.DAT 2009-03-07 18:25 . 2009-03-07 18:25 -------- d-----w c:\program files\Brother 2009-03-07 18:25 . 2005-11-21 16:19 -------- d--h--w c:\program files\InstallShield Installation Information 2009-03-06 14:22 . 2002-08-29 12:00 284160 ----a-w c:\windows\system32\pdh.dll 2009-03-05 08:39 . 2008-12-21 17:33 -------- d-----w c:\program files\Combined Community Codec Pack 2009-03-03 00:18 . 2006-06-23 19:33 826368 ----a-w c:\windows\system32\wininet.dll 2009-03-01 15:42 . 2009-03-01 15:42 1337489 ----a-w C:\MGtools.exe 2009-02-28 07:07 . 2009-02-21 04:51 -------- d-----w c:\program files\Microsoft Silverlight 2009-02-20 18:09 . 2004-08-04 07:56 78336 ----a-w c:\windows\system32\ieencode.dll 2009-02-20 15:48 . 2005-11-24 16:30 14384 ----a-w c:\documents and settings\BigDaddy\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-02-11 18:19 . 2009-01-12 19:05 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys 2009-02-11 18:19 . 2009-01-12 19:05 15504 ----a-w c:\windows\system32\drivers\mbam.sys 2009-02-09 12:10 . 2002-08-29 12:00 729088 ----a-w c:\windows\system32\lsasrv.dll 2009-02-09 12:10 . 2005-07-26 04:31 401408 ----a-w c:\windows\system32\rpcss.dll 2009-02-09 12:10 . 2002-08-29 12:00 714752 ----a-w c:\windows\system32\ntdll.dll 2009-02-09 12:10 . 2002-08-29 12:00 617472 ----a-w c:\windows\system32\advapi32.dll 2009-02-09 11:13 . 2002-08-29 12:00 1846784 ----a-w c:\windows\system32\win32k.sys 2009-02-07 09:30 . 2009-02-07 09:30 724992 ----a-w c:\windows\is-VG092.exe 2009-02-07 09:02 . 2009-02-07 09:02 724992 ----a-w c:\windows\is-PHB0G.exe 2009-02-06 11:11 . 2002-08-29 12:00 110592 ----a-w c:\windows\system32\services.exe 2009-02-06 11:06 . 2002-08-29 12:00 2145280 ----a-w c:\windows\system32\ntoskrnl.exe 2009-02-06 10:39 . 2002-08-29 12:00 35328 ----a-w c:\windows\system32\sc.exe 2009-02-06 10:32 . 2002-08-29 01:04 2023936 ----a-w c:\windows\system32\ntkrnlpa.exe 2009-02-03 19:59 . 2002-08-29 12:00 56832 ----a-w c:\windows\system32\secur32.dll 2009-04-01 15:30 . 2008-10-31 01:34 49664 ----a-w c:\program files\mozilla firefox\components\FFComm.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-04-01 486856] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-28 68856] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\System32\igfxtray.exe" [2004-11-02 155648] "HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2004-11-02 126976] "SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-07-27 1388544] "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2007-02-05 849280] "itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2006-11-22 813912] "DVDTray"="c:\program files\Ahead\ODD Toolkit\DVDTray.exe" [2004-09-03 65536] "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648] "Firefly"="c:\program files\SnapStream Media\Firefly\Firefly.exe" [2006-06-06 180224] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-01-11 185896] "BDAgent"="c:\program files\BitDefender\BitDefender 2009\bdagent.exe" [2009-04-15 778240] "BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2009\IEShow.exe" [2009-04-01 69632] "BrStsWnd"="c:\program files\Brownie\BrstsWnd.exe" [2008-01-08 864256] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-28 35696] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888] "Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-02-03 233304] "RMETray"="digi96.exe" - c:\windows\system32\digi96.exe [2005-06-15 86016] c:\documents and settings\BigDaddy\Start Menu\Programs\Startup\ ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Beyond TV.lnk - c:\program files\SnapStream Media\Beyond TV\BTVD3DShell.exe [2008-3-19 208896] InterVideo WinCinema Manager.lnk.disabled [2007-4-19 1779] Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-27 304128] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-12-22 19:05 356352 ----a-w c:\program files\SUPERAntiSpyware\SASWINLO.dll HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32 "midi1"= usbmn2x2.dll "midi2"= usbmn2x2.dll "wave"= digi96.dll [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0Partizan [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-] "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" -autorun [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVRegistrationService.exe"= "c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVLibraryService.exe"= "c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVNetworkService.exe"= "c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVNotifierService.exe"= "c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVRecordingEngine.exe"= "c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVGuideDataLoader.exe"= "c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVSettingsService.exe"= "c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVTaskManagerService.exe"= "c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVD3DShell.exe"= "c:\\Program Files\\SnapStream Media\\Beyond TV\\SetupWizard.exe"= "c:\\Program Files\\Azureus\\Azureus.exe"= "c:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"= "c:\\Program Files\\SUPERAntiSpyware\\SUPERAntiSpyware.exe"= "c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"= "c:\\Program Files\\SUPERAntiSpyware\\RUNSAS.EXE"= "c:\\Program Files\\Mozilla Firefox\\firefox.exe"= R0 Partizan;Partizan;c:\windows\system32\drivers\Partizan.sys [2009-03-09 34760] R3 Arrakis3;BitDefender Arrakis Server;c:\program files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe [2008-07-17 118784] R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2008-12-22 7408] R3 TMPassthruMP;TMPassthruMP; [x] R3 USB22LDR;M-Audio USB MidiSport 2x2 Loader;c:\windows\system32\drivers\usb22ldr.sys [2006-03-26 14272] S0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2008-06-20 28544] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2008-12-22 8944] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2008-12-22 55024] S2 BDVEDISK;BDVEDISK;c:\program files\BitDefender\BitDefender 2009\BDVEDISK.sys [2008-10-07 82696] S2 digi96;RME Digi Audio Device;c:\windows\system32\DRIVERS\digi96.sys [2005-07-22 48768] S2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-15 226656] S3 ATIDACXX;ATI DTV Wonder Analog Audio Capture Device;c:\windows\system32\drivers\atidacxx.sys [2005-09-27 12800] S3 ATIDDCXX;ATI DTV Wonder Digital BDA Capture Device;c:\windows\system32\drivers\atiddcxx.sys [2005-09-27 10112] S3 ATIDTUXX;ATI DTV Wonder Digital And Analog Tuner Device;c:\windows\system32\drivers\atidtuxx.sys [2005-09-27 44544] S3 ATIDVCXX;ATI DTV Wonder Analog AV Capture Device;c:\windows\system32\drivers\atidvcxx.sys [2005-09-27 201472] S3 ATIDXBXX;ATI DTV Wonder Analog AV Crossbar Device;c:\windows\system32\drivers\atidxbxx.sys [2005-09-27 9728] S3 bdfm;bdfm;c:\windows\system32\drivers\bdfm.sys [2008-09-18 111112] S3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\DRIVERS\bdfndisf.sys [2009-04-01 104328] S3 SynasUSB;SynasUSB;c:\windows\system32\drivers\SynasUSB.sys [2005-11-03 16896] S3 USBMN2X2;M-Audio USB MidiSport 2x2;c:\windows\system32\drivers\usbmn2x2.sys [2006-03-26 22304] --- Other Services/Drivers In Memory --- *NewlyCreated* - 49902CE6 *NewlyCreated* - 86E027E6 *NewlyCreated* - GUSVC *Deregistered* - 49902ce6 *Deregistered* - 86e027e6 [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] bdx REG_MULTI_SZ scan . Contents of the 'Scheduled Tasks' folder 2009-04-23 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34] . - - - - ORPHANS REMOVED - - - - WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file) . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.com/ uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyServer = ftp=192.168.0.1:80;http=192.168.0.1:80;https=192.168.0.1:80 uSearchURL,(Default) = about:blank TCP: {E8FE347E-1C8A-49D6-955C-C45B56AF0BC8} = 192.168.0.1,192.168.0.2 Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab FF - ProfilePath - c:\documents and settings\BigDaddy\Application Data\Mozilla\Firefox\Profiles\i9417xms.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=SOLTDF&q= FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://google.com FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=SOLTDF&q= FF - prefs.js: network.proxy.http - 192.168.0.1 FF - prefs.js: network.proxy.type - 4 FF - component: c:\program files\Mozilla Firefox\components\FFComm.dll FF - component: c:\program files\PayPal\PayPal Plug-In\components\PayPalPlugin.dll FF - plugin: c:\program files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-04-28 15:50 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\System32\\OLE32.DLL" "cd042efbbd7f7af1647644e76e06692b"=hex:c8,28,51,af,b0,29,a3,98,2d,ca,1e,da,68, 64,62,c8,c8,28,51,af,b0,29,a3,98,fa,4a,70,f2,95,5b,ab,04,e2,63,26,f1,3f,c8,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\System32\\OLE32.DLL" "bca643cdc5c2726b20d2ecedcc62c59b"=hex:71,3b,04,66,8b,46,0d,96,d3,49,9d,6a,86, c2,ad,b7,71,3b,04,66,8b,46,0d,96,1c,e4,35,9d,81,2b,b4,ff,6a,9c,d6,61,af,45,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\System32\\OLE32.DLL" "2c81e34222e8052573023a60d06dd016"=hex:ff,7c,85,e0,43,d4,0e,fe,7d,aa,b3,9b,d9, 18,95,80,25,da,ec,7e,55,20,c9,26,3f,0d,cc,4e,1f,a2,f2,a0,ff,7c,85,e0,43,d4,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\System32\\OLE32.DLL" "2582ae41fb52324423be06337561aa48"=hex:3e,1e,9e,e0,57,5a,93,61,11,96,b9,4b,27, 67,6a,e2,3e,1e,9e,e0,57,5a,93,61,ce,21,b3,04,47,dc,55,1e,86,8c,21,01,be,91,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\System32\\OLE32.DLL" "caaeda5fd7a9ed7697d9686d4b818472"=hex:f5,1d,4d,73,a8,13,5c,05,fb,89,af,cb,5e, 4b,ae,f3,cd,44,cd,b9,a6,33,6c,cd,48,76,a5,dd,a5,ce,2c,03,f5,1d,4d,73,a8,13,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\System32\\OLE32.DLL" "a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:50,93,e5,ab,ec,6a,4e,ab,03,5e,43,87,e6, f5,87,9f,b0,18,ed,a7,3f,8d,37,a4,14,78,ed,00,3f,e6,53,6b,df,20,58,62,78,6b,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\System32\\OLE32.DLL" "4d370831d2c43cd13623e232fed27b7b"=hex:31,77,e1,ba,b1,f8,68,02,2c,1c,ab,c0,91, 82,91,1d,31,77,e1,ba,b1,f8,68,02,48,12,f8,fa,5c,ed,7a,39,fb,a7,78,e6,12,2f,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\System32\\OLE32.DLL" "1d68fe701cdea33e477eb204b76f993d"=hex:01,3a,48,fc,e8,04,4a,f1,38,ef,20,b5,ef, ba,73,b2,83,6c,56,8b,a0,85,96,ab,b5,85,d0,27,c8,bd,07,5b,01,3a,48,fc,e8,04,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\System32\\OLE32.DLL" "1fac81b91d8e3c5aa4b0a51804d844a3"=hex:f6,0f,4e,58,98,5b,89,c9,4e,93,e0,69,d2, 95,ef,bc,51,fa,6e,91,28,9e,14,cc,a0,c7,0e,75,2a,be,1d,eb,f6,0f,4e,58,98,5b,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\System32\\OLE32.DLL" "f5f62a6129303efb32fbe080bb27835b"=hex:b1,cd,45,5a,a8,c4,f8,b9,b1,6e,14,79,4d, f8,07,0d,b1,cd,45,5a,a8,c4,f8,b9,fd,fc,de,46,5e,66,9c,7c,3d,ce,ea,26,2d,45,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\System32\\OLE32.DLL" "fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:2a,b7,cc,b5,b9,7f,41,e7,9d,43,5c,3a,d9, 5c,37,c3,e3,0e,66,d5,eb,bc,2f,6b,7a,cb,0c,9e,48,e6,e6,c4,2a,b7,cc,b5,b9,7f,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\System32\\OLE32.DLL" "8a8aec57dd6508a385616fbc86791ec2"=hex:fa,ea,66,7f,d4,3b,6b,70,97,a7,3d,6a,20, 5f,b9,7a,fa,ea,66,7f,d4,3b,6b,70,1d,e5,e3,d0,fe,f3,f4,d0,6c,43,2d,1e,aa,22,\ . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(1028) c:\program files\SUPERAntiSpyware\SASWINLO.dll . Completion time: 2009-04-28 15:53 ComboFix-quarantined-files.txt 2009-04-28 22:53 Pre-Run: 67,407,966,208 bytes free Post-Run: 67,400,024,064 bytes free WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Professional" /Fastdetect 301 --- E O F --- 2009-04-16 10:05 <----------- THE OTLI2 Log -----------> OTListIt logfile created on: 4/28/2009 3:59:16 PM - Run 2 OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\BigDaddy\Desktop Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.13) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 100.00% Memory free 4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free Paging file location(s): C:\pagefile.sys 1488 1488; %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 93.36 Gb Total Space | 62.78 Gb Free Space | 67.24% Space Free | Partition Type: NTFS Drive D: | 79.23 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS Drive E: | 189.92 Gb Total Space | 65.16 Gb Free Space | 34.31% Space Free | Partition Type: NTFS Drive F: | 698.64 Gb Total Space | 36.06 Gb Free Space | 5.16% Space Free | Partition Type: NTFS G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: sonhouse Current User Name: BigDaddy Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Output = Minimal File Age = 30 Days Company Name Whitelist: On ========== Processes (SafeList) ========== PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.) PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.) PRC - C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company) PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corp.) PRC - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.) PRC - C:\WINDOWS\system32\digi96.exe (RME) PRC - C:\WINDOWS\System32\igfxtray.exe (Intel Corporation) PRC - C:\WINDOWS\System32\hkcmd.exe (Intel Corporation) PRC - C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.) PRC - C:\Program Files\Analog Devices\SoundMAX\smax4.exe (Analog Devices, Inc.) PRC - C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation) PRC - C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation) PRC - C:\Program Files\Ahead\ODD Toolkit\DVDTray.exe (Hewlett-Packard Company) PRC - C:\Program Files\SnapStream Media\Firefly\Firefly.exe (SnapStream Media) PRC - C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe (BitDefender S.R.L.) PRC - C:\Program Files\Brownie\BrstsWnd.exe (brother) PRC - C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe () PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.) PRC - C:\Program Files\DAEMON Tools Lite\daemon.exe (DT Soft Ltd) PRC - C:\Program Files\Common Files\SnapStream\Common\X10nets.exe (X10) PRC - C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe (Microsoft Corp.) PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.) PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.) PRC - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe (BitDefender S. R. L.) PRC - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe (BitDefender SRL) PRC - C:\WINDOWS\system32\wscntfy.exe (Microsoft Corporation) PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation) PRC - C:\Documents and Settings\BigDaddy\Desktop\OTListIt2.exe (OldTimer Tools) ========== Win32 Services (SafeList) ========== SRV - (Apple Mobile Device [Auto | Running]) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.) SRV - (Arrakis3 [On_Demand | Stopped]) -- C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe (BitDefender S.R.L. http://www.bitdefender.com) SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation) SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation) SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation) SRV - (gusvc [On_Demand | Stopped]) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google) SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation) SRV - (idsvc [Unknown | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation) SRV - (iPod Service [On_Demand | Stopped]) -- C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.) SRV - (JavaQuickStarterService [Auto | Running]) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.) SRV - (LightScribeService [Auto | Running]) -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company) SRV - (LIVESRV [Auto | Running]) -- C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe (BitDefender SRL) SRV - (NetTcpPortSharing [Disabled | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation) SRV - (scan [On_Demand | Stopped]) -- C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\scan.dll (S.C. BitDefender S.R.L) SRV - (SeaPort [Auto | Running]) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corp.) SRV - (SoundMAX Agent Service (default) [Auto | Running]) -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.) SRV - (VSSERV [Auto | Running]) -- C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe (BitDefender S. R. L.) SRV - (WMPNetworkSvc [On_Demand | Stopped]) -- C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation) SRV - (x10nets [On_Demand | Running]) -- C:\Program Files\Common Files\SnapStream\Common\X10nets.exe (X10) ========== Driver Services (SafeList) ========== DRV - (aeaudio [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\aeaudio.sys (Andrea Electronics Corporation) DRV - (ATIDACXX [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\atidacxx.sys (ATI Technologies Inc.) DRV - (ATIDDCXX [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\atiddcxx.sys (ATI Technologies Inc.) DRV - (ATIDTUXX [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\atidtuxx.sys (ATI Technologies Inc.) DRV - (ATIDVCXX [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\atidvcxx.sys (ATI Technologies Inc.) DRV - (ATIDXBXX [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\atidxbxx.sys (ATI Technologies Inc.) DRV - (bdfm [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\bdfm.sys (BitDefender S.R.L. Bucharest, ROMANIA) DRV - (Bdfndisf [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\bdfndisf.sys (BitDefender LLC) DRV - (bdfsfltr [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\bdfsfltr.sys (BitDefender S.R.L. Bucharest, ROMANIA) DRV - (bdftdif [System | Running]) -- C:\Program Files\Common Files\BitDefender\BitDefender Firewall\bdftdif.sys (BitDefender LLC) DRV - (BDSelfPr [On_Demand | Running]) -- C:\Program Files\BitDefender\BitDefender 2009\bdselfpr.sys (BitDefender S.R.L.) DRV - (BDVEDISK [Auto | Running]) -- C:\Program Files\BitDefender\BitDefender 2009\BDVEDISK.sys (BitDefender S.R.L.) DRV - (BVRPMPR5 [On_Demand | Stopped]) -- C:\windows\system32\drivers\BVRPMPR5.SYS (Avanquest Software) DRV - (digi96 [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\digi96.sys (RME) DRV - (E100B [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\e100b325.sys (Intel Corporation) DRV - (GEARAspiWDM [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.) DRV - (ialm [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ialmnt5.sys (Intel Corporation) DRV - (MidiSyn [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\MidiSyn.sys (Analog Devices Inc) DRV - (MPE [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\MPE.sys (Microsoft Corporation) DRV - (Partizan [Boot | Stopped]) -- C:\WINDOWS\system32\drivers\Partizan.sys (Greatis Software) DRV - (pavboot [Boot | Running]) -- C:\WINDOWS\system32\drivers\pavboot.sys (Panda Security, S.L.) DRV - (Point32 [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\point32.sys (Microsoft Corporation) DRV - (Profos [On_Demand | Running]) -- C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\profos.sys () DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.) DRV - (PxHelp20 [Boot | Running]) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions) DRV - (SASDIFSV [System | Running]) -- C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com) DRV - (SASENUM [On_Demand | Stopped]) -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com) DRV - (SASKUTIL [System | Running]) -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com) DRV - (Secdrv [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) DRV - (senfilt [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\senfilt.sys (Sensaura) DRV - (sf [System | Running]) -- C:\WINDOWS\system32\drivers\sf.sys (Sonic Focus, Inc) DRV - (smwdm [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\smwdm.sys (Analog Devices, Inc.) DRV - (sptd [Boot | Running]) -- C:\WINDOWS\System32\Drivers\sptd.sys (Duplex Secure Ltd.) DRV - (SynasUSB [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\SynasUSB.sys (SIA Syncrosoft) DRV - (Trufos [On_Demand | Running]) -- C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\trufos.sys (BitDefender S.R.L.) DRV - (USB22LDR [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\usb22ldr.sys (MIDIMAN) DRV - (USBMN2X2 [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\usbmn2x2.sys (Doug Fetter Software Wizardry) DRV - (XUIF [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\x10ufx2.sys (X10 Wireless Technology, Inc.) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "Live Search" FF - prefs.js..browser.search.defaulturl: "http://search.live.com/results.aspx?FORM=SOLTDF&q=" FF - prefs.js..browser.search.order.1: "Ask" FF - prefs.js..browser.search.selectedEngine: "Google" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "http://google.com" FF - prefs.js..extensions.enabledItems: FFToolbar@bitdefender.com:2.0 FF - prefs.js..extensions.enabledItems: {77b819fa-95ad-4f2c-ac7c-486b356188a9}:1.5.20090207 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13 FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0 FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.0 FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:1.9.1.6 FF - prefs.js..extensions.enabledItems: paypalfirefoxplugin@orbiscom:2.2.19.0 FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.9 FF - prefs.js..keyword.URL: "http://search.live.com/results.aspx?FORM=SOLTDF&q=" FF - HKLM\software\mozilla\Firefox\Extensions\\paypalfirefoxplugin@orbiscom: C:\PROGRAM FILES\PAYPAL\PAYPAL PLUG-IN FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\ [2009/02/20 08:30:43 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Firefox\Extensions\\FFToolbar@bitdefender.com: C:\PROGRAM FILES\BITDEFENDER\BITDEFENDER 2009\FFTOOLBAR\ [2009/02/20 21:37:59 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Firefox\Extensions\\jqs@sun.com: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/01/27 12:36:52 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.0.9\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/04/23 17:20:49 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.0.9\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/04/23 17:20:49 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Thunderbird\Extensions\\bdThunderbird@bitdefender.com: C:\PROGRAM FILES\BITDEFENDER\BITDEFENDER 2009\TBEXTENSION\ [2009/02/20 21:38:11 | 00,000,000 | ---D | M] [2008/09/09 00:38:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\BigDaddy\Application Data\mozilla\Extensions [2008/09/09 00:38:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\BigDaddy\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} [2009/04/27 20:00:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\BigDaddy\Application Data\mozilla\Firefox\Profiles\i9417xms.default\extensions [2009/04/03 09:55:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\BigDaddy\Application Data\mozilla\Firefox\Profiles\i9417xms.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232} [2009/03/04 21:36:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\BigDaddy\Application Data\mozilla\Firefox\Profiles\i9417xms.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9} [2008/06/19 20:40:26 | 00,002,921 | ---- | M] () -- C:\Documents and Settings\BigDaddy\Application Data\Mozilla\FireFox\Profiles\i9417xms.default\searchplugins\daemon-search.xml [2009/04/26 14:06:31 | 00,001,633 | ---- | M] () -- C:\Documents and Settings\BigDaddy\Application Data\Mozilla\FireFox\Profiles\i9417xms.default\searchplugins\live-search.xml [2009/04/27 20:00:42 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions [2007/04/08 23:23:38 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c} [2009/04/23 17:20:49 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2009/01/27 12:37:11 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} [2009/04/14 22:41:04 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} [2009/04/23 17:20:40 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll [2009/04/23 17:20:41 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll [2009/04/01 08:30:05 | 00,049,664 | ---- | M] () -- C:\Program Files\mozilla firefox\components\FFComm.dll [2008/09/09 00:38:41 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml [2008/09/09 00:38:41 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml [2008/09/09 00:38:41 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml [2008/11/16 20:44:21 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml [2008/09/09 00:38:41 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml [2008/09/09 00:38:41 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml [2008/09/09 00:38:41 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml O1 HOSTS File: (302468 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: 127.0.0.1 007guard.com O1 - Hosts: 127.0.0.1 www.007guard.com O1 - Hosts: 127.0.0.1 008i.com O1 - Hosts: 127.0.0.1 008k.com O1 - Hosts: 127.0.0.1 www.008k.com O1 - Hosts: 127.0.0.1 00hq.com O1 - Hosts: 127.0.0.1 www.00hq.com O1 - Hosts: 127.0.0.1 010402.com O1 - Hosts: 127.0.0.1 032439.com O1 - Hosts: 127.0.0.1 www.032439.com O1 - Hosts: 127.0.0.1 0scan.com O1 - Hosts: 127.0.0.1 www.0scan.com O1 - Hosts: 127.0.0.1 1-2005-search.com O1 - Hosts: 127.0.0.1 www.1-2005-search.com O1 - Hosts: 127.0.0.1 1-domains-registrations.com O1 - Hosts: 127.0.0.1 www.1-domains-registrations.com O1 - Hosts: 127.0.0.1 1000gratisproben.com O1 - Hosts: 127.0.0.1 www.1000gratisproben.com O1 - Hosts: 127.0.0.1 1001namen.com O1 - Hosts: 127.0.0.1 www.1001namen.com O1 - Hosts: 127.0.0.1 100888290cs.com O1 - Hosts: 127.0.0.1 www.100888290cs.com O1 - Hosts: 127.0.0.1 100sexlinks.com O1 - Hosts: 127.0.0.1 www.100sexlinks.com O1 - Hosts: 10427 more lines... O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll (Microsoft Corp.) O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.) O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.) O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.) O2 - BHO: (MSN Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll (Microsoft Corp.) O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.) O2 - BHO: (OToolbarHelper Class) - {EAD3A971-6A23-4246-8691-C9244E858967} - C:\Program Files\PayPal\PayPal Plug-In\PayPalHelper.dll () O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll (Microsoft Corp.) O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.) O3 - HKLM\..\Toolbar: (BitDefender Toolbar) - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll (Bitdefender) O3 - HKLM\..\Toolbar: (Veoh Browser Plug-in) - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll (Veoh Networks Inc) O3 - HKLM\..\Toolbar: (PayPal Plug-In) - {DC0F2F93-27FA-4f84-ACAA-9416F90B9511} - C:\Program Files\PayPal\PayPal Plug-In\OToolbar.dll () O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.) O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated) O4 - HKLM..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe" (BitDefender S.R.L.) O4 - HKLM..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe" (BitDefender) O4 - HKLM..\Run: [BrStsWnd] C:\Program Files\Brownie\BrstsWnd.exe Autorun (brother) O4 - HKLM..\Run: [DVDTray] C:\Program Files\Ahead\ODD Toolkit\DVDTray.exe (Hewlett-Packard Company) O4 - HKLM..\Run: [Firefly] C:\Program Files\SnapStream Media\Firefly\Firefly.exe (SnapStream Media) O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe (Intel Corporation) O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe (Intel Corporation) O4 - HKLM..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe" (Microsoft Corporation) O4 - HKLM..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe" (Microsoft Corporation) O4 - HKLM..\Run: [Microsoft Default Manager] "C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume (Microsoft Corp.) O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh) O4 - HKLM..\Run: [RMETray] digi96.exe (RME) O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.) O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.) O4 - HKLM..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc.) O4 - HKCU..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun (DT Soft Ltd) O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Beyond TV.lnk = C:\Program Files\SnapStream Media\Beyond TV\BTVD3DShell.exe (SnapStream Media, Inc.) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk.disabled () O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation) O4 - Startup: C:\Documents and Settings\BigDaddy\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0 O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [NWLink IPX/SPX/NetBIOS Compatible Transport Protocol] - C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation) O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll (InterTrust Technologies Corporation, Inc.) O15 - HKLM\..Trusted Domains: 48 domain(s) and sub-domain(s) not assigned to a zone. O15 - HKCU\..Trusted Domains: 48 domain(s) and sub-domain(s) not assigned to a zone. O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa...director/sw.cab (Shockwave ActiveX Control) O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/8/b...heckControl.cab (Windows Genuine Advantage Validation Tool) O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab (Trend Micro ActiveX Scan Agent 6.6) O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/...b?1170029355062 (WUWebControl Class) O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat...b?1170030100531 (MUWebControl Class) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13) O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash...r/ultrashim.cab (Reg Error: Key error.) O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} http://www.crucial.com/controls/cpcScanner.cab (Crucial cpcScan) O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock...ash/swflash.cab (Shockwave Flash Object) O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.) O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Interfaces\{E8FE347E-1C8A-49D6-955C-C45B56AF0BC8}\\NameServer = 192.168.0.1,192.168.0.2 O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Filter: - x-sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com) O24 - Desktop Components:0 (My Current Home Page) - About:Home O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation) O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com) O31 - SafeBoot: AlternateShell - cmd.exe O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (autocheck) - File not found O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation) O34 - HKLM BootExecute: (*) - File not found O34 - HKLM BootExecute: (Partizan) - C:\WINDOWS\System32\Partizan.exe (Greatis Software) ========== Files/Folders - Created Within 30 Days ========== [2009/04/28 15:47:33 | 00,000,184 | ---- | C] () -- C:\Boot.bak [2009/04/28 15:47:29 | 00,260,272 | ---- | C] () -- C:\cmldr [2009/04/28 15:47:27 | 00,000,000 | RHSD | C] -- C:\cmdcons [2009/04/28 15:45:53 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe [2009/04/28 15:45:53 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe [2009/04/28 15:45:53 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe [2009/04/28 15:45:53 | 00,113,152 | ---- | C] () -- C:\WINDOWS\vFind.exe [2009/04/28 15:45:53 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe [2009/04/28 15:45:53 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe [2009/04/28 15:45:53 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe [2009/04/28 15:45:53 | 00,029,696 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe [2009/04/28 15:45:19 | 00,000,000 | ---D | C] -- C:\Qoobox [2009/04/26 17:28:30 | 00,000,767 | ---- | C] () -- C:\Documents and Settings\BigDaddy\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk [2009/04/26 17:28:27 | 00,000,592 | ---- | C] () -- C:\Documents and Settings\BigDaddy\Desktop\ERUNT.lnk [2009/04/26 17:24:12 | 00,021,504 | ---- | C] (Doug Knox) -- C:\Documents and Settings\BigDaddy\Desktop\SysRestorePoint.exe [2009/04/26 13:19:13 | 00,501,248 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\BigDaddy\Desktop\OTListIt2.exe [2009/04/26 13:01:08 | 00,267,612 | ---- | C] () -- C:\Documents and Settings\BigDaddy\Desktop\Rooter.exe [2009/04/26 13:00:22 | 00,000,000 | ---D | C] -- C:\Rooter$ [2009/04/21 19:27:49 | 00,000,000 | ---D | C] -- C:\Documents and Settings\BigDaddy\My Documents\Twitter Docs [2009/04/15 04:31:03 | 00,284,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pdh.dll [2009/04/15 04:31:02 | 00,473,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fastprox.dll [2009/04/15 04:31:02 | 00,401,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rpcss.dll [2009/04/15 04:31:02 | 00,110,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\services.exe [2009/04/15 04:31:01 | 00,729,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\lsasrv.dll [2009/04/15 04:31:01 | 00,453,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmiprvsd.dll [2009/04/15 04:31:01 | 00,227,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmiprvse.exe [2009/04/15 04:31:00 | 00,617,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\advapi32.dll [2009/04/15 04:30:59 | 00,714,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntdll.dll [2009/04/15 04:30:10 | 00,002,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xpsp4res.dll [2009/04/15 04:30:09 | 01,203,922 | ---- | C] () -- C:\WINDOWS\System32\dllcache\sysmain.sdb [2009/04/15 04:30:09 | 00,215,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wordpad.exe [2009/04/14 22:42:03 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft [2009/04/12 07:58:21 | 00,001,729 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk [2009/03/30 20:36:15 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\DVD Shrink [2009/03/30 20:36:14 | 00,000,670 | ---- | C] () -- C:\Documents and Settings\BigDaddy\Desktop\DVD Shrink 3.2.lnk [2009/03/30 20:36:12 | 00,000,000 | ---D | C] -- C:\Program Files\DVD Shrink [2009/03/07 11:27:51 | 00,000,146 | ---- | C] () -- C:\WINDOWS\BRVIDEO.INI [2009/03/07 11:27:51 | 00,000,000 | ---- | C] () -- C:\WINDOWS\brmx2001.ini [2009/03/07 11:26:46 | 00,000,114 | ---- | C] () -- C:\WINDOWS\System32\brlmw03a.ini [2009/03/07 11:26:45 | 00,009,853 | ---- | C] () -- C:\WINDOWS\HL-2170W.INI [2009/03/07 11:22:41 | 00,000,291 | ---- | C] () -- C:\WINDOWS\Brownie.ini [2009/02/23 13:00:29 | 00,000,121 | ---- | C] () -- C:\WINDOWS\bdagent.INI [2009/02/08 14:10:59 | 00,000,461 | ---- | C] () -- C:\WINDOWS\Jelly.ini [2008/10/09 16:31:54 | 00,192,512 | ---- | C] () -- C:\WINDOWS\System32\txmlutil.dll [2008/09/01 18:03:52 | 00,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI [2008/07/23 09:50:52 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll [2008/07/23 09:47:34 | 00,000,416 | ---- | C] () -- C:\WINDOWS\System32\dtu100.dll.manifest [2008/07/23 09:47:34 | 00,000,416 | ---- | C] () -- C:\WINDOWS\System32\dpl100.dll.manifest [2008/07/23 09:46:38 | 00,012,288 | ---- | C] () -- C:\WINDOWS\System32\DivXWMPExtType.dll [2008/05/12 22:42:27 | 00,000,426 | ---- | C] () -- C:\WINDOWS\BRWMARK.INI [2007/09/27 11:51:02 | 00,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini [2007/09/27 11:48:48 | 00,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini [2007/09/27 11:48:28 | 00,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini [2007/05/26 21:41:02 | 00,000,000 | ---- | C] () -- C:\WINDOWS\iplayer.INI [2007/04/19 22:51:52 | 00,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll [2007/04/19 22:51:51 | 00,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll [2007/04/19 22:51:51 | 00,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll [2007/04/19 22:51:51 | 00,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll [2007/04/19 22:51:51 | 00,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll [2007/04/19 22:51:51 | 00,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll [2007/01/31 14:50:32 | 00,913,408 | ---- | C] () -- C:\WINDOWS\System32\xreglib.dll [2005/11/24 09:42:51 | 00,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini [2005/11/24 09:15:01 | 00,000,000 | ---- | C] () -- C:\WINDOWS\ATIMMC.INI [2005/11/23 23:16:14 | 00,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll [2005/11/21 09:18:36 | 00,000,037 | ---- | C] () -- C:\WINDOWS\Acroread.ini [2005/05/08 09:56:00 | 00,055,808 | ---- | C] () -- C:\WINDOWS\System32\zlib1.dll [2002/08/29 05:00:00 | 00,000,664 | ---- | C] () -- C:\WINDOWS\win.ini [2002/08/29 05:00:00 | 00,000,227 | ---- | C] () -- C:\WINDOWS\system.ini ========== Files - Modified Within 30 Days ========== [1 C:\WINDOWS\System32\*.tmp files] [5 C:\WINDOWS\*.tmp files] [2009/04/28 15:53:38 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT [2009/04/28 15:50:59 | 00,000,227 | ---- | M] () -- C:\WINDOWS\system.ini [2009/04/28 15:47:33 | 00,000,254 | RHS- | M] () -- C:\boot.ini [2009/04/28 15:40:23 | 00,000,426 | ---- | M] () -- C:\WINDOWS\BRWMARK.INI [2009/04/28 15:29:35 | 00,081,984 | ---- | M] () -- C:\WINDOWS\System32\bdod.bin [2009/04/28 15:29:22 | 00,000,566 | ---- | M] () -- C:\WINDOWS\System32\BDUpdateV1.xml [2009/04/28 15:28:44 | 03,007,964 | R--- | M] () -- C:\Documents and Settings\BigDaddy\Desktop\ComboFix.exe [2009/04/28 01:28:42 | 00,113,152 | ---- | M] () -- C:\WINDOWS\vFind.exe [2009/04/26 17:35:36 | 00,021,504 | ---- | M] (Doug Knox) -- C:\Documents and Settings\BigDaddy\Desktop\SysRestorePoint.exe [2009/04/26 17:28:30 | 00,000,767 | ---- | M] () -- C:\Documents and Settings\BigDaddy\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk [2009/04/26 17:28:27 | 00,000,592 | ---- | M] () -- C:\Documents and Settings\BigDaddy\Desktop\ERUNT.lnk [2009/04/26 14:19:27 | 00,501,248 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\BigDaddy\Desktop\OTListIt2.exe [2009/04/26 13:52:35 | 00,000,291 | ---- | M] () -- C:\WINDOWS\Brownie.ini [2009/04/26 13:51:53 | 00,012,598 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2009/04/26 13:50:48 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2009/04/26 12:55:49 | 00,267,612 | ---- | M] () -- C:\Documents and Settings\BigDaddy\Desktop\Rooter.exe [2009/04/26 01:24:26 | 00,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini [2009/04/23 09:51:03 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job [2009/04/21 19:27:22 | 00,001,507 | ---- | M] () -- C:\Documents and Settings\BigDaddy\Desktop\Notepad.lnk [2009/04/21 15:47:00 | 00,000,276 | ---- | M] () -- C:\WINDOWS\tasks\Uniblue SpeedUpMyPC Nag.job [2009/04/16 08:53:57 | 00,551,164 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI [2009/04/16 08:53:57 | 00,462,168 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2009/04/16 08:53:57 | 00,078,114 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2009/04/12 07:58:21 | 00,001,729 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk [2009/04/06 07:57:24 | 24,921,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe [2009/04/01 08:29:44 | 00,104,328 | ---- | M] (BitDefender LLC) -- C:\WINDOWS\System32\drivers\bdfndisf.sys [2009/03/30 20:36:14 | 00,000,670 | ---- | M] () -- C:\Documents and Settings\BigDaddy\Desktop\DVD Shrink 3.2.lnk ========== Alternate Data Streams ========== @Alternate Data Stream - 1238 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:yoA9MubIGHKEzbUl @Alternate Data Stream - 1121 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:K9ty5unsT444tnWigkMVu8vJ @Alternate Data Stream - 1112 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:D0JejUiHUPX6bYcaXEcZv < End of report > <------ NOW THE OTLI2 Extras Log ------> OTListIt Extras logfile created on: 4/28/2009 3:59:16 PM - Run 2 OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\BigDaddy\Desktop Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.13) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 100.00% Memory free 4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free Paging file location(s): C:\pagefile.sys 1488 1488; %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 93.36 Gb Total Space | 62.78 Gb Free Space | 67.24% Space Free | Partition Type: NTFS Drive D: | 79.23 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS Drive E: | 189.92 Gb Total Space | 65.16 Gb Free Space | 34.31% Space Free | Partition Type: NTFS Drive F: | 698.64 Gb Total Space | 36.06 Gb Free Space | 5.16% Space Free | Partition Type: NTFS G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: sonhouse Current User Name: BigDaddy Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Output = Minimal File Age = 30 Days Company Name Whitelist: On ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "AntiVirusDisableNotify" = 0 "FirewallDisableNotify" = 0 "UpdatesDisableNotify" = 0 "AntiVirusOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile "EnableFirewall" = 0 "DisableNotifications" = 0 "DoNotAllowExceptions" = 0 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007 "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008 "139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004 "445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005 "137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001 "138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] C:\Program Files\SnapStream Media\Beyond TV\BTVRegistrationService.exe:*:Enabled:TV Registration Service (SnapStream Media) C:\Program Files\SnapStream Media\Beyond TV\BTVLibraryService.exe:*:Enabled:TV Library Service (SnapStream Media) C:\Program Files\SnapStream Media\Beyond TV\BTVNetworkService.exe:*:Enabled:TV Network Service (SnapStream Media) C:\Program Files\SnapStream Media\Beyond TV\BTVNotifierService.exe:*:Enabled:TV Notifier Service (SnapStream Media) C:\Program Files\SnapStream Media\Beyond TV\BTVRecordingEngine.exe:*:Enabled:TV Recording Engine (SnapStream Media) C:\Program Files\SnapStream Media\Beyond TV\BTVGuideDataLoader.exe:*:Enabled:TV Guide Data Loader (SnapStream Media) C:\Program Files\SnapStream Media\Beyond TV\BTVSettingsService.exe:*:Enabled:TV Settings Service (SnapStream Media) C:\Program Files\SnapStream Media\Beyond TV\BTVTaskManagerService.exe:*:Enabled:TV Task Manager Service (SnapStream Media) C:\Program Files\SnapStream Media\Beyond TV\BTVD3DShell.exe:*:Enabled:TV ViewScape (SnapStream Media, Inc.) C:\Program Files\SnapStream Media\Beyond TV\SetupWizard.exe:*:Enabled:TV Setup Wizard (SnapStream Media, Inc.) C:\Program Files\Azureus\Azureus.exe:*:Enabled:Azureus (Vuze Inc.) C:\Program Files\Veoh Networks\Veoh\VeohClient.exe:*:Enabled:Veoh Client (Veoh Networks) C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe:*:Enabled:SUPERAntiSpyware Free Edition (SUPERAntiSpyware.com) C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe:*:Enabled:Malwarebytes' Anti-Malware (Malwarebytes Corporation) C:\Program Files\SUPERAntiSpyware\RUNSAS.EXE:*:Enabled:SUPERAntiSpyware Alternate Start () C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Mozilla Firefox (Mozilla Corporation) ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR "{0405E51E-9582-4207-8F38-AC44201D3808}" = VeohTV BETA "{0570669C-39D2-4074-863C-0925BF6E4A9B}" = HP f2105 Wide LCD Driver Software "{0E4BC542-9CFD-4E97-B586-9F1E5516E7B9}" = Microsoft IntelliPoint 6.1 "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer "{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate "{1B45DFED-2510-4053-ADEB-1DE66890EF98}" = FX Teleport "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer "{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java 6 Update 13 "{2CCBABCB-6427-4A55-B091-49864623C43F}" = Google Toolbar for Firefox "{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}" = Rhapsody Player Engine "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{37A89DF0-5DD6-48BB-BC34-0CEB2A9E6F63}" = LS_HSI "{3EDFFD11-B9AB-4296-9757-B5AF1F2B8E5C}" = Beyond TV DVD Burning Foundation "{422182E5-97A6-4E54-B5C2-07A349A411AC}" = Brother HL-2170W "{639858DD-4966-40F3-A706-7C838BCF3A2B}" = MaxBlast 4 "{647CC6E9-7F59-4CFB-8E23-F8FD7908FC30}" = BitDefender Definitions Update "{648C1BFD-6A70-46D8-B855-F84D95C2DC34}" = CSR "{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update "{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK "{73317C31-2B6E-4B88-9865-B97C1331A39D}" = PayPal Plug-In "{777AD08E-B32A-4456-AFE1-094DBECEB268}" = Intel® Network Connections 13.5.32.0 "{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver "{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player "{8DC42D05-680B-41B0-8878-6C14D24602DB}" = QuickTime "{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo XPack (Combo) "{976C2B2A-CE59-4AB3-83FB-BF895E28F2E6}" = Apple Mobile Device Support "{98177940-C048-4831-A279-F3888B1E2C7F}" = InstallMgr "{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}" = Microsoft Search Enhancement Pack "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2 "{A7E80619-A6CC-438C-92B3-708FFC004AFE}" = BitDefender Internet Security 2009 "{A8AC89BA-D8CB-4372-9743-1C54D23286B0}" = MSN Toolbar "{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1 "{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter "{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy "{B6EF6DCE-078E-4952-A7FA-352A9C349EB0}" = MSN Toolbar "{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player "{B7148D71-0A8F-4501-96B4-4E1CC67F874E}" = Microsoft Default Manager "{BA0D0121-A3BA-487D-9C78-7AB0E676C722}" = Miroslav Philharmonik "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2 "{C29B13CC-F0C5-4973-8980-2BCDC7C44E39}" = Beyond TV DVD Burning Foundation "{C73A3AB4-99A4-45E5-B77F-09A3065E0D6A}" = Microsoft IntelliType Pro 6.1 "{C88E49AA-41C5-4420-A08D-BE1B6C5A3A74}" = DAO "{C894366E-51C4-4162-BA82-ECBEFC1C2C61}" = PayPal Plug-In "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1 "{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{D8C2C5B1-1A88-4B87-9116-59D082B1CE30}" = Visual Studio 2005 Redist Package "{DDDE0BE3-0CBE-4BF6-B75A-E3F69C947843}" = iTunes "{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series "{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX "7-Zip" = 7-Zip 4.57 "ActiveScan 2.0" = Panda ActiveScan 2.0 "Adobe Acrobat 5.0" = Adobe Acrobat 5.0 "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Adobe Shockwave Player" = Adobe Shockwave Player 11 "Beyond TV" = SnapStream Beyond TV 4.8.1 "BFD" = BFD "CCleaner" = CCleaner (remove only) "com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com "Combined Community Codec Pack_is1" = Combined Community Codec Pack 2008-09-21 16:18 "DIGI96" = RME DIGI32, DIGI96 and Hammerfall Series "DVD Shrink_is1" = DVD Shrink 3.2 "ERUNT_is1" = ERUNT 1.1j "Firefly" = Snapstream Firefly 1.2.1.916 "Firefly Mini" = SnapStream Firefly Mini 1.0.2 "Groove Monkee Blues" = Groove Monkee Blues "Groove Monkee Country" = Groove Monkee Country "Groove Monkee Electronic" = Groove Monkee Electronic "Groove Monkee Funk HH RB" = Groove Monkee Funk HH RB "Groove Monkee Jazz" = Groove Monkee Jazz "Groove Monkee Metal" = Groove Monkee Metal "Groove Monkee Rock" = Groove Monkee Rock "Groove Monkee World Beats" = Groove Monkee World Beats "HDSP" = Steinberg ST24/96 and Nuendo 96/52 "HijackThis" = HijackThis 2.0.2 "IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs "ie7" = Windows Internet Explorer 7 "InstallShield_{0405E51E-9582-4207-8F38-AC44201D3808}" = VeohTV BETA "InstallShield_{C88E49AA-41C5-4420-A08D-BE1B6C5A3A74}" = DAO "InterActual Player" = InterActual Player "JellyFish Light 3.5" = JellyFish Light 3.5 "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1 "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "MIDIsport2x2" = Midisport 2x2 1.0.1.0 "Mozilla Firefox (3.0.9)" = Mozilla Firefox (3.0.9) "MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP "NeroMultiInstaller!UninstallKey" = Nero Suite "NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs "PeerGuardian_is1" = PeerGuardian 2.0 "RealPlayer 6.0" = RealPlayer "Steinberg Nuendo 3" = Steinberg Nuendo 3 "SubtitleWorkshop" = Subtitle Workshop 2.51 "Syncrosoft's License Control" = Syncrosoft's License Control "The KMPlayer" = The KMPlayer (remove only) "UnHackMe_is1" = UnHackMe 5.00 release "VLC media player" = VLC media player 0.9.6 "VobSub" = VobSub v2.23 (Remove Only) "Vuze" = Vuze "Windows Media Encoder 9" = Windows Media Encoder 9 Series "Windows Media Format Runtime" = Windows Media Format 11 runtime "Windows Media Player" = Windows Media Player 11 "Windows XP Service Pack" = Windows XP Service Pack 3 "WinRAR archiver" = WinRAR archiver "WMFDist11" = Windows Media Format 11 runtime "wmp11" = Windows Media Player 11 "Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0 "Yahoo! Companion" = Yahoo! Toolbar "Yahoo! Toolbar" = Yahoo! Toolbar "Zipeg" = Zipeg ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Adobe ConnectNow" = Adobe ConnectNow ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 12/21/2008 2:15:48 AM | Computer Name = SONHOUSE | Source = Application Error | ID = 1000 Description = Faulting application vlc.exe, version 0.9.6.99, faulting module avcodec-51.dll, version 0.0.0.0, fault address 0x0007678d. Error - 12/24/2008 12:00:24 AM | Computer Name = SONHOUSE | Source = Application Error | ID = 1000 Description = Faulting application zplayer.exe, version 5.0.0.0, faulting module libavcodec.dll, version 0.0.0.0, fault address 0x001a598e. Error - 1/9/2009 4:07:19 AM | Computer Name = SONHOUSE | Source = crypt32 | ID = 131080 Description = Failed auto update retrieval of third-party root list sequence number from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: This operation returned because the timeout period expired. Error - 1/9/2009 4:07:19 AM | Computer Name = SONHOUSE | Source = crypt32 | ID = 131080 Description = Failed auto update retrieval of third-party root list sequence number from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: The specified server cannot perform the requested operation. Error - 1/11/2009 3:54:57 AM | Computer Name = SONHOUSE | Source = Application Error | ID = 1000 Description = Faulting application msiexec.exe, version 3.1.4001.5512, faulting module msi25.tmp, version 1.1.0.0, fault address 0x00011328. Error - 1/11/2009 3:55:09 AM | Computer Name = SONHOUSE | Source = Application Error | ID = 1000 Description = Faulting application msiexec.exe, version 3.1.4001.5512, faulting module msi34.tmp, version 1.1.0.0, fault address 0x00011328. Error - 1/11/2009 3:55:11 AM | Computer Name = SONHOUSE | Source = Application Error | ID = 1000 Description = Faulting application msiexec.exe, version 3.1.4001.5512, faulting module msi35.tmp, version 1.1.0.0, fault address 0x00011328. Error - 1/11/2009 3:57:15 AM | Computer Name = SONHOUSE | Source = Application Error | ID = 1000 Description = Faulting application msiexec.exe, version 3.1.4001.5512, faulting module msi8b.tmp, version 1.1.0.0, fault address 0x00011328. Error - 1/11/2009 3:57:20 AM | Computer Name = SONHOUSE | Source = Application Error | ID = 1000 Description = Faulting application msiexec.exe, version 3.1.4001.5512, faulting module msi99.tmp, version 1.1.0.0, fault address 0x00011328. Error - 1/11/2009 3:57:23 AM | Computer Name = SONHOUSE | Source = Application Error | ID = 1000 Description = Faulting application msiexec.exe, version 3.1.4001.5512, faulting module msi9a.tmp, version 1.1.0.0, fault address 0x00011328. [ System Events ] Error - 4/2/2009 12:59:23 AM | Computer Name = sonhouse | Source = Service Control Manager | ID = 7000 Description = The Nsynas32 service failed to start due to the following error: %%2 Error - 4/2/2009 1:02:49 AM | Computer Name = sonhouse | Source = Service Control Manager | ID = 7000 Description = The Nsynas32 service failed to start due to the following error: %%2 Error - 4/12/2009 12:31:49 PM | Computer Name = sonhouse | Source = Service Control Manager | ID = 7034 Description = The BitDefender Virus Shield service terminated unexpectedly. It has done this 1 time(s). Error - 4/12/2009 12:40:18 PM | Computer Name = sonhouse | Source = Service Control Manager | ID = 7000 Description = The Nsynas32 service failed to start due to the following error: %%2 Error - 4/12/2009 12:58:35 PM | Computer Name = sonhouse | Source = BROWSER | ID = 8032 Description = The browser service has failed to retrieve the backup list too many times on transport \Device\NetBT_Tcpip_{E8FE347E-1C8A-49D6-955C-C45B56AF0BC8}. The backup browser is stopping. Error - 4/15/2009 9:58:52 AM | Computer Name = sonhouse | Source = Service Control Manager | ID = 7000 Description = The Nsynas32 service failed to start due to the following error: %%2 Error - 4/16/2009 6:12:08 AM | Computer Name = sonhouse | Source = Service Control Manager | ID = 7000 Description = The Nsynas32 service failed to start due to the following error: %%2 Error - 4/26/2009 4:51:17 PM | Computer Name = sonhouse | Source = Service Control Manager | ID = 7000 Description = The Nsynas32 service failed to start due to the following error: %%2 Error - 4/27/2009 6:29:59 PM | Computer Name = sonhouse | Source = Cdrom | ID = 262151 Description = The device, \Device\CdRom0, has a bad block. Error - 4/27/2009 6:30:29 PM | Computer Name = sonhouse | Source = Cdrom | ID = 262151 Description = The device, \Device\CdRom0, has a bad block. < End of report > |
|
|
Apr 28 2009, 05:36 PM
Post
#4
|
|
![]() GeekU Moderator Posts: 8,651 From: Massachusetts OS: Windows XP Pro, Windows 7 Pro 64- and 32-bit; Virtual PC |
Double Click mbam-setup.exe to install the application.
Extra Note: If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediatly. Please do an online scan with Kaspersky WebScanner
Please post both logs in your next reply. |
|
|
Apr 29 2009, 03:06 PM
Post
#5
|
|
|
Member ![]() ![]() Posts: 17 OS: XP Pro |
<--------- HERE IS MY MALWAREBYTES LOG ----------> Malwarebytes' Anti-Malware 1.36 Database version: 2056 Windows 5.1.2600 Service Pack 3 4/28/2009 8:23:16 PM mbam-log-2009-04-28 (20-23-16).txt Scan type: Quick Scan Objects scanned: 28637 Time elapsed: 3 minute(s), 15 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) <------------------- NOW STARTS THE KASPERSKY LOG -- IT FOUND BISS, I DON'T EVEN USE THAT PROGRAM, BUT NOT YET DELETED OR QUARANTINED ---------------------> -------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER 7.0 REPORT Wednesday, April 29, 2009 Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Program database last update: Wednesday, April 29, 2009 05:11:54 Records in database: 2089254 -------------------------------------------------------------------------------- Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: A:\ C:\ D:\ E:\ F:\ G:\ Scan statistics: Files scanned: 384848 Threat name: 1 Infected objects: 1 Suspicious objects: 0 Duration of the scan: 13:53:01 File name / Threat name / Threats count F:\Setup Files\BISS\Blocklist Manager\BLMInstall277.exe Infected: not-a-virus:NetTool.Win32.Portscan.c 1 The selected area was scanned. |
|
|
Apr 29 2009, 09:35 PM
Post
#6
|
|
![]() GeekU Moderator Posts: 8,651 From: Massachusetts OS: Windows XP Pro, Windows 7 Pro 64- and 32-bit; Virtual PC |
Your logs all look clean. Are you still experiencing problems? What issues are you having?
|
|
|
May 1 2009, 08:37 PM
Post
#7
|
|
|
Member ![]() ![]() Posts: 17 OS: XP Pro |
Mostly just slow page loading and mouse reaction. I had already scanned with several
tools before I posted, and all scans were clean, so my problems may be OS based. But I tried Windows XP Repair and it did not do much good. One thing I did think of is, I put some RAM in my machine just before I got the Codec Trojan back in February. I wonder whether I may have a RAM problem, which got partially confused with the Codec Trojan symptoms. I ran MemTest several times, and it showed good. So I am at a little bit of a loss. Therefore I thought I would reformat my C: OS drive, but not the other drives. Thus the message in my original post. Tniah |
|
|
May 1 2009, 08:42 PM
Post
#8
|
|
![]() GeekU Moderator Posts: 8,651 From: Massachusetts OS: Windows XP Pro, Windows 7 Pro 64- and 32-bit; Virtual PC |
Yeah, sounds like it may be a OS or Hardware issue. It doesn't seem malware related. Feel free to post a new topic in the Windows XP forum and give them all the details about the issue you are experiencing, and that you have gone through the malware forum already. They will best be able to help you from here out.
Your logs look clean. There is only a bit of cleanup that we will deal with in this post, as well as prevention from future infections. If you have any questions or other problems, please let me know. Other than that, and the steps below, you should be all set. Follow these steps to uninstall Combofix and tools used in the removal of malware
Please update Adobe Reader, by downloading and installing Adobe Reader 9.1. Now that you are clean, to help protect your computer in the future I recommend that you get the following free programs:
To keep your operating system up to date visit Microsoft Windows Update monthly. Remember to be aware of what emails you open and websites you visit. Have a safe and happy computing day! |
|
|
May 3 2009, 04:42 PM
Post
#9
|
|
|
Member ![]() ![]() Posts: 17 OS: XP Pro |
Handhfan,
Thanks for your help. I have uninstalled ComboFix and run the OTCleaner that you suggested. The remaining issues I will post in the hardware forum. I am going to post the logs from the laptop that I use in my DAW music system here for you to look at. But I will start a new topic for that machine with an explanation that it is related to this series of posts. I still have one question that remains unanswered, I have BitDefender 2009 as my primary VirusScanner and Firewall. I thought that BD 2009 had a Spyware scanner implemented, but now I don't see it, so maybe I was wrong about that. Regardless, my question is, can I have the spyware scanners installed while using BD 2009? I thought that you just could not have them running at the same time, but that it was OK to have them all, or at least some of them, installed. I currently have the following installed: MalWareBytes SuperAntiSpyware SpyBot S & D (but TeaTimer is not running) If BD 2009 does not have a SpyWare Scanner, can one of the Spyware scanners be running in real-time mode? I think you will get the gist. If I can leave them installed, but not running, I can used them to scan periodcally, turning off BD temporarily if necessary. Thanks for your help, Tniah |
|
|
May 3 2009, 04:45 PM
Post
#10
|
|
![]() GeekU Moderator Posts: 8,651 From: Massachusetts OS: Windows XP Pro, Windows 7 Pro 64- and 32-bit; Virtual PC |
If BD 2009 does not have a SpyWare Scanner, can one of the Spyware scanners be running in real-time mode? You are correct. Only one spyware scanner should be running in real-time (either Malwarebytes or SuperAntispyware). The other you can do an occasional scan with. It will not interfere with BitDefender. |
|
|
May 7 2009, 03:56 PM
Post
#11
|
|
![]() GeekU Moderator Posts: 8,651 From: Massachusetts OS: Windows XP Pro, Windows 7 Pro 64- and 32-bit; Virtual PC |
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic. |
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
15 / 7,741 | 17th December 2008 - 12:11 AM shuh08 started - last by emeraldnzl |
|||||
![]() |
3 / 585 | 20th January 2009 - 06:40 PM Agrona started - last by handhfan |
|||||
![]() |
2 / 329 | 23rd March 2009 - 02:06 PM goldster started - last by Rorschach112 |
|||||
![]() |
10 / 412 | 18th November 2009 - 06:23 PM green&yellow started - last by hammerman |
|||||
|
Time is now: 21st November 2009 - 11:44 PM |
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising