Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Google redirect problem [Solved]


  • This topic is locked This topic is locked

#1
Hiarashi

Hiarashi

    New Member

  • Member
  • Pip
  • 9 posts
Hello,

Like the topic says, I keep getting redirected if I click on a link through a Google search. I tried the "How to fix the Google redirect" link you guys have, but I still have the issue. Here are my logs...I couldn't run GMER because it seems to always crash a few seconds after it starts. Thanks a lot in advance.

MBAM Log:

Malwarebytes' Anti-Malware 1.44
Database version: 3613
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

2/23/2010 10:06:00 AM
mbam-log-2010-02-23 (10-05-59).txt

Scan type: Quick Scan
Objects scanned: 182959
Time elapsed: 7 minute(s), 27 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

OTL Log (And the Extra log, I don't know if that's necessary):

OTL logfile created on: 2/23/2010 9:47:53 AM - Run 1
OTL by OldTimer - Version 3.1.30.1 Folder = C:\Documents and Settings\Diego.HATTORIHANZO\My Documents\Downloads
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 57.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 76.00% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 224.87 Gb Total Space | 91.35 Gb Free Space | 40.62% Space Free | Partition Type: NTFS
Drive D: | 8.00 Gb Total Space | 1.39 Gb Free Space | 17.43% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
Drive F: | 4.35 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive K: | 9.50 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: HATTORIHANZO
Current User Name: Diego
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Processes (SafeList) ==========

PRC - [2010/02/23 09:46:57 | 000,549,376 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Diego.HATTORIHANZO\My Documents\Downloads\OTL.exe
PRC - [2010/02/20 21:20:10 | 000,908,248 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010/01/22 19:16:42 | 000,141,608 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunes\iTunesHelper.exe
PRC - [2010/01/22 19:16:30 | 000,545,576 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe
PRC - [2009/12/31 11:17:07 | 002,033,432 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgtray.exe
PRC - [2009/12/17 17:14:11 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2009/12/12 11:18:28 | 000,600,344 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgnsx.exe
PRC - [2009/12/12 11:18:28 | 000,503,576 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgrsx.exe
PRC - [2009/11/27 12:25:48 | 001,055,000 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgchsvx.exe
PRC - [2009/11/27 12:25:45 | 000,702,744 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgcsrvx.exe
PRC - [2009/11/27 12:25:39 | 000,285,392 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgwdsvc.exe
PRC - [2009/11/10 23:08:18 | 000,417,792 | ---- | M] (Apple Inc.) -- C:\Program Files\QuickTime\QTTask.exe
PRC - [2009/05/29 12:41:26 | 000,144,712 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2009/03/05 15:07:20 | 002,260,480 | RHS- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2008/12/12 10:17:38 | 000,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe
PRC - [2008/10/25 10:44:34 | 000,031,072 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
PRC - [2008/10/07 13:33:00 | 000,163,908 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe
PRC - [2008/04/13 18:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/01/19 12:49:30 | 000,103,928 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe
PRC - [2007/01/04 15:38:08 | 000,024,652 | ---- | M] (Viewpoint Corporation) -- C:\Program Files\Viewpoint\Common\ViewpointService.exe
PRC - [2006/10/18 20:05:26 | 000,204,288 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnscfg.exe
PRC - [2006/10/16 15:10:22 | 000,118,784 | ---- | M] (Nikon Corporation) -- C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
PRC - [2006/05/09 18:24:16 | 000,050,760 | ---- | M] (America Online, Inc.) -- C:\Program Files\Common Files\AOL\1184648623\ee\aolsoftware.exe
PRC - [2005/10/20 18:55:40 | 000,028,160 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ehome\RMSvc.exe
PRC - [2005/10/20 18:55:40 | 000,018,432 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ehome\RMSysTry.exe
PRC - [2005/05/12 00:40:38 | 000,204,800 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
PRC - [2005/05/11 23:23:26 | 000,282,624 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
PRC - [2005/05/11 23:16:22 | 000,077,824 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
PRC - [2005/05/08 22:04:06 | 000,053,248 | ---- | M] (Hewlett-Packard Company) -- c:\Program Files\Common Files\LightScribe\LSSrvc.exe
PRC - [2005/04/28 21:20:26 | 005,046,784 | ---- | M] (Linksys) -- C:\Program Files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WMP54GSv1_1.exe
PRC - [2005/02/02 09:44:24 | 000,061,440 | ---- | M] (Hewlett-Packard Company) -- C:\hp\KBD\KBD.exe
PRC - [2004/09/07 07:47:52 | 000,057,344 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\ALCXMNTR.EXE
PRC - [2004/08/22 16:05:02 | 000,081,920 | ---- | M] (DAEMON'S HOME) -- C:\Program Files\D-Tools\daemon.exe
PRC - [2004/06/29 04:06:38 | 000,088,363 | ---- | M] (Agere Systems) -- C:\WINDOWS\AGRSMMSG.exe
PRC - [2004/06/07 05:42:30 | 000,659,456 | ---- | M] (Hewlett-Packard) -- C:\WINDOWS\system32\hphmon06.exe
PRC - [2004/02/06 21:56:14 | 000,041,025 | ---- | M] (GEMTEKS) -- C:\Program Files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WLService.exe
PRC - [2003/12/22 07:38:42 | 000,241,664 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
PRC - [1998/05/07 03:04:38 | 000,052,736 | ---- | M] (Hewlett-Packard Company) -- c:\WINDOWS\system\hpsysdrv.exe


========== Modules (SafeList) ==========

MOD - [2010/02/23 09:46:57 | 000,549,376 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Diego.HATTORIHANZO\My Documents\Downloads\OTL.exe


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Running] -- -- (WMP54GSSVC)
SRV - File not found [On_Demand | Stopped] -- -- (NMIndexingService)
SRV - [2010/01/22 19:16:30 | 000,545,576 | ---- | M] (Apple Inc.) [On_Demand | Running] -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service)
SRV - [2009/12/17 17:14:11 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) [Auto | Running] -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2009/11/27 12:25:39 | 000,285,392 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG9\avgwdsvc.exe -- (avg9wd)
SRV - [2009/05/29 12:41:26 | 000,144,712 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2008/12/12 10:17:38 | 000,238,888 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service)
SRV - [2008/11/04 00:06:28 | 000,441,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv)
SRV - [2008/10/25 10:44:08 | 000,065,888 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe -- (Microsoft Office Groove Audit Service)
SRV - [2008/10/07 13:33:00 | 000,163,908 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\WINDOWS\system32\nvsvc32.exe -- (NVSvc)
SRV - [2007/08/16 08:56:16 | 000,309,744 | ---- | M] (Sonic Solutions) [Auto | Stopped] -- C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe -- (RoxLiveShare9)
SRV - [2007/08/16 08:56:14 | 000,166,384 | ---- | M] (Sonic Solutions) [Auto | Stopped] -- C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe -- (RoxWatch9)
SRV - [2007/08/16 08:56:10 | 001,092,080 | ---- | M] (Sonic Solutions) [On_Demand | Stopped] -- C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe -- (RoxMediaDB9)
SRV - [2007/07/24 05:14:08 | 000,088,560 | ---- | M] (Sonic Solutions) [On_Demand | Stopped] -- C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe -- (Roxio UPnP Renderer 9)
SRV - [2007/07/24 05:14:06 | 000,358,896 | ---- | M] (Sonic Solutions) [Auto | Stopped] -- C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe -- (Roxio Upnp Server 9)
SRV - [2007/01/19 11:54:14 | 000,097,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\MSN Messenger\usnsvc.exe -- (usnjsvc)
SRV - [2007/01/04 15:38:08 | 000,024,652 | ---- | M] (Viewpoint Corporation) [Auto | Running] -- C:\Program Files\Viewpoint\Common\ViewpointService.exe -- (Viewpoint Manager Service)
SRV - [2006/10/26 14:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose)
SRV - [2005/10/29 22:25:16 | 000,068,096 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe -- (Adobe LM Service)
SRV - [2005/10/20 18:55:40 | 000,028,160 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\ehome\RMSvc.exe -- (RMSvc)
SRV - [2005/05/08 22:04:06 | 000,053,248 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- c:\Program Files\Common Files\LightScribe\LSSrvc.exe -- (LightScribeService)
SRV - [2004/10/22 04:24:18 | 000,073,728 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe -- (IDriverT)
SRV - [2004/09/29 13:14:36 | 000,069,632 | ---- | M] (HP) [Auto | Stopped] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "YouTube Video Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.gamefaqs.com/"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.716
FF - prefs.js..extensions.enabledItems: [email protected]:1.0


FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2009/12/12 11:19:04 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/02/20 21:20:23 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/02/20 21:20:23 | 000,000,000 | ---D | M]

[2008/08/26 22:51:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\Mozilla\Extensions
[2010/02/21 22:24:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\Mozilla\Firefox\Profiles\8pc0a37l.default\extensions
[2008/04/07 01:31:09 | 000,002,300 | ---- | M] () -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\Mozilla\Firefox\Profiles\8pc0a37l.default\searchplugins\encyclopedia-dramatica-.xml
[2009/01/31 12:26:02 | 000,002,006 | ---- | M] () -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\Mozilla\Firefox\Profiles\8pc0a37l.default\searchplugins\urban-dictionary.xml
[2008/07/03 20:17:07 | 000,000,681 | ---- | M] () -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\Mozilla\Firefox\Profiles\8pc0a37l.default\searchplugins\webster.xml
[2008/07/03 20:17:07 | 000,001,108 | ---- | M] () -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\Mozilla\Firefox\Profiles\8pc0a37l.default\searchplugins\wikipedia-en.xml
[2009/05/10 14:41:02 | 000,003,077 | ---- | M] () -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\Mozilla\Firefox\Profiles\8pc0a37l.default\searchplugins\wikitravel-en.xml
[2007/07/01 00:14:20 | 000,001,406 | ---- | M] () -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\Mozilla\Firefox\Profiles\8pc0a37l.default\searchplugins\wowhead.xml
[2007/12/13 03:14:37 | 000,001,826 | ---- | M] () -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\Mozilla\Firefox\Profiles\8pc0a37l.default\searchplugins\wowwiki-english.xml
[2007/05/19 01:10:04 | 000,002,109 | ---- | M] () -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\Mozilla\Firefox\Profiles\8pc0a37l.default\searchplugins\youtube-video-search.xml
[2010/02/21 22:24:11 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2005/08/30 11:55:28 | 000,015,360 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\npclntax.dll
[2007/04/16 11:07:12 | 000,180,293 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll

O1 HOSTS File: ([2009/04/20 23:51:32 | 000,305,173 | R--- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 10509 more lines...
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll File not found
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O2 - BHO: (QUICKfind BHO Object) - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\Program Files\TEXTware\QUICKfind\PlugIns\IEHelp.dll ()
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O3 - HKLM\..\Toolbar: (HP view) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll (Hewlett-Packard Company)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (HP view) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll (Hewlett-Packard Company)
O3 - HKCU\..\Toolbar\WebBrowser: (HP view) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll (Hewlett-Packard Company)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [DAEMON Tools-1033] C:\Program Files\D-Tools\daemon.exe (DAEMON'S HOME)
O4 - HKLM..\Run: [GrooveMonitor] C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
O4 - HKLM..\Run: [HP Component Manager] C:\Program Files\HP\hpcoretech\hpcmpmgr.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [HPBootOp] C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe (HP)
O4 - HKLM..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe (Hewlett-Packard)
O4 - HKLM..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\imekrmig.exe (Microsoft Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe (America Online, Inc.)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\LSBurnWatcher.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Sonic Solutions)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe File not found
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe File not found
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Extender Resource Monitor.lnk = C:\WINDOWS\ehome\RMSysTry.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe (Nikon Corporation)
O4 - Startup: C:\Documents and Settings\Diego.HATTORIHANZO\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Google Search - c:\program files\google\GoogleToolbar2.dll (Google Inc.)
O8 - Extra context menu item: &Translate English Word - c:\program files\google\GoogleToolbar2.dll (Google Inc.)
O8 - Extra context menu item: Backward Links - c:\program files\google\GoogleToolbar2.dll (Google Inc.)
O8 - Extra context menu item: Cached Snapshot of Page - c:\program files\google\GoogleToolbar2.dll (Google Inc.)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Similar Pages - c:\program files\google\GoogleToolbar2.dll (Google Inc.)
O8 - Extra context menu item: Translate Page into English - c:\program files\google\GoogleToolbar2.dll (Google Inc.)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_18.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O9 - Extra 'Tools' menuitem : Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 51 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft....k/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://go.divx.com/p...owserPlugin.cab (DivXBrowserPlugin Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} http://acs.pandasoft...free/asinst.cab (ActiveScan Installer Class)
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} http://www.crucial.c.../cpcScanner.cab (Crucial cpcScan)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.ma...ent/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 68.87.77.134 68.87.72.134
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (jakegetu.dll) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop WallPaper: C:\Documents and Settings\Diego.HATTORIHANZO\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Diego.HATTORIHANZO\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/05/26 05:08:45 | 000,000,100 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2001/07/28 07:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT -- [ FAT32 ]
O32 - AutoRun File - [2004/04/30 23:01:14 | 000,000,053 | -HS- | M] () - D:\Autorun.inf -- [ FAT32 ]
O32 - AutoRun File - [2003/05/10 12:01:49 | 000,000,055 | R--- | M] () - K:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{bdb5aca8-4ed1-11de-9057-0013d352aa9b}\Shell\AutoRun\command - "" = H:\knupkb.com -- File not found
O33 - MountPoints2\{bdb5aca8-4ed1-11de-9057-0013d352aa9b}\Shell\explore\Command - "" = H:\knupkb.com -- File not found
O33 - MountPoints2\{bdb5aca8-4ed1-11de-9057-0013d352aa9b}\Shell\open\Command - "" = H:\knupkb.com -- File not found
O33 - MountPoints2\D\Shell - "" = AutoRun
O33 - MountPoints2\D\Shell\AutoRun - "" = Auto&Play
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] -- "%1" %*
O35 - exefile [open] -- "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2005/05/26 05:14:26 | 000,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (68683287341563904)

========== Files/Folders - Created Within 14 Days ==========

[2010/02/23 09:31:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Diego.HATTORIHANZO\Desktop\GooredFix Backups
[2010/02/23 09:23:43 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010/02/23 09:22:55 | 000,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2010/02/19 23:55:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Application Data\AdobeUM
[2010/02/19 14:33:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2010/02/17 20:15:26 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Diego.HATTORIHANZO\Recent
[2010/02/17 10:04:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2010/02/17 10:04:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/02/17 09:25:53 | 000,000,000 | ---D | C] -- C:\Avenger
[2010/02/17 00:22:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Application Data\Sun
[2010/02/16 23:57:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/02/14 21:59:33 | 000,000,000 | ---D | C] -- C:\Program Files\RADVideo
[2010/02/13 00:13:29 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2010/02/12 12:41:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AIM
[2010/02/12 12:41:16 | 000,000,000 | ---D | C] -- C:\Program Files\AIM7
[2010/02/12 12:41:15 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Software Update Utility
[2008/08/07 10:43:20 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2008/08/07 10:43:20 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
[2008/08/07 10:42:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2008/03/30 20:32:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Mozilla
[2008/03/30 20:32:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Mozilla
[2007/11/22 14:57:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2005/10/06 23:21:13 | 000,155,136 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\d347bus.sys
[2005/10/06 23:21:13 | 000,005,248 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\d347prt.sys

========== Files - Modified Within 14 Days ==========

[2010/02/23 09:50:45 | 015,990,784 | -H-- | M] () -- C:\Documents and Settings\Diego.HATTORIHANZO\NTUSER.DAT
[2010/02/23 09:40:25 | 000,528,084 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010/02/23 09:40:25 | 000,445,700 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/02/23 09:40:25 | 000,072,780 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/02/23 09:39:25 | 000,000,188 | ---- | M] () -- C:\WINDOWS\System\hpsysdrv.DAT
[2010/02/23 09:37:36 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/02/23 09:35:34 | 000,200,819 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2010/02/23 09:35:22 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/02/23 09:35:18 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/02/23 09:35:17 | 2145,964,032 | -HS- | M] () -- C:\hiberfil.sys
[2010/02/23 09:23:19 | 000,000,778 | ---- | M] () -- C:\Documents and Settings\Diego.HATTORIHANZO\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2010/02/23 09:21:53 | 056,121,581 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/02/22 14:01:57 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Diego.HATTORIHANZO\Local Settings\Application Data\prvlcl.dat
[2010/02/21 23:55:26 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/02/21 23:04:36 | 098,836,992 | ---- | M] () -- C:\Documents and Settings\Diego.HATTORIHANZO\Desktop\lolmilf.avi
[2010/02/20 00:24:48 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\Diego.HATTORIHANZO\ntuser.ini
[2010/02/19 23:52:01 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/02/18 23:52:20 | 000,001,125 | ---- | M] () -- C:\WINDOWS\winamp.ini
[2010/02/18 23:02:43 | 000,002,451 | ---- | M] () -- C:\WINDOWS\kaillera.ini
[2010/02/17 22:55:07 | 000,000,637 | ---- | M] () -- C:\Documents and Settings\Diego.HATTORIHANZO\Desktop\Jnes.lnk
[2010/02/17 22:00:18 | 000,000,538 | ---- | M] () -- C:\WINDOWS\WININIT.INI
[2010/02/14 22:12:45 | 000,030,720 | ---- | M] () -- C:\Documents and Settings\Diego.HATTORIHANZO\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/02/12 13:52:03 | 000,010,470 | ---- | M] () -- C:\Documents and Settings\Diego.HATTORIHANZO\My Documents\Games to Rent.docx
[2010/02/12 12:41:59 | 000,003,143 | -H-- | M] () -- C:\IPH.PH
[2010/02/09 12:35:15 | 000,012,540 | ---- | M] () -- C:\Documents and Settings\Diego.HATTORIHANZO\My Documents\Interview.docx

========== Files Created - No Company Name ==========

[2099/01/01 12:00:00 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\rewelugi
[2010/02/23 09:23:19 | 000,000,778 | ---- | C] () -- C:\Documents and Settings\Diego.HATTORIHANZO\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2010/02/21 23:04:18 | 098,836,992 | ---- | C] () -- C:\Documents and Settings\Diego.HATTORIHANZO\Desktop\lolmilf.avi
[2010/02/17 22:55:07 | 000,000,637 | ---- | C] () -- C:\Documents and Settings\Diego.HATTORIHANZO\Desktop\Jnes.lnk
[2010/02/09 12:35:15 | 000,012,540 | ---- | C] () -- C:\Documents and Settings\Diego.HATTORIHANZO\My Documents\Interview.docx
[2009/12/03 13:09:53 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Diego.HATTORIHANZO\Local Settings\Application Data\prvlcl.dat
[2009/02/25 16:36:16 | 000,000,376 | ---- | C] () -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\wklnhst.dat
[2008/11/10 22:14:41 | 000,000,538 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2008/10/07 13:33:00 | 001,703,936 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2008/10/07 13:33:00 | 001,486,848 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2008/10/07 13:33:00 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2008/10/07 13:33:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2008/10/07 13:33:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2008/02/15 16:50:10 | 000,000,032 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\ezsid.dat
[2007/08/17 16:54:43 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\Synth Textures
[2007/08/17 16:54:43 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\Sync Services
[2007/08/17 16:54:43 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLds.DAT
[2007/08/17 16:54:43 | 000,000,012 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\Techno Kit
[2007/07/29 23:46:31 | 000,000,000 | ---- | C] () -- C:\WINDOWS\iPlayer.INI
[2007/06/09 13:25:58 | 000,000,063 | ---- | C] () -- C:\WINDOWS\TEXTware.ini
[2007/06/09 13:25:53 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\TWAVBX32.DLL
[2007/06/09 13:25:52 | 000,018,432 | ---- | C] () -- C:\WINDOWS\System32\TWAIED02.DLL
[2007/06/09 13:25:51 | 000,099,092 | ---- | C] () -- C:\WINDOWS\System32\bass.dll
[2007/06/09 13:25:45 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\ILXTBS.DLL
[2007/05/22 20:53:47 | 000,000,049 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2007/03/29 00:02:04 | 000,000,000 | ---- | C] () -- C:\WINDOWS\muveeapp.INI
[2007/01/22 00:53:55 | 000,000,029 | ---- | C] () -- C:\WINDOWS\atid.ini
[2007/01/21 01:27:24 | 000,233,472 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll
[2007/01/10 03:16:54 | 000,011,776 | ---- | C] () -- C:\WINDOWS\System32\ZPORT4AS.dll
[2006/12/07 03:16:46 | 000,005,120 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2006/12/07 03:16:46 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2006/09/08 16:28:53 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT
[2006/05/09 08:51:02 | 000,002,536 | ---- | C] () -- C:\WINDOWS\EaseAudioConverter.ini
[2006/04/14 09:37:26 | 000,000,032 | ---- | C] () -- C:\WINDOWS\aceg.ini
[2005/12/25 02:27:08 | 000,002,451 | ---- | C] () -- C:\WINDOWS\kaillera.ini
[2005/10/20 23:35:01 | 000,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll
[2005/10/20 23:34:02 | 000,021,840 | ---- | C] () -- C:\WINDOWS\System32\SIntfNT.dll
[2005/10/20 23:34:02 | 000,017,212 | ---- | C] () -- C:\WINDOWS\System32\SIntf32.dll
[2005/10/20 23:34:01 | 000,012,067 | ---- | C] () -- C:\WINDOWS\System32\SIntf16.dll
[2005/10/09 14:38:34 | 000,000,026 | ---- | C] () -- C:\WINDOWS\WAR2R.INI
[2005/09/17 22:16:06 | 000,176,152 | ---- | C] () -- C:\WINDOWS\System32\CSGina.dll
[2005/09/15 12:23:20 | 000,030,720 | ---- | C] () -- C:\Documents and Settings\Diego.HATTORIHANZO\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/09/14 23:36:34 | 000,000,141 | ---- | C] () -- C:\Documents and Settings\Diego.HATTORIHANZO\Local Settings\Application Data\fusioncache.dat
[2005/09/14 22:02:05 | 000,001,695 | ---- | C] () -- C:\WINDOWS\hpdj3840.ini
[2005/09/14 22:01:48 | 000,000,516 | ---- | C] () -- C:\WINDOWS\hpbvspst.ini
[2005/09/14 14:24:37 | 000,002,917 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2005/09/14 13:21:57 | 000,001,125 | ---- | C] () -- C:\WINDOWS\winamp.ini
[2005/09/13 21:30:40 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\GTW32N50.dll
[2005/09/13 21:30:38 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\ssleay32.dll
[2005/09/13 21:30:37 | 000,651,264 | ---- | C] () -- C:\WINDOWS\System32\libeay32.dll
[2005/09/13 21:30:29 | 000,004,254 | ---- | C] () -- C:\WINDOWS\System32\WLAN.INI
[2005/08/05 13:01:54 | 000,235,008 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2005/05/26 05:10:37 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2005/05/26 05:08:00 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll
[2005/05/26 05:08:00 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll
[2005/05/26 05:08:00 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll
[2005/05/26 05:08:00 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll
[2005/05/26 05:08:00 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll
[2005/05/26 05:08:00 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll
[2005/05/26 04:39:53 | 000,015,328 | ---- | C] () -- C:\WINDOWS\System32\CHODDI.SYS
[2005/05/26 04:39:48 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\hpreg.dll
[2005/05/26 04:39:34 | 000,002,154 | ---- | C] () -- C:\WINDOWS\System32\ssmute.ini
[2005/05/26 04:36:41 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2005/05/26 04:17:16 | 000,006,468 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2005/05/26 04:16:03 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2005/05/26 03:58:07 | 000,000,791 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2005/05/26 03:55:53 | 000,016,896 | ---- | C] () -- C:\WINDOWS\System32\bcbmm.dll
[2005/04/27 12:38:00 | 000,372,736 | ---- | C] () -- C:\WINDOWS\System32\hpzidi01.dll
[2005/04/27 12:37:49 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\hpzids01.dll
[2005/02/18 04:56:18 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2005/01/19 16:45:40 | 000,090,112 | ---- | C] () -- C:\WINDOWS\System32\PcdrKernelModeServices.dll
[2005/01/19 16:45:40 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\ProgressTrace.dll
[2004/08/22 16:04:56 | 000,069,120 | ---- | C] () -- C:\WINDOWS\daemon.dll
[2004/07/26 08:51:38 | 000,000,560 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2004/03/30 01:15:02 | 000,051,200 | ---- | C] () -- C:\WINDOWS\System32\ThriXXX010205PNG.dll
[2004/03/30 01:15:01 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\ThriXXX015003JP2.dll
[2004/03/30 01:15:01 | 000,023,040 | ---- | C] () -- C:\WINDOWS\System32\ThriXXX010104Z.dll
[2004/02/26 00:18:04 | 000,565,248 | ---- | C] () -- C:\WINDOWS\System32\hpotscl.dll
[2003/05/23 04:08:52 | 000,107,008 | ---- | C] () -- C:\WINDOWS\System32\vorbis.dll
[2003/05/23 04:08:52 | 000,020,992 | ---- | C] () -- C:\WINDOWS\System32\ogg.dll
[2003/04/10 16:04:00 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\JAWTAccessBridge.dll
[2002/12/05 16:51:00 | 000,059,392 | R--- | C] () -- C:\WINDOWS\streamhlp.dll

========== LOP Check ==========

[2009/03/04 11:57:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\acccore
[2010/02/12 12:41:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AIM
[2010/01/14 12:22:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ASign
[2009/11/27 12:25:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9
[2007/08/17 16:54:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EnterNHelp
[2007/09/14 21:50:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Last.fm
[2007/03/29 00:01:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\muvee Technologies
[2007/08/17 16:55:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nikon
[2005/09/15 19:15:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Otto
[2008/09/20 18:49:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TechSmith
[2007/08/17 16:54:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ultima_T15
[2009/03/04 11:57:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/03/20 11:25:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2009/10/16 23:08:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/04/10 14:20:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2005/09/14 23:48:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\.BitTornado
[2007/07/16 23:04:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\acccore
[2005/09/14 23:39:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\Aim
[2007/06/09 13:26:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\Cambridge
[2008/09/25 21:13:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\HorizonWimba
[2005/05/26 05:18:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\InterMute
[2005/10/05 21:04:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\InterVideo
[2005/09/18 11:29:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\Leadertech
[2007/06/09 00:36:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\MSNInstaller
[2007/03/29 00:02:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\muvee Technologies
[2007/08/19 12:34:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\Nikon
[2009/01/17 22:49:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\Research In Motion
[2005/05/26 05:18:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\SampleView
[2006/12/16 02:57:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\System Requirements Lab
[2009/02/25 16:36:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\Template
[2009/03/02 23:53:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\Viewpoint

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >
[2005/10/31 09:56:00 | 000,700,416 | ---- | M] (LimeWire) -- C:\StubInstaller.exe


< MD5 for: AGP440.SYS >
[2004/08/10 05:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/09/17 20:54:51 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2004/08/09 22:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\WINDOWS\I386\sp2.cab:AGP440.sys
[2008/09/17 20:54:51 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 12:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 12:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys

< MD5 for: ATAPI.SYS >
[2004/08/10 05:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/09/17 20:54:51 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2004/08/09 22:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\WINDOWS\I386\sp2.cab:atapi.sys
[2008/09/17 20:54:51 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 12:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 12:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/03 23:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2004/08/09 22:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\i386\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/13 18:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 18:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\eventlog.dll
[2004/08/09 22:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: NETLOGON.DLL >
[2008/04/13 18:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 18:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\netlogon.dll
[2004/08/09 22:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004/08/09 22:00:00 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 18:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 18:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2008/04/13 18:11:51 | 001,267,200 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\comsvcs.dll

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2005/01/27 12:28:56 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2005/01/27 12:28:56 | 000,659,456 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2005/01/27 12:28:56 | 000,872,448 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< End of report >

OTL Extras logfile created on: 2/23/2010 9:47:53 AM - Run 1
OTL by OldTimer - Version 3.1.30.1 Folder = C:\Documents and Settings\Diego.HATTORIHANZO\My Documents\Downloads
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 57.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 76.00% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 224.87 Gb Total Space | 91.35 Gb Free Space | 40.62% Space Free | Partition Type: NTFS
Drive D: | 8.00 Gb Total Space | 1.39 Gb Free Space | 17.43% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
Drive F: | 4.35 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive K: | 9.50 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: HATTORIHANZO
Current User Name: Diego
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~1\MI1933~1\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\Winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\Winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] -- "C:\Program Files\Winamp\Winamp.exe" "%1" (Nullsoft)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"3776:UDP" = 3776:UDP:*:Enabled:Media Center Extender Service
"3390:TCP" = 3390:TCP:*:Enabled:Remote Media Center Experience
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"6112:TCP" = 6112:TCP:*:Enabled:Blizzard Downloader
"3724:TCP" = 3724:TCP:*:Enabled:Blizzard Downloader: 3724

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%ProgramFiles%\iTunes\iTunes.exe" = %ProgramFiles%\iTunes\iTunes.exe:*:enabled:iTunes -- (Apple Inc.)
"C:\Program Files\MSN Messenger\msncall.exe" = C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone) -- File not found
"C:\Program Files\AIM\aim.exe" = C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger -- File not found
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) -- (Microsoft Corporation)
"%windir%\system32\drivers\svchost.exe" = %windir%\system32\drivers\svchost.exe:*:Enabled:svchost -- File not found

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe" = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe:*:Enabled:BackWeb for Pavilion -- (Hewlett-Packard)
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink -- File not found
"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire -- File not found
"C:\sysreset\mirc.exe" = C:\sysreset\mirc.exe:*:Enabled:mIRC -- (mIRC Co. Ltd.)
"C:\Program Files\BitTornado\btdownloadgui.exe" = C:\Program Files\BitTornado\btdownloadgui.exe:*:Enabled:btdownloadgui -- ()
"C:\Program Files\Macromedia\Fireworks MX\Fireworks.exe" = C:\Program Files\Macromedia\Fireworks MX\Fireworks.exe:*:Enabled:Fireworks MX -- (Macromedia Inc.)
"C:\Program Files\Grisoft\AVG Free\avginet.exe" = C:\Program Files\Grisoft\AVG Free\avginet.exe:*:Enabled:avginet.exe -- File not found
"C:\NeverwinterNights\NWN\nwmain.exe" = C:\NeverwinterNights\NWN\nwmain.exe:*:Enabled:Neverwinter Nights -- File not found
"C:\WINDOWS\system32\windir32.exe" = C:\WINDOWS\system32\windir32.exe:*:Enabled:windir32 -- File not found
"C:\Program Files\Starcraft\StarCraft.exe" = C:\Program Files\Starcraft\StarCraft.exe:*:Enabled:Starcraft -- (Blizzard Entertainment)
"C:\Program Files\Warcraft III\Warcraft III.exe" = C:\Program Files\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III -- (Blizzard Entertainment)
"C:\Program Files\EA GAMES\Battlefield 2\BF2.exe" = C:\Program Files\EA GAMES\Battlefield 2\BF2.exe:*:Enabled:Battlefield 2 -- ()
"C:\Program Files\Dobermann\Halozero\halozero.exe" = C:\Program Files\Dobermann\Halozero\halozero.exe:*:Enabled:Halo Zero -- File not found
"C:\Documents and Settings\Diego.HATTORIHANZO\Desktop\Games\zsnesw142\zsnesw.exe" = C:\Documents and Settings\Diego.HATTORIHANZO\Desktop\Games\zsnesw142\zsnesw.exe:*:Enabled:zsnesw -- File not found
"C:\Program Files\Xfire\Xfire.exe" = C:\Program Files\Xfire\Xfire.exe:*:Enabled:Xfire -- File not found
"C:\Program Files\PlayOnline\SquareEnix\PlayOnlineViewer\pol.exe" = C:\Program Files\PlayOnline\SquareEnix\PlayOnlineViewer\pol.exe:*:Enabled:PlayOnline Viewer -- File not found
"C:\Documents and Settings\Diego.HATTORIHANZO\Desktop\MBR_Netplay\mbr_net_b7.exe" = C:\Documents and Settings\Diego.HATTORIHANZO\Desktop\MBR_Netplay\mbr_net_b7.exe:*:Enabled:mbr_net_b7 -- File not found
"C:\Documents and Settings\Diego.HATTORIHANZO\Desktop\MBR_NET_B7V2_Release\MBR_NET_B7V2_Release\mbr_net_b7v2.exe" = C:\Documents and Settings\Diego.HATTORIHANZO\Desktop\MBR_NET_B7V2_Release\MBR_NET_B7V2_Release\mbr_net_b7v2.exe:*:Enabled:mbr_net_b7v2 -- File not found
"C:\Program Files\Watanabe-Production and TYPE-MOON\Melty Blood Re-ACT Final Tuned\mbr_net_b7v2.exe" = C:\Program Files\Watanabe-Production and TYPE-MOON\Melty Blood Re-ACT Final Tuned\mbr_net_b7v2.exe:*:Enabled:mbr_net_b7v2 -- ()
"C:\Program Files\MSN Messenger\msncall.exe" = C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone) -- File not found
"C:\StubInstaller.exe" = C:\StubInstaller.exe:*:Enabled:LimeWire swarmed installer -- (LimeWire)
"C:\Documents and Settings\Diego.HATTORIHANZO\Desktop\Games\Immaterial_and_Missing_Powe1r\Immaterial and Missing Power\th075Caster060514p79a.exe" = C:\Documents and Settings\Diego.HATTORIHANZO\Desktop\Games\Immaterial_and_Missing_Powe1r\Immaterial and Missing Power\th075Caster060514p79a.exe:*:Enabled:th075Caster060514p79a -- File not found
"C:\Program Files\AIM\aim.exe" = C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger -- File not found
"C:\WINDOWS\ehome\ehshell.exe" = C:\WINDOWS\ehome\ehshell.exe:LocalSubNet:Enabled:Media Center -- (Microsoft Corporation)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger -- (Yahoo! Inc.)
"C:\Program Files\Yahoo!\Messenger\YServer.exe" = C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server -- (Yahoo! Inc.)
"C:\Program Files\TVersity\Media Server\MediaServer.exe" = C:\Program Files\TVersity\Media Server\MediaServer.exe:*:Enabled:MediaServer.exe -- File not found
"C:\Program Files\Last.fm\LastFM.exe" = C:\Program Files\Last.fm\LastFM.exe:*:Enabled:LastFM -- (Last.fm)
"C:\Program Files\Google\Google Talk\googletalk.exe" = C:\Program Files\Google\Google Talk\googletalk.exe:*:Enabled:Google Talk -- File not found
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader -- (AOL LLC)
"C:\Program Files\Grisoft\AVG Free\avgamsvr.exe" = C:\Program Files\Grisoft\AVG Free\avgamsvr.exe:*:Enabled:avgamsvr.exe -- File not found
"C:\Program Files\Grisoft\AVG Free\avgcc.exe" = C:\Program Files\Grisoft\AVG Free\avgcc.exe:*:Enabled:avgcc.exe -- File not found
"C:\Program Files\AIM6\aim6.exe" = C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM -- File not found
"C:\Program Files\World of Warcraft\WoW-1.12.0-enUS-downloader.exe" = C:\Program Files\World of Warcraft\WoW-1.12.0-enUS-downloader.exe:*:Enabled:Blizzard Downloader -- (Blizzard Entertainment)
"C:\Program Files\World of Warcraft\WoW-1.12.x-to-2.0.1-enUS-patch-downloader.exe" = C:\Program Files\World of Warcraft\WoW-1.12.x-to-2.0.1-enUS-patch-downloader.exe:*:Enabled:Blizzard Downloader -- (Blizzard Entertainment)
"C:\Program Files\World of Warcraft\WoW-2.0.3-enUS-downloader.exe" = C:\Program Files\World of Warcraft\WoW-2.0.3-enUS-downloader.exe:*:Enabled:Blizzard Downloader -- (Blizzard Entertainment)
"C:\Program Files\World of Warcraft\WoW-2.0.3.6299-to-2.0.12.6546-enUS-downloader.exe" = C:\Program Files\World of Warcraft\WoW-2.0.3.6299-to-2.0.12.6546-enUS-downloader.exe:*:Enabled:Blizzard Downloader -- (Blizzard Entertainment)
"C:\Program Files\Common Files\AOL\1184648623\ee\aolsoftware.exe" = C:\Program Files\Common Files\AOL\1184648623\ee\aolsoftware.exe:*:Enabled:AOL Services -- (America Online, Inc.)
"C:\Program Files\Common Files\AOL\1184648623\ee\aim6.exe" = C:\Program Files\Common Files\AOL\1184648623\ee\aim6.exe:*:Enabled:AIM -- (America Online, Inc.)
"C:\Program Files\World of Warcraft\BackgroundDownloader.exe" = C:\Program Files\World of Warcraft\BackgroundDownloader.exe:*:Enabled:Blizzard Downloader -- (Blizzard Entertainment)
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook -- (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE" = C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove -- (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote -- (Microsoft Corporation)
"C:\Documents and Settings\Diego.HATTORIHANZO\Desktop\snes9x-1.51-win32\snes9x.exe" = C:\Documents and Settings\Diego.HATTORIHANZO\Desktop\snes9x-1.51-win32\snes9x.exe:*:Enabled:Snes9XW -- File not found
"C:\Documents and Settings\Diego.HATTORIHANZO\Desktop\snes9k_0.09\snes9k.exe" = C:\Documents and Settings\Diego.HATTORIHANZO\Desktop\snes9k_0.09\snes9k.exe:*:Enabled:Snes9XW -- File not found
"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test -- (Microsoft Corporation)
"C:\Documents and Settings\Diego.HATTORIHANZO\Desktop\kaillerasrv-0.86-win32\kaillerasrv.exe" = C:\Documents and Settings\Diego.HATTORIHANZO\Desktop\kaillerasrv-0.86-win32\kaillerasrv.exe:*:Enabled:kaillerasrv -- File not found
"C:\Documents and Settings\Diego.HATTORIHANZO\Desktop\Games\Emulators\mameppk_bin_gcc-0.119-20070914\kaillera\kaillerasrv.exe" = C:\Documents and Settings\Diego.HATTORIHANZO\Desktop\Games\Emulators\mameppk_bin_gcc-0.119-20070914\kaillera\kaillerasrv.exe:*:Enabled:kaillerasrv -- File not found
"C:\Program Files\AVG\AVG8\avgupd.exe" = C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe -- File not found
"C:\Documents and Settings\Diego.HATTORIHANZO\Desktop\Games\Fusion351\Fusion.exe" = C:\Documents and Settings\Diego.HATTORIHANZO\Desktop\Games\Fusion351\Fusion.exe:*:Enabled:Fusion -- File not found
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) -- (Microsoft Corporation)
"C:\Program Files\EcoleSoftware\MBACWIN\exe\mbcaster.exe" = C:\Program Files\EcoleSoftware\MBACWIN\exe\mbcaster.exe:*:Enabled:mbcaster -- File not found
"C:\Program Files\EcoleSoftware\MBACWIN\mbcaster.exe" = C:\Program Files\EcoleSoftware\MBACWIN\mbcaster.exe:*:Enabled:mbcaster -- ()
"C:\Documents and Settings\Diego.HATTORIHANZO\Local Settings\Temp\Blizzard Launcher Temporary - 344b7900\Launcher.exe" = C:\Documents and Settings\Diego.HATTORIHANZO\Local Settings\Temp\Blizzard Launcher Temporary - 344b7900\Launcher.exe:*:Enabled:Blizzard Launcher -- File not found
"%windir%\system32\drivers\svchost.exe" = %windir%\system32\drivers\svchost.exe:*:Enabled:svchost -- File not found
"C:\Program Files\World of Warcraft\Launcher.exe" = C:\Program Files\World of Warcraft\Launcher.exe:*:Enabled:Blizzard Launcher -- (Blizzard Entertainment)
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour -- (Apple Inc.)
"C:\Documents and Settings\Diego.HATTORIHANZO\Desktop\WallWatcher\WallWatcher.exe" = C:\Documents and Settings\Diego.HATTORIHANZO\Desktop\WallWatcher\WallWatcher.exe:*:Enabled:WallWatcher -- File not found
"C:\Program Files\World of Warcraft\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe" = C:\Program Files\World of Warcraft\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe:*:Enabled:Blizzard Downloader -- (Blizzard Entertainment)
"C:\Program Files\World of Warcraft\WoW-3.2.0.10192-to-3.2.0.10314-enUS-downloader.exe" = C:\Program Files\World of Warcraft\WoW-3.2.0.10192-to-3.2.0.10314-enUS-downloader.exe:*:Enabled:Blizzard Downloader -- (Blizzard Entertainment)
"C:\Program Files\World of Warcraft\WoW-3.2.0.10314-to-3.2.2.10482-enUS-downloader.exe" = C:\Program Files\World of Warcraft\WoW-3.2.0.10314-to-3.2.2.10482-enUS-downloader.exe:*:Enabled:Blizzard Downloader -- (Blizzard Entertainment)
"C:\Program Files\World of Warcraft\WoW-3.2.2.10482-to-3.2.2.10505-enUS-downloader.exe" = C:\Program Files\World of Warcraft\WoW-3.2.2.10482-to-3.2.2.10505-enUS-downloader.exe:*:Enabled:Blizzard Downloader -- (Blizzard Entertainment)
"C:\Program Files\AVG\AVG9\avgupd.exe" = C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgnsx.exe" = C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath -- (Skype Technologies S.A.)
"C:\Program Files\AIM7\aim.exe" = C:\Program Files\AIM7\aim.exe:*:Enabled:AIM -- (AOL LLC)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{03ABC33C-10B1-400E-B1FA-E817FE98D11C}" = YUME MIRU KUSURI
"{04858915-9F49-4B2A-AED4-DC49A7DE6A7B}" = Battlefield 2™
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic RecordNow Data
"{09984AEC-6B9F-4ca7-B78D-CB44D4771DA3}" = Destinations
"{0E484A60-A429-49A8-982C-D6475F1E80A9}" = HPIZplus450
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{14589F05-C658-4594-9429-D437BA688686}" = IntelliMover Data Transfer Demo
"{14BEB6DF-A499-4A38-8E06-E173BCD5C087}" = ScannerCopy
"{15EE79F4-4ED1-4267-9B0F-351009325D7D}" = HP Software Update
"{18E0918E-1060-48f3-925C-56C82E88551B}" = HP PSC & OfficeJet 3.5
"{19C989C4-50AE-43A4-B06E-8C70FFFF852F}" = PC-Doctor for Windows
"{1AD5F465-8282-4DAD-B957-E09C0B783D18}" = InstantShare
"{1B680FBA-E317-4E93-AF43-3B59798A4BE0}" = Copy
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD Plus
"{23FE964A-853B-4176-86D7-9E18B5CA1FC0}" = Media Center Extender
"{24FBE9FC-6C0E-4221-AE41-55A40BEFE93F}" = CameraDrivers
"{257EC58E-03FD-472B-A9B6-93F23A3C4CB0}" = Scan
"{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java™ 6 Update 18
"{272EC8BA-5A08-4ea1-A189-684466A06B02}" = cp_dwShrek2Albums1
"{28CFF19D-B92C-4109-A427-F75505E81688}" = cp_dwSharkTaleAlbums1
"{2C5D07FB-31A2-4F2D-9FDA-0B24ACD42BD0}" = HP Deskjet Printer Preload
"{2E8428AD-6CD2-4031-916A-3CF9BBF2DEC9}" = Unload
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{30C19FF2-7FBA-4d09-B9DE-1659977F64F6}" = TrayApp
"{3248F0A8-6813-11D6-A77B-00B0D0150110}" = J2SE Runtime Environment 5.0 Update 11
"{32498B7B-E1F3-4ad5-A23B-F26414E94BE0}" = HP Image Zone Plus 4.8.6
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35B8D05F-F52A-4356-9629-844A3E52DC38}" = 1200_Help
"{36FCD82D-1CED-436d-B33C-874EEC666D68}" = cp_dwSharkTaleCards1
"{3762DB2D-71BD-421F-9E55-C74DA7DF4D07}" = CueTour
"{3819891A-030B-4a4e-98ED-B28A649E48AB}" = HP Deskjet 3900 series
"{3912A629-0020-0005-3757-2FBA74D4DF0A}" = InterVideo WinDVD Player
"{3AC54383-31D1-4907-961B-B12CBB1D0AE8}" = MobileMe Control Panel
"{3AEF2F6C-F1D3-47CD-BF3B-A327F1FABE58}" = PSPrinters06
"{3BA95526-6AE0-4B87-A62D-17187EF565FC}" = HP Boot Optimizer
"{3DED3A72-61A8-4B87-98A5-EF0BC8038AA0}" = DAEMON Tools
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works
"{42F6BED9-41DD-40F1-85A8-8E0350493626}" = HPDeskjet3900Series
"{47C25360-AEBC-4B21-B233-87CE653B3369}" = AIOMinimal
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{50D4CB89-AF34-4978-96DC-C3034062E901}" = Battlefield 2: Special Forces
"{55508A44-8225-47AB-9666-1F57A5B5CE2E}" = CP_PLSBusinessFlyers
"{55DCBED7-5710-4939-A928-4CBD9AB09EBB}" = 1310_Help
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{56F8AFC3-FA98-4ff1-9673-8A026CBF85BE}" = WebReg
"{571700F0-DB9D-4B3A-B03D-35A14BB5939F}" = Windows Live Messenger
"{5786D2C8-A4C4-4DDB-B671-8ED2A53310EC}" = 1310Tour
"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.6
"{5E8D588F-307C-4250-B622-26969027319A}" = PanoStandAlone
"{5EED93A8-33AD-46A7-A6AC-4DEAFBEFEEE1}" = Roxio Media Manager
"{5F26311C-B135-4F7F-B11E-8E650F83651E}" = DeviceFunctionQFolder
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{644D04A2-C682-4FD5-977D-03B804C4B9C5}" = CreativeProjects
"{646A65DD-23FC-418E-B9F0-E0500FB42CB1}" = PhotoGallery
"{6512B303-F989-4C13-B9F6-A99989E4ED54}" = HP Tunes
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Sonic Express Labeler
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6864A62D-3EF3-415F-9922-240EED34B4C0}" = Fax
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{724517BD-1DE1-4986-BFCA-C1DFD379E3BC}" = cp_dwShrek2Cards1
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{7AD25C9F-9957-4D1C-95EF-9BCD09F6D31B}" = HPSystemDiagnostics
"{7BB40A22-8D98-43F9-A08A-E7EFF5AB1324}" = Camtasia Studio 5
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{84CDF5A8-1D57-4B69-BAB6-1F11D8923375}" = SkinsHP1
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{8BC3B99B-A6BE-4A0B-8535-B1B94BA4B1B1}" = DocProc
"{8D0C57BC-4942-4960-BB6D-142456D6F233}" = HP Image Zone for Media Center PC
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISER_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISER_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISER_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD Player
"{930B2432-43D4-11D5-9871-00C04F8EEB39}" = Macromedia Fireworks MX
"{9941F0AA-B903-4AF4-A055-83A9815CC011}" = Sonic Encoders
"{99D48FBB-2DEF-49A9-BCC9-C5AF63DD2643}" = AiOSoftware
"{9AC70B07-AD4C-4733-8F0C-9245D8F0DC7E}" = Melty Blood Re-ACT Final Tuned
"{9CB2512B-3EC4-43DF-8002-46BDAB5EDD1B}" = QuickProjects
"{9EEBF8D5-8712-4D1D-88F4-4CDC2D270BC3}" = PrintScreen
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A5B9D22C-755A-4AC6-9904-875E80838BB6}" = CP_AtenaShokunin1Config
"{A5F68DC8-0278-4AD8-B413-861509B5F25B}" = ArcSoft Panorama Maker 3
"{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}" = HP Help and Support 4.0
"{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}" = Photosmart 320,370,7400,8100,8400 Series
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Sonic RecordNow Audio
"{ABA2B37F-AB88-486e-870A-52454A23FEE0}" = HP Photosmart Cameras 4.5
"{AC76BA86-7AD7-1033-7B44-A71000000002}" = Adobe Reader 7.1.0
"{AEC20FEC-47D8-4DEA-85D7-0B7E5D905D11}" = AiO_Scan
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Sonic RecordNow Copy
"{B1591C79-1C35-4E09-AA15-F7D6923AFB96}" = HP Deskjet 3840
"{B15D07E4-74DD-413A-91F7-1DE93595A5EC}" = 1000Tour
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B9242864-2841-4ADE-86E0-8F90F91B04DD}" = Logitech Gaming Software
"{B996AE66-10DB-4ac5-B151-E8B4BFBC42FC}" = BufferChm
"{BC339BFD-F550-471a-8D26-4D08126C62F7}" = SkinsHP2
"{BCE72AED-3332-4863-9567-C5DCB9052CA2}" = Netflix Movie Viewer
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C178B38F-613A-4EFE-B718-A675BD27A1E1}" = BlackBerry Desktop Software 4.3
"{C4124E95-5061-4776-8D5D-E3D931C778E1}" = Microsoft VC9 runtime libraries
"{C5103338-8DA1-4C51-A8B1-1855D29BB324}" = 1200
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE0C8CC5-E396-442B-A50E-D1D374A9E820}" = DocumentViewer
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D186329B-1B4D-408D-ABEC-EA5CE1F182C9}" = Overland
"{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}" = Nikon Message Center
"{D8E4A88B-E35A-4F3B-AB60-42E7DB0EC765}" = muvee autoProducer unPlugged - HPD
"{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" = HpSdpAppCoreApp
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E3F90083-80D4-4b5a-87C7-E97E12F5516D}" = HPProductAssistant
"{E443F067-3345-482C-BD7A-12675A53D292}" = Readme
"{EA103B64-C0E4-4C0E-A506-751590E1653D}" = SolutionCenter
"{EAE4A00B-D290-4B65-8287-B82A80FC0619}" = Linksys Wireless-G PCI Network Adapter with SpeedBooster
"{EFB21DE7-8C19-4A88-BB28-A766E16493BC}" = Adobe Photoshop CS
"{EFF913ED-03A6-42D2-A2A7-5966A612EEB9}" = LS_HSI
"{F439D7AF-03F3-4F8E-AEC4-571BFE977C61}" = iTunes
"{F4C2E5F5-2970-45f4-ABD3-C180C4D961C4}" = Status
"{F730A60D-F6DA-4653-9C6E-548F7A3A5EE0}" = 1310Trb
"{F9B0968A-810E-484C-B81D-7F19DC2CBBF5}" = 1310
"{FC10C922-52E9-4739-ACD0-EB0FF035EE7E}" = muvee autoProducer 4.0
"{FC22D020-3005-4715-8DF9-F3EDE81DEB3D}" = CreativeProjectsTemplates
"{FE64AE29-0883-4C70-8388-DC026019C900}" = HP Image Zone Express
"{FF3999BE-1A7B-4738-88AA-97BF14094A4A}" = PictureProject
"{FF87EC18-F8DC-4458-BBA0-299595F8A962}" = 1200Trb
"Ad-Aware SE Personal" = Ad-Aware SE Personal
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"Agere Systems Soft Modem" = Agere Systems PCI Soft Modem
"AIM_7" = AIM 7
"AOL Uninstaller" = AOL Uninstaller (Choose which Products to Remove)
"Audacity_is1" = Audacity 1.2.6
"AVG9Uninstall" = AVG Free 9.0
"B3EE3001-DC24-4cd1-8743-5692C716659F" = Otto
"BackWeb-309731 Uninstaller" = Updates from HP
"BitTornado" = BitTornado 0.3.7
"BlackBerry_{C178B38F-613A-4EFE-B718-A675BD27A1E1}" = BlackBerry Desktop Software 4.3
"CamStudio" = CamStudio
"CCleaner" = CCleaner (remove only)
"CleanUp!" = CleanUp!
"Combined Community Codec Pack_is1" = Combined Community Codec Pack 2008-09-21 16:18
"Diccionario Cambridge Klett Compact" = Diccionario Cambridge Klett Compact
"DVDStyler_is1" = DVDStyler v1.4
"Ease Audio Converter_is1" = Ease Audio Converter 3.50
"EHome Devices" = Media Center Extender
"ENTERPRISER" = Microsoft Office Enterprise 2007
"ERUNT_is1" = ERUNT 1.1j
"Eyeball Chat 2.2" = Eyeball Chat 2.2
"Fate-stay night English" = Fate/stay night English v3.2
"ffdshow_is1" = ffdshow [rev 621] [2006-12-03]
"Free Audio CD Burner_is1" = Free Audio CD Burner version 1.2
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.2
"HaaliMkx" = Haali Media Splitter
"Hamachi" = Hamachi 1.0.3.0
"Help and Support Additions" = Help and Support Additions
"Hentai3D2-052.003" = thriXXX Hentai3D2-052.003
"HijackThis" = HijackThis 1.99.1
"HP Imaging Device Functions" = HP Imaging Device Functions 5.0
"HP Photo & Imaging" = HP Image Zone 4.8.6
"HP Solution Center & Imaging Support Tools" = HP Solution Center & Imaging Support Tools 5.0
"ICMOICMCICKOICPBJENOIPJH" = ‚΂‚®‚ñ”̃—
"ie8" = Windows Internet Explorer 8
"InstallShield_{19C989C4-50AE-43A4-B06E-8C70FFFF852F}" = PC-Doctor for Windows
"InterActual Player" = InterActual Player
"LastFM_is1" = Last.fm 1.5.4.24567
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MAME32k" = MAME32k (remove only)
"MediaCoder" = MediaCoder 0.6.1
"Melty Blood Act Cadenza English" = Melty Blood: Act Cadenza English v1.0
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"mIRC" = mIRC
"Mozilla Firefox (3.5.8)" = Mozilla Firefox (3.5.8)
"MP3 Converter Simple" = MP3 Converter Simple
"MP3 WAV Converter 3.18" = MP3 WAV Converter 3.18
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSN Music Assistant" = MSN Music Assistant
"MSNINST" = MSN
"NVIDIA Drivers" = NVIDIA Drivers
"Panda ActiveScan" = Panda ActiveScan
"PictureProject In Touch Downloader" = PictureProject In Touch Downloader 1.0
"PS2" = PS2
"RADVideo" = RAD Video Tools
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"Spybot - Search & Destroy_is1" = Spybot - Search & Destroy 1.5.2.20
"Starcraft" = Starcraft
"System Requirements Lab" = System Requirements Lab
"Teamspeak 2 RC2_is1" = TeamSpeak 2 RC2
"Tokimeki Check in!" = Tokimeki Check in!
"ToneThis" = ToneThis 3.0
"Uninstall_is1" = Uninstall 1.0.0.1
"ViewpointMediaPlayer" = Viewpoint Media Player
"VisiooWriter" = VisiooWriter 0.6.1
"VLC media player" = VideoLAN VLC media player 0.8.2
"VSFilter_is1" = VSFilter 2.36
"WallWatcher" = WallWatcher
"Winamp" = Winamp (remove only)
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WMCSetup" = Windows Media Connect
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"World of Warcraft" = World of Warcraft
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Messenger" = Yahoo! Messenger

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"727d1ea1876aa06e" = WowAceUpdater
"Warcraft III" = Warcraft III: All Products

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/12/2010 2:13:45 PM | Computer Name = HATTORIHANZO | Source = Application Hang | ID = 1002
Description = Hanging application aim6.exe, version 1.4.9.1, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 2/15/2010 12:21:54 AM | Computer Name = HATTORIHANZO | Source = COM+ | ID = 135761
Description = The run-time environment has detected an inconsistency in its internal
state. This indicates a potential instability in the process that could be caused
by the custom components running in the COM+ application, the components they make
use of, or other factors. Error in f:\xpsp3\com\com1x\src\comsvcs\package\cpackage.cpp(1184),
hr = 8007041f: InitEventCollector fail

Error - 2/15/2010 12:53:53 AM | Computer Name = HATTORIHANZO | Source = Application Error | ID = 1000
Description = Faulting application yahoomessenger.exe, version 8.1.0.239, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x0001b21a.

Error - 2/17/2010 2:29:09 AM | Computer Name = HATTORIHANZO | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.5512, faulting
module AcroPDF.dll, version 8.1.0.0, fault address 0x000140d6.

Error - 2/17/2010 2:29:14 AM | Computer Name = HATTORIHANZO | Source = Application Error | ID = 1001
Description = Fault bucket 1607903176.

Error - 2/17/2010 10:50:22 AM | Computer Name = HATTORIHANZO | Source = COM+ | ID = 135761
Description = The run-time environment has detected an inconsistency in its internal
state. This indicates a potential instability in the process that could be caused
by the custom components running in the COM+ application, the components they make
use of, or other factors. Error in f:\xpsp3\com\com1x\src\comsvcs\package\cpackage.cpp(1184),
hr = 8007041f: InitEventCollector fail

Error - 2/19/2010 1:45:45 AM | Computer Name = HATTORIHANZO | Source = Application Error | ID = 1000
Description = Faulting application jnes.exe, version 1.0.2.15, faulting module kailleraclient.dll,
version 0.0.0.0, fault address 0x000010f3.

Error - 2/23/2010 11:46:05 AM | Computer Name = HATTORIHANZO | Source = Application Error | ID = 1000
Description = Faulting application gmer.exe, version 1.0.15.15281, faulting module
gmer.exe, version 1.0.15.15281, fault address 0x0005c887.

Error - 2/23/2010 11:46:13 AM | Computer Name = HATTORIHANZO | Source = Application Error | ID = 1000
Description = Faulting application gmer.exe, version 1.0.15.15281, faulting module
gmer.exe, version 1.0.15.15281, fault address 0x0005c887.

Error - 2/23/2010 11:46:47 AM | Computer Name = HATTORIHANZO | Source = Application Error | ID = 1000
Description = Faulting application gmer.exe, version 1.0.15.15281, faulting module
gmer.exe, version 1.0.15.15281, fault address 0x0005c887.

[ System Events ]
Error - 2/23/2010 11:25:25 AM | Computer Name = HATTORIHANZO | Source = Service Control Manager | ID = 7034
Description = The NVIDIA Display Driver Service service terminated unexpectedly.
It has done this 1 time(s).

Error - 2/23/2010 11:25:25 AM | Computer Name = HATTORIHANZO | Source = Service Control Manager | ID = 7031
Description = The Media Center Extender Resource Monitor service terminated unexpectedly.
It has done this 1 time(s). The following corrective action will be taken in
5000 milliseconds: Restart the service.

Error - 2/23/2010 11:25:25 AM | Computer Name = HATTORIHANZO | Source = Service Control Manager | ID = 7034
Description = The Viewpoint Manager Service service terminated unexpectedly. It
has done this 1 time(s).

Error - 2/23/2010 11:25:25 AM | Computer Name = HATTORIHANZO | Source = Service Control Manager | ID = 7034
Description = The WMP54GSSVC service terminated unexpectedly. It has done this
1 time(s).

Error - 2/23/2010 11:25:25 AM | Computer Name = HATTORIHANZO | Source = Service Control Manager | ID = 7034
Description = The Java Quick Starter service terminated unexpectedly. It has done
this 1 time(s).

Error - 2/23/2010 11:25:25 AM | Computer Name = HATTORIHANZO | Source = Service Control Manager | ID = 7034
Description = The iPod Service service terminated unexpectedly. It has done this
1 time(s).

Error - 2/23/2010 11:28:02 AM | Computer Name = HATTORIHANZO | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.

Error - 2/23/2010 11:28:02 AM | Computer Name = HATTORIHANZO | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.

Error - 2/23/2010 11:35:44 AM | Computer Name = HATTORIHANZO | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.

Error - 2/23/2010 11:35:44 AM | Computer Name = HATTORIHANZO | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.


< End of report >
  • 0

Advertisements


#2
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
can you post the tdsskiller log, it should be in your C:\ drive


Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    O32 - AutoRun File - [2001/07/28 07:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT -- [ FAT32 ]
    O32 - AutoRun File - [2004/04/30 23:01:14 | 000,000,053 | -HS- | M] () - D:\Autorun.inf -- [ FAT32 ]
    O32 - AutoRun File - [2003/05/10 12:01:49 | 000,000,055 | R--- | M] () - K:\autorun.inf -- [ CDFS ]
    O33 - MountPoints2\{bdb5aca8-4ed1-11de-9057-0013d352aa9b}\Shell\AutoRun\command - "" = H:\knupkb.com -- File not found
    O33 - MountPoints2\{bdb5aca8-4ed1-11de-9057-0013d352aa9b}\Shell\explore\Command - "" = H:\knupkb.com -- File not found
    O33 - MountPoints2\{bdb5aca8-4ed1-11de-9057-0013d352aa9b}\Shell\open\Command - "" = H:\knupkb.com -- File not found
    O33 - MountPoints2\D\Shell - "" = AutoRun
    O33 - MountPoints2\D\Shell\AutoRun - "" = Auto&Play
    [2099/01/01 12:00:00 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\rewelugi
    
    :Services
    
    :Reg
    
    :Files
    
    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done



Download ComboFix here :

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you don't know how to disable them then just continue on.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


Posted Image



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Posted Image


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix\ComboFix.txt log in your next reply.
  • 0

#3
Hiarashi

Hiarashi

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
Alright, here's the log I didn't include in the earlier post:

21:53:23:625 1132 TDSS rootkit removing tool 2.2.4 Feb 15 2010 19:38:31
21:53:23:625 1132 ================================================================================
21:53:23:625 1132 SystemInfo:

21:53:23:625 1132 OS Version: 5.1.2600 ServicePack: 3.0
21:53:23:625 1132 Product type: Workstation
21:53:23:625 1132 ComputerName: HATTORIHANZO
21:53:23:625 1132 UserName: Diego
21:53:23:625 1132 Windows directory: C:\WINDOWS
21:53:23:625 1132 Processor architecture: Intel x86
21:53:23:625 1132 Number of processors: 1
21:53:23:625 1132 Page size: 0x1000
21:53:23:625 1132 Boot type: Normal boot
21:53:23:625 1132 ================================================================================
21:53:23:625 1132 UnloadDriverW: NtUnloadDriver error 2
21:53:23:625 1132 ForceUnloadDriverW: UnloadDriverW(klmd21) error 2
21:53:23:625 1132 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\drivers\klmd.sys) returned status 00000000
21:53:23:656 1132 UtilityInit: KLMD drop and load success
21:53:23:656 1132 KLMD_OpenDevice: Trying to open KLMD Device(KLMD201010)
21:53:23:656 1132 UtilityInit: KLMD open success
21:53:23:656 1132 UtilityInit: Initialize success
21:53:23:656 1132
21:53:23:656 1132 Scanning Services ...
21:53:23:656 1132 CreateRegParser: Registry parser init started
21:53:23:656 1132 DisableWow64Redirection: GetProcAddress(Wow64DisableWow64FsRedirection) error 127
21:53:23:656 1132 CreateRegParser: DisableWow64Redirection error
21:53:23:656 1132 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\system
21:53:23:656 1132 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\config\system) returned status C0000043
21:53:23:656 1132 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
21:53:23:656 1132 wfopen_ex: Trying to KLMD file open
21:53:23:656 1132 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\config\system
21:53:23:656 1132 wfopen_ex: File opened ok (Flags 2)
21:53:23:656 1132 CreateRegParser: HIVE_ADAPTER(C:\WINDOWS\system32\config\system) init success: 264AC8
21:53:23:656 1132 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\software
21:53:23:656 1132 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\config\software) returned status C0000043
21:53:23:656 1132 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
21:53:23:656 1132 wfopen_ex: Trying to KLMD file open
21:53:23:656 1132 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\config\software
21:53:23:656 1132 wfopen_ex: File opened ok (Flags 2)
21:53:23:656 1132 CreateRegParser: HIVE_ADAPTER(C:\WINDOWS\system32\config\software) init success: 264B70
21:53:23:656 1132 EnableWow64Redirection: GetProcAddress(Wow64RevertWow64FsRedirection) error 127
21:53:23:656 1132 CreateRegParser: EnableWow64Redirection error
21:53:23:656 1132 CreateRegParser: RegParser init completed
21:53:24:078 1132 GetAdvancedServicesInfo: Raw services enum returned 371 services
21:53:24:093 1132 fclose_ex: Trying to close file C:\WINDOWS\system32\config\system
21:53:24:093 1132 fclose_ex: Trying to close file C:\WINDOWS\system32\config\software
21:53:24:093 1132
21:53:24:093 1132 Scanning Kernel memory ...
21:53:24:093 1132 KLMD_GetSystemObjectAddressByNameW: Trying to get system object address by name \Driver\Disk
21:53:24:093 1132 DetectCureTDL3: \Driver\Disk PDRIVER_OBJECT: 8A4ECB80
21:53:24:093 1132 DetectCureTDL3: KLMD_GetDeviceObjectList returned 3 DevObjects
21:53:24:093 1132
21:53:24:093 1132 DetectCureTDL3: DEVICE_OBJECT: 8A59DC68
21:53:24:093 1132 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8A59DC68
21:53:24:093 1132 KLMD_ReadMem: Trying to ReadMemory 0x8A59DC68[0x38]
21:53:24:093 1132 DetectCureTDL3: DRIVER_OBJECT: 8A4ECB80
21:53:24:093 1132 KLMD_ReadMem: Trying to ReadMemory 0x8A4ECB80[0xA8]
21:53:24:093 1132 KLMD_ReadMem: Trying to ReadMemory 0xE101EA18[0x18]
21:53:24:093 1132 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
21:53:24:093 1132 DetectCureTDL3: IRP_MJ_CREATE : BA8EEBB0
21:53:24:093 1132 DetectCureTDL3: IRP_MJ_CREATE_NAMED_PIPE : 804F355A
21:53:24:093 1132 DetectCureTDL3: IRP_MJ_CLOSE : BA8EEBB0
21:53:24:093 1132 DetectCureTDL3: IRP_MJ_READ : BA8E8D1F
21:53:24:093 1132 DetectCureTDL3: IRP_MJ_WRITE : BA8E8D1F
21:53:24:093 1132 DetectCureTDL3: IRP_MJ_QUERY_INFORMATION : 804F355A
21:53:24:093 1132 DetectCureTDL3: IRP_MJ_SET_INFORMATION : 804F355A
21:53:24:093 1132 DetectCureTDL3: IRP_MJ_QUERY_EA : 804F355A
21:53:24:093 1132 DetectCureTDL3: IRP_MJ_SET_EA : 804F355A
21:53:24:093 1132 DetectCureTDL3: IRP_MJ_FLUSH_BUFFERS : BA8E92E2
21:53:24:093 1132 DetectCureTDL3: IRP_MJ_QUERY_VOLUME_INFORMATION : 804F355A
21:53:24:093 1132 DetectCureTDL3: IRP_MJ_SET_VOLUME_INFORMATION : 804F355A
21:53:24:093 1132 DetectCureTDL3: IRP_MJ_DIRECTORY_CONTROL : 804F355A
21:53:24:093 1132 DetectCureTDL3: IRP_MJ_FILE_SYSTEM_CONTROL : 804F355A
21:53:24:093 1132 DetectCureTDL3: IRP_MJ_DEVICE_CONTROL : BA8E93BB
21:53:24:093 1132 DetectCureTDL3: IRP_MJ_INTERNAL_DEVICE_CONTROL : BA8ECF28
21:53:24:093 1132 DetectCureTDL3: IRP_MJ_SHUTDOWN : BA8E92E2
21:53:24:093 1132 DetectCureTDL3: IRP_MJ_LOCK_CONTROL : 804F355A
21:53:24:093 1132 DetectCureTDL3: IRP_MJ_CLEANUP : 804F355A
21:53:24:093 1132 DetectCureTDL3: IRP_MJ_CREATE_MAILSLOT : 804F355A
21:53:24:093 1132 DetectCureTDL3: IRP_MJ_QUERY_SECURITY : 804F355A
21:53:24:093 1132 DetectCureTDL3: IRP_MJ_SET_SECURITY : 804F355A
21:53:24:093 1132 DetectCureTDL3: IRP_MJ_POWER : BA8EAC82
21:53:24:093 1132 DetectCureTDL3: IRP_MJ_SYSTEM_CONTROL : BA8EF99E
21:53:24:093 1132 DetectCureTDL3: IRP_MJ_DEVICE_CHANGE : 804F355A
21:53:24:093 1132 DetectCureTDL3: IRP_MJ_QUERY_QUOTA : 804F355A
21:53:24:093 1132 DetectCureTDL3: IRP_MJ_SET_QUOTA : 804F355A
21:53:24:093 1132 TDL3_FileDetect: Processing driver: Disk
21:53:24:093 1132 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
21:53:24:093 1132 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
21:53:24:140 1132 TDL3_FileDetect: Processing driver: Disk
21:53:24:140 1132 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
21:53:24:140 1132 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
21:53:24:156 1132 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
21:53:24:156 1132
21:53:24:156 1132 DetectCureTDL3: DEVICE_OBJECT: 8A4EAC68
21:53:24:156 1132 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8A4EAC68
21:53:24:156 1132 KLMD_ReadMem: Trying to ReadMemory 0x8A4EAC68[0x38]
21:53:24:156 1132 DetectCureTDL3: DRIVER_OBJECT: 8A4ECB80
21:53:24:156 1132 KLMD_ReadMem: Trying to ReadMemory 0x8A4ECB80[0xA8]
21:53:24:156 1132 KLMD_ReadMem: Trying to ReadMemory 0xE101EA18[0x18]
21:53:24:156 1132 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
21:53:24:156 1132 DetectCureTDL3: IRP_MJ_CREATE : BA8EEBB0
21:53:24:156 1132 DetectCureTDL3: IRP_MJ_CREATE_NAMED_PIPE : 804F355A
21:53:24:156 1132 DetectCureTDL3: IRP_MJ_CLOSE : BA8EEBB0
21:53:24:156 1132 DetectCureTDL3: IRP_MJ_READ : BA8E8D1F
21:53:24:156 1132 DetectCureTDL3: IRP_MJ_WRITE : BA8E8D1F
21:53:24:156 1132 DetectCureTDL3: IRP_MJ_QUERY_INFORMATION : 804F355A
21:53:24:156 1132 DetectCureTDL3: IRP_MJ_SET_INFORMATION : 804F355A
21:53:24:156 1132 DetectCureTDL3: IRP_MJ_QUERY_EA : 804F355A
21:53:24:156 1132 DetectCureTDL3: IRP_MJ_SET_EA : 804F355A
21:53:24:156 1132 DetectCureTDL3: IRP_MJ_FLUSH_BUFFERS : BA8E92E2
21:53:24:156 1132 DetectCureTDL3: IRP_MJ_QUERY_VOLUME_INFORMATION : 804F355A
21:53:24:156 1132 DetectCureTDL3: IRP_MJ_SET_VOLUME_INFORMATION : 804F355A
21:53:24:156 1132 DetectCureTDL3: IRP_MJ_DIRECTORY_CONTROL : 804F355A
21:53:24:156 1132 DetectCureTDL3: IRP_MJ_FILE_SYSTEM_CONTROL : 804F355A
21:53:24:156 1132 DetectCureTDL3: IRP_MJ_DEVICE_CONTROL : BA8E93BB
21:53:24:156 1132 DetectCureTDL3: IRP_MJ_INTERNAL_DEVICE_CONTROL : BA8ECF28
21:53:24:156 1132 DetectCureTDL3: IRP_MJ_SHUTDOWN : BA8E92E2
21:53:24:156 1132 DetectCureTDL3: IRP_MJ_LOCK_CONTROL : 804F355A
21:53:24:156 1132 DetectCureTDL3: IRP_MJ_CLEANUP : 804F355A
21:53:24:156 1132 DetectCureTDL3: IRP_MJ_CREATE_MAILSLOT : 804F355A
21:53:24:156 1132 DetectCureTDL3: IRP_MJ_QUERY_SECURITY : 804F355A
21:53:24:156 1132 DetectCureTDL3: IRP_MJ_SET_SECURITY : 804F355A
21:53:24:156 1132 DetectCureTDL3: IRP_MJ_POWER : BA8EAC82
21:53:24:156 1132 DetectCureTDL3: IRP_MJ_SYSTEM_CONTROL : BA8EF99E
21:53:24:156 1132 DetectCureTDL3: IRP_MJ_DEVICE_CHANGE : 804F355A
21:53:24:156 1132 DetectCureTDL3: IRP_MJ_QUERY_QUOTA : 804F355A
21:53:24:156 1132 DetectCureTDL3: IRP_MJ_SET_QUOTA : 804F355A
21:53:24:156 1132 TDL3_FileDetect: Processing driver: Disk
21:53:24:156 1132 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
21:53:24:156 1132 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
21:53:24:171 1132 TDL3_FileDetect: Processing driver: Disk
21:53:24:171 1132 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
21:53:24:171 1132 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
21:53:24:171 1132 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
21:53:24:171 1132
21:53:24:171 1132 DetectCureTDL3: DEVICE_OBJECT: 8A5A8998
21:53:24:171 1132 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8A5A8998
21:53:24:171 1132 DetectCureTDL3: DEVICE_OBJECT: 8A5E72B0
21:53:24:171 1132 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8A5E72B0
21:53:24:171 1132 DetectCureTDL3: DEVICE_OBJECT: 8A5B5B00
21:53:24:171 1132 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8A5B5B00
21:53:24:171 1132 KLMD_ReadMem: Trying to ReadMemory 0x8A5B5B00[0x38]
21:53:24:171 1132 DetectCureTDL3: DRIVER_OBJECT: 8A59B370
21:53:24:171 1132 KLMD_ReadMem: Trying to ReadMemory 0x8A59B370[0xA8]
21:53:24:171 1132 KLMD_ReadMem: Trying to ReadMemory 0x8A5B8030[0x38]
21:53:24:171 1132 KLMD_ReadMem: Trying to ReadMemory 0x8A607568[0xA8]
21:53:24:171 1132 KLMD_ReadMem: Trying to ReadMemory 0xE1845E50[0x1A]
21:53:24:171 1132 DetectCureTDL3: DRIVER_OBJECT name: \Driver\atapi, Driver Name: atapi
21:53:24:171 1132 DetectCureTDL3: IRP_MJ_CREATE : 8A4F6A9A
21:53:24:171 1132 DetectCureTDL3: IRP_MJ_CREATE_NAMED_PIPE : 8A4F6A9A
21:53:24:171 1132 DetectCureTDL3: IRP_MJ_CLOSE : 8A4F6A9A
21:53:24:171 1132 DetectCureTDL3: IRP_MJ_READ : 8A4F6A9A
21:53:24:171 1132 DetectCureTDL3: IRP_MJ_WRITE : 8A4F6A9A
21:53:24:171 1132 DetectCureTDL3: IRP_MJ_QUERY_INFORMATION : 8A4F6A9A
21:53:24:171 1132 DetectCureTDL3: IRP_MJ_SET_INFORMATION : 8A4F6A9A
21:53:24:171 1132 DetectCureTDL3: IRP_MJ_QUERY_EA : 8A4F6A9A
21:53:24:171 1132 DetectCureTDL3: IRP_MJ_SET_EA : 8A4F6A9A
21:53:24:171 1132 DetectCureTDL3: IRP_MJ_FLUSH_BUFFERS : 8A4F6A9A
21:53:24:171 1132 DetectCureTDL3: IRP_MJ_QUERY_VOLUME_INFORMATION : 8A4F6A9A
21:53:24:171 1132 DetectCureTDL3: IRP_MJ_SET_VOLUME_INFORMATION : 8A4F6A9A
21:53:24:171 1132 DetectCureTDL3: IRP_MJ_DIRECTORY_CONTROL : 8A4F6A9A
21:53:24:171 1132 DetectCureTDL3: IRP_MJ_FILE_SYSTEM_CONTROL : 8A4F6A9A
21:53:24:171 1132 DetectCureTDL3: IRP_MJ_DEVICE_CONTROL : 8A4F6A9A
21:53:24:171 1132 DetectCureTDL3: IRP_MJ_INTERNAL_DEVICE_CONTROL : 8A4F6A9A
21:53:24:171 1132 DetectCureTDL3: IRP_MJ_SHUTDOWN : 8A4F6A9A
21:53:24:171 1132 DetectCureTDL3: IRP_MJ_LOCK_CONTROL : 8A4F6A9A
21:53:24:171 1132 DetectCureTDL3: IRP_MJ_CLEANUP : 8A4F6A9A
21:53:24:171 1132 DetectCureTDL3: IRP_MJ_CREATE_MAILSLOT : 8A4F6A9A
21:53:24:171 1132 DetectCureTDL3: IRP_MJ_QUERY_SECURITY : 8A4F6A9A
21:53:24:171 1132 DetectCureTDL3: IRP_MJ_SET_SECURITY : 8A4F6A9A
21:53:24:171 1132 DetectCureTDL3: IRP_MJ_POWER : 8A4F6A9A
21:53:24:171 1132 DetectCureTDL3: IRP_MJ_SYSTEM_CONTROL : 8A4F6A9A
21:53:24:171 1132 DetectCureTDL3: IRP_MJ_DEVICE_CHANGE : 8A4F6A9A
21:53:24:171 1132 DetectCureTDL3: IRP_MJ_QUERY_QUOTA : 8A4F6A9A
21:53:24:171 1132 DetectCureTDL3: IRP_MJ_SET_QUOTA : 8A4F6A9A
21:53:24:171 1132 TDL3_FileDetect: Processing driver: atapi
21:53:24:171 1132 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\atapi.sys
21:53:24:171 1132 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\atapi.sys
21:53:24:171 1132 DetectCureTDL3: All IRP handlers pointed to one addr: 8A4F6A9A
21:53:24:171 1132 KLMD_ReadMem: Trying to ReadMemory 0x8A4F6A9A[0x400]
21:53:24:171 1132 TDL3_IrpHookDetect: CheckParameters: 0, 0, 607, 138, 3, 120
21:53:24:171 1132 KLMD_ReadMem: Trying to ReadMemory 0x8A4F6909[0x400]
21:53:24:171 1132 TDL3_StartIoHookDetect: CheckParameters: 0, 00000000, 1
21:53:24:171 1132 TDL3_FileDetect: Processing driver: atapi
21:53:24:171 1132 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\atapi.sys
21:53:24:171 1132 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\atapi.sys
21:53:24:171 1132 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\atapi.sys - Verdict: Clean
21:53:24:171 1132
21:53:24:171 1132 Completed
21:53:24:171 1132
21:53:24:171 1132 Results:
21:53:24:171 1132 Memory objects infected / cured / cured on reboot: 0 / 0 / 0
21:53:24:171 1132 Registry objects infected / cured / cured on reboot: 0 / 0 / 0
21:53:24:171 1132 File objects infected / cured / cured on reboot: 0 / 0 / 0
21:53:24:171 1132
21:53:24:187 1132 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\drivers\klmd.sys) returned status 00000000
21:53:24:187 1132 UtilityDeinit: KLMD(ARK) unloaded successfully

And here's the ComboFix Log:

ComboFix 10-02-23.03 - Diego 02/23/2010 22:28:16.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1532 [GMT -6:00]
Running from: c:\documents and settings\Diego.HATTORIHANZO\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Mozilla Firefox\plugins\npclntax.dll
c:\recycler\S-1-5-21-3532202289-1017233673-4241735999-500
c:\recycler\S-1-5-21-995972935-656752182-1893798182-1009
c:\windows\system32\dumphive.exe
c:\windows\system32\Process.exe
c:\windows\system32\ps2.bat
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe

Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected
Restored copy from - Kitty ate it :)
.
((((((((((((((((((((((((( Files Created from 2010-01-24 to 2010-02-24 )))))))))))))))))))))))))))))))
.

2010-02-24 03:55 . 2010-02-24 03:55 -------- d-----w- C:\_OTL
2010-02-23 15:22 . 2010-02-23 15:23 -------- d-----w- c:\program files\ERUNT
2010-02-20 05:55 . 2010-02-20 05:55 -------- d-----w- c:\documents and settings\NetworkService\Application Data\AdobeUM
2010-02-17 16:04 . 2010-02-17 16:04 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-02-17 14:59 . 2010-02-17 14:59 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2010-02-15 03:59 . 2010-02-15 03:59 -------- d-----w- c:\program files\RADVideo
2010-02-13 06:13 . 2010-02-13 06:13 -------- d-----w- c:\program files\iPod
2010-02-12 18:41 . 2010-02-12 18:41 -------- d-----w- c:\documents and settings\All Users\Application Data\AIM
2010-02-12 18:41 . 2010-02-12 18:41 -------- d-----w- c:\program files\AIM7
2010-02-12 18:41 . 2010-02-12 18:41 -------- d-----w- c:\program files\Common Files\Software Update Utility

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-23 21:01 . 2009-12-03 19:09 0 ----a-w- c:\documents and settings\Diego.HATTORIHANZO\Local Settings\Application Data\prvlcl.dat
2010-02-22 05:55 . 2006-12-02 20:42 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2010-02-18 04:58 . 2008-04-12 05:34 -------- d-----w- c:\program files\Jnes
2010-02-18 02:46 . 2005-09-14 04:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-02-13 06:14 . 2006-11-25 18:45 -------- d-----w- c:\program files\iTunes
2010-02-13 06:13 . 2007-11-21 22:40 -------- d-----w- c:\program files\Common Files\Apple
2010-02-13 06:07 . 2010-02-13 06:07 72488 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
2010-02-12 19:49 . 2005-05-26 10:02 -------- d-----w- c:\program files\Java
2010-02-12 18:41 . 2007-01-22 06:56 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL
2010-02-10 07:29 . 2007-11-21 21:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-02-06 18:05 . 2008-02-15 22:48 -------- d-----w- c:\documents and settings\Diego.HATTORIHANZO\Application Data\Skype
2010-02-06 17:56 . 2008-02-15 22:50 -------- d-----w- c:\documents and settings\Diego.HATTORIHANZO\Application Data\skypePM
2010-02-05 01:05 . 2007-05-08 18:30 -------- d-----w- c:\program files\World of Warcraft
2010-01-27 05:15 . 2010-01-27 05:15 503808 ----a-w- c:\documents and settings\Diego.HATTORIHANZO\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-58c32131-n\msvcp71.dll
2010-01-27 05:15 . 2010-01-27 05:15 499712 ----a-w- c:\documents and settings\Diego.HATTORIHANZO\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-58c32131-n\jmc.dll
2010-01-27 05:15 . 2010-01-27 05:15 348160 ----a-w- c:\documents and settings\Diego.HATTORIHANZO\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-58c32131-n\msvcr71.dll
2010-01-27 05:15 . 2010-01-27 05:15 61440 ----a-w- c:\documents and settings\Diego.HATTORIHANZO\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-26606f46-n\decora-sse.dll
2010-01-27 05:15 . 2010-01-27 05:15 12800 ----a-w- c:\documents and settings\Diego.HATTORIHANZO\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-26606f46-n\decora-d3d.dll
2010-01-27 05:15 . 2005-05-26 10:02 -------- d-----w- c:\program files\Common Files\Java
2010-01-22 09:14 . 2010-01-22 09:14 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-22 07:00 . 2005-09-14 04:56 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-01-14 18:22 . 2010-01-14 18:22 -------- d-----w- c:\documents and settings\All Users\Application Data\ASign
2010-01-07 22:07 . 2010-01-22 09:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 22:07 . 2010-01-22 09:14 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-03 07:28 . 2007-08-17 22:54 20 ---h--w- c:\documents and settings\All Users\Application Data\PKP_DLds.DAT
2010-01-03 07:28 . 2006-09-08 22:28 20 ---h--w- c:\documents and settings\All Users\Application Data\PKP_DLec.DAT
2009-12-31 16:50 . 2004-08-10 04:00 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:14 . 2004-08-10 04:00 916480 ----a-w- c:\windows\system32\wininet.dll
2009-12-19 08:18 . 2009-12-19 08:18 96284 ---ha-w- c:\windows\system32\mlfcache.dat
2009-12-17 23:14 . 2009-01-13 17:29 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-16 18:43 . 2004-08-10 04:00 343040 ----a-w- c:\windows\system32\mspaint.exe
2009-12-15 16:44 . 2009-12-15 16:44 152576 ----a-w- c:\documents and settings\Diego.HATTORIHANZO\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-12-15 16:44 . 2009-12-15 16:44 79488 ----a-w- c:\documents and settings\Diego.HATTORIHANZO\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-12-14 07:08 . 2004-08-10 04:00 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-12-08 19:27 . 2004-08-10 04:00 2189184 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-12-08 18:43 . 2004-08-10 11:00 2066048 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-12-04 18:22 . 2004-08-10 04:00 455424 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-11-27 18:26 . 2008-08-07 16:44 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-11-27 18:26 . 2008-08-07 16:44 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-11-27 18:25 . 2009-01-29 15:39 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2009-11-27 18:25 . 2009-11-27 18:25 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-11-27 17:11 . 2004-08-10 11:00 17920 ----a-w- c:\windows\system32\msyuv.dll
2009-11-27 17:11 . 2004-08-10 04:00 1291776 ----a-w- c:\windows\system32\quartz.dll
2009-11-27 16:07 . 2004-08-10 11:00 8704 ----a-w- c:\windows\system32\tsbyuv.dll
2009-11-27 16:07 . 2004-08-10 04:00 28672 ----a-w- c:\windows\system32\msvidc32.dll
2009-11-27 16:07 . 2004-08-10 11:00 48128 ----a-w- c:\windows\system32\iyuv_32.dll
2009-11-27 16:07 . 2004-08-10 04:00 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-11-27 16:07 . 2004-08-10 04:00 11264 ----a-w- c:\windows\system32\msrle32.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-01-19 4670968]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-02-25 245760]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 253952]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2004-02-26 176128]
"DAEMON Tools-1033"="c:\program files\D-Tools\daemon.exe" [2004-08-22 81920]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 241664]
"HPHmon06"="c:\windows\system32\hphmon06.exe" [2004-06-07 659456]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-10 208952]
"IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-10 44032]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-10 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168]
"IPHSend"="c:\program files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-02-17 124520]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"nwiz"="nwiz.exe" [2008-10-07 1630208]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2007-08-16 236016]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-01-23 141608]

c:\documents and settings\Diego.HATTORIHANZO\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-10-29 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
Extender Resource Monitor.lnk - c:\windows\ehome\RMSysTry.exe [2005-10-20 18432]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-11 282624]
NkbMonitor.exe.lnk - c:\program files\Nikon\PictureProject\NkbMonitor.exe [2006-9-8 118784]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-11-27 18:25 12464 ----a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Updates from HP\\309731\\Program\\Updates from HP.exe"=
"c:\\sysreset\\mirc.exe"=
"c:\\Program Files\\BitTornado\\btdownloadgui.exe"=
"c:\\Program Files\\Macromedia\\Fireworks MX\\Fireworks.exe"=
"c:\\Program Files\\Starcraft\\StarCraft.exe"=
"c:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"c:\\Program Files\\Watanabe-Production and TYPE-MOON\\Melty Blood Re-ACT Final Tuned\\mbr_net_b7v2.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Last.fm\\LastFM.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-1.12.0-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-1.12.x-to-2.0.1-enUS-patch-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.3-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.3.6299-to-2.0.12.6546-enUS-downloader.exe"=
"c:\\Program Files\\Common Files\\AOL\\1184648623\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1184648623\\ee\\aim6.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\EcoleSoftware\\MBACWIN\\mbcaster.exe"=
"%windir%\\system32\\drivers\\svchost.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0.10192-to-3.2.0.10314-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0.10314-to-3.2.2.10482-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.2.10482-to-3.2.2.10505-enUS-downloader.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\AIM7\\aim.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3776:UDP"= 3776:UDP:Media Center Extender Service
"3390:TCP"= 3390:TCP:Remote Media Center Experience
"6112:TCP"= 6112:TCP:Blizzard Downloader
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724

R0 d347bus;d347bus;c:\windows\system32\drivers\d347bus.sys [10/6/2005 11:21 PM 155136]
R0 d347prt;d347prt;c:\windows\system32\drivers\d347prt.sys [10/6/2005 11:21 PM 5248]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [8/7/2008 10:44 AM 333192]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [11/27/2009 12:25 PM 360584]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [11/27/2009 12:25 PM 285392]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [3/4/2009 11:57 AM 24652]
S2 wjrgxpifylr;wjrgxpifylr;\??\c:\windows\system32\drivers\gaxpjzn.sys --> c:\windows\system32\drivers\gaxpjzn.sys [?]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - GTNDIS5

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
QWAVE REG_MULTI_SZ QWAVE
.
Contents of the 'Scheduled Tasks' folder

2010-02-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:34]
.
.
------- Supplementary Scan -------
.
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=desktop&parm1=seconduser
uInternet Settings,ProxyOverride = *.local
IE: &Google Search - c:\program files\google\GoogleToolbar2.dll/cmsearch.html
IE: &Translate English Word - c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
IE: Backward Links - c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar2.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\google\GoogleToolbar2.dll/cmtrans.html
FF - ProfilePath - c:\documents and settings\Diego.HATTORIHANZO\Application Data\Mozilla\Firefox\Profiles\8pc0a37l.default\
FF - prefs.js: browser.search.selectedEngine - YouTube Video Search
FF - prefs.js: browser.startup.homepage - hxxp://www.gamefaqs.com/
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: c:\progra~1\Yahoo!\Common\npyaxmpb.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdnupdater2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\QuickTime\Plugins\npqtplugin8.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
FF - user.js: network.protocol-handler.warn-external.dnupdate - false.
- - - - ORPHANS REMOVED - - - -

Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
HKCU-Run-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
HKLM-Run-SunJavaUpdateSched - c:\program files\Java\jre6\bin\jusched.exe
Notify-AtiExtEvent - (no file)
AddRemove-HijackThis - c:\documents and settings\Diego.HATTORIHANZO\Desktop\HijackThis.exe
AddRemove-WallWatcher - c:\documents and settings\Diego.HATTORIHANZO\Desktop\WallWatcher\Setup.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-23 22:40
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8A23BB10]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xba8ecf28
\Driver\ACPI -> ACPI.sys @ 0xba759cb8
\Driver\atapi -> 0x8a23bb10
IoDeviceObjectType -> ParseProcedure -> ntkrnlpa.exe @ 0x80577c84
SecurityProcedure -> ntkrnlpa.exe @ 0x80579208
\Device\Harddisk0\DR0 -> ParseProcedure -> ntkrnlpa.exe @ 0x80577c84
SecurityProcedure -> ntkrnlpa.exe @ 0x80579208
NDIS: Realtek RTL8139/810x Family Fast Ethernet NIC -> SendCompleteHandler -> NDIS.sys @ 0xba5bdbd4
PacketIndicateHandler -> NDIS.sys @ 0xba5aba0d
SendHandler -> NDIS.sys @ 0xba5bfb40
Warning: possible MBR rootkit infection !
user & kernel MBR OK

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(3224)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\nvsvc32.exe
c:\windows\ehome\RMSvc.exe
c:\windows\system32\RUNDLL32.EXE
c:\program files\Common Files\AOL\1184648623\ee\aolsoftware.exe
c:\program files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WLService.exe
c:\program files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WMP54GSv1_1.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Yahoo!\Messenger\ymsgr_tray.exe
c:\windows\system32\dllhost.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
c:\windows\eHome\ehmsas.exe
.
**************************************************************************
.
Completion time: 2010-02-23 22:45:52 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-24 04:45

Pre-Run: 97,747,972,096 bytes free
Post-Run: 101,019,009,024 bytes free

- - End Of File - - 6B82DD3644BBDBC52C37FDD9465AC8B7
  • 0

#4
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
hi

Open notepad and copy/paste the text in the quotebox below into it:

http://www.geekstogo...92#entry1770792

Collect::

Suspect::[22]
c:\qoobox\quarantine\c\windows\system32\drivers\atapi.sys.vir


Save this as CFScript.txt


Posted Image

Refering to the picture above, drag CFScript.txt into ComboFix.exe

When finished, it shall produce a log for you. Post that log in your next reply.

**Note**

When CF finishes running, the ComboFix log will open along with a message box--do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.

Edited by Rorschach112, 24 February 2010 - 05:54 AM.

  • 0

#5
Hiarashi

Hiarashi

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
Alright, here's the log for that one:

ComboFix 10-02-23.03 - Diego 02/24/2010 9:10.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1430 [GMT -6:00]
Running from: c:\documents and settings\Diego.HATTORIHANZO\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Diego.HATTORIHANZO\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

file zipped: c:\qoobox\Quarantine\C\WINDOWS\system32\drivers\atapi.sys.vir
.

((((((((((((((((((((((((( Files Created from 2010-01-24 to 2010-02-24 )))))))))))))))))))))))))))))))
.

2010-02-24 03:55 . 2010-02-24 03:55 -------- d-----w- C:\_OTL
2010-02-23 15:22 . 2010-02-23 15:23 -------- d-----w- c:\program files\ERUNT
2010-02-20 05:55 . 2010-02-20 05:55 -------- d-----w- c:\documents and settings\NetworkService\Application Data\AdobeUM
2010-02-17 16:04 . 2010-02-17 16:04 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-02-17 14:59 . 2010-02-17 14:59 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2010-02-15 03:59 . 2010-02-15 03:59 -------- d-----w- c:\program files\RADVideo
2010-02-13 06:13 . 2010-02-13 06:13 -------- d-----w- c:\program files\iPod
2010-02-13 06:07 . 2010-02-13 06:07 72488 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
2010-02-12 18:41 . 2010-02-12 18:41 -------- d-----w- c:\documents and settings\All Users\Application Data\AIM
2010-02-12 18:41 . 2010-02-12 18:41 -------- d-----w- c:\program files\AIM7
2010-02-12 18:41 . 2010-02-12 18:41 -------- d-----w- c:\program files\Common Files\Software Update Utility
2010-01-27 05:15 . 2010-01-27 05:15 503808 ----a-w- c:\documents and settings\Diego.HATTORIHANZO\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-58c32131-n\msvcp71.dll
2010-01-27 05:15 . 2010-01-27 05:15 499712 ----a-w- c:\documents and settings\Diego.HATTORIHANZO\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-58c32131-n\jmc.dll
2010-01-27 05:15 . 2010-01-27 05:15 348160 ----a-w- c:\documents and settings\Diego.HATTORIHANZO\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-58c32131-n\msvcr71.dll
2010-01-27 05:15 . 2010-01-27 05:15 61440 ----a-w- c:\documents and settings\Diego.HATTORIHANZO\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-26606f46-n\decora-sse.dll
2010-01-27 05:15 . 2010-01-27 05:15 12800 ----a-w- c:\documents and settings\Diego.HATTORIHANZO\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-26606f46-n\decora-d3d.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-24 15:01 . 2009-12-03 19:09 0 ----a-w- c:\documents and settings\Diego.HATTORIHANZO\Local Settings\Application Data\prvlcl.dat
2010-02-22 05:55 . 2006-12-02 20:42 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2010-02-18 04:58 . 2008-04-12 05:34 -------- d-----w- c:\program files\Jnes
2010-02-18 02:46 . 2005-09-14 04:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-02-13 06:14 . 2006-11-25 18:45 -------- d-----w- c:\program files\iTunes
2010-02-13 06:13 . 2007-11-21 22:40 -------- d-----w- c:\program files\Common Files\Apple
2010-02-12 19:49 . 2005-05-26 10:02 -------- d-----w- c:\program files\Java
2010-02-12 18:41 . 2007-01-22 06:56 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL
2010-02-10 07:29 . 2007-11-21 21:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-02-06 18:05 . 2008-02-15 22:48 -------- d-----w- c:\documents and settings\Diego.HATTORIHANZO\Application Data\Skype
2010-02-06 17:56 . 2008-02-15 22:50 -------- d-----w- c:\documents and settings\Diego.HATTORIHANZO\Application Data\skypePM
2010-02-05 01:05 . 2007-05-08 18:30 -------- d-----w- c:\program files\World of Warcraft
2010-01-27 05:15 . 2005-05-26 10:02 -------- d-----w- c:\program files\Common Files\Java
2010-01-22 09:14 . 2010-01-22 09:14 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-22 07:00 . 2005-09-14 04:56 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-01-14 18:22 . 2010-01-14 18:22 -------- d-----w- c:\documents and settings\All Users\Application Data\ASign
2010-01-07 22:07 . 2010-01-22 09:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 22:07 . 2010-01-22 09:14 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-03 07:28 . 2007-08-17 22:54 20 ---h--w- c:\documents and settings\All Users\Application Data\PKP_DLds.DAT
2010-01-03 07:28 . 2006-09-08 22:28 20 ---h--w- c:\documents and settings\All Users\Application Data\PKP_DLec.DAT
2009-12-31 16:50 . 2004-08-10 04:00 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:14 . 2004-08-10 04:00 916480 ------w- c:\windows\system32\wininet.dll
2009-12-19 08:18 . 2009-12-19 08:18 96284 ---ha-w- c:\windows\system32\mlfcache.dat
2009-12-17 23:14 . 2009-01-13 17:29 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-16 18:43 . 2004-08-10 04:00 343040 ----a-w- c:\windows\system32\mspaint.exe
2009-12-15 16:44 . 2009-12-15 16:44 152576 ----a-w- c:\documents and settings\Diego.HATTORIHANZO\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-12-15 16:44 . 2009-12-15 16:44 79488 ----a-w- c:\documents and settings\Diego.HATTORIHANZO\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-12-14 07:08 . 2004-08-10 04:00 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-12-08 19:27 . 2004-08-10 04:00 2189184 ------w- c:\windows\system32\ntoskrnl.exe
2009-12-08 18:43 . 2004-08-10 11:00 2066048 ------w- c:\windows\system32\ntkrnlpa.exe
2009-12-04 18:22 . 2004-08-10 04:00 455424 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-11-27 18:26 . 2008-08-07 16:44 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-11-27 18:26 . 2008-08-07 16:44 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-11-27 18:25 . 2009-01-29 15:39 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2009-11-27 18:25 . 2009-11-27 18:25 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-11-27 17:11 . 2004-08-10 11:00 17920 ----a-w- c:\windows\system32\msyuv.dll
2009-11-27 17:11 . 2004-08-10 04:00 1291776 ----a-w- c:\windows\system32\quartz.dll
2009-11-27 16:07 . 2004-08-10 11:00 8704 ----a-w- c:\windows\system32\tsbyuv.dll
2009-11-27 16:07 . 2004-08-10 04:00 28672 ----a-w- c:\windows\system32\msvidc32.dll
2009-11-27 16:07 . 2004-08-10 11:00 48128 ----a-w- c:\windows\system32\iyuv_32.dll
2009-11-27 16:07 . 2004-08-10 04:00 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-11-27 16:07 . 2004-08-10 04:00 11264 ----a-w- c:\windows\system32\msrle32.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-01-19 4670968]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-02-25 245760]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 253952]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2004-02-26 176128]
"DAEMON Tools-1033"="c:\program files\D-Tools\daemon.exe" [2004-08-22 81920]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 241664]
"HPHmon06"="c:\windows\system32\hphmon06.exe" [2004-06-07 659456]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-10 208952]
"IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-10 44032]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-10 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168]
"IPHSend"="c:\program files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-02-17 124520]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"nwiz"="nwiz.exe" [2008-10-07 1630208]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2007-08-16 236016]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-01-23 141608]

c:\documents and settings\Diego.HATTORIHANZO\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-10-29 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
Extender Resource Monitor.lnk - c:\windows\ehome\RMSysTry.exe [2005-10-20 18432]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-11 282624]
NkbMonitor.exe.lnk - c:\program files\Nikon\PictureProject\NkbMonitor.exe [2006-9-8 118784]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AtiExtEvent]
[BU]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-11-27 18:25 12464 ----a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Updates from HP\\309731\\Program\\Updates from HP.exe"=
"c:\\sysreset\\mirc.exe"=
"c:\\Program Files\\BitTornado\\btdownloadgui.exe"=
"c:\\Program Files\\Macromedia\\Fireworks MX\\Fireworks.exe"=
"c:\\Program Files\\Starcraft\\StarCraft.exe"=
"c:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"c:\\Program Files\\Watanabe-Production and TYPE-MOON\\Melty Blood Re-ACT Final Tuned\\mbr_net_b7v2.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Last.fm\\LastFM.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-1.12.0-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-1.12.x-to-2.0.1-enUS-patch-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.3-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.3.6299-to-2.0.12.6546-enUS-downloader.exe"=
"c:\\Program Files\\Common Files\\AOL\\1184648623\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1184648623\\ee\\aim6.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\EcoleSoftware\\MBACWIN\\mbcaster.exe"=
"%windir%\\system32\\drivers\\svchost.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0.10192-to-3.2.0.10314-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0.10314-to-3.2.2.10482-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.2.10482-to-3.2.2.10505-enUS-downloader.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\AIM7\\aim.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3776:UDP"= 3776:UDP:Media Center Extender Service
"3390:TCP"= 3390:TCP:Remote Media Center Experience
"6112:TCP"= 6112:TCP:Blizzard Downloader
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724

R0 d347bus;d347bus;c:\windows\system32\drivers\d347bus.sys [10/6/2005 11:21 PM 155136]
R0 d347prt;d347prt;c:\windows\system32\drivers\d347prt.sys [10/6/2005 11:21 PM 5248]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [8/7/2008 10:44 AM 333192]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [11/27/2009 12:25 PM 360584]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [11/27/2009 12:25 PM 285392]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [3/4/2009 11:57 AM 24652]
S2 wjrgxpifylr;wjrgxpifylr;\??\c:\windows\system32\drivers\gaxpjzn.sys --> c:\windows\system32\drivers\gaxpjzn.sys [?]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
QWAVE REG_MULTI_SZ QWAVE
.
Contents of the 'Scheduled Tasks' folder

2010-02-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:34]
.
.
------- Supplementary Scan -------
.
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=desktop&parm1=seconduser
uInternet Settings,ProxyOverride = *.local
IE: &Google Search - c:\program files\google\GoogleToolbar2.dll/cmsearch.html
IE: &Translate English Word - c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
IE: Backward Links - c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar2.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\google\GoogleToolbar2.dll/cmtrans.html
FF - ProfilePath - c:\documents and settings\Diego.HATTORIHANZO\Application Data\Mozilla\Firefox\Profiles\8pc0a37l.default\
FF - prefs.js: browser.search.selectedEngine - Wikipedia (en)
FF - prefs.js: browser.startup.homepage - hxxp://www.gamefaqs.com/
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: c:\progra~1\Yahoo!\Common\npyaxmpb.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdnupdater2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\QuickTime\Plugins\npqtplugin8.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
FF - user.js: network.protocol-handler.warn-external.dnupdate - false.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-24 09:17
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe catchme.sys CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8A36B008]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xba8ecf28
\Driver\ACPI -> ACPI.sys @ 0xba759cb8
\Driver\atapi -> 0x8a36b008
IoDeviceObjectType -> ParseProcedure -> ntkrnlpa.exe @ 0x80577c84
SecurityProcedure -> ntkrnlpa.exe @ 0x80579208
\Device\Harddisk0\DR0 -> ParseProcedure -> ntkrnlpa.exe @ 0x80577c84
SecurityProcedure -> ntkrnlpa.exe @ 0x80579208
NDIS: Realtek RTL8139/810x Family Fast Ethernet NIC -> SendCompleteHandler -> NDIS.sys @ 0xba5bdbd4
PacketIndicateHandler -> NDIS.sys @ 0xba5aba0d
SendHandler -> NDIS.sys @ 0xba5bfb40
Warning: possible MBR rootkit infection !
user & kernel MBR OK

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(1360)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-02-24 09:19:32
ComboFix-quarantined-files.txt 2010-02-24 15:19
ComboFix2.txt 2010-02-24 04:45

Pre-Run: 100,884,107,264 bytes free
Post-Run: 100,844,335,104 bytes free

- - End Of File - - B65E5444B639D31E9B6F0FA3BD156818
Upload was successful
  • 0

#6
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
hi

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

File::
c:\documents and settings\Diego.HATTORIHANZO\Local Settings\Application Data\prvlcl.dat
c:\windows\system32\drivers\gaxpjzn.sys

Registry::
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\drivers\\svchost.exe"=-

Driver::
wjrgxpifylr


Save this as CFScript.txt, in the same location as ComboFix.exe


Posted Image

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.



Download TDSSKiller and save it to your Desktop.

  • Extract the file and run it.
  • Once completed it will create a log in your C:\ drive
  • Please post the contents of that log

  • 0

#7
Hiarashi

Hiarashi

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
Okay, here's the ComboFix log:

ComboFix 10-02-23.03 - Diego 02/24/2010 10:08:57.3.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1358 [GMT -6:00]
Running from: c:\documents and settings\Diego.HATTORIHANZO\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Diego.HATTORIHANZO\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

FILE ::
"c:\documents and settings\Diego.HATTORIHANZO\Local Settings\Application Data\prvlcl.dat"
"c:\windows\system32\drivers\gaxpjzn.sys"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Diego.HATTORIHANZO\Local Settings\Application Data\prvlcl.dat

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_wjrgxpifylr


((((((((((((((((((((((((( Files Created from 2010-01-24 to 2010-02-24 )))))))))))))))))))))))))))))))
.

2010-02-24 03:55 . 2010-02-24 03:55 -------- d-----w- C:\_OTL
2010-02-23 15:22 . 2010-02-23 15:23 -------- d-----w- c:\program files\ERUNT
2010-02-20 05:55 . 2010-02-20 05:55 -------- d-----w- c:\documents and settings\NetworkService\Application Data\AdobeUM
2010-02-17 16:04 . 2010-02-17 16:04 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-02-17 14:59 . 2010-02-17 14:59 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2010-02-15 03:59 . 2010-02-15 03:59 -------- d-----w- c:\program files\RADVideo
2010-02-13 06:13 . 2010-02-13 06:13 -------- d-----w- c:\program files\iPod
2010-02-12 18:41 . 2010-02-12 18:41 -------- d-----w- c:\documents and settings\All Users\Application Data\AIM
2010-02-12 18:41 . 2010-02-12 18:41 -------- d-----w- c:\program files\AIM7
2010-02-12 18:41 . 2010-02-12 18:41 -------- d-----w- c:\program files\Common Files\Software Update Utility

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-22 05:55 . 2006-12-02 20:42 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2010-02-18 04:58 . 2008-04-12 05:34 -------- d-----w- c:\program files\Jnes
2010-02-18 02:46 . 2005-09-14 04:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-02-13 06:14 . 2006-11-25 18:45 -------- d-----w- c:\program files\iTunes
2010-02-13 06:13 . 2007-11-21 22:40 -------- d-----w- c:\program files\Common Files\Apple
2010-02-13 06:07 . 2010-02-13 06:07 72488 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
2010-02-12 19:49 . 2005-05-26 10:02 -------- d-----w- c:\program files\Java
2010-02-12 18:41 . 2007-01-22 06:56 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL
2010-02-10 07:29 . 2007-11-21 21:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-02-06 18:05 . 2008-02-15 22:48 -------- d-----w- c:\documents and settings\Diego.HATTORIHANZO\Application Data\Skype
2010-02-06 17:56 . 2008-02-15 22:50 -------- d-----w- c:\documents and settings\Diego.HATTORIHANZO\Application Data\skypePM
2010-02-05 01:05 . 2007-05-08 18:30 -------- d-----w- c:\program files\World of Warcraft
2010-01-27 05:15 . 2010-01-27 05:15 503808 ----a-w- c:\documents and settings\Diego.HATTORIHANZO\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-58c32131-n\msvcp71.dll
2010-01-27 05:15 . 2010-01-27 05:15 499712 ----a-w- c:\documents and settings\Diego.HATTORIHANZO\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-58c32131-n\jmc.dll
2010-01-27 05:15 . 2010-01-27 05:15 348160 ----a-w- c:\documents and settings\Diego.HATTORIHANZO\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-58c32131-n\msvcr71.dll
2010-01-27 05:15 . 2010-01-27 05:15 61440 ----a-w- c:\documents and settings\Diego.HATTORIHANZO\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-26606f46-n\decora-sse.dll
2010-01-27 05:15 . 2010-01-27 05:15 12800 ----a-w- c:\documents and settings\Diego.HATTORIHANZO\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-26606f46-n\decora-d3d.dll
2010-01-27 05:15 . 2005-05-26 10:02 -------- d-----w- c:\program files\Common Files\Java
2010-01-22 09:14 . 2010-01-22 09:14 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-22 07:00 . 2005-09-14 04:56 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-01-14 18:22 . 2010-01-14 18:22 -------- d-----w- c:\documents and settings\All Users\Application Data\ASign
2010-01-07 22:07 . 2010-01-22 09:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 22:07 . 2010-01-22 09:14 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-03 07:28 . 2007-08-17 22:54 20 ---h--w- c:\documents and settings\All Users\Application Data\PKP_DLds.DAT
2010-01-03 07:28 . 2006-09-08 22:28 20 ---h--w- c:\documents and settings\All Users\Application Data\PKP_DLec.DAT
2009-12-31 16:50 . 2004-08-10 04:00 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:14 . 2004-08-10 04:00 916480 ------w- c:\windows\system32\wininet.dll
2009-12-19 08:18 . 2009-12-19 08:18 96284 ---ha-w- c:\windows\system32\mlfcache.dat
2009-12-17 23:14 . 2009-01-13 17:29 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-16 18:43 . 2004-08-10 04:00 343040 ----a-w- c:\windows\system32\mspaint.exe
2009-12-15 16:44 . 2009-12-15 16:44 152576 ----a-w- c:\documents and settings\Diego.HATTORIHANZO\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-12-15 16:44 . 2009-12-15 16:44 79488 ----a-w- c:\documents and settings\Diego.HATTORIHANZO\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-12-14 07:08 . 2004-08-10 04:00 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-12-08 19:27 . 2004-08-10 04:00 2189184 ------w- c:\windows\system32\ntoskrnl.exe
2009-12-08 18:43 . 2004-08-10 11:00 2066048 ------w- c:\windows\system32\ntkrnlpa.exe
2009-12-04 18:22 . 2004-08-10 04:00 455424 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-11-27 18:26 . 2008-08-07 16:44 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-11-27 18:26 . 2008-08-07 16:44 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-11-27 18:25 . 2009-01-29 15:39 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2009-11-27 18:25 . 2009-11-27 18:25 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-11-27 17:11 . 2004-08-10 11:00 17920 ----a-w- c:\windows\system32\msyuv.dll
2009-11-27 17:11 . 2004-08-10 04:00 1291776 ----a-w- c:\windows\system32\quartz.dll
2009-11-27 16:07 . 2004-08-10 11:00 8704 ----a-w- c:\windows\system32\tsbyuv.dll
2009-11-27 16:07 . 2004-08-10 04:00 28672 ----a-w- c:\windows\system32\msvidc32.dll
2009-11-27 16:07 . 2004-08-10 11:00 48128 ----a-w- c:\windows\system32\iyuv_32.dll
2009-11-27 16:07 . 2004-08-10 04:00 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-11-27 16:07 . 2004-08-10 04:00 11264 ----a-w- c:\windows\system32\msrle32.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-01-19 4670968]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-02-25 245760]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 253952]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2004-02-26 176128]
"DAEMON Tools-1033"="c:\program files\D-Tools\daemon.exe" [2004-08-22 81920]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 241664]
"HPHmon06"="c:\windows\system32\hphmon06.exe" [2004-06-07 659456]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-10 208952]
"IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-10 44032]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-10 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168]
"IPHSend"="c:\program files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-02-17 124520]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"nwiz"="nwiz.exe" [2008-10-07 1630208]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2007-08-16 236016]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-01-23 141608]

c:\documents and settings\Diego.HATTORIHANZO\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-10-29 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
Extender Resource Monitor.lnk - c:\windows\ehome\RMSysTry.exe [2005-10-20 18432]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-11 282624]
NkbMonitor.exe.lnk - c:\program files\Nikon\PictureProject\NkbMonitor.exe [2006-9-8 118784]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AtiExtEvent]
[BU]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-11-27 18:25 12464 ----a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Updates from HP\\309731\\Program\\Updates from HP.exe"=
"c:\\sysreset\\mirc.exe"=
"c:\\Program Files\\BitTornado\\btdownloadgui.exe"=
"c:\\Program Files\\Macromedia\\Fireworks MX\\Fireworks.exe"=
"c:\\Program Files\\Starcraft\\StarCraft.exe"=
"c:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"c:\\Program Files\\Watanabe-Production and TYPE-MOON\\Melty Blood Re-ACT Final Tuned\\mbr_net_b7v2.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Last.fm\\LastFM.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-1.12.0-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-1.12.x-to-2.0.1-enUS-patch-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.3-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.3.6299-to-2.0.12.6546-enUS-downloader.exe"=
"c:\\Program Files\\Common Files\\AOL\\1184648623\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1184648623\\ee\\aim6.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\EcoleSoftware\\MBACWIN\\mbcaster.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0.10192-to-3.2.0.10314-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0.10314-to-3.2.2.10482-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.2.10482-to-3.2.2.10505-enUS-downloader.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\AIM7\\aim.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3776:UDP"= 3776:UDP:Media Center Extender Service
"3390:TCP"= 3390:TCP:Remote Media Center Experience
"6112:TCP"= 6112:TCP:Blizzard Downloader
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724

R0 d347bus;d347bus;c:\windows\system32\drivers\d347bus.sys [10/6/2005 11:21 PM 155136]
R0 d347prt;d347prt;c:\windows\system32\drivers\d347prt.sys [10/6/2005 11:21 PM 5248]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [8/7/2008 10:44 AM 333192]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [11/27/2009 12:25 PM 360584]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [11/27/2009 12:25 PM 285392]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [3/4/2009 11:57 AM 24652]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - GTNDIS5

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
QWAVE REG_MULTI_SZ QWAVE
.
Contents of the 'Scheduled Tasks' folder

2010-02-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:34]
.
.
------- Supplementary Scan -------
.
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=desktop&parm1=seconduser
uInternet Settings,ProxyOverride = *.local
IE: &Google Search - c:\program files\google\GoogleToolbar2.dll/cmsearch.html
IE: &Translate English Word - c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
IE: Backward Links - c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar2.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\google\GoogleToolbar2.dll/cmtrans.html
FF - ProfilePath - c:\documents and settings\Diego.HATTORIHANZO\Application Data\Mozilla\Firefox\Profiles\8pc0a37l.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.gamefaqs.com/
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: c:\progra~1\Yahoo!\Common\npyaxmpb.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdnupdater2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\QuickTime\Plugins\npqtplugin8.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
FF - user.js: network.protocol-handler.warn-external.dnupdate - false.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-24 10:15
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8A22B060]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xba8ecf28
\Driver\ACPI -> ACPI.sys @ 0xba759cb8
\Driver\atapi -> 0x8a22b060
IoDeviceObjectType -> ParseProcedure -> ntkrnlpa.exe @ 0x80577c84
SecurityProcedure -> ntkrnlpa.exe @ 0x80579208
\Device\Harddisk0\DR0 -> ParseProcedure -> ntkrnlpa.exe @ 0x80577c84
SecurityProcedure -> ntkrnlpa.exe @ 0x80579208
NDIS: Realtek RTL8139/810x Family Fast Ethernet NIC -> SendCompleteHandler -> NDIS.sys @ 0xba5bdbd4
PacketIndicateHandler -> NDIS.sys @ 0xba5aba0d
SendHandler -> NDIS.sys @ 0xba5bfb40
Warning: possible MBR rootkit infection !
user & kernel MBR OK

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(1180)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\nvsvc32.exe
c:\windows\ehome\RMSvc.exe
c:\program files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WLService.exe
c:\program files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WMP54GSv1_1.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
c:\windows\eHome\ehmsas.exe
c:\windows\system32\RUNDLL32.EXE
c:\program files\Common Files\AOL\1184648623\ee\aolsoftware.exe
c:\program files\Yahoo!\Messenger\ymsgr_tray.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
.
**************************************************************************
.
Completion time: 2010-02-24 10:22:50 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-24 16:22
ComboFix2.txt 2010-02-24 15:21
ComboFix3.txt 2010-02-24 04:45

Pre-Run: 100,846,383,104 bytes free
Post-Run: 100,815,306,752 bytes free

- - End Of File - - 91279D95BDE027219D6F165F21D148D0


And here's the other log:

10:41:07:562 3240 TDSS rootkit removing tool 2.2.4 Feb 15 2010 19:38:31
10:41:07:562 3240 ================================================================================
10:41:07:562 3240 SystemInfo:

10:41:07:562 3240 OS Version: 5.1.2600 ServicePack: 3.0
10:41:07:562 3240 Product type: Workstation
10:41:07:562 3240 ComputerName: HATTORIHANZO
10:41:07:562 3240 UserName: Diego
10:41:07:562 3240 Windows directory: C:\WINDOWS
10:41:07:562 3240 Processor architecture: Intel x86
10:41:07:562 3240 Number of processors: 1
10:41:07:562 3240 Page size: 0x1000
10:41:07:578 3240 Boot type: Normal boot
10:41:07:578 3240 ================================================================================
10:41:07:578 3240 UnloadDriverW: NtUnloadDriver error 2
10:41:07:578 3240 ForceUnloadDriverW: UnloadDriverW(klmd21) error 2
10:41:07:578 3240 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\drivers\klmd.sys) returned status 00000000
10:41:07:578 3240 UtilityInit: KLMD drop and load success
10:41:07:578 3240 KLMD_OpenDevice: Trying to open KLMD Device(KLMD201010)
10:41:07:578 3240 UtilityInit: KLMD open success
10:41:07:578 3240 UtilityInit: Initialize success
10:41:07:578 3240
10:41:07:578 3240 Scanning Services ...
10:41:07:578 3240 CreateRegParser: Registry parser init started
10:41:07:578 3240 DisableWow64Redirection: GetProcAddress(Wow64DisableWow64FsRedirection) error 127
10:41:07:578 3240 CreateRegParser: DisableWow64Redirection error
10:41:07:578 3240 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\system
10:41:07:578 3240 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\config\system) returned status C0000043
10:41:07:578 3240 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
10:41:07:578 3240 wfopen_ex: Trying to KLMD file open
10:41:07:578 3240 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\config\system
10:41:07:578 3240 wfopen_ex: File opened ok (Flags 2)
10:41:07:578 3240 CreateRegParser: HIVE_ADAPTER(C:\WINDOWS\system32\config\system) init success: 394A98
10:41:07:578 3240 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\software
10:41:07:578 3240 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\config\software) returned status C0000043
10:41:07:578 3240 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
10:41:07:578 3240 wfopen_ex: Trying to KLMD file open
10:41:07:578 3240 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\config\software
10:41:07:578 3240 wfopen_ex: File opened ok (Flags 2)
10:41:07:578 3240 CreateRegParser: HIVE_ADAPTER(C:\WINDOWS\system32\config\software) init success: 394B40
10:41:07:578 3240 EnableWow64Redirection: GetProcAddress(Wow64RevertWow64FsRedirection) error 127
10:41:07:578 3240 CreateRegParser: EnableWow64Redirection error
10:41:07:578 3240 CreateRegParser: RegParser init completed
10:41:08:015 3240 GetAdvancedServicesInfo: Raw services enum returned 371 services
10:41:08:015 3240 fclose_ex: Trying to close file C:\WINDOWS\system32\config\system
10:41:08:015 3240 fclose_ex: Trying to close file C:\WINDOWS\system32\config\software
10:41:08:015 3240
10:41:08:015 3240 Scanning Kernel memory ...
10:41:08:015 3240 KLMD_GetSystemObjectAddressByNameW: Trying to get system object address by name \Driver\Disk
10:41:08:015 3240 DetectCureTDL3: \Driver\Disk PDRIVER_OBJECT: 8A5DE2B8
10:41:08:015 3240 DetectCureTDL3: KLMD_GetDeviceObjectList returned 3 DevObjects
10:41:08:015 3240
10:41:08:015 3240 DetectCureTDL3: DEVICE_OBJECT: 8A51DC68
10:41:08:015 3240 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8A51DC68
10:41:08:015 3240 KLMD_ReadMem: Trying to ReadMemory 0x8A51DC68[0x38]
10:41:08:015 3240 DetectCureTDL3: DRIVER_OBJECT: 8A5DE2B8
10:41:08:015 3240 KLMD_ReadMem: Trying to ReadMemory 0x8A5DE2B8[0xA8]
10:41:08:015 3240 KLMD_ReadMem: Trying to ReadMemory 0xE1019D80[0x18]
10:41:08:015 3240 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
10:41:08:015 3240 DetectCureTDL3: IRP_MJ_CREATE : BA8EEBB0
10:41:08:015 3240 DetectCureTDL3: IRP_MJ_CREATE_NAMED_PIPE : 804F355A
10:41:08:015 3240 DetectCureTDL3: IRP_MJ_CLOSE : BA8EEBB0
10:41:08:015 3240 DetectCureTDL3: IRP_MJ_READ : BA8E8D1F
10:41:08:015 3240 DetectCureTDL3: IRP_MJ_WRITE : BA8E8D1F
10:41:08:015 3240 DetectCureTDL3: IRP_MJ_QUERY_INFORMATION : 804F355A
10:41:08:015 3240 DetectCureTDL3: IRP_MJ_SET_INFORMATION : 804F355A
10:41:08:015 3240 DetectCureTDL3: IRP_MJ_QUERY_EA : 804F355A
10:41:08:015 3240 DetectCureTDL3: IRP_MJ_SET_EA : 804F355A
10:41:08:015 3240 DetectCureTDL3: IRP_MJ_FLUSH_BUFFERS : BA8E92E2
10:41:08:015 3240 DetectCureTDL3: IRP_MJ_QUERY_VOLUME_INFORMATION : 804F355A
10:41:08:015 3240 DetectCureTDL3: IRP_MJ_SET_VOLUME_INFORMATION : 804F355A
10:41:08:015 3240 DetectCureTDL3: IRP_MJ_DIRECTORY_CONTROL : 804F355A
10:41:08:015 3240 DetectCureTDL3: IRP_MJ_FILE_SYSTEM_CONTROL : 804F355A
10:41:08:015 3240 DetectCureTDL3: IRP_MJ_DEVICE_CONTROL : BA8E93BB
10:41:08:015 3240 DetectCureTDL3: IRP_MJ_INTERNAL_DEVICE_CONTROL : BA8ECF28
10:41:08:015 3240 DetectCureTDL3: IRP_MJ_SHUTDOWN : BA8E92E2
10:41:08:015 3240 DetectCureTDL3: IRP_MJ_LOCK_CONTROL : 804F355A
10:41:08:015 3240 DetectCureTDL3: IRP_MJ_CLEANUP : 804F355A
10:41:08:015 3240 DetectCureTDL3: IRP_MJ_CREATE_MAILSLOT : 804F355A
10:41:08:015 3240 DetectCureTDL3: IRP_MJ_QUERY_SECURITY : 804F355A
10:41:08:015 3240 DetectCureTDL3: IRP_MJ_SET_SECURITY : 804F355A
10:41:08:015 3240 DetectCureTDL3: IRP_MJ_POWER : BA8EAC82
10:41:08:015 3240 DetectCureTDL3: IRP_MJ_SYSTEM_CONTROL : BA8EF99E
10:41:08:015 3240 DetectCureTDL3: IRP_MJ_DEVICE_CHANGE : 804F355A
10:41:08:015 3240 DetectCureTDL3: IRP_MJ_QUERY_QUOTA : 804F355A
10:41:08:015 3240 DetectCureTDL3: IRP_MJ_SET_QUOTA : 804F355A
10:41:08:015 3240 TDL3_FileDetect: Processing driver: Disk
10:41:08:015 3240 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
10:41:08:015 3240 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
10:41:08:046 3240 TDL3_FileDetect: Processing driver: Disk
10:41:08:046 3240 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
10:41:08:046 3240 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
10:41:08:046 3240 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
10:41:08:046 3240
10:41:08:046 3240 DetectCureTDL3: DEVICE_OBJECT: 8A5689F0
10:41:08:046 3240 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8A5689F0
10:41:08:046 3240 KLMD_ReadMem: Trying to ReadMemory 0x8A5689F0[0x38]
10:41:08:046 3240 DetectCureTDL3: DRIVER_OBJECT: 8A5DE2B8
10:41:08:046 3240 KLMD_ReadMem: Trying to ReadMemory 0x8A5DE2B8[0xA8]
10:41:08:046 3240 KLMD_ReadMem: Trying to ReadMemory 0xE1019D80[0x18]
10:41:08:046 3240 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_CREATE : BA8EEBB0
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_CREATE_NAMED_PIPE : 804F355A
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_CLOSE : BA8EEBB0
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_READ : BA8E8D1F
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_WRITE : BA8E8D1F
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_QUERY_INFORMATION : 804F355A
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_SET_INFORMATION : 804F355A
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_QUERY_EA : 804F355A
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_SET_EA : 804F355A
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_FLUSH_BUFFERS : BA8E92E2
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_QUERY_VOLUME_INFORMATION : 804F355A
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_SET_VOLUME_INFORMATION : 804F355A
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_DIRECTORY_CONTROL : 804F355A
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_FILE_SYSTEM_CONTROL : 804F355A
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_DEVICE_CONTROL : BA8E93BB
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_INTERNAL_DEVICE_CONTROL : BA8ECF28
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_SHUTDOWN : BA8E92E2
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_LOCK_CONTROL : 804F355A
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_CLEANUP : 804F355A
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_CREATE_MAILSLOT : 804F355A
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_QUERY_SECURITY : 804F355A
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_SET_SECURITY : 804F355A
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_POWER : BA8EAC82
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_SYSTEM_CONTROL : BA8EF99E
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_DEVICE_CHANGE : 804F355A
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_QUERY_QUOTA : 804F355A
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_SET_QUOTA : 804F355A
10:41:08:046 3240 TDL3_FileDetect: Processing driver: Disk
10:41:08:046 3240 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
10:41:08:046 3240 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
10:41:08:046 3240 TDL3_FileDetect: Processing driver: Disk
10:41:08:046 3240 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
10:41:08:046 3240 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
10:41:08:046 3240 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
10:41:08:046 3240
10:41:08:046 3240 DetectCureTDL3: DEVICE_OBJECT: 8A572AB8
10:41:08:046 3240 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8A572AB8
10:41:08:046 3240 DetectCureTDL3: DEVICE_OBJECT: 8A5819E8
10:41:08:046 3240 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8A5819E8
10:41:08:046 3240 DetectCureTDL3: DEVICE_OBJECT: 8A57CB00
10:41:08:046 3240 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8A57CB00
10:41:08:046 3240 KLMD_ReadMem: Trying to ReadMemory 0x8A57CB00[0x38]
10:41:08:046 3240 DetectCureTDL3: DRIVER_OBJECT: 8A529470
10:41:08:046 3240 KLMD_ReadMem: Trying to ReadMemory 0x8A529470[0xA8]
10:41:08:046 3240 KLMD_ReadMem: Trying to ReadMemory 0xE17F5968[0x1A]
10:41:08:046 3240 DetectCureTDL3: DRIVER_OBJECT name: \Driver\atapi, Driver Name: atapi
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_CREATE : 8A22B060
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_CREATE_NAMED_PIPE : 8A22B060
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_CLOSE : 8A22B060
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_READ : 8A22B060
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_WRITE : 8A22B060
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_QUERY_INFORMATION : 8A22B060
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_SET_INFORMATION : 8A22B060
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_QUERY_EA : 8A22B060
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_SET_EA : 8A22B060
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_FLUSH_BUFFERS : 8A22B060
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_QUERY_VOLUME_INFORMATION : 8A22B060
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_SET_VOLUME_INFORMATION : 8A22B060
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_DIRECTORY_CONTROL : 8A22B060
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_FILE_SYSTEM_CONTROL : 8A22B060
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_DEVICE_CONTROL : 8A22B060
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_INTERNAL_DEVICE_CONTROL : 8A22B060
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_SHUTDOWN : 8A22B060
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_LOCK_CONTROL : 8A22B060
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_CLEANUP : 8A22B060
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_CREATE_MAILSLOT : 8A22B060
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_QUERY_SECURITY : 8A22B060
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_SET_SECURITY : 8A22B060
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_POWER : 8A22B060
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_SYSTEM_CONTROL : 8A22B060
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_DEVICE_CHANGE : 8A22B060
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_QUERY_QUOTA : 8A22B060
10:41:08:046 3240 DetectCureTDL3: IRP_MJ_SET_QUOTA : 8A22B060
10:41:08:046 3240 TDL3_FileDetect: Processing driver: atapi
10:41:08:046 3240 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\atapi.sys
10:41:08:046 3240 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\atapi.sys
10:41:08:062 3240 DetectCureTDL3: All IRP handlers pointed to one addr: 8A22B060
10:41:08:062 3240 KLMD_ReadMem: Trying to ReadMemory 0x8A22B060[0x400]
10:41:08:062 3240 TDL3_IrpHookDetect: CheckParameters: 0, 0, 0, 0, 0, 0
10:41:08:062 3240 KLMD_ReadMem: Trying to ReadMemory 0xBA6EC864[0x400]
10:41:08:062 3240 TDL3_StartIoHookDetect: CheckParameters: 0, 00000000, 0
10:41:08:062 3240 TDL3_FileDetect: Processing driver: atapi
10:41:08:062 3240 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\atapi.sys
10:41:08:062 3240 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\atapi.sys
10:41:08:078 3240 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\atapi.sys - Verdict: Clean
10:41:08:078 3240
10:41:08:078 3240 Completed
10:41:08:078 3240
10:41:08:078 3240 Results:
10:41:08:078 3240 Memory objects infected / cured / cured on reboot: 0 / 0 / 0
10:41:08:078 3240 Registry objects infected / cured / cured on reboot: 0 / 0 / 0
10:41:08:078 3240 File objects infected / cured / cured on reboot: 0 / 0 / 0
10:41:08:078 3240
10:41:08:078 3240 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\drivers\klmd.sys) returned status 00000000
10:41:08:078 3240 UtilityDeinit: KLMD(ARK) unloaded successfully
  • 0

#8
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
hi

Download TFC to your desktop
  • Open the file and close any other windows.
  • It will close all programs itself when run, make sure to let it run uninterrupted.
  • Click the Start button to begin the process. The program should not take long to finish its job
  • Once its finished it should reboot your machine, if not, do this yourself to ensure a complete clean




Please download Malwarebytes' Anti-Malware from Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.






Go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As....
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.

  • 0

#9
Hiarashi

Hiarashi

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
MBAM log:

Malwarebytes' Anti-Malware 1.44
Database version: 3613
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

2/26/2010 9:28:18 AM
mbam-log-2010-02-26 (09-28-18).txt

Scan type: Quick Scan
Objects scanned: 182120
Time elapsed: 6 minute(s), 52 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

And the Kaspersky log:

--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0: scan report
Friday, February 26, 2010
Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Friday, February 26, 2010 10:09:37
Records in database: 3651045
--------------------------------------------------------------------------------

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\
F:\
G:\
K:\

Scan statistics:
Objects scanned: 157606
Threats found: 9
Infected objects found: 14
Suspicious objects found: 0
Scan duration: 04:07:53


File name / Threat / Threats count
C:\Documents and Settings\Diego.HATTORIHANZO\.housecall\Quarantine\classload.jar-5b2a33e6-40efe1ae.zip.bac_a00920 Infected: Trojan.Java.ClassLoader.c 1
C:\Documents and Settings\Diego.HATTORIHANZO\.housecall\Quarantine\classload.jar-5b2a33e6-40efe1ae.zip.bac_a00920 Infected: Exploit.Java.ByteVerify 1
C:\Documents and Settings\Diego.HATTORIHANZO\.housecall\Quarantine\classload.jar-5b2a33e6-40efe1ae.zip.bac_a00920 Infected: Trojan.Java.ClassLoader.Dummy.a 1
C:\Documents and Settings\Diego.HATTORIHANZO\.housecall\Quarantine\classload.jar-5b2a33e6-40efe1ae.zip.bac_a00920 Infected: Trojan-Downloader.Java.OpenConnection.v 1
C:\Documents and Settings\Diego.HATTORIHANZO\.housecall\Quarantine\jrl.jar-44604b10-3c2d58f3.zip.bac_a00920 Infected: Trojan-Downloader.Java.OpenConnection.aj 2
C:\Documents and Settings\Diego.HATTORIHANZO\.housecall\Quarantine\jrl.jar-44604b10-3c2d58f3.zip.bac_a00920 Infected: Exploit.Java.ByteVerify 2
C:\Program Files\Online Services\AOL90US\comps\toolbar\toolbr.EXE Infected: not-a-virus:AdWare.Win32.SearchIt.t 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\atapi.sys.vir Infected: Rootkit.Win32.Tdss.ai 1
C:\Qoobox\Quarantine\[22]-Submit_2010-02-24_09.10.12.zip Infected: Rootkit.Win32.Tdss.ai 1
C:\sysreset\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.614 1
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP1080\A0252536.exe Infected: Packed.Win32.Krap.w 1
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP1086\A0257257.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.614 1

Selected area has been scanned.
  • 0

#10
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
  • 0

#11
Hiarashi

Hiarashi

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
Here it is:

OTL logfile created on: 2/26/2010 10:04:53 PM - Run 2
OTL by OldTimer - Version 3.1.30.1 Folder = C:\Documents and Settings\Diego.HATTORIHANZO\My Documents\Downloads
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 63.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 224.87 Gb Total Space | 93.93 Gb Free Space | 41.77% Space Free | Partition Type: NTFS
Drive D: | 8.00 Gb Total Space | 1.39 Gb Free Space | 17.43% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
Drive F: | 4.35 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: HATTORIHANZO
Current User Name: Diego
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Processes (SafeList) ==========

PRC - [2010/02/23 09:46:57 | 000,549,376 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Diego.HATTORIHANZO\My Documents\Downloads\OTL.exe
PRC - [2010/01/22 19:16:42 | 000,141,608 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunes\iTunesHelper.exe
PRC - [2010/01/22 19:16:30 | 000,545,576 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe
PRC - [2009/12/17 17:14:11 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2009/12/12 11:18:28 | 000,600,344 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgnsx.exe
PRC - [2009/12/12 11:18:28 | 000,503,576 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgrsx.exe
PRC - [2009/12/01 11:38:47 | 003,951,976 | ---- | M] (AOL LLC) -- C:\Program Files\AIM7\aim.exe
PRC - [2009/11/27 12:25:48 | 001,055,000 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgchsvx.exe
PRC - [2009/11/27 12:25:45 | 000,702,744 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgcsrvx.exe
PRC - [2009/11/27 12:25:39 | 000,285,392 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgwdsvc.exe
PRC - [2009/11/10 23:08:18 | 000,417,792 | ---- | M] (Apple Inc.) -- C:\Program Files\QuickTime\QTTask.exe
PRC - [2009/05/29 12:41:26 | 000,144,712 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2009/03/05 15:07:20 | 002,260,480 | RHS- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2008/12/12 10:17:38 | 000,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe
PRC - [2008/10/25 10:44:34 | 000,031,072 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
PRC - [2008/10/07 13:33:00 | 000,163,908 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe
PRC - [2008/04/13 18:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/01/19 12:49:30 | 000,103,928 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe
PRC - [2007/01/04 15:38:08 | 000,024,652 | ---- | M] (Viewpoint Corporation) -- C:\Program Files\Viewpoint\Common\ViewpointService.exe
PRC - [2006/10/18 20:05:26 | 000,204,288 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnscfg.exe
PRC - [2006/10/16 15:10:22 | 000,118,784 | ---- | M] (Nikon Corporation) -- C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
PRC - [2006/05/09 18:24:16 | 000,050,760 | ---- | M] (America Online, Inc.) -- C:\Program Files\Common Files\AOL\1184648623\ee\aolsoftware.exe
PRC - [2005/10/20 18:55:40 | 000,028,160 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ehome\RMSvc.exe
PRC - [2005/10/20 18:55:40 | 000,018,432 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ehome\RMSysTry.exe
PRC - [2005/05/12 00:40:38 | 000,204,800 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
PRC - [2005/05/11 23:23:26 | 000,282,624 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
PRC - [2005/05/11 23:16:22 | 000,077,824 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
PRC - [2005/05/08 22:04:06 | 000,053,248 | ---- | M] (Hewlett-Packard Company) -- c:\Program Files\Common Files\LightScribe\LSSrvc.exe
PRC - [2005/04/28 21:20:26 | 005,046,784 | ---- | M] (Linksys) -- C:\Program Files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WMP54GSv1_1.exe
PRC - [2005/02/02 09:44:24 | 000,061,440 | ---- | M] (Hewlett-Packard Company) -- C:\hp\KBD\KBD.exe
PRC - [2004/09/07 07:47:52 | 000,057,344 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\ALCXMNTR.EXE
PRC - [2004/08/22 16:05:02 | 000,081,920 | ---- | M] (DAEMON'S HOME) -- C:\Program Files\D-Tools\daemon.exe
PRC - [2004/06/29 04:06:38 | 000,088,363 | ---- | M] (Agere Systems) -- C:\WINDOWS\AGRSMMSG.exe
PRC - [2004/06/07 05:42:30 | 000,659,456 | ---- | M] (Hewlett-Packard) -- C:\WINDOWS\system32\hphmon06.exe
PRC - [2004/02/06 21:56:14 | 000,041,025 | ---- | M] (GEMTEKS) -- C:\Program Files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WLService.exe
PRC - [2003/12/22 07:38:42 | 000,241,664 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
PRC - [1998/05/07 03:04:38 | 000,052,736 | ---- | M] (Hewlett-Packard Company) -- c:\WINDOWS\system\hpsysdrv.exe


========== Modules (SafeList) ==========

MOD - [2010/02/23 09:46:57 | 000,549,376 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Diego.HATTORIHANZO\My Documents\Downloads\OTL.exe


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Running] -- -- (WMP54GSSVC)
SRV - File not found [On_Demand | Stopped] -- -- (NMIndexingService)
SRV - [2010/01/22 19:16:30 | 000,545,576 | ---- | M] (Apple Inc.) [On_Demand | Running] -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service)
SRV - [2009/12/17 17:14:11 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) [Auto | Running] -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2009/11/27 12:25:39 | 000,285,392 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG9\avgwdsvc.exe -- (avg9wd)
SRV - [2009/05/29 12:41:26 | 000,144,712 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2008/12/12 10:17:38 | 000,238,888 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service)
SRV - [2008/11/04 00:06:28 | 000,441,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv)
SRV - [2008/10/25 10:44:08 | 000,065,888 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe -- (Microsoft Office Groove Audit Service)
SRV - [2008/10/07 13:33:00 | 000,163,908 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\WINDOWS\system32\nvsvc32.exe -- (NVSvc)
SRV - [2007/08/16 08:56:16 | 000,309,744 | ---- | M] (Sonic Solutions) [Auto | Stopped] -- C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe -- (RoxLiveShare9)
SRV - [2007/08/16 08:56:14 | 000,166,384 | ---- | M] (Sonic Solutions) [Auto | Stopped] -- C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe -- (RoxWatch9)
SRV - [2007/08/16 08:56:10 | 001,092,080 | ---- | M] (Sonic Solutions) [On_Demand | Stopped] -- C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe -- (RoxMediaDB9)
SRV - [2007/07/24 05:14:08 | 000,088,560 | ---- | M] (Sonic Solutions) [On_Demand | Stopped] -- C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe -- (Roxio UPnP Renderer 9)
SRV - [2007/07/24 05:14:06 | 000,358,896 | ---- | M] (Sonic Solutions) [Auto | Stopped] -- C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe -- (Roxio Upnp Server 9)
SRV - [2007/01/19 11:54:14 | 000,097,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\MSN Messenger\usnsvc.exe -- (usnjsvc)
SRV - [2007/01/04 15:38:08 | 000,024,652 | ---- | M] (Viewpoint Corporation) [Auto | Running] -- C:\Program Files\Viewpoint\Common\ViewpointService.exe -- (Viewpoint Manager Service)
SRV - [2006/10/26 14:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose)
SRV - [2005/10/29 22:25:16 | 000,068,096 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe -- (Adobe LM Service)
SRV - [2005/10/20 18:55:40 | 000,028,160 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\ehome\RMSvc.exe -- (RMSvc)
SRV - [2005/05/08 22:04:06 | 000,053,248 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- c:\Program Files\Common Files\LightScribe\LSSrvc.exe -- (LightScribeService)
SRV - [2004/10/22 04:24:18 | 000,073,728 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe -- (IDriverT)
SRV - [2004/09/29 13:14:36 | 000,069,632 | ---- | M] (HP) [Auto | Stopped] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.gamefaqs.com/"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.716
FF - prefs.js..extensions.enabledItems: [email protected]:1.0


FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2009/12/12 11:19:04 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/02/20 21:20:23 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/02/23 22:35:28 | 000,000,000 | ---D | M]

[2008/08/26 22:51:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\Mozilla\Extensions
[2010/02/25 11:08:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\Mozilla\Firefox\Profiles\8pc0a37l.default\extensions
[2008/04/07 01:31:09 | 000,002,300 | ---- | M] () -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\Mozilla\Firefox\Profiles\8pc0a37l.default\searchplugins\encyclopedia-dramatica-.xml
[2009/01/31 12:26:02 | 000,002,006 | ---- | M] () -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\Mozilla\Firefox\Profiles\8pc0a37l.default\searchplugins\urban-dictionary.xml
[2008/07/03 20:17:07 | 000,000,681 | ---- | M] () -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\Mozilla\Firefox\Profiles\8pc0a37l.default\searchplugins\webster.xml
[2008/07/03 20:17:07 | 000,001,108 | ---- | M] () -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\Mozilla\Firefox\Profiles\8pc0a37l.default\searchplugins\wikipedia-en.xml
[2009/05/10 14:41:02 | 000,003,077 | ---- | M] () -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\Mozilla\Firefox\Profiles\8pc0a37l.default\searchplugins\wikitravel-en.xml
[2007/07/01 00:14:20 | 000,001,406 | ---- | M] () -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\Mozilla\Firefox\Profiles\8pc0a37l.default\searchplugins\wowhead.xml
[2007/12/13 03:14:37 | 000,001,826 | ---- | M] () -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\Mozilla\Firefox\Profiles\8pc0a37l.default\searchplugins\wowwiki-english.xml
[2007/05/19 01:10:04 | 000,002,109 | ---- | M] () -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\Mozilla\Firefox\Profiles\8pc0a37l.default\searchplugins\youtube-video-search.xml
[2010/02/26 11:18:24 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2007/04/16 11:07:12 | 000,180,293 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll

O1 HOSTS File: ([2010/02/24 10:15:43 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll File not found
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O2 - BHO: (QUICKfind BHO Object) - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\Program Files\TEXTware\QUICKfind\PlugIns\IEHelp.dll ()
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O3 - HKLM\..\Toolbar: (HP view) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll (Hewlett-Packard Company)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (HP view) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll (Hewlett-Packard Company)
O3 - HKCU\..\Toolbar\WebBrowser: (HP view) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll (Hewlett-Packard Company)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [DAEMON Tools-1033] C:\Program Files\D-Tools\daemon.exe (DAEMON'S HOME)
O4 - HKLM..\Run: [GrooveMonitor] C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
O4 - HKLM..\Run: [HP Component Manager] C:\Program Files\HP\hpcoretech\hpcmpmgr.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [HPBootOp] C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe (HP)
O4 - HKLM..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe (Hewlett-Packard)
O4 - HKLM..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\imekrmig.exe (Microsoft Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe (America Online, Inc.)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\LSBurnWatcher.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Sonic Solutions)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Extender Resource Monitor.lnk = C:\WINDOWS\ehome\RMSysTry.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe (Nikon Corporation)
O4 - Startup: C:\Documents and Settings\Diego.HATTORIHANZO\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Google Search - c:\program files\google\GoogleToolbar2.dll (Google Inc.)
O8 - Extra context menu item: &Translate English Word - c:\program files\google\GoogleToolbar2.dll (Google Inc.)
O8 - Extra context menu item: Backward Links - c:\program files\google\GoogleToolbar2.dll (Google Inc.)
O8 - Extra context menu item: Cached Snapshot of Page - c:\program files\google\GoogleToolbar2.dll (Google Inc.)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Similar Pages - c:\program files\google\GoogleToolbar2.dll (Google Inc.)
O8 - Extra context menu item: Translate Page into English - c:\program files\google\GoogleToolbar2.dll (Google Inc.)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_18.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O9 - Extra 'Tools' menuitem : Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 51 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft....k/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://go.divx.com/p...owserPlugin.cab (DivXBrowserPlugin Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} http://acs.pandasoft...free/asinst.cab (ActiveScan Installer Class)
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} http://www.crucial.c.../cpcScanner.cab (Crucial cpcScan)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.ma...ent/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 68.87.77.134 68.87.72.134
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop WallPaper: C:\Documents and Settings\Diego.HATTORIHANZO\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Diego.HATTORIHANZO\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/05/26 05:08:45 | 000,000,100 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] -- "%1" %*
O35 - exefile [open] -- "%1" %*

========== Files/Folders - Created Within 14 Days ==========

[2010/02/24 10:40:52 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010/02/23 22:22:14 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010/02/23 22:22:14 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010/02/23 22:22:14 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010/02/23 22:22:14 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010/02/23 22:21:33 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010/02/23 21:55:23 | 000,000,000 | ---D | C] -- C:\_OTL
[2010/02/23 09:31:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Diego.HATTORIHANZO\Desktop\GooredFix Backups
[2010/02/23 09:23:43 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010/02/23 09:22:55 | 000,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2010/02/19 23:55:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Application Data\AdobeUM
[2010/02/19 14:33:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2010/02/17 20:15:26 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Diego.HATTORIHANZO\Recent
[2010/02/17 10:04:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2010/02/17 10:04:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/02/17 00:22:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Application Data\Sun
[2010/02/16 23:57:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/02/14 21:59:33 | 000,000,000 | ---D | C] -- C:\Program Files\RADVideo
[2010/02/13 00:13:29 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2008/08/07 10:43:20 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2008/08/07 10:43:20 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
[2008/08/07 10:42:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2008/03/30 20:32:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Mozilla
[2008/03/30 20:32:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Mozilla
[2007/11/22 14:57:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2005/10/06 23:21:13 | 000,155,136 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\d347bus.sys
[2005/10/06 23:21:13 | 000,005,248 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\d347prt.sys

========== Files - Modified Within 14 Days ==========

[2010/02/26 21:50:17 | 000,528,084 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010/02/26 21:50:17 | 000,445,700 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/02/26 21:50:17 | 000,072,780 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/02/26 21:49:34 | 056,305,693 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/02/26 21:47:35 | 000,000,188 | ---- | M] () -- C:\WINDOWS\System\hpsysdrv.DAT
[2010/02/26 21:46:30 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/02/26 21:45:30 | 000,200,819 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2010/02/26 21:45:19 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/02/26 21:45:09 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/02/26 21:45:07 | 2145,964,032 | -HS- | M] () -- C:\hiberfil.sys
[2010/02/26 14:05:43 | 015,990,784 | -H-- | M] () -- C:\Documents and Settings\Diego.HATTORIHANZO\NTUSER.DAT
[2010/02/26 08:24:20 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\Diego.HATTORIHANZO\ntuser.ini
[2010/02/24 11:49:43 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010/02/24 11:49:03 | 000,001,125 | ---- | M] () -- C:\WINDOWS\winamp.ini
[2010/02/24 10:15:53 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010/02/24 10:15:43 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010/02/23 22:17:20 | 003,870,177 | R--- | M] () -- C:\Documents and Settings\Diego.HATTORIHANZO\Desktop\ComboFix.exe
[2010/02/23 09:23:19 | 000,000,778 | ---- | M] () -- C:\Documents and Settings\Diego.HATTORIHANZO\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2010/02/21 23:55:26 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/02/21 23:04:36 | 098,836,992 | ---- | M] () -- C:\Documents and Settings\Diego.HATTORIHANZO\Desktop\lolmilf.avi
[2010/02/19 23:52:01 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/02/18 23:02:43 | 000,002,451 | ---- | M] () -- C:\WINDOWS\kaillera.ini
[2010/02/17 22:55:07 | 000,000,637 | ---- | M] () -- C:\Documents and Settings\Diego.HATTORIHANZO\Desktop\Jnes.lnk
[2010/02/17 22:00:18 | 000,000,538 | ---- | M] () -- C:\WINDOWS\WININIT.INI
[2010/02/14 22:12:45 | 000,030,720 | ---- | M] () -- C:\Documents and Settings\Diego.HATTORIHANZO\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== Files Created - No Company Name ==========

[2010/02/24 11:49:41 | 000,001,374 | ---- | C] () -- C:\WINDOWS\imsins.BAK
[2010/02/23 22:22:14 | 000,261,632 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010/02/23 22:22:14 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010/02/23 22:22:14 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010/02/23 22:22:14 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010/02/23 22:22:14 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010/02/23 22:17:18 | 003,870,177 | R--- | C] () -- C:\Documents and Settings\Diego.HATTORIHANZO\Desktop\ComboFix.exe
[2010/02/23 09:23:19 | 000,000,778 | ---- | C] () -- C:\Documents and Settings\Diego.HATTORIHANZO\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2010/02/21 23:04:18 | 098,836,992 | ---- | C] () -- C:\Documents and Settings\Diego.HATTORIHANZO\Desktop\lolmilf.avi
[2010/02/17 22:55:07 | 000,000,637 | ---- | C] () -- C:\Documents and Settings\Diego.HATTORIHANZO\Desktop\Jnes.lnk
[2009/02/25 16:36:16 | 000,000,376 | ---- | C] () -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\wklnhst.dat
[2008/11/10 22:14:41 | 000,000,538 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2008/10/07 13:33:00 | 001,703,936 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2008/10/07 13:33:00 | 001,486,848 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2008/10/07 13:33:00 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2008/10/07 13:33:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2008/10/07 13:33:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2008/02/15 16:50:10 | 000,000,032 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\ezsid.dat
[2007/08/17 16:54:43 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\Synth Textures
[2007/08/17 16:54:43 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\Sync Services
[2007/08/17 16:54:43 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLds.DAT
[2007/08/17 16:54:43 | 000,000,012 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\Techno Kit
[2007/07/29 23:46:31 | 000,000,000 | ---- | C] () -- C:\WINDOWS\iPlayer.INI
[2007/06/09 13:25:58 | 000,000,063 | ---- | C] () -- C:\WINDOWS\TEXTware.ini
[2007/06/09 13:25:53 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\TWAVBX32.DLL
[2007/06/09 13:25:52 | 000,018,432 | ---- | C] () -- C:\WINDOWS\System32\TWAIED02.DLL
[2007/06/09 13:25:51 | 000,099,092 | ---- | C] () -- C:\WINDOWS\System32\bass.dll
[2007/06/09 13:25:45 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\ILXTBS.DLL
[2007/05/22 20:53:47 | 000,000,049 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2007/03/29 00:02:04 | 000,000,000 | ---- | C] () -- C:\WINDOWS\muveeapp.INI
[2007/01/22 00:53:55 | 000,000,029 | ---- | C] () -- C:\WINDOWS\atid.ini
[2007/01/21 01:27:24 | 000,233,472 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll
[2007/01/10 03:16:54 | 000,011,776 | ---- | C] () -- C:\WINDOWS\System32\ZPORT4AS.dll
[2006/12/07 03:16:46 | 000,005,120 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2006/12/07 03:16:46 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2006/09/08 16:28:53 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT
[2006/05/09 08:51:02 | 000,002,536 | ---- | C] () -- C:\WINDOWS\EaseAudioConverter.ini
[2006/04/14 09:37:26 | 000,000,032 | ---- | C] () -- C:\WINDOWS\aceg.ini
[2005/12/25 02:27:08 | 000,002,451 | ---- | C] () -- C:\WINDOWS\kaillera.ini
[2005/10/20 23:35:01 | 000,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll
[2005/10/20 23:34:02 | 000,021,840 | ---- | C] () -- C:\WINDOWS\System32\SIntfNT.dll
[2005/10/20 23:34:02 | 000,017,212 | ---- | C] () -- C:\WINDOWS\System32\SIntf32.dll
[2005/10/20 23:34:01 | 000,012,067 | ---- | C] () -- C:\WINDOWS\System32\SIntf16.dll
[2005/10/09 14:38:34 | 000,000,026 | ---- | C] () -- C:\WINDOWS\WAR2R.INI
[2005/09/17 22:16:06 | 000,176,152 | ---- | C] () -- C:\WINDOWS\System32\CSGina.dll
[2005/09/15 12:23:20 | 000,030,720 | ---- | C] () -- C:\Documents and Settings\Diego.HATTORIHANZO\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/09/14 23:36:34 | 000,000,141 | ---- | C] () -- C:\Documents and Settings\Diego.HATTORIHANZO\Local Settings\Application Data\fusioncache.dat
[2005/09/14 22:02:05 | 000,001,695 | ---- | C] () -- C:\WINDOWS\hpdj3840.ini
[2005/09/14 22:01:48 | 000,000,516 | ---- | C] () -- C:\WINDOWS\hpbvspst.ini
[2005/09/14 14:24:37 | 000,002,917 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2005/09/14 13:21:57 | 000,001,125 | ---- | C] () -- C:\WINDOWS\winamp.ini
[2005/09/13 21:30:40 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\GTW32N50.dll
[2005/09/13 21:30:38 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\ssleay32.dll
[2005/09/13 21:30:37 | 000,651,264 | ---- | C] () -- C:\WINDOWS\System32\libeay32.dll
[2005/09/13 21:30:29 | 000,004,254 | ---- | C] () -- C:\WINDOWS\System32\WLAN.INI
[2005/08/05 13:01:54 | 000,235,008 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2005/05/26 05:10:37 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2005/05/26 05:08:00 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll
[2005/05/26 05:08:00 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll
[2005/05/26 05:08:00 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll
[2005/05/26 05:08:00 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll
[2005/05/26 05:08:00 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll
[2005/05/26 05:08:00 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll
[2005/05/26 04:39:53 | 000,015,328 | ---- | C] () -- C:\WINDOWS\System32\CHODDI.SYS
[2005/05/26 04:39:48 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\hpreg.dll
[2005/05/26 04:39:34 | 000,002,154 | ---- | C] () -- C:\WINDOWS\System32\ssmute.ini
[2005/05/26 04:36:41 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2005/05/26 04:17:16 | 000,006,468 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2005/05/26 04:16:03 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2005/05/26 03:58:07 | 000,000,791 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2005/05/26 03:55:53 | 000,016,896 | ---- | C] () -- C:\WINDOWS\System32\bcbmm.dll
[2005/04/27 12:38:00 | 000,372,736 | ---- | C] () -- C:\WINDOWS\System32\hpzidi01.dll
[2005/04/27 12:37:49 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\hpzids01.dll
[2005/02/18 04:56:18 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2005/01/19 16:45:40 | 000,090,112 | ---- | C] () -- C:\WINDOWS\System32\PcdrKernelModeServices.dll
[2005/01/19 16:45:40 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\ProgressTrace.dll
[2004/08/22 16:04:56 | 000,069,120 | ---- | C] () -- C:\WINDOWS\daemon.dll
[2004/07/26 08:51:38 | 000,000,560 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2004/03/30 01:15:02 | 000,051,200 | ---- | C] () -- C:\WINDOWS\System32\ThriXXX010205PNG.dll
[2004/03/30 01:15:01 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\ThriXXX015003JP2.dll
[2004/03/30 01:15:01 | 000,023,040 | ---- | C] () -- C:\WINDOWS\System32\ThriXXX010104Z.dll
[2004/02/26 00:18:04 | 000,565,248 | ---- | C] () -- C:\WINDOWS\System32\hpotscl.dll
[2003/05/23 04:08:52 | 000,107,008 | ---- | C] () -- C:\WINDOWS\System32\vorbis.dll
[2003/05/23 04:08:52 | 000,020,992 | ---- | C] () -- C:\WINDOWS\System32\ogg.dll
[2003/04/10 16:04:00 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\JAWTAccessBridge.dll
[2002/12/05 16:51:00 | 000,059,392 | R--- | C] () -- C:\WINDOWS\streamhlp.dll

========== LOP Check ==========

[2009/03/04 11:57:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\acccore
[2010/02/12 12:41:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AIM
[2010/01/14 12:22:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ASign
[2009/11/27 12:25:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9
[2007/08/17 16:54:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EnterNHelp
[2007/09/14 21:50:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Last.fm
[2007/03/29 00:01:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\muvee Technologies
[2007/08/17 16:55:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nikon
[2005/09/15 19:15:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Otto
[2008/09/20 18:49:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TechSmith
[2007/08/17 16:54:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ultima_T15
[2009/03/04 11:57:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/03/20 11:25:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2009/10/16 23:08:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/04/10 14:20:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2005/09/14 23:48:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\.BitTornado
[2007/07/16 23:04:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\acccore
[2005/09/14 23:39:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\Aim
[2007/06/09 13:26:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\Cambridge
[2008/09/25 21:13:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\HorizonWimba
[2005/05/26 05:18:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\InterMute
[2005/10/05 21:04:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\InterVideo
[2005/09/18 11:29:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\Leadertech
[2007/06/09 00:36:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\MSNInstaller
[2007/03/29 00:02:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\muvee Technologies
[2007/08/19 12:34:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\Nikon
[2009/01/17 22:49:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\Research In Motion
[2005/05/26 05:18:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\SampleView
[2006/12/16 02:57:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\System Requirements Lab
[2009/02/25 16:36:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\Template
[2009/03/02 23:53:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Diego.HATTORIHANZO\Application Data\Viewpoint

========== Purity Check ==========


< End of report >
  • 0

#12
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Your logs are clean


Follow these steps to uninstall Combofix and tools used in the removal of malware

Uninstall ComboFix

Remove Combofix now that we're done with it.
  • Please press the Windows Key and R on your keyboard. This will bring up the Run... command.
  • Now type in Combofix /Uninstall in the runbox and click OK. (Notice the space between the "x" and "/")
    Posted Image
  • Please follow the prompts to uninstall Combofix.
  • You will then recieve a message saying Combofix was uninstalled successfully once it's done uninstalling itself.



  • Download OTC to your desktop and run it
  • Click Yes to beginning the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. Choose Yes.



Below I have included a number of recommendations for how to protect your computer against malware infections.
  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.

  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • TFC - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.

  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

  • Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
    secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
    blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from
    Here


    If you choose to use Firefox, I highly recommend these add-ons to keep your PC even more secure.
    • NoScript - for blocking ads and other potential website attacks
    • McAfee SiteAdvisor - this tells you whether the sites you are about to visit are safe or not. A must if you do a lot of Googling

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • FileHippo Update Checker is an extremely helpful program that will tell you which of your programs need to be updated. Its important to keep programs up to date so that malware doesn't exploit any old security flaws.

  • Recovery Console - Recent trends appear to indicate that future infections will include attacks to the boot sector of the computer. The installation of the Recovery Console in the computer will be our only defense against this threat. For more information and steps to install the Recovery Console see This Article. Should you need assistance in installing the Recovery Console, please do not hesitate to ask.

  • Please read my guide on how to prevent malware and about safe computing here
Thank you for your patience, and performing all of the procedures requested.
  • 0

#13
Hiarashi

Hiarashi

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
Thank you for the help! One question: I noticed a few infected files and whatnot on the Kaspersky scan log...were those taken care of already?
  • 0

#14
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
yup
  • 0

#15
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP