Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Multiple Undetected Viruses [Solved]


  • This topic is locked This topic is locked

#1
Michael Smith

Michael Smith

    Member

  • Member
  • PipPip
  • 10 posts
Hi, as of Sunday my system has been comprimised by multiple viruses. None of which have been detected by a full system scan by Trend Micro, but this may be because I've stopped them from starting. Trend Micro also asked if I want to block or allow several programs wanting to create a new startup program, all of which I blocked.

Programs Deleted: asam.exe (from Program Files and 2 subfolders containing asam as well as 2 keys in the registry), MSK.exe (from Program Files) and MSL.exe (from Program Files).

Programs stopped from auto-start: asam.exe, hsfe8owijfisjhgs7ye39gjsoighsd7y3eu, hsfg9w8gujsokgahi8gysgnsdgefshyjy, M5T8QL3YW3, and mcexecwin (Location for all: HKCU\SOFTWARE\Microsoft\Windows\Current Version)

Below are copies of both the Trend Micro System Cleaner log and the HijackThis log.

Is my system now safe, or are there still files that need to be deleted to completely remove this malware?

Any help would be greatly appreciated.

/--------------------------------------------------------------\
| Trend Micro System Cleaner |
| Copyright 2009-2010, Trend Micro, Inc. |
| http://www.trendmicro.com |
\--------------------------------------------------------------/


2010-05-31, 20:05:23, Auto-clean mode specified.
2010-05-31, 20:05:23, Running scanner "C:\Users\Luke\Desktop\System Cleaner\TSC.BIN"...
2010-05-31, 20:05:42, Scanner "C:\Users\Luke\Desktop\System Cleaner\TSC.BIN" has finished running.
2010-05-31, 20:05:42, TSC Log:

˙ţD a m a g e C l e a n u p E n g i n e ( D C E ) 6 . 2 ( B u i l d 1 0 1 6 ) ( R C M : D r i v e r n o t r e a d y ! )


W i n d o w s V i s t a ( B u i l d 6 0 0 1 : S e r v i c e P a c k 1 )




S t a r t t i m e : M o n M a y 3 1 2 0 1 0 2 0 : 0 5 : 2 3





L o a d D a m a g e C l e a n u p T e m p l a t e ( D C T ) " C : \ U s e r s \ L u k e \ D e s k t o p \ S y s t e m C l e a n e r \ T M R D C T . p t n " ( v e r s i o n ) [ f a i l ]


L o a d D a m a g e C l e a n u p T e m p l a t e ( D C T ) " C : \ U s e r s \ L u k e \ D e s k t o p \ S y s t e m C l e a n e r \ t s c . p t n " ( v e r s i o n 1 0 7 8 ) [ s u c c e s s ]





C o m p l e t e t i m e : M o n M a y 3 1 2 0 1 0 2 0 : 0 5 : 4 2


E x e c u t e p a t t e r n c o u n t ( 3 0 6 3 ) , V i r u s f o u n d c o u n t ( 0 ) , V i r u s c l e a n c o u n t ( 0 ) , C l e a n f a i l e d c o u n t ( 0 )





2010-05-31, 20:05:42, Running scanner "C:\Users\Luke\Desktop\System Cleaner\VSCANTM.BIN"...
2010-05-31, 21:28:51, Scanner "C:\Users\Luke\Desktop\System Cleaner\VSCANTM.BIN" has finished running.
2010-05-31, 21:28:51, VSCANTM Log:

2010-05-31, 21:28:51, Files Detected:
Copyright © 1990 - 2006 Trend Micro Inc.
Report Date : 5/31/2010 20:05:43
VSAPI Engine Version : 9.120-1004
VSCANTM Version : 3.00-1018 (Official Build)

VSGetVirusPatternInformation is invoked

Virus Pattern Version : 210 (525838/525838 Patterns) (2010/05/31) (721019)

Command Line: C:\Users\Luke\Desktop\System Cleaner\VSCANTM.BIN /NBPM /S /CLEANALL /LD /LC /LCF /NM /NB /DCEGENCLEAN /HIDEDCECONSOLE /C /ACTIVEACTION=5 /VSBKENC+ /BK /LR C:\*.* /P=C:\Users\Luke\Desktop\System Cleaner\lpt$vpn.210

C:\ProgramData\COMMDLG32.dll [TROJ_TRACUR.AN]
C:\Users\Luke\AppData\Local\Temp\1119256304.exe [TROJ_CLICKER.GAT]
C:\Users\Luke\AppData\Local\Temp\1277493060.exe [TROJ_CLICKER.GAT]
C:\Users\Luke\AppData\Local\Temp\1913815461.exe [TROJ_CLICKER.GAT]
C:\Users\Luke\AppData\Local\Temp\1967029596.exe [TROJ_CLICKER.GAT]
C:\Users\Luke\AppData\Local\Temp\2008651647.exe [TROJ_CLICKER.GAT]
C:\Users\Luke\AppData\Local\Temp\2603048165.exe [TROJ_CLICKER.GAT]
C:\Users\Luke\AppData\Local\Temp\2625881321.exe [TROJ_CLICKER.GAT]
C:\Users\Luke\AppData\Local\Temp\2673242300.exe [TROJ_CLICKER.GAT]
C:\Users\Luke\AppData\Local\Temp\413775600.exe [TROJ_CLICKER.GAT]
C:\Users\Luke\AppData\Local\Temp\avp32.exe [TROJ_CLICKER.GAT]
C:\Users\Luke\AppData\Local\Temp\cmd.exe [TROJ_CLICKER.GAT]
C:\Users\Luke\AppData\Local\Temp\debug.exe [TROJ_CLICKER.GAT]
C:\Users\Luke\AppData\Local\Temp\drweb.exe [TROJ_CLICKER.GAT]
C:\Users\Luke\AppData\Local\Temp\hexdump.exe [TROJ_CLICKER.GAT]
C:\Users\Luke\AppData\Local\Temp\iexplarer.exe [TROJ_CLICKER.GAT]
C:\Users\Luke\AppData\Local\Temp\login.exe [TROJ_CLICKER.GAT]
C:\Users\Luke\AppData\Local\Temp\lugpdba.exe [TROJ_FAKEAV.RIL]
C:\Users\Luke\AppData\Local\Temp\mdm.exe [TROJ_CLICKER.GAT]
C:\Users\Luke\AppData\Local\Temp\nvsvc32.exe [TROJ_CLICKER.GAT]
C:\Users\Luke\AppData\Local\Temp\setup.exe [TROJ_CLICKER.GAT]
C:\Users\Luke\AppData\Local\Temp\smss.exe [TROJ_DWNLDR.DT]
C:\Users\Luke\AppData\Local\Temp\spoolsv.exe [TROJ_CLICKER.GAT]
C:\Users\Luke\AppData\Local\Temp\taskmgr.exe [TROJ_CLICKER.GAT]
C:\Users\Luke\AppData\Local\Temp\user.exe [TROJ_CLICKER.GAT]
C:\Users\Luke\AppData\Local\Temp\win.exe [TROJ_CLICKER.GAT]
C:\Users\Luke\AppData\Local\Temp\win32.exe [TROJ_CLICKER.GAT]
C:\Users\Luke\AppData\Local\Temp\winamp.exe [TROJ_CLICKER.GAT]
C:\Users\Luke\AppData\Local\Temp\x60zj.dll [TROJ_FAKEAV.BLR]
190780 files have been read.
190780 files have been checked.
190725 files have been scanned.
390451 files have been scanned. (including files in archived)
29 files containing viruses.
Found 29 viruses totally.
Maybe 0 viruses totally.
Stop At: 5/31/2010 21:28:51 1 hour 23 minutes 7 seconds (4987.02 seconds) has elapsed.(26.140 msec/file)
---------*---------*---------*---------*---------*---------*---------*---------*
2010-05-31, 21:28:51, Files Clean:
Copyright © 1990 - 2006 Trend Micro Inc.
Report Date : 5/31/2010 20:05:43
VSAPI Engine Version : 9.120-1004
VSCANTM Version : 3.00-1018 (Official Build)

VSGetVirusPatternInformation is invoked

Virus Pattern Version : 210 (525838/525838 Patterns) (2010/05/31) (721019)

Command Line: C:\Users\Luke\Desktop\System Cleaner\VSCANTM.BIN /NBPM /S /CLEANALL /LD /LC /LCF /NM /NB /DCEGENCLEAN /HIDEDCECONSOLE /C /ACTIVEACTION=5 /VSBKENC+ /BK /LR C:\*.* /P=C:\Users\Luke\Desktop\System Cleaner\lpt$vpn.210

190780 files have been read.
190780 files have been checked.
190725 files have been scanned.
390451 files have been scanned. (including files in archived)
29 files containing viruses.
Found 29 viruses totally.
Maybe 0 viruses totally.
Stop At: 5/31/2010 21:28:51 1 hour 23 minutes 7 seconds (4987.02 seconds) has elapsed.(26.140 msec/file)
---------*---------*---------*---------*---------*---------*---------*---------*
2010-05-31, 21:28:51, Clean Fail:
Copyright © 1990 - 2006 Trend Micro Inc.
Report Date : 5/31/2010 20:05:43
VSAPI Engine Version : 9.120-1004
VSCANTM Version : 3.00-1018 (Official Build)

VSGetVirusPatternInformation is invoked

Virus Pattern Version : 210 (525838/525838 Patterns) (2010/05/31) (721019)

Command Line: C:\Users\Luke\Desktop\System Cleaner\VSCANTM.BIN /NBPM /S /CLEANALL /LD /LC /LCF /NM /NB /DCEGENCLEAN /HIDEDCECONSOLE /C /ACTIVEACTION=5 /VSBKENC+ /BK /LR C:\*.* /P=C:\Users\Luke\Desktop\System Cleaner\lpt$vpn.210

190780 files have been read.
190780 files have been checked.
190725 files have been scanned.
390451 files have been scanned. (including files in archived)
29 files containing viruses.
Found 29 viruses totally.
Maybe 0 viruses totally.
Stop At: 5/31/2010 21:28:51 1 hour 23 minutes 7 seconds (4987.02 seconds) has elapsed.(26.140 msec/file)
---------*---------*---------*---------*---------*---------*---------*---------*
2010-05-31, 21:28:51, Running scanner "C:\Users\Luke\Desktop\System Cleaner\VSCANTM.BIN"...
2010-05-31, 21:28:59, Scanner "C:\Users\Luke\Desktop\System Cleaner\VSCANTM.BIN" has finished running.
2010-05-31, 21:28:59, VSCANTM Log:

2010-05-31, 21:28:59, Files Detected:
Copyright © 1990 - 2006 Trend Micro Inc.
Report Date : 5/31/2010 21:28:51
VSAPI Engine Version : 9.120-1004
VSCANTM Version : 3.00-1018 (Official Build)

VSGetVirusPatternInformation is invoked

Virus Pattern Version : 210 (525838/525838 Patterns) (2010/05/31) (721019)

Command Line: C:\Users\Luke\Desktop\System Cleaner\VSCANTM.BIN /NBPM /S /CLEANALL /LD /LC /LCF /NM /NB /DCEGENCLEAN /HIDEDCECONSOLE /C /ACTIVEACTION=5 /VSBKENC+ /BK /LR D:\*.* /P=C:\Users\Luke\Desktop\System Cleaner\lpt$vpn.210

286 files have been read.
286 files have been checked.
286 files have been scanned.
286 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At: 5/31/2010 21:28:59 5 seconds (5.05 seconds) has elapsed.(17.671 msec/file)
---------*---------*---------*---------*---------*---------*---------*---------*
2010-05-31, 21:28:59, Files Clean:
Copyright © 1990 - 2006 Trend Micro Inc.
Report Date : 5/31/2010 21:28:51
VSAPI Engine Version : 9.120-1004
VSCANTM Version : 3.00-1018 (Official Build)

VSGetVirusPatternInformation is invoked

Virus Pattern Version : 210 (525838/525838 Patterns) (2010/05/31) (721019)

Command Line: C:\Users\Luke\Desktop\System Cleaner\VSCANTM.BIN /NBPM /S /CLEANALL /LD /LC /LCF /NM /NB /DCEGENCLEAN /HIDEDCECONSOLE /C /ACTIVEACTION=5 /VSBKENC+ /BK /LR D:\*.* /P=C:\Users\Luke\Desktop\System Cleaner\lpt$vpn.210

286 files have been read.
286 files have been checked.
286 files have been scanned.
286 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At: 5/31/2010 21:28:59 5 seconds (5.05 seconds) has elapsed.(17.671 msec/file)
---------*---------*---------*---------*---------*---------*---------*---------*
2010-05-31, 21:28:59, Clean Fail:
Copyright © 1990 - 2006 Trend Micro Inc.
Report Date : 5/31/2010 21:28:51
VSAPI Engine Version : 9.120-1004
VSCANTM Version : 3.00-1018 (Official Build)

VSGetVirusPatternInformation is invoked

Virus Pattern Version : 210 (525838/525838 Patterns) (2010/05/31) (721019)

Command Line: C:\Users\Luke\Desktop\System Cleaner\VSCANTM.BIN /NBPM /S /CLEANALL /LD /LC /LCF /NM /NB /DCEGENCLEAN /HIDEDCECONSOLE /C /ACTIVEACTION=5 /VSBKENC+ /BK /LR D:\*.* /P=C:\Users\Luke\Desktop\System Cleaner\lpt$vpn.210

286 files have been read.
286 files have been checked.
286 files have been scanned.
286 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At: 5/31/2010 21:28:59 5 seconds (5.05 seconds) has elapsed.(17.671 msec/file)
---------*---------*---------*---------*---------*---------*---------*---------*
2010-05-31, 21:28:59, Running SSAPI scanner ""...
2010-05-31, 22:15:18, SSAPI Log:

SSAPI Scanner Version: 1.0.1003
SSAPI Engine Version: 5.2.1032
SSAPI Pattern Version: 8.71
SSAPI Anti-Rootkit Version: <Failed>

Spyware Scan Started: 05/31/2010 21:29:02


SSAPI requires the system to reboot.
Detected Items:
[CLEAN SUCCESS][Cookie_YieldManager] Internet Explorer Cache\ad.yieldmanager.com,Cookie:[email protected]/,C:\Users\Luke\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
[CLEAN SUCCESS][Cookie_CoreMetrics] Internet Explorer Cache\data.coremetrics.com,Cookie:[email protected]/,C:\Users\Luke\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
[CLEAN SUCCESS][Cookie_DoubleClick] Internet Explorer Cache\doubleclick.net,Cookie:[email protected]/,C:\Users\Luke\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
Detected: 3 items.
Cleaned Success: 3 items.
Clean Failed: 0 items.

Spyware Scan Ended: 05/31/2010 22:15:18
Scan Complete. Time=2779.028809.

__________________________________________________________________

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 1:56:40 PM, on 6/1/2010
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18904)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxpers.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\PlatformDependent\ProToolbarComm.exe
C:\Program Files\Trend Micro\TrendSecure\TSCFPlatformCOMSvr.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Luke\Desktop\Hijack\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...a...n&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Trend Micro Toolbar BHO - {43C6D902-A1C5-45c9-91F6-FD9E90337E18} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O2 - BHO: HP Print Clips - {FFFFFFFF-FF12-44C5-91EC-068E3AA1B2D7} - c:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Trend Micro Toolbar - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Vongo Tray.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll/cmsidewiki.html
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: HP Smart Select - {58ECB495-38F0-49cb-A538-10282ABF65E7} - c:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O18 - Protocol: tmtb - {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: PCPitstop Scheduling - PC Pitstop LLC - C:\Program Files\PCPitstop\PCPitstopScheduleService.exe
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: Vongo Service - Starz Entertainment Group LLC - C:\Program Files\Vongo\VongoService.exe

--
End of file - 10675 bytes
  • 0

Advertisements


#2
hammerman

hammerman

    Member 4k

  • Member
  • PipPipPipPipPipPipPip
  • 4,183 posts
Hello Michael Smith and welcome to GeeksToGo :)
I'm hammerman and I'm going to help you fix your problem.

Before we begin, here are some guidelines which will help us both in fixing your problem.
  • Malware removal is not instantaneous and will take a number of steps to complete. Please continue to carry out the steps requested until I let you know that your computer appears clean.
  • Please do no attach logs or post them in Quote/Code boxes unless requested.
  • I suggest you print or save any instructions I give you for easy reference. We may be using Safe mode and you will not always be able to access this thread. You can copy and paste these instructions into Notepad and then save the text file to your Desktop. If you need any help with this or further clarification, please let me know.
  • When posting logs, please ensure Word Wrap is turned off in Notepad. Open Notepad, select Format on the menu bar and make sure that Word Wrap is unchecked.
  • Please follow the steps exactly in the same order posted. If you can't perform a certain step, or you're unsure on what to do, please stop and let me know.
  • If in doubt about anything, please ask.
Please follow these steps.

-- Step 1 --
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Under the Custom Scan box paste this in

    netsvcs
    %SYSTEMDRIVE%\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\drivers\*.sys /90

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won't take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.
-- Step 2 --

Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.
  • Double click GMER.exe.
    Posted Image
  • If it gives you a warning about rootkit activity and asks if you want to run a full scan...click on NO, then use the following settings for a more complete scan..
  • In the right panel, you will see several boxes that have been checked. Ensure the following are UNCHECKED ...
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
      Posted Image
      Click the image to enlarge it
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "ark.txt"
  • Save the log where you can easily find it, such as your desktop.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries

Please copy and paste the report into your Post.
  • 0

#3
Michael Smith

Michael Smith

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
Okay so step 1 is complete, but I can't complete step 2. It gets to \Device\Harddisk\VolumeShadowCopy1 and then the program stops responding. The system also seems very sluggish since downloading that and I've had 2 BSOD's.

Here are the logs for step 1:

OTL logfile created on: 6/1/2010 3:23:45 PM - Run 1
OTL by OldTimer - Version 3.2.5.2 Folder = C:\Users\Luke\Desktop\Fixes\OTL
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18904)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 45.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 63.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 221.03 Gb Total Space | 128.11 Gb Free Space | 57.96% Space Free | Partition Type: NTFS
Drive D: | 11.85 Gb Total Space | 1.93 Gb Free Space | 16.29% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: LUKES-COMPUTER
Current User Name: Luke
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\Luke\Desktop\Fixes\OTL\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\Internet Security\TmPfw.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\BM\TMBMSRV.exe (Trend Micro Inc.)
PRC - C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe (Google Inc.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\ProToolbarUpdate.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\platformdependent\ProToolbarComm.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\TrendSecure\TSCFPlatformCOMSvr.exe (Trend Micro Inc.)
PRC - C:\Program Files\PCPitstop\PCPitstopScheduleService.exe (PC Pitstop LLC)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\WINDOWS\System32\Macromed\Flash\FlashUtil10b.exe (Adobe Systems, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe (Broadcom Corporation.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)


========== Modules (SafeList) ==========

MOD - C:\Users\Luke\Desktop\Fixes\OTL\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\System32\msscript.ocx (Microsoft Corporation)
MOD - C:\WINDOWS\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (TmProxy) -- C:\Program Files\Trend Micro\Internet Security\TmProxy.exe (Trend Micro Inc.)
SRV - (TmPfw) -- C:\Program Files\Trend Micro\Internet Security\TmPfw.exe (Trend Micro Inc.)
SRV - (TMBMServer) -- C:\Program Files\Trend Micro\BM\TMBMSRV.exe (Trend Micro Inc.)
SRV - (Steam Client Service) -- C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (Apple Mobile Device) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (SfCtlCom) -- C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe (Trend Micro Inc.)
SRV - (PCPitstop Scheduling) -- C:\Program Files\PCPitstop\PCPitstopScheduleService.exe (PC Pitstop LLC)
SRV - (IAANTMON) Intel® -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (WLSetupSvc) -- C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
SRV - (usnjsvc) -- C:\Program Files\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (Vongo Service) -- C:\Program Files\Vongo\VongoService.exe (Starz Entertainment Group LLC)
SRV - (Com4Qlb) -- C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe (Hewlett-Packard Development Company, L.P.)


========== Driver Services (SafeList) ==========

DRV - (tmwfp) -- C:\WINDOWS\System32\drivers\tmwfp.sys (Trend Micro Inc.)
DRV - (tmcomm) -- C:\WINDOWS\System32\drivers\tmcomm.sys (Trend Micro Inc.)
DRV - (tmlwf) -- C:\WINDOWS\System32\drivers\tmlwf.sys (Trend Micro Inc.)
DRV - (tmtdi) -- C:\WINDOWS\System32\drivers\tmtdi.sys (Trend Micro Inc.)
DRV - (tmactmon) -- C:\WINDOWS\System32\drivers\tmactmon.sys (Trend Micro Inc.)
DRV - (tmevtmgr) -- C:\WINDOWS\System32\drivers\tmevtmgr.sys (Trend Micro Inc.)
DRV - (tmxpflt) -- C:\WINDOWS\System32\drivers\tmxpflt.sys (Trend Micro Inc.)
DRV - (tmpreflt) -- C:\WINDOWS\System32\drivers\tmpreflt.sys (Trend Micro Inc.)
DRV - (vsapint) -- C:\WINDOWS\System32\drivers\vsapint.sys (Trend Micro Inc.)
DRV - (NuidFltr) -- C:\WINDOWS\System32\drivers\nuidfltr.sys (Microsoft Corporation)
DRV - (igfx) -- C:\WINDOWS\System32\drivers\igdkmd32.sys (Intel Corporation)
DRV - (ialm) -- C:\WINDOWS\System32\drivers\igdkmd32.sys (Intel Corporation)
DRV - (NETw5v32) Intel® -- C:\WINDOWS\System32\drivers\NETw5v32.sys (Intel Corporation)
DRV - (iaStor) -- C:\Windows\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (btwavdt) -- C:\WINDOWS\System32\drivers\btwavdt.sys (Broadcom Corporation.)
DRV - (btwaudio) -- C:\WINDOWS\System32\drivers\btwaudio.sys (Broadcom Corporation.)
DRV - (btwrchid) -- C:\WINDOWS\System32\drivers\btwrchid.sys (Broadcom Corporation.)
DRV - (RTL8169) -- C:\WINDOWS\System32\drivers\Rtlh86.sys (Realtek Corporation )
DRV - (SynTP) -- C:\WINDOWS\System32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (HpqRemHid) -- C:\WINDOWS\System32\drivers\HpqRemHid.sys (Hewlett-Packard Development Company, L.P.)
DRV - (NETw4v32) Intel® -- C:\WINDOWS\System32\drivers\NETw4v32.sys (Intel Corporation)
DRV - (HpqKbFiltr) -- C:\WINDOWS\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (rismxdp) -- C:\WINDOWS\System32\drivers\rixdptsk.sys (REDC)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\WINDOWS\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (rimmptsk) -- C:\WINDOWS\System32\drivers\rimmptsk.sys (REDC)
DRV - (rimsptsk) -- C:\WINDOWS\System32\drivers\rimsptsk.sys (REDC)
DRV - (smserial) -- C:\WINDOWS\System32\drivers\smserial.sys (Motorola Inc.)
DRV - (ql2300) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) -- C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (nvstor) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (aic78xx) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) -- C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) -- C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (viaide) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (HSF_DPV) -- C:\WINDOWS\System32\drivers\VSTDPV3.SYS (Conexant Systems, Inc.)
DRV - (HSFHWAZL) -- C:\WINDOWS\System32\drivers\VSTAZL3.SYS (Conexant Systems, Inc.)
DRV - (winachsf) -- C:\WINDOWS\System32\drivers\VSTCNXT3.SYS (Conexant Systems, Inc.)
DRV - (ntrigdigi) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (E1G60) Intel® -- C:\WINDOWS\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (BCM43XV) -- C:\WINDOWS\System32\drivers\BCMWL6.SYS (Broadcom Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...a...n&pf=laptop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-29969543-1051296006-1331863856-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
IE - HKU\S-1-5-21-29969543-1051296006-1331863856-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-29969543-1051296006-1331863856-1000\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKU\S-1-5-21-29969543-1051296006-1331863856-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-29969543-1051296006-1331863856-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>

FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 [2009/01/08 17:14:58 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{22181a4d-af90-4ca3-a569-faed9118d6bc}: C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\FirefoxExtension [2010/05/31 01:46:21 | 000,000,000 | ---D | M]

[2010/05/05 18:40:41 | 000,000,000 | ---D | M] -- C:\Users\Luke\AppData\Roaming\Mozilla\Extensions
[2010/05/05 18:40:41 | 000,000,000 | ---D | M] -- C:\Users\Luke\AppData\Roaming\Mozilla\Extensions\[email protected]

O1 HOSTS File: ([2006/09/18 17:41:30 | 000,000,761 | ---- | M]) - C:\WINDOWS\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (TSToolbarBHO) - {43C6D902-A1C5-45c9-91F6-FD9E90337E18} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll (Trend Micro Inc.)
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll (Google Inc.)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O2 - BHO: (HP Print Clips) - {FFFFFFFF-FF12-44C5-91EC-068E3AA1B2D7} - c:\Program Files\HP\Smart Web Printing\hpswp_framework.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Trend Micro Toolbar) - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll (Trend Micro Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKU\S-1-5-21-29969543-1051296006-1331863856-1000\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe (ScanSoft, Inc.)
O4 - HKLM..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [UfSeAgnt.exe] C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe (Trend Micro Inc.)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-29969543-1051296006-1331863856-1000..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-21-29969543-1051296006-1331863856-1000\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-21-29969543-1051296006-1331863856-1000\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-21-29969543-1051296006-1331863856-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKU\S-1-5-21-29969543-1051296006-1331863856-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll (Google Inc.)
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: HP Smart Select - {58ECB495-38F0-49cb-A538-10282ABF65E7} - c:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKU\.DEFAULT\..Trusted Ranges: Range1 ([http] in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Ranges: Range1 ([http] in Local intranet)
O15 - HKU\S-1-5-21-29969543-1051296006-1331863856-1000\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...r/ultrashim.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\tmtb {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll (Trend Micro Inc.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: Reg Error: Invalid data type.
O24 - Desktop BackupWallPaper: Reg Error: Invalid data type.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/04/02 01:57:16 | 000,000,074 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2005/09/11 11:18:54 | 000,000,340 | -HS- | M] () - D:\AUTOMODE -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKU\S-1-5-21-29969543-1051296006-1331863856-1000\...exe [@ = exefile] -- Reg Error: Key error. File not found

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\WINDOWS\System32\ias [2009/01/04 16:41:13 | 000,000,000 | ---D | M]
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2010/06/01 15:19:26 | 000,000,000 | ---D | C] -- C:\Users\Luke\Desktop\Fixes
[2010/06/01 13:26:50 | 000,000,000 | ---D | C] -- C:\Users\Luke\Desktop\Hijack
[2010/05/31 23:14:27 | 000,000,000 | ---D | C] -- C:\Windows\pss
[2010/05/31 19:51:14 | 000,000,000 | ---D | C] -- C:\Users\Luke\Desktop\System Cleaner
[2010/05/31 01:53:32 | 000,230,928 | ---- | C] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmxpflt.sys
[2010/05/31 01:46:00 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Trend Micro
[2010/05/31 01:23:43 | 000,000,000 | ---D | C] -- C:\Users\Luke\AppData\Local\Trend Micro
[2010/05/31 01:17:19 | 001,322,680 | ---- | C] (Trend Micro Inc.) -- C:\Windows\System32\drivers\vsapint.sys
[2010/05/31 01:17:18 | 000,283,152 | ---- | C] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmwfp.sys
[2010/05/31 01:17:18 | 000,158,224 | ---- | C] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmcomm.sys
[2010/05/31 01:17:18 | 000,146,448 | ---- | C] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmlwf.sys
[2010/05/31 01:17:18 | 000,089,872 | ---- | C] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmtdi.sys
[2010/05/31 01:17:18 | 000,059,920 | ---- | C] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmactmon.sys
[2010/05/31 01:17:18 | 000,050,704 | ---- | C] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmevtmgr.sys
[2010/05/31 01:17:18 | 000,036,368 | ---- | C] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmpreflt.sys
[2010/05/31 01:11:01 | 000,000,000 | ---D | C] -- C:\Users\Luke\Desktop\TIS
[2010/05/31 00:15:13 | 000,000,000 | ---D | C] -- C:\ProgramData\SITEguard
[2010/05/31 00:12:25 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\iS3
[2010/05/31 00:12:23 | 000,000,000 | ---D | C] -- C:\ProgramData\STOPzilla!
[2010/05/31 00:10:18 | 000,390,656 | ---- | C] (iS3, Inc.) -- C:\Users\Luke\Desktop\STOPzilla_Setup.exe
[2010/05/30 01:14:35 | 000,000,000 | ---D | C] -- C:\Users\Luke\AppData\Roaming\SystemProc
[2010/05/30 01:14:22 | 000,000,000 | ---D | C] -- C:\Users\Luke\AppData\Local\Windows Server
[2010/05/30 01:14:19 | 000,067,584 | ---- | C] (Microsoft Corporation) -- C:\Users\Luke\AppData\Roaming\ecd5be71.exe
[2010/05/30 01:14:15 | 000,000,000 | ---D | C] -- C:\Users\Luke\AppData\Roaming\EA56BAB4929BDBC2F4DB0E2C19EAF6B0
[2010/05/27 17:09:25 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2010/05/12 18:58:14 | 000,024,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\nshhttp.dll
[2010/05/12 18:58:09 | 000,031,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\httpapi.dll
[2010/05/05 18:40:41 | 000,000,000 | ---D | C] -- C:\Users\Luke\AppData\Roaming\Mozilla
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/06/01 15:33:12 | 003,407,872 | -HS- | M] () -- C:\Users\Luke\NTUSER.DAT
[2010/06/01 15:30:27 | 000,823,808 | ---- | M] () -- C:\Windows\System32\drivers\vwskvrg.sys
[2010/06/01 15:16:38 | 000,003,296 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/06/01 15:16:38 | 000,003,296 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/06/01 15:07:01 | 000,000,282 | -H-- | M] () -- C:\Windows\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
[2010/06/01 14:41:01 | 000,000,282 | -H-- | M] () -- C:\Windows\tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job
[2010/06/01 14:38:02 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/06/01 01:59:54 | 000,000,416 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{FC6A490E-08C5-4CBE-8E48-6122E6C1A673}.job
[2010/05/31 23:17:08 | 000,000,164 | ---- | M] () -- C:\Users\Public\Documents\hpqp.ini
[2010/05/31 23:16:32 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/05/31 23:16:04 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010/05/31 23:16:01 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/05/31 23:15:58 | 2137,448,448 | -HS- | M] () -- C:\hiberfil.sys
[2010/05/31 23:14:57 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2010/05/31 23:14:55 | 000,524,288 | -HS- | M] () -- C:\Users\Luke\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2010/05/31 23:14:55 | 000,065,536 | -HS- | M] () -- C:\Users\Luke\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2010/05/31 23:06:00 | 002,199,709 | -H-- | M] () -- C:\Users\Luke\AppData\Local\IconCache.db
[2010/05/31 16:25:09 | 000,000,896 | ---- | M] () -- C:\Windows\System32\drivers\kgpcpy.cfg
[2010/05/31 15:24:53 | 000,000,440 | ---- | M] () -- C:\Windows\System32\drivers\kgpfr2.cfg
[2010/05/31 15:19:59 | 441,804,621 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2010/05/31 04:36:56 | 000,690,960 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2010/05/31 04:36:56 | 000,595,684 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010/05/31 04:36:56 | 000,101,350 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010/05/31 01:27:21 | 000,001,843 | ---- | M] () -- C:\Users\Public\Desktop\Trend Micro Internet Security Pro.lnk
[2010/05/31 01:17:18 | 000,283,152 | ---- | M] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmwfp.sys
[2010/05/31 01:17:18 | 000,158,224 | ---- | M] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmcomm.sys
[2010/05/31 01:17:18 | 000,146,448 | ---- | M] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmlwf.sys
[2010/05/31 01:17:18 | 000,089,872 | ---- | M] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmtdi.sys
[2010/05/31 01:17:18 | 000,059,920 | ---- | M] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmactmon.sys
[2010/05/31 01:17:18 | 000,050,704 | ---- | M] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmevtmgr.sys
[2010/05/31 01:07:53 | 000,077,528 | ---- | M] () -- C:\Users\Luke\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/05/31 01:04:05 | 000,316,936 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010/05/31 00:15:03 | 001,863,680 | -H-- | M] () -- C:\SZKGFS.dat
[2010/05/30 23:07:38 | 000,390,656 | ---- | M] (iS3, Inc.) -- C:\Users\Luke\Desktop\STOPzilla_Setup.exe
[2010/05/30 01:15:59 | 000,003,321 | -HS- | M] () -- C:\Users\Luke\AppData\Roaming\0200000052ff8f9b922P.manifest
[2010/05/30 01:14:33 | 000,000,011 | -HS- | M] () -- C:\Users\Luke\AppData\Roaming\0200000052ff8f9b922O.manifest
[2010/05/30 01:14:32 | 000,000,013 | -HS- | M] () -- C:\Users\Luke\AppData\Roaming\0200000052ff8f9b922C.manifest
[2010/05/30 01:14:32 | 000,000,011 | -HS- | M] () -- C:\Users\Luke\AppData\Roaming\0200000052ff8f9b922S.manifest
[2010/05/30 01:14:19 | 000,000,238 | -H-- | M] () -- C:\Windows\tasks\MSWD-ecd5be71.job
[2010/05/30 01:14:18 | 000,067,584 | ---- | M] (Microsoft Corporation) -- C:\Users\Luke\AppData\Roaming\ecd5be71.exe
[2010/05/20 23:36:00 | 000,024,064 | ---- | M] () -- C:\Users\Luke\Documents\BOOK COVER.doc
[2010/05/20 23:18:08 | 000,025,600 | ---- | M] () -- C:\Users\Luke\Documents\BOOK REVIEW.doc
[2010/05/12 19:02:59 | 000,000,240 | ---- | M] () -- C:\Windows\win.ini
[2010/05/12 18:32:10 | 000,019,039 | ---- | M] () -- C:\Users\Luke\Documents\DK Gearcheck.xlsx
[2010/05/06 17:49:12 | 000,000,318 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForLuke.job
[2010/05/05 19:06:17 | 000,025,088 | ---- | M] () -- C:\Users\Luke\Documents\THE HOBBIT theme.doc
[2010/05/05 18:38:32 | 000,001,700 | ---- | M] () -- C:\Users\Luke\Desktop\LimeWire 5.5.8.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/05/31 22:41:29 | 2137,448,448 | -HS- | C] () -- C:\hiberfil.sys
[2010/05/31 15:24:42 | 000,000,440 | ---- | C] () -- C:\Windows\System32\drivers\kgpfr2.cfg
[2010/05/31 15:20:46 | 000,000,896 | ---- | C] () -- C:\Windows\System32\drivers\kgpcpy.cfg
[2010/05/31 01:27:21 | 000,001,843 | ---- | C] () -- C:\Users\Public\Desktop\Trend Micro Internet Security Pro.lnk
[2010/05/31 01:02:37 | 441,804,621 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2010/05/31 00:15:03 | 001,863,680 | -H-- | C] () -- C:\SZKGFS.dat
[2010/05/30 01:15:50 | 000,823,808 | ---- | C] () -- C:\Windows\System32\drivers\vwskvrg.sys
[2010/05/30 01:14:32 | 000,003,321 | -HS- | C] () -- C:\Users\Luke\AppData\Roaming\0200000052ff8f9b922P.manifest
[2010/05/30 01:14:32 | 000,000,013 | -HS- | C] () -- C:\Users\Luke\AppData\Roaming\0200000052ff8f9b922C.manifest
[2010/05/30 01:14:32 | 000,000,011 | -HS- | C] () -- C:\Users\Luke\AppData\Roaming\0200000052ff8f9b922S.manifest
[2010/05/30 01:14:32 | 000,000,011 | -HS- | C] () -- C:\Users\Luke\AppData\Roaming\0200000052ff8f9b922O.manifest
[2010/05/30 01:14:21 | 000,000,282 | -H-- | C] () -- C:\Windows\tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job
[2010/05/30 01:14:21 | 000,000,282 | -H-- | C] () -- C:\Windows\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
[2010/05/30 01:14:19 | 000,000,238 | -H-- | C] () -- C:\Windows\tasks\MSWD-ecd5be71.job
[2010/05/20 23:36:00 | 000,024,064 | ---- | C] () -- C:\Users\Luke\Documents\BOOK COVER.doc
[2010/05/20 23:18:08 | 000,025,600 | ---- | C] () -- C:\Users\Luke\Documents\BOOK REVIEW.doc
[2010/05/05 19:06:17 | 000,025,088 | ---- | C] () -- C:\Users\Luke\Documents\THE HOBBIT theme.doc
[2010/05/05 18:38:32 | 000,001,700 | ---- | C] () -- C:\Users\Luke\Desktop\LimeWire 5.5.8.lnk
[2009/05/03 20:29:35 | 000,000,262 | ---- | C] () -- C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2009/04/19 20:16:37 | 000,140,288 | ---- | C] () -- C:\Windows\System32\igfxtvcx.dll
[2009/04/17 16:12:31 | 000,000,376 | ---- | C] () -- C:\Windows\ODBC.INI
[2009/02/04 22:42:40 | 000,027,019 | ---- | C] () -- C:\Windows\maxlink.ini
[2008/04/02 03:01:35 | 000,016,480 | ---- | C] () -- C:\Windows\System32\rixdicon.dll
[2008/02/10 21:55:18 | 000,147,456 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1437.dll
[2007/09/13 11:31:06 | 000,147,456 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1329.dll
[2007/09/13 11:22:46 | 001,238,832 | ---- | C] () -- C:\Windows\System32\igmedkrn.dll
[2007/09/13 11:22:46 | 000,104,636 | ---- | C] () -- C:\Windows\System32\igmedcompkrn.dll
[2007/09/05 15:52:04 | 000,389,120 | ---- | C] () -- C:\Windows\System32\btwhidcs.dll
[2006/11/02 08:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 03:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/03/09 18:58:00 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2003/01/07 15:05:08 | 000,002,695 | ---- | C] () -- C:\Windows\System32\OUTLPERF.INI
[2002/03/04 11:16:34 | 000,110,592 | R--- | C] () -- C:\Windows\System32\Jpeg32.dll
[2001/11/14 16:56:00 | 001,802,240 | ---- | C] () -- C:\Windows\System32\lcppn21.dll

========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2008/04/02 01:57:16 | 000,000,074 | ---- | M] () -- C:\autoexec.bat
[2008/01/19 03:45:45 | 000,333,203 | RHS- | M] () -- C:\bootmgr
[2006/09/18 17:43:37 | 000,000,010 | ---- | M] () -- C:\config.sys
[2010/05/31 23:15:58 | 2137,448,448 | -HS- | M] () -- C:\hiberfil.sys
[2008/04/02 01:33:50 | 000,000,367 | -H-- | M] () -- C:\IPH.PH
[2010/05/31 23:15:57 | 2451,238,912 | -HS- | M] () -- C:\pagefile.sys
[2008/12/26 21:02:06 | 000,000,471 | ---- | M] () -- C:\RHDSetup.log
[2010/05/31 00:15:03 | 001,863,680 | -H-- | M] () -- C:\SZKGFS.dat
[2008/12/26 20:51:02 | 000,000,594 | ---- | M] () -- C:\updatedatfix.log

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2009/03/08 07:31:42 | 000,348,160 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\System32\dxtmsft.dll
[2009/03/08 07:31:37 | 000,216,064 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\System32\dxtrans.dll
[2008/01/19 03:38:03 | 000,242,744 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\System32\rsaenh.dll
[2008/01/19 03:36:10 | 000,225,792 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\System32\SLC.dll

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2006/11/02 06:34:05 | 000,008,192 | ---- | M] () -- C:\WINDOWS\System32\config\COMPONENTS.SAV
[2006/11/02 06:34:05 | 000,020,480 | ---- | M] () -- C:\WINDOWS\System32\config\DEFAULT.SAV
[2006/11/02 06:34:05 | 000,008,192 | ---- | M] () -- C:\WINDOWS\System32\config\SECURITY.SAV
[2006/11/02 06:34:08 | 010,133,504 | ---- | M] () -- C:\WINDOWS\System32\config\SOFTWARE.SAV
[2006/11/02 06:34:08 | 001,826,816 | ---- | M] () -- C:\WINDOWS\System32\config\SYSTEM.SAV

< %systemroot%\system32\drivers\*.sys /90 >
[2010/05/31 01:17:18 | 000,059,920 | ---- | M] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmactmon.sys
[2010/05/31 01:17:18 | 000,158,224 | ---- | M] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmcomm.sys
[2010/05/31 01:17:18 | 000,050,704 | ---- | M] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmevtmgr.sys
[2010/05/31 01:17:18 | 000,146,448 | ---- | M] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmlwf.sys
[2010/05/31 01:17:18 | 000,089,872 | ---- | M] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmtdi.sys
[2010/05/31 01:17:18 | 000,283,152 | ---- | M] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmwfp.sys
[2010/06/01 15:38:58 | 000,823,808 | ---- | M] () -- C:\Windows\System32\drivers\vwskvrg.sys
< End of report >
__________________________________________________________

OTL Extras logfile created on: 6/1/2010 3:23:45 PM - Run 1
OTL by OldTimer - Version 3.2.5.2 Folder = C:\Users\Luke\Desktop\Fixes\OTL
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18904)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 45.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 63.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 221.03 Gb Total Space | 128.11 Gb Free Space | 57.96% Space Free | Partition Type: NTFS
Drive D: | 11.85 Gb Total Space | 1.93 Gb Free Space | 16.29% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: LUKES-COMPUTER
Current User Name: Luke
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-29969543-1051296006-1331863856-1000\SOFTWARE\Classes\<extension>]
.exe [@ = exefile] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
"" =

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"" =
"C:\Program Files\Vongo\VongoService.exe" = C:\Program Files\Vongo\VongoService.exe:*:enabled:VongoService -- (Starz Entertainment Group LLC)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink -- (EarthLink, Inc.)


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{11B1FFC5-D556-4AF8-9A21-CABEF78F24D7}" = lport=2869 | protocol=6 | dir=in | app=system |
"{5F15C5C5-BC3F-401D-A8D3-E3E97A120C66}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{015DA3AD-DA9C-4585-98B9-DEED9BFBA254}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{09635D90-2B93-4E72-8214-7650ED883DB2}" = dir=in | app=c:\program files\hp\quickplay\qp.exe |
"{0B10241F-7724-4F56-990E-3C05FB5ECD75}" = protocol=6 | dir=in | app=c:\program files\curse\curseclient.exe |
"{111C79F1-0755-4734-8DE6-1721338E1AE4}" = protocol=17 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{145DBFF5-CD12-4F10-8F4D-F3DD3ADB1814}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{2CF08DA8-5BDD-45F8-8E19-D3168B6E2CCD}" = protocol=17 | dir=in | app=c:\program files\curse\curseclient.exe |
"{3FE3FBFF-B367-4D23-A7BA-4DB0CDB8F507}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead\left4dead.exe |
"{44265255-DEEF-4D27-9CD2-CD39C08B7BFA}" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |
"{44D3B33F-A4C2-4C22-AB1A-563D0781A70F}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{45763025-86E7-4D35-AB49-BF658EF9BE7A}" = dir=in | app=c:\program files\hp\quickplay\qpservice.exe |
"{4C5F0924-4CEE-4349-96A1-5A955A194B8A}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{58920BD8-7613-4D23-9C8E-34D49E8CB83F}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{5B081B0D-7C09-4EAB-9CCE-8713FBD5E9BA}" = protocol=17 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{65E48975-FCF6-44CB-AD18-B0ED974D3B90}" = protocol=6 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{9D9E3FB4-AD87-46B1-8049-687AD4C29C41}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{A84BE376-D29A-4419-87D8-6CFD5380C55C}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{B8563BB9-3224-432C-85BE-8200C71E6FE6}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{BD7A00E8-6BC9-490D-ACF5-740C5FB5FB63}" = protocol=6 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{BE95CDCE-DE92-4F30-8CB2-542078B959D1}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{CA38306F-C2CD-422E-8F53-BEAEA3EF4F49}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead\left4dead.exe |
"{CB815D18-E2B9-4456-BADC-6B92B4CEB969}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{CDB65592-AF2A-42A1-A30C-11F90B78F0F9}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{DF83971C-5442-453C-888E-C6E3C9D30531}" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |
"{E9337355-DEF1-4C66-AB45-53477B8ACCBC}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe |
"{F175F9D1-35CF-46E8-A14E-98E14FE9C34A}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"TCP Query User{712437C5-C872-413B-92C6-315E3643C58D}C:\program files\itunes\itunes.exe" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"TCP Query User{7B911F1A-5784-45B2-AAD2-41DC09E62147}C:\program files\limewire\limewire.exe" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |
"UDP Query User{6FC75242-D6E8-47DC-8651-C1EAFDBE9D6B}C:\program files\itunes\itunes.exe" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"UDP Query User{7D78FEA0-5DD2-441B-9ADF-74885AED8878}C:\program files\limewire\limewire.exe" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{03D1988F-469F-4843-8E6E-E5FE9D17889D}" = HP Integrated Module with Bluetooth wireless technology 6.0.1.5500
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{06E74B9B-631F-4378-BF3A-40D868450C05}" = HPPhotoSmartPhotobookHolidayPack1
"{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer
"{082F8ABA-84D5-4837-9DFC-F365D91A07D4}" = HP Smart Web Printing
"{12A76360-388E-4B27-ABEB-D5FC5378DD2A}" = HPPhotoSmartPhotobookWebPack1
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{172AEB5E-CBB2-4CDD-A4CF-388600825839}" = HPPhotoSmartPhotobookPlayfulPack1
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1BDC9633-895B-4842-BCB6-8FA1EC2A3C5A}" = Adobe Shockwave Player
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = DVD Suite
"{209CDA54-D390-46A2-A97C-7BF61734418D}" = WeatherBug Gadget
"{2284D904-C138-4B58-93EC-5C362AB5130A}" = The Sims™ Life Stories
"{228C6B46-64E2-404E-898A-EF0830603EF4}" = HPNetworkAssistant
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{250E9609-E830-43EB-B379-DAB7546A2422}" = muvee autoProducer 6.1
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 13
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{31216452-5540-4C96-B754-94890A63D5AB}" = HP Help and Support
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{34BFB099-07B2-4E95-A673-7362D60866A2}" = PSSWCORE
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.30 E1
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP QuickPlay 3.6
"{4CACFCD9-F71B-413A-8DF5-1A6419D5CDC6}" = Cards_Calendar_OrderGift_DoMorePlugout
"{4D49757C-367A-4333-BDB3-68966162B14E}" = HP User Guides 0087
"{508CE775-4BA4-4748-82DF-FE28DA9F03B0}" = Windows Live Messenger
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support
"{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{68471BF2-F1F7-4C89-BBBA-400B94996596}" = ESU for Microsoft Vista
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{718D791F-F4E8-4aa7-98A6-15FDED17BDD0}" = Trend Micro Internet Security Pro
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{76BC2442-0002-47FA-9617-43BAD82BEF4C}" = Bonjour
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{7DC4A410-9986-4329-9E5D-687B2C42CA39}" = HP QuickTouch 1.00 C4
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista
"{89E052B2-5CA5-4B7A-AF0C-28CA2836B030}" = HPPhotoSmartPhotobookModernPack1
"{8C3AE2D1-854D-4650-A73D-C7CC7EE36B80}" = Vongo
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{9885A11E-60E4-417C-B58B-8B31B21C0B8A}" = HP Easy Setup - Frontend
"{996A2FAA-7514-4628-9D12-A8FC34A0016E}" = iTunes
"{9D2B0322-44AE-460E-9283-4D2D7A9205AE}" = Trend Micro Internet Security Pro
"{A07840FC-CE63-4CB8-8030-EF4B9805925A}" = HPPhotoSmartDiscLabel_PaperLabel
"{A17EABB6-D0C6-44E5-820C-72DC7F495064}" = PaperPort
"{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}" = Windows Live installer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.4
"{AC95121F-1576-45B8-82F7-3911D27882E6}" = HPPhotoSmartPhotobookScrapbookPack1
"{ADFB9653-F44C-460C-BF58-189CC552DFFE}" = hpphotosmartdisclabelplugin
"{AF36CE1D-FD2C-4BA0-93FA-1196785DD610}" = Adobe Flash Player 10 Plugin
"{b02df929-29a7-4fd2-9a70-81a644b635f7}" = HP Total Care Advisor
"{B4E91E95-A5BA-4E50-A465-DB7EFEB176E8}" = HPPhotoSmartDiscLabel_PrintOnDisc
"{B5C3B892-0849-476C-9F46-B12F84819D57}" = Apple Mobile Device Support
"{BAD0FA60-09CF-4411-AE6A-C2844C8812FA}" = HP Photosmart Essential 2.5
"{BD0E2B92-3814-46F0-893B-4612EA010C7E}" = HP Customer Experience Enhancements
"{BE9880CD-73A9-4EFD-83E5-4BB38D48E2BD}" = HP Smart Web Printing
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CBAE4F50-9FC9-4557-AB36-9826DF3C103C}" = HP Wireless Assistant
"{CC4A73BF-938E-4C19-A553-853C035C9BA1}" = LightScribe System Software 1.10.13.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE7E3BE0-2DD3-4416-A690-F9E4A99A8CFF}" = HP Active Support Library
"{DD3C88A0-C53C-41D0-A21B-6D021981D23E}" = HPPhotoSmartDiscLabelContent1
"{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}" = VideoToolkit01
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F5577101-33CC-4711-8235-3A95BCD49DB0}" = EA Link
"{F636EE9A-F9EC-4606-BCFA-77DD0E210788}" = HPPhotoSmartDiscLabel_Tattoo
"{F7F3B252-E772-48AA-93EB-7964BC326067}" = MSCU for Microsoft Vista
"{FE57DE70-95DE-4B64-9266-84DA811053DB}" = HP Update
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11
"AIM_6" = AIM 6
"Hauppauge MCE2005 Software Encoder" = Hauppauge MCE XP/Vista Software Encoder (2.0.25149)
"HDMI" = Intel® Graphics Media Accelerator Driver
"HP Photosmart Essential" = HP Photosmart Essential 2.5
"HP Smart Web Printing" = HP Smart Web Printing
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallShield_{F5577101-33CC-4711-8235-3A95BCD49DB0}" = EA Link
"LimeWire" = LimeWire 5.5.8
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"PC Pitstop Optimize3_is1" = PC Pitstop Optimize3 3.0
"SlingMedia.QPSlingPlayer_is1" = QuickPlay SlingPlayer 0.4.4
"SMSERIAL" = Motorola SM56 Data Fax Modem
"Steam App 500" = Left 4 Dead
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"SystemRequirementsLab" = System Requirements Lab
"TVWiz" = Intel® TV Wizard
"ViewpointMediaPlayer" = Viewpoint Media Player
"Warcraft III" = Warcraft III
"WildTangent hp Master Uninstall" = My HP Games
"Word Roots A1" = Word Roots A1
"World of Warcraft" = World of Warcraft
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Toolbar" = Yahoo! Toolbar

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-29969543-1051296006-1331863856-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"090215de958f1060" = Curse Client
"Warcraft III" = Warcraft III: All Products

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 5/31/2010 1:52:24 PM | Computer Name = Lukes-computer | Source = VSS | ID = 8194
Description =

Error - 5/31/2010 4:10:46 PM | Computer Name = Lukes-computer | Source = VSS | ID = 8194
Description =

Error - 5/31/2010 4:30:12 PM | Computer Name = Lukes-computer | Source = VSS | ID = 8194
Description =

Error - 5/31/2010 7:14:49 PM | Computer Name = Lukes-computer | Source = VSS | ID = 8194
Description =

Error - 5/31/2010 7:15:23 PM | Computer Name = Lukes-computer | Source = VSS | ID = 12301
Description =

Error - 5/31/2010 7:15:23 PM | Computer Name = Lukes-computer | Source = System Restore | ID = 8193
Description =

Error - 5/31/2010 7:57:59 PM | Computer Name = LUKES-COMPUTER | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 5/31/2010 7:57:59 PM | Computer Name = LUKES-COMPUTER | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 17441

Error - 5/31/2010 7:57:59 PM | Computer Name = LUKES-COMPUTER | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 17441

Error - 5/31/2010 8:02:40 PM | Computer Name = Lukes-computer | Source = EventSystem | ID = 4609
Description =

[ System Events ]
Error - 7/14/2009 9:08:22 PM | Computer Name = Lukes-computer | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.6 for the Network Card with network
address 001DE02B33F5 has been denied by the DHCP server 0.0.0.0 (The DHCP Server
sent a DHCPNACK message).

Error - 7/16/2009 3:13:35 AM | Computer Name = Lukes-computer | Source = HTTP | ID = 15016
Description =

Error - 7/16/2009 3:14:41 AM | Computer Name = Lukes-computer | Source = Service Control Manager | ID = 7000
Description =

Error - 7/16/2009 3:15:26 AM | Computer Name = Lukes-computer | Source = Service Control Manager | ID = 7022
Description =

Error - 7/16/2009 3:15:26 AM | Computer Name = Lukes-computer | Source = Service Control Manager | ID = 7001
Description =

Error - 7/16/2009 12:08:01 PM | Computer Name = Lukes-computer | Source = Service Control Manager | ID = 7009
Description =

Error - 7/16/2009 12:08:01 PM | Computer Name = Lukes-computer | Source = Service Control Manager | ID = 7000
Description =

Error - 7/16/2009 6:37:56 PM | Computer Name = Lukes-computer | Source = Tcpip | ID = 4199
Description = The system detected an address conflict for IP address 192.168.1.7
with the system having network hardware address 00-19-7E-81-1C-19. Network operations
on this system may be disrupted as a result.

Error - 7/20/2009 7:01:51 PM | Computer Name = Lukes-computer | Source = Tcpip | ID = 4199
Description = The system detected an address conflict for IP address 192.168.1.3
with the system having network hardware address 00-0E-A6-42-B9-E8. Network operations
on this system may be disrupted as a result.

Error - 7/24/2009 1:39:05 PM | Computer Name = Lukes-computer | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.5 for the Network Card with network
address 001DE02B33F5 has been denied by the DHCP server 0.0.0.0 (The DHCP Server
sent a DHCPNACK message).


< End of report >
  • 0

#4
hammerman

hammerman

    Member 4k

  • Member
  • PipPipPipPipPipPipPip
  • 4,183 posts
Hi,

Please run GMER in Safe mode.

To enter Safe Mode, restart your computer and continually tapping the F8 key until a menu appears.
Use your up arrow key to highlight SafeMode then hit enter.
  • 0

#5
Michael Smith

Michael Smith

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
Just tried running it in safe mode and the same thing happened. The scan started, I was prompted and then hit no, unchecked what I was supposed to, and hit scan. The scan started and once it reached \Device\HarddiskVolumeShadowCopy1 it stopped responding as was forced to close.
  • 0

#6
hammerman

hammerman

    Member 4k

  • Member
  • PipPipPipPipPipPipPip
  • 4,183 posts
Hi,

Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


Posted Image



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Posted Image


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt log in your next reply.
  • 0

#7
Michael Smith

Michael Smith

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
ComboFix 10-06-01.05 - Luke 06/02/2010 13:10:35.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.2038.1053 [GMT -4:00]
Running from: c:\users\Luke\Desktop\Fixes\ComboFix\ComboFix.exe
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\users\Luke\AppData\Local\Windows Server
c:\users\Luke\AppData\Local\Windows Server\flags.ini
c:\users\Luke\AppData\Local\Windows Server\uses32.dat
c:\users\Luke\AppData\Roaming\0200000052ff8f9b922C.manifest
c:\users\Luke\AppData\Roaming\0200000052ff8f9b922O.manifest
c:\users\Luke\AppData\Roaming\0200000052ff8f9b922P.manifest
c:\users\Luke\AppData\Roaming\0200000052ff8f9b922S.manifest
c:\users\Luke\AppData\Roaming\Microsoft\Windows\Templates\memory.tmp
c:\users\Luke\AppData\Roaming\SystemProc
c:\windows\system32\drivers\vwskvrg.sys
c:\windows\system32\KBL.LOG
c:\windows\system32\Vb40032.dll
c:\windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_vwskvrg
-------\Service_vwskvrg


((((((((((((((((((((((((( Files Created from 2010-05-02 to 2010-06-02 )))))))))))))))))))))))))))))))
.

2010-06-01 20:12 . 2010-06-01 20:12 -------- d-----w- c:\programdata\WindowsSearch
2010-05-31 05:53 . 2009-12-04 16:39 230928 ----a-w- c:\windows\system32\drivers\tmxpflt.sys
2010-05-31 05:23 . 2010-05-31 05:50 -------- d-----w- c:\users\Luke\AppData\Local\Trend Micro
2010-05-31 05:17 . 2009-12-04 16:05 1322680 ----a-w- c:\windows\system32\drivers\vsapint.sys
2010-05-31 05:17 . 2010-05-31 05:17 89872 ----a-w- c:\windows\system32\drivers\tmtdi.sys
2010-05-31 05:17 . 2010-05-31 05:17 59920 ----a-w- c:\windows\system32\drivers\tmactmon.sys
2010-05-31 05:17 . 2010-05-31 05:17 50704 ----a-w- c:\windows\system32\drivers\tmevtmgr.sys
2010-05-31 05:17 . 2010-05-31 05:17 283152 ----a-w- c:\windows\system32\drivers\tmwfp.sys
2010-05-31 05:17 . 2010-05-31 05:17 158224 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2010-05-31 05:17 . 2010-05-31 05:17 146448 ----a-w- c:\windows\system32\drivers\tmlwf.sys
2010-05-31 05:17 . 2009-12-04 16:38 36368 ----a-w- c:\windows\system32\drivers\tmpreflt.sys
2010-05-31 04:15 . 2010-05-31 04:15 -------- d-----w- c:\programdata\SITEguard
2010-05-31 04:15 . 2010-05-31 04:15 1863680 ---ha-w- C:\SZKGFS.dat
2010-05-31 04:12 . 2010-05-31 04:12 -------- d-----w- c:\program files\Common Files\iS3
2010-05-31 04:12 . 2010-05-31 23:50 -------- d-----w- c:\programdata\STOPzilla!
2010-05-30 05:14 . 2010-05-31 10:11 -------- d-----w- c:\users\Luke\AppData\Roaming\EA56BAB4929BDBC2F4DB0E2C19EAF6B0
2010-05-27 21:09 . 2010-04-23 13:55 2048 ----a-w- c:\windows\system32\tzres.dll
2010-05-12 22:58 . 2010-02-20 23:39 24064 ----a-w- c:\windows\system32\nshhttp.dll
2010-05-12 22:58 . 2010-02-20 23:37 31232 ----a-w- c:\windows\system32\httpapi.dll
2010-05-12 22:58 . 2010-02-20 21:18 411136 ----a-w- c:\windows\system32\drivers\http.sys
2010-05-12 22:34 . 2010-01-29 16:21 738304 ----a-w- c:\windows\system32\inetcomm.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-02 17:24 . 2009-11-29 18:37 -------- d-----w- c:\programdata\PCPitstop
2010-06-02 17:23 . 2008-04-02 04:17 12 ----a-w- c:\windows\bthservsdp.dat
2010-05-31 20:25 . 2010-05-31 19:20 896 ----a-w- c:\windows\system32\drivers\kgpcpy.cfg
2010-05-31 19:24 . 2010-05-31 19:24 440 ----a-w- c:\windows\system32\drivers\kgpfr2.cfg
2010-05-31 06:55 . 2009-06-11 21:57 -------- d-----w- c:\program files\Gamevance
2010-05-31 05:50 . 2009-02-24 00:32 -------- d-----w- c:\programdata\Trend Micro
2010-05-31 05:43 . 2009-03-14 21:18 -------- d-----w- c:\program files\Trend Micro
2010-05-31 05:07 . 2008-12-25 14:36 77528 ----a-w- c:\users\Luke\AppData\Local\GDIPFONTCACHEV1.DAT
2010-05-31 04:35 . 2009-02-01 01:36 -------- d-----w- c:\program files\Steam
2010-05-31 04:16 . 2010-05-31 04:19 1129120 ----a-w- c:\programdata\STOPzilla!\vdb\vbcorent.dll
2010-05-31 02:26 . 2009-02-01 01:37 -------- d-----w- c:\program files\Common Files\Steam
2010-05-30 05:14 . 2010-05-30 05:14 67584 ----a-w- c:\users\Luke\AppData\Roaming\ecd5be71.exe
2010-05-30 05:14 . 2010-05-30 05:14 67584 ----a-w- c:\users\Luke\AppData\Roaming\ecd5be71.exe
2010-05-24 23:59 . 2010-05-24 23:59 501872 ----a-w- c:\programdata\Google\Google Toolbar\Update\gtbFDA0.tmp.exe
2010-05-20 04:13 . 2009-01-11 23:55 -------- d-----w- c:\users\Luke\AppData\Roaming\LimeWire
2010-05-13 19:41 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-05-05 22:38 . 2009-01-11 23:55 -------- d-----w- c:\program files\LimeWire
2010-04-13 00:50 . 2010-04-13 00:49 -------- d-----w- c:\programdata\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-04-13 00:50 . 2010-04-13 00:49 -------- d-----w- c:\program files\iTunes
2010-04-13 00:49 . 2010-04-13 00:49 -------- d-----w- c:\program files\iPod
2010-04-13 00:49 . 2010-03-30 14:38 -------- d-----w- c:\program files\Common Files\Apple
2010-04-13 00:44 . 2010-04-13 00:43 -------- d-----w- c:\program files\QuickTime
2010-04-13 00:36 . 2010-04-13 00:36 -------- d-----w- c:\program files\Bonjour
2010-04-13 00:34 . 2010-04-13 00:34 73000 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.1.0.79\SetupAdmin.exe
2010-04-10 17:25 . 2009-01-10 20:30 -------- d-----w- c:\program files\World of Warcraft
2010-03-05 14:01 . 2010-04-14 22:24 420352 ----a-w- c:\windows\system32\vbscript.dll
.
<pre>
c:\program files\Critical Thinking Software\Word Roots A1\UninstallerData\Word Roots A1 Uninstall .exe
</pre>

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-02-20 39408]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 102400]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-04-15 178712]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-10-01 181544]
"OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-09-04 554320]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-06-02 80896]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-09-13 480560]
"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-08 311296]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2004-04-14 40960]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-02-26 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-02-26 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-02-26 150552]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-09 75008]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-03-26 142120]
"UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [1601-01-01 0]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-9-5 727592]
Vongo Tray.lnk - c:\windows\Installer\{8C3AE2D1-854D-4650-A73D-C7CC7EE36B80}\NewShortcut2_DB7E00C96DEF489A8112D8F81614F45A.exe [2008-4-2 53248]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^Users^Luke^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^CurseClientStartup.ccip]
path=c:\users\Luke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip
backup=c:\windows\pss\CurseClientStartup.ccip.Startup
backupExtension=.Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\asam]
c:\users\Luke\AppData\Local\asam.exe [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hsfe8owijfisjhgs7ye39gjsoighsd7y3eu]
c:\users\Luke\AppData\Local\Temp\lugpdba.exe [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hsfg9w8gujsokgahi8gysgnsdgefshyjy]
c:\users\Luke\AppData\Local\Temp\hexdump.exe [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\M5T8QL3YW3]
c:\users\Luke\AppData\Local\Temp\Msl.exe [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mcexecwin]
c:\users\Luke\AppData\Local\Temp\x60zj.dll [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 135664]
S1 tmlwf;Trend Micro NDIS 6.0 Filter Driver;c:\windows\system32\DRIVERS\tmlwf.sys [2010-05-31 146448]
S2 PCPitstop Scheduling;PCPitstop Scheduling;c:\program files\PCPitstop\PCPitstopScheduleService.exe [2009-04-26 90352]
S2 tmpreflt;tmpreflt;c:\windows\system32\DRIVERS\tmpreflt.sys [2009-12-04 36368]
S2 tmwfp;Trend Micro WFP Callout Driver;c:\windows\system32\DRIVERS\tmwfp.sys [2010-05-31 283152]
S3 NETw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\NETw5v32.sys [2008-11-17 3668480]
S3 tmevtmgr;tmevtmgr;c:\windows\system32\DRIVERS\tmevtmgr.sys [1601-01-01 0]
S3 TmPfw;Trend Micro Personal Firewall;c:\program files\Trend Micro\Internet Security\TmPfw.exe [1601-01-01 0]
S3 TmProxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [1601-01-01 0]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-08-23 22:34 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder

2010-06-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 23:23]

2010-06-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 23:23]

2010-05-06 c:\windows\Tasks\HPCeeScheduleForLuke.job
- c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2008-04-02 18:58]

2010-05-30 c:\windows\Tasks\MSWD-ecd5be71.job
- c:\users\Luke\AppData\Roaming\ecd5be71.exe [2010-05-30 05:14]

2010-06-02 c:\windows\Tasks\User_Feed_Synchronization-{FC6A490E-08C5-4CBE-8E48-6122E6C1A673}.job
- c:\windows\system32\msfeedssync.exe [2010-03-31 04:54]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.comcast.net/
mStart Page = about:blank
uInternet Settings,ProxyOverride = <local>
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll/cmsidewiki.html
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-02 13:27
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'Explorer.exe'(3976)
c:\program files\Hewlett-Packard\HP Advisor\Pillars\Market\MLDeskBand.dll
c:\windows\system32\btncopy.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Trend Micro\Internet Security\SfCtlCom.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Trend Micro\TrendSecure\TISProToolbar\ProToolbarUpdate.exe
c:\program files\Hewlett-Packard\HP Health Check\hphc_service.exe
c:\program files\Trend Micro\BM\TMBMSRV.exe
c:\program files\Windows Media Player\wmpnscfg.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Completion time: 2010-06-02 13:45:17 - machine was rebooted
ComboFix-quarantined-files.txt 2010-06-02 17:42

Pre-Run: 139,364,737,024 bytes free
Post-Run: 139,286,990,848 bytes free

- - End Of File - - C14F3EB92E29790661BB46887430B660
  • 0

#8
hammerman

hammerman

    Member 4k

  • Member
  • PipPipPipPipPipPipPip
  • 4,183 posts
Hi,

Please follow these steps.

-- Step 1 --

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

File::
c:\users\Luke\AppData\Local\asam.exe
c:\users\Luke\AppData\Local\Temp\lugpdba.exe
c:\users\Luke\AppData\Local\Temp\hexdump.exe
c:\users\Luke\AppData\Local\Temp\Msl.exe
c:\users\Luke\AppData\Local\Temp\x60zj.dll
c:\users\Luke\AppData\Roaming\ecd5be71.exe
c:\windows\Tasks\MSWD-ecd5be71.job

Folder::

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\asam]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hsfe8owijfisjhgs7ye39gjsoighsd7y3eu]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hsfg9w8gujsokgahi8gysgnsdgefshyjy]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\M5T8QL3YW3]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mcexecwin]

Driver::

RenV::
c:\program files\Critical Thinking Software\Word Roots A1\UninstallerData\Word Roots A1 Uninstall .exe


Save this as CFScript.txt, in the same location as ComboFix.exe


Posted Image

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

-- Step 2 --

Posted Image Please download Malwarebytes' Anti-Malware from Here.

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.

-- Step 3 --

Run OTL and select Minimal Output. Use the Quick Scan button to start a scan.
Please post the OTL report in your reply.
  • 0

#9
Michael Smith

Michael Smith

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
ComboFix 10-06-02.01 - Luke 06/02/2010 16:39:07.3.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.2038.1136 [GMT -4:00]
Running from: c:\users\Luke\Desktop\Fixes\ComboFix\ComboFix.exe
Command switches used :: c:\users\Luke\Desktop\Fixes\ComboFix\CFScript.txt
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

FILE ::
"c:\users\Luke\AppData\Local\asam.exe"
"c:\users\Luke\AppData\Local\Temp\hexdump.exe"
"c:\users\Luke\AppData\Local\Temp\lugpdba.exe"
"c:\users\Luke\AppData\Local\Temp\Msl.exe"
"c:\users\Luke\AppData\Local\Temp\x60zj.dll"
"c:\users\Luke\AppData\Roaming\ecd5be71.exe"
"c:\windows\Tasks\MSWD-ecd5be71.job"
.

((((((((((((((((((((((((( Files Created from 2010-05-02 to 2010-06-02 )))))))))))))))))))))))))))))))
.

2010-06-02 20:49 . 2010-06-02 20:49 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-06-02 20:49 . 2010-06-02 20:49 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-06-02 17:45 . 2010-06-02 20:49 -------- d-----w- c:\users\Luke\AppData\Local\temp
2010-06-01 20:12 . 2010-06-01 20:12 -------- d-----w- c:\programdata\WindowsSearch
2010-05-31 05:53 . 2009-12-04 16:39 230928 ----a-w- c:\windows\system32\drivers\tmxpflt.sys
2010-05-31 05:23 . 2010-05-31 05:50 -------- d-----w- c:\users\Luke\AppData\Local\Trend Micro
2010-05-31 05:17 . 2009-12-04 16:05 1322680 ----a-w- c:\windows\system32\drivers\vsapint.sys
2010-05-31 05:17 . 2010-05-31 05:17 89872 ----a-w- c:\windows\system32\drivers\tmtdi.sys
2010-05-31 05:17 . 2010-05-31 05:17 59920 ----a-w- c:\windows\system32\drivers\tmactmon.sys
2010-05-31 05:17 . 2010-05-31 05:17 50704 ----a-w- c:\windows\system32\drivers\tmevtmgr.sys
2010-05-31 05:17 . 2010-05-31 05:17 283152 ----a-w- c:\windows\system32\drivers\tmwfp.sys
2010-05-31 05:17 . 2010-05-31 05:17 158224 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2010-05-31 05:17 . 2010-05-31 05:17 146448 ----a-w- c:\windows\system32\drivers\tmlwf.sys
2010-05-31 05:17 . 2009-12-04 16:38 36368 ----a-w- c:\windows\system32\drivers\tmpreflt.sys
2010-05-31 04:19 . 2010-05-31 04:16 1129120 ----a-w- c:\programdata\STOPzilla!\vdb\vbcorent.dll
2010-05-31 04:15 . 2010-05-31 04:15 -------- d-----w- c:\programdata\SITEguard
2010-05-31 04:15 . 2010-05-31 04:15 1863680 ---ha-w- C:\SZKGFS.dat
2010-05-31 04:12 . 2010-05-31 04:12 -------- d-----w- c:\program files\Common Files\iS3
2010-05-31 04:12 . 2010-05-31 23:50 -------- d-----w- c:\programdata\STOPzilla!
2010-05-30 05:14 . 2010-05-31 10:11 -------- d-----w- c:\users\Luke\AppData\Roaming\EA56BAB4929BDBC2F4DB0E2C19EAF6B0
2010-05-27 21:09 . 2010-04-23 13:55 2048 ----a-w- c:\windows\system32\tzres.dll
2010-05-24 23:59 . 2010-05-24 23:59 501872 ----a-w- c:\programdata\Google\Google Toolbar\Update\gtbFDA0.tmp.exe
2010-05-12 22:58 . 2010-02-20 23:39 24064 ----a-w- c:\windows\system32\nshhttp.dll
2010-05-12 22:58 . 2010-02-20 23:37 31232 ----a-w- c:\windows\system32\httpapi.dll
2010-05-12 22:58 . 2010-02-20 21:18 411136 ----a-w- c:\windows\system32\drivers\http.sys
2010-05-12 22:34 . 2010-01-29 16:21 738304 ----a-w- c:\windows\system32\inetcomm.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-02 20:11 . 2008-04-02 04:17 12 ----a-w- c:\windows\bthservsdp.dat
2010-06-02 17:24 . 2009-11-29 18:37 -------- d-----w- c:\programdata\PCPitstop
2010-05-31 20:25 . 2010-05-31 19:20 896 ----a-w- c:\windows\system32\drivers\kgpcpy.cfg
2010-05-31 19:24 . 2010-05-31 19:24 440 ----a-w- c:\windows\system32\drivers\kgpfr2.cfg
2010-05-31 06:55 . 2009-06-11 21:57 -------- d-----w- c:\program files\Gamevance
2010-05-31 05:50 . 2009-02-24 00:32 -------- d-----w- c:\programdata\Trend Micro
2010-05-31 05:43 . 2009-03-14 21:18 -------- d-----w- c:\program files\Trend Micro
2010-05-31 05:07 . 2008-12-25 14:36 77528 ----a-w- c:\users\Luke\AppData\Local\GDIPFONTCACHEV1.DAT
2010-05-31 04:35 . 2009-02-01 01:36 -------- d-----w- c:\program files\Steam
2010-05-31 02:26 . 2009-02-01 01:37 -------- d-----w- c:\program files\Common Files\Steam
2010-05-20 04:13 . 2009-01-11 23:55 -------- d-----w- c:\users\Luke\AppData\Roaming\LimeWire
2010-05-13 19:41 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-05-05 22:38 . 2009-01-11 23:55 -------- d-----w- c:\program files\LimeWire
2010-04-13 00:50 . 2010-04-13 00:49 -------- d-----w- c:\programdata\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-04-13 00:50 . 2010-04-13 00:49 -------- d-----w- c:\program files\iTunes
2010-04-13 00:49 . 2010-04-13 00:49 -------- d-----w- c:\program files\iPod
2010-04-13 00:49 . 2010-03-30 14:38 -------- d-----w- c:\program files\Common Files\Apple
2010-04-13 00:44 . 2010-04-13 00:43 -------- d-----w- c:\program files\QuickTime
2010-04-13 00:36 . 2010-04-13 00:36 -------- d-----w- c:\program files\Bonjour
2010-04-13 00:34 . 2010-04-13 00:34 73000 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.1.0.79\SetupAdmin.exe
2010-04-10 17:25 . 2009-01-10 20:30 -------- d-----w- c:\program files\World of Warcraft
2010-03-05 14:01 . 2010-04-14 22:24 420352 ----a-w- c:\windows\system32\vbscript.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-02-20 39408]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 102400]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-04-15 178712]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-10-01 181544]
"OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-09-04 554320]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-06-02 80896]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-09-13 480560]
"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-08 311296]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2004-04-14 40960]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-02-26 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-02-26 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-02-26 150552]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-09 75008]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-03-26 142120]
"UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2010-01-26 1020248]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-9-5 727592]
Vongo Tray.lnk - c:\windows\Installer\{8C3AE2D1-854D-4650-A73D-C7CC7EE36B80}\NewShortcut2_DB7E00C96DEF489A8112D8F81614F45A.exe [2008-4-2 53248]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^Users^Luke^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^CurseClientStartup.ccip]
path=c:\users\Luke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip
backup=c:\windows\pss\CurseClientStartup.ccip.Startup
backupExtension=.Startup

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 135664]
R3 tmevtmgr;tmevtmgr;c:\windows\system32\DRIVERS\tmevtmgr.sys [2010-05-31 50704]
R3 TmPfw;Trend Micro Personal Firewall;c:\program files\Trend Micro\Internet Security\TmPfw.exe [2010-05-31 497008]
R3 TmProxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [2010-05-31 689416]
S1 tmlwf;Trend Micro NDIS 6.0 Filter Driver;c:\windows\system32\DRIVERS\tmlwf.sys [2010-05-31 146448]
S2 PCPitstop Scheduling;PCPitstop Scheduling;c:\program files\PCPitstop\PCPitstopScheduleService.exe [2009-04-26 90352]
S2 tmpreflt;tmpreflt;c:\windows\system32\DRIVERS\tmpreflt.sys [2009-12-04 36368]
S2 tmwfp;Trend Micro WFP Callout Driver;c:\windows\system32\DRIVERS\tmwfp.sys [2010-05-31 283152]
S3 NETw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\NETw5v32.sys [2008-11-17 3668480]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-08-23 22:34 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder

2010-06-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 23:23]

2010-06-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 23:23]

2010-05-06 c:\windows\Tasks\HPCeeScheduleForLuke.job
- c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2008-04-02 18:58]

2010-06-02 c:\windows\Tasks\User_Feed_Synchronization-{FC6A490E-08C5-4CBE-8E48-6122E6C1A673}.job
- c:\windows\system32\msfeedssync.exe [2010-03-31 04:54]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.comcast.net/
mStart Page = about:blank
uInternet Settings,ProxyOverride = <local>
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll/cmsidewiki.html
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
.
- - - - ORPHANS REMOVED - - - -

AddRemove-Word Roots A1 - c:\program files\Critical Thinking Software\Word Roots A1\UninstallerData\Word Roots A1 Uninstall .exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-02 16:49
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Completion time: 2010-06-02 16:53:27
ComboFix-quarantined-files.txt 2010-06-02 20:53

Pre-Run: 139,213,242,368 bytes free
Post-Run: 139,178,881,024 bytes free

- - End Of File - - 0291C755E6B4F38042BD8D77A3A3EF26



Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4165

Windows 6.0.6001 Service Pack 1
Internet Explorer 8.0.6001.18904

6/2/2010 5:13:34 PM
mbam-log-2010-06-02 (17-13-34).txt

Scan type: Quick scan
Objects scanned: 122773
Time elapsed: 4 minute(s), 38 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 2
Files Infected: 5

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\ProgramData\148760655 (Rogue.WindowsSmartSecurity) -> Quarantined and deleted successfully.
C:\Program Files\Gamevance (Adware.Gamevance) -> Quarantined and deleted successfully.

Files Infected:
C:\ProgramData\148760655\config.udb (Rogue.WindowsSmartSecurity) -> Quarantined and deleted successfully.
C:\ProgramData\148760655\init.udb (Rogue.WindowsSmartSecurity) -> Quarantined and deleted successfully.
C:\ProgramData\148760655\Langs.udb (Rogue.WindowsSmartSecurity) -> Quarantined and deleted successfully.
C:\Program Files\Gamevance\ars.cfg (Adware.Gamevance) -> Quarantined and deleted successfully.
C:\Program Files\Gamevance\icon.ico (Adware.Gamevance) -> Quarantined and deleted successfully.
_____________________________________

OTL logfile created on: 6/2/2010 6:03:40 PM - Run 2
OTL by OldTimer - Version 3.2.5.2 Folder = C:\Users\Luke\Desktop\Fixes\OTL
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18904)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 51.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 76.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 221.03 Gb Total Space | 128.89 Gb Free Space | 58.31% Space Free | Partition Type: NTFS
Drive D: | 11.85 Gb Total Space | 1.93 Gb Free Space | 16.29% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: LUKES-COMPUTER
Current User Name: Luke
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\Users\Luke\Desktop\Fixes\OTL\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\ProToolbarUpdate.exe (Trend Micro Inc.)
PRC - C:\Program Files\PCPitstop\PCPitstopScheduleService.exe (PC Pitstop LLC)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe (Broadcom Corporation.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)


========== Modules (SafeList) ==========

MOD - C:\Users\Luke\Desktop\Fixes\OTL\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\System32\msscript.ocx (Microsoft Corporation)
MOD - C:\WINDOWS\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (TmProxy) -- C:\Program Files\Trend Micro\Internet Security\TmProxy.exe (Trend Micro Inc.)
SRV - (TmPfw) -- C:\Program Files\Trend Micro\Internet Security\TmPfw.exe (Trend Micro Inc.)
SRV - (TMBMServer) -- C:\Program Files\Trend Micro\BM\TMBMSRV.exe (Trend Micro Inc.)
SRV - (Steam Client Service) -- C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (Apple Mobile Device) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (SfCtlCom) -- C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe (Trend Micro Inc.)
SRV - (PCPitstop Scheduling) -- C:\Program Files\PCPitstop\PCPitstopScheduleService.exe (PC Pitstop LLC)
SRV - (IAANTMON) Intel® -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (WLSetupSvc) -- C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
SRV - (usnjsvc) -- C:\Program Files\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (Vongo Service) -- C:\Program Files\Vongo\VongoService.exe (Starz Entertainment Group LLC)
SRV - (Com4Qlb) -- C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe (Hewlett-Packard Development Company, L.P.)


========== Driver Services (SafeList) ==========

DRV - (tmwfp) -- C:\WINDOWS\System32\drivers\tmwfp.sys (Trend Micro Inc.)
DRV - (tmcomm) -- C:\WINDOWS\System32\drivers\tmcomm.sys (Trend Micro Inc.)
DRV - (tmlwf) -- C:\WINDOWS\System32\drivers\tmlwf.sys (Trend Micro Inc.)
DRV - (tmtdi) -- C:\WINDOWS\System32\drivers\tmtdi.sys (Trend Micro Inc.)
DRV - (tmactmon) -- C:\WINDOWS\System32\drivers\tmactmon.sys (Trend Micro Inc.)
DRV - (tmevtmgr) -- C:\WINDOWS\System32\drivers\tmevtmgr.sys (Trend Micro Inc.)
DRV - (tmxpflt) -- C:\WINDOWS\System32\drivers\tmxpflt.sys (Trend Micro Inc.)
DRV - (tmpreflt) -- C:\WINDOWS\System32\drivers\tmpreflt.sys (Trend Micro Inc.)
DRV - (vsapint) -- C:\WINDOWS\System32\drivers\vsapint.sys (Trend Micro Inc.)
DRV - (NuidFltr) -- C:\WINDOWS\System32\drivers\nuidfltr.sys (Microsoft Corporation)
DRV - (igfx) -- C:\WINDOWS\System32\drivers\igdkmd32.sys (Intel Corporation)
DRV - (ialm) -- C:\WINDOWS\System32\drivers\igdkmd32.sys (Intel Corporation)
DRV - (NETw5v32) Intel® -- C:\WINDOWS\System32\drivers\NETw5v32.sys (Intel Corporation)
DRV - (iaStor) -- C:\Windows\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (btwavdt) -- C:\WINDOWS\System32\drivers\btwavdt.sys (Broadcom Corporation.)
DRV - (btwaudio) -- C:\WINDOWS\System32\drivers\btwaudio.sys (Broadcom Corporation.)
DRV - (btwrchid) -- C:\WINDOWS\System32\drivers\btwrchid.sys (Broadcom Corporation.)
DRV - (RTL8169) -- C:\WINDOWS\System32\drivers\Rtlh86.sys (Realtek Corporation )
DRV - (SynTP) -- C:\WINDOWS\System32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (HpqRemHid) -- C:\WINDOWS\System32\drivers\HpqRemHid.sys (Hewlett-Packard Development Company, L.P.)
DRV - (NETw4v32) Intel® -- C:\WINDOWS\System32\drivers\NETw4v32.sys (Intel Corporation)
DRV - (HpqKbFiltr) -- C:\WINDOWS\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (rismxdp) -- C:\WINDOWS\System32\drivers\rixdptsk.sys (REDC)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\WINDOWS\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (rimmptsk) -- C:\WINDOWS\System32\drivers\rimmptsk.sys (REDC)
DRV - (rimsptsk) -- C:\WINDOWS\System32\drivers\rimsptsk.sys (REDC)
DRV - (smserial) -- C:\WINDOWS\System32\drivers\smserial.sys (Motorola Inc.)
DRV - (ql2300) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) -- C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (nvstor) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (aic78xx) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) -- C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) -- C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (viaide) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (HSF_DPV) -- C:\WINDOWS\System32\drivers\VSTDPV3.SYS (Conexant Systems, Inc.)
DRV - (HSFHWAZL) -- C:\WINDOWS\System32\drivers\VSTAZL3.SYS (Conexant Systems, Inc.)
DRV - (winachsf) -- C:\WINDOWS\System32\drivers\VSTCNXT3.SYS (Conexant Systems, Inc.)
DRV - (ntrigdigi) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (E1G60) Intel® -- C:\WINDOWS\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (BCM43XV) -- C:\WINDOWS\System32\drivers\BCMWL6.SYS (Broadcom Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>

FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 [2009/01/08 17:14:58 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{22181a4d-af90-4ca3-a569-faed9118d6bc}: C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\FirefoxExtension [2010/05/31 01:46:21 | 000,000,000 | ---D | M]

[2010/05/05 18:40:41 | 000,000,000 | ---D | M] -- C:\Users\Luke\AppData\Roaming\Mozilla\Extensions
[2010/05/05 18:40:41 | 000,000,000 | ---D | M] -- C:\Users\Luke\AppData\Roaming\Mozilla\Extensions\[email protected]

O1 HOSTS File: ([2010/06/02 16:27:39 | 000,000,027 | ---- | M]) - C:\WINDOWS\System32\drivers\etc\hosts
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (TSToolbarBHO) - {43C6D902-A1C5-45c9-91F6-FD9E90337E18} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll (Trend Micro Inc.)
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll (Google Inc.)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O2 - BHO: (HP Print Clips) - {FFFFFFFF-FF12-44C5-91EC-068E3AA1B2D7} - c:\Program Files\HP\Smart Web Printing\hpswp_framework.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Trend Micro Toolbar) - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll (Trend Micro Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe (ScanSoft, Inc.)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [UfSeAgnt.exe] C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe (Trend Micro Inc.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll (Google Inc.)
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: HP Smart Select - {58ECB495-38F0-49cb-A538-10282ABF65E7} - c:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...r/ultrashim.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\tmtb {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll (Trend Micro Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Users\Luke\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: Reg Error: Invalid data type.
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/04/02 01:57:16 | 000,000,074 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2005/09/11 11:18:54 | 000,000,340 | -HS- | M] () - D:\AUTOMODE -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKCU\...exe [@ = exefile] -- Reg Error: Key error. File not found

========== Files/Folders - Created Within 90 Days ==========

[2010/06/02 17:06:47 | 000,000,000 | ---D | C] -- C:\Users\Luke\AppData\Roaming\Malwarebytes
[2010/06/02 17:06:40 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/06/02 17:06:39 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010/06/02 17:06:39 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/06/02 17:06:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010/06/02 16:53:45 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2010/06/02 16:53:36 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2010/06/02 16:36:57 | 000,212,480 | ---- | C] (SteelWerX) -- C:\Windows\SWXCACLS.exe
[2010/06/02 13:45:45 | 000,000,000 | ---D | C] -- C:\Users\Luke\AppData\Local\temp
[2010/06/02 13:07:50 | 000,161,792 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2010/06/02 13:07:50 | 000,136,704 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2010/06/02 13:07:50 | 000,031,232 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2010/06/02 13:07:45 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2010/06/02 13:07:10 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010/06/01 16:12:30 | 000,000,000 | ---D | C] -- C:\ProgramData\WindowsSearch
[2010/06/01 15:19:26 | 000,000,000 | ---D | C] -- C:\Users\Luke\Desktop\Fixes
[2010/06/01 13:26:50 | 000,000,000 | ---D | C] -- C:\Users\Luke\Desktop\Hijack
[2010/05/31 23:14:27 | 000,000,000 | ---D | C] -- C:\Windows\pss
[2010/05/31 19:51:14 | 000,000,000 | ---D | C] -- C:\Users\Luke\Desktop\System Cleaner
[2010/05/31 01:53:32 | 000,230,928 | ---- | C] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmxpflt.sys
[2010/05/31 01:46:00 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Trend Micro
[2010/05/31 01:23:43 | 000,000,000 | ---D | C] -- C:\Users\Luke\AppData\Local\Trend Micro
[2010/05/31 01:17:19 | 001,322,680 | ---- | C] (Trend Micro Inc.) -- C:\Windows\System32\drivers\vsapint.sys
[2010/05/31 01:17:18 | 000,283,152 | ---- | C] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmwfp.sys
[2010/05/31 01:17:18 | 000,158,224 | ---- | C] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmcomm.sys
[2010/05/31 01:17:18 | 000,146,448 | ---- | C] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmlwf.sys
[2010/05/31 01:17:18 | 000,089,872 | ---- | C] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmtdi.sys
[2010/05/31 01:17:18 | 000,059,920 | ---- | C] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmactmon.sys
[2010/05/31 01:17:18 | 000,050,704 | ---- | C] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmevtmgr.sys
[2010/05/31 01:17:18 | 000,036,368 | ---- | C] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmpreflt.sys
[2010/05/31 01:11:01 | 000,000,000 | ---D | C] -- C:\Users\Luke\Desktop\TIS
[2010/05/31 00:15:13 | 000,000,000 | ---D | C] -- C:\ProgramData\SITEguard
[2010/05/31 00:12:25 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\iS3
[2010/05/31 00:12:23 | 000,000,000 | ---D | C] -- C:\ProgramData\STOPzilla!
[2010/05/31 00:10:18 | 000,390,656 | ---- | C] (iS3, Inc.) -- C:\Users\Luke\Desktop\STOPzilla_Setup.exe
[2010/05/30 01:14:15 | 000,000,000 | ---D | C] -- C:\Users\Luke\AppData\Roaming\EA56BAB4929BDBC2F4DB0E2C19EAF6B0
[2010/05/05 18:40:41 | 000,000,000 | ---D | C] -- C:\Users\Luke\AppData\Roaming\Mozilla
[2010/04/12 20:49:13 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2010/04/12 20:49:07 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2010/04/12 20:49:07 | 000,000,000 | ---D | C] -- C:\ProgramData\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/04/12 20:43:43 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2010/04/12 20:36:55 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2010/03/30 10:49:34 | 000,000,000 | ---D | C] -- C:\Users\Luke\AppData\Roaming\Apple Computer
[2010/03/30 10:49:34 | 000,000,000 | ---D | C] -- C:\Users\Luke\AppData\Local\Apple Computer
[2010/03/30 10:48:57 | 000,000,000 | ---D | C] -- C:\Windows\System32\DRVSTORE
[2010/03/30 10:47:44 | 000,000,000 | ---D | C] -- C:\ProgramData\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2010/03/30 10:44:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
[2010/03/30 10:42:20 | 000,000,000 | ---D | C] -- C:\Users\Luke\AppData\Local\Apple
[2010/03/30 10:41:59 | 000,000,000 | ---D | C] -- C:\Program Files\Apple Software Update
[2010/03/30 10:38:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple
[2010/03/30 10:38:15 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 90 Days ==========

[2010/06/02 18:05:20 | 003,407,872 | -HS- | M] () -- C:\Users\Luke\NTUSER.DAT
[2010/06/02 17:38:00 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/06/02 17:17:45 | 000,000,164 | ---- | M] () -- C:\Users\Public\Documents\hpqp.ini
[2010/06/02 17:15:38 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/06/02 17:15:10 | 000,003,296 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/06/02 17:15:10 | 000,003,296 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/06/02 17:15:09 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010/06/02 17:15:07 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/06/02 17:15:04 | 2137,448,448 | -HS- | M] () -- C:\hiberfil.sys
[2010/06/02 17:14:10 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2010/06/02 17:14:05 | 000,524,288 | -HS- | M] () -- C:\Users\Luke\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2010/06/02 17:14:05 | 000,065,536 | -HS- | M] () -- C:\Users\Luke\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2010/06/02 17:14:04 | 002,206,603 | -H-- | M] () -- C:\Users\Luke\AppData\Local\IconCache.db
[2010/06/02 16:49:53 | 000,000,215 | ---- | M] () -- C:\Windows\system.ini
[2010/06/02 16:28:37 | 339,871,117 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2010/06/02 16:27:39 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2010/06/02 02:45:43 | 000,000,416 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{FC6A490E-08C5-4CBE-8E48-6122E6C1A673}.job
[2010/05/31 16:25:09 | 000,000,896 | ---- | M] () -- C:\Windows\System32\drivers\kgpcpy.cfg
[2010/05/31 15:24:53 | 000,000,440 | ---- | M] () -- C:\Windows\System32\drivers\kgpfr2.cfg
[2010/05/31 04:36:56 | 000,690,960 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2010/05/31 04:36:56 | 000,595,684 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010/05/31 04:36:56 | 000,101,350 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010/05/31 01:27:21 | 000,001,843 | ---- | M] () -- C:\Users\Public\Desktop\Trend Micro Internet Security Pro.lnk
[2010/05/31 01:17:18 | 000,283,152 | ---- | M] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmwfp.sys
[2010/05/31 01:17:18 | 000,158,224 | ---- | M] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmcomm.sys
[2010/05/31 01:17:18 | 000,146,448 | ---- | M] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmlwf.sys
[2010/05/31 01:17:18 | 000,089,872 | ---- | M] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmtdi.sys
[2010/05/31 01:17:18 | 000,059,920 | ---- | M] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmactmon.sys
[2010/05/31 01:17:18 | 000,050,704 | ---- | M] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmevtmgr.sys
[2010/05/31 01:07:53 | 000,077,528 | ---- | M] () -- C:\Users\Luke\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/05/31 01:04:05 | 000,316,936 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010/05/31 00:15:03 | 001,863,680 | -H-- | M] () -- C:\SZKGFS.dat
[2010/05/30 23:07:38 | 000,390,656 | ---- | M] (iS3, Inc.) -- C:\Users\Luke\Desktop\STOPzilla_Setup.exe
[2010/05/20 23:36:00 | 000,024,064 | ---- | M] () -- C:\Users\Luke\Documents\BOOK COVER.doc
[2010/05/20 23:18:08 | 000,025,600 | ---- | M] () -- C:\Users\Luke\Documents\BOOK REVIEW.doc
[2010/05/12 19:02:59 | 000,000,240 | ---- | M] () -- C:\Windows\win.ini
[2010/05/12 18:32:10 | 000,019,039 | ---- | M] () -- C:\Users\Luke\Documents\DK Gearcheck.xlsx
[2010/05/06 17:49:12 | 000,000,318 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForLuke.job
[2010/05/05 19:06:17 | 000,025,088 | ---- | M] () -- C:\Users\Luke\Documents\THE HOBBIT theme.doc
[2010/05/05 18:38:32 | 000,001,700 | ---- | M] () -- C:\Users\Luke\Desktop\LimeWire 5.5.8.lnk
[2010/04/29 15:39:38 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/04/29 15:39:26 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010/04/28 22:09:45 | 000,026,624 | ---- | M] () -- C:\Users\Luke\Documents\Romeo and Juiet fate vs free will essay.doc
[2010/04/28 13:54:33 | 000,024,064 | ---- | M] () -- C:\Users\Luke\Documents\Fate.doc
[2010/04/26 15:58:12 | 000,256,512 | ---- | M] () -- C:\Windows\PEV.exe
[2010/04/12 20:50:13 | 000,001,804 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2010/04/12 20:44:12 | 000,001,726 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2010/03/31 15:49:13 | 000,025,600 | ---- | M] () -- C:\Users\Luke\Documents\Romeo e-mail.doc
[2010/03/26 16:35:00 | 000,025,600 | ---- | M] () -- C:\Users\Luke\Documents\Mini Report 6.doc
[2010/03/19 16:54:55 | 000,025,088 | ---- | M] () -- C:\Users\Luke\Documents\Mini Report 5.doc
[2010/03/12 17:26:29 | 000,026,112 | ---- | M] () -- C:\Users\Luke\Documents\Mini Report 4.doc
[2010/03/12 17:23:28 | 000,026,112 | ---- | M] () -- C:\Users\Luke\Documents\Mini Reoirt 4.doc
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/06/02 13:07:50 | 000,256,512 | ---- | C] () -- C:\Windows\PEV.exe
[2010/06/02 13:07:50 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2010/06/02 13:07:50 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2010/06/02 13:07:50 | 000,077,312 | ---- | C] () -- C:\Windows\MBR.exe
[2010/06/02 13:07:50 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2010/06/01 22:10:29 | 2137,448,448 | -HS- | C] () -- C:\hiberfil.sys
[2010/05/31 15:24:42 | 000,000,440 | ---- | C] () -- C:\Windows\System32\drivers\kgpfr2.cfg
[2010/05/31 15:20:46 | 000,000,896 | ---- | C] () -- C:\Windows\System32\drivers\kgpcpy.cfg
[2010/05/31 01:27:21 | 000,001,843 | ---- | C] () -- C:\Users\Public\Desktop\Trend Micro Internet Security Pro.lnk
[2010/05/31 01:02:37 | 339,871,117 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2010/05/31 00:15:03 | 001,863,680 | -H-- | C] () -- C:\SZKGFS.dat
[2010/05/20 23:36:00 | 000,024,064 | ---- | C] () -- C:\Users\Luke\Documents\BOOK COVER.doc
[2010/05/20 23:18:08 | 000,025,600 | ---- | C] () -- C:\Users\Luke\Documents\BOOK REVIEW.doc
[2010/05/05 19:06:17 | 000,025,088 | ---- | C] () -- C:\Users\Luke\Documents\THE HOBBIT theme.doc
[2010/05/05 18:38:32 | 000,001,700 | ---- | C] () -- C:\Users\Luke\Desktop\LimeWire 5.5.8.lnk
[2010/04/28 13:54:33 | 000,024,064 | ---- | C] () -- C:\Users\Luke\Documents\Fate.doc
[2010/04/28 13:45:13 | 000,026,624 | ---- | C] () -- C:\Users\Luke\Documents\Romeo and Juiet fate vs free will essay.doc
[2010/04/12 20:50:13 | 000,001,804 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2010/04/12 20:44:12 | 000,001,726 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2010/03/30 21:34:43 | 000,025,600 | ---- | C] () -- C:\Users\Luke\Documents\Romeo e-mail.doc
[2010/03/26 16:35:00 | 000,025,600 | ---- | C] () -- C:\Users\Luke\Documents\Mini Report 6.doc
[2010/03/19 16:54:55 | 000,025,088 | ---- | C] () -- C:\Users\Luke\Documents\Mini Report 5.doc
[2010/03/12 17:26:29 | 000,026,112 | ---- | C] () -- C:\Users\Luke\Documents\Mini Report 4.doc
[2010/03/12 17:23:28 | 000,026,112 | ---- | C] () -- C:\Users\Luke\Documents\Mini Reoirt 4.doc
[2010/03/12 16:41:04 | 000,019,039 | ---- | C] () -- C:\Users\Luke\Documents\DK Gearcheck.xlsx
[2009/05/03 20:29:35 | 000,000,262 | ---- | C] () -- C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2009/04/19 20:16:37 | 000,140,288 | ---- | C] () -- C:\Windows\System32\igfxtvcx.dll
[2009/04/17 16:12:31 | 000,000,376 | ---- | C] () -- C:\Windows\ODBC.INI
[2009/02/04 22:42:40 | 000,027,019 | ---- | C] () -- C:\Windows\maxlink.ini
[2008/04/02 03:01:35 | 000,016,480 | ---- | C] () -- C:\Windows\System32\rixdicon.dll
[2008/02/10 21:55:18 | 000,147,456 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1437.dll
[2007/09/13 11:31:06 | 000,147,456 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1329.dll
[2007/09/13 11:22:46 | 001,238,832 | ---- | C] () -- C:\Windows\System32\igmedkrn.dll
[2007/09/13 11:22:46 | 000,104,636 | ---- | C] () -- C:\Windows\System32\igmedcompkrn.dll
[2007/09/05 15:52:04 | 000,389,120 | ---- | C] () -- C:\Windows\System32\btwhidcs.dll
[2006/11/02 08:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 03:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/03/09 18:58:00 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2003/01/07 15:05:08 | 000,002,695 | ---- | C] () -- C:\Windows\System32\OUTLPERF.INI
[2002/03/04 11:16:34 | 000,110,592 | R--- | C] () -- C:\Windows\System32\Jpeg32.dll
[2001/11/14 16:56:00 | 001,802,240 | ---- | C] () -- C:\Windows\System32\lcppn21.dll

========== LOP Check ==========

[2010/05/31 06:11:52 | 000,000,000 | ---D | M] -- C:\Users\Luke\AppData\Roaming\EA56BAB4929BDBC2F4DB0E2C19EAF6B0
[2010/05/20 00:13:46 | 000,000,000 | ---D | M] -- C:\Users\Luke\AppData\Roaming\LimeWire
[2008/12/25 15:46:54 | 000,000,000 | ---D | M] -- C:\Users\Luke\AppData\Roaming\WildTangent
[2010/06/02 17:14:10 | 000,032,584 | ---- | M] () -- C:\WINDOWS\Tasks\SCHEDLGU.TXT
[2010/06/02 02:45:43 | 000,000,416 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{FC6A490E-08C5-4CBE-8E48-6122E6C1A673}.job

========== Purity Check ==========


< End of report >
  • 0

#10
hammerman

hammerman

    Member 4k

  • Member
  • PipPipPipPipPipPipPip
  • 4,183 posts
Hi,

Please follow these steps.

-- Step 1 --

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
    O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
    [2010/05/30 01:14:15 | 000,000,000 | ---D | C] -- C:\Users\Luke\AppData\Roaming\EA56BAB4929BDBC2F4DB0E2C19EAF6B0
    
    :Services
    
    :Reg
    
    :Files
    
    :Commands
    [purity]
    [emptytemp]
    [emptyflash]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • This fix will produce a report. Please add this to your reply.
-- Step 2 --

Please click here to download AVP Tool by Kaspersky.
  • Save it to your desktop.
  • Reboot your computer into SafeMode.

    You can do this by restarting your computer and continually tapping the F8 key until a menu appears.
    Use your up arrow key to highlight SafeMode then hit enter
    .

  • Double click the setup file to run it.
  • Accept the agreement and click Next to continue.
  • It will by default install it to your desktop folder. Click Next.
  • Hit ok at the prompt for scanning in Safe Mode.
  • It will then open a box. There will be a tab that says Autoscan.
  • Under Autoscan make sure these are checked.

  • Hidden startup Objects
  • System memory
  • Disk boot sectors.
  • My Computer.
  • Also any other drives (Removable that you may have)


After that click on Recommended to the right of Security level. Select Settings.. and then click on the tab that says Additional then under Rootkit scan. Turn on Deep scan then choose OK.

  • Then click on Start Scan at the to right hand Corner.
  • It will automatically Neutralize any objects found.
  • If some objects are left un-neutralized then click the button that says Neutralize all
  • If it says it cannot be Neutralized then chooose The delete option when prompted.
  • After that is done click on the reports button at the bottom and save it to file name it Kas.
  • Save it somewhere convenient like your desktop and just post only the detected Virus\malware in the report it will be at the very top under Detected post those results in your next reply.

    Note: This tool will self uninstall when you close it so please save the log before closing it.


  • 0

Advertisements


#11
Michael Smith

Michael Smith

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
Hi,
I'm on step 2 and rather than the scan completing and telling me what it found it pops up with an alert in the bottom right corner and asks if I want to quarantine, delete or skip for everything it finds. I chose quarantine for the first two and then on the next two that came up the quarantine option said disinfect and was disabled so I chose delete. Should I just keep doing that?
Thanks for all the help so far.
  • 0

#12
hammerman

hammerman

    Member 4k

  • Member
  • PipPipPipPipPipPipPip
  • 4,183 posts
Yes, what you're doing is fine.
  • 0

#13
Michael Smith

Michael Smith

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
All processes killed
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\\{AEB6717E-7E19-11d0-97EE-00C04FD91972} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}\ not found.
C:\Users\Luke\AppData\Roaming\EA56BAB4929BDBC2F4DB0E2C19EAF6B0 folder moved successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Luke
->Temp folder emptied: 15968346 bytes
->Temporary Internet Files folder emptied: 24089713 bytes
->Java cache emptied: 52801900 bytes
->Flash cache emptied: 90724 bytes

User: Public
->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 90 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 89.00 mb


[EMPTYFLASH]

User: All Users

User: Default

User: Default User

User: Luke
->Flash cache emptied: 0 bytes

User: Public

Total Flash Files Cleaned = 0.00 mb


OTL by OldTimer - Version 3.2.5.2 log created on 06032010_115600

Files\Folders moved on Reboot...
C:\Users\Luke\AppData\Local\Temp\ehmsas.txt moved successfully.

Registry entries deleted on Reboot...
____________________________________________________

Kaspersky log

6/3/2010 12:54:03 PM Detected: HEUR:Trojan.Win32.Generic C:\Qoobox\Quarantine\C\Users\Luke\AppData\Roaming\Microsoft\Windows\Templates\memory.tmp.vir
6/3/2010 12:54:03 PM Detected: Trojan.Win32.Pakes.oey C:\Qoobox\Quarantine\C\Users\Luke\AppData\Roaming\ecd5be71.exe.vir
6/3/2010 12:54:04 PM Detected: Rootkit.Win32.Agent.bert C:\Qoobox\Quarantine\C\WINDOWS\System32\drivers\vwskvrg.sys.vir
6/3/2010 12:54:04 PM Detected: Rootkit.Win32.Agent.bert C:\Qoobox\Quarantine\C\WINDOWS\System32\drivers\_vwskvrg_.sys.zip/vwskvrg.sys

Edited by Michael Smith, 04 June 2010 - 11:11 AM.

  • 0

#14
hammerman

hammerman

    Member 4k

  • Member
  • PipPipPipPipPipPipPip
  • 4,183 posts
Hi,

How's your computer running now?

Download Security Check from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

  • 0

#15
Michael Smith

Michael Smith

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
It seems to be running a bit faster than it was, especially when loading internet pages. The viruses I disable from the startup applications have gone so that's a good sign. I really appreciate the help!

Results of screen317's Security Check version 0.99.4
Windows Vista Service Pack 1 (UAC is enabled)
Out of date service pack!!
Internet Explorer 8
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Disabled!
Trend Micro Internet Security Pro
WMI entry may not exist for antivirus; attempting automatic update.
```````````````````````````````
Anti-malware/Other Utilities Check:

Malwarebytes' Anti-Malware
Java™ 6 Update 13
Java™ 6 Update 2
Out of date Java installed!
Adobe Flash Player 10.0.45.2
Adobe Reader 8.1.4
Out of date Adobe Reader installed!
````````````````````````````````
Process Check:
objlist.exe by Laurent

Trend Micro Internet Security SfCtlCom.exe
Trend Micro Internet Security TmProxy.exe
Trend Micro TrendSecure TISProToolbar ProToolbarUpdate.exe
Trend Micro Internet Security TmPfw.exe
Trend Micro Internet Security UfSeAgnt.exe
Trend Micro TrendSecure TISProToolbar PlatformDependent\ProToolbarComm.exe
Trend Micro TrendSecure TSCFPlatformCOMSvr.exe
Trend Micro BM TMBMSRV.exe
````````````````````````````````
DNS Vulnerability Check:

GREAT! (Not vulnerable to DNS cache poisoning)

``````````End of Log````````````
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP