Here is my Combofix and Bitdefender logs:
2 Things first:
some time after running combofix, a fraud AV Security Program appeared and denied any programs from running. I was able to use Spybot to remove it right now so I could get back online.
ComboFix 10-07-03.06 - Albert 07/04/2010 15:09:43.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2038.1331 [GMT -5:00]
Running from: c:\documents and settings\Albert\Desktop\george.exe
AV: AVG *On-access scanning disabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Albert\Application Data\chrtmp
c:\documents and settings\All Users\Application Data\sysReserve.ini
c:\windows\system32\lsprst7.dll
c:\windows\system32\msvcsv60.dll
c:\windows\system32\ssprs.dll
c:\windows\system32\st325602.dll
c:\windows\system32\tmpPrst.dll
c:\windows\xpsp1hfm.log
.
((((((((((((((((((((((((( Files Created from 2010-06-04 to 2010-07-04 )))))))))))))))))))))))))))))))
.
2010-07-03 08:31 . 2010-07-03 08:31 -------- d-----w- c:\windows\system32\wbem\Repository
2010-07-03 08:30 . 2010-07-03 08:30 -------- d-----w- c:\program files\NOS
2010-07-03 08:29 . 2010-07-03 08:29 -------- d-----w- c:\documents and settings\NetworkService\Application Data\Adobe(2)
2010-06-17 17:26 . 2010-06-17 17:26 53632 ----a-w- c:\documents and settings\Albert\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-06-17 17:19 . 2010-06-17 17:19 71680 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2010-06-17 17:19 . 2010-03-29 13:53 32576 ----a-w- c:\documents and settings\Albert\Application Data\Mozilla\Firefox\Profiles\p6i9mjrs.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
2010-06-17 17:19 . 2010-03-29 13:53 29984 ----a-w- c:\documents and settings\Albert\Application Data\Mozilla\Firefox\Profiles\p6i9mjrs.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg.exe
2010-06-07 20:26 . 2010-06-07 20:26 57344 ----a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-06-07 20:14 . 2010-06-07 20:14 56765 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DivXPlusShortcuts\Uninstaller.exe
2010-06-07 20:14 . 2010-06-07 20:14 56997 ----a-w- c:\documents and settings\All Users\Application Data\DivX\WebPlayer\Uninstaller.exe
2010-06-07 20:14 . 2010-06-07 20:14 53600 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Update\Uninstaller.exe
2010-06-07 20:14 . 2010-06-07 20:14 57715 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Player\Uninstaller.exe
2010-06-07 20:13 . 2010-06-07 20:13 84062 ----a-w- c:\documents and settings\All Users\Application Data\DivX\TransferWizard\Uninstaller.exe
2010-06-07 20:12 . 2010-06-07 20:12 54166 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DSAVCDecoder\Uninstaller.exe
2010-06-07 20:12 . 2010-06-07 20:12 57532 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DSASPDecoder\Uninstaller.exe
2010-06-07 20:12 . 2010-06-07 20:12 54153 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DFXPlugin\Uninstaller.exe
2010-06-07 20:12 . 2010-06-07 20:12 54128 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Converter\Uninstaller.exe
2010-06-07 20:12 . 2010-06-07 20:12 54644 ----a-w- c:\documents and settings\All Users\Application Data\DivX\TranscodeEngine\Uninstaller.exe
2010-06-07 20:12 . 2010-06-07 20:12 54101 ----a-w- c:\documents and settings\All Users\Application Data\DivX\MPEG2Plugin\Uninstaller.exe
2010-06-07 20:12 . 2010-06-07 20:12 57409 ----a-w- c:\documents and settings\All Users\Application Data\DivX\ControlPanel\Uninstaller.exe
2010-06-07 20:07 . 2010-06-07 20:07 144696 ----a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-03 08:36 . 2009-03-02 04:00 -------- d-----w- c:\program files\Dl_cats
2010-07-03 08:30 . 2009-11-21 16:20 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-07-03 08:30 . 2006-11-05 01:15 -------- d-----w- c:\documents and settings\Albert\Application Data\BitTorrent
2010-06-29 23:38 . 2006-06-05 05:05 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-06-17 17:39 . 2006-06-14 04:57 -------- d-----w- c:\program files\Common Files\Adobe
2010-06-17 17:26 . 2010-01-07 05:50 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-06-15 03:35 . 2010-05-18 23:37 -------- d-----w- c:\documents and settings\Albert\Application Data\Wirecast
2010-06-15 02:23 . 2009-09-22 22:20 -------- d-----w- c:\documents and settings\Albert\Application Data\DiskAid
2010-06-08 22:07 . 2010-05-06 01:35 -------- d-----w- c:\documents and settings\Albert\Application Data\vlc
2010-06-07 20:26 . 2010-04-05 04:12 -------- d-----w- c:\documents and settings\All Users\Application Data\DivX
2010-06-07 20:14 . 2009-08-13 00:40 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-06-07 20:14 . 2007-02-02 23:50 -------- d-----w- c:\program files\DivX
2010-06-07 20:07 . 2010-04-05 04:17 1062184 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\Resource.dll
2010-06-07 20:07 . 2010-04-05 04:17 895256 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\DivXSetup.exe
2010-06-07 20:06 . 2010-06-03 17:21 -------- d-----w- c:\documents and settings\Albert\Application Data\Skype
2010-06-07 18:52 . 2010-06-03 17:21 -------- d-----w- c:\documents and settings\Albert\Application Data\skypePM
2010-06-07 07:50 . 2008-07-20 21:57 -------- d-----w- c:\program files\Microsoft Silverlight
2010-06-03 17:36 . 2010-06-03 17:27 -------- d-----w- c:\documents and settings\Albert\Application Data\Pamela
2010-06-03 17:27 . 2010-06-03 17:27 -------- d-----w- c:\program files\Pamela
2010-06-03 17:21 . 2010-06-03 17:21 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2010-06-03 17:15 . 2010-06-03 17:14 -------- d-----r- c:\program files\Skype
2010-06-03 17:15 . 2010-06-03 17:15 -------- d-----w- c:\program files\Common Files\Skype
2010-06-03 17:14 . 2010-06-03 17:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2010-05-30 02:46 . 2010-05-30 02:46 4 ----a-w- c:\documents and settings\Albert\Application Data\czyiwa.dat
2010-05-29 03:43 . 2008-08-27 22:48 32 -c--a-w- c:\windows\msocreg32.dat
2010-05-24 08:18 . 2010-05-24 08:18 503808 ----a-w- c:\documents and settings\Albert\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-254b0c78-n\msvcp71.dll
2010-05-24 08:18 . 2010-05-24 08:18 499712 ----a-w- c:\documents and settings\Albert\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-254b0c78-n\jmc.dll
2010-05-24 08:18 . 2010-05-24 08:18 348160 ----a-w- c:\documents and settings\Albert\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-254b0c78-n\msvcr71.dll
2010-05-24 04:47 . 2010-05-24 04:47 -------- d-----w- c:\program files\HotRecorder
2010-05-18 23:37 . 2010-05-18 23:37 -------- d-----w- c:\documents and settings\Albert\Application Data\Vara Software
2010-05-18 23:37 . 2010-05-18 23:37 -------- d-----w- c:\program files\Common Files\eSellerate
2010-05-18 23:37 . 2010-05-18 23:37 -------- d-----w- c:\documents and settings\All Users\Application Data\Telestream
2010-05-18 23:37 . 2010-05-18 23:37 -------- d-----w- c:\program files\Ustream
2010-05-18 04:04 . 2006-06-05 05:27 -------- d-----w- c:\program files\Google
2010-05-17 16:02 . 2010-05-17 16:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Kodak
2010-05-06 12:06 . 2006-06-14 05:11 42032 -c--a-w- c:\documents and settings\Albert\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-05-06 01:34 . 2010-05-06 01:34 -------- d-----w- c:\program files\VideoLAN
2010-05-06 01:22 . 2010-05-06 01:21 -------- d-----w- c:\program files\Rising Software
2010-05-06 01:22 . 2010-05-06 01:22 61440 ----a-r- c:\documents and settings\Albert\Application Data\Microsoft\Installer\{458C07CB-75D4-4987-B46B-D9CD88583BF4}\NewShortcut2_458C07CB75D44987B46BD9CD88583BF4.exe
2010-05-06 01:22 . 2010-05-06 01:22 61440 ----a-r- c:\documents and settings\Albert\Application Data\Microsoft\Installer\{458C07CB-75D4-4987-B46B-D9CD88583BF4}\New_Shortcut_S5846_D43F473F7E40495F971D19BD4DBED1BD.exe
2010-05-06 01:22 . 2010-05-06 01:22 61440 ----a-r- c:\documents and settings\Albert\Application Data\Microsoft\Installer\{458C07CB-75D4-4987-B46B-D9CD88583BF4}\ARPPRODUCTICON.exe
2010-05-04 17:20 . 2005-08-16 09:18 832512 ----a-w- c:\windows\system32\wininet.dll
2010-05-04 17:20 . 2005-08-16 09:18 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-05-04 17:20 . 2005-08-16 09:18 17408 ----a-w- c:\windows\system32\corpol.dll
2010-05-02 05:22 . 2005-08-16 09:18 1851264 ----a-w- c:\windows\system32\win32k.sys
2010-04-27 18:40 . 2008-02-06 20:52 126448 ------w- c:\windows\system32\pxinsi64.exe
2010-04-27 18:40 . 2007-02-02 23:51 133616 ------w- c:\windows\system32\pxafs.dll
2010-04-27 18:40 . 2006-09-27 21:53 45648 ------w- c:\windows\system32\drivers\pxhelp20.sys
2010-04-20 05:30 . 2005-08-16 09:18 285696 ----a-w- c:\windows\system32\atmfd.dll
2007-03-02 16:20 . 2006-06-13 04:33 104 -csha-r- c:\windows\system32\1DB60C6654.sys
2006-07-18 05:53 . 2006-06-12 23:26 88 -csha-r- c:\windows\system32\54660CB61D.sys
2007-03-02 16:20 . 2006-06-12 23:26 6580 -csha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{14f0d511-36a2-41ca-ae01-ba4f87282c97}"= "c:\program files\SHOUTcast Radio Toolbar\shoutcasttb.dll" [2008-09-17 1275176]
[HKEY_CLASSES_ROOT\clsid\{14f0d511-36a2-41ca-ae01-ba4f87282c97}]
[HKEY_CLASSES_ROOT\SHOUTcastTb.AOLTBSearch.1]
[HKEY_CLASSES_ROOT\TypeLib\{8613efdf-b530-4b1d-b970-b09f99977813}]
[HKEY_CLASSES_ROOT\SHOUTcastTb.AOLTBSearch]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"ModemOnHold"="c:\program files\NetWaiting\netWaiting.exe" [2003-09-10 20480]
"Google Update"="c:\documents and settings\Albert\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-11-06 133104]
"FreeRAM XP"="c:\program files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" [2006-03-23 1591808]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-11-29 761947]
"Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2008-04-04 88584]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
"sealmon.exe"="c:\program files\Oracle\Information Rights Management\Desktop\sealmon.exe" [2008-08-21 371000]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-09 305440]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"iPhoneVideoConverter_upgrade"="c:\program files\E-Zsoft\iPhoneVideoConverter\iPhoneVideoConverter.exe" [2009-09-08 503808]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-12-13 98304]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-12-13 118784]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-12-13 77824]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-10 49152]
"dlcdmon.exe"="c:\program files\Dell Photo AIO Printer 944\dlcdmon.exe" [2005-10-07 430080]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2006-04-06 1032192]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-12-01 1261336]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"Adobe Acrobat Speed Launcher"="f:\program files\Adobe2\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2008-06-12 37232]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2010-01-27 788880]
"Acrobat Assistant 8.0"="f:\program files\Adobe2\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-06-12 640376]
"DLCDCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCDtime.dll" [2005-09-14 73728]
"PWRISOVM.EXE"="f:\program files\PowerISO\PWRISOVM.EXE" [2009-07-27 180224]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-06-03 1144104]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-6-5 24576]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-01-29 05:08 10520 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"midi2"=xgusb.cpl
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
2009-07-27 01:37 180224 ----a-w- f:\program files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"aawservice"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\BeatPack\\BeatPack.exe"=
"f:\\Program Files\\µTorrent\\uTorrent.exe"=
"f:\\Program Files\\EA Sports\\Madden NFL 08\\Updater.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"f:\\Program Files\\EA Sports\\Madden NFL 08\\MAINAPP.EXE"=
"c:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS4\\Server\\bin\\VersionCueCS4.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Ustream\\Ustream Producer\\rsrc\\Desktop Presenter.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
"3703:TCP"= 3703:TCP:Adobe Version Cue CS4 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS4 Server
"51000:TCP"= 51000:TCP:Adobe Version Cue CS4 Server
"51001:TCP"= 51001:TCP:Adobe Version Cue CS4 Server
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [1/31/2009 5:34 PM 64288]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [9/17/2008 1:33 AM 325128]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [9/17/2008 1:33 AM 107272]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [9/17/2008 1:32 AM 231704]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [5/3/2009 8:51 PM 24652]
R3 dlcd_device;dlcd_device;c:\windows\system32\dlcdcoms.exe -service --> c:\windows\system32\dlcdcoms.exe -service [?]
S1 vcdrom;Virtual CD-ROM Device Driver;\??\d:\applications\Windows Virtual CD\VCdRom.sys --> d:\applications\Windows Virtual CD\VCdRom.sys [?]
S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [9/17/2008 1:32 AM 875288]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [5/17/2010 11:04 PM 136176]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [9/24/2009 6:17 AM 1181328]
S3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [8/15/2008 5:46 AM 284016]
S3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\drivers\netaapl.sys [6/17/2009 4:17 PM 17408]
S3 PsSdk30;PsSdk30;\??\c:\windows\system32\Drivers\PsSdk30.drv --> c:\windows\system32\Drivers\PsSdk30.drv [?]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [5/20/2007 10:57 PM 682232]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder
2010-07-04 c:\windows\Tasks\Ad-Aware Update (Daily 1).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 18:10]
2010-07-04 c:\windows\Tasks\Ad-Aware Update (Daily 2).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 18:10]
2010-07-04 c:\windows\Tasks\Ad-Aware Update (Daily 3).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 18:10]
2010-07-04 c:\windows\Tasks\Ad-Aware Update (Daily 4).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 18:10]
2010-07-04 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 18:10]
2010-07-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 17:34]
2010-07-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-18 06:28]
2010-07-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-18 06:28]
2010-07-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1555433744-3350049914-2593877280-1005Core.job
- c:\documents and settings\Albert\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-06 05:36]
2010-07-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1555433744-3350049914-2593877280-1005UA.job
- c:\documents and settings\Albert\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-06 05:36]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://www.yahoo.com/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: {{898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
TCP: {1F2AC2F8-C3C5-48A7-A8FF-E06BA3CE58DE} = 192.168.2.1
DPF: {CEDDF50D-9FA7-41A8-BCD0-6350D1ED2306} - hxxps://care.windstream.com/lwp/static/installers/WebflowActiveXInstaller_3-0-0.cab
DPF: {EFD3EA56-234D-4240-90EA-CC9FA3AF5A01} - hxxps://care.windstream.com/lwp/static/installers/ALLTELControls.cab
FF - ProfilePath - c:\documents and settings\Albert\Application Data\Mozilla\Firefox\Profiles\p6i9mjrs.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50-ff-shoutcast-chromesbox-en-us&query=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50-ff-shoutcast-ab-en-us&query=
FF - component: c:\documents and settings\Albert\Application Data\Mozilla\Firefox\Profiles\p6i9mjrs.default\extensions\{12e4c684-c03e-4e4d-85bc-0c065e7a9489}\components\WinampPlayer.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}\components\Contribute.dll
FF - plugin: c:\documents and settings\Albert\Application Data\Move Networks\plugins\npqmp071502000008.dll
FF - plugin: c:\documents and settings\Albert\Local Settings\Application Data\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npContribute.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: dom.disable_open_during_load - false // Popupblocker control handled by McAfee Privacy Service
FF - user.js: browser.sessionstore.resume_from_crash - false
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-MemoryCardManager - (no file)
AddRemove-Antares AVOX Vocal Kit Bundle VST v1.02 - c:\progra~1\VSTPLU~1\AVOXVO~1\Choir\UNWISE.EXE
AddRemove-Korg Legacy Collection v1.0.0.2 - c:\progra~1\KORG\KORGLE~1\UNWISE.EXE
AddRemove-{7B63B2922B174135AFC0E1377DD81EC2} - c:\program files\DivX\DivXCodecUninstall.exe
AddRemove-Octoshape add-in for Adobe Flash Player - c:\documents and settings\Albert\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-07-04 15:20
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCDCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCDtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet004\Services\PsSdk30]
"ImagePath"="\??\c:\windows\system32\Drivers\PsSdk30.drv"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•Ôw*]
"5E7CEC10DF0760D4F8DAFB12FDC06CCD"=""
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•A~*]
"5E7CEC10DF0760D4F8DAFB12FDC06CCD"="02:\\Software\\Adobe\\FeatureSubscriptions\\DVAAdobeDocMeta\\{01CEC7E5-70FD-4D06-8FAD-BF21DF0CC6DC}\\Registered"
"AB141C35E9F4BF344B9FC010BB17F68A"=""
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•A~*]
"AB141C35E9F4BF344B9FC010BB17F68A"=""
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1088)
c:\windows\system32\NavLogon.dll
.
Completion time: 2010-07-04 15:25:15
ComboFix-quarantined-files.txt 2010-07-04 20:24
ComboFix2.txt 2009-12-29 21:07
Pre-Run: 4,878,925,824 bytes free
Post-Run: 4,947,349,504 bytes free
Current=4 Default=4 Failed=2 LastKnownGood=5 Sets=1,2,3,4,5
- - End Of File - - 3B1FB4F3BA3E196182E991AEE1B4EE2B
QuickScan Beta 32-bit v0.9.9.23
-------------------------------
Scan date: Tue Jul 06 13:00:24 2010
Machine ID: C4EE6D05
No infection found.
-------------------
Processes
---------
<unsigned> BVRP Software TestLine 2404 C:\Program Files\Digital Line Detect\DLG.exe
<unsigned> Cyberlink PowerCinema 3.0 752 C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
<unsigned> DellDevice Monitor 728 C:\Program Files\Dell Photo AIO Printer 944\dlcdmon.exe
<unsigned> Drive Letter Access Component 144 C:\WINDOWS\system32\dla\tfswctrl.exe
<unsigned> FRXPRO 684 C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
<unsigned> InstallShield Update Service 3020 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
<unsigned> netWaiting.exe 2576 C:\Program Files\NetWaiting\netWaiting.exe
<unsigned> NicConfigSvc 528 C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
<unsigned> PowerISO Virtual Drive Manager 2504 F:\Program Files\PowerISO\PWRISOVM.EXE
<unsigned> QuickSet 1792 C:\Program Files\Dell\QuickSet\quickset.exe
<unsigned> Viewpoint Manager 1844 C:\Program Files\Viewpoint\Common\ViewpointService.exe
<verified> AcroTray - Adobe Acrobat Distiller help 2788 F:\Program Files\Adobe2\Acrobat 9.0\Acrobat\Acrotray.exe
<verified> Ad-Aware Service Application 1620 C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
<verified> Ad-Aware Tray Application 3128 C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
<verified> Apple Mobile Device Service 212 C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
<verified> AVG Internet Security 232 C:\Program Files\AVG\AVG8\avgwdsvc.exe
<verified> Bonjour 276 C:\Program Files\Bonjour\mDNSResponder.exe
<verified> DivX Update 1804 C:\Program Files\DivX\DivX Update\DivXUpdate.exe
<verified> Firefox 2484 C:\Program Files\Mozilla Firefox\firefox.exe
<verified> Intel® Common User Interface 1012 C:\WINDOWS\system32\hkcmd.exe
<verified> Intel® Common User Interface 3896 C:\WINDOWS\system32\igfxpers.exe
<verified> Intel® Common User Interface 2752 C:\WINDOWS\system32\igfxsrvc.exe
<verified> iTunes 1392 C:\Program Files\iPod\bin\iPodService.exe
<verified> iTunes 1236 C:\Program Files\iTunes\iTunesHelper.exe
<verified> Java Platform SE 6 U17 332 C:\Program Files\Java\jre6\bin\jqs.exe
<verified> Java Platform SE 6 U17 2724 C:\Program Files\Java\jre6\bin\jusched.exe
<verified> LWEMon.exe 2488 C:\Program Files\Logitech\Gaming Software\LWEMon.exe
<verified> Microsoft® Windows® Operating System 2928 C:\WINDOWS\eHome\ehmsas.exe
<verified> Microsoft® Windows® Operating System 452 C:\WINDOWS\eHome\ehRecvr.exe
<verified> Microsoft® Windows® Operating System 1768 C:\WINDOWS\eHome\ehSched.exe
<verified> Microsoft® Windows® Operating System 2784 C:\WINDOWS\ehome\ehtray.exe
<verified> Microsoft® Windows® Operating System 2748 C:\WINDOWS\Explorer.EXE
<verified> Microsoft® Windows® Operating System 3248 C:\WINDOWS\System32\alg.exe
<verified> Microsoft® Windows® Operating System 1056 C:\WINDOWS\system32\csrss.exe
<verified> Microsoft® Windows® Operating System 3148 C:\WINDOWS\system32\ctfmon.exe
<verified> Microsoft® Windows® Operating System 3004 C:\WINDOWS\system32\dllhost.exe
<verified> Microsoft® Windows® Operating System 1140 C:\WINDOWS\system32\lsass.exe
<verified> Microsoft® Windows® Operating System 2860 C:\WINDOWS\system32\NOTEPAD.EXE
<verified> Microsoft® Windows® Operating System 1144 C:\WINDOWS\system32\NOTEPAD.EXE
<verified> Microsoft® Windows® Operating System 1128 C:\WINDOWS\system32\services.exe
<verified> Microsoft® Windows® Operating System 992 C:\WINDOWS\System32\smss.exe
<verified> Microsoft® Windows® Operating System 1984 C:\WINDOWS\system32\spoolsv.exe
<verified> Microsoft® Windows® Operating System 1296 C:\WINDOWS\system32\svchost.exe
<verified> Microsoft® Windows® Operating System 1624 C:\WINDOWS\system32\svchost.exe
<verified> Microsoft® Windows® Operating System 1172 C:\WINDOWS\system32\svchost.exe
<verified> Microsoft® Windows® Operating System 1484 C:\WINDOWS\system32\svchost.exe
<verified> Microsoft® Windows® Operating System 1480 C:\WINDOWS\System32\svchost.exe
<verified> Microsoft® Windows® Operating System 1724 C:\WINDOWS\system32\svchost.exe
<verified> Microsoft® Windows® Operating System 1444 C:\WINDOWS\system32\svchost.exe
<verified> Microsoft® Windows® Operating System 1428 C:\WINDOWS\system32\svchost.exe
<verified> Microsoft® Windows® Operating System 176 C:\WINDOWS\system32\svchost.exe
<verified> Microsoft® Windows® Operating System 1348 C:\WINDOWS\system32\svchost.exe
<verified> Microsoft® Windows® Operating System 2096 C:\WINDOWS\system32\wbem\unsecapp.exe
<verified> Microsoft® Windows® Operating System 3028 C:\WINDOWS\system32\wbem\wmiprvse.exe
<verified> Microsoft® Windows® Operating System 1080 C:\WINDOWS\system32\winlogon.exe
<verified> Oracle Information Rights Management De 2512 C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe
<verified> Printer Communication System 3684 C:\WINDOWS\system32\dlcdcoms.exe
<verified> Synaptics Pointing Device Driver 2796 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
Network activity
----------------
Process firefox.exe (2484) connected on port 80 (HTTP) --> 184.50.252.20
Process firefox.exe (2484) connected on port 80 (HTTP) --> 66.220.147.44
Process firefox.exe (2484) connected on port 80 (HTTP) --> 204.156.15.43
Process firefox.exe (2484) connected on port 80 (HTTP) --> 207.46.192.232
Process firefox.exe (2484) connected on port 80 (HTTP) --> 184.50.245.115
Process firefox.exe (2484) connected on port 80 (HTTP) --> 204.156.15.9
Process firefox.exe (2484) connected on port 80 (HTTP) --> 74.125.157.102
Process svchost.exe (1428) listens on ports: 135 (RPC)
Autoruns and critical files
---------------------------
<unsigned> Cyberlink PowerCinema 3.0 C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
<unsigned> DellDevice Monitor C:\Program Files\Dell Photo AIO Printer 944\dlcdmon.exe
<unsigned> Drive Letter Access Component C:\WINDOWS\system32\dla\tfswctrl.exe
<unsigned> FRXPRO C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
<unsigned> InstallShield Update Service C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
<unsigned> InstallShield Update Service C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
<unsigned> Microsoft Office 2000 C:\Program Files\Microsoft Office\Office\OSA9.EXE
<unsigned> NavLogon.dll C:\WINDOWS\system32\NavLogon.dll
<unsigned> netWaiting.exe C:\Program Files\NetWaiting\netWaiting.exe
<unsigned> PowerISO Virtual Drive Manager F:\Program Files\PowerISO\PWRISOVM.EXE
<unsigned> QuickSet C:\Program Files\Dell\QuickSet\quickset.exe
<unsigned> QuickTime C:\Program Files\QuickTime\QTTask.exe
<unsigned> TeaTimer.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
<verified> Adobe Version Cue CS4 C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4Tray.exe
<verified> AcroTray - Adobe Acrobat Distiller help F:\Program Files\Adobe2\Acrobat 9.0\Acrobat\Acrotray.exe
<verified> Ad-Aware Admin Application C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe
<verified> Ad-Aware Tray Application C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
<verified> Adobe Acrobat C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
<verified> Adobe Acrobat F:\Program Files\Adobe2\Acrobat 9.0\Acrobat\Acrobat_sl.exe
<verified> Adobe CS4 Service Manager C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe
<verified> Adobe Reader and Acrobat Manager C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
<verified> Apple Software Update C:\Program Files\Apple Software Update\SoftwareUpdate.exe
<verified> AVG Internet Security C:\Program Files\AVG\AVG8\avgtray.exe
<verified> AVG Internet Security C:\WINDOWS\system32\avgrsstx.dll
<verified> C-Major Audio C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
<verified> DivX Update C:\Program Files\DivX\DivX Update\DivXUpdate.exe
<verified> Google Update C:\Documents and Settings\Albert\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
<verified> Google Update C:\Program Files\Google\Update\GoogleUpdate.exe
<verified> Intel® Common User Interface C:\WINDOWS\system32\hkcmd.exe
<verified> Intel® Common User Interface C:\WINDOWS\system32\igfxdev.dll
<verified> Intel® Common User Interface C:\WINDOWS\system32\igfxpers.exe
<verified> Intel® Common User Interface C:\WINDOWS\system32\igfxtray.exe
<verified> iTunes C:\Program Files\iTunes\iTunesHelper.exe
<verified> Java Platform SE 6 U17 C:\Program Files\Java\jre6\bin\jusched.exe
<verified> LWEMon.exe C:\Program Files\Logitech\Gaming Software\LWEMon.exe
<verified> Malwarebytes' Anti-Malware C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
<verified> Microsoft® Windows® Operating System C:\WINDOWS\ehome\ehtray.exe
<verified> Microsoft® Windows® Operating System C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\browseui.dll
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\crypt32.dll
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\cryptnet.dll
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\cscdll.dll
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\ctfmon.exe
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\dimsntfy.dll
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\LogonUI.EXE
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\sclgntfy.dll
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\shell32.dll
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\stobject.dll
<verified> Microsoft® Windows® Operating System c:\windows\system32\userinit.exe
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\wlnotify.dll
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\WPDShServiceObj.dll
<verified> Oracle Information Rights Management De C:\Program Files\Oracle\Information Rights Management\Desktop\sealmon.exe
<verified> SpybotSD.exe C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
<verified> Synaptics Pointing Device Driver C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
<verified> Timer DLL C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCDtime.dll
<verified> Windows Genuine Advantage C:\WINDOWS\system32\WgaLogon.dll
<verified> Windows® Internet Explorer C:\WINDOWS\system32\webcheck.dll
Browser plugins
---------------
<unsigned> Bonjour C:\Program Files\Bonjour\mdnsNSP.dll
<unsigned> DivX Player Netscape Plugin C:\Program Files\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll
<unsigned> DivX® Content Upload Plugin C:\Program Files\DivX\DivX Content Uploader\npUpload.dll
<unsigned> Drive Letter Access Component c:\windows\system32\dla\tfswshx.dll
<unsigned> EconPlayer.ocx C:\WINDOWS\Downloaded Program Files\EconPlayer.ocx
<unsigned> Google Earth Plugin C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
<unsigned> InstallShield Update Service C:\WINDOWS\Downloaded Program Files\dwusplay.dll
<unsigned> InstallShield Update Service C:\WINDOWS\Downloaded Program Files\dwusplay.exe
<unsigned> InstallShield Update Service C:\WINDOWS\Downloaded Program Files\isusweb.dll
<unsigned> Java Platform SE 6 U17 c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
<unsigned> MetaStream 3 Plugin C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
<unsigned> MetaStream 3 Plugin C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
<unsigned> Microsoft ClearAdjust Module C:\WINDOWS\Downloaded Program Files\clearadjust.dll
<unsigned> MJOLauncher Module C:\WINDOWS\Downloaded Program Files\mjolauncher.dll
<unsigned> Nexon Game Controller C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
<unsigned> nppdf32.DEU C:\Program Files\Mozilla Firefox\plugins\nppdf32.DEU
<unsigned> nppdf32.FRA C:\Program Files\Mozilla Firefox\plugins\nppdf32.FRA
<unsigned> PearsonInstallAsst2.ocx C:\WINDOWS\Downloaded Program Files\PearsonInstallAsst2.ocx
<unsigned> QuickTime Plug-in 7.6.4 C:\Program Files\Internet Explorer\plugins\npqtplugin.dll
<unsigned> QuickTime Plug-in 7.6.4 C:\Program Files\Internet Explorer\plugins\npqtplugin2.dll
<unsigned> QuickTime Plug-in 7.6.4 C:\Program Files\Internet Explorer\plugins\npqtplugin3.dll
<unsigned> QuickTime Plug-in 7.6.4 C:\Program Files\Internet Explorer\plugins\npqtplugin4.dll
<unsigned> QuickTime Plug-in 7.6.4 C:\Program Files\Internet Explorer\plugins\npqtplugin5.dll
<unsigned> QuickTime Plug-in 7.6.4 C:\Program Files\Internet Explorer\plugins\npqtplugin6.dll
<unsigned> QuickTime Plug-in 7.6.4 C:\Program Files\Internet Explorer\plugins\npqtplugin7.dll
<unsigned> QuickTime Plug-in 7.6.4 C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
<unsigned> QuickTime Plug-in 7.6.4 C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
<unsigned> QuickTime Plug-in 7.6.4 C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
<unsigned> QuickTime Plug-in 7.6.4 C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
<unsigned> QuickTime Plug-in 7.6.4 C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
<unsigned> QuickTime Plug-in 7.6.4 C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
<unsigned> QuickTime Plug-in 7.6.4 C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
<unsigned> RealPlayer Version Plugin C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
<unsigned> RealPlayer Version Plugin C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll
<unsigned> RealPlayer G2 LiveConnect-Enabled P C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
<unsigned> RealPlayer G2 LiveConnect-Enabled P C:\Program Files\Real Alternative\browser\plugins\nppl3260.dll
<unsigned> Shockwave for Director C:\Program Files\Mozilla Firefox\plugins\np32dsw.dll
<unsigned> Silverlight Plug-In C:\Program Files\Microsoft Silverlight\4.0.50524.0\npctrl.dll
<unsigned> TestGen Plug-in 7.3 C:\Program Files\Internet Explorer\plugins\nptgeqplugin.dll
<unsigned> TestGenXInstall.dll C:\WINDOWS\Downloaded Program Files\TestGenXInstall.dll
<unsigned> unagiuninst.exe C:\WINDOWS\Downloaded Program Files\unagiuninst.exe
<unsigned> WinampPlayer.dll C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\p6i9mjrs.default\extensions\{12e4c684-c03e-4e4d-85bc-0c065e7a9489}\components\WinampPlayer.dll
<unsigned> xwrapper.ocx C:\Program Files\Internet Explorer\plugins\xwrapper.ocx
<verified> AcroIEHelper Library c:\program files\common files\adobe\acrobat\activex\acroiehelper.dll
<verified> AcroIEHelperShim Library c:\program files\common files\adobe\acrobat\activex\acroiehelpershim.dll
<verified> Adobe Acrobat C:\Program Files\Internet Explorer\plugins\nppdf32.dll
<verified> Adobe Acrobat C:\Program Files\Mozilla Firefox\plugins\nppdf32.dll
<verified> Adobe Contribute CS4 C:\Program Files\Mozilla Firefox\plugins\npContribute.dll
<verified> Adobe PDF Toolbar for IE c:\program files\common files\adobe\acrobat\activex\acroiefavclient.dll
<verified> AOL Media Playback Control C:\WINDOWS\Downloaded Program Files\ampAx3.0.84.2.dll
<verified> BitDefender QuickScan C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\p6i9mjrs.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\qscanff.dll
<verified> BitDefender QuickScan C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\p6i9mjrs.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
<verified> Contribute f:\program files\adobe2\/adobe contribute cs4/contributeieplugin.dll
<verified> DivX Web Player C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
<verified> Facebook Photo Uploader C:\WINDOWS\Downloaded Program Files\CONFLICT.1\FacebookPhotoUploader.ocx
<verified> Facebook Photo Uploader C:\WINDOWS\Downloaded Program Files\CONFLICT.2\FacebookPhotoUploader.ocx
<verified> Facebook Photo Uploader C:\WINDOWS\Downloaded Program Files\FacebookPhotoUploader.ocx
<verified> getPlusPlus for Adobe 16263 C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\p6i9mjrs.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
<verified> getPlusPlus for Adobe 16263 C:\Program Files\Mozilla Firefox\plugins\np_gp.dll
<verified> Google Update C:\Program Files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
<verified> Google Updater C:\Program Files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
<verified> GoogleToolbarNotifier c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
<verified> Java Deployment Toolkit 6.0.170.4 C:\Program Files\Mozilla Firefox\plugins\npdeploytk.dll
<verified> Java Platform SE 6 U17 c:\program files\java\jre6\bin\jp2ssv.dll
<verified> Messenger C:\Program Files\Messenger\msmsgs.exe
<verified> Microsoft® Windows Media Player Firefox C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
<verified> Microsoft® Windows® Operating System C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\mswsock.dll
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\rsvpsp.dll
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\winrnr.dll
<verified> Move Streaming Media Player C:\Documents and Settings\Albert\Application Data\Move Networks\plugins\npqmp071502000008.dll
<verified> Mozilla Default Plug-in C:\Program Files\Mozilla Firefox\plugins\npnul32.dll
<verified> npitunes.dll C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
<verified> NPSWF32.dll C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
<verified> SDHelper.dll C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
<verified> SHOUTcast Radio IE Toolbar c:\program files\shoutcast radio toolbar\shoutcasttb.dll
<verified> Skype Toolbars c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
<verified> Windows Presentation Foundation C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
<verified> Windows® Internet Explorer C:\WINDOWS\system32\ieframe.dll
<verified> Yahoo Application State Plugin C:\Program Files\Yahoo!\Shared\npYState.dll
<verified> Yahoo! activeX Plug-in Bridge C:\Program Files\Yahoo!\Common\npyaxmpb.dll
<verified> Yahoo! Messenger C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
Missing files
-------------
File not found: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll
referenced in: HLKM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0\"Path"
Scan
----
<unsigned> MD5: de3b8e41165d9c61fb7c77fc0765e6e3 C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\p6i9mjrs.default\extensions\{12e4c684-c03e-4e4d-85bc-0c065e7a9489}\components\WinampPlayer.dll
<unsigned> MD5: f4dcc3149ef542af4e55b4e9def96736 C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
<unsigned> MD5: 292f92469efb2fd402e00742c06d539d C:\Program Files\Bonjour\mdnsNSP.dll
<unsigned> MD5: c1eb9968ec89fba5f3a264e2e57923ab C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
<unsigned> MD5: 87af77718e3bfb5a7766f575609c057a C:\Program Files\Common Files\Adobe\Adobe Drive CS4\BIB.dll
<unsigned> MD5: 5706a9bc07aa1a61748b7c37d518672f C:\Program Files\Common Files\Apple\Mobile Device Support\bin\CFNetwork.dll
<unsigned> MD5: 92599fe833c307fe6ade661908cfc5ac C:\Program Files\Common Files\Apple\Mobile Device Support\bin\CoreFoundation.dll
<unsigned> MD5: 114c844ff5c47a2cdf2ef5a4f4c8215d C:\Program Files\Common Files\Apple\Mobile Device Support\bin\libobjc.i386.A.dll
<unsigned> MD5: 980995d78138f62e082fbd2af549b4fe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\pthreadGC2.dll
<unsigned> MD5: 003cb9477ede79fcd99d6b8669a335ab C:\Program Files\Common Files\Apple\Mobile Device Support\bin\sqlite3.dll
<unsigned> MD5: 9074e71190873c880d7791701ce676ba C:\Program Files\Common Files\Apple\Mobile Device Support\bin\YSFileShim.dll
<unsigned> MD5: a611aed01a534087a0292d47a39fdcc2 C:\Program Files\Common Files\Apple\Mobile Device Support\bin\zlib1.dll
<unsigned> MD5: 583b7d111304be63d7d9cb65482d2187 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
<unsigned> MD5: 9e109b03018763fdcb075ce74547be22 C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
<unsigned> MD5: fdd5d54d4eacce42b260225863f9a0f0 C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
<unsigned> MD5: a532d8bae6caaef24b3c84553fa7f37c C:\Program Files\Dell Photo AIO Printer 944\dlcdmon.exe
<unsigned> MD5: c923f4d287ddb197e0d2a8d64f456b30 C:\Program Files\Dell Photo AIO Printer 944\dlcdscw.dll
<unsigned> MD5: 8dd2cfe68931f1b8e744a70c3950c42a C:\Program Files\Dell\QuickSet\dadkeyb.dll
<unsigned> MD5: f65343bd123b0d517afa20a9bda24f10 C:\Program Files\Dell\QuickSet\IWH10.dll
<unsigned> MD5: 004c802a8214f8d2c72af136bc07bab0 C:\Program Files\Dell\QuickSet\IWH9.dll
<unsigned> MD5: 11d8a00c7eff1aaec8e8464769c84a3d C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
<unsigned> MD5: 90753c9e5c84b3ec5c299b554e5a86e3 C:\Program Files\Dell\QuickSet\quickset.exe
<unsigned> MD5: a476968c08667b1e09f2a95234e8ceef C:\Program Files\Digital Line Detect\BVRPDiag.dll
<unsigned> MD5: b66e56733e2cd6a10fda5919625fbf46 C:\Program Files\Digital Line Detect\DLG.exe
<unsigned> MD5: e14f0925b4ece11ff0c1d53b155266c4 C:\Program Files\DivX\DivX Content Uploader\npUpload.dll
<unsigned> MD5: 30c11d027da6df390772146490273fd1 C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
<unsigned> MD5: 14062265b274c0a43b4a401cca776f5e C:\Program Files\Internet Explorer\plugins\npqtplugin.dll
<unsigned> MD5: 14062265b274c0a43b4a401cca776f5e C:\Program Files\Internet Explorer\plugins\npqtplugin2.dll
<unsigned> MD5: 14062265b274c0a43b4a401cca776f5e C:\Program Files\Internet Explorer\plugins\npqtplugin3.dll
<unsigned> MD5: 14062265b274c0a43b4a401cca776f5e C:\Program Files\Internet Explorer\plugins\npqtplugin4.dll
<unsigned> MD5: 14062265b274c0a43b4a401cca776f5e C:\Program Files\Internet Explorer\plugins\npqtplugin5.dll
<unsigned> MD5: 14062265b274c0a43b4a401cca776f5e C:\Program Files\Internet Explorer\plugins\npqtplugin6.dll
<unsigned> MD5: 14062265b274c0a43b4a401cca776f5e C:\Program Files\Internet Explorer\plugins\npqtplugin7.dll
<unsigned> MD5: dcefc06a923943cff59749fcf7dc01bf C:\Program Files\Internet Explorer\plugins\nptgeqplugin.dll
<unsigned> MD5: 4b8fe2760e9b7c91b4d1e64231f6b00c C:\Program Files\Internet Explorer\plugins\xwrapper.ocx
<unsigned> MD5: dee8f03d1eace0c8f914a2c76568ea32 c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
<unsigned> MD5: b70fa5fea34b4f803e543f92b6c206be C:\Program Files\Microsoft Office\Office\OSA9.EXE
<unsigned> MD5: 2cb7c019a1ab8ea3d281c9606d097331 C:\Program Files\Microsoft Silverlight\4.0.50524.0\npctrl.dll
<unsigned> MD5: 7c50b6946f9304a28995da8803d8d751 C:\Program Files\Mozilla Firefox\extensions\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}\components\Contribute.dll
<unsigned> MD5: 6f9b85c270d7287011670411801c9dbf C:\Program Files\Mozilla Firefox\freebl3.dll
<unsigned> MD5: a0b507e037c3d2369f42a7bbfd08d878 C:\Program Files\Mozilla Firefox\nssdbm3.dll
<unsigned> MD5: 2294930212bb0472b19e824dc35999ad C:\Program Files\Mozilla Firefox\plugins\np32dsw.dll
<unsigned> MD5: e93467c5327c2760fcab2b4670847496 C:\Program Files\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll
<unsigned> MD5: 8d9d6896ae583b4025e810342b50257e C:\Program Files\Mozilla Firefox\plugins\nppdf32.DEU
<unsigned> MD5: b6a50dbf117db339e81dca97fd96340f C:\Program Files\Mozilla Firefox\plugins\nppdf32.FRA
<unsigned> MD5: 8a5657af7b9944d1aca509fb1ef2a12a C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
<unsigned> MD5: 14062265b274c0a43b4a401cca776f5e C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
<unsigned> MD5: 14062265b274c0a43b4a401cca776f5e C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
<unsigned> MD5: 14062265b274c0a43b4a401cca776f5e C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
<unsigned> MD5: 14062265b274c0a43b4a401cca776f5e C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
<unsigned> MD5: 14062265b274c0a43b4a401cca776f5e C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
<unsigned> MD5: 14062265b274c0a43b4a401cca776f5e C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
<unsigned> MD5: 14062265b274c0a43b4a401cca776f5e C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
<unsigned> MD5: 3d84a7e0cd7a1fc93eab9f2d50e5bd9c C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
<unsigned> MD5: b49a14eb7fdd597dc4cf8160ba4be245 C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
<unsigned> MD5: 7206da15f187595389741f85dc47d2a5 C:\Program Files\Mozilla Firefox\softokn3.dll
<unsigned> MD5: 8b1db47ae508698be86b84dfb4a3526a C:\Program Files\NetWaiting\BVRPCTLN.DLL
<unsigned> MD5: 131966da924ddffbe8ae6aad0f048630 C:\Program Files\NetWaiting\BVRPDiag.dll
<unsigned> MD5: 208e667393822ba7c9349be19cadbee8 C:\Program Files\NetWaiting\ModemMOH.dll
<unsigned> MD5: 2f92ed73ac0335c73b07aadc9ca79674 C:\Program Files\NetWaiting\mohrc.dll
<unsigned> MD5: 676b1d0bfa5ef8005395ab43f33de1f1 C:\Program Files\NetWaiting\netWaiting.exe
<unsigned> MD5: e3b13d52c99acb7120f419f3234e0107 C:\Program Files\Oracle\Information Rights Management\Desktop\DesktopSealerResource.dll
<unsigned> MD5: f559dd8ffc3a89da658ff4c15edba344 C:\Program Files\Oracle\Information Rights Management\Desktop\Languages.dll
<unsigned> MD5: 41dcd0b9a8e6066ad9b71f9e108d9db5 C:\Program Files\Oracle\Information Rights Management\Desktop\MsgError.dll
<unsigned> MD5: fa7f9a29e08c1f1e288658ef0b0009e1 C:\Program Files\Oracle\Information Rights Management\Desktop\seal.dll
<unsigned> MD5: 2bd09485e04470a2965ec874777fdcab C:\Program Files\Oracle\Information Rights Management\Desktop\SEALNT.dll
<unsigned> MD5: 08ed3f9bc285547aa1281fe4ff2c2385 C:\Program Files\Oracle\Information Rights Management\Desktop\smdesktopsealer.dll
<unsigned> MD5: 9efba6358df505d6e451d7cf981e0bda C:\Program Files\Oracle\Information Rights Management\Desktop\smFilt.dll
<unsigned> MD5: 0a195a3f17928cf41611a20eb42a7c9e C:\Program Files\Oracle\Information Rights Management\Desktop\smSearchResource.dll
<unsigned> MD5: 44beead8920c6f3d1884640b82db7858 C:\Program Files\Oracle\Information Rights Management\Desktop\smSyncMgrResource.dll
<unsigned> MD5: 295f3f6856b4e75444039227d001b9cd C:\Program Files\QuickTime\QTSystem\QTCF.dll
<unsigned> MD5: e2177dfefe6dba82e13a66f1bcbce56b C:\Program Files\QuickTime\QTSystem\QuickTime.qts
<unsigned> MD5: 18bf2d5cb7e6a979b61a9ac0f05bff26 C:\Program Files\QuickTime\QTSystem\QuickTime.Resources\en.lproj\QuickTimeLocalized.dll
<unsigned> MD5: 43cf388dab66e46f5f2231ae8bb7089a C:\Program Files\QuickTime\QTSystem\QuickTime.Resources\QuickTime.dll
<unsigned> MD5: 8cbd57d84729debee1e83cb5fa3e3d7a C:\Program Files\QuickTime\QTTask.exe
<unsigned> MD5: 8a5657af7b9944d1aca509fb1ef2a12a C:\Program Files\Real Alternative\browser\plugins\nppl3260.dll
<unsigned> MD5: 3d84a7e0cd7a1fc93eab9f2d50e5bd9c C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll
<unsigned> MD5: 390679f7a217a5e73d756276c40ae887 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
<unsigned> MD5: 5f974fde801c73952770736becde11e7 C:\Program Files\Viewpoint\Common\ViewpointService.exe
<unsigned> MD5: b49a14eb7fdd597dc4cf8160ba4be245 C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
<unsigned> MD5: f9354ac8336b37e2693e3ed941f0e5d4 C:\Program Files\WinRAR\RarExt.dll
<unsigned> MD5: 667f078955a93fe382f74d5f109dfe31 C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
<unsigned> MD5: 939522429b24a97d57e84c2a2daec45e C:\WINDOWS\Downloaded Program Files\clearadjust.dll
<unsigned> MD5: 3fea9d2edf23b0283c7a66c8dea380bd C:\WINDOWS\Downloaded Program Files\dwusplay.dll
<unsigned> MD5: cdbe35ea59bc9223e4f800bd1db82d27 C:\WINDOWS\Downloaded Program Files\dwusplay.exe
<unsigned> MD5: 4f98fe3ef4a631ce17cf1085f5756215 C:\WINDOWS\Downloaded Program Files\EconPlayer.ocx
<unsigned> MD5: d8fb851a9fbd62352fd74283f9c14c77 C:\WINDOWS\Downloaded Program Files\isusweb.dll
<unsigned> MD5: 346095dc2bb642ca18a4e7e05442ce8c C:\WINDOWS\Downloaded Program Files\mjolauncher.dll
<unsigned> MD5: f8deb38f965876664468fb2dbc3b4644 C:\WINDOWS\Downloaded Program Files\PearsonInstallAsst2.ocx
<unsigned> MD5: b43771342bde83a1e0b414cdec24bf33 C:\WINDOWS\Downloaded Program Files\TestGenXInstall.dll
<unsigned> MD5: 6f678556a6fce04fc94f3435f6313705 C:\WINDOWS\Downloaded Program Files\unagiuninst.exe
<unsigned> MD5: 30698355067d07da5f9eb81132c9fdd6 C:\WINDOWS\system32\dla\tfsnboio.sys
<unsigned> MD5: fb9d825bb4a2abdf24600f7505050e2b C:\WINDOWS\system32\dla\tfsncofs.sys
<unsigned> MD5: cafd8cca11aa1e8b6d2ea1ba8f70ec33 C:\WINDOWS\system32\dla\tfsndrct.sys
<unsigned> MD5: 8db1e78fbf7c426d8ec3d8f1a33d6485 C:\WINDOWS\system32\dla\tfsndres.sys
<unsigned> MD5: b92f67a71cc8176f331b8aa8d9f555ad C:\WINDOWS\system32\dla\tfsnifs.sys
<unsigned> MD5: 85985faa9a71e2358fcc2edefc2a3c5c C:\WINDOWS\system32\dla\tfsnopio.sys
<unsigned> MD5: bba22094f0f7c210567efdaf11f64495 C:\WINDOWS\system32\dla\tfsnpool.sys
<unsigned> MD5: 81340bef80b9811e98ce64611e67e3ff C:\WINDOWS\system32\dla\tfsnudf.sys
<unsigned> MD5: c035fd116224ccc8325f384776b6a8bb C:\WINDOWS\system32\dla\tfsnudfa.sys
<unsigned> MD5: 32182cbbdc1dc700096ec3253e31cb3c C:\WINDOWS\system32\dla\tfswcres.dll
<unsigned> MD5: 2ca827ba68d0cdb5437c40c6f53d7f20 C:\WINDOWS\system32\dla\tfswctrl.exe
<unsigned> MD5: 37943b990d318145d1efcbeef8f9566a c:\windows\system32\dla\tfswshx.dll
<unsigned> MD5: ec94e05b76d033b74394e7b2175103cf C:\WINDOWS\system32\drivers\APPDRV.sys
<unsigned> MD5: 54ab078660e536da72b21a27f56b035b C:\WINDOWS\system32\drivers\ASPI32.sys
<unsigned> MD5: e814854e6b246ccf498874839ab64d77 C:\WINDOWS\system32\drivers\drvmcdb.sys
<unsigned> MD5: ee83a4ebae70bc93cf14879d062f548b C:\WINDOWS\system32\drivers\DRVNDDM.sys
<unsigned> MD5: 7f2f1d2815a6449d346fcccbc569fbd6 C:\WINDOWS\system32\DRIVERS\mhndrv.sys
<unsigned> MD5: b17228142cec9b3c222239fd935a37ca C:\WINDOWS\system32\DRIVERS\omci.sys
<unsigned> MD5: 444f122e68db44c0589227781f3c8b3f C:\WINDOWS\system32\drivers\pfc.sys
<unsigned> MD5: 30d94039a729571146eb9d736ec1aadd C:\WINDOWS\system32\drivers\SBCPHID.sys
<unsigned> MD5: d7968049be0adbb6a57cee3960320911 C:\WINDOWS\system32\drivers\sscdbhk5.sys
<unsigned> MD5: c3ffd65abfb6441e7606cf74f1155273 C:\WINDOWS\system32\drivers\SSRTLN.sys
<unsigned> MD5: 48d2ca257a22481f830d9ce434e3827a C:\WINDOWS\System32\Drivers\ymidusb.sys
<unsigned> MD5: b7521f69c0a9b29d356157229376fb21 C:\WINDOWS\System32\mhn.dll
<unsigned> MD5: c8d5ebecf889534fe52537f18cfeb1c0 C:\WINDOWS\system32\NavLogon.dll
<unsigned> MD5: 53f7546e8daefb3a0813f5e19c4613c9 C:\WINDOWS\system32\NSNDIS5.SYS
<unsigned> MD5: b5c05ce075f48cc44c154f0ce25c4cfe C:\WINDOWS\system32\tfswapi.dll
<unsigned> MD5: 1b7524806d0270b81360c63a2fa047cb C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfc80.dll
<unsigned> MD5: ccc2e312486ae6b80970211da472268b C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfc80u.dll
<unsigned> MD5: 9090454e6772f7cfbce240bf4dc5f7e8 C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ENU.dll
<unsigned> MD5: 9818ff792cb0fe3a7c226fb5aa194010 F:\Program Files\Adobe2\Acrobat 9.0\Acrobat\AcroTray.DEU
<unsigned> MD5: 35b000440df7855da29ca7df50d6952d F:\Program Files\Adobe2\Acrobat 9.0\Acrobat\AcroTray.FRA
<unsigned> MD5: 44a81087db05e3cbd1c0f848bd6c4c0d F:\Program Files\dBpoweramp\dBShell.dll
<unsigned> MD5: baa3e635383278ec32a160967a53db59 F:\Program Files\PowerISO\PWRISOSH.DLL
<unsigned> MD5: 61d35eee356fba70f4e30e6a5b7d8d6c F:\Program Files\PowerISO\PWRISOVM.EXE
No file uploaded.
Scan finished - communication took 8 sec
Total traffic - 0.08 MB sent, 3.81 KB recvd
Scanned 1328 files and modules - 136 seconds
==============================================================================