here's what comes up after clicking "repair your computer":
here's what happens when I use the username and password of the only account on the system:
Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!
recdisc.exe
Edited by Amlak, 16 October 2011 - 04:24 PM.
Edited by Amlak, 19 October 2011 - 04:39 PM.
Files to delete: C:\WINDOWS\system32\hdsector.sys Drivers to delete: hdsector.sys hdsector
Logfile of The Avenger Version 2.0, (c) by Swandog46 http://swandog46.geekstogo.com Platform: Windows Vista ******************* Script file opened successfully. Script file read successfully. Backups directory opened successfully at C:\Avenger ******************* Beginning to process script file: Rootkit scan active. No rootkits found! Error: could not open file "C:\WINDOWS\sytem32\hdsector.sys" Deletion of file "C:\WINDOWS\sytem32\hdsector.sys" failed! Status: 0xc000003a (STATUS_OBJECT_PATH_NOT_FOUND) --> bad path / the parent directory does not exist Error: registry key "\Registry\Machine\System\CurrentControlSet\Services\hdsector.sys" not found! Deletion of driver "hdsector.sys" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Driver "hdsector" deleted successfully. Completed script processing. ******************* Finished! Terminate.
ComboFix 11-10-28.03 - Martain 28/10/2011 13:17:45.1.1 - x86 Microsoft® Windows Vista™ Home Basic 6.0.6000.0.1252.44.1033.18.1013.123 [GMT 1:00] Running from: c:\users\Martain\Desktop\ComboFix.exe * Created a new restore point . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe c:\programdata\vc71Gx4F.exe C:\sys920e.bin C:\syst63e.bin c:\users\Martain\AppData\Local\{2AAE53E8-258E-4B63-A156-108607283E21} c:\users\Martain\AppData\Local\{2AAE53E8-258E-4B63-A156-108607283E21}\chrome.manifest c:\users\Martain\AppData\Local\{2AAE53E8-258E-4B63-A156-108607283E21}\chrome\content\_cfg.js c:\users\Martain\AppData\Local\{2AAE53E8-258E-4B63-A156-108607283E21}\chrome\content\overlay.xul c:\users\Martain\AppData\Local\{2AAE53E8-258E-4B63-A156-108607283E21}\install.rdf c:\users\Martain\AppData\Local\dbnsdfte.log c:\users\Martain\AppData\Local\Facebook\Update\FacebookUpdate.exe c:\users\Martain\AppData\Local\fteppexh.log c:\users\Martain\AppData\Local\jiwfrnxf.log c:\users\Martain\AppData\Local\rcqfcmpn.log c:\users\Martain\AppData\Local\syjuatse.log c:\users\Martain\AppData\Local\vuhmlici.log c:\users\Martain\AppData\Roaming\Adobe\plugs c:\users\Martain\AppData\Roaming\Adobe\shed c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\ANTIGEN.dll c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\ANTIGEN.drv c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\ANTIGEN.exe c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\ANTIGEN.sys c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\cb.exe c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\cb.sys c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\cb.tmp c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\cid.dll c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\cid.drv c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\CLSV.dll c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\CLSV.drv c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\CLSV.exe c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\CLSV.tmp c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\DBOLE.drv c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\DBOLE.exe c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\DBOLE.sys c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\DBOLE.tmp c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\ddv.dll c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\ddv.drv c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\delfile.tmp c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\dudl.drv c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\eb.dll c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\eb.drv c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\eb.exe c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\eb.sys c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\eb.tmp c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\energy.drv c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\energy.exe c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\energy.sys c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\energy.tmp c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\exec.dll c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\exec.drv c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\exec.exe c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\exec.tmp c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\fan.exe c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\fan.sys c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\fix.tmp c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\FS.exe c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\FS.sys c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\FW.dll c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\FW.exe c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\FW.tmp c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\gid.drv c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\gid.exe c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\gid.sys c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\grid.drv c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\grid.sys c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\hymt.dll c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\hymt.drv c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\hymt.tmp c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\kernel32.dll c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\kernel32.drv c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\kernel32.exe c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\kernel32.sys c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\kernel32.tmp c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\pal.dll c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\pal.drv c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\pal.tmp c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\PE.dll c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\PE.drv c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\PE.exe c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\PE.sys c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\PE.tmp c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\ppal.exe c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\ppal.sys c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\ppal.tmp c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\runddl.drv c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\runddl.exe c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\runddl.sys c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\runddlkey.dll c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\runddlkey.drv c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\SICKBOY.drv c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\sld.drv c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\SM.drv c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\snl2w.dll c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\snl2w.exe c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\snl2w.tmp c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\std.dll c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\std.tmp c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\tempdoc.dll c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\tempdoc.drv c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\tjd.dll c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\tjd.drv c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\tjd.exe c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\tjd.sys c:\users\Martain\AppData\Roaming\Microsoft\Windows\Recent\tjd.tmp c:\users\Martain\GoToAssistDownloadHelper.exe c:\windows\Fonts\e28R26x.com c:\windows\Tasks\At1.job c:\windows\Tasks\At10.job c:\windows\Tasks\At11.job c:\windows\Tasks\At12.job c:\windows\Tasks\At13.job c:\windows\Tasks\At14.job c:\windows\Tasks\At15.job c:\windows\Tasks\At16.job c:\windows\Tasks\At17.job c:\windows\Tasks\At18.job c:\windows\Tasks\At19.job c:\windows\Tasks\At2.job c:\windows\Tasks\At20.job c:\windows\Tasks\At21.job c:\windows\Tasks\At22.job c:\windows\Tasks\At23.job c:\windows\Tasks\At24.job c:\windows\Tasks\At25.job c:\windows\Tasks\At26.job c:\windows\Tasks\At3.job c:\windows\Tasks\At4.job c:\windows\Tasks\At5.job c:\windows\Tasks\At6.job c:\windows\Tasks\At7.job c:\windows\Tasks\At8.job c:\windows\Tasks\At9.job . . ((((((((((((((((((((((((( Files Created from 2011-09-28 to 2011-10-28 ))))))))))))))))))))))))))))))) . . 2011-10-28 12:55 . 2011-10-28 12:55 -------- d-----w- c:\users\Martain\AppData\Local\temp 2011-10-28 12:55 . 2011-10-28 12:55 -------- d-----w- c:\users\Default\AppData\Local\temp 2011-10-28 12:55 . 2011-10-28 12:55 -------- d-----w- c:\users\Guest\AppData\Local\temp 2011-10-28 12:03 . 2011-10-28 12:03 41680 ----a-w- c:\windows\system32\drivers\mdtnioqd.sys 2011-10-28 11:51 . 2011-10-28 11:51 28752 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1733BB72-7441-4F8C-8957-53FD41D58478}\MpKsl2383d859.sys 2011-10-28 11:51 . 2011-10-28 11:51 56200 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1733BB72-7441-4F8C-8957-53FD41D58478}\offreg.dll 2011-10-28 11:44 . 2011-10-28 11:44 352 ----a-w- C:\avexport.bat 2011-10-23 17:59 . 2011-10-23 17:59 14720 ----a-w- c:\windows\system32\hdsector.sys 2011-10-09 15:14 . 2011-10-09 15:14 28752 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1733BB72-7441-4F8C-8957-53FD41D58478}\MpKsl0cc83c6f.sys 2011-10-07 19:29 . 2011-10-07 19:29 41984 ----a-w- c:\windows\system32\vulmu.exe 2011-10-07 19:24 . 2011-10-07 19:24 -------- d-----w- C:\_OTL 2011-10-01 13:43 . 2011-10-01 13:43 -------- d-----w- c:\users\Martain\AppData\Local\AskToolbar 2011-09-30 09:16 . 2011-09-30 09:16 143360 ----a-w- c:\users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StartUp\uxome.exe 2011-09-30 09:16 . 2011-09-30 09:16 143360 ----a-w- c:\users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\huyn.exe . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-09-12 23:14 . 2011-09-26 16:12 7269712 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1733BB72-7441-4F8C-8957-53FD41D58478}\mpengine.dll 2011-09-12 23:14 . 2010-06-10 16:11 7269712 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2011-08-31 16:00 . 2011-08-02 12:11 22216 ----a-w- c:\windows\system32\drivers\mbam.sys . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-05-17 1490312] . [HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}] . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}] 2011-05-17 12:29 1490312 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-05-17 1490312] . [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1] [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd] . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-05-17 1490312] . [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1] [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2011-10-04 147464] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920] . c:\users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ huyn.exe [2011-9-30 143360] OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [N/A] . c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ uxome.exe [2011-9-30 143360] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableLUA"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Desktop Manager.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Desktop Manager.lnk backup=c:\windows\pss\Desktop Manager.lnk.CommonStartup backupExtension=.CommonStartup . [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Empowering Technology Launcher.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Empowering Technology Launcher.lnk backup=c:\windows\pss\Empowering Technology Launcher.lnk.CommonStartup backupExtension=.CommonStartup . [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^TotalMedia Backup Monitor.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\TotalMedia Backup Monitor.lnk backup=c:\windows\pss\TotalMedia Backup Monitor.lnk.CommonStartup backupExtension=.CommonStartup . [HKLM\~\startupfolder\C:^Users^Martain^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^LimeWire On Startup.lnk] path=c:\users\Martain\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LimeWire On Startup.lnk backup=c:\windows\pss\LimeWire On Startup.lnk.Startup backupExtension=.Startup . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] 2007-03-08 11:38 40048 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ApnUpdater] 2011-05-17 12:29 395144 ----a-w- c:\program files\Ask.com\Updater\Updater.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint] 2007-06-06 08:06 159744 ----a-w- c:\program files\Apoint2K\Apoint.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BlackBerryAutoUpdate] 2009-05-12 11:36 623888 ----a-w- c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eDataSecurity Loader] 2007-04-25 23:33 573350 ------w- c:\acer\Empowering Technology\eDataSecurity\eDSLoader.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds] 2008-01-02 17:06 166424 ----a-w- c:\windows\System32\hkcmd.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray] 2008-01-02 17:07 141848 ----a-w- c:\windows\System32\igfxtray.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM] 2008-10-24 09:14 206112 ----a-w- c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LManager] 2007-07-16 05:51 768520 ----a-w- c:\progra~1\LAUNCH~1\LManager.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSC] 2011-06-15 14:16 997920 ----a-w- c:\program files\Microsoft Security Client\msseces.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService] 2007-06-22 01:25 155648 ----a-w- c:\program files\Acer\Acer Arcade\PCMService.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence] 2008-01-02 17:07 133656 ----a-w- c:\windows\System32\igfxpers.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray] 2009-04-11 14:17 236016 ----a-w- c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl] 2007-07-06 03:06 4669440 ----a-w- c:\windows\RtHDVCpl.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] 2009-09-08 15:48 149280 ----a-w- c:\program files\Java\jre6\bin\jusched.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec PIF AlertEng] 2008-01-29 17:38 583048 ----a-w- c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WarReg_PopUp] 2006-11-05 21:48 57344 ----a-w- c:\acer\WR_PopUp\WarReg_PopUp.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender] 2007-07-31 13:15 1006264 ----a-w- c:\program files\Windows Defender\MSASCui.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG] 2011-10-04 16:50 147464 ----a-w- c:\program files\Windows Media Player\WMPNSCFG.exe . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 . R1 fgdbiydf;fgdbiydf;c:\windows\system32\drivers\fgdbiydf.sys [x] R1 hrcvcibk;hrcvcibk;c:\windows\system32\drivers\hrcvcibk.sys [x] R1 hsvzayol;hsvzayol;c:\windows\system32\drivers\hsvzayol.sys [x] R1 kxnxersm;kxnxersm;c:\windows\system32\drivers\kxnxersm.sys [x] R1 lbfuboxw;lbfuboxw;c:\windows\system32\drivers\lbfuboxw.sys [x] R1 mdtnioqd;mdtnioqd;c:\windows\system32\drivers\mdtnioqd.sys [2011-10-28 41680] R1 MpKsl0bf0b4de;MpKsl0bf0b4de;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{33A5A340-C082-48F1-9BB7-3A047F7FACD0}\MpKsl0bf0b4de.sys [x] R1 MpKsl0cc83c6f;MpKsl0cc83c6f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1733BB72-7441-4F8C-8957-53FD41D58478}\MpKsl0cc83c6f.sys [2011-10-09 28752] R1 MpKsl1a7ef16d;MpKsl1a7ef16d;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{33A5A340-C082-48F1-9BB7-3A047F7FACD0}\MpKsl1a7ef16d.sys [x] R1 MpKsl2cf0134b;MpKsl2cf0134b;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1733BB72-7441-4F8C-8957-53FD41D58478}\MpKsl2cf0134b.sys [2011-10-05 28752] R1 MpKsl38f69197;MpKsl38f69197;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{DF6A108E-88F8-4F10-BCBF-221A89D98C98}\MpKsl38f69197.sys [x] R1 MpKsl470d76c9;MpKsl470d76c9;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E40F279B-EA86-4B8D-8A59-C52579D6DB97}\MpKsl470d76c9.sys [x] R1 MpKsl4b027d58;MpKsl4b027d58;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1733BB72-7441-4F8C-8957-53FD41D58478}\MpKsl4b027d58.sys [x] R1 MpKsl50148d0f;MpKsl50148d0f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1733BB72-7441-4F8C-8957-53FD41D58478}\MpKsl50148d0f.sys [x] R1 MpKsl527695ba;MpKsl527695ba;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1733BB72-7441-4F8C-8957-53FD41D58478}\MpKsl527695ba.sys [x] R1 MpKsl55d0abf5;MpKsl55d0abf5;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C3DEDED3-7CEA-4723-BC5C-BE80E13772C8}\MpKsl55d0abf5.sys [x] R1 MpKsl5b777f9f;MpKsl5b777f9f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C3DEDED3-7CEA-4723-BC5C-BE80E13772C8}\MpKsl5b777f9f.sys [x] R1 MpKsl6422714b;MpKsl6422714b;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E40F279B-EA86-4B8D-8A59-C52579D6DB97}\MpKsl6422714b.sys [x] R1 MpKsl65aff1e3;MpKsl65aff1e3;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E40F279B-EA86-4B8D-8A59-C52579D6DB97}\MpKsl65aff1e3.sys [x] R1 MpKsl7fa15cee;MpKsl7fa15cee;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1496EB84-D296-48FC-9E1E-78C8764D50BC}\MpKsl7fa15cee.sys [x] R1 MpKsl80ff5f28;MpKsl80ff5f28;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{2E7451B7-D7F2-4073-83D7-56A618313762}\MpKsl80ff5f28.sys [x] R1 MpKsl8171da99;MpKsl8171da99;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1733BB72-7441-4F8C-8957-53FD41D58478}\MpKsl8171da99.sys [2011-10-25 28752] R1 MpKsl9cf69675;MpKsl9cf69675;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{2E7451B7-D7F2-4073-83D7-56A618313762}\MpKsl9cf69675.sys [x] R1 MpKsld00b7504;MpKsld00b7504;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{2E7451B7-D7F2-4073-83D7-56A618313762}\MpKsld00b7504.sys [x] R1 MpKsld29d8f0b;MpKsld29d8f0b;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7E31799D-4F48-4F21-89EE-7D67BF4A9CD8}\MpKsld29d8f0b.sys [x] R1 MpKsle19d267c;MpKsle19d267c;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1733BB72-7441-4F8C-8957-53FD41D58478}\MpKsle19d267c.sys [2011-10-01 28752] R1 MpKsle51785a3;MpKsle51785a3;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D4C964FC-6AC8-422E-98F9-455E6A3A9AA9}\MpKsle51785a3.sys [x] R1 MpKsle654493e;MpKsle654493e;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7C205F55-72F9-4395-9CDE-F43BAC6A9AD6}\MpKsle654493e.sys [x] R1 nctsyppt;nctsyppt;c:\windows\system32\drivers\nctsyppt.sys [x] R1 nrglnlwq;nrglnlwq;c:\windows\system32\drivers\nrglnlwq.sys [x] R1 ofbgxdne;ofbgxdne;c:\windows\system32\drivers\ofbgxdne.sys [x] R1 qeiaigaa;qeiaigaa;c:\windows\system32\drivers\qeiaigaa.sys [x] R1 szmpqibw;szmpqibw;c:\windows\system32\drivers\szmpqibw.sys [x] R1 tsylpymq;tsylpymq;c:\windows\system32\drivers\tsylpymq.sys [x] R2 vulmu;NVIDIA Display Srv;c:\windows\system32\vulmu.exe [2011-10-07 41984] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-09-02 99376] R4 ALaunchService;ALaunch Service;c:\acer\ALaunch\ALaunchSvc.exe [2007-01-26 50688] S1 MpKsl2383d859;MpKsl2383d859;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1733BB72-7441-4F8C-8957-53FD41D58478}\MpKsl2383d859.sys [2011-10-28 28752] S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-08-31 366152] S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\b57nd60x.sys [2007-06-05 179712] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-08-31 22216] S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2011-04-18 43392] . . --- Other Services/Drivers In Memory --- . *NewlyCreated* - MPKSL2383D859 . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc . Contents of the 'Scheduled Tasks' folder . . ------- Supplementary Scan ------- . uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 mStart Page = hxxp://en.uk.acer.yahoo.com uInternet Settings,ProxyOverride = *.local IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.1.254 FF - ProfilePath - c:\users\Martain\AppData\Roaming\Mozilla\Firefox\Profiles\ksagft2t.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/ FF - prefs.js: keyword.URL - hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=LMW2&o=16046&locale=en_UK&apn_uid=60DDF12B-76F8-42B5-970B-09C79539A2EF&apn_ptnrs=OE&apn_sauid=D66240B2-47E3-4EF0-A05D-DFB9CD329B50&apn_dtid=VIN007YYGB&q= FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: WOT: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} - %profile%\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} FF - user.js: network.cookie.cookieBehavior - 0 FF - user.js: privacy.clearOnShutdown.cookies - false FF - user.js: security.warn_viewing_mixed - false FF - user.js: security.warn_viewing_mixed.show_once - false FF - user.js: security.warn_submit_insecure - false FF - user.js: security.warn_submit_insecure.show_once - false . - - - - ORPHANS REMOVED - - - - . HKCU-Run-Facebook Update - c:\users\Martain\AppData\Local\Facebook\Update\FacebookUpdate.exe HKLM-Run-eRecoveryService - (no file) HKLM-Run-Malwarebytes' Anti-Malware - c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe HKU-Default-Run-QIjLeJwkSi.exe - c:\programdata\QIjLeJwkSi.exe MSConfigStartUp-7GXX3W7H9U0C3HXBTVL - c:\ballantinex\A1E22D3FAB2.exe MSConfigStartUp-Acer Tour Reminder - c:\acer\AcerTour\Reminder.exe MSConfigStartUp-ALaunch - c:\acer\ALaunch\AlaunchClient.exe MSConfigStartUp-ArcSoft Connection Service - c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe MSConfigStartUp-ccApp - c:\program files\Common Files\Symantec Shared\ccApp.exe MSConfigStartUp-Pposedoxiraki - c:\users\Martain\AppData\Local\rvecfs.dll MSConfigStartUp-Security Protection - c:\users\Martain\AppData\Roaming\defender.exe MSConfigStartUp-SetPanel - c:\acer\APanel\APanel.cmd MSConfigStartUp-Spyware Protection - c:\users\Martain\AppData\Roaming\defender.exe MSConfigStartUp-Steam - c:\program files\Steam\Steam.exe MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe MSConfigStartUp-Wwasudu - c:\users\Martain\AppData\Local\iwixajij.dll MSConfigStartUp-{2847DD1B-465C-426A-46BD-4598A29001AA} - c:\users\Martain\AppData\Roaming\Saviqo\ecep.exe . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2011-10-28 13:55 Windows 6.0.6000 NTFS . scanning hidden processes ... . scanning hidden autostart entries ... . scanning hidden files ... . scan completed successfully hidden files: 0 . ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . Completion time: 2011-10-28 14:13:29 ComboFix-quarantined-files.txt 2011-10-28 13:13 . Pre-Run: 3,130,773,504 bytes free Post-Run: 2,976,153,600 bytes free . - - End Of File - - ACC7BCF531D3AE1255AFD12E43C6BA71
KillAll:: Driver:: fgdbiydf hrcvcibk hsvzayol kxnxersm lbfuboxw mdtnioqd MpKsl0bf0b4de MpKsl0cc83c6f MpKsl1a7ef16d MpKsl2cf0134b MpKsl38f69197 MpKsl470d76c9 MpKsl4b027d58 MpKsl50148d0f MpKsl527695ba MpKsl55d0abf5 MpKsl5b777f9f MpKsl6422714b MpKsl65aff1e3 MpKsl7fa15cee MpKsl80ff5f28 MpKsl8171da99 MpKsl9cf69675 MpKsld00b7504 MpKsld29d8f0b MpKsle19d267c MpKsle51785a3 MpKsle654493e nctsyppt nrglnlwq ofbgxdne qeiaigaa szmpqibw tsylpymq vulmu MPKSL2383D859 File:: c:\windows\system32\drivers\mdtnioqd.sys C:\avexport.bat c:\windows\system32\hdsector.sys c:\windows\system32\vulmu.exe c:\users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StartUp\uxome.exe c:\users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\huyn.exe c:\windows\system32\drivers\fgdbiydf.sys c:\windows\system32\drivers\hrcvcibk.sys c:\windows\system32\drivers\hsvzayol.sys c:\windows\system32\drivers\kxnxersm.sys c:\windows\system32\drivers\lbfuboxw.sys c:\windows\system32\drivers\nctsyppt.sys c:\windows\system32\drivers\nrglnlwq.sys c:\windows\system32\drivers\ofbgxdne.sys c:\windows\system32\drivers\qeiaigaa.sys c:\windows\system32\drivers\szmpqibw.sys c:\windows\system32\drivers\tsylpymq.sys Folder:: c:\programdata\Microsoft\Microsoft Antimalware
i must have had the laptop in a stupid position, there's definitely viruses, keep getting ad pop ups.Yes, do try again soon. But make sure you update ComboFix to the latest version first.
If the laptop doesn't power off at Stage 30 the next time (or it powers off at another stage or something), then we might be looking at an overheating issue or some other hardware failure.
ComboFix 11-11-01.03 - Martain 01/11/2011 17:12:38.3.1 - x86 Microsoft® Windows Vista™ Home Basic 6.0.6000.0.1252.44.1033.18.1013.257 [GMT 0:00] Running from: c:\users\Martain\Desktop\ComboFix.exe Command switches used :: c:\users\Martain\Desktop\CFScript.txt . FILE :: "C:\avexport.bat" "c:\users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StartUp\uxome.exe" "c:\users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\huyn.exe" "c:\windows\system32\drivers\fgdbiydf.sys" "c:\windows\system32\drivers\hrcvcibk.sys" "c:\windows\system32\drivers\hsvzayol.sys" "c:\windows\system32\drivers\kxnxersm.sys" "c:\windows\system32\drivers\lbfuboxw.sys" "c:\windows\system32\drivers\mdtnioqd.sys" "c:\windows\system32\drivers\nctsyppt.sys" "c:\windows\system32\drivers\nrglnlwq.sys" "c:\windows\system32\drivers\ofbgxdne.sys" "c:\windows\system32\drivers\qeiaigaa.sys" "c:\windows\system32\drivers\szmpqibw.sys" "c:\windows\system32\drivers\tsylpymq.sys" "c:\windows\system32\hdsector.sys" "c:\windows\system32\vulmu.exe" . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\Microsoft\Microsoft Antimalware c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D18097BC-81B5-44A2-AD24-1F86702C1060}\MpKsl04e32135.sys c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E19C322D-36F9-475C-8329-7A894CCE6AF5}\mpasbase.vdm c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E19C322D-36F9-475C-8329-7A894CCE6AF5}\mpasdlta.vdm c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E19C322D-36F9-475C-8329-7A894CCE6AF5}\mpavbase.vdm c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E19C322D-36F9-475C-8329-7A894CCE6AF5}\mpavdlta.vdm c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E19C322D-36F9-475C-8329-7A894CCE6AF5}\mpengine.dll c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E19C322D-36F9-475C-8329-7A894CCE6AF5}\offreg.dll c:\programdata\Microsoft\Microsoft Antimalware\LocalCopy\{0855A899-7101-C8B8-821A-7793FCD56991}-huyn.exe c:\programdata\Microsoft\Microsoft Antimalware\LocalCopy\{FA5154A5-F1AE-4BF9-9F95-C106D130C83B} c:\programdata\Microsoft\Microsoft Antimalware\Scans\History\CacheManager\MpScanCache-1.bin c:\programdata\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{5A1A0404-AF72-43F4-99A7-060282FFBAD6} c:\programdata\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{71D2C875-FDEF-4102-8185-47E08C93DC71} c:\programdata\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{FA5154A5-F1AE-4BF9-9F95-C106D130C83B} c:\programdata\Microsoft\Microsoft Antimalware\Scans\History\Service\DetectionHistory\13\AD51CCDF-560D-4C57-A4A8-D549C9D7D898 c:\programdata\Microsoft\Microsoft Antimalware\Scans\History\Service\Detections.log c:\programdata\Microsoft\Microsoft Antimalware\Scans\MpDiag.bin c:\programdata\Microsoft\Microsoft Antimalware\Scans\RebootActions\uhpgnoqo.dat c:\programdata\Microsoft\Microsoft Antimalware\Support\MpCacheStats.log c:\programdata\Microsoft\Microsoft Antimalware\Support\MPDetection-10152011-144944.log c:\programdata\Microsoft\Microsoft Antimalware\Support\MPLog-06082010-200938.log c:\programdata\Microsoft\Microsoft Antimalware\Support\MPLog-09252011-162343.log c:\programdata\Microsoft\Microsoft Antimalware\Support\MpWppTracing-10182011-175351-00000003-ffffffff.bin c:\programdata\Microsoft\Microsoft Antimalware\Support\MpWppTracing-10232011-185102-00000003-ffffffff.bin c:\programdata\Microsoft\Microsoft Antimalware\Support\MpWppTracing-10252011-144650-00000003-ffffffff.bin c:\programdata\Microsoft\Microsoft Antimalware\Support\MpWppTracing-10252011-150130-00000003-ffffffff.bin c:\programdata\Microsoft\Microsoft Antimalware\Support\MpWppTracing-10282011-123725-00000003-ffffffff.bin c:\programdata\Microsoft\Microsoft Antimalware\Support\MpWppTracing-10282011-125122-00000003-ffffffff.bin c:\programdata\Microsoft\Microsoft Antimalware\Support\MpWppTracing-10312011-192716-00000003-ffffffff.bin c:\programdata\Microsoft\Microsoft Antimalware\Support\MpWppTracing-10312011-202542-00000003-ffffffff.bin c:\programdata\Microsoft\Microsoft Antimalware\Support\MpWppTracing-10312011-203931-00000003-ffffffff.bin c:\programdata\Microsoft\Microsoft Antimalware\Support\MpWppTracing-10312011-205540-00000003-ffffffff.bin c:\programdata\Microsoft\Microsoft Antimalware\Support\MpWppTracing-10312011-213404-00000003-ffffffff.bin c:\programdata\Microsoft\Microsoft Antimalware\Support\MpWppTracing-11012011-170141-00000003-ffffffff.bin c:\programdata\Microsoft\Microsoft Antimalware\Support\MpWppTracing-11012011-170511-00000003-ffffffff.bin c:\programdata\Microsoft\Microsoft Antimalware\Support\MpWppTracing-11012011-170607-00000003-ffffffff.bin c:\programdata\Microsoft\Microsoft Antimalware\Support\MpWppTracing.bin c:\programdata\vc71Gx4F.exe c:\windows\Tasks\At1.job c:\windows\Tasks\At10.job c:\windows\Tasks\At11.job c:\windows\Tasks\At12.job c:\windows\Tasks\At13.job c:\windows\Tasks\At14.job c:\windows\Tasks\At15.job c:\windows\Tasks\At16.job c:\windows\Tasks\At17.job c:\windows\Tasks\At18.job c:\windows\Tasks\At19.job c:\windows\Tasks\At2.job c:\windows\Tasks\At20.job c:\windows\Tasks\At21.job c:\windows\Tasks\At22.job c:\windows\Tasks\At23.job c:\windows\Tasks\At24.job c:\windows\Tasks\At25.job c:\windows\Tasks\At26.job c:\windows\Tasks\At27.job c:\windows\Tasks\At28.job c:\windows\Tasks\At29.job c:\windows\Tasks\At3.job c:\windows\Tasks\At30.job c:\windows\Tasks\At31.job c:\windows\Tasks\At32.job c:\windows\Tasks\At33.job c:\windows\Tasks\At34.job c:\windows\Tasks\At35.job c:\windows\Tasks\At36.job c:\windows\Tasks\At37.job c:\windows\Tasks\At38.job c:\windows\Tasks\At39.job c:\windows\Tasks\At4.job c:\windows\Tasks\At40.job c:\windows\Tasks\At41.job c:\windows\Tasks\At42.job c:\windows\Tasks\At43.job c:\windows\Tasks\At44.job c:\windows\Tasks\At45.job c:\windows\Tasks\At46.job c:\windows\Tasks\At47.job c:\windows\Tasks\At48.job c:\windows\Tasks\At5.job c:\windows\Tasks\At6.job c:\windows\Tasks\At7.job c:\windows\Tasks\At8.job c:\windows\Tasks\At9.job . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . . -------\Legacy_MPKSL0BF0B4DE -------\Legacy_MPKSL1A7EF16D -------\Legacy_MPKSL38F69197 -------\Legacy_MPKSL470D76C9 -------\Legacy_MPKSL4B027D58 -------\Legacy_MPKSL50148D0F -------\Legacy_MPKSL527695BA -------\Legacy_MPKSL5B777F9F -------\Legacy_MPKSL6422714B -------\Legacy_MPKSL65AFF1E3 -------\Legacy_MPKSL7FA15CEE -------\Legacy_MPKSL80FF5F28 -------\Legacy_MPKSL8171DA99 -------\Legacy_MPKSL9CF69675 -------\Legacy_MPKSLD00B7504 -------\Legacy_MPKSLD29D8F0B -------\Legacy_MPKSLE51785A3 -------\Legacy_MPKSLE654493E -------\Service_fgdbiydf -------\Service_hrcvcibk -------\Service_hsvzayol -------\Service_kxnxersm -------\Service_lbfuboxw -------\Service_MpKsl0bf0b4de -------\Service_MpKsl0cc83c6f -------\Service_MpKsl1a7ef16d -------\Service_MpKsl2cf0134b -------\Service_MpKsl38f69197 -------\Service_MpKsl470d76c9 -------\Service_MpKsl4b027d58 -------\Service_MpKsl50148d0f -------\Service_MpKsl527695ba -------\Service_MpKsl55d0abf5 -------\Service_MpKsl5b777f9f -------\Service_MpKsl6422714b -------\Service_MpKsl65aff1e3 -------\Service_MpKsl7fa15cee -------\Service_MpKsl80ff5f28 -------\Service_MpKsl8171da99 -------\Service_MpKsl9cf69675 -------\Service_MpKsld00b7504 -------\Service_MpKsld29d8f0b -------\Service_MpKsle19d267c -------\Service_MpKsle51785a3 -------\Service_MpKsle654493e -------\Service_nctsyppt -------\Service_nrglnlwq -------\Service_ofbgxdne -------\Service_qeiaigaa -------\Service_szmpqibw -------\Service_tsylpymq -------\Service_vulmu -------\Legacy_MpKsl04e32135 -------\Legacy_MpKsl04e32135 -------\Service_MpKsl04e32135 -------\Service_MpKsl04e32135 . . ((((((((((((((((((((((((( Files Created from 2011-10-01 to 2011-11-01 ))))))))))))))))))))))))))))))) . . 2011-11-01 17:24 . 2011-11-01 17:28 -------- d-----w- c:\users\Martain\AppData\Local\temp 2011-11-01 17:24 . 2011-11-01 17:24 -------- d-----w- c:\users\Guest\AppData\Local\temp 2011-11-01 17:24 . 2011-11-01 17:24 -------- d-----w- c:\users\Default\AppData\Local\temp 2011-10-31 21:31 . 2011-10-31 21:31 41984 ----a-w- c:\windows\system32\fterve.exe 2011-10-31 21:30 . 2011-10-31 21:30 41984 ----a-w- c:\windows\system32\aqrotp.exe 2011-10-31 21:30 . 2011-10-31 21:30 41984 ----a-w- c:\windows\system32\iqroth.exe 2011-10-31 21:30 . 2011-10-31 21:30 41984 ----a-w- c:\windows\system32\gtervf.exe 2011-10-31 21:29 . 2011-10-31 21:29 41984 ----a-w- c:\windows\system32\rqrotq.exe 2011-10-31 21:29 . 2011-10-31 21:29 41984 ----a-w- c:\windows\system32\ttixc.exe 2011-10-31 21:28 . 2011-10-31 21:28 41984 ----a-w- c:\windows\system32\wbegeg.exe 2011-10-31 21:28 . 2011-10-31 21:28 41984 ----a-w- c:\windows\system32\wtervf.exe 2011-10-31 21:28 . 2011-10-31 21:28 41984 ----a-w- c:\windows\system32\vterve.exe 2011-10-31 21:28 . 2011-10-31 21:28 41984 ----a-w- c:\windows\system32\etervu.exe 2011-10-31 21:27 . 2011-10-31 21:27 41984 ----a-w- c:\windows\system32\stixc.exe 2011-10-31 21:27 . 2011-10-31 21:27 41984 ----a-w- c:\windows\system32\sfinb.exe 2011-10-31 21:27 . 2011-10-31 21:27 41984 ----a-w- c:\windows\system32\xbegeg.exe 2011-10-31 21:27 . 2011-10-31 21:27 41984 ----a-w- c:\windows\system32\tsodt.exe 2011-10-31 21:27 . 2011-10-31 21:27 41984 ----a-w- c:\windows\system32\csodc.exe 2011-10-31 21:27 . 2011-10-31 21:27 41984 ----a-w- c:\windows\system32\xtervw.exe 2011-10-31 21:27 . 2011-10-31 21:27 41984 ----a-w- c:\windows\system32\ksodz.exe 2011-10-31 21:27 . 2011-10-31 21:27 41984 ----a-w- c:\windows\system32\iweryx.exe 2011-10-31 21:25 . 2011-10-31 21:25 41984 ----a-w- c:\windows\system32\ybegeg.exe 2011-10-31 21:25 . 2011-10-31 21:25 41984 ----a-w- c:\windows\system32\xweryg.exe 2011-10-31 21:25 . 2011-10-31 21:25 41984 ----a-w- c:\windows\system32\etixt.exe 2011-10-31 21:25 . 2011-10-31 21:25 41984 ----a-w- c:\windows\system32\mtixl.exe 2011-10-31 21:25 . 2011-10-31 21:25 41984 ----a-w- c:\windows\system32\zqroth.exe 2011-10-31 21:25 . 2011-10-31 21:25 41984 ----a-w- c:\windows\system32\ssodc.exe 2011-10-31 21:25 . 2011-10-31 21:25 41984 ----a-w- c:\windows\system32\hweryx.exe 2011-10-31 21:25 . 2011-10-31 21:25 41984 ----a-w- c:\windows\system32\ltixk.exe 2011-10-31 21:25 . 2011-10-31 21:25 41984 ----a-w- c:\windows\system32\aqrota.exe 2011-10-31 21:23 . 2011-10-31 21:23 41984 ----a-w- c:\windows\system32\yweryx.exe 2011-10-31 21:22 . 2011-10-31 21:22 41984 ----a-w- c:\windows\system32\pweryo.exe 2011-10-31 21:22 . 2011-10-31 21:22 41984 ----a-w- c:\windows\system32\obegeo.exe 2011-10-31 21:22 . 2011-10-31 21:22 41984 ----a-w- c:\windows\system32\sfinr.exe 2011-10-31 21:22 . 2011-10-31 21:22 41984 ----a-w- c:\windows\system32\otervn.exe 2011-10-31 21:22 . 2011-10-31 21:22 41984 ----a-w- c:\windows\system32\qweryp.exe 2011-10-31 21:21 . 2011-10-31 21:21 41984 ----a-w- c:\windows\system32\qqrotq.exe 2011-10-31 21:21 . 2011-10-31 21:21 41984 ----a-w- c:\windows\system32\uulmd.exe 2011-10-31 21:21 . 2011-10-31 21:21 41984 ----a-w- c:\windows\system32\bfinq.exe 2011-10-31 21:20 . 2011-10-31 21:20 41984 ----a-w- c:\windows\system32\zqrotj.exe 2011-10-31 21:20 . 2011-10-31 21:20 41984 ----a-w- c:\windows\system32\yweryh.exe 2011-10-31 21:20 . 2011-10-31 21:20 41984 ----a-w- c:\windows\system32\gbegev.exe 2011-10-31 21:20 . 2011-10-31 21:20 41984 ----a-w- c:\windows\system32\xweryh.exe 2011-10-31 21:20 . 2011-10-31 21:20 41984 ----a-w- c:\windows\system32\tsodc.exe 2011-10-31 21:19 . 2011-10-31 21:19 41984 ----a-w- c:\windows\system32\ttixt.exe 2011-10-31 21:19 . 2011-10-31 21:19 41984 ----a-w- c:\windows\system32\iqroti.exe 2011-10-31 21:19 . 2011-10-31 21:19 41984 ----a-w- c:\windows\system32\jfiny.exe 2011-10-31 21:19 . 2011-10-31 21:19 41984 ----a-w- c:\windows\system32\vtervf.exe 2011-10-31 21:19 . 2011-10-31 21:19 41984 ----a-w- c:\windows\system32\utixd.exe 2011-10-31 21:19 . 2011-10-31 21:19 41984 ----a-w- c:\windows\system32\oweryo.exe 2011-10-31 21:19 . 2011-10-31 21:19 41984 ----a-w- c:\windows\system32\jqroty.exe 2011-10-31 21:19 . 2011-10-31 21:19 41984 ----a-w- c:\windows\system32\nbegen.exe 2011-10-31 21:19 . 2011-10-31 21:19 41984 ----a-w- c:\windows\system32\iqrotx.exe 2011-10-31 21:19 . 2011-10-31 21:19 41984 ----a-w- c:\windows\system32\lulml.exe 2011-10-31 21:19 . 2011-10-31 21:19 41984 ----a-w- c:\windows\system32\rfina.exe 2011-10-31 21:17 . 2011-10-31 21:22 41984 ----a-w- c:\windows\system32\ctixc.exe 2011-10-31 21:16 . 2011-10-31 21:22 41984 ----a-w- c:\windows\system32\zfini.exe 2011-10-31 21:16 . 2011-10-31 21:22 41984 ----a-w- c:\windows\system32\mulmm.exe 2011-10-31 21:16 . 2011-10-31 21:22 41984 ----a-w- c:\windows\system32\xbegew.exe 2011-10-31 21:15 . 2011-10-31 21:22 41984 ----a-w- c:\windows\system32\csodr.exe 2011-10-31 21:15 . 2011-10-31 21:22 41984 ----a-w- c:\windows\system32\uulme.exe 2011-10-31 21:15 . 2011-10-31 21:22 41984 ----a-w- c:\windows\system32\ntervm.exe 2011-10-31 21:15 . 2011-10-31 21:22 41984 ----a-w- c:\windows\system32\afina.exe 2011-10-31 21:15 . 2011-10-31 21:22 41984 ----a-w- c:\windows\system32\ltixl.exe 2011-10-31 20:58 . 2011-10-31 21:22 41984 ----a-w- c:\windows\system32\pbegeo.exe 2011-10-23 17:59 . 2011-10-23 17:59 14720 ----a-w- c:\windows\system32\hdsector.sys 2011-10-07 19:24 . 2011-10-07 19:24 -------- d-----w- C:\_OTL . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-08-31 16:00 . 2011-08-02 12:11 22216 ----a-w- c:\windows\system32\drivers\mbam.sys . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-05-17 1490312] . [HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}] . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}] 2011-05-17 12:29 1490312 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-05-17 1490312] . [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1] [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd] . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-05-17 1490312] . [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1] [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2011-10-04 147464] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableLUA"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Desktop Manager.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Desktop Manager.lnk backup=c:\windows\pss\Desktop Manager.lnk.CommonStartup backupExtension=.CommonStartup . [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Empowering Technology Launcher.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Empowering Technology Launcher.lnk backup=c:\windows\pss\Empowering Technology Launcher.lnk.CommonStartup backupExtension=.CommonStartup . [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^TotalMedia Backup Monitor.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\TotalMedia Backup Monitor.lnk backup=c:\windows\pss\TotalMedia Backup Monitor.lnk.CommonStartup backupExtension=.CommonStartup . [HKLM\~\startupfolder\C:^Users^Martain^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^LimeWire On Startup.lnk] path=c:\users\Martain\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LimeWire On Startup.lnk backup=c:\windows\pss\LimeWire On Startup.lnk.Startup backupExtension=.Startup . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] 2007-03-08 11:38 40048 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ApnUpdater] 2011-05-17 12:29 395144 ----a-w- c:\program files\Ask.com\Updater\Updater.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint] 2007-06-06 08:06 159744 ----a-w- c:\program files\Apoint2K\Apoint.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BlackBerryAutoUpdate] 2009-05-12 11:36 623888 ----a-w- c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eDataSecurity Loader] 2007-04-25 23:33 573350 ------w- c:\acer\Empowering Technology\eDataSecurity\eDSLoader.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds] 2008-01-02 17:06 166424 ----a-w- c:\windows\System32\hkcmd.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray] 2008-01-02 17:07 141848 ----a-w- c:\windows\System32\igfxtray.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM] 2008-10-24 09:14 206112 ----a-w- c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LManager] 2007-07-16 05:51 768520 ----a-w- c:\progra~1\LAUNCH~1\LManager.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSC] 2011-06-15 14:16 997920 ----a-w- c:\program files\Microsoft Security Client\msseces.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService] 2007-06-22 01:25 155648 ----a-w- c:\program files\Acer\Acer Arcade\PCMService.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence] 2008-01-02 17:07 133656 ----a-w- c:\windows\System32\igfxpers.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray] 2009-04-11 14:17 236016 ----a-w- c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl] 2007-07-06 03:06 4669440 ----a-w- c:\windows\RtHDVCpl.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] 2009-09-08 15:48 149280 ----a-w- c:\program files\Java\jre6\bin\jusched.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec PIF AlertEng] 2008-01-29 17:38 583048 ----a-w- c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WarReg_PopUp] 2006-11-05 21:48 57344 ----a-w- c:\acer\WR_PopUp\WarReg_PopUp.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender] 2007-07-31 13:15 1006264 ----a-w- c:\program files\Windows Defender\MSASCui.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG] 2011-10-04 16:50 147464 ----a-w- c:\program files\Windows Media Player\WMPNSCFG.exe . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 . R1 uhpgnoqo;uhpgnoqo;c:\windows\system32\drivers\uhpgnoqo.sys [x] R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-08-31 366152] R2 wbegef;NVIDIA Display Srv;c:\windows\system32\wbegef.exe [2011-10-31 41984] R3 CFcatchme;CFcatchme;c:\combofix\CFcatchme.sys [x] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-09-02 99376] R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2011-04-18 43392] R4 ALaunchService;ALaunch Service;c:\acer\ALaunch\ALaunchSvc.exe [2007-01-26 50688] S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\b57nd60x.sys [2007-06-05 179712] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-08-31 22216] . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc . . ------- Supplementary Scan ------- . uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 mStart Page = hxxp://en.uk.acer.yahoo.com uInternet Settings,ProxyOverride = *.local IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.1.254 FF - ProfilePath - c:\users\Martain\AppData\Roaming\Mozilla\Firefox\Profiles\ksagft2t.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/ FF - prefs.js: keyword.URL - hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=LMW2&o=16046&locale=en_UK&apn_uid=60DDF12B-76F8-42B5-970B-09C79539A2EF&apn_ptnrs=OE&apn_sauid=D66240B2-47E3-4EF0-A05D-DFB9CD329B50&apn_dtid=VIN007YYGB&q= FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: WOT: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} - %profile%\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} FF - user.js: network.cookie.cookieBehavior - 0 FF - user.js: privacy.clearOnShutdown.cookies - false FF - user.js: security.warn_viewing_mixed - false FF - user.js: security.warn_viewing_mixed.show_once - false FF - user.js: security.warn_submit_insecure - false FF - user.js: security.warn_submit_insecure.show_once - false . . ************************************************************************** scanning hidden processes ... . scanning hidden autostart entries ... . scanning hidden files ... . scan completed successfully hidden files: . ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . ------------------------ Other Running Processes ------------------------ . c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe c:\program files\Windows Media Player\wmpnetwk.exe c:\program files\Windows Media Player\wmpnscfg .exe c:\windows\servicing\TrustedInstaller.exe c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe . ************************************************************************** . Completion time: 2011-11-01 17:39:47 - machine was rebooted ComboFix-quarantined-files.txt 2011-11-01 17:39 ComboFix2.txt 2011-10-28 13:13 . Pre-Run: 1,959,890,944 bytes free Post-Run: 2,544,799,744 bytes free . - - End Of File - - 7D62DC2B23332D93A5E1248E065414D8
0 members, 0 guests, 0 anonymous users
Community Forum Software by IP.Board
Licensed to: Geeks to Go, Inc.