I've done as suggested at http://www.geekstogo...uide-t2852.html
Spybot repeatedly finds, but cannot remove Win32.TDSS.rtk (sbi $36FD6719) System Service
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\gao. When I used 'jump to', Spybot only opened Registry Editor, and gao is not found when I search the registry.
I've run the following online scans: F-Secure, Trend Micro Housecall, Kaspersky, Panda, BitDefender, Norton, and Eset. –
Kaspersky found: File Name: C:\System Volume Information\_restore{A9C08A01-F248-4873-8B01-BDBFAB10F713}\RP13\A0003448.dll (The only files in that folder are MountPointManagerRemoteDatabase (0KB) and tracking log (20KB)both modified last June)
Threat Name: Infected: Packed.Win32.Tdss.c
Comodo (my AV/firewall), MBAM, and Ad-Aware found nothing.
Microsoft Windows XP Professional (5.1.2600) Service Pack 3
A:\ [Removable] (Total:0 Mo/Free:0 Mo)
C:\ [Fixed] - NTFS - (Total:76285 Mo/Free:154 Mo)
D:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
E:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
Fri 03/20/2009|17:27
----------------------\\ Processes..
--Locked-- [System Process]
---------- System
---------- \SystemRoot\System32\smss.exe
---------- \??\C:\WINDOWS\system32\csrss.exe
---------- \??\C:\WINDOWS\system32\winlogon.exe
---------- C:\WINDOWS\system32\services.exe
---------- C:\WINDOWS\system32\lsass.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\system32\svchost.exe
--Locked-- cmdagent.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\system32\spoolsv.exe
---------- C:\WINDOWS\Explorer.EXE
---------- C:\WINDOWS\system32\nvsvc32.exe
--Locked-- cfp.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\notepad.exe
---------- C:\Program Files 2\Mozilla Firefox\firefox.exe
---------- C:\Program Files\Microsoft Office\Office\WINWORD.EXE
---------- C:\WINDOWS\system32\cmd.exe
---------- C:\Rooter$\RK.exe
----------------------\\ Search..
----------------------\\ ROOTKIT !!
1 - "C:\Rooter$\Rooter_1.txt" - Fri 03/20/2009|16:41
2 - "C:\Rooter$\Rooter_2.txt" - Fri 03/20/2009|17:27
----------------------\\ Scan completed at 17:27
OTListIt logfile created on: 3/20/2009 4:48:55 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.7.0 Folder = C:\Documents and Settings\Owner One\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 100.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.50 Gb Total Space | 48.15 Gb Free Space | 64.64% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: D
Current User Name: Owner
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe ()
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\Program Files\COMODO\COMODO Internet Security\cfp.exe ()
PRC - C:\Documents and Settings\Owner One\Desktop\OTListIt2.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (aawservice [Disabled | Stopped]) -- C:\Program Files\Utilities\Ad-Aware\aawservice.exe (Lavasoft)
SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (cmdAgent [Auto | Running]) -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe ()
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (gupdate1c942787e9fe88c [Disabled | Stopped]) -- File not found
SRV - (gusvc [Disabled | Stopped]) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [Disabled | Stopped]) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (NetTcpPortSharing [Disabled | Stopped]) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (nmservice [Disabled | Stopped]) -- File not found
SRV - (NVSvc [Auto | Running]) -- C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (SimpTcp [On_Demand | Stopped]) -- C:\WINDOWS\system32\tcpsvcs.exe (Microsoft Corporation)
SRV - (WMPNetworkSvc [Disabled | Stopped]) -- C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (cmdGuard [System | Running]) -- C:\WINDOWS\System32\DRIVERS\cmdguard.sys (COMODO)
DRV - (cmdHlp [System | Running]) -- C:\WINDOWS\System32\DRIVERS\cmdhlp.sys (COMODO)
DRV - (ctsfm2k [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ctsfm2k.sys (Creative Technology Ltd)
DRV - (E100B [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\e100b325.sys (Intel Corporation)
DRV - (exdisk [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\exdisk.sys ()
DRV - (HDAudBus [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\HDAudBus.sys (Windows ® Server 2003 DDK provider)
DRV - (hp4200c [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\hp4200c.sys (Hewlett-Packard)
DRV - (Inspect [Boot | Running]) -- C:\WINDOWS\System32\DRIVERS\inspect.sys (COMODO)
DRV - (NTIDrvr [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\NTIDrvr.sys (NewTech Infosystems, Inc.)
DRV - (nv [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (OsaFsLoc [Auto | Running]) -- C:\WINDOWS\system32\drivers\OsaFsLoc.sys (OSA Technologies)
DRV - (osaio [Auto | Running]) -- C:\WINDOWS\system32\drivers\osaio.sys (Avocent/OSA Technologies Inc.)
DRV - (ossrv [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ctoss2k.sys (Creative Technology Ltd.)
DRV - (P17 [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\P17.sys (Creative Technology Ltd.)
DRV - (p17filt [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\p17filt.sys (Sensaura)
DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (SDTHOOK [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\SDTHOOK.sys (Panda Software)
DRV - (Secdrv [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sfdrv01 [Boot | Running]) -- C:\WINDOWS\System32\drivers\sfdrv01.sys (Protection Technology (StarForce))
DRV - (sfhlp02 [Boot | Running]) -- C:\WINDOWS\System32\drivers\sfhlp02.sys (Protection Technology (StarForce))
DRV - (sfsync04 [Boot | Running]) -- C:\WINDOWS\System32\drivers\sfsync04.sys (Protection Technology (StarForce))
DRV - (sfvfs02 [Boot | Running]) -- C:\WINDOWS\System32\drivers\sfvfs02.sys (Protection Technology)
DRV - (SMBios [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\SMBios.sys (Intel Corporation)
DRV - (smbusp [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\intelsmb.sys (Intel Corporation)
DRV - (STHDA [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\sthda.sys (IDT, Inc.)
DRV - (tmcomm [Auto | Running]) -- C:\WINDOWS\system32\drivers\tmcomm.sys (Trend Micro Inc.)
DRV - (WinMTBus [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\WinMTBus.sys (WinMount International Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn...st/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.microsoft...amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn...st/srchasst.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.startup.homepage: "about:blank"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.0.1
FF - prefs.js..extensions.enabledItems: [email protected]:1.0.5
FF - prefs.js..extensions.enabledItems: {00084897-021a-4361-8423-083407a033e0}:1.4
FF - prefs.js..extensions.enabledItems: {fce36c1e-58d8-498a-b2a5-66ad1cedebbb}:0.76
FF - prefs.js..extensions.enabledItems: {3d7eb24f-2740-49df-8937-200b1cc08f8a}:1.5.8
FF - prefs.js..extensions.enabledItems: {B9C8BE50-7105-4ec6-8FB4-4935C0671648}:0.5.98
FF - prefs.js..extensions.enabledItems: {37E4D8EA-8BDA-4831-8EA1-89053939A250}:2.1.0.2
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.6
FF - prefs.js..extensions.enabledItems: {403304EE-066A-4a2a-8F41-F12028480A0A}:1.8.48
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.6\extensions\\Components: C:\PROGRAM FILES 2\MOZILLA FIREFOX\COMPONENTS [2009/02/22 02:27:01 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.6\extensions\\Plugins: C:\PROGRAM FILES 2\MOZILLA FIREFOX\PLUGINS [2009/02/08 10:42:21 | 00,000,000 | ---D | M]
[2009/03/05 11:07:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner One\Application Data\mozilla\Extensions
[2009/03/05 11:07:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner One\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/03/20 16:29:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner One\Application Data\mozilla\Firefox\Profiles\n0y9n3ds.default\extensions
[2009/01/28 19:42:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner One\Application Data\mozilla\Firefox\Profiles\n0y9n3ds.default\extensions\{00084897-021a-4361-8423-083407a033e0}
[2009/03/16 12:54:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner One\Application Data\mozilla\Firefox\Profiles\n0y9n3ds.default\extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}
[2009/02/06 10:47:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner One\Application Data\mozilla\Firefox\Profiles\n0y9n3ds.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
[2009/03/11 18:28:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner One\Application Data\mozilla\Firefox\Profiles\n0y9n3ds.default\extensions\{403304EE-066A-4a2a-8F41-F12028480A0A}
[2009/02/06 10:47:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner One\Application Data\mozilla\Firefox\Profiles\n0y9n3ds.default\extensions\{B9C8BE50-7105-4ec6-8FB4-4935C0671648}
[2009/01/14 13:18:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner One\Application Data\mozilla\Firefox\Profiles\n0y9n3ds.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2008/11/09 15:18:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner One\Application Data\mozilla\Firefox\Profiles\n0y9n3ds.default\extensions\{fce36c1e-58d8-498a-b2a5-66ad1cedebbb}
[2008/11/09 15:18:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner One\Application Data\mozilla\Firefox\Profiles\n0y9n3ds.default\extensions\[email protected]
O1 HOSTS File: (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h ()
O4 - HKLM..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClearRecentDocsOnExit = [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\CavEmLSP.dll (COMODO)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\CavEmLSP.dll (COMODO)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\CavEmLSP.dll (COMODO)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\CavEmLSP.dll (COMODO)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\CavEmLSP.dll (COMODO)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\CavEmLSP.dll (COMODO)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\CavEmLSP.dll (COMODO)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\CavEmLSP.dll (COMODO)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\CavEmLSP.dll (COMODO)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\CavEmLSP.dll (COMODO)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\CavEmLSP.dll (COMODO)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\CavEmLSP.dll (COMODO)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\CavEmLSP.dll (COMODO)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\CavEmLSP.dll (COMODO)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\CavEmLSP.dll (COMODO)
O15 - HKLM\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: microsoft.com ([*.update] http in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([*.update] https in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([www.update] https in Trusted sites)
O15 - HKCU\..Trusted Domains: windowsupdate.com ([download] http in Trusted sites)
O15 - HKCU\..Trusted Domains: 57 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} http://security.syma...bin/AvSniff.cab (Symantec AntiVirus scanner)
O16 - DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} http://h20264.www2.h...nosticsxp2k.cab (DeviceEnum Class)
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} http://www.eset.eu/b...lineScanner.cab (Reg Error: Key error.)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitd...can8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} http://security.syma...n/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} http://www.creative....101/CTSUEng.cab (Creative Software AutoUpdate)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.mi...b?1204390637593 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} http://support.f-sec...m/ols/fscax.cab (F-Secure Online Scanner 3.3)
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://www.creative....15106/CTPID.cab (Creative Software AutoUpdate Support Package)
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\WINDOWS\system32\guard32.dll) - C:\WINDOWS\system32\guard32.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{8db87591-ff56-11dc-9b93-001676d06dcc}\Shell - "" = AutoRun
O33 - MountPoints2\{8db87591-ff56-11dc-9b93-001676d06dcc}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{8db87596-ff56-11dc-9b93-001676d06dcc}\Shell - "" = AutoRun
O33 - MountPoints2\{8db87596-ff56-11dc-9b93-001676d06dcc}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun - "" = Auto&Play
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
========== Files/Folders - Created Within 30 Days ==========
[2009/03/20 16:48:19 | 00,000,098 | ---- | C] () -- C:\DOCUME~1\OWNERO~1\Desktop\Malware and Spyware Cleaning Guide.URL
[2009/03/20 16:46:18 | 00,499,200 | ---- | C] (OldTimer Tools) -- C:\DOCUME~1\OWNERO~1\Desktop\OTListIt2.exe
[2009/03/20 16:40:51 | 00,000,000 | ---D | C] -- C:\Rooter$
[2009/03/20 16:40:30 | 00,267,612 | ---- | C] () -- C:\DOCUME~1\OWNERO~1\Desktop\Rooter.exe
[2009/03/20 16:38:53 | 00,000,611 | ---- | C] () -- C:\DOCUME~1\OWNERO~1\Desktop\NTREGOPT.lnk
[2009/03/20 16:38:53 | 00,000,592 | ---- | C] () -- C:\DOCUME~1\OWNERO~1\Desktop\ERUNT.lnk
[2009/03/20 16:38:49 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009/03/20 16:36:46 | 00,791,393 | ---- | C] (Lars Hederer ) -- C:\DOCUME~1\OWNERO~1\Desktop\erunt_setup.exe
[2009/03/20 16:29:11 | 00,009,334 | ---- | C] () -- C:\DOCUME~1\OWNERO~1\Desktop\SysRestorePoint_v13.zip
[2009/03/20 16:10:44 | 00,000,000 | -HSD | C] -- C:\RECYCLER
[2009/03/20 15:28:12 | 00,155,384 | ---- | C] () -- C:\WINDOWS\System32\guard32.dll
[2009/03/20 15:28:12 | 00,110,992 | ---- | C] (COMODO) -- C:\WINDOWS\System32\drivers\cmdguard.sys
[2009/03/20 15:28:12 | 00,080,400 | ---- | C] (COMODO) -- C:\WINDOWS\System32\drivers\inspect.sys
[2009/03/20 15:28:12 | 00,024,336 | ---- | C] (COMODO) -- C:\WINDOWS\System32\drivers\cmdhlp.sys
[2009/03/20 15:28:10 | 00,000,000 | ---D | C] -- C:\Program Files\COMODO
[2009/03/20 14:19:21 | 00,000,000 | ---D | C] -- C:\WINDOWS\temp
[2009/03/20 14:15:51 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2009/03/20 14:15:51 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2009/03/20 14:15:51 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2009/03/20 14:15:51 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2009/03/20 14:15:51 | 00,089,504 | ---- | C] (Smallfrogs Studio) -- C:\WINDOWS\fdsv.exe
[2009/03/20 14:15:51 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2009/03/20 14:15:51 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2009/03/20 14:15:51 | 00,049,152 | ---- | C] () -- C:\WINDOWS\VFIND.exe
[2009/03/20 14:15:49 | 00,000,000 | ---D | C] -- C:\ComboFix
[2009/03/19 19:31:27 | 00,002,938 | ---- | C] () -- C:\DOCUME~1\OWNERO~1\Desktop\kaspersky report.html
[2009/03/19 01:28:52 | 00,000,000 | ---D | C] -- C:\VundoFix Backups
[2009/03/17 22:22:15 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Owner One\Application Data\OtakuSoftware
[2009/03/17 22:19:43 | 00,000,000 | ---D | C] -- C:\Program Files\DeskSpace
[2009/03/17 16:21:04 | 00,000,068 | ---- | C] () -- C:\DOCUME~1\OWNERO~1\Desktop\Movies.URL
[2009/03/17 15:15:40 | 00,000,000 | ---D | C] -- C:\DOCUME~1\OWNERO~1\Desktop\crafts
[2009/03/17 15:04:29 | 00,000,426 | ---- | C] () -- C:\WINDOWS\{21D15DED-F125-46C8-8017-CB9F1CEB5B4D}_WiseFW.ini
[2009/03/17 14:45:21 | 00,005,700 | ---- | C] () -- C:\DOCUME~1\OWNERO~1\My Documents\Dark Zune.theme
[2009/03/17 12:40:41 | 00,000,042 | ---- | C] () -- C:\WINDOWS\AlchemyMindworksUpdateList.INI
[2009/03/17 12:36:56 | 00,212,992 | ---- | C] () -- C:\WINDOWS\ALCHUNIN.EXE
[2009/03/17 12:34:08 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Owner One\Application Data\Alchemy Mindworks
[2009/03/13 15:43:28 | 00,045,568 | ---- | C] () -- C:\DOCUME~1\ALLUSE~1\Documents\Anne Shawl.doc
[2009/03/10 19:41:08 | 00,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\{1E65648D-FEE6-4A10-AE6E-FD82DAAE84EB}
[2009/03/10 19:40:43 | 00,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\{30F60971-A986-4BEC-83E3-5D5F2531A590}
[2009/03/10 19:39:06 | 00,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\{438914D2-3454-4B38-AC4F-D34204727071}
[2009/03/10 19:37:38 | 00,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\{C6B2832F-43D8-4E6B-8D87-20BEDCB9687D}
[2009/03/06 19:36:00 | 00,000,000 | ---D | C] -- C:\DOCUME~1\ALLUSE~1\Documents\Crochet with Wire
[2009/03/04 15:38:08 | 00,005,616 | ---- | C] () -- C:\DOCUME~1\OWNERO~1\My Documents\My Favorite Theme.theme
[2009/02/27 20:31:14 | 00,029,112 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2009/02/26 20:07:14 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Owner One\Local Settings\Application Data\Google
[2009/02/26 20:07:13 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\IOSUBSYS
[2009/02/26 20:07:03 | 00,000,000 | ---D | C] -- C:\Program Files\Google
[2009/02/25 08:05:50 | 01,089,593 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ntprint.cat
[2009/02/22 13:49:47 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\XPSViewer
[2009/02/22 13:49:43 | 00,000,000 | ---D | C] -- C:\Program Files\MSBuild
[2009/02/22 13:49:36 | 00,000,000 | ---D | C] -- C:\Program Files\Reference Assemblies
[2009/02/22 13:48:16 | 00,117,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\prntvpt.dll
[2009/02/22 13:48:16 | 00,089,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\filterpipelineprintproc.dll
[2009/02/22 13:48:15 | 01,676,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xpssvcs.dll
[2009/02/22 13:48:15 | 01,676,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xpssvcs.dll
[2009/02/22 13:48:15 | 00,597,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\printfilterpipelinesvc.exe
[2009/02/22 13:48:15 | 00,575,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xpsshhdr.dll
[2009/02/22 13:48:15 | 00,575,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xpsshhdr.dll
[2009/02/22 13:48:14 | 00,000,000 | ---D | C] -- C:\8d60e51be0cadd4069a11a6fffb9
[2009/02/21 21:54:56 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/02/21 17:28:11 | 36,011,174 | ---- | C] () -- C:\DOCUME~1\ALLUSE~1\Documents\Crochet for Dummies.rar
[2009/02/21 12:32:41 | 08,948,869 | ---- | C] () -- C:\DOCUME~1\ALLUSE~1\Documents\crochet patterns for dummies.rar
[2009/02/18 18:03:44 | 00,005,236 | ---- | C] () -- C:\DOCUME~1\OWNERO~1\My Documents\My Faroese Shawl.mht
[2009/02/18 18:02:57 | 00,012,571 | ---- | C] () -- C:\DOCUME~1\OWNERO~1\My Documents\Faroese Shawls.mht
========== Files - Modified Within 30 Days ==========
[2009/03/20 16:48:19 | 00,000,098 | ---- | M] () -- C:\DOCUME~1\OWNERO~1\Desktop\Malware and Spyware Cleaning Guide.URL
[2009/03/20 16:46:18 | 00,499,200 | ---- | M] (OldTimer Tools) -- C:\DOCUME~1\OWNERO~1\Desktop\OTListIt2.exe
[2009/03/20 16:40:30 | 00,267,612 | ---- | M] () -- C:\DOCUME~1\OWNERO~1\Desktop\Rooter.exe
[2009/03/20 16:38:53 | 00,000,611 | ---- | M] () -- C:\DOCUME~1\OWNERO~1\Desktop\NTREGOPT.lnk
[2009/03/20 16:38:53 | 00,000,592 | ---- | M] () -- C:\DOCUME~1\OWNERO~1\Desktop\ERUNT.lnk
[2009/03/20 16:36:47 | 00,791,393 | ---- | M] (Lars Hederer ) -- C:\DOCUME~1\OWNERO~1\Desktop\erunt_setup.exe
[2009/03/20 16:29:11 | 00,009,334 | ---- | M] () -- C:\DOCUME~1\OWNERO~1\Desktop\SysRestorePoint_v13.zip
[2009/03/20 15:56:27 | 00,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/03/20 15:55:54 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/03/20 15:54:22 | 03,651,940 | -H-- | M] () -- C:\Documents and Settings\Owner One\Local Settings\Application Data\IconCache.db
[2009/03/20 15:28:10 | 00,155,384 | ---- | M] () -- C:\WINDOWS\System32\guard32.dll
[2009/03/20 15:28:10 | 00,110,992 | ---- | M] (COMODO) -- C:\WINDOWS\System32\drivers\cmdguard.sys
[2009/03/20 15:28:10 | 00,080,400 | ---- | M] (COMODO) -- C:\WINDOWS\System32\drivers\inspect.sys
[2009/03/20 15:28:10 | 00,024,336 | ---- | M] (COMODO) -- C:\WINDOWS\System32\drivers\cmdhlp.sys
[2009/03/20 14:17:35 | 00,000,246 | ---- | M] () -- C:\WINDOWS\system.ini
[2009/03/20 09:07:11 | 00,000,566 | ---- | M] () -- C:\WINDOWS\win.ini
[2009/03/20 09:07:11 | 00,000,282 | RHS- | M] () -- C:\boot.ini
[2009/03/20 03:08:06 | 00,156,360 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/03/19 20:40:51 | 02,933,805 | R--- | M] () -- C:\DOCUME~1\OWNERO~1\Desktop\ComboFix.exe
[2009/03/19 19:31:27 | 00,002,938 | ---- | M] () -- C:\DOCUME~1\OWNERO~1\Desktop\kaspersky report.html
[2009/03/19 09:22:38 | 00,029,360 | ---- | M] () -- C:\Documents and Settings\Owner One\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/03/17 16:27:31 | 00,500,104 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/03/17 16:27:31 | 00,426,400 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/03/17 16:27:31 | 00,065,284 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/03/17 16:21:04 | 00,000,068 | ---- | M] () -- C:\DOCUME~1\OWNERO~1\Desktop\Movies.URL
[2009/03/17 15:04:40 | 00,000,426 | ---- | M] () -- C:\WINDOWS\{21D15DED-F125-46C8-8017-CB9F1CEB5B4D}_WiseFW.ini
[2009/03/17 14:45:21 | 00,005,700 | ---- | M] () -- C:\DOCUME~1\OWNERO~1\My Documents\Dark Zune.theme
[2009/03/17 12:40:41 | 00,000,042 | ---- | M] () -- C:\WINDOWS\AlchemyMindworksUpdateList.INI
[2009/03/13 15:43:28 | 00,045,568 | ---- | M] () -- C:\DOCUME~1\ALLUSE~1\Documents\Anne Shawl.doc
[2009/03/04 15:38:08 | 00,005,616 | ---- | M] () -- C:\DOCUME~1\OWNERO~1\My Documents\My Favorite Theme.theme
[2009/02/27 20:31:14 | 00,029,112 | -H-- | M] () -- C:\WINDOWS\System32\mlfcache.dat
[2009/02/25 16:54:59 | 24,768,960 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
[2009/02/22 19:23:26 | 00,020,992 | ---- | M] () -- C:\Documents and Settings\Owner One\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/02/21 17:52:16 | 36,011,174 | ---- | M] () -- C:\DOCUME~1\ALLUSE~1\Documents\Crochet for Dummies.rar
[2009/02/21 12:38:41 | 08,948,869 | ---- | M] () -- C:\DOCUME~1\ALLUSE~1\Documents\crochet patterns for dummies.rar
[2009/02/18 18:03:45 | 00,005,236 | ---- | M] () -- C:\DOCUME~1\OWNERO~1\My Documents\My Faroese Shawl.mht
[2009/02/18 18:02:59 | 00,012,571 | ---- | M] () -- C:\DOCUME~1\OWNERO~1\My Documents\Faroese Shawls.mht
========== Alternate Data Streams ==========
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
< End of report >
TIA