GeekPolice
Welcome to GeekPolice.net!

From "wow" to "whoa" - we're teaching practical technology and helping others with tech support. Join our family here!

You are viewing the forum as a "Guest" which doesn't give you member privileges to ask questions or post comments.

Take 30 seconds to register or log in below and unlock the limitations of this website to discover new computer knowledge!

Infected with unknown virus/malware

View previous topic View next topic Go down

Infected with unknown virus/malware

Post by mcp1959 on Sun Sep 26, 2010 9:33 pm

I was trying Kaspersky on a 30 day free trial. On the 2nd day I received an error message which appeared again and again, saying Kaspersky has experienced an error and needed to close. After I would click send/don't send it appeared repeatedly. I attempted to uninstall manually and could not. I removed manually as best I could. I then installed Norton successfully - for a day, not it's also giving me an error message.

I ran Malwarebytes quick scan, nothing. I ran Sysprot Anti-Rootkit and found SYMDS.SYS and
SYMEFA.SYS, which I disabled. Internet works, but I have no Media Player and my search function is corrupted. The OTL file follows; I only received one output file after following the instructions. Your help would be greatly appreciated:

OTL logfile created on: 9/26/2010 5:05:16 PM - Run 2
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Documents and Settings\Emily Safewright.D2LTG0C1\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

478.00 Mb Total Physical Memory | 87.00 Mb Available Physical Memory | 18.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 70.00% Paging File free
Paging file location(s): C:\pagefile.sys 672 1344 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 71.36 Gb Total Space | 41.02 Gb Free Space | 57.49% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: D2LTG0C1
Current User Name: Emily Safewright
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Emily Safewright.D2LTG0C1\desktop\OTL.com (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Norton AntiVirus\Engine\18.1.0.37\ccSvcHst.exe (Symantec Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\dlcxcoms.exe ( )


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Emily Safewright.D2LTG0C1\desktop\OTL.com (OldTimer Tools)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (MDM) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE File not found
SRV - (HidServ) -- C:\WINDOWS\System32\hidserv.dll File not found
SRV - (AVP) -- File not found
SRV - (AppMgmt) -- C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (AOL TopSpeedMonitor) -- C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe File not found
SRV - (AOL ACS) -- C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe File not found
SRV - (NAV) -- C:\Program Files\Norton AntiVirus\Engine\18.1.0.37\ccSvcHst.exe (Symantec Corporation)
SRV - (SeaPort) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (getPlusHelper) getPlus(R) -- C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (fsssvc) -- C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (spupdsvc) -- C:\WINDOWS\system32\spupdsvc.exe (Microsoft Corporation)
SRV - (SNMP) -- C:\WINDOWS\system32\snmp.exe (Microsoft Corporation)
SRV - (dlcx_device) -- C:\WINDOWS\System32\dlcxcoms.exe ( )
SRV - (LPDSVC) -- C:\WINDOWS\system32\tcpsvcs.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (USBAAPL) -- C:\WINDOWS\System32\Drivers\usbaapl.sys File not found
DRV - (MR97310_VGA_DUAL_CAMERA) -- C:\WINDOWS\System32\DRIVERS\mr97310v.sys File not found
DRV - (KProcWatch) -- C:\WINDOWS\System32\drivers\KProcWatch.sys File not found
DRV - (FPAV_RTP) -- C:\WINDOWS\System32\DRIVERS\FStopW.sys File not found
DRV - (NAVEX15) -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20100925.003\navex15.sys (Symantec Corporation)
DRV - (eeCtrl) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (NAVENG) -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20100925.003\naveng.sys (Symantec Corporation)
DRV - (SymEvent) -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (KLIF) -- C:\WINDOWS\system32\drivers\klif.sys (Kaspersky Lab)
DRV - (BHDrvx86) -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\BASHDefs\20100901.003\BHDrvx86.sys (Symantec Corporation)
DRV - (SymEFA) -- C:\WINDOWS\system32\drivers\NAV\1201000.025\SymEFA.sys (Symantec Corporation)
DRV - (SRTSP) -- C:\WINDOWS\system32\drivers\NAV\1201000.025\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) -- C:\WINDOWS\system32\drivers\NAV\1201000.025\SRTSPX.SYS (Symantec Corporation)
DRV - (SYMTDI) -- C:\WINDOWS\system32\drivers\NAV\1201000.025\SYMTDI.SYS (Symantec Corporation)
DRV - (SymIRON) -- C:\WINDOWS\system32\drivers\NAV\1201000.025\Ironx86.SYS (Symantec Corporation)
DRV - (IDSxpx86) -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\IPSDefs\20100924.001\IDSXpx86.sys (Symantec Corporation)
DRV - (SymDS) -- C:\WINDOWS\system32\drivers\NAV\1201000.025\SymDS.sys (Symantec Corporation)
DRV - (kl2) -- C:\WINDOWS\system32\drivers\kl2.sys (Kaspersky Lab ZAO)
DRV - (KL1) -- C:\WINDOWS\system32\DRIVERS\kl1.sys (Kaspersky Lab ZAO)
DRV - (klim5) -- C:\WINDOWS\system32\drivers\klim5.sys (Kaspersky Lab ZAO)
DRV - (SbTis) -- C:\WINDOWS\system32\drivers\sbtis.sys (Sunbelt Software, Inc.)
DRV - (nv) -- C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (sbapifs) -- C:\WINDOWS\system32\drivers\sbapifs.sys (Sunbelt Software)
DRV - (sbaphd) -- C:\WINDOWS\system32\drivers\sbaphd.sys (Sunbelt Software)
DRV - (klmouflt) -- C:\WINDOWS\system32\drivers\klmouflt.sys (Kaspersky Lab)
DRV - (SBRE) -- C:\WINDOWS\system32\drivers\SBREDrv.sys (Sunbelt Software)
DRV - (fssfltr) -- C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (atksgt) -- C:\WINDOWS\system32\drivers\atksgt.sys ()
DRV - (lirsgt) -- C:\WINDOWS\system32\drivers\lirsgt.sys ()
DRV - (usbaudio) USB Audio Driver (WDM) -- C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (amdagp) -- C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) -- C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (HDAudBus) -- C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows (R) Server 2003 DDK provider)
DRV - (MCSTRM) -- C:\WINDOWS\System32\drivers\mcstrm.sys (RealNetworks, Inc.)
DRV - (ASCTRM) -- C:\WINDOWS\System32\drivers\asctrm.sys (Windows (R) 2000 DDK provider)
DRV - (bcm4sbxp) -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (STHDA) -- C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (AmdK8) -- C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
DRV - (DSproct) -- C:\Program Files\Dell Support\GTAction\triggers\DSproct.sys (GTek Technologies Ltd.)
DRV - (DRVMCDB) -- C:\WINDOWS\System32\Drivers\DRVMCDB.SYS (Sonic Solutions)
DRV - (DLAUDFAM) -- C:\WINDOWS\system32\DLA\DLAUDFAM.SYS (Sonic Solutions)
DRV - (DLAUDF_M) -- C:\WINDOWS\system32\DLA\DLAUDF_M.SYS (Sonic Solutions)
DRV - (DLAIFS_M) -- C:\WINDOWS\system32\DLA\DLAIFS_M.SYS (Sonic Solutions)
DRV - (DLABOIOM) -- C:\WINDOWS\system32\DLA\DLABOIOM.SYS (Sonic Solutions)
DRV - (DLAOPIOM) -- C:\WINDOWS\system32\DLA\DLAOPIOM.SYS (Sonic Solutions)
DRV - (DLAPoolM) -- C:\WINDOWS\system32\DLA\DLAPoolM.SYS (Sonic Solutions)
DRV - (DLADResN) -- C:\WINDOWS\system32\DLA\DLADResN.SYS (Sonic Solutions)
DRV - (DLACDBHM) -- C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Sonic Solutions)
DRV - (DLARTL_N) -- C:\WINDOWS\system32\drivers\DLARTL_N.SYS (Sonic Solutions)
DRV - (DRVNDDM) -- C:\WINDOWS\system32\drivers\DRVNDDM.SYS (Sonic Solutions)
DRV - (HSFHWBS2) -- C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) -- C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (wanatw) WAN Miniport (ATW) -- C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (Sparrow) -- C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) -- C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) -- C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) -- C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) -- C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (MODEMCSA) -- C:\WINDOWS\system32\drivers\MODEMCSA.sys (Microsoft Corporation)
DRV - (ultra) -- C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) -- C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) -- C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) -- C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) -- C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) -- C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) -- C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) -- C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) -- C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) -- C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = [You must be registered and logged in to see this link.]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = [You must be registered and logged in to see this link.]

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = [You must be registered and logged in to see this link.]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = [You must be registered and logged in to see this link.]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = D8 84 6D 04 C7 B1 CA 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.alltheweb.com/"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.825

FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\IPSFFPlgn\ [2010/09/25 18:33:16 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/09/17 06:19:44 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/09/26 17:00:57 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
FF - HKLM\software\mozilla\Thunderbird\Extensions\\{eea12ec4-729d-4703-bc37-106ce9879ce2}: C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\THBExt

[2010/03/15 13:08:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emily Safewright.D2LTG0C1\Application Data\Mozilla\Extensions
[2009/07/17 09:20:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emily Safewright.D2LTG0C1\Application Data\Mozilla\Extensions\mozswing@mozswing.org
[2010/06/21 21:41:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emily Safewright.D2LTG0C1\Application Data\Mozilla\Firefox\Profiles\nq4k36jh.default\extensions
[2010/04/27 20:48:06 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Emily Safewright.D2LTG0C1\Application Data\Mozilla\Firefox\Profiles\nq4k36jh.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/07/04 14:00:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emily Safewright.D2LTG0C1\Application Data\Mozilla\Firefox\Profiles\nq4k36jh.default\extensions\toolbar@ask.com
[2010/09/26 17:01:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emily Safewright.D2LTG0C1\Application Data\Mozilla\Firefox\Profiles\x6rmhy2x.booger\extensions
[2010/06/28 11:39:36 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Emily Safewright.D2LTG0C1\Application Data\Mozilla\Firefox\Profiles\x6rmhy2x.booger\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/09/26 17:02:18 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/09/26 17:01:07 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2007/01/23 21:41:00 | 000,800,344 | ---- | M] (America Online, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npampx3.0.84.2.dll
[2008/06/18 03:43:04 | 000,086,016 | ---- | M] (Coupons, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
[2010/09/26 17:00:36 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2007/01/04 18:41:16 | 000,114,688 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\npmozax.dll
[2010/01/13 18:46:00 | 000,063,488 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npwachk.dll

O1 HOSTS File: ([2010/09/20 18:57:12 | 000,419,339 | R--- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 [You must be registered and logged in to see this link.]
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 [You must be registered and logged in to see this link.]
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 [You must be registered and logged in to see this link.]
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 [You must be registered and logged in to see this link.]
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 [You must be registered and logged in to see this link.]
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 [You must be registered and logged in to see this link.]
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 [You must be registered and logged in to see this link.]
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 [You must be registered and logged in to see this link.]
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 [You must be registered and logged in to see this link.]
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 [You must be registered and logged in to see this link.]
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 [You must be registered and logged in to see this link.]
O1 - Hosts: 14471 more lines...
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - Reg Error: Value error. File not found
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\18.1.0.37\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - Reg Error: Value error. File not found
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (no name) - 8EAB99C9-F9EC-4b64-A4BA-D9BCAE8779C2 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O4 - HKLM..\Run: [DLCXCATS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCXtime.DLL ()
O4 - HKLM..\Run: [dlcxmon.exe] C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe ()
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKCU..\Run: [cdloader] C:\Documents and Settings\Emily Safewright.D2LTG0C1\Application Data\mjusbsp\cdloader2.exe (magicJack L.P.)
O4 - HKCU..\Run: [igndlm.exe] C:\Program Files\Download Manager\dlm.exe (IGN Entertainment)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: nousernameinstartmenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: nosimplestartmenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: nostartmenumoreprograms = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: nochangestartmenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: norecentdochistory = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: maxrecentdocs = 0
O9 - Extra Button: &Virtual Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - Reg Error: Value error. File not found
O9 - Extra Button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - Reg Error: Value error. File not found
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} [You must be registered and logged in to see this link.] (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} [You must be registered and logged in to see this link.] (Java Plug-in 1.6.0_21)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} [You must be registered and logged in to see this link.] (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} [You must be registered and logged in to see this link.] (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} [You must be registered and logged in to see this link.] (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} [You must be registered and logged in to see this link.] (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [You must be registered and logged in to see this link.] (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} [You must be registered and logged in to see this link.] (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} [You must be registered and logged in to see this link.] (get_atlcom Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 68.87.68.166 68.87.74.166
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll) - C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\klogon: DllName - C:\WINDOWS\system32\klogon.dll - C:\WINDOWS\system32\klogon.dll (Kaspersky Lab ZAO)
O24 - Desktop WallPaper: C:\Documents and Settings\Emily Safewright.D2LTG0C1\Application Data\IrfanView\IrfanView_Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Emily Safewright.D2LTG0C1\Application Data\IrfanView\IrfanView_Wallpaper.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 14:04:08 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\E\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\autorun.exe -- File not found
O33 - MountPoints2\E\Shell\phone\command - "" = E:\autorun.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

MsConfig - Services: "WZCSVC"
MsConfig - Services: "ImapiService"
MsConfig - Services: "Fax"
MsConfig - Services: "AOL TopSpeedMonitor"
MsConfig - Services: "AOL ACS"
MsConfig - State: "system.ini" - 0
MsConfig - State: "win.ini" - 0
MsConfig - State: "bootini" - 0
MsConfig - State: "services" - 2
MsConfig - State: "startup" - 0

SafeBootMin: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: MCODS - Service
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: SBAMSvc - Service
SafeBootMin: SBPIMSvc - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sermouse.sys - Driver
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vds - Service
SafeBootMin: vga.sys - Driver
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

SafeBootNet: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: MCODS - Service
SafeBootNet: MpfService - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: SBAMSvc - Service
SafeBootNet: SBPIMSvc - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sermouse.sys - Driver
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vga.sys - Driver
SafeBootNet: vsmon - Service
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

ActiveX: {0291E591-EA41-4c82-8106-3DC6CE7F7664} - Reg Error: Value error.
ActiveX: {03F998B2-0E00-11D3-A498-00104B6EB52E} - Viewpoint Media Player
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vector Graphics Rendering (VML)
ActiveX: {1B00725B-C455-4DE6-BFB6-AD540AD427CD} - Viewpoint Media Player
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4
ActiveX: {233C1507-6A77-46A4-9443-F871F945D258} - Adobe Shockwave Director 11.0
ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation
ActiveX: {2A202491-F00D-11cf-87CC-0020AFEECF20} - Adobe Shockwave Director 11.0
ActiveX: {2A3320D6-C805-4280-B423-B665BDE33D8F} - Microsoft .NET Framework 1.1 Security Update (KB979906)
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} - Reg Error: Value error.
ActiveX: {347B0667-C7ED-429B-BDE3-CC8D3BACAA31} - Reg Error: Value error.
ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML Data Binding for Java
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe
ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Advanced Authoring
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7131646D-CD3C-40F4-97B9-CD9E4E6262EF} - .NET Framework
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Web Folders
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install
ActiveX: {8b15971b-5355-4c82-8c07-7e181ea07608} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\fxsocm.inf,Fax.Install.PerUser
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {94de52c8-2d59-4f1b-883e-79663d2d9a8c} - Fax Provider
ActiveX: {B508B3F1-A24A-32C0-B310-85786919EF28} - .NET Framework
ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework
ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Task Scheduler
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - Reg Error: Value error.
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {ECD292A0-0347-4244-8C24-5DBCE990FB40} - Hotfix for Microsoft .NET Framework 3.0 (KB932471)
ActiveX: {EF289A85-8E57-408d-BE47-73B55609861A} - RootsUpdate
ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE
ActiveX: Microsoft Base Smart Card Crypto Provider Package -

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.siren - C:\WINDOWS\System32\sirenacm.dll (Microsoft Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)

========== Files/Folders - Created Within 30 Days ==========

[2010/09/26 17:03:46 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Emily Safewright.D2LTG0C1\Desktop\OTL.com
[2010/09/26 17:01:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sun
[2010/09/26 17:00:57 | 000,423,656 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deployJava1.dll
[2010/09/26 17:00:57 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2010/09/26 17:00:56 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2010/09/26 17:00:56 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2010/09/26 13:03:36 | 000,014,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spmsg.dll
[2010/09/26 12:49:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[2010/09/26 12:27:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\ICS
[2010/09/26 12:27:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\LMI65.tmp
[2010/09/26 12:27:11 | 000,895,216 | ---- | C] (LogMeIn, Inc.) -- C:\Documents and Settings\Emily Safewright.D2LTG0C1\Desktop\Support-LogMeInRescue.exe
[2010/09/26 12:02:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emily Safewright.D2LTG0C1\Application Data\Tific
[2010/09/25 18:32:33 | 000,126,512 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2010/09/25 18:32:33 | 000,060,808 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\S32EVNT1.DLL
[2010/09/25 18:32:32 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Symantec Shared
[2010/09/25 18:32:32 | 000,000,000 | ---D | C] -- C:\Program Files\Symantec
[2010/09/25 18:32:17 | 000,666,672 | R--- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NAV\1201000.025\SymEFA.sys
[2010/09/25 18:32:17 | 000,369,072 | R--- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NAV\1201000.025\symtdi.sys
[2010/09/25 18:32:17 | 000,339,504 | R--- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NAV\1201000.025\SymDS.sys
[2010/09/25 18:32:17 | 000,331,312 | R--- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NAV\1201000.025\symtdiv.sys
[2010/09/25 18:32:17 | 000,294,448 | R--- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NAV\1201000.025\symnets.sys
[2010/09/25 18:32:16 | 000,489,008 | R--- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NAV\1201000.025\srtsp.sys
[2010/09/25 18:32:16 | 000,134,704 | R--- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NAV\1201000.025\Ironx86.sys
[2010/09/25 18:32:16 | 000,050,096 | R--- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NAV\1201000.025\srtspx.sys
[2010/09/25 18:31:43 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\NAV
[2010/09/25 18:31:43 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\NAV\1201000.025
[2010/09/25 18:31:40 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Sidebar
[2010/09/25 18:31:40 | 000,000,000 | ---D | C] -- C:\Program Files\Norton AntiVirus
[2010/09/25 18:31:18 | 000,000,000 | ---D | C] -- C:\Program Files\NortonInstaller
[2010/09/20 20:03:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
[2010/09/20 20:03:30 | 000,475,736 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\klif.sys
[2010/09/20 19:38:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
[2010/03/23 10:47:03 | 000,323,584 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcxhcp.dll
[2010/03/23 10:47:02 | 000,413,696 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcxinpa.dll
[2010/03/23 10:47:02 | 000,397,312 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcxiesc.dll
[2010/03/23 10:47:01 | 000,991,232 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcxusb1.dll
[2010/03/23 10:47:00 | 001,224,704 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcxserv.dll
[2010/03/23 10:46:59 | 000,643,072 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcxpmui.dll
[2010/03/23 10:46:59 | 000,163,840 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcxprox.dll
[2010/03/23 10:46:59 | 000,094,208 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcxpplc.dll
[2010/03/23 10:46:58 | 000,585,728 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcxlmpm.dll
[2010/03/23 10:46:53 | 000,696,320 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcxhbn3.dll
[2010/03/23 10:46:44 | 000,684,032 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcxcomc.dll
[2010/03/23 10:46:44 | 000,421,888 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcxcomm.dll
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/09/26 17:03:48 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Emily Safewright.D2LTG0C1\Desktop\OTL.com
[2010/09/26 17:01:05 | 000,000,256 | ---- | M] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2010/09/26 17:00:36 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2010/09/26 17:00:36 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2010/09/26 17:00:36 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2010/09/26 17:00:36 | 000,073,728 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javacpl.cpl
[2010/09/26 17:00:35 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deployJava1.dll
[2010/09/26 16:55:10 | 000,000,444 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{74E3B3F6-800A-4959-AFFA-7DCF0B91911E}.job
[2010/09/26 13:04:08 | 000,000,782 | ---- | M] () -- C:\Documents and Settings\Emily Safewright.D2LTG0C1\Desktop\Windows Media Player.lnk
[2010/09/26 13:03:23 | 000,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
[2010/09/26 13:03:23 | 000,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
[2010/09/26 13:02:08 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010/09/26 13:00:01 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/09/26 12:57:31 | 000,537,820 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010/09/26 12:57:31 | 000,452,328 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/09/26 12:57:31 | 000,076,308 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/09/26 12:45:02 | 000,000,435 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.ics
[2010/09/26 12:44:58 | 000,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx
[2010/09/26 12:44:04 | 000,271,490 | ---- | M] () -- C:\WINDOWS\System32\NvApps.xml
[2010/09/26 12:44:01 | 000,000,334 | ---- | M] () -- C:\WINDOWS\tasks\GlaryInitialize.job
[2010/09/26 12:43:49 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/09/26 12:43:42 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/09/26 12:42:55 | 011,010,048 | ---- | M] () -- C:\Documents and Settings\Emily Safewright.D2LTG0C1\NTUSER.DAT
[2010/09/26 12:27:07 | 000,895,216 | ---- | M] (LogMeIn, Inc.) -- C:\Documents and Settings\Emily Safewright.D2LTG0C1\Desktop\Support-LogMeInRescue.exe
[2010/09/26 11:47:49 | 000,685,958 | ---- | M] () -- C:\WINDOWS\System32\drivers\NAV\1201000.025\Cat.DB
[2010/09/26 11:41:52 | 000,000,568 | ---- | M] () -- C:\WINDOWS\win.ini
[2010/09/26 10:44:46 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf
[2010/09/25 18:32:32 | 000,126,512 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2010/09/25 18:32:32 | 000,060,808 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\S32EVNT1.DLL
[2010/09/25 18:32:32 | 000,007,456 | ---- | M] () -- C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2010/09/25 18:32:32 | 000,000,805 | ---- | M] () -- C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2010/09/25 18:32:22 | 000,001,885 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Norton AntiVirus.LNK
[2010/09/25 17:40:59 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Emily Safewright.D2LTG0C1\ntuser.ini
[2010/09/25 09:19:00 | 000,000,288 | ---- | M] () -- C:\WINDOWS\tasks\America Online 9.job
[2010/09/21 20:38:27 | 000,293,376 | ---- | M] () -- C:\Documents and Settings\Emily Safewright.D2LTG0C1\Desktop\2ixx0b8z.exe
[2010/09/20 20:21:05 | 000,475,736 | ---- | M] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\klif.sys
[2010/09/20 20:05:41 | 000,113,933 | ---- | M] () -- C:\WINDOWS\System32\drivers\klin.dat
[2010/09/20 20:05:41 | 000,097,549 | ---- | M] () -- C:\WINDOWS\System32\drivers\klick.dat
[2010/09/20 19:34:29 | 000,002,577 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2010/09/20 18:57:12 | 000,419,339 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010/09/20 08:30:03 | 000,000,144 | ---- | M] () -- C:\WINDOWS\PG3prefs.ini
[2010/09/20 06:59:00 | 000,000,384 | ---- | M] () -- C:\WINDOWS\tasks\Disk Cleanup.job
[2010/09/20 00:21:00 | 000,000,314 | ---- | M] () -- C:\WINDOWS\tasks\Yahoo! Messenger.job
[2010/09/19 09:59:09 | 000,064,512 | ---- | M] () -- C:\Documents and Settings\Emily Safewright.D2LTG0C1\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/13 10:43:11 | 000,000,675 | ---- | M] () -- C:\Documents and Settings\Emily Safewright.D2LTG0C1\Desktop\Glary Utilities.lnk
[2010/09/04 10:43:05 | 000,001,729 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 8.lnk
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]


mcp1959
Novice
Novice

Status :
Online
Offline

Posts : 30
Joined : 2010-09-26
OS : XP
Points : 22970
# Likes : 0

View user profile

Back to top Go down

Re: Infected with unknown virus/malware

Post by mcp1959 on Sun Sep 26, 2010 9:34 pm

remaining text follows:

========== Files Created - No Company Name ==========

[2010/09/26 13:04:08 | 000,000,782 | ---- | C] () -- C:\Documents and Settings\Emily Safewright.D2LTG0C1\Desktop\Windows Media Player.lnk
[2010/09/26 11:52:24 | 000,023,392 | ---- | C] () -- C:\WINDOWS\System32\nscompat.tlb
[2010/09/26 11:52:24 | 000,016,832 | ---- | C] () -- C:\WINDOWS\System32\amcompat.tlb
[2010/09/25 18:32:42 | 000,685,958 | ---- | C] () -- C:\WINDOWS\System32\drivers\NAV\1201000.025\Cat.DB
[2010/09/25 18:32:33 | 000,007,456 | ---- | C] () -- C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2010/09/25 18:32:33 | 000,000,805 | ---- | C] () -- C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2010/09/25 18:32:22 | 000,001,885 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Norton AntiVirus.LNK
[2010/09/25 18:31:54 | 000,003,373 | R--- | C] () -- C:\WINDOWS\System32\drivers\NAV\1201000.025\SymEFA.inf
[2010/09/25 18:31:54 | 000,002,792 | R--- | C] () -- C:\WINDOWS\System32\drivers\NAV\1201000.025\SymDS.inf
[2010/09/25 18:31:54 | 000,001,473 | R--- | C] () -- C:\WINDOWS\System32\drivers\NAV\1201000.025\SymNetV.inf
[2010/09/25 18:31:54 | 000,001,445 | R--- | C] () -- C:\WINDOWS\System32\drivers\NAV\1201000.025\SymNet.inf
[2010/09/25 18:31:54 | 000,001,389 | R--- | C] () -- C:\WINDOWS\System32\drivers\NAV\1201000.025\srtspx.inf
[2010/09/25 18:31:54 | 000,001,383 | R--- | C] () -- C:\WINDOWS\System32\drivers\NAV\1201000.025\srtsp.inf
[2010/09/25 18:31:54 | 000,000,741 | R--- | C] () -- C:\WINDOWS\System32\drivers\NAV\1201000.025\Iron.inf
[2010/09/25 18:31:44 | 000,007,787 | R--- | C] () -- C:\WINDOWS\System32\drivers\NAV\1201000.025\symnetv.cat
[2010/09/25 18:31:44 | 000,007,446 | R--- | C] () -- C:\WINDOWS\System32\drivers\NAV\1201000.025\SymNet.cat
[2010/09/25 18:31:44 | 000,007,444 | R--- | C] () -- C:\WINDOWS\System32\drivers\NAV\1201000.025\SymEFA.cat
[2010/09/25 18:31:44 | 000,007,442 | R--- | C] () -- C:\WINDOWS\System32\drivers\NAV\1201000.025\srtspx.cat
[2010/09/25 18:31:44 | 000,007,438 | R--- | C] () -- C:\WINDOWS\System32\drivers\NAV\1201000.025\SymDS.cat
[2010/09/25 18:31:44 | 000,007,438 | R--- | C] () -- C:\WINDOWS\System32\drivers\NAV\1201000.025\srtsp.cat
[2010/09/25 18:31:44 | 000,007,438 | R--- | C] () -- C:\WINDOWS\System32\drivers\NAV\1201000.025\iron.cat
[2010/09/25 18:31:43 | 000,000,172 | ---- | C] () -- C:\WINDOWS\System32\drivers\NAV\1201000.025\isolate.ini
[2010/09/21 20:38:31 | 000,293,376 | ---- | C] () -- C:\Documents and Settings\Emily Safewright.D2LTG0C1\Desktop\2ixx0b8z.exe
[2010/09/20 20:05:41 | 000,113,933 | ---- | C] () -- C:\WINDOWS\System32\drivers\klin.dat
[2010/09/20 20:05:41 | 000,097,549 | ---- | C] () -- C:\WINDOWS\System32\drivers\klick.dat
[2010/07/31 10:34:50 | 000,000,127 | ---- | C] () -- C:\Documents and Settings\Emily Safewright.D2LTG0C1\Application Data\netstat.bat
[2010/03/23 10:49:49 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\dlcxvs.dll
[2010/03/23 10:49:37 | 000,344,064 | ---- | C] () -- C:\WINDOWS\System32\dlcxcoin.dll
[2010/03/23 10:48:58 | 000,692,224 | ---- | C] () -- C:\WINDOWS\System32\dlcxdrs.dll
[2010/03/23 10:48:58 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\dlcxcaps.dll
[2010/03/23 10:48:57 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\dlcxcnv4.dll
[2010/03/23 10:47:03 | 000,274,432 | ---- | C] () -- C:\WINDOWS\System32\dlcxinst.dll
[2010/03/23 10:47:01 | 000,454,656 | ---- | C] () -- C:\WINDOWS\System32\dlcxutil.dll
[2010/03/23 10:46:58 | 000,176,128 | ---- | C] () -- C:\WINDOWS\System32\dlcxinsb.dll
[2010/03/23 10:46:58 | 000,139,264 | ---- | C] () -- C:\WINDOWS\System32\dlcxjswr.dll
[2010/03/23 10:46:57 | 000,176,128 | ---- | C] () -- C:\WINDOWS\System32\dlcxins.dll
[2010/03/23 10:46:57 | 000,106,496 | ---- | C] () -- C:\WINDOWS\System32\dlcxinsr.dll
[2010/03/23 10:46:53 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\dlcxgrd.dll
[2010/03/23 10:46:51 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\dlcxcub.dll
[2010/03/23 10:46:51 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\dlcxcu.dll
[2010/03/23 10:46:51 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\dlcxcur.dll
[2010/03/23 10:46:32 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\DLCXcfg.dll
[2010/02/09 17:43:22 | 000,000,000 | ---- | C] () -- C:\WINDOWS\iPlayer.INI
[2010/01/12 21:08:38 | 000,323,584 | ---- | C] () -- C:\WINDOWS\System32\FoxImager.dll
[2009/11/01 09:21:45 | 000,000,036 | ---- | C] () -- C:\Documents and Settings\Emily Safewright.D2LTG0C1\Local Settings\Application Data\housecall.guid.cache
[2009/10/16 21:17:19 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll
[2008/11/29 13:14:43 | 000,271,360 | ---- | C] () -- C:\WINDOWS\System32\drivers\atksgt.sys
[2008/11/29 13:14:40 | 000,018,048 | ---- | C] () -- C:\WINDOWS\System32\drivers\lirsgt.sys
[2008/09/11 10:03:13 | 000,000,000 | ---- | C] () -- C:\WINDOWS\PTWebCam.INI
[2008/06/28 20:11:58 | 000,000,144 | ---- | C] () -- C:\WINDOWS\PG3prefs.ini
[2008/06/11 20:23:45 | 000,063,488 | ---- | C] () -- C:\WINDOWS\xobglu16.dll
[2008/06/11 20:23:45 | 000,023,552 | ---- | C] () -- C:\WINDOWS\xobglu32.dll
[2008/06/11 20:22:39 | 000,000,060 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2008/06/11 20:22:35 | 000,000,068 | ---- | C] () -- C:\WINDOWS\KA.INI
[2008/05/02 15:10:52 | 000,000,056 | RHS- | C] () -- C:\WINDOWS\System32\50B3B90E9B.sys
[2008/05/02 14:29:49 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\DLPRMON.DLL
[2008/05/02 14:29:49 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\DLPMONUI.DLL
[2008/04/15 11:30:10 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2008/02/01 10:06:06 | 000,000,000 | ---- | C] () -- C:\WINDOWS\SETUP32.INI
[2008/01/17 08:35:58 | 000,000,148 | ---- | C] () -- C:\WINDOWS\STATDEM.INI
[2008/01/04 19:44:54 | 000,000,520 | ---- | C] () -- C:\WINDOWS\netdet.ini
[2007/12/29 10:47:38 | 000,000,080 | RHS- | C] () -- C:\WINDOWS\System32\50B3B90E9B.dll
[2007/10/21 23:36:07 | 000,001,356 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/10/11 22:40:18 | 000,064,512 | ---- | C] () -- C:\Documents and Settings\Emily Safewright.D2LTG0C1\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/10/09 23:11:33 | 000,000,492 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2007/10/08 21:08:36 | 000,106,496 | ---- | C] () -- C:\WINDOWS\System32\TPActiveX.dll
[2007/10/04 06:40:33 | 000,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2007/10/03 02:47:48 | 000,003,584 | ---- | C] () -- C:\Documents and Settings\Emily Safewright.D2LTG0C1\Application Data\dvd.bmk
[2007/10/03 02:42:56 | 000,000,148 | ---- | C] () -- C:\Documents and Settings\Emily Safewright.D2LTG0C1\Local Settings\Application Data\fusioncache.dat
[2006/12/20 15:40:16 | 000,000,029 | ---- | C] () -- C:\WINDOWS\atid.ini
[2006/12/09 01:14:21 | 000,005,852 | -HS- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2006/12/09 01:14:21 | 000,000,088 | RHS- | C] () -- C:\WINDOWS\System32\EEA1BBBC51.sys
[2006/10/25 19:44:56 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006/10/25 19:40:39 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/10/25 19:10:50 | 000,581,632 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2006/10/25 19:10:50 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2006/10/25 19:10:44 | 000,000,394 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2005/11/10 09:56:34 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2004/08/10 14:12:05 | 000,000,780 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2004/08/10 14:01:18 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini

========== Custom Scans ==========


< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[3 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\*.exe /lockedfiles >
[3 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2004/08/10 13:56:48 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2004/08/10 13:56:46 | 000,634,880 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2004/08/10 13:56:46 | 000,872,448 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav

< %systemroot%\system32\*.sys >
[2008/05/02 15:10:52 | 000,000,056 | RHS- | M] () -- C:\WINDOWS\system32\50B3B90E9B.sys
[2004/08/04 06:00:00 | 000,009,029 | ---- | M] () -- C:\WINDOWS\system32\ansi.sys
[2004/08/04 06:00:00 | 000,027,097 | ---- | M] () -- C:\WINDOWS\system32\country.sys
[2005/03/13 17:54:00 | 000,006,656 | ---- | M] (GTek Technologies Ltd.) -- C:\WINDOWS\system32\DLPT2.sys
[2007/01/04 11:27:06 | 000,000,088 | RHS- | M] () -- C:\WINDOWS\system32\EEA1BBBC51.sys
[2005/02/08 13:37:52 | 000,007,626 | ---- | M] (Gteko Ltd.) -- C:\WINDOWS\system32\GPCIEnum.sys
[2004/06/15 16:55:56 | 000,007,882 | ---- | M] (Gteko Ltd.) -- C:\WINDOWS\system32\GTKCMOS.sys
[2004/08/04 06:00:00 | 000,004,768 | ---- | M] () -- C:\WINDOWS\system32\himem.sys
[2004/08/04 06:00:00 | 000,042,809 | ---- | M] () -- C:\WINDOWS\system32\key01.sys
[2004/08/04 06:00:00 | 000,042,537 | ---- | M] () -- C:\WINDOWS\system32\keyboard.sys
[2008/05/02 18:10:52 | 000,005,852 | -HS- | M] () -- C:\WINDOWS\system32\KGyGaAvL.sys
[2004/08/04 06:00:00 | 000,027,866 | ---- | M] () -- C:\WINDOWS\system32\ntdos.sys
[2004/08/04 06:00:00 | 000,029,146 | ---- | M] () -- C:\WINDOWS\system32\ntdos404.sys
[2004/08/04 06:00:00 | 000,029,370 | ---- | M] () -- C:\WINDOWS\system32\ntdos411.sys
[2004/08/04 06:00:00 | 000,029,274 | ---- | M] () -- C:\WINDOWS\system32\ntdos412.sys
[2004/08/04 06:00:00 | 000,029,146 | ---- | M] () -- C:\WINDOWS\system32\ntdos804.sys
[2004/08/04 06:00:00 | 000,033,840 | ---- | M] () -- C:\WINDOWS\system32\ntio.sys
[2004/08/04 06:00:00 | 000,034,560 | ---- | M] () -- C:\WINDOWS\system32\ntio404.sys
[2004/08/04 06:00:00 | 000,035,648 | ---- | M] () -- C:\WINDOWS\system32\ntio411.sys
[2004/08/04 06:00:00 | 000,035,424 | ---- | M] () -- C:\WINDOWS\system32\ntio412.sys
[2004/08/04 06:00:00 | 000,034,560 | ---- | M] () -- C:\WINDOWS\system32\ntio804.sys
[2008/04/13 14:44:59 | 000,017,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\watchdog.sys
[2010/06/23 09:44:04 | 001,851,904 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\win32k.sys
[3 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\drivers\*.dll >
[2008/04/13 20:11:48 | 000,004,255 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv01nt5.dll
[2008/04/13 20:11:48 | 000,003,967 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv02nt5.dll
[2008/04/13 20:11:48 | 000,003,615 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv05nt5.dll
[2008/04/13 20:11:48 | 000,003,647 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv07nt5.dll
[2008/04/13 20:11:48 | 000,003,135 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv08nt5.dll
[2008/04/13 20:11:48 | 000,003,711 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv09nt5.dll
[2008/04/13 20:11:48 | 000,003,775 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv11nt5.dll
[2008/04/13 20:11:50 | 000,021,183 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv01nt5.dll
[2008/04/13 20:11:50 | 000,011,359 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv02nt5.dll
[2008/04/13 20:11:50 | 000,025,471 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv04nt5.dll
[2008/04/13 20:11:50 | 000,014,143 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv06nt5.dll
[2008/04/13 20:11:50 | 000,017,279 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv10nt5.dll
[2008/04/13 20:11:50 | 000,015,423 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\ch7xxnt5.dll
[2008/04/13 20:12:05 | 000,003,901 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\siint5.dll
[2008/04/13 20:12:08 | 000,011,325 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\vchnt5.dll

< %systemroot%\system32\drivers\*.ini >

< %systemroot%\system32\drivers\*.exe >

< %SYSTEMDRIVE%\*.* >
[2010/07/08 20:44:54 | 000,079,680 | ---- | M] () -- C:\800px-Koh_Samui_Lipa_Noi2.jpg
[2010/07/17 18:11:31 | 000,127,559 | ---- | M] () -- C:\800px-Salem_witch2.jpg
[2010/06/16 21:46:41 | 000,000,073 | ---- | M] () -- C:\AskScreen.ini
[2004/08/10 14:04:08 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2010/03/15 07:45:12 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2010/05/17 21:12:48 | 001,637,799 | ---- | M] () -- C:\Broadway_tower_edit.jpg
[2010/09/25 18:20:41 | 000,003,324 | ---- | M] () -- C:\CD3rdPartyWrapper.log
[2007/12/28 20:28:51 | 000,000,455 | ---- | M] () -- C:\checksystem.log
[2004/08/10 14:04:08 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2010/08/23 17:25:39 | 000,159,674 | ---- | M] () -- C:\delaware.jpg
[2006/10/25 19:14:36 | 000,005,803 | RH-- | M] () -- C:\dell.sdr
[2010/04/20 21:39:53 | 005,242,691 | ---- | M] () -- C:\Dharmaraya_Swamy_Temple_Bangalore_edit1.jpg
[2010/07/11 15:51:59 | 000,184,454 | ---- | M] () -- C:\dlcx.log
[2010/05/25 17:22:41 | 000,082,297 | ---- | M] () -- C:\Don and Tracy Smileys.jpg
[2010/04/22 14:50:29 | 000,068,540 | ---- | M] () -- C:\Don and Tracy victorian.jpg
[2010/06/08 15:07:54 | 000,047,029 | ---- | M] () -- C:\Don hippie black and white.jpg
[2010/04/22 14:51:43 | 000,061,173 | ---- | M] () -- C:\Don top hat.jpg
[2010/02/17 12:08:07 | 000,000,081 | ---- | M] () -- C:\DVDPATH.TXT
[2010/04/27 20:53:15 | 000,203,647 | ---- | M] () -- C:\galaxy.jpg
[2006/12/14 11:27:00 | 000,004,128 | ---- | M] () -- C:\INFCACHE.1
[2004/08/10 14:04:08 | 000,000,000 | -H-- | M] () -- C:\IO.SYS
[2008/05/06 14:02:06 | 000,000,125 | ---- | M] () -- C:\ioSpecial.ini
[2010/05/15 09:15:28 | 000,909,014 | ---- | M] () -- C:\Jupiter_from_Voyager_1.jpg
[2010/05/07 21:09:53 | 000,583,585 | ---- | M] () -- C:\Last_Moon_Walk_Apollo17_1024x768.jpg
[2010/05/23 08:57:06 | 000,629,699 | ---- | M] () -- C:\Male-total.jpg
[2010/04/30 07:29:04 | 000,000,109 | ---- | M] () -- C:\mbam-error.txt
[2004/08/10 14:04:08 | 000,000,000 | -H-- | M] () -- C:\MSDOS.SYS
[2007/12/05 08:21:54 | 000,001,055 | ---- | M] () -- C:\net_save.dna
[2004/08/04 06:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2008/06/06 12:01:06 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2010/09/26 12:43:36 | 704,643,072 | -HS- | M] () -- C:\pagefile.sys
[2010/06/21 12:37:37 | 001,047,292 | ---- | M] () -- C:\Panthera_tigris_altaica_13_-_Buffalo_Zoo.jpg
[2010/07/09 21:33:40 | 000,036,824 | ---- | M] () -- C:\prairie belt.jpg
[2010/05/11 21:59:48 | 000,055,937 | ---- | M] () -- C:\SAHARA.jpg
[2010/07/17 18:16:11 | 084,439,991 | ---- | M] () -- C:\Salem_witch2.jpg
[2007/10/14 21:04:08 | 000,000,494 | ---- | M] () -- C:\settings.ini
[2008/11/12 20:46:49 | 000,000,232 | -H-- | M] () -- C:\sqmdata00.sqm
[2009/10/25 09:55:18 | 000,000,232 | -H-- | M] () -- C:\sqmdata01.sqm
[2008/11/12 20:46:49 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt00.sqm
[2009/10/25 09:55:18 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt01.sqm
[2010/02/28 15:58:39 | 000,032,768 | ---- | M] () -- C:\t218.1
[2010/02/24 09:17:34 | 000,032,768 | ---- | M] () -- C:\t290.i
[2010/02/23 22:50:23 | 000,032,768 | ---- | M] () -- C:\t2tk.1
[2007/12/09 18:14:37 | 000,028,672 | ---- | M] () -- C:\t3l0.c
[2006/12/11 17:25:28 | 000,000,307 | -H-- | M] () -- C:\T4Metrics.log
[2010/04/22 14:51:18 | 000,072,003 | ---- | M] () -- C:\The mystic spirit long hair.jpg
[2010/04/22 14:52:05 | 000,068,332 | ---- | M] () -- C:\Tracy rock shower.jpg
[2010/04/22 14:49:29 | 000,055,759 | ---- | M] () -- C:\Tracy victorian.jpg
[2010/05/31 21:21:36 | 000,159,507 | ---- | M] () -- C:\waterfall-9j_496l.jpg
[2010/05/13 20:40:18 | 000,018,095 | ---- | M] () -- C:\wolfbird.jpg
[2009/08/07 11:54:55 | 000,033,717 | ---- | M] () -- C:\YServer.txt
[1 C:\*.tmp files -> C:\*.tmp -> ]

< %PROGRAMFILES%\*. >
[2007/02/08 01:31:05 | 000,000,000 | ---D | M] -- C:\Program Files\3B Software
[2009/12/11 09:02:16 | 000,000,000 | ---D | M] -- C:\Program Files\7-Zip
[2010/03/01 20:48:43 | 000,000,000 | ---D | M] -- C:\Program Files\A123 All to mp3 Converter
[2009/09/20 10:53:10 | 000,000,000 | ---D | M] -- C:\Program Files\Activision
[2010/03/08 18:33:35 | 000,000,000 | ---D | M] -- C:\Program Files\Adobe
[2010/04/18 09:22:00 | 000,000,000 | ---D | M] -- C:\Program Files\Alwil Software
[2010/06/26 05:43:17 | 000,000,000 | ---D | M] -- C:\Program Files\AMD
[2010/07/04 14:01:05 | 000,000,000 | ---D | M] -- C:\Program Files\Ask.com
[2010/06/16 23:09:37 | 000,000,000 | ---D | M] -- C:\Program Files\AVG
[2009/10/14 10:04:50 | 000,000,000 | ---D | M] -- C:\Program Files\AVS4YOU
[2010/06/22 12:28:43 | 000,000,000 | ---D | M] -- C:\Program Files\BearShare Applications
[2008/01/28 12:51:46 | 000,000,000 | ---D | M] -- C:\Program Files\bfgclient
[2010/03/08 19:59:32 | 000,000,000 | ---D | M] -- C:\Program Files\Broadcom
[2008/01/21 09:28:38 | 000,000,000 | ---D | M] -- C:\Program Files\Bugatron
[2008/01/25 09:05:24 | 000,000,000 | ---D | M] -- C:\Program Files\Call of Duty Dawnville Demo
[2010/03/01 20:49:14 | 000,000,000 | ---D | M] -- C:\Program Files\Call of Duty Single Player Demo
[2009/04/17 15:01:40 | 000,000,000 | ---D | M] -- C:\Program Files\CD to MP3 Freeware
[2010/03/15 12:26:10 | 000,000,000 | ---D | M] -- C:\Program Files\CheckPoint
[2007/10/15 23:23:01 | 000,000,000 | ---D | M] -- C:\Program Files\Comcast Rhapsody
[2010/09/25 18:32:32 | 000,000,000 | ---D | M] -- C:\Program Files\Common Files
[2006/10/25 19:17:28 | 000,000,000 | ---D | M] -- C:\Program Files\CONEXANT
[2008/12/22 10:49:26 | 000,000,000 | ---D | M] -- C:\Program Files\Coupons
[2008/02/01 10:09:27 | 000,000,000 | ---D | M] -- C:\Program Files\Creative Wonders
[2010/03/23 10:48:53 | 000,000,000 | ---D | M] -- C:\Program Files\Dell
[2010/03/23 10:48:37 | 000,000,000 | ---D | M] -- C:\Program Files\Dell PC Fax
[2010/03/23 10:48:57 | 000,000,000 | ---D | M] -- C:\Program Files\Dell Photo AIO Printer 926
[2006/10/25 19:40:54 | 000,000,000 | ---D | M] -- C:\Program Files\Dell Support
[2007/10/28 10:06:32 | 000,000,000 | ---D | M] -- C:\Program Files\Destroyer Studios
[2006/10/25 19:30:20 | 000,000,000 | ---D | M] -- C:\Program Files\Digital Line Detect
[2010/09/26 12:44:38 | 000,000,000 | ---D | M] -- C:\Program Files\Dl_cats
[2010/03/07 22:43:14 | 000,000,000 | ---D | M] -- C:\Program Files\Download Manager
[2007/10/24 01:13:11 | 000,000,000 | ---D | M] -- C:\Program Files\Drengin.net
[2007/02/24 23:59:33 | 000,000,000 | ---D | M] -- C:\Program Files\eGames
[2010/01/02 11:40:56 | 000,000,000 | ---D | M] -- C:\Program Files\Eidos Interactive
[2007/10/06 22:26:52 | 000,000,000 | ---D | M] -- C:\Program Files\eMusic Remote
[2010/04/04 17:22:17 | 000,000,000 | ---D | M] -- C:\Program Files\Essentials Codec Pack
[2008/11/01 15:08:06 | 000,000,000 | ---D | M] -- C:\Program Files\Free Audio Pack
[2009/10/16 21:18:22 | 000,000,000 | ---D | M] -- C:\Program Files\FreeCDRipper
[2008/09/04 17:52:17 | 000,000,000 | ---D | M] -- C:\Program Files\Freeze.com
[2010/06/09 07:20:02 | 000,000,000 | ---D | M] -- C:\Program Files\Funkitron
[2010/08/15 13:56:48 | 000,000,000 | ---D | M] -- C:\Program Files\Genius 2000
[2010/09/13 10:43:16 | 000,000,000 | ---D | M] -- C:\Program Files\Glary Utilities
[2008/06/29 17:23:58 | 000,000,000 | ---D | M] -- C:\Program Files\Ingenuware
[2010/06/26 05:43:15 | 000,000,000 | -H-D | M] -- C:\Program Files\InstallShield Installation Information
[2006/10/25 19:27:48 | 000,000,000 | ---D | M] -- C:\Program Files\InterActual
[2010/08/12 09:07:57 | 000,000,000 | ---D | M] -- C:\Program Files\Internet Explorer
[2007/10/06 21:07:18 | 000,000,000 | ---D | M] -- C:\Program Files\IrfanView
[2008/06/27 17:27:32 | 000,000,000 | ---D | M] -- C:\Program Files\iTunes
[2010/09/26 17:00:29 | 000,000,000 | ---D | M] -- C:\Program Files\Java
[2010/04/30 07:28:57 | 000,000,000 | ---D | M] -- C:\Program Files\Malwarebytes' Anti-Malware
[2008/08/14 03:07:35 | 000,000,000 | ---D | M] -- C:\Program Files\Messenger
[2010/03/02 09:22:34 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft
[2004/08/10 14:04:18 | 000,000,000 | ---D | M] -- C:\Program Files\microsoft frontpage
[2010/03/02 09:26:01 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Office
[2006/10/25 19:31:36 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Plus! Digital Media Edition
[2010/03/02 09:28:26 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Plus! Photo Story 2 LE
[2010/09/15 17:52:09 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Silverlight
[2008/09/04 18:10:54 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft SQL Server
[2010/01/28 18:31:40 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Sync Framework
[2006/10/25 19:39:46 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Visual Studio
[2008/09/04 18:02:00 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Works
[2007/01/13 15:59:25 | 000,000,000 | ---D | M] -- C:\Program Files\Modem Diagnostic Tool
[2010/08/12 09:02:11 | 000,000,000 | ---D | M] -- C:\Program Files\Movie Maker
[2010/09/22 19:07:40 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox
[2007/02/17 11:26:55 | 000,000,000 | ---D | M] -- C:\Program Files\MP3 Rocket
[2007/10/17 02:21:33 | 000,000,000 | ---D | M] -- C:\Program Files\MSBuild
[2007/02/17 11:23:22 | 000,000,000 | ---D | M] -- C:\Program Files\MSN
[2004/08/10 14:01:24 | 000,000,000 | ---D | M] -- C:\Program Files\MSN Gaming Zone
[2009/04/17 15:01:40 | 000,000,000 | ---D | M] -- C:\Program Files\MUSICMATCH
[2008/05/11 13:53:36 | 000,000,000 | ---D | M] -- C:\Program Files\MySpace
[2008/10/08 19:50:53 | 000,000,000 | ---D | M] -- C:\Program Files\Netflix
[2008/06/06 12:05:28 | 000,000,000 | ---D | M] -- C:\Program Files\NetMeeting
[2007/02/17 11:28:29 | 000,000,000 | ---D | M] -- C:\Program Files\NetWaiting
[2010/09/25 18:31:43 | 000,000,000 | ---D | M] -- C:\Program Files\Norton AntiVirus
[2010/09/25 18:31:18 | 000,000,000 | ---D | M] -- C:\Program Files\NortonInstaller
[2010/04/21 09:43:40 | 000,000,000 | ---D | M] -- C:\Program Files\NOS
[2010/02/28 13:05:32 | 000,000,000 | ---D | M] -- C:\Program Files\NVIDIA Corporation
[2007/02/17 11:28:42 | 000,000,000 | ---D | M] -- C:\Program Files\Online Services
[2009/04/17 15:01:40 | 000,000,000 | ---D | M] -- C:\Program Files\OpenOffice.org 3
[2008/10/12 22:05:33 | 000,000,000 | ---D | M] -- C:\Program Files\Opera
[2010/05/11 21:28:59 | 000,000,000 | ---D | M] -- C:\Program Files\Outlook Express
[2008/02/24 10:20:45 | 000,000,000 | ---D | M] -- C:\Program Files\PassAlong
[2008/10/24 09:49:39 | 000,000,000 | ---D | M] -- C:\Program Files\PhoTags Express
[2008/01/04 19:10:58 | 000,000,000 | ---D | M] -- C:\Program Files\Prezzie Hunt
[2010/03/22 13:17:15 | 000,000,000 | ---D | M] -- C:\Program Files\QuickTime
[2008/06/07 19:17:57 | 000,000,000 | ---D | M] -- C:\Program Files\Raven
[2007/10/16 21:55:19 | 000,000,000 | ---D | M] -- C:\Program Files\Real
[2007/10/17 02:16:03 | 000,000,000 | ---D | M] -- C:\Program Files\Reference Assemblies
[2010/09/20 15:46:53 | 000,000,000 | ---D | M] -- C:\Program Files\Return to Castle Wolfenstein DEMO
[2006/10/25 19:36:53 | 000,000,000 | ---D | M] -- C:\Program Files\Roxio
[2010/03/25 10:37:11 | 000,000,000 | ---D | M] -- C:\Program Files\Sateira
[2010/01/08 15:25:45 | 000,000,000 | ---D | M] -- C:\Program Files\Scholastic
[2010/03/22 15:20:44 | 000,000,000 | ---D | M] -- C:\Program Files\Security Task Manager
[2006/10/25 19:28:28 | 000,000,000 | ---D | M] -- C:\Program Files\Sigmatel
[2007/11/06 03:08:28 | 000,000,000 | ---D | M] -- C:\Program Files\Slacker
[2010/03/07 22:42:57 | 000,000,000 | ---D | M] -- C:\Program Files\Spybot - Search & Destroy
[2008/06/28 20:07:42 | 000,000,000 | ---D | M] -- C:\Program Files\SSI
[2009/04/17 15:01:41 | 000,000,000 | ---D | M] -- C:\Program Files\support.com
[2010/09/25 18:32:33 | 000,000,000 | ---D | M] -- C:\Program Files\Symantec
[2007/12/07 12:58:16 | 000,000,000 | ---D | M] -- C:\Program Files\SystemRequirementsLab
[2007/11/26 05:55:29 | 000,000,000 | ---D | M] -- C:\Program Files\THQ
[2008/04/12 22:22:25 | 000,000,000 | ---D | M] -- C:\Program Files\Trend Micro
[2008/01/28 09:51:58 | 000,000,000 | ---D | M] -- C:\Program Files\Unity
[2009/09/04 08:11:12 | 000,000,000 | ---D | M] -- C:\Program Files\Unlocker
[2009/06/21 15:32:09 | 000,000,000 | ---D | M] -- C:\Program Files\Utherverse Digital Inc
[2007/10/03 03:01:58 | 000,000,000 | ---D | M] -- C:\Program Files\Viewpoint
[2009/07/28 20:04:21 | 000,000,000 | ---D | M] -- C:\Program Files\Virtools
[2008/01/11 09:03:03 | 000,000,000 | ---D | M] -- C:\Program Files\WAV to MP3 Encoder
[2010/03/22 13:17:19 | 000,000,000 | ---D | M] -- C:\Program Files\Winamp
[2010/01/24 11:14:30 | 000,000,000 | ---D | M] -- C:\Program Files\Winamp Detect
[2010/01/28 18:33:31 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Live
[2010/01/28 18:21:42 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Live SkyDrive
[2010/09/26 13:03:00 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Connect 2
[2010/09/26 13:02:57 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Player
[2008/06/06 12:05:20 | 000,000,000 | ---D | M] -- C:\Program Files\Windows NT
[2010/09/25 18:31:40 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Sidebar
[2009/01/01 18:49:27 | 000,000,000 | ---D | M] -- C:\Program Files\Wise Registry Cleaner
[2004/08/10 14:04:18 | 000,000,000 | ---D | M] -- C:\Program Files\xerox
[2010/03/04 10:16:12 | 000,000,000 | ---D | M] -- C:\Program Files\Yahoo!

< %appdata%\*.* >
[2004/08/10 13:57:42 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\Emily Safewright.D2LTG0C1\Application Data\desktop.ini
[2007/10/03 15:27:04 | 000,003,584 | ---- | M] () -- C:\Documents and Settings\Emily Safewright.D2LTG0C1\Application Data\dvd.bmk
[2010/07/31 10:34:50 | 000,000,127 | ---- | M] () -- C:\Documents and Settings\Emily Safewright.D2LTG0C1\Application Data\netstat.bat


< MD5 for: AGP440.SYS >
[2004/08/04 06:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\i386\sp2.cab:AGP440.sys
[2004/08/04 06:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/06/06 11:54:39 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008/06/06 11:54:39 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 14:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 14:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\dllcache\agp440.sys
[2008/04/13 14:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
[2004/08/04 00:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\$NtServicePackUninstall$\agp440.sys

< MD5 for: ATAPI.SYS >
[2004/08/04 06:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\i386\sp2.cab:atapi.sys
[2004/08/04 06:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/06/06 11:54:39 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008/06/06 11:54:39 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\dllcache\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/03 23:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys

< MD5 for: DISK.SYS >
[2004/08/04 06:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\i386\sp2.cab:disk.sys
[2004/08/04 06:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:disk.sys
[2008/06/06 11:54:39 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:disk.sys
[2008/06/06 11:54:39 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:disk.sys
[2004/08/04 06:00:00 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=00CA44E4534865F8A3B64F7C0984BFF0 -- C:\WINDOWS\$NtServicePackUninstall$\disk.sys
[2008/04/13 14:40:47 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=044452051F3E02E7963599FC8F4F3E25 -- C:\WINDOWS\ServicePackFiles\i386\disk.sys
[2008/04/13 14:40:47 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=044452051F3E02E7963599FC8F4F3E25 -- C:\WINDOWS\system32\dllcache\disk.sys
[2008/04/13 14:40:47 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=044452051F3E02E7963599FC8F4F3E25 -- C:\WINDOWS\system32\drivers\disk.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/13 20:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 20:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\dllcache\eventlog.dll
[2008/04/13 20:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\eventlog.dll
[2004/08/04 06:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: NETLOGON.DLL >
[2008/04/13 20:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 20:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\dllcache\netlogon.dll
[2008/04/13 20:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\netlogon.dll
[2004/08/04 06:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004/08/04 06:00:00 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\dllcache\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\scecli.dll

< MD5 for: USBSTOR.SYS >
[2004/08/04 06:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\i386\sp2.cab:usbstor.sys
[2004/08/04 06:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:usbstor.sys
[2008/06/06 11:54:39 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:usbstor.sys
[2008/06/06 11:54:39 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:usbstor.sys
[2004/08/04 00:08:48 | 000,026,496 | ---- | M] (Microsoft Corporation) MD5=6CD7B22193718F1D17A47A1CD6D37E75 -- C:\WINDOWS\$NtServicePackUninstall$\usbstor.sys
[2008/04/13 14:45:38 | 000,026,368 | ---- | M] (Microsoft Corporation) MD5=A32426D9B14A089EAA1D922E0C5801A9 -- C:\WINDOWS\ServicePackFiles\i386\usbstor.sys
[2008/04/13 14:45:38 | 000,026,368 | ---- | M] (Microsoft Corporation) MD5=A32426D9B14A089EAA1D922E0C5801A9 -- C:\WINDOWS\system32\dllcache\usbstor.sys
[2008/04/13 14:45:38 | 000,026,368 | ---- | M] (Microsoft Corporation) MD5=A32426D9B14A089EAA1D922E0C5801A9 -- C:\WINDOWS\system32\drivers\usbstor.sys

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-09-26 16:50:11

< >

< >
< End of report >

mcp1959
Novice
Novice

Status :
Online
Offline

Posts : 30
Joined : 2010-09-26
OS : XP
Points : 22970
# Likes : 0

View user profile

Back to top Go down

Re: Infected with unknown virus/malware

Post by Belahzur on Mon Sep 27, 2010 7:44 pm

Please download and run this tool.

Download Malwarebytes' Anti-Malware from [You must be registered and logged in to see this link.]

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately.


Post the contents of the MBAM Log.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre
Points : 245039
# Likes : 1

View user profile

Back to top Go down

Re: Infected with unknown virus/malware

Post by mcp1959 on Tue Sep 28, 2010 7:49 pm

As Requested:

Malwarebytes' Anti-Malware 1.46
[You must be registered and logged in to see this link.]

Database version: 4712

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

9/28/2010 3:41:30 PM
mbam-log-2010-09-28 (15-41-30).txt

Scan type: Quick scan
Objects scanned: 170854
Time elapsed: 13 minute(s), 23 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

mcp1959
Novice
Novice

Status :
Online
Offline

Posts : 30
Joined : 2010-09-26
OS : XP
Points : 22970
# Likes : 0

View user profile

Back to top Go down

Re: Infected with unknown virus/malware

Post by Belahzur on Tue Sep 28, 2010 8:42 pm

Hello.

  • Download combofix from here
    [You must be registered and logged in to see this link.]
    [You must be registered and logged in to see this link.]

    1. If you are using Firefox, make sure that your download settings are as follows:

    * Tools->Options->Main tab
    * Set to "Always ask me where to Save the files".

    2. During the download, rename Combofix to Combo-Fix as follows:





    3. It is important you rename Combofix during the download, but not after.
    4. Please do not rename Combofix to other names, but only to the one indicated.
    5. Close any open browsers.
    6. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

  • We need to disable your local AV (Anti-virus) before running Combofix.
  • See [You must be registered and logged in to see this link.] for how to disable your AV.
  • Double click on ComboFix.exe.
  • Follow the prompts. NOTE:
  • ComboFix will check to see if the Microsoft Windows Recovery Console is installed.
    ***It's strongly recommended to have the Recovery Console installed before doing any malware removal.***

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will automatically proceed with its scan.


  • The Recovery Console provides a recovery/repair mode should a problem occur during a Combofix run.



  • Allow ComboFix to download the Recovery Console.
  • Accept the End-User License Agreement.
  • The Recovery Console will be installed.
  • You will then get this next prompt that asks if you want to continue the malware scan, select yes



  • Allow combofix to run
  • Post C:\combofix.txt back here.

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre
Points : 245039
# Likes : 1

View user profile

Back to top Go down

Re: Infected with unknown virus/malware

Post by mcp1959 on Wed Sep 29, 2010 10:20 am

Here is the combo-fix log. FYI my media player and search function have been restored.

ComboFix 10-09-28.03 - Emily Safewright 09/29/2010 3:30.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.478.189 [GMT -4:00]
Running from: c:\documents and settings\Emily Safewright.D2LTG0C1\Desktop\Combo-Fix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\Thumbs.db

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_FAD


((((((((((((((((((((((((( Files Created from 2010-08-28 to 2010-09-29 )))))))))))))))))))))))))))))))
.

2010-09-26 21:00 . 2010-09-26 21:00 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-09-26 16:27 . 2010-09-26 16:27 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\ICS
2010-09-26 16:02 . 2010-09-26 16:02 -------- d-----w- c:\documents and settings\Emily Safewright.D2LTG0C1\Application Data\Tific
2010-09-25 22:32 . 2010-09-25 22:32 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL
2010-09-25 22:32 . 2010-09-25 22:32 126512 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2010-09-25 22:32 . 2010-09-25 22:40 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-09-25 22:32 . 2010-09-25 22:32 -------- d-----w- c:\program files\Symantec
2010-09-25 22:31 . 2010-09-25 22:31 -------- d-----w- c:\windows\system32\drivers\NAV
2010-09-25 22:31 . 2010-09-25 22:31 -------- d-----w- c:\program files\Norton AntiVirus
2010-09-25 22:31 . 2010-09-25 22:31 -------- d-----w- c:\program files\Windows Sidebar
2010-09-25 22:31 . 2010-09-25 22:31 -------- d-----w- c:\program files\NortonInstaller
2010-09-21 00:05 . 2010-09-21 00:05 97549 ----a-w- c:\windows\system32\drivers\klick.dat
2010-09-21 00:05 . 2010-09-21 00:05 113933 ----a-w- c:\windows\system32\drivers\klin.dat
2010-09-21 00:03 . 2010-09-25 20:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2010-09-20 23:38 . 2010-09-20 23:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-29 07:50 . 2008-05-02 18:34 -------- d-----w- c:\program files\Dl_cats
2010-09-29 07:44 . 2008-02-19 14:07 -------- d-----w- c:\program files\Microsoft Silverlight
2010-09-28 19:27 . 2010-02-18 00:45 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-09-26 21:01 . 2006-10-25 23:25 -------- d-----w- c:\program files\Common Files\Java
2010-09-26 21:00 . 2006-10-25 23:25 -------- d-----w- c:\program files\Java
2010-09-26 17:03 . 2007-10-06 01:28 -------- d-----w- c:\program files\Windows Media Connect 2
2010-09-25 22:32 . 2010-09-25 22:32 805 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF
2010-09-25 22:32 . 2010-09-25 22:32 7456 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2010-09-25 22:31 . 2010-03-16 13:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2010-09-25 22:31 . 2010-03-15 15:49 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller
2010-09-25 13:38 . 2009-02-03 18:53 -------- d-----w- c:\documents and settings\Emily Safewright.D2LTG0C1\Application Data\mjusbsp
2010-09-20 23:50 . 2010-02-26 00:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2010-09-20 23:34 . 2010-04-18 13:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-09-20 19:46 . 2008-01-04 04:47 -------- d-----w- c:\program files\Return to Castle Wolfenstein DEMO
2010-09-13 14:43 . 2010-03-14 22:19 -------- d-----w- c:\program files\Glary Utilities
2010-09-05 19:49 . 2008-01-04 04:21 -------- d-----w- c:\documents and settings\Emily Safewright.D2LTG0C1\Application Data\IGN_DLM
2010-08-17 13:17 . 2004-08-10 17:51 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-08-15 18:02 . 2010-08-15 18:02 10 ----a-w- c:\windows\devqdat7417.dat
2010-08-15 17:56 . 2010-08-15 17:56 -------- d-----w- c:\program files\Genius 2000
2010-07-31 14:34 . 2010-07-31 14:34 127 ----a-w- c:\documents and settings\Emily Safewright.D2LTG0C1\Application Data\netstat.bat
2010-07-22 15:49 . 2004-08-10 17:51 590848 ----a-w- c:\windows\system32\rpcrt4.dll
2010-07-22 05:57 . 2009-04-15 23:04 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2010-07-02 01:35 . 2010-07-02 01:35 228024 ----a-w- c:\windows\system32\klogon.dll
2007-12-30 22:01 . 2007-12-29 14:47 80 --sh--r- c:\windows\system32\50B3B90E9B.dll
2008-05-02 19:10 . 2008-05-02 19:10 56 --sh--r- c:\windows\system32\50B3B90E9B.sys
2007-01-04 15:27 . 2006-12-09 05:14 88 --sh--r- c:\windows\system32\EEA1BBBC51.sys
2008-05-02 22:10 . 2006-12-09 05:14 5852 --sha-w- c:\windows\system32\KGyGaAvL.sys
.

------- Sigcheck -------

[7] 2008-04-14 . 5F1D5F88303D4A4DBC8E5F97BA967CC3 . 15360 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ctfmon.exe
[7] 2008-04-14 . 5F1D5F88303D4A4DBC8E5F97BA967CC3 . 15360 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\ctfmon.exe


c:\windows\System32\ctfmon.exe ... is missing !!
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2009-11-18 22:40 1196936 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-11-18 1196936]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-11-18 1196936]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"cdloader"="c:\documents and settings\Emily Safewright.D2LTG0C1\Application Data\mjusbsp\cdloader2.exe" [2010-02-26 50520]
"igndlm.exe"="c:\program files\Download Manager\dlm.exe" [2009-05-14 1103216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-01-12 13666408]
"dlcxmon.exe"="c:\program files\Dell Photo AIO Printer 926\dlcxmon.exe" [2007-01-12 292336]
"DLCXCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll" [2006-10-16 106496]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"nosimplestartmenu"= 0 (0x0)
"norecentdochistory"= 1 (0x1)
"maxrecentdocs"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WZCSVC"=2 (0x2)
"ImapiService"=3 (0x3)
"Fax"=2 (0x2)
"AOL TopSpeedMonitor"=2 (0x2)
"AOL ACS"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"NvCplDaemon"=RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"DLCXCATS"=rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16
"NvCplDaemon"=RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
"NvMediaCenter"=RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
"KernelFaultCheck"=%systemroot%\system32\dumprep 0 -k
"SpybotSnD"="c:\program files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck /autofix

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\WINDOWS\\system32\\dlcxcoms.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\WINDOWS\\LMI26.tmp\\lmi_rescue.exe"=
"c:\\Documents and Settings\\Emily Safewright.D2LTG0C1\\Application Data\\mjusbsp\\magicJack.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"65533:TCP"= 65533:TCP:Services
"52344:TCP"= 52344:TCP:Services
"2479:TCP"= 2479:TCP:Services
"3246:TCP"= 3246:TCP:Services
"3389:TCP"= 3389:TCP:Remote Desktop
"9895:TCP"= 9895:TCP:Services

R1 kl2;kl2;c:\windows\system32\drivers\kl2.sys [6/9/2010 5:43 PM 11352]
R1 sbaphd;sbaphd;c:\windows\system32\drivers\sbaphd.sys [7/17/2010 9:14 AM 13400]
R1 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [10/13/2009 9:02 AM 95024]
R1 SbTis;SbTis;c:\windows\system32\drivers\sbtis.sys [7/17/2010 9:03 AM 204632]
R2 dlcx_device;dlcx_device;c:\windows\system32\dlcxcoms.exe -service --> c:\windows\system32\dlcxcoms.exe -service [?]
R2 NAV;Norton AntiVirus;c:\program files\Norton AntiVirus\Engine\18.1.0.37\ccSvcHst.exe [9/25/2010 6:32 PM 126904]
R2 sbapifs;sbapifs;c:\windows\system32\drivers\sbapifs.sys [7/17/2010 9:14 AM 69720]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [9/25/2010 6:38 PM 102448]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\IPSDefs\20100927.001\IDSXpx86.sys [9/27/2010 6:47 PM 331640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [5/7/2010 12:06 PM 32856]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [11/2/2009 8:27 PM 19472]
R4 SymDS;Symantec Data Store;c:\windows\system32\drivers\NAV\1201000.025\SymDS.sys [9/25/2010 6:32 PM 339504]
R4 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NAV\1201000.025\SymEFA.sys [9/25/2010 6:32 PM 666672]
S0 FPAV_RTP;FPAV_RTP;c:\windows\system32\DRIVERS\FStopW.sys --> c:\windows\system32\DRIVERS\FStopW.sys [?]
S1 BHDrvx86;BHDrvx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\BASHDefs\20100901.003\BHDrvx86.sys [8/31/2010 6:57 PM 692272]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NAV\1201000.025\Ironx86.sys [9/25/2010 6:32 PM 134704]
S3 KProcWatch;KProcWatch;\??\c:\windows\system32\drivers\KProcWatch.sys --> c:\windows\system32\drivers\KProcWatch.sys [?]
S3 MR97310_VGA_DUAL_CAMERA;VGA Dual-Mode Camera;c:\windows\system32\DRIVERS\mr97310v.sys --> c:\windows\system32\DRIVERS\mr97310v.sys [?]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder

2010-09-29 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2010-03-14 14:32]

2010-09-29 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2009-11-18 22:40]

2010-09-29 c:\windows\Tasks\User_Feed_Synchronization-{74E3B3F6-800A-4959-AFFA-7DCF0B91911E}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 09:31]
.
.
------- Supplementary Scan -------
.
uStart Page = [You must be registered and logged in to see this link.]
mWindow Title = Windows Internet Explorer provided by Comcast
uInternet Connection Wizard,ShellNext = iexplore
IE: Google Sidewiki...
IE: Translate Page into English
FF - ProfilePath - c:\documents and settings\Emily Safewright.D2LTG0C1\Application Data\Mozilla\Firefox\Profiles\x6rmhy2x.booger\
FF - prefs.js: browser.startup.homepage - [You must be registered and logged in to see this link.]
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\IPSFFPlgn\components\IPSFFPl.dll
FF - plugin: c:\documents and settings\Emily Safewright.D2LTG0C1\Application Data\Facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\program files\Download Manager\npfpdlm.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npampx3.0.84.2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll
FF - plugin: c:\program files\Opera\program\plugins\np_gp.dll
FF - plugin: c:\program files\Opera\program\plugins\np_gp.dll
FF - plugin: c:\program files\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - plugin: c:\program files\Virtools\3D Life Player\npvirtools.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\activexFF15.js - pref("capability.policy.default.ClassID.CID4E7FF8BB-0A5A-4AA3-B764-B39BA9A13E38", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activexFF15.js - pref("capability.policy.default.ClassID.CIDB24F189F-FB14-4EFD-8B9D-217EC6C84EA1", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activexFF15.js - pref("capability.policy.default.ClassID.CID86ED3659-02F6-465D-8F19-A9334614CCC3", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activexFF15.js - pref("capability.policy.default.ClassID.CID5D7F48C0-CB49-4ea6-97D4-04F4EACC2F3B", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activexFF15.js - pref("capability.policy.default.ClassID.CID4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activexFF15.js - pref("capability.policy.default.ClassID.CIDA43C6FC7-09F6-4E04-B8E3-683F3BDFEF7C", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activexFF15.js - pref("capability.policy.default.ClassID.CID4C8D6404-A9F6-4236-8488-6C5732CB3BFA", "AllAccess");c:\program files\Mozilla Firefox\defaults\pref\firefox.js:pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -

Toolbar-8EAB99C9-F9EC-4b64-A4BA-D9BCAE8779C2 - (no file)
Toolbar-Locked - (no file)
WebBrowser-{58FFDB40-C6F7-4ADD-A456-ED972D6AF9B6} - (no file)
WebBrowser-{D0523BB4-21E7-11DD-9AB7-415B56D89593} - (no file)
SafeBoot-MCODS
SafeBoot-SBAMSvc
SafeBoot-SBPIMSvc



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
Rootkit scan 2010-09-29 03:50
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCXCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\NAV]
"ImagePath"=""c:\program files\Norton AntiVirus\Engine\18.1.0.37\ccSvcHst.exe" /s "NAV" /m "c:\program files\Norton AntiVirus\Engine\18.1.0.37\diMaster.dll" /prefetch:1"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(2512)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\windows\system32\dlcxcoms.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Norton AntiVirus\Engine\18.1.0.37\hsplayer.exe
.
**************************************************************************
.
Completion time: 2010-09-29 04:05:35 - machine was rebooted
ComboFix-quarantined-files.txt 2010-09-29 08:05

Pre-Run: 44,630,007,808 bytes free
Post-Run: 44,527,398,912 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - 6F9D8ACBE7E1E7C42821DFC529EB1026

mcp1959
Novice
Novice

Status :
Online
Offline

Posts : 30
Joined : 2010-09-26
OS : XP
Points : 22970
# Likes : 0

View user profile

Back to top Go down

Re: Infected with unknown virus/malware

Post by Belahzur on Wed Sep 29, 2010 11:38 pm

Hello.

  1. Close any open browsers.
  2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  3. Open notepad and copy/paste the text in the quotebox below into it:
    Code:

    KILLALL::

    FCopy::
    c:\windows\system32\dllcache\ctfmon.exe | c:\windows\System32\ctfmon.exe

    Registry::
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "65533:TCP"=-
    "52344:TCP"=-
    "2479:TCP"=-
    "3246:TCP"=-
    "3389:TCP"=-
    "9895:TCP"=-
  4. Save this as CFScript.txt, in the same location as ComboFix.exe



  5. Referring to the picture above, drag CFScript into ComboFix.exe
  6. When finished, it shall produce a log for you at C:\ComboFix.txt
  7. Please post the contents of the log in your next reply.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre
Points : 245039
# Likes : 1

View user profile

Back to top Go down

Re: Infected with unknown virus/malware

Post by mcp1959 on Thu Sep 30, 2010 1:14 am

The log generated was also named log.txt, same as the last one. It follows:

ComboFix 10-09-29.01 - Emily Safewright 09/29/2010 20:35:51.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.478.203 [GMT -4:00]
Running from: c:\documents and settings\Emily Safewright.D2LTG0C1\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\Emily Safewright.D2LTG0C1\Desktop\CFScript.txt
AV: avast! Internet Security *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Outdated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
AV: Sunbelt VIPRE *On-access scanning enabled* (Updated) {964FCE60-0B18-4D30-ADD6-EB178909041C}
FW: avast! Internet Security *enabled* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: Kaspersky Anti-Virus *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
--------------- FCopy ---------------

c:\windows\system32\dllcache\ctfmon.exe --> c:\windows\System32\ctfmon.exe
.
((((((((((((((((((((((((( Files Created from 2010-08-28 to 2010-09-30 )))))))))))))))))))))))))))))))
.

2010-09-30 00:35 . 2008-04-14 00:12 15360 ----a-w- c:\windows\system32\dllcache\ctfmon.exe
2010-09-30 00:35 . 2008-04-14 00:12 15360 ----a-w- c:\windows\system32\ctfmon.exe
2010-09-29 10:04 . 2010-09-07 14:47 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-09-29 10:04 . 2010-09-07 14:52 165584 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-09-29 10:04 . 2010-09-07 14:53 340048 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2010-09-29 10:04 . 2010-09-07 14:54 99792 ----a-w- c:\windows\system32\drivers\aswFW.sys
2010-09-29 10:04 . 2010-09-07 14:53 190416 ----a-w- c:\windows\system32\drivers\aswNdis2.sys
2010-09-29 10:04 . 2010-09-07 14:47 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-09-29 10:04 . 2010-09-07 14:52 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-09-29 10:04 . 2010-09-07 14:47 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-09-29 10:04 . 2010-09-07 14:47 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-09-29 10:04 . 2010-09-07 14:46 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-09-29 10:03 . 2010-09-07 14:24 12112 ----a-w- c:\windows\system32\drivers\aswNdis.sys
2010-09-29 10:03 . 2010-09-07 15:12 38848 ----a-w- c:\windows\avastSS.scr
2010-09-29 10:03 . 2010-09-07 15:11 167592 ----a-w- c:\windows\system32\aswBoot.exe
2010-09-26 21:01 . 2010-09-26 21:01 503808 ----a-w- c:\documents and settings\Emily Safewright.D2LTG0C1\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-1bbb2344-n\msvcp71.dll
2010-09-26 21:01 . 2010-09-26 21:01 499712 ----a-w- c:\documents and settings\Emily Safewright.D2LTG0C1\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-1bbb2344-n\jmc.dll
2010-09-26 21:01 . 2010-09-26 21:01 348160 ----a-w- c:\documents and settings\Emily Safewright.D2LTG0C1\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-1bbb2344-n\msvcr71.dll
2010-09-26 21:01 . 2010-09-26 21:01 61440 ----a-w- c:\documents and settings\Emily Safewright.D2LTG0C1\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-583c0466-n\decora-sse.dll
2010-09-26 21:01 . 2010-09-26 21:01 12800 ----a-w- c:\documents and settings\Emily Safewright.D2LTG0C1\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-583c0466-n\decora-d3d.dll
2010-09-26 21:00 . 2010-09-26 21:00 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-09-26 16:27 . 2010-09-26 16:27 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\ICS
2010-09-26 16:02 . 2010-09-26 16:02 -------- d-----w- c:\documents and settings\Emily Safewright.D2LTG0C1\Application Data\Tific
2010-09-25 22:31 . 2010-09-25 22:31 -------- d-----w- c:\program files\Windows Sidebar
2010-09-21 00:21 . 2010-09-21 00:21 989880 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP11\Data\Updater\Temporary Files\rollback\patch\AutoPatches\kav11\11.0.1.400\updater.dll
2010-09-21 00:21 . 2010-09-21 00:21 84664 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP11\Data\Updater\Temporary Files\rollback\patch\AutoPatches\kav11\11.0.1.400\libola.dll
2010-09-21 00:21 . 2010-09-21 00:21 482392 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP11\Data\Updater\Temporary Files\rollback\patch\AutoPatches\kav11\11.0.1.400\sys\i386\5.1\klif.sys
2010-09-21 00:21 . 2010-09-21 00:21 391864 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP11\Data\Updater\Temporary Files\rollback\patch\AutoPatches\kav11\11.0.1.400\klifpp.dll
2010-09-21 00:21 . 2010-09-21 00:21 357096 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP11\Data\Updater\Temporary Files\rollback\patch\AutoPatches\kav11\11.0.1.400\avp.exe
2010-09-21 00:21 . 2010-09-21 00:21 146104 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP11\Data\Updater\Temporary Files\rollback\patch\AutoPatches\kav11\11.0.1.400\threatsmanager.dll
2010-09-20 23:38 . 2010-09-20 23:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-30 01:02 . 2008-05-02 18:34 -------- d-----w- c:\program files\Dl_cats
2010-09-29 10:03 . 2010-04-18 13:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-09-29 09:56 . 2010-03-16 13:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2010-09-29 07:44 . 2008-02-19 14:07 -------- d-----w- c:\program files\Microsoft Silverlight
2010-09-28 19:27 . 2010-02-18 00:45 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-09-26 21:01 . 2006-10-25 23:25 -------- d-----w- c:\program files\Common Files\Java
2010-09-26 21:00 . 2006-10-25 23:25 -------- d-----w- c:\program files\Java
2010-09-26 17:03 . 2007-10-06 01:28 -------- d-----w- c:\program files\Windows Media Connect 2
2010-09-25 22:31 . 2010-03-15 15:49 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller
2010-09-25 20:18 . 2010-09-21 00:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2010-09-25 13:38 . 2009-02-03 18:53 -------- d-----w- c:\documents and settings\Emily Safewright.D2LTG0C1\Application Data\mjusbsp
2010-09-21 00:21 . 2010-08-17 21:50 288080 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP11\Bases\avengine.dll
2010-09-21 00:21 . 2010-09-21 00:21 117432 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP11\Data\Updater\Temporary Files\rollback\patch\AutoPatches\kav11\11.0.1.400\dumpwriter.dll
2010-09-21 00:21 . 2010-09-21 00:20 989880 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP11\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav11\11.0.1.400\updater.dll
2010-09-21 00:20 . 2010-09-21 00:20 146104 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP11\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav11\11.0.1.400\threatsmanager.dll
2010-09-21 00:20 . 2010-09-21 00:20 84664 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP11\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav11\11.0.1.400\libola.dll
2010-09-21 00:20 . 2010-09-21 00:20 395960 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP11\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav11\11.0.1.400\klifpp.dll
2010-09-21 00:20 . 2010-09-21 00:20 117432 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP11\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav11\11.0.1.400\dumpwriter.dll
2010-09-21 00:20 . 2010-09-21 00:20 352976 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP11\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav11\11.0.1.400\avp.exe
2010-09-21 00:20 . 2010-09-21 00:20 475736 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP11\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav11\11.0.1.400\sys\i386\5.1\klif.sys
2010-09-21 00:18 . 2010-09-21 00:18 288080 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP11\Data\Updater\Temporary Files\temporaryFolder\bases\av\kdb\i386\win\avengine.dll
2010-09-21 00:05 . 2010-09-21 00:05 97549 ----a-w- c:\windows\system32\drivers\klick.dat
2010-09-21 00:05 . 2010-09-21 00:05 113933 ----a-w- c:\windows\system32\drivers\klin.dat
2010-09-20 23:50 . 2010-02-26 00:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2010-09-20 19:46 . 2008-01-04 04:47 -------- d-----w- c:\program files\Return to Castle Wolfenstein DEMO
2010-09-13 14:43 . 2010-03-14 22:19 -------- d-----w- c:\program files\Glary Utilities
2010-09-05 19:49 . 2008-01-04 04:21 -------- d-----w- c:\documents and settings\Emily Safewright.D2LTG0C1\Application Data\IGN_DLM
2010-08-18 18:16 . 2010-08-18 18:16 271696 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP11\Bases\sys_critical_obj.dll
2010-08-17 13:17 . 2004-08-10 17:51 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-08-15 18:02 . 2010-08-15 18:02 10 ----a-w- c:\windows\devqdat7417.dat
2010-08-15 17:56 . 2010-08-15 17:56 -------- d-----w- c:\program files\Genius 2000
2010-07-31 14:34 . 2010-07-31 14:34 127 ----a-w- c:\documents and settings\Emily Safewright.D2LTG0C1\Application Data\netstat.bat
2010-07-31 14:34 . 2010-07-31 14:34 127 ----a-w- c:\documents and settings\Emily Safewright.D2LTG0C1\Application Data\netstat.bat
2010-07-22 15:49 . 2004-08-10 17:51 590848 ----a-w- c:\windows\system32\rpcrt4.dll
2010-07-22 05:57 . 2009-04-15 23:04 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2010-07-07 08:46 . 2010-07-07 08:46 92816 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files\Kaspersky Anti-Virus 2011 11.0.1.400\english\setup.exe
2010-07-02 01:35 . 2010-07-02 01:35 228024 ----a-w- c:\windows\system32\klogon.dll
2007-12-30 22:01 . 2007-12-29 14:47 80 --sh--r- c:\windows\system32\50B3B90E9B.dll
2008-05-02 19:10 . 2008-05-02 19:10 56 --sh--r- c:\windows\system32\50B3B90E9B.sys
2007-01-04 15:27 . 2006-12-09 05:14 88 --sh--r- c:\windows\system32\EEA1BBBC51.sys
2008-05-02 22:10 . 2006-12-09 05:14 5852 --sha-w- c:\windows\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2009-11-18 22:40 1196936 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-11-18 1196936]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-11-18 1196936]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\snxPluginsShell]
@="{F4B3B0AA-13D1-4a36-BDA2-2055B0F3D5DE}"
[HKEY_CLASSES_ROOT\CLSID\{F4B3B0AA-13D1-4a36-BDA2-2055B0F3D5DE}]
2010-09-07 15:14 152160 ----a-w- c:\program files\Alwil Software\Avast5\snxPlugins.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"cdloader"="c:\documents and settings\Emily Safewright.D2LTG0C1\Application Data\mjusbsp\cdloader2.exe" [2010-02-26 50520]
"igndlm.exe"="c:\program files\Download Manager\dlm.exe" [2009-05-14 1103216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-01-12 13666408]
"dlcxmon.exe"="c:\program files\Dell Photo AIO Printer 926\dlcxmon.exe" [2007-01-12 292336]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2010-09-07 2838912]
"DLCXCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll" [2006-10-16 106496]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"nosimplestartmenu"= 0 (0x0)
"norecentdochistory"= 1 (0x1)
"maxrecentdocs"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WZCSVC"=2 (0x2)
"ImapiService"=3 (0x3)
"Fax"=2 (0x2)
"AOL TopSpeedMonitor"=2 (0x2)
"AOL ACS"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"NvCplDaemon"=RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"DLCXCATS"=rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16
"NvCplDaemon"=RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
"NvMediaCenter"=RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
"KernelFaultCheck"=%systemroot%\system32\dumprep 0 -k
"SpybotSnD"="c:\program files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck /autofix

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\WINDOWS\\system32\\dlcxcoms.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\WINDOWS\\LMI26.tmp\\lmi_rescue.exe"=
"c:\\Documents and Settings\\Emily Safewright.D2LTG0C1\\Application Data\\mjusbsp\\magicJack.exe"=

R0 aswNdis;avast! Firewall NDIS Filter Service;c:\windows\system32\drivers\aswNdis.sys [9/29/2010 6:03 AM 12112]
R0 aswNdis2;avast! Firewall Core Firewall Service;c:\windows\system32\drivers\aswNdis2.sys [9/29/2010 6:04 AM 190416]
R1 aswFW;avast! TDI Firewall driver;c:\windows\system32\drivers\aswFW.sys [9/29/2010 6:04 AM 99792]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [9/29/2010 6:04 AM 340048]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [9/29/2010 6:04 AM 165584]
R1 kl2;kl2;c:\windows\system32\drivers\kl2.sys [6/9/2010 5:43 PM 11352]
R1 sbaphd;sbaphd;c:\windows\system32\drivers\sbaphd.sys [7/17/2010 9:14 AM 13400]
R1 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [10/13/2009 9:02 AM 95024]
R1 SbTis;SbTis;c:\windows\system32\drivers\sbtis.sys [7/17/2010 9:03 AM 204632]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [9/29/2010 6:04 AM 17744]
R2 avast! Firewall;avast! Firewall;c:\program files\Alwil Software\Avast5\afwServ.exe [9/29/2010 6:03 AM 119200]
R2 dlcx_device;dlcx_device;c:\windows\system32\dlcxcoms.exe -service --> c:\windows\system32\dlcxcoms.exe -service [?]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [5/7/2010 12:06 PM 32856]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [11/2/2009 8:27 PM 19472]
S0 FPAV_RTP;FPAV_RTP;c:\windows\system32\DRIVERS\FStopW.sys --> c:\windows\system32\DRIVERS\FStopW.sys [?]
S2 sbapifs;sbapifs;c:\windows\system32\drivers\sbapifs.sys [7/17/2010 9:14 AM 69720]
S3 KProcWatch;KProcWatch;\??\c:\windows\system32\drivers\KProcWatch.sys --> c:\windows\system32\drivers\KProcWatch.sys [?]
S3 MR97310_VGA_DUAL_CAMERA;VGA Dual-Mode Camera;c:\windows\system32\DRIVERS\mr97310v.sys --> c:\windows\system32\DRIVERS\mr97310v.sys [?]
S3 SysProtDrv.sys;SysProtDrv.sys;c:\documents and settings\Emily Safewright.D2LTG0C1\desktop\SysProtDrv.sys [9/29/2010 8:20 PM 44288]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder

2010-09-30 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2010-03-14 14:32]

2010-09-30 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2009-11-18 22:40]

2010-09-30 c:\windows\Tasks\User_Feed_Synchronization-{74E3B3F6-800A-4959-AFFA-7DCF0B91911E}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 09:31]
.
.
------- Supplementary Scan -------
.
uStart Page = [You must be registered and logged in to see this link.]
mWindow Title = Windows Internet Explorer provided by Comcast
uInternet Connection Wizard,ShellNext = iexplore
IE: Google Sidewiki...
IE: Translate Page into English
FF - ProfilePath - c:\documents and settings\Emily Safewright.D2LTG0C1\Application Data\Mozilla\Firefox\Profiles\x6rmhy2x.booger\
FF - prefs.js: browser.startup.homepage - [You must be registered and logged in to see this link.]
FF - plugin: c:\documents and settings\Emily Safewright.D2LTG0C1\Application Data\Facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\program files\Download Manager\npfpdlm.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npampx3.0.84.2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll
FF - plugin: c:\program files\Opera\program\plugins\np_gp.dll
FF - plugin: c:\program files\Opera\program\plugins\np_gp.dll
FF - plugin: c:\program files\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - plugin: c:\program files\Virtools\3D Life Player\npvirtools.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\activexFF15.js - pref("capability.policy.default.ClassID.CID4E7FF8BB-0A5A-4AA3-B764-B39BA9A13E38", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activexFF15.js - pref("capability.policy.default.ClassID.CIDB24F189F-FB14-4EFD-8B9D-217EC6C84EA1", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activexFF15.js - pref("capability.policy.default.ClassID.CID86ED3659-02F6-465D-8F19-A9334614CCC3", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activexFF15.js - pref("capability.policy.default.ClassID.CID5D7F48C0-CB49-4ea6-97D4-04F4EACC2F3B", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activexFF15.js - pref("capability.policy.default.ClassID.CID4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activexFF15.js - pref("capability.policy.default.ClassID.CIDA43C6FC7-09F6-4E04-B8E3-683F3BDFEF7C", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activexFF15.js - pref("capability.policy.default.ClassID.CID4C8D6404-A9F6-4236-8488-6C5732CB3BFA", "AllAccess");c:\program files\Mozilla Firefox\defaults\pref\firefox.js:pref("dom.ipc.plugins.enabled", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
Rootkit scan 2010-09-29 21:02
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCXCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(2740)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\PhoTags Express\PWSSearchHandler.dll
c:\program files\Malwarebytes' Anti-Malware\mbamext.dll
c:\progra~1\GLARYU~1\CONTEX~1.DLL
c:\progra~1\GLARYU~1\vcl70.bpl
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\system32\dlcxcoms.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
.
**************************************************************************
.
Completion time: 2010-09-29 21:12:52 - machine was rebooted
ComboFix-quarantined-files.txt 2010-09-30 01:12
ComboFix2.txt 2010-09-29 08:05

Pre-Run: 44,542,816,256 bytes free
Post-Run: 44,524,027,904 bytes free

- - End Of File - - 30FB704C7B648163582078BAD54FBDF6


mcp1959
Novice
Novice

Status :
Online
Offline

Posts : 30
Joined : 2010-09-26
OS : XP
Points : 22970
# Likes : 0

View user profile

Back to top Go down

Re: Infected with unknown virus/malware

Post by Belahzur on Thu Sep 30, 2010 11:31 pm

Hello.
Did OTL make an Extras.txt when you ran it? if so please post that log too.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre
Points : 245039
# Likes : 1

View user profile

Back to top Go down

Re: Infected with unknown virus/malware

Post by mcp1959 on Fri Oct 01, 2010 11:21 am

I did not find a file with that name. Should I run OTL again?

mcp1959
Novice
Novice

Status :
Online
Offline

Posts : 30
Joined : 2010-09-26
OS : XP
Points : 22970
# Likes : 0

View user profile

Back to top Go down

Re: Infected with unknown virus/malware

Post by Belahzur on Fri Oct 01, 2010 10:37 pm

Hello.

Please download the current version of HijackThis from [You must be registered and logged in to see this link.]

  • Double click and run the installer.
  • It will install to C:\Program Files\Trend Micro\HijackThis\hijackthis.exe
  • After installing, you should get the user agreement, press accept and Hijack This will run.
  • When Hijack This opens, click "Open the Misc Tools section"
  • Then select "Open Uninstall Manager"
  • Click on "Save List..." (generates uninstall_list.txt)
  • Click Save, copy and paste the results in your next post.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre
Points : 245039
# Likes : 1

View user profile

Back to top Go down

Re: Infected with unknown virus/malware

Post by mcp1959 on Sat Oct 02, 2010 1:10 am

Results are here. As mentioned before, the issues w/Media Player and search function have been corrected.

3DVIA player 5.0
50 FREE MP3s +1 Free Audiobook!
7-Zip 4.65
Adobe Download Manager
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 8.2.4
Adobe Shockwave Player 11.5
Anagram Genius version 9 trial
Ask Toolbar
Athlon 64 Processor Driver
avast! Internet Security
Big Fish Games Client
Broadcom Management Programs
Comcast High-Speed Internet Install Wizard
Coupon Printer for Windows
Critical Update for Windows Media Player 11 (KB959772)
Dell PC Fax
Dell Photo AIO Printer 926
Dell Support 3.2
Deus Ex: Game of the Year
Digital Content Portal
Digital Line Detect
Download Manager 2.3.6
Free CD Ripper 3.1
Free CD to MP3 Converter
Geiss2 for Winamp 2x (remove only)
Glary Utilities 2.28.0.1011
Half-Life Uplink
High Definition Audio Driver Package - KB835221
HiJackThis
Hotfix for Microsoft .NET Framework 3.0 (KB932471)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB2158563)
Hotfix for Windows XP (KB915800-v4)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954708)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
IrfanView (remove only)
J2SE Runtime Environment 5.0 Update 6
Java(TM) 6 Update 21
Java(TM) 6 Update 7
Junk Mail filter update
Malwarebytes' Anti-Malware
MCU
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2416447)
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Choice Guard
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Plus! Digital Media Edition Installer
Microsoft Search Enhancement Pack
Microsoft Silverlight
Microsoft Sync Framework Runtime Native v1.0 (x86)
Microsoft Sync Framework Services Native v1.0 (x86)
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Mirar
Modem Diagnostic Tool
Mojo Master Winamp Visualizer for Winamp (remove only)
Mozilla Firefox (3.6.10)
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MySpaceIM
Netflix Movie Viewer
NVIDIA Drivers
NVIDIA nView Desktop Manager
Opera 9.23
Opera 9.60
PassAlong Software
PhoTags Express
QuickTime
RealPlayer Basic
Roxio DLA
Roxio RecordNow Audio
Roxio RecordNow Copy
Roxio RecordNow Data
Security Task Manager 1.7h
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 8 (KB2183461)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Internet Explorer 8 (KB978207)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Internet Explorer 8 (KB982381)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB975558)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Search 4 - KB963093
Security Update for Windows XP (KB2079403)
Security Update for Windows XP (KB2115168)
Security Update for Windows XP (KB2121546)
Security Update for Windows XP (KB2160329)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2259922)
Security Update for Windows XP (KB2286198)
Security Update for Windows XP (KB2347290)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB980436)
Security Update for Windows XP (KB981322)
Security Update for Windows XP (KB981852)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982214)
Security Update for Windows XP (KB982665)
Security Update for Windows XP (KB982802)
Segoe UI
Sonic Activation Module
Spelling Dictionaries Support For Adobe Reader 8
SpongeBob SquarePants® Operation Krabby Patty
Spybot - Search & Destroy
System Requirements Lab
Unity Web Player
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows Internet Explorer 8 (KB978506)
Update for Windows Internet Explorer 8 (KB980182)
Update for Windows XP (KB2141007)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB961503)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Viewpoint Media Player
WAV to MP3 Encoder
Winamp
Windows Essentials Media Codec Pack 2.3d
Windows Imaging Component
Windows Internet Explorer 8
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Essentials
Windows Live Family Safety
Windows Live Mail
Windows Live Messenger
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Toolbar
Windows Live Upload Tool
Windows Live Writer
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 10
Windows Media Player 11
Windows Media Player 11
Windows Media Player Firefox Plugin
Windows Presentation Foundation
Windows XP Service Pack 3
Yahoo! Install Manager
Yahoo! Messenger


mcp1959
Novice
Novice

Status :
Online
Offline

Posts : 30
Joined : 2010-09-26
OS : XP
Points : 22970
# Likes : 0

View user profile

Back to top Go down

Re: Infected with unknown virus/malware

Post by Belahzur on Sat Oct 02, 2010 8:33 pm

Hello.

You are running two antivirus', I see from the uninstall list you have Norton/Symantec installed, along with AVG. This is a bad idea as they can conflict and cause more problems. I would recommend that you remove Symantec to avoid conflict and other future problems.

Go to Start > Control Panel > Add/Remove Programs and remove the following programs.

    Adobe Reader 8.2.4
    Ask Toolbar
    avast! Internet Security
    J2SE Runtime Environment 5.0 Update 6
    Java(TM) 6 Update 7
    Viewpoint Media Player

Click Start > Run and copy/paste the following bolded text into the Run box and click OK:

ComboFix /uninstall

This will also reset your restore points.

Run ESET Online Scan
Please do an online scan with [You must be registered and logged in to see this link.]. Please use Internet Explorer as it uses ActiveX.

  • Check (tick) this box: YES, I accept the Terms of Use.
  • Click on the Start button next to it.
  • When prompted to run ActiveX. click Yes.
  • You will be asked to install an ActiveX. Click Install.
  • Once installed, the scanner will be initialized.
  • After the scanner is initialized, click Start.
  • Check (tick) Remove found threats box.
  • Check (tick) Scan unwanted applications.
  • Click on Scan.
  • It will start scanning. Please be patient.
  • Once the scan is done, the log will be saved here: C:\Program Files\esetonlinescanner\log.txt.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre
Points : 245039
# Likes : 1

View user profile

Back to top Go down

Re: Infected with unknown virus/malware

Post by mcp1959 on Sat Oct 02, 2010 10:32 pm

You stated I should remove Symantec. I thought I had. You then ask me to uninstall avast as well. I just want to confirm I should remove avast as well.

mcp1959
Novice
Novice

Status :
Online
Offline

Posts : 30
Joined : 2010-09-26
OS : XP
Points : 22970
# Likes : 0

View user profile

Back to top Go down

Re: Infected with unknown virus/malware

Post by Belahzur on Sun Oct 03, 2010 12:07 am

Sorry error in my post.

You have Avast/Kaspersky/Sunbelt VIPRE installed, so remove Avast and Kaspersky please.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre
Points : 245039
# Likes : 1

View user profile

Back to top Go down

Re: Infected with unknown virus/malware

Post by mcp1959 on Sun Oct 03, 2010 2:39 pm

I had tried to remove both Vipre and Kaspersky using normal uninstall methods with no success, so I removed them both manually as best I could. If there are tools to remove the vestiges of these programs please let me know.

I am only running Avast and will continue unless you tell me otherwise. With that in mind I followed your instructions; here is the text

ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
# version=7
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=5c26719539390b489e3a36d8ae416585
# end=finished
# remove_checked=true
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2010-10-03 02:16:37
# local_time=2010-10-03 10:16:37 (-0500, Eastern Daylight Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=256 16777175 100 0 0 0 0 0
# compatibility_mode=512 16777215 100 0 0 0 0 0
# compatibility_mode=768 16777215 100 0 13590158 13590158 0 0
# compatibility_mode=1029 16777214 0 1 5819095 5819095 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=93252
# found=0
# cleaned=0
# scan_time=3122

mcp1959
Novice
Novice

Status :
Online
Offline

Posts : 30
Joined : 2010-09-26
OS : XP
Points : 22970
# Likes : 0

View user profile

Back to top Go down

Re: Infected with unknown virus/malware

Post by Belahzur on Sun Oct 03, 2010 11:37 pm

Hello.
How is the machine running now?


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre
Points : 245039
# Likes : 1

View user profile

Back to top Go down

Re: Infected with unknown virus/malware

Post by mcp1959 on Mon Oct 04, 2010 4:06 pm

I had to remove both Vipre and Kaspersky manually and am only using Avast now. If you are aware of any tools which will remove the vestiges of those programs please let me know. I am only using Avast will continue to do so unless told otherwise. With that in mind here is the log from the Eset scan

ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
# version=7
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=5c26719539390b489e3a36d8ae416585
# end=finished
# remove_checked=true
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2010-10-03 02:16:37
# local_time=2010-10-03 10:16:37 (-0500, Eastern Daylight Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=256 16777175 100 0 0 0 0 0
# compatibility_mode=512 16777215 100 0 0 0 0 0
# compatibility_mode=768 16777215 100 0 13590158 13590158 0 0
# compatibility_mode=1029 16777214 0 1 5819095 5819095 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=93252
# found=0
# cleaned=0
# scan_time=3122
# version=7
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=5c26719539390b489e3a36d8ae416585
# end=finished
# remove_checked=true
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2010-10-04 03:55:12
# local_time=2010-10-04 11:55:12 (-0500, Eastern Daylight Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=256 16777175 100 0 0 0 0 0
# compatibility_mode=512 16777215 100 0 0 0 0 0
# compatibility_mode=768 16777215 100 0 13686478 13686478 0 0
# compatibility_mode=1029 16777214 0 1 5911815 5911815 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=92746
# found=0
# cleaned=0
# scan_time=2716

mcp1959
Novice
Novice

Status :
Online
Offline

Posts : 30
Joined : 2010-09-26
OS : XP
Points : 22970
# Likes : 0

View user profile

Back to top Go down

Re: Infected with unknown virus/malware

Post by Belahzur on Mon Oct 04, 2010 11:07 pm

Looks good, if the machine is running okay now then you should be good to go.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre
Points : 245039
# Likes : 1

View user profile

Back to top Go down

Re: Infected with unknown virus/malware

Post by mcp1959 on Tue Oct 05, 2010 9:50 pm

yes, it is running impeccably.

My sincerest thanks for you help and you patience!

mcp1959
Novice
Novice

Status :
Online
Offline

Posts : 30
Joined : 2010-09-26
OS : XP
Points : 22970
# Likes : 0

View user profile

Back to top Go down

View previous topic View next topic Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum