Reginald Hirsch
Posts: 30 +0
As you can see infection started August 13 here are the logs requested and any help appreciated :
First detected problem:
2012/08/13 10:28:37 -0600REGINALD-PCReginaldIP-BLOCK109.163.227.72 (Type: incoming, Port: 3389)
2012/08/13 10:28:46 -0600REGINALD-PCReginaldIP-BLOCK109.163.227.72 (Type: incoming, Port: 3389)
2012/08/13 10:28:46 -0600REGINALD-PCReginaldIP-BLOCK109.163.227.72 (Type: incoming, Port: 3389)
2012/08/13 14:28:50 -0600REGINALD-PCReginaldMESSAGEStopping IP protection
2012/08/13 14:31:56 -0600REGINALD-PCReginaldMESSAGEIP Protection stopped
2012/08/13 17:47:08 -0600REGINALD-PCReginaldDETECTIONC:\Users\Reginald\AppData\Local\Temp\013922622cb0.exeRootKit.0AccessALLOW
2012/08/13 17:47:39 -0600REGINALD-PCReginaldDETECTIONC:\Windows\Installer\{f9ef26a6-5650-2172-7144-5aa984cc63b0}\U\800000cb.@Rootkit.0AccessALLOW
2012/08/13 17:47:43 -0600REGINALD-PCReginaldDETECTIONC:\Users\Reginald\AppData\Local\Temp\013922622CB0.EXERootKit.0AccessALLOW
2012/08/13 17:47:44 -0600REGINALD-PCReginaldDETECTIONC:\Windows\Installer\{f9ef26a6-5650-2172-7144-5aa984cc63b0}\U\800000cb.@Rootkit.0AccessALLOW
2012/08/13 22:38:27 -0600REGINALD-PCReginaldDETECTIONC:\Users\Reginald\AppData\Local\{f9ef26a6-5650-2172-7144-5aa984cc63b0}\nRootKit.0AccessALLOW
2012/08/13 22:39:07 -0600REGINALD-PCReginaldDETECTIONC:\Users\Reginald\AppData\Local\{f9ef26a6-5650-2172-7144-5aa984cc63b0}\nRootKit.0AccessALLOW
2012/08/13 23:00:37 -0600REGINALD-PCReginaldDETECTIONC:\Users\Reginald\AppData\Local\{f9ef26a6-5650-2172-7144-5aa984cc63b0}\nRootKit.0AccessALLOW
Then next log reported :
2012/08/14 13:09:52 -0600REGINALD-PCReginaldMESSAGEStarting protection
2012/08/14 13:09:55 -0600REGINALD-PCReginaldMESSAGEProtection started successfully
2012/08/14 13:09:58 -0600REGINALD-PCReginaldMESSAGEStarting IP protection
2012/08/14 13:09:58 -0600REGINALD-PCReginaldERRORIP protection failed: FwpmEngineOpen0 failed with error code 1753
2012/08/14 15:31:38 -0600REGINALD-PCReginaldDETECTIONC:\Users\Reginald\AppData\Local\{F9EF26A6-5650-2172-7144-5AA984CC63B0}\nRootKit.0AccessQUARANTINE
2012/08/14 15:31:38 -0600REGINALD-PCReginaldERRORQuarantine failed: DeleteFile failed with error code 5
2012/08/14 15:40:24 -0600REGINALD-PCReginaldMESSAGEStarting protection
2012/08/14 15:40:27 -0600REGINALD-PCReginaldMESSAGEProtection started successfully
2012/08/14 15:40:30 -0600REGINALD-PCReginaldMESSAGEStarting IP protection
2012/08/14 15:40:30 -0600REGINALD-PCReginaldERRORIP protection failed: FwpmEngineOpen0 failed with error code 1753
2012/08/14 15:43:08 -0600REGINALD-PCReginaldMESSAGEStarting database refresh
2012/08/14 15:43:10 -0600REGINALD-PCReginaldMESSAGEDatabase refreshed successfully
2012/08/14 16:34:15 -0600REGINALD-PCReginaldDETECTIONC:\Windows\Installer\{f9ef26a6-5650-2172-7144-5aa984cc63b0}\U\800000cb.@Rootkit.0AccessQUARANTINE
2012/08/14 19:06:59 -0600REGINALD-PCReginaldMESSAGEStarting protection
2012/08/14 19:07:08 -0600REGINALD-PCReginaldMESSAGEProtection started successfully
2012/08/14 19:07:11 -0600REGINALD-PCReginaldMESSAGEStarting IP protection
2012/08/14 19:07:11 -0600REGINALD-PCReginaldERRORIP protection failed: FwpmEngineOpen0 failed with error code 1753
2012/08/14 20:01:14 -0600REGINALD-PCReginaldMESSAGEStarting protection
2012/08/14 20:01:17 -0600REGINALD-PCReginaldMESSAGEProtection started successfully
2012/08/14 20:01:20 -0600REGINALD-PCReginaldMESSAGEStarting IP protection
2012/08/14 20:01:20 -0600REGINALD-PCReginaldERRORIP protection failed: FwpmEngineOpen0 failed with error code 1753
2012/08/14 21:03:29 -0600REGINALD-PCReginaldMESSAGEStarting protection
2012/08/14 21:03:32 -0600REGINALD-PCReginaldMESSAGEProtection started successfully
2012/08/14 21:03:35 -0600REGINALD-PCReginaldMESSAGEStarting IP protection
2012/08/14 21:03:35 -0600REGINALD-PCReginaldERRORIP protection failed: FwpmEngineOpen0 failed with error code 1753
Then next log reported :
2012/08/15 07:48:49 -0600REGINALD-PCReginaldMESSAGEStarting protection
2012/08/15 07:48:52 -0600REGINALD-PCReginaldMESSAGEProtection started successfully
2012/08/15 07:48:55 -0600REGINALD-PCReginaldMESSAGEStarting IP protection
2012/08/15 07:48:55 -0600REGINALD-PCReginaldERRORIP protection failed: FwpmEngineOpen0 failed with error code 1753
2012/08/15 21:27:20 -0600REGINALD-PCReginaldMESSAGEExecuting scheduled update: Weekly | Silent
2012/08/15 21:27:48 -0600REGINALD-PCReginaldMESSAGEScheduled update executed successfully: database updated from version v2012.08.14.07 to version v2012.08.16.02
2012/08/15 22:30:00 -0600REGINALD-PCReginaldMESSAGEExecuting scheduled scan: Quick Scan | Weekly | -reboot
2012/08/15 22:30:00 -0600REGINALD-PCReginaldMESSAGEScheduled scan executed successfully
Next Log:
012/08/16 07:53:54 -0600REGINALD-PCReginaldMESSAGEStarting protection
2012/08/16 07:54:05 -0600REGINALD-PCReginaldMESSAGEProtection started successfully
2012/08/16 07:54:08 -0600REGINALD-PCReginaldMESSAGEStarting IP protection
2012/08/16 07:54:09 -0600REGINALD-PCReginaldMESSAGEIP Protection started successfully
Last log:
2012/08/17 08:18:44 -0600REGINALD-PCReginaldMESSAGEStopping IP protection
2012/08/17 08:18:44 -0600REGINALD-PCReginaldMESSAGEIP Protection stopped
2012/08/17 13:01:51 -0600REGINALD-PCReginaldMESSAGEStarting database refresh
2012/08/17 13:02:01 -0600REGINALD-PCReginaldMESSAGEDatabase refreshed successfully
2012/08/17 13:02:21 -0600REGINALD-PCReginaldMESSAGEStarting IP protection
2012/08/17 13:02:23 -0600REGINALD-PCReginaldMESSAGEIP Protection started successfully
GMER:
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit quick scan 2012-08-18 15:13:30
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST332062 rev.3.AD
Running: cztdodz5.exe; Driver: C:\Users\Reginald\AppData\Local\Temp\pwlyikod.sys
---- Devices - GMER 1.0.15 ----
Device \Driver\iaStor \Device\Ide\iaStor0 [8B900580] \SystemRoot\system32\DRIVERS\iaStor.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\iaStor \Device\Ide\IAAStorageDevice-0 [8B900580] \SystemRoot\system32\DRIVERS\iaStor.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device iaStor.sys (Intel Matrix Storage Manager driver - ia32/Intel Corporation)
Device 85B891F8
Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
AttachedDevice tdrpm273.sys (Acronis Try&Decide Volume Filter Driver/Acronis)
Device 878541F8
Device fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Ip kmodurl.sys
AttachedDevice \Driver\tdx \Device\Tcp kmodurl.sys
AttachedDevice \Driver\tdx \Device\Udp kmodurl.sys
AttachedDevice \Driver\tdx \Device\RawIp kmodurl.sys
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 VMkbd.sys
---- EOF - GMER 1.0.15 ----
DDS File:
DDS
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_17
Run by Reginald at 15:18:21 on 2012-08-18
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\system32\atieclxx.exe
C:\Program Files\Kingsoft\PcDoctor\KSafeSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Google\Update\1.3.21.115\GoogleCrashHandler.exe
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Microsoft\BingBar\SeaPort.EXE
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
C:\Program Files\DebugDiag\DbgSvc.exe
C:\Program Files\DU Meter\DUMeterSvc.exe
C:\Program Files\Citrix\GoToMyPC\g2svc.exe
C:\Program Files\Citrix\GoToMyPC\g2comm.exe
C:\Program Files\Citrix\GoToMyPC\g2pre.exe
C:\Program Files\Citrix\GoToMyPC\g2tray.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Windows\vVX6000.exe
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\VMware\VMware Workstation\vmware-tray.exe
C:\Program Files\SysMetrix\SysMetrix.exe
C:\Program Files\Acronis\OnlineBackupStandalone\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Kingsoft\PcDoctor\KSafeTray.exe
C:\Program Files\Garmin\Lifetime Updater\GarminLifetime.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\AirPort\APAgent.exe
C:\Program Files\AirVideoServer\AirVideoServer.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\DU Meter\DUMeter.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE
c:\Program Files\Microsoft SQL Server\MSSQL10.MICROSOFTSCM\MSSQL\Binn\sqlservr.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\Program Files\Xmarks\IE Extension\xmarkssync.exe
C:\Program Files\Common Files\Apple\Internet Services\ubd.exe
C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\TechSmith\Snagit 10\Snagit32.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe
C:\Windows\system32\conhost.exe
C:\Program Files\TechSmith\Snagit 10\TSCHelp.exe
C:\Program Files\TechSmith\Snagit 10\SnagPriv.exe
C:\Program Files\Sling Media\SlingAgent\SlingAgentService.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe
C:\Program Files\Active WebCam\WebCam.exe
C:\Users\Reginald\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\vws\vws.exe
C:\Program Files\WePrint\WePrint Server.exe
C:\Program Files\TechSmith\Snagit 10\snagiteditor.exe
C:\Program Files\APC\APC PowerChute Personal Edition\dataserv.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\TeamViewer\Version6\TeamViewer.exe
C:\Program Files\Active WebCam\CompParams.exe
C:\Program Files\Active WebCam\Watchdog.exe
C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\dllhost.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Windows\System32\msdtc.exe
C:\Program Files\Malwarebytes' Anti-Malware\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Users\Reginald\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Reginald\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Reginald\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Reginald\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Reginald\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Reginald\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Reginald\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Anvisoft\Anvi Smart Defender\ASDSrv.exe
C:\Windows\system32\taskhost.exe
C:\Users\Reginald\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Reginald\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Dell Support Center\pcdrcui.exe
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Users\Reginald\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Reginald\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Users\Reginald\Desktop\rootkit\dds.com
C:\Windows\system32\conhost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\msfeedssync.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
uURLSearchHooks: FCToolbarURLSearchHook Class: {fa887e92-8f5f-4ec9-99ca-09be0e4120d6} - c:\program files\addthis toolbar\Helper.dll
BHO: SnagIt Toolbar Loader: {00c6482d-c502-44c8-8409-fce54ad9c208} - c:\program files\techsmith\snagit 10\SnagitBHO.dll
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: ThumbnailsBHO Class: {1bd0befe-f697-4eee-b7e1-76b849a5cb84} - c:\program files\xmarks\thumbnails for ie\xmarksthumbnails.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot - search & destroy\SDHelper.dll
BHO: {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - No File
BHO: RoboForm Toolbar Helper: {724d43a9-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\microsoft office\office14\GROOVEEX.DLL
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: {9EBF8AAF-0A31-4786-909A-97A0EF101743} - No File
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
BHO: Skype add-on for Internet Explorer: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\microsoft office\office14\URLREDIR.DLL
BHO: {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - No File
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "c:\program files\microsoft\bingbar\BingExt.dll"
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: ChromeFrame BHO: {ecb3c477-1a0a-44bd-bb57-78f9efe34fa7} - c:\program files\google\chrome\application\21.0.1180.79\npchrome_frame.dll
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: &RoboForm Toolbar: {724d43a0-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll
TB: Snagit: {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - c:\program files\techsmith\snagit 10\SnagitIEAddin.dll
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "c:\program files\microsoft\bingbar\BingExt.dll"
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [AirVideoServer] c:\program files\airvideoserver\AirVideoServer.exe
uRun: [AlcoholAutomount] "c:\program files\alcohol soft\alcohol 120\axcmd.exe" /automount
uRun: [DU Meter] c:\program files\du meter\DUMeter.exe
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [OfficeSyncProcess] "c:\program files\microsoft office\office14\MSOSYNC.EXE"
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [MobileDocuments] c:\program files\common files\apple\internet services\ubd.exe
uRun: [RoboForm] "c:\program files\siber systems\ai roboform\RoboTaskBarIcon.exe"
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
mRun: [VX6000] c:\windows\vVX6000.exe
mRun: [Bluetooth HCI Monitor] RunDll32 HCIMNTR.DLL,RunCheckHCIMode
mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 9.0\acrobat\Acrotray.exe"
mRun: [Adobe Acrobat Speed Launcher] "c:\program files\adobe\acrobat 9.0\acrobat\Acrobat_sl.exe"
mRun: [AdobeCS4ServiceManager] "c:\program files\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe
mRun: [ECenter] c:\dell\e-center\EULALauncher.exe
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [IAAnotif] "c:\program files\intel\intel matrix storage manager\Iaanotif.exe"
mRun: [LifeCam] "c:\program files\microsoft lifecam\LifeExp.exe"
mRun: [LogMeIn GUI] "c:\program files\logmein\x86\LogMeInSystray.exe"
mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume
mRun: [QuickFinder Scheduler] "c:\program files\corel\wordperfect office x4\programs\QFSCHD140.EXE"
mRun: [vmware-tray] "c:\program files\vmware\vmware workstation\vmware-tray.exe"
mRun: [ATICustomerCare] "c:\program files\ati\aticustomercare\ATICustomerCare.exe"
mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe"
mRun: [BCSSync] "c:\program files\microsoft office\office14\BCSSync.exe" /DelayServices
mRun: [SysMetrix] c:\program files\sysmetrix\SysMetrix.exe
mRun: [SAOB Monitor] c:\program files\acronis\onlinebackupstandalone\TrueImageMonitor.exe
mRun: [TrueImageMonitor.exe] "c:\program files\acronis\trueimagehome\TrueImageMonitor.exe"
mRun: [Acronis Scheduler2 Service] "c:\program files\common files\acronis\schedule2\schedhlp.exe"
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [KSafeTray] "c:\program files\kingsoft\pcdoctor\KSafeTray.exe" -autorun
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\malwarebytes' anti-malware\mbamgui.exe" /starttray
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [AirPort Base Station Agent] "c:\program files\airport\APAgent.exe"
mRun: [Anvi Smart Defender] c:\program files\anvisoft\anvi smart defender\ASDTray.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
mPolicies-system: EnableLinkedConnections = 1 (0x1)
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Append Link Target to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html
IE: Customize Menu - file://c:\program files\siber systems\ai roboform\RoboFormComCustomizeIEMenu.html
IE: E&xport to Microsoft Excel - c:\progra~1\microsoft office\office14\EXCEL.EXE/3000
IE: Fill Forms - file://c:\program files\siber systems\ai roboform\RoboFormComFillForms.html
IE: Open with WordPerfect - c:\program files\corel\wordperfect office x4\programs\WPLauncher.hta
IE: Save Forms - file://c:\program files\siber systems\ai roboform\RoboFormComSavePass.html
IE: Se&nd to OneNote - c:\progra~1\microsoft office\office14\ONBttnIE.dll/105
IE: Send image to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: Show RoboForm Toolbar - file://c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - c:\program files\siber systems\ai roboform\roboform.dll
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - c:\program files\siber systems\ai roboform\roboform.dll
IE: {724d43aa-0d85-11d4-9908-00400523e39a} - {724d43aa-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot - search & destroy\SDHelper.dll
Trusted Zone: garmin.com\connect
Trusted Zone: garmin.com\mygarmin
Trusted Zone: garmin.com\www
Trusted Zone: real.com\rhap-app-4-0
Trusted Zone: real.com\rhapreg
Trusted Zone: zoombak.com\locate
Trusted Zone: zoombak.com\shop
DPF: CaptureClient - hxxp://192.168.1.110/CaptureClient.cab
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {22D82B43-FF26-455A-A96D-A6C61F056ED7} - hxxp://192.168.1.210/xplugxLiteTW.cab
DPF: {362C56AA-6E4F-40C7-A0B5-85501DBDAD77} - hxxp://I.dell.com/images/global/js/scanner/SysProExe.cab
DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} - hxxp://support.dell.com/systemprofiler/SysProExe.CAB
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {82774781-8F4E-11D1-AB1C-0000F8773BF0} - hxxps://transfers.ds.microsoft.com/FTM/TransferSource/grTransferCtrl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {B80CD4E6-5B02-4B6C-99BE-68F1511E9549} - hxxp://plugin.slingbox.com/downloads/pc/1.4.0.111/WebSlingPlayer.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.1.66.0.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - hxxps://secure.logmein.com/activex/ractrl.cab?lmi=100
TCP: DhcpNameServer = 72.19.128.53 72.19.128.99
TCP: Interfaces\{297982DB-7F42-4718-8D4B-A71C72C5621A} : DhcpNameServer = 72.19.128.53 72.19.128.99
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Handler: gcf - {9875BFAF-B04D-445E-8A69-BE36838CDE3E} - c:\program files\google\chrome\application\21.0.1180.79\npchrome_frame.dll
Handler: skyline - {3a4f9195-65a8-11d5-85c1-0001023952c1} - c:\program files\skyline\terraexplorer\TerraExplorerX.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\Skype4COM.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
AppInit_DLLs: acaptuser32.dll
STS: FencesShlExt Class: {1984dd45-52cf-49cd-ab77-18f378fea264} - c:\program files\stardock\fences\FencesMenu.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\microsoft office\office14\GROOVEEX.DLL
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\reginald\appdata\roaming\mozilla\firefox\profiles\0gixnud9.default\
FF - prefs.js: browser.startup.homepage - hxxp://watch.slingbox.com/watch/sling_player
.
============= SERVICES / DRIVERS ===============
.
R? ACTIVEWEBCAM;Active WebCam
R? ACTIVEWEBCAMWATCHDOG;Active WebCam Watchdog
R? AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service
R? b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0
R? BBSvc;Bing Bar Update Service
R? btusbflt;Bluetooth USB Filter
R? clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86
R? cpudrv;cpudrv
R? DUMeterDrv;Hagel Technologies DU Meter traffic accounting driver
R? epmntdrv;epmntdrv
R? EuGdiDrv;EuGdiDrv
R? GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335
R? gupdate;Google Update Service (gupdate)
R? gupdatem;Google Update Service (gupdatem)
R? libusb0;LibUsb-Win32 - Kernel Driver 06/04/2010,1.12.1.0
R? LMIRfsClientNP;LMIRfsClientNP
R? Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service
R? MSSQLServerADHelper100;SQL Active Directory Helper Service
R? NisDrv;Microsoft Network Inspection System
R? NisSrv;Microsoft Network Inspection
R? osppsvc;Office Software Protection Platform
R? PLCNDIS5;PLCNDIS5 NDIS Protocol Driver
R? RdpVideoMiniport;Remote Desktop Video Miniport Driver
R? RsFx0103;RsFx0103 Driver
R? SandraAgentSrv;SiSoftware Deployment Agent Service
R? SBSDWSCService;SBSD Security Center Service
R? SkypeUpdate;Skype Updater
R? SQLAgent$MICROSOFTSCM;SQL Server Agent (MICROSOFTSCM)
R? Synth3dVsc;Synth3dVsc
R? TsUsbFlt;TsUsbFlt
R? tsusbhub;tsusbhub
R? VGPU;VGPU
R? WatAdminSvc;Windows Activation Technologies Service
R? XE102Mp5;XE102Mp5 NDIS Protocol Driver
R? XE102Sp5;XE102Sp5 NDIS Protocol Driver
S? !SASCORE;SAS Core Service
S? afcdp;afcdp
S? afcdpsrv;Acronis Nonstop Backup service
S? AMD External Events Utility;AMD External Events Utility
S? amdkmdag;amdkmdag
S? amdkmdap;amdkmdap
S? APC Data Service;APC Data Service
S? asdrs;AntiMalware Host-based Intrusion Prevention System
S? asdsrv;Anvi Smart Defender Realtime Guard Service
S? asdws;AnviSmartDefender Web Guard
S? BBUpdate;BBUpdate
S? btwl2cap;Bluetooth L2CAP Service
S? DbgSvc;Debug Diagnostic Service
S? DUMeterSvc;DU Meter Service
S? kmodurl;kmodurl
S? KSafeSvc;KSafe service
S? LMIGuardianSvc;LMIGuardianSvc
S? LMIInfo;LogMeIn Kernel Information Provider
S? LMIRfsDriver;LogMeIn Remote File System Driver
S? MBAMProtector;MBAMProtector
S? MBAMService;MBAMService
S? MpFilter;Microsoft Malware Protection Driver
S? MpKsl7ad2c85a;MpKsl7ad2c85a
S? MSSQL$MICROSOFTSCM;SQL Server (MICROSOFTSCM)
S? PCDSRVC{E9D79540-57D5953E-06020101}_0;PCDSRVC{E9D79540-57D5953E-06020101}_0 - PCDR Kernel Mode Service Helper Driver
S? SASDIFSV;SASDIFSV
S? SASKUTIL;SASKUTIL
S? silabenm;Silicon Labs CP210x USB to UART Bridge Serial Port Enumerator Driver
S? silabser;Silicon Labs CP210x USB to UART Bridge Driver
S? SlingAgentService;SlingAgentService
S? StarWindServiceAE;StarWind AE Service
S? tdrpman273;Acronis Try&Decide and Restore Points filter (build 273)
S? TeamViewer6;TeamViewer 6
S? VST_DPV;VST_DPV
S? VSTHWBS2;VSTHWBS2
S? VX6000;Microsoft LifeCam VX-6000
.
=============== Created Last 30 ================
.
2012-08-18 14:28:5856200----a-w-c:\programdata\microsoft\microsoft antimalware\definition updates\{d038ea17-3377-478b-b5ed-19b9e4cfa74b}\offreg.dll
2012-08-18 14:27:54--------d-----w-c:\users\reginald\appdata\roaming\Anvisoft
2012-08-18 14:27:4422864----a-w-c:\windows\system32\drivers\asdrs.sys
2012-08-18 14:27:4416208----a-w-c:\windows\system32\drivers\asdrm.sys
2012-08-18 14:27:4414160----a-w-c:\windows\system32\drivers\asdws.sys
2012-08-18 14:27:43--------d-----w-c:\programdata\Anvisoft
2012-08-18 14:27:36--------d-----w-c:\program files\Anvisoft
2012-08-18 13:39:5729904----a-w-c:\programdata\microsoft\microsoft antimalware\definition updates\{d038ea17-3377-478b-b5ed-19b9e4cfa74b}\MpKsl7ad2c85a.sys
2012-08-18 12:45:35--------d-----w-c:\programdata\Safe
2012-08-17 20:51:3622872----a-r-c:\windows\system32\AdobePDFUI.dll
2012-08-17 20:47:02103904----a-w-c:\program files\mozilla firefox\plugins\nppdf32.dll
2012-08-17 19:02:316891424----a-w-c:\programdata\microsoft\microsoft antimalware\definition updates\{d038ea17-3377-478b-b5ed-19b9e4cfa74b}\mpengine.dll
2012-08-17 16:23:48--------d-----w-c:\program files\ESET
2012-08-17 15:11:25--------d-sh--w-C:\$RECYCLE.BIN
2012-08-16 17:25:59--------d-----w-c:\users\reginald\appdata\roaming\ActiveWords 2.0
2012-08-16 17:25:49--------d-----w-c:\programdata\Licenses
2012-08-16 17:25:17232915----a-w-c:\windows\ActiveWords Uninstaller.exe
2012-08-16 17:25:16--------d-----w-c:\program files\common files\orangequava
2012-08-16 17:25:10--------d-----w-c:\program files\ActiveWords
2012-08-16 13:42:396891424----a-w-c:\programdata\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2012-08-16 13:13:20393728----a-w-c:\windows\system32\drivers\bthport.sys
2012-08-16 13:09:562345984----a-w-c:\windows\system32\win32k.sys
2012-08-16 13:09:54400896----a-w-c:\windows\system32\srcore.dll
2012-08-16 13:09:2741984----a-w-c:\windows\system32\browcli.dll
2012-08-16 13:09:27102912----a-w-c:\windows\system32\browser.dll
2012-08-16 13:09:25769024----a-w-c:\windows\system32\localspl.dll
2012-08-15 23:44:51--------d-----w-c:\program files\AirPort
2012-08-15 15:23:34--------d-----w-C:\Backreg
2012-08-15 14:56:0398816----a-w-c:\windows\sed.exe
2012-08-15 14:56:03518144----a-w-c:\windows\SWREG.exe
2012-08-15 14:56:03256000----a-w-c:\windows\PEV.exe
2012-08-15 14:56:03208896----a-w-c:\windows\MBR.exe
2012-08-15 12:10:46691696----a-w-c:\windows\system32\drivers\sptd.sys
2012-08-15 12:10:06--------d-----w-c:\program files\LSoft Technologies
2012-08-15 03:59:39--------d-----w-c:\windows\RestoreSafeDeleted
2012-08-15 03:52:59--------d-----w-c:\program files\UnHackMe
2012-08-15 03:28:262--shatr-c:\windows\winstart.bat
2012-08-15 03:28:16--------d-----w-c:\program files\Greatis
2012-08-15 03:23:05--------d-----w-c:\programdata\RegRun
2012-08-15 02:08:43--------d-----w-c:\programdata\HitmanPro
2012-08-15 01:14:14713784------w-c:\programdata\microsoft\microsoft antimalware\definition updates\{93354889-7ea1-40c7-ac78-80f571619cc8}\gapaengine.dll
2012-08-15 01:13:24100864----a-w-C:\pwlyikod.sys
2012-08-15 01:08:28--------d-----w-c:\program files\Microsoft Security Client
2012-08-15 00:41:12--------d-----w-c:\programdata\Sophos
2012-08-15 00:41:0473728----a-r-c:\users\reginald\appdata\roaming\microsoft\installer\{b829e117-d072-41ea-9606-9826a38d34c1}\SVRTgui.exe1_810EDD9E2F0A4E2BACF86673C38D9F48.exe
2012-08-15 00:41:0473728----a-r-c:\users\reginald\appdata\roaming\microsoft\installer\{b829e117-d072-41ea-9606-9826a38d34c1}\SVRTgui.exe_810EDD9E2F0A4E2BACF86673C38D9F48.exe
2012-08-15 00:41:0473728----a-r-c:\users\reginald\appdata\roaming\microsoft\installer\{b829e117-d072-41ea-9606-9826a38d34c1}\ARPPRODUCTICON.exe
2012-08-15 00:41:01--------d-----w-c:\program files\Sophos
2012-08-15 00:19:33--------d-----w-C:\TDSSKiller_Quarantine
2012-07-21 11:43:40--------d-----w-c:\users\reginald\appdata\roaming\SUPERAntiSpyware.com
2012-07-21 11:43:26--------d-----w-c:\programdata\SUPERAntiSpyware.com
2012-07-21 11:43:26--------d-----w-c:\program files\SUPERAntiSpyware
.
==================== Find3M ====================
.
2012-08-16 16:11:15848--sha-w-c:\programdata\KGyGaAvL.sys
2012-08-15 07:17:43426184----a-w-c:\windows\system32\FlashPlayerApp.exe
2012-08-15 07:17:4270344----a-w-c:\windows\system32\FlashPlayerCPLApp.cpl
2012-08-15 00:20:37259072----a-w-c:\windows\system32\services.exe
2012-07-12 09:36:3483392----a-w-c:\windows\system32\LMIRfsClientNP.dll
2012-07-12 09:36:3352128----a-w-c:\windows\system32\spool\prtprocs\w32x86\LMIproc.dll
2012-07-12 09:36:3330624----a-w-c:\windows\system32\LMIport.dll
2012-07-12 09:36:3287456----a-w-c:\windows\system32\LMIinit.dll
2012-07-03 19:46:4422344----a-w-c:\windows\system32\drivers\mbam.sys
2012-06-29 00:16:581800704----a-w-c:\windows\system32\jscript9.dll
2012-06-29 00:09:011129472----a-w-c:\windows\system32\wininet.dll
2012-06-29 00:08:591427968----a-w-c:\windows\system32\inetcpl.cpl
2012-06-29 00:04:43142848----a-w-c:\windows\system32\ieUnatt.exe
2012-06-29 00:00:452382848----a-w-c:\windows\system32\mshtml.tlb
2012-06-06 14:49:521070152----a-w-c:\windows\system32\MSCOMCTL.OCX
2012-06-06 05:05:521390080----a-w-c:\windows\system32\msxml6.dll
2012-06-06 05:05:521236992----a-w-c:\windows\system32\msxml3.dll
2012-06-06 05:03:06805376----a-w-c:\windows\system32\cdosys.dll
2012-06-02 22:12:322422272----a-w-c:\windows\system32\wucltux.dll
2012-06-02 22:12:1388576----a-w-c:\windows\system32\wudriver.dll
2012-06-02 21:19:42171904----a-w-c:\windows\system32\wuwebv.dll
2012-06-02 21:12:2033792----a-w-c:\windows\system32\wuapp.exe
2012-06-02 04:45:0467440----a-w-c:\windows\system32\drivers\ksecdd.sys
2012-06-02 04:45:03134000----a-w-c:\windows\system32\drivers\ksecpkg.sys
2012-06-02 04:40:59369336----a-w-c:\windows\system32\drivers\cng.sys
2012-06-02 04:40:39225280----a-w-c:\windows\system32\schannel.dll
2012-06-02 04:39:10219136----a-w-c:\windows\system32\ncrypt.dll
2012-05-22 19:16:2183360----a-w-c:\windows\system32\LMIRfsClientNP.dll.000.bak
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 6.1.7601 Disk: ST332062 rev.3.AD -> Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: >>UNKNOWN [0x83000000]<< >>UNKNOWN [0x8C188000]<< >>UNKNOWN [0x8C177000]<< >>UNKNOWN [0x8B8BB000]<< >>UNKNOWN [0x8B6AD000]<< >>UNKNOWN [0x83412000]<< >>UNKNOWN [0x85B5C938]<<
_asm { DEC EBP; POP EDX; NOP ; ADD [EBX], AL; ADD [EAX], AL; ADD [EAX+EAX], AL; ADD [EAX], AL; }
1 ntkrnlpa!IofCallDriver[0x8303755A] -> \Device\Harddisk0\DR0[0x874134B0]
\Driver\Disk[0x87412388] -> IRP_MJ_CREATE -> 0x8C18C39F
3 [0x8C18C59E] -> ntkrnlpa!IofCallDriver[0x8303755A] -> \Device\Ide\IAAStorageDevice-1[0x86ECB028]
\Driver\iaStor[0x868EC770] -> IRP_MJ_CREATE -> 0x8B900580
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; MOV ES, AX; MOV DS, AX; MOV SI, 0x7c00; MOV DI, 0x600; MOV CX, 0x200; CLD ; REP MOVSB ; PUSH AX; PUSH 0x61c; RETF ; STI ; MOV CX, 0x4; MOV BP, 0x7be; CMP BYTE [BP+0x0], 0x0; }
user & kernel MBR OK
Warning: possible TDL3 rootkit infection !
.
============= FINISH: 15:23:00.94 ===============
Attach:
NLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
.
==== Installed Programs ======================
.
µTorrent
32 bit Windows Card Reader Driver
7-Zip 4.65
Acronis True Image Home 2011
Active@ ISO Burner
ActiveWords
AddThis Toolbar
Adobe Acrobat 9 Pro Extended - English, Français, Deutsch
Adobe Acrobat 9.5.2 - CPSID_83708
Adobe After Effects CS4 Third Party Content
Adobe Anchor Service CS4
Adobe Creative Suite 4 Master Collection
Adobe CSI CS4
Adobe Dreamweaver CS4
Adobe Encore CS4 Codecs
Adobe ExtendScript Toolkit CS4
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Media Encoder CS4 Exporter
Adobe Media Encoder CS4 Importer
Adobe Photoshop Lightroom 3
Adobe Premiere Pro CS4 Third Party Content
Adobe Search for Help
Adobe Service Manager Extension
Adobe Setup
Adobe Soundbooth CS4 Codecs
Adobe Update Manager CS4
Air Video Server 2.4.3
AirPort
AMD Drag and Drop Transcoding
Anvi Smart Defender 1.5
Any Video Converter Professional 2.7.6
APC PowerChute Personal Edition
APC PowerChute Personal Edition 3.0
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ArcSoft Print Creations
ArcSoft Print Creations - Album Page
ArcSoft Print Creations - Funhouse
ArcSoft Print Creations - Greeting Card
ArcSoft Print Creations - Photo Book
ArcSoft Print Creations - Photo Calendar
ArcSoft Print Creations - Scrapbook
ArcSoft Print Creations - Slimline Card
ATI Catalyst Install Manager
ATI Catalyst Registration
Bing Bar
BlackBerry Desktop Software 6.0
BlackBerry® Media Sync
Bonjour
Browser Address Error Redirector
BS.Player PRO
Catalyst Control Center - Branding
CCleaner
CCScore
Choice Guard
Chromium
Compatibility Pack for the 2007 Office system
Connect
CopyTrans Suite Remove Only
Corel WordPerfect Office - iFilter
Cumulus 1.9.2
CuteFTP 8 Professional
Debug Diagnostics 1.2 32-bit
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition
Dell Driver Download Manager
Dell Getting Started Guide
Dell Support Center
Digital Line Detect
Dropbox
DU Meter
EASEUS Partition Master 9.0.0 Home Edition
ESET Online Scanner v3
ESSBrwr
ESSCDBK
ESScore
ESSgui
ESSini
ESSPCD
ESSPDock
ESSTOOLS
essvatgt
EVEREST Ultimate Edition v5.02
Fences Pro
fflink
Garmin Communicator Plugin
Garmin Lifetime Updater
Garmin USB Drivers
GoodSync
Google Chrome
Google Chrome Frame
Google Desktop
Google Earth
Google Earth Pro
Google Toolbar for Internet Explorer
Google Update Helper
GoToMyPC
HD Tune 2.55
HijackThis 2.0.2
HP Integrated Module with Bluetooth wireless technology
iCloud
InstallMgr
Intel(R) Matrix Storage Manager
Intel(R) Network Connections 15.2.89.0
Intel(R) Processor ID Utility
Ipswitch WS_FTP Pro
IPView Pro 2.0
iTunes
Java(TM) 6 Update 17
Jawbone Updater
kgcbaby
kgchday
kgchlwn
kgcinvt
kgckids
kgcmove
kgcvday
Kingsoft PC Doctor 3.3.1.9
Kodak EasyShare software
kuler
Licensing Service Install
LogMeIn
Loki ActiveX Control
MagicDisc 2.7.106
Malwarebytes Anti-Malware version 1.62.0.1300
Microsoft .NET Framework 4 Client Profile
Microsoft Corporation
Microsoft Default Manager
Microsoft IntelliPoint 8.2
Microsoft LifeCam
Microsoft Mathematics Add-in (32-bit)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office Access MUI (English) 2010
Microsoft Office Access Setup Metadata MUI (English) 2010
Microsoft Office Excel MUI (English) 2010
Microsoft Office Groove MUI (English) 2010
Microsoft Office InfoPath MUI (English) 2010
Microsoft Office Live Add-in 1.5
Microsoft Office OneNote MUI (English) 2010
Microsoft Office Outlook MUI (English) 2010
Microsoft Office PowerPoint MUI (English) 2010
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Professional Plus 2010
Microsoft Office Proof (English) 2010
Microsoft Office Proof (French) 2010
Microsoft Office Proof (Spanish) 2010
Microsoft Office Proofing (English) 2010
Microsoft Office Publisher MUI (English) 2010
Microsoft Office Shared MUI (English) 2010
Microsoft Office Shared Setup Metadata MUI (English) 2010
Microsoft Office Word MUI (English) 2010
Microsoft Security Client
Microsoft Security Compliance Manager 1.0
Microsoft Security Essentials
Microsoft Silverlight
Microsoft SQL Server 2008
Microsoft SQL Server 2008 Browser
Microsoft SQL Server 2008 Common Files
Microsoft SQL Server 2008 Database Engine Services
Microsoft SQL Server 2008 Database Engine Shared
Microsoft SQL Server 2008 Native Client
Microsoft SQL Server 2008 RsFx Driver
Microsoft SQL Server 2008 Setup Support Files
Microsoft SQL Server VSS Writer
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
Microsoft Works
MobileMe Control Panel
Mozilla Firefox 11.0 (x86 en-US)
MSN Toolbar
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Music, Photos & Videos Launcher
netbrdg
NETGEAR XE102 Powerline Encryption Utility
NETGEAR XE104 Powerline Encryption Utility
NetWaiting
NetworkView Version 3.60
Nuance OmniPage 17
Octoshape add-in for Adobe Flash Player
OfotoXMI
OGA Notifier 2.0.0048.0
OpenOffice.org 3.1
Picasa 3
Product Documentation Launcher
QuickTime
RegRun Reanimator
RoboForm 7-7-9-9 (All Users)
Roxio Creator Audio
Roxio Creator Copy
Roxio Creator Data
Roxio Creator DE
Roxio Creator Tools
Roxio Express Labeler 3
Roxio Media Manager
Roxio Update Manager
SABnzbd 0.6.10
Safari
Sanmaxi Outlook Password Recovery Trial Version 5.0.1
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft Excel 2010 (KB2597166) 32-Bit Edition
Security Update for Microsoft InfoPath 2010 (KB2553322) 32-Bit Edition
Security Update for Microsoft InfoPath 2010 (KB2553431) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2553091)
Security Update for Microsoft Office 2010 (KB2553096)
Security Update for Microsoft Office 2010 (KB2553260) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2553371) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2553447) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2589320) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2589322) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2597986) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2598243) 32-Bit Edition
Security Update for Microsoft PowerPoint 2010 (KB2553185) 32-Bit Edition
Security Update for Microsoft SharePoint Workspace 2010 (KB2566445)
Security Update for Microsoft Visio Viewer 2010 (KB2598287) 32-Bit Edition
Service Pack 1 for SQL Server 2008 (KB968369)
Setup Wizard
SetupWizard
SFR
SHASTA
SigmaTel Audio
Silicon Laboratories CP210x VCP Drivers for Windows 2000/XP/2003 Server/Vista
SiSoftware Sandra Professional Business 2009.SP3c
skin0001
SKINXSDK
Skype Toolbars
Skype™ 5.10
SlingPlayer
Snagit 10
Sophos Virus Removal Tool
Spybot - Search & Destroy
Sql Server Customer Experience Improvement Program
StarDot Tools 1.5.3
staticcr
Suite Shared Configuration CS4
SUPERAntiSpyware
SysMetrix 3.44
System Requirements Lab for Intel
TeamViewer 6
TerraExplorer
The Lord of the Rings FREE Trial
tooltips
Uniblue DriverScanner 2009
Uniblue PowerSuite 2009
Uniblue RegistryBooster 2009
Uniblue SpeedUpMyPC 2009
Unity Web Player
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft Office 2010 (KB2494150)
Update for Microsoft Office 2010 (KB2553065)
Update for Microsoft Office 2010 (KB2553092)
Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553272) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition
Update for Microsoft Office 2010 (KB2566458)
Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition
Update for Microsoft Office 2010 (KB2598289) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2589345) 32-Bit Edition
Update for Microsoft Outlook 2010 (KB2553248) 32-Bit Edition
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition
User's Guides
V CAST Music with Rhapsody
ViewSonic Monitor Drivers
Virtual Weather Station
VLC media player 1.0.0
VMware Workstation
VNC Enterprise Edition E4.4.2
VNC Mirror Driver 1.8.0
VPRINTOL
WeatherLink 5.8.3
WebSlingPlayer ActiveX
WePrint
Windows 7 Upgrade Advisor
Windows Driver Package - Garmin (grmnusb) GARMIN Devices (03/08/2007 2.2.1.0)
Windows Live ID Sign-in Assistant
Windows Live Upload Tool
Windows XP Mode
WinRAR archiver
WinZip 12.1
WIRELESS
WordPerfect Office X4
WordPerfect Office X4 - Common
WordPerfect Office X4 - Content
WordPerfect Office X4 - EN
WordPerfect Office X4 - Filters
WordPerfect Office X4 - Graphics
WordPerfect Office X4 - ICA
WordPerfect Office X4 - IPM
WordPerfect Office X4 - IPM EN
WordPerfect Office X4 - MAIL
WordPerfect Office X4 - Migration Manager
WordPerfect Office X4 - PerfectExperts
WordPerfect Office X4 - PR
WordPerfect Office X4 - QP
WordPerfect Office X4 - Skins
WordPerfect Office X4 - System
WordPerfect Office X4 - WP
World of Warcraft FREE Trial
Xmarks for IE
Xmarks Thumbnails for IE
XPS MiniView Gadget
.
==== End Of File ===========================
First detected problem:
2012/08/13 10:28:37 -0600REGINALD-PCReginaldIP-BLOCK109.163.227.72 (Type: incoming, Port: 3389)
2012/08/13 10:28:46 -0600REGINALD-PCReginaldIP-BLOCK109.163.227.72 (Type: incoming, Port: 3389)
2012/08/13 10:28:46 -0600REGINALD-PCReginaldIP-BLOCK109.163.227.72 (Type: incoming, Port: 3389)
2012/08/13 14:28:50 -0600REGINALD-PCReginaldMESSAGEStopping IP protection
2012/08/13 14:31:56 -0600REGINALD-PCReginaldMESSAGEIP Protection stopped
2012/08/13 17:47:08 -0600REGINALD-PCReginaldDETECTIONC:\Users\Reginald\AppData\Local\Temp\013922622cb0.exeRootKit.0AccessALLOW
2012/08/13 17:47:39 -0600REGINALD-PCReginaldDETECTIONC:\Windows\Installer\{f9ef26a6-5650-2172-7144-5aa984cc63b0}\U\800000cb.@Rootkit.0AccessALLOW
2012/08/13 17:47:43 -0600REGINALD-PCReginaldDETECTIONC:\Users\Reginald\AppData\Local\Temp\013922622CB0.EXERootKit.0AccessALLOW
2012/08/13 17:47:44 -0600REGINALD-PCReginaldDETECTIONC:\Windows\Installer\{f9ef26a6-5650-2172-7144-5aa984cc63b0}\U\800000cb.@Rootkit.0AccessALLOW
2012/08/13 22:38:27 -0600REGINALD-PCReginaldDETECTIONC:\Users\Reginald\AppData\Local\{f9ef26a6-5650-2172-7144-5aa984cc63b0}\nRootKit.0AccessALLOW
2012/08/13 22:39:07 -0600REGINALD-PCReginaldDETECTIONC:\Users\Reginald\AppData\Local\{f9ef26a6-5650-2172-7144-5aa984cc63b0}\nRootKit.0AccessALLOW
2012/08/13 23:00:37 -0600REGINALD-PCReginaldDETECTIONC:\Users\Reginald\AppData\Local\{f9ef26a6-5650-2172-7144-5aa984cc63b0}\nRootKit.0AccessALLOW
Then next log reported :
2012/08/14 13:09:52 -0600REGINALD-PCReginaldMESSAGEStarting protection
2012/08/14 13:09:55 -0600REGINALD-PCReginaldMESSAGEProtection started successfully
2012/08/14 13:09:58 -0600REGINALD-PCReginaldMESSAGEStarting IP protection
2012/08/14 13:09:58 -0600REGINALD-PCReginaldERRORIP protection failed: FwpmEngineOpen0 failed with error code 1753
2012/08/14 15:31:38 -0600REGINALD-PCReginaldDETECTIONC:\Users\Reginald\AppData\Local\{F9EF26A6-5650-2172-7144-5AA984CC63B0}\nRootKit.0AccessQUARANTINE
2012/08/14 15:31:38 -0600REGINALD-PCReginaldERRORQuarantine failed: DeleteFile failed with error code 5
2012/08/14 15:40:24 -0600REGINALD-PCReginaldMESSAGEStarting protection
2012/08/14 15:40:27 -0600REGINALD-PCReginaldMESSAGEProtection started successfully
2012/08/14 15:40:30 -0600REGINALD-PCReginaldMESSAGEStarting IP protection
2012/08/14 15:40:30 -0600REGINALD-PCReginaldERRORIP protection failed: FwpmEngineOpen0 failed with error code 1753
2012/08/14 15:43:08 -0600REGINALD-PCReginaldMESSAGEStarting database refresh
2012/08/14 15:43:10 -0600REGINALD-PCReginaldMESSAGEDatabase refreshed successfully
2012/08/14 16:34:15 -0600REGINALD-PCReginaldDETECTIONC:\Windows\Installer\{f9ef26a6-5650-2172-7144-5aa984cc63b0}\U\800000cb.@Rootkit.0AccessQUARANTINE
2012/08/14 19:06:59 -0600REGINALD-PCReginaldMESSAGEStarting protection
2012/08/14 19:07:08 -0600REGINALD-PCReginaldMESSAGEProtection started successfully
2012/08/14 19:07:11 -0600REGINALD-PCReginaldMESSAGEStarting IP protection
2012/08/14 19:07:11 -0600REGINALD-PCReginaldERRORIP protection failed: FwpmEngineOpen0 failed with error code 1753
2012/08/14 20:01:14 -0600REGINALD-PCReginaldMESSAGEStarting protection
2012/08/14 20:01:17 -0600REGINALD-PCReginaldMESSAGEProtection started successfully
2012/08/14 20:01:20 -0600REGINALD-PCReginaldMESSAGEStarting IP protection
2012/08/14 20:01:20 -0600REGINALD-PCReginaldERRORIP protection failed: FwpmEngineOpen0 failed with error code 1753
2012/08/14 21:03:29 -0600REGINALD-PCReginaldMESSAGEStarting protection
2012/08/14 21:03:32 -0600REGINALD-PCReginaldMESSAGEProtection started successfully
2012/08/14 21:03:35 -0600REGINALD-PCReginaldMESSAGEStarting IP protection
2012/08/14 21:03:35 -0600REGINALD-PCReginaldERRORIP protection failed: FwpmEngineOpen0 failed with error code 1753
Then next log reported :
2012/08/15 07:48:49 -0600REGINALD-PCReginaldMESSAGEStarting protection
2012/08/15 07:48:52 -0600REGINALD-PCReginaldMESSAGEProtection started successfully
2012/08/15 07:48:55 -0600REGINALD-PCReginaldMESSAGEStarting IP protection
2012/08/15 07:48:55 -0600REGINALD-PCReginaldERRORIP protection failed: FwpmEngineOpen0 failed with error code 1753
2012/08/15 21:27:20 -0600REGINALD-PCReginaldMESSAGEExecuting scheduled update: Weekly | Silent
2012/08/15 21:27:48 -0600REGINALD-PCReginaldMESSAGEScheduled update executed successfully: database updated from version v2012.08.14.07 to version v2012.08.16.02
2012/08/15 22:30:00 -0600REGINALD-PCReginaldMESSAGEExecuting scheduled scan: Quick Scan | Weekly | -reboot
2012/08/15 22:30:00 -0600REGINALD-PCReginaldMESSAGEScheduled scan executed successfully
Next Log:
012/08/16 07:53:54 -0600REGINALD-PCReginaldMESSAGEStarting protection
2012/08/16 07:54:05 -0600REGINALD-PCReginaldMESSAGEProtection started successfully
2012/08/16 07:54:08 -0600REGINALD-PCReginaldMESSAGEStarting IP protection
2012/08/16 07:54:09 -0600REGINALD-PCReginaldMESSAGEIP Protection started successfully
Last log:
2012/08/17 08:18:44 -0600REGINALD-PCReginaldMESSAGEStopping IP protection
2012/08/17 08:18:44 -0600REGINALD-PCReginaldMESSAGEIP Protection stopped
2012/08/17 13:01:51 -0600REGINALD-PCReginaldMESSAGEStarting database refresh
2012/08/17 13:02:01 -0600REGINALD-PCReginaldMESSAGEDatabase refreshed successfully
2012/08/17 13:02:21 -0600REGINALD-PCReginaldMESSAGEStarting IP protection
2012/08/17 13:02:23 -0600REGINALD-PCReginaldMESSAGEIP Protection started successfully
GMER:
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit quick scan 2012-08-18 15:13:30
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST332062 rev.3.AD
Running: cztdodz5.exe; Driver: C:\Users\Reginald\AppData\Local\Temp\pwlyikod.sys
---- Devices - GMER 1.0.15 ----
Device \Driver\iaStor \Device\Ide\iaStor0 [8B900580] \SystemRoot\system32\DRIVERS\iaStor.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\iaStor \Device\Ide\IAAStorageDevice-0 [8B900580] \SystemRoot\system32\DRIVERS\iaStor.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device iaStor.sys (Intel Matrix Storage Manager driver - ia32/Intel Corporation)
Device 85B891F8
Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
AttachedDevice tdrpm273.sys (Acronis Try&Decide Volume Filter Driver/Acronis)
Device 878541F8
Device fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Ip kmodurl.sys
AttachedDevice \Driver\tdx \Device\Tcp kmodurl.sys
AttachedDevice \Driver\tdx \Device\Udp kmodurl.sys
AttachedDevice \Driver\tdx \Device\RawIp kmodurl.sys
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 VMkbd.sys
---- EOF - GMER 1.0.15 ----
DDS File:
DDS
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_17
Run by Reginald at 15:18:21 on 2012-08-18
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\system32\atieclxx.exe
C:\Program Files\Kingsoft\PcDoctor\KSafeSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Google\Update\1.3.21.115\GoogleCrashHandler.exe
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Microsoft\BingBar\SeaPort.EXE
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
C:\Program Files\DebugDiag\DbgSvc.exe
C:\Program Files\DU Meter\DUMeterSvc.exe
C:\Program Files\Citrix\GoToMyPC\g2svc.exe
C:\Program Files\Citrix\GoToMyPC\g2comm.exe
C:\Program Files\Citrix\GoToMyPC\g2pre.exe
C:\Program Files\Citrix\GoToMyPC\g2tray.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Windows\vVX6000.exe
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\VMware\VMware Workstation\vmware-tray.exe
C:\Program Files\SysMetrix\SysMetrix.exe
C:\Program Files\Acronis\OnlineBackupStandalone\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Kingsoft\PcDoctor\KSafeTray.exe
C:\Program Files\Garmin\Lifetime Updater\GarminLifetime.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\AirPort\APAgent.exe
C:\Program Files\AirVideoServer\AirVideoServer.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\DU Meter\DUMeter.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE
c:\Program Files\Microsoft SQL Server\MSSQL10.MICROSOFTSCM\MSSQL\Binn\sqlservr.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\Program Files\Xmarks\IE Extension\xmarkssync.exe
C:\Program Files\Common Files\Apple\Internet Services\ubd.exe
C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\TechSmith\Snagit 10\Snagit32.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe
C:\Windows\system32\conhost.exe
C:\Program Files\TechSmith\Snagit 10\TSCHelp.exe
C:\Program Files\TechSmith\Snagit 10\SnagPriv.exe
C:\Program Files\Sling Media\SlingAgent\SlingAgentService.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe
C:\Program Files\Active WebCam\WebCam.exe
C:\Users\Reginald\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\vws\vws.exe
C:\Program Files\WePrint\WePrint Server.exe
C:\Program Files\TechSmith\Snagit 10\snagiteditor.exe
C:\Program Files\APC\APC PowerChute Personal Edition\dataserv.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\TeamViewer\Version6\TeamViewer.exe
C:\Program Files\Active WebCam\CompParams.exe
C:\Program Files\Active WebCam\Watchdog.exe
C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\dllhost.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Windows\System32\msdtc.exe
C:\Program Files\Malwarebytes' Anti-Malware\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Users\Reginald\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Reginald\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Reginald\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Reginald\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Reginald\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Reginald\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Reginald\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Anvisoft\Anvi Smart Defender\ASDSrv.exe
C:\Windows\system32\taskhost.exe
C:\Users\Reginald\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Reginald\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Dell Support Center\pcdrcui.exe
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Users\Reginald\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Reginald\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Users\Reginald\Desktop\rootkit\dds.com
C:\Windows\system32\conhost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\msfeedssync.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
uURLSearchHooks: FCToolbarURLSearchHook Class: {fa887e92-8f5f-4ec9-99ca-09be0e4120d6} - c:\program files\addthis toolbar\Helper.dll
BHO: SnagIt Toolbar Loader: {00c6482d-c502-44c8-8409-fce54ad9c208} - c:\program files\techsmith\snagit 10\SnagitBHO.dll
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: ThumbnailsBHO Class: {1bd0befe-f697-4eee-b7e1-76b849a5cb84} - c:\program files\xmarks\thumbnails for ie\xmarksthumbnails.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot - search & destroy\SDHelper.dll
BHO: {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - No File
BHO: RoboForm Toolbar Helper: {724d43a9-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\microsoft office\office14\GROOVEEX.DLL
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: {9EBF8AAF-0A31-4786-909A-97A0EF101743} - No File
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
BHO: Skype add-on for Internet Explorer: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\microsoft office\office14\URLREDIR.DLL
BHO: {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - No File
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "c:\program files\microsoft\bingbar\BingExt.dll"
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: ChromeFrame BHO: {ecb3c477-1a0a-44bd-bb57-78f9efe34fa7} - c:\program files\google\chrome\application\21.0.1180.79\npchrome_frame.dll
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: &RoboForm Toolbar: {724d43a0-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll
TB: Snagit: {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - c:\program files\techsmith\snagit 10\SnagitIEAddin.dll
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "c:\program files\microsoft\bingbar\BingExt.dll"
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [AirVideoServer] c:\program files\airvideoserver\AirVideoServer.exe
uRun: [AlcoholAutomount] "c:\program files\alcohol soft\alcohol 120\axcmd.exe" /automount
uRun: [DU Meter] c:\program files\du meter\DUMeter.exe
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [OfficeSyncProcess] "c:\program files\microsoft office\office14\MSOSYNC.EXE"
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [MobileDocuments] c:\program files\common files\apple\internet services\ubd.exe
uRun: [RoboForm] "c:\program files\siber systems\ai roboform\RoboTaskBarIcon.exe"
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
mRun: [VX6000] c:\windows\vVX6000.exe
mRun: [Bluetooth HCI Monitor] RunDll32 HCIMNTR.DLL,RunCheckHCIMode
mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 9.0\acrobat\Acrotray.exe"
mRun: [Adobe Acrobat Speed Launcher] "c:\program files\adobe\acrobat 9.0\acrobat\Acrobat_sl.exe"
mRun: [AdobeCS4ServiceManager] "c:\program files\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe
mRun: [ECenter] c:\dell\e-center\EULALauncher.exe
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [IAAnotif] "c:\program files\intel\intel matrix storage manager\Iaanotif.exe"
mRun: [LifeCam] "c:\program files\microsoft lifecam\LifeExp.exe"
mRun: [LogMeIn GUI] "c:\program files\logmein\x86\LogMeInSystray.exe"
mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume
mRun: [QuickFinder Scheduler] "c:\program files\corel\wordperfect office x4\programs\QFSCHD140.EXE"
mRun: [vmware-tray] "c:\program files\vmware\vmware workstation\vmware-tray.exe"
mRun: [ATICustomerCare] "c:\program files\ati\aticustomercare\ATICustomerCare.exe"
mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe"
mRun: [BCSSync] "c:\program files\microsoft office\office14\BCSSync.exe" /DelayServices
mRun: [SysMetrix] c:\program files\sysmetrix\SysMetrix.exe
mRun: [SAOB Monitor] c:\program files\acronis\onlinebackupstandalone\TrueImageMonitor.exe
mRun: [TrueImageMonitor.exe] "c:\program files\acronis\trueimagehome\TrueImageMonitor.exe"
mRun: [Acronis Scheduler2 Service] "c:\program files\common files\acronis\schedule2\schedhlp.exe"
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [KSafeTray] "c:\program files\kingsoft\pcdoctor\KSafeTray.exe" -autorun
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\malwarebytes' anti-malware\mbamgui.exe" /starttray
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [AirPort Base Station Agent] "c:\program files\airport\APAgent.exe"
mRun: [Anvi Smart Defender] c:\program files\anvisoft\anvi smart defender\ASDTray.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
mPolicies-system: EnableLinkedConnections = 1 (0x1)
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Append Link Target to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html
IE: Customize Menu - file://c:\program files\siber systems\ai roboform\RoboFormComCustomizeIEMenu.html
IE: E&xport to Microsoft Excel - c:\progra~1\microsoft office\office14\EXCEL.EXE/3000
IE: Fill Forms - file://c:\program files\siber systems\ai roboform\RoboFormComFillForms.html
IE: Open with WordPerfect - c:\program files\corel\wordperfect office x4\programs\WPLauncher.hta
IE: Save Forms - file://c:\program files\siber systems\ai roboform\RoboFormComSavePass.html
IE: Se&nd to OneNote - c:\progra~1\microsoft office\office14\ONBttnIE.dll/105
IE: Send image to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: Show RoboForm Toolbar - file://c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - c:\program files\siber systems\ai roboform\roboform.dll
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - c:\program files\siber systems\ai roboform\roboform.dll
IE: {724d43aa-0d85-11d4-9908-00400523e39a} - {724d43aa-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot - search & destroy\SDHelper.dll
Trusted Zone: garmin.com\connect
Trusted Zone: garmin.com\mygarmin
Trusted Zone: garmin.com\www
Trusted Zone: real.com\rhap-app-4-0
Trusted Zone: real.com\rhapreg
Trusted Zone: zoombak.com\locate
Trusted Zone: zoombak.com\shop
DPF: CaptureClient - hxxp://192.168.1.110/CaptureClient.cab
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {22D82B43-FF26-455A-A96D-A6C61F056ED7} - hxxp://192.168.1.210/xplugxLiteTW.cab
DPF: {362C56AA-6E4F-40C7-A0B5-85501DBDAD77} - hxxp://I.dell.com/images/global/js/scanner/SysProExe.cab
DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} - hxxp://support.dell.com/systemprofiler/SysProExe.CAB
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {82774781-8F4E-11D1-AB1C-0000F8773BF0} - hxxps://transfers.ds.microsoft.com/FTM/TransferSource/grTransferCtrl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {B80CD4E6-5B02-4B6C-99BE-68F1511E9549} - hxxp://plugin.slingbox.com/downloads/pc/1.4.0.111/WebSlingPlayer.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.1.66.0.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - hxxps://secure.logmein.com/activex/ractrl.cab?lmi=100
TCP: DhcpNameServer = 72.19.128.53 72.19.128.99
TCP: Interfaces\{297982DB-7F42-4718-8D4B-A71C72C5621A} : DhcpNameServer = 72.19.128.53 72.19.128.99
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Handler: gcf - {9875BFAF-B04D-445E-8A69-BE36838CDE3E} - c:\program files\google\chrome\application\21.0.1180.79\npchrome_frame.dll
Handler: skyline - {3a4f9195-65a8-11d5-85c1-0001023952c1} - c:\program files\skyline\terraexplorer\TerraExplorerX.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\Skype4COM.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
AppInit_DLLs: acaptuser32.dll
STS: FencesShlExt Class: {1984dd45-52cf-49cd-ab77-18f378fea264} - c:\program files\stardock\fences\FencesMenu.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\microsoft office\office14\GROOVEEX.DLL
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\reginald\appdata\roaming\mozilla\firefox\profiles\0gixnud9.default\
FF - prefs.js: browser.startup.homepage - hxxp://watch.slingbox.com/watch/sling_player
.
============= SERVICES / DRIVERS ===============
.
R? ACTIVEWEBCAM;Active WebCam
R? ACTIVEWEBCAMWATCHDOG;Active WebCam Watchdog
R? AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service
R? b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0
R? BBSvc;Bing Bar Update Service
R? btusbflt;Bluetooth USB Filter
R? clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86
R? cpudrv;cpudrv
R? DUMeterDrv;Hagel Technologies DU Meter traffic accounting driver
R? epmntdrv;epmntdrv
R? EuGdiDrv;EuGdiDrv
R? GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335
R? gupdate;Google Update Service (gupdate)
R? gupdatem;Google Update Service (gupdatem)
R? libusb0;LibUsb-Win32 - Kernel Driver 06/04/2010,1.12.1.0
R? LMIRfsClientNP;LMIRfsClientNP
R? Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service
R? MSSQLServerADHelper100;SQL Active Directory Helper Service
R? NisDrv;Microsoft Network Inspection System
R? NisSrv;Microsoft Network Inspection
R? osppsvc;Office Software Protection Platform
R? PLCNDIS5;PLCNDIS5 NDIS Protocol Driver
R? RdpVideoMiniport;Remote Desktop Video Miniport Driver
R? RsFx0103;RsFx0103 Driver
R? SandraAgentSrv;SiSoftware Deployment Agent Service
R? SBSDWSCService;SBSD Security Center Service
R? SkypeUpdate;Skype Updater
R? SQLAgent$MICROSOFTSCM;SQL Server Agent (MICROSOFTSCM)
R? Synth3dVsc;Synth3dVsc
R? TsUsbFlt;TsUsbFlt
R? tsusbhub;tsusbhub
R? VGPU;VGPU
R? WatAdminSvc;Windows Activation Technologies Service
R? XE102Mp5;XE102Mp5 NDIS Protocol Driver
R? XE102Sp5;XE102Sp5 NDIS Protocol Driver
S? !SASCORE;SAS Core Service
S? afcdp;afcdp
S? afcdpsrv;Acronis Nonstop Backup service
S? AMD External Events Utility;AMD External Events Utility
S? amdkmdag;amdkmdag
S? amdkmdap;amdkmdap
S? APC Data Service;APC Data Service
S? asdrs;AntiMalware Host-based Intrusion Prevention System
S? asdsrv;Anvi Smart Defender Realtime Guard Service
S? asdws;AnviSmartDefender Web Guard
S? BBUpdate;BBUpdate
S? btwl2cap;Bluetooth L2CAP Service
S? DbgSvc;Debug Diagnostic Service
S? DUMeterSvc;DU Meter Service
S? kmodurl;kmodurl
S? KSafeSvc;KSafe service
S? LMIGuardianSvc;LMIGuardianSvc
S? LMIInfo;LogMeIn Kernel Information Provider
S? LMIRfsDriver;LogMeIn Remote File System Driver
S? MBAMProtector;MBAMProtector
S? MBAMService;MBAMService
S? MpFilter;Microsoft Malware Protection Driver
S? MpKsl7ad2c85a;MpKsl7ad2c85a
S? MSSQL$MICROSOFTSCM;SQL Server (MICROSOFTSCM)
S? PCDSRVC{E9D79540-57D5953E-06020101}_0;PCDSRVC{E9D79540-57D5953E-06020101}_0 - PCDR Kernel Mode Service Helper Driver
S? SASDIFSV;SASDIFSV
S? SASKUTIL;SASKUTIL
S? silabenm;Silicon Labs CP210x USB to UART Bridge Serial Port Enumerator Driver
S? silabser;Silicon Labs CP210x USB to UART Bridge Driver
S? SlingAgentService;SlingAgentService
S? StarWindServiceAE;StarWind AE Service
S? tdrpman273;Acronis Try&Decide and Restore Points filter (build 273)
S? TeamViewer6;TeamViewer 6
S? VST_DPV;VST_DPV
S? VSTHWBS2;VSTHWBS2
S? VX6000;Microsoft LifeCam VX-6000
.
=============== Created Last 30 ================
.
2012-08-18 14:28:5856200----a-w-c:\programdata\microsoft\microsoft antimalware\definition updates\{d038ea17-3377-478b-b5ed-19b9e4cfa74b}\offreg.dll
2012-08-18 14:27:54--------d-----w-c:\users\reginald\appdata\roaming\Anvisoft
2012-08-18 14:27:4422864----a-w-c:\windows\system32\drivers\asdrs.sys
2012-08-18 14:27:4416208----a-w-c:\windows\system32\drivers\asdrm.sys
2012-08-18 14:27:4414160----a-w-c:\windows\system32\drivers\asdws.sys
2012-08-18 14:27:43--------d-----w-c:\programdata\Anvisoft
2012-08-18 14:27:36--------d-----w-c:\program files\Anvisoft
2012-08-18 13:39:5729904----a-w-c:\programdata\microsoft\microsoft antimalware\definition updates\{d038ea17-3377-478b-b5ed-19b9e4cfa74b}\MpKsl7ad2c85a.sys
2012-08-18 12:45:35--------d-----w-c:\programdata\Safe
2012-08-17 20:51:3622872----a-r-c:\windows\system32\AdobePDFUI.dll
2012-08-17 20:47:02103904----a-w-c:\program files\mozilla firefox\plugins\nppdf32.dll
2012-08-17 19:02:316891424----a-w-c:\programdata\microsoft\microsoft antimalware\definition updates\{d038ea17-3377-478b-b5ed-19b9e4cfa74b}\mpengine.dll
2012-08-17 16:23:48--------d-----w-c:\program files\ESET
2012-08-17 15:11:25--------d-sh--w-C:\$RECYCLE.BIN
2012-08-16 17:25:59--------d-----w-c:\users\reginald\appdata\roaming\ActiveWords 2.0
2012-08-16 17:25:49--------d-----w-c:\programdata\Licenses
2012-08-16 17:25:17232915----a-w-c:\windows\ActiveWords Uninstaller.exe
2012-08-16 17:25:16--------d-----w-c:\program files\common files\orangequava
2012-08-16 17:25:10--------d-----w-c:\program files\ActiveWords
2012-08-16 13:42:396891424----a-w-c:\programdata\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2012-08-16 13:13:20393728----a-w-c:\windows\system32\drivers\bthport.sys
2012-08-16 13:09:562345984----a-w-c:\windows\system32\win32k.sys
2012-08-16 13:09:54400896----a-w-c:\windows\system32\srcore.dll
2012-08-16 13:09:2741984----a-w-c:\windows\system32\browcli.dll
2012-08-16 13:09:27102912----a-w-c:\windows\system32\browser.dll
2012-08-16 13:09:25769024----a-w-c:\windows\system32\localspl.dll
2012-08-15 23:44:51--------d-----w-c:\program files\AirPort
2012-08-15 15:23:34--------d-----w-C:\Backreg
2012-08-15 14:56:0398816----a-w-c:\windows\sed.exe
2012-08-15 14:56:03518144----a-w-c:\windows\SWREG.exe
2012-08-15 14:56:03256000----a-w-c:\windows\PEV.exe
2012-08-15 14:56:03208896----a-w-c:\windows\MBR.exe
2012-08-15 12:10:46691696----a-w-c:\windows\system32\drivers\sptd.sys
2012-08-15 12:10:06--------d-----w-c:\program files\LSoft Technologies
2012-08-15 03:59:39--------d-----w-c:\windows\RestoreSafeDeleted
2012-08-15 03:52:59--------d-----w-c:\program files\UnHackMe
2012-08-15 03:28:262--shatr-c:\windows\winstart.bat
2012-08-15 03:28:16--------d-----w-c:\program files\Greatis
2012-08-15 03:23:05--------d-----w-c:\programdata\RegRun
2012-08-15 02:08:43--------d-----w-c:\programdata\HitmanPro
2012-08-15 01:14:14713784------w-c:\programdata\microsoft\microsoft antimalware\definition updates\{93354889-7ea1-40c7-ac78-80f571619cc8}\gapaengine.dll
2012-08-15 01:13:24100864----a-w-C:\pwlyikod.sys
2012-08-15 01:08:28--------d-----w-c:\program files\Microsoft Security Client
2012-08-15 00:41:12--------d-----w-c:\programdata\Sophos
2012-08-15 00:41:0473728----a-r-c:\users\reginald\appdata\roaming\microsoft\installer\{b829e117-d072-41ea-9606-9826a38d34c1}\SVRTgui.exe1_810EDD9E2F0A4E2BACF86673C38D9F48.exe
2012-08-15 00:41:0473728----a-r-c:\users\reginald\appdata\roaming\microsoft\installer\{b829e117-d072-41ea-9606-9826a38d34c1}\SVRTgui.exe_810EDD9E2F0A4E2BACF86673C38D9F48.exe
2012-08-15 00:41:0473728----a-r-c:\users\reginald\appdata\roaming\microsoft\installer\{b829e117-d072-41ea-9606-9826a38d34c1}\ARPPRODUCTICON.exe
2012-08-15 00:41:01--------d-----w-c:\program files\Sophos
2012-08-15 00:19:33--------d-----w-C:\TDSSKiller_Quarantine
2012-07-21 11:43:40--------d-----w-c:\users\reginald\appdata\roaming\SUPERAntiSpyware.com
2012-07-21 11:43:26--------d-----w-c:\programdata\SUPERAntiSpyware.com
2012-07-21 11:43:26--------d-----w-c:\program files\SUPERAntiSpyware
.
==================== Find3M ====================
.
2012-08-16 16:11:15848--sha-w-c:\programdata\KGyGaAvL.sys
2012-08-15 07:17:43426184----a-w-c:\windows\system32\FlashPlayerApp.exe
2012-08-15 07:17:4270344----a-w-c:\windows\system32\FlashPlayerCPLApp.cpl
2012-08-15 00:20:37259072----a-w-c:\windows\system32\services.exe
2012-07-12 09:36:3483392----a-w-c:\windows\system32\LMIRfsClientNP.dll
2012-07-12 09:36:3352128----a-w-c:\windows\system32\spool\prtprocs\w32x86\LMIproc.dll
2012-07-12 09:36:3330624----a-w-c:\windows\system32\LMIport.dll
2012-07-12 09:36:3287456----a-w-c:\windows\system32\LMIinit.dll
2012-07-03 19:46:4422344----a-w-c:\windows\system32\drivers\mbam.sys
2012-06-29 00:16:581800704----a-w-c:\windows\system32\jscript9.dll
2012-06-29 00:09:011129472----a-w-c:\windows\system32\wininet.dll
2012-06-29 00:08:591427968----a-w-c:\windows\system32\inetcpl.cpl
2012-06-29 00:04:43142848----a-w-c:\windows\system32\ieUnatt.exe
2012-06-29 00:00:452382848----a-w-c:\windows\system32\mshtml.tlb
2012-06-06 14:49:521070152----a-w-c:\windows\system32\MSCOMCTL.OCX
2012-06-06 05:05:521390080----a-w-c:\windows\system32\msxml6.dll
2012-06-06 05:05:521236992----a-w-c:\windows\system32\msxml3.dll
2012-06-06 05:03:06805376----a-w-c:\windows\system32\cdosys.dll
2012-06-02 22:12:322422272----a-w-c:\windows\system32\wucltux.dll
2012-06-02 22:12:1388576----a-w-c:\windows\system32\wudriver.dll
2012-06-02 21:19:42171904----a-w-c:\windows\system32\wuwebv.dll
2012-06-02 21:12:2033792----a-w-c:\windows\system32\wuapp.exe
2012-06-02 04:45:0467440----a-w-c:\windows\system32\drivers\ksecdd.sys
2012-06-02 04:45:03134000----a-w-c:\windows\system32\drivers\ksecpkg.sys
2012-06-02 04:40:59369336----a-w-c:\windows\system32\drivers\cng.sys
2012-06-02 04:40:39225280----a-w-c:\windows\system32\schannel.dll
2012-06-02 04:39:10219136----a-w-c:\windows\system32\ncrypt.dll
2012-05-22 19:16:2183360----a-w-c:\windows\system32\LMIRfsClientNP.dll.000.bak
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 6.1.7601 Disk: ST332062 rev.3.AD -> Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: >>UNKNOWN [0x83000000]<< >>UNKNOWN [0x8C188000]<< >>UNKNOWN [0x8C177000]<< >>UNKNOWN [0x8B8BB000]<< >>UNKNOWN [0x8B6AD000]<< >>UNKNOWN [0x83412000]<< >>UNKNOWN [0x85B5C938]<<
_asm { DEC EBP; POP EDX; NOP ; ADD [EBX], AL; ADD [EAX], AL; ADD [EAX+EAX], AL; ADD [EAX], AL; }
1 ntkrnlpa!IofCallDriver[0x8303755A] -> \Device\Harddisk0\DR0[0x874134B0]
\Driver\Disk[0x87412388] -> IRP_MJ_CREATE -> 0x8C18C39F
3 [0x8C18C59E] -> ntkrnlpa!IofCallDriver[0x8303755A] -> \Device\Ide\IAAStorageDevice-1[0x86ECB028]
\Driver\iaStor[0x868EC770] -> IRP_MJ_CREATE -> 0x8B900580
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; MOV ES, AX; MOV DS, AX; MOV SI, 0x7c00; MOV DI, 0x600; MOV CX, 0x200; CLD ; REP MOVSB ; PUSH AX; PUSH 0x61c; RETF ; STI ; MOV CX, 0x4; MOV BP, 0x7be; CMP BYTE [BP+0x0], 0x0; }
user & kernel MBR OK
Warning: possible TDL3 rootkit infection !
.
============= FINISH: 15:23:00.94 ===============
Attach:
NLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
.
==== Installed Programs ======================
.
µTorrent
32 bit Windows Card Reader Driver
7-Zip 4.65
Acronis True Image Home 2011
Active@ ISO Burner
ActiveWords
AddThis Toolbar
Adobe Acrobat 9 Pro Extended - English, Français, Deutsch
Adobe Acrobat 9.5.2 - CPSID_83708
Adobe After Effects CS4 Third Party Content
Adobe Anchor Service CS4
Adobe Creative Suite 4 Master Collection
Adobe CSI CS4
Adobe Dreamweaver CS4
Adobe Encore CS4 Codecs
Adobe ExtendScript Toolkit CS4
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Media Encoder CS4 Exporter
Adobe Media Encoder CS4 Importer
Adobe Photoshop Lightroom 3
Adobe Premiere Pro CS4 Third Party Content
Adobe Search for Help
Adobe Service Manager Extension
Adobe Setup
Adobe Soundbooth CS4 Codecs
Adobe Update Manager CS4
Air Video Server 2.4.3
AirPort
AMD Drag and Drop Transcoding
Anvi Smart Defender 1.5
Any Video Converter Professional 2.7.6
APC PowerChute Personal Edition
APC PowerChute Personal Edition 3.0
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ArcSoft Print Creations
ArcSoft Print Creations - Album Page
ArcSoft Print Creations - Funhouse
ArcSoft Print Creations - Greeting Card
ArcSoft Print Creations - Photo Book
ArcSoft Print Creations - Photo Calendar
ArcSoft Print Creations - Scrapbook
ArcSoft Print Creations - Slimline Card
ATI Catalyst Install Manager
ATI Catalyst Registration
Bing Bar
BlackBerry Desktop Software 6.0
BlackBerry® Media Sync
Bonjour
Browser Address Error Redirector
BS.Player PRO
Catalyst Control Center - Branding
CCleaner
CCScore
Choice Guard
Chromium
Compatibility Pack for the 2007 Office system
Connect
CopyTrans Suite Remove Only
Corel WordPerfect Office - iFilter
Cumulus 1.9.2
CuteFTP 8 Professional
Debug Diagnostics 1.2 32-bit
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition
Dell Driver Download Manager
Dell Getting Started Guide
Dell Support Center
Digital Line Detect
Dropbox
DU Meter
EASEUS Partition Master 9.0.0 Home Edition
ESET Online Scanner v3
ESSBrwr
ESSCDBK
ESScore
ESSgui
ESSini
ESSPCD
ESSPDock
ESSTOOLS
essvatgt
EVEREST Ultimate Edition v5.02
Fences Pro
fflink
Garmin Communicator Plugin
Garmin Lifetime Updater
Garmin USB Drivers
GoodSync
Google Chrome
Google Chrome Frame
Google Desktop
Google Earth
Google Earth Pro
Google Toolbar for Internet Explorer
Google Update Helper
GoToMyPC
HD Tune 2.55
HijackThis 2.0.2
HP Integrated Module with Bluetooth wireless technology
iCloud
InstallMgr
Intel(R) Matrix Storage Manager
Intel(R) Network Connections 15.2.89.0
Intel(R) Processor ID Utility
Ipswitch WS_FTP Pro
IPView Pro 2.0
iTunes
Java(TM) 6 Update 17
Jawbone Updater
kgcbaby
kgchday
kgchlwn
kgcinvt
kgckids
kgcmove
kgcvday
Kingsoft PC Doctor 3.3.1.9
Kodak EasyShare software
kuler
Licensing Service Install
LogMeIn
Loki ActiveX Control
MagicDisc 2.7.106
Malwarebytes Anti-Malware version 1.62.0.1300
Microsoft .NET Framework 4 Client Profile
Microsoft Corporation
Microsoft Default Manager
Microsoft IntelliPoint 8.2
Microsoft LifeCam
Microsoft Mathematics Add-in (32-bit)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office Access MUI (English) 2010
Microsoft Office Access Setup Metadata MUI (English) 2010
Microsoft Office Excel MUI (English) 2010
Microsoft Office Groove MUI (English) 2010
Microsoft Office InfoPath MUI (English) 2010
Microsoft Office Live Add-in 1.5
Microsoft Office OneNote MUI (English) 2010
Microsoft Office Outlook MUI (English) 2010
Microsoft Office PowerPoint MUI (English) 2010
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Professional Plus 2010
Microsoft Office Proof (English) 2010
Microsoft Office Proof (French) 2010
Microsoft Office Proof (Spanish) 2010
Microsoft Office Proofing (English) 2010
Microsoft Office Publisher MUI (English) 2010
Microsoft Office Shared MUI (English) 2010
Microsoft Office Shared Setup Metadata MUI (English) 2010
Microsoft Office Word MUI (English) 2010
Microsoft Security Client
Microsoft Security Compliance Manager 1.0
Microsoft Security Essentials
Microsoft Silverlight
Microsoft SQL Server 2008
Microsoft SQL Server 2008 Browser
Microsoft SQL Server 2008 Common Files
Microsoft SQL Server 2008 Database Engine Services
Microsoft SQL Server 2008 Database Engine Shared
Microsoft SQL Server 2008 Native Client
Microsoft SQL Server 2008 RsFx Driver
Microsoft SQL Server 2008 Setup Support Files
Microsoft SQL Server VSS Writer
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
Microsoft Works
MobileMe Control Panel
Mozilla Firefox 11.0 (x86 en-US)
MSN Toolbar
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Music, Photos & Videos Launcher
netbrdg
NETGEAR XE102 Powerline Encryption Utility
NETGEAR XE104 Powerline Encryption Utility
NetWaiting
NetworkView Version 3.60
Nuance OmniPage 17
Octoshape add-in for Adobe Flash Player
OfotoXMI
OGA Notifier 2.0.0048.0
OpenOffice.org 3.1
Picasa 3
Product Documentation Launcher
QuickTime
RegRun Reanimator
RoboForm 7-7-9-9 (All Users)
Roxio Creator Audio
Roxio Creator Copy
Roxio Creator Data
Roxio Creator DE
Roxio Creator Tools
Roxio Express Labeler 3
Roxio Media Manager
Roxio Update Manager
SABnzbd 0.6.10
Safari
Sanmaxi Outlook Password Recovery Trial Version 5.0.1
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft Excel 2010 (KB2597166) 32-Bit Edition
Security Update for Microsoft InfoPath 2010 (KB2553322) 32-Bit Edition
Security Update for Microsoft InfoPath 2010 (KB2553431) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2553091)
Security Update for Microsoft Office 2010 (KB2553096)
Security Update for Microsoft Office 2010 (KB2553260) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2553371) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2553447) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2589320) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2589322) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2597986) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2598243) 32-Bit Edition
Security Update for Microsoft PowerPoint 2010 (KB2553185) 32-Bit Edition
Security Update for Microsoft SharePoint Workspace 2010 (KB2566445)
Security Update for Microsoft Visio Viewer 2010 (KB2598287) 32-Bit Edition
Service Pack 1 for SQL Server 2008 (KB968369)
Setup Wizard
SetupWizard
SFR
SHASTA
SigmaTel Audio
Silicon Laboratories CP210x VCP Drivers for Windows 2000/XP/2003 Server/Vista
SiSoftware Sandra Professional Business 2009.SP3c
skin0001
SKINXSDK
Skype Toolbars
Skype™ 5.10
SlingPlayer
Snagit 10
Sophos Virus Removal Tool
Spybot - Search & Destroy
Sql Server Customer Experience Improvement Program
StarDot Tools 1.5.3
staticcr
Suite Shared Configuration CS4
SUPERAntiSpyware
SysMetrix 3.44
System Requirements Lab for Intel
TeamViewer 6
TerraExplorer
The Lord of the Rings FREE Trial
tooltips
Uniblue DriverScanner 2009
Uniblue PowerSuite 2009
Uniblue RegistryBooster 2009
Uniblue SpeedUpMyPC 2009
Unity Web Player
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft Office 2010 (KB2494150)
Update for Microsoft Office 2010 (KB2553065)
Update for Microsoft Office 2010 (KB2553092)
Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553272) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition
Update for Microsoft Office 2010 (KB2566458)
Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition
Update for Microsoft Office 2010 (KB2598289) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2589345) 32-Bit Edition
Update for Microsoft Outlook 2010 (KB2553248) 32-Bit Edition
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition
User's Guides
V CAST Music with Rhapsody
ViewSonic Monitor Drivers
Virtual Weather Station
VLC media player 1.0.0
VMware Workstation
VNC Enterprise Edition E4.4.2
VNC Mirror Driver 1.8.0
VPRINTOL
WeatherLink 5.8.3
WebSlingPlayer ActiveX
WePrint
Windows 7 Upgrade Advisor
Windows Driver Package - Garmin (grmnusb) GARMIN Devices (03/08/2007 2.2.1.0)
Windows Live ID Sign-in Assistant
Windows Live Upload Tool
Windows XP Mode
WinRAR archiver
WinZip 12.1
WIRELESS
WordPerfect Office X4
WordPerfect Office X4 - Common
WordPerfect Office X4 - Content
WordPerfect Office X4 - EN
WordPerfect Office X4 - Filters
WordPerfect Office X4 - Graphics
WordPerfect Office X4 - ICA
WordPerfect Office X4 - IPM
WordPerfect Office X4 - IPM EN
WordPerfect Office X4 - MAIL
WordPerfect Office X4 - Migration Manager
WordPerfect Office X4 - PerfectExperts
WordPerfect Office X4 - PR
WordPerfect Office X4 - QP
WordPerfect Office X4 - Skins
WordPerfect Office X4 - System
WordPerfect Office X4 - WP
World of Warcraft FREE Trial
Xmarks for IE
Xmarks Thumbnails for IE
XPS MiniView Gadget
.
==== End Of File ===========================