TechSpot

MBRcheck reports non-standard or infected MBR

By Anchorage
May 8, 2011
  1. Hello,
    My initial symptoms was inability to run Windows Update as well as inability to update my AV (Microsoft Security Essentials). In addition, running MS Security Essentials reported my WinXP SP3 PC was infected with Trojan DOS/Alureon.A and Win32/Wimpixo.E. MSE was unable to remove the infection even with repeated tries. I then also started seeing IE8 page redirects to sites trying to sell me get rich quick work at home for Google...

    Before finding your very informative and professional site, I ran TDSSkiller based on advice in another site to get rid of Alureon.A. That seemed to fix my issues, but when I ran MBRcheck (also recommended on that site) it reported an unknown MBR code for drive0 and called it out as non-standard or infected MBR.

    More research brought me to your site, and I wish I had started here. In any event, I have now run through the updated "8-steps" and am pasting the logs below. Even though all my issues only occurred in the last 2 days, I think I need to change all my passwords, but want to make sure my PC is truly clean before I do that and start using it again.

    Thanks in advance for any help you can give me!

    ===================================
    MBAM log:
    Malwarebytes' Anti-Malware 1.50.1.1100
    www.malwarebytes.org

    Database version: 6533

    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702

    5/8/2011 10:03:23 AM
    mbam-log-2011-05-08 (10-03-23).txt

    Scan type: Quick scan
    Objects scanned: 192864
    Time elapsed: 6 minute(s), 24 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)


    ============================================
    GMER log:
    GMER 1.0.15.15627 - http://www.gmer.net
    Rootkit quick scan 2011-05-08 10:11:24
    Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-17 WDC_WD2500JD-22HBB0 rev.08.02D08
    Running: zwuhphcc.exe; Driver: C:\DOCUME~1\HP_Owner\LOCALS~1\Temp\ugtyiaow.sys


    ---- Devices - GMER 1.0.15 ----

    AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

    ---- EOF - GMER 1.0.15 ----


    ==========================================
    DDS.txt report:
    .
    DDS (Ver_11-03-05.01) - NTFSx86
    Run by HP_Owner at 10:20:21.28 on Sun 05/08/2011
    Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_25
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1527.957 [GMT -7:00]
    .
    AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
    AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
    .
    ============== Running Processes ===============
    .
    C:\WINDOWS\system32\svchost.exe -k DcomLaunch
    svchost.exe
    c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
    svchost.exe
    svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    svchost.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
    c:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\Program Files\Cox\Media Store and Share Backup Manager\VaultClientSRV.exe
    C:\Program Files\Cox\Media Store and Share Backup Manager\VaultClientUpgrade.exe
    C:\Program Files\Viewpoint\Common\ViewpointService.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\WINDOWS\Explorer.EXE
    C:\windows\system\hpsysdrv.exe
    C:\WINDOWS\system32\hphmon06.exe
    C:\HP\KBD\KBD.EXE
    C:\WINDOWS\AGRSMMSG.exe
    C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
    C:\WINDOWS\system32\igfxtray.exe
    C:\WINDOWS\System32\svchost.exe -k HTTPFilter
    C:\WINDOWS\SOUNDMAN.EXE
    C:\WINDOWS\ALCWZRD.EXE
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Microsoft IntelliPoint\point32.exe
    C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
    C:\Program Files\Cox\Media Store and Share Backup Manager\VaultClientTray.exe
    C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
    C:\Program Files\Microsoft Security Client\msseces.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Microsoft Student\Microsoft Student 2006 DVD\EDICT.EXE
    C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\FinePixViewer\QuickDCF.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Southwest Airlines\Ding\Ding.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Documents and Settings\HP_Owner\Desktop\dds.scr
    .
    ============== Pseudo HJT Report ===============
    .
    uStart Page = hxxp://my.yahoo.com/
    mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
    uInternet Settings,ProxyOverride = *.local
    BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
    BHO: Encarta Web Companion Helper Object: {955be0b8-bc85-4caf-856e-8e0d8b610560} - c:\program files\common files\microsoft shared\encarta web companion\ENCWCBAR.DLL
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    TB: HP view: {b2847e28-5d7d-4deb-8b67-05d28bcf79f5} - c:\program files\hp\digital imaging\bin\HPDTLK02.dll
    TB: Encarta Web Companion: {147d6308-0614-4112-89b1-31402f9b82c4} - c:\program files\common files\microsoft shared\encarta web companion\ENCWCBAR.DLL
    TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
    uRun: [L06AXLRD_6820281] "c:\program files\microsoft student\microsoft student 2006 dvd\EDICT.EXE" -m
    uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler
    uRun: [updateMgr] "c:\program files\adobe\acrobat 7.0\reader\AdobeUpdateManager.exe" AcRdB7_1_0 -reboot 1
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    mRun: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
    mRun: [HPHUPD06] c:\program files\hp\{aac4fc36-8f89-4587-8dd3-ebc57c83374d}\hphupd06.exe
    mRun: [HPHmon06] c:\windows\system32\hphmon06.exe
    mRun: [KBD] c:\hp\kbd\KBD.EXE
    mRun: [Recguard] c:\windows\sminst\RECGUARD.EXE
    mRun: [AlcxMonitor] ALCXMNTR.EXE
    mRun: [AGRSMMSG] AGRSMMSG.exe
    mRun: [PS2] c:\windows\system32\ps2.exe
    mRun: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
    mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
    mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
    mRun: [SoundMan] SOUNDMAN.EXE
    mRun: [AlcWzrd] ALCWZRD.EXE
    mRun: [REGSHAVE] c:\program files\regshave\REGSHAVE.EXE /AUTORUN
    mRun: [UpdateManager] "c:\program files\common files\sonic\update manager\sgtray.exe" /r
    mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
    mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\point32.exe"
    mRun: [SsAAD.exe] c:\progra~1\sony\sonics~1\SsAAD.exe
    mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
    mRun: [TrayStartup] c:\program files\cox\media store and share backup manager\VaultClientTray.exe
    mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
    mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
    mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
    mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
    StartupFolder: c:\docume~1\hp_owner\startm~1\programs\startup\ding!.lnk - c:\program files\southwest airlines\ding\Ding.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\exifla~1.lnk - c:\program files\finepixviewer\QuickDCF.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL
    IE: {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - {552781AF-37E4-4FEE-920A-CED9E648EADD} - c:\program files\common files\microsoft shared\encarta search bar\ENCSBAR.DLL
    Trusted Zone: boeing.com\bpn
    Trusted Zone: intuit.com\ttlc
    Trusted Zone: turbotax.com
    DPF: MCInstallCAB - hxxps://content101.mc.iconf.net/gcc_installer/mcInstall.cab
    DPF: {001EE746-A1F9-460E-80AD-269E088D6A01} - hxxp://site.ebrary.com/lib/anysite/support/plugins/ebraryRdr.cab
    DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/d/c/8/dc8362b3-f410-4e7d-b672-209d6bd8fcea/OGAControl.cab
    DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/3/9/8/398422c0-8d3e-40e1-a617-af65a72a0465/LegitCheckControl.cab
    DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - hxxps://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
    DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} - hxxp://h20270.www2.hp.com/ediags/gmn/install/hpobjinstaller_gmn.cab
    DPF: {26B2A5DA-BFD6-422F-A89A-28A54C74B12B} - hxxp://images3.pnimedia.com/ProductAssets/costcous/activex/v3_0_0_4/PhotoCenter_ActiveX_Control.cab
    DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
    DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - hxxp://office.microsoft.com/officeupdate/content/opuc3.cab
    DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://www.costcophotocenter.com/CostcoActivia.cab
    DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8942.cab
    DPF: {60246658-5626-449F-8701-66D278AD2EB2} - hxxp://www.brainfuse.com/downloads/QCDetector/BrainfuseQuickConnectDetector.CAB
    DPF: {62789780-B744-11D0-986B-00609731A21D} - hxxp://www.maricopa.gov/assessor/gis/plugin/mgaxctrl.cab
    DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1137554925921
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
    DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
    DPF: {90051A81-3018-4826-8B38-DD60B6B53F9C} - hxxp://www.costcophotocenter.com/CostcoUpload.cab
    DPF: {A1662FB6-39BE-41BB-ACDC-0448FB1B5817} - hxxp://images3.pnimedia.com/ProductAssets/costcous/activex/v3_0_0_5/PhotoCenter_ActiveX_Control.cab
    DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} - hxxp://www.crucial.com/controls/cpcScanner.cab
    DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
    DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - hxxps://www-secure.symantec.com/techsupp/asa/SymAData.cab
    DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} - hxxp://ccon.futuremark.com/global/msc34.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} - hxxps://music.msn.com/client/msnmusax2614.cab
    Filter: application/xhtml+xml - {32F66A26-7614-11D4-BD11-00104BD3F987} - c:\program files\design science\mathplayer\MathMLMimer.dll
    Filter: text/xml; charset=iso-8859-1 - {32F66A26-7614-11D4-BD11-00104BD3F987} - c:\program files\design science\mathplayer\MathMLMimer.dll
    Filter: text/xml; charset=utf-8 - {32F66A26-7614-11D4-BD11-00104BD3F987} - c:\program files\design science\mathplayer\MathMLMimer.dll
    Notify: igfxcui - igfxsrvc.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    .
    ================= FIREFOX ===================
    .
    FF - ProfilePath - c:\docume~1\hp_owner\applic~1\mozilla\firefox\profiles\y5yrcg4q.default\
    FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
    FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\java\jre6\lib\deploy\jqs\ff
    .
    ============= SERVICES / DRIVERS ===============
    .
    R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-3-25 165264]
    R1 MpKsl835a39a6;MpKsl835a39a6;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{5d7a2628-836d-4a9e-bc2d-dfa019bedb68}\MpKsl835a39a6.sys [2011-5-8 28752]
    R2 VaultClientSRV;Media Store and Share Backup Manager Service;c:\program files\cox\media store and share backup manager\VaultClientSRV.exe [2008-10-8 981456]
    R2 VaultClientUpgrade;Backup Manager Upgrade Service;c:\program files\cox\media store and share backup manager\VaultClientUpgrade.exe [2008-10-8 55760]
    R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2007-10-27 24652]
    S1 MpKsl49aa2db8;MpKsl49aa2db8;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{0ede0d93-3970-4fc5-a549-a96208d63ae9}\mpksl49aa2db8.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{0ede0d93-3970-4fc5-a549-a96208d63ae9}\MpKsl49aa2db8.sys [?]
    S1 MpKsl70ae1981;MpKsl70ae1981;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{3036d298-57ab-4d3d-b17b-173a5171db20}\mpksl70ae1981.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{3036d298-57ab-4d3d-b17b-173a5171db20}\MpKsl70ae1981.sys [?]
    S2 portD;CMS PortIO Service;c:\windows\system32\drivers\portd2k.sys --> c:\windows\system32\drivers\portd2k.sys [?]
    .
    =============== Created Last 30 ================
    .
    2011-05-08 17:12:19 28752 ----a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{5d7a2628-836d-4a9e-bc2d-dfa019bedb68}\MpKsl835a39a6.sys
    2011-05-08 17:12:08 7071056 ----a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{5d7a2628-836d-4a9e-bc2d-dfa019bedb68}\mpengine.dll
    2011-05-08 16:53:23 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2011-05-08 16:53:19 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2011-05-08 16:53:19 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2011-05-08 06:49:13 -------- d-----w- c:\docume~1\hp_owner\applic~1\Foxit Software
    2011-05-08 06:48:14 -------- d-----w- c:\program files\Foxit Software
    2011-04-24 20:18:24 -------- d-----w- c:\program files\iPod
    2011-04-24 20:18:19 -------- d-----w- c:\program files\iTunes
    2011-04-24 20:14:27 -------- d-----w- c:\program files\Bonjour
    2011-04-23 00:19:01 -------- d-----r- c:\program files\Skype
    .
    ==================== Find3M ====================
    .
    2011-04-14 12:07:59 472808 ----a-w- c:\windows\system32\deployJava1.dll
    2011-04-14 09:40:22 73728 ----a-w- c:\windows\system32\javacpl.cpl
    2011-04-06 23:20:16 91424 ----a-w- c:\windows\system32\dnssd.dll
    2011-04-06 23:20:16 107808 ----a-w- c:\windows\system32\dns-sd.exe
    2011-03-07 05:33:50 692736 ----a-w- c:\windows\system32\inetcomm.dll
    2011-03-04 06:37:06 420864 ----a-w- c:\windows\system32\vbscript.dll
    2011-03-03 13:21:11 1857920 ----a-w- c:\windows\system32\win32k.sys
    2011-02-22 23:06:29 916480 ----a-w- c:\windows\system32\wininet.dll
    2011-02-22 23:06:29 43520 ----a-w- c:\windows\system32\licmgr10.dll
    2011-02-22 23:06:29 1469440 ------w- c:\windows\system32\inetcpl.cpl
    2011-02-22 11:41:59 385024 ----a-w- c:\windows\system32\html.iec
    2011-02-17 12:32:12 5120 ----a-w- c:\windows\system32\xpsp4res.dll
    2011-02-15 12:56:39 290432 ----a-w- c:\windows\system32\atmfd.dll
    2011-02-11 13:25:52 229888 ----a-w- c:\windows\system32\fxscover.exe
    2011-02-09 13:53:52 270848 ----a-w- c:\windows\system32\sbe.dll
    2011-02-09 13:53:52 186880 ----a-w- c:\windows\system32\encdec.dll
    2011-02-08 13:33:55 978944 ----a-w- c:\windows\system32\mfc42.dll
    2011-02-08 13:33:55 974848 ----a-w- c:\windows\system32\mfc42u.dll
    .
    ============= FINISH: 10:21:26.89 ===============

    =================================================
    Attach.txt report (from running DDS):
    .
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    .
    DDS (Ver_11-03-05.01)
    .
    Microsoft Windows XP Home Edition
    Boot Device: \Device\HarddiskVolume2
    Install Date: 2/19/2005 2:56:14 PM
    System Uptime: 5/8/2011 8:21:40 AM (2 hours ago)
    .
    Motherboard: ASUSTeK Computer INC. | | Goldfish2
    Processor: Intel(R) Pentium(R) 4 CPU 3.20GHz | CPU 1 | 3201/200mhz
    .
    ==== Disk Partitions =========================
    .
    C: is FIXED (NTFS) - 227 GiB total, 97.482 GiB free.
    D: is FIXED (FAT32) - 6 GiB total, 0.707 GiB free.
    E: is CDROM (CDFS)
    F: is CDROM ()
    G: is Removable
    H: is Removable
    I: is Removable
    J: is Removable
    .
    ==== Disabled Device Manager Items =============
    .
    ==== System Restore Points ===================
    .
    No restore point in system.
    .
    ==== Installed Programs ======================
    .
    .
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Shockwave Player 11.5
    Agere Systems PCI Soft Modem
    AIM 6
    AiO_Scan
    AiOSoftware
    AnswerWorks 4.0 Runtime - English
    AnswerWorks 5.0 English Runtime
    Apple Application Support
    Apple Mobile Device Support
    Apple Software Update
    Beyond Compare Version 2.3.1
    Bonjour
    Brainfuse Participant QuickConnect
    BufferChm
    Cakewalk VST Adapter 4
    CameraDrivers
    Canon Camera Access Library
    Canon Camera Support Core Library
    Canon Camera Window DC_DV 5 for ZoomBrowser EX
    Canon CanoScan Toolbox 4.1
    Canon Digital Camera Solution Disk 40-46 Software Starter Guide
    Canon G.726 WMP-Decoder
    CANON iMAGE GATEWAY Task for ZoomBrowser EX
    Canon Internet Library for ZoomBrowser EX
    Canon MovieEdit Task for ZoomBrowser EX
    Canon Personal Printing Guide
    Canon PhotoRecord
    Canon PowerShot SD1200 IS_IXUS 95 IS Camera User Guide
    Canon RAW Image Task for ZoomBrowser EX
    Canon Utilities CameraWindow
    Canon Utilities CameraWindow DC
    Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX
    Canon Utilities EOS Utility
    Canon Utilities MyCamera
    Canon Utilities MyCamera DC
    Canon Utilities PhotoStitch
    Canon Utilities RemoteCapture Task for ZoomBrowser EX
    Canon Utilities ZoomBrowser EX
    Canon ZoomBrowser EX Memory Card Utility
    Citrix Presentation Server Client
    Compatibility Pack for the 2007 Office system
    Copy
    CreativeProjects
    CreativeProjectsTemplates
    Critical Update for Windows Media Player 11 (KB959772)
    CueTour
    CyberView X - SF v1.18c
    Destinations
    DING!
    Director
    DocProc
    DocumentViewer
    DreamStation DXi2
    Exifer
    Fax
    FinePixViewer Resource
    FinePixViewer Ver.5.0
    Foxit Reader
    Free Video Flip and Rotate version 1.8.10
    FUJIFILM USB Driver
    Futuremark Measurement Services Client
    Genesys Meeting Center
    Google Chrome
    Google Earth
    Google Talk Plugin
    Help and Support Additions
    High Definition Audio Driver Package - KB835221
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows Media Player 11 (KB939683)
    Hotfix for Windows XP (KB2158563)
    Hotfix for Windows XP (KB2443685)
    Hotfix for Windows XP (KB952287)
    Hotfix for Windows XP (KB954550-v5)
    Hotfix for Windows XP (KB961118)
    Hotfix for Windows XP (KB970653-v3)
    Hotfix for Windows XP (KB976098-v2)
    Hotfix for Windows XP (KB979306)
    Hotfix for Windows XP (KB981793)
    HP Deskjet Preloaded Printer Drivers
    HP Diagnostic Assistant
    HP Image Zone 4.2.3
    HP Image Zone Plus 4.2.3
    HP Organize
    HP Photosmart Cameras 4.0
    HP PSC & OfficeJet 4.0
    HP Software Update
    HPIZ423
    HpSdpAppCoreApp
    Image Plugin
    Inspiration 8
    InstantShare
    Intel(R) Graphics Media Accelerator Driver
    IntelliMover Data Transfer Demo
    InterVideo DiscLabel
    InterVideo WinDVD Creator
    InterVideo WinDVD Creator 2
    InterVideo WinDVD Player
    ItsDeductible Express
    iTunes
    Java(TM) 6 Update 25
    jetAudio Basic
    KBD
    Kid Pix Studio Deluxe
    Learning Essentials for Microsoft Office
    LS_HSI
    Mall Tycoon 2
    Malwarebytes' Anti-Malware
    MathPlayer
    Media Store and Share Backup Manager
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Security Update (KB2416447)
    Microsoft .NET Framework 1.1 Security Update (KB979906)
    Microsoft .NET Framework 2.0 Service Pack 2
    Microsoft .NET Framework 3.0 Service Pack 2
    Microsoft .NET Framework 3.5 SP1
    Microsoft Antimalware
    Microsoft Application Error Reporting
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft IntelliPoint 5.3
    Microsoft Internationalized Domain Names Mitigation APIs
    Microsoft National Language Support Downlevel APIs
    Microsoft Office Professional Edition 2003
    Microsoft Plus! Digital Media Edition Installer
    Microsoft Plus! Photo Story 2 LE
    Microsoft Security Client
    Microsoft Security Essentials
    Microsoft Silverlight
    Microsoft Student 2006 DVD
    Microsoft Student Graphing Calculator
    Microsoft Text-to-Speech Engine 4.0 (English)
    Microsoft User-Mode Driver Framework Feature Pack 1.0
    Microsoft VC9 runtime libraries
    Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    Microsoft Works
    MobileMe Control Panel
    Move Media Player
    Mozilla Firefox (3.0.7)
    MSXML 4.0 SP2 (KB925672)
    MSXML 4.0 SP2 (KB927978)
    MSXML 4.0 SP2 (KB936181)
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    muvee autoProducer 3.5 magicMoments - HPD
    Nancy Drew: Legend of the Crystal Skull
    NETGEAR Print Server Software
    Network Play System (Patching)
    Nolo's Encyclopedia of Everyday Law
    OpenMG Limited Patch 4.1-05-14-24-01
    OpenMG Secure Module 4.1.00
    OverDrive Media Console
    PC-Doctor for Windows
    Photo Story 3 for Windows
    PhotoGallery
    Photosmart 320,370,7400,8100,8400 Series
    Pivot Stickfigure Animator
    PrintScreen
    PS2
    PSPrinters06
    Python 2.2 combined Win32 extensions
    Python 2.2.1
    QFolder
    Quicken 2005
    Quicken WillMaker Plus 2004
    Quicken WillMaker Plus 2006
    QuickProjects
    QuickTime
    RAW FILE CONVERTER LE
    Readme
    RealPlayer
    Realtek High Definition Audio Driver
    Respondus LockDown Browser
    Scan
    Security Update for CAPICOM (KB931906)
    Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
    Security Update for Step By Step Interactive Training (KB898458)
    Security Update for Step By Step Interactive Training (KB923723)
    Security Update for Windows Internet Explorer 8 (KB2183461)
    Security Update for Windows Internet Explorer 8 (KB2360131)
    Security Update for Windows Internet Explorer 8 (KB2416400)
    Security Update for Windows Internet Explorer 8 (KB2482017)
    Security Update for Windows Internet Explorer 8 (KB2497640)
    Security Update for Windows Internet Explorer 8 (KB2510531)
    Security Update for Windows Internet Explorer 8 (KB969897)
    Security Update for Windows Internet Explorer 8 (KB971961)
    Security Update for Windows Internet Explorer 8 (KB972260)
    Security Update for Windows Internet Explorer 8 (KB974455)
    Security Update for Windows Internet Explorer 8 (KB976325)
    Security Update for Windows Internet Explorer 8 (KB978207)
    Security Update for Windows Internet Explorer 8 (KB981332)
    Security Update for Windows Internet Explorer 8 (KB982381)
    Security Update for Windows Media Encoder (KB2447961)
    Security Update for Windows Media Encoder (KB954156)
    Security Update for Windows Media Encoder (KB979332)
    Security Update for Windows Media Player (KB2378111)
    Security Update for Windows Media Player (KB911564)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player (KB954155)
    Security Update for Windows Media Player (KB968816)
    Security Update for Windows Media Player (KB973540)
    Security Update for Windows Media Player (KB975558)
    Security Update for Windows Media Player (KB978695)
    Security Update for Windows Media Player 10 (KB911565)
    Security Update for Windows Media Player 10 (KB917734)
    Security Update for Windows Media Player 10 (KB936782)
    Security Update for Windows Media Player 11 (KB936782)
    Security Update for Windows Media Player 11 (KB954154)
    Security Update for Windows Media Player 6.4 (KB925398)
    Security Update for Windows XP (KB2079403)
    Security Update for Windows XP (KB2115168)
    Security Update for Windows XP (KB2121546)
    Security Update for Windows XP (KB2160329)
    Security Update for Windows XP (KB2229593)
    Security Update for Windows XP (KB2259922)
    Security Update for Windows XP (KB2279986)
    Security Update for Windows XP (KB2286198)
    Security Update for Windows XP (KB2296011)
    Security Update for Windows XP (KB2296199)
    Security Update for Windows XP (KB2347290)
    Security Update for Windows XP (KB2360937)
    Security Update for Windows XP (KB2387149)
    Security Update for Windows XP (KB2393802)
    Security Update for Windows XP (KB2412687)
    Security Update for Windows XP (KB2419632)
    Security Update for Windows XP (KB2423089)
    Security Update for Windows XP (KB2436673)
    Security Update for Windows XP (KB2440591)
    Security Update for Windows XP (KB2443105)
    Security Update for Windows XP (KB2476687)
    Security Update for Windows XP (KB2478960)
    Security Update for Windows XP (KB2478971)
    Security Update for Windows XP (KB2479628)
    Security Update for Windows XP (KB2479943)
    Security Update for Windows XP (KB2481109)
    Security Update for Windows XP (KB2483185)
    Security Update for Windows XP (KB2485376)
    Security Update for Windows XP (KB2485663)
    Security Update for Windows XP (KB2491683)
    Security Update for Windows XP (KB2503658)
    Security Update for Windows XP (KB2506212)
    Security Update for Windows XP (KB2506223)
    Security Update for Windows XP (KB2507618)
    Security Update for Windows XP (KB2508272)
    Security Update for Windows XP (KB2508429)
    Security Update for Windows XP (KB2509553)
    Security Update for Windows XP (KB2511455)
    Security Update for Windows XP (KB2524375)
    Security Update for Windows XP (KB923561)
    Security Update for Windows XP (KB923689)
    Security Update for Windows XP (KB938464)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB950759)
    Security Update for Windows XP (KB950760)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951066)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951376)
    Security Update for Windows XP (KB951698)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952004)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB953838)
    Security Update for Windows XP (KB953839)
    Security Update for Windows XP (KB954211)
    Security Update for Windows XP (KB954459)
    Security Update for Windows XP (KB954600)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956390)
    Security Update for Windows XP (KB956391)
    Security Update for Windows XP (KB956572)
    Security Update for Windows XP (KB956744)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956841)
    Security Update for Windows XP (KB956844)
    Security Update for Windows XP (KB957095)
    Security Update for Windows XP (KB957097)
    Security Update for Windows XP (KB958215)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB958687)
    Security Update for Windows XP (KB958690)
    Security Update for Windows XP (KB958869)
    Security Update for Windows XP (KB959426)
    Security Update for Windows XP (KB960225)
    Security Update for Windows XP (KB960714)
    Security Update for Windows XP (KB960715)
    Security Update for Windows XP (KB960803)
    Security Update for Windows XP (KB960859)
    Security Update for Windows XP (KB961371)
    Security Update for Windows XP (KB961373)
    Security Update for Windows XP (KB961501)
    Security Update for Windows XP (KB963027)
    Security Update for Windows XP (KB968537)
    Security Update for Windows XP (KB969059)
    Security Update for Windows XP (KB969897)
    Security Update for Windows XP (KB969898)
    Security Update for Windows XP (KB969947)
    Security Update for Windows XP (KB970238)
    Security Update for Windows XP (KB970430)
    Security Update for Windows XP (KB971468)
    Security Update for Windows XP (KB971486)
    Security Update for Windows XP (KB971557)
    Security Update for Windows XP (KB971633)
    Security Update for Windows XP (KB971657)
    Security Update for Windows XP (KB972270)
    Security Update for Windows XP (KB973346)
    Security Update for Windows XP (KB973354)
    Security Update for Windows XP (KB973507)
    Security Update for Windows XP (KB973525)
    Security Update for Windows XP (KB973869)
    Security Update for Windows XP (KB973904)
    Security Update for Windows XP (KB974112)
    Security Update for Windows XP (KB974318)
    Security Update for Windows XP (KB974392)
    Security Update for Windows XP (KB974571)
    Security Update for Windows XP (KB975025)
    Security Update for Windows XP (KB975467)
    Security Update for Windows XP (KB975560)
    Security Update for Windows XP (KB975561)
    Security Update for Windows XP (KB975562)
    Security Update for Windows XP (KB975713)
    Security Update for Windows XP (KB977165)
    Security Update for Windows XP (KB977816)
    Security Update for Windows XP (KB977914)
    Security Update for Windows XP (KB978037)
    Security Update for Windows XP (KB978251)
    Security Update for Windows XP (KB978262)
    Security Update for Windows XP (KB978338)
    Security Update for Windows XP (KB978542)
    Security Update for Windows XP (KB978601)
    Security Update for Windows XP (KB978706)
    Security Update for Windows XP (KB979309)
    Security Update for Windows XP (KB979482)
    Security Update for Windows XP (KB979559)
    Security Update for Windows XP (KB979683)
    Security Update for Windows XP (KB979687)
    Security Update for Windows XP (KB980195)
    Security Update for Windows XP (KB980218)
    Security Update for Windows XP (KB980232)
    Security Update for Windows XP (KB980436)
    Security Update for Windows XP (KB981322)
    Security Update for Windows XP (KB981852)
    Security Update for Windows XP (KB981957)
    Security Update for Windows XP (KB981997)
    Security Update for Windows XP (KB982132)
    Security Update for Windows XP (KB982214)
    Security Update for Windows XP (KB982665)
    Security Update for Windows XP (KB982802)
    SkinsHP1
    Skype™ 5.3
    SnagIt 7
    SONAR LE
    Sonic Express Labeler
    Sonic RecordNow!
    Sonic Update Manager
    SonicStage 3.1
    The White Wolf of Icicle Creek
    TrayApp
    TurboTax 2005
    TurboTax 2008
    TurboTax 2008 waziper
    TurboTax 2008 WinPerFedFormset
    TurboTax 2008 WinPerProgramHelp
    TurboTax 2008 WinPerReleaseEngine
    TurboTax 2008 WinPerTaxSupport
    TurboTax 2008 WinPerUserEducation
    TurboTax 2008 wrapper
    TurboTax 2009
    TurboTax 2009 waziper
    TurboTax 2009 WinPerFedFormset
    TurboTax 2009 WinPerReleaseEngine
    TurboTax 2009 WinPerTaxSupport
    TurboTax 2009 wrapper
    TurboTax 2010
    TurboTax 2010 waziper
    TurboTax 2010 WinPerFedFormset
    TurboTax 2010 WinPerReleaseEngine
    TurboTax 2010 WinPerTaxSupport
    TurboTax 2010 wrapper
    TurboTax Deluxe 2004
    TurboTax Deluxe 2007
    TurboTax Deluxe Deduction Maximizer 2006
    TurboTax ItsDeductible 2005
    TurboTax ItsDeductible 2006
    Uninstall 1.0.0.1
    Unload
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    Update for Windows Internet Explorer 8 (KB971930)
    Update for Windows Internet Explorer 8 (KB976662)
    Update for Windows Internet Explorer 8 (KB976749)
    Update for Windows Internet Explorer 8 (KB980182)
    Update for Windows XP (KB2141007)
    Update for Windows XP (KB2345886)
    Update for Windows XP (KB2467659)
    Update for Windows XP (KB951072-v2)
    Update for Windows XP (KB951978)
    Update for Windows XP (KB955759)
    Update for Windows XP (KB955839)
    Update for Windows XP (KB967715)
    Update for Windows XP (KB968389)
    Update for Windows XP (KB971029)
    Update for Windows XP (KB971737)
    Update for Windows XP (KB973687)
    Update for Windows XP (KB973815)
    Updates from HP
    Viewpoint Media Player
    Virtual Earth 3D (Beta)
    Walmart MP3 Music Downloads
    WebFldrs XP
    WebReg
    WexTech AnswerWorks
    Windows Defender Signatures
    Windows Driver Package - PIE Image 10/22/2002 1.1.1
    Windows Genuine Advantage Notifications (KB905474)
    Windows Genuine Advantage v1.3.0254.0
    Windows Genuine Advantage Validation Tool (KB892130)
    Windows Imaging Component
    Windows Internet Explorer 8
    Windows Live OneCare safety scanner
    Windows Media Encoder 9 Series
    Windows Media Format 11 runtime
    Windows Media Player 11
    Windows XP Service Pack 3
    WinZip
    Yahoo! Messenger
    Yahoo! Photos Print-at-Home Tool
    Yahoo! Toolbar
    .
    ==== Event Viewer Messages From Past Week ========
    .
    5/7/2011 12:35:18 PM, error: Microsoft Antimalware [1119] - Microsoft Antimalware has encountered a critical error when taking action on malware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:DOS/Alureon.A&threatid=2147636949 Name: Trojan:DOS/Alureon.A ID: 2147636949 Severity: Severe Category: Trojan Path: rootkit:_AlureonMbr Detection Origin: Unknown Detection Type: Concrete Detection Source: System User: NT AUTHORITY\NETWORK SERVICE Process Name: Unknown Action: Remove Action Status: To finish removing malware and other potentially unwanted software, restart the computer. To see how to finish removing malware and other potentially unwanted software, see the support article on the Microsoft Security website. Error Code: 0x80070032 Error description: The request is not supported. Signature Version: AV: 1.103.1181.0, AS: 1.103.1181.0, NIS: 0.0.0.0 Engine Version: AM: 1.1.6802.0, NIS: 0.0.0.0
    5/7/2011 12:31:05 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.103.1181.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.6802.0 Error code: 0x80072efe Error description: The connection with the server was terminated abnormally
    5/7/2011 12:16:51 PM, error: Microsoft Antimalware [1119] - Microsoft Antimalware has encountered a critical error when taking action on malware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:DOS/Alureon.A&threatid=2147636949 Name: Trojan:DOS/Alureon.A ID: 2147636949 Severity: Severe Category: Trojan Path: rootkit:_AlureonMbr Detection Origin: Unknown Detection Type: Concrete Detection Source: User User: HP540-HOMEPC\HP_Owner Process Name: Unknown Action: Remove Action Status: To finish removing malware and other potentially unwanted software, restart the computer. To see how to finish removing malware and other potentially unwanted software, see the support article on the Microsoft Security website. Error Code: 0x80070032 Error description: The request is not supported. Signature Version: AV: 1.103.1181.0, AS: 1.103.1181.0, NIS: 0.0.0.0 Engine Version: AM: 1.1.6802.0, NIS: 0.0.0.0
    5/7/2011 12:16:51 PM, error: Microsoft Antimalware [1119] - Microsoft Antimalware has encountered a critical error when taking action on malware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:DOS/Alureon.A&threatid=2147636949 Name: Trojan:DOS/Alureon.A ID: 2147636949 Severity: Severe Category: Trojan Path: rootkit:_AlureonMbr Detection Origin: Unknown Detection Type: Concrete Detection Source: User User: HP540-HOMEPC\HP_Owner Process Name: Unknown Action: Quarantine Action Status: To finish removing malware and other potentially unwanted software, restart the computer. To see how to finish removing malware and other potentially unwanted software, see the support article on the Microsoft Security website. Error Code: 0x80070032 Error description: The request is not supported. Signature Version: AV: 1.103.1181.0, AS: 1.103.1181.0, NIS: 0.0.0.0 Engine Version: AM: 1.1.6802.0, NIS: 0.0.0.0
    5/7/2011 12:04:42 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.103.1181.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.6802.0 Error code: 0x80072efe Error description: The connection with the server was terminated abnormally
    5/7/2011 11:57:22 AM, error: Microsoft Antimalware [1119] - Microsoft Antimalware has encountered a critical error when taking action on malware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:DOS/Alureon.A&threatid=2147636949 Name: Trojan:DOS/Alureon.A ID: 2147636949 Severity: Severe Category: Trojan Path: rootkit:_AlureonMbr Detection Origin: Unknown Detection Type: Concrete Detection Source: System User: NT AUTHORITY\NETWORK SERVICE Process Name: Unknown Action: Remove Action Status: To finish removing malware and other potentially unwanted software, restart the computer. To see how to finish removing malware and other potentially unwanted software, see the support article on the Microsoft Security website. Error Code: 0x80070032 Error description: The request is not supported. Signature Version: AV: 1.103.1181.0, AS: 1.103.1181.0, NIS: 0.0.0.0 Engine Version: AM: 1.1.6802.0, NIS: 0.0.0.0
    5/7/2011 11:46:28 AM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.103.1181.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.6802.0 Error code: 0x80072efe Error description: The connection with the server was terminated abnormally
    5/7/2011 11:44:23 PM, error: Service Control Manager [7023] - The Application Management service terminated with the following error: The specified module could not be found.
    5/7/2011 11:31:21 AM, error: Microsoft Antimalware [1119] - Microsoft Antimalware has encountered a critical error when taking action on malware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:DOS/Alureon.A&threatid=2147636949 Name: Trojan:DOS/Alureon.A ID: 2147636949 Severity: Severe Category: Trojan Path: rootkit:_AlureonMbr Detection Origin: Unknown Detection Type: Concrete Detection Source: User User: HP540-HOMEPC\HP_Owner Process Name: Unknown Action: Remove Action Status: To finish removing malware and other potentially unwanted software, restart the computer. To see how to finish removing malware and other potentially unwanted software, see the support article on the Microsoft Security website. Error Code: 0x80070032 Error description: The request is not supported. Signature Version: AV: 1.103.1181.0, AS: 1.103.1181.0, NIS: 0.0.0.0 Engine Version: AM: 1.1.6802.0, NIS: 0.0.0.0
    5/7/2011 10:37:00 PM, error: Service Control Manager [7034] - The Viewpoint Manager Service service terminated unexpectedly. It has done this 1 time(s).
    5/7/2011 10:37:00 PM, error: Service Control Manager [7034] - The SonicStage SCSI Service service terminated unexpectedly. It has done this 1 time(s).
    5/7/2011 10:37:00 PM, error: Service Control Manager [7034] - The Media Store and Share Backup Manager Service service terminated unexpectedly. It has done this 1 time(s).
    5/7/2011 10:37:00 PM, error: Service Control Manager [7034] - The LightScribeService Direct Disc Labeling Service service terminated unexpectedly. It has done this 1 time(s).
    5/7/2011 10:37:00 PM, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s).
    5/7/2011 10:37:00 PM, error: Service Control Manager [7034] - The iPod Service service terminated unexpectedly. It has done this 1 time(s).
    5/7/2011 10:37:00 PM, error: Service Control Manager [7034] - The Intuit Update Service service terminated unexpectedly. It has done this 1 time(s).
    5/7/2011 10:37:00 PM, error: Service Control Manager [7034] - The Canon Camera Access Library 8 service terminated unexpectedly. It has done this 1 time(s).
    5/7/2011 10:37:00 PM, error: Service Control Manager [7034] - The Bonjour Service service terminated unexpectedly. It has done this 1 time(s).
    5/7/2011 10:37:00 PM, error: Service Control Manager [7034] - The Backup Manager Upgrade Service service terminated unexpectedly. It has done this 1 time(s).
    5/7/2011 10:37:00 PM, error: Service Control Manager [7031] - The Microsoft Antimalware Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 15000 milliseconds: Restart the service.
    5/7/2011 10:37:00 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    5/7/2011 10:04:02 PM, error: PlugPlayManager [11] - The device Root\LEGACY_NPF\0000 disappeared from the system without first being prepared for removal.
    5/7/2011 1:22:02 PM, error: Microsoft Antimalware [1119] - Microsoft Antimalware has encountered a critical error when taking action on malware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:DOS/Alureon.A&threatid=2147636949 Name: Trojan:DOS/Alureon.A ID: 2147636949 Severity: Severe Category: Trojan Path: rootkit:_AlureonMbr Detection Origin: Unknown Detection Type: Concrete Detection Source: System User: HP540-HOMEPC\HP_Owner Process Name: Unknown Action: Remove Action Status: To finish removing malware and other potentially unwanted software, restart the computer. To see how to finish removing malware and other potentially unwanted software, see the support article on the Microsoft Security website. Error Code: 0x80070032 Error description: The request is not supported. Signature Version: AV: 1.103.1181.0, AS: 1.103.1181.0, NIS: 0.0.0.0 Engine Version: AM: 1.1.6802.0, NIS: 0.0.0.0
    5/7/2011 1:22:02 PM, error: Microsoft Antimalware [1119] - Microsoft Antimalware has encountered a critical error when taking action on malware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:DOS/Alureon.A&threatid=2147636949 Name: Trojan:DOS/Alureon.A ID: 2147636949 Severity: Severe Category: Trojan Path: rootkit:_AlureonMbr Detection Origin: Unknown Detection Type: Concrete Detection Source: System User: HP540-HOMEPC\HP_Owner Process Name: Unknown Action: Quarantine Action Status: To finish removing malware and other potentially unwanted software, restart the computer. To see how to finish removing malware and other potentially unwanted software, see the support article on the Microsoft Security website. Error Code: 0x80070032 Error description: The request is not supported. Signature Version: AV: 1.103.1181.0, AS: 1.103.1181.0, NIS: 0.0.0.0 Engine Version: AM: 1.1.6802.0, NIS: 0.0.0.0
    5/6/2011 9:17:57 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.103.1181.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.6802.0 Error code: 0x80072efe Error description: The connection with the server was terminated abnormally
    5/6/2011 7:45:50 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.103.1181.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: Default URL Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.6802.0 Error code: 0x80072efe Error description: The connection with the server was terminated abnormally
    5/6/2011 7:29:17 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.103.1094.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.6802.0 Error code: 0x80072efe Error description: The connection with the server was terminated abnormally
    5/6/2011 3:35:32 AM, error: Microsoft Antimalware [1119] - Microsoft Antimalware has encountered a critical error when taking action on malware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:DOS/Alureon.A&threatid=2147636949 Name: Trojan:DOS/Alureon.A ID: 2147636949 Severity: Severe Category: Trojan Path: rootkit:_AlureonMbr Detection Origin: Unknown Detection Type: Concrete Detection Source: User User: NT AUTHORITY\SYSTEM Process Name: Unknown Action: Remove Action Status: To finish removing malware and other potentially unwanted software, restart the computer. To see how to finish removing malware and other potentially unwanted software, see the support article on the Microsoft Security website. Error Code: 0x80070032 Error description: The request is not supported. Signature Version: AV: 1.103.1094.0, AS: 1.103.1094.0, NIS: 0.0.0.0 Engine Version: AM: 1.1.6802.0, NIS: 0.0.0.0
    5/6/2011 12:53:39 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.103.1094.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.6802.0 Error code: 0x80072efe Error description: The connection with the server was terminated abnormally
    5/4/2011 11:00:26 AM, error: Service Control Manager [7000] - The CMS PortIO Service service failed to start due to the following error: The system cannot find the file specified.
    5/3/2011 8:11:41 PM, error: SideBySide [59] - Resolve Partial Assembly failed for Microsoft.VC80.MFCLOC. Reference error message: The referenced assembly is not installed on your system. .
    5/3/2011 8:11:41 PM, error: SideBySide [59] - Generate Activation Context failed for C:\Program Files\Cox\Media Store and Share Backup Manager\MFC80U.DLL. Reference error message: The operation completed successfully. .
    5/3/2011 8:11:41 PM, error: SideBySide [32] - Dependent Assembly Microsoft.VC80.MFCLOC could not be found and Last Error was The referenced assembly is not installed on your system.
    5/1/2011 8:26:36 PM, error: SideBySide [59] - Generate Activation Context failed for C:\Program Files\Canon\ZoomBrowser EX\Program\MFC80U.DLL. Reference error message: The operation completed successfully. .
    .
    ==== End Of File ===========================
     
  2. Broni

    Broni Malware Annihilator Posts: 52,898   +344

    Welcome aboard [​IMG]

    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running tools or applying updates other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

    ======================================================================

    It may be just that, "non-standard MBR", but we'll check.

    Download Bootkit Remover to your Desktop.

    • You then need to extract the remover.exe file from the RAR using a program capable of extracing RAR compressed files. If you don't have an extraction program, you can use 7-Zip: http://www.7-zip.org/
    • After extracing remover.exe to your Desktop, double-click on remover.exe to run the program (Vista/7 users,right click on remover.exe and click Run As Administrator).
    • It will show a Black screen with some data on it.
    • Right click on the screen and click Select All.
    • Press CTRL+C
    • Open a Notepad and press CTRL+V
    • Post the output back here.

    =======================================================================

    Please download ComboFix from Here or Here to your Desktop.

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    1. Please, never rename Combofix unless instructed.
    2. Close any open browsers.
    3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
      • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
      NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
      • Close any open browsers.
      • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
      • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
      • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    4. Double click on combofix.exe & follow the prompts.
    5. When finished, it will produce a report for you.
    6. Please post the "C:\ComboFix.txt"
    **Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
    **Note 2 for AVG users: ComboFix will not run until AVG is uninstalled as a protective measure against the anti-virus. This is because AVG "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results". Since AVG cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG first.
    Use AppRemover to uninstall it: http://www.appremover.com/
    We can reinstall it when we're done with CF.
    **Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion", restart computer to fix the issue.



    Make sure, you re-enable your security programs, when you're done with Combofix.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    NOTE.
    If, for some reason, Combofix refuses to run, try one of the following:

    1. Run Combofix from Safe Mode.

    2. Delete Combofix file, download fresh one, but rename combofix.exe to yourname.exe BEFORE saving it to your desktop.
    Do NOT run it yet.

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click Rkill and choose Run as Administrator

    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    Rkill.com
    Rkill.scr
    Rkill.exe

    • Double-click on the Rkill desktop icon to run the tool.
    • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    • If not, delete the file, then download and use the one provided in Link 2.
    • If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
    • Do not reboot until instructed.
    • If the tool does not run from any of the links provided, please let me know.

    Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

    If normal mode still doesn't work, run BOTH tools from safe mode.

    In case #2, please post BOTH logs, rKill and Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
     
  3. Anchorage

    Anchorage TS Rookie Topic Starter Posts: 18

    Thanks, Broni. Here's the logs for remover and combo fix:

    MBRCheck, version 1.2.3
    (c) 2010, AD

    Command-line:
    Windows Version: Windows XP Home Edition
    Windows Information: Service Pack 3 (build 2600)
    Logical Drives Mask: 0x000003fc

    Kernel Drivers (total 126):
    0x804D7000 \WINDOWS\system32\ntkrnlpa.exe
    0x806E5000 \WINDOWS\system32\hal.dll
    0xBA5A8000 \WINDOWS\system32\KDCOM.DLL
    0xBA4B8000 \WINDOWS\system32\BOOTVID.dll
    0xB9F79000 ACPI.sys
    0xBA5AA000 \WINDOWS\system32\DRIVERS\WMILIB.SYS
    0xB9F68000 pci.sys
    0xBA0A8000 isapnp.sys
    0xBA5AC000 intelide.sys
    0xBA328000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
    0xBA0B8000 MountMgr.sys
    0xB9F49000 ftdisk.sys
    0xBA330000 PartMgr.sys
    0xBA0C8000 VolSnap.sys
    0xB9F31000 atapi.sys
    0xB9F0E000 fasttx2k.sys
    0xB9EF6000 \WINDOWS\system32\DRIVERS\SCSIPORT.SYS
    0xBA0D8000 disk.sys
    0xBA0E8000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
    0xB9ED6000 fltmgr.sys
    0xB9EC4000 sr.sys
    0xBA338000 PxHelp20.sys
    0xB9EAD000 KSecDD.sys
    0xB9E9A000 WudfPf.sys
    0xB9E0D000 Ntfs.sys
    0xB9DE0000 NDIS.sys
    0xBA340000 viaagp1.sys
    0xBA0F8000 SISAGPX.sys
    0xBA108000 ohci1394.sys
    0xBA118000 \WINDOWS\system32\DRIVERS\1394BUS.SYS
    0xB9DC6000 Mup.sys
    0xBA168000 \SystemRoot\system32\DRIVERS\nic1394.sys
    0xBA178000 \SystemRoot\system32\DRIVERS\intelppm.sys
    0xB96B0000 \SystemRoot\system32\DRIVERS\ialmnt5.sys
    0xB969C000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
    0xB9674000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
    0xBA3F0000 \SystemRoot\system32\DRIVERS\usbuhci.sys
    0xB9650000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
    0xBA3F8000 \SystemRoot\system32\DRIVERS\usbehci.sys
    0xB97FD000 \SystemRoot\system32\DRIVERS\R8139n51.SYS
    0xB954B000 \SystemRoot\system32\DRIVERS\AGRSM.sys
    0xBA400000 \SystemRoot\System32\Drivers\Modem.SYS
    0xB9537000 \SystemRoot\system32\DRIVERS\parport.sys
    0xB97ED000 \SystemRoot\system32\DRIVERS\imapi.sys
    0xBA560000 \SystemRoot\system32\drivers\pfc.sys
    0xBA408000 \SystemRoot\system32\drivers\iviaspi.sys
    0xB97DD000 \SystemRoot\system32\DRIVERS\cdrom.sys
    0xB97CD000 \SystemRoot\system32\DRIVERS\redbook.sys
    0xB9514000 \SystemRoot\system32\DRIVERS\ks.sys
    0xBA410000 \SystemRoot\SYSTEM32\DRIVERS\GEARAspiWDM.sys
    0xBA7B4000 \SystemRoot\system32\DRIVERS\audstub.sys
    0xB97BD000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
    0xBA56C000 \SystemRoot\system32\DRIVERS\ndistapi.sys
    0xB94FD000 \SystemRoot\system32\DRIVERS\ndiswan.sys
    0xB97AD000 \SystemRoot\system32\DRIVERS\raspppoe.sys
    0xB979D000 \SystemRoot\system32\DRIVERS\raspptp.sys
    0xBA418000 \SystemRoot\system32\DRIVERS\TDI.SYS
    0xB94EC000 \SystemRoot\system32\DRIVERS\psched.sys
    0xB978D000 \SystemRoot\system32\DRIVERS\msgpc.sys
    0xBA420000 \SystemRoot\system32\DRIVERS\ptilink.sys
    0xBA428000 \SystemRoot\system32\DRIVERS\raspti.sys
    0xB977D000 \SystemRoot\system32\DRIVERS\termdd.sys
    0xBA430000 \SystemRoot\system32\DRIVERS\kbdclass.sys
    0xBA438000 \SystemRoot\system32\DRIVERS\mouclass.sys
    0xBA5C2000 \SystemRoot\system32\DRIVERS\swenum.sys
    0xB948E000 \SystemRoot\system32\DRIVERS\update.sys
    0xBA578000 \SystemRoot\system32\DRIVERS\mssmbios.sys
    0xBA1A8000 \SystemRoot\System32\Drivers\NDProxy.SYS
    0xA86C6000 \SystemRoot\system32\drivers\RtkHDAud.sys
    0xA86A2000 \SystemRoot\system32\drivers\portcls.sys
    0xBA1D8000 \SystemRoot\system32\drivers\drmk.sys
    0xBA1E8000 \SystemRoot\system32\DRIVERS\usbhub.sys
    0xBA5CA000 \SystemRoot\system32\DRIVERS\USBD.SYS
    0xA862B000 \SystemRoot\system32\DRIVERS\MpFilter.sys
    0xA8696000 \SystemRoot\system32\DRIVERS\usbscan.sys
    0xBA60A000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
    0xBA7FB000 \SystemRoot\System32\Drivers\Null.SYS
    0xBA60C000 \SystemRoot\System32\Drivers\Beep.SYS
    0xBA480000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
    0xBA488000 \SystemRoot\System32\drivers\vga.sys
    0xBA60E000 \SystemRoot\System32\Drivers\mnmdd.SYS
    0xBA610000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
    0xBA490000 \SystemRoot\System32\Drivers\Msfs.SYS
    0xBA498000 \SystemRoot\System32\Drivers\Npfs.SYS
    0xA868E000 \SystemRoot\system32\DRIVERS\rasacd.sys
    0xA85F8000 \SystemRoot\system32\DRIVERS\ipsec.sys
    0xA859F000 \SystemRoot\system32\DRIVERS\tcpip.sys
    0xA8577000 \SystemRoot\system32\DRIVERS\netbt.sys
    0xA8555000 \SystemRoot\System32\drivers\afd.sys
    0xBA218000 \SystemRoot\system32\DRIVERS\netbios.sys
    0xA852F000 \SystemRoot\system32\DRIVERS\ipnat.sys
    0xBA248000 \SystemRoot\system32\DRIVERS\wanarp.sys
    0xBA258000 \SystemRoot\system32\DRIVERS\arp1394.sys
    0xA867A000 \SystemRoot\system32\DRIVERS\srvkp.sys
    0xA8464000 \SystemRoot\system32\DRIVERS\rdbss.sys
    0xA83F4000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
    0xBA278000 \SystemRoot\System32\Drivers\Fips.SYS
    0xA865E000 \SystemRoot\system32\DRIVERS\hidusb.sys
    0xBA2B8000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
    0xA83A8000 \SystemRoot\System32\Drivers\Fastfat.SYS
    0xBA4A8000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
    0xA8656000 \SystemRoot\system32\DRIVERS\kbdhid.sys
    0xA8652000 \SystemRoot\system32\DRIVERS\mouhid.sys
    0xBA2C8000 \SystemRoot\System32\Drivers\Cdfs.SYS
    0xA8390000 \SystemRoot\System32\Drivers\dump_atapi.sys
    0xBA62C000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS
    0xBF800000 \SystemRoot\System32\win32k.sys
    0xB947E000 \SystemRoot\System32\drivers\Dxapi.sys
    0xBA380000 \SystemRoot\System32\watchdog.sys
    0xBF000000 \SystemRoot\System32\drivers\dxg.sys
    0xBA745000 \SystemRoot\System32\drivers\dxgthk.sys
    0xBF020000 \SystemRoot\System32\ialmdnt5.dll
    0xBF012000 \SystemRoot\System32\ialmrnt5.dll
    0xBF03F000 \SystemRoot\System32\ialmdev5.DLL
    0xBF068000 \SystemRoot\System32\ialmdd5.DLL
    0xBF136000 \SystemRoot\System32\ATMFD.DLL
    0xA8228000 \SystemRoot\system32\DRIVERS\ndisuio.sys
    0xA7FA3000 \SystemRoot\system32\DRIVERS\mrxdav.sys
    0xA7F3A000 \SystemRoot\System32\Drivers\HTTP.sys
    0xA7DF2000 \SystemRoot\system32\DRIVERS\srv.sys
    0xA7FE0000 \SystemRoot\system32\DRIVERS\secdrv.sys
    0xA7C50000 \??\C:\WINDOWS\system32\drivers\tmcomm.sys
    0xBA478000 \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{251B5871-0E3C-452F-ACC7-CB343190C0D0}\MpKsl8eafea47.sys
    0xA7943000 \SystemRoot\system32\drivers\wdmaud.sys
    0xA79C0000 \SystemRoot\system32\drivers\sysaudio.sys
    0x7C900000 \WINDOWS\system32\ntdll.dll

    Processes (total 55):
    0 System Idle Process
    4 System
    492 C:\WINDOWS\system32\smss.exe
    552 csrss.exe
    576 C:\WINDOWS\system32\winlogon.exe
    620 C:\WINDOWS\system32\services.exe
    632 C:\WINDOWS\system32\lsass.exe
    792 C:\WINDOWS\system32\svchost.exe
    844 svchost.exe
    912 C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
    948 C:\WINDOWS\system32\svchost.exe
    988 C:\WINDOWS\system32\svchost.exe
    1076 svchost.exe
    1176 svchost.exe
    1316 C:\WINDOWS\system32\spoolsv.exe
    1444 svchost.exe
    1476 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    1492 C:\Program Files\Bonjour\mDNSResponder.exe
    1564 C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
    1644 C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    1700 C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    1796 C:\WINDOWS\system32\svchost.exe
    372 C:\Program Files\Cox\Media Store and Share Backup Manager\VaultClientSRV.exe
    384 C:\Program Files\Cox\Media Store and Share Backup Manager\VaultClientUpgrade.exe
    400 C:\Program Files\Viewpoint\Common\ViewpointService.exe
    544 C:\Program Files\Canon\CAL\CALMAIN.exe
    1736 alg.exe
    2808 C:\WINDOWS\explorer.exe
    3388 C:\WINDOWS\system\hpsysdrv.exe
    3396 C:\WINDOWS\system32\hkcmd.exe
    3628 C:\WINDOWS\system32\hphmon06.exe
    3672 C:\hp\KBD\kbd.exe
    3784 C:\WINDOWS\AGRSMMSG.exe
    3820 C:\hp\drivers\hplsbwatcher\LSBurnWatcher.exe
    3860 C:\WINDOWS\system32\igfxtray.exe
    3924 C:\WINDOWS\system32\svchost.exe
    3932 C:\WINDOWS\SOUNDMAN.EXE
    3944 C:\WINDOWS\ALCWZRD.EXE
    3988 C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
    4036 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    4060 C:\Program Files\Microsoft IntelliPoint\point32.exe
    1928 C:\PROGRA~1\Sony\SONICS~1\SSAAD.exe
    2032 C:\Program Files\Cox\Media Store and Share Backup Manager\VaultClientTray.exe
    2044 C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
    464 C:\Program Files\Microsoft Security Client\msseces.exe
    740 C:\Program Files\iTunes\iTunesHelper.exe
    1520 C:\Program Files\Common Files\Java\Java Update\jusched.exe
    420 C:\Program Files\Microsoft Student\Microsoft Student 2006 DVD\EDICT.EXE
    132 C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
    744 C:\WINDOWS\system32\ctfmon.exe
    356 C:\Program Files\FinePixViewer\QuickDCF.exe
    1280 C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    2236 C:\Program Files\Southwest Airlines\Ding\Ding.exe
    2588 C:\Program Files\iPod\bin\iPodService.exe
    1104 C:\Documents and Settings\HP_Owner\Desktop\MBRCheck.exe

    \\.\C: --> \\.\PhysicalDrive0 at offset 0x00000001`84fb6000 (NTFS)
    \\.\D: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (FAT32)

    PhysicalDrive0 Model Number: WDCWD2500JD-22HBB0, Rev: 08.02D08

    Size Device Name MBR Status
    --------------------------------------------
    232 GB \\.\PhysicalDrive0 Unknown MBR code
    SHA1: EC5B6F4B08268D5344F30BFF61C8B587F034795B


    Found non-standard or infected MBR.
    Enter 'Y' and hit ENTER for more options, or 'N' to exit:

    Done!

    ======================================


    ComboFix 11-05-08.04 - HP_Owner 05/08/2011 23:00:14.3.2 - x86
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1527.776 [GMT -7:00]
    Running from: c:\documents and settings\HP_Owner\Desktop\ComboFix.exe
    AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
    AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
    * Created a new restore point
    .
    .
    ((((((((((((((((((((((((( Files Created from 2011-04-09 to 2011-05-09 )))))))))))))))))))))))))))))))
    .
    .
    2011-05-09 05:46 . 2011-05-09 05:46 -------- d-----w- c:\program files\7-Zip
    2011-05-08 18:48 . 2011-05-08 18:48 28752 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{1C4E42EE-88D6-41BA-8709-6F2D62D43942}\MpKsle7e10c5d.sys
    2011-05-08 18:47 . 2011-04-11 07:04 7071056 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{1C4E42EE-88D6-41BA-8709-6F2D62D43942}\mpengine.dll
    2011-05-08 16:53 . 2010-12-21 01:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2011-05-08 16:53 . 2011-05-08 16:53 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2011-05-08 16:53 . 2010-12-21 01:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2011-05-08 06:49 . 2011-05-08 06:49 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\Foxit Software
    2011-05-08 06:48 . 2011-05-08 06:48 -------- d-----w- c:\program files\Foxit Software
    2011-05-08 06:09 . 2011-05-08 06:09 -------- d-----w- c:\program files\Common Files\Java
    2011-05-08 03:00 . 2011-05-08 03:00 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
    2011-05-06 14:36 . 2011-05-06 14:36 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
    2011-04-24 20:18 . 2011-04-24 20:18 -------- d-----w- c:\program files\iPod
    2011-04-24 20:18 . 2011-04-24 20:19 -------- d-----w- c:\program files\iTunes
    2011-04-24 20:14 . 2011-04-24 20:14 -------- d-----w- c:\program files\Bonjour
    2011-04-23 00:19 . 2011-04-23 06:16 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\Skype
    2011-04-23 00:19 . 2011-04-23 00:19 -------- d-----r- c:\program files\Skype
    2011-04-23 00:18 . 2011-04-23 00:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-04-14 12:07 . 2010-05-27 06:07 472808 ----a-w- c:\windows\system32\deployJava1.dll
    2011-04-14 09:40 . 2007-04-14 03:11 73728 ----a-w- c:\windows\system32\javacpl.cpl
    2011-04-11 07:04 . 2010-08-28 23:55 7071056 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
    2011-04-06 23:20 . 2011-04-06 23:20 91424 ----a-w- c:\windows\system32\dnssd.dll
    2011-04-06 23:20 . 2011-04-06 23:20 107808 ----a-w- c:\windows\system32\dns-sd.exe
    2011-03-07 05:33 . 2004-11-03 18:50 692736 ----a-w- c:\windows\system32\inetcomm.dll
    2011-03-04 06:37 . 2004-11-03 18:52 420864 ----a-w- c:\windows\system32\vbscript.dll
    2011-03-03 13:21 . 2004-11-03 18:52 1857920 ----a-w- c:\windows\system32\win32k.sys
    2011-02-22 23:06 . 2004-11-03 18:52 916480 ----a-w- c:\windows\system32\wininet.dll
    2011-02-22 23:06 . 2004-11-03 18:50 43520 ----a-w- c:\windows\system32\licmgr10.dll
    2011-02-22 23:06 . 2004-11-03 18:50 1469440 ------w- c:\windows\system32\inetcpl.cpl
    2011-02-22 11:41 . 2004-11-03 18:50 385024 ----a-w- c:\windows\system32\html.iec
    2011-02-17 13:18 . 2004-11-03 18:50 455936 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
    2011-02-17 13:18 . 2004-11-03 18:51 357888 ----a-w- c:\windows\system32\drivers\srv.sys
    2011-02-17 12:32 . 2009-04-16 13:25 5120 ----a-w- c:\windows\system32\xpsp4res.dll
    2011-02-15 12:56 . 2004-11-03 19:19 290432 ----a-w- c:\windows\system32\atmfd.dll
    2011-02-11 13:25 . 2004-11-03 18:49 229888 ----a-w- c:\windows\system32\fxscover.exe
    2011-02-09 13:53 . 2004-11-03 18:50 270848 ----a-w- c:\windows\system32\sbe.dll
    2011-02-09 13:53 . 2004-11-03 18:49 186880 ----a-w- c:\windows\system32\encdec.dll
    2011-02-08 13:33 . 2004-11-03 18:50 978944 ----a-w- c:\windows\system32\mfc42.dll
    2011-02-08 13:33 . 2004-11-03 18:50 974848 ----a-w- c:\windows\system32\mfc42u.dll
    2008-02-08 04:46 . 2008-02-08 04:46 13624 ----a-w- c:\program files\mozilla firefox\plugins\cgpcfg.dll
    2008-02-08 04:46 . 2008-02-08 04:46 87360 ----a-w- c:\program files\mozilla firefox\plugins\CgpCore.dll
    2008-02-08 04:46 . 2008-02-08 04:46 91448 ----a-w- c:\program files\mozilla firefox\plugins\confmgr.dll
    2008-02-08 04:46 . 2008-02-08 04:46 21824 ----a-w- c:\program files\mozilla firefox\plugins\ctxlogging.dll
    2008-02-08 04:46 . 2008-02-08 04:46 206136 ----a-w- c:\program files\mozilla firefox\plugins\ctxmui.dll
    2008-02-08 04:46 . 2008-02-08 04:46 31544 ----a-w- c:\program files\mozilla firefox\plugins\icafile.dll
    2008-02-08 04:46 . 2008-02-08 04:46 40248 ----a-w- c:\program files\mozilla firefox\plugins\icalogon.dll
    2007-03-17 00:27 . 2007-03-17 00:27 479232 ----a-w- c:\program files\mozilla firefox\plugins\msvcm80.dll
    2007-03-17 00:27 . 2007-03-17 00:27 548864 ----a-w- c:\program files\mozilla firefox\plugins\msvcp80.dll
    2007-03-17 00:27 . 2007-03-17 00:27 626688 ----a-w- c:\program files\mozilla firefox\plugins\msvcr80.dll
    2007-07-20 19:47 . 2007-07-20 19:47 981170 ----a-w- c:\program files\mozilla firefox\plugins\sslsdk_b.dll
    2008-02-08 04:46 . 2008-02-08 04:46 24384 ----a-w- c:\program files\mozilla firefox\plugins\TcpPServ.dll
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\VaultIcon1]
    @="{B976888E-DC7B-456C-A62F-44EA07ED231F}"
    [HKEY_CLASSES_ROOT\CLSID\{B976888E-DC7B-456C-A62F-44EA07ED231F}]
    2008-10-08 21:44 495616 ----a-w- c:\program files\Cox\Media Store and Share Backup Manager\VaultClientMenu.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\VaultIcon2]
    @="{E30CEB29-7F47-4d0e-B2E1-56A7FC25E97D}"
    [HKEY_CLASSES_ROOT\CLSID\{E30CEB29-7F47-4d0e-B2E1-56A7FC25E97D}]
    2008-10-08 21:44 491520 ----a-w- c:\program files\Cox\Media Store and Share Backup Manager\VaultClientIcon.dll
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "L06AXLRD_6820281"="c:\program files\Microsoft Student\Microsoft Student 2006 DVD\EDICT.EXE" [2005-06-03 301776]
    "ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-11-02 126976]
    "HPHUPD06"="c:\program files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe" [2004-06-08 49152]
    "HPHmon06"="c:\windows\system32\hphmon06.exe" [2004-06-08 659456]
    "KBD"="c:\hp\KBD\KBD.EXE" [2003-02-12 61440]
    "Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-15 233472]
    "AlcxMonitor"="ALCXMNTR.EXE" [2004-09-08 57344]
    "AGRSMMSG"="AGRSMMSG.exe" [2005-03-04 88209]
    "PS2"="c:\windows\system32\ps2.exe" [2002-10-16 81920]
    "LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-15 253952]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-11-02 155648]
    "ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-09-11 218032]
    "SoundMan"="SOUNDMAN.EXE" [2005-09-21 86016]
    "AlcWzrd"="ALCWZRD.EXE" [2005-09-21 2807808]
    "REGSHAVE"="c:\program files\REGSHAVE\REGSHAVE.EXE" [2002-02-05 53248]
    "UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
    "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2004-10-22 180269]
    "IntelliPoint"="c:\program files\Microsoft IntelliPoint\point32.exe" [2005-03-23 217088]
    "SsAAD.exe"="c:\progra~1\Sony\SONICS~1\SsAAD.exe" [2005-03-11 81920]
    "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-04-13 47392]
    "TrayStartup"="c:\program files\Cox\Media Store and Share Backup Manager\VaultClientTray.exe" [2008-10-08 293328]
    "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-30 421888]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-04-14 421160]
    "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-01-07 253672]
    .
    c:\documents and settings\HP_Owner\Start Menu\Programs\Startup\
    DING!.lnk - c:\program files\Southwest Airlines\Ding\Ding.exe [2006-6-22 462848]
    .
    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Exif Launcher.lnk - c:\program files\FinePixViewer\QuickDCF.exe [2006-8-4 282624]
    HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-5-29 241664]
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
    @="Service"
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Updates from HP\\309731\\Program\\Updates from HP.exe"=
    "c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
    "c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
    "c:\\Program Files\\NetMeeting\\conf.exe"=
    "c:\\Program Files\\Quicken WillMaker Plus 2004\\qlp.exe"=
    "c:\\WINDOWS\\system32\\dpvsetup.exe"=
    "c:\\Program Files\\Messenger\\msmsgs.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
    "c:\\Program Files\\AIM6\\aim6.exe"=
    "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
    "c:\\StubInstaller.exe"=
    "c:\\WINDOWS\\pchealth\\helpctr\\binaries\\helpctr.exe"=
    "c:\\Documents and Settings\\HP_Owner\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
    "c:\\Program Files\\Skype\\Phone\\Skype.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "25126:TCP"= 25126:TCP:pORT_25126
    "29865:TCP"= 29865:TCP:pORT_29865
    "53960:TCP"= 53960:TCP:pORT_53960
    "20601:TCP"= 20601:TCP:pORT_20601
    "36394:TCP"= 36394:TCP:pORT_36394
    "37498:TCP"= 37498:TCP:pORT_37498
    "21701:TCP"= 21701:TCP:pORT_21701
    "21624:TCP"= 21624:TCP:pORT_21624
    "58984:TCP"= 58984:TCP:pORT_58984
    "51664:TCP"= 51664:TCP:pORT_51664
    "40820:TCP"= 40820:TCP:pORT_40820
    "56425:TCP"= 56425:TCP:pORT_56425
    "62603:TCP"= 62603:TCP:pORT_62603
    "7255:TCP"= 7255:TCP:pORT_7255
    "23495:TCP"= 23495:TCP:pORT_23495
    "27476:TCP"= 27476:TCP:pORT_27476
    "35468:TCP"= 35468:TCP:pORT_35468
    "26023:TCP"= 26023:TCP:pORT_26023
    "65164:TCP"= 65164:TCP:pORT_65164
    "9563:TCP"= 9563:TCP:pORT_9563
    "26080:TCP"= 26080:TCP:pORT_26080
    "38295:TCP"= 38295:TCP:pORT_38295
    "54692:TCP"= 54692:TCP:pORT_54692
    "58653:TCP"= 58653:TCP:pORT_58653
    "40082:TCP"= 40082:TCP:pORT_40082
    "61640:TCP"= 61640:TCP:pORT_61640
    "32712:TCP"= 32712:TCP:pORT_32712
    "14538:TCP"= 14538:TCP:pORT_14538
    "14930:TCP"= 14930:TCP:pORT_14930
    "27677:TCP"= 27677:TCP:pORT_27677
    "34565:TCP"= 34565:TCP:pORT_34565
    "42700:TCP"= 42700:TCP:pORT_42700
    "16738:TCP"= 16738:TCP:pORT_16738
    "56043:TCP"= 56043:TCP:pORT_56043
    "27453:TCP"= 27453:TCP:pORT_27453
    "13338:TCP"= 13338:TCP:pORT_13338
    "62986:TCP"= 62986:TCP:pORT_62986
    "19895:TCP"= 19895:TCP:pORT_19895
    "32254:TCP"= 32254:TCP:pORT_32254
    "54498:TCP"= 54498:TCP:pORT_54498
    "47688:TCP"= 47688:TCP:pORT_47688
    "20611:TCP"= 20611:TCP:pORT_20611
    "9594:TCP"= 9594:TCP:pORT_9594
    "13238:TCP"= 13238:TCP:pORT_13238
    "65398:TCP"= 65398:TCP:pORT_65398
    "55765:TCP"= 55765:TCP:pORT_55765
    "34191:TCP"= 34191:TCP:pORT_34191
    "45039:TCP"= 45039:TCP:pORT_45039
    "47035:TCP"= 47035:TCP:pORT_47035
    "44803:TCP"= 44803:TCP:pORT_44803
    "20084:TCP"= 20084:TCP:pORT_20084
    "60306:TCP"= 60306:TCP:pORT_60306
    "47230:TCP"= 47230:TCP:pORT_47230
    "37029:TCP"= 37029:TCP:pORT_37029
    "65473:TCP"= 65473:TCP:pORT_65473
    "37843:TCP"= 37843:TCP:pORT_37843
    "47313:TCP"= 47313:TCP:pORT_47313
    "63828:TCP"= 63828:TCP:pORT_63828
    "40645:TCP"= 40645:TCP:pORT_40645
    "28413:TCP"= 28413:TCP:pORT_28413
    "10160:TCP"= 10160:TCP:pORT_10160
    .
    R1 MpKsle7e10c5d;MpKsle7e10c5d;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{1C4E42EE-88D6-41BA-8709-6F2D62D43942}\MpKsle7e10c5d.sys [5/8/2011 11:48 AM 28752]
    R2 VaultClientSRV;Media Store and Share Backup Manager Service;c:\program files\Cox\Media Store and Share Backup Manager\VaultClientSRV.exe [10/8/2008 2:45 PM 981456]
    R2 VaultClientUpgrade;Backup Manager Upgrade Service;c:\program files\Cox\Media Store and Share Backup Manager\VaultClientUpgrade.exe [10/8/2008 2:45 PM 55760]
    R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [10/27/2007 11:29 AM 24652]
    S1 MpKsl49aa2db8;MpKsl49aa2db8;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0EDE0D93-3970-4FC5-A549-A96208D63AE9}\MpKsl49aa2db8.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0EDE0D93-3970-4FC5-A549-A96208D63AE9}\MpKsl49aa2db8.sys [?]
    S1 MpKsl70ae1981;MpKsl70ae1981;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3036D298-57AB-4D3D-B17B-173A5171DB20}\MpKsl70ae1981.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3036D298-57AB-4D3D-B17B-173A5171DB20}\MpKsl70ae1981.sys [?]
    S2 portD;CMS PortIO Service;c:\windows\system32\DRIVERS\portd2k.sys --> c:\windows\system32\DRIVERS\portd2k.sys [?]
    .
    --- Other Services/Drivers In Memory ---
    .
    *NewlyCreated* - MPKSL8EAFEA47
    *NewlyCreated* - MPKSLE7E10C5D
    *NewlyCreated* - UGTYIAOW
    *Deregistered* - MpKsl8eafea47
    *Deregistered* - ugtyiaow
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    itlsvc REG_MULTI_SZ itlperf
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2011-04-21 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]
    .
    2011-05-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-290765245-458117374-2010186662-1009Core.job
    - c:\documents and settings\HP_Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-08-27 03:20]
    .
    2011-05-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-290765245-458117374-2010186662-1009UA.job
    - c:\documents and settings\HP_Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-08-27 03:20]
    .
    2011-05-08 c:\windows\Tasks\MP Scheduled Scan.job
    - c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2010-11-11 19:26]
    .
    2011-05-09 c:\windows\Tasks\User_Feed_Synchronization-{F58D5285-DFA7-4EB6-9C2C-0DFF06830970}.job
    - c:\windows\system32\msfeedssync.exe [2009-03-08 11:31]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://my.yahoo.com/
    mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
    uInternet Settings,ProxyOverride = *.local
    Trusted Zone: boeing.com\bpn
    Trusted Zone: intuit.com\ttlc
    Trusted Zone: turbotax.com
    DPF: MCInstallCAB - hxxps://content101.mc.iconf.net/gcc_installer/mcInstall.cab
    DPF: {26B2A5DA-BFD6-422F-A89A-28A54C74B12B} - hxxp://images3.pnimedia.com/ProductAssets/costcous/activex/v3_0_0_4/PhotoCenter_ActiveX_Control.cab
    DPF: {60246658-5626-449F-8701-66D278AD2EB2} - hxxp://www.brainfuse.com/downloads/QCDetector/BrainfuseQuickConnectDetector.CAB
    FF - ProfilePath - c:\documents and settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\y5yrcg4q.default\
    FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
    FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
    .
    - - - - ORPHANS REMOVED - - - -
    .
    HKCU-Run-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
    .
    .
    .
    **************************************************************************
    .
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2011-05-08 23:09
    Windows 5.1.2600 Service Pack 3 NTFS
    .
    scanning hidden processes ...
    .
    scanning hidden autostart entries ...
    .
    scanning hidden files ...
    .
    scan completed successfully
    hidden files: 0
    .
    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_USERS\S-1-5-21-290765245-458117374-2010186662-1009\Software\Microsoft\SystemCertificates\AddressBook*]
    @Allowed: (Read) (RestrictedCode)
    @Allowed: (Read) (RestrictedCode)
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
    @="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker4"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------
    .
    - - - - - - - > 'explorer.exe'(3136)
    c:\windows\system32\WININET.dll
    c:\program files\Cox\Media Store and Share Backup Manager\VaultClientMenu.dll
    c:\program files\Cox\Media Store and Share Backup Manager\LIBEXPAT.dll
    c:\program files\Cox\Media Store and Share Backup Manager\VaultClientCOM.dll
    c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
    c:\program files\Cox\Media Store and Share Backup Manager\VaultClientIcon.dll
    c:\windows\system32\ieframe.dll
    c:\windows\system32\webcheck.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    Completion time: 2011-05-08 23:13:22
    ComboFix-quarantined-files.txt 2011-05-09 06:13
    .
    Pre-Run: 104,526,770,176 bytes free
    Post-Run: 104,541,679,616 bytes free
    .
    - - End Of File - - 611FA63CFC9C775E6F554F93D716DA9E
     
  4. Broni

    Broni Malware Annihilator Posts: 52,898   +344

    I still need Bootkit Remover log.
     
  5. Anchorage

    Anchorage TS Rookie Topic Starter Posts: 18

    Sorry, I had missed that running remover.exe also created a file on my desktop called bootkit_remover_debug_log.txt. It opens in Notepad but looks unformatted, so attaching here as text file.
     

    Attached Files:

  6. Broni

    Broni Malware Annihilator Posts: 52,898   +344

    Combofix doesn't show any MBR issues, so you should be OK.

    Any current issues?
     
  7. Anchorage

    Anchorage TS Rookie Topic Starter Posts: 18

    No virus-like issues, just getting a jusched.exe failure warning, but when I follow the link it gives to resolve it, it says I already have the latest version (25?) and doesn't update. Assuming that's not a security issue, however...
     
  8. Broni

    Broni Malware Annihilator Posts: 52,898   +344

  9. Anchorage

    Anchorage TS Rookie Topic Starter Posts: 18

    Thanks for the help, Broni! Guess I'll just have to live with knowing my PC has a "non-standard MBR", :)
     
  10. Broni

    Broni Malware Annihilator Posts: 52,898   +344

    I've seen this before on many healthy computers. No worries :)
     
Topic Status:
Not open for further replies.

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...