Here are my logs:
Malwarebytes Anti-Malware 1.61.0.1400
www.malwarebytes.org
Database version: v2012.05.07.03
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Owner :: ANTIREAL-917A9F [administrator]
5/7/2012 2:07:05 PM
mbam-log-2012-05-07 (14-07-05).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 199371
Time elapsed: 5 minute(s), 55 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 1
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SETUP.EXE (Spyware.Password) -> Quarantined and deleted successfully.
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 1
C:\WINDOWS\Temp\mtwple\setup.exe (Spyware.Password) -> Quarantined and deleted successfully.
(end)
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-05-07 21:19:17
Windows 5.1.2600 Service Pack 3 Harddisk1\DR1 -> \Device\Ide\IdeDeviceP2T0L0-17 WDC_WD5000AAKS-22V1A0 rev.05.01D05
Running: e1xgmfot.exe; Driver: C:\DOCUME~1\Owner\LOCALS~1\Temp\kxkyqkob.sys
---- System - GMER 1.0.15 ----
SSDT spbj.sys ZwCreateKey [0xB7EB50E0]
SSDT spbj.sys ZwEnumerateKey [0xB7ECDDA4]
SSDT spbj.sys ZwEnumerateValueKey [0xB7ECE132]
SSDT spbj.sys ZwOpenKey [0xB7EB50C0]
SSDT spbj.sys ZwQueryKey [0xB7ECE20A]
SSDT spbj.sys ZwQueryValueKey [0xB7ECE08A]
SSDT spbj.sys ZwSetValueKey [0xB7ECE29C]
INT 0x62 ? 8A693BF8
INT 0x63 ? 8A693BF8
INT 0x63 ? 8A693BF8
INT 0x63 ? 8A469F00
INT 0x63 ? 8A693BF8
INT 0x82 ? 8A693BF8
INT 0x83 ? 8A469F00
INT 0xA4 ? 8A469F00
INT 0xB4 ? 8A469F00
---- Kernel code sections - GMER 1.0.15 ----
? fkubf.sys The system cannot find the file specified. !
? spbj.sys The system cannot find the file specified. !
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB6A993A0, 0x5FE082, 0xE8000020]
.text USBPORT.SYS!DllUnload B6A1A8AC 5 Bytes JMP 8A4694E0
.text mrxsmb.sys!?GenerateMonitorW@@IJXEGGPAH@X B1B95000 12 Bytes JMP B1B95C0D \SystemRoot\system32\DRIVERS\mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)
.text mrxsmb.sys!?GenerateMonitorW@@IJXEGGPAH@X B1B9500D 227 Bytes [25, 28, 0A, BB, B1, 8B, 0D, ...]
.text mrxsmb.sys!?GenerateMonitorW@@IJXEGGPAH@X B1B950F2 5 Bytes [90, 90, 90, 90, 90] {NOP ; NOP ; NOP ; NOP ; NOP }
.text mrxsmb.sys!?GenerateMonitorW@@IJXEGGPAH@X B1B950F8 67 Bytes [FF, 55, 8B, EC, 51, 83, 65, ...]
.text mrxsmb.sys!?GenerateMonitorW@@IJXEGGPAH@X B1B9513C 66 Bytes [EB, EA, 80, BF, CE, 00, 00, ...]
.text ...
? C:\WINDOWS\system32\DRIVERS\mrxsmb.sys suspicious PE modification
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [B7EB6042] spbj.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [B7EB613E] spbj.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [B7EB60C0] spbj.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [B7EB6800] spbj.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [B7EB66D6] spbj.sys
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 8A6231F8
Device \FileSystem\Fastfat \FatCdrom 898C2500
Device \FileSystem\MacOpen \MacOpenCd 8A6241F8
Device \FileSystem\MacOpen \MacOpen 8A6241F8
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
Device \Driver\usbuhci \Device\USBPDO-0 8A4681F8
Device \Driver\usbuhci \Device\USBPDO-1 8A4681F8
Device \Driver\usbuhci \Device\USBPDO-2 8A4681F8
Device \Driver\usbuhci \Device\USBPDO-3 8A4681F8
Device \Driver\usbehci \Device\USBPDO-4 8A43F1F8
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
Device \Driver\Ftdisk \Device\HarddiskVolume1 8A6251F8
Device \Driver\Ftdisk \Device\HarddiskVolume2 8A6251F8
Device \Driver\Cdrom \Device\CdRom0 8A43B1F8
Device \Driver\atapi \Device\Ide\IdePort0 [B7E2FB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort1 [B7E2FB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 [B7E2FB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort2 [B7E2FB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort3 [B7E2FB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c [B7E2FB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-17 [B7E2FB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\Ftdisk \Device\HarddiskVolume3 8A6251F8
Device \Driver\dtsoftbus01 \Device\DTSoftBusCtl 8A38C1F8
Device \Driver\NetBT \Device\NetBt_Wins_Export 89E63408
Device \Driver\NetBT \Device\NetbiosSmb 89E63408
Device \Driver\USBSTOR \Device\00000079 8990B1F8
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
Device \Driver\usbuhci \Device\USBFDO-0 8A4681F8
Device \Driver\usbuhci \Device\USBFDO-1 8A4681F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 89946500
Device \Driver\usbuhci \Device\USBFDO-2 8A4681F8
Device \Driver\USBSTOR \Device\0000007c 8990B1F8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 89946500
Device \Driver\usbuhci \Device\USBFDO-3 8A4681F8
Device \Driver\usbehci \Device\USBFDO-4 8A43F1F8
Device \Driver\Ftdisk \Device\FtControl 8A6251F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{FB538499-B92F-4DF6-B0B6-E3E1A8AAAA9A} 89E63408
Device \FileSystem\Fastfat \Fat 898C2500
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device \FileSystem\Cdfs \Cdfs 8A1EE500
---- Modules - GMER 1.0.15 ----
Module (noname) (*** hidden *** ) B1C04000-B1C19000 (86016 bytes)
---- Processes - GMER 1.0.15 ----
Process C:\WINDOWS\System32\ping.exe (*** hidden *** ) 3732
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKCU\Software\Microsoft\Windows\CurrentVersion@IQ\ahß\x8d\x8f\x2013 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{EB1D1CCD-4AE7-D0B5-C8C7-D7DA3F86DF23}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{EB1D1CCD-4AE7-D0B5-C8C7-D7DA3F86DF23}@najoclpngfpmhgbbbapibcghiemc 0x69 0x61 0x70 0x68 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@Í\x2039í\x2039T\x20acó` 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@Í\x2039í\x2039\x201c\x008feQ 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@\20\x90\20nÐc:y 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@\26Y\1xÐc:y 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@Òczz<h 0
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@IQ\ahß\x8d\x8f\x2013 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@Í\x2039í\x2039T\x20acó` 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@Í\x2039í\x2039\x201c\x008feQ 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@\20\x90\20nÐc:y 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@\26Y\1xÐc:y 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@Òczz<h 0
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@IQ\ahß\x8d\x8f\x2013 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@Í\x2039í\x2039T\x20acó` 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@Í\x2039í\x2039\x201c\x008feQ 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@\20\x90\20nÐc:y 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@\26Y\1xÐc:y 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@Òczz<h 0
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@IQ\ahß\x8d\x8f\x2013 1
---- Files - GMER 1.0.15 ----
File C:\WINDOWS\$NtUninstallKB13146$\1598319646 0 bytes
File C:\WINDOWS\$NtUninstallKB13146$\1598319646\@ 2048 bytes
File C:\WINDOWS\$NtUninstallKB13146$\1598319646\cfg.ini 298 bytes
File C:\WINDOWS\$NtUninstallKB13146$\1598319646\Desktop.ini 4608 bytes
File C:\WINDOWS\$NtUninstallKB13146$\1598319646\L 0 bytes
File C:\WINDOWS\$NtUninstallKB13146$\1598319646\L\vjjaxloi 456320 bytes
File C:\WINDOWS\$NtUninstallKB13146$\1598319646\oemid 233 bytes
File C:\WINDOWS\$NtUninstallKB13146$\1598319646\U 0 bytes
File C:\WINDOWS\$NtUninstallKB13146$\1598319646\U\00000001.@ 2048 bytes
File C:\WINDOWS\$NtUninstallKB13146$\1598319646\U\00000002.@ 224768 bytes
File C:\WINDOWS\$NtUninstallKB13146$\1598319646\U\00000004.@ 1024 bytes
File C:\WINDOWS\$NtUninstallKB13146$\1598319646\U\80000000.@ 66560 bytes
File C:\WINDOWS\$NtUninstallKB13146$\1598319646\U\80000004.@ 1024 bytes
File C:\WINDOWS\$NtUninstallKB13146$\1598319646\U\80000032.@ 115712 bytes
File C:\WINDOWS\$NtUninstallKB13146$\1598319646\version 1265 bytes
File C:\WINDOWS\$NtUninstallKB13146$\322140457 0 bytes
---- EOF - GMER 1.0.15 ----
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_31
Run by Owner at 21:24:43 on 2012-05-07
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.956 [GMT -4:00]
.
AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG2012\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\AVG\AVG2012\avgtray.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\PixArt\PAC7311\Monitor.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe
C:\Program Files\MacOpener\MacName.exe
C:\Program Files\AVG\AVG2012\avgnsx.exe
C:\Program Files\AVG\AVG2012\avgrsx.exe
C:\Program Files\AVG\AVG2012\avgcsrvx.exe
C:\Program Files\Mozilla Firefox4\firefox.exe
C:\Program Files\Mozilla Firefox4\plugin-container.exe
.
============== Pseudo HJT Report ===============
.
uInternet Settings,ProxyOverride = *.local
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg2012\avgssie.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
uRun: [Facebook Update] "c:\documents and settings\owner\local settings\application data\facebook\update\FacebookUpdate.exe" /c /nocrashserver
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [DAEMON Tools Pro Agent] "c:\program files\daemon tools pro\DTAgent.exe" -autorun
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [AVG_TRAY] "c:\program files\avg\avg2012\avgtray.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [nwiz] c:\program files\nvidia corporation\nview\nwiz.exe /installquiet
mRun: [PAC7311_Monitor] c:\windows\pixart\pac7311\Monitor.exe
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [CanonSolutionMenu] c:\program files\canon\solutionmenu\CNSLMAIN.exe /logon
mRun: [CanonMyPrinter] c:\program files\canon\myprinter\BJMyPrt.exe /logon
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [<NO NAME>]
mRun: [Adobe Acrobat Speed Launcher] "c:\program files\adobe\acrobat 10.0\acrobat\Acrobat_sl.exe"
mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 10.0\acrobat\Acrotray.exe"
mRun: [MacLicense] "c:\program files\macopener\MacLic.exe"
mRun: [PWRISOVM.EXE] c:\program files\poweriso\PWRISOVM.EXE
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\macname.lnk - c:\program files\macopener\MacName.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
LSP: mswsock.dll
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
TCP: DhcpNameServer = 192.168.1.1 192.168.1.1
TCP: Interfaces\{FB538499-B92F-4DF6-B0B6-E3E1A8AAAA9A} : DhcpNameServer = 192.168.1.1 192.168.1.1
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg2012\avgpp.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Notify: igfxcui - igfxdev.dll
Hosts: 216.172.189.172 www.nauscopy.net
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\owner\application data\mozilla\firefox\profiles\2c56x62f.default\
FF - component: c:\documents and settings\owner\application data\mozilla\firefox\profiles\2c56x62f.default\extensions\firesheep@codebutler.com\platform\winnt_x86-msvc\components\mozpopen.dll
FF - component: c:\program files\avg\avg10\firefox4\components\avgssff4.dll
FF - plugin: c:\documents and settings\owner\local settings\application data\facebook\video\skype\npFacebookVideoCalling.dll
FF - plugin: c:\program files\adobe\acrobat 10.0\acrobat\air\nppdf32.dll
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\canon\easy-photoprint ex\NPEZFFPI.DLL
FF - plugin: c:\program files\java\jre6\bin\plugin2\npdeployJava1.dll
FF - plugin: c:\program files\java\jre6\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\sony online entertainment\npsoe.dll
FF - plugin: c:\program files\sony online entertainment\npsoeact.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_2_202_235.dll
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2010-9-13 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2010-9-7 32592]
R0 MacOpen;MacOpen;c:\windows\system32\drivers\MacOpen.sys [2012-4-14 177152]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2010-9-7 230608]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2010-9-7 40016]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2010-9-7 295248]
R2 avgwd;AVG WatchDog;c:\program files\avg\avg2012\avgwdsvc.exe [2011-8-2 192776]
R2 cdenable;cdenable;c:\windows\system32\drivers\cdenable.sys [2012-4-18 6112]
R2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\program files\sony\pmb\PMBDeviceInfoProvider.exe [2010-11-27 398176]
R3 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [2012-4-28 242240]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32.sys [2010-11-16 100456]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 starwindservice;RIOXDRV;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-4 257696]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2010-11-16 1691480]
S3 arusb(SMC);SMCWUSB-N2 802.11n Wireless USB 2.0 Adapter Service(SMC);c:\windows\system32\drivers\arusb.sys --> c:\windows\system32\drivers\arusb.sys [?]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2011-8-18 2152152]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\lavasoft\ad-aware\kernexplorer.sys [2011-8-18 15232]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2012-5-4 129976]
S3 NPF;WinPcap Packet Driver (NPF);c:\windows\system32\drivers\npf.sys [2010-6-25 35088]
S3 rt2870;Linksys 802.11n USB Wireless LAN Card Driver;c:\windows\system32\drivers\rt2870.sys --> c:\windows\system32\drivers\rt2870.sys [?]
S3 ts_arusb;[CommView] Atheros Wireless Network Adapter Service;c:\windows\system32\drivers\ts_arusb.sys [2010-5-22 1054312]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2012-05-07 18:05:50 -------- d-----w- c:\documents and settings\owner\application data\Malwarebytes
2012-05-07 18:05:42 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2012-05-07 18:05:41 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-05-07 18:05:41 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-05-07 04:28:44 0 --sha-w- c:\windows\system32\dds_trash_log.cmd
2012-05-05 06:11:01 20976 ----a-w- c:\windows\system\CTL3D.DLL
2012-05-05 06:11:01 136448 ----a-w- c:\windows\RMTOOLS.DLL
2012-05-05 06:11:00 -------- d-----w- C:\MAXIS
2012-05-05 00:46:16 -------- d-----w- C:\dosgames
2012-05-05 00:42:09 -------- d-----w- c:\documents and settings\owner\local settings\application data\DOSBox
2012-05-05 00:41:37 -------- d-----w- c:\program files\DOSBox-0.74
2012-05-04 22:09:14 4140192 ----a-w- c:\windows\system32\FlashPlayerInstaller.exe
2012-05-04 19:54:54 -------- d-----w- c:\program files\Mozilla Maintenance Service
2012-04-28 23:58:37 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2012-04-28 23:58:18 -------- d-----w- c:\program files\LSoft Technologies
2012-04-28 23:03:39 -------- d-----w- c:\program files\PowerISO
2012-04-28 22:13:38 242240 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-04-28 22:13:25 -------- d-----w- c:\program files\DAEMON Tools Pro
2012-04-28 22:06:50 -------- d-----w- c:\documents and settings\owner\application data\DAEMON Tools Pro
2012-04-28 22:06:46 -------- d-----w- c:\documents and settings\all users\application data\DAEMON Tools Pro
2012-04-22 00:11:22 8827904 ----a-w- C:\QuickTime_Installer.smi(1).bin
2012-04-22 00:00:48 8101888 ----a-w- C:\QuickTime_Installer.smi.bin
2012-04-21 02:12:28 26 ---ha-w- c:\windows\esr.sys
2012-04-21 02:12:26 24576 ----a-w- c:\windows\EarSteady Uninstall.exe
2012-04-21 02:12:26 -------- d-----w- c:\program files\EarSteady
2012-04-20 16:41:18 -------- d-----w- C:\Stuffit Deluxe 3.5.1
2012-04-20 04:39:55 -------- d-----w- C:\ASDG Split & Join
2012-04-19 20:56:13 -------- d-----w- c:\program files\WinImage
2012-04-19 18:08:29 -------- d-----w- c:\program files\MacOpener
2012-04-19 18:01:04 -------- d-----w- c:\program files\Mediafour
2012-04-19 03:04:42 -------- d-----w- C:\.rsrc
2012-04-19 02:09:35 -------- d-----w- c:\documents and settings\owner\.finf
2012-04-19 02:09:35 -------- d-----w- C:\.finf
2012-04-19 01:30:07 6112 ----a-w- c:\windows\system32\drivers\cdenable.sys
2012-04-19 00:25:22 -------- d-----w- c:\program files\common files\GTK
2012-04-18 22:15:23 6112 ----a-w- c:\windows\system32\cdenable.sys
2012-04-18 22:15:22 -------- d-----w- c:\program files\Executor
2012-04-18 21:17:29 2073088 ----a-w- C:\DiskCopy.sit_.bin
2012-04-16 06:36:14 -------- d-----w- c:\program files\StarGate
2012-04-16 06:35:59 299520 ----a-w- c:\windows\uninst.exe
2012-04-16 04:33:40 771584 ----a-w- C:\Disk_Copy_6.3.3.smi.bin
2012-04-16 04:09:02 57344 ----a-w- c:\windows\system32\MACDRAPI.DLL
2012-04-16 04:09:02 -------- d-----w- c:\program files\Aladdin Systems
2012-04-16 04:08:29 77824 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\ctor.dll
2012-04-16 04:08:29 32768 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\objectps.dll
2012-04-16 04:08:29 217088 ----a-w- c:\program files\common files\installshield\iscript\IScript.dll
2012-04-16 04:08:29 217088 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\iuser.dll
2012-04-16 04:08:29 212992 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\ILog.dll
2012-04-15 05:42:32 -------- d-----w- c:\program files\TransMac
2012-04-15 05:42:32 -------- d-----w- c:\documents and settings\owner\local settings\application data\TransMac
2012-04-14 05:13:44 177152 ----a-w- c:\windows\system32\drivers\MacOpen.sys
2012-04-12 23:29:12 -------- d-----w- C:\Crash
2012-04-11 02:07:01 -------- d-----w- c:\program files\Klax
.
==================== Find3M ====================
.
2012-05-04 22:09:16 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-05-04 22:09:16 419488 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-04-02 04:03:11 53248 ----a-w- c:\documents and settings\owner\lametritonus_en.dll
2012-04-02 04:03:11 162304 ----a-w- c:\documents and settings\owner\lame_enc_en.dll
2012-03-08 08:08:15 23552 ----a-w- c:\windows\system32\wdmaud.drv
2012-03-08 08:05:42 48640 ----a-w- c:\windows\system32\drivers\stream.sys
2012-03-08 07:42:35 294912 ----a-w- c:\windows\system32\msh263.drv
2012-03-08 07:37:51 90624 ----a-w- c:\windows\system32\kswdmcap.ax
2012-03-08 07:35:22 43008 ----a-w- c:\windows\system32\ksxbar.ax
2012-03-08 07:31:49 140928 ----a-w- c:\windows\system32\drivers\ks.sys
2012-03-08 07:29:02 130048 ----a-w- c:\windows\system32\ksproxy.ax
2012-03-01 11:01:32 916992 ----a-w- c:\windows\system32\wininet.dll
2012-03-01 11:01:32 43520 ----a-w- c:\windows\system32\licmgr10.dll
2012-03-01 11:01:32 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-02-29 14:10:16 177664 ----a-w- c:\windows\system32\wintrust.dll
2012-02-29 14:10:16 148480 ----a-w- c:\windows\system32\imagehlp.dll
2012-02-29 12:17:40 385024 ----a-w- c:\windows\system32\html.iec
2012-02-20 01:39:11 73728 ----a-w- c:\windows\system32\javacpl.cpl
2012-02-20 01:39:10 472808 ----a-w- c:\windows\system32\deployJava1.dll
2006-05-03 16:06:54 163328 --sh--r- c:\windows\system32\flvDX.dll
2007-02-21 17:47:16 31232 --sh--r- c:\windows\system32\msfDX.dll
2008-03-16 19:30:52 216064 --sh--r- c:\windows\system32\nbDX.dll
.
============= FINISH: 21:25:28.32 ===============
Malwarebytes Anti-Malware 1.61.0.1400
www.malwarebytes.org
Database version: v2012.05.07.03
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Owner :: ANTIREAL-917A9F [administrator]
5/7/2012 2:07:05 PM
mbam-log-2012-05-07 (14-07-05).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 199371
Time elapsed: 5 minute(s), 55 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 1
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SETUP.EXE (Spyware.Password) -> Quarantined and deleted successfully.
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 1
C:\WINDOWS\Temp\mtwple\setup.exe (Spyware.Password) -> Quarantined and deleted successfully.
(end)
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-05-07 21:19:17
Windows 5.1.2600 Service Pack 3 Harddisk1\DR1 -> \Device\Ide\IdeDeviceP2T0L0-17 WDC_WD5000AAKS-22V1A0 rev.05.01D05
Running: e1xgmfot.exe; Driver: C:\DOCUME~1\Owner\LOCALS~1\Temp\kxkyqkob.sys
---- System - GMER 1.0.15 ----
SSDT spbj.sys ZwCreateKey [0xB7EB50E0]
SSDT spbj.sys ZwEnumerateKey [0xB7ECDDA4]
SSDT spbj.sys ZwEnumerateValueKey [0xB7ECE132]
SSDT spbj.sys ZwOpenKey [0xB7EB50C0]
SSDT spbj.sys ZwQueryKey [0xB7ECE20A]
SSDT spbj.sys ZwQueryValueKey [0xB7ECE08A]
SSDT spbj.sys ZwSetValueKey [0xB7ECE29C]
INT 0x62 ? 8A693BF8
INT 0x63 ? 8A693BF8
INT 0x63 ? 8A693BF8
INT 0x63 ? 8A469F00
INT 0x63 ? 8A693BF8
INT 0x82 ? 8A693BF8
INT 0x83 ? 8A469F00
INT 0xA4 ? 8A469F00
INT 0xB4 ? 8A469F00
---- Kernel code sections - GMER 1.0.15 ----
? fkubf.sys The system cannot find the file specified. !
? spbj.sys The system cannot find the file specified. !
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB6A993A0, 0x5FE082, 0xE8000020]
.text USBPORT.SYS!DllUnload B6A1A8AC 5 Bytes JMP 8A4694E0
.text mrxsmb.sys!?GenerateMonitorW@@IJXEGGPAH@X B1B95000 12 Bytes JMP B1B95C0D \SystemRoot\system32\DRIVERS\mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)
.text mrxsmb.sys!?GenerateMonitorW@@IJXEGGPAH@X B1B9500D 227 Bytes [25, 28, 0A, BB, B1, 8B, 0D, ...]
.text mrxsmb.sys!?GenerateMonitorW@@IJXEGGPAH@X B1B950F2 5 Bytes [90, 90, 90, 90, 90] {NOP ; NOP ; NOP ; NOP ; NOP }
.text mrxsmb.sys!?GenerateMonitorW@@IJXEGGPAH@X B1B950F8 67 Bytes [FF, 55, 8B, EC, 51, 83, 65, ...]
.text mrxsmb.sys!?GenerateMonitorW@@IJXEGGPAH@X B1B9513C 66 Bytes [EB, EA, 80, BF, CE, 00, 00, ...]
.text ...
? C:\WINDOWS\system32\DRIVERS\mrxsmb.sys suspicious PE modification
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [B7EB6042] spbj.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [B7EB613E] spbj.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [B7EB60C0] spbj.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [B7EB6800] spbj.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [B7EB66D6] spbj.sys
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 8A6231F8
Device \FileSystem\Fastfat \FatCdrom 898C2500
Device \FileSystem\MacOpen \MacOpenCd 8A6241F8
Device \FileSystem\MacOpen \MacOpen 8A6241F8
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
Device \Driver\usbuhci \Device\USBPDO-0 8A4681F8
Device \Driver\usbuhci \Device\USBPDO-1 8A4681F8
Device \Driver\usbuhci \Device\USBPDO-2 8A4681F8
Device \Driver\usbuhci \Device\USBPDO-3 8A4681F8
Device \Driver\usbehci \Device\USBPDO-4 8A43F1F8
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
Device \Driver\Ftdisk \Device\HarddiskVolume1 8A6251F8
Device \Driver\Ftdisk \Device\HarddiskVolume2 8A6251F8
Device \Driver\Cdrom \Device\CdRom0 8A43B1F8
Device \Driver\atapi \Device\Ide\IdePort0 [B7E2FB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort1 [B7E2FB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 [B7E2FB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort2 [B7E2FB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort3 [B7E2FB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c [B7E2FB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-17 [B7E2FB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\Ftdisk \Device\HarddiskVolume3 8A6251F8
Device \Driver\dtsoftbus01 \Device\DTSoftBusCtl 8A38C1F8
Device \Driver\NetBT \Device\NetBt_Wins_Export 89E63408
Device \Driver\NetBT \Device\NetbiosSmb 89E63408
Device \Driver\USBSTOR \Device\00000079 8990B1F8
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
Device \Driver\usbuhci \Device\USBFDO-0 8A4681F8
Device \Driver\usbuhci \Device\USBFDO-1 8A4681F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 89946500
Device \Driver\usbuhci \Device\USBFDO-2 8A4681F8
Device \Driver\USBSTOR \Device\0000007c 8990B1F8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 89946500
Device \Driver\usbuhci \Device\USBFDO-3 8A4681F8
Device \Driver\usbehci \Device\USBFDO-4 8A43F1F8
Device \Driver\Ftdisk \Device\FtControl 8A6251F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{FB538499-B92F-4DF6-B0B6-E3E1A8AAAA9A} 89E63408
Device \FileSystem\Fastfat \Fat 898C2500
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device \FileSystem\Cdfs \Cdfs 8A1EE500
---- Modules - GMER 1.0.15 ----
Module (noname) (*** hidden *** ) B1C04000-B1C19000 (86016 bytes)
---- Processes - GMER 1.0.15 ----
Process C:\WINDOWS\System32\ping.exe (*** hidden *** ) 3732
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKCU\Software\Microsoft\Windows\CurrentVersion@IQ\ahß\x8d\x8f\x2013 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{EB1D1CCD-4AE7-D0B5-C8C7-D7DA3F86DF23}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{EB1D1CCD-4AE7-D0B5-C8C7-D7DA3F86DF23}@najoclpngfpmhgbbbapibcghiemc 0x69 0x61 0x70 0x68 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@Í\x2039í\x2039T\x20acó` 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@Í\x2039í\x2039\x201c\x008feQ 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@\20\x90\20nÐc:y 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@\26Y\1xÐc:y 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@Òczz<h 0
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@IQ\ahß\x8d\x8f\x2013 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@Í\x2039í\x2039T\x20acó` 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@Í\x2039í\x2039\x201c\x008feQ 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@\20\x90\20nÐc:y 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@\26Y\1xÐc:y 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@Òczz<h 0
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@IQ\ahß\x8d\x8f\x2013 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@Í\x2039í\x2039T\x20acó` 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@Í\x2039í\x2039\x201c\x008feQ 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@\20\x90\20nÐc:y 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@\26Y\1xÐc:y 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@Òczz<h 0
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@IQ\ahß\x8d\x8f\x2013 1
---- Files - GMER 1.0.15 ----
File C:\WINDOWS\$NtUninstallKB13146$\1598319646 0 bytes
File C:\WINDOWS\$NtUninstallKB13146$\1598319646\@ 2048 bytes
File C:\WINDOWS\$NtUninstallKB13146$\1598319646\cfg.ini 298 bytes
File C:\WINDOWS\$NtUninstallKB13146$\1598319646\Desktop.ini 4608 bytes
File C:\WINDOWS\$NtUninstallKB13146$\1598319646\L 0 bytes
File C:\WINDOWS\$NtUninstallKB13146$\1598319646\L\vjjaxloi 456320 bytes
File C:\WINDOWS\$NtUninstallKB13146$\1598319646\oemid 233 bytes
File C:\WINDOWS\$NtUninstallKB13146$\1598319646\U 0 bytes
File C:\WINDOWS\$NtUninstallKB13146$\1598319646\U\00000001.@ 2048 bytes
File C:\WINDOWS\$NtUninstallKB13146$\1598319646\U\00000002.@ 224768 bytes
File C:\WINDOWS\$NtUninstallKB13146$\1598319646\U\00000004.@ 1024 bytes
File C:\WINDOWS\$NtUninstallKB13146$\1598319646\U\80000000.@ 66560 bytes
File C:\WINDOWS\$NtUninstallKB13146$\1598319646\U\80000004.@ 1024 bytes
File C:\WINDOWS\$NtUninstallKB13146$\1598319646\U\80000032.@ 115712 bytes
File C:\WINDOWS\$NtUninstallKB13146$\1598319646\version 1265 bytes
File C:\WINDOWS\$NtUninstallKB13146$\322140457 0 bytes
---- EOF - GMER 1.0.15 ----
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_31
Run by Owner at 21:24:43 on 2012-05-07
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.956 [GMT -4:00]
.
AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG2012\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\AVG\AVG2012\avgtray.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\PixArt\PAC7311\Monitor.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe
C:\Program Files\MacOpener\MacName.exe
C:\Program Files\AVG\AVG2012\avgnsx.exe
C:\Program Files\AVG\AVG2012\avgrsx.exe
C:\Program Files\AVG\AVG2012\avgcsrvx.exe
C:\Program Files\Mozilla Firefox4\firefox.exe
C:\Program Files\Mozilla Firefox4\plugin-container.exe
.
============== Pseudo HJT Report ===============
.
uInternet Settings,ProxyOverride = *.local
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg2012\avgssie.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
uRun: [Facebook Update] "c:\documents and settings\owner\local settings\application data\facebook\update\FacebookUpdate.exe" /c /nocrashserver
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [DAEMON Tools Pro Agent] "c:\program files\daemon tools pro\DTAgent.exe" -autorun
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [AVG_TRAY] "c:\program files\avg\avg2012\avgtray.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [nwiz] c:\program files\nvidia corporation\nview\nwiz.exe /installquiet
mRun: [PAC7311_Monitor] c:\windows\pixart\pac7311\Monitor.exe
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [CanonSolutionMenu] c:\program files\canon\solutionmenu\CNSLMAIN.exe /logon
mRun: [CanonMyPrinter] c:\program files\canon\myprinter\BJMyPrt.exe /logon
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [<NO NAME>]
mRun: [Adobe Acrobat Speed Launcher] "c:\program files\adobe\acrobat 10.0\acrobat\Acrobat_sl.exe"
mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 10.0\acrobat\Acrotray.exe"
mRun: [MacLicense] "c:\program files\macopener\MacLic.exe"
mRun: [PWRISOVM.EXE] c:\program files\poweriso\PWRISOVM.EXE
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\macname.lnk - c:\program files\macopener\MacName.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
LSP: mswsock.dll
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
TCP: DhcpNameServer = 192.168.1.1 192.168.1.1
TCP: Interfaces\{FB538499-B92F-4DF6-B0B6-E3E1A8AAAA9A} : DhcpNameServer = 192.168.1.1 192.168.1.1
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg2012\avgpp.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Notify: igfxcui - igfxdev.dll
Hosts: 216.172.189.172 www.nauscopy.net
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\owner\application data\mozilla\firefox\profiles\2c56x62f.default\
FF - component: c:\documents and settings\owner\application data\mozilla\firefox\profiles\2c56x62f.default\extensions\firesheep@codebutler.com\platform\winnt_x86-msvc\components\mozpopen.dll
FF - component: c:\program files\avg\avg10\firefox4\components\avgssff4.dll
FF - plugin: c:\documents and settings\owner\local settings\application data\facebook\video\skype\npFacebookVideoCalling.dll
FF - plugin: c:\program files\adobe\acrobat 10.0\acrobat\air\nppdf32.dll
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\canon\easy-photoprint ex\NPEZFFPI.DLL
FF - plugin: c:\program files\java\jre6\bin\plugin2\npdeployJava1.dll
FF - plugin: c:\program files\java\jre6\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\sony online entertainment\npsoe.dll
FF - plugin: c:\program files\sony online entertainment\npsoeact.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_2_202_235.dll
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2010-9-13 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2010-9-7 32592]
R0 MacOpen;MacOpen;c:\windows\system32\drivers\MacOpen.sys [2012-4-14 177152]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2010-9-7 230608]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2010-9-7 40016]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2010-9-7 295248]
R2 avgwd;AVG WatchDog;c:\program files\avg\avg2012\avgwdsvc.exe [2011-8-2 192776]
R2 cdenable;cdenable;c:\windows\system32\drivers\cdenable.sys [2012-4-18 6112]
R2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\program files\sony\pmb\PMBDeviceInfoProvider.exe [2010-11-27 398176]
R3 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [2012-4-28 242240]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32.sys [2010-11-16 100456]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 starwindservice;RIOXDRV;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-4 257696]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2010-11-16 1691480]
S3 arusb(SMC);SMCWUSB-N2 802.11n Wireless USB 2.0 Adapter Service(SMC);c:\windows\system32\drivers\arusb.sys --> c:\windows\system32\drivers\arusb.sys [?]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2011-8-18 2152152]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\lavasoft\ad-aware\kernexplorer.sys [2011-8-18 15232]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2012-5-4 129976]
S3 NPF;WinPcap Packet Driver (NPF);c:\windows\system32\drivers\npf.sys [2010-6-25 35088]
S3 rt2870;Linksys 802.11n USB Wireless LAN Card Driver;c:\windows\system32\drivers\rt2870.sys --> c:\windows\system32\drivers\rt2870.sys [?]
S3 ts_arusb;[CommView] Atheros Wireless Network Adapter Service;c:\windows\system32\drivers\ts_arusb.sys [2010-5-22 1054312]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2012-05-07 18:05:50 -------- d-----w- c:\documents and settings\owner\application data\Malwarebytes
2012-05-07 18:05:42 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2012-05-07 18:05:41 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-05-07 18:05:41 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-05-07 04:28:44 0 --sha-w- c:\windows\system32\dds_trash_log.cmd
2012-05-05 06:11:01 20976 ----a-w- c:\windows\system\CTL3D.DLL
2012-05-05 06:11:01 136448 ----a-w- c:\windows\RMTOOLS.DLL
2012-05-05 06:11:00 -------- d-----w- C:\MAXIS
2012-05-05 00:46:16 -------- d-----w- C:\dosgames
2012-05-05 00:42:09 -------- d-----w- c:\documents and settings\owner\local settings\application data\DOSBox
2012-05-05 00:41:37 -------- d-----w- c:\program files\DOSBox-0.74
2012-05-04 22:09:14 4140192 ----a-w- c:\windows\system32\FlashPlayerInstaller.exe
2012-05-04 19:54:54 -------- d-----w- c:\program files\Mozilla Maintenance Service
2012-04-28 23:58:37 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2012-04-28 23:58:18 -------- d-----w- c:\program files\LSoft Technologies
2012-04-28 23:03:39 -------- d-----w- c:\program files\PowerISO
2012-04-28 22:13:38 242240 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-04-28 22:13:25 -------- d-----w- c:\program files\DAEMON Tools Pro
2012-04-28 22:06:50 -------- d-----w- c:\documents and settings\owner\application data\DAEMON Tools Pro
2012-04-28 22:06:46 -------- d-----w- c:\documents and settings\all users\application data\DAEMON Tools Pro
2012-04-22 00:11:22 8827904 ----a-w- C:\QuickTime_Installer.smi(1).bin
2012-04-22 00:00:48 8101888 ----a-w- C:\QuickTime_Installer.smi.bin
2012-04-21 02:12:28 26 ---ha-w- c:\windows\esr.sys
2012-04-21 02:12:26 24576 ----a-w- c:\windows\EarSteady Uninstall.exe
2012-04-21 02:12:26 -------- d-----w- c:\program files\EarSteady
2012-04-20 16:41:18 -------- d-----w- C:\Stuffit Deluxe 3.5.1
2012-04-20 04:39:55 -------- d-----w- C:\ASDG Split & Join
2012-04-19 20:56:13 -------- d-----w- c:\program files\WinImage
2012-04-19 18:08:29 -------- d-----w- c:\program files\MacOpener
2012-04-19 18:01:04 -------- d-----w- c:\program files\Mediafour
2012-04-19 03:04:42 -------- d-----w- C:\.rsrc
2012-04-19 02:09:35 -------- d-----w- c:\documents and settings\owner\.finf
2012-04-19 02:09:35 -------- d-----w- C:\.finf
2012-04-19 01:30:07 6112 ----a-w- c:\windows\system32\drivers\cdenable.sys
2012-04-19 00:25:22 -------- d-----w- c:\program files\common files\GTK
2012-04-18 22:15:23 6112 ----a-w- c:\windows\system32\cdenable.sys
2012-04-18 22:15:22 -------- d-----w- c:\program files\Executor
2012-04-18 21:17:29 2073088 ----a-w- C:\DiskCopy.sit_.bin
2012-04-16 06:36:14 -------- d-----w- c:\program files\StarGate
2012-04-16 06:35:59 299520 ----a-w- c:\windows\uninst.exe
2012-04-16 04:33:40 771584 ----a-w- C:\Disk_Copy_6.3.3.smi.bin
2012-04-16 04:09:02 57344 ----a-w- c:\windows\system32\MACDRAPI.DLL
2012-04-16 04:09:02 -------- d-----w- c:\program files\Aladdin Systems
2012-04-16 04:08:29 77824 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\ctor.dll
2012-04-16 04:08:29 32768 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\objectps.dll
2012-04-16 04:08:29 217088 ----a-w- c:\program files\common files\installshield\iscript\IScript.dll
2012-04-16 04:08:29 217088 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\iuser.dll
2012-04-16 04:08:29 212992 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\ILog.dll
2012-04-15 05:42:32 -------- d-----w- c:\program files\TransMac
2012-04-15 05:42:32 -------- d-----w- c:\documents and settings\owner\local settings\application data\TransMac
2012-04-14 05:13:44 177152 ----a-w- c:\windows\system32\drivers\MacOpen.sys
2012-04-12 23:29:12 -------- d-----w- C:\Crash
2012-04-11 02:07:01 -------- d-----w- c:\program files\Klax
.
==================== Find3M ====================
.
2012-05-04 22:09:16 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-05-04 22:09:16 419488 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-04-02 04:03:11 53248 ----a-w- c:\documents and settings\owner\lametritonus_en.dll
2012-04-02 04:03:11 162304 ----a-w- c:\documents and settings\owner\lame_enc_en.dll
2012-03-08 08:08:15 23552 ----a-w- c:\windows\system32\wdmaud.drv
2012-03-08 08:05:42 48640 ----a-w- c:\windows\system32\drivers\stream.sys
2012-03-08 07:42:35 294912 ----a-w- c:\windows\system32\msh263.drv
2012-03-08 07:37:51 90624 ----a-w- c:\windows\system32\kswdmcap.ax
2012-03-08 07:35:22 43008 ----a-w- c:\windows\system32\ksxbar.ax
2012-03-08 07:31:49 140928 ----a-w- c:\windows\system32\drivers\ks.sys
2012-03-08 07:29:02 130048 ----a-w- c:\windows\system32\ksproxy.ax
2012-03-01 11:01:32 916992 ----a-w- c:\windows\system32\wininet.dll
2012-03-01 11:01:32 43520 ----a-w- c:\windows\system32\licmgr10.dll
2012-03-01 11:01:32 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-02-29 14:10:16 177664 ----a-w- c:\windows\system32\wintrust.dll
2012-02-29 14:10:16 148480 ----a-w- c:\windows\system32\imagehlp.dll
2012-02-29 12:17:40 385024 ----a-w- c:\windows\system32\html.iec
2012-02-20 01:39:11 73728 ----a-w- c:\windows\system32\javacpl.cpl
2012-02-20 01:39:10 472808 ----a-w- c:\windows\system32\deployJava1.dll
2006-05-03 16:06:54 163328 --sh--r- c:\windows\system32\flvDX.dll
2007-02-21 17:47:16 31232 --sh--r- c:\windows\system32\msfDX.dll
2008-03-16 19:30:52 216064 --sh--r- c:\windows\system32\nbDX.dll
.
============= FINISH: 21:25:28.32 ===============