Originally I had an AV Gaurd scanner pop up so I just blew it off as a Netsky.G Worm or rogue anti virus. Well once I took care of that it was much worse, random ads started popping up, with the internet connected "voices" start talking about news and tv without IE even open, my Vipre antivirus stopped working (couldn't update definitions), advanced system care 4 from iobit had over 9thousand ad, porn, etc sites it wanted to protect with Passive Defense, Protected Mode on IE wont turn on, and the first day of this it screwed my malwarebytes. Sysclean didn't even take care of it. Now that I've finally been able to do some scans and follow the six step I'm hoping someone will be able to help me get rid of this. Wasn't sure if the first flash can I did today that caught viruses would make a difference, but its the first mbam scan posted.
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org
Database version: 7954
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.19154
10/15/2011 1:28:11 PM
mbam-log-2011-10-15 (13-28-11).txt
Scan type: Flash scan
Objects scanned: 131804
Time elapsed: 1 minute(s), 29 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 2
Registry Keys Infected: 5
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 10
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
c:\Users\Mark\AppData\Local\Apps\appsupdate\appsupdt32.dll (Trojan.SHarpro) -> Delete on reboot.
c:\Users\Mark\AppData\Local\Adobe\adobeupdate\adobeupdt32.dll (Trojan.SHarpro) -> Delete on reboot.
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{01DB8D44-42B3-4F79-AFC4-1FB190CCC8E2} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{01DB8D44-42B3-4F79-AFC4-1FB190CCC8E2} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{01DB8D44-42B3-4F79-AFC4-1FB190CCC8E2} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{01DB8D44-42B3-4F79-AFC4-1FB190CCC8E2} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\.fsharproj (Trojan.BHO) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\The Update (Trojan.SHarpro) -> Value: The Update -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\AppDataLow Update (Trojan.SHarpro) -> Value: AppDataLow Update -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\Users\Mark\AppData\Local\networksys32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
c:\Users\Mark\local settings\application data\Apps\appsupdate\appsupdt32.dll (Trojan.SHarpro) -> Delete on reboot.
c:\Users\Mark\AppData\Local\Apps\appsupdate\appsupdt32.dll (Trojan.SHarpro) -> Delete on reboot.
c:\Users\Mark\AppData\Roaming\Adobe\shed\thr1.chm (Malware.Trace) -> Quarantined and deleted successfully.
c:\Users\Mark\AppData\Roaming\Adobe\plugs\mmc20365010.txt (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
c:\Users\Mark\AppData\Roaming\Adobe\plugs\mmc236.exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
c:\Users\Mark\AppData\Roaming\Adobe\plugs\mmc79.exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
c:\Users\Mark\local settings\application data\Adobe\adobeupdate\adobeupdt32.dll (Trojan.SHarpro) -> Delete on reboot.
c:\Users\Mark\AppData\Local\Adobe\adobeupdate\adobeupdt32.dll (Trojan.SHarpro) -> Delete on reboot.
c:\Users\Mark\local settings\application data\networksys32.dll (Trojan.SHarpro.Gen) -> Quarantined and deleted successfully.
Restarted and:
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org
Database version: 7954
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.19154
10/15/2011 1:31:13 PM
mbam-log-2011-10-15 (13-31-13).txt
Scan type: Quick scan
Objects scanned: 40264
Time elapsed: 2 minute(s), 44 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-10-15 16:53:40
Windows 6.0.6002 Service Pack 2
Running: gmer.exe; Driver: f:\Temp\pxldypoc.sys
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001c26dd0b28
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001c26dd0b28@2021a5f786ae 0x96 0x95 0xE4 0x2C ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001c26dd0b28@001fe46d49d5 0x46 0x53 0x12 0x40 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001c26dd0b28@00249576113c 0xDB 0x28 0x86 0x30 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001c26dd0b28@0015d3828585 0x37 0x59 0x74 0x83 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001c26dd0b28@2021a5ceeec3 0x8A 0x4B 0x94 0x5D ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001c26dd0b28@3816d12a9793 0x2B 0xA9 0x64 0xC1 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xB4 0x6D 0x90 0x02 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Pro\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x6A 0xF3 0xE0 0x60 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x35 0x48 0xB9 0x16 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x13 0xED 0xDE 0x34 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002@hdf12 0x87 0xEB 0xB8 0xF2 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq0@hdf12 0xEF 0x8B 0xF1 0x24 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xDE 0xA7 0xC6 0xAC ...
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\001c26dd0b28 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\001c26dd0b28@2021a5f786ae 0x96 0x95 0xE4 0x2C ...
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\001c26dd0b28@001fe46d49d5 0x46 0x53 0x12 0x40 ...
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\001c26dd0b28@00249576113c 0xDB 0x28 0x86 0x30 ...
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\001c26dd0b28@0015d3828585 0x37 0x59 0x74 0x83 ...
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\001c26dd0b28@2021a5ceeec3 0x8A 0x4B 0x94 0x5D ...
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\001c26dd0b28@3816d12a9793 0x2B 0xA9 0x64 0xC1 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xB4 0x6D 0x90 0x02 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Pro\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x6A 0xF3 0xE0 0x60 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x35 0x48 0xB9 0x16 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x13 0xED 0xDE 0x34 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002@hdf12 0x87 0xEB 0xB8 0xF2 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq0@hdf12 0xEF 0x8B 0xF1 0x24 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xDE 0xA7 0xC6 0xAC ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Disabled (Startup Manager)@igndlm.exe C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
---- Files - GMER 1.0.15 ----
File C:\Windows\$NtUninstallKB14408$\1307381887 0 bytes
File C:\Windows\$NtUninstallKB14408$\3632275255 0 bytes
---- EOF - GMER 1.0.15 ----
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.19154 BrowserJavaVersion: 1.6.0_20
Run by Mark at 17:10:12 on 2011-10-15
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3069.1484 [GMT -5:00]
.
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\IObit\Advanced SystemCare 4\PMonitor.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe
C:\Windows\System32\svchost.exe -k Akamai
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Windows\System32\svchost.exe -k ipripsvc
C:\Windows\system32\lxdpcoms.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Windows\system32\STacSV.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Lexmark Z2300 Series\lxdpmon.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\DAEMON Tools Pro\DTProAgent.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Lexmark Z2300 Series\lxdpMsdMon.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\rundll32.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\DAEMON Tools Pro\DTProShellHlp.exe
C:\Windows\REGEDIT.EXE
C:\Windows\REGEDIT.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\REGSVR32.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
uSearch Bar = Preserve
uWindow Title = Internet Explorer provided by Dell
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - MSN Toolbar BHO
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: MSN Toolbar: {8dcb7100-df86-4384-8842-8fa844297b3f} -
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [DAEMON Tools Pro Agent] "c:\program files\daemon tools pro\DTProAgent.exe" -autorun
uRun: [SmartRAM] "c:\program files\iobit\advanced systemcare 3\Sup_SmartRAM.exe" /m
uRun: [WindowsTrayProfile] rundll32.exe "c:\programdata\WindowsTrayProfile.dll",DllRegisterServer
uRun: [Advanced SystemCare 4] c:\program files\iobit\advanced systemcare 4\ASCTray.exe
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil10x_ActiveX.exe -update activex
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [SigmatelSysTrayApp] c:\program files\sigmatel\c-major audio\wdm\sttray.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume
mRun: [lxdpmon.exe] "c:\program files\lexmark z2300 series\lxdpmon.exe"
mRun: [lxdpamon] "c:\program files\lexmark z2300 series\lxdpamon.exe"
mRun: [IAAnotif] "c:\program files\intel\intel matrix storage manager\Iaanotif.exe"
mRun: [Bluetooth HCI Monitor] RunDll32 HCIMNTR.DLL,RunCheckHCIMode
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\netgea~1.lnk - c:\program files\netgear\wg111v3\WG111v3.exe
uPolicies-explorer: NoThumbnailCache = 1 (0x1)
uPolicies-explorer: DisableThumbnailsOnNetworkFolders = 1 (0x1)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-explorer: NoStrCmpLogical = 1 (0x1)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: DisableStartupSound = 1 (0x1)
mPolicies-system: DisableStatusMessages = 1 (0x1)
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {d9288080-1baa-4bc4-9cf8-a92d743db949}
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
TCP: DhcpNameServer = 192.168.2.1 192.168.2.1
TCP: Interfaces\{5D1C303C-8FFD-454E-A0F2-8C69B6786967} : DhcpNameServer = 67.14.214.5 67.14.214.9
TCP: Interfaces\{AEA707A9-CAA3-4D3F-AD6E-E11C8044C27A} : NameServer = 67.14.214.5,67.14.214.9
TCP: Interfaces\{BA605217-5848-4EA3-8D1D-92C75C299DA1} : DhcpNameServer = 67.14.214.5 67.14.214.9
TCP: Interfaces\{C91AF9B2-C392-4437-8829-54B3C897ABE8} : DhcpNameServer = 67.14.214.5 67.14.214.9
TCP: Interfaces\{CCCD8129-FC46-44AA-AD96-BCD9F26ECB6E} : DhcpNameServer = 67.14.214.5 67.14.214.9
TCP: Interfaces\{D2BC8AE5-6E4D-4758-8C27-F8A603A8C33D} : DhcpNameServer = 67.14.214.5 67.14.214.9
TCP: Interfaces\{DB943B22-1045-4C31-BB95-2EEB3528E00E} : DhcpNameServer = 67.14.214.5 67.14.214.9
TCP: Interfaces\{F6F7EA89-08F2-49A0-837D-F2E163D2F55E} : DhcpNameServer = 192.168.2.1 192.168.2.1
TCP: Interfaces\{FB918CEB-6012-430F-A293-72D37280105B} : DhcpNameServer = 67.14.214.5 67.14.214.9
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
.
============= SERVICES / DRIVERS ===============
.
R1 RtlProt;Realtke RtlProt WLAN Utility Protocol Driver;c:\windows\system32\drivers\RtlProt.sys [2007-4-23 25896]
R1 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [2011-8-29 101720]
R1 SbTis;SbTis;c:\windows\system32\drivers\sbtis.sys [2010-12-8 78936]
R2 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\iobit\advanced systemcare 4\ASCService.exe [2011-10-12 328536]
R2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2008-1-20 21504]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-4-28 176128]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
R2 iprip;RIP Listener;c:\windows\system32\svchost.exe -k ipripsvc [2008-1-20 21504]
R2 lxdp_device;lxdp_device;c:\windows\system32\lxdpcoms.exe -service --> c:\windows\system32\lxdpcoms.exe -service [?]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-10-15 366152]
R2 sbapifs;sbapifs;c:\windows\system32\drivers\sbapifs.sys [2011-8-29 74456]
R3 amdkmdag;amdkmdag;c:\windows\system32\drivers\atikmdag.sys [2011-7-28 8396800]
R3 amdkmdap;amdkmdap;c:\windows\system32\drivers\atikmpag.sys [2011-7-28 247296]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-10-15 22216]
R3 pxldypoc;pxldypoc;f:\temp\pxldypoc.sys [2011-10-15 100864]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2010-10-20 39272]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-9-23 1493352]
S3 MRV6X32U;Marvell TOPDOG 802.11n WLAN Driver for Vista x86 (USB8x);c:\windows\system32\drivers\MRVW24B.sys [2008-3-19 310016]
S3 RTL8187B;NETGEAR WG111v3 Wireless-G USB Adapter Vista Driver;c:\windows\system32\drivers\wg111v3.sys [2011-5-3 348160]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 gameupdater;Game Updater; [x]
S4 gupdate;Google Update Service (gupdate);c:\program files\google\update\googleupdate.exe /svc --> c:\program files\google\update\GoogleUpdate.exe [?]
S4 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\googleupdate.exe /medsvc --> c:\program files\google\update\GoogleUpdate.exe [?]
.
=============== File Associations ===============
.
.txt=GetDiz.TextFile
.
=============== Created Last 30 ================
.
2011-10-15 18:25:26 -------- d-----w- c:\users\mark\appdata\roaming\Malwarebytes
2011-10-15 18:25:18 -------- d-----w- c:\programdata\Malwarebytes
2011-10-15 18:25:13 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-10-15 18:25:13 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-10-15 17:46:49 -------- d-----w- c:\users\mark\appdata\local\{F97BD6E5-174B-4BED-BAFD-A906A5ABAABD}
2011-10-15 16:38:06 7269712 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{39eb116c-22a0-4c9b-9a83-8840ac494f42}\mpengine.dll
2011-10-14 21:40:51 -------- d-----w- c:\users\mark\appdata\roaming\Sunbelt
2011-10-13 17:06:02 -------- d-----w- C:\TEMP
2011-10-13 02:58:25 -------- d-----w- C:\edd269d7d5d6738fe07e5365cd98
2011-10-13 01:47:17 65808 ----a-w- c:\windows\system32\drivers\tmrkb.sys
2011-10-13 01:47:17 205072 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2011-10-12 21:10:47 563712 ----a-w- c:\windows\system32\oleaut32.dll
2011-10-12 21:10:47 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2011-10-12 21:10:47 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2011-10-12 21:10:47 238080 ----a-w- c:\windows\system32\oleacc.dll
2011-10-12 21:09:22 2043392 ----a-w- c:\windows\system32\win32k.sys
2011-10-12 21:08:43 69632 ----a-w- c:\windows\system32\Mpeg2Data.ax
2011-10-12 21:08:43 57856 ----a-w- c:\windows\system32\MSDvbNP.ax
2011-10-12 21:08:43 293376 ----a-w- c:\windows\system32\psisdecd.dll
2011-10-12 21:08:43 217088 ----a-w- c:\windows\system32\psisrndr.ax
2011-10-12 15:47:43 88 ----a-w- c:\users\mark\appdata\roaming\netstat.bat
2011-10-12 15:16:29 -------- d-----w- c:\windows\pss
2011-10-06 15:40:28 -------- d-----w- c:\users\mark\sysclean
2011-10-04 00:36:16 81920 ----a-w- c:\programdata\WindowsTrayProfile.dll
2011-10-03 14:32:37 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-10-03 14:32:36 758784 ----a-w- c:\program files\common files\microsoft shared\vgx\VGX.dll
2011-09-28 12:18:07 -------- d-----w- c:\users\mark\appdata\roaming\Lexmark Productivity Studio
2011-09-27 17:09:42 147968 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\lxdpdrpp.dll
2011-09-27 16:43:24 -------- d-----w- c:\programdata\PC Drivers HeadQuarters
2011-09-27 16:21:44 -------- d-----w- c:\programdata\Ezprint
2011-09-27 16:21:22 -------- d-----w- c:\program files\Lexmark Toolbar
2011-09-27 16:19:41 -------- d-----w- C:\drivers
2011-09-25 19:41:13 -------- d-----w- C:\AeriaGames
2011-09-25 17:03:17 -------- d-----w- c:\program files\common files\Akamai
.
==================== Find3M ====================
.
2011-10-12 21:11:17 916480 ----a-w- c:\windows\system32\wininet.dll
2011-10-12 21:11:17 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-10-12 21:11:15 385024 ----a-w- c:\windows\system32\html.iec
2011-10-12 21:11:15 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2011-10-12 21:11:15 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2011-10-12 21:11:15 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2011-10-12 21:11:14 71680 ----a-w- c:\windows\system32\iesetup.dll
2011-10-12 21:11:14 109056 ----a-w- c:\windows\system32\iesysprep.dll
2011-10-04 01:11:22 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-09-06 17:30:42 42832 ----a-w- c:\windows\system32\sbbd.exe
2011-08-29 22:36:34 74456 ----a-w- c:\windows\system32\drivers\sbapifs.sys
2011-08-29 22:36:34 101720 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-07-29 03:22:06 8396800 ----a-w- c:\windows\system32\drivers\atikmdag.sys
2011-07-29 02:44:08 18388480 ----a-w- c:\windows\system32\atioglxx.dll
2011-07-29 02:41:00 151552 ----a-w- c:\windows\system32\atiapfxx.exe
2011-07-29 02:40:46 726528 ----a-w- c:\windows\system32\aticfx32.dll
2011-07-29 02:36:28 462848 ----a-w- c:\windows\system32\ATIDEMGX.dll
2011-07-29 02:35:54 401408 ----a-w- c:\windows\system32\atieclxx.exe
2011-07-29 02:35:26 176128 ----a-w- c:\windows\system32\atiesrxx.exe
2011-07-29 02:34:12 159744 ----a-w- c:\windows\system32\atitmmxx.dll
2011-07-29 02:33:56 356352 ----a-w- c:\windows\system32\atipdlxx.dll
2011-07-29 02:33:44 278528 ----a-w- c:\windows\system32\Oemdspif.dll
2011-07-29 02:33:36 20992 ----a-w- c:\windows\system32\atimuixx.dll
2011-07-29 02:33:28 43520 ----a-w- c:\windows\system32\ati2edxx.dll
2011-07-29 02:30:28 4198912 ----a-w- c:\windows\system32\atidxx32.dll
2011-07-29 02:11:44 1828864 ----a-w- c:\windows\system32\atiumdmv.dll
2011-07-29 02:11:16 46080 ----a-w- c:\windows\system32\aticalrt.dll
2011-07-29 02:11:04 44032 ----a-w- c:\windows\system32\aticalcl.dll
2011-07-29 02:09:12 4256768 ----a-w- c:\windows\system32\atiumdag.dll
2011-07-29 02:07:26 8247296 ----a-w- c:\windows\system32\aticaldd.dll
2011-07-29 02:04:00 4056064 ----a-w- c:\windows\system32\atiumdva.dll
2011-07-29 02:01:50 52736 ----a-w- c:\windows\system32\coinst.dll
2011-07-29 01:54:44 266240 ----a-w- c:\windows\system32\SETDB59.tmp
2011-07-29 01:54:44 266240 ----a-w- c:\windows\system32\SETA520.tmp
2011-07-29 01:54:44 266240 ----a-w- c:\windows\system32\SET277A.tmp
2011-07-29 01:54:44 266240 ----a-w- c:\windows\system32\atiadlxx.dll
2011-07-29 01:54:32 13312 ----a-w- c:\windows\system32\atiglpxx.dll
2011-07-29 01:54:20 32768 ----a-w- c:\windows\system32\atigktxx.dll
2011-07-29 01:53:48 247296 ----a-w- c:\windows\system32\drivers\atikmpag.sys
2011-07-29 01:53:16 31744 ----a-w- c:\windows\system32\atiuxpag.dll
2011-07-29 01:53:02 29184 ----a-w- c:\windows\system32\atiu9pag.dll
2011-07-29 01:52:40 37376 ----a-w- c:\windows\system32\atitmpxx.dll
2011-07-29 01:52:28 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2011-07-29 01:51:06 52736 ----a-w- c:\windows\system32\atimpc32.dll
2011-07-29 01:51:06 52736 ----a-w- c:\windows\system32\amdpcom32.dll
2011-07-22 20:51:50 94208 ----a-w- c:\windows\system32\dpl100.dll
.
============= FINISH: 17:16:06.62 ===============
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org
Database version: 7954
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.19154
10/15/2011 1:28:11 PM
mbam-log-2011-10-15 (13-28-11).txt
Scan type: Flash scan
Objects scanned: 131804
Time elapsed: 1 minute(s), 29 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 2
Registry Keys Infected: 5
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 10
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
c:\Users\Mark\AppData\Local\Apps\appsupdate\appsupdt32.dll (Trojan.SHarpro) -> Delete on reboot.
c:\Users\Mark\AppData\Local\Adobe\adobeupdate\adobeupdt32.dll (Trojan.SHarpro) -> Delete on reboot.
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{01DB8D44-42B3-4F79-AFC4-1FB190CCC8E2} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{01DB8D44-42B3-4F79-AFC4-1FB190CCC8E2} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{01DB8D44-42B3-4F79-AFC4-1FB190CCC8E2} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{01DB8D44-42B3-4F79-AFC4-1FB190CCC8E2} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\.fsharproj (Trojan.BHO) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\The Update (Trojan.SHarpro) -> Value: The Update -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\AppDataLow Update (Trojan.SHarpro) -> Value: AppDataLow Update -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\Users\Mark\AppData\Local\networksys32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
c:\Users\Mark\local settings\application data\Apps\appsupdate\appsupdt32.dll (Trojan.SHarpro) -> Delete on reboot.
c:\Users\Mark\AppData\Local\Apps\appsupdate\appsupdt32.dll (Trojan.SHarpro) -> Delete on reboot.
c:\Users\Mark\AppData\Roaming\Adobe\shed\thr1.chm (Malware.Trace) -> Quarantined and deleted successfully.
c:\Users\Mark\AppData\Roaming\Adobe\plugs\mmc20365010.txt (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
c:\Users\Mark\AppData\Roaming\Adobe\plugs\mmc236.exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
c:\Users\Mark\AppData\Roaming\Adobe\plugs\mmc79.exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
c:\Users\Mark\local settings\application data\Adobe\adobeupdate\adobeupdt32.dll (Trojan.SHarpro) -> Delete on reboot.
c:\Users\Mark\AppData\Local\Adobe\adobeupdate\adobeupdt32.dll (Trojan.SHarpro) -> Delete on reboot.
c:\Users\Mark\local settings\application data\networksys32.dll (Trojan.SHarpro.Gen) -> Quarantined and deleted successfully.
Restarted and:
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org
Database version: 7954
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.19154
10/15/2011 1:31:13 PM
mbam-log-2011-10-15 (13-31-13).txt
Scan type: Quick scan
Objects scanned: 40264
Time elapsed: 2 minute(s), 44 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-10-15 16:53:40
Windows 6.0.6002 Service Pack 2
Running: gmer.exe; Driver: f:\Temp\pxldypoc.sys
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001c26dd0b28
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001c26dd0b28@2021a5f786ae 0x96 0x95 0xE4 0x2C ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001c26dd0b28@001fe46d49d5 0x46 0x53 0x12 0x40 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001c26dd0b28@00249576113c 0xDB 0x28 0x86 0x30 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001c26dd0b28@0015d3828585 0x37 0x59 0x74 0x83 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001c26dd0b28@2021a5ceeec3 0x8A 0x4B 0x94 0x5D ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001c26dd0b28@3816d12a9793 0x2B 0xA9 0x64 0xC1 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xB4 0x6D 0x90 0x02 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Pro\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x6A 0xF3 0xE0 0x60 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x35 0x48 0xB9 0x16 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x13 0xED 0xDE 0x34 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002@hdf12 0x87 0xEB 0xB8 0xF2 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq0@hdf12 0xEF 0x8B 0xF1 0x24 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xDE 0xA7 0xC6 0xAC ...
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\001c26dd0b28 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\001c26dd0b28@2021a5f786ae 0x96 0x95 0xE4 0x2C ...
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\001c26dd0b28@001fe46d49d5 0x46 0x53 0x12 0x40 ...
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\001c26dd0b28@00249576113c 0xDB 0x28 0x86 0x30 ...
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\001c26dd0b28@0015d3828585 0x37 0x59 0x74 0x83 ...
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\001c26dd0b28@2021a5ceeec3 0x8A 0x4B 0x94 0x5D ...
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\001c26dd0b28@3816d12a9793 0x2B 0xA9 0x64 0xC1 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xB4 0x6D 0x90 0x02 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Pro\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x6A 0xF3 0xE0 0x60 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x35 0x48 0xB9 0x16 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x13 0xED 0xDE 0x34 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002@hdf12 0x87 0xEB 0xB8 0xF2 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq0@hdf12 0xEF 0x8B 0xF1 0x24 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xDE 0xA7 0xC6 0xAC ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Disabled (Startup Manager)@igndlm.exe C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
---- Files - GMER 1.0.15 ----
File C:\Windows\$NtUninstallKB14408$\1307381887 0 bytes
File C:\Windows\$NtUninstallKB14408$\3632275255 0 bytes
---- EOF - GMER 1.0.15 ----
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.19154 BrowserJavaVersion: 1.6.0_20
Run by Mark at 17:10:12 on 2011-10-15
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3069.1484 [GMT -5:00]
.
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\IObit\Advanced SystemCare 4\PMonitor.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe
C:\Windows\System32\svchost.exe -k Akamai
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Windows\System32\svchost.exe -k ipripsvc
C:\Windows\system32\lxdpcoms.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Windows\system32\STacSV.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Lexmark Z2300 Series\lxdpmon.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\DAEMON Tools Pro\DTProAgent.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Lexmark Z2300 Series\lxdpMsdMon.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\rundll32.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\DAEMON Tools Pro\DTProShellHlp.exe
C:\Windows\REGEDIT.EXE
C:\Windows\REGEDIT.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\REGSVR32.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
uSearch Bar = Preserve
uWindow Title = Internet Explorer provided by Dell
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - MSN Toolbar BHO
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: MSN Toolbar: {8dcb7100-df86-4384-8842-8fa844297b3f} -
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [DAEMON Tools Pro Agent] "c:\program files\daemon tools pro\DTProAgent.exe" -autorun
uRun: [SmartRAM] "c:\program files\iobit\advanced systemcare 3\Sup_SmartRAM.exe" /m
uRun: [WindowsTrayProfile] rundll32.exe "c:\programdata\WindowsTrayProfile.dll",DllRegisterServer
uRun: [Advanced SystemCare 4] c:\program files\iobit\advanced systemcare 4\ASCTray.exe
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil10x_ActiveX.exe -update activex
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [SigmatelSysTrayApp] c:\program files\sigmatel\c-major audio\wdm\sttray.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume
mRun: [lxdpmon.exe] "c:\program files\lexmark z2300 series\lxdpmon.exe"
mRun: [lxdpamon] "c:\program files\lexmark z2300 series\lxdpamon.exe"
mRun: [IAAnotif] "c:\program files\intel\intel matrix storage manager\Iaanotif.exe"
mRun: [Bluetooth HCI Monitor] RunDll32 HCIMNTR.DLL,RunCheckHCIMode
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\netgea~1.lnk - c:\program files\netgear\wg111v3\WG111v3.exe
uPolicies-explorer: NoThumbnailCache = 1 (0x1)
uPolicies-explorer: DisableThumbnailsOnNetworkFolders = 1 (0x1)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-explorer: NoStrCmpLogical = 1 (0x1)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: DisableStartupSound = 1 (0x1)
mPolicies-system: DisableStatusMessages = 1 (0x1)
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {d9288080-1baa-4bc4-9cf8-a92d743db949}
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
TCP: DhcpNameServer = 192.168.2.1 192.168.2.1
TCP: Interfaces\{5D1C303C-8FFD-454E-A0F2-8C69B6786967} : DhcpNameServer = 67.14.214.5 67.14.214.9
TCP: Interfaces\{AEA707A9-CAA3-4D3F-AD6E-E11C8044C27A} : NameServer = 67.14.214.5,67.14.214.9
TCP: Interfaces\{BA605217-5848-4EA3-8D1D-92C75C299DA1} : DhcpNameServer = 67.14.214.5 67.14.214.9
TCP: Interfaces\{C91AF9B2-C392-4437-8829-54B3C897ABE8} : DhcpNameServer = 67.14.214.5 67.14.214.9
TCP: Interfaces\{CCCD8129-FC46-44AA-AD96-BCD9F26ECB6E} : DhcpNameServer = 67.14.214.5 67.14.214.9
TCP: Interfaces\{D2BC8AE5-6E4D-4758-8C27-F8A603A8C33D} : DhcpNameServer = 67.14.214.5 67.14.214.9
TCP: Interfaces\{DB943B22-1045-4C31-BB95-2EEB3528E00E} : DhcpNameServer = 67.14.214.5 67.14.214.9
TCP: Interfaces\{F6F7EA89-08F2-49A0-837D-F2E163D2F55E} : DhcpNameServer = 192.168.2.1 192.168.2.1
TCP: Interfaces\{FB918CEB-6012-430F-A293-72D37280105B} : DhcpNameServer = 67.14.214.5 67.14.214.9
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
.
============= SERVICES / DRIVERS ===============
.
R1 RtlProt;Realtke RtlProt WLAN Utility Protocol Driver;c:\windows\system32\drivers\RtlProt.sys [2007-4-23 25896]
R1 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [2011-8-29 101720]
R1 SbTis;SbTis;c:\windows\system32\drivers\sbtis.sys [2010-12-8 78936]
R2 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\iobit\advanced systemcare 4\ASCService.exe [2011-10-12 328536]
R2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2008-1-20 21504]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-4-28 176128]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
R2 iprip;RIP Listener;c:\windows\system32\svchost.exe -k ipripsvc [2008-1-20 21504]
R2 lxdp_device;lxdp_device;c:\windows\system32\lxdpcoms.exe -service --> c:\windows\system32\lxdpcoms.exe -service [?]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-10-15 366152]
R2 sbapifs;sbapifs;c:\windows\system32\drivers\sbapifs.sys [2011-8-29 74456]
R3 amdkmdag;amdkmdag;c:\windows\system32\drivers\atikmdag.sys [2011-7-28 8396800]
R3 amdkmdap;amdkmdap;c:\windows\system32\drivers\atikmpag.sys [2011-7-28 247296]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-10-15 22216]
R3 pxldypoc;pxldypoc;f:\temp\pxldypoc.sys [2011-10-15 100864]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2010-10-20 39272]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-9-23 1493352]
S3 MRV6X32U;Marvell TOPDOG 802.11n WLAN Driver for Vista x86 (USB8x);c:\windows\system32\drivers\MRVW24B.sys [2008-3-19 310016]
S3 RTL8187B;NETGEAR WG111v3 Wireless-G USB Adapter Vista Driver;c:\windows\system32\drivers\wg111v3.sys [2011-5-3 348160]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 gameupdater;Game Updater; [x]
S4 gupdate;Google Update Service (gupdate);c:\program files\google\update\googleupdate.exe /svc --> c:\program files\google\update\GoogleUpdate.exe [?]
S4 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\googleupdate.exe /medsvc --> c:\program files\google\update\GoogleUpdate.exe [?]
.
=============== File Associations ===============
.
.txt=GetDiz.TextFile
.
=============== Created Last 30 ================
.
2011-10-15 18:25:26 -------- d-----w- c:\users\mark\appdata\roaming\Malwarebytes
2011-10-15 18:25:18 -------- d-----w- c:\programdata\Malwarebytes
2011-10-15 18:25:13 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-10-15 18:25:13 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-10-15 17:46:49 -------- d-----w- c:\users\mark\appdata\local\{F97BD6E5-174B-4BED-BAFD-A906A5ABAABD}
2011-10-15 16:38:06 7269712 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{39eb116c-22a0-4c9b-9a83-8840ac494f42}\mpengine.dll
2011-10-14 21:40:51 -------- d-----w- c:\users\mark\appdata\roaming\Sunbelt
2011-10-13 17:06:02 -------- d-----w- C:\TEMP
2011-10-13 02:58:25 -------- d-----w- C:\edd269d7d5d6738fe07e5365cd98
2011-10-13 01:47:17 65808 ----a-w- c:\windows\system32\drivers\tmrkb.sys
2011-10-13 01:47:17 205072 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2011-10-12 21:10:47 563712 ----a-w- c:\windows\system32\oleaut32.dll
2011-10-12 21:10:47 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2011-10-12 21:10:47 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2011-10-12 21:10:47 238080 ----a-w- c:\windows\system32\oleacc.dll
2011-10-12 21:09:22 2043392 ----a-w- c:\windows\system32\win32k.sys
2011-10-12 21:08:43 69632 ----a-w- c:\windows\system32\Mpeg2Data.ax
2011-10-12 21:08:43 57856 ----a-w- c:\windows\system32\MSDvbNP.ax
2011-10-12 21:08:43 293376 ----a-w- c:\windows\system32\psisdecd.dll
2011-10-12 21:08:43 217088 ----a-w- c:\windows\system32\psisrndr.ax
2011-10-12 15:47:43 88 ----a-w- c:\users\mark\appdata\roaming\netstat.bat
2011-10-12 15:16:29 -------- d-----w- c:\windows\pss
2011-10-06 15:40:28 -------- d-----w- c:\users\mark\sysclean
2011-10-04 00:36:16 81920 ----a-w- c:\programdata\WindowsTrayProfile.dll
2011-10-03 14:32:37 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-10-03 14:32:36 758784 ----a-w- c:\program files\common files\microsoft shared\vgx\VGX.dll
2011-09-28 12:18:07 -------- d-----w- c:\users\mark\appdata\roaming\Lexmark Productivity Studio
2011-09-27 17:09:42 147968 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\lxdpdrpp.dll
2011-09-27 16:43:24 -------- d-----w- c:\programdata\PC Drivers HeadQuarters
2011-09-27 16:21:44 -------- d-----w- c:\programdata\Ezprint
2011-09-27 16:21:22 -------- d-----w- c:\program files\Lexmark Toolbar
2011-09-27 16:19:41 -------- d-----w- C:\drivers
2011-09-25 19:41:13 -------- d-----w- C:\AeriaGames
2011-09-25 17:03:17 -------- d-----w- c:\program files\common files\Akamai
.
==================== Find3M ====================
.
2011-10-12 21:11:17 916480 ----a-w- c:\windows\system32\wininet.dll
2011-10-12 21:11:17 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-10-12 21:11:15 385024 ----a-w- c:\windows\system32\html.iec
2011-10-12 21:11:15 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2011-10-12 21:11:15 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2011-10-12 21:11:15 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2011-10-12 21:11:14 71680 ----a-w- c:\windows\system32\iesetup.dll
2011-10-12 21:11:14 109056 ----a-w- c:\windows\system32\iesysprep.dll
2011-10-04 01:11:22 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-09-06 17:30:42 42832 ----a-w- c:\windows\system32\sbbd.exe
2011-08-29 22:36:34 74456 ----a-w- c:\windows\system32\drivers\sbapifs.sys
2011-08-29 22:36:34 101720 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-07-29 03:22:06 8396800 ----a-w- c:\windows\system32\drivers\atikmdag.sys
2011-07-29 02:44:08 18388480 ----a-w- c:\windows\system32\atioglxx.dll
2011-07-29 02:41:00 151552 ----a-w- c:\windows\system32\atiapfxx.exe
2011-07-29 02:40:46 726528 ----a-w- c:\windows\system32\aticfx32.dll
2011-07-29 02:36:28 462848 ----a-w- c:\windows\system32\ATIDEMGX.dll
2011-07-29 02:35:54 401408 ----a-w- c:\windows\system32\atieclxx.exe
2011-07-29 02:35:26 176128 ----a-w- c:\windows\system32\atiesrxx.exe
2011-07-29 02:34:12 159744 ----a-w- c:\windows\system32\atitmmxx.dll
2011-07-29 02:33:56 356352 ----a-w- c:\windows\system32\atipdlxx.dll
2011-07-29 02:33:44 278528 ----a-w- c:\windows\system32\Oemdspif.dll
2011-07-29 02:33:36 20992 ----a-w- c:\windows\system32\atimuixx.dll
2011-07-29 02:33:28 43520 ----a-w- c:\windows\system32\ati2edxx.dll
2011-07-29 02:30:28 4198912 ----a-w- c:\windows\system32\atidxx32.dll
2011-07-29 02:11:44 1828864 ----a-w- c:\windows\system32\atiumdmv.dll
2011-07-29 02:11:16 46080 ----a-w- c:\windows\system32\aticalrt.dll
2011-07-29 02:11:04 44032 ----a-w- c:\windows\system32\aticalcl.dll
2011-07-29 02:09:12 4256768 ----a-w- c:\windows\system32\atiumdag.dll
2011-07-29 02:07:26 8247296 ----a-w- c:\windows\system32\aticaldd.dll
2011-07-29 02:04:00 4056064 ----a-w- c:\windows\system32\atiumdva.dll
2011-07-29 02:01:50 52736 ----a-w- c:\windows\system32\coinst.dll
2011-07-29 01:54:44 266240 ----a-w- c:\windows\system32\SETDB59.tmp
2011-07-29 01:54:44 266240 ----a-w- c:\windows\system32\SETA520.tmp
2011-07-29 01:54:44 266240 ----a-w- c:\windows\system32\SET277A.tmp
2011-07-29 01:54:44 266240 ----a-w- c:\windows\system32\atiadlxx.dll
2011-07-29 01:54:32 13312 ----a-w- c:\windows\system32\atiglpxx.dll
2011-07-29 01:54:20 32768 ----a-w- c:\windows\system32\atigktxx.dll
2011-07-29 01:53:48 247296 ----a-w- c:\windows\system32\drivers\atikmpag.sys
2011-07-29 01:53:16 31744 ----a-w- c:\windows\system32\atiuxpag.dll
2011-07-29 01:53:02 29184 ----a-w- c:\windows\system32\atiu9pag.dll
2011-07-29 01:52:40 37376 ----a-w- c:\windows\system32\atitmpxx.dll
2011-07-29 01:52:28 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2011-07-29 01:51:06 52736 ----a-w- c:\windows\system32\atimpc32.dll
2011-07-29 01:51:06 52736 ----a-w- c:\windows\system32\amdpcom32.dll
2011-07-22 20:51:50 94208 ----a-w- c:\windows\system32\dpl100.dll
.
============= FINISH: 17:16:06.62 ===============