Taken to websites

Hi

When I boot up my PC without opening IE two websites are continually opened up on sceeen apprimately one every five minutes.

The websites / pages are
Live Links Removed

I have tried to save a hijack this log but when I hit save log nothing happensa nd the programme closes.

thanks

Matt

Comments

  • edited November 2008
    Please note that all instructions given are customised for this computer only, the tools used may cause damage if used on a computer with different infections.

    If you think you have similar problems, please post a log in the HJT forum and wait for help.

    Hello and welcome to the forums

    My name is Katana and I will be helping you to remove any infection(s) that you may have.

    Please observe these rules while we work:
    1. Please Read All Instructions Carefully
    2. If you don't understand something, stop and ask! Don't keep going on.
    3. Please do not run any other tools or scans whilst I am helping you
    4. Please continue to respond until I give you the "All Clear"
      (Just because you can't see a problem doesn't mean it isn't there)

    If you can do those few things, everything should go smoothly laechel.gif

    Please ensure that any USB/Flash/External drives are connected whilst we are cleaning your machine.

    Please Note, your security programs may give warnings for some of the tools I will ask you to use.
    Be assured, any links I give are safe






    Download and Run RSIT
    • Please download Random's System Information Tool by random/random from here and save it to your desktop.
    • Double click on RSIT.exe to run RSIT.
    • Click Continue at the disclaimer screen.
    • Once it has finished, two logs will open:
      • log.txt will be opened maximized.
      • info.txt will be opened minimized.
    • Please post the contents of both log.txt and info.txt.
  • edited November 2008
    Katana

    Thank you.

    Here is one log - the info txt is tool ong so will put on next post


    ogfile of random's system information tool 1.04 (written by random/random)
    Run by Matt at 2008-11-18 22:35:12
    Microsoft Windows XP Professional Service Pack 2
    System drive C: has 8 GB (19%) free of 39 GB
    Total RAM: 191 MB (5% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 22:35:50, on 18/11/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Trend Micro\PC-cillin 2002\Tmntsrv.exe
    C:\Program Files\Trend Micro\PC-cillin 2002\PCCPFW.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\Program Files\Trend Micro\PC-cillin 2002\pccguide.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\Trend Micro\PC-cillin 2002\PCCClient.exe
    C:\Program Files\Trend Micro\PC-cillin 2002\Pop3trap.exe
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe
    C:\Program Files\ScreenPrint32 v3\ScreenPrint32.exe
    C:\Program Files\Lexmark 2300 Series\lxcgmon.exe
    C:\Program Files\Lexmark 2300 Series\ezprint.exe
    C:\Program Files\Trend Micro\PC-cillin 2002\WebTrap.EXE
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\FixCamera.exe
    C:\WINDOWS\tsnp2std.exe
    C:\WINDOWS\system32\lxcgcoms.exe
    C:\WINDOWS\vsnp2std.exe
    C:\WINDOWS\Fonts\svchost.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\system32\WgaTray.exe
    C:\WINDOWS\system32\Rundll32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Documents and Settings\Matt\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
    C:\Documents and Settings\Matt\Application Data\gadcom\gadcom.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\GetPack\GetPack24.exe
    C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\CalCheck.exe
    C:\Documents and Settings\All Users\Application Data\ipd\tray.exe
    C:\WINDOWS\system32\dPI02\dPI022328.exe
    C:\Program Files\Linksys\WMP11 Config Utility\WMP11CFG.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
    C:\Documents and Settings\Matt\Desktop\RSIT.exe
    C:\Program Files\trend micro\Matt.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.yahoo.com/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    O2 - BHO: IP - {000051AF-07E2-461B-BA37-A2AF7E652E7D} - C:\Documents and Settings\All Users\Application Data\ipd\ipb.dll
    O2 - BHO: bambanner browser enhancer - {31b35a87-c9a2-0132-5713-431be04c5e51} - C:\WINDOWS\system32\yexehfqmltzpjph.dll
    O2 - BHO: (no name) - {4CAB59B4-55A3-4737-9FD5-B93C6430BF76} - C:\WINDOWS\system32\cwqjyhge.dll
    O2 - BHO: (no name) - {4CAFAF0C-C38F-43C1-8080-390E776254DE} - C:\WINDOWS\system32\tuvVPfgf.dll
    O2 - BHO: (no name) - {514A5C49-0C7D-42c3-A71B-38864A269B7A} - C:\WINDOWS\system32\kkknikjo.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: (no name) - {D2524837-DE9C-4ABD-8A48-E3E2BB5FC9BC} - C:\WINDOWS\system32\xxyawuVM.dll
    O2 - BHO: {a68a08e3-a047-a768-9434-d50765f2becd} - {dceb2f56-705d-4349-867a-740a3e80a86a} - C:\WINDOWS\system32\sqnnhy.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Matt\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
    O4 - HKCU\..\Run: [gadcom] "C:\Documents and Settings\Matt\Application Data\gadcom\gadcom.exe" 61A847B5BBF72813339330466188719AB689201522886B092CBD44BD8689220221DD3257
    O4 - HKCU\..\Run: [cc4c48c9] rundll32.exe "C:\WINDOWS\system32\uydianye.dll",b
    O4 - HKCU\..\Run: [GetPack24] "C:\Program Files\GetPack\GetPack24.exe"
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
    O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: Photo Express Calendar Checker SE.lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\CalCheck.exe
    O4 - Global Startup: Start Shopper Link System Tray App.lnk = C:\Documents and Settings\All Users\Application Data\ipd\tray.exe
    O4 - Global Startup: Wireless PCI Card Configuration Utility.lnk = C:\Program Files\Linksys\WMP11 Config Utility\WMP11CFG.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: Fiddler - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - "C:\Program Files\Fiddler\Fiddler.exe" (file missing)
    O9 - Extra 'Tools' menuitem: Fiddler - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - "C:\Program Files\Fiddler\Fiddler.exe" (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
    O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EPUWALControl_v1-0-3-18.cab
    O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/autocomplete.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O20 - AppInit_DLLs: sqnnhy.dll
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O20 - Winlogon Notify: tuvVPfgf - C:\WINDOWS\SYSTEM32\tuvVPfgf.dll
    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: lxcg_device - - C:\WINDOWS\system32\lxcgcoms.exe
    O23 - Service: PC-cillin PersonalFirewall (PCCPFW) - Trend Micro Inc. - C:\Program Files\Trend Micro\PC-cillin 2002\PCCPFW.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Inc. - C:\Program Files\Trend Micro\PC-cillin 2002\Tmntsrv.exe

    --
    End of file - 8478 bytes

    ======Scheduled tasks folder======

    C:\WINDOWS\tasks\GoogleUpdateTaskUser.job

    ======Registry dump======

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000051AF-07E2-461B-BA37-A2AF7E652E7D}]
    IP - C:\Documents and Settings\All Users\Application Data\ipd\ipb.dll [2008-08-14 176128]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31b35a87-c9a2-0132-5713-431be04c5e51}]
    bambanner browser enhancer - C:\WINDOWS\system32\yexehfqmltzpjph.dll [2008-08-29 166400]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4CAB59B4-55A3-4737-9FD5-B93C6430BF76}]
    C:\WINDOWS\system32\cwqjyhge.dll [2008-11-17 85504]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4CAFAF0C-C38F-43C1-8080-390E776254DE}]
    C:\WINDOWS\system32\tuvVPfgf.dll [2008-09-13 34816]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{514A5C49-0C7D-42c3-A71B-38864A269B7A}]
    C:\WINDOWS\system32\kkknikjo.dll [2008-11-04 92160]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
    SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D2524837-DE9C-4ABD-8A48-E3E2BB5FC9BC}]
    C:\WINDOWS\system32\xxyawuVM.dll [2008-09-13 284160]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{dceb2f56-705d-4349-867a-740a3e80a86a}]
    C:\WINDOWS\system32\sqnnhy.dll [2008-11-18 120832]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll [2005-07-19 342600]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2004-10-13 1694208]
    "MsnMsgr"=C:\Program Files\MSN Messenger\MsnMsgr.Exe /background []
    "SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2007-06-21 1318912]
    "AdobeUpdater"=C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe [2007-06-11 2321600]
    "ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360]
    "Google Update"=C:\Documents and Settings\Matt\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-07 133104]
    "gadcom"=C:\Documents and Settings\Matt\Application Data\gadcom\gadcom.exe [2008-11-17 56832]
    "cc4c48c9"=C:\WINDOWS\system32\uydianye.dll [2008-11-17 75776]
    "GetPack24"=C:\Program Files\GetPack\GetPack24.exe [2008-11-03 350720]

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup
    Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
    Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
    Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE
    Photo Express Calendar Checker SE.lnk - C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\CalCheck.exe
    Start Shopper Link System Tray App.lnk - C:\Documents and Settings\All Users\Application Data\ipd\tray.exe
    Wireless PCI Card Configuration Utility.lnk - C:\Program Files\Linksys\WMP11 Config Utility\WMP11CFG.exe

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "AppInit_DLLS"="sqnnhy.dll"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
    C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [2007-04-19 294912]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tuvVPfgf]
    C:\WINDOWS\system32\tuvVPfgf.dll [2008-09-13 34816]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
    C:\WINDOWS\system32\WgaLogon.dll [2006-06-19 702768]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 77824]
    "{4CAFAF0C-C38F-43C1-8080-390E776254DE}"=C:\WINDOWS\system32\tuvVPfgf.dll [2008-09-13 34816]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
    "authentication packages"=msv1_0
    C:\WINDOWS\system32\xxyawuVM
    "notification packages"=
    scecli
    scecli

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "dontdisplaylastusername"=0
    "legalnoticecaption"=
    "legalnoticetext"=
    "shutdownwithoutlogon"=1
    "undockwithoutlogon"=1

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDriveTypeAutoRun"=145

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\Program Files\K1RFD\EchoLink\EchoLink.exe"="C:\Program Files\K1RFD\EchoLink\EchoLink.exe:*:Enabled:EchoLink"
    "C:\Program Files\Trend Micro\PC-cillin 2002\pccmain.exe"="C:\Program Files\Trend Micro\PC-cillin 2002\pccmain.exe:*:Enabled:PC-cillin 2002"
    "C:\WINDOWS\system32\P2P Networking\P2P Networking.exe"="C:\WINDOWS\system32\P2P Networking\P2P Networking.exe:*:Disabled:P2P Networking"
    "C:\Program Files\Trend Micro\PC-cillin 2002\PCCSet.exe"="C:\Program Files\Trend Micro\PC-cillin 2002\PCCSet.exe:*:Enabled:PC-cillin 2002 Settings"
    "C:\Program Files\Linksys\WMP11 Config Utility\WMP11CFG.exe"="C:\Program Files\Linksys\WMP11 Config Utility\WMP11CFG.exe:*:Enabled:Wireless PCI Card Configuration Utility"
    "C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
    "C:\WINDOWS\system32\rundll32.exe"="C:\WINDOWS\system32\rundll32.exe:*:Disabled:Run a DLL as an App"
    "C:\Program Files\Yahoo!\Messenger\YServer.exe"="C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Disabled:Yahoo! FT Server"
    "C:\Program Files\Yahoo!\Messenger\ypager.exe"="C:\Program Files\Yahoo!\Messenger\ypager.exe:*:Disabled:Yahoo! Messenger"
    "C:\WINDOWS\system32\java.exe"="C:\WINDOWS\system32\java.exe:*:Enabled:Java(TM) 2 Platform Standard Edition binary"
    "C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Mozilla Firefox"
    "C:\Program Files\Internet Explorer\iexplore.exe"="C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer"
    "C:\Program Files\Adobe\Acrobat 5.0\Reader\AcroRd32.exe"="C:\Program Files\Adobe\Acrobat 5.0\Reader\AcroRd32.exe:*:Enabled:Acrobat Reader 5.0"
    "C:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe"="C:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe:*:Enabled:javaw"
    "C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:MSN Messenger 7.5"
    "C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
    "C:\Program Files\CQPhone\CQPhone.exe"="C:\Program Files\CQPhone\CQPhone.exe:*:Enabled:CQPhone"
    "C:\Program Files\CQPhone\cqvideo.exe"="C:\Program Files\CQPhone\cqvideo.exe:*:Enabled:CQVideo"
    "C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:MSN Messenger 7.5"

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
    shell\AutoRun\command - F:\Enterprise_Launcher.exe


    ======List of files/folders created in the last 1 months======

    2008-11-18 22:35:12 ----D---- C:\rsit
    2008-11-18 21:55:15 ----A---- C:\WINDOWS\system32\sqnnhy.dll
    2008-11-18 21:55:14 ----A---- C:\WINDOWS\system32\uhbmkvvq.dll
    2008-11-18 21:55:12 ----A---- C:\WINDOWS\system32\gfcnncad.dll
    2008-11-18 18:47:26 ----A---- C:\WINDOWS\system32\khfGwVOf.dll
    2008-11-18 18:47:24 ----A---- C:\WINDOWS\system32\qoMdARKC.dll
    2008-11-18 10:10:22 ----A---- C:\WINDOWS\system32\ljJCuSIB.dll
    2008-11-18 10:10:21 ----A---- C:\WINDOWS\system32\tuvTnOff.dll
    2008-11-18 08:35:17 ----D---- C:\Program Files\iCheck
    2008-11-18 08:35:17 ----D---- C:\Program Files\GetPack
    2008-11-18 08:31:44 ----D---- C:\WINDOWS\system32\dPI02
    2008-11-18 08:31:35 ----A---- C:\WINDOWS\system32\xxyvvSmM.dll
    2008-11-18 08:31:34 ----A---- C:\WINDOWS\system32\wvUkJaxY.dll
    2008-11-18 08:31:25 ----D---- C:\Program Files\Mjcore
    2008-11-17 21:58:26 ----A---- C:\WINDOWS\system32\nyrxlt.dll
    2008-11-17 21:58:25 ----A---- C:\WINDOWS\system32\eangcaco.dll
    2008-11-17 21:56:00 ----SH---- C:\WINDOWS\system32\eynaidyu.ini
    2008-11-17 21:55:53 ----A---- C:\WINDOWS\system32\uydianye.dll
    2008-11-17 21:55:26 ----A---- C:\WINDOWS\system32\cwqjyhge.dll
    2008-11-17 08:16:57 ----D---- C:\Documents and Settings\Matt\Application Data\gadcom
    2008-11-17 08:16:39 ----A---- C:\WINDOWS\system32\iifgHabY.dll
    2008-11-17 08:16:38 ----A---- C:\WINDOWS\system32\mlJAsQii.dll
    2008-11-16 22:00:19 ----SH---- C:\WINDOWS\system32\eemefaun.ini
    2008-11-16 22:00:18 ----A---- C:\WINDOWS\system32\nuafemee.dll
    2008-11-16 21:57:19 ----A---- C:\WINDOWS\system32\wsvrxc.dll
    2008-11-16 21:57:18 ----A---- C:\WINDOWS\system32\wxhlbptd.dll
    2008-11-16 21:54:20 ----A---- C:\WINDOWS\system32\qlldefca.dll
    2008-11-16 16:19:40 ----A---- C:\WINDOWS\system32\opnkjJcD.dll
    2008-11-16 16:19:38 ----A---- C:\WINDOWS\system32\qoMeCrqr.dll
    2008-11-16 09:55:27 ----A---- C:\WINDOWS\system32\ljJCvUKa.dll
    2008-11-16 09:55:26 ----A---- C:\WINDOWS\system32\opnlIxUL.dll
    2008-11-15 21:59:06 ----A---- C:\WINDOWS\system32\udnxux.dll
    2008-11-15 21:59:05 ----A---- C:\WINDOWS\system32\bvseespe.dll
    2008-11-15 21:56:10 ----SH---- C:\WINDOWS\system32\stynljxm.ini
    2008-11-15 21:53:28 ----A---- C:\WINDOWS\system32\eoumymtw.dll
    2008-11-15 08:56:59 ----A---- C:\WINDOWS\system32\rqRIyVmL.dll
    2008-11-15 08:56:59 ----A---- C:\WINDOWS\system32\pmnmnKEu.dll
    2008-11-14 21:59:18 ----A---- C:\WINDOWS\system32\kjgbqb.dll
    2008-11-14 21:59:17 ----A---- C:\WINDOWS\system32\kkkfagsk.dll
    2008-11-14 21:56:27 ----SH---- C:\WINDOWS\system32\rgapomkw.ini
    2008-11-14 21:56:17 ----A---- C:\WINDOWS\system32\wkmopagr.dll
    2008-11-14 21:53:19 ----A---- C:\WINDOWS\system32\eeovgobr.dll
    2008-11-14 07:51:12 ----A---- C:\WINDOWS\system32\ljJDSKCs.dll
    2008-11-14 07:51:11 ----A---- C:\WINDOWS\system32\byXNfFuU.dll
    2008-11-13 21:54:36 ----SH---- C:\WINDOWS\system32\jnjodixa.ini
    2008-11-13 21:54:28 ----A---- C:\WINDOWS\system32\axidojnj.dll
    2008-11-13 21:52:43 ----A---- C:\WINDOWS\system32\kvwsbs.dll
    2008-11-13 21:52:40 ----A---- C:\WINDOWS\system32\frkoodfm.dll
    2008-11-13 21:51:38 ----A---- C:\WINDOWS\system32\mxfwkkfd.dll
    2008-11-12 21:54:02 ----A---- C:\WINDOWS\system32\pmooihhn.dll
    2008-11-12 21:52:01 ----A---- C:\WINDOWS\system32\ssqnkLFy.dll
    2008-11-12 21:52:00 ----A---- C:\WINDOWS\system32\gEwvUlKE.dll
    2008-11-12 21:51:15 ----A---- C:\WINDOWS\system32\felcry.dll
    2008-11-12 21:51:14 ----A---- C:\WINDOWS\system32\jhcwyjgs.dll
    2008-11-12 21:50:37 ----A---- C:\WINDOWS\system32\lxsxlmpc.dll
    2008-11-11 10:07:38 ----A---- C:\WINDOWS\system32\djyesm.dll
    2008-11-11 10:07:37 ----A---- C:\WINDOWS\system32\kdonmtfs.dll
    2008-11-11 10:05:21 ----SH---- C:\WINDOWS\system32\asmiyaef.ini
    2008-11-11 10:05:15 ----A---- C:\WINDOWS\system32\feayimsa.dll
    2008-11-11 10:04:38 ----A---- C:\WINDOWS\system32\bhlvrgmk.dll
    2008-11-10 17:32:01 ----A---- C:\WINDOWS\system32\OIUUYG.DLL
    2008-11-10 10:09:47 ----SH---- C:\WINDOWS\system32\sfkmfxec.ini
    2008-11-10 10:09:46 ----A---- C:\WINDOWS\system32\cexfmkfs.dll
    2008-11-10 10:06:47 ----A---- C:\WINDOWS\system32\dvzywv.dll
    2008-11-10 10:06:46 ----A---- C:\WINDOWS\system32\hiraimhm.dll
    2008-11-09 10:09:42 ----A---- C:\WINDOWS\system32\qmcicjpt.dll
    2008-11-09 10:09:42 ----A---- C:\WINDOWS\system32\fwgpin.dll
    2008-11-09 10:06:46 ----SH---- C:\WINDOWS\system32\mrfkrgpr.ini
    2008-11-09 09:29:31 ----D---- C:\WINDOWS\system32\sX3i02
    2008-11-09 09:29:06 ----A---- C:\WINDOWS\system32\cbXOIxvt.dll
    2008-11-09 09:29:05 ----A---- C:\WINDOWS\system32\tuvVNFWo.dll
    2008-11-08 10:05:55 ----A---- C:\WINDOWS\system32\itunah.dll
    2008-11-08 10:05:55 ----A---- C:\WINDOWS\system32\ikpruvcs.dll
    2008-11-08 10:03:14 ----SH---- C:\WINDOWS\system32\lgjopvwm.ini
    2008-11-08 10:03:07 ----A---- C:\WINDOWS\system32\mwvpojgl.dll
    2008-11-08 08:33:11 ----A---- C:\WINDOWS\system32\tuvVLdcD.dll
    2008-11-08 08:33:10 ----A---- C:\WINDOWS\system32\tuvWmNhG.dll
    2008-11-07 16:41:49 ----D---- C:\Program Files\Safari
    2008-11-07 16:38:56 ----D---- C:\Program Files\Apple Software Update
    2008-11-07 09:19:51 ----A---- C:\WINDOWS\system32\neakklxj.dll
    2008-11-07 09:18:08 ----A---- C:\WINDOWS\system32\fccaBSmM.dll
    2008-11-07 09:18:08 ----A---- C:\WINDOWS\system32\efcCvWOF.dll
    2008-11-07 09:17:15 ----SH---- C:\WINDOWS\system32\jihbbprd.ini
    2008-11-07 09:17:07 ----A---- C:\WINDOWS\system32\drpbbhij.dll
    2008-11-06 07:36:24 ----A---- C:\WINDOWS\system32\pmnnKARj.dll
    2008-11-06 07:36:24 ----A---- C:\WINDOWS\system32\opnnkkJY.dll
    2008-11-05 22:02:05 ----A---- C:\WINDOWS\system32\wianxk.dll
    2008-11-05 22:01:56 ----A---- C:\WINDOWS\system32\lfgcqktg.dll
    2008-11-05 22:01:52 ----SH---- C:\WINDOWS\system32\vrbjlbap.ini
    2008-11-05 22:01:50 ----A---- C:\WINDOWS\system32\pabljbrv.dll
    2008-11-05 22:01:17 ----A---- C:\WINDOWS\system32\tuivyemh.dll
    2008-11-05 10:03:56 ----D---- C:\Documents and Settings\Matt\Application Data\Opera
    2008-11-05 10:02:55 ----D---- C:\Program Files\Opera
    2008-11-05 08:29:57 ----A---- C:\WINDOWS\system32\urqRHyvS.dll
    2008-11-05 08:29:57 ----A---- C:\WINDOWS\system32\ddcYpmnk.dll
    2008-11-04 22:02:44 ----A---- C:\WINDOWS\system32\ypskil.dll
    2008-11-04 22:02:43 ----A---- C:\WINDOWS\system32\cimqbxoy.dll
    2008-11-04 21:59:57 ----SH---- C:\WINDOWS\system32\dbavjtvw.ini
    2008-11-04 21:59:22 ----A---- C:\WINDOWS\system32\kkknikjo.dll
    2008-11-04 09:20:47 ----D---- C:\Program Files\Sun
    2008-11-04 09:20:10 ----A---- C:\WINDOWS\system32\javaws.exe
    2008-11-04 09:20:10 ----A---- C:\WINDOWS\system32\javaw.exe
    2008-11-04 09:20:09 ----A---- C:\WINDOWS\system32\java.exe
    2008-11-04 08:39:07 ----A---- C:\WINDOWS\system32\jkkJbxVm.dll
    2008-11-04 08:39:07 ----A---- C:\WINDOWS\system32\ddcAsppM.dll
    2008-11-03 22:06:11 ----A---- C:\WINDOWS\system32\vhmbml.dll
    2008-11-03 22:06:01 ----A---- C:\WINDOWS\system32\skbewwoa.dll
    2008-11-03 22:00:41 ----SH---- C:\WINDOWS\system32\orpnujqh.ini
    2008-11-03 22:00:34 ----A---- C:\WINDOWS\system32\hqjunpro.dll
    2008-11-03 21:59:34 ----A---- C:\WINDOWS\system32\salsyrsi.dll
    2008-11-03 07:12:39 ----A---- C:\WINDOWS\system32\vtUnnmMC.dll
    2008-11-03 07:12:38 ----A---- C:\WINDOWS\system32\urqPgddC.dll
    2008-11-02 22:02:27 ----A---- C:\WINDOWS\system32\aurdzx.dll
    2008-11-02 22:02:25 ----A---- C:\WINDOWS\system32\dldthdys.dll
    2008-11-02 21:59:26 ----SH---- C:\WINDOWS\system32\xwxdevdl.ini
    2008-11-02 21:59:20 ----A---- C:\WINDOWS\system32\ldvedxwx.dll
    2008-11-02 21:58:51 ----A---- C:\WINDOWS\system32\jnxlhkps.dll
    2008-11-02 09:03:31 ----A---- C:\WINDOWS\system32\ljJAQKcA.dll
    2008-11-02 09:03:30 ----A---- C:\WINDOWS\system32\yayyXOFX.dll
    2008-11-01 22:03:15 ----A---- C:\WINDOWS\system32\cqmozv.dll
    2008-11-01 22:03:07 ----A---- C:\WINDOWS\system32\qupkcyhc.dll
    2008-11-01 22:00:14 ----SH---- C:\WINDOWS\system32\xivgtjwx.ini
    2008-11-01 22:00:05 ----A---- C:\WINDOWS\system32\xwjtgvix.dll
    2008-11-01 21:57:09 ----A---- C:\WINDOWS\system32\lyudeuvi.dll
    2008-11-01 08:31:36 ----A---- C:\WINDOWS\system32\yayvSlMD.dll
    2008-11-01 08:31:36 ----A---- C:\WINDOWS\system32\hgGvtQKa.dll
    2008-10-31 22:00:51 ----SH---- C:\WINDOWS\system32\txgbavxm.ini
    2008-10-31 22:00:47 ----A---- C:\WINDOWS\system32\mxvabgxt.dll
    2008-10-31 21:57:47 ----A---- C:\WINDOWS\system32\xugjwb.dll
    2008-10-31 21:57:47 ----A---- C:\WINDOWS\system32\ogljwfke.dll
    2008-10-31 21:54:47 ----A---- C:\WINDOWS\system32\ibebnxau.dll
    2008-10-31 07:44:39 ----A---- C:\WINDOWS\system32\rqRJCRJc.dll
    2008-10-31 07:44:38 ----A---- C:\WINDOWS\system32\opnnmJdd.dll
    2008-10-30 22:56:10 ----D---- C:\Program Files\MSECache
    2008-10-30 22:00:20 ----A---- C:\WINDOWS\system32\ivhemx.dll
    2008-10-30 22:00:19 ----A---- C:\WINDOWS\system32\ibjnuwnx.dll
    2008-10-30 21:57:24 ----SH---- C:\WINDOWS\system32\qrtfuksj.ini
    2008-10-30 21:57:19 ----A---- C:\WINDOWS\system32\jskuftrq.dll
    2008-10-30 21:54:19 ----A---- C:\WINDOWS\system32\ixowwcxh.dll
    2008-10-30 15:25:20 ----D---- C:\WINDOWS\system32\QI02
    2008-10-30 15:24:49 ----A---- C:\WINDOWS\system32\qoMdDuuT.dll
    2008-10-30 15:24:48 ----A---- C:\WINDOWS\system32\khfFXrQH.dll
    2008-10-29 22:00:48 ----A---- C:\WINDOWS\system32\gplmgr.dll
    2008-10-29 22:00:47 ----A---- C:\WINDOWS\system32\tuvcrnxj.dll
    2008-10-29 21:57:47 ----A---- C:\WINDOWS\system32\mbxxxgyq.exe
    2008-10-29 21:56:31 ----A---- C:\WINDOWS\system32\cbXRKDSK.dll
    2008-10-29 21:56:30 ----A---- C:\WINDOWS\system32\vtUlLBtS.dll
    2008-10-29 21:55:02 ----SH---- C:\WINDOWS\system32\cmsqqrxv.ini
    2008-10-29 21:54:55 ----A---- C:\WINDOWS\system32\vxrqqsmc.dll
    2008-10-29 21:53:19 ----A---- C:\WINDOWS\system32\fxkohtqt.dll
    2008-10-28 20:59:28 ----A---- C:\WINDOWS\system32\hxdunt.dll
    2008-10-28 20:59:21 ----A---- C:\WINDOWS\system32\tebjqsiw.dll
    2008-10-28 20:56:05 ----SH---- C:\WINDOWS\system32\sxkvwfgd.ini
    2008-10-28 20:56:03 ----A---- C:\WINDOWS\system32\dgfwvkxs.dll
    2008-10-28 20:54:20 ----A---- C:\WINDOWS\system32\lwqaplmg.exe
    2008-10-28 20:53:46 ----A---- C:\WINDOWS\system32\pdsjqvuc.dll
    2008-10-27 20:56:27 ----A---- C:\WINDOWS\system32\bmmvoaqs.exe
    2008-10-27 20:56:03 ----SH---- C:\WINDOWS\system32\dvndljfd.ini
    2008-10-27 20:53:46 ----A---- C:\WINDOWS\system32\cusxcf.dll
    2008-10-27 20:53:45 ----A---- C:\WINDOWS\system32\espatnsc.dll
    2008-10-27 20:53:02 ----A---- C:\WINDOWS\system32\hmuttlem.dll
    2008-10-27 07:42:34 ----A---- C:\WINDOWS\system32\nnnmmljJ.dll
    2008-10-27 07:42:33 ----A---- C:\WINDOWS\system32\xxyxWOfd.dll
    2008-10-26 20:59:43 ----A---- C:\WINDOWS\system32\dsmrpoiv.exe
    2008-10-26 20:55:35 ----SH---- C:\WINDOWS\system32\dgxsxeaj.ini
    2008-10-26 20:52:39 ----A---- C:\WINDOWS\system32\rbbfbdyw.dll
    2008-10-26 20:52:39 ----A---- C:\WINDOWS\system32\jeplvd.dll
    2008-10-26 20:52:10 ----A---- C:\WINDOWS\system32\uqaorppx.dll
    2008-10-25 21:01:26 ----A---- C:\WINDOWS\system32\hxrbjo.dll
    2008-10-25 21:01:24 ----A---- C:\WINDOWS\system32\twerkoey.dll
    2008-10-25 20:55:54 ----SH---- C:\WINDOWS\system32\ywswyruc.ini
    2008-10-25 20:52:50 ----A---- C:\WINDOWS\system32\qjtnxvrl.exe
    2008-10-25 20:52:16 ----A---- C:\WINDOWS\system32\qtonefne.dll
    2008-10-25 08:08:31 ----A---- C:\WINDOWS\system32\mlJApPHb.dll
    2008-10-25 08:08:31 ----A---- C:\WINDOWS\system32\hgGvtSjK.dll
    2008-10-24 21:01:32 ----A---- C:\WINDOWS\system32\fkjgssmj.exe
    2008-10-24 20:58:31 ----SH---- C:\WINDOWS\system32\yfisxdbs.ini
    2008-10-24 20:55:27 ----A---- C:\WINDOWS\system32\ynewjq.dll
    2008-10-24 20:55:27 ----A---- C:\WINDOWS\system32\puvqxunw.dll
    2008-10-24 20:49:45 ----A---- C:\WINDOWS\system32\ruxmpgys.dll
    2008-10-24 06:45:03 ----A---- C:\WINDOWS\system32\vtUnmMdA.dll
    2008-10-24 06:45:02 ----A---- C:\WINDOWS\system32\geBuRJab.dll
    2008-10-23 20:52:12 ----SH---- C:\WINDOWS\system32\mudawlag.ini
    2008-10-23 20:52:07 ----A---- C:\WINDOWS\system32\galwadum.dll
    2008-10-23 20:49:46 ----A---- C:\WINDOWS\system32\uumnnkie.exe
    2008-10-23 20:49:43 ----A---- C:\WINDOWS\system32\zejzlb.dll
    2008-10-23 20:49:43 ----A---- C:\WINDOWS\system32\nvciykwo.dll
    2008-10-23 20:49:14 ----A---- C:\WINDOWS\system32\cobtxfto.dll
    2008-10-23 06:41:47 ----A---- C:\WINDOWS\system32\ssqNHbYP.dll
    2008-10-23 06:41:47 ----A---- C:\WINDOWS\system32\hgGvuTKc.dll
    2008-10-22 20:51:14 ----A---- C:\WINDOWS\system32\arcqwg.dll
    2008-10-22 20:51:13 ----SH---- C:\WINDOWS\system32\tvjcfewj.ini
    2008-10-22 20:51:13 ----A---- C:\WINDOWS\system32\rcwmdmtk.dll
    2008-10-22 20:51:08 ----A---- C:\WINDOWS\system32\jwefcjvt.dll
    2008-10-22 20:50:58 ----A---- C:\WINDOWS\system32\gogmfacr.exe
    2008-10-22 20:50:06 ----A---- C:\WINDOWS\system32\pvivhbma.dll
    2008-10-22 06:48:30 ----A---- C:\WINDOWS\system32\opnkjJyA.dll
    2008-10-22 06:48:30 ----A---- C:\WINDOWS\system32\awtttsrS.dll
    2008-10-21 20:53:52 ----SH---- C:\WINDOWS\system32\bqwnpeck.ini
    2008-10-21 20:53:50 ----A---- C:\WINDOWS\system32\twjnvmcy.exe
    2008-10-21 20:53:47 ----A---- C:\WINDOWS\system32\kcepnwqb.dll
    2008-10-21 20:50:55 ----A---- C:\WINDOWS\system32\gmkhao.dll
    2008-10-21 20:50:54 ----A---- C:\WINDOWS\system32\xhxldjib.dll
    2008-10-21 20:47:47 ----A---- C:\WINDOWS\system32\bbmjpsfc.dll
    2008-10-21 07:48:53 ----A---- C:\WINDOWS\system32\qoMfebxw.dll
    2008-10-21 07:48:53 ----A---- C:\WINDOWS\system32\hgGvspOh.dll
    2008-10-20 20:49:46 ----SH---- C:\WINDOWS\system32\npxrbngi.ini
    2008-10-20 20:49:45 ----A---- C:\WINDOWS\system32\ignbrxpn.dll
    2008-10-20 20:48:19 ----A---- C:\WINDOWS\system32\qeslpgiw.exe
    2008-10-20 20:47:33 ----A---- C:\WINDOWS\system32\gegigt.dll
    2008-10-20 20:47:32 ----A---- C:\WINDOWS\system32\juufpkmh.dll
    2008-10-20 20:47:00 ----A---- C:\WINDOWS\system32\rbsxvhnv.dll
    2008-10-19 20:52:51 ----SH---- C:\WINDOWS\system32\httgwujx.ini
    2008-10-19 20:50:05 ----A---- C:\WINDOWS\system32\jqfpcefj.exe
    2008-10-19 20:47:29 ----A---- C:\WINDOWS\system32\affeok.dll
    2008-10-19 20:47:28 ----A---- C:\WINDOWS\system32\lugysidl.dll
    2008-10-19 20:46:45 ----A---- C:\WINDOWS\system32\jhgjqiwf.dll
    2008-10-19 08:23:08 ----A---- C:\WINDOWS\system32\ddcYsSJa.dll
    2008-10-19 08:23:08 ----A---- C:\WINDOWS\system32\cbXOGYPF.dll

    ======List of files/folders modified in the last 1 months======

    2008-11-18 22:35:57 ----ASH---- C:\WINDOWS\system32\MVuwayxx.ini
    2008-11-18 22:35:49 ----D---- C:\Program Files\Trend Micro
    2008-11-18 22:35:45 ----ASH---- C:\WINDOWS\system32\MVuwayxx.ini2
    2008-11-18 22:35:09 ----D---- C:\WINDOWS\Prefetch
    2008-11-18 22:28:19 ----A---- C:\WINDOWS\BMcf7f7b55.txt
    2008-11-18 22:23:34 ----D---- C:\Program Files\TextAloud
    2008-11-18 22:23:11 ----D---- C:\Program Files\Mozilla Firefox
    2008-11-18 21:58:24 ----SHD---- C:\WINDOWS\system32
    2008-11-18 21:56:08 ----AD---- C:\WINDOWS\Temp
    2008-11-18 21:55:10 ----A---- C:\WINDOWS\system32\c76f8cb7-.txt
    2008-11-18 18:49:54 ----RSD---- C:\WINDOWS\Fonts
    2008-11-18 18:47:40 ----A---- C:\WINDOWS\ULEAD32.INI
    2008-11-18 18:46:33 ----D---- C:\WINDOWS
    2008-11-18 18:45:14 ----A---- C:\WINDOWS\pskt.ini
    2008-11-18 18:41:23 ----A---- C:\WINDOWS\SchedLgU.Txt
    2008-11-18 17:10:25 ----D---- C:\Program Files\SUPERAntiSpyware
    2008-11-18 15:07:30 ----D---- C:\WINDOWS\system32\CatRoot2
    2008-11-18 11:11:54 ----SHD---- C:\WINDOWS\Installer
    2008-11-18 09:42:01 ----RD---- C:\Program Files
    2008-11-18 08:31:55 ----D---- C:\Temp
    2008-11-17 21:46:45 ----D---- C:\Documents and Settings\Matt\Application Data\Skype
    2008-11-17 20:47:29 ----D---- C:\Documents and Settings\Matt\Application Data\skypePM
    2008-11-14 16:13:19 ----D---- C:\WINDOWS\Help
    2008-11-09 09:28:42 ----D---- C:\WINDOWS\system32\drivers
    2008-11-07 20:54:37 ----D---- C:\Program Files\Hewlett-Packard
    2008-11-07 16:45:21 ----D---- C:\Documents and Settings\Matt\Application Data\Apple Computer
    2008-11-07 16:38:05 ----SD---- C:\WINDOWS\Tasks
    2008-11-04 09:19:58 ----D---- C:\Program Files\Java
    2008-11-01 23:20:09 ----D---- C:\unzipped
    2008-10-30 15:23:08 ----D---- C:\Program Files\Lx_cats
    2008-10-27 07:42:51 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
    2008-10-25 20:56:00 ----D---- C:\Documents and Settings\Matt\Application Data\Pamela
    2008-10-25 20:55:19 ----D---- C:\Program Files\Pamela
    2008-10-23 10:39:52 ----A---- C:\WINDOWS\system32\mcrh.tmp

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R1 AmdK7;AMD K7 Processor Driver; C:\WINDOWS\System32\DRIVERS\amdk7.sys [2004-08-04 37376]
    R1 incdrm;InCD EasyWrite Reader; C:\WINDOWS\system32\drivers\incdrm.sys [2003-08-21 25520]
    R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
    R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys []
    R2 PCC_PFW;PC-Cillin Personal Firewall; C:\WINDOWS\System32\Drivers\PCC_PFW.sys [2003-10-27 57468]
    R2 Tmfilter;Tmfilter; C:\WINDOWS\system32\drivers\TmXPFlt.sys [2005-03-28 183808]
    R2 Tmpreflt;Tmpreflt; C:\WINDOWS\system32\drivers\Tmpreflt.sys [2005-03-28 25088]
    R2 Vsapint;Vsapint; C:\WINDOWS\system32\drivers\Vsapint.sys [2005-03-28 962672]
    R3 ALCXSENS;Service for WDM 3D Audio Driver; C:\WINDOWS\system32\drivers\ALCXSENS.SYS [2003-08-14 404736]
    R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2003-08-21 462940]
    R3 FETND5BV;VIA Rhine-Family Fast Ethernet Adapter Driver Service; C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [2004-12-16 42496]
    R3 GEARAspiWDM;GEAR CDRom Filter; C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys [2006-09-19 15664]
    R3 PCANDIS5;PCANDIS5 Protocol Driver; \??\C:\WINDOWS\system32\PCANDIS5.SYS []
    R3 SASENUM;SASENUM; \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS []
    R3 SNP2STD;USB2.0 PC Camera (SNP2STD); C:\WINDOWS\system32\DRIVERS\snp2sxp.sys [2006-05-13 10305664]
    R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2004-08-04 26624]
    R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2004-08-04 57600]
    R3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-04 25856]
    R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2004-08-04 20480]
    R3 viagfx;viagfx; C:\WINDOWS\System32\DRIVERS\vtmini.sys [2003-08-11 265344]
    R3 vulfnths;VIA USB Host Controller Lower Filter; C:\WINDOWS\System32\Drivers\vulfnth.sys [2002-10-24 6912]
    R3 vulfntrs;VIA USB Roothub Lower Filter; C:\WINDOWS\System32\Drivers\vulfntr.sys [2003-05-24 11392]
    S2 W9986;DVR driver; C:\WINDOWS\System32\Drivers\dvr.sys [2001-02-02 18172]
    S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-04 17024]
    S3 Dot4;MS IEEE-1284.4 Driver; C:\WINDOWS\system32\DRIVERS\Dot4.sys [2004-08-04 207360]
    S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\WINDOWS\system32\DRIVERS\Dot4Prt.sys [2001-08-17 12928]
    S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\WINDOWS\system32\DRIVERS\dot4usb.sys [2001-08-17 23808]
    S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\System32\DRIVERS\fetnd5.sys [2001-08-17 27165]
    S3 FETNDISB;VIA Rhine Family Fast Ethernet Adapter Driver Service; C:\WINDOWS\System32\DRIVERS\fetnd5b.sys [2004-07-22 42496]
    S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
    S3 iteio;iteio; \??\C:\WINDOWS\System32\drivers\iteio.sys []
    S3 LMouKE;Logitech SetPoint Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\LMouKE.Sys []
    S3 mouhid;Mouse HID Driver; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-08-17 12160]
    S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-04 5504]
    S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-04 85376]
    S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-04 10880]
    S3 NTSIM;NTSIM; \??\C:\WINDOWS\System32\ntsim.sys []
    S3 RimUsb;BlackBerry Device; C:\WINDOWS\System32\Drivers\RimUsb.sys [2006-07-04 22528]
    S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-04 11136]
    S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-04 15360]
    S3 usbaudio;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-04 59264]
    S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-04 31616]
    S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-04 15104]
    S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]
    S3 WMP11V27;Instant Wireless PCI Card V2.7 Driver; C:\WINDOWS\system32\DRIVERS\WMP11V27.sys [2002-07-30 171776]
    S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-04 19328]
    S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2008-09-15 611664]
    R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2007-09-06 110592]
    R2 PCCPFW;PC-cillin PersonalFirewall; C:\Program Files\Trend Micro\PC-cillin 2002\PCCPFW.exe [2003-10-27 163840]
    R2 Tmntsrv;Trend NT Realtime Service; C:\Program Files\Trend Micro\PC-cillin 2002\Tmntsrv.exe [2003-10-27 176128]
    R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
    R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2006-10-30 492608]
    R3 lxcg_device;lxcg_device; C:\WINDOWS\system32\lxcgcoms.exe [2005-07-25 491520]
    S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
    S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
    S3 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2002-08-01 65536]
    S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2007-03-26 292864]

    EOF
  • edited November 2008
    and here is the info.txt log

    nfo.txt logfile of random's system information tool 1.04 2008-11-18 22:36:03

    ======Uninstall list======

    -->C:\bsw.exe /UNINSTALL
    -->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
    -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
    ABBYY FineReader 6.0 Sprint-->MsiExec.exe /I{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}
    Ad-Aware-->MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
    Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
    Adobe Flash Player Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
    Adobe Reader 8-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A80000000002}
    Ahead InCD EasyWrite Reader-->C:\WINDOWS\unmrw.exe /UNINSTALL
    Ahead NeroMediaPlayer-->C:\WINDOWS\UNNMP.exe /UNINSTALL
    Apple Mobile Device Support-->MsiExec.exe /I{3EBD3749-304E-4A4C-9575-C00E5F015217}
    Apple Software Update-->MsiExec.exe /I{02DFF6B1-1654-411C-8D7B-FD6052EF016F}
    Audacity 1.3.2 (Unicode)-->"C:\Program Files\Audacity 1.3 Beta (Unicode)\unins000.exe"
    Citrix Web Client-->C:\WINDOWS\system32\ctxsetup.exe /uninst C:\PROGRA~1\Citrix\icaweb32\uninst.inf
    CleanUp!-->C:\Program Files\CleanUp!\uninstall.exe
    CQ100-->C:\WINDOWS\CQ100 Uninstaller.exe
    CQPhone-->C:\WINDOWS\CQPhone Uninstaller.exe
    EchoLink-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\K1RFD\EchoLink\Uninst.isu"
    Enhancement Browser Tools Bambanner-->C:\WINDOWS\system32\dzrinpxdvrfclic.exe
    eQSO PC Client 3.00-->"C:\Program Files\eQSO-PC-Client\setup\uninst.exe"
    Fiddler (remove only)-->"C:\Program Files\Fiddler\uninst.exe"
    HighMAT Extension to Microsoft Windows XP CD Writing Wizard-->MsiExec.exe /X{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}
    HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
    Hotfix for Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
    hp LaserJet 1010 Series-->MsiExec.exe /x {292C47B2-8DB7-47BF-896C-C3C5EE8108C4}
    Internet Speed Monitor-->C:\Program Files\iCheck\Uninstall.exe
    iPod for Windows 2005-03-23-->C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{44A537A5-859C-43A6-8285-C0668142A090} /l1033
    iTunes-->MsiExec.exe /I{446DBFFA-4088-48E3-8932-74316BA4CAE4}
    J2SE Runtime Environment 5.0 Update 1-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150010}
    Jasc Paint Shop Pro 8-->MsiExec.exe /I{81A34902-9D0B-4920-A25C-4CDC5D14B328}
    Java(TM) 6 Update 2-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
    Java(TM) 6 Update 3-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
    Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
    LaserJet 1020 series-->C:\Program Files\Zenographics\{0A60D272-429C-4300-A399-500ACE46C14F}\Setup.exe -u "HPLJInstaller.dll=Hplj1020.inf"
    Lexmark 2300 Series-->C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\lxcgUNST.EXE -NOLICENSE
    Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
    Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
    Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
    Microsoft Office XP Professional with FrontPage-->MsiExec.exe /I{90280409-6000-11D3-8CFE-0050048383C9}
    Microsoft Plus! for Windows XP-->MsiExec.exe /I{EEC2DAFD-5558-40AC-8E9C-5005C8F810E8}
    Microsoft Windows Journal Viewer-->MsiExec.exe /X{43DCF766-6838-4F9A-8C91-D92DA586DFA7}
    Mozilla Firefox (3.0.4)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
    MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
    MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
    MSXML4 Parser-->MsiExec.exe /I{01501EBA-EC35-4F9F-8889-3BE346E5DA13}
    OLYMPUS CAMEDIA Master 4.2-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{30BB4D60-81DB-11D5-BB77-00400536ABAC}\setup.exe" CAMEDIA Master 4.2
    OpenOffice.org Installer 1.0-->MsiExec.exe /X{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}
    Pamela Basic 4.0-->C:\Program Files\Pamela\Uninst.exe
    PC Connectivity Solution-->MsiExec.exe /I{066D65EA-ED53-44E4-A96A-F81B6E409D2E}
    PC-cillin 2002-->MsiExec.exe /X{C90F3E44-3BF6-11D4-A110-00500405613A}
    Pdf995-->C:\Program Files\pdf995\setup.exe uninstall
    PowerDVD-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\setup.exe" -uninstall
    QuickTime-->MsiExec.exe /I{50D8FFDD-90CD-4859-841F-AA1961C7767A}
    RealPlayer-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
    Realtek AC'97 Audio-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" REMOVE
    Registry Mechanic 5.1-->"C:\Program Files\Registry Mechanic\unins000.exe"
    S3 S3Display-->vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Display'
    S3 S3Gamma2-->vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Gamma2'
    S3 S3Info2-->vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Info2'
    S3 S3Overlay-->vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Overlay'
    ScreenPrint32 v3.5 (C:\Program Files\ScreenPrint32 v3\) #3-->C:\WINDOWS\st6unst.exe -n "C:\Program Files\ScreenPrint32 v3\ST6UNST.001"
    ScreenPrint32 v3.5-->C:\WINDOWS\st6unst.exe -n "C:\Program Files\ScreenPrint32 v3\ST6UNST.LOG"
    ScreenPrint32-->C:\WINDOWS\ST5UNST.EXE -n "C:\WINDOWS\ST5UNST.LOG"
    Security Update for Windows Media Player (KB911564)-->"C:\WINDOWS\$NtUninstallKB911564$\spuninst\spuninst.exe"
    Security Update for Windows Media Player 6.4 (KB925398)-->"C:\WINDOWS\$NtUninstallKB925398_WMP64$\spuninst\spuninst.exe"
    Security Update for Windows Media Player 9 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP9$\spuninst\spuninst.exe"
    Security Update for Windows Media Player 9 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP9$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB890046)-->"C:\WINDOWS\$NtUninstallKB890046$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB893756)-->"C:\WINDOWS\$NtUninstallKB893756$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB896358)-->"C:\WINDOWS\$NtUninstallKB896358$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB896423)-->"C:\WINDOWS\$NtUninstallKB896423$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB896424)-->"C:\WINDOWS\$NtUninstallKB896424$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB896428)-->"C:\WINDOWS\$NtUninstallKB896428$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB899587)-->"C:\WINDOWS\$NtUninstallKB899587$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB899589)-->"C:\WINDOWS\$NtUninstallKB899589$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB899591)-->"C:\WINDOWS\$NtUninstallKB899591$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB900725)-->"C:\WINDOWS\$NtUninstallKB900725$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB901017)-->"C:\WINDOWS\$NtUninstallKB901017$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB901214)-->"C:\WINDOWS\$NtUninstallKB901214$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB902400)-->"C:\WINDOWS\$NtUninstallKB902400$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB904706)-->"C:\WINDOWS\$NtUninstallKB904706$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB905414)-->"C:\WINDOWS\$NtUninstallKB905414$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB905749)-->"C:\WINDOWS\$NtUninstallKB905749$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB908519)-->"C:\WINDOWS\$NtUninstallKB908519$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB911562)-->"C:\WINDOWS\$NtUninstallKB911562$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB911567)-->"C:\WINDOWS\$NtUninstallKB911567$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB911927)-->"C:\WINDOWS\$NtUninstallKB911927$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB912919)-->"C:\WINDOWS\$NtUninstallKB912919$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB913580)-->"C:\WINDOWS\$NtUninstallKB913580$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB914388)-->"C:\WINDOWS\$NtUninstallKB914388$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB914389)-->"C:\WINDOWS\$NtUninstallKB914389$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB916281)-->"C:\WINDOWS\$NtUninstallKB916281$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB917159)-->"C:\WINDOWS\$NtUninstallKB917159$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB917344)-->"C:\WINDOWS\$NtUninstallKB917344$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB917422)-->"C:\WINDOWS\$NtUninstallKB917422$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB917953)-->"C:\WINDOWS\$NtUninstallKB917953$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB918118)-->"C:\WINDOWS\$NtUninstallKB918118$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB918439)-->"C:\WINDOWS\$NtUninstallKB918439$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB918899)-->"C:\WINDOWS\$NtUninstallKB918899$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB919007)-->"C:\WINDOWS\$NtUninstallKB919007$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB920213)-->"C:\WINDOWS\$NtUninstallKB920213$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB920214)-->"C:\WINDOWS\$NtUninstallKB920214$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB920670)-->"C:\WINDOWS\$NtUninstallKB920670$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB920683)-->"C:\WINDOWS\$NtUninstallKB920683$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB920685)-->"C:\WINDOWS\$NtUninstallKB920685$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB921398)-->"C:\WINDOWS\$NtUninstallKB921398$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB921503)-->"C:\WINDOWS\$NtUninstallKB921503$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB921883)-->"C:\WINDOWS\$NtUninstallKB921883$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB922616)-->"C:\WINDOWS\$NtUninstallKB922616$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB922760)-->"C:\WINDOWS\$NtUninstallKB922760$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB922819)-->"C:\WINDOWS\$NtUninstallKB922819$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB923191)-->"C:\WINDOWS\$NtUninstallKB923191$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB923414)-->"C:\WINDOWS\$NtUninstallKB923414$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB923689)-->"C:\WINDOWS\$NtUninstallKB923689$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB923694)-->"C:\WINDOWS\$NtUninstallKB923694$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
    Security Update for Windows XP (KB923980)-->"C:\WINDOWS\$NtUninstallKB923980$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB924191)-->"C:\WINDOWS\$NtUninstallKB924191$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB924270)-->"C:\WINDOWS\$NtUninstallKB924270$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB924496)-->"C:\WINDOWS\$NtUninstallKB924496$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB924667)-->"C:\WINDOWS\$NtUninstallKB924667$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB925454)-->"C:\WINDOWS\$NtUninstallKB925454$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB925486)-->"C:\WINDOWS\$NtUninstallKB925486$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB925902)-->"C:\WINDOWS\$NtUninstallKB925902$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB926255)-->"C:\WINDOWS\$NtUninstallKB926255$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB926436)-->"C:\WINDOWS\$NtUninstallKB926436$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB927779)-->"C:\WINDOWS\$NtUninstallKB927779$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB927802)-->"C:\WINDOWS\$NtUninstallKB927802$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB928090)-->"C:\WINDOWS\$NtUninstallKB928090$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB928255)-->"C:\WINDOWS\$NtUninstallKB928255$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB928843)-->"C:\WINDOWS\$NtUninstallKB928843$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB929123)-->"C:\WINDOWS\$NtUninstallKB929123$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB929969)-->"C:\WINDOWS\$NtUninstallKB929969$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB930178)-->"C:\WINDOWS\$NtUninstallKB930178$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB931261)-->"C:\WINDOWS\$NtUninstallKB931261$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB931768)-->"C:\WINDOWS\$NtUninstallKB931768$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB931784)-->"C:\WINDOWS\$NtUninstallKB931784$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB932168)-->"C:\WINDOWS\$NtUninstallKB932168$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB933566)-->"C:\WINDOWS\$NtUninstallKB933566$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB933729)-->"C:\WINDOWS\$NtUninstallKB933729$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB935839)-->"C:\WINDOWS\$NtUninstallKB935839$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB935840)-->"C:\WINDOWS\$NtUninstallKB935840$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB936021)-->"C:\WINDOWS\$NtUninstallKB936021$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB937143)-->"C:\WINDOWS\$NtUninstallKB937143$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB937894)-->"C:\WINDOWS\$NtUninstallKB937894$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB938127)-->"C:\WINDOWS\$NtUninstallKB938127$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB938829)-->"C:\WINDOWS\$NtUninstallKB938829$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB939653)-->"C:\WINDOWS\$NtUninstallKB939653$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB941202)-->"C:\WINDOWS\$NtUninstallKB941202$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB941568)-->"C:\WINDOWS\$NtUninstallKB941568$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB941644)-->"C:\WINDOWS\$NtUninstallKB941644$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB941693)-->"C:\WINDOWS\$NtUninstallKB941693$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB942615)-->"C:\WINDOWS\$NtUninstallKB942615$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB943055)-->"C:\WINDOWS\$NtUninstallKB943055$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB943460)-->"C:\WINDOWS\$NtUninstallKB943460$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB943485)-->"C:\WINDOWS\$NtUninstallKB943485$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB944338)-->"C:\WINDOWS\$NtUninstallKB944338$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB944533)-->"C:\WINDOWS\$NtUninstallKB944533$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB944653)-->"C:\WINDOWS\$NtUninstallKB944653$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB945553)-->"C:\WINDOWS\$NtUninstallKB945553$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB946026)-->"C:\WINDOWS\$NtUninstallKB946026$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB947864)-->"C:\WINDOWS\$NtUninstallKB947864$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB948590)-->"C:\WINDOWS\$NtUninstallKB948590$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB948881)-->"C:\WINDOWS\$NtUninstallKB948881$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB950749)-->"C:\WINDOWS\$NtUninstallKB950749$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB950759)-->"C:\WINDOWS\$NtUninstallKB950759$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB953838)-->"C:\WINDOWS\$NtUninstallKB953838$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
    Senselang-->C:\Program Files\Senselang\uninstall.exe
    Skypeâ„¢ 3.8-->MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
    Smart Guardian-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\ITE\Smart Guardian\Uninst.isu"
    Spybot - Search & Destroy 1.4-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
    Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins001.exe"
    SpywareBlaster v3.2-->"C:\Program Files\SpywareBlaster\unins000.exe"
    SUPERAntiSpyware Free Edition-->MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}
    UK Driving Secrets Guide-->"C:\Program Files\UK Driving Secrets Guide\unins000.exe"
    Ulead Photo Express 2.0 SE-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\Uninst.isu" -c"C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\IS32Inst.dll"
    Update for Windows XP (KB894391)-->"C:\WINDOWS\$NtUninstallKB894391$\spuninst\spuninst.exe"
    Update for Windows XP (KB898461)-->"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
    Update for Windows XP (KB900485)-->"C:\WINDOWS\$NtUninstallKB900485$\spuninst\spuninst.exe"
    Update for Windows XP (KB908531)-->"C:\WINDOWS\$NtUninstallKB908531$\spuninst\spuninst.exe"
    Update for Windows XP (KB910437)-->"C:\WINDOWS\$NtUninstallKB910437$\spuninst\spuninst.exe"
    Update for Windows XP (KB911280)-->"C:\WINDOWS\$NtUninstallKB911280$\spuninst\spuninst.exe"
    Update for Windows XP (KB916595)-->"C:\WINDOWS\$NtUninstallKB916595$\spuninst\spuninst.exe"
    Update for Windows XP (KB920872)-->"C:\WINDOWS\$NtUninstallKB920872$\spuninst\spuninst.exe"
    Update for Windows XP (KB922582)-->"C:\WINDOWS\$NtUninstallKB922582$\spuninst\spuninst.exe"
    Update for Windows XP (KB927891)-->"C:\WINDOWS\$NtUninstallKB927891$\spuninst\spuninst.exe"
    Update for Windows XP (KB929338)-->"C:\WINDOWS\$NtUninstallKB929338$\spuninst\spuninst.exe"
    Update for Windows XP (KB930916)-->"C:\WINDOWS\$NtUninstallKB930916$\spuninst\spuninst.exe"
    Update for Windows XP (KB931836)-->"C:\WINDOWS\$NtUninstallKB931836$\spuninst\spuninst.exe"
    Update for Windows XP (KB933360)-->"C:\WINDOWS\$NtUninstallKB933360$\spuninst\spuninst.exe"
    Update for Windows XP (KB938828)-->"C:\WINDOWS\$NtUninstallKB938828$\spuninst\spuninst.exe"
    Update for Windows XP (KB942763)-->"C:\WINDOWS\$NtUninstallKB942763$\spuninst\spuninst.exe"
    Update for Windows XP (KB942840)-->"C:\WINDOWS\$NtUninstallKB942840$\spuninst\spuninst.exe"
    Update for Windows XP (KB946627)-->"C:\WINDOWS\$NtUninstallKB946627$\spuninst\spuninst.exe"
    Update for Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
    USB2.0 PC Camera-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{75438C0E-9925-412E-AD85-D0E71C6CE2ED}\Setup.exe" -l0x9
    VIA Rhine-Family Fast Ethernet Adapter-->Rundll32.exe vuins32.dll,vuins32Ex $Rhine $VIA
    Windows Installer 3.1 (KB893803)-->"C:\WINDOWS\$MSI31Uninstall_KB893803$\spuninst\spuninst.exe"
    Windows Media Format Runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
    Windows Media Player 10-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
    Windows XP Hotfix - KB834707-->C:\WINDOWS\$NtUninstallKB834707$\spuninst\spuninst.exe
    Windows XP Hotfix - KB867282-->C:\WINDOWS\$NtUninstallKB867282$\spuninst\spuninst.exe
    Windows XP Hotfix - KB873333-->C:\WINDOWS\$NtUninstallKB873333$\spuninst\spuninst.exe
    Windows XP Hotfix - KB873339-->C:\WINDOWS\$NtUninstallKB873339$\spuninst\spuninst.exe
    Windows XP Hotfix - KB885250-->C:\WINDOWS\$NtUninstallKB885250$\spuninst\spuninst.exe
    Windows XP Hotfix - KB885835-->C:\WINDOWS\$NtUninstallKB885835$\spuninst\spuninst.exe
    Windows XP Hotfix - KB885836-->C:\WINDOWS\$NtUninstallKB885836$\spuninst\spuninst.exe
    Windows XP Hotfix - KB885884-->C:\WINDOWS\$NtUninstallKB885884$\spuninst\spuninst.exe
    Windows XP Hotfix - KB886185-->C:\WINDOWS\$NtUninstallKB886185$\spuninst\spuninst.exe
    Windows XP Hotfix - KB887472-->C:\WINDOWS\$NtUninstallKB887472$\spuninst\spuninst.exe
    Windows XP Hotfix - KB887742-->C:\WINDOWS\$NtUninstallKB887742$\spuninst\spuninst.exe
    Windows XP Hotfix - KB888113-->C:\WINDOWS\$NtUninstallKB888113$\spuninst\spuninst.exe
    Windows XP Hotfix - KB888302-->C:\WINDOWS\$NtUninstallKB888302$\spuninst\spuninst.exe
    Windows XP Hotfix - KB890047-->C:\WINDOWS\$NtUninstallKB890047$\spuninst\spuninst.exe
    Windows XP Hotfix - KB890175-->C:\WINDOWS\$NtUninstallKB890175$\spuninst\spuninst.exe
    Windows XP Hotfix - KB890859-->"C:\WINDOWS\$NtUninstallKB890859$\spuninst\spuninst.exe"
    Windows XP Hotfix - KB890923-->"C:\WINDOWS\$NtUninstallKB890923$\spuninst\spuninst.exe"
    Windows XP Hotfix - KB891781-->C:\WINDOWS\$NtUninstallKB891781$\spuninst\spuninst.exe
    Windows XP Hotfix - KB893066-->"C:\WINDOWS\$NtUninstallKB893066$\spuninst\spuninst.exe"
    Windows XP Hotfix - KB893086-->"C:\WINDOWS\$NtUninstallKB893086$\spuninst\spuninst.exe"
    Windows XP Service Pack 2-->C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe
    WinZip-->"C:\Program Files\WinZip\WINZIP32.EXE" /uninstall
    Wireless PCI Card Configuration Utility-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5C6956F3-B586-4674-BCD0-CCF7EC1DF766}\Setup.exe" -l0x9
    XMLog-->C:\WINDOWS\st6unst.exe -n "c:\mlog\ST6UNST.UNS"
    Yahoo! Internet Mail-->C:\WINDOWS\system32\regsvr32 /u /s C:\PROGRA~1\Yahoo!\Common\ymmapi.dll
    Yahoo! Toolbar-->C:\PROGRA~1\Yahoo!\Common\unyt.exe

    ======Security center information======

    FW: Norton Internet Worm Protection (disabled)

    ======Environment variables======

    "ComSpec"=%SystemRoot%\system32\cmd.exe
    "Path"=C:\Program Files\PC Connectivity Solution\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\QuickTime\QTSystem\
    "windir"=%SystemRoot%
    "OS"=Windows_NT
    "PROCESSOR_ARCHITECTURE"=x86
    "PROCESSOR_LEVEL"=6
    "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 8 Stepping 1, AuthenticAMD
    "PROCESSOR_REVISION"=0801
    "NUMBER_OF_PROCESSORS"=1
    "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
    "TEMP"=%SystemRoot%\TEMP
    "TMP"=%SystemRoot%\TEMP
    "FP_NO_HOST_CHECK"=NO
    "CLASSPATH"=.;C:\Program Files\Java\jre1.5.0_01\lib\ext\QTJava.zip
    "QTJAVA"=C:\Program Files\Java\jre1.5.0_01\lib\ext\QTJava.zip



    Thanks

    Matt
  • edited November 2008
    Information

    Registry Cleaners

    Re. Registry Mechanic 5.1

    I don't personally recommend the use of ANY registry cleaners.
    Here is an excerpt from a discussion on regcleaners
    Most reg cleaners aren't "bad" as such, but they aren't perfect and even the best have been known to cause problems.
    The point we are trying to make is that the risk of using one far outweighs any benefit.
    If it does work perfectly you will not see any difference
    If it doesn't work properly you may end up with an expensive doorstop.
    http://forums.whatthetech.com/Regcleaner_t42862.html



    Step 1


    Malwarebytes' Anti-Malware

    Please download Malwarebytes' Anti-Malware to your desktop.

    • Double-click mbam-setup.exe and follow the prompts to install the program.
    • At the end, be sure a checkmark is placed next to
      • Update Malwarebytes' Anti-Malware
      • and Launch Malwarebytes' Anti-Malware
    • then click Finish.
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select Perform full scan, then click Scan.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Be sure that everything is checked, and click Remove Selected.
    • When completed, a log will open in Notepad. please copy and paste the log into your next reply
      • If you accidently close it, the log file is saved here and will be named like this:
      • C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt



    Step 2


    Download ComboFix from one of these locations:

    Link 1
    Link 2
    Link 3

    * IMPORTANT !!! Save ComboFix.exe to your Desktop


    • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
      See HERE for help
    • Double click on ComboFix.exe & follow the prompts.

    • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

    • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.


    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

    RcAuto1.gif


    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    whatnext.png


    Click on Yes, to continue scanning for malware.

    When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


    Step 3


    Remove Programs

    Older versions of some programs have vulnerabilities that malware can use to infect your system.

    Now click Start---Control Panel. Double click Add or Remove Programs (XP) / Programs and Features (Vista) . If any of the following programs are listed there,
    click on the program to highlight it, and click on remove.
    • Adobe Reader 8 << Please see below for updating Adobe
    • J2SE Runtime Environment 5.0 Update 1
      Java(TM) 6 Update 2
      Java(TM) 6 Update 3
    Now close the Control Panel.


    Step 4

    Logs/Information to Post in Reply
    Please post the following logs/Information in your reply
    • MalwareBytes Log
    • Combofix Log
    • A Fresh HJT Log ( if HJT still doesn't run, use RSIT again )
    • How are things running now ?




    Additional Notes


    Your Adobe Acrobat Reader is out of date. Older versions have vulnerabilities that malware can use to infect your system.

    Adobe Reader is a large program and uses unnecessary space.
    If you prefer a smaller program you can get Foxit 2.0 from http://www.foxitsoftware.com/pdf/rd_intro.php << Recommended

    There is a newer version of Adobe Acrobat Reader available.
    • Please go to this link Adobe Acrobat Reader Download Link
    • Click Download
    • On the right Untick Adobe Phototshop Album Starter Edition if you do not wish to include this in the installation.
    • Click the Continue button
    • Click Run, and click Run again
    • Next click the Install Now button and follow the on screen prompts


    When the installation is complete go to Add/Remove Programs and uninstall all previous versions.
  • edited November 2008
    Dear Katana,

    Thank you for your advice.
    On Step 1 that has been completed and the PC is now not suffering from the same problems.

    The log for the mailbyte program is attached.

    I have aslo downloaded a new Adobe Reader 9.

    I am not sure whther I now need to do the Combi fix.

    I am not sure what antu virus porgrams I have active. I have no bought software.

    There is an old version of pc illin 2002 that seems to pop up every now and again but no updates are uploaded. ot surewhatelese I have so not sure what and how to turn off.

    thank you

    Matt

    alwarebytes' Anti-Malware 1.30
    Database version: 1411
    Windows 5.1.2600 Service Pack 2

    19/11/2008 19:00:45
    mbam-log-2008-11-19 (19-00-44).txt

    Scan type: Full Scan (C:\|D:\|)
    Objects scanned: 112005
    Time elapsed: 1 hour(s), 40 minute(s), 51 second(s)

    Memory Processes Infected: 4
    Memory Modules Infected: 4
    Registry Keys Infected: 45
    Registry Values Infected: 7
    Registry Data Items Infected: 2
    Folders Infected: 5
    Files Infected: 269

    Memory Processes Infected:
    C:\Documents and Settings\Matt\Application Data\gadcom\gadcom.exe () -> Unloaded process successfully.
    C:\Program Files\GetPack\GetPack24.exe (Trojan.Agent) -> Unloaded process successfully.
    C:\WINDOWS\Fonts\svchost.exe (Trojan.Agent) -> Unloaded process successfully.
    C:\Documents and Settings\All Users\Application Data\ipd\tray.exe (Trojan.Agent) -> Unloaded process successfully.

    Memory Modules Infected:
    C:\WINDOWS\system32\uydianye.dll (Trojan.Vundo.H) -> Delete on reboot.
    C:\WINDOWS\system32\xxyawuVM.dll (Trojan.Vundo.H) -> Delete on reboot.
    C:\WINDOWS\system32\sqnnhy.dll (Trojan.Vundo) -> Delete on reboot.
    C:\WINDOWS\system32\tuvVPfgf.dll (Trojan.Vundo.H) -> Delete on reboot.

    Registry Keys Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4cafaf0c-c38f-43c1-8080-390e776254de} (Trojan.Vundo.H) -> Delete on reboot.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tuvvpfgf (Trojan.Vundo.H) -> Delete on reboot.
    HKEY_CLASSES_ROOT\CLSID\{4cafaf0c-c38f-43c1-8080-390e776254de} (Trojan.Vundo.H) -> Delete on reboot.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{85b59c84-bb49-4ad1-b45a-576daf69571e} (Trojan.Vundo.H) -> Delete on reboot.
    HKEY_CLASSES_ROOT\CLSID\{85b59c84-bb49-4ad1-b45a-576daf69571e} (Trojan.Vundo.H) -> Delete on reboot.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{dceb2f56-705d-4349-867a-740a3e80a86a} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{dceb2f56-705d-4349-867a-740a3e80a86a} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{514a5c49-0c7d-42c3-a71b-38864a269b7a} (Trojan.BHO.H) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{514a5c49-0c7d-42c3-a71b-38864a269b7a} (Trojan.BHO.H) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\bho_myjavacore.mjcore (Trojan.BHO) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\bho_myjavacore.mjcore.1 (Trojan.BHO) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\ipb.band (Trojan.BHO) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\TypeLib\{63114106-3276-4086-aaec-fe2cb7c1be0f} (Trojan.BHO) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Interface\{bdc8b76a-50d4-41e1-a03a-32f18fc324f4} (Trojan.BHO) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Interface\{c8280a80-5219-42c0-ad72-afe645e768e4} (Trojan.BHO) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{000051af-07e2-461b-ba37-a2af7e652e7d} (Trojan.BHO) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000051af-07e2-461b-ba37-a2af7e652e7d} (Trojan.BHO) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\ipb.band.1 (Trojan.BHO) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\mywebsearch.htmlpanel (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\mywebsearch.htmlpanel.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\mywebsearch.pseudotransparentplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\mywebsearch.pseudotransparentplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Interface\{17e44256-51e0-4d46-a0c8-44e80ab4ba5b} (Trojan.BHO) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{4cab59b4-55a3-4737-9fd5-b93c6430bf76} (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4cab59b4-55a3-4737-9fd5-b93c6430bf76} (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Typelib\{e0f01490-dcf3-4357-95aa-169a8c2b2190} (Trojan.BHO) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\AppID\{80ef304a-b1c4-425c-8535-95ab6f1eefb8} (Trojan.BHO) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\bambanner (Adware.Adrotator) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\icheck (Trojan.Agent) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\AppID\BHO_MyJavaCore.DLL (Trojan.BHO) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\GetPack (Adware.Agent) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Delete on reboot.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Delete on reboot.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\IProxyProvider (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Delete on reboot.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31b35a87-c9a2-0132-5713-431be04c5e51} (Adware.BHO) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{31b35a87-c9a2-0132-5713-431be04c5e51} (Adware.BHO) -> Quarantined and deleted successfully.

    Registry Values Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cc4c48c9 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cc4c48c9 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\gadcom () -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{4cafaf0c-c38f-43c1-8080-390e776254de} (Trojan.Vundo.H) -> Delete on reboot.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\getpack24 (Trojan.Agent) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\bmcf7f7b55 (Trojan.Agent) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Host Process (Worm.IRCBot) -> Quarantined and deleted successfully.

    Registry Data Items Infected:
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\xxyawuvm -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\xxyawuvm -> Delete on reboot.

    Folders Infected:
    C:\WINDOWS\Fonts\' (Trojan.Agent) -> Files: 40753 -> Quarantined and deleted successfully.
    C:\Program Files\GetPack (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\Program Files\iCheck (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\Program Files\Mjcore (Trojan.BHO) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Matt\Application Data\gadcom (Trojan.Agent) -> Quarantined and deleted successfully.

    Files Infected:
    C:\WINDOWS\system32\tuvVPfgf.dll (Trojan.Vundo.H) -> Delete on reboot.
    C:\WINDOWS\system32\xxyawuVM.dll (Trojan.Vundo.H) -> Delete on reboot.
    C:\WINDOWS\system32\MVuwayxx.ini (Trojan.Vundo.H) -> Delete on reboot.
    C:\WINDOWS\system32\MVuwayxx.ini2 (Trojan.Vundo.H) -> Delete on reboot.
    C:\WINDOWS\system32\sqnnhy.dll (Trojan.Vundo.H) -> Delete on reboot.
    C:\WINDOWS\system32\axidojnj.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\jnjodixa.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\cexfmkfs.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\sfkmfxec.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\dgfwvkxs.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\sxkvwfgd.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\drpbbhij.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\jihbbprd.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\dujjqurf.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\fruqjjud.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\ebfumnpn.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\npnmufbe.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\feayimsa.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\asmiyaef.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\galwadum.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\mudawlag.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\gdbwfxmo.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\omxfwbdg.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\gekbqgbd.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\dbgqbkeg.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\hfatsafq.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\qfastafh.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\hlttsotg.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\gtosttlh.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\hqjunpro.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\orpnujqh.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\ignbrxpn.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\npxrbngi.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\jskuftrq.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\qrtfuksj.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\jwefcjvt.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\tvjcfewj.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\kcepnwqb.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\bqwnpeck.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\ldvedxwx.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\xwxdevdl.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\ltoylxfn.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\nfxlyotl.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\mihlkwkd.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\dkwklhim.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\mwvpojgl.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\lgjopvwm.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\mxvabgxt.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\txgbavxm.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\nqehuwuy.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\yuwuheqn.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\nuafemee.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\eemefaun.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\odrpfoun.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\nuofprdo.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\oocsnwrt.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\trwnscoo.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\ootmegkx.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\xkgemtoo.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\pabljbrv.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\vrbjlbap.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\pbwhvyrf.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\fryvhwbp.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\qghqpbte.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\etbpqhgq.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\rbjvsevr.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\rvesvjbr.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\saqyrfye.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\eyfryqas.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\ttawgawf.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\fwagwatt.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\tudvpbuc.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\cubpvdut.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\uydianye.dll (Trojan.Vundo.H) -> Delete on reboot.
    C:\WINDOWS\system32\eynaidyu.ini (Trojan.Vundo.H) -> Delete on reboot.
    C:\WINDOWS\system32\vxrqqsmc.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\cmsqqrxv.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\wkmopagr.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\rgapomkw.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\xwjtgvix.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\xivgtjwx.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\kkknikjo.dll (Trojan.BHO.H) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Matt\Application Data\gadcom\gadcom.exe () -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\ipd\ipb.dll (Trojan.BHO) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\cwqjyhge.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\Program Files\Mjcore\Mjcore.dll (Trojan.BHO) -> Quarantined and deleted successfully.
    C:\onoes.exe (Backdoor.Rbot) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Matt\Local Settings\Temp\__9.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Matt\Local Settings\Temporary Internet Files\Content.IE5\Q9ATUVWF\nd82m0[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1033\A0114571.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1033\A0115703.EXE (Backdoor.Rbot) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1033\A0115706.EXE (Adware.CommAd) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1033\A0115710.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1035\A0116794.exe (Worm.P2P) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1035\A0116796.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1035\A0116831.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1091\A0124139.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1044\A0118676.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1044\A0118725.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1048\A0118872.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1048\A0118874.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1050\A0119036.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1050\A0119060.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1051\A0119094.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1052\A0119133.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1053\A0119178.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1054\A0119228.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1055\A0119273.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1056\A0119332.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1056\A0119353.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1057\A0119427.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1057\A0119441.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1058\A0119487.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1060\A0119598.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1060\A0119604.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1061\A0119665.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1061\A0119618.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1061\A0119622.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1062\A0119713.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1063\A0119750.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1064\A0119790.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1064\A0119804.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1066\A0120804.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1066\A0120790.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1066\A0120827.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1067\A0120885.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1068\A0120948.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1068\A0121041.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1069\A0121103.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1070\A0122085.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1070\A0122086.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1070\A0122121.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\WINDOWS\stfMeane1000106.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\psqsdiga.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\puaqryfy.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\qeslpgiw.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\qjtnxvrl.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\qoMcyWQK.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\qoMggdBr.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\cneilpaw.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\affeok.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\aurdzx.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\cadyibhq.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\cbXOGYPF.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\cbXPgecc.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\ccnqsa.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\dldthdys.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\dshaun.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\dsmrpoiv.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\efcCvWOF.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\erktkrnv.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\erpinkwn.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\ezxjlr.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\faoepf.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\fbclifvu.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\fcbhaw.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\fccaBSmM.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\feawsa.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\gdjhheyq.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\gegigt.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\gfevwmrb.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\gogmfacr.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\hgGawVNe.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\ljJAPGVM.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\ljJAQKcA.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\jkkJbxVm.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\jqfpcefj.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\jspill.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\mbxxxgyq.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\mnjuox.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\opnnkkJY.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\oscddw.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\otzprp.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\ssqQgHaw.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\ssuurqdw.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\tbdiit.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\tcgpvm.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\tebjqsiw.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\tibisb.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\vmkrxmqk.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\vrjjdv.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\wfyjnl.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\wgrblise.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\wianxk.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\uumnnkie.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\uvqfiawb.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\ckhqcmpm.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\ckxnbjck.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\kdcgelwx.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\khcldbfw.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\klosngpt.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\rbbfbdyw.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\rdhtgalm.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\svnsbded.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\vtUlKEXP.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\vyxgecru.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\bcplejrq.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\biclcikf.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\bmmvoaqs.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\boeeoaof.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\wwmpfu.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\xdytao.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\xfmfps.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\yabfleqi.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\yayaBSkk.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\hxdunt.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\hxkwup.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\hxrbjo.dll (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\hycdpjgf.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\urqRHyvS.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\uhbmkvvq.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\ujowss.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\ukoyta.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\lprrgsoa.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\lugysidl.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\lwqaplmg.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\pmnnKARj.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\pmooihhn.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\jeplvd.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\mwfjjbow.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\nblnlepl.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\ddcAsppM.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\ddcCRKbC.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\ddcDwtsp.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\ddcYpmnk.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\ddcYsSJa.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\fkjgssmj.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\dzrinpxdvrfclic.exe (Adware.Adrotator) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\yayyXOFX.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\yllppl.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\yqvboa.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\yuarhoff.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\cusxcf.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\espatnsc.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\haoarlut.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\kuotutdx.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\lagcldut.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\lfgcqktg.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\qsxydouu.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\qwsgfe.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\juufpkmh.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\tuvVLdcD.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\tuvWmLBU.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\tuvWmNhG.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\tvsiag.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\twerkoey.dll (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\twjnvmcy.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\EV02\EV022328.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\Program Files\GetPack\dictame.gz (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\Program Files\GetPack\GetPack24.exe (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\Program Files\GetPack\trgtame.gz (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\Program Files\iCheck\Uninstall.exe (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\mcrh.tmp (Malware.Trace) -> Quarantined and deleted successfully.
    C:\WINDOWS\cookies.ini (Malware.Trace) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\blnaetmn.dll (Trojan.Agent) -> Delete on reboot.
    C:\WINDOWS\system32\pac.txt (Malware.Trace) -> Quarantined and deleted successfully.
    C:\WINDOWS\Fonts\Setup.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\Program Files\outlook\p.zip (Worm.Alcra) -> Quarantined and deleted successfully.
    C:\WINDOWS\Fonts\svchost.exe (Worm.IRCBot) -> Quarantined and deleted successfully.
    C:\WINDOWS\Fonts\acrsecB.fon (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\Fonts\acrsecI.fon (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\pskt.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\BMcf7f7b55.xml (Trojan.Vundo) -> Delete on reboot.
    C:\WINDOWS\BMcf7f7b55.txt (Trojan.Vundo) -> Delete on reboot.
    C:\Program Files\SETUP.EXE (Rogue.Installer) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Matt\Application Data\RBXML550.dll (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\ipd\tray.exe (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\smdat32m.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\yexehfqmltzpjph.dll (Adware.BHO) -> Quarantined and deleted successfully.
  • edited November 2008
    I'm afraid I have unpleasant news for you. You have evidence of at least one Very Dangerous infection on this machine.

    It allow outsiders COMPLETE access to every keystroke, account, and password you use while on this machine, and complete access to any other data present...
    IF this computer has been used for any kind of important data, my best recommendation is to Disconnect from Internet, Re-Format the entire drive and re-install your Operating system and Applications.

    We can likely clean the infected files off the computer, and if you wish we will attempt to do so, but we cannot be sure that the infection didn't do something to your system to reduce the system security. In that instance, even after removal of the infection, you could be subject to another attack or takeover as soon as you re-connect to the Internet.

    The Decision Whether to ReFormat or Not should be based on:
    • The use of the computer - this is the primary factor in the decision whether to re-format and re-install, or just disinfect.
    • The variety of malware - this influences the decision on whether to re-format and re-install, or just disinfect. IN THIS CASE we have the worst kind.

    If the Computer has been used for any important data, you are strongly advised to do the following, immediately:
    • Disconnect the infected computer from the internet and from any networked computers until the computer can be cleaned.
    • Back up all important data on the machine. Do not back up any Applications (programs). Those should be re-installed from the original source CDs or websites.
    • If you have ever used this computer for shopping, banking, or any transactions relating to your financial well being:
      Call all of your banks, credit card companies, and financial institutions, informing them that you may be a victim of identity theft, and to put a watch on your accounts or change all your account numbers.
    • From a clean computer, change ALL your online passwords -- for ISP login, email, banks, financial accounts, PayPal, eBay, online companies, and any online forums or groups you belong to.
    • DO NOT change passwords or do any transactions while using the infected computer because the attacker will get the new password and transaction information.
    • Take any other steps you think appropriate for an attempted identity theft.

    While you are deciding whether to ReFormat and Re-Install, a useful link is here: http://www.dslreports.com/faq/10063
    Please let me know what you decide.
  • edited November 2008
    OK thanks. Please take me through how to get rid of it ! I have no disks for any porgrams that rae on the PC
  • edited November 2008
    Run ComboFix using these instructions:

    Click the Windows 'Start' button > Select 'Run' - then copy/paste the following bolded text into the run box & click OK.

    "%userprofile%\desktop\combofix.exe" /killall

    When finished, it shall produce a log for you. Post that log in your next reply.

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

    There is an old version of pc illin 2002 that seems to pop up every now and again but no updates are uploaded
    If you do not have a current subscription for PC-cillin 2002, then please do the following


    Remove Programs

    Older versions of some programs have vulnerabilities that malware can use to infect your system.

    Now click Start---Control Panel. Double click Add or Remove Programs (XP) / Programs and Features (Vista) . If any of the following programs are listed there,
    click on the program to highlight it, and click on remove.
    • PC-cillin 2002
    Now close the Control Panel.


    Use an AntiVirus Software - It is very important that you have anti-virus software running on your machine.
    This alone can save you a lot of trouble with malware in the future.
    Free AV list ( Home users only)
    Avira AntiVir
    Avast

    Update your AntiVirus Software - It is imperitive that you update your Antivirus software at least once a week.
    If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

    Antivirus is a MUST
  • edited November 2008
    Thank you.

    I will download the combifix presumably as per your instructions in one of the earlier posts, then run as suggested above.

    I have deleted PC illin and downloaed and am now running the free antivirus software you kindly highlighted.

    I have also chnged all banking and financial based passwords plus persoanl email passwords and alerted all relevant parties as to the security threat. I did this in termso fpassword chnages from another PC.

    Could you tell me when this dnagerous infection was added ie how long have I bben at risk for ?

    I will ensure hat no confodential or ne password datat is entred via the infected PC.
    Will reply to log request within 24 hours.

    Thank you for the continued support. MAtt
  • edited November 2008
    mattami wrote:
    Could you tell me when this dnagerous infection was added ie how long have I bben at risk for ?

    There is no way of telling how long it has been there from the logs, we may get an idea when you run Combofix.
  • edited November 2008
    Hi

    Ok here is the Combofix log as completed after step 2 of your original post / advice

    ComboFix 08-11-20.02 - Matt 2008-11-21 16:41:59.1 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.57 [GMT 0:00]
    Running from: c:\documents and settings\Matt\Desktop\ComboFix.exe
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\documents and settings\Matt\Application Data\RBInternetEncodings550.dll
    c:\documents and settings\Matt\Application Data\RBShell550.dll
    c:\documents and settings\Matt\Local Settings\Temporary Internet Files\fbk.sts
    c:\program files\outlook
    c:\temp\1cb
    c:\temp\1cb\syscheck.log
    C:\win.txt
    c:\windows\a3kebook.ini
    c:\windows\akebook.ini
    c:\windows\ANS2000.INI
    c:\windows\Fonts\a.zip
    c:\windows\system32\akhndy.dll
    c:\windows\system32\arcqwg.dll
    c:\windows\system32\awtttsrS.dll
    c:\windows\system32\bvseespe.dll
    c:\windows\system32\byXNfFuU.dll
    c:\windows\system32\byXPJBTl.dll
    c:\windows\system32\byXQIBsQ.dll
    c:\windows\system32\cbXOIxvt.dll
    c:\windows\system32\cbXRKDSK.dll
    c:\windows\system32\cimqbxoy.dll
    c:\windows\system32\cpupfcyn.ini
    c:\windows\system32\cqmozv.dll
    c:\windows\system32\dbavjtvw.ini
    c:\windows\system32\deronsao.ini
    c:\windows\system32\dgxsxeaj.ini
    c:\windows\system32\djyesm.dll
    c:\windows\system32\dvndljfd.ini
    c:\windows\system32\dvzywv.dll
    c:\windows\system32\eangcaco.dll
    c:\windows\system32\eapedoog.ini
    c:\windows\system32\EV02
    c:\windows\system32\f1
    c:\windows\system32\f1\uPA34v10.exe
    c:\windows\system32\felcry.dll
    c:\windows\system32\frkoodfm.dll
    c:\windows\system32\fvdwshxf.ini
    c:\windows\system32\fwgpin.dll
    c:\windows\system32\geBuRJab.dll
    c:\windows\system32\gectdwhu.dll
    c:\windows\system32\gEwvUlKE.dll
    c:\windows\system32\gmkhao.dll
    c:\windows\system32\gplmgr.dll
    c:\windows\system32\hgGayvuR.dll
    c:\windows\system32\hgGvspOh.dll
    c:\windows\system32\hgGvtQKa.dll
    c:\windows\system32\hgGvtSjK.dll
    c:\windows\system32\hgGvuTKc.dll
    c:\windows\system32\hiraimhm.dll
    c:\windows\system32\httgwujx.ini
    c:\windows\system32\ibjnuwnx.dll
    c:\windows\system32\iifeeEtT.dll
    c:\windows\system32\iiffDSKD.dll
    c:\windows\system32\iifgHabY.dll
    c:\windows\system32\ikpruvcs.dll
    c:\windows\system32\itunah.dll
    c:\windows\system32\ivhemx.dll
    c:\windows\system32\jcqfgobi.ini
    c:\windows\system32\jhcwyjgs.dll
    c:\windows\system32\jkkLEUKB.dll
    c:\windows\system32\jkkLEULB.dll
    c:\windows\system32\kdonmtfs.dll
    c:\windows\system32\khfFXrQH.dll
    c:\windows\system32\khfGwVOf.dll
    c:\windows\system32\kjgbqb.dll
    c:\windows\system32\kkkfagsk.dll
    c:\windows\system32\ljJCuSIB.dll
    c:\windows\system32\ljJCvUKa.dll
    c:\windows\system32\ljJDSKCs.dll
    c:\windows\system32\ljJDWQJB.dll
    c:\windows\system32\mlJApPHb.dll
    c:\windows\system32\mlJAsQii.dll
    c:\windows\system32\mlJYqRIa.dll
    c:\windows\system32\mlJYspND.dll
    c:\windows\system32\mqwvobxo.ini
    c:\windows\system32\mrfkrgpr.ini
    c:\windows\system32\MSINET.oca
    c:\windows\system32\MVuwayxx.ini
    c:\windows\system32\neakklxj.dll
    c:\windows\system32\nnnmmljJ.dll
    c:\windows\system32\nnnoNhhi.dll
    c:\windows\system32\NUBKlUtv.ini
    c:\windows\system32\nvciykwo.dll
    c:\windows\system32\nyrxlt.dll
    c:\windows\system32\ogljwfke.dll
    c:\windows\system32\OIUUYG.DLL
    c:\windows\system32\opnkjJcD.dll
    c:\windows\system32\opnkjJyA.dll
    c:\windows\system32\opnlIxUL.dll
    c:\windows\system32\opnnmJdd.dll
    c:\windows\system32\opnonnOG.dll
    c:\windows\system32\pmnmnKEu.dll
    c:\windows\system32\puvqxunw.dll
    c:\windows\system32\pyomvklb.ini
    c:\windows\system32\qmcicjpt.dll
    c:\windows\system32\qoMdARKC.dll
    c:\windows\system32\qoMdDuuT.dll
    c:\windows\system32\qoMeCrqr.dll
    c:\windows\system32\qoMfebxw.dll
    c:\windows\system32\qupkcyhc.dll
    c:\windows\system32\rcwmdmtk.dll
    c:\windows\system32\rqRIyVmL.dll
    c:\windows\system32\rqRJCRJc.dll
    c:\windows\system32\RtAIQXyb.ini
    c:\windows\system32\sbevybfp.ini
    c:\windows\system32\skbewwoa.dll
    c:\windows\system32\squytaqv.ini
    c:\windows\system32\ssqNHbYP.dll
    c:\windows\system32\ssqnkLFy.dll
    c:\windows\system32\stynljxm.ini
    c:\windows\system32\trvgwlfk.ini
    c:\windows\system32\tuvcrnxj.dll
    c:\windows\system32\tuvSliIB.dll
    c:\windows\system32\tuvTnOff.dll
    c:\windows\system32\tuvVNFWo.dll
    c:\windows\system32\udnxux.dll
    c:\windows\system32\uhmdkion.ini
    c:\windows\system32\urqPgddC.dll
    c:\windows\system32\vCJiQqru.ini
    c:\windows\system32\vhmbml.dll
    c:\windows\system32\vtUlLBtS.dll
    c:\windows\system32\vtUnmMdA.dll
    c:\windows\system32\vtUnnmMC.dll
    c:\windows\system32\wsvrxc.dll
    c:\windows\system32\wvUkJaxY.dll
    c:\windows\system32\wvUmkkhf.dll
    c:\windows\system32\wxhlbptd.dll
    c:\windows\system32\wxmxvjfp.ini
    c:\windows\system32\xayJknmp.ini
    c:\windows\system32\xhxldjib.dll
    c:\windows\system32\xugjwb.dll
    c:\windows\system32\xxyawuVM.dll
    c:\windows\system32\xxyvvSmM.dll
    c:\windows\system32\xxyxWOfd.dll
    c:\windows\system32\yayvSjiF.dll
    c:\windows\system32\yayvSlMD.dll
    c:\windows\system32\yfisxdbs.ini
    c:\windows\system32\ynewjq.dll
    c:\windows\system32\ypskil.dll
    c:\windows\system32\ywswyruc.ini
    c:\windows\system32\zejzlb.dll

    .
    ((((((((((((((((((((((((( Files Created from 2008-10-21 to 2008-11-21 )))))))))))))))))))))))))))))))
    .

    2008-11-21 10:03 . 2008-11-21 10:03 <DIR> d
    c:\program files\Avira
    2008-11-21 10:03 . 2008-11-21 10:03 <DIR> d
    c:\documents and settings\All Users\Application Data\Avira
    2008-11-20 11:16 . 2008-11-20 11:16 <DIR> d
    c:\documents and settings\Matt\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
    2008-11-20 10:44 . 2008-11-20 10:44 <DIR> d
    c:\program files\Common Files\Adobe AIR
    2008-11-20 10:23 . 2008-11-20 10:50 <DIR> d
    c:\program files\NOS
    2008-11-20 10:23 . 2008-11-20 10:50 <DIR> d
    c:\documents and settings\All Users\Application Data\NOS
    2008-11-19 16:10 . 2008-11-19 16:10 <DIR> d
    c:\documents and settings\Matt\Application Data\Malwarebytes
    2008-11-19 16:10 . 2008-10-22 16:10 15,504 --a
    c:\windows\system32\drivers\mbam.sys
    2008-11-19 16:09 . 2008-11-19 16:10 <DIR> d
    c:\program files\Malwarebytes' Anti-Malware
    2008-11-19 16:09 . 2008-11-19 16:09 <DIR> d
    c:\documents and settings\All Users\Application Data\Malwarebytes
    2008-11-19 16:09 . 2008-10-22 16:10 38,496 --a
    c:\windows\system32\drivers\mbamswissarmy.sys
    2008-11-19 08:39 . 2008-11-19 08:39 465,920 --a
    c:\windows\system32\iesvcmon.exe
    2008-11-18 22:35 . 2008-11-18 22:36 <DIR> d
    C:\rsit
    2008-11-18 21:55 . 2008-11-18 21:55 41,472 --a
    c:\windows\system32\gfcnncad.dll
    2008-11-18 08:31 . 2008-11-18 08:31 <DIR> d
    c:\windows\system32\dPI02
    2008-11-18 08:31 . 2008-11-18 08:31 <DIR> d
    c:\temp\FT62
    2008-11-16 21:54 . 2008-11-16 21:54 85,504 --a
    c:\windows\system32\qlldefca.dll
    2008-11-15 21:53 . 2008-11-15 21:53 85,504 --a
    c:\windows\system32\eoumymtw.dll
    2008-11-14 21:53 . 2008-11-14 21:53 85,504 --a
    c:\windows\system32\eeovgobr.dll
    2008-11-13 21:51 . 2008-11-13 21:51 85,504 --a
    c:\windows\system32\mxfwkkfd.dll
    2008-11-12 21:50 . 2008-11-12 21:50 85,504 --a
    c:\windows\system32\lxsxlmpc.dll
    2008-11-11 10:04 . 2008-11-11 10:04 85,504 --a
    c:\windows\system32\bhlvrgmk.dll
    2008-11-09 09:29 . 2008-11-09 09:29 <DIR> d
    c:\windows\system32\sX3i02
    2008-11-09 09:29 . 2008-11-09 09:29 <DIR> d
    c:\temp\PRE45
    2008-11-07 16:41 . 2008-11-07 17:17 <DIR> d
    c:\program files\Safari
    2008-11-07 16:38 . 2008-11-07 16:39 <DIR> d
    c:\program files\Apple Software Update
    2008-11-05 22:01 . 2008-11-05 22:01 85,504 --a
    c:\windows\system32\tuivyemh.dll
    2008-11-05 10:02 . 2008-11-07 20:53 <DIR> d
    c:\program files\Opera
    2008-11-04 09:20 . 2008-11-04 09:20 <DIR> d
    c:\program files\Sun
    2008-11-03 21:59 . 2008-11-03 21:59 92,160 --a
    c:\windows\system32\salsyrsi.dll
    2008-11-02 21:58 . 2008-11-02 21:58 92,160 --a
    c:\windows\system32\jnxlhkps.dll
    2008-11-01 21:57 . 2008-11-01 21:57 92,160 --a
    c:\windows\system32\lyudeuvi.dll
    2008-10-31 21:54 . 2008-10-31 21:54 92,160 --a
    c:\windows\system32\ibebnxau.dll
    2008-10-30 22:56 . 2008-10-30 22:56 <DIR> d
    c:\program files\MSECache
    2008-10-30 21:54 . 2008-10-30 21:54 92,160 --a
    c:\windows\system32\ixowwcxh.dll
    2008-10-30 15:25 . 2008-10-30 15:25 <DIR> d
    c:\windows\system32\QI02
    2008-10-30 15:25 . 2008-10-30 15:25 <DIR> d
    c:\temp\NT32
    2008-10-29 21:53 . 2008-10-29 21:53 92,160 --a
    c:\windows\system32\fxkohtqt.dll
    2008-10-28 20:53 . 2008-10-28 20:53 92,160 --a
    c:\windows\system32\pdsjqvuc.dll
    2008-10-27 20:53 . 2008-10-27 20:53 92,160 --a
    c:\windows\system32\hmuttlem.dll
    2008-10-26 20:52 . 2008-10-26 20:52 92,160 --a
    c:\windows\system32\uqaorppx.dll
    2008-10-25 20:52 . 2008-10-25 20:52 92,160 --a
    c:\windows\system32\qtonefne.dll
    2008-10-24 20:49 . 2008-10-24 20:49 92,160 --a
    c:\windows\system32\ruxmpgys.dll
    2008-10-23 20:49 . 2008-10-23 20:49 92,160 --a
    c:\windows\system32\cobtxfto.dll
    2008-10-22 20:50 . 2008-10-22 20:50 92,160 --a
    c:\windows\system32\pvivhbma.dll
    2008-10-21 20:47 . 2008-10-21 20:47 92,160 --a
    c:\windows\system32\bbmjpsfc.dll

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-11-21 16:20
    d
    w c:\program files\TextAloud
    2008-11-20 11:15
    d
    w c:\program files\Common Files\Adobe
    2008-11-19 22:12
    d
    w c:\program files\Java
    2008-11-19 22:05
    d
    w c:\program files\Lavasoft
    2008-11-19 22:05
    d
    w c:\program files\Common Files\Wise Installation Wizard
    2008-11-19 18:49
    d
    w c:\documents and settings\All Users\Application Data\ipd
    2008-11-18 22:35
    d
    w c:\program files\Trend Micro
    2008-11-18 17:10
    d
    w c:\program files\SUPERAntiSpyware
    2008-11-17 21:46
    d
    w c:\documents and settings\Matt\Application Data\Skype
    2008-11-17 20:47
    d
    w c:\documents and settings\Matt\Application Data\skypePM
    2008-11-07 20:54
    d
    w c:\program files\Hewlett-Packard
    2008-11-07 16:45
    d
    w c:\documents and settings\Matt\Application Data\Apple Computer
    2008-10-30 15:23
    d
    w c:\program files\Lx_cats
    2008-10-25 20:56
    d
    w c:\documents and settings\Matt\Application Data\Pamela
    2008-10-25 20:55
    d
    w c:\program files\Pamela
    2008-10-19 20:46 92,160 ----a-w c:\windows\system32\jhgjqiwf.dll
    2008-10-18 20:45 92,160 ----a-w c:\windows\system32\fjtnqpxn.dll
    2008-10-17 20:44 92,160 ----a-w c:\windows\system32\tnempaoh.dll
    2008-10-16 20:45 92,160 ----a-w c:\windows\system32\lufrostj.dll
    2008-10-15 20:43 92,160 ----a-w c:\windows\system32\grielanq.dll
    2008-10-14 20:42 92,160 ----a-w c:\windows\system32\wqwecstt.dll
    2008-10-13 20:42 92,160 ----a-w c:\windows\system32\cfveenur.dll
    2008-10-12 08:56 92,160 ----a-w c:\windows\system32\vtgjivvm.dll
    2008-10-12 08:50 34,816 ----a-w c:\windows\system32\urqQiGWQ.dll
    2008-10-12 08:50 34,816 ----a-w c:\windows\system32\cbXPhhhG.dll
    2008-10-11 08:55 92,160 ----a-w c:\windows\system32\lrubxina.dll
    2008-10-11 07:28
    d
    w c:\program files\eQSO-PC-Client
    2008-10-10 08:58 114,688 ----a-w c:\windows\system32\niemicnp.dll
    2008-10-10 08:58 114,688 ----a-w c:\windows\system32\khxxto.dll
    2008-10-10 08:53 92,160 ----a-w c:\windows\system32\sihpxlef.dll
    2008-10-09 08:53 92,160 ----a-w c:\windows\system32\tvbackua.dll
    2008-10-08 08:56 115,200 ----a-w c:\windows\system32\ooitju.dll
    2008-10-08 08:56 115,200 ----a-w c:\windows\system32\hmkmvvit.dll
    2008-10-08 08:53 92,160 ----a-w c:\windows\system32\trwctuwa.dll
    2008-10-07 08:52 92,160 ----a-w c:\windows\system32\hyrwctts.dll
    2008-10-06 08:58 114,688 ----a-w c:\windows\system32\slzjti.dll
    2008-10-06 08:58 114,688 ----a-w c:\windows\system32\bxtpyjaw.dll
    2008-10-06 08:55 92,160 ----a-w c:\windows\system32\jmjhvwrc.dll
    2008-10-05 08:55 114,688 ----a-w c:\windows\system32\rjpehnoc.dll
    2008-10-05 08:55 114,688 ----a-w c:\windows\system32\pbeesf.dll
    2008-10-05 08:52 92,160 ----a-w c:\windows\system32\ofaxisfd.dll
    2008-10-05 08:50 105,984 ----a-w c:\windows\system32\nurrjeta.dll
    2008-10-03 21:45 92,160 ----a-w c:\windows\system32\pqbkjlxc.dll
    2008-10-03 21:45 115,200 ----a-w c:\windows\system32\qerjvxhh.dll
    2008-10-03 21:45 115,200 ----a-w c:\windows\system32\fsjlth.dll
    2008-10-03 21:42 104,960 ----a-w c:\windows\system32\mftbgoba.dll
    2008-10-03 21:40 92,160 ----a-w c:\windows\system32\gkiyvwrj.dll
    2008-10-03 07:42 34,304 ----a-w c:\windows\system32\fccddeCu.dll
    2008-10-03 07:42 34,304 ----a-w c:\windows\system32\byXPHwXp.dll
    2008-10-02 20:58 114,688 ----a-w c:\windows\system32\kiynpu.dll
    2008-10-02 20:58 114,688 ----a-w c:\windows\system32\ciejgtht.dll
    2008-10-02 20:56 105,472 ----a-w c:\windows\system32\ybkmtrfl.dll
    2008-10-02 20:55 92,160 ----a-w c:\windows\system32\qlvesiln.dll
    2008-10-02 06:47 34,304 ----a-w c:\windows\system32\xxyayYrR.dll
    2008-10-02 06:47 34,304 ----a-w c:\windows\system32\tuvVOFYR.dll
    2008-10-01 21:00 115,200 ----a-w c:\windows\system32\ljzggz.dll
    2008-10-01 21:00 115,200 ----a-w c:\windows\system32\ddsqwnbi.dll
    2008-10-01 20:55 34,304 ----a-w c:\windows\system32\wvUmnNGV.dll
    2008-10-01 20:55 34,304 ----a-w c:\windows\system32\geBuVOGx.dll
    2008-10-01 20:54 92,160 ----a-w c:\windows\system32\rfpuoalk.dll
    2008-10-01 20:53 105,472 ----a-w c:\windows\system32\hqwyrgoa.dll
    2008-09-30 20:19 92,160 ----a-w c:\windows\system32\iggdygjk.dll
    2008-09-30 20:19 105,472 ----a-w c:\windows\system32\banvvlld.dll
    2008-09-29 20:20 92,160 ----a-w c:\windows\system32\hspuirar.dll
    2008-09-29 20:19 105,472 ----a-w c:\windows\system32\rkireasp.dll
    2008-09-29 07:58 35,328 ----a-w c:\windows\system32\iifebBsQ.dll
    2008-09-29 07:58 35,328 ----a-w c:\windows\system32\awtusppq.dll
    2008-09-28 20:18 104,960 ----a-w c:\windows\system32\pnyttyla.dll
    2008-09-27 20:18 92,160 ----a-w c:\windows\system32\jggxoknu.dll
    2008-09-27 20:18 105,984 ----a-w c:\windows\system32\foxuyoxu.dll
    2008-09-27 07:39 34,304 ----a-w c:\windows\system32\jkkJyASm.dll
    2008-09-27 07:39 34,304 ----a-w c:\windows\system32\efcASiGA.dll
    2008-09-26 20:19 92,160 ----a-w c:\windows\system32\kewwaxud.dll
    2008-09-26 20:19 105,984 ----a-w c:\windows\system32\gpyxmyee.dll
    2008-09-26 06:48 34,304 ----a-w c:\windows\system32\iifgGYst.dll
    2008-09-26 06:48 34,304 ----a-w c:\windows\system32\awtqnnlL.dll
    2008-09-25 20:16 92,160 ----a-w c:\windows\system32\tkdkgujq.dll
    2008-09-25 20:16 105,472 ----a-w c:\windows\system32\roqilymp.dll
    2008-09-25 06:38 68,096 ----a-w c:\windows\system32\ljJBusQh.dll
    2008-09-24 20:16 92,160 ----a-w c:\windows\system32\qopiodoh.dll
    2008-09-24 20:16 105,472 ----a-w c:\windows\system32\ixldxrbj.dll
    2008-09-24 07:14 68,096 ----a-w c:\windows\system32\hgGwWPIA.dll
    2008-09-23 20:17 96,256 ----a-w c:\windows\system32\gdwfestj.dll
    2008-09-23 20:17 92,160 ----a-w c:\windows\system32\qkprtcwv.dll
    2008-09-23 07:33 34,816 ----a-w c:\windows\system32\pmnkKcda.dll
    2008-09-23 07:33 34,816 ----a-w c:\windows\system32\efcCuSjI.dll
    2008-09-22 20:17 92,160 ----a-w c:\windows\system32\dbkfvdhb.dll
    2008-09-22 20:14 95,232 ----a-w c:\windows\system32\nyfmjgbx.dll
    2008-09-22 07:45 34,816 ----a-w c:\windows\system32\tuvUMcbb.dll
    2008-09-22 07:45 34,816 ----a-w c:\windows\system32\cbXQiGxu.dll
    2008-09-21 20:19 221,184 ----a-w c:\windows\system32\oahcpfop.dll
    2008-09-21 20:19 108,544 ----a-w c:\windows\system32\xxywTNDW.dll
    2008-09-21 20:16 92,160 ----a-w c:\windows\system32\rklmmbgk.dll
    2008-09-21 10:16
    d
    w c:\program files\Skype
    2008-09-21 10:16
    d
    w c:\documents and settings\All Users\Application Data\Skype
    2008-09-21 10:15
    d
    w c:\program files\Common Files\Skype
    2008-09-21 10:02 34,816 ----a-w c:\windows\system32\rqRHwTLe.dll
    2008-09-21 10:02 34,816 ----a-w c:\windows\system32\jkkHXOfe.dll
    2008-09-20 20:16 221,184 ----a-w c:\windows\system32\aqluveyb.dll
    2008-09-20 20:16 108,544 ----a-w c:\windows\system32\mlJCSmNg.dll
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
    "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 1318912]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
    "iesvcmon"="c:\windows\system32\iesvcmon.exe" [2008-11-19 465920]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 32768]
    "PE2CKFNT SE"="c:\program files\Ulead Systems\Ulead Photo Express 2 SE\ChkFont.exe" [1998-07-03 25088]
    "StatusClient"="c:\program files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe" [2002-12-16 36864]
    "TomcatStartup"="c:\program files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe" [2003-03-31 155648]
    "HPLJ Config"="c:\program files\Hewlett-Packard\hp LaserJet 1010 Series\SetConfig.exe" [2003-03-31 28672]
    "ScreenPrint32"="c:\program files\ScreenPrint32 v3\ScreenPrint32.exe" [2003-05-15 446464]
    "LXCGCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll" [2005-07-20 73728]
    "lxcgmon.exe"="c:\program files\Lexmark 2300 Series\lxcgmon.exe" [2005-07-21 200704]
    "EzPrint"="c:\program files\Lexmark 2300 Series\ezprint.exe" [2005-08-01 94208]
    "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-08-23 180269]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-10-25 282624]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2006-10-30 256576]
    "FixCamera"="c:\windows\FixCamera.exe" [2006-06-01 20480]
    "tsnp2std"="c:\windows\tsnp2std.exe" [2006-01-06 110592]
    "snp2std"="c:\windows\vsnp2std.exe" [2006-01-06 344064]
    "hp Update 2100C"="c:\sj644\hpupdate.exe" [2002-01-24 28672]
    "iesvcmon"="c:\windows\system32\iesvcmon.exe" [2008-11-19 465920]
    "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
    "avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
    "SoundMan"="SOUNDMAN.EXE" [2003-08-15 c:\windows\SOUNDMAN.EXE]
    "VTTimer"="VTTimer.exe" [2003-05-07 c:\windows\system32\VTTimer.exe]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-04 15360]

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2006-12-20 77824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    2007-04-19 12:41 294912 c:\program files\SUPERAntiSpyware\SASWINLO.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=sqnnhy.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\K1RFD\\EchoLink\\EchoLink.exe"=
    "c:\\Program Files\\Linksys\\WMP11 Config Utility\\WMP11CFG.exe"=
    "c:\\WINDOWS\\system32\\dpvsetup.exe"=
    "c:\\Program Files\\Yahoo!\\Messenger\\ypager.exe"=
    "c:\\WINDOWS\\system32\\java.exe"=
    "c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Toolbox2.0\\Javasoft\\JRE\\1.3.1\\bin\\javaw.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=
    "c:\\Program Files\\CQPhone\\CQPhone.exe"=
    "c:\\Program Files\\CQPhone\\cqvideo.exe"=
    "c:\\Program Files\\Skype\\Phone\\Skype.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "5200:UDP"= 5200:UDP:tcp 5200
    "5199:UDP"= 5199:UDP:udp 5199
    "3689:UDP"= 3689:UDP:udp
    "3689:TCP"= 3689:TCP:tcp

    R3 SNP2STD;USB2.0 PC Camera (SNP2STD);c:\windows\system32\DRIVERS\snp2sxp.sys [2006-12-29 10305664]
    S2 W9986;DVR driver;c:\windows\system32\Drivers\dvr.sys [2005-03-27 18172]
    S3 iteio;iteio;\??\c:\windows\System32\drivers\iteio.sys [2004-09-07 3680]
    S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys [2008-11-19 38496]
    S3 WMP11V27;Instant Wireless PCI Card V2.7 Driver;c:\windows\system32\DRIVERS\WMP11V27.sys [2004-10-05 171776]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
    \Shell\AutoRun\command - F:\Enterprise_Launcher.exe

    *Newly Created Service* - SSMDRV
    .
    - - - - ORPHANS REMOVED - - - -

    BHO-{4CAFAF0C-C38F-43C1-8080-390E776254DE} - c:\windows\system32\tuvVPfgf.dll
    BHO-{85B59C84-BB49-4AD1-B45A-576DAF69571E} - c:\windows\system32\xxyawuVM.dll
    HKCU-Run-MsnMsgr - c:\program files\MSN Messenger\MsnMsgr.Exe
    HKCU-Run-AdobeUpdater - c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe
    HKLM-Run-LogitechVideoRepair - c:\program files\Logitech\Video\ISStart.exe
    HKLM-Run-cc4c48c9 - c:\windows\system32\uydianye.dll
    HKLM-Run-BMcf7f7b55 - c:\windows\system32\blnaetmn.dll
    HKLM-Run-RegistryMechanic - (no file)
    ShellExecuteHooks-{4CAFAF0C-C38F-43C1-8080-390E776254DE} - c:\windows\system32\tuvVPfgf.dll
    Notify-tuvVPfgf - tuvVPfgf.dll


    .
    Supplementary Scan
    .
    FireFox -: Profile - c:\documents and settings\Matt\Application Data\Mozilla\Firefox\Profiles\vj4olpl0.Default User\
    FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://start.mozilla.org/firefox?client=firefox-a&rls=org.mozilla:en-GB:official
    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-11-21 16:49:02
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    Other Running Processes
    .
    c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe
    c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    c:\windows\system32\wdfmgr.exe
    c:\windows\system32\WgaTray.exe
    c:\windows\system32\wscntfy.exe
    c:\program files\iPod\bin\iPodService.exe
    c:\windows\system32\lxcgcoms.exe
    c:\program files\Ulead Systems\Ulead Photo Express 2 SE\CalCheck.exe
    c:\program files\Linksys\WMP11 Config Utility\WMP11CFG.exe
    c:\windows\SoftwareDistribution\Download\a17b5df07c4dfb0b394eabad42d90933\update\update.exe
    .
    **************************************************************************
    .
    Completion time: 2008-11-21 17:03:06 - machine was rebooted [Matt]
    ComboFix-quarantined-files.txt 2008-11-21 17:02:46

    Pre-Run: 12,907,528,192 bytes free
    Post-Run: 12,907,597,824 bytes free

    WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

    427 --- E O F --- 2008-09-12 08:18:26
  • edited November 2008
    Step 1


    Custom CFScript
    • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
      http://icrontic.com/forum/showthread.php?p=655019#post655019
      Comment:: Katana
      Collect::[4]
      c:\windows\system32\gfcnncad.dll
      c:\windows\system32\qlldefca.dll
      c:\windows\system32\salsyrsi.dll
      c:\windows\system32\niemicnp.dll
      c:\windows\system32\ooitju.dll
      c:\windows\system32\nurrjeta.dll
      c:\windows\system32\mftbgoba.dll
      c:\windows\system32\fccddeCu.dll
      c:\windows\system32\ybkmtrfl.dll
      c:\windows\system32\iifebBsQ.dll
      c:\windows\system32\ljJBusQh.dll
      c:\windows\system32\gdwfestj.dll
      c:\windows\system32\nyfmjgbx.dll
      c:\windows\system32\aqluveyb.dll
      c:\windows\system32\mlJCSmNg.dll
      c:\windows\system32\iesvcmon.exe
      c:\windows\system32\gfcnncad.dll
      c:\windows\system32\urqQiGWQ.dll
      DirLook::
      c:\windows\system32\dPI02
      c:\windows\system32\sX3i02
      c:\windows\system32\QI02
      
      File::
      c:\windows\system32\eoumymtw.dll
      c:\windows\system32\eeovgobr.dll
      c:\windows\system32\mxfwkkfd.dll
      c:\windows\system32\lxsxlmpc.dll
      c:\windows\system32\bhlvrgmk.dll
      c:\windows\system32\tuivyemh.dll
      c:\windows\system32\jnxlhkps.dll
      c:\windows\system32\lyudeuvi.dll
      c:\windows\system32\ibebnxau.dll
      c:\windows\system32\ixowwcxh.dll
      c:\windows\system32\fxkohtqt.dll
      c:\windows\system32\pdsjqvuc.dll
      c:\windows\system32\hmuttlem.dll
      c:\windows\system32\uqaorppx.dll
      c:\windows\system32\qtonefne.dll
      c:\windows\system32\ruxmpgys.dll
      c:\windows\system32\cobtxfto.dll
      c:\windows\system32\pvivhbma.dll
      c:\windows\system32\bbmjpsfc.dll
      c:\windows\system32\jhgjqiwf.dll
      c:\windows\system32\fjtnqpxn.dll
      c:\windows\system32\tnempaoh.dll
      c:\windows\system32\lufrostj.dll
      c:\windows\system32\grielanq.dll
      c:\windows\system32\wqwecstt.dll
      c:\windows\system32\cfveenur.dll
      c:\windows\system32\vtgjivvm.dll
      c:\windows\system32\cbXPhhhG.dll
      c:\windows\system32\lrubxina.dll
      c:\windows\system32\khxxto.dll
      c:\windows\system32\sihpxlef.dll
      c:\windows\system32\tvbackua.dll
      c:\windows\system32\hmkmvvit.dll
      c:\windows\system32\trwctuwa.dll
      c:\windows\system32\hyrwctts.dll
      c:\windows\system32\slzjti.dll
      c:\windows\system32\bxtpyjaw.dll
      c:\windows\system32\jmjhvwrc.dll
      c:\windows\system32\rjpehnoc.dll
      c:\windows\system32\pbeesf.dll
      c:\windows\system32\ofaxisfd.dll
      c:\windows\system32\pqbkjlxc.dll
      c:\windows\system32\qerjvxhh.dll
      c:\windows\system32\fsjlth.dll
      c:\windows\system32\gkiyvwrj.dll
      c:\windows\system32\byXPHwXp.dll
      c:\windows\system32\kiynpu.dll
      c:\windows\system32\ciejgtht.dll
      c:\windows\system32\qlvesiln.dll
      c:\windows\system32\xxyayYrR.dll
      c:\windows\system32\tuvVOFYR.dll
      c:\windows\system32\ljzggz.dll
      c:\windows\system32\ddsqwnbi.dll
      c:\windows\system32\wvUmnNGV.dll
      c:\windows\system32\geBuVOGx.dll
      c:\windows\system32\rfpuoalk.dll
      c:\windows\system32\hqwyrgoa.dll
      c:\windows\system32\iggdygjk.dll
      c:\windows\system32\banvvlld.dll
      c:\windows\system32\hspuirar.dll
      c:\windows\system32\rkireasp.dll
      c:\windows\system32\awtusppq.dll
      c:\windows\system32\pnyttyla.dll
      c:\windows\system32\jggxoknu.dll
      c:\windows\system32\foxuyoxu.dll
      c:\windows\system32\jkkJyASm.dll
      c:\windows\system32\efcASiGA.dll
      c:\windows\system32\kewwaxud.dll
      c:\windows\system32\gpyxmyee.dll
      c:\windows\system32\iifgGYst.dll
      c:\windows\system32\awtqnnlL.dll
      c:\windows\system32\tkdkgujq.dll
      c:\windows\system32\roqilymp.dll
      c:\windows\system32\qopiodoh.dll
      c:\windows\system32\ixldxrbj.dll
      c:\windows\system32\hgGwWPIA.dll
      c:\windows\system32\qkprtcwv.dll
      c:\windows\system32\pmnkKcda.dll
      c:\windows\system32\efcCuSjI.dll
      c:\windows\system32\dbkfvdhb.dll
      c:\windows\system32\tuvUMcbb.dll
      c:\windows\system32\cbXQiGxu.dll
      c:\windows\system32\oahcpfop.dll
      c:\windows\system32\xxywTNDW.dll
      c:\windows\system32\rklmmbgk.dll
      c:\windows\system32\rqRHwTLe.dll
      c:\windows\system32\jkkHXOfe.dll
      Folder::
      c:\temp\FT62
      c:\temp\PRE45
      c:\temp\NT32
      Driver::
      Registry::
      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "iesvcmon"=-
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "iesvcmon"=-
      "SunJavaUpdateSched"=-
      "Adobe Reader Speed Launcher"=-
      
      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
      "AppInit_DLLs"=""
      Files::
      
    • Save this as CFScript.txt and place it on your desktop.


      CFScriptb.gif
    • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
    • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
    • When finished, it will produce a log for you. Copy and paste the contents of the log in your next reply.
    • A window will open asking you to ensure you are connected to the internet, this is so a file can be submitted for analysis.
    • Click OK and follow the instructions to submit the file.


    CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
    Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.



    Step 2


    Kaspersky Online Scanner .
    Your Antivirus and/or Antispyware may give a warning during the scan. This is perfectly normal
    NOTE:- This scan is best done from IE (Internet Explorer)

    NOTE:- Vista users should start IE by Start(Vista Orb) >> Internet Explorer >> Right-Click Run As Admin
    Go Here http://www.kaspersky.com/kos/eng/partner/default/kavwebscan.html

    Read the Requirements and limitations before you click Accept.
    Once the database has downloaded, click My Computer in the left pane
    Now go and put the kettle on !
    When the scan has completed, click Save Report As...
    Enter a name for the file in the Filename: text box and then click the down arrow to the right of Save as type: and select text file (*.txt)
    Click Save - by default the file will be saved to your Desktop, but you can change this if you wish.


    **Note**

    To optimize scanning time and produce a more sensible report for review:
    • Close any open programs.
    • Turn off the real-time scanner of all antivirus or antispyware programs while performing the online scan.

    Note for Internet Explorer 7 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%.


    Step 3

    Logs/Information to Post in Reply
    Please post the following logs/Information in your reply
    • ComboFix Log
    • Kaspersky Log
    • How are things running now ?
  • edited November 2008
    Whilst we appreciate that you may be busy, it has been 5 days or more since we heard from you. This topic is now closed.

    Infections can change and fresh instructions will now need to be given. If you wish to reopen your topic, please send a Private Message (PM) to Trogan with a link to your thread.

    If you are not the user who started this thread, you must start your own Thread instead :)
This discussion has been closed.