Taken to websites
Hi
When I boot up my PC without opening IE two websites are continually opened up on sceeen apprimately one every five minutes.
The websites / pages are
Live Links Removed
I have tried to save a hijack this log but when I hit save log nothing happensa nd the programme closes.
thanks
Matt
When I boot up my PC without opening IE two websites are continually opened up on sceeen apprimately one every five minutes.
The websites / pages are
Live Links Removed
I have tried to save a hijack this log but when I hit save log nothing happensa nd the programme closes.
thanks
Matt
0
This discussion has been closed.
Comments
My name is Katana and I will be helping you to remove any infection(s) that you may have.
Please observe these rules while we work:
(Just because you can't see a problem doesn't mean it isn't there)
If you can do those few things, everything should go smoothly
Please ensure that any USB/Flash/External drives are connected whilst we are cleaning your machine.
Please Note, your security programs may give warnings for some of the tools I will ask you to use.
Be assured, any links I give are safe
Download and Run RSIT
Thank you.
Here is one log - the info txt is tool ong so will put on next post
ogfile of random's system information tool 1.04 (written by random/random)
Run by Matt at 2008-11-18 22:35:12
Microsoft Windows XP Professional Service Pack 2
System drive C: has 8 GB (19%) free of 39 GB
Total RAM: 191 MB (5% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:35:50, on 18/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\PC-cillin 2002\Tmntsrv.exe
C:\Program Files\Trend Micro\PC-cillin 2002\PCCPFW.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Trend Micro\PC-cillin 2002\pccguide.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Trend Micro\PC-cillin 2002\PCCClient.exe
C:\Program Files\Trend Micro\PC-cillin 2002\Pop3trap.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe
C:\Program Files\ScreenPrint32 v3\ScreenPrint32.exe
C:\Program Files\Lexmark 2300 Series\lxcgmon.exe
C:\Program Files\Lexmark 2300 Series\ezprint.exe
C:\Program Files\Trend Micro\PC-cillin 2002\WebTrap.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\FixCamera.exe
C:\WINDOWS\tsnp2std.exe
C:\WINDOWS\system32\lxcgcoms.exe
C:\WINDOWS\vsnp2std.exe
C:\WINDOWS\Fonts\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Matt\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Documents and Settings\Matt\Application Data\gadcom\gadcom.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\GetPack\GetPack24.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\CalCheck.exe
C:\Documents and Settings\All Users\Application Data\ipd\tray.exe
C:\WINDOWS\system32\dPI02\dPI022328.exe
C:\Program Files\Linksys\WMP11 Config Utility\WMP11CFG.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Documents and Settings\Matt\Desktop\RSIT.exe
C:\Program Files\trend micro\Matt.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: IP - {000051AF-07E2-461B-BA37-A2AF7E652E7D} - C:\Documents and Settings\All Users\Application Data\ipd\ipb.dll
O2 - BHO: bambanner browser enhancer - {31b35a87-c9a2-0132-5713-431be04c5e51} - C:\WINDOWS\system32\yexehfqmltzpjph.dll
O2 - BHO: (no name) - {4CAB59B4-55A3-4737-9FD5-B93C6430BF76} - C:\WINDOWS\system32\cwqjyhge.dll
O2 - BHO: (no name) - {4CAFAF0C-C38F-43C1-8080-390E776254DE} - C:\WINDOWS\system32\tuvVPfgf.dll
O2 - BHO: (no name) - {514A5C49-0C7D-42c3-A71B-38864A269B7A} - C:\WINDOWS\system32\kkknikjo.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {D2524837-DE9C-4ABD-8A48-E3E2BB5FC9BC} - C:\WINDOWS\system32\xxyawuVM.dll
O2 - BHO: {a68a08e3-a047-a768-9434-d50765f2becd} - {dceb2f56-705d-4349-867a-740a3e80a86a} - C:\WINDOWS\system32\sqnnhy.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Matt\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [gadcom] "C:\Documents and Settings\Matt\Application Data\gadcom\gadcom.exe" 61A847B5BBF72813339330466188719AB689201522886B092CBD44BD8689220221DD3257
O4 - HKCU\..\Run: [cc4c48c9] rundll32.exe "C:\WINDOWS\system32\uydianye.dll",b
O4 - HKCU\..\Run: [GetPack24] "C:\Program Files\GetPack\GetPack24.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Photo Express Calendar Checker SE.lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\CalCheck.exe
O4 - Global Startup: Start Shopper Link System Tray App.lnk = C:\Documents and Settings\All Users\Application Data\ipd\tray.exe
O4 - Global Startup: Wireless PCI Card Configuration Utility.lnk = C:\Program Files\Linksys\WMP11 Config Utility\WMP11CFG.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Fiddler - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - "C:\Program Files\Fiddler\Fiddler.exe" (file missing)
O9 - Extra 'Tools' menuitem: Fiddler - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - "C:\Program Files\Fiddler\Fiddler.exe" (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EPUWALControl_v1-0-3-18.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/autocomplete.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: sqnnhy.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: tuvVPfgf - C:\WINDOWS\SYSTEM32\tuvVPfgf.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: lxcg_device - - C:\WINDOWS\system32\lxcgcoms.exe
O23 - Service: PC-cillin PersonalFirewall (PCCPFW) - Trend Micro Inc. - C:\Program Files\Trend Micro\PC-cillin 2002\PCCPFW.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Inc. - C:\Program Files\Trend Micro\PC-cillin 2002\Tmntsrv.exe
--
End of file - 8478 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\GoogleUpdateTaskUser.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000051AF-07E2-461B-BA37-A2AF7E652E7D}]
IP - C:\Documents and Settings\All Users\Application Data\ipd\ipb.dll [2008-08-14 176128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31b35a87-c9a2-0132-5713-431be04c5e51}]
bambanner browser enhancer - C:\WINDOWS\system32\yexehfqmltzpjph.dll [2008-08-29 166400]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4CAB59B4-55A3-4737-9FD5-B93C6430BF76}]
C:\WINDOWS\system32\cwqjyhge.dll [2008-11-17 85504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4CAFAF0C-C38F-43C1-8080-390E776254DE}]
C:\WINDOWS\system32\tuvVPfgf.dll [2008-09-13 34816]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{514A5C49-0C7D-42c3-A71B-38864A269B7A}]
C:\WINDOWS\system32\kkknikjo.dll [2008-11-04 92160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D2524837-DE9C-4ABD-8A48-E3E2BB5FC9BC}]
C:\WINDOWS\system32\xxyawuVM.dll [2008-09-13 284160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{dceb2f56-705d-4349-867a-740a3e80a86a}]
C:\WINDOWS\system32\sqnnhy.dll [2008-11-18 120832]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll [2005-07-19 342600]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2004-10-13 1694208]
"MsnMsgr"=C:\Program Files\MSN Messenger\MsnMsgr.Exe /background []
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2007-06-21 1318912]
"AdobeUpdater"=C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe [2007-06-11 2321600]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360]
"Google Update"=C:\Documents and Settings\Matt\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-07 133104]
"gadcom"=C:\Documents and Settings\Matt\Application Data\gadcom\gadcom.exe [2008-11-17 56832]
"cc4c48c9"=C:\WINDOWS\system32\uydianye.dll [2008-11-17 75776]
"GetPack24"=C:\Program Files\GetPack\GetPack24.exe [2008-11-03 350720]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE
Photo Express Calendar Checker SE.lnk - C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\CalCheck.exe
Start Shopper Link System Tray App.lnk - C:\Documents and Settings\All Users\Application Data\ipd\tray.exe
Wireless PCI Card Configuration Utility.lnk - C:\Program Files\Linksys\WMP11 Config Utility\WMP11CFG.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="sqnnhy.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [2007-04-19 294912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tuvVPfgf]
C:\WINDOWS\system32\tuvVPfgf.dll [2008-09-13 34816]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2006-06-19 702768]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 77824]
"{4CAFAF0C-C38F-43C1-8080-390E776254DE}"=C:\WINDOWS\system32\tuvVPfgf.dll [2008-09-13 34816]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
C:\WINDOWS\system32\xxyawuVM
"notification packages"=
scecli
scecli
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\K1RFD\EchoLink\EchoLink.exe"="C:\Program Files\K1RFD\EchoLink\EchoLink.exe:*:Enabled:EchoLink"
"C:\Program Files\Trend Micro\PC-cillin 2002\pccmain.exe"="C:\Program Files\Trend Micro\PC-cillin 2002\pccmain.exe:*:Enabled:PC-cillin 2002"
"C:\WINDOWS\system32\P2P Networking\P2P Networking.exe"="C:\WINDOWS\system32\P2P Networking\P2P Networking.exe:*:Disabled:P2P Networking"
"C:\Program Files\Trend Micro\PC-cillin 2002\PCCSet.exe"="C:\Program Files\Trend Micro\PC-cillin 2002\PCCSet.exe:*:Enabled:PC-cillin 2002 Settings"
"C:\Program Files\Linksys\WMP11 Config Utility\WMP11CFG.exe"="C:\Program Files\Linksys\WMP11 Config Utility\WMP11CFG.exe:*:Enabled:Wireless PCI Card Configuration Utility"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\WINDOWS\system32\rundll32.exe"="C:\WINDOWS\system32\rundll32.exe:*:Disabled:Run a DLL as an App"
"C:\Program Files\Yahoo!\Messenger\YServer.exe"="C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Disabled:Yahoo! FT Server"
"C:\Program Files\Yahoo!\Messenger\ypager.exe"="C:\Program Files\Yahoo!\Messenger\ypager.exe:*:Disabled:Yahoo! Messenger"
"C:\WINDOWS\system32\java.exe"="C:\WINDOWS\system32\java.exe:*:Enabled:Java(TM) 2 Platform Standard Edition binary"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Mozilla Firefox"
"C:\Program Files\Internet Explorer\iexplore.exe"="C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer"
"C:\Program Files\Adobe\Acrobat 5.0\Reader\AcroRd32.exe"="C:\Program Files\Adobe\Acrobat 5.0\Reader\AcroRd32.exe:*:Enabled:Acrobat Reader 5.0"
"C:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe"="C:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe:*:Enabled:javaw"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:MSN Messenger 7.5"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\CQPhone\CQPhone.exe"="C:\Program Files\CQPhone\CQPhone.exe:*:Enabled:CQPhone"
"C:\Program Files\CQPhone\cqvideo.exe"="C:\Program Files\CQPhone\cqvideo.exe:*:Enabled:CQVideo"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:MSN Messenger 7.5"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
shell\AutoRun\command - F:\Enterprise_Launcher.exe
======List of files/folders created in the last 1 months======
2008-11-18 22:35:12 ----D---- C:\rsit
2008-11-18 21:55:15 ----A---- C:\WINDOWS\system32\sqnnhy.dll
2008-11-18 21:55:14 ----A---- C:\WINDOWS\system32\uhbmkvvq.dll
2008-11-18 21:55:12 ----A---- C:\WINDOWS\system32\gfcnncad.dll
2008-11-18 18:47:26 ----A---- C:\WINDOWS\system32\khfGwVOf.dll
2008-11-18 18:47:24 ----A---- C:\WINDOWS\system32\qoMdARKC.dll
2008-11-18 10:10:22 ----A---- C:\WINDOWS\system32\ljJCuSIB.dll
2008-11-18 10:10:21 ----A---- C:\WINDOWS\system32\tuvTnOff.dll
2008-11-18 08:35:17 ----D---- C:\Program Files\iCheck
2008-11-18 08:35:17 ----D---- C:\Program Files\GetPack
2008-11-18 08:31:44 ----D---- C:\WINDOWS\system32\dPI02
2008-11-18 08:31:35 ----A---- C:\WINDOWS\system32\xxyvvSmM.dll
2008-11-18 08:31:34 ----A---- C:\WINDOWS\system32\wvUkJaxY.dll
2008-11-18 08:31:25 ----D---- C:\Program Files\Mjcore
2008-11-17 21:58:26 ----A---- C:\WINDOWS\system32\nyrxlt.dll
2008-11-17 21:58:25 ----A---- C:\WINDOWS\system32\eangcaco.dll
2008-11-17 21:56:00 ----SH---- C:\WINDOWS\system32\eynaidyu.ini
2008-11-17 21:55:53 ----A---- C:\WINDOWS\system32\uydianye.dll
2008-11-17 21:55:26 ----A---- C:\WINDOWS\system32\cwqjyhge.dll
2008-11-17 08:16:57 ----D---- C:\Documents and Settings\Matt\Application Data\gadcom
2008-11-17 08:16:39 ----A---- C:\WINDOWS\system32\iifgHabY.dll
2008-11-17 08:16:38 ----A---- C:\WINDOWS\system32\mlJAsQii.dll
2008-11-16 22:00:19 ----SH---- C:\WINDOWS\system32\eemefaun.ini
2008-11-16 22:00:18 ----A---- C:\WINDOWS\system32\nuafemee.dll
2008-11-16 21:57:19 ----A---- C:\WINDOWS\system32\wsvrxc.dll
2008-11-16 21:57:18 ----A---- C:\WINDOWS\system32\wxhlbptd.dll
2008-11-16 21:54:20 ----A---- C:\WINDOWS\system32\qlldefca.dll
2008-11-16 16:19:40 ----A---- C:\WINDOWS\system32\opnkjJcD.dll
2008-11-16 16:19:38 ----A---- C:\WINDOWS\system32\qoMeCrqr.dll
2008-11-16 09:55:27 ----A---- C:\WINDOWS\system32\ljJCvUKa.dll
2008-11-16 09:55:26 ----A---- C:\WINDOWS\system32\opnlIxUL.dll
2008-11-15 21:59:06 ----A---- C:\WINDOWS\system32\udnxux.dll
2008-11-15 21:59:05 ----A---- C:\WINDOWS\system32\bvseespe.dll
2008-11-15 21:56:10 ----SH---- C:\WINDOWS\system32\stynljxm.ini
2008-11-15 21:53:28 ----A---- C:\WINDOWS\system32\eoumymtw.dll
2008-11-15 08:56:59 ----A---- C:\WINDOWS\system32\rqRIyVmL.dll
2008-11-15 08:56:59 ----A---- C:\WINDOWS\system32\pmnmnKEu.dll
2008-11-14 21:59:18 ----A---- C:\WINDOWS\system32\kjgbqb.dll
2008-11-14 21:59:17 ----A---- C:\WINDOWS\system32\kkkfagsk.dll
2008-11-14 21:56:27 ----SH---- C:\WINDOWS\system32\rgapomkw.ini
2008-11-14 21:56:17 ----A---- C:\WINDOWS\system32\wkmopagr.dll
2008-11-14 21:53:19 ----A---- C:\WINDOWS\system32\eeovgobr.dll
2008-11-14 07:51:12 ----A---- C:\WINDOWS\system32\ljJDSKCs.dll
2008-11-14 07:51:11 ----A---- C:\WINDOWS\system32\byXNfFuU.dll
2008-11-13 21:54:36 ----SH---- C:\WINDOWS\system32\jnjodixa.ini
2008-11-13 21:54:28 ----A---- C:\WINDOWS\system32\axidojnj.dll
2008-11-13 21:52:43 ----A---- C:\WINDOWS\system32\kvwsbs.dll
2008-11-13 21:52:40 ----A---- C:\WINDOWS\system32\frkoodfm.dll
2008-11-13 21:51:38 ----A---- C:\WINDOWS\system32\mxfwkkfd.dll
2008-11-12 21:54:02 ----A---- C:\WINDOWS\system32\pmooihhn.dll
2008-11-12 21:52:01 ----A---- C:\WINDOWS\system32\ssqnkLFy.dll
2008-11-12 21:52:00 ----A---- C:\WINDOWS\system32\gEwvUlKE.dll
2008-11-12 21:51:15 ----A---- C:\WINDOWS\system32\felcry.dll
2008-11-12 21:51:14 ----A---- C:\WINDOWS\system32\jhcwyjgs.dll
2008-11-12 21:50:37 ----A---- C:\WINDOWS\system32\lxsxlmpc.dll
2008-11-11 10:07:38 ----A---- C:\WINDOWS\system32\djyesm.dll
2008-11-11 10:07:37 ----A---- C:\WINDOWS\system32\kdonmtfs.dll
2008-11-11 10:05:21 ----SH---- C:\WINDOWS\system32\asmiyaef.ini
2008-11-11 10:05:15 ----A---- C:\WINDOWS\system32\feayimsa.dll
2008-11-11 10:04:38 ----A---- C:\WINDOWS\system32\bhlvrgmk.dll
2008-11-10 17:32:01 ----A---- C:\WINDOWS\system32\OIUUYG.DLL
2008-11-10 10:09:47 ----SH---- C:\WINDOWS\system32\sfkmfxec.ini
2008-11-10 10:09:46 ----A---- C:\WINDOWS\system32\cexfmkfs.dll
2008-11-10 10:06:47 ----A---- C:\WINDOWS\system32\dvzywv.dll
2008-11-10 10:06:46 ----A---- C:\WINDOWS\system32\hiraimhm.dll
2008-11-09 10:09:42 ----A---- C:\WINDOWS\system32\qmcicjpt.dll
2008-11-09 10:09:42 ----A---- C:\WINDOWS\system32\fwgpin.dll
2008-11-09 10:06:46 ----SH---- C:\WINDOWS\system32\mrfkrgpr.ini
2008-11-09 09:29:31 ----D---- C:\WINDOWS\system32\sX3i02
2008-11-09 09:29:06 ----A---- C:\WINDOWS\system32\cbXOIxvt.dll
2008-11-09 09:29:05 ----A---- C:\WINDOWS\system32\tuvVNFWo.dll
2008-11-08 10:05:55 ----A---- C:\WINDOWS\system32\itunah.dll
2008-11-08 10:05:55 ----A---- C:\WINDOWS\system32\ikpruvcs.dll
2008-11-08 10:03:14 ----SH---- C:\WINDOWS\system32\lgjopvwm.ini
2008-11-08 10:03:07 ----A---- C:\WINDOWS\system32\mwvpojgl.dll
2008-11-08 08:33:11 ----A---- C:\WINDOWS\system32\tuvVLdcD.dll
2008-11-08 08:33:10 ----A---- C:\WINDOWS\system32\tuvWmNhG.dll
2008-11-07 16:41:49 ----D---- C:\Program Files\Safari
2008-11-07 16:38:56 ----D---- C:\Program Files\Apple Software Update
2008-11-07 09:19:51 ----A---- C:\WINDOWS\system32\neakklxj.dll
2008-11-07 09:18:08 ----A---- C:\WINDOWS\system32\fccaBSmM.dll
2008-11-07 09:18:08 ----A---- C:\WINDOWS\system32\efcCvWOF.dll
2008-11-07 09:17:15 ----SH---- C:\WINDOWS\system32\jihbbprd.ini
2008-11-07 09:17:07 ----A---- C:\WINDOWS\system32\drpbbhij.dll
2008-11-06 07:36:24 ----A---- C:\WINDOWS\system32\pmnnKARj.dll
2008-11-06 07:36:24 ----A---- C:\WINDOWS\system32\opnnkkJY.dll
2008-11-05 22:02:05 ----A---- C:\WINDOWS\system32\wianxk.dll
2008-11-05 22:01:56 ----A---- C:\WINDOWS\system32\lfgcqktg.dll
2008-11-05 22:01:52 ----SH---- C:\WINDOWS\system32\vrbjlbap.ini
2008-11-05 22:01:50 ----A---- C:\WINDOWS\system32\pabljbrv.dll
2008-11-05 22:01:17 ----A---- C:\WINDOWS\system32\tuivyemh.dll
2008-11-05 10:03:56 ----D---- C:\Documents and Settings\Matt\Application Data\Opera
2008-11-05 10:02:55 ----D---- C:\Program Files\Opera
2008-11-05 08:29:57 ----A---- C:\WINDOWS\system32\urqRHyvS.dll
2008-11-05 08:29:57 ----A---- C:\WINDOWS\system32\ddcYpmnk.dll
2008-11-04 22:02:44 ----A---- C:\WINDOWS\system32\ypskil.dll
2008-11-04 22:02:43 ----A---- C:\WINDOWS\system32\cimqbxoy.dll
2008-11-04 21:59:57 ----SH---- C:\WINDOWS\system32\dbavjtvw.ini
2008-11-04 21:59:22 ----A---- C:\WINDOWS\system32\kkknikjo.dll
2008-11-04 09:20:47 ----D---- C:\Program Files\Sun
2008-11-04 09:20:10 ----A---- C:\WINDOWS\system32\javaws.exe
2008-11-04 09:20:10 ----A---- C:\WINDOWS\system32\javaw.exe
2008-11-04 09:20:09 ----A---- C:\WINDOWS\system32\java.exe
2008-11-04 08:39:07 ----A---- C:\WINDOWS\system32\jkkJbxVm.dll
2008-11-04 08:39:07 ----A---- C:\WINDOWS\system32\ddcAsppM.dll
2008-11-03 22:06:11 ----A---- C:\WINDOWS\system32\vhmbml.dll
2008-11-03 22:06:01 ----A---- C:\WINDOWS\system32\skbewwoa.dll
2008-11-03 22:00:41 ----SH---- C:\WINDOWS\system32\orpnujqh.ini
2008-11-03 22:00:34 ----A---- C:\WINDOWS\system32\hqjunpro.dll
2008-11-03 21:59:34 ----A---- C:\WINDOWS\system32\salsyrsi.dll
2008-11-03 07:12:39 ----A---- C:\WINDOWS\system32\vtUnnmMC.dll
2008-11-03 07:12:38 ----A---- C:\WINDOWS\system32\urqPgddC.dll
2008-11-02 22:02:27 ----A---- C:\WINDOWS\system32\aurdzx.dll
2008-11-02 22:02:25 ----A---- C:\WINDOWS\system32\dldthdys.dll
2008-11-02 21:59:26 ----SH---- C:\WINDOWS\system32\xwxdevdl.ini
2008-11-02 21:59:20 ----A---- C:\WINDOWS\system32\ldvedxwx.dll
2008-11-02 21:58:51 ----A---- C:\WINDOWS\system32\jnxlhkps.dll
2008-11-02 09:03:31 ----A---- C:\WINDOWS\system32\ljJAQKcA.dll
2008-11-02 09:03:30 ----A---- C:\WINDOWS\system32\yayyXOFX.dll
2008-11-01 22:03:15 ----A---- C:\WINDOWS\system32\cqmozv.dll
2008-11-01 22:03:07 ----A---- C:\WINDOWS\system32\qupkcyhc.dll
2008-11-01 22:00:14 ----SH---- C:\WINDOWS\system32\xivgtjwx.ini
2008-11-01 22:00:05 ----A---- C:\WINDOWS\system32\xwjtgvix.dll
2008-11-01 21:57:09 ----A---- C:\WINDOWS\system32\lyudeuvi.dll
2008-11-01 08:31:36 ----A---- C:\WINDOWS\system32\yayvSlMD.dll
2008-11-01 08:31:36 ----A---- C:\WINDOWS\system32\hgGvtQKa.dll
2008-10-31 22:00:51 ----SH---- C:\WINDOWS\system32\txgbavxm.ini
2008-10-31 22:00:47 ----A---- C:\WINDOWS\system32\mxvabgxt.dll
2008-10-31 21:57:47 ----A---- C:\WINDOWS\system32\xugjwb.dll
2008-10-31 21:57:47 ----A---- C:\WINDOWS\system32\ogljwfke.dll
2008-10-31 21:54:47 ----A---- C:\WINDOWS\system32\ibebnxau.dll
2008-10-31 07:44:39 ----A---- C:\WINDOWS\system32\rqRJCRJc.dll
2008-10-31 07:44:38 ----A---- C:\WINDOWS\system32\opnnmJdd.dll
2008-10-30 22:56:10 ----D---- C:\Program Files\MSECache
2008-10-30 22:00:20 ----A---- C:\WINDOWS\system32\ivhemx.dll
2008-10-30 22:00:19 ----A---- C:\WINDOWS\system32\ibjnuwnx.dll
2008-10-30 21:57:24 ----SH---- C:\WINDOWS\system32\qrtfuksj.ini
2008-10-30 21:57:19 ----A---- C:\WINDOWS\system32\jskuftrq.dll
2008-10-30 21:54:19 ----A---- C:\WINDOWS\system32\ixowwcxh.dll
2008-10-30 15:25:20 ----D---- C:\WINDOWS\system32\QI02
2008-10-30 15:24:49 ----A---- C:\WINDOWS\system32\qoMdDuuT.dll
2008-10-30 15:24:48 ----A---- C:\WINDOWS\system32\khfFXrQH.dll
2008-10-29 22:00:48 ----A---- C:\WINDOWS\system32\gplmgr.dll
2008-10-29 22:00:47 ----A---- C:\WINDOWS\system32\tuvcrnxj.dll
2008-10-29 21:57:47 ----A---- C:\WINDOWS\system32\mbxxxgyq.exe
2008-10-29 21:56:31 ----A---- C:\WINDOWS\system32\cbXRKDSK.dll
2008-10-29 21:56:30 ----A---- C:\WINDOWS\system32\vtUlLBtS.dll
2008-10-29 21:55:02 ----SH---- C:\WINDOWS\system32\cmsqqrxv.ini
2008-10-29 21:54:55 ----A---- C:\WINDOWS\system32\vxrqqsmc.dll
2008-10-29 21:53:19 ----A---- C:\WINDOWS\system32\fxkohtqt.dll
2008-10-28 20:59:28 ----A---- C:\WINDOWS\system32\hxdunt.dll
2008-10-28 20:59:21 ----A---- C:\WINDOWS\system32\tebjqsiw.dll
2008-10-28 20:56:05 ----SH---- C:\WINDOWS\system32\sxkvwfgd.ini
2008-10-28 20:56:03 ----A---- C:\WINDOWS\system32\dgfwvkxs.dll
2008-10-28 20:54:20 ----A---- C:\WINDOWS\system32\lwqaplmg.exe
2008-10-28 20:53:46 ----A---- C:\WINDOWS\system32\pdsjqvuc.dll
2008-10-27 20:56:27 ----A---- C:\WINDOWS\system32\bmmvoaqs.exe
2008-10-27 20:56:03 ----SH---- C:\WINDOWS\system32\dvndljfd.ini
2008-10-27 20:53:46 ----A---- C:\WINDOWS\system32\cusxcf.dll
2008-10-27 20:53:45 ----A---- C:\WINDOWS\system32\espatnsc.dll
2008-10-27 20:53:02 ----A---- C:\WINDOWS\system32\hmuttlem.dll
2008-10-27 07:42:34 ----A---- C:\WINDOWS\system32\nnnmmljJ.dll
2008-10-27 07:42:33 ----A---- C:\WINDOWS\system32\xxyxWOfd.dll
2008-10-26 20:59:43 ----A---- C:\WINDOWS\system32\dsmrpoiv.exe
2008-10-26 20:55:35 ----SH---- C:\WINDOWS\system32\dgxsxeaj.ini
2008-10-26 20:52:39 ----A---- C:\WINDOWS\system32\rbbfbdyw.dll
2008-10-26 20:52:39 ----A---- C:\WINDOWS\system32\jeplvd.dll
2008-10-26 20:52:10 ----A---- C:\WINDOWS\system32\uqaorppx.dll
2008-10-25 21:01:26 ----A---- C:\WINDOWS\system32\hxrbjo.dll
2008-10-25 21:01:24 ----A---- C:\WINDOWS\system32\twerkoey.dll
2008-10-25 20:55:54 ----SH---- C:\WINDOWS\system32\ywswyruc.ini
2008-10-25 20:52:50 ----A---- C:\WINDOWS\system32\qjtnxvrl.exe
2008-10-25 20:52:16 ----A---- C:\WINDOWS\system32\qtonefne.dll
2008-10-25 08:08:31 ----A---- C:\WINDOWS\system32\mlJApPHb.dll
2008-10-25 08:08:31 ----A---- C:\WINDOWS\system32\hgGvtSjK.dll
2008-10-24 21:01:32 ----A---- C:\WINDOWS\system32\fkjgssmj.exe
2008-10-24 20:58:31 ----SH---- C:\WINDOWS\system32\yfisxdbs.ini
2008-10-24 20:55:27 ----A---- C:\WINDOWS\system32\ynewjq.dll
2008-10-24 20:55:27 ----A---- C:\WINDOWS\system32\puvqxunw.dll
2008-10-24 20:49:45 ----A---- C:\WINDOWS\system32\ruxmpgys.dll
2008-10-24 06:45:03 ----A---- C:\WINDOWS\system32\vtUnmMdA.dll
2008-10-24 06:45:02 ----A---- C:\WINDOWS\system32\geBuRJab.dll
2008-10-23 20:52:12 ----SH---- C:\WINDOWS\system32\mudawlag.ini
2008-10-23 20:52:07 ----A---- C:\WINDOWS\system32\galwadum.dll
2008-10-23 20:49:46 ----A---- C:\WINDOWS\system32\uumnnkie.exe
2008-10-23 20:49:43 ----A---- C:\WINDOWS\system32\zejzlb.dll
2008-10-23 20:49:43 ----A---- C:\WINDOWS\system32\nvciykwo.dll
2008-10-23 20:49:14 ----A---- C:\WINDOWS\system32\cobtxfto.dll
2008-10-23 06:41:47 ----A---- C:\WINDOWS\system32\ssqNHbYP.dll
2008-10-23 06:41:47 ----A---- C:\WINDOWS\system32\hgGvuTKc.dll
2008-10-22 20:51:14 ----A---- C:\WINDOWS\system32\arcqwg.dll
2008-10-22 20:51:13 ----SH---- C:\WINDOWS\system32\tvjcfewj.ini
2008-10-22 20:51:13 ----A---- C:\WINDOWS\system32\rcwmdmtk.dll
2008-10-22 20:51:08 ----A---- C:\WINDOWS\system32\jwefcjvt.dll
2008-10-22 20:50:58 ----A---- C:\WINDOWS\system32\gogmfacr.exe
2008-10-22 20:50:06 ----A---- C:\WINDOWS\system32\pvivhbma.dll
2008-10-22 06:48:30 ----A---- C:\WINDOWS\system32\opnkjJyA.dll
2008-10-22 06:48:30 ----A---- C:\WINDOWS\system32\awtttsrS.dll
2008-10-21 20:53:52 ----SH---- C:\WINDOWS\system32\bqwnpeck.ini
2008-10-21 20:53:50 ----A---- C:\WINDOWS\system32\twjnvmcy.exe
2008-10-21 20:53:47 ----A---- C:\WINDOWS\system32\kcepnwqb.dll
2008-10-21 20:50:55 ----A---- C:\WINDOWS\system32\gmkhao.dll
2008-10-21 20:50:54 ----A---- C:\WINDOWS\system32\xhxldjib.dll
2008-10-21 20:47:47 ----A---- C:\WINDOWS\system32\bbmjpsfc.dll
2008-10-21 07:48:53 ----A---- C:\WINDOWS\system32\qoMfebxw.dll
2008-10-21 07:48:53 ----A---- C:\WINDOWS\system32\hgGvspOh.dll
2008-10-20 20:49:46 ----SH---- C:\WINDOWS\system32\npxrbngi.ini
2008-10-20 20:49:45 ----A---- C:\WINDOWS\system32\ignbrxpn.dll
2008-10-20 20:48:19 ----A---- C:\WINDOWS\system32\qeslpgiw.exe
2008-10-20 20:47:33 ----A---- C:\WINDOWS\system32\gegigt.dll
2008-10-20 20:47:32 ----A---- C:\WINDOWS\system32\juufpkmh.dll
2008-10-20 20:47:00 ----A---- C:\WINDOWS\system32\rbsxvhnv.dll
2008-10-19 20:52:51 ----SH---- C:\WINDOWS\system32\httgwujx.ini
2008-10-19 20:50:05 ----A---- C:\WINDOWS\system32\jqfpcefj.exe
2008-10-19 20:47:29 ----A---- C:\WINDOWS\system32\affeok.dll
2008-10-19 20:47:28 ----A---- C:\WINDOWS\system32\lugysidl.dll
2008-10-19 20:46:45 ----A---- C:\WINDOWS\system32\jhgjqiwf.dll
2008-10-19 08:23:08 ----A---- C:\WINDOWS\system32\ddcYsSJa.dll
2008-10-19 08:23:08 ----A---- C:\WINDOWS\system32\cbXOGYPF.dll
======List of files/folders modified in the last 1 months======
2008-11-18 22:35:57 ----ASH---- C:\WINDOWS\system32\MVuwayxx.ini
2008-11-18 22:35:49 ----D---- C:\Program Files\Trend Micro
2008-11-18 22:35:45 ----ASH---- C:\WINDOWS\system32\MVuwayxx.ini2
2008-11-18 22:35:09 ----D---- C:\WINDOWS\Prefetch
2008-11-18 22:28:19 ----A---- C:\WINDOWS\BMcf7f7b55.txt
2008-11-18 22:23:34 ----D---- C:\Program Files\TextAloud
2008-11-18 22:23:11 ----D---- C:\Program Files\Mozilla Firefox
2008-11-18 21:58:24 ----SHD---- C:\WINDOWS\system32
2008-11-18 21:56:08 ----AD---- C:\WINDOWS\Temp
2008-11-18 21:55:10 ----A---- C:\WINDOWS\system32\c76f8cb7-.txt
2008-11-18 18:49:54 ----RSD---- C:\WINDOWS\Fonts
2008-11-18 18:47:40 ----A---- C:\WINDOWS\ULEAD32.INI
2008-11-18 18:46:33 ----D---- C:\WINDOWS
2008-11-18 18:45:14 ----A---- C:\WINDOWS\pskt.ini
2008-11-18 18:41:23 ----A---- C:\WINDOWS\SchedLgU.Txt
2008-11-18 17:10:25 ----D---- C:\Program Files\SUPERAntiSpyware
2008-11-18 15:07:30 ----D---- C:\WINDOWS\system32\CatRoot2
2008-11-18 11:11:54 ----SHD---- C:\WINDOWS\Installer
2008-11-18 09:42:01 ----RD---- C:\Program Files
2008-11-18 08:31:55 ----D---- C:\Temp
2008-11-17 21:46:45 ----D---- C:\Documents and Settings\Matt\Application Data\Skype
2008-11-17 20:47:29 ----D---- C:\Documents and Settings\Matt\Application Data\skypePM
2008-11-14 16:13:19 ----D---- C:\WINDOWS\Help
2008-11-09 09:28:42 ----D---- C:\WINDOWS\system32\drivers
2008-11-07 20:54:37 ----D---- C:\Program Files\Hewlett-Packard
2008-11-07 16:45:21 ----D---- C:\Documents and Settings\Matt\Application Data\Apple Computer
2008-11-07 16:38:05 ----SD---- C:\WINDOWS\Tasks
2008-11-04 09:19:58 ----D---- C:\Program Files\Java
2008-11-01 23:20:09 ----D---- C:\unzipped
2008-10-30 15:23:08 ----D---- C:\Program Files\Lx_cats
2008-10-27 07:42:51 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2008-10-25 20:56:00 ----D---- C:\Documents and Settings\Matt\Application Data\Pamela
2008-10-25 20:55:19 ----D---- C:\Program Files\Pamela
2008-10-23 10:39:52 ----A---- C:\WINDOWS\system32\mcrh.tmp
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AmdK7;AMD K7 Processor Driver; C:\WINDOWS\System32\DRIVERS\amdk7.sys [2004-08-04 37376]
R1 incdrm;InCD EasyWrite Reader; C:\WINDOWS\system32\drivers\incdrm.sys [2003-08-21 25520]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys []
R2 PCC_PFW;PC-Cillin Personal Firewall; C:\WINDOWS\System32\Drivers\PCC_PFW.sys [2003-10-27 57468]
R2 Tmfilter;Tmfilter; C:\WINDOWS\system32\drivers\TmXPFlt.sys [2005-03-28 183808]
R2 Tmpreflt;Tmpreflt; C:\WINDOWS\system32\drivers\Tmpreflt.sys [2005-03-28 25088]
R2 Vsapint;Vsapint; C:\WINDOWS\system32\drivers\Vsapint.sys [2005-03-28 962672]
R3 ALCXSENS;Service for WDM 3D Audio Driver; C:\WINDOWS\system32\drivers\ALCXSENS.SYS [2003-08-14 404736]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2003-08-21 462940]
R3 FETND5BV;VIA Rhine-Family Fast Ethernet Adapter Driver Service; C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [2004-12-16 42496]
R3 GEARAspiWDM;GEAR CDRom Filter; C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys [2006-09-19 15664]
R3 PCANDIS5;PCANDIS5 Protocol Driver; \??\C:\WINDOWS\system32\PCANDIS5.SYS []
R3 SASENUM;SASENUM; \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS []
R3 SNP2STD;USB2.0 PC Camera (SNP2STD); C:\WINDOWS\system32\DRIVERS\snp2sxp.sys [2006-05-13 10305664]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2004-08-04 26624]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2004-08-04 57600]
R3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-04 25856]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2004-08-04 20480]
R3 viagfx;viagfx; C:\WINDOWS\System32\DRIVERS\vtmini.sys [2003-08-11 265344]
R3 vulfnths;VIA USB Host Controller Lower Filter; C:\WINDOWS\System32\Drivers\vulfnth.sys [2002-10-24 6912]
R3 vulfntrs;VIA USB Roothub Lower Filter; C:\WINDOWS\System32\Drivers\vulfntr.sys [2003-05-24 11392]
S2 W9986;DVR driver; C:\WINDOWS\System32\Drivers\dvr.sys [2001-02-02 18172]
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-04 17024]
S3 Dot4;MS IEEE-1284.4 Driver; C:\WINDOWS\system32\DRIVERS\Dot4.sys [2004-08-04 207360]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\WINDOWS\system32\DRIVERS\Dot4Prt.sys [2001-08-17 12928]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\WINDOWS\system32\DRIVERS\dot4usb.sys [2001-08-17 23808]
S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\System32\DRIVERS\fetnd5.sys [2001-08-17 27165]
S3 FETNDISB;VIA Rhine Family Fast Ethernet Adapter Driver Service; C:\WINDOWS\System32\DRIVERS\fetnd5b.sys [2004-07-22 42496]
S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
S3 iteio;iteio; \??\C:\WINDOWS\System32\drivers\iteio.sys []
S3 LMouKE;Logitech SetPoint Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\LMouKE.Sys []
S3 mouhid;Mouse HID Driver; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-08-17 12160]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-04 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-04 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-04 10880]
S3 NTSIM;NTSIM; \??\C:\WINDOWS\System32\ntsim.sys []
S3 RimUsb;BlackBerry Device; C:\WINDOWS\System32\Drivers\RimUsb.sys [2006-07-04 22528]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-04 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-04 15360]
S3 usbaudio;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-04 59264]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-04 31616]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-04 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]
S3 WMP11V27;Instant Wireless PCI Card V2.7 Driver; C:\WINDOWS\system32\DRIVERS\WMP11V27.sys [2002-07-30 171776]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-04 19328]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2008-09-15 611664]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2007-09-06 110592]
R2 PCCPFW;PC-cillin PersonalFirewall; C:\Program Files\Trend Micro\PC-cillin 2002\PCCPFW.exe [2003-10-27 163840]
R2 Tmntsrv;Trend NT Realtime Service; C:\Program Files\Trend Micro\PC-cillin 2002\Tmntsrv.exe [2003-10-27 176128]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2006-10-30 492608]
R3 lxcg_device;lxcg_device; C:\WINDOWS\system32\lxcgcoms.exe [2005-07-25 491520]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2002-08-01 65536]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2007-03-26 292864]
EOF
nfo.txt logfile of random's system information tool 1.04 2008-11-18 22:36:03
======Uninstall list======
-->C:\bsw.exe /UNINSTALL
-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
ABBYY FineReader 6.0 Sprint-->MsiExec.exe /I{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}
Ad-Aware-->MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 8-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A80000000002}
Ahead InCD EasyWrite Reader-->C:\WINDOWS\unmrw.exe /UNINSTALL
Ahead NeroMediaPlayer-->C:\WINDOWS\UNNMP.exe /UNINSTALL
Apple Mobile Device Support-->MsiExec.exe /I{3EBD3749-304E-4A4C-9575-C00E5F015217}
Apple Software Update-->MsiExec.exe /I{02DFF6B1-1654-411C-8D7B-FD6052EF016F}
Audacity 1.3.2 (Unicode)-->"C:\Program Files\Audacity 1.3 Beta (Unicode)\unins000.exe"
Citrix Web Client-->C:\WINDOWS\system32\ctxsetup.exe /uninst C:\PROGRA~1\Citrix\icaweb32\uninst.inf
CleanUp!-->C:\Program Files\CleanUp!\uninstall.exe
CQ100-->C:\WINDOWS\CQ100 Uninstaller.exe
CQPhone-->C:\WINDOWS\CQPhone Uninstaller.exe
EchoLink-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\K1RFD\EchoLink\Uninst.isu"
Enhancement Browser Tools Bambanner-->C:\WINDOWS\system32\dzrinpxdvrfclic.exe
eQSO PC Client 3.00-->"C:\Program Files\eQSO-PC-Client\setup\uninst.exe"
Fiddler (remove only)-->"C:\Program Files\Fiddler\uninst.exe"
HighMAT Extension to Microsoft Windows XP CD Writing Wizard-->MsiExec.exe /X{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}
HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
Hotfix for Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
hp LaserJet 1010 Series-->MsiExec.exe /x {292C47B2-8DB7-47BF-896C-C3C5EE8108C4}
Internet Speed Monitor-->C:\Program Files\iCheck\Uninstall.exe
iPod for Windows 2005-03-23-->C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{44A537A5-859C-43A6-8285-C0668142A090} /l1033
iTunes-->MsiExec.exe /I{446DBFFA-4088-48E3-8932-74316BA4CAE4}
J2SE Runtime Environment 5.0 Update 1-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150010}
Jasc Paint Shop Pro 8-->MsiExec.exe /I{81A34902-9D0B-4920-A25C-4CDC5D14B328}
Java(TM) 6 Update 2-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
Java(TM) 6 Update 3-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
LaserJet 1020 series-->C:\Program Files\Zenographics\{0A60D272-429C-4300-A399-500ACE46C14F}\Setup.exe -u "HPLJInstaller.dll=Hplj1020.inf"
Lexmark 2300 Series-->C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\lxcgUNST.EXE -NOLICENSE
Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft Office XP Professional with FrontPage-->MsiExec.exe /I{90280409-6000-11D3-8CFE-0050048383C9}
Microsoft Plus! for Windows XP-->MsiExec.exe /I{EEC2DAFD-5558-40AC-8E9C-5005C8F810E8}
Microsoft Windows Journal Viewer-->MsiExec.exe /X{43DCF766-6838-4F9A-8C91-D92DA586DFA7}
Mozilla Firefox (3.0.4)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML4 Parser-->MsiExec.exe /I{01501EBA-EC35-4F9F-8889-3BE346E5DA13}
OLYMPUS CAMEDIA Master 4.2-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{30BB4D60-81DB-11D5-BB77-00400536ABAC}\setup.exe" CAMEDIA Master 4.2
OpenOffice.org Installer 1.0-->MsiExec.exe /X{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}
Pamela Basic 4.0-->C:\Program Files\Pamela\Uninst.exe
PC Connectivity Solution-->MsiExec.exe /I{066D65EA-ED53-44E4-A96A-F81B6E409D2E}
PC-cillin 2002-->MsiExec.exe /X{C90F3E44-3BF6-11D4-A110-00500405613A}
Pdf995-->C:\Program Files\pdf995\setup.exe uninstall
PowerDVD-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\setup.exe" -uninstall
QuickTime-->MsiExec.exe /I{50D8FFDD-90CD-4859-841F-AA1961C7767A}
RealPlayer-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
Realtek AC'97 Audio-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" REMOVE
Registry Mechanic 5.1-->"C:\Program Files\Registry Mechanic\unins000.exe"
S3 S3Display-->vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Display'
S3 S3Gamma2-->vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Gamma2'
S3 S3Info2-->vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Info2'
S3 S3Overlay-->vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Overlay'
ScreenPrint32 v3.5 (C:\Program Files\ScreenPrint32 v3\) #3-->C:\WINDOWS\st6unst.exe -n "C:\Program Files\ScreenPrint32 v3\ST6UNST.001"
ScreenPrint32 v3.5-->C:\WINDOWS\st6unst.exe -n "C:\Program Files\ScreenPrint32 v3\ST6UNST.LOG"
ScreenPrint32-->C:\WINDOWS\ST5UNST.EXE -n "C:\WINDOWS\ST5UNST.LOG"
Security Update for Windows Media Player (KB911564)-->"C:\WINDOWS\$NtUninstallKB911564$\spuninst\spuninst.exe"
Security Update for Windows Media Player 6.4 (KB925398)-->"C:\WINDOWS\$NtUninstallKB925398_WMP64$\spuninst\spuninst.exe"
Security Update for Windows Media Player 9 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP9$\spuninst\spuninst.exe"
Security Update for Windows Media Player 9 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP9$\spuninst\spuninst.exe"
Security Update for Windows XP (KB890046)-->"C:\WINDOWS\$NtUninstallKB890046$\spuninst\spuninst.exe"
Security Update for Windows XP (KB893756)-->"C:\WINDOWS\$NtUninstallKB893756$\spuninst\spuninst.exe"
Security Update for Windows XP (KB896358)-->"C:\WINDOWS\$NtUninstallKB896358$\spuninst\spuninst.exe"
Security Update for Windows XP (KB896423)-->"C:\WINDOWS\$NtUninstallKB896423$\spuninst\spuninst.exe"
Security Update for Windows XP (KB896424)-->"C:\WINDOWS\$NtUninstallKB896424$\spuninst\spuninst.exe"
Security Update for Windows XP (KB896428)-->"C:\WINDOWS\$NtUninstallKB896428$\spuninst\spuninst.exe"
Security Update for Windows XP (KB899587)-->"C:\WINDOWS\$NtUninstallKB899587$\spuninst\spuninst.exe"
Security Update for Windows XP (KB899589)-->"C:\WINDOWS\$NtUninstallKB899589$\spuninst\spuninst.exe"
Security Update for Windows XP (KB899591)-->"C:\WINDOWS\$NtUninstallKB899591$\spuninst\spuninst.exe"
Security Update for Windows XP (KB900725)-->"C:\WINDOWS\$NtUninstallKB900725$\spuninst\spuninst.exe"
Security Update for Windows XP (KB901017)-->"C:\WINDOWS\$NtUninstallKB901017$\spuninst\spuninst.exe"
Security Update for Windows XP (KB901214)-->"C:\WINDOWS\$NtUninstallKB901214$\spuninst\spuninst.exe"
Security Update for Windows XP (KB902400)-->"C:\WINDOWS\$NtUninstallKB902400$\spuninst\spuninst.exe"
Security Update for Windows XP (KB904706)-->"C:\WINDOWS\$NtUninstallKB904706$\spuninst\spuninst.exe"
Security Update for Windows XP (KB905414)-->"C:\WINDOWS\$NtUninstallKB905414$\spuninst\spuninst.exe"
Security Update for Windows XP (KB905749)-->"C:\WINDOWS\$NtUninstallKB905749$\spuninst\spuninst.exe"
Security Update for Windows XP (KB908519)-->"C:\WINDOWS\$NtUninstallKB908519$\spuninst\spuninst.exe"
Security Update for Windows XP (KB911562)-->"C:\WINDOWS\$NtUninstallKB911562$\spuninst\spuninst.exe"
Security Update for Windows XP (KB911567)-->"C:\WINDOWS\$NtUninstallKB911567$\spuninst\spuninst.exe"
Security Update for Windows XP (KB911927)-->"C:\WINDOWS\$NtUninstallKB911927$\spuninst\spuninst.exe"
Security Update for Windows XP (KB912919)-->"C:\WINDOWS\$NtUninstallKB912919$\spuninst\spuninst.exe"
Security Update for Windows XP (KB913580)-->"C:\WINDOWS\$NtUninstallKB913580$\spuninst\spuninst.exe"
Security Update for Windows XP (KB914388)-->"C:\WINDOWS\$NtUninstallKB914388$\spuninst\spuninst.exe"
Security Update for Windows XP (KB914389)-->"C:\WINDOWS\$NtUninstallKB914389$\spuninst\spuninst.exe"
Security Update for Windows XP (KB916281)-->"C:\WINDOWS\$NtUninstallKB916281$\spuninst\spuninst.exe"
Security Update for Windows XP (KB917159)-->"C:\WINDOWS\$NtUninstallKB917159$\spuninst\spuninst.exe"
Security Update for Windows XP (KB917344)-->"C:\WINDOWS\$NtUninstallKB917344$\spuninst\spuninst.exe"
Security Update for Windows XP (KB917422)-->"C:\WINDOWS\$NtUninstallKB917422$\spuninst\spuninst.exe"
Security Update for Windows XP (KB917953)-->"C:\WINDOWS\$NtUninstallKB917953$\spuninst\spuninst.exe"
Security Update for Windows XP (KB918118)-->"C:\WINDOWS\$NtUninstallKB918118$\spuninst\spuninst.exe"
Security Update for Windows XP (KB918439)-->"C:\WINDOWS\$NtUninstallKB918439$\spuninst\spuninst.exe"
Security Update for Windows XP (KB918899)-->"C:\WINDOWS\$NtUninstallKB918899$\spuninst\spuninst.exe"
Security Update for Windows XP (KB919007)-->"C:\WINDOWS\$NtUninstallKB919007$\spuninst\spuninst.exe"
Security Update for Windows XP (KB920213)-->"C:\WINDOWS\$NtUninstallKB920213$\spuninst\spuninst.exe"
Security Update for Windows XP (KB920214)-->"C:\WINDOWS\$NtUninstallKB920214$\spuninst\spuninst.exe"
Security Update for Windows XP (KB920670)-->"C:\WINDOWS\$NtUninstallKB920670$\spuninst\spuninst.exe"
Security Update for Windows XP (KB920683)-->"C:\WINDOWS\$NtUninstallKB920683$\spuninst\spuninst.exe"
Security Update for Windows XP (KB920685)-->"C:\WINDOWS\$NtUninstallKB920685$\spuninst\spuninst.exe"
Security Update for Windows XP (KB921398)-->"C:\WINDOWS\$NtUninstallKB921398$\spuninst\spuninst.exe"
Security Update for Windows XP (KB921503)-->"C:\WINDOWS\$NtUninstallKB921503$\spuninst\spuninst.exe"
Security Update for Windows XP (KB921883)-->"C:\WINDOWS\$NtUninstallKB921883$\spuninst\spuninst.exe"
Security Update for Windows XP (KB922616)-->"C:\WINDOWS\$NtUninstallKB922616$\spuninst\spuninst.exe"
Security Update for Windows XP (KB922760)-->"C:\WINDOWS\$NtUninstallKB922760$\spuninst\spuninst.exe"
Security Update for Windows XP (KB922819)-->"C:\WINDOWS\$NtUninstallKB922819$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923191)-->"C:\WINDOWS\$NtUninstallKB923191$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923414)-->"C:\WINDOWS\$NtUninstallKB923414$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923689)-->"C:\WINDOWS\$NtUninstallKB923689$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923694)-->"C:\WINDOWS\$NtUninstallKB923694$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
Security Update for Windows XP (KB923980)-->"C:\WINDOWS\$NtUninstallKB923980$\spuninst\spuninst.exe"
Security Update for Windows XP (KB924191)-->"C:\WINDOWS\$NtUninstallKB924191$\spuninst\spuninst.exe"
Security Update for Windows XP (KB924270)-->"C:\WINDOWS\$NtUninstallKB924270$\spuninst\spuninst.exe"
Security Update for Windows XP (KB924496)-->"C:\WINDOWS\$NtUninstallKB924496$\spuninst\spuninst.exe"
Security Update for Windows XP (KB924667)-->"C:\WINDOWS\$NtUninstallKB924667$\spuninst\spuninst.exe"
Security Update for Windows XP (KB925454)-->"C:\WINDOWS\$NtUninstallKB925454$\spuninst\spuninst.exe"
Security Update for Windows XP (KB925486)-->"C:\WINDOWS\$NtUninstallKB925486$\spuninst\spuninst.exe"
Security Update for Windows XP (KB925902)-->"C:\WINDOWS\$NtUninstallKB925902$\spuninst\spuninst.exe"
Security Update for Windows XP (KB926255)-->"C:\WINDOWS\$NtUninstallKB926255$\spuninst\spuninst.exe"
Security Update for Windows XP (KB926436)-->"C:\WINDOWS\$NtUninstallKB926436$\spuninst\spuninst.exe"
Security Update for Windows XP (KB927779)-->"C:\WINDOWS\$NtUninstallKB927779$\spuninst\spuninst.exe"
Security Update for Windows XP (KB927802)-->"C:\WINDOWS\$NtUninstallKB927802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB928090)-->"C:\WINDOWS\$NtUninstallKB928090$\spuninst\spuninst.exe"
Security Update for Windows XP (KB928255)-->"C:\WINDOWS\$NtUninstallKB928255$\spuninst\spuninst.exe"
Security Update for Windows XP (KB928843)-->"C:\WINDOWS\$NtUninstallKB928843$\spuninst\spuninst.exe"
Security Update for Windows XP (KB929123)-->"C:\WINDOWS\$NtUninstallKB929123$\spuninst\spuninst.exe"
Security Update for Windows XP (KB929969)-->"C:\WINDOWS\$NtUninstallKB929969$\spuninst\spuninst.exe"
Security Update for Windows XP (KB930178)-->"C:\WINDOWS\$NtUninstallKB930178$\spuninst\spuninst.exe"
Security Update for Windows XP (KB931261)-->"C:\WINDOWS\$NtUninstallKB931261$\spuninst\spuninst.exe"
Security Update for Windows XP (KB931768)-->"C:\WINDOWS\$NtUninstallKB931768$\spuninst\spuninst.exe"
Security Update for Windows XP (KB931784)-->"C:\WINDOWS\$NtUninstallKB931784$\spuninst\spuninst.exe"
Security Update for Windows XP (KB932168)-->"C:\WINDOWS\$NtUninstallKB932168$\spuninst\spuninst.exe"
Security Update for Windows XP (KB933566)-->"C:\WINDOWS\$NtUninstallKB933566$\spuninst\spuninst.exe"
Security Update for Windows XP (KB933729)-->"C:\WINDOWS\$NtUninstallKB933729$\spuninst\spuninst.exe"
Security Update for Windows XP (KB935839)-->"C:\WINDOWS\$NtUninstallKB935839$\spuninst\spuninst.exe"
Security Update for Windows XP (KB935840)-->"C:\WINDOWS\$NtUninstallKB935840$\spuninst\spuninst.exe"
Security Update for Windows XP (KB936021)-->"C:\WINDOWS\$NtUninstallKB936021$\spuninst\spuninst.exe"
Security Update for Windows XP (KB937143)-->"C:\WINDOWS\$NtUninstallKB937143$\spuninst\spuninst.exe"
Security Update for Windows XP (KB937894)-->"C:\WINDOWS\$NtUninstallKB937894$\spuninst\spuninst.exe"
Security Update for Windows XP (KB938127)-->"C:\WINDOWS\$NtUninstallKB938127$\spuninst\spuninst.exe"
Security Update for Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB938829)-->"C:\WINDOWS\$NtUninstallKB938829$\spuninst\spuninst.exe"
Security Update for Windows XP (KB939653)-->"C:\WINDOWS\$NtUninstallKB939653$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941202)-->"C:\WINDOWS\$NtUninstallKB941202$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941568)-->"C:\WINDOWS\$NtUninstallKB941568$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941644)-->"C:\WINDOWS\$NtUninstallKB941644$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941693)-->"C:\WINDOWS\$NtUninstallKB941693$\spuninst\spuninst.exe"
Security Update for Windows XP (KB942615)-->"C:\WINDOWS\$NtUninstallKB942615$\spuninst\spuninst.exe"
Security Update for Windows XP (KB943055)-->"C:\WINDOWS\$NtUninstallKB943055$\spuninst\spuninst.exe"
Security Update for Windows XP (KB943460)-->"C:\WINDOWS\$NtUninstallKB943460$\spuninst\spuninst.exe"
Security Update for Windows XP (KB943485)-->"C:\WINDOWS\$NtUninstallKB943485$\spuninst\spuninst.exe"
Security Update for Windows XP (KB944338)-->"C:\WINDOWS\$NtUninstallKB944338$\spuninst\spuninst.exe"
Security Update for Windows XP (KB944533)-->"C:\WINDOWS\$NtUninstallKB944533$\spuninst\spuninst.exe"
Security Update for Windows XP (KB944653)-->"C:\WINDOWS\$NtUninstallKB944653$\spuninst\spuninst.exe"
Security Update for Windows XP (KB945553)-->"C:\WINDOWS\$NtUninstallKB945553$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946026)-->"C:\WINDOWS\$NtUninstallKB946026$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB947864)-->"C:\WINDOWS\$NtUninstallKB947864$\spuninst\spuninst.exe"
Security Update for Windows XP (KB948590)-->"C:\WINDOWS\$NtUninstallKB948590$\spuninst\spuninst.exe"
Security Update for Windows XP (KB948881)-->"C:\WINDOWS\$NtUninstallKB948881$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950749)-->"C:\WINDOWS\$NtUninstallKB950749$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950759)-->"C:\WINDOWS\$NtUninstallKB950759$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953838)-->"C:\WINDOWS\$NtUninstallKB953838$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
Senselang-->C:\Program Files\Senselang\uninstall.exe
Skypeâ„¢ 3.8-->MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
Smart Guardian-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\ITE\Smart Guardian\Uninst.isu"
Spybot - Search & Destroy 1.4-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins001.exe"
SpywareBlaster v3.2-->"C:\Program Files\SpywareBlaster\unins000.exe"
SUPERAntiSpyware Free Edition-->MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}
UK Driving Secrets Guide-->"C:\Program Files\UK Driving Secrets Guide\unins000.exe"
Ulead Photo Express 2.0 SE-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\Uninst.isu" -c"C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\IS32Inst.dll"
Update for Windows XP (KB894391)-->"C:\WINDOWS\$NtUninstallKB894391$\spuninst\spuninst.exe"
Update for Windows XP (KB898461)-->"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
Update for Windows XP (KB900485)-->"C:\WINDOWS\$NtUninstallKB900485$\spuninst\spuninst.exe"
Update for Windows XP (KB908531)-->"C:\WINDOWS\$NtUninstallKB908531$\spuninst\spuninst.exe"
Update for Windows XP (KB910437)-->"C:\WINDOWS\$NtUninstallKB910437$\spuninst\spuninst.exe"
Update for Windows XP (KB911280)-->"C:\WINDOWS\$NtUninstallKB911280$\spuninst\spuninst.exe"
Update for Windows XP (KB916595)-->"C:\WINDOWS\$NtUninstallKB916595$\spuninst\spuninst.exe"
Update for Windows XP (KB920872)-->"C:\WINDOWS\$NtUninstallKB920872$\spuninst\spuninst.exe"
Update for Windows XP (KB922582)-->"C:\WINDOWS\$NtUninstallKB922582$\spuninst\spuninst.exe"
Update for Windows XP (KB927891)-->"C:\WINDOWS\$NtUninstallKB927891$\spuninst\spuninst.exe"
Update for Windows XP (KB929338)-->"C:\WINDOWS\$NtUninstallKB929338$\spuninst\spuninst.exe"
Update for Windows XP (KB930916)-->"C:\WINDOWS\$NtUninstallKB930916$\spuninst\spuninst.exe"
Update for Windows XP (KB931836)-->"C:\WINDOWS\$NtUninstallKB931836$\spuninst\spuninst.exe"
Update for Windows XP (KB933360)-->"C:\WINDOWS\$NtUninstallKB933360$\spuninst\spuninst.exe"
Update for Windows XP (KB938828)-->"C:\WINDOWS\$NtUninstallKB938828$\spuninst\spuninst.exe"
Update for Windows XP (KB942763)-->"C:\WINDOWS\$NtUninstallKB942763$\spuninst\spuninst.exe"
Update for Windows XP (KB942840)-->"C:\WINDOWS\$NtUninstallKB942840$\spuninst\spuninst.exe"
Update for Windows XP (KB946627)-->"C:\WINDOWS\$NtUninstallKB946627$\spuninst\spuninst.exe"
Update for Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
USB2.0 PC Camera-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{75438C0E-9925-412E-AD85-D0E71C6CE2ED}\Setup.exe" -l0x9
VIA Rhine-Family Fast Ethernet Adapter-->Rundll32.exe vuins32.dll,vuins32Ex $Rhine $VIA
Windows Installer 3.1 (KB893803)-->"C:\WINDOWS\$MSI31Uninstall_KB893803$\spuninst\spuninst.exe"
Windows Media Format Runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Player 10-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows XP Hotfix - KB834707-->C:\WINDOWS\$NtUninstallKB834707$\spuninst\spuninst.exe
Windows XP Hotfix - KB867282-->C:\WINDOWS\$NtUninstallKB867282$\spuninst\spuninst.exe
Windows XP Hotfix - KB873333-->C:\WINDOWS\$NtUninstallKB873333$\spuninst\spuninst.exe
Windows XP Hotfix - KB873339-->C:\WINDOWS\$NtUninstallKB873339$\spuninst\spuninst.exe
Windows XP Hotfix - KB885250-->C:\WINDOWS\$NtUninstallKB885250$\spuninst\spuninst.exe
Windows XP Hotfix - KB885835-->C:\WINDOWS\$NtUninstallKB885835$\spuninst\spuninst.exe
Windows XP Hotfix - KB885836-->C:\WINDOWS\$NtUninstallKB885836$\spuninst\spuninst.exe
Windows XP Hotfix - KB885884-->C:\WINDOWS\$NtUninstallKB885884$\spuninst\spuninst.exe
Windows XP Hotfix - KB886185-->C:\WINDOWS\$NtUninstallKB886185$\spuninst\spuninst.exe
Windows XP Hotfix - KB887472-->C:\WINDOWS\$NtUninstallKB887472$\spuninst\spuninst.exe
Windows XP Hotfix - KB887742-->C:\WINDOWS\$NtUninstallKB887742$\spuninst\spuninst.exe
Windows XP Hotfix - KB888113-->C:\WINDOWS\$NtUninstallKB888113$\spuninst\spuninst.exe
Windows XP Hotfix - KB888302-->C:\WINDOWS\$NtUninstallKB888302$\spuninst\spuninst.exe
Windows XP Hotfix - KB890047-->C:\WINDOWS\$NtUninstallKB890047$\spuninst\spuninst.exe
Windows XP Hotfix - KB890175-->C:\WINDOWS\$NtUninstallKB890175$\spuninst\spuninst.exe
Windows XP Hotfix - KB890859-->"C:\WINDOWS\$NtUninstallKB890859$\spuninst\spuninst.exe"
Windows XP Hotfix - KB890923-->"C:\WINDOWS\$NtUninstallKB890923$\spuninst\spuninst.exe"
Windows XP Hotfix - KB891781-->C:\WINDOWS\$NtUninstallKB891781$\spuninst\spuninst.exe
Windows XP Hotfix - KB893066-->"C:\WINDOWS\$NtUninstallKB893066$\spuninst\spuninst.exe"
Windows XP Hotfix - KB893086-->"C:\WINDOWS\$NtUninstallKB893086$\spuninst\spuninst.exe"
Windows XP Service Pack 2-->C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe
WinZip-->"C:\Program Files\WinZip\WINZIP32.EXE" /uninstall
Wireless PCI Card Configuration Utility-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5C6956F3-B586-4674-BCD0-CCF7EC1DF766}\Setup.exe" -l0x9
XMLog-->C:\WINDOWS\st6unst.exe -n "c:\mlog\ST6UNST.UNS"
Yahoo! Internet Mail-->C:\WINDOWS\system32\regsvr32 /u /s C:\PROGRA~1\Yahoo!\Common\ymmapi.dll
Yahoo! Toolbar-->C:\PROGRA~1\Yahoo!\Common\unyt.exe
======Security center information======
FW: Norton Internet Worm Protection (disabled)
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=C:\Program Files\PC Connectivity Solution\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\QuickTime\QTSystem\
"windir"=%SystemRoot%
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 8 Stepping 1, AuthenticAMD
"PROCESSOR_REVISION"=0801
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"FP_NO_HOST_CHECK"=NO
"CLASSPATH"=.;C:\Program Files\Java\jre1.5.0_01\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre1.5.0_01\lib\ext\QTJava.zip
Thanks
Matt
Registry Cleaners
Re. Registry Mechanic 5.1
I don't personally recommend the use of ANY registry cleaners.
Here is an excerpt from a discussion on regcleaners http://forums.whatthetech.com/Regcleaner_t42862.html
Step 1
Malwarebytes' Anti-Malware
Please download Malwarebytes' Anti-Malware to your desktop.
Step 2
Download ComboFix from one of these locations:
Link 1
Link 2
Link 3
* IMPORTANT !!! Save ComboFix.exe to your Desktop
See HERE for help
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Step 3
Remove Programs
Older versions of some programs have vulnerabilities that malware can use to infect your system.
Now click Start---Control Panel. Double click Add or Remove Programs (XP) / Programs and Features (Vista) . If any of the following programs are listed there,
click on the program to highlight it, and click on remove.
- Adobe Reader 8 << Please see below for updating Adobe
- J2SE Runtime Environment 5.0 Update 1
Now close the Control Panel.Java(TM) 6 Update 2
Java(TM) 6 Update 3
Step 4
Logs/Information to Post in Reply
Please post the following logs/Information in your reply
Additional Notes
Your Adobe Acrobat Reader is out of date. Older versions have vulnerabilities that malware can use to infect your system.
Adobe Reader is a large program and uses unnecessary space.
If you prefer a smaller program you can get Foxit 2.0 from http://www.foxitsoftware.com/pdf/rd_intro.php << Recommended
There is a newer version of Adobe Acrobat Reader available.
When the installation is complete go to Add/Remove Programs and uninstall all previous versions.
Thank you for your advice.
On Step 1 that has been completed and the PC is now not suffering from the same problems.
The log for the mailbyte program is attached.
I have aslo downloaded a new Adobe Reader 9.
I am not sure whther I now need to do the Combi fix.
I am not sure what antu virus porgrams I have active. I have no bought software.
There is an old version of pc illin 2002 that seems to pop up every now and again but no updates are uploaded. ot surewhatelese I have so not sure what and how to turn off.
thank you
Matt
alwarebytes' Anti-Malware 1.30
Database version: 1411
Windows 5.1.2600 Service Pack 2
19/11/2008 19:00:45
mbam-log-2008-11-19 (19-00-44).txt
Scan type: Full Scan (C:\|D:\|)
Objects scanned: 112005
Time elapsed: 1 hour(s), 40 minute(s), 51 second(s)
Memory Processes Infected: 4
Memory Modules Infected: 4
Registry Keys Infected: 45
Registry Values Infected: 7
Registry Data Items Infected: 2
Folders Infected: 5
Files Infected: 269
Memory Processes Infected:
C:\Documents and Settings\Matt\Application Data\gadcom\gadcom.exe () -> Unloaded process successfully.
C:\Program Files\GetPack\GetPack24.exe (Trojan.Agent) -> Unloaded process successfully.
C:\WINDOWS\Fonts\svchost.exe (Trojan.Agent) -> Unloaded process successfully.
C:\Documents and Settings\All Users\Application Data\ipd\tray.exe (Trojan.Agent) -> Unloaded process successfully.
Memory Modules Infected:
C:\WINDOWS\system32\uydianye.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\xxyawuVM.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\sqnnhy.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\tuvVPfgf.dll (Trojan.Vundo.H) -> Delete on reboot.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4cafaf0c-c38f-43c1-8080-390e776254de} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tuvvpfgf (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{4cafaf0c-c38f-43c1-8080-390e776254de} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{85b59c84-bb49-4ad1-b45a-576daf69571e} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{85b59c84-bb49-4ad1-b45a-576daf69571e} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{dceb2f56-705d-4349-867a-740a3e80a86a} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{dceb2f56-705d-4349-867a-740a3e80a86a} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{514a5c49-0c7d-42c3-a71b-38864a269b7a} (Trojan.BHO.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{514a5c49-0c7d-42c3-a71b-38864a269b7a} (Trojan.BHO.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\bho_myjavacore.mjcore (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\bho_myjavacore.mjcore.1 (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ipb.band (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{63114106-3276-4086-aaec-fe2cb7c1be0f} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{bdc8b76a-50d4-41e1-a03a-32f18fc324f4} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{c8280a80-5219-42c0-ad72-afe645e768e4} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{000051af-07e2-461b-ba37-a2af7e652e7d} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000051af-07e2-461b-ba37-a2af7e652e7d} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ipb.band.1 (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.htmlpanel (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.htmlpanel.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.pseudotransparentplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.pseudotransparentplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{17e44256-51e0-4d46-a0c8-44e80ab4ba5b} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{4cab59b4-55a3-4737-9fd5-b93c6430bf76} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4cab59b4-55a3-4737-9fd5-b93c6430bf76} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{e0f01490-dcf3-4357-95aa-169a8c2b2190} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{80ef304a-b1c4-425c-8535-95ab6f1eefb8} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\bambanner (Adware.Adrotator) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\icheck (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\BHO_MyJavaCore.DLL (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\GetPack (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\IProxyProvider (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31b35a87-c9a2-0132-5713-431be04c5e51} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{31b35a87-c9a2-0132-5713-431be04c5e51} (Adware.BHO) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cc4c48c9 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cc4c48c9 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\gadcom () -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{4cafaf0c-c38f-43c1-8080-390e776254de} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\getpack24 (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\bmcf7f7b55 (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Host Process (Worm.IRCBot) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\xxyawuvm -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\xxyawuvm -> Delete on reboot.
Folders Infected:
C:\WINDOWS\Fonts\' (Trojan.Agent) -> Files: 40753 -> Quarantined and deleted successfully.
C:\Program Files\GetPack (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\iCheck (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Mjcore (Trojan.BHO) -> Quarantined and deleted successfully.
C:\Documents and Settings\Matt\Application Data\gadcom (Trojan.Agent) -> Quarantined and deleted successfully.
Files Infected:
C:\WINDOWS\system32\tuvVPfgf.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\xxyawuVM.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\MVuwayxx.ini (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\MVuwayxx.ini2 (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\sqnnhy.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\axidojnj.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\jnjodixa.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cexfmkfs.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\sfkmfxec.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dgfwvkxs.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\sxkvwfgd.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drpbbhij.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\jihbbprd.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dujjqurf.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\fruqjjud.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ebfumnpn.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\npnmufbe.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\feayimsa.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\asmiyaef.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\galwadum.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mudawlag.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\gdbwfxmo.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\omxfwbdg.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\gekbqgbd.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dbgqbkeg.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hfatsafq.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\qfastafh.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hlttsotg.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\gtosttlh.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hqjunpro.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\orpnujqh.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ignbrxpn.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\npxrbngi.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\jskuftrq.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\qrtfuksj.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\jwefcjvt.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tvjcfewj.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\kcepnwqb.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\bqwnpeck.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ldvedxwx.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\xwxdevdl.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ltoylxfn.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\nfxlyotl.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mihlkwkd.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dkwklhim.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mwvpojgl.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\lgjopvwm.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mxvabgxt.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\txgbavxm.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\nqehuwuy.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\yuwuheqn.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\nuafemee.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\eemefaun.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\odrpfoun.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\nuofprdo.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\oocsnwrt.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\trwnscoo.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ootmegkx.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\xkgemtoo.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\pabljbrv.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\vrbjlbap.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\pbwhvyrf.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\fryvhwbp.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\qghqpbte.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\etbpqhgq.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\rbjvsevr.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\rvesvjbr.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\saqyrfye.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\eyfryqas.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ttawgawf.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\fwagwatt.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tudvpbuc.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cubpvdut.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\uydianye.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\eynaidyu.ini (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\vxrqqsmc.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cmsqqrxv.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\wkmopagr.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\rgapomkw.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\xwjtgvix.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\xivgtjwx.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\kkknikjo.dll (Trojan.BHO.H) -> Quarantined and deleted successfully.
C:\Documents and Settings\Matt\Application Data\gadcom\gadcom.exe () -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\ipd\ipb.dll (Trojan.BHO) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cwqjyhge.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Program Files\Mjcore\Mjcore.dll (Trojan.BHO) -> Quarantined and deleted successfully.
C:\onoes.exe (Backdoor.Rbot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Matt\Local Settings\Temp\__9.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Matt\Local Settings\Temporary Internet Files\Content.IE5\Q9ATUVWF\nd82m0[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1033\A0114571.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1033\A0115703.EXE (Backdoor.Rbot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1033\A0115706.EXE (Adware.CommAd) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1033\A0115710.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1035\A0116794.exe (Worm.P2P) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1035\A0116796.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1035\A0116831.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1091\A0124139.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1044\A0118676.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1044\A0118725.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1048\A0118872.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1048\A0118874.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1050\A0119036.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1050\A0119060.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1051\A0119094.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1052\A0119133.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1053\A0119178.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1054\A0119228.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1055\A0119273.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1056\A0119332.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1056\A0119353.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1057\A0119427.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1057\A0119441.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1058\A0119487.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1060\A0119598.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1060\A0119604.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1061\A0119665.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1061\A0119618.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1061\A0119622.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1062\A0119713.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1063\A0119750.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1064\A0119790.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1064\A0119804.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1066\A0120804.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1066\A0120790.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1066\A0120827.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1067\A0120885.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1068\A0120948.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1068\A0121041.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1069\A0121103.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1070\A0122085.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1070\A0122086.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5F640FEC-4B3F-4395-A9AE-C028C24E0594}\RP1070\A0122121.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\stfMeane1000106.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\psqsdiga.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\puaqryfy.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\qeslpgiw.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\qjtnxvrl.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\qoMcyWQK.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\qoMggdBr.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cneilpaw.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\affeok.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\aurdzx.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cadyibhq.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cbXOGYPF.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cbXPgecc.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ccnqsa.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dldthdys.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dshaun.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dsmrpoiv.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\efcCvWOF.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\erktkrnv.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\erpinkwn.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ezxjlr.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\faoepf.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\fbclifvu.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\fcbhaw.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\fccaBSmM.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\feawsa.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\gdjhheyq.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\gegigt.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\gfevwmrb.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\gogmfacr.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hgGawVNe.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ljJAPGVM.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ljJAQKcA.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\jkkJbxVm.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\jqfpcefj.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\jspill.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mbxxxgyq.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mnjuox.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\opnnkkJY.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\oscddw.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\otzprp.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ssqQgHaw.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ssuurqdw.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tbdiit.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tcgpvm.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tebjqsiw.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tibisb.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\vmkrxmqk.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\vrjjdv.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\wfyjnl.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\wgrblise.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\wianxk.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\uumnnkie.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\uvqfiawb.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ckhqcmpm.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ckxnbjck.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\kdcgelwx.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\khcldbfw.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\klosngpt.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\rbbfbdyw.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\rdhtgalm.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\svnsbded.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\vtUlKEXP.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\vyxgecru.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\bcplejrq.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\biclcikf.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\bmmvoaqs.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\boeeoaof.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\wwmpfu.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\xdytao.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\xfmfps.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\yabfleqi.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\yayaBSkk.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hxdunt.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hxkwup.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hxrbjo.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hycdpjgf.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\urqRHyvS.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\uhbmkvvq.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ujowss.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ukoyta.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\lprrgsoa.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\lugysidl.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\lwqaplmg.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\pmnnKARj.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\pmooihhn.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\jeplvd.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mwfjjbow.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\nblnlepl.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ddcAsppM.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ddcCRKbC.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ddcDwtsp.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ddcYpmnk.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ddcYsSJa.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\fkjgssmj.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dzrinpxdvrfclic.exe (Adware.Adrotator) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\yayyXOFX.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\yllppl.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\yqvboa.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\yuarhoff.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cusxcf.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\espatnsc.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\haoarlut.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\kuotutdx.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\lagcldut.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\lfgcqktg.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\qsxydouu.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\qwsgfe.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\juufpkmh.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tuvVLdcD.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tuvWmLBU.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tuvWmNhG.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tvsiag.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\twerkoey.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\twjnvmcy.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\EV02\EV022328.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Program Files\GetPack\dictame.gz (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\GetPack\GetPack24.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\GetPack\trgtame.gz (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\iCheck\Uninstall.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mcrh.tmp (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\cookies.ini (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\blnaetmn.dll (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\pac.txt (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\Fonts\Setup.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Program Files\outlook\p.zip (Worm.Alcra) -> Quarantined and deleted successfully.
C:\WINDOWS\Fonts\svchost.exe (Worm.IRCBot) -> Quarantined and deleted successfully.
C:\WINDOWS\Fonts\acrsecB.fon (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\Fonts\acrsecI.fon (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\pskt.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\BMcf7f7b55.xml (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\BMcf7f7b55.txt (Trojan.Vundo) -> Delete on reboot.
C:\Program Files\SETUP.EXE (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Documents and Settings\Matt\Application Data\RBXML550.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\ipd\tray.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\smdat32m.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\yexehfqmltzpjph.dll (Adware.BHO) -> Quarantined and deleted successfully.
It allow outsiders COMPLETE access to every keystroke, account, and password you use while on this machine, and complete access to any other data present...
IF this computer has been used for any kind of important data, my best recommendation is to Disconnect from Internet, Re-Format the entire drive and re-install your Operating system and Applications.
We can likely clean the infected files off the computer, and if you wish we will attempt to do so, but we cannot be sure that the infection didn't do something to your system to reduce the system security. In that instance, even after removal of the infection, you could be subject to another attack or takeover as soon as you re-connect to the Internet.
The Decision Whether to ReFormat or Not should be based on:
If the Computer has been used for any important data, you are strongly advised to do the following, immediately:
Call all of your banks, credit card companies, and financial institutions, informing them that you may be a victim of identity theft, and to put a watch on your accounts or change all your account numbers.
While you are deciding whether to ReFormat and Re-Install, a useful link is here: http://www.dslreports.com/faq/10063
Please let me know what you decide.
Click the Windows 'Start' button > Select 'Run' - then copy/paste the following bolded text into the run box & click OK.
"%userprofile%\desktop\combofix.exe" /killall
When finished, it shall produce a log for you. Post that log in your next reply.
Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall.
If you do not have a current subscription for PC-cillin 2002, then please do the following
Remove Programs
Older versions of some programs have vulnerabilities that malware can use to infect your system.
Now click Start---Control Panel. Double click Add or Remove Programs (XP) / Programs and Features (Vista) . If any of the following programs are listed there,
click on the program to highlight it, and click on remove.
- PC-cillin 2002
Now close the Control Panel.Use an AntiVirus Software - It is very important that you have anti-virus software running on your machine.
This alone can save you a lot of trouble with malware in the future.
Free AV list ( Home users only)
Avira AntiVir
Avast
Update your AntiVirus Software - It is imperitive that you update your Antivirus software at least once a week.
If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.
Antivirus is a MUST
I will download the combifix presumably as per your instructions in one of the earlier posts, then run as suggested above.
I have deleted PC illin and downloaed and am now running the free antivirus software you kindly highlighted.
I have also chnged all banking and financial based passwords plus persoanl email passwords and alerted all relevant parties as to the security threat. I did this in termso fpassword chnages from another PC.
Could you tell me when this dnagerous infection was added ie how long have I bben at risk for ?
I will ensure hat no confodential or ne password datat is entred via the infected PC.
Will reply to log request within 24 hours.
Thank you for the continued support. MAtt
There is no way of telling how long it has been there from the logs, we may get an idea when you run Combofix.
Ok here is the Combofix log as completed after step 2 of your original post / advice
ComboFix 08-11-20.02 - Matt 2008-11-21 16:41:59.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.57 [GMT 0:00]
Running from: c:\documents and settings\Matt\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Matt\Application Data\RBInternetEncodings550.dll
c:\documents and settings\Matt\Application Data\RBShell550.dll
c:\documents and settings\Matt\Local Settings\Temporary Internet Files\fbk.sts
c:\program files\outlook
c:\temp\1cb
c:\temp\1cb\syscheck.log
C:\win.txt
c:\windows\a3kebook.ini
c:\windows\akebook.ini
c:\windows\ANS2000.INI
c:\windows\Fonts\a.zip
c:\windows\system32\akhndy.dll
c:\windows\system32\arcqwg.dll
c:\windows\system32\awtttsrS.dll
c:\windows\system32\bvseespe.dll
c:\windows\system32\byXNfFuU.dll
c:\windows\system32\byXPJBTl.dll
c:\windows\system32\byXQIBsQ.dll
c:\windows\system32\cbXOIxvt.dll
c:\windows\system32\cbXRKDSK.dll
c:\windows\system32\cimqbxoy.dll
c:\windows\system32\cpupfcyn.ini
c:\windows\system32\cqmozv.dll
c:\windows\system32\dbavjtvw.ini
c:\windows\system32\deronsao.ini
c:\windows\system32\dgxsxeaj.ini
c:\windows\system32\djyesm.dll
c:\windows\system32\dvndljfd.ini
c:\windows\system32\dvzywv.dll
c:\windows\system32\eangcaco.dll
c:\windows\system32\eapedoog.ini
c:\windows\system32\EV02
c:\windows\system32\f1
c:\windows\system32\f1\uPA34v10.exe
c:\windows\system32\felcry.dll
c:\windows\system32\frkoodfm.dll
c:\windows\system32\fvdwshxf.ini
c:\windows\system32\fwgpin.dll
c:\windows\system32\geBuRJab.dll
c:\windows\system32\gectdwhu.dll
c:\windows\system32\gEwvUlKE.dll
c:\windows\system32\gmkhao.dll
c:\windows\system32\gplmgr.dll
c:\windows\system32\hgGayvuR.dll
c:\windows\system32\hgGvspOh.dll
c:\windows\system32\hgGvtQKa.dll
c:\windows\system32\hgGvtSjK.dll
c:\windows\system32\hgGvuTKc.dll
c:\windows\system32\hiraimhm.dll
c:\windows\system32\httgwujx.ini
c:\windows\system32\ibjnuwnx.dll
c:\windows\system32\iifeeEtT.dll
c:\windows\system32\iiffDSKD.dll
c:\windows\system32\iifgHabY.dll
c:\windows\system32\ikpruvcs.dll
c:\windows\system32\itunah.dll
c:\windows\system32\ivhemx.dll
c:\windows\system32\jcqfgobi.ini
c:\windows\system32\jhcwyjgs.dll
c:\windows\system32\jkkLEUKB.dll
c:\windows\system32\jkkLEULB.dll
c:\windows\system32\kdonmtfs.dll
c:\windows\system32\khfFXrQH.dll
c:\windows\system32\khfGwVOf.dll
c:\windows\system32\kjgbqb.dll
c:\windows\system32\kkkfagsk.dll
c:\windows\system32\ljJCuSIB.dll
c:\windows\system32\ljJCvUKa.dll
c:\windows\system32\ljJDSKCs.dll
c:\windows\system32\ljJDWQJB.dll
c:\windows\system32\mlJApPHb.dll
c:\windows\system32\mlJAsQii.dll
c:\windows\system32\mlJYqRIa.dll
c:\windows\system32\mlJYspND.dll
c:\windows\system32\mqwvobxo.ini
c:\windows\system32\mrfkrgpr.ini
c:\windows\system32\MSINET.oca
c:\windows\system32\MVuwayxx.ini
c:\windows\system32\neakklxj.dll
c:\windows\system32\nnnmmljJ.dll
c:\windows\system32\nnnoNhhi.dll
c:\windows\system32\NUBKlUtv.ini
c:\windows\system32\nvciykwo.dll
c:\windows\system32\nyrxlt.dll
c:\windows\system32\ogljwfke.dll
c:\windows\system32\OIUUYG.DLL
c:\windows\system32\opnkjJcD.dll
c:\windows\system32\opnkjJyA.dll
c:\windows\system32\opnlIxUL.dll
c:\windows\system32\opnnmJdd.dll
c:\windows\system32\opnonnOG.dll
c:\windows\system32\pmnmnKEu.dll
c:\windows\system32\puvqxunw.dll
c:\windows\system32\pyomvklb.ini
c:\windows\system32\qmcicjpt.dll
c:\windows\system32\qoMdARKC.dll
c:\windows\system32\qoMdDuuT.dll
c:\windows\system32\qoMeCrqr.dll
c:\windows\system32\qoMfebxw.dll
c:\windows\system32\qupkcyhc.dll
c:\windows\system32\rcwmdmtk.dll
c:\windows\system32\rqRIyVmL.dll
c:\windows\system32\rqRJCRJc.dll
c:\windows\system32\RtAIQXyb.ini
c:\windows\system32\sbevybfp.ini
c:\windows\system32\skbewwoa.dll
c:\windows\system32\squytaqv.ini
c:\windows\system32\ssqNHbYP.dll
c:\windows\system32\ssqnkLFy.dll
c:\windows\system32\stynljxm.ini
c:\windows\system32\trvgwlfk.ini
c:\windows\system32\tuvcrnxj.dll
c:\windows\system32\tuvSliIB.dll
c:\windows\system32\tuvTnOff.dll
c:\windows\system32\tuvVNFWo.dll
c:\windows\system32\udnxux.dll
c:\windows\system32\uhmdkion.ini
c:\windows\system32\urqPgddC.dll
c:\windows\system32\vCJiQqru.ini
c:\windows\system32\vhmbml.dll
c:\windows\system32\vtUlLBtS.dll
c:\windows\system32\vtUnmMdA.dll
c:\windows\system32\vtUnnmMC.dll
c:\windows\system32\wsvrxc.dll
c:\windows\system32\wvUkJaxY.dll
c:\windows\system32\wvUmkkhf.dll
c:\windows\system32\wxhlbptd.dll
c:\windows\system32\wxmxvjfp.ini
c:\windows\system32\xayJknmp.ini
c:\windows\system32\xhxldjib.dll
c:\windows\system32\xugjwb.dll
c:\windows\system32\xxyawuVM.dll
c:\windows\system32\xxyvvSmM.dll
c:\windows\system32\xxyxWOfd.dll
c:\windows\system32\yayvSjiF.dll
c:\windows\system32\yayvSlMD.dll
c:\windows\system32\yfisxdbs.ini
c:\windows\system32\ynewjq.dll
c:\windows\system32\ypskil.dll
c:\windows\system32\ywswyruc.ini
c:\windows\system32\zejzlb.dll
.
((((((((((((((((((((((((( Files Created from 2008-10-21 to 2008-11-21 )))))))))))))))))))))))))))))))
.
2008-11-21 10:03 . 2008-11-21 10:03 <DIR> d
c:\program files\Avira
2008-11-21 10:03 . 2008-11-21 10:03 <DIR> d
c:\documents and settings\All Users\Application Data\Avira
2008-11-20 11:16 . 2008-11-20 11:16 <DIR> d
c:\documents and settings\Matt\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2008-11-20 10:44 . 2008-11-20 10:44 <DIR> d
c:\program files\Common Files\Adobe AIR
2008-11-20 10:23 . 2008-11-20 10:50 <DIR> d
c:\program files\NOS
2008-11-20 10:23 . 2008-11-20 10:50 <DIR> d
c:\documents and settings\All Users\Application Data\NOS
2008-11-19 16:10 . 2008-11-19 16:10 <DIR> d
c:\documents and settings\Matt\Application Data\Malwarebytes
2008-11-19 16:10 . 2008-10-22 16:10 15,504 --a
c:\windows\system32\drivers\mbam.sys
2008-11-19 16:09 . 2008-11-19 16:10 <DIR> d
c:\program files\Malwarebytes' Anti-Malware
2008-11-19 16:09 . 2008-11-19 16:09 <DIR> d
c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-19 16:09 . 2008-10-22 16:10 38,496 --a
c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-19 08:39 . 2008-11-19 08:39 465,920 --a
c:\windows\system32\iesvcmon.exe
2008-11-18 22:35 . 2008-11-18 22:36 <DIR> d
C:\rsit
2008-11-18 21:55 . 2008-11-18 21:55 41,472 --a
c:\windows\system32\gfcnncad.dll
2008-11-18 08:31 . 2008-11-18 08:31 <DIR> d
c:\windows\system32\dPI02
2008-11-18 08:31 . 2008-11-18 08:31 <DIR> d
c:\temp\FT62
2008-11-16 21:54 . 2008-11-16 21:54 85,504 --a
c:\windows\system32\qlldefca.dll
2008-11-15 21:53 . 2008-11-15 21:53 85,504 --a
c:\windows\system32\eoumymtw.dll
2008-11-14 21:53 . 2008-11-14 21:53 85,504 --a
c:\windows\system32\eeovgobr.dll
2008-11-13 21:51 . 2008-11-13 21:51 85,504 --a
c:\windows\system32\mxfwkkfd.dll
2008-11-12 21:50 . 2008-11-12 21:50 85,504 --a
c:\windows\system32\lxsxlmpc.dll
2008-11-11 10:04 . 2008-11-11 10:04 85,504 --a
c:\windows\system32\bhlvrgmk.dll
2008-11-09 09:29 . 2008-11-09 09:29 <DIR> d
c:\windows\system32\sX3i02
2008-11-09 09:29 . 2008-11-09 09:29 <DIR> d
c:\temp\PRE45
2008-11-07 16:41 . 2008-11-07 17:17 <DIR> d
c:\program files\Safari
2008-11-07 16:38 . 2008-11-07 16:39 <DIR> d
c:\program files\Apple Software Update
2008-11-05 22:01 . 2008-11-05 22:01 85,504 --a
c:\windows\system32\tuivyemh.dll
2008-11-05 10:02 . 2008-11-07 20:53 <DIR> d
c:\program files\Opera
2008-11-04 09:20 . 2008-11-04 09:20 <DIR> d
c:\program files\Sun
2008-11-03 21:59 . 2008-11-03 21:59 92,160 --a
c:\windows\system32\salsyrsi.dll
2008-11-02 21:58 . 2008-11-02 21:58 92,160 --a
c:\windows\system32\jnxlhkps.dll
2008-11-01 21:57 . 2008-11-01 21:57 92,160 --a
c:\windows\system32\lyudeuvi.dll
2008-10-31 21:54 . 2008-10-31 21:54 92,160 --a
c:\windows\system32\ibebnxau.dll
2008-10-30 22:56 . 2008-10-30 22:56 <DIR> d
c:\program files\MSECache
2008-10-30 21:54 . 2008-10-30 21:54 92,160 --a
c:\windows\system32\ixowwcxh.dll
2008-10-30 15:25 . 2008-10-30 15:25 <DIR> d
c:\windows\system32\QI02
2008-10-30 15:25 . 2008-10-30 15:25 <DIR> d
c:\temp\NT32
2008-10-29 21:53 . 2008-10-29 21:53 92,160 --a
c:\windows\system32\fxkohtqt.dll
2008-10-28 20:53 . 2008-10-28 20:53 92,160 --a
c:\windows\system32\pdsjqvuc.dll
2008-10-27 20:53 . 2008-10-27 20:53 92,160 --a
c:\windows\system32\hmuttlem.dll
2008-10-26 20:52 . 2008-10-26 20:52 92,160 --a
c:\windows\system32\uqaorppx.dll
2008-10-25 20:52 . 2008-10-25 20:52 92,160 --a
c:\windows\system32\qtonefne.dll
2008-10-24 20:49 . 2008-10-24 20:49 92,160 --a
c:\windows\system32\ruxmpgys.dll
2008-10-23 20:49 . 2008-10-23 20:49 92,160 --a
c:\windows\system32\cobtxfto.dll
2008-10-22 20:50 . 2008-10-22 20:50 92,160 --a
c:\windows\system32\pvivhbma.dll
2008-10-21 20:47 . 2008-10-21 20:47 92,160 --a
c:\windows\system32\bbmjpsfc.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-21 16:20
d
w c:\program files\TextAloud
2008-11-20 11:15
d
w c:\program files\Common Files\Adobe
2008-11-19 22:12
d
w c:\program files\Java
2008-11-19 22:05
d
w c:\program files\Lavasoft
2008-11-19 22:05
d
w c:\program files\Common Files\Wise Installation Wizard
2008-11-19 18:49
d
w c:\documents and settings\All Users\Application Data\ipd
2008-11-18 22:35
d
w c:\program files\Trend Micro
2008-11-18 17:10
d
w c:\program files\SUPERAntiSpyware
2008-11-17 21:46
d
w c:\documents and settings\Matt\Application Data\Skype
2008-11-17 20:47
d
w c:\documents and settings\Matt\Application Data\skypePM
2008-11-07 20:54
d
w c:\program files\Hewlett-Packard
2008-11-07 16:45
d
w c:\documents and settings\Matt\Application Data\Apple Computer
2008-10-30 15:23
d
w c:\program files\Lx_cats
2008-10-25 20:56
d
w c:\documents and settings\Matt\Application Data\Pamela
2008-10-25 20:55
d
w c:\program files\Pamela
2008-10-19 20:46 92,160 ----a-w c:\windows\system32\jhgjqiwf.dll
2008-10-18 20:45 92,160 ----a-w c:\windows\system32\fjtnqpxn.dll
2008-10-17 20:44 92,160 ----a-w c:\windows\system32\tnempaoh.dll
2008-10-16 20:45 92,160 ----a-w c:\windows\system32\lufrostj.dll
2008-10-15 20:43 92,160 ----a-w c:\windows\system32\grielanq.dll
2008-10-14 20:42 92,160 ----a-w c:\windows\system32\wqwecstt.dll
2008-10-13 20:42 92,160 ----a-w c:\windows\system32\cfveenur.dll
2008-10-12 08:56 92,160 ----a-w c:\windows\system32\vtgjivvm.dll
2008-10-12 08:50 34,816 ----a-w c:\windows\system32\urqQiGWQ.dll
2008-10-12 08:50 34,816 ----a-w c:\windows\system32\cbXPhhhG.dll
2008-10-11 08:55 92,160 ----a-w c:\windows\system32\lrubxina.dll
2008-10-11 07:28
d
w c:\program files\eQSO-PC-Client
2008-10-10 08:58 114,688 ----a-w c:\windows\system32\niemicnp.dll
2008-10-10 08:58 114,688 ----a-w c:\windows\system32\khxxto.dll
2008-10-10 08:53 92,160 ----a-w c:\windows\system32\sihpxlef.dll
2008-10-09 08:53 92,160 ----a-w c:\windows\system32\tvbackua.dll
2008-10-08 08:56 115,200 ----a-w c:\windows\system32\ooitju.dll
2008-10-08 08:56 115,200 ----a-w c:\windows\system32\hmkmvvit.dll
2008-10-08 08:53 92,160 ----a-w c:\windows\system32\trwctuwa.dll
2008-10-07 08:52 92,160 ----a-w c:\windows\system32\hyrwctts.dll
2008-10-06 08:58 114,688 ----a-w c:\windows\system32\slzjti.dll
2008-10-06 08:58 114,688 ----a-w c:\windows\system32\bxtpyjaw.dll
2008-10-06 08:55 92,160 ----a-w c:\windows\system32\jmjhvwrc.dll
2008-10-05 08:55 114,688 ----a-w c:\windows\system32\rjpehnoc.dll
2008-10-05 08:55 114,688 ----a-w c:\windows\system32\pbeesf.dll
2008-10-05 08:52 92,160 ----a-w c:\windows\system32\ofaxisfd.dll
2008-10-05 08:50 105,984 ----a-w c:\windows\system32\nurrjeta.dll
2008-10-03 21:45 92,160 ----a-w c:\windows\system32\pqbkjlxc.dll
2008-10-03 21:45 115,200 ----a-w c:\windows\system32\qerjvxhh.dll
2008-10-03 21:45 115,200 ----a-w c:\windows\system32\fsjlth.dll
2008-10-03 21:42 104,960 ----a-w c:\windows\system32\mftbgoba.dll
2008-10-03 21:40 92,160 ----a-w c:\windows\system32\gkiyvwrj.dll
2008-10-03 07:42 34,304 ----a-w c:\windows\system32\fccddeCu.dll
2008-10-03 07:42 34,304 ----a-w c:\windows\system32\byXPHwXp.dll
2008-10-02 20:58 114,688 ----a-w c:\windows\system32\kiynpu.dll
2008-10-02 20:58 114,688 ----a-w c:\windows\system32\ciejgtht.dll
2008-10-02 20:56 105,472 ----a-w c:\windows\system32\ybkmtrfl.dll
2008-10-02 20:55 92,160 ----a-w c:\windows\system32\qlvesiln.dll
2008-10-02 06:47 34,304 ----a-w c:\windows\system32\xxyayYrR.dll
2008-10-02 06:47 34,304 ----a-w c:\windows\system32\tuvVOFYR.dll
2008-10-01 21:00 115,200 ----a-w c:\windows\system32\ljzggz.dll
2008-10-01 21:00 115,200 ----a-w c:\windows\system32\ddsqwnbi.dll
2008-10-01 20:55 34,304 ----a-w c:\windows\system32\wvUmnNGV.dll
2008-10-01 20:55 34,304 ----a-w c:\windows\system32\geBuVOGx.dll
2008-10-01 20:54 92,160 ----a-w c:\windows\system32\rfpuoalk.dll
2008-10-01 20:53 105,472 ----a-w c:\windows\system32\hqwyrgoa.dll
2008-09-30 20:19 92,160 ----a-w c:\windows\system32\iggdygjk.dll
2008-09-30 20:19 105,472 ----a-w c:\windows\system32\banvvlld.dll
2008-09-29 20:20 92,160 ----a-w c:\windows\system32\hspuirar.dll
2008-09-29 20:19 105,472 ----a-w c:\windows\system32\rkireasp.dll
2008-09-29 07:58 35,328 ----a-w c:\windows\system32\iifebBsQ.dll
2008-09-29 07:58 35,328 ----a-w c:\windows\system32\awtusppq.dll
2008-09-28 20:18 104,960 ----a-w c:\windows\system32\pnyttyla.dll
2008-09-27 20:18 92,160 ----a-w c:\windows\system32\jggxoknu.dll
2008-09-27 20:18 105,984 ----a-w c:\windows\system32\foxuyoxu.dll
2008-09-27 07:39 34,304 ----a-w c:\windows\system32\jkkJyASm.dll
2008-09-27 07:39 34,304 ----a-w c:\windows\system32\efcASiGA.dll
2008-09-26 20:19 92,160 ----a-w c:\windows\system32\kewwaxud.dll
2008-09-26 20:19 105,984 ----a-w c:\windows\system32\gpyxmyee.dll
2008-09-26 06:48 34,304 ----a-w c:\windows\system32\iifgGYst.dll
2008-09-26 06:48 34,304 ----a-w c:\windows\system32\awtqnnlL.dll
2008-09-25 20:16 92,160 ----a-w c:\windows\system32\tkdkgujq.dll
2008-09-25 20:16 105,472 ----a-w c:\windows\system32\roqilymp.dll
2008-09-25 06:38 68,096 ----a-w c:\windows\system32\ljJBusQh.dll
2008-09-24 20:16 92,160 ----a-w c:\windows\system32\qopiodoh.dll
2008-09-24 20:16 105,472 ----a-w c:\windows\system32\ixldxrbj.dll
2008-09-24 07:14 68,096 ----a-w c:\windows\system32\hgGwWPIA.dll
2008-09-23 20:17 96,256 ----a-w c:\windows\system32\gdwfestj.dll
2008-09-23 20:17 92,160 ----a-w c:\windows\system32\qkprtcwv.dll
2008-09-23 07:33 34,816 ----a-w c:\windows\system32\pmnkKcda.dll
2008-09-23 07:33 34,816 ----a-w c:\windows\system32\efcCuSjI.dll
2008-09-22 20:17 92,160 ----a-w c:\windows\system32\dbkfvdhb.dll
2008-09-22 20:14 95,232 ----a-w c:\windows\system32\nyfmjgbx.dll
2008-09-22 07:45 34,816 ----a-w c:\windows\system32\tuvUMcbb.dll
2008-09-22 07:45 34,816 ----a-w c:\windows\system32\cbXQiGxu.dll
2008-09-21 20:19 221,184 ----a-w c:\windows\system32\oahcpfop.dll
2008-09-21 20:19 108,544 ----a-w c:\windows\system32\xxywTNDW.dll
2008-09-21 20:16 92,160 ----a-w c:\windows\system32\rklmmbgk.dll
2008-09-21 10:16
d
w c:\program files\Skype
2008-09-21 10:16
d
w c:\documents and settings\All Users\Application Data\Skype
2008-09-21 10:15
d
w c:\program files\Common Files\Skype
2008-09-21 10:02 34,816 ----a-w c:\windows\system32\rqRHwTLe.dll
2008-09-21 10:02 34,816 ----a-w c:\windows\system32\jkkHXOfe.dll
2008-09-20 20:16 221,184 ----a-w c:\windows\system32\aqluveyb.dll
2008-09-20 20:16 108,544 ----a-w c:\windows\system32\mlJCSmNg.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 1318912]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"iesvcmon"="c:\windows\system32\iesvcmon.exe" [2008-11-19 465920]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 32768]
"PE2CKFNT SE"="c:\program files\Ulead Systems\Ulead Photo Express 2 SE\ChkFont.exe" [1998-07-03 25088]
"StatusClient"="c:\program files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe" [2002-12-16 36864]
"TomcatStartup"="c:\program files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe" [2003-03-31 155648]
"HPLJ Config"="c:\program files\Hewlett-Packard\hp LaserJet 1010 Series\SetConfig.exe" [2003-03-31 28672]
"ScreenPrint32"="c:\program files\ScreenPrint32 v3\ScreenPrint32.exe" [2003-05-15 446464]
"LXCGCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll" [2005-07-20 73728]
"lxcgmon.exe"="c:\program files\Lexmark 2300 Series\lxcgmon.exe" [2005-07-21 200704]
"EzPrint"="c:\program files\Lexmark 2300 Series\ezprint.exe" [2005-08-01 94208]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-08-23 180269]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-10-25 282624]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2006-10-30 256576]
"FixCamera"="c:\windows\FixCamera.exe" [2006-06-01 20480]
"tsnp2std"="c:\windows\tsnp2std.exe" [2006-01-06 110592]
"snp2std"="c:\windows\vsnp2std.exe" [2006-01-06 344064]
"hp Update 2100C"="c:\sj644\hpupdate.exe" [2002-01-24 28672]
"iesvcmon"="c:\windows\system32\iesvcmon.exe" [2008-11-19 465920]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"SoundMan"="SOUNDMAN.EXE" [2003-08-15 c:\windows\SOUNDMAN.EXE]
"VTTimer"="VTTimer.exe" [2003-05-07 c:\windows\system32\VTTimer.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-04 15360]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2006-12-20 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 12:41 294912 c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=sqnnhy.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\K1RFD\\EchoLink\\EchoLink.exe"=
"c:\\Program Files\\Linksys\\WMP11 Config Utility\\WMP11CFG.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\ypager.exe"=
"c:\\WINDOWS\\system32\\java.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Hewlett-Packard\\Toolbox2.0\\Javasoft\\JRE\\1.3.1\\bin\\javaw.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\CQPhone\\CQPhone.exe"=
"c:\\Program Files\\CQPhone\\cqvideo.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5200:UDP"= 5200:UDP:tcp 5200
"5199:UDP"= 5199:UDP:udp 5199
"3689:UDP"= 3689:UDP:udp
"3689:TCP"= 3689:TCP:tcp
R3 SNP2STD;USB2.0 PC Camera (SNP2STD);c:\windows\system32\DRIVERS\snp2sxp.sys [2006-12-29 10305664]
S2 W9986;DVR driver;c:\windows\system32\Drivers\dvr.sys [2005-03-27 18172]
S3 iteio;iteio;\??\c:\windows\System32\drivers\iteio.sys [2004-09-07 3680]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys [2008-11-19 38496]
S3 WMP11V27;Instant Wireless PCI Card V2.7 Driver;c:\windows\system32\DRIVERS\WMP11V27.sys [2004-10-05 171776]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\Enterprise_Launcher.exe
*Newly Created Service* - SSMDRV
.
- - - - ORPHANS REMOVED - - - -
BHO-{4CAFAF0C-C38F-43C1-8080-390E776254DE} - c:\windows\system32\tuvVPfgf.dll
BHO-{85B59C84-BB49-4AD1-B45A-576DAF69571E} - c:\windows\system32\xxyawuVM.dll
HKCU-Run-MsnMsgr - c:\program files\MSN Messenger\MsnMsgr.Exe
HKCU-Run-AdobeUpdater - c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe
HKLM-Run-LogitechVideoRepair - c:\program files\Logitech\Video\ISStart.exe
HKLM-Run-cc4c48c9 - c:\windows\system32\uydianye.dll
HKLM-Run-BMcf7f7b55 - c:\windows\system32\blnaetmn.dll
HKLM-Run-RegistryMechanic - (no file)
ShellExecuteHooks-{4CAFAF0C-C38F-43C1-8080-390E776254DE} - c:\windows\system32\tuvVPfgf.dll
Notify-tuvVPfgf - tuvVPfgf.dll
.
Supplementary Scan
.
FireFox -: Profile - c:\documents and settings\Matt\Application Data\Mozilla\Firefox\Profiles\vj4olpl0.Default User\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://start.mozilla.org/firefox?client=firefox-a&rls=org.mozilla:en-GB:official
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-21 16:49:02
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Other Running Processes
.
c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\WgaTray.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\lxcgcoms.exe
c:\program files\Ulead Systems\Ulead Photo Express 2 SE\CalCheck.exe
c:\program files\Linksys\WMP11 Config Utility\WMP11CFG.exe
c:\windows\SoftwareDistribution\Download\a17b5df07c4dfb0b394eabad42d90933\update\update.exe
.
**************************************************************************
.
Completion time: 2008-11-21 17:03:06 - machine was rebooted [Matt]
ComboFix-quarantined-files.txt 2008-11-21 17:02:46
Pre-Run: 12,907,528,192 bytes free
Post-Run: 12,907,597,824 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
427 --- E O F --- 2008-09-12 08:18:26
Custom CFScript
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.
Step 2
Kaspersky Online Scanner .
Your Antivirus and/or Antispyware may give a warning during the scan. This is perfectly normal
NOTE:- This scan is best done from IE (Internet Explorer)
NOTE:- Vista users should start IE by Start(Vista Orb) >> Internet Explorer >> Right-Click Run As Admin
Go Here http://www.kaspersky.com/kos/eng/partner/default/kavwebscan.html
Read the Requirements and limitations before you click Accept.
Once the database has downloaded, click My Computer in the left pane
Now go and put the kettle on !
When the scan has completed, click Save Report As...
Enter a name for the file in the Filename: text box and then click the down arrow to the right of Save as type: and select text file (*.txt)
Click Save - by default the file will be saved to your Desktop, but you can change this if you wish.
**Note**
To optimize scanning time and produce a more sensible report for review:
Note for Internet Explorer 7 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%.
Step 3
Logs/Information to Post in Reply
Please post the following logs/Information in your reply