Hello!
My name is Sam and I will be helping you.
I will do my best to communicate clearly to you so that we can resolve your issues as quickly as possible. In order to see what's going on with your computer I will ask for you to post various logs from the tools that we will use to fix your computer. Please communicate freely with me about how your computer is reacting and behaving as we work through this process.
Download SDFix and save it to your Desktop.
Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)
Please then reboot your computer in Safe Mode by doing the following :
- Restart your computer
- After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
- Instead of Windows loading as normal, the Advanced Options Menu should appear;
- Select the first option, to run Windows in Safe Mode, then press Enter.
- Choose your usual account.
- Open the extracted SDFix folder and double click RunThis.bat to start the script.
- Type Y to begin the cleanup process.
- It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
- Press any Key and it will restart the PC.
- When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
- Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
(Report.txt will also be copied to Clipboard ready for posting back on the forum). - Finally paste the contents of the Report.txt back here in your next reply.
==================
Please download random's system information tool (RSIT) and save it to your desktop.- Double click on RSIT.exe to run it.
- Click Continue at the disclaimer screen.
- Once it has finished, two logs will open. Please post the contents of both log.txt (<<will be maximized) and info.txt (<<will be minimized)
Here is what you requested and thanks for your help. I included a comment after the report and log.
SDFix: Version 1.240 Run by Ray on Wed 11/19/2008 at 03:21 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Checking Services :
Name :
TDSSserv.sys
Path :
\systemroot\system32\drivers\TDSSmaxt.sys
TDSSserv.sys - Deleted
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
Checking Files :
Trojan Files Found:
C:\115430~1 - Deleted
C:\DOCUME~1\RAY\COOKIES\EGEGYSA.SCR - Deleted
C:\Documents and Settings\All Users.WINDOWS.0\Documents\pymazoxore.scr - Deleted
C:\Program Files\Common Files\abaz._sy - Deleted
C:\WINDOWS.0\system32\e2.exe - Deleted
C:\WINDOWS.sys - Deleted
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-11-19 15:43:10
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Azureus\\Azureus.exe"="C:\\Program Files\\Azureus\\Azureus.exe:*:Enabled:Azureus"
"C:\\Program Files\\Emule\\emule.exe"="C:\\Program Files\\Emule\\emule.exe:*:Enabled:DaZZle Emule Mod"
"C:\\Program Files\\Ubisoft\\IL-2 Sturmovik 1946\\il2fb.exe"="C:\\Program Files\\Ubisoft\\IL-2 Sturmovik 1946\\il2fb.exe:*:Enabled:il2fb"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Pinnacle\\Studio 10\\programs\\RM.exe"="C:\\Program Files\\Pinnacle\\Studio 10\\programs\\RM.exe:*:Enabled:Render Manager"
"C:\\Program Files\\Pinnacle\\Studio 10\\programs\\Studio.exe"="C:\\Program Files\\Pinnacle\\Studio 10\\programs\\Studio.exe:*:Enabled:Studio"
"C:\\Program Files\\Pinnacle\\Studio 10\\programs\\PMSRegisterFile.exe"="C:\\Program Files\\Pinnacle\\Studio 10\\programs\\PMSRegisterFile.exe:*:Enabled:PMSRegisterFile"
"C:\\Program Files\\Pinnacle\\Studio 10\\programs\\umi.exe"="C:\\Program Files\\Pinnacle\\Studio 10\\programs\\umi.exe:*:Enabled:umi"
"C:\\rowan\\mig\\Mig.exe"="C:\\rowan\\mig\\Mig.exe:*:Enabled:MIG"
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"="C:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Enabled:Firefox"
"C:\\Program Files\\InterVideo\\DVD8\\WinDVD.exe"="C:\\Program Files\\InterVideo\\DVD8\\WinDVD.exe:*:Enabled:WinDVD"
"C:\\Program Files\\Steam\\steamapps\\nonaste\\counter-strike source\\hl2.exe"="C:\\Program Files\\Steam\\steamapps\\nonaste\\counter-strike source\\hl2.exe:*:Enabled:hl2"
"C:\\Program Files\\Steam\\steamapps\\nonaste\\half-life 2 deathmatch\\hl2.exe"="C:\\Program Files\\Steam\\steamapps\\nonaste\\half-life 2 deathmatch\\hl2.exe:*:Enabled:hl2"
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"="C:\\Program Files\\AVG\\AVG8\\avgemc.exe:*:Enabled:avgemc.exe"
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"="C:\\Program Files\\AVG\\AVG8\\avgupd.exe:*:Enabled:avgupd.exe"
"C:\\Program Files\\Steam\\steamapps\\nonaste\\day of defeat source\\hl2.exe"="C:\\Program Files\\Steam\\steamapps\\nonaste\\day of defeat source\\hl2.exe:*:Enabled:hl2"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
Remaining Files :
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes :
Mon 3 Mar 2008 5,702 A..H. --- "C:\WINDOWS.0\nod32restoretemdono.reg"
Sat 26 Apr 2008 24 ..SH. --- "C:\WINDOWS.0\SCE3C12D1.tmp"
Thu 2 Nov 2006 200,706 A.SHR --- "C:\WINDOWS.0\server.exe"
Wed 22 Oct 2008 949,072 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\advcheck.dll"
Mon 7 Jul 2008 1,429,840 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
Mon 7 Jul 2008 4,891,472 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
Mon 18 Aug 2008 1,832,272 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
Wed 22 Oct 2008 962,896 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\Tools.dll"
Fri 12 Nov 2004 37,376 A..H. --- "C:\Program Files\Common Files\Adobe\ESD\DLMCleanup.exe"
Mon 5 May 2003 348,160 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\AACMP4.EXE"
Thu 7 Feb 2002 94,208 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\lpaccodec.dll"
Fri 2 Feb 2001 40,960 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\lpac_codec_api.dll"
Mon 12 Apr 2004 212,992 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\OFR.EXE"
Thu 16 Jan 2003 278,528 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\PNCRT.dll"
Mon 5 May 2003 16,384 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\RMADEC.EXE"
Fri 24 Nov 2006 4,348 ..SH. --- "C:\SDFix\backups\movedfile.vir\DRM\DRMv1.bak"
Wed 28 Jun 2006 4,348 ..SH. --- "C:\SDFix\backups\movedfile.vir\DRM\DRMv1.key.bak"
Thu 28 Dec 2006 444 A..HR --- "C:\Documents and Settings\Raymond\Application Data\SecuROM\UserData\securom_v7_01.bak"
Sat 20 Jul 2002 45,056 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\AC3\AC3ENC.DLL"
Wed 20 Feb 2002 98,304 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\AC3\AZID.DLL"
Fri 11 Apr 2003 73,766 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\Common\atrc3260.dll"
Fri 11 Apr 2003 45,099 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\Common\auth3260.dll"
Fri 11 Apr 2003 65,575 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\Common\cook3260.dll"
Fri 11 Apr 2003 102,437 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\Common\drv13260.dll"
Fri 11 Apr 2003 176,165 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\Common\drv23260.dll"
Fri 11 Apr 2003 208,935 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\Common\drv33260.dll"
Fri 11 Apr 2003 217,127 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\Common\drv43260.dll"
Tue 15 Apr 2003 976,896 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\Common\pnen3260.dll"
Fri 11 Apr 2003 348,203 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\Common\pnvi3260.dll"
Fri 11 Apr 2003 53,289 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\Common\pnxr3260.dll"
Fri 11 Apr 2003 45,101 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\Common\ramf3260.dll"
Fri 11 Apr 2003 135,213 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\Common\rare3260.dll"
Mon 14 Oct 2002 57,344 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\Common\rims3290.dll"
Fri 11 Apr 2003 163,885 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\Common\rmff3260.dll"
Mon 14 Oct 2002 737,280 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\Common\rmse3290.dll"
Sun 13 Oct 2002 245,760 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\Common\rmwr3260.dll"
Fri 11 Apr 2003 245,805 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\Common\rnlt3260.dll"
Sun 13 Oct 2002 245,760 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\Common\rorw3290.dll"
Sun 13 Oct 2002 114,688 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\Common\rtae3290.dll"
Mon 14 Oct 2002 65,536 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\Common\rtin3290.dll"
Mon 14 Oct 2002 163,840 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\Common\rtve3290.dll"
Fri 11 Apr 2003 45,093 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\Common\rv103260.dll"
Fri 11 Apr 2003 98,341 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\Common\rv203260.dll"
Fri 11 Apr 2003 94,247 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\Common\rv303260.dll"
Fri 11 Apr 2003 90,151 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\Common\rv403260.dll"
Fri 11 Apr 2003 159,785 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\Common\rvre3260.dll"
Mon 14 Oct 2002 102,400 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\Common\sipr3260.dll"
Fri 11 Apr 2003 61,485 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\Common\smpl3260.dll"
Fri 11 Apr 2003 106,541 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\Common\vsrl3260.dll"
Fri 11 Apr 2003 86,061 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\Common\xmlp3261.dll"
Fri 11 Apr 2003 159,787 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\Common\zipf3260.dll"
Sun 23 Feb 2003 64,512 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\MusePack\MPPDEC.EXE"
Fri 25 Oct 2002 79,360 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\MusePack\MPPENC.EXE"
Mon 4 Mar 2002 352,299 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\PsyTEL\AACENC.EXE"
Mon 5 May 2003 348,160 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\PsyTEL\AACMP4.EXE"
Mon 4 Mar 2002 221,184 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\PsyTEL\FASTENC.EXE"
Thu 6 Sep 2001 688,128 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\PsyTEL\IA32MATH.DLL"
Fri 14 Feb 2003 910,152 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\Shorten\CYGWIN1.DLL"
Sat 19 Apr 2003 60,928 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\Shorten\SHORTEN.EXE"
Wed 8 Oct 2003 75,264 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\Speex\speexdec.exe"
Wed 8 Oct 2003 77,312 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\Speex\speexenc.exe"
Tue 18 Feb 2003 103,936 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\WavPack\WAVPACK.EXE"
Tue 18 Feb 2003 102,912 ...H. --- "C:\Program Files\Common Files\Ahead\AudioPlugins\WavPack\WVUNPACK.EXE"
Finished!Logfile of random's system information tool 1.04 (written by random/random)
Run by Ray at 2008-11-19 15:48:26
Microsoft Windows XP Professional Service Pack 2
System drive C: has 138 GB (58%) free of 238 GB
Total RAM: 2047 MB (75% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:48:49 PM, on 11/19/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS.0\System32\smss.exe
C:\WINDOWS.0\system32\winlogon.exe
C:\WINDOWS.0\system32\services.exe
C:\WINDOWS.0\system32\lsass.exe
C:\WINDOWS.0\system32\svchost.exe
C:\WINDOWS.0\system32\svchost.exe
C:\WINDOWS.0\system32\ZoneLabs\vsmon.exe
C:\WINDOWS.0\Explorer.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS.0\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\nHancer\nHancerService.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS.0\system32\nvsvc32.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS.0\System32\PAStiSvc.exe
C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Ray\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Ray.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://safesearch.cyberdefender.com/smallsearch.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Service Pack 3 Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = dynhost.inetcam.com;register.inetcam.com;
R3 - URLSearchHook: (no name) - ~CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: MyIdentityDefender - {A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6} - C:\Documents and Settings\Ray\Local Settings\Application Data\CyberDefender\cdmyidd.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS.0\system32\userinit.exe,"C:\WINDOWS.0\server.exe",
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: MyIdentityDefender - {A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6} - C:\Documents and Settings\Ray\Local Settings\Application Data\CyberDefender\cdmyidd.dll
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: ZoneAlarm Spy Blocker BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: SurfLite Toolbar - {6226BA26-C017-4007-928C-DE9715C6FA68} - C:\Program Files\IESurfBar\SurfLite Toolbar\dyn_surflite_aff_1000.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: MyIdentityDefender - {A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6} - C:\Documents and Settings\Ray\Local Settings\Application Data\CyberDefender\cdmyidd.dll
O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS.0\system32\NvCpl.dll,NvStartup
O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'Default user')
O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM
O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1C1CB5F8-D5A3-4FD9-876C-ECD2BDA32716} - C:\Program Files\Reify Software\Turnabout\turnabout.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: SurfLite Toolbar - {6226ba26-c017-4007-928c-de9715c6fa68} - C:\Program Files\IESurfBar\SurfLite Toolbar\dyn_surflite_aff_1000.dll
O9 - Extra 'Tools' menuitem: SurfLite Toolbar - {6226ba26-c017-4007-928c-de9715c6fa68} - C:\Program Files\IESurfBar\SurfLite Toolbar\dyn_surflite_aff_1000.dll
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS.0\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS.0\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} -
http://www.creative.com/su2/CTL_V02002/ocx/15031/CTPID.cabO18 - Protocol: data - {038664DA-5BA5-47FC-88D9-15ADE940ED55} - C:\Program Files\Reify Software\Turnabout\turnabout.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: karna.dat?,avgrsstx.dll
O20 - Winlogon Notify: fsp_lmwl - C:\WINDOWS.0\SYSTEM32\fsp_lmwl.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: nHancer Support (nHancer) - KSE - Korndörfer Software Engineering - C:\Program Files\nHancer\nHancerService.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS.0\system32\nvsvc32.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS.0\System32\PAStiSvc.exe
O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS.0\system32\ZoneLabs\vsmon.exe
--
End of file - 10491 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG8\avgssie.dll [2008-11-18 455960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2008-11-18 320920]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
AVG Security Toolbar - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2008-11-18 2055960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6}]
MyIdentityDefender - C:\Documents and Settings\Ray\Local Settings\Application Data\CyberDefender\cdmyidd.dll [2008-11-18 3962184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-11-18 34816]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2008-11-18 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA}]
ZoneAlarm Spy Blocker BHO - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL [2008-11-18 262144]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{724d43a0-0d85-11d4-9908-00400523e39a} - &RoboForm - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll [2006-09-12 4924472]
{6226BA26-C017-4007-928C-DE9715C6FA68} - SurfLite Toolbar - C:\Program Files\IESurfBar\SurfLite Toolbar\dyn_surflite_aff_1000.dll [2008-06-07 2404352]
{A057A204-BACC-4D26-9990-79A187E2698E} - AVG Security Toolbar - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2008-11-18 2055960]
{A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6} - MyIdentityDefender - C:\Documents and Settings\Ray\Local Settings\Application Data\CyberDefender\cdmyidd.dll [2008-11-18 3962184]
{F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - ZoneAlarm Spy Blocker - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL [2008-11-18 262144]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS.0\system32\NvCpl.dll [2008-08-15 13570048]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\44cd49b8]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acronis Scheduler2 Service]
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe [2007-10-30 140568]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTimounterMonitor]
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe [2007-10-30 909208]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Atari Launcher 2]
C:\Program Files\Infogrames\Atari Anniversary Edition\Volume 2\Atari icon.exe [2001-05-22 55296]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AtariBanner]
C:\Program Files\Infogrames\Atari Anniversary Edition\Volume 2\Banner.exe [2001-05-22 49152]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY]
C:\PROGRA~1\AVG\AVG8\avgtray.exe [2008-11-18 1234712]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\COMODO Firewall Pro]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS.0\system32\ctfmon.exe [2006-01-12 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSysVol]
C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe [2005-10-31 57344]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTXFIREG]
CTxfiReg.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DiscWizardMonitor.exe]
C:\Program Files\Maxtor\MaxBlast\DiscWizardMonitor.exe [2007-04-19 1169744]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IconixOEAddOn]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM]
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe [2006-03-20 213936]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS.0\system32\dumprep 0 -k []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Keyboard Driver]
skfhost.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MaxBlastMonitor.exe]
C:\Program Files\Maxtor\MaxBlast\MaxBlastMonitor.exe [2007-04-19 1169720]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NaturalPoint]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nod32kui]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
C:\WINDOWS.0\system32\NvCpl.dll [2008-08-15 13570048]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVIDIA nTune]
C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe [2007-09-04 81920]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
C:\WINDOWS.0\system32\NvMcTray.dll [2008-08-15 86016]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\P17Helper]
Rundll32 P17.dll []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Pitstop Optimize Scheduler]
C:\Program Files\PCPitstop\Optimize\PCPOptimize.exe [2008-07-03 1684480]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe [2006-09-01 282624]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoboForm]
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [2007-07-23 144448]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2008-08-18 1832272]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpySweeper]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre6\bin\jusched.exe [2008-11-18 136600]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\THGuard]
C:\Program Files\TrojanHunter 5.0\THGuard.exe [2007-10-10 1046688]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueImageMonitor.exe]
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe [2007-10-30 2595616]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
C:\WINDOWS.0\UpdReg.EXE [2000-05-10 90112]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZoneAlarm Client]
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe [2008-07-09 919016]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS.0^Start Menu^Programs^Startup^MightyFAX Controller.lnk]
C:\PROGRA~1\MIGHTY~1\MFNTCTL.EXE [2005-07-27 513536]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS.0^Start Menu^Programs^Startup^Privoxy.lnk]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wscsvc"=2
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="karna.dat?,avgrsstx.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\fsp_lmwl]
C:\WINDOWS.0\system32\fsp_lmwl.dll [2007-06-12 44400]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
relog_ap
C:\WINDOWS.0\system32\awtrOiJB
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Azureus\Azureus.exe"="C:\Program Files\Azureus\Azureus.exe:*:Enabled:Azureus"
"C:\Program Files\Emule\emule.exe"="C:\Program Files\Emule\emule.exe:*:Enabled:DaZZle Emule Mod"
"C:\Program Files\Ubisoft\IL-2 Sturmovik 1946\il2fb.exe"="C:\Program Files\Ubisoft\IL-2 Sturmovik 1946\il2fb.exe:*:Enabled:il2fb"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Pinnacle\Studio 10\programs\RM.exe"="C:\Program Files\Pinnacle\Studio 10\programs\RM.exe:*:Enabled:Render Manager"
"C:\Program Files\Pinnacle\Studio 10\programs\Studio.exe"="C:\Program Files\Pinnacle\Studio 10\programs\Studio.exe:*:Enabled:Studio"
"C:\Program Files\Pinnacle\Studio 10\programs\PMSRegisterFile.exe"="C:\Program Files\Pinnacle\Studio 10\programs\PMSRegisterFile.exe:*:Enabled:PMSRegisterFile"
"C:\Program Files\Pinnacle\Studio 10\programs\umi.exe"="C:\Program Files\Pinnacle\Studio 10\programs\umi.exe:*:Enabled:umi"
"C:\rowan\mig\Mig.exe"="C:\rowan\mig\Mig.exe:*:Enabled:MIG"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"C:\Program Files\InterVideo\DVD8\WinDVD.exe"="C:\Program Files\InterVideo\DVD8\WinDVD.exe:*:Enabled:WinDVD"
"C:\Program Files\Steam\steamapps\nonaste\counter-strike source\hl2.exe"="C:\Program Files\Steam\steamapps\nonaste\counter-strike source\hl2.exe:*:Enabled:hl2"
"C:\Program Files\Steam\steamapps\nonaste\half-life 2 deathmatch\hl2.exe"="C:\Program Files\Steam\steamapps\nonaste\half-life 2 deathmatch\hl2.exe:*:Enabled:hl2"
"C:\Program Files\AVG\AVG8\avgemc.exe"="C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe"
"C:\Program Files\AVG\AVG8\avgupd.exe"="C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe"
"C:\Program Files\Steam\steamapps\nonaste\day of defeat source\hl2.exe"="C:\Program Files\Steam\steamapps\nonaste\day of defeat source\hl2.exe:*:Enabled:hl2"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{adee6e49-fbe5-11dc-aaec-00508dcb517d}]
shell\AutoRun\command - F:\TVCenterPro.exe -autorun
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{adee6e4a-fbe5-11dc-aaec-00508dcb517d}]
shell\AutoRun\command - G:\TVCenterPro.exe -autorun
shell\Shell01\command - G:\TVCenterPro.exe
shell\Shell02\command - G:\TVCenterProSettings.exe
======List of files/folders created in the last 1 months======
2008-11-19 15:48:26 ----D---- C:\rsit
2008-11-19 15:18:40 ----D---- C:\WINDOWS.0\ERUNT
2008-11-19 15:16:45 ----A---- C:\WINDOWS.0\ntbtlog.txt
2008-11-19 15:13:48 ----D---- C:\SDFix
2008-11-19 06:47:37 ----HDC---- C:\WINDOWS.0\$NtUninstallKB912919$
2008-11-18 17:53:12 ----A---- C:\WINDOWS.0\system32\deploytk.dll
2008-11-18 17:53:11 ----A---- C:\WINDOWS.0\system32\javaws.exe
2008-11-18 17:53:11 ----A---- C:\WINDOWS.0\system32\javaw.exe
2008-11-18 17:53:11 ----A---- C:\WINDOWS.0\system32\java.exe
2008-11-18 09:46:56 ----D---- C:\Program Files\Trend Micro
2008-11-18 09:18:29 ----D---- C:\Program Files\ZoneAlarmSB
2008-11-18 09:16:22 ----D---- C:\Documents and Settings\All Users.WINDOWS.0\Application Data\MailFrontier
2008-11-18 09:15:53 ----A---- C:\WINDOWS.0\zllsputility.exe
2008-11-18 09:15:52 ----A---- C:\WINDOWS.0\system32\SpOrder.dll
2008-11-18 09:15:36 ----A---- C:\WINDOWS.0\system32\vsregexp.dll
2008-11-18 09:15:36 ----A---- C:\WINDOWS.0\system32\libeay32_0.9.6l.dll
2008-11-18 09:15:25 ----A---- C:\WINDOWS.0\system32\zlcommdb.dll
2008-11-18 09:15:25 ----A---- C:\WINDOWS.0\system32\zlcomm.dll
2008-11-18 09:15:20 ----A---- C:\WINDOWS.0\system32\vswmi.dll
2008-11-18 09:15:19 ----D---- C:\WINDOWS.0\system32\ZoneLabs
2008-11-18 09:15:19 ----D---- C:\Program Files\Zone Labs
2008-11-18 09:15:19 ----A---- C:\WINDOWS.0\system32\zpeng24.dll
2008-11-18 09:15:19 ----A---- C:\WINDOWS.0\system32\vsxml.dll
2008-11-18 09:15:19 ----A---- C:\WINDOWS.0\system32\vspubapi.dll
2008-11-18 09:15:19 ----A---- C:\WINDOWS.0\system32\vsmonapi.dll
2008-11-18 09:14:47 ----D---- C:\WINDOWS.0\Internet Logs
2008-11-18 09:14:47 ----A---- C:\WINDOWS.0\system32\vsutil.dll
2008-11-18 09:14:47 ----A---- C:\WINDOWS.0\system32\vsinit.dll
2008-11-18 09:14:47 ----A---- C:\WINDOWS.0\system32\vsdata.dll
2008-11-18 04:37:50 ----HD---- C:\$AVG8.VAULT$
2008-11-18 04:20:49 ----A---- C:\WINDOWS.0\system32\avgrsstx.dll
2008-11-18 04:20:41 ----D---- C:\Documents and Settings\Ray\Application Data\AVGTOOLBAR
2008-11-18 04:20:36 ----D---- C:\Program Files\AVG
2008-11-17 12:26:52 ----D---- C:\Program Files\TrojanHunter 5.0
2008-11-17 11:04:15 ----D---- C:\Documents and Settings\Ray\Application Data\Malwarebytes
2008-11-17 11:03:35 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2008-11-17 11:03:35 ----D---- C:\Documents and Settings\All Users.WINDOWS.0\Application Data\Malwarebytes
2008-11-17 06:56:13 ----A---- C:\WINDOWS.0\system32\4fee8dc6-.txt
2008-11-17 06:55:18 ----SHD---- C:\WINDOWS.0\CSC
2008-11-17 06:21:14 ----D---- C:\Documents and Settings\All Users.WINDOWS.0\Application Data\ESET
2008-11-17 06:02:49 ----A---- C:\WINDOWS.0\ixicytuwib.bat
2008-11-17 05:53:15 ----D---- C:\CloneDVDTemp
2008-11-17 05:51:12 ----D---- C:\Program Files\IESurfBar
2008-11-17 05:50:41 ----D---- C:\Program Files\Reify Software
2008-11-17 05:50:40 ----A---- C:\raeogcjp.exe
2008-11-17 04:38:48 ----D---- C:\Documents and Settings\All Users.WINDOWS.0\Application Data\Avg8
2008-11-16 20:53:59 ----SHD---- C:\WINDOWS.0\ftpcache
2008-11-11 13:49:23 ----A---- C:\WINDOWS.0\system32\hidserv.dll
2008-11-11 13:09:27 ----A---- C:\WINDOWS.0\system32\SaiCfg.dll
2008-11-11 13:09:27 ----A---- C:\WINDOWS.0\system32\REnum.exe
2008-11-11 13:09:27 ----A---- C:\WINDOWS.0\system32\PrfAct.exe
2008-11-11 13:09:27 ----A---- C:\WINDOWS.0\system32\NX.exe
2008-11-11 07:51:41 ----D---- C:\Program Files\KALiNKOsoft
2008-11-11 07:42:17 ----D---- C:\Documents and Settings\All Users.WINDOWS.0\Application Data\Innovative Solutions
2008-11-11 07:42:03 ----D---- C:\Program Files\Innovative Solutions
2008-11-03 05:15:16 ----D---- C:\Documents and Settings\Ray\Application Data\KALiNKOsoft
2008-11-03 05:13:21 ----N---- C:\WINDOWS.0\system32\ADsSecurity.dll
2008-11-03 05:13:21 ----A---- C:\WINDOWS.0\system32\zlib.dll
2008-11-03 05:13:21 ----A---- C:\WINDOWS.0\system32\VB5DB.DLL
2008-11-03 05:13:21 ----A---- C:\WINDOWS.0\system32\SSubTmr6.dll
2008-11-03 05:13:21 ----A---- C:\WINDOWS.0\system32\dxinputdll.dll
2008-11-03 05:13:21 ----A---- C:\WINDOWS.0\system32\capicom.dll
2008-10-29 15:59:19 ----D---- C:\Program Files\KeyTweak
2008-10-29 09:52:15 ----D---- C:\Program Files\THQ
2008-10-27 04:29:08 ----D---- C:\Program Files\7-Zip
2008-10-24 09:49:43 ----D---- C:\Documents and Settings\Ray\Application Data\Gearbox Software
2008-10-24 03:34:46 ----D---- C:\Program Files\Common Files\EasyInfo
2008-10-24 03:12:35 ----D---- C:\Program Files\EA GAMES
2008-10-21 08:51:48 ----A---- C:\WINDOWS.0\system32\kbdkor.dll
2008-10-21 08:51:48 ----A---- C:\WINDOWS.0\system32\kbdjpn.dll
2008-10-21 08:51:48 ----A---- C:\WINDOWS.0\system32\kbd106.dll
2008-10-21 08:51:48 ----A---- C:\WINDOWS.0\system32\kbd103.dll
2008-10-21 08:51:48 ----A---- C:\WINDOWS.0\system32\kbd101c.dll
2008-10-21 08:51:48 ----A---- C:\WINDOWS.0\system32\kbd101b.dll
======List of files/folders modified in the last 1 months======
2008-11-19 15:48:49 ----D---- C:\WINDOWS.0\Temp
2008-11-19 15:46:36 ----D---- C:\Program Files\Mozilla Firefox
2008-11-19 15:40:54 ----D---- C:\WINDOWS.0
2008-11-19 15:39:23 ----D---- C:\Documents and Settings
2008-11-19 15:23:26 ----D---- C:\WINDOWS.0\system32
2008-11-19 15:23:26 ----D---- C:\Program Files\Common Files
2008-11-19 15:21:06 ----D---- C:\WINDOWS.0\system32\DllCache
2008-11-19 15:15:45 ----D---- C:\WINDOWS.0\system32\CatRoot2
2008-11-19 15:15:09 ----D---- C:\Documents and Settings\Ray\Application Data\SiteAdvisor
2008-11-19 15:10:50 ----D---- C:\Program Files\Mozilla Thunderbird
2008-11-19 09:26:07 ----D---- C:\Program Files\Steam
2008-11-19 06:47:41 ----HD---- C:\WINDOWS.0\inf
2008-11-19 06:47:27 ----HD---- C:\WINDOWS.0\$hf_mig$
2008-11-19 04:21:20 ----D---- C:\Documents and Settings\Ray\Application Data\Azureus
2008-11-19 03:15:34 ----D---- C:\Documents and Settings\Ray\Application Data\MailWasherPro
2008-11-19 03:14:09 ----RSH---- C:\boot.ini
2008-11-19 03:14:09 ----AC---- C:\WINDOWS.0\win.ini
2008-11-19 03:14:09 ----AC---- C:\WINDOWS.0\system.ini
2008-11-18 19:06:10 ----D---- C:\WINDOWS.0\system32\drivers
2008-11-18 17:53:01 ----SHD---- C:\WINDOWS.0\Installer
2008-11-18 17:53:01 ----D---- C:\Program Files\Java
2008-11-18 09:46:56 ----RD---- C:\Program Files
2008-11-18 07:36:33 ----D---- C:\Documents and Settings\Ray\Application Data\Spyware Terminator
2008-11-18 04:19:33 ----D---- C:\Documents and Settings\Ray\Application Data\Microsoft
2008-11-18 03:56:06 ----D---- C:\Documents and Settings\All Users.WINDOWS.0\Application Data\Spybot - Search & Destroy
2008-11-18 03:49:51 ----D---- C:\Program Files\Spybot - Search & Destroy
2008-11-17 17:55:45 ----D---- C:\Documents and Settings\Ray\Application Data\Mozilla
2008-11-17 16:39:41 ----SD---- C:\WINDOWS.0\Downloaded Program Files
2008-11-17 16:02:02 ----D---- C:\Program Files\PeerGuardian2
2008-11-17 10:51:01 ----D---- C:\Program Files\Spyware Terminator
2008-11-17 10:10:41 ----D---- C:\Documents and Settings\All Users.WINDOWS.0\Application Data\Spyware Terminator
2008-11-17 09:49:26 ----A---- C:\WINDOWS.0\DUMP2b46.tmp
2008-11-17 09:26:41 ----A---- C:\WINDOWS.0\DUMP2c5f.tmp
2008-11-17 07:25:58 ----A---- C:\WINDOWS.0\DUMP2f8b.tmp
2008-11-17 06:32:09 ----SHD---- C:\RECYCLER
2008-11-17 06:21:14 ----D---- C:\Program Files\ESET
2008-11-17 05:54:18 ----D---- C:\Tech stuff
2008-11-17 05:47:42 ----D---- C:\Program Files\Elaborate Bytes
2008-11-17 04:48:56 ----D---- C:\Program Files\TrojanHunter 4.7
2008-11-16 20:35:40 ----D---- C:\WINDOWS.0\WinSxS
2008-11-16 20:29:34 ----AD---- C:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP
2008-11-16 20:28:16 ----D---- C:\Documents and Settings\All Users.WINDOWS.0\Application Data\Kaspersky Lab
2008-11-15 19:49:36 ----D---- C:\Program Files\HyperLobbyPro3
2008-11-12 07:56:00 ----HD---- C:\Program Files\InstallShield Installation Information
2008-11-12 07:55:58 ----DC---- C:\WINDOWS.0\system32\DRVSTORE
2008-11-12 07:55:58 ----D---- C:\WINDOWS.0\Help
2008-11-11 13:47:10 ----D---- C:\Program Files\Saitek
2008-11-11 13:43:24 ----A---- C:\WINDOWS.0\DUMP34db.tmp
2008-11-11 13:33:05 ----A---- C:\WINDOWS.0\DUMP2a3c.tmp
2008-11-11 13:28:20 ----AC---- C:\WINDOWS.0\DUMP2896.tmp
2008-11-02 11:02:28 ----D---- C:\WINDOWS.0\system32\ReinstallBackups
2008-11-01 20:53:36 ----RD---- C:\Mp3
2008-10-31 03:32:36 ----AC---- C:\WINDOWS.0\NeroDigital.ini
2008-10-29 09:52:52 ----D---- C:\WINDOWS.0\system32\DirectX
2008-10-27 09:52:09 ----D---- C:\Program Files\Ubisoft
2008-10-27 03:07:08 ----D---- C:\Program Files\InterActual
2008-10-21 14:43:27 ----AC---- C:\WINDOWS.0\ModemLog_Smart Link 56K Voice Modem.txt
2008-10-21 14:38:50 ----AC---- C:\WINDOWS.0\MFPD.INI
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AvgArCln;Avg Anti-Rootkit Clean Driver; C:\WINDOWS.0\System32\DRIVERS\AvgArCln.sys [2007-01-18 3968]
R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\WINDOWS.0\System32\Drivers\avgldx86.sys [2008-11-18 97928]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\WINDOWS.0\System32\Drivers\avgmfx86.sys [2008-11-18 26824]
R1 intelppm;Intel Processor Driver; C:\WINDOWS.0\system32\DRIVERS\intelppm.sys [2006-01-12 36096]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS.0\system32\DRIVERS\kbdhid.sys [2006-01-06 14848]
R1 KLIF;KLIF; C:\WINDOWS.0\system32\DRIVERS\klif.sys [2007-07-19 127768]
R1 PCLEPCI;PCLEPCI; \??\C:\WINDOWS.0\system32\drivers\pclepci.sys []
R1 vsdatant;vsdatant; C:\WINDOWS.0\System32\vsdatant.sys [2008-07-09 394952]
R2 AvgTdiX;AVG Free8 Network Redirector; C:\WINDOWS.0\System32\Drivers\avgtdix.sys [2008-11-18 76040]
R2 ElbyCDIO;ElbyCDIO Driver; C:\WINDOWS.0\System32\Drivers\ElbyCDIO.sys [2007-08-07 25160]
R2 tifsfilter;Acronis True Image FS Filter; C:\WINDOWS.0\system32\DRIVERS\tifsfilt.sys [2008-02-03 44384]
R2 tmcomm;tmcomm; \??\C:\WINDOWS.0\system32\drivers\tmcomm.sys []
R3 AnyDVD;AnyDVD; C:\WINDOWS.0\System32\Drivers\AnyDVD.sys [2008-04-10 97728]
R3 catchme;catchme; \??\C:\DOCUME~1\Ray\LOCALS~1\Temp\catchme.sys []
R3 ctsfm2k;Creative SoundFont Management Device Driver; C:\WINDOWS.0\system32\DRIVERS\ctsfm2k.sys [2005-12-08 142336]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS.0\system32\DRIVERS\hidusb.sys [2006-01-06 9600]
R3 LMPC4;LMPC4; C:\WINDOWS.0\system32\drivers\LMPC4.sys [2007-02-21 10096]
R3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS.0\system32\drivers\MODEMCSA.sys [2006-01-06 16128]
R3 mouhid;Mouse HID Driver; C:\WINDOWS.0\system32\DRIVERS\mouhid.sys [2006-01-12 12160]
R3 Mtlmnt5;Mtlmnt5; C:\WINDOWS.0\system32\DRIVERS\SLDRV\Mtlmnt5.sys [2005-05-10 237616]
R3 npusbio;npusbio; C:\WINDOWS.0\System32\Drivers\npusbio.sys [2008-01-11 36384]
R3 nv;nv; C:\WINDOWS.0\system32\DRIVERS\nv4_mini.sys [2008-08-15 6121504]
R3 NVR0Dev;NVR0Dev; \??\C:\WINDOWS.0\nvoclock.sys []
R3 ossrv;Creative OS Services Driver; C:\WINDOWS.0\system32\DRIVERS\ctoss2k.sys [2005-12-08 114688]
R3 P17;Sound Blaster Audigy; C:\WINDOWS.0\system32\drivers\P17.sys [2006-03-17 1163264]
R3 p17filt;p17filt; C:\WINDOWS.0\system32\drivers\p17filt.sys [2006-03-20 1452032]
R3 RTL8023;corega PCI-GT NT Driver; C:\WINDOWS.0\system32\DRIVERS\corega5.sys [2003-10-08 65280]
R3 Slntamr;SmartLink AMR_PCI Driver; C:\WINDOWS.0\system32\DRIVERS\SLDRV\slntamr.sys [2005-05-10 698848]
R3 SlWdmSup;SlWdmSup; C:\WINDOWS.0\system32\DRIVERS\SLDRV\SlWdmSup.sys [2005-05-10 13248]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS.0\system32\DRIVERS\usbccgp.sys [2006-01-06 31744]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS.0\system32\DRIVERS\usbehci.sys [2006-01-12 27008]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS.0\system32\DRIVERS\usbhub.sys [2006-01-12 57856]
R3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS.0\system32\DRIVERS\usbprint.sys [2006-01-06 25856]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS.0\system32\DRIVERS\usbuhci.sys [2006-01-12 20480]
S1 5ea275fb;5ea275fb; C:\WINDOWS.0\System32\drivers\5ea275fb.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS.0\system32\DRIVERS\CCDECODE.sys [2006-01-06 17024]
S3 gmer;gmer; C:\WINDOWS.0\System32\DRIVERS\gmer.sys [2007-07-23 83889]
S3 ICAM3NT5;Intel® PC Camera CS331; C:\WINDOWS.0\System32\Drivers\ICAM3D2.SYS [2001-07-18 145184]
S3 MagicTune;MagicTune; C:\WINDOWS.0\system32\drivers\MTiCtwl.sys []
S3 MPE;BDA MPE Filter; C:\WINDOWS.0\system32\DRIVERS\MPE.sys [2006-01-06 15360]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS.0\system32\drivers\MSTEE.sys [2006-01-06 5504]
S3 Mtlstrm;Mtlstrm; C:\WINDOWS.0\system32\DRIVERS\SLDRV\Mtlstrm.sys [2005-05-10 1464848]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS.0\system32\DRIVERS\NABTSFEC.sys [2006-01-06 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS.0\system32\DRIVERS\NdisIP.sys [2006-01-06 10880]
S3 NPF;Netgroup Packet Filter; C:\WINDOWS.0\system32\drivers\npf.sys [2007-12-17 42512]
S3 NPUSB;NPUSB; C:\WINDOWS.0\system32\DRIVERS\npusb.sys [2007-03-23 22816]
S3 PAC207;Webcam Basic; C:\WINDOWS.0\system32\DRIVERS\pfc027.sys [2005-04-08 162176]
S3 RivaTuner32;RivaTuner32; \??\C:\Program Files\RivaTuner v2.08\RivaTuner32.sys []
S3 SaiClass;SaiClass; C:\WINDOWS.0\system32\drivers\SaiNtBus.sys [2003-04-10 26368]
S3 SaiH0109;SaiH0109; C:\WINDOWS.0\system32\DRIVERS\SaiH0109.sys [2007-05-01 132232]
S3 SaiMini;SaiMini; C:\WINDOWS.0\system32\drivers\SaiMini.sys [2007-10-05 14080]
S3 SaiNtBus;SaiNtBus; C:\WINDOWS.0\system32\drivers\SaiBus.sys [2007-10-05 35200]
S3 SaiNtHid;SaiNtHid; C:\WINDOWS.0\system32\DRIVERS\SaiNtHid.sys [2003-04-10 48384]
S3 SaiNtSub;SaiNtSub; C:\WINDOWS.0\system32\DRIVERS\SaiNtSub.sys [2003-04-10 19200]
S3 SaiU0109;SaiU0109; C:\WINDOWS.0\system32\DRIVERS\SaiU0109.sys [2007-05-01 28416]
S3 SIVDRIVER;SIV Kernel Driver; \??\C:\WINDOWS.0\system32\Drivers\SIVX32.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS.0\system32\DRIVERS\SLIP.sys [2006-01-06 11136]
S3 SlNtHal;SlNtHal; C:\WINDOWS.0\system32\DRIVERS\SLDRV\Slnthal.sys [2005-05-10 101328]
S3 streamip;BDA IPSink; C:\WINDOWS.0\system32\DRIVERS\StreamIP.sys [2006-01-06 15360]
S3 USB28xxBGA;PCTV 330e/8x0e Device; C:\WINDOWS.0\system32\DRIVERS\emBDA.sys [2007-08-07 476288]
S3 USB28xxOEM;USB 28xx OEM Filter; C:\WINDOWS.0\system32\DRIVERS\emOEM.sys [2007-08-07 38656]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS.0\system32\DRIVERS\USBSTOR.SYS [2006-01-06 26368]
S3 wceusbsh;Windows CE USB Serial Host Driver; C:\WINDOWS.0\system32\DRIVERS\wceusbsh.sys [2006-11-06 28672]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS.0\system32\DRIVERS\WSTCODEC.SYS [2006-01-06 19328]
S4 IntelIde;IntelIde; C:\WINDOWS.0\system32\drivers\IntelIde.sys []
S4 sr;System Restore Filter Driver; C:\WINDOWS.0\system32\DRIVERS\sr.sys [2006-01-12 73472]
S4 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS.0\System32\drivers\ws2ifsl.sys [2006-01-12 12032]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AcrSch2Svc;Acronis Scheduler2 Service; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe [2007-10-30 427288]
R2 avg8emc;AVG Free8 E-mail Scanner; C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-11-18 875288]
R2 avg8wd;AVG Free8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-11-18 231704]
R2 IviRegMgr;IviRegMgr; C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe [2007-01-04 112152]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2008-11-18 152984]
R2 nHancer;nHancer Support; C:\Program Files\nHancer\nHancerService.exe [2007-10-31 20480]
R2 nTuneService;nTune Service; C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe [2007-09-04 131072]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS.0\system32\nvsvc32.exe [2008-08-15 163908]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2008-08-22 570880]
R2 STI Simulator;STI Simulator; C:\WINDOWS.0\System32\PAStiSvc.exe [2005-01-14 53248]
R2 TryAndDecideService;Acronis Try And Decide Service; C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe [2007-10-30 492720]
R2 vsmon;TrueVector Internet Monitor; C:\WINDOWS.0\system32\ZoneLabs\vsmon.exe [2008-07-09 75304]
S3 aawservice;Ad-Aware 2007 Service; C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe [2007-10-29 587096]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS.0\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS.0\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 Diskeeper;Diskeeper; C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe [2007-10-16 1094936]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-21 73728]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS.0\system32\wdfmgr.exe [2006-01-12 38912]
-----------------EOF-----------------
Also, I don't know if this will help but after running those programs I opened up Firefox and did a Google search on Trojans. I clicked on some of the sites and went directly to them. However, the Wikilink took me to advertisement sites. I went to a different place with each click. Two of the urls I could see flashing by at the bottom of the browser were "125search.com" and "vfsearch.com". The third one flashed by too quick to catch. So I guess I still have a problem although not as serious as before.
Another curious thing is if I did the web search in AVG's toolbar in the browser and clicked on the links AVG provided I went to the selected site with no misdirections.