I ran the new ComboFix, and it did fix the start up error message issue. Also all of the malware seems to be gone. There is a small problem though, which is that whenever I open the Internet browser it takes about 5 seconds to open. But that is a very minor issue, so thanks for helping me to get rid of the malware. Please let me know in case that browser problem can be fixed as well.
Anyway here are the logs:
ComboFix:
ComboFix 09-11-07.02 - Nick 11/09/2009 22:17.3.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1609 [GMT -5:00]
Running from: c:\documents and settings\Nick\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\Nick\Desktop\CFScript.txt
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FILE ::
"c:\windows\system32\tusavila.dll"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\system32\femizaji.dll
c:\windows\system32\fihasine.dll
c:\windows\system32\jopisado.dll
c:\windows\system32\kisafigu.dll
c:\windows\system32\retufuri.dll
c:\windows\system32\toyoyavi.dll
c:\windows\system32\tusavila.dll
c:\windows\Tasks\jbqlhjqo.job
.
((((((((((((((((((((((((( Files Created from 2009-10-10 to 2009-11-10 )))))))))))))))))))))))))))))))
.
2009-11-07 21:57 . 2009-11-07 21:57 -------- d-----w- c:\program files\ESET
2009-11-07 21:56 . 2009-11-07 21:56 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-11-07 21:52 . 2009-11-07 21:55 152576 ----a-w- c:\documents and settings\Nick\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-07 19:37 . 2009-11-07 19:37 932368 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\profiles-1-6.dll
2009-11-07 19:37 . 2009-11-07 19:37 678416 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\content_interpreter-1-1.dll
2009-11-07 19:37 . 2009-11-07 19:37 604688 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\gsg-3-9.dll
2009-11-07 19:37 . 2009-11-07 19:37 522768 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\database-1-5.dll
2009-11-07 19:37 . 2009-11-07 19:37 1096208 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\filtration-4-6.dll
2009-11-07 19:33 . 2009-11-07 19:33 108059 ----a-w- c:\windows\system32\drivers\klin.dat
2009-11-07 19:33 . 2009-11-07 19:33 95259 ----a-w- c:\windows\system32\drivers\klick.dat
2009-11-07 19:32 . 2009-11-10 03:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-11-07 19:32 . 2009-11-07 19:32 -------- d-----w- c:\program files\Kaspersky Lab
2009-11-07 19:21 . 2009-11-07 19:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-10-21 01:34 . 2009-10-21 01:34 219664 ----a-w- c:\windows\system32\klogon.dll
2009-10-20 16:54 . 2009-10-20 16:54 59992 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files\Kaspersky Internet Security 2010 9.0.0.736\English\setup.exe
2009-10-15 02:18 . 2009-10-15 02:18 36880 ----a-w- c:\windows\system32\drivers\klbg.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-07 21:56 . 2005-10-11 16:52 -------- d-----w- c:\program files\Java
2009-11-07 19:23 . 2009-09-19 18:32 -------- dc-h--w- c:\documents and settings\All Users\Application Data\~0
2009-10-27 23:25 . 2009-09-19 17:40 -------- d-----w- c:\documents and settings\Nick\Application Data\AdobeUM
2009-10-06 00:05 . 2009-10-06 00:05 -------- d-----w- c:\documents and settings\Nick\Application Data\Apple Computer
2009-10-03 00:39 . 2009-10-03 00:39 19472 ----a-w- c:\windows\system32\drivers\klmouflt.sys
2009-10-02 11:42 . 2009-10-02 11:42 -------- d-----w- c:\documents and settings\Nick\Application Data\ICAClient
2009-10-02 11:42 . 2009-10-02 11:42 -------- d-----w- c:\program files\Citrix
2009-09-21 00:47 . 2009-09-21 00:46 -------- d-----w- c:\program files\QuickTime
2009-09-21 00:46 . 2009-09-21 00:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-09-21 00:46 . 2009-09-21 00:46 -------- d-----w- c:\program files\Common Files\Apple
2009-09-21 00:46 . 2009-09-21 00:46 -------- d-----w- c:\program files\Apple Software Update
2009-09-21 00:46 . 2009-09-21 00:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-09-20 02:19 . 2009-09-20 02:19 -------- d-----w- c:\program files\Google
2009-09-19 21:22 . 2009-09-19 20:37 139072 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-09-19 21:22 . 2009-09-19 20:36 189672 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-09-19 20:35 . 2009-09-19 20:35 75064 ----a-w- c:\windows\system32\PnkBstrA.exe
2009-09-19 20:05 . 2009-09-19 19:35 -------- d-----w- c:\program files\EA GAMES
2009-09-19 19:51 . 2009-09-19 17:15 17856 ----a-w- c:\documents and settings\Nick\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-19 19:51 . 2009-09-19 18:56 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-09-19 19:42 . 2009-09-19 19:42 -------- d-----w- c:\program files\Common Files\EasyInfo
2009-09-19 19:35 . 2005-10-11 16:53 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-09-19 19:25 . 2009-09-19 19:24 -------- d-----w- c:\program files\EPSON
2009-09-19 19:16 . 2009-09-19 19:16 -------- d-----w- c:\program files\Microsoft ActiveSync
2009-09-19 19:08 . 2009-09-19 15:37 -------- d-----w- c:\documents and settings\Nick\Application Data\Jasc Software Inc
2009-09-19 19:08 . 2005-10-11 16:58 -------- d-----w- c:\program files\Jasc Software Inc
2009-09-19 19:04 . 2009-09-19 19:01 -------- d-----w- c:\program files\Rhapsody
2009-09-19 19:04 . 2005-10-11 17:00 -------- d-----w- c:\program files\Common Files\Real
2009-09-19 18:57 . 2009-09-19 18:57 1962544 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\install_flash_player_ax.exe
2009-09-19 18:33 . 2009-09-19 18:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-09-19 18:33 . 2009-09-19 18:33 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2009-09-19 18:26 . 2009-09-19 18:26 -------- d-----w- c:\documents and settings\Nick\Application Data\Malwarebytes
2009-09-19 18:26 . 2009-09-19 18:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-09-19 18:17 . 2009-09-19 18:17 -------- d-----w- c:\program files\Alwil Software
2009-09-19 18:13 . 2005-10-11 17:03 -------- d-----w- c:\program files\Symantec
2009-09-19 18:13 . 2005-10-11 17:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-09-19 18:12 . 2005-10-11 17:01 -------- d-----w- c:\program files\Common Files\Intuit
2009-09-19 18:11 . 2009-09-19 18:11 -------- d-----w- c:\documents and settings\Nick\Application Data\Sonic
2009-09-19 18:09 . 2009-09-19 18:09 -------- d-----w- c:\documents and settings\Nick\Application Data\Leadertech
2009-09-19 17:57 . 2009-09-19 15:37 -------- d--h--w- c:\documents and settings\Nick\Application Data\Gtek
2009-09-19 17:57 . 2005-10-11 17:07 -------- d-----w- c:\documents and settings\All Users\Application Data\GTek
2009-09-19 17:51 . 2005-10-11 16:59 -------- d-----w- c:\program files\Common Files\AOL
2009-09-19 17:51 . 2005-10-11 16:59 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL
2009-09-19 17:47 . 2009-09-19 15:41 -------- d-----w- c:\program files\Common Files\ATI
2009-09-19 17:45 . 2009-09-19 17:45 9158 ----a-r- c:\documents and settings\Nick\Application Data\Microsoft\Installer\{89DE67AD-08B8-4699-A55D-CA5C0AF82BF3}\ARPPRODUCTICON.exe
2009-09-19 17:45 . 2009-09-19 17:45 -------- d-----w- c:\program files\Common Files\ATI Technologies
2009-09-19 17:44 . 2009-09-19 17:44 -------- d-----w- c:\program files\DIFX
2009-09-19 17:44 . 2009-09-19 17:44 -------- d-----w- c:\program files\USB TV
2009-09-19 17:44 . 2009-09-19 17:44 -------- d-----w- c:\documents and settings\Nick\Application Data\InstallShield
2009-09-19 17:40 . 2009-09-19 17:40 -------- d-----w- c:\program files\Common Files\Adobe
2009-09-19 17:39 . 2009-09-19 17:39 -------- d-----w- c:\documents and settings\Nick\Application Data\ATI
2009-09-19 17:39 . 2009-09-19 17:39 -------- d-----w- c:\documents and settings\All Users\Application Data\ATI
2009-09-19 17:38 . 2009-09-19 17:38 0 ----a-w- c:\windows\ativpsrm.bin
2009-09-19 17:37 . 2005-10-11 16:56 -------- d-----w- c:\program files\ATI Technologies
2009-09-19 17:30 . 2009-09-19 17:30 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-09-19 17:03 . 2009-09-19 17:03 -------- d-----w- c:\program files\Windows Media Connect 2
2009-09-19 16:31 . 2009-09-19 16:31 -------- d-----w- c:\program files\MSXML 4.0
2009-09-19 16:22 . 2009-09-19 16:22 -------- d-----w- c:\program files\MSBuild
2009-09-19 16:22 . 2009-09-19 16:22 -------- d-----w- c:\program files\Reference Assemblies
2009-09-19 16:18 . 2009-09-19 16:18 -------- d-----w- c:\program files\Common Files\SWF Studio
2009-09-19 16:13 . 2004-08-10 18:03 77859 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-09-19 15:43 . 2009-09-19 15:42 -------- d-----w- c:\program files\ATI Multimedia
2009-09-19 15:41 . 2009-09-19 15:41 -------- d-----w- c:\program files\Windows Media Components
2009-09-19 15:41 . 2009-09-19 15:41 -------- d-----w- c:\program files\Common Files\CyberLink
2009-09-19 15:40 . 2005-10-11 16:53 -------- d-----w- c:\program files\Common Files\InstallShield
2009-09-14 19:42 . 2009-09-14 19:42 32272 ----a-w- c:\windows\system32\drivers\klim5.sys
2009-09-11 14:18 . 2004-08-10 17:51 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-10 00:01 . 2009-09-10 00:01 27675 ----a-w- c:\windows\system32\drivers\klopp.dat
2009-09-04 21:03 . 2004-08-10 17:51 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-09-01 20:29 . 2009-09-01 20:29 128016 ----a-w- c:\windows\system32\drivers\kl1.sys
2009-08-29 08:08 . 2004-08-10 17:51 916480 ------w- c:\windows\system32\wininet.dll
2009-08-26 08:00 . 2004-08-10 17:51 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-20 19:09 . 2009-08-20 19:09 1193832 ----a-w- c:\windows\system32\FM20.DLL
.
((((((((((((((((((((((((((((( SnapShot@2009-11-07_20.38.22 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-11-10 03:23 . 2009-11-10 03:23 16384 c:\windows\temp\Perflib_Perfdata_5d8.dat
- 2009-09-19 15:35 . 2009-11-07 19:29 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-09-19 15:35 . 2009-11-08 00:50 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-09-19 15:35 . 2009-11-08 00:50 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2009-09-19 15:35 . 2009-11-07 19:29 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-11-08 00:50 . 2009-11-08 00:50 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2009-09-19 15:35 . 2009-11-07 19:29 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-11-07 21:56 . 2009-11-07 21:56 149280 c:\windows\system32\javaws.exe
+ 2009-11-07 21:56 . 2009-11-07 21:56 145184 c:\windows\system32\javaw.exe
+ 2009-11-07 21:56 . 2009-11-07 21:56 145184 c:\windows\system32\java.exe
+ 2009-11-07 21:56 . 2009-11-07 21:56 537600 c:\windows\Installer\43f303.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2f32e627-cbb0-4ad3-adc0-bc96803fc30f}]
tusavila.dll [BU]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-04-25 139264]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-09-05 417792]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-07-21 61440]
"EPSON Stylus C88 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIABA.EXE" [2005-01-27 98304]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe" [2009-10-21 340456]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-11-07 149280]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2005-03-23 339968]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"c:\\WINDOWS\\system32\\wbem\\unsecapp.exe"=
"c:\\Program Files\\Kaspersky Lab\\Kaspersky Internet Security 2010\\avp.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [10/14/2009 9:18 PM 36880]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [9/14/2009 2:42 PM 32272]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [10/2/2009 7:39 PM 19472]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [9/19/2009 9:19 PM 133104]
.
Contents of the 'Scheduled Tasks' folder
2009-10-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2009-11-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-09-20 02:19]
2009-11-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-09-20 02:19]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
IE: Add to Anti-Banner - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office10\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-11-09 22:24
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(984)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(720)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Intel\Intel Matrix Storage Manager\iaantmon.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
.
**************************************************************************
.
Completion time: 2009-11-10 22:30 - machine was rebooted
ComboFix-quarantined-files.txt 2009-11-10 03:30
ComboFix2.txt 2009-11-07 20:44
Pre-Run: 134,969,847,808 bytes free
Post-Run: 134,970,171,392 bytes free
- - End Of File - - 1187DD6EE478E22CD0D9B70575140C3B
DDS:
DDS (Ver_09-10-26.01) - NTFSx86
Run by Nick at 23:45:47.51 on Mon 11/09/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1537 [GMT -5:00]
AV: Kaspersky Internet Security *On-access scanning enabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *enabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\Ati2evxx.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Nick\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.yahoo.com/
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0\reader\activex\AcroIEHelper.dll
BHO: {2f32e627-cbb0-4ad3-adc0-bc96803fc30f} - tusavila.dll
BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files\kaspersky lab\kaspersky internet security 2010\ievkbd.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - c:\program files\kaspersky lab\kaspersky internet security 2010\klwtbbho.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [EPSON Stylus C88 Series] c:\windows\system32\spool\drivers\w32x86\3\E_FATIABA.EXE /P23 "EPSON Stylus C88 Series" /O6 "USB001" /M "Stylus C88"
mRun: [AVP] "c:\program files\kaspersky lab\kaspersky internet security 2010\avp.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
IE: Add to Anti-Banner - c:\program files\kaspersky lab\kaspersky internet security 2010\ie_banner_deny.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office10\EXCEL.EXE/3000
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - c:\program files\kaspersky lab\kaspersky internet security 2010\klwtbbho.dll
IE: {44226DFF-747E-4edc-B30C-78752E50CD0C} - {44226DFF-747E-4edc-B30C-78752E50CD0C} - c:\program files\ati multimedia\tv\EXPLBAR.DLL
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - c:\program files\kaspersky lab\kaspersky internet security 2010\klwtbbho.dll
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1253384945781
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Notify: AtiExtEvent - Ati2evxx.dll
Notify: klogon - c:\windows\system32\klogon.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
============= SERVICES / DRIVERS ===============
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2009-10-14 36880]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2009-9-14 32272]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2009-10-2 19472]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-9-19 133104]
=============== Created Last 30 ================
2009-11-07 21:57:54 0 d-----w- c:\program files\ESET
2009-11-07 21:56:18 73728 ----a-w- c:\windows\system32\javacpl.cpl
2009-11-07 21:56:18 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-11-07 20:31:28 0 d-sha-r- C:\cmdcons
2009-11-07 20:30:52 98816 ----a-w- c:\windows\sed.exe
2009-11-07 20:30:52 77312 ----a-w- c:\windows\MBR.exe
2009-11-07 20:30:52 267264 ----a-w- c:\windows\PEV.exe
2009-11-07 20:30:52 161792 ----a-w- c:\windows\SWREG.exe
2009-11-07 19:33:08 108059 ----a-w- c:\windows\system32\drivers\klin.dat
2009-11-07 19:33:07 95259 ----a-w- c:\windows\system32\drivers\klick.dat
2009-11-07 19:32:14 0 d-----w- c:\program files\Kaspersky Lab
2009-11-07 19:32:14 0 d-----w- c:\docume~1\alluse~1\applic~1\Kaspersky Lab
2009-11-07 19:21:24 0 d-----w- c:\docume~1\alluse~1\applic~1\Kaspersky Lab Setup Files
2009-10-21 01:34:56 219664 ----a-w- c:\windows\system32\klogon.dll
2009-10-15 02:18:34 36880 ----a-w- c:\windows\system32\drivers\klbg.sys
==================== Find3M ====================
2009-10-22 09:19:04 5939712 ----a-w- c:\windows\system32\dllcache\mshtml.dll
2009-10-03 00:39:44 19472 ----a-w- c:\windows\system32\drivers\klmouflt.sys
2009-09-19 21:22:13 139072 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-09-19 21:22:02 189672 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-09-19 20:35:59 75064 ----a-w- c:\windows\system32\PnkBstrA.exe
2009-09-14 19:42:46 32272 ----a-w- c:\windows\system32\drivers\klim5.sys
2009-09-11 14:18:39 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-11 14:18:39 136192 ------w- c:\windows\system32\dllcache\msv1_0.dll
2009-09-04 21:03:36 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-09-04 21:03:36 58880 ------w- c:\windows\system32\dllcache\msasn1.dll
2009-08-28 10:35:52 173056 ----a-w- c:\windows\system32\dllcache\ie4uinit.exe
2009-08-26 08:00:21 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-26 08:00:21 247326 ------w- c:\windows\system32\dllcache\strmdll.dll
2009-08-20 19:09:06 1193832 ----a-w- c:\windows\system32\FM20.DLL
============= FINISH: 23:46:18.12 ===============