DDS (Ver_09-10-26.01) - NTFSx86
Run by UserOne at 11:31:28.10 on Thu 11/12/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1085 [GMT -6:00]
AV: Avira AntiVir PersonalEdition *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\WINDOWS\System32\svchost.exe -k LocalService
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
c:\program files\a-squared free\a2service.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\lxducoms.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\wbem\unsecapp.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Lexmark 5600-6600 Series\lxdumon.exe
C:\Program Files\Lexmark 5600-6600 Series\ezprint.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Apoint\HidFind.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe
C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe
C:\WINDOWS\System32\vssvc.exe
C:\WINDOWS\System32\dllhost.exe
C:\WINDOWS\System32\dllhost.exe
C:\WINDOWS\System32\msdtc.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\UserOne\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
mWinlogon: Userinit=c:\windows\system32\userinit.exe
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: : {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Lexmark Printable Web: {d2c5e510-be6d-42cc-9f61-e4f939078474} - c:\program files\lexmark printable web\bho.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
mRun: [Apoint] c:\program files\apoint\Apoint.exe
mRun: [avgnt] "c:\program files\avira\antivir personaledition classic\avgnt.exe" /min
mRun: [lxdumon.exe] "c:\program files\lexmark 5600-6600 series\lxdumon.exe"
mRun: [EzPrint] "c:\program files\lexmark 5600-6600 series\ezprint.exe"
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [ISTray] "c:\program files\spyware doctor\pctsTray.exe"
mRun: [99518840] c:\documents and settings\all users\application data\99518840\99518840.exe
mRun: [71246727] c:\documents and settings\all users\application data\71246727\71246727.exe
mRun: [kozajazil] Rundll32.exe "c:\windows\system32\lojaloke.dll",a
mRun: [Carbonite Backup] c:\program files\carbonite\carbonite backup\CarboniteUI.exe
IE: E&xport to Microsoft Excel - c:\progra~1\microsoft office\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\microsoft office\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\microsoft office\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\Skype4COM.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: c:\windows\system32\fareruta.dll c:\windows\system32\kadisevo.dll c:\windows\system32\dinizuha.dll c:\windows\system32\mafutaje.dll kakojubo.dll c:\windows\system32\lojaloke.dll
SSODL: miherowos - {f8fbd46c-da5c-402d-a7be-353ee4d05569} - c:\windows\system32\fareruta.dll
SSODL: gakapedak - {103fa4dc-0fef-4d2b-94f4-dc7fd2e3b1b0} - c:\windows\system32\dinizuha.dll
SSODL: mujabanay - {ac5f15a2-c3fe-43f7-a92a-df9d3c9711a6} - c:\windows\system32\mafutaje.dll
SSODL: powogezum - {444af847-c1b5-4249-84ce-a4393f628e6e} - c:\windows\system32\lojaloke.dll
STS: gahurihor: {f8fbd46c-da5c-402d-a7be-353ee4d05569} - c:\windows\system32\fareruta.dll
STS: {796bf4ee-d947-43e7-bdd6-f19379a7a05e} - No File
STS: tokatiluy: {103fa4dc-0fef-4d2b-94f4-dc7fd2e3b1b0} - c:\windows\system32\dinizuha.dll
STS: kupuhivus: {ac5f15a2-c3fe-43f7-a92a-df9d3c9711a6} - c:\windows\system32\mafutaje.dll
STS: jugezatag: {444af847-c1b5-4249-84ce-a4393f628e6e} - c:\windows\system32\lojaloke.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
LSA: Notification Packages = scecli m ??$ zidajaji.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\userone\applic~1\mozilla\firefox\profiles\sbipzz3y.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-10-31 64288]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-10-26 206256]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-9-24 1179232]
R2 lxdu_device;lxdu_device;c:\windows\system32\lxducoms.exe -service --> c:\windows\system32\lxducoms.exe -service [?]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2009-10-26 348824]
R3 GTIPCI21;GTIPCI21;c:\windows\system32\drivers\gtipci21.sys [2007-3-1 87936]
S2 lxduCATSCustConnectService;lxduCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxduserv.exe [2009-5-8 98984]
=============== Created Last 30 ================
2009-11-12 16:34:53 0 d-----w- c:\program files\Carbonite
2009-11-12 16:34:53 0 d-----w- c:\docume~1\alluse~1\applic~1\Carbonite
2009-11-12 15:42:39 0 d-----w- c:\program files\Cobian Backup 8
2009-11-12 01:13:57 0 d-----w- c:\docume~1\alluse~1\applic~1\71246727
2009-11-10 14:59:08 0 d-----w- c:\program files\Microsoft
2009-10-31 14:59:28 15880 ----a-w- c:\windows\system32\lsdelete.exe
2009-10-31 13:58:02 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-10-31 13:57:56 93360 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2009-10-31 13:56:12 0 dc-h--w- c:\docume~1\alluse~1\applic~1\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
2009-10-31 11:22:38 3 --sh--w- c:\windows\system32\towozoha.dll
2009-10-31 11:22:35 3 --sh--w- c:\windows\system32\vopuvemi.dll
2009-10-30 13:11:07 135680 ----a-w- c:\windows\system32\explorer.exe
2009-10-29 22:32:15 0 d-----w- c:\docume~1\alluse~1\applic~1\99518840
2009-10-27 13:43:06 0 d-----w- c:\docume~1\alluse~1\applic~1\28252827
2009-10-26 16:15:40 195440 ------w- c:\windows\system32\MpSigStub.exe
2009-10-26 14:27:36 159600 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-10-26 14:27:27 86888 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-10-26 14:27:27 7396 ----a-w- c:\windows\system32\drivers\pctcore.cat
2009-10-26 14:27:27 206256 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2009-10-26 14:27:20 0 d-----w- c:\program files\common files\PC Tools
2009-10-26 14:27:19 64392 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2009-10-26 14:27:11 0 d-----w- c:\program files\Spyware Doctor
2009-10-26 14:27:11 0 d-----w- c:\docume~1\userone\applic~1\PC Tools
2009-10-26 14:27:11 0 d-----w- c:\docume~1\alluse~1\applic~1\PC Tools
2009-10-21 14:55:09 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-21 14:50:54 4045544 ----a-w- C:\mbam-setup.exe
2009-10-21 14:31:47 3550592 ----a-w- C:\explorer.exe
2009-10-20 20:58:25 0 d-sh--w- c:\documents and settings\userone\PrivacIE
2009-10-20 20:54:27 0 d-----w- c:\docume~1\alluse~1\applic~1\09836935
2009-10-20 16:42:39 0 d-sh--w- c:\documents and settings\userone\IETldCache
2009-10-20 16:35:26 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-10-20 16:35:24 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-10-20 16:35:15 0 d-----w- c:\windows\ie8updates
2009-10-20 16:34:52 100352 -c----w- c:\windows\system32\dllcache\iecompat.dll
2009-10-20 16:32:21 0 dc-h--w- c:\windows\ie8
2009-10-20 15:38:49 0 d-----w- c:\windows\system32\scripting
2009-10-20 15:38:48 0 d-----w- c:\windows\system32\en
2009-10-20 15:38:48 0 d-----w- c:\windows\system32\bits
2009-10-20 15:38:48 0 d-----w- c:\windows\l2schemas
==================== Find3M ====================
2009-09-17 15:53:04 70984 ----a-w- c:\documents and settings\userone\g2mdlhlpx.exe
2009-09-11 14:18:39 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 21:03:36 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 08:08:21 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-26 08:00:21 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-25 13:52:40 33308 ---ha-w- c:\windows\system32\mlfcache.dat
2009-08-18 04:33:52 1193832 ----a-w- c:\windows\system32\FM20.DLL
2009-08-10 14:31:40 53760 --sha-w- c:\windows\system32\dekoyemu.dll
2009-07-28 13:41:11 37888 --sha-w- c:\windows\system32\dodedeva.dll
2007-03-02 20:14:30 5 --sha-w- c:\windows\system32\fadeafcfd5_d.dll
2009-07-30 12:44:54 38912 --sha-w- c:\windows\system32\forukabe.dll
2009-08-09 14:42:35 38912 --sha-w- c:\windows\system32\hiniripa.dll
2009-08-10 14:32:18 53760 --sha-w- c:\windows\system32\jopinowo.dll
2009-08-10 14:32:18 53760 --sha-w- c:\windows\system32\kakojubo.dll
2009-07-28 01:40:49 37888 --sha-w- c:\windows\system32\kapidapu.dll
2009-08-09 14:42:35 91648 --sha-w- c:\windows\system32\lejiwafe.dll
2009-08-10 14:31:40 92160 --sha-w- c:\windows\system32\lifikano.dll
2009-08-12 14:23:05 92672 --sha-w- c:\windows\system32\lojaloke.dll
2009-08-11 13:14:58 39424 --sha-w- c:\windows\system32\mikasova.dll
2009-07-21 14:03:02 51712 --sha-w- c:\windows\system32\nadojizu.dll
2009-08-10 14:31:41 39424 --sha-w- c:\windows\system32\nonowoda.dll
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-10-26.01)
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 2/28/2007 1:46:35 PM
System Uptime: 11/12/2009 8:55:48 AM (3 hours ago)
Motherboard: Dell Inc. | |
Processor: Intel® Pentium® M processor 1.60GHz | Microprocessor | 1324/133mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 37 GiB total, 24.098 GiB free.
D: is CDROM ()
==== Disabled Device Manager Items =============
==== System Restore Points ===================
No restore point in system.
==== Installed Programs ======================
2007 Microsoft Office Suite Service Pack 1 (SP1)
a-squared Free 2.1
Ad-Aware
Ad-Aware SE Personal
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 8.1.2
ALPS Touch Pad Driver
Apple Application Support
Apple Software Update
ATI - Software Uninstall Utility
ATI Control Panel
ATI Display Driver
Avira AntiVir Personal - Free Antivirus
Broadcom Gigabit Integrated Controller
C-Major Audio
Carbonite
Conexant D110 MDC V.92 Modem
Dell Wireless WLAN Card
Easy CD Creator 5 Basic
Free Easy Burner V 1.0.313
GoToMeeting 4.1.0.366
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954708)
Hotfix for Windows XP (KB970653-v3)
Intel® Graphics Media Accelerator Driver for Mobile
Intel® PROSet/Wireless Software
Java 6 Update 13
Java 6 Update 4
Java 6 Update 5
Java SE Runtime Environment 6
K-Lite Codec Pack 3.1.5 Full
Lexmark 5600-6600 Series
Lexmark Printable Web
mCore
mDriver
mDrWiFi
mHlpDell
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Project 2007 Service Pack 1 (SP1)
Microsoft Office Project MUI (English) 2007
Microsoft Office Project Professional 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs
Microsoft Silverlight
Microsoft Software Update for Web Folders (English) 12
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
mIWA
mLogView
mMHouse
Mozilla Firefox (3.0.14)
mPfMgr
mPfWiz
mProSafe
mSSO
MSVCRT
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 6 Service Pack 2 (KB954459)
mWlsSafe
mWMI
mXML
mZConfig
Pdf995
PowerDVD 5.7
QuickTime
Security Update for 2007 Microsoft Office System (KB951550)
Security Update for 2007 Microsoft Office System (KB951944)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB969679)
Security Update for Microsoft Office Excel 2007 (KB969682)
Security Update for Microsoft Office OneNote 2007 (KB950130)
Security Update for Microsoft Office Outlook 2007 (KB972363)
Security Update for Microsoft Office PowerPoint 2007 (KB957789)
Security Update for Microsoft Office Project 2007 (KB949046)
Security Update for Microsoft Office Publisher 2007 (KB969693)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB969613)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB969604)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 7 (KB974455)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows Media Player 9 (KB936782)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Segoe UI
Skype web features
Skype™ 4.1
Spell Checker For OE 2.1
Spelling Dictionaries Support For Adobe Reader 8
Spybot - Search & Destroy 1.5.2.20
Spyware Doctor 6.1
Texas Instruments PCIxx21/x515 drivers.
TI_Inst
Tweakui Powertoy for Windows XP
TweetDeck
Update for 2007 Microsoft Office System (KB967642)
Update for Outlook 2007 Junk Email Filter (KB974810)
Update for Windows Internet Explorer 8 (KB973874)
Update for Windows XP (KB955839)
Update for Windows XP (KB961503)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB973815)
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Live Upload Tool
Windows Media Format Runtime
Windows XP Service Pack 3
==== Event Viewer Messages From Past Week ========
11/9/2009 5:35:43 PM, error: MRxSmb [8003] - The master browser has received a server announcement from the computer OFFICECOMPUTER that believes that it is the master browser for the domain on transport NetBT_Tcpip_{2A6A90A3-5BE1. The master browser is stopping or an election is being forced.
11/9/2009 3:10:15 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the lxduCATSCustConnectService service to connect.
11/9/2009 3:10:15 PM, error: Service Control Manager [7000] - The lxduCATSCustConnectService service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
11/12/2009 9:13:22 AM, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\taskmgr.exe. This file was restored to the original version to maintain system stability. The file version of the system file is 5.1.2600.5512.
11/12/2009 9:04:51 AM, information: Windows File Protection [64002] - File replacement was attempted on the protected system file taskmgr.exe. This file was restored to the original version to maintain system stability. The file version of the system file is 5.1.2600.5512.
11/10/2009 8:51:00 AM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
==== End Of File ===========================
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/11/12 11:38
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================
Drivers
-------------------
Name: mchInjDrv.sys
Image Path: C:\WINDOWS\system32\Drivers\mchInjDrv.sys
Address: 0xBAECB000 Size: 2560 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xB20E7000 Size: 49152 File Visible: No Signed: -
Status: -
SSDT
-------------------
#: 041 Function Name: NtCreateKey
Status: Hooked by "PCTCore.sys" at address 0xba6e4d72
#: 047 Function Name: NtCreateProcess
Status: Hooked by "PCTCore.sys" at address 0xba6c59a6
#: 048 Function Name: NtCreateProcessEx
Status: Hooked by "PCTCore.sys" at address 0xba6c5b98
#: 053 Function Name: NtCreateThread
Status: Hooked by "<unknown>" at address 0xbaea14c4
#: 063 Function Name: NtDeleteKey
Status: Hooked by "PCTCore.sys" at address 0xba6e5568
#: 065 Function Name: NtDeleteValueKey
Status: Hooked by "PCTCore.sys" at address 0xba6e5820
#: 119 Function Name: NtOpenKey
Status: Hooked by "PCTCore.sys" at address 0xba6e3a80
#: 122 Function Name: NtOpenProcess
Status: Hooked by "<unknown>" at address 0xbaea14b0
#: 128 Function Name: NtOpenThread
Status: Hooked by "<unknown>" at address 0xbaea14b5
#: 192 Function Name: NtRenameKey
Status: Hooked by "PCTCore.sys" at address 0xba6e5c8a
#: 247 Function Name: NtSetValueKey
Status: Hooked by "PCTCore.sys" at address 0xba6e5036
#: 257 Function Name: NtTerminateProcess
Status: Hooked by "<unknown>" at address 0xbaea14bf
#: 277 Function Name: NtWriteVirtualMemory
Status: Hooked by "<unknown>" at address 0xbaea14ba
==EOF==
2009-08-09 02:43:52 38400 --sha-w- c:\windows\system32\nozuzito.dll
2009-08-12 01:13:41 39424 --sha-w- c:\windows\system32\pozogere.dll
2009-07-26 13:10:24 52224 --sha-w- c:\windows\system32\rajijofa.dll
2009-07-27 13:42:21 51200 --sha-w- c:\windows\system32\rarayuna.dll
2009-07-27 13:42:22 38400 --sha-w- c:\windows\system32\rijikoyi.dll
2009-08-12 01:13:40 112128 --sha-w- c:\windows\system32\saheloju.exe
2009-07-20 20:54:19 3 --sha-w- c:\windows\system32\siguzuwi.dll
2009-08-12 01:13:43 1212987 --sha-w- c:\windows\system32\suhokamo.exe
2009-08-11 13:14:58 92672 --sha-w- c:\windows\system32\telelepu.dll
2009-08-12 14:23:05 39424 --sha-w- c:\windows\system32\yuhisona.dll
2009-08-10 14:32:17 53760 --sha-w- c:\windows\system32\zidajaji.dll
============= FINISH: 11:33:19.03 ===============

Help
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
This topic is locked

Back to top















