Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Virtumonde Infection?


  • Please log in to reply
9 replies to this topic

#1 Relikie

Relikie

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:04:40 AM

Posted 21 June 2008 - 08:59 PM

Hello. I am new to this, so please bear with me. On startup, my computer is fine, until I log in. After I log in, I am bombarded by cmd windows popping up. They open themselves, then close themselves and I cannot intervene. I have run numerous programs, including VundoFix and VundoBeGone. It used to be worse, but I think I contained it a little. It used to make my start bar disappear, as well as hide all my icons. Somehow, Spybot S&D was able to get my icons and startmenu to come back on login, but I still get these annoying cmd windows.

Anyway, onward with the logs.
Deckard's System Scanner v20071014.68
Run by nate on 2008-06-21 17:40:55
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Successfully created a Deckard's System Scanner Restore Point.


-- Last 5 Restore Point(s) --
19: 2008-06-21 21:41:10 UTC - RP298 - Deckard's System Scanner Restore Point
18: 2008-06-21 21:24:56 UTC - RP297 - Installed Java™ 6 Update 5
17: 2008-06-21 07:39:46 UTC - RP296 - System Checkpoint
16: 2008-06-20 07:00:32 UTC - RP295 - Software Distribution Service 3.0
15: 2008-06-19 06:50:28 UTC - RP294 - System Checkpoint


-- First Restore Point --
1: 2008-06-06 14:41:24 UTC - RP280 - Removed SOFTIMAGE CROSSWALK 2.05


Backed up registry hives.
Performed disk cleanup.

Percentage of Memory in Use: 76% (more than 75%).
System Drive C: has 7.97 GiB (less than 15%) free.


-- HijackThis (run as nate.exe) ------------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:43:19 PM, on 6/21/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\Program Files\Apoint\HidFind.exe
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\PROGRA~1\MICROI~1\INTERN~1\KEMailKb.EXE
C:\PROGRA~1\MICROI~1\INTERN~1\KPDrv4XP.EXE
C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
C:\Program Files\Speeditup Free\SearchDefender.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\Chimera Virtual Desktop\VirtDesktop.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Software\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\nate.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {0541290B-954E-4B9E-B9D0-907944A5F690} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {06E12C36-760F-4D92-8509-5E5DBF12C423} - (no file)
O2 - BHO: (no name) - {245A2F99-CB03-46A6-B303-ABD532A027C1} - (no file)
O2 - BHO: (no name) - {28DFB706-1E7C-4F26-97C9-F8FB9DD1A215} - (no file)
O2 - BHO: QFX Software KeyScrambler - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O2 - BHO: (no name) - {46A65EBF-FDA8-4D16-B78E-D7A50C31664A} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: (no name) - {6372BCEC-CDDD-4439-B0FC-21F802225EB2} - (no file)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {8984cb57-6ffe-c1ce-f2ac-125978cdc936} - (no file)
O2 - BHO: (no name) - {A559F2F0-36D6-488D-BC52-798F64847CAB} - (no file)
O2 - BHO: (no name) - {E1BC0AAB-2C35-40DF-8F1D-4FD437DF432E} - (no file)
O2 - BHO: (no name) - {E23136A1-1AC4-4D1B-926F-5D537CFFF359} - (no file)
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [cafwc] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl
O4 - HKLM\..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
O4 - HKLM\..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe" -H
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [KEMailKb] C:\PROGRA~1\MICROI~1\INTERN~1\KEMailKb.EXE
O4 - HKLM\..\Run: [KPDrv4XP] C:\PROGRA~1\MICROI~1\INTERN~1\KPDrv4XP.EXE
O4 - HKLM\..\Run: [SmartDefrag] "C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" /StartUp
O4 - HKLM\..\RunOnce: [SpybotDeletingA9320] command /c del "C:\WINDOWS\Fonts\'\00jj99uuii66ddxxqqq.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1292] cmd /c del "C:\WINDOWS\Fonts\'\00jj99uuii66ddxxqqq.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7429] command /c del "C:\WINDOWS\system32\jkkLEWOe.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4670] cmd /c del "C:\WINDOWS\system32\jkkLEWOe.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3592] command /c del "C:\WINDOWS\system32\mlJBQhgE.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3244] cmd /c del "C:\WINDOWS\system32\mlJBQhgE.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3007] command /c del "C:\WINDOWS\system32\jkkLEWOe.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1672] cmd /c del "C:\WINDOWS\system32\jkkLEWOe.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6732] command /c del "C:\WINDOWS\system32\jkkLEWOe.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5548] cmd /c del "C:\WINDOWS\system32\jkkLEWOe.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3903] command /c del "C:\WINDOWS\system32\mlJBQhgE.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8944] cmd /c del "C:\WINDOWS\system32\mlJBQhgE.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1396] command /c del "C:\WINDOWS\system32\opnlMcdC.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4938] cmd /c del "C:\WINDOWS\system32\opnlMcdC.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA139] command /c del "C:\WINDOWS\system32\opnlMcdC.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7792] cmd /c del "C:\WINDOWS\system32\opnlMcdC.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8947] command /c del "C:\WINDOWS\system32\mlJAtTmM.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4075] cmd /c del "C:\WINDOWS\system32\mlJAtTmM.dll"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Search Defender] "C:\Program Files\Speeditup Free\SearchDefender.exe"
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [chimeravirtdesk] "C:\Program Files\Chimera Virtual Desktop\VirtDesktop.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingD5499] cmd /c del "C:\WINDOWS\system32\jkkLEWOe.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9936] command /c del "C:\WINDOWS\system32\opnlMcdC.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1362] command /c del "C:\WINDOWS\system32\mlJAtTmM.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4603] cmd /c del "C:\WINDOWS\system32\opnlMcdC.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3664] command /c del "C:\WINDOWS\system32\mlJBQhgE.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6167] cmd /c del "C:\WINDOWS\system32\mlJBQhgE.dll_old"
O4 - HKCU\..\Policies\Explorer\Run: [Windows Printing Driver] WinSpooler.exe
O4 - HKCU\..\Policies\Explorer\Run: [WinUpdating] WinUpdating.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: (no name) - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O9 - Extra 'Tools' menuitem: &KeyScrambler... - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo...toUploader5.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase9563.cab
O16 - DPF: {AA07EBD2-EBDD-4BD6-9F8F-114BD513492C} -
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: awtqnkhe - awtqnkhe.dll (file missing)
O20 - Winlogon Notify: mlJDvSkL - mlJDvSkL.dll (file missing)
O20 - Winlogon Notify: rqRIxVPi - rqRIxVPi.dll (file missing)
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: Google Desktop Manager 5.7.802.22438 (GoogleDesktopManager-022208-143751) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PPCtlPriv - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

--
End of file - 15265 bytes

-- File Associations -----------------------------------------------------------

.cpl - cplfile - shell\cplopen\command - rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.cpl - cplfile - shell\runas\command - rundll32.exe shell32.dll,Control_RunDLLAsUser "%1",%*
.js - unable to read key
.js - unable to read key
.txt - unable to read key
.txt - unable to read key


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R2 HIDKbFlt (HIDKbFlt.SvcDesc%) - c:\windows\system32\drivers\hidkbflt.sys <Not Verified; Dritek System Inc.; Dritek USB Keyboard HID Filter Driver>

S0 cercsr6 - c:\windows\system32\drivers\cercsr6.sys <Not Verified; Adaptec, Inc.; Dell RAID Controller>
S1 OMCI - c:\windows\system32\drivers\omci.sys (file missing)
S3 CoachUsb (Coach Digital Camera on USB) - c:\windows\system32\drivers\coachusb.sys <Not Verified; FotoNation Ltd.; USB Driver for Digital Camera>
S3 EagleNT - c:\windows\system32\drivers\eaglent.sys (file missing)
S3 senfilt - c:\windows\system32\drivers\senfilt.sys (file missing)
S3 SenfiltService - c:\windows\system32\drivers\senfilt.sys (file missing)
S3 UIUSys (Conexant Setup API) - c:\windows\system32\drivers\uiusys.sys (file missing)
S4 s24trans (WLAN Transport) - c:\windows\system32\drivers\s24trans.sys (file missing)


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

R2 Viewpoint Manager Service - "c:\program files\viewpoint\common\viewpointservice.exe" <Not Verified; Viewpoint Corporation; Viewpoint Manager>


-- Device Manager: Disabled ----------------------------------------------------

No disabled devices found.


-- Scheduled Tasks -------------------------------------------------------------

2008-06-21 17:15:56 310 --a------ C:\WINDOWS\Tasks\GlaryInitialize.job
2008-06-21 10:47:00 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2008-06-20 21:51:30 420 --ah----- C:\WINDOWS\Tasks\User_Feed_Synchronization-{25C204A9-25A2-4EF2-AC22-4E545EFF63B8}.job
2008-06-20 16:20:20 382 --a------ C:\WINDOWS\Tasks\SmartDefrag.job
2008-06-07 14:35:33 512 --a------ C:\WINDOWS\Tasks\CAAntiSpywareScan_Daily as nate at 12 02 PM.job
2008-03-28 11:46:12 104 --a------ C:\WINDOWS\Tasks\Low Battery Alarm Program.job


-- Files created between 2008-05-21 and 2008-06-21 -----------------------------

2008-06-21 17:23:51 0 d-------- C:\Program Files\Trend Micro
2008-06-20 18:40:22 0 d-------- C:\Documents and Settings\nate\Application Data\PCF-VLC
2008-06-20 16:40:45 0 dr-h----- C:\Documents and Settings\nate\Recent
2008-06-20 12:40:28 0 d-------- C:\Documents and Settings\nate\Application Data\Uniblue
2008-06-19 22:06:34 0 d-------- C:\Program Files\a-squared Free
2008-06-19 21:59:17 0 d-------- C:\Program Files\CCleaner
2008-06-18 10:19:15 2048 --a------ C:\WINDOWS\system32\Tr_sttool.dat
2008-06-18 10:19:15 147456 --a------ C:\WINDOWS\system32\bsratwmv.dll
2008-06-18 10:19:15 585728 --a------ C:\WINDOWS\system32\bsratswf.dll
2008-06-18 10:19:14 0 d-------- C:\Program Files\BSR Screen Recorder 4
2008-06-13 22:32:56 39 --a------ C:\WINDOWS\popcinfot.dat
2008-06-08 15:55:13 0 d-------- C:\Documents and Settings\nate\Application Data\KompoZer
2008-06-08 15:55:01 0 d-------- C:\Program Files\KompoZer 0.7.10
2008-06-07 21:10:57 0 d-------- C:\WINDOWS\VistaMizer
2008-06-06 11:03:23 0 d-------- C:\Documents and Settings\nate\Application Data\GlarySoft
2008-06-06 11:00:34 0 d-------- C:\Program Files\Glary Utilities
2008-05-29 14:31:42 589378 --ahs---- C:\WINDOWS\system32\PAHNnnnn.ini2
2008-05-28 22:23:49 592393 --ahs---- C:\WINDOWS\system32\StAHNXyb.ini2
2008-05-28 05:27:14 610203 --ahs---- C:\WINDOWS\system32\oVDKUvut.ini2
2008-05-27 10:20:22 0 d-------- C:\Program Files\Rohan
2008-05-25 21:49:54 0 d-------- C:\WINDOWS\Prefetch
2008-05-25 20:59:53 0 d-------- C:\WINDOWS\system32\scripting
2008-05-25 20:59:44 0 d-------- C:\WINDOWS\l2schemas
2008-05-25 20:59:37 0 d-------- C:\WINDOWS\system32\en
2008-05-25 20:59:35 0 d-------- C:\WINDOWS\system32\bits
2008-05-25 20:22:28 0 d-------- C:\WINDOWS\ServicePackFiles
2008-05-25 11:11:34 0 d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-05-25 10:12:25 0 d-------- C:\Program Files\Windows Live Safety Center
2008-05-25 08:03:32 5182 --a------ C:\WINDOWS\system32\tmp.reg
2008-05-24 09:44:13 708138 --ahs---- C:\WINDOWS\system32\MmTtAJlm.ini2
2008-05-24 01:29:07 321 --ahs---- C:\WINDOWS\system32\CdcMlnpo.ini2
2008-05-22 17:17:30 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-22 17:14:51 0 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-22 16:23:11 0 d-------- C:\WINDOWS\system32\vntiho18
2008-05-22 16:21:58 790112 --ahs---- C:\WINDOWS\system32\EghQBJlm.ini2
2008-05-22 16:16:52 0 d-------- C:\Documents and Settings\nate\Application Data\Help
2008-05-21 21:14:36 0 d-------- C:\WINDOWS\system32\logXv18
2008-05-21 21:14:33 0 d-------- C:\Temp
2008-05-21 07:31:26 147456 --a------ C:\WINDOWS\system32\vbzip10.dll <Not Verified; Info-ZIP; Info-ZIP's WiZ>


-- Find3M Report ---------------------------------------------------------------

2008-06-21 17:27:04 0 d-------- C:\Program Files\Java
2008-06-21 17:17:44 0 d-------- C:\Program Files\Chimera Virtual Desktop
2008-06-21 17:15:29 85162 --a------ C:\WINDOWS\system32\nvModes.dat
2008-06-21 16:52:55 0 d-------- C:\Program Files\Steam
2008-06-19 22:07:26 0 d-------- C:\Program Files\IObit
2008-06-07 21:24:37 0 d-------- C:\Program Files\Movie Maker
2008-06-07 21:24:37 0 d-------- C:\Program Files\Messenger
2008-06-07 21:24:33 0 d-------- C:\Program Files\Windows NT
2008-06-07 21:23:07 218624 --a------ C:\WINDOWS\system32\uxtheme.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-06-06 10:46:19 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-06-06 10:38:49 0 d-------- C:\Program Files\Common Files\Adobe
2008-06-06 10:38:48 0 d-------- C:\Program Files\Common Files
2008-06-06 09:56:07 0 d-------- C:\Documents and Settings\nate\Application Data\Adobe
2008-05-27 11:02:40 0 d-------- C:\Program Files\Outspark
2008-05-22 16:26:10 0 d-------- C:\Documents and Settings\nate\Application Data\LimeWire
2008-05-22 16:26:10 0 d-------- C:\Documents and Settings\nate\Application Data\FrostWire
2008-05-22 16:21:07 403794 --a------ C:\WINDOWS\469.exe
2008-05-22 16:21:04 266607 --a------ C:\WINDOWS\ISMSetup Venora3 (aid=3 smiley).exe
2008-05-22 16:16:29 786921 --ahs---- C:\WINDOWS\system32\eOWELkkj.ini2
2008-05-21 17:06:45 37888 --a------ C:\WINDOWS\system32\rar.exe <Not Verified; Microsoft Corporation; Microsoft® Windows ® 2000 Operating System>
2008-05-19 16:10:56 0 d-------- C:\Documents and Settings\nate\Application Data\BitTorrent
2008-05-18 21:31:27 33 --a------ C:\WINDOWS\system32\684557f1
2008-05-06 20:46:35 0 d-------- C:\Program Files\Google
2008-04-19 12:47:54 98304 --a------ C:\WINDOWS\system32CmdLineExt.dll <Not Verified; Sony DADC Austria AG.; >
2008-04-14 05:42:06 1379840 --a------ C:\WINDOWS\system32\setupapi.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:16:51 3556352 --a------ C:\WINDOWS\system32\netsetup.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:41 199680 --a------ C:\WINDOWS\system32\wuauclt1.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:41 204800 --a------ C:\WINDOWS\system32\wscript.exe <Not Verified; Microsoft Corporation; Microsoft ® Windows Script Host>
2008-04-13 20:12:40 34304 --a------ C:\WINDOWS\system32\wpabaln.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:39 351232 --a------ C:\WINDOWS\winhlp32.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:39 547328 --a------ C:\WINDOWS\system32\winlogon.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:39 527872 --a------ C:\WINDOWS\system32\wiaacmgr.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:39 3291648 --a------ C:\WINDOWS\system32\wextract.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:38 51712 --a------ C:\WINDOWS\system32\utilman.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:37 99840 --a------ C:\WINDOWS\system32\telnet.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:37 239104 --a------ C:\WINDOWS\system32\taskmgr.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:37 3308544 --a------ C:\WINDOWS\system32\sysocmgr.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:36 30208 --a------ C:\WINDOWS\system32\stimon.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:36 1564672 --a------ C:\WINDOWS\system32\spider.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:36 180736 --a------ C:\WINDOWS\system32\sndrec32.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:35 94720 --a------ C:\WINDOWS\system32\sigverif.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:35 102400 --a------ C:\WINDOWS\system32\shrpubw.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:34 47616 --a------ C:\WINDOWS\system32\setup.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:33 38912 --a------ C:\WINDOWS\system32\runonce.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:33 34816 --a------ C:\WINDOWS\system32\rundll32.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:33 77824 --a------ C:\WINDOWS\system32\rtcshare.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:32 43520 --a------ C:\WINDOWS\system32\rcimlby.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:32 59392 --a------ C:\WINDOWS\system32\rasphone.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:32 108544 --a------ C:\WINDOWS\system32\proquota.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:32 267264 --a------ C:\WINDOWS\regedit.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:31 607232 --a------ C:\WINDOWS\system32\progman.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:31 32768 --a------ C:\WINDOWS\system32\perfmon.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:31 82432 --a------ C:\WINDOWS\system32\packager.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:31 217088 --a------ C:\WINDOWS\system32\osk.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:30 5317120 --a------ C:\WINDOWS\system32\ntbackup.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:29 101376 --a------ C:\WINDOWS\system32\nslookup.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:29 69120 --a------ C:\WINDOWS\system32\notepad.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:29 55808 --a------ C:\WINDOWS\system32\narrator.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:28 354816 --a------ C:\WINDOWS\system32\mspaint.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:28 99840 --a------ C:\WINDOWS\system32\msiexec.exe <Not Verified; Microsoft Corporation; Windows Installer - Unicode>
2008-04-13 20:12:27 30720 --a------ C:\WINDOWS\system32\msdtc.exe <Not Verified; Microsoft Corporation; Microsoft Distributed Transaction Coordinator>
2008-04-13 20:12:27 267264 --a------ C:\WINDOWS\system32\mplay32.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:26 3504128 --a------ C:\WINDOWS\system32\mobsync.exe <Not Verified; Microsoft Corporation; Microsoft Synchronization Manager>
2008-04-13 20:12:25 53248 --a------ C:\WINDOWS\system32\mnmsrvc.exe <Not Verified; Microsoft Corporation; Windows® NetMeeting®>
2008-04-13 20:12:25 1518080 --a------ C:\WINDOWS\system32\mmc.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:24 59392 --a------ C:\WINDOWS\system32\magnify.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:24 6192640 --a------ C:\WINDOWS\system32\logonui.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:23 667136 --a------ C:\WINDOWS\system32\mstsc.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:22 161280 --a------ C:\WINDOWS\system32\iexpress.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:21 66560 --a------ C:\WINDOWS\system32\grpconv.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:21 20992 --a------ C:\WINDOWS\hh.exe <Not Verified; Microsoft Corporation; HTML Help>
2008-04-13 20:12:20 409088 --a------ C:\WINDOWS\system32\fsquirt.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:19 1551872 --a------ C:\WINDOWS\explorer.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:16 103936 --a------ C:\WINDOWS\system32\ddeshare.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:16 25088 --a------ C:\WINDOWS\system32\ctfmon.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:15 163840 --a------ C:\WINDOWS\system32\cscript.exe <Not Verified; Microsoft Corporation; Microsoft ® Windows Script Host>
2008-04-13 20:12:15 52224 --a------ C:\WINDOWS\system32\conime.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:15 78336 --a------ C:\WINDOWS\system32\cmstp.exe <Not Verified; Microsoft Corporation; Microsoft® Connection Manager>
2008-04-13 20:12:15 54272 --a------ C:\WINDOWS\system32\cmmon32.exe <Not Verified; Microsoft Corporation; Microsoft® Connection Manager>
2008-04-13 20:12:14 48640 --a------ C:\WINDOWS\system32\cmdl32.exe <Not Verified; Microsoft Corporation; Microsoft® Connection Manager>
2008-04-13 20:12:14 390656 --a------ C:\WINDOWS\system32\cmd.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:14 43008 --a------ C:\WINDOWS\system32\clipsrv.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:14 187392 --a------ C:\WINDOWS\system32\clipbrd.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:14 111616 --a------ C:\WINDOWS\system32\cleanmgr.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:12 84480 --a------ C:\WINDOWS\system32\ahui.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:11 3676160 --a------ C:\WINDOWS\system32\zipfldr.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:11 183296 --a------ C:\WINDOWS\system32\wuaueng1.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:11 185856 --a------ C:\WINDOWS\system32\accwiz.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:10 940032 --a------ C:\WINDOWS\system32\wsecedit.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:09 186368 --a------ C:\WINDOWS\system32\wintrust.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:09 294912 --a------ C:\WINDOWS\system32\winsrv.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:08 698880 --a------ C:\WINDOWS\system32\wiashext.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:08 3698688 --a------ C:\WINDOWS\system32\wiadefui.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:08 83456 --a------ C:\WINDOWS\system32\usbui.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:08 286208 --a------ C:\WINDOWS\system32\upnpui.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:07 447488 --a------ C:\WINDOWS\system32\themeui.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:07 100352 --a------ C:\WINDOWS\system32\tcpmonui.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:07 4344320 --a------ C:\WINDOWS\system32\syssetup.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:07 677888 --a------ C:\WINDOWS\system32\syncui.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:07 743424 --a------ C:\WINDOWS\system32\sxs.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:07 75776 --a------ C:\WINDOWS\system32\storprop.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:07 133120 --a------ C:\WINDOWS\system32\stobject.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:07 263680 --a------ C:\WINDOWS\system32\sti_ci.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:07 265216 --a------ C:\WINDOWS\system32\srrstr.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:07 78336 --a------ C:\WINDOWS\system32\srclient.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:05 36864 --a------ C:\WINDOWS\system32\shscrap.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:05 6873600 --a------ C:\WINDOWS\system32\shimgvw.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:05 134656 --a------ C:\WINDOWS\system32\servdeps.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:05 57856 --a------ C:\WINDOWS\system32\sendmail.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:05 188416 --a------ C:\WINDOWS\system32\scrobj.dll <Not Verified; Microsoft Corporation; Microsoft ® Windows ® Script Component Runtime>
2008-04-13 20:12:04 151552 --a------ C:\WINDOWS\system32\remotepg.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:04 737792 --a------ C:\WINDOWS\system32\regwizc.dll <Not Verified; Microsoft; RegWizCtrl Module>
2008-04-13 20:12:03 927232 --a------ C:\WINDOWS\system32\rasdlg.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:03 913408 --a------ C:\WINDOWS\system32\printui.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:02 296960 --a------ C:\WINDOWS\system32\photowiz.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:02 112128 --a------ C:\WINDOWS\system32\pautoenr.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:02 450560 --a------ C:\WINDOWS\system32\objsel.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:02 153088 --a------ C:\WINDOWS\system32\ntshrui.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:02 3557376 --a------ C:\WINDOWS\system32\newdev.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:02 2355712 --a------ C:\WINDOWS\system32\netshell.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:01 979456 --a------ C:\WINDOWS\system32\netplwiz.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:01 159744 --a------ C:\WINDOWS\system32\netid.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:01 80896 --a------ C:\WINDOWS\system32\mydocs.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:01 1146368 --a------ C:\WINDOWS\system32\msxml3.dll <Not Verified; Microsoft Corporation; Microsoft® MSXML 3.0 SP9>
2008-04-13 20:12:01 742912 --a------ C:\WINDOWS\system32\msxml2.dll <Not Verified; Microsoft Corporation; Microsoft® MSXML 2.0 SP 3>
2008-04-13 20:12:01 547840 --a------ C:\WINDOWS\system32\msxml.dll <Not Verified; Microsoft Corporation; Microsoft XML Core Services>
2008-04-13 20:12:00 323072 --a------ C:\WINDOWS\system32\mstask.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:59 911360 --a------ C:\WINDOWS\system32\msihnd.dll <Not Verified; Microsoft Corporation; Windows Installer - Unicode>
2008-04-13 20:11:59 9441792 --a------ C:\WINDOWS\system32\msieftp.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:59 73728 --a------ C:\WINDOWS\system32\msident.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:59 2893824 --a------ C:\WINDOWS\system32\msi.dll <Not Verified; Microsoft Corporation; Windows Installer - Unicode>
2008-04-13 20:11:59 3165696 --a------ C:\WINDOWS\system32\msgina.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:58 106496 --a------ C:\WINDOWS\system32\msconf.dll <Not Verified; Microsoft Corporation; Windows® NetMeeting®>
2008-04-13 20:11:58 846336 --a------ C:\WINDOWS\system32\mqutil.dll <Not Verified; Microsoft Corporation; Microsoft Message Queue>
2008-04-13 20:11:58 563712 --a------ C:\WINDOWS\system32\mqsnap.dll <Not Verified; Microsoft Corporation; Microsoft Message Queue>
2008-04-13 20:11:57 253440 --a------ C:\WINDOWS\system32\modemui.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:57 369152 --a------ C:\WINDOWS\system32\mobsync.dll <Not Verified; Microsoft Corporation; Microsoft Synchronization Manager>
2008-04-13 20:11:57 85504 --a------ C:\WINDOWS\system32\mmcshext.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:57 3971584 --a------ C:\WINDOWS\system32\mmcndmgr.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:57 325632 --a------ C:\WINDOWS\system32\mmcbase.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:57 42496 --a------ C:\WINDOWS\system32\midimap.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:56 161280 --a------ C:\WINDOWS\system32\mdminst.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:56 489984 --a------ C:\WINDOWS\system32\localsec.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:56 225280 --a------ C:\WINDOWS\system32\keymgr.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:55 153600 --a------ C:\WINDOWS\system32\itss.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:55 155648 --a------ C:\WINDOWS\system32\isign32.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:55 466432 --a------ C:\WINDOWS\system32\ipsmsnap.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:55 423936 --a------ C:\WINDOWS\system32\ipsecsnp.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:55 231424 --a------ C:\WINDOWS\system32\input.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:55 46592 --a------ C:\WINDOWS\system32\inetppui.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:54 417792 --a------ C:\WINDOWS\system32\inetcfg.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:54 122880 --a------ C:\WINDOWS\system32\icwdial.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:54 175616 --a------ C:\WINDOWS\system32\hotplug.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:54 2174976 --a------ C:\WINDOWS\system32\hnetwiz.dll <Not Verified; Microsoft Corporation; Microsoft® Windows ® 2000 Operating System>
2008-04-13 20:11:54 368640 --a------ C:\WINDOWS\system32\hnetcfg.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:54 306688 --a------ C:\WINDOWS\system32\gptext.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:53 393216 --a------ C:\WINDOWS\system32\fontext.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:53 73728 --a------ C:\WINDOWS\system32\fldrclnr.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:53 443904 --a------ C:\WINDOWS\system32\filemgmt.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:53 170496 --a------ C:\WINDOWS\system32\fde.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:53 258048 --a------ C:\WINDOWS\system32\els.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:52 775168 --a------ C:\WINDOWS\system32\dsuiext.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:52 423936 --a------ C:\WINDOWS\system32\dsquery.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:52 192512 --a------ C:\WINDOWS\system32\dsprop.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:52 287744 --a------ C:\WINDOWS\system32\dskquoui.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:52 261120 --a------ C:\WINDOWS\system32\dpvoice.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:52 48128 --a------ C:\WINDOWS\system32\dpmodemx.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:52 385024 --a------ C:\WINDOWS\system32\dmdlgs.dll <Not Verified; Microsoft Corp.; Logical Disk Manager for Windows NT>
2008-04-13 20:11:52 1528832 --a------ C:\WINDOWS\system32\diskcopy.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:52 93184 --a------ C:\WINDOWS\system32\digest.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:51 173056 --a------ C:\WINDOWS\system32\dfrgui.dll <Not Verified; Microsoft Corp. and Executive Software International, Inc.; Windows Disk Defragmenter>
2008-04-13 20:11:51 384000 --a------ C:\WINDOWS\system32\devmgr.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:51 114688 --a------ C:\WINDOWS\system32\dataclen.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:51 6859776 --a------ C:\WINDOWS\system32\cscui.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:51 301568 --a------ C:\WINDOWS\system32\cscdll.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:51 1114112 --a------ C:\WINDOWS\system32\cryptui.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:51 188928 --a------ C:\WINDOWS\system32\credui.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:51 1390080 --a------ C:\WINDOWS\system32\comres.dll <Not Verified; Microsoft Corporation; COM Services>
2008-04-13 20:11:51 1733632 --a------ C:\WINDOWS\system32\compstui.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:51 407040 --a------ C:\WINDOWS\system32\compatui.dll <Not Verified; ; CompatUI Module>
2008-04-13 20:11:51 340992 --a------ C:\WINDOWS\system32\comdlg32.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:51 724992 --a------ C:\WINDOWS\system32\comctl32.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:50 303616 --a------ C:\WINDOWS\system32\cmprops.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:50 515584 --a------ C:\WINDOWS\system32\cmdial32.dll <Not Verified; Microsoft Corporation; Microsoft® Connection Manager>
2008-04-13 20:11:50 1213952 --a------ C:\WINDOWS\system32\certmgr.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:50 220672 --a------ C:\WINDOWS\system32\capesnpn.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:50 89088 --a------ C:\WINDOWS\system32\cabview.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:50 45056 --a------ C:\WINDOWS\system32\bthci.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:50 33280 --a------ C:\WINDOWS\system32\batt.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:50 38400 --a------ C:\WINDOWS\system32\batmeter.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:49 369152 --a------ C:\WINDOWS\system32\appmgr.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:11 3954688 --a------ C:\WINDOWS\system32\winntbbu.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:09:35 949248 --a------ C:\WINDOWS\system32\gpedit.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 13:39:24 3535872 --a------ C:\WINDOWS\system32\xpsp2res.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 13:39:22 218624 --a------ C:\WINDOWS\system32\xpsp1res.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 13:03:19 626176 --a------ C:\WINDOWS\system32\shdoclc.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 12:48:53 2957312 --a------ C:\WINDOWS\system32\winbrand.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 12:45:30 497152 --a------ C:\WINDOWS\system32\moricons.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 12:22:12 97280 --a------ C:\WINDOWS\system32\inetres.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0541290B-954E-4B9E-B9D0-907944A5F690}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06E12C36-760F-4D92-8509-5E5DBF12C423}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{245A2F99-CB03-46A6-B303-ABD532A027C1}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{28DFB706-1E7C-4F26-97C9-F8FB9DD1A215}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{46A65EBF-FDA8-4D16-B78E-D7A50C31664A}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6372BCEC-CDDD-4439-B0FC-21F802225EB2}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8984cb57-6ffe-c1ce-f2ac-125978cdc936}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A559F2F0-36D6-488D-BC52-798F64847CAB}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E1BC0AAB-2C35-40DF-8F1D-4FD437DF432E}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E23136A1-1AC4-4D1B-926F-5D537CFFF359}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [05/01/2006 04:46 PM]
"nwiz"="nwiz.exe" [05/01/2006 04:46 PM C:\WINDOWS\system32\nwiz.exe]
"NVHotkey"="nvHotkey.dll" [05/01/2006 04:46 PM C:\WINDOWS\system32\nvhotkey.dll]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [10/07/2005 03:13 PM]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [09/08/2005 06:20 AM]
"ISUSPM Startup"="c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [08/11/2005 04:30 PM]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [08/11/2005 04:30 PM]
"cctray"="C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe" [11/10/2007 01:03 PM]
"CAVRID"="C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [05/25/2007 12:40 PM]
"cafwc"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe" [05/21/2008 05:36 PM]
"capfasem"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe" [05/21/2008 05:36 PM]
"capfupgrade"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe" [05/21/2008 05:36 PM]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [10/10/2007 08:51 PM]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [04/01/2008 02:49 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [02/22/2008 04:25 AM]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [09/21/2007 04:10 AM C:\WINDOWS\KHALMNPR.Exe]
"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" [09/07/2006 01:19 PM]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [05/06/2008 08:46 PM]
"KEMailKb"="C:\PROGRA~1\MICROI~1\INTERN~1\KEMailKb.EXE" [08/09/2005 04:27 AM]
"KPDrv4XP"="C:\PROGRA~1\MICROI~1\INTERN~1\KPDrv4XP.EXE" [02/21/2005 07:15 AM]
"SmartDefrag"="C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" [04/17/2008 02:51 PM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [04/13/2008 08:12 PM]
"Search Defender"="C:\Program Files\Speeditup Free\SearchDefender.exe" [08/01/2007 08:54 PM]
"RoboForm"="C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [11/10/2007 07:52 PM]
"chimeravirtdesk"="C:\Program Files\Chimera Virtual Desktop\VirtDesktop.exe" [12/02/2005 12:08 AM]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [01/28/2008 11:43 AM]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [04/13/2008 08:12 PM]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce]
"SpybotDeletingD5499"=cmd /c del "C:\WINDOWS\system32\jkkLEWOe.dll_old"
"SpybotDeletingB9936"=command /c del "C:\WINDOWS\system32\opnlMcdC.dll_old"
"SpybotDeletingB1362"=command /c del "C:\WINDOWS\system32\mlJAtTmM.dll"
"SpybotDeletingD4603"=cmd /c del "C:\WINDOWS\system32\opnlMcdC.dll_old"
"SpybotDeletingB3664"=command /c del "C:\WINDOWS\system32\mlJBQhgE.dll_old"
"SpybotDeletingD6167"=cmd /c del "C:\WINDOWS\system32\mlJBQhgE.dll_old"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce]
"SpybotDeletingA9320"=command /c del "C:\WINDOWS\Fonts\'\00jj99uuii66ddxxqqq.zip"
"SpybotDeletingC1292"=cmd /c del "C:\WINDOWS\Fonts\'\00jj99uuii66ddxxqqq.zip"
"SpybotDeletingA7429"=command /c del "C:\WINDOWS\system32\jkkLEWOe.dll_old"
"SpybotDeletingC4670"=cmd /c del "C:\WINDOWS\system32\jkkLEWOe.dll_old"
"SpybotDeletingA3592"=command /c del "C:\WINDOWS\system32\mlJBQhgE.dll_old"
"SpybotDeletingC3244"=cmd /c del "C:\WINDOWS\system32\mlJBQhgE.dll_old"
"SpybotDeletingA3007"=command /c del "C:\WINDOWS\system32\jkkLEWOe.dll_old"
"SpybotDeletingC1672"=cmd /c del "C:\WINDOWS\system32\jkkLEWOe.dll_old"
"SpybotDeletingA6732"=command /c del "C:\WINDOWS\system32\jkkLEWOe.dll_old"
"SpybotDeletingC5548"=cmd /c del "C:\WINDOWS\system32\jkkLEWOe.dll_old"
"SpybotDeletingA3903"=command /c del "C:\WINDOWS\system32\mlJBQhgE.dll_old"
"SpybotDeletingC8944"=cmd /c del "C:\WINDOWS\system32\mlJBQhgE.dll_old"
"SpybotDeletingA1396"=command /c del "C:\WINDOWS\system32\opnlMcdC.dll_old"
"SpybotDeletingC4938"=cmd /c del "C:\WINDOWS\system32\opnlMcdC.dll_old"
"SpybotDeletingA139"=command /c del "C:\WINDOWS\system32\opnlMcdC.dll_old"
"SpybotDeletingC7792"=cmd /c del "C:\WINDOWS\system32\opnlMcdC.dll_old"
"SpybotDeletingA8947"=command /c del "C:\WINDOWS\system32\mlJAtTmM.dll"
"SpybotDeletingC4075"=cmd /c del "C:\WINDOWS\system32\mlJAtTmM.dll"

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2/27/2008 6:22:07 PM]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [1/5/2008 6:44:36 PM]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"LinkResolveIgnoreLinkInfo"=0 (0x0)
"NoResolveSearch"=1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"LinkResolveIgnoreLinkInfo"=0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
"Windows Printing Driver"=WinSpooler.exe
"WinUpdating"=WinUpdating.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awtqnkhe]
awtqnkhe.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
C:\WINDOWS\System32\dimsntfy.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll 11/15/2007 11:10 AM 72208 c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mlJDvSkL]
mlJDvSkL.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PFW]
UmxWnp.Dll 01/31/2007 04:00 PM 79368 C:\WINDOWS\system32\UmxWNP.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rqRIxVPi]
rqRIxVPi.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
eapsvcs eaphost
dot3svc dot3svc

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
napagent
hkmsvc


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
AutoRun\command- D:\autorun.exe




-- Hosts -----------------------------------------------------------------------

127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com

8518 more entries in hosts file.


-- End of Deckard's System Scanner: finished at 2008-06-21 17:48:25 ------------

Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------

-- System Information ----------------------------------------------------------

Microsoft Windows XP Professional (build 2600) SP 3.0
Architecture: X86; Language: English

CPU 0: Intel® Pentium® M processor 2.00GHz
Percentage of Memory in Use: 77%
Physical Memory (total/avail): 1023.4 MiB / 226.65 MiB
Pagefile Memory (total/avail): 2458.3 MiB / 1866.54 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1912.53 MiB

C: is Fixed (NTFS) - 74.52 GiB total, 7.96 GiB free.
D: is CDROM (UDF)

\\.\PHYSICALDRIVE0 - FUJITSU MHV2080AH - 74.53 GiB - 1 partition
\PARTITION0 (bootable) - Installable File System - 74.52 GiB - C:



-- Security Center -------------------------------------------------------------

AUOptions is scheduled to auto-install.


-- Environment Variables -------------------------------------------------------

ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\nate\Application Data
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=XPS
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\nate
LOGONSERVER=\\XPS
MOZ_CRASHREPORTER_DATA_DIRECTORY=C:\Documents and Settings\nate\Application Data\Mozilla\Firefox\Crash Reports
MOZ_CRASHREPORTER_RESTART_ARG_0=C:\Program Files\Mozilla Firefox\firefox.exe
MOZ_CRASHREPORTER_STRINGS_OVERRIDE=C:\Program Files\Mozilla Firefox\crashreporter-override.ini
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\Program Files\Mozilla Firefox;C:\Program Files\Mozilla Firefox;C:\Program Files\Mozilla Firefox;C:\Program Files\Mozilla Firefox;C:\Program Files\Mozilla Firefox;C:\Program Files\Mozilla Firefox;C:\Program Files\Mozilla Firefox;C:\Program Files\Mozilla Firefox;C:\Program Files\Mozilla Firefox;C:\Program Files\Mozilla Firefox;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\system32\wbem;C:\Program Files\Common Files\Softimage
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 6 Model 13 Stepping 8, GenuineIntel
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=0d08
ProgramFiles=C:\Program Files
PROMPT=$P$G
SESSIONNAME=Console
SonicCentral=C:\Program Files\Common Files\Sonic Shared\Sonic Central\
sourcesdk=c:\program files\steam\steamapps\jedmaster03\sourcesdk
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\nate\LOCALS~1\Temp
TMP=C:\DOCUME~1\nate\LOCALS~1\Temp
USERDOMAIN=XPS
USERNAME=nate
USERPROFILE=C:\Documents and Settings\nate
VProject=c:\program files\steam\SteamApps\SourceMods\Empires
windir=C:\WINDOWS


-- User Profiles ---------------------------------------------------------------

nate (admin)
eric (admin)
Guest (new local, guest)


-- Add/Remove Programs ---------------------------------------------------------

--> C:\WINDOWS\system32\\MSIEXEC.EXE /x {075473F5-846A-448B-BCB3-104AA1760205}
--> C:\WINDOWS\system32\\MSIEXEC.EXE /x {1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
--> C:\WINDOWS\system32\\MSIEXEC.EXE /x {AB708C9B-97C8-4AC9-899B-DBF226AC9382}
--> C:\WINDOWS\system32\\MSIEXEC.EXE /x {B12665F4-4E93-4AB4-B7FC-37053B524629}
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{943884D4-B604-496F-B132-DFA9C63FAF6A}\setup.exe" -l0x9
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Photoshop 7.0 --> C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Adobe\Photoshop 7.0\Uninst.isu" -c"C:\Program Files\Adobe\Photoshop 7.0\Uninst.dll"
Adobe Reader 8.1.1 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81100000003}
Adobe Shockwave Player --> C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
Advanced WindowsCare Personal 2.7.0 --> "C:\Program Files\IObit\Advanced WindowsCare V2\unins000.exe"
AI RoboForm --> "C:\Program Files\Siber Systems\AI RoboForm\rfwipeout.exe"
AIM 6 --> C:\Program Files\AIM6\uninst.exe
ALPS Touch Pad Driver --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}\setup.exe" UNINSTALL
Apple Software Update --> MsiExec.exe /I{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}
Broadcom 440x 10/100 Integrated Controller --> MsiExec.exe /X{9C9D0F85-5658-4A5E-95A9-65F7DB2916EE}
Broadcom Gigabit Integrated Controller --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{BE6890C7-31EF-478C-812E-1E2899ABFCA9} /l1033
BSR Screen Recorder 4 --> C:\Program Files\BSR Screen Recorder 4\Uninstall Screen Recorder 4.exe
C-Major Audio --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}\setup.exe" -l0x9 -remove -removeonly
CA Internet Security Suite --> "C:\Program Files\CA\CA Internet Security Suite\caunst.exe" /u
Camera Driver --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D1B3874F-3057-11D6-B2EA-0050BA18806B}\Setup.exe"
CCleaner (remove only) --> "C:\Program Files\CCleaner\uninst.exe"
CDDRV_Installer --> MsiExec.exe /I{0C826C5B-B131-423A-A229-C71B3CACCD6A}
Chimera Virtual Desktop v1.3.7 PRO (051201) --> "C:\Program Files\Chimera Virtual Desktop\unins000.exe"
Command & Conquer 3 --> MsiExec.exe /I{DDEDAF6C-488E-4CDA-8276-1CCF5F3C5C32}
Counter-Strike: Source --> "C:\Program Files\Steam\steam.exe" steam://uninstall/240
Dell Printer Software Uninstall --> C:\Program Files\Dell_HostCD\Install\Uninstall.exe
Dell Resource CD --> MsiExec.exe /X{FCD9CD52-7222-4672-94A0-A722BA702FD0}
DivX Codec --> C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
Glary Utilities 2.5.2 --> "C:\Program Files\Glary Utilities\unins000.exe"
Google Desktop --> C:\Program Files\Google\Google Desktop Search\GoogleDesktopSetup.exe -uninstall
GTK+ Runtime 2.12.8 rev a (remove only) --> C:\Program Files\Common Files\GTK\2.0\uninst.exe
Half-Life 2 --> "C:\Program Files\Steam\steam.exe" steam://uninstall/220
Half-Life 2: Deathmatch --> "C:\Program Files\Steam\steam.exe" steam://uninstall/320
Half-Life 2: Episode One --> "C:\Program Files\Steam\steam.exe" steam://uninstall/380
Half-Life 2: Episode Two --> "C:\Program Files\Steam\steam.exe" steam://uninstall/420
HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Install(US)2 --> C:\Program Files\InstallShield Installation Information\{8A4D41F3-3EDA-4DAC-9403-839708EA0667}\setup.exe -runfromtemp -l0x0009 -removeonly
Insurgency ( Remove only) --> "c:\program files\steam\SteamApps\SourceMods\Insurgency\uninstall.exe"
IObit SmartDefrag --> "C:\Program Files\IObit\IObit SmartDefrag\unins000.exe"
Java™ 6 Update 2 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
Java™ 6 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
Java™ 6 Update 5 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
KeyScrambler --> C:\Program Files\KeyScrambler\uninstall.exe
KhalInstallWrapper --> MsiExec.exe /I{3101CB58-3482-4D21-AF1A-7057FC935355}
Logitech SetPoint --> C:\Program Files\InstallShield Installation Information\{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}\setup.exe -runfromtemp -l0x0009 -removeonly
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 --> "C:\WINDOWS\$NtUninstallWdf01005$\spuninst\spuninst.exe"
Microsoft Office Professional Edition 2003 --> MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
Microsoft Office Shared MUI (English) 2007 --> MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
Microsoft Office Shared Setup Metadata MUI (English) 2007 --> MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
Microsoft Office Visual Web Developer 2007 --> MsiExec.exe /X{90120000-0021-0000-0000-0000000FF1CE}
Microsoft Office Visual Web Developer MUI (English) 2007 --> MsiExec.exe /X{90120000-0021-0409-0000-0000000FF1CE}
Microsoft Rise Of Nations --> "C:\Program Files\Microsoft Games\Rise of Nations\UNINSTAL.EXE" /runtemp /addremove
Microsoft Silverlight --> MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft SQL Server Compact 3.5 Design Tools ENU --> MsiExec.exe /X{2E5C075E-11AB-4BDD-918C-7B9A68953FF8}
Microsoft SQL Server Compact 3.5 ENU --> MsiExec.exe /I{BCC899FE-2DAA-460C-A5FB-60291E73D9C3}
Microsoft SQL Server Database Publishing Wizard 1.2 --> MsiExec.exe /X{9A33B83D-FFC4-44CF-BEEF-632DECEF2FCD}
Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual Web Developer 2008 Express Edition - ENU --> C:\Program Files\Microsoft Visual Studio 9.0\Microsoft Visual Web Developer 2008 Express Edition - ENU\setup.exe
Microsoft Visual Web Developer 2008 Express Edition - ENU --> MsiExec.exe /X{19700927-105D-3812-8548-53EDA3F5A22D}
Microsoft Windows SDK for Visual Studio 2008 Express Tools for .NET Framework --> MsiExec.exe /X{B4C0A315-07FB-39F9-85CD-8CE20C019350}
Microsoft Windows SDK for Visual Studio 2008 Express Tools for Web --> MsiExec.exe /X{3C7EEEC3-464F-3FE9-8795-3CC8B4EAD82A}
Microsoft Windows SDK for Visual Studio 2008 Express Tools for Win32 --> MsiExec.exe /X{07FCBED5-94C3-4F94-B9D3-360FA27C7B06}
Miro --> C:\Program Files\Participatory Culture Foundation\Miro\uninstall.exe
Mozilla Firefox (3.0) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSXML 6.0 Parser (KB933579) --> MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
MSXML4 Parser --> MsiExec.exe /I{01501EBA-EC35-4F9F-8889-3BE346E5DA13}
Notepad++ --> C:\Program Files\Notepad++\uninstall.exe
NVIDIA Drivers --> C:\WINDOWS\system32\nvudisp.exe UninstallGUI
Nvu 1.0 --> "C:\Program Files\Nvu\unins000.exe"
Peggle Deluxe Demo --> "C:\Program Files\Steam\steam.exe" steam://uninstall/3482
Portal --> "C:\Program Files\Steam\steam.exe" steam://uninstall/400
Rohan_USA --> C:\Program Files\Rohan\GoUninstUSA.exe
Roxio DLA --> MsiExec.exe /I{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
Roxio RecordNow Audio --> MsiExec.exe /I{AB708C9B-97C8-4AC9-899B-DBF226AC9382}
Roxio RecordNow Copy --> MsiExec.exe /I{B12665F4-4E93-4AB4-B7FC-37053B524629}
Roxio RecordNow Data --> MsiExec.exe /I{075473F5-846A-448B-BCB3-104AA1760205}
Sonic Update Manager --> MsiExec.exe /I{30465B6C-B53F-49A1-9EBA-A3F187AD502E}
Sound Blaster ADVANCED MB Drivers --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{943884D4-B604-496F-B132-DFA9C63FAF6A}\setup.exe" -l0x9 /remove
Source SDK --> "C:\Program Files\Steam\steam.exe" steam://uninstall/211
Source SDK Base --> "C:\Program Files\Steam\steam.exe" steam://uninstall/215
Speeditup Free 4.70 --> "C:\WINDOWS\Speeditup Free\uninstall.exe" "/U:C:\Program Files\Speeditup Free\irunin.xml"
Spybot - Search & Destroy --> "C:\Program Files\Spybot - Search & Destroy\unins000.exe"
Star Wars® Knights of the Old Republic® II: The Sith Lords™ --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{629F65FB-7F3C-4D66-A1C0-20722744B7B6}\setup.exe" -l0x9 -removeonly
Starcraft --> C:\WINDOWS\SCunin.exe C:\WINDOWS\SCunin.dat
Steam --> MsiExec.exe /X{048298C9-A4D3-490B-9FF9-AB023A9238F3}
System Requirements Lab --> C:\Program Files\SystemRequirementsLab\Uninstall.exe
Team Fortress 2 --> "C:\Program Files\Steam\steam.exe" steam://uninstall/440
TeamSpeak 2 RC2 --> "C:\Program Files\Teamspeak2_RC2\unins000.exe"
Unlocker 1.8.5 --> C:\Program Files\Unlocker\uninst.exe
Valve Hammer Editor --> C:\PROGRA~1\Steam\VALVEH~1\UNWISE.EXE C:\PROGRA~1\Steam\VALVEH~1\INSTALL.LOG
Ventrilo Client --> MsiExec.exe /I{789289CA-F73A-4A16-A331-54D498CE069F}
Viewpoint Media Player --> C:\Program Files\Viewpoint\Viewpoint Media Player\mtsAxInstaller.exe /u
VistaMizer 2.5.1.0 --> C:\WINDOWS\VistaMizer\Uninstall.exe
Winamp --> "C:\Program Files\Winamp\UninstWA.exe"
Windows Live OneCare safety scanner --> RunDll32.exe "C:\Program Files\Windows Live Safety Center\wlscCore.dll",UninstallFunction WLSC_SCANNER_PRODUCT
Windows Presentation Foundation --> MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}
Windows XP Service Pack 3 --> "C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
WinRAR archiver --> C:\Program Files\WinRAR\uninstall.exe
XML Paper Specification Shared Components Pack 1.0 -->
XPS LightFX SDK --> C:\Program Files\InstallShield Installation Information\{777C06F9-8462-4289-9026-0462906E177F}\setup.exe -runfromtemp -l0x0009 -removeonly


-- Application Event Log -------------------------------------------------------

Event Record #/Type6332 / Success
Event Submitted/Written: 06/21/2008 05:15:53 PM
Event ID/Source: 88 / UmxAgent
Event Description:
Sync client C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe registered successfully

Event Record #/Type6331 / Success
Event Submitted/Written: 06/21/2008 05:15:49 PM
Event ID/Source: 88 / UmxAgent
Event Description:
Shell is started at session 0

Event Record #/Type6330 / Success
Event Submitted/Written: 06/21/2008 05:15:49 PM
Event ID/Source: 88 / UmxAgent
Event Description:
explorer.exe started

Event Record #/Type6329 / Success
Event Submitted/Written: 06/21/2008 05:15:49 PM
Event ID/Source: 88 / UmxAgent
Event Description:
explorer.exe started

Event Record #/Type6326 / Success
Event Submitted/Written: 06/21/2008 05:15:18 PM
Event ID/Source: 88 / UmxAgent
Event Description:
Async Process Map: ReadProcessesFromKmxCfg: count=18



-- Security Event Log ----------------------------------------------------------

No Errors/Warnings found.


-- System Event Log ------------------------------------------------------------

Event Record #/Type2245 / Error
Event Submitted/Written: 06/21/2008 05:14:04 PM
Event ID/Source: 10005 / DCOM
Event Description:
DCOM got error "%%1084" attempting to start the service EventSystem with arguments ""
in order to run the server:
{1BE1F766-5536-11D1-B726-00C04FB926AF}

Event Record #/Type2244 / Error
Event Submitted/Written: 06/21/2008 05:14:04 PM
Event ID/Source: 10005 / DCOM
Event Description:
DCOM got error "%%1084" attempting to start the service UmxPol with arguments "-Service"
in order to run the server:
{4C89C3FD-5F94-4678-BBB5-F64759C3C54A}

Event Record #/Type2243 / Error
Event Submitted/Written: 06/21/2008 05:12:20 PM
Event ID/Source: 10005 / DCOM
Event Description:
DCOM got error "%%1084" attempting to start the service netman with arguments ""
in order to run the server:
{BA126AE5-2166-11D1-B1D0-00805FC1270E}

Event Record #/Type2242 / Error
Event Submitted/Written: 06/21/2008 05:12:17 PM
Event ID/Source: 7026 / Service Control Manager
Event Description:
The following boot-start or system-start driver(s) failed to load:
AFD
Fips
intelppm
IPSec
KmxAgent
KmxFile
KmxFw
KmxStart
MRxSmb
NetBIOS--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Saturday, June 21, 2008
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Saturday, June 21, 2008 22:14:16
Records in database: 880037
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\

Scan statistics:
Files scanned: 137595
Threat name: 2
Infected objects: 2
Suspicious objects: 0
Duration of the scan: 02:44:46


File name / Threat name / Threats count
C:\WINDOWS\469.exe Infected: not-a-virus:AdWare.Win32.Agent.cmz 1
C:\WINDOWS\ISMSetup Venora3 (aid=3 smiley).exe Infected: not-a-virus:AdWare.Win32.AdBand.z 1

The selected area was scanned.


Thank you very much for your time!
NetBT
RasAcd
Rdbss
Tcpip
VET-FILT
VET-REC
VETEFILE
VETMONNT

Event Record #/Type2241 / Error
Event Submitted/Written: 06/21/2008 05:12:17 PM
Event ID/Source: 7001 / Service Control Manager
Event Description:
The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error:
%%31



-- End of Deckard's System Scanner: finished at 2008-06-21 17:48:25 ------------

BC AdBot (Login to Remove)

 


#2 Thunder

Thunder

  • Members
  • 3,294 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Belgium
  • Local time:10:40 AM

Posted 23 June 2008 - 04:19 PM

Hello Relikie and welcome to BleepingComputer,

1. * Clean your Cache and Cookies in IE:
  • Close all instances of Outlook Express and Internet Explorer
  • Go to Control Panel > Internet Options > General tab
  • Under Browsing History, click Delete.
  • Click Delete Files, Delete cookies and Delete history
  • Click Close below.
* Clean your Cache and Cookies in Firefox (In case you also have Firefox installed):
  • Go to Tools > Options.
  • Click Privacy in the menu..
  • Click the Clear now button below.. A new window will popup what to clear.
  • Select all and click the Clear button again.
  • Click OK to close the Options window
* Clean other Temporary files + Recycle bin
  • Go to start > run and type: cleanmgr and click ok.
  • Let it scan your system for files to remove.
  • Make sure Temporary Files, Temporary Internet Files, and Recycle Bin are the only things checked.
  • Press OK to remove them.
2. Please download Malwarebytes' Anti-Malware from Here or Here

Doubleclick mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply along with a fresh HijackThis log.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

3. Please visit this webpage for instructions for downloading and running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Please ensure you read this guide carefully and install the Recovery Console first (not for Windows Vista users !).
The Windows Recovery Console will allow you to boot up into a special recovery mode, in case your computer has a problem after an attempted removal of malware. This allows us to help you. (WinXP SP3 users, please download the appropriate SP2 file, Home or Pro, to install the RC)

In the event you already have Combofix, delete your current version and download the latest version as described in the tutorial.
It must be saved directly to your desktop.


Note: Make sure not to click ComboFix's window while it's running. That may cause it to stall or freeze.

Please post the log from ComboFix (can also be found as C:\ComboFix.txt) in your next reply. :thumbsup:

If you have any questions along the way, STOP and ask them before proceeding !!

Greetings,
Thunder
Whatever happens, make believe it was intended to ...
-----------------------------------------------------------------------
Posted Image - If I have helped you in any way, please consider a donation to help me continue the fight against malware.
-----------------------------------------------------------------------
Stand Up & Be Counted --> Posted Image <-- And make a difference

#3 Relikie

Relikie
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:04:40 AM

Posted 28 June 2008 - 09:00 AM

I followed all the steps and nothing went wrong. Here are the new logs:

Malwarebytes' Anti-Malware 1.18
Database version: 897

9:19:00 AM 6/28/2008
mbam-log-6-28-2008 (09-18-56).txt

Scan type: Quick Scan
Objects scanned: 42527
Time elapsed: 6 minute(s), 49 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 6
Registry Values Infected: 3
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06e12c36-760f-4d92-8509-5e5dbf12c423} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0541290b-954e-4b9e-b9d0-907944a5f690} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e1bc0aab-2c35-40df-8f1d-4fd437df432e} (Trojan.Vundo) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\MediaHoldings (Adware.PlayMP3Z) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\QdrDrive (Adware.ISM) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> No action taken.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{06e12c36-760f-4d92-8509-5e5dbf12c423} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{0541290b-954e-4b9e-b9d0-907944a5f690} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{e1bc0aab-2c35-40df-8f1d-4fd437df432e} (Trojan.Vundo) -> No action taken.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\Fonts\a.zip (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\clkcnt.txt (Trojan.Vundo) -> No action taken.

ComboFix 08-06-20.4 - nate 2008-06-28 9:23:17.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.541 [GMT -4:00]
Running from: C:\Documents and Settings\nate\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Autorun.inf
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Temp\vtmp2
C:\WINDOWS\469.exe
C:\WINDOWS\system32\CdcMlnpo.ini
C:\WINDOWS\system32\CdcMlnpo.ini2
C:\WINDOWS\system32\EghQBJlm.ini
C:\WINDOWS\system32\EghQBJlm.ini2
C:\WINDOWS\system32\eOWELkkj.ini
C:\WINDOWS\system32\eOWELkkj.ini2
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\MmTtAJlm.ini
C:\WINDOWS\system32\MmTtAJlm.ini2
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\oVDKUvut.ini
C:\WINDOWS\system32\oVDKUvut.ini2
C:\WINDOWS\system32\PAHNnnnn.ini
C:\WINDOWS\system32\PAHNnnnn.ini2
C:\WINDOWS\system32\StAHNXyb.ini
C:\WINDOWS\system32\StAHNXyb.ini2

----- BITS: Possible infected sites -----

hxxp://s106.photobucket.com
hxxp://i106.photobucket.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_NPF


((((((((((((((((((((((((( Files Created from 2008-05-28 to 2008-06-28 )))))))))))))))))))))))))))))))
.

2008-06-28 08:50 . 2008-06-28 08:50 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-28 08:50 . 2008-06-28 08:50 <DIR> d-------- C:\Documents and Settings\nate\Application Data\Malwarebytes
2008-06-28 08:50 . 2008-06-28 08:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-28 08:50 . 2008-06-19 17:48 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-28 08:50 . 2008-06-19 17:47 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-24 17:56 . 2008-06-24 17:56 <DIR> d-------- C:\Documents and Settings\nate\Application Data\PCF-VLC
2008-06-23 11:25 . 2008-06-23 11:25 <DIR> d-------- C:\Program Files\GoldWave
2008-06-23 11:25 . 2008-06-23 11:25 36,104 --a------ C:\WINDOWS\system32\SpoonUninstall-dBpowerAMP Music Converter.dat
2008-06-23 11:25 . 2008-06-23 11:24 33,846 --a------ C:\WINDOWS\system32\SpoonUninstall-dBpowerAMP Music Converter.bmp
2008-06-23 10:49 . 2008-06-23 10:49 <DIR> d-------- C:\Program Files\Illustrate
2008-06-23 10:49 . 2008-06-23 10:49 <DIR> d-------- C:\Documents and Settings\nate\Application Data\AccurateRip
2008-06-23 10:49 . 2008-06-23 11:25 131,072 --a------ C:\WINDOWS\system32\SpoonUninstall.exe
2008-06-23 10:27 . 2008-06-23 10:27 <DIR> d-------- C:\Program Files\DVDVideoSoft
2008-06-23 10:27 . 2008-06-23 10:27 <DIR> d-------- C:\Program Files\Common Files\DVDVideoSoft
2008-06-23 10:27 . 2008-06-23 16:26 <DIR> d-------- C:\DVDVideoSoft
2008-06-23 10:27 . 2002-01-05 15:37 344,064 --a------ C:\WINDOWS\system32\msvcr70.dll
2008-06-22 11:13 . 2008-06-22 11:13 <DIR> d-------- C:\WINDOWS\system32\AGEIA
2008-06-22 11:13 . 2008-06-22 11:13 <DIR> d-------- C:\Program Files\AGEIA Technologies
2008-06-22 11:11 . 2008-06-22 11:11 <DIR> d-------- C:\Documents and Settings\nate\Application Data\Blender Foundation
2008-06-22 11:09 . 2008-06-22 19:55 <DIR> d-------- C:\Program Files\Worldweaver
2008-06-22 11:03 . 2008-06-22 11:03 <DIR> d-------- C:\Program Files\Blender Foundation
2008-06-21 17:40 . 2008-06-21 17:40 <DIR> d-------- C:\Deckard
2008-06-21 17:23 . 2008-06-21 17:23 <DIR> d-------- C:\Program Files\Trend Micro
2008-06-20 12:40 . 2008-06-20 12:40 <DIR> d-------- C:\Documents and Settings\nate\Application Data\Uniblue
2008-06-19 22:06 . 2008-06-21 16:49 <DIR> d-------- C:\Program Files\a-squared Free
2008-06-19 21:59 . 2008-06-19 21:59 <DIR> d-------- C:\Program Files\CCleaner
2008-06-18 10:19 . 2008-06-18 10:19 <DIR> d-------- C:\Program Files\BSR Screen Recorder 4
2008-06-18 10:19 . 2008-06-18 10:19 585,728 --a------ C:\WINDOWS\system32\bsratswf.dll
2008-06-18 10:19 . 2008-06-18 10:19 147,456 --a------ C:\WINDOWS\system32\bsratwmv.dll
2008-06-18 10:19 . 2008-06-28 09:21 2,048 --a------ C:\WINDOWS\system32\Tr_sttool.dat
2008-06-13 22:32 . 2008-06-23 21:11 39 --a------ C:\WINDOWS\popcinfot.dat
2008-06-11 04:20 . 2008-06-13 07:05 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-11 04:20 . 2008-05-08 10:02 203,136 -----c--- C:\WINDOWS\system32\dllcache\rmcast.sys
2008-06-08 15:55 . 2008-06-08 15:58 <DIR> d-------- C:\Program Files\KompoZer 0.7.10
2008-06-08 15:55 . 2008-06-08 15:55 <DIR> d-------- C:\Documents and Settings\nate\Application Data\KompoZer
2008-06-07 21:23 . 2008-06-07 21:23 8,294,454 --a------ C:\WINDOWS\startup.bmp
2008-06-07 21:23 . 2008-04-13 20:12 218,624 --a------ C:\WINDOWS\system32\uxtheme.backup
2008-06-07 21:10 . 2008-06-07 21:23 <DIR> d-------- C:\WINDOWS\VistaMizer
2008-06-06 11:03 . 2008-06-06 11:03 <DIR> d-------- C:\Documents and Settings\nate\Application Data\GlarySoft
2008-06-06 11:00 . 2008-06-06 11:00 <DIR> d-------- C:\Program Files\Glary Utilities
2008-06-04 09:04 . 2008-06-04 09:04 880,560 --a------ C:\WINDOWS\system32\drivers\vetefile.sys
2008-06-04 09:04 . 2008-06-04 09:04 108,368 --a------ C:\WINDOWS\system32\drivers\veteboot.sys
2008-05-29 19:48 . 2008-05-29 21:50 284 --ahs---- C:\WINDOWS\system32\uBbaGfhk.ini

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-28 13:44 --------- d-----w C:\Program Files\Chimera Virtual Desktop
2008-06-28 13:29 64 ----a-w C:\WINDOWS\system32\drivers\kmxcfg.u2k7
2008-06-28 13:29 64 ----a-w C:\WINDOWS\system32\drivers\kmxcfg.u2k6
2008-06-28 13:29 64 ----a-w C:\WINDOWS\system32\drivers\kmxcfg.u2k5
2008-06-28 13:29 64 ----a-w C:\WINDOWS\system32\drivers\kmxcfg.u2k4
2008-06-28 13:29 64 ----a-w C:\WINDOWS\system32\drivers\kmxcfg.u2k3
2008-06-28 13:29 64 ----a-w C:\WINDOWS\system32\drivers\kmxcfg.u2k2
2008-06-28 13:29 64 ----a-w C:\WINDOWS\system32\drivers\kmxcfg.u2k1
2008-06-28 13:29 358,694 ----a-w C:\WINDOWS\system32\drivers\kmxcfg.u2k0
2008-06-28 01:49 --------- d-----w C:\Program Files\Steam
2008-06-21 21:27 --------- d-----w C:\Program Files\Java
2008-06-20 02:07 --------- d-----w C:\Program Files\IObit
2008-06-14 22:34 --------- d-----w C:\Program Files\Rohan
2008-06-13 11:05 272,128 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-08 01:23 218,624 ----a-w C:\WINDOWS\system32\uxtheme.dll
2008-06-06 14:46 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-06-06 14:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-06-06 14:38 --------- d-----w C:\Program Files\Common Files\Adobe
2008-05-30 12:05 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-30 00:40 --------- d-----w C:\Program Files\Windows Live Safety Center
2008-05-27 15:02 --------- d-----w C:\Program Files\Outspark
2008-05-25 22:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\SecTaskMan
2008-05-25 15:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-05-25 12:07 5,182 ----a-w C:\WINDOWS\system32\tmp.reg
2008-05-22 21:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-22 21:15 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-05-22 20:26 --------- d-----w C:\Documents and Settings\nate\Application Data\LimeWire
2008-05-22 20:26 --------- d-----w C:\Documents and Settings\nate\Application Data\FrostWire
2008-05-22 20:21 266,607 ----a-w C:\WINDOWS\ISMSetup Venora3 (aid=3 smiley).exe
2008-05-21 21:06 37,888 ----a-w C:\WINDOWS\system32\rar.exe
2008-05-21 11:31 147,456 ----a-w C:\WINDOWS\system32\vbzip10.dll
2008-05-19 20:10 --------- d-----w C:\Documents and Settings\nate\Application Data\BitTorrent
2008-05-17 21:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-05-08 14:02 203,136 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:12 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll
2008-05-07 00:46 --------- d-----w C:\Program Files\Google
2008-05-03 20:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\TrackMania
2008-04-27 22:47 357 ----a-w C:\Documents and Settings\nate\.cb_layout.bin
2008-04-23 04:16 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-04-19 16:47 98,304 ----a-w C:\WINDOWS\system32CmdLineExt.dll
2008-04-14 09:42 11,264 ----a-w C:\WINDOWS\system32\spnpinst.exe
2008-04-14 09:42 1,379,840 ----a-w C:\WINDOWS\system32\setupapi.dll
2008-04-14 09:41 423,936 ----a-w C:\WINDOWS\system32\licdll.dll
2008-04-14 00:25 1,804 ----a-w C:\WINDOWS\system32\dcache.bin
2008-04-14 00:16 3,556,352 ----a-w C:\WINDOWS\system32\netsetup.exe
2008-04-14 00:13 92,424 ----a-w C:\WINDOWS\system32\rdpdd.dll
2008-04-14 00:13 87,176 ----a-w C:\WINDOWS\system32\rdpwsx.dll
2008-04-14 00:13 299,520 ----a-w C:\WINDOWS\system32\drmclien.dll
2008-04-14 00:13 12,168 ----a-w C:\WINDOWS\system32\tsddd.dll
2008-04-14 00:11 98,304 ----a-w C:\WINDOWS\system32\actxprxy.dll
2008-04-14 00:10 53,279 ----a-w C:\WINDOWS\system32\odbcji32.dll
2008-04-14 00:10 4,126 ----a-w C:\WINDOWS\system32\msdxmlc.dll
2008-04-14 00:10 3,584 ----a-w C:\WINDOWS\system32\msafd.dll
2008-04-13 19:30 1,845,632 ----a-w C:\WINDOWS\system32\win32k.sys
2008-04-13 19:27 2,446,208 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-04-13 18:44 17,664 ----a-w C:\WINDOWS\system32\watchdog.sys
2008-04-13 18:43 9,728 ----a-w C:\WINDOWS\system32\comsdupd.exe
2008-04-13 18:43 12,800 ----a-w C:\WINDOWS\system32\spiisupd.exe
2008-04-13 18:31 7,424 ----a-w C:\WINDOWS\system32\kd1394.dll
2008-04-13 18:31 2,323,072 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
2008-04-13 18:30 61,440 ----a-w C:\WINDOWS\system32\msvcrt40.dll
2008-04-13 18:14 76,800 ----a-w C:\WINDOWS\system32\msshavmsg.dll
2008-04-13 17:39 438,784 ----a-w C:\WINDOWS\system32\xpob2res.dll
2008-04-13 17:39 3,535,872 ----a-w C:\WINDOWS\system32\xpsp2res.dll
2008-04-13 17:39 218,624 ----a-w C:\WINDOWS\system32\xpsp1res.dll
2008-04-13 17:37 208,384 ----a-w C:\WINDOWS\system32\rsaenh.dll
2008-04-13 17:37 138,752 ----a-w C:\WINDOWS\system32\dssenh.dll
2008-04-13 17:27 79,872 ----a-w C:\WINDOWS\system32\msxml6r.dll
2008-04-13 17:26 212,992 ----a-w C:\WINDOWS\system32\odbcint.dll
2008-04-13 17:26 12,288 ----a-w C:\WINDOWS\system32\odbcp32r.dll
2008-04-13 17:26 12,288 ----a-w C:\WINDOWS\system32\mscpx32r.dll
2008-04-13 17:24 20,480 ----a-w C:\WINDOWS\system32\msorc32r.dll
2008-04-13 17:21 733,696 ----a-w C:\WINDOWS\system32\qedwipes.dll
2008-04-13 17:09 4,096 ----a-w C:\WINDOWS\system32\dsprpres.dll
2008-04-13 17:03 63,488 ----a-w C:\WINDOWS\system32\browselc.dll
2008-04-13 17:03 626,176 ----a-w C:\WINDOWS\system32\shdoclc.dll
2008-04-13 16:48 2,957,312 ----a-w C:\WINDOWS\system32\winbrand.dll
2008-04-13 16:45 497,152 ----a-w C:\WINDOWS\system32\moricons.dll
2008-04-13 16:23 48,128 ----a-w C:\WINDOWS\system32\msprivs.dll
2008-04-13 16:22 97,280 ----a-w C:\WINDOWS\system32\inetres.dll
2008-04-13 15:39 884,736 ----a-w C:\WINDOWS\system32\msimsg.dll
2007-12-22 04:14 13 ---h--w C:\Documents and Settings\All Users\Application Data\1ÌØ13.sys
.

------- Sigcheck -------

2004-08-04 06:00 502272 01c3346c241652f43aed8e2149881bfe C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
2008-04-13 20:12 547328 a55b8899d2ea2e800061bcfd456e34dc C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
2008-04-13 20:12 547328 a55b8899d2ea2e800061bcfd456e34dc C:\WINDOWS\system32\winlogon.exe
2008-04-13 20:12 507904 ed0ef0a136dec83df69f04118870003e C:\WINDOWS\VistaMizer\old\winlogon.exe

2007-02-28 05:15 2059392 4d3dbdccbf97f5ba1e74f322b155c3ba C:\WINDOWS\$NtServicePackUninstall$\ntkrnlpa.exe
2008-04-13 14:31 2323072 063ff1fa9777d2fd8d6b608f1f700e1f C:\WINDOWS\ServicePackFiles\i386\ntkrnlpa.exe
2008-04-13 14:31 2323072 063ff1fa9777d2fd8d6b608f1f700e1f C:\WINDOWS\system32\ntkrnlpa.exe
2008-04-13 14:31 2065792 109f8e3e3c82e337bb71b6bc9b895d61 C:\WINDOWS\VistaMizer\old\ntkrnlpa.exe

2007-02-28 05:55 2182144 5a5c8db4aa962c714c8371fbdf189fc9 C:\WINDOWS\$NtServicePackUninstall$\ntoskrnl.exe
2008-04-13 15:27 2446208 1c48d9f3ea6db95915564655c006be8a C:\WINDOWS\ServicePackFiles\i386\ntoskrnl.exe
2008-04-13 15:27 2446208 1c48d9f3ea6db95915564655c006be8a C:\WINDOWS\system32\ntoskrnl.exe
2008-04-13 15:27 2188928 0c89243c7c3ee199b96fcc16990e0679 C:\WINDOWS\VistaMizer\old\ntoskrnl.exe

2008-04-13 20:12 1551872 c26978d5f821a7330439dd7f0aaaf678 C:\WINDOWS\explorer.exe
2007-06-13 06:23 1033216 97bd6515465659ff8f3b7be375b2ea87 C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
2008-04-13 20:12 1551872 c26978d5f821a7330439dd7f0aaaf678 C:\WINDOWS\ServicePackFiles\i386\explorer.exe
2008-04-13 20:12 1033728 12896823fb95bfb3dc9b46bcaedc9923 C:\WINDOWS\VistaMizer\old\explorer.exe

2004-08-04 06:00 15360 24232996a38c0b0cf151c2140ae29fc8 C:\WINDOWS\$NtServicePackUninstall$\ctfmon.exe
2008-04-13 20:12 25088 b5e8782d4af1b3756f38e11e7c157bbe C:\WINDOWS\ServicePackFiles\i386\ctfmon.exe
2008-04-13 20:12 25088 b5e8782d4af1b3756f38e11e7c157bbe C:\WINDOWS\system32\ctfmon.exe
2008-04-13 20:12 15360 5f1d5f88303d4a4dbc8e5f97ba967cc3 C:\WINDOWS\VistaMizer\old\ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0541290B-954E-4B9E-B9D0-907944A5F690}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06E12C36-760F-4D92-8509-5E5DBF12C423}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{245A2F99-CB03-46A6-B303-ABD532A027C1}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{28DFB706-1E7C-4F26-97C9-F8FB9DD1A215}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{46A65EBF-FDA8-4D16-B78E-D7A50C31664A}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6372BCEC-CDDD-4439-B0FC-21F802225EB2}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8984cb57-6ffe-c1ce-f2ac-125978cdc936}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A559F2F0-36D6-488D-BC52-798F64847CAB}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E1BC0AAB-2C35-40DF-8F1D-4FD437DF432E}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E23136A1-1AC4-4D1B-926F-5D537CFFF359}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Search Defender"="C:\Program Files\Speeditup Free\SearchDefender.exe" [2007-08-01 20:54 541696]
"RoboForm"="C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2007-11-10 19:52 160592]
"chimeravirtdesk"="C:\Program Files\Chimera Virtual Desktop\VirtDesktop.exe" [2005-12-02 00:08 1686528]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 20:12 25088]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-04-13 20:12 1826816]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"SpybotDeletingD5499"="del" []
"SpybotDeletingB9936"="command" []
"SpybotDeletingB1362"="command" []
"SpybotDeletingD4603"="del" []
"SpybotDeletingB3664"="command" []
"SpybotDeletingD6167"="del" []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-05-01 16:46 7561216]
"nwiz"="nwiz.exe" [2006-05-01 16:46 1519616 C:\WINDOWS\system32\nwiz.exe]
"NVHotkey"="nvHotkey.dll" [2006-05-01 16:46 73728 C:\WINDOWS\system32\nvhotkey.dll]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2005-10-07 15:13 176128]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 06:20 122940]
"ISUSPM Startup"="c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 16:30 249856]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 16:30 81920]
"cctray"="C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe" [2007-11-10 13:03 177416]
"CAVRID"="C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [2007-05-25 12:40 228416]
"cafwc"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe" [2008-05-21 17:36 1193224]
"capfasem"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe" [2008-05-21 17:36 173320]
"capfupgrade"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe" [2008-05-21 17:36 259336]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 20:51 39792]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-04-01 14:49 36352]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-09-21 04:10 55824 C:\WINDOWS\KHALMNPR.Exe]
"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" [2006-09-07 13:19 15872]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-05-06 20:46 29744]
"KEMailKb"="C:\PROGRA~1\MICROI~1\INTERN~1\KEMailKb.EXE" [2005-08-09 04:27 401408]
"KPDrv4XP"="C:\PROGRA~1\MICROI~1\INTERN~1\KPDrv4XP.EXE" [2005-02-21 07:15 40960]
"SmartDefrag"="C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" [2008-04-17 14:51 1870592]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"SpybotDeletingA9320"="command" []
"SpybotDeletingC1292"="del" []
"SpybotDeletingA7429"="command" []
"SpybotDeletingC4670"="del" []
"SpybotDeletingA3592"="command" []
"SpybotDeletingC3244"="del" []
"SpybotDeletingA3007"="command" []
"SpybotDeletingC1672"="del" []
"SpybotDeletingA6732"="command" []
"SpybotDeletingC5548"="del" []
"SpybotDeletingA3903"="command" []
"SpybotDeletingC8944"="del" []
"SpybotDeletingA1396"="command" []
"SpybotDeletingC4938"="del" []
"SpybotDeletingA139"="command" []
"SpybotDeletingC7792"="del" []
"SpybotDeletingA8947"="command" []
"SpybotDeletingC4075"="del" []

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-22 20:29 39264]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-02-27 18:22:07 113664]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2008-01-05 18:44:36 784912]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveSearch"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awtqnkhe]
awtqnkhe.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll 2007-11-15 11:10 72208 c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mlJDvSkL]
mlJDvSkL.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PFW]
UmxWnp.Dll 2007-01-31 16:00 79368 C:\WINDOWS\system32\UmxWNP.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rqRIxVPi]
rqRIxVPi.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSACM.SPEEXACM"= SPEEXW.ACM

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\CA Personal Firewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Participatory Culture Foundation\\Miro\\Miro_Downloader.exe"=
"C:\\Program Files\\Steam\\steamapps\\jedmaster03\\source sdk base\\hl2.exe"=
"C:\\Program Files\\Participatory Culture Foundation\\Miro\\xulrunner\\python\\Miro_Downloader.exe"=
"C:\\Program Files\\Steam\\Steam.exe"=
"C:\\Program Files\\Steam\\steamapps\\jedmaster03\\team fortress 2\\hl2.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Rohan\\rohanclient.exe"=

R0 KmxStart;KmxStart;C:\WINDOWS\system32\DRIVERS\kmxstart.sys [2007-10-18 10:46]
R1 KmxAgent;KmxAgent;C:\WINDOWS\system32\DRIVERS\kmxagent.sys [2007-03-21 19:57]
R1 KmxFile;KmxFile;C:\WINDOWS\system32\DRIVERS\KmxFile.sys [2007-03-16 05:39]
R1 KmxFw;KmxFw;C:\WINDOWS\system32\DRIVERS\kmxfw.sys [2007-10-18 14:28]
R2 HIDKbFlt;HIDKbFlt.SvcDesc%;C:\WINDOWS\system32\DRIVERS\HIDKbFlt.sys [2005-07-25 06:13]
R2 KmxCF;KmxCF;C:\WINDOWS\system32\DRIVERS\KmxCF.sys [2007-10-18 10:46]
R2 KmxSbx;KmxSbx;C:\WINDOWS\system32\DRIVERS\KmxSbx.sys [2007-11-02 04:54]
R2 UmxAgent;HIPS Event Manager;"C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe" [2007-10-04 09:23]
R2 UmxCfg;HIPS Configuration Interpreter;"C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe" [2007-10-18 09:39]
R2 UmxPol;HIPS Policy Manager;"C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe" [2007-03-05 20:36]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 17:38]
R3 KeyScrambler;KeyScrambler;C:\WINDOWS\system32\drivers\keyscrambler.sys [2007-12-29 10:35]
R3 KmxCfg;KmxCfg;C:\WINDOWS\system32\DRIVERS\kmxcfg.sys [2007-09-12 12:02]
R3 PPCtlPriv;PPCtlPriv;"C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe" [2007-11-10 13:24]
S3 CoachUsb;Coach Digital Camera on USB;C:\WINDOWS\system32\DRIVERS\CoachUsb.sys [2004-01-22 00:41]
S3 GoogleDesktopManager-022208-143751;Google Desktop Manager 5.7.802.22438;"C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-05-06 20:46]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\autorun.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-06-21 14:47:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-06-07 18:35:33 C:\WINDOWS\Tasks\CAAntiSpywareScan_Daily as nate at 12 02 PM.job"
- C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAAntiSpyware.exe
"2008-06-28 13:42:14 C:\WINDOWS\Tasks\GlaryInitialize.job"
- C:\Program Files\Glary Utilities\initialize.exe
"2008-03-28 15:46:12 C:\WINDOWS\Tasks\Low Battery Alarm Program.job"
"2008-06-22 15:13:20 C:\WINDOWS\Tasks\SmartDefrag.job"
- C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.ex
- C:\Program Files\IObit\IObit SmartDefrag\
"2008-06-28 06:44:29 C:\WINDOWS\Tasks\User_Feed_Synchronization-{25C204A9-25A2-4EF2-AC22-4E545EFF63B8}.job"
- C:\WINDOWS\system32\msfeedssync.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-28 09:43:10
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\explorer.exe
-> C:\Program Files\Unlocker\UnlockerHook.dll
-> C:\Program Files\Chimera Virtual Desktop\CVDH120.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\isafe.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\vetmsg.exe
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Apoint\hidfind.exe
C:\Program Files\Apoint\ApntEx.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
.
**************************************************************************
.
Completion time: 2008-06-28 9:52:32 - machine was rebooted [nate]
ComboFix-quarantined-files.txt 2008-06-28 13:51:15

Pre-Run: 8,316,866,560 bytes free
Post-Run: 8,197,189,632 bytes free

366 --- E O F --- 2008-06-20 07:00:55





Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:54:55 AM, on 6/28/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
C:\Program Files\Apoint\HidFind.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
C:\PROGRA~1\MICROI~1\INTERN~1\KEMailKb.EXE
C:\PROGRA~1\MICROI~1\INTERN~1\KPDrv4XP.EXE
C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe
C:\Program Files\Speeditup Free\SearchDefender.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\Chimera Virtual Desktop\VirtDesktop.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {245A2F99-CB03-46A6-B303-ABD532A027C1} - (no file)
O2 - BHO: (no name) - {28DFB706-1E7C-4F26-97C9-F8FB9DD1A215} - (no file)
O2 - BHO: QFX Software KeyScrambler - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O2 - BHO: (no name) - {46A65EBF-FDA8-4D16-B78E-D7A50C31664A} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: (no name) - {6372BCEC-CDDD-4439-B0FC-21F802225EB2} - (no file)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {8984cb57-6ffe-c1ce-f2ac-125978cdc936} - (no file)
O2 - BHO: (no name) - {A559F2F0-36D6-488D-BC52-798F64847CAB} - (no file)
O2 - BHO: (no name) - {E23136A1-1AC4-4D1B-926F-5D537CFFF359} - (no file)
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [cafwc] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl
O4 - HKLM\..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
O4 - HKLM\..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe" -H
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [KEMailKb] C:\PROGRA~1\MICROI~1\INTERN~1\KEMailKb.EXE
O4 - HKLM\..\Run: [KPDrv4XP] C:\PROGRA~1\MICROI~1\INTERN~1\KPDrv4XP.EXE
O4 - HKLM\..\Run: [SmartDefrag] "C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" /StartUp
O4 - HKLM\..\RunOnce: [SpybotDeletingA9320] command /c del "C:\WINDOWS\Fonts\'\00jj99uuii66ddxxqqq.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1292] cmd /c del "C:\WINDOWS\Fonts\'\00jj99uuii66ddxxqqq.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7429] command /c del "C:\WINDOWS\system32\jkkLEWOe.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4670] cmd /c del "C:\WINDOWS\system32\jkkLEWOe.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3592] command /c del "C:\WINDOWS\system32\mlJBQhgE.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3244] cmd /c del "C:\WINDOWS\system32\mlJBQhgE.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3007] command /c del "C:\WINDOWS\system32\jkkLEWOe.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1672] cmd /c del "C:\WINDOWS\system32\jkkLEWOe.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6732] command /c del "C:\WINDOWS\system32\jkkLEWOe.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5548] cmd /c del "C:\WINDOWS\system32\jkkLEWOe.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3903] command /c del "C:\WINDOWS\system32\mlJBQhgE.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8944] cmd /c del "C:\WINDOWS\system32\mlJBQhgE.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1396] command /c del "C:\WINDOWS\system32\opnlMcdC.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4938] cmd /c del "C:\WINDOWS\system32\opnlMcdC.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA139] command /c del "C:\WINDOWS\system32\opnlMcdC.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7792] cmd /c del "C:\WINDOWS\system32\opnlMcdC.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8947] command /c del "C:\WINDOWS\system32\mlJAtTmM.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4075] cmd /c del "C:\WINDOWS\system32\mlJAtTmM.dll"
O4 - HKCU\..\Run: [Search Defender] "C:\Program Files\Speeditup Free\SearchDefender.exe"
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [chimeravirtdesk] "C:\Program Files\Chimera Virtual Desktop\VirtDesktop.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingD5499] cmd /c del "C:\WINDOWS\system32\jkkLEWOe.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9936] command /c del "C:\WINDOWS\system32\opnlMcdC.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1362] command /c del "C:\WINDOWS\system32\mlJAtTmM.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4603] cmd /c del "C:\WINDOWS\system32\opnlMcdC.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3664] command /c del "C:\WINDOWS\system32\mlJBQhgE.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6167] cmd /c del "C:\WINDOWS\system32\mlJBQhgE.dll_old"
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: (no name) - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O9 - Extra 'Tools' menuitem: &KeyScrambler... - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo...toUploader5.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase9563.cab
O16 - DPF: {AA07EBD2-EBDD-4BD6-9F8F-114BD513492C} -
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: awtqnkhe - awtqnkhe.dll (file missing)
O20 - Winlogon Notify: mlJDvSkL - mlJDvSkL.dll (file missing)
O20 - Winlogon Notify: rqRIxVPi - rqRIxVPi.dll (file missing)
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: Google Desktop Manager 5.7.802.22438 (GoogleDesktopManager-022208-143751) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PPCtlPriv - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

--
End of file - 15148 bytes

#4 Thunder

Thunder

  • Members
  • 3,294 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Belgium
  • Local time:10:40 AM

Posted 29 June 2008 - 05:16 AM

Hello Relikie,

Let's clean up some more :

Open Notepad - don't use any other texteditor than Notepad or the script will fail !
Copy/paste the bold, blue text below into an empty notepad window:File::
C:\WINDOWS\popcinfot.dat
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0541290B-954E-4B9E-B9D0-907944A5F690}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06E12C36-760F-4D92-8509-5E5DBF12C423}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{245A2F99-CB03-46A6-B303-ABD532A027C1}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{28DFB706-1E7C-4F26-97C9-F8FB9DD1A215}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{46A65EBF-FDA8-4D16-B78E-D7A50C31664A}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6372BCEC-CDDD-4439-B0FC-21F802225EB2}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8984cb57-6ffe-c1ce-f2ac-125978cdc936}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A559F2F0-36D6-488D-BC52-798F64847CAB}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E1BC0AAB-2C35-40DF-8F1D-4FD437DF432E}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E23136A1-1AC4-4D1B-926F-5D537CFFF359}]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awtqnkhe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mlJDvSkL]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rqRIxVPi]

Save this as txtfile CFScript

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

Posted Image

This will start ComboFix again. Upon reboot, (in case it asks to reboot), post the contents of the Combofix log in your next reply, as well as a fresh HijackThislog.

Are you still having problems ?

Greetings,
Thunder
Whatever happens, make believe it was intended to ...
-----------------------------------------------------------------------
Posted Image - If I have helped you in any way, please consider a donation to help me continue the fight against malware.
-----------------------------------------------------------------------
Stand Up & Be Counted --> Posted Image <-- And make a difference

#5 Relikie

Relikie
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:04:40 AM

Posted 30 June 2008 - 06:37 PM

ComboFix 08-06-20.4 - nate 2008-06-30 18:59:35.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.528 [GMT -4:00]
Running from: C:\Documents and Settings\nate\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\nate\Desktop\CFscript.txt
* Created a new restore point

FILE ::
C:\WINDOWS\popcinfot.dat
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\popcinfot.dat

.
((((((((((((((((((((((((( Files Created from 2008-05-28 to 2008-06-30 )))))))))))))))))))))))))))))))
.

2008-06-29 19:13 . 2008-06-29 19:13 <DIR> d-------- C:\Program Files\Bonjour
2008-06-29 18:58 . 2008-06-29 18:58 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2008-06-29 18:49 . 2008-06-29 18:49 <DIR> d-------- C:\Program Files\PowerISO
2008-06-29 11:45 . 2008-06-29 13:29 <DIR> d-------- C:\Program Files\PeerGuardian2
2008-06-29 11:33 . 2008-06-29 12:14 <DIR> d-------- C:\Program Files\uTorrent
2008-06-29 11:32 . 2008-06-30 16:33 <DIR> d-------- C:\Documents and Settings\nate\Application Data\uTorrent
2008-06-28 11:39 . 2008-06-28 11:39 <DIR> d-------- C:\Documents and Settings\nate\Application Data\PCF-VLC
2008-06-28 08:50 . 2008-06-28 08:50 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-28 08:50 . 2008-06-28 08:50 <DIR> d-------- C:\Documents and Settings\nate\Application Data\Malwarebytes
2008-06-28 08:50 . 2008-06-28 08:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-28 08:50 . 2008-06-19 17:48 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-28 08:50 . 2008-06-19 17:47 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-23 11:25 . 2008-06-23 11:25 <DIR> d-------- C:\Program Files\GoldWave
2008-06-23 11:25 . 2008-06-23 11:25 36,104 --a------ C:\WINDOWS\system32\SpoonUninstall-dBpowerAMP Music Converter.dat
2008-06-23 11:25 . 2008-06-23 11:24 33,846 --a------ C:\WINDOWS\system32\SpoonUninstall-dBpowerAMP Music Converter.bmp
2008-06-23 10:49 . 2008-06-23 10:49 <DIR> d-------- C:\Program Files\Illustrate
2008-06-23 10:49 . 2008-06-23 10:49 <DIR> d-------- C:\Documents and Settings\nate\Application Data\AccurateRip
2008-06-23 10:49 . 2008-06-23 11:25 131,072 --a------ C:\WINDOWS\system32\SpoonUninstall.exe
2008-06-23 10:27 . 2008-06-23 10:27 <DIR> d-------- C:\Program Files\DVDVideoSoft
2008-06-23 10:27 . 2008-06-23 10:27 <DIR> d-------- C:\Program Files\Common Files\DVDVideoSoft
2008-06-23 10:27 . 2008-06-23 16:26 <DIR> d-------- C:\DVDVideoSoft
2008-06-23 10:27 . 2002-01-05 15:37 344,064 --a------ C:\WINDOWS\system32\msvcr70.dll
2008-06-22 11:13 . 2008-06-22 11:13 <DIR> d-------- C:\WINDOWS\system32\AGEIA
2008-06-22 11:13 . 2008-06-22 11:13 <DIR> d-------- C:\Program Files\AGEIA Technologies
2008-06-22 11:11 . 2008-06-22 11:11 <DIR> d-------- C:\Documents and Settings\nate\Application Data\Blender Foundation
2008-06-21 17:40 . 2008-06-21 17:40 <DIR> d-------- C:\Deckard
2008-06-21 17:23 . 2008-06-21 17:23 <DIR> d-------- C:\Program Files\Trend Micro
2008-06-20 12:40 . 2008-06-20 12:40 <DIR> d-------- C:\Documents and Settings\nate\Application Data\Uniblue
2008-06-19 21:59 . 2008-06-19 21:59 <DIR> d-------- C:\Program Files\CCleaner
2008-06-18 10:19 . 2008-06-18 10:19 <DIR> d-------- C:\Program Files\BSR Screen Recorder 4
2008-06-18 10:19 . 2008-06-18 10:19 585,728 --a------ C:\WINDOWS\system32\bsratswf.dll
2008-06-18 10:19 . 2008-06-18 10:19 147,456 --a------ C:\WINDOWS\system32\bsratwmv.dll
2008-06-18 10:19 . 2008-06-28 10:05 2,048 --a------ C:\WINDOWS\system32\Tr_sttool.dat
2008-06-12 02:28 . 2008-06-12 02:28 56,108 --a------ C:\WINDOWS\system32\drivers\scdemu.sys
2008-06-11 04:20 . 2008-06-13 07:05 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-11 04:20 . 2008-05-08 10:02 203,136 -----c--- C:\WINDOWS\system32\dllcache\rmcast.sys
2008-06-08 15:55 . 2008-06-08 15:58 <DIR> d-------- C:\Program Files\KompoZer 0.7.10
2008-06-08 15:55 . 2008-06-08 15:55 <DIR> d-------- C:\Documents and Settings\nate\Application Data\KompoZer
2008-06-07 21:23 . 2008-06-07 21:23 8,294,454 --a------ C:\WINDOWS\startup.bmp
2008-06-07 21:23 . 2008-04-13 20:12 218,624 --a------ C:\WINDOWS\system32\uxtheme.backup
2008-06-07 21:10 . 2008-06-07 21:23 <DIR> d-------- C:\WINDOWS\VistaMizer
2008-06-06 11:03 . 2008-06-06 11:03 <DIR> d-------- C:\Documents and Settings\nate\Application Data\GlarySoft
2008-06-06 11:00 . 2008-06-06 11:00 <DIR> d-------- C:\Program Files\Glary Utilities
2008-06-04 09:04 . 2008-06-04 09:04 880,560 --a------ C:\WINDOWS\system32\drivers\vetefile.sys
2008-06-04 09:04 . 2008-06-04 09:04 108,368 --a------ C:\WINDOWS\system32\drivers\veteboot.sys
2008-05-29 19:48 . 2008-05-29 21:50 284 --ahs---- C:\WINDOWS\system32\uBbaGfhk.ini
2008-05-27 15:52 . 2008-05-27 17:10 321 --ahs---- C:\WINDOWS\system32\twxEffii.ini
2008-05-25 21:52 . 2004-08-04 06:00 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-05-25 20:59 . 2008-05-25 20:59 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-05-25 20:59 . 2008-05-25 20:59 <DIR> d-------- C:\WINDOWS\system32\en
2008-05-25 20:59 . 2008-05-25 20:59 <DIR> d-------- C:\WINDOWS\system32\bits
2008-05-25 20:59 . 2008-05-25 20:59 <DIR> d-------- C:\WINDOWS\l2schemas
2008-05-25 20:22 . 2008-05-25 20:22 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-05-25 15:59 . 2008-04-13 20:12 69,120 --a------ C:\WINDOWS\system32\wlanapi.dll
2008-05-25 15:59 . 2008-04-13 14:36 42,240 --------- C:\WINDOWS\system32\drivers\viaagp.sys
2008-05-25 15:59 . 2004-08-03 22:29 25,471 --------- C:\WINDOWS\system32\drivers\watv10nt.sys
2008-05-25 15:59 . 2004-08-03 22:29 22,271 --------- C:\WINDOWS\system32\drivers\watv06nt.sys
2008-05-25 15:59 . 2008-04-13 14:43 14,208 --------- C:\WINDOWS\system32\drivers\wacompen.sys
2008-05-25 15:59 . 2004-08-03 22:29 11,935 --------- C:\WINDOWS\system32\drivers\wadv11nt.sys
2008-05-25 15:59 . 2004-08-03 22:29 11,871 --------- C:\WINDOWS\system32\drivers\wadv09nt.sys
2008-05-25 15:59 . 2004-08-03 22:29 11,807 --------- C:\WINDOWS\system32\drivers\wadv07nt.sys
2008-05-25 15:59 . 2004-08-03 22:29 11,295 --------- C:\WINDOWS\system32\drivers\wadv08nt.sys
2008-05-25 15:58 . 2008-04-13 14:46 121,984 --------- C:\WINDOWS\system32\drivers\usbvideo.sys
2008-05-25 15:58 . 2008-04-13 20:12 50,688 --a------ C:\WINDOWS\system32\tspkg.dll
2008-05-25 15:58 . 2008-04-13 14:36 44,672 --------- C:\WINDOWS\system32\drivers\uagp35.sys
2008-05-25 15:58 . 2008-04-13 14:56 12,800 --------- C:\WINDOWS\system32\drivers\usb8023x.sys
2008-05-25 15:58 . 2008-04-13 20:12 11,325 --------- C:\WINDOWS\system32\drivers\vchnt5.dll
2008-05-25 15:56 . 2008-04-13 20:12 397,056 --a------ C:\WINDOWS\system32\s3gnb.dll
2008-05-25 15:56 . 2008-04-13 20:12 291,328 --a------ C:\WINDOWS\system32\qagentrt.dll
2008-05-25 15:56 . 2004-08-03 22:29 166,912 --------- C:\WINDOWS\system32\drivers\s3gnbm.sys
2008-05-25 15:56 . 2008-04-13 20:12 150,528 --a------ C:\WINDOWS\system32\qagent.dll
2008-05-25 15:56 . 2008-04-13 20:12 76,800 --a------ C:\WINDOWS\system32\qutil.dll
2008-05-25 15:56 . 2008-04-13 20:12 62,464 --a------ C:\WINDOWS\system32\qcliprov.dll
2008-05-25 15:56 . 2008-04-13 20:12 61,952 --a------ C:\WINDOWS\system32\rasqec.dll
2008-05-25 15:56 . 2008-04-13 14:46 59,136 --------- C:\WINDOWS\system32\drivers\rfcomm.sys
2008-05-25 15:56 . 2008-04-13 14:56 30,592 --------- C:\WINDOWS\system32\drivers\rndismpx.sys
2008-05-25 15:56 . 2004-08-03 22:41 13,776 --------- C:\WINDOWS\system32\drivers\recagent.sys
2008-05-25 15:54 . 2008-04-13 20:12 155,136 --a------ C:\WINDOWS\system32\mssha.dll
2008-05-25 15:54 . 2008-04-13 14:14 76,800 --a------ C:\WINDOWS\system32\msshavmsg.dll
2008-05-25 15:53 . 2008-04-13 20:11 397,312 --a------ C:\WINDOWS\system32\mmcex.dll
2008-05-25 15:53 . 2008-04-13 20:11 184,320 --a------ C:\WINDOWS\system32\microsoft.managementconsole.dll
2008-05-25 15:53 . 2008-04-13 20:11 106,496 --a------ C:\WINDOWS\system32\mmcfxcommon.dll
2008-05-25 15:53 . 2008-04-13 20:12 33,792 --a------ C:\WINDOWS\system32\mmcperf.exe
2008-05-25 15:52 . 2008-04-13 20:11 61,440 --a------ C:\WINDOWS\system32\kmsvc.dll
2008-05-25 15:52 . 2008-04-13 20:11 37,376 --a------ C:\WINDOWS\system32\l2gpstore.dll
2008-05-25 15:52 . 2008-04-13 20:09 6,144 --a------ C:\WINDOWS\system32\kbdpash.dll
2008-05-25 15:52 . 2008-04-13 20:09 6,144 --a------ C:\WINDOWS\system32\kbdnepr.dll
2008-05-25 15:52 . 2008-04-13 20:09 6,144 --a------ C:\WINDOWS\system32\kbdiultn.dll
2008-05-25 15:52 . 2008-04-13 20:09 6,144 --a------ C:\WINDOWS\system32\kbdbhc.dll
2008-05-25 15:49 . 2008-04-13 20:11 180,224 --a------ C:\WINDOWS\system32\eapphost.dll
2008-05-25 15:49 . 2008-04-13 20:11 94,208 --a------ C:\WINDOWS\system32\eappgnui.dll
2008-05-25 15:49 . 2008-04-13 20:11 59,392 --a------ C:\WINDOWS\system32\eapqec.dll
2008-05-25 15:49 . 2008-04-13 14:36 46,464 --------- C:\WINDOWS\system32\drivers\gagp30kx.sys
2008-05-25 15:49 . 2008-04-13 20:11 40,960 --a------ C:\WINDOWS\system32\eappprxy.dll
2008-05-25 15:49 . 2008-04-13 20:11 33,792 --a------ C:\WINDOWS\system32\eapsvc.dll
2008-05-25 15:49 . 2008-04-13 20:12 20,992 --a------ C:\WINDOWS\system32\faxpatch.exe
2008-05-25 15:49 . 2006-12-28 15:01 19,569 --a------ C:\WINDOWS\003414_.tmp
2008-05-25 15:47 . 2008-04-13 20:11 870,784 --a------ C:\WINDOWS\system32\ati3d1ag.dll
2008-05-25 11:11 . 2008-05-25 11:28 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-05-25 10:12 . 2008-05-29 20:40 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2008-05-25 08:03 . 2008-05-25 08:07 5,182 --a------ C:\WINDOWS\system32\tmp.reg
2008-05-23 14:45 . 2008-06-14 15:59 914 --a------ C:\WINDOWS\system32\LexFiles.usr
2008-05-22 17:17 . 2008-06-06 10:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-22 17:14 . 2008-05-22 17:15 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-05-22 17:14 . 2008-05-22 17:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-22 16:23 . 2008-05-25 21:49 <DIR> d-------- C:\WINDOWS\system32\vntiho18
2008-05-21 21:14 . 2008-05-25 21:49 <DIR> d-------- C:\WINDOWS\system32\logXv18
2008-05-21 21:14 . 2008-05-21 21:14 <DIR> d-------- C:\Temp\dmpxp32
2008-05-21 21:14 . 2008-06-28 09:23 <DIR> d-------- C:\Temp
2008-05-21 07:31 . 2008-05-21 07:31 147,456 --a------ C:\WINDOWS\system32\vbzip10.dll
2008-05-20 20:50 . 2008-05-21 17:06 37,888 --a------ C:\WINDOWS\system32\rar.exe
2008-05-20 20:46 . 2008-05-22 16:21 266,607 --a------ C:\WINDOWS\ISMSetup Venora3 (aid=3 smiley).exe
2008-05-20 16:29 . 2008-05-25 18:05 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SecTaskMan
2008-05-18 21:31 . 2008-05-18 21:31 33 --a------ C:\WINDOWS\system32\684557f1
2008-05-18 17:41 . 2008-05-19 16:10 <DIR> d-------- C:\Documents and Settings\nate\Application Data\BitTorrent
2008-05-07 01:12 . 2008-05-07 01:12 1,288,192 -----c--- C:\WINDOWS\system32\dllcache\quartz.dll
2008-05-01 17:49 . 2008-05-03 16:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TrackMania

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-30 18:27 --------- d-----w C:\Program Files\Steam
2008-06-30 00:11 --------- d-----w C:\Program Files\Chimera Virtual Desktop
2008-06-29 23:13 --------- d-----w C:\Program Files\Common Files\Adobe
2008-06-28 13:29 64 ----a-w C:\WINDOWS\system32\drivers\kmxcfg.u2k7
2008-06-28 13:29 64 ----a-w C:\WINDOWS\system32\drivers\kmxcfg.u2k6
2008-06-28 13:29 64 ----a-w C:\WINDOWS\system32\drivers\kmxcfg.u2k5
2008-06-28 13:29 64 ----a-w C:\WINDOWS\system32\drivers\kmxcfg.u2k4
2008-06-28 13:29 64 ----a-w C:\WINDOWS\system32\drivers\kmxcfg.u2k3
2008-06-28 13:29 64 ----a-w C:\WINDOWS\system32\drivers\kmxcfg.u2k2
2008-06-28 13:29 64 ----a-w C:\WINDOWS\system32\drivers\kmxcfg.u2k1
2008-06-28 13:29 358,694 ----a-w C:\WINDOWS\system32\drivers\kmxcfg.u2k0
2008-06-21 21:27 --------- d-----w C:\Program Files\Java
2008-06-20 02:07 --------- d-----w C:\Program Files\IObit
2008-06-13 11:05 272,128 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-08 01:23 218,624 ----a-w C:\WINDOWS\system32\uxtheme.dll
2008-06-06 14:46 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-05-30 12:05 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-27 15:02 --------- d-----w C:\Program Files\Outspark
2008-05-22 20:26 --------- d-----w C:\Documents and Settings\nate\Application Data\LimeWire
2008-05-22 20:26 --------- d-----w C:\Documents and Settings\nate\Application Data\FrostWire
2008-05-17 21:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-05-08 14:02 203,136 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:12 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll
2008-05-07 00:46 --------- d-----w C:\Program Files\Google
2008-04-27 22:47 357 ----a-w C:\Documents and Settings\nate\.cb_layout.bin
2008-04-23 04:16 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-04-19 16:47 98,304 ----a-w C:\WINDOWS\system32CmdLineExt.dll
2008-04-14 09:42 11,264 ----a-w C:\WINDOWS\system32\spnpinst.exe
2008-04-14 09:42 1,379,840 ----a-w C:\WINDOWS\system32\setupapi.dll
2008-04-14 09:41 423,936 ----a-w C:\WINDOWS\system32\licdll.dll
2008-04-14 00:25 1,804 ----a-w C:\WINDOWS\system32\dcache.bin
2008-04-14 00:16 3,556,352 ----a-w C:\WINDOWS\system32\netsetup.exe
2008-04-14 00:13 92,424 ----a-w C:\WINDOWS\system32\rdpdd.dll
2008-04-14 00:13 87,176 ----a-w C:\WINDOWS\system32\rdpwsx.dll
2008-04-14 00:13 299,520 ----a-w C:\WINDOWS\system32\drmclien.dll
2008-04-14 00:13 12,168 ----a-w C:\WINDOWS\system32\tsddd.dll
2008-04-14 00:11 98,304 ----a-w C:\WINDOWS\system32\actxprxy.dll
2008-04-14 00:10 53,279 ----a-w C:\WINDOWS\system32\odbcji32.dll
2008-04-14 00:10 4,126 ----a-w C:\WINDOWS\system32\msdxmlc.dll
2008-04-14 00:10 3,584 ----a-w C:\WINDOWS\system32\msafd.dll
2008-04-13 19:30 1,845,632 ----a-w C:\WINDOWS\system32\win32k.sys
2008-04-13 19:27 2,446,208 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-04-13 18:44 17,664 ----a-w C:\WINDOWS\system32\watchdog.sys
2008-04-13 18:43 9,728 ----a-w C:\WINDOWS\system32\comsdupd.exe
2008-04-13 18:43 12,800 ----a-w C:\WINDOWS\system32\spiisupd.exe
2008-04-13 18:31 7,424 ----a-w C:\WINDOWS\system32\kd1394.dll
2008-04-13 18:31 2,323,072 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
2008-04-13 18:30 61,440 ----a-w C:\WINDOWS\system32\msvcrt40.dll
2008-04-13 17:39 438,784 ----a-w C:\WINDOWS\system32\xpob2res.dll
2008-04-13 17:39 3,535,872 ----a-w C:\WINDOWS\system32\xpsp2res.dll
2008-04-13 17:39 218,624 ----a-w C:\WINDOWS\system32\xpsp1res.dll
2008-04-13 17:37 208,384 ----a-w C:\WINDOWS\system32\rsaenh.dll
2008-04-13 17:37 138,752 ----a-w C:\WINDOWS\system32\dssenh.dll
2008-04-13 17:27 79,872 ----a-w C:\WINDOWS\system32\msxml6r.dll
2008-04-13 17:26 212,992 ----a-w C:\WINDOWS\system32\odbcint.dll
2008-04-13 17:26 12,288 ----a-w C:\WINDOWS\system32\odbcp32r.dll
2008-04-13 17:26 12,288 ----a-w C:\WINDOWS\system32\mscpx32r.dll
2008-04-13 17:24 20,480 ----a-w C:\WINDOWS\system32\msorc32r.dll
2008-04-13 17:21 733,696 ----a-w C:\WINDOWS\system32\qedwipes.dll
2008-04-13 17:09 4,096 ----a-w C:\WINDOWS\system32\dsprpres.dll
2008-04-13 17:03 63,488 ----a-w C:\WINDOWS\system32\browselc.dll
2008-04-13 17:03 626,176 ----a-w C:\WINDOWS\system32\shdoclc.dll
2008-04-13 16:48 2,957,312 ----a-w C:\WINDOWS\system32\winbrand.dll
2008-04-13 16:45 497,152 ----a-w C:\WINDOWS\system32\moricons.dll
2008-04-13 16:23 48,128 ----a-w C:\WINDOWS\system32\msprivs.dll
2008-04-13 16:22 97,280 ----a-w C:\WINDOWS\system32\inetres.dll
2008-04-13 15:39 884,736 ----a-w C:\WINDOWS\system32\msimsg.dll
2008-03-27 01:49 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-03-12 23:41 724,992 ----a-w C:\WINDOWS\iun6002.exe
2008-03-02 13:35 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe
2007-12-22 04:14 13 ---h--w C:\Documents and Settings\All Users\Application Data\1ÌØ13.sys
.

------- Sigcheck -------

2004-08-04 06:00 502272 01c3346c241652f43aed8e2149881bfe C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
2008-04-13 20:12 547328 a55b8899d2ea2e800061bcfd456e34dc C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
2008-04-13 20:12 547328 a55b8899d2ea2e800061bcfd456e34dc C:\WINDOWS\system32\winlogon.exe
2008-04-13 20:12 507904 ed0ef0a136dec83df69f04118870003e C:\WINDOWS\VistaMizer\old\winlogon.exe

2007-02-28 05:15 2059392 4d3dbdccbf97f5ba1e74f322b155c3ba C:\WINDOWS\$NtServicePackUninstall$\ntkrnlpa.exe
2008-04-13 14:31 2323072 063ff1fa9777d2fd8d6b608f1f700e1f C:\WINDOWS\ServicePackFiles\i386\ntkrnlpa.exe
2008-04-13 14:31 2323072 063ff1fa9777d2fd8d6b608f1f700e1f C:\WINDOWS\system32\ntkrnlpa.exe
2008-04-13 14:31 2065792 109f8e3e3c82e337bb71b6bc9b895d61 C:\WINDOWS\VistaMizer\old\ntkrnlpa.exe

2007-02-28 05:55 2182144 5a5c8db4aa962c714c8371fbdf189fc9 C:\WINDOWS\$NtServicePackUninstall$\ntoskrnl.exe
2008-04-13 15:27 2446208 1c48d9f3ea6db95915564655c006be8a C:\WINDOWS\ServicePackFiles\i386\ntoskrnl.exe
2008-04-13 15:27 2446208 1c48d9f3ea6db95915564655c006be8a C:\WINDOWS\system32\ntoskrnl.exe
2008-04-13 15:27 2188928 0c89243c7c3ee199b96fcc16990e0679 C:\WINDOWS\VistaMizer\old\ntoskrnl.exe

2008-04-13 20:12 1551872 c26978d5f821a7330439dd7f0aaaf678 C:\WINDOWS\explorer.exe
2007-06-13 06:23 1033216 97bd6515465659ff8f3b7be375b2ea87 C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
2008-04-13 20:12 1551872 c26978d5f821a7330439dd7f0aaaf678 C:\WINDOWS\ServicePackFiles\i386\explorer.exe
2008-04-13 20:12 1033728 12896823fb95bfb3dc9b46bcaedc9923 C:\WINDOWS\VistaMizer\old\explorer.exe

2004-08-04 06:00 15360 24232996a38c0b0cf151c2140ae29fc8 C:\WINDOWS\$NtServicePackUninstall$\ctfmon.exe
2008-04-13 20:12 25088 b5e8782d4af1b3756f38e11e7c157bbe C:\WINDOWS\ServicePackFiles\i386\ctfmon.exe
2008-04-13 20:12 25088 b5e8782d4af1b3756f38e11e7c157bbe C:\WINDOWS\system32\ctfmon.exe
2008-04-13 20:12 15360 5f1d5f88303d4a4dbc8e5f97ba967cc3 C:\WINDOWS\VistaMizer\old\ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Search Defender"="C:\Program Files\Speeditup Free\SearchDefender.exe" [2007-08-01 20:54 541696]
"RoboForm"="C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2007-11-10 19:52 160592]
"chimeravirtdesk"="C:\Program Files\Chimera Virtual Desktop\VirtDesktop.exe" [2005-12-02 00:08 1686528]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 20:12 25088]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"SpybotDeletingD6167"="del" []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-05-01 16:46 7561216]
"nwiz"="nwiz.exe" [2006-05-01 16:46 1519616 C:\WINDOWS\system32\nwiz.exe]
"NVHotkey"="nvHotkey.dll" [2006-05-01 16:46 73728 C:\WINDOWS\system32\nvhotkey.dll]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2005-10-07 15:13 176128]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 06:20 122940]
"ISUSPM Startup"="c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 16:30 249856]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 16:30 81920]
"cctray"="C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe" [2007-11-10 13:03 177416]
"CAVRID"="C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [2007-05-25 12:40 228416]
"cafwc"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe" [2008-05-21 17:36 1193224]
"capfasem"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe" [2008-05-21 17:36 173320]
"capfupgrade"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe" [2008-05-21 17:36 259336]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 20:51 39792]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-04-01 14:49 36352]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-09-21 04:10 55824 C:\WINDOWS\KHALMNPR.Exe]
"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" [2006-09-07 13:19 15872]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-05-06 20:46 29744]
"KEMailKb"="C:\PROGRA~1\MICROI~1\INTERN~1\KEMailKb.EXE" [2005-08-09 04:27 401408]
"KPDrv4XP"="C:\PROGRA~1\MICROI~1\INTERN~1\KPDrv4XP.EXE" [2005-02-21 07:15 40960]
"SmartDefrag"="C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" [2008-04-17 14:51 1870592]
"PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2008-06-16 04:52 167936]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"SpybotDeletingA9320"="command" []
"SpybotDeletingC1292"="del" []
"SpybotDeletingA7429"="command" []
"SpybotDeletingC4670"="del" []
"SpybotDeletingA3592"="command" []
"SpybotDeletingC3244"="del" []
"SpybotDeletingA3007"="command" []
"SpybotDeletingC1672"="del" []
"SpybotDeletingA6732"="command" []
"SpybotDeletingC5548"="del" []
"SpybotDeletingA3903"="command" []
"SpybotDeletingC8944"="del" []
"SpybotDeletingA1396"="command" []
"SpybotDeletingC4938"="del" []
"SpybotDeletingA139"="command" []
"SpybotDeletingC7792"="del" []
"SpybotDeletingA8947"="command" []
"SpybotDeletingC4075"="del" []

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-22 20:29 39264]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-02-27 18:22:07 113664]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2008-01-05 18:44:36 784912]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveSearch"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll 2007-11-15 11:10 72208 c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PFW]
UmxWnp.Dll 2007-01-31 16:00 79368 C:\WINDOWS\system32\UmxWNP.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSACM.SPEEXACM"= SPEEXW.ACM

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\CA Personal Firewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Participatory Culture Foundation\\Miro\\Miro_Downloader.exe"=
"C:\\Program Files\\Steam\\steamapps\\jedmaster03\\source sdk base\\hl2.exe"=
"C:\\Program Files\\Participatory Culture Foundation\\Miro\\xulrunner\\python\\Miro_Downloader.exe"=
"C:\\Program Files\\Steam\\Steam.exe"=
"C:\\Program Files\\Steam\\steamapps\\jedmaster03\\team fortress 2\\hl2.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=

R0 KmxStart;KmxStart;C:\WINDOWS\system32\DRIVERS\kmxstart.sys [2007-10-18 10:46]
R1 KmxAgent;KmxAgent;C:\WINDOWS\system32\DRIVERS\kmxagent.sys [2007-03-21 19:57]
R1 KmxFile;KmxFile;C:\WINDOWS\system32\DRIVERS\KmxFile.sys [2007-03-16 05:39]
R1 KmxFw;KmxFw;C:\WINDOWS\system32\DRIVERS\kmxfw.sys [2007-10-18 14:28]
R2 HIDKbFlt;HIDKbFlt.SvcDesc%;C:\WINDOWS\system32\DRIVERS\HIDKbFlt.sys [2005-07-25 06:13]
R2 KmxCF;KmxCF;C:\WINDOWS\system32\DRIVERS\KmxCF.sys [2007-10-18 10:46]
R2 KmxSbx;KmxSbx;C:\WINDOWS\system32\DRIVERS\KmxSbx.sys [2007-11-02 04:54]
R2 UmxAgent;HIPS Event Manager;"C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe" [2007-10-04 09:23]
R2 UmxCfg;HIPS Configuration Interpreter;"C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe" [2007-10-18 09:39]
R2 UmxPol;HIPS Policy Manager;"C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe" [2007-03-05 20:36]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 17:38]
R3 KeyScrambler;KeyScrambler;C:\WINDOWS\system32\drivers\keyscrambler.sys [2007-12-29 10:35]
R3 KmxCfg;KmxCfg;C:\WINDOWS\system32\DRIVERS\kmxcfg.sys [2007-09-12 12:02]
R3 PPCtlPriv;PPCtlPriv;"C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe" [2007-11-10 13:24]
S3 CoachUsb;Coach Digital Camera on USB;C:\WINDOWS\system32\DRIVERS\CoachUsb.sys [2004-01-22 00:41]
S3 GoogleDesktopManager-022208-143751;Google Desktop Manager 5.7.802.22438;"C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-05-06 20:46]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\autorun.exe

*Newly Created Service* - CATCHME
*Newly Created Service* - SCDEMU
.
Contents of the 'Scheduled Tasks' folder
"2008-06-28 14:47:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-06-29 17:01:46 C:\WINDOWS\Tasks\CAAntiSpywareScan_Daily as nate at 2 02 AM.job"
- C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAAntiSpyware.exe
"2008-06-30 00:09:26 C:\WINDOWS\Tasks\GlaryInitialize.job"
- C:\Program Files\Glary Utilities\initialize.exe
"2008-03-28 15:46:12 C:\WINDOWS\Tasks\Low Battery Alarm Program.job"
"2008-06-22 15:13:20 C:\WINDOWS\Tasks\SmartDefrag.job"
- C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.ex
- C:\Program Files\IObit\IObit SmartDefrag\
"2008-06-30 08:06:17 C:\WINDOWS\Tasks\User_Feed_Synchronization-{25C204A9-25A2-4EF2-AC22-4E545EFF63B8}.job"
- C:\WINDOWS\system32\msfeedssync.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-30 19:19:25
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-06-30 19:26:10
ComboFix-quarantined-files.txt 2008-06-30 23:24:46
ComboFix2.txt 2008-06-28 13:52:36

Pre-Run: 9,448,394,752 bytes free
Post-Run: 9,432,510,464 bytes free

366 --- E O F --- 2008-06-20 07:00:55

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:35:21 PM, on 6/30/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Apoint\HidFind.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\PROGRA~1\MICROI~1\INTERN~1\KEMailKb.EXE
C:\PROGRA~1\MICROI~1\INTERN~1\KPDrv4XP.EXE
C:\Program Files\Speeditup Free\SearchDefender.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\Chimera Virtual Desktop\VirtDesktop.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Steam\steam.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {245A2F99-CB03-46A6-B303-ABD532A027C1} - (no file)
O2 - BHO: (no name) - {28DFB706-1E7C-4F26-97C9-F8FB9DD1A215} - (no file)
O2 - BHO: QFX Software KeyScrambler - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O2 - BHO: (no name) - {46A65EBF-FDA8-4D16-B78E-D7A50C31664A} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: (no name) - {6372BCEC-CDDD-4439-B0FC-21F802225EB2} - (no file)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {8984cb57-6ffe-c1ce-f2ac-125978cdc936} - (no file)
O2 - BHO: (no name) - {A559F2F0-36D6-488D-BC52-798F64847CAB} - (no file)
O2 - BHO: (no name) - {E23136A1-1AC4-4D1B-926F-5D537CFFF359} - (no file)
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [cafwc] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl
O4 - HKLM\..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
O4 - HKLM\..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe" -H
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [KEMailKb] C:\PROGRA~1\MICROI~1\INTERN~1\KEMailKb.EXE
O4 - HKLM\..\Run: [KPDrv4XP] C:\PROGRA~1\MICROI~1\INTERN~1\KPDrv4XP.EXE
O4 - HKLM\..\Run: [SmartDefrag] "C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" /StartUp
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\RunOnce: [SpybotDeletingA9320] command /c del "C:\WINDOWS\Fonts\'\00jj99uuii66ddxxqqq.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1292] cmd /c del "C:\WINDOWS\Fonts\'\00jj99uuii66ddxxqqq.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7429] command /c del "C:\WINDOWS\system32\jkkLEWOe.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4670] cmd /c del "C:\WINDOWS\system32\jkkLEWOe.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3592] command /c del "C:\WINDOWS\system32\mlJBQhgE.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3244] cmd /c del "C:\WINDOWS\system32\mlJBQhgE.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3007] command /c del "C:\WINDOWS\system32\jkkLEWOe.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1672] cmd /c del "C:\WINDOWS\system32\jkkLEWOe.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6732] command /c del "C:\WINDOWS\system32\jkkLEWOe.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5548] cmd /c del "C:\WINDOWS\system32\jkkLEWOe.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3903] command /c del "C:\WINDOWS\system32\mlJBQhgE.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8944] cmd /c del "C:\WINDOWS\system32\mlJBQhgE.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1396] command /c del "C:\WINDOWS\system32\opnlMcdC.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4938] cmd /c del "C:\WINDOWS\system32\opnlMcdC.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA139] command /c del "C:\WINDOWS\system32\opnlMcdC.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7792] cmd /c del "C:\WINDOWS\system32\opnlMcdC.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8947] command /c del "C:\WINDOWS\system32\mlJAtTmM.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4075] cmd /c del "C:\WINDOWS\system32\mlJAtTmM.dll"
O4 - HKCU\..\Run: [Search Defender] "C:\Program Files\Speeditup Free\SearchDefender.exe"
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [chimeravirtdesk] "C:\Program Files\Chimera Virtual Desktop\VirtDesktop.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingD5499] cmd /c del "C:\WINDOWS\system32\jkkLEWOe.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9936] command /c del "C:\WINDOWS\system32\opnlMcdC.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1362] command /c del "C:\WINDOWS\system32\mlJAtTmM.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4603] cmd /c del "C:\WINDOWS\system32\opnlMcdC.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3664] command /c del "C:\WINDOWS\system32\mlJBQhgE.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6167] cmd /c del "C:\WINDOWS\system32\mlJBQhgE.dll_old"
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: (no name) - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O9 - Extra 'Tools' menuitem: &KeyScrambler... - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo...toUploader5.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase9563.cab
O16 - DPF: {AA07EBD2-EBDD-4BD6-9F8F-114BD513492C} -
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: awtqnkhe - C:\WINDOWS\
O20 - Winlogon Notify: rqRIxVPi - C:\WINDOWS\
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Desktop Manager 5.7.802.22438 (GoogleDesktopManager-022208-143751) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PPCtlPriv - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

--
End of file - 15372 bytes

Yes, my problem is persisting. Below is a screenshot of what happens when I log in. I am bombarded by many of these as soon as I log in. The name of the window changes at the end sometimes. It is sometimes cmd.exe command.exe and a bunch of letters.exe.
Problem

Edited by Relikie, 30 June 2008 - 09:05 PM.


#6 Thunder

Thunder

  • Members
  • 3,294 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Belgium
  • Local time:10:40 AM

Posted 01 July 2008 - 03:43 AM

Hello Relikie,

I see you are running Teatimer.
I suggest you to disable it because it can interfere with the changes you'll make on your system.
When everything is done and your log is clean again, you can enable it again.
If teatimer gives you a warning afterwards that some changes were made, allow this instead of blocking it.
How to disable TeaTimer during HijackThis Cleanup
Then, Download ResetTeaTimer.bat.
Double click ResetTeaTimer.bat to remove all entries set by TeaTimer.

Start HijackThis, close all open windows leaving only HijackThis running. Place a check against each of the following, if still present :O2 - BHO: (no name) - {245A2F99-CB03-46A6-B303-ABD532A027C1} - (no file)
O2 - BHO: (no name) - {28DFB706-1E7C-4F26-97C9-F8FB9DD1A215} - (no file)
O2 - BHO: (no name) - {46A65EBF-FDA8-4D16-B78E-D7A50C31664A} - (no file)
O2 - BHO: (no name) - {6372BCEC-CDDD-4439-B0FC-21F802225EB2} - (no file)
O2 - BHO: (no name) - {8984cb57-6ffe-c1ce-f2ac-125978cdc936} - (no file)
O2 - BHO: (no name) - {A559F2F0-36D6-488D-BC52-798F64847CAB} - (no file)
O2 - BHO: (no name) - {E23136A1-1AC4-4D1B-926F-5D537CFFF359} - (no file)
O4 - HKLM\..\RunOnce: [SpybotDeletingA9320] command /c del "C:\WINDOWS\Fonts\'\00jj99uuii66ddxxqqq.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1292] cmd /c del "C:\WINDOWS\Fonts\'\00jj99uuii66ddxxqqq.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7429] command /c del "C:\WINDOWS\system32\jkkLEWOe.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4670] cmd /c del "C:\WINDOWS\system32\jkkLEWOe.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3592] command /c del "C:\WINDOWS\system32\mlJBQhgE.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3244] cmd /c del "C:\WINDOWS\system32\mlJBQhgE.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3007] command /c del "C:\WINDOWS\system32\jkkLEWOe.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1672] cmd /c del "C:\WINDOWS\system32\jkkLEWOe.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6732] command /c del "C:\WINDOWS\system32\jkkLEWOe.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5548] cmd /c del "C:\WINDOWS\system32\jkkLEWOe.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3903] command /c del "C:\WINDOWS\system32\mlJBQhgE.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8944] cmd /c del "C:\WINDOWS\system32\mlJBQhgE.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1396] command /c del "C:\WINDOWS\system32\opnlMcdC.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4938] cmd /c del "C:\WINDOWS\system32\opnlMcdC.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA139] command /c del "C:\WINDOWS\system32\opnlMcdC.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7792] cmd /c del "C:\WINDOWS\system32\opnlMcdC.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8947] command /c del "C:\WINDOWS\system32\mlJAtTmM.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4075] cmd /c del "C:\WINDOWS\system32\mlJAtTmM.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5499] cmd /c del "C:\WINDOWS\system32\jkkLEWOe.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9936] command /c del "C:\WINDOWS\system32\opnlMcdC.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1362] command /c del "C:\WINDOWS\system32\mlJAtTmM.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4603] cmd /c del "C:\WINDOWS\system32\opnlMcdC.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3664] command /c del "C:\WINDOWS\system32\mlJBQhgE.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6167] cmd /c del "C:\WINDOWS\system32\mlJBQhgE.dll_old"
O16 - DPF: {AA07EBD2-EBDD-4BD6-9F8F-114BD513492C} -
O20 - Winlogon Notify: awtqnkhe - C:\WINDOWS\
O20 - Winlogon Notify: rqRIxVPi - C:\WINDOWS\

Click on Fix Checked when finished and exit HijackThis.
Make sure your Internet Explorer is closed when you click Fix Checked!

Then, let's clean up some more :

Open Notepad - don't use any other texteditor than Notepad or the script will fail !
Copy/paste the bold, blue text below into an empty notepad window:File::
C:\WINDOWS\system32\uBbaGfhk.ini
C:\WINDOWS\system32\twxEffii.ini
C:\WINDOWS\system32\rar.exe
C:\WINDOWS\ISMSetup Venora3 (aid=3 smiley).exe
C:\WINDOWS\system32\684557f1
Folder::
C:\WINDOWS\system32\vntiho18
C:\WINDOWS\system32\logXv18
C:\Temp\dmpxp32

Save this as txtfile CFScript

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

Posted Image

This will start ComboFix again. Upon reboot, (in case it asks to reboot), post the contents of the Combofix log in your next reply, as well as a fresh HijackThislog.

What problems are remaining ?

Greetings,
Thunder
Whatever happens, make believe it was intended to ...
-----------------------------------------------------------------------
Posted Image - If I have helped you in any way, please consider a donation to help me continue the fight against malware.
-----------------------------------------------------------------------
Stand Up & Be Counted --> Posted Image <-- And make a difference

#7 Relikie

Relikie
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:04:40 AM

Posted 01 July 2008 - 03:16 PM

Thank you very much, the command windows did not open upon logging in this time! I am still going to post the logs, just in case there was something else you were looking at.

ComboFix 08-06-20.4 - nate 2008-07-01 15:37:01.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.390 [GMT -4:00]
Running from: C:\Documents and Settings\nate\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\nate\Desktop\CFscript.txt
* Created a new restore point

FILE ::
C:\WINDOWS\ISMSetup Venora3 (aid=3 smiley).exe
C:\WINDOWS\system32\684557f1
C:\WINDOWS\system32\rar.exe
C:\WINDOWS\system32\twxEffii.ini
C:\WINDOWS\system32\uBbaGfhk.ini
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Temp\dmpxp32
C:\WINDOWS\ISMSetup Venora3 (aid=3 smiley).exe
C:\WINDOWS\system32\684557f1
C:\WINDOWS\system32\logXv18
C:\WINDOWS\system32\rar.exe
C:\WINDOWS\system32\twxEffii.ini
C:\WINDOWS\system32\uBbaGfhk.ini
C:\WINDOWS\system32\vntiho18

.
((((((((((((((((((((((((( Files Created from 2008-06-01 to 2008-07-01 )))))))))))))))))))))))))))))))
.

2008-07-01 13:53 . 2008-07-01 13:53 <DIR> d-------- C:\WINDOWS\system32\QuickTime
2008-07-01 10:54 . 2008-07-01 13:59 <DIR> d-------- C:\Program Files\Macromedia
2008-07-01 10:54 . 2008-07-01 14:00 <DIR> d-------- C:\Program Files\Common Files\Macromedia
2008-07-01 09:01 . 2008-07-01 09:01 <DIR> d-------- C:\Documents and Settings\nate\Application Data\WebApps
2008-07-01 09:01 . 2008-07-01 09:01 <DIR> d-------- C:\Documents and Settings\nate\Application Data\Prism
2008-06-29 19:13 . 2008-06-29 19:13 <DIR> d-------- C:\Program Files\Bonjour
2008-06-29 18:58 . 2008-06-29 18:58 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2008-06-29 18:49 . 2008-06-29 18:49 <DIR> d-------- C:\Program Files\PowerISO
2008-06-29 11:45 . 2008-06-29 13:29 <DIR> d-------- C:\Program Files\PeerGuardian2
2008-06-29 11:33 . 2008-06-29 12:14 <DIR> d-------- C:\Program Files\uTorrent
2008-06-29 11:32 . 2008-07-01 15:57 <DIR> d-------- C:\Documents and Settings\nate\Application Data\uTorrent
2008-06-28 11:39 . 2008-06-28 11:39 <DIR> d-------- C:\Documents and Settings\nate\Application Data\PCF-VLC
2008-06-28 08:50 . 2008-06-28 08:50 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-28 08:50 . 2008-06-28 08:50 <DIR> d-------- C:\Documents and Settings\nate\Application Data\Malwarebytes
2008-06-28 08:50 . 2008-06-28 08:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-28 08:50 . 2008-06-19 17:48 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-28 08:50 . 2008-06-19 17:47 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-23 11:25 . 2008-06-23 11:25 <DIR> d-------- C:\Program Files\GoldWave
2008-06-23 11:25 . 2008-06-23 11:25 36,104 --a------ C:\WINDOWS\system32\SpoonUninstall-dBpowerAMP Music Converter.dat
2008-06-23 11:25 . 2008-06-23 11:24 33,846 --a------ C:\WINDOWS\system32\SpoonUninstall-dBpowerAMP Music Converter.bmp
2008-06-23 10:49 . 2008-06-23 10:49 <DIR> d-------- C:\Program Files\Illustrate
2008-06-23 10:49 . 2008-06-23 10:49 <DIR> d-------- C:\Documents and Settings\nate\Application Data\AccurateRip
2008-06-23 10:49 . 2008-06-23 11:25 131,072 --a------ C:\WINDOWS\system32\SpoonUninstall.exe
2008-06-23 10:27 . 2008-06-23 10:27 <DIR> d-------- C:\Program Files\DVDVideoSoft
2008-06-23 10:27 . 2008-06-23 10:27 <DIR> d-------- C:\Program Files\Common Files\DVDVideoSoft
2008-06-23 10:27 . 2008-06-23 16:26 <DIR> d-------- C:\DVDVideoSoft
2008-06-23 10:27 . 2002-01-05 15:37 344,064 --a------ C:\WINDOWS\system32\msvcr70.dll
2008-06-22 11:13 . 2008-06-22 11:13 <DIR> d-------- C:\WINDOWS\system32\AGEIA
2008-06-22 11:13 . 2008-06-22 11:13 <DIR> d-------- C:\Program Files\AGEIA Technologies
2008-06-22 11:11 . 2008-06-22 11:11 <DIR> d-------- C:\Documents and Settings\nate\Application Data\Blender Foundation
2008-06-21 17:40 . 2008-06-21 17:40 <DIR> d-------- C:\Deckard
2008-06-21 17:23 . 2008-06-21 17:23 <DIR> d-------- C:\Program Files\Trend Micro
2008-06-20 12:40 . 2008-06-20 12:40 <DIR> d-------- C:\Documents and Settings\nate\Application Data\Uniblue
2008-06-19 21:59 . 2008-06-19 21:59 <DIR> d-------- C:\Program Files\CCleaner
2008-06-18 10:19 . 2008-06-18 10:19 <DIR> d-------- C:\Program Files\BSR Screen Recorder 4
2008-06-18 10:19 . 2008-06-18 10:19 585,728 --a------ C:\WINDOWS\system32\bsratswf.dll
2008-06-18 10:19 . 2008-06-18 10:19 147,456 --a------ C:\WINDOWS\system32\bsratwmv.dll
2008-06-18 10:19 . 2008-06-28 10:05 2,048 --a------ C:\WINDOWS\system32\Tr_sttool.dat
2008-06-12 02:28 . 2008-06-12 02:28 56,108 --a------ C:\WINDOWS\system32\drivers\scdemu.sys
2008-06-11 04:20 . 2008-06-13 07:05 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-11 04:20 . 2008-05-08 10:02 203,136 -----c--- C:\WINDOWS\system32\dllcache\rmcast.sys
2008-06-08 15:55 . 2008-06-08 15:58 <DIR> d-------- C:\Program Files\KompoZer 0.7.10
2008-06-08 15:55 . 2008-06-08 15:55 <DIR> d-------- C:\Documents and Settings\nate\Application Data\KompoZer
2008-06-07 21:23 . 2008-06-07 21:23 8,294,454 --a------ C:\WINDOWS\startup.bmp
2008-06-07 21:23 . 2008-04-13 20:12 218,624 --a------ C:\WINDOWS\system32\uxtheme.backup
2008-06-07 21:10 . 2008-06-07 21:23 <DIR> d-------- C:\WINDOWS\VistaMizer
2008-06-06 11:03 . 2008-06-06 11:03 <DIR> d-------- C:\Documents and Settings\nate\Application Data\GlarySoft
2008-06-06 11:00 . 2008-06-06 11:00 <DIR> d-------- C:\Program Files\Glary Utilities
2008-06-04 09:04 . 2008-06-04 09:04 880,560 --a------ C:\WINDOWS\system32\drivers\vetefile.sys
2008-06-04 09:04 . 2008-06-04 09:04 108,368 --a------ C:\WINDOWS\system32\drivers\veteboot.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-01 17:44 --------- d-----w C:\Program Files\Chimera Virtual Desktop
2008-07-01 14:46 --------- d-----w C:\Program Files\Steam
2008-06-29 23:13 --------- d-----w C:\Program Files\Common Files\Adobe
2008-06-28 13:29 64 ----a-w C:\WINDOWS\system32\drivers\kmxcfg.u2k7
2008-06-28 13:29 64 ----a-w C:\WINDOWS\system32\drivers\kmxcfg.u2k6
2008-06-28 13:29 64 ----a-w C:\WINDOWS\system32\drivers\kmxcfg.u2k5
2008-06-28 13:29 64 ----a-w C:\WINDOWS\system32\drivers\kmxcfg.u2k4
2008-06-28 13:29 64 ----a-w C:\WINDOWS\system32\drivers\kmxcfg.u2k3
2008-06-28 13:29 64 ----a-w C:\WINDOWS\system32\drivers\kmxcfg.u2k2
2008-06-28 13:29 64 ----a-w C:\WINDOWS\system32\drivers\kmxcfg.u2k1
2008-06-28 13:29 358,694 ----a-w C:\WINDOWS\system32\drivers\kmxcfg.u2k0
2008-06-21 21:27 --------- d-----w C:\Program Files\Java
2008-06-20 02:07 --------- d-----w C:\Program Files\IObit
2008-06-13 11:05 272,128 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-08 01:23 218,624 ----a-w C:\WINDOWS\system32\uxtheme.dll
2008-06-06 14:46 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-06-06 14:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-30 12:05 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-30 00:40 --------- d-----w C:\Program Files\Windows Live Safety Center
2008-05-27 15:02 --------- d-----w C:\Program Files\Outspark
2008-05-25 22:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\SecTaskMan
2008-05-25 15:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-05-25 12:07 5,182 ----a-w C:\WINDOWS\system32\tmp.reg
2008-05-22 21:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-22 21:15 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-05-22 20:26 --------- d-----w C:\Documents and Settings\nate\Application Data\LimeWire
2008-05-22 20:26 --------- d-----w C:\Documents and Settings\nate\Application Data\FrostWire
2008-05-21 11:31 147,456 ----a-w C:\WINDOWS\system32\vbzip10.dll
2008-05-19 20:10 --------- d-----w C:\Documents and Settings\nate\Application Data\BitTorrent
2008-05-17 21:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-05-08 14:02 203,136 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:12 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll
2008-05-07 00:46 --------- d-----w C:\Program Files\Google
2008-05-03 20:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\TrackMania
2008-04-27 22:47 357 ----a-w C:\Documents and Settings\nate\.cb_layout.bin
2008-04-23 04:16 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-04-19 16:47 98,304 ----a-w C:\WINDOWS\system32CmdLineExt.dll
2008-04-14 09:42 11,264 ----a-w C:\WINDOWS\system32\spnpinst.exe
2008-04-14 09:42 1,379,840 ----a-w C:\WINDOWS\system32\setupapi.dll
2008-04-14 09:41 423,936 ----a-w C:\WINDOWS\system32\licdll.dll
2008-04-14 00:25 1,804 ----a-w C:\WINDOWS\system32\dcache.bin
2008-04-14 00:16 3,556,352 ----a-w C:\WINDOWS\system32\netsetup.exe
2008-04-14 00:13 92,424 ----a-w C:\WINDOWS\system32\rdpdd.dll
2008-04-14 00:13 87,176 ----a-w C:\WINDOWS\system32\rdpwsx.dll
2008-04-14 00:13 299,520 ----a-w C:\WINDOWS\system32\drmclien.dll
2008-04-14 00:13 12,168 ----a-w C:\WINDOWS\system32\tsddd.dll
2008-04-14 00:11 98,304 ----a-w C:\WINDOWS\system32\actxprxy.dll
2008-04-14 00:10 53,279 ----a-w C:\WINDOWS\system32\odbcji32.dll
2008-04-14 00:10 4,126 ----a-w C:\WINDOWS\system32\msdxmlc.dll
2008-04-14 00:10 3,584 ----a-w C:\WINDOWS\system32\msafd.dll
2008-04-13 19:30 1,845,632 ----a-w C:\WINDOWS\system32\win32k.sys
2008-04-13 19:27 2,446,208 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-04-13 18:44 17,664 ----a-w C:\WINDOWS\system32\watchdog.sys
2008-04-13 18:43 9,728 ----a-w C:\WINDOWS\system32\comsdupd.exe
2008-04-13 18:43 12,800 ----a-w C:\WINDOWS\system32\spiisupd.exe
2008-04-13 18:31 7,424 ----a-w C:\WINDOWS\system32\kd1394.dll
2008-04-13 18:31 2,323,072 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
2008-04-13 18:30 61,440 ----a-w C:\WINDOWS\system32\msvcrt40.dll
2008-04-13 18:14 76,800 ----a-w C:\WINDOWS\system32\msshavmsg.dll
2008-04-13 17:39 438,784 ----a-w C:\WINDOWS\system32\xpob2res.dll
2008-04-13 17:39 3,535,872 ----a-w C:\WINDOWS\system32\xpsp2res.dll
2008-04-13 17:39 218,624 ----a-w C:\WINDOWS\system32\xpsp1res.dll
2008-04-13 17:37 208,384 ----a-w C:\WINDOWS\system32\rsaenh.dll
2008-04-13 17:37 138,752 ----a-w C:\WINDOWS\system32\dssenh.dll
2008-04-13 17:27 79,872 ----a-w C:\WINDOWS\system32\msxml6r.dll
2008-04-13 17:26 212,992 ----a-w C:\WINDOWS\system32\odbcint.dll
2008-04-13 17:26 12,288 ----a-w C:\WINDOWS\system32\odbcp32r.dll
2008-04-13 17:26 12,288 ----a-w C:\WINDOWS\system32\mscpx32r.dll
2008-04-13 17:24 20,480 ----a-w C:\WINDOWS\system32\msorc32r.dll
2008-04-13 17:21 733,696 ----a-w C:\WINDOWS\system32\qedwipes.dll
2008-04-13 17:09 4,096 ----a-w C:\WINDOWS\system32\dsprpres.dll
2008-04-13 17:03 63,488 ----a-w C:\WINDOWS\system32\browselc.dll
2008-04-13 17:03 626,176 ----a-w C:\WINDOWS\system32\shdoclc.dll
2008-04-13 16:48 2,957,312 ----a-w C:\WINDOWS\system32\winbrand.dll
2008-04-13 16:45 497,152 ----a-w C:\WINDOWS\system32\moricons.dll
2008-04-13 16:23 48,128 ----a-w C:\WINDOWS\system32\msprivs.dll
2008-04-13 16:22 97,280 ----a-w C:\WINDOWS\system32\inetres.dll
2008-04-13 15:39 884,736 ----a-w C:\WINDOWS\system32\msimsg.dll
2007-12-22 04:14 13 ---h--w C:\Documents and Settings\All Users\Application Data\1ÌØ13.sys
.

------- Sigcheck -------

2004-08-04 06:00 502272 01c3346c241652f43aed8e2149881bfe C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
2008-04-13 20:12 547328 a55b8899d2ea2e800061bcfd456e34dc C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
2008-04-13 20:12 547328 a55b8899d2ea2e800061bcfd456e34dc C:\WINDOWS\system32\winlogon.exe
2008-04-13 20:12 507904 ed0ef0a136dec83df69f04118870003e C:\WINDOWS\VistaMizer\old\winlogon.exe

2007-02-28 05:15 2059392 4d3dbdccbf97f5ba1e74f322b155c3ba C:\WINDOWS\$NtServicePackUninstall$\ntkrnlpa.exe
2008-04-13 14:31 2323072 063ff1fa9777d2fd8d6b608f1f700e1f C:\WINDOWS\ServicePackFiles\i386\ntkrnlpa.exe
2008-04-13 14:31 2323072 063ff1fa9777d2fd8d6b608f1f700e1f C:\WINDOWS\system32\ntkrnlpa.exe
2008-04-13 14:31 2065792 109f8e3e3c82e337bb71b6bc9b895d61 C:\WINDOWS\VistaMizer\old\ntkrnlpa.exe

2007-02-28 05:55 2182144 5a5c8db4aa962c714c8371fbdf189fc9 C:\WINDOWS\$NtServicePackUninstall$\ntoskrnl.exe
2008-04-13 15:27 2446208 1c48d9f3ea6db95915564655c006be8a C:\WINDOWS\ServicePackFiles\i386\ntoskrnl.exe
2008-04-13 15:27 2446208 1c48d9f3ea6db95915564655c006be8a C:\WINDOWS\system32\ntoskrnl.exe
2008-04-13 15:27 2188928 0c89243c7c3ee199b96fcc16990e0679 C:\WINDOWS\VistaMizer\old\ntoskrnl.exe

2008-04-13 20:12 1551872 c26978d5f821a7330439dd7f0aaaf678 C:\WINDOWS\explorer.exe
2007-06-13 06:23 1033216 97bd6515465659ff8f3b7be375b2ea87 C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
2008-04-13 20:12 1551872 c26978d5f821a7330439dd7f0aaaf678 C:\WINDOWS\ServicePackFiles\i386\explorer.exe
2008-04-13 20:12 1033728 12896823fb95bfb3dc9b46bcaedc9923 C:\WINDOWS\VistaMizer\old\explorer.exe

2004-08-04 06:00 15360 24232996a38c0b0cf151c2140ae29fc8 C:\WINDOWS\$NtServicePackUninstall$\ctfmon.exe
2008-04-13 20:12 25088 b5e8782d4af1b3756f38e11e7c157bbe C:\WINDOWS\ServicePackFiles\i386\ctfmon.exe
2008-04-13 20:12 25088 b5e8782d4af1b3756f38e11e7c157bbe C:\WINDOWS\system32\ctfmon.exe
2008-04-13 20:12 15360 5f1d5f88303d4a4dbc8e5f97ba967cc3 C:\WINDOWS\VistaMizer\old\ctfmon.exe
.
((((((((((((((((((((((((((((( snapshot@2008-06-30_19.21.50.94 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-30 00:08:50 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-07-01 17:42:12 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2005-08-31 08:31:28 120,464 ----a-w C:\WINDOWS\Downloaded Installations\Macromedia Flash 8\FL_Client_Installer.exe
+ 2005-04-04 18:49:16 2,003,176 ----a-w C:\WINDOWS\Downloaded Installations\Macromedia Flash 8\WindowsInstaller-KB884016-v2-x86.exe
+ 2008-07-01 18:01:53 65,536 ----a-r C:\WINDOWS\Installer\{2BD5C305-1B27-4D41-B690-7A61172D2FEB}\ARPPRODUCTICONFL8.exe
+ 2008-07-01 14:54:48 65,536 ----a-r C:\WINDOWS\Installer\{5546CDB5-2CE2-498B-B059-5B3BF81FC41F}\EMARPPRODUCTICON.exe
+ 2008-07-01 17:54:01 53,248 ----a-r C:\WINDOWS\Installer\{8BF2C401-02CE-424D-BC26-6C4F9FB446B6}\ARPPRODUCTICONFLV1.exe
- 2007-11-20 21:52:00 2,884,992 ----a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
+ 2005-08-27 18:08:06 1,398,408 ----a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
- 2008-06-30 00:09:41 91,260 ----a-w C:\WINDOWS\system32\nvModes.dat
+ 2008-07-01 17:42:46 91,260 ----a-w C:\WINDOWS\system32\nvModes.dat
+ 2005-08-05 12:52:14 1,642,496 ----a-w C:\WINDOWS\system32\QuickTime\MMxptResources.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A559F2F0-36D6-488D-BC52-798F64847CAB}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Search Defender"="C:\Program Files\Speeditup Free\SearchDefender.exe" [2007-08-01 20:54 541696]
"RoboForm"="C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2007-11-10 19:52 160592]
"chimeravirtdesk"="C:\Program Files\Chimera Virtual Desktop\VirtDesktop.exe" [2005-12-02 00:08 1686528]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 20:12 25088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-05-01 16:46 7561216]
"nwiz"="nwiz.exe" [2006-05-01 16:46 1519616 C:\WINDOWS\system32\nwiz.exe]
"NVHotkey"="nvHotkey.dll" [2006-05-01 16:46 73728 C:\WINDOWS\system32\nvhotkey.dll]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2005-10-07 15:13 176128]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 06:20 122940]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 16:30 249856]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 16:30 81920]
"cctray"="C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe" [2007-11-10 13:03 177416]
"CAVRID"="C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [2007-05-25 12:40 228416]
"cafwc"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe" [2008-05-21 17:36 1193224]
"capfasem"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe" [2008-05-21 17:36 173320]
"capfupgrade"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe" [2008-05-21 17:36 259336]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 20:51 39792]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-04-01 14:49 36352]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-09-21 04:10 55824 C:\WINDOWS\KHALMNPR.Exe]
"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" [2006-09-07 13:19 15872]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-05-06 20:46 29744]
"KEMailKb"="C:\PROGRA~1\MICROI~1\INTERN~1\KEMailKb.EXE" [2005-08-09 04:27 401408]
"KPDrv4XP"="C:\PROGRA~1\MICROI~1\INTERN~1\KPDrv4XP.EXE" [2005-02-21 07:15 40960]
"SmartDefrag"="C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" [2008-04-17 14:51 1870592]
"PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2008-06-16 04:52 167936]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-22 20:29 39264]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-02-27 18:22:07 113664]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2008-01-05 18:44:36 784912]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveSearch"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll 2007-11-15 11:10 72208 c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PFW]
UmxWnp.Dll 2007-01-31 16:00 79368 C:\WINDOWS\system32\UmxWNP.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSACM.SPEEXACM"= SPEEXW.ACM

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\CA Personal Firewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Participatory Culture Foundation\\Miro\\Miro_Downloader.exe"=
"C:\\Program Files\\Steam\\steamapps\\jedmaster03\\source sdk base\\hl2.exe"=
"C:\\Program Files\\Participatory Culture Foundation\\Miro\\xulrunner\\python\\Miro_Downloader.exe"=
"C:\\Program Files\\Steam\\Steam.exe"=
"C:\\Program Files\\Steam\\steamapps\\jedmaster03\\team fortress 2\\hl2.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=

R0 KmxStart;KmxStart;C:\WINDOWS\system32\DRIVERS\kmxstart.sys [2007-10-18 10:46]
R1 KmxAgent;KmxAgent;C:\WINDOWS\system32\DRIVERS\kmxagent.sys [2007-03-21 19:57]
R1 KmxFile;KmxFile;C:\WINDOWS\system32\DRIVERS\KmxFile.sys [2007-03-16 05:39]
R1 KmxFw;KmxFw;C:\WINDOWS\system32\DRIVERS\kmxfw.sys [2007-10-18 14:28]
R2 HIDKbFlt;HIDKbFlt.SvcDesc%;C:\WINDOWS\system32\DRIVERS\HIDKbFlt.sys [2005-07-25 06:13]
R2 KmxCF;KmxCF;C:\WINDOWS\system32\DRIVERS\KmxCF.sys [2007-10-18 10:46]
R2 KmxSbx;KmxSbx;C:\WINDOWS\system32\DRIVERS\KmxSbx.sys [2007-11-02 04:54]
R2 UmxAgent;HIPS Event Manager;"C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe" [2007-10-04 09:23]
R2 UmxCfg;HIPS Configuration Interpreter;"C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe" [2007-10-18 09:39]
R2 UmxPol;HIPS Policy Manager;"C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe" [2007-03-05 20:36]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 17:38]
R3 KeyScrambler;KeyScrambler;C:\WINDOWS\system32\drivers\keyscrambler.sys [2007-12-29 10:35]
R3 KmxCfg;KmxCfg;C:\WINDOWS\system32\DRIVERS\kmxcfg.sys [2007-09-12 12:02]
R3 PPCtlPriv;PPCtlPriv;"C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe" [2007-11-10 13:24]
S3 CoachUsb;Coach Digital Camera on USB;C:\WINDOWS\system32\DRIVERS\CoachUsb.sys [2004-01-22 00:41]
S3 GoogleDesktopManager-022208-143751;Google Desktop Manager 5.7.802.22438;"C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-05-06 20:46]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\autorun.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-06-28 14:47:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-06-29 17:01:46 C:\WINDOWS\Tasks\CAAntiSpywareScan_Daily as nate at 2 02 AM.job"
- C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAAntiSpyware.exe
"2008-07-01 17:42:37 C:\WINDOWS\Tasks\GlaryInitialize.job"
- C:\Program Files\Glary Utilities\initialize.exe
"2008-03-28 15:46:12 C:\WINDOWS\Tasks\Low Battery Alarm Program.job"
"2008-06-22 15:13:20 C:\WINDOWS\Tasks\SmartDefrag.job"
- C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.ex
- C:\Program Files\IObit\IObit SmartDefrag\
"2008-07-01 08:47:13 C:\WINDOWS\Tasks\User_Feed_Synchronization-{25C204A9-25A2-4EF2-AC22-4E545EFF63B8}.job"
- C:\WINDOWS\system32\msfeedssync.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-01 15:56:21
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\explorer.exe
-> C:\Program Files\Chimera Virtual Desktop\CVDH120.dll
.
Completion time: 2008-07-01 16:03:15
ComboFix-quarantined-files.txt 2008-07-01 20:01:30
ComboFix2.txt 2008-06-30 23:26:20
ComboFix3.txt 2008-06-28 13:52:36

Pre-Run: 4,314,349,568 bytes free
Post-Run: 4,349,399,040 bytes free

315 --- E O F --- 2008-06-20 07:00:55



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:16:07 PM, on 7/1/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\PROGRA~1\MICROI~1\INTERN~1\KEMailKb.EXE
C:\PROGRA~1\MICROI~1\INTERN~1\KPDrv4XP.EXE
C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe
C:\Program Files\Speeditup Free\SearchDefender.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\Program Files\Chimera Virtual Desktop\VirtDesktop.exe
C:\Program Files\Apoint\HidFind.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: QFX Software KeyScrambler - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {A559F2F0-36D6-488D-BC52-798F64847CAB} - (no file)
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [cafwc] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl
O4 - HKLM\..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
O4 - HKLM\..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe" -H
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [KEMailKb] C:\PROGRA~1\MICROI~1\INTERN~1\KEMailKb.EXE
O4 - HKLM\..\Run: [KPDrv4XP] C:\PROGRA~1\MICROI~1\INTERN~1\KPDrv4XP.EXE
O4 - HKLM\..\Run: [SmartDefrag] "C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" /StartUp
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKCU\..\Run: [Search Defender] "C:\Program Files\Speeditup Free\SearchDefender.exe"
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [chimeravirtdesk] "C:\Program Files\Chimera Virtual Desktop\VirtDesktop.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: (no name) - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O9 - Extra 'Tools' menuitem: &KeyScrambler... - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo...toUploader5.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase9563.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Desktop Manager 5.7.802.22438 (GoogleDesktopManager-022208-143751) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PPCtlPriv - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

--
End of file - 12148 bytes

#8 Thunder

Thunder

  • Members
  • 3,294 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Belgium
  • Local time:10:40 AM

Posted 02 July 2008 - 04:20 AM

Hello Relikie,

That definitely looks better. :thumbsup:

Start HijackThis, close all open windows leaving only HijackThis running. Place a check against the following, if still present :O2 - BHO: (no name) - {A559F2F0-36D6-488D-BC52-798F64847CAB} - (no file)
Click on Fix Checked when finished and exit HijackThis.
Make sure your Internet Explorer is closed when you click Fix Checked!

Then, you can remove all used tools and folders created in the process.
To remove ComboFix :
Go to Start > Run, and copy and paste next command in the field:ComboFix /u
Make sure there's a space between Combofix and /u
Then press Enter.
This will uninstall Combofix, delete its related folders and files, restore your clock settings, hide file extensions, hide the system/hidden files and resets System Restore again.

Your JavaVM is also out of date. Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 6u6.
  • Scroll down to where it says The Java SE Runtime Environment (JRE) allows end-users to run Java applications.
  • Click the Download button to the right.
  • Check the box that says: Accept License Agreement
  • The page will refresh.
  • Click on the link to download Windows Offline Installation (jre-6u6-windows-i586-p.exe) and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u6-windowsi586-p.exe to install the newest version.
No more problems ?

Greetings,
Thunder
Whatever happens, make believe it was intended to ...
-----------------------------------------------------------------------
Posted Image - If I have helped you in any way, please consider a donation to help me continue the fight against malware.
-----------------------------------------------------------------------
Stand Up & Be Counted --> Posted Image <-- And make a difference

#9 Relikie

Relikie
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:04:40 AM

Posted 02 July 2008 - 04:56 PM

Thank you very much, I have updated with no problems at all and upon restart I am not recieving these annoying cmd windows. Thank you again!

I have a quick question however. Inside this folder, QooBox (ComboFix) there is a quarantine folder. Is it safe to completely delete this QooBox folder?

#10 Thunder

Thunder

  • Members
  • 3,294 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Belgium
  • Local time:10:40 AM

Posted 03 July 2008 - 04:31 AM

Hello Relikie,

If you ran the ComboFix /u command, that folder should be gone.
If it isn't you can delete it completely. :thumbsup:

Greetings,
Thunder
Whatever happens, make believe it was intended to ...
-----------------------------------------------------------------------
Posted Image - If I have helped you in any way, please consider a donation to help me continue the fight against malware.
-----------------------------------------------------------------------
Stand Up & Be Counted --> Posted Image <-- And make a difference




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users