Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

trojan C:\Windows\Winlogon.exe


  • This topic is locked This topic is locked
5 replies to this topic

#1 usm

usm

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:02:40 AM

Posted 24 November 2008 - 08:50 PM

had the Windows cannot find C:\Windows\Winlogon.exe error everytime i started my computer, asked my win xp teacher to help me n he said i should google it n give it a shoot in trying to remove it. so here i am. did sum reading n found outs its a trojan. did the two scan as requested by grinler cuz the more info u hav the easier u can help m deal wit the trojan efficiently. below r the logs. Thanks in advance to any1 who will help m n reply. usm

Logfile of random's system information tool 1.04 (written by random/random)
Run by User at 2008-11-25 02:44:28
Microsoft Windows XP Professional Service Pack 2
System drive C: has 8 GB (19%) free of 40 GB
Total RAM: 2038 MB (64% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:45:05 AM, on 11/25/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
c:\program files\avira\antivir personaledition classic\avcenter.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avscan.exe
C:\Documents and Settings\User\Desktop\RSIT.exe
C:\Program Files\trend micro\User.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Amazing%20Adventures%20The%20Lost%20Tomb/Images/stg_drm.ocx
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1215533576000
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Amazing%20Adventures%20Around%20the%20World/Images/armhelper.ocx
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe

--
End of file - 6312 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\Disk Cleanup.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2008-07-11 308856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2007-09-20 328752]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avgnt"=C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe [2008-06-12 266497]
"BluetoothAuthenticationAgent"=C:\WINDOWS\system32\bthprops.cpl [2008-04-14 110592]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\CTFMON.EXE [2004-08-04 15360]
"msnmsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2007-10-18 5724184]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
C:\WINDOWS\ALCMTR.EXE [2005-05-04 69632]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AzMixerSel]
C:\Program Files\Realtek\InstallShield\AzMixerSel.exe [2005-06-12 53248]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
C:\WINDOWS\system32\bthprops.cpl [2008-04-14 110592]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
C:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut]
C:\WINDOWS\system32\CHDAudPropShortcut.exe [2006-07-27 61952]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
C:\WINDOWS\system32\hkcmd.exe [2007-09-06 166424]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [2005-02-16 49152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
C:\WINDOWS\system32\igfxtray.exe [2007-09-06 141848]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe [2008-09-19 4347120]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2007-10-18 5724184]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpwareSE4]
C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe [2006-10-11 75304]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE [2006-06-15 229376]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PcSync]
C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe [2006-06-27 1449984]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
C:\WINDOWS\system32\igfxpers.exe [2007-09-06 137752]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl]
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2006-11-06 159744]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
C:\WINDOWS\RTHDCPL.EXE [2007-05-29 16132608]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
C:\WINDOWS\SkyTel.EXE [2007-05-29 1826816]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
C:\WINDOWS\SOUNDMAN.EXE [2006-07-22 86016]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [2006-09-28 185896]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2008-07-11 185896]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
D:\Winamp\winampa.exe [2008-08-04 36352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2007-08-24 208896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2007-04-10 236928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=
"NoDrives"=
"NoDriveAutoRun"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\Program Files\DNA\btdna.exe"="C:\Program Files\DNA\btdna.exe:*:Enabled:DNA"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c6b17d5a-5bdb-11dd-a112-001f3a40fe00}]
shell\AutoRun\command - g2pfnid.com
shell\explore\command - g2pfnid.com
shell\open\command - g2pfnid.com


======File associations======

.js - open -

======List of files/folders created in the last 1 months======

2008-11-25 02:44:32 ----SHD---- C:\RECYCLER
2008-11-25 02:44:31 ----D---- C:\Program Files\trend micro
2008-11-25 02:44:28 ----D---- C:\rsit
2008-11-25 02:08:33 ----D---- C:\WINDOWS\temp
2008-11-25 02:08:32 ----D---- C:\WINDOWS\Prefetch
2008-11-25 02:08:32 ----A---- C:\ComboFix.txt
2008-11-25 02:03:08 ----A---- C:\Boot.bak
2008-11-25 02:03:01 ----RASHD---- C:\cmdcons
2008-11-25 02:02:29 ----A---- C:\WINDOWS\NIRCMD.exe
2008-11-25 02:02:25 ----D---- C:\ComboFix
2008-11-25 01:57:59 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2008-11-25 01:57:42 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
2008-11-25 01:57:26 ----HDC---- C:\WINDOWS\$NtUninstallKB957095$
2008-11-25 01:57:05 ----HDC---- C:\WINDOWS\$NtUninstallKB956841$
2008-11-25 01:56:46 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2008-11-25 01:56:10 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2008-11-25 01:55:53 ----HDC---- C:\WINDOWS\$NtUninstallKB954211$
2008-11-25 01:55:36 ----HDC---- C:\WINDOWS\$NtUninstallKB953155$
2008-11-25 01:55:21 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2008-11-25 01:55:04 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2008-11-25 01:54:44 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2008-11-25 01:54:09 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
2008-11-25 01:53:53 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2008-11-25 01:53:27 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2008-11-25 01:53:00 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2008-11-25 01:52:22 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2008-11-25 01:52:17 ----D---- C:\WINDOWS\system32\CatRoot_bak
2008-11-25 01:51:51 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2008-11-25 01:50:39 ----HDC---- C:\WINDOWS\$NtUninstallKB938464$
2008-11-25 01:50:21 ----D---- C:\WINDOWS\LastGood
2008-11-25 01:46:22 ----D---- C:\WINDOWS\system32\scripting
2008-11-25 01:46:22 ----D---- C:\WINDOWS\system32\en
2008-11-25 01:46:22 ----D---- C:\WINDOWS\l2schemas
2008-11-25 01:46:21 ----D---- C:\WINDOWS\system32\bits
2008-11-25 01:42:30 ----A---- C:\WINDOWS\zip.exe
2008-11-25 01:42:30 ----A---- C:\WINDOWS\VFIND.exe
2008-11-25 01:42:30 ----A---- C:\WINDOWS\SWXCACLS.exe
2008-11-25 01:42:30 ----A---- C:\WINDOWS\SWSC.exe
2008-11-25 01:42:30 ----A---- C:\WINDOWS\SWREG.exe
2008-11-25 01:42:30 ----A---- C:\WINDOWS\sed.exe
2008-11-25 01:42:30 ----A---- C:\WINDOWS\grep.exe
2008-11-25 01:42:30 ----A---- C:\WINDOWS\fdsv.exe
2008-11-25 01:42:21 ----D---- C:\WINDOWS\ERDNT
2008-11-25 01:42:21 ----D---- C:\Qoobox
2008-11-25 01:41:46 ----D---- C:\WINDOWS\ServicePackFiles
2008-11-25 01:36:02 ----D---- C:\WINDOWS\network diagnostic
2008-11-25 01:29:57 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2008-11-25 01:11:12 ----D---- C:\Program Files\Avira
2008-11-25 01:11:12 ----D---- C:\Documents and Settings\All Users\Application Data\Avira
2008-11-25 01:03:23 ----HDC---- C:\WINDOWS\$NtUninstallKB952954_0$
2008-11-25 01:03:16 ----HDC---- C:\WINDOWS\$NtUninstallKB946648_0$
2008-11-25 01:03:10 ----HDC---- C:\WINDOWS\$NtUninstallKB956803_0$
2008-11-25 01:03:03 ----HDC---- C:\WINDOWS\$NtUninstallKB956391$
2008-11-25 01:02:56 ----HDC---- C:\WINDOWS\$NtUninstallKB957095_0$
2008-11-25 01:02:28 ----HDC---- C:\WINDOWS\$NtUninstallKB950974_0$
2008-11-25 01:02:20 ----HDC---- C:\WINDOWS\$NtUninstallKB954211_0$
2008-11-25 01:01:29 ----A---- C:\WINDOWS\system32\SET16F.tmp
2008-11-25 01:01:29 ----A---- C:\WINDOWS\system32\SET16E.tmp
2008-11-25 01:01:29 ----A---- C:\WINDOWS\system32\SET1230.tmp
2008-11-25 01:01:29 ----A---- C:\WINDOWS\system32\SET122D.tmp
2008-11-25 01:01:28 ----A---- C:\WINDOWS\system32\SET181.tmp
2008-11-25 01:01:28 ----A---- C:\WINDOWS\system32\SET17E.tmp
2008-11-25 01:01:28 ----A---- C:\WINDOWS\system32\SET17D.tmp
2008-11-25 01:01:28 ----A---- C:\WINDOWS\system32\SET175.tmp
2008-11-25 01:01:28 ----A---- C:\WINDOWS\system32\SET173.tmp
2008-11-25 01:01:28 ----A---- C:\WINDOWS\system32\SET171.tmp
2008-11-25 01:01:28 ----A---- C:\WINDOWS\system32\SET1235.tmp
2008-11-25 01:01:28 ----A---- C:\WINDOWS\system32\SET1233.tmp
2008-11-25 01:01:27 ----N---- C:\WINDOWS\system32\wlanapi.dll
2008-11-25 01:01:27 ----A---- C:\WINDOWS\system32\SET196.tmp
2008-11-25 01:01:27 ----A---- C:\WINDOWS\system32\SET195.tmp
2008-11-25 01:01:27 ----A---- C:\WINDOWS\system32\SET194.tmp
2008-11-25 01:01:27 ----A---- C:\WINDOWS\system32\SET192.tmp
2008-11-25 01:01:27 ----A---- C:\WINDOWS\system32\SET191.tmp
2008-11-25 01:01:27 ----A---- C:\WINDOWS\system32\SET190.tmp
2008-11-25 01:01:27 ----A---- C:\WINDOWS\system32\SET18F.tmp
2008-11-25 01:01:27 ----A---- C:\WINDOWS\system32\SET18E.tmp
2008-11-25 01:01:27 ----A---- C:\WINDOWS\system32\SET18C.tmp
2008-11-25 01:01:27 ----A---- C:\WINDOWS\system32\SET18B.tmp
2008-11-25 01:01:27 ----A---- C:\WINDOWS\system32\SET18A.tmp
2008-11-25 01:01:27 ----A---- C:\WINDOWS\system32\SET123A.tmp
2008-11-25 01:01:26 ----A---- C:\WINDOWS\system32\SET1A5.tmp
2008-11-25 01:01:26 ----A---- C:\WINDOWS\system32\SET1A2.tmp
2008-11-25 01:01:26 ----A---- C:\WINDOWS\system32\SET1A0.tmp
2008-11-25 01:01:26 ----A---- C:\WINDOWS\system32\SET199.tmp
2008-11-25 01:01:26 ----A---- C:\WINDOWS\system32\SET123E.tmp
2008-11-25 01:01:25 ----A---- C:\WINDOWS\system32\SET1B4.tmp
2008-11-25 01:01:25 ----A---- C:\WINDOWS\system32\SET1B3.tmp
2008-11-25 01:01:25 ----A---- C:\WINDOWS\system32\SET1B2.tmp
2008-11-25 01:01:25 ----A---- C:\WINDOWS\system32\SET1B0.tmp
2008-11-25 01:01:25 ----A---- C:\WINDOWS\system32\SET1A9.tmp
2008-11-25 01:01:25 ----A---- C:\WINDOWS\system32\SET1A7.tmp
2008-11-25 01:01:24 ----A---- C:\WINDOWS\system32\SET1BF.tmp
2008-11-25 01:01:24 ----A---- C:\WINDOWS\system32\SET1BE.tmp
2008-11-25 01:01:24 ----A---- C:\WINDOWS\system32\SET1BD.tmp
2008-11-25 01:01:24 ----A---- C:\WINDOWS\system32\SET1BC.tmp
2008-11-25 01:01:24 ----A---- C:\WINDOWS\system32\SET1BB.tmp
2008-11-25 01:01:24 ----A---- C:\WINDOWS\system32\SET1B9.tmp
2008-11-25 01:01:24 ----A---- C:\WINDOWS\system32\SET1B6.tmp
2008-11-25 01:01:23 ----N---- C:\WINDOWS\system32\tspkg.dll
2008-11-25 01:01:23 ----N---- C:\WINDOWS\system32\tsgqec.dll
2008-11-25 01:01:23 ----A---- C:\WINDOWS\system32\SET1D2.tmp
2008-11-25 01:01:23 ----A---- C:\WINDOWS\system32\SET1D1.tmp
2008-11-25 01:01:23 ----A---- C:\WINDOWS\system32\SET1CE.tmp
2008-11-25 01:01:23 ----A---- C:\WINDOWS\system32\SET1CB.tmp
2008-11-25 01:01:23 ----A---- C:\WINDOWS\system32\SET1CA.tmp
2008-11-25 01:01:23 ----A---- C:\WINDOWS\system32\SET1C5.tmp
2008-11-25 01:01:21 ----N---- C:\WINDOWS\system32\spupdwxp.exe
2008-11-25 01:01:21 ----A---- C:\WINDOWS\system32\SET5E4.tmp
2008-11-25 01:01:21 ----A---- C:\WINDOWS\system32\SET1F3.tmp
2008-11-25 01:01:21 ----A---- C:\WINDOWS\system32\SET1F2.tmp
2008-11-25 01:01:21 ----A---- C:\WINDOWS\system32\SET1F1.tmp
2008-11-25 01:01:21 ----A---- C:\WINDOWS\system32\SET1F0.tmp
2008-11-25 01:01:21 ----A---- C:\WINDOWS\system32\SET1EE.tmp
2008-11-25 01:01:21 ----A---- C:\WINDOWS\system32\SET1EB.tmp
2008-11-25 01:01:21 ----A---- C:\WINDOWS\system32\SET1EA.tmp
2008-11-25 01:01:21 ----A---- C:\WINDOWS\system32\SET1E0.tmp
2008-11-25 01:01:21 ----A---- C:\WINDOWS\system32\SET1DD.tmp
2008-11-25 01:01:21 ----A---- C:\WINDOWS\system32\SET1DA.tmp
2008-11-25 01:01:21 ----A---- C:\WINDOWS\system32\SET1D9.tmp
2008-11-25 01:01:21 ----A---- C:\WINDOWS\system32\SET1245.tmp
2008-11-25 01:01:20 ----A---- C:\WINDOWS\system32\spdwnwxp.exe
2008-11-25 01:01:20 ----A---- C:\WINDOWS\system32\SET1F5.tmp
2008-11-25 01:01:20 ----A---- C:\WINDOWS\system32\SET1F4.tmp
2008-11-25 01:01:18 ----N---- C:\WINDOWS\system32\slserv.exe
2008-11-25 01:01:18 ----N---- C:\WINDOWS\system32\slrundll.exe
2008-11-25 01:01:18 ----N---- C:\WINDOWS\system32\slgen.dll
2008-11-25 01:01:18 ----N---- C:\WINDOWS\system32\slextspk.dll
2008-11-25 01:01:18 ----N---- C:\WINDOWS\system32\slcoinst.dll
2008-11-25 01:01:18 ----N---- C:\WINDOWS\slrundll.exe
2008-11-25 01:01:18 ----A---- C:\WINDOWS\system32\SET20E.tmp
2008-11-25 01:01:18 ----A---- C:\WINDOWS\system32\SET20C.tmp
2008-11-25 01:01:18 ----A---- C:\WINDOWS\system32\SET20A.tmp
2008-11-25 01:01:18 ----A---- C:\WINDOWS\system32\SET205.tmp
2008-11-25 01:01:17 ----N---- C:\WINDOWS\system32\setupn.exe
2008-11-25 01:01:17 ----A---- C:\WINDOWS\system32\SET214.tmp
2008-11-25 01:01:17 ----A---- C:\WINDOWS\system32\SET213.tmp
2008-11-25 01:01:17 ----A---- C:\WINDOWS\system32\SET210.tmp
2008-11-25 01:01:17 ----A---- C:\WINDOWS\system32\SET20F.tmp
2008-11-25 01:01:16 ----N---- C:\WINDOWS\system32\s3gnb.dll
2008-11-25 01:01:16 ----A---- C:\WINDOWS\system32\SET237.tmp
2008-11-25 01:01:16 ----A---- C:\WINDOWS\system32\SET236.tmp
2008-11-25 01:01:16 ----A---- C:\WINDOWS\system32\SET235.tmp
2008-11-25 01:01:16 ----A---- C:\WINDOWS\system32\SET234.tmp
2008-11-25 01:01:16 ----A---- C:\WINDOWS\system32\SET22E.tmp
2008-11-25 01:01:16 ----A---- C:\WINDOWS\system32\SET226.tmp
2008-11-25 01:01:16 ----A---- C:\WINDOWS\system32\SET225.tmp
2008-11-25 01:01:16 ----A---- C:\WINDOWS\system32\SET224.tmp
2008-11-25 01:01:16 ----A---- C:\WINDOWS\system32\SET223.tmp
2008-11-25 01:01:16 ----A---- C:\WINDOWS\system32\SET21E.tmp
2008-11-25 01:01:16 ----A---- C:\WINDOWS\system32\SET21D.tmp
2008-11-25 01:01:16 ----A---- C:\WINDOWS\system32\SET21C.tmp
2008-11-25 01:01:16 ----A---- C:\WINDOWS\system32\SET219.tmp
2008-11-25 01:01:16 ----A---- C:\WINDOWS\system32\SET218.tmp
2008-11-25 01:01:15 ----N---- C:\WINDOWS\system32\rhttpaa.dll
2008-11-25 01:01:15 ----N---- C:\WINDOWS\system32\rasqec.dll
2008-11-25 01:01:15 ----N---- C:\WINDOWS\system32\qutil.dll
2008-11-25 01:01:15 ----A---- C:\WINDOWS\system32\SET251.tmp
2008-11-25 01:01:15 ----A---- C:\WINDOWS\system32\SET250.tmp
2008-11-25 01:01:15 ----A---- C:\WINDOWS\system32\SET24F.tmp
2008-11-25 01:01:15 ----A---- C:\WINDOWS\system32\SET24D.tmp
2008-11-25 01:01:15 ----A---- C:\WINDOWS\system32\SET24B.tmp
2008-11-25 01:01:15 ----A---- C:\WINDOWS\system32\SET23F.tmp
2008-11-25 01:01:15 ----A---- C:\WINDOWS\system32\SET23E.tmp
2008-11-25 01:01:15 ----A---- C:\WINDOWS\system32\SET239.tmp
2008-11-25 01:01:14 ----N---- C:\WINDOWS\system32\qcliprov.dll
2008-11-25 01:01:14 ----N---- C:\WINDOWS\system32\qagentrt.dll
2008-11-25 01:01:14 ----N---- C:\WINDOWS\system32\qagent.dll
2008-11-25 01:01:14 ----A---- C:\WINDOWS\system32\SET267.tmp
2008-11-25 01:01:14 ----A---- C:\WINDOWS\system32\SET264.tmp
2008-11-25 01:01:14 ----A---- C:\WINDOWS\system32\SET262.tmp
2008-11-25 01:01:14 ----A---- C:\WINDOWS\system32\SET25F.tmp
2008-11-25 01:01:14 ----A---- C:\WINDOWS\system32\SET25E.tmp
2008-11-25 01:01:14 ----A---- C:\WINDOWS\system32\SET25C.tmp
2008-11-25 01:01:13 ----N---- C:\WINDOWS\system32\onex.dll
2008-11-25 01:01:13 ----A---- C:\WINDOWS\system32\SET291.tmp
2008-11-25 01:01:13 ----A---- C:\WINDOWS\system32\SET290.tmp
2008-11-25 01:01:13 ----A---- C:\WINDOWS\system32\SET28F.tmp
2008-11-25 01:01:13 ----A---- C:\WINDOWS\system32\SET28D.tmp
2008-11-25 01:01:13 ----A---- C:\WINDOWS\system32\SET28C.tmp
2008-11-25 01:01:13 ----A---- C:\WINDOWS\system32\SET28B.tmp
2008-11-25 01:01:13 ----A---- C:\WINDOWS\system32\SET289.tmp
2008-11-25 01:01:13 ----A---- C:\WINDOWS\system32\SET288.tmp
2008-11-25 01:01:13 ----A---- C:\WINDOWS\system32\SET287.tmp
2008-11-25 01:01:13 ----A---- C:\WINDOWS\system32\SET286.tmp
2008-11-25 01:01:13 ----A---- C:\WINDOWS\system32\SET285.tmp
2008-11-25 01:01:13 ----A---- C:\WINDOWS\system32\SET282.tmp
2008-11-25 01:01:13 ----A---- C:\WINDOWS\system32\SET281.tmp
2008-11-25 01:01:13 ----A---- C:\WINDOWS\system32\SET27A.tmp
2008-11-25 01:01:13 ----A---- C:\WINDOWS\system32\SET279.tmp
2008-11-25 01:01:13 ----A---- C:\WINDOWS\system32\SET276.tmp
2008-11-25 01:01:12 ----N---- C:\WINDOWS\system32\nv4_disp.dll
2008-11-25 01:01:12 ----A---- C:\WINDOWS\system32\SET296.tmp
2008-11-25 01:01:12 ----A---- C:\WINDOWS\system32\SET293.tmp
2008-11-25 01:01:11 ----A---- C:\WINDOWS\system32\SET29D.tmp
2008-11-25 01:01:11 ----A---- C:\WINDOWS\system32\SET29C.tmp
2008-11-25 01:01:11 ----A---- C:\WINDOWS\system32\SET29B.tmp
2008-11-25 01:01:10 ----N---- C:\WINDOWS\system32\napstat.exe
2008-11-25 01:01:10 ----N---- C:\WINDOWS\system32\napmontr.dll
2008-11-25 01:01:10 ----N---- C:\WINDOWS\system32\napipsec.dll
2008-11-25 01:01:10 ----N---- C:\WINDOWS\system32\mtxparhd.dll
2008-11-25 01:01:10 ----A---- C:\WINDOWS\system32\SET2B9.tmp
2008-11-25 01:01:10 ----A---- C:\WINDOWS\system32\SET2B7.tmp
2008-11-25 01:01:10 ----A---- C:\WINDOWS\system32\SET2B6.tmp
2008-11-25 01:01:10 ----A---- C:\WINDOWS\system32\SET2B3.tmp
2008-11-25 01:01:10 ----A---- C:\WINDOWS\system32\SET2AF.tmp
2008-11-25 01:01:10 ----A---- C:\WINDOWS\system32\SET2AC.tmp
2008-11-25 01:01:10 ----A---- C:\WINDOWS\system32\SET2AB.tmp
2008-11-25 01:01:10 ----A---- C:\WINDOWS\system32\SET2A9.tmp
2008-11-25 01:01:10 ----A---- C:\WINDOWS\system32\SET2A6.tmp
2008-11-25 01:01:10 ----A---- C:\WINDOWS\system32\SET2A4.tmp
2008-11-25 01:01:10 ----A---- C:\WINDOWS\system32\SET2A3.tmp
2008-11-25 01:01:10 ----A---- C:\WINDOWS\system32\SET2A2.tmp
2008-11-25 01:01:09 ----A---- C:\WINDOWS\system32\SET2C9.tmp
2008-11-25 01:01:09 ----A---- C:\WINDOWS\system32\SET2C8.tmp
2008-11-25 01:01:09 ----A---- C:\WINDOWS\system32\SET2BE.tmp
2008-11-25 01:01:08 ----N---- C:\WINDOWS\system32\msshavmsg.dll
2008-11-25 01:01:08 ----N---- C:\WINDOWS\system32\mssha.dll
2008-11-25 01:01:08 ----A---- C:\WINDOWS\system32\SET2D7.tmp
2008-11-25 01:01:08 ----A---- C:\WINDOWS\system32\SET2D6.tmp
2008-11-25 01:01:08 ----A---- C:\WINDOWS\system32\SET2D4.tmp
2008-11-25 01:01:08 ----A---- C:\WINDOWS\system32\SET2D3.tmp
2008-11-25 01:01:08 ----A---- C:\WINDOWS\system32\SET2CD.tmp
2008-11-25 01:01:08 ----A---- C:\WINDOWS\system32\SET2CC.tmp
2008-11-25 01:01:06 ----A---- C:\WINDOWS\system32\SET2E6.tmp
2008-11-25 01:01:06 ----A---- C:\WINDOWS\system32\SET2E4.tmp
2008-11-25 01:01:06 ----A---- C:\WINDOWS\system32\SET2E2.tmp
2008-11-25 01:01:06 ----A---- C:\WINDOWS\system32\SET2E1.tmp
2008-11-25 01:01:06 ----A---- C:\WINDOWS\system32\SET2E0.tmp
2008-11-25 01:01:06 ----A---- C:\WINDOWS\system32\SET2DF.tmp
2008-11-25 01:01:06 ----A---- C:\WINDOWS\system32\SET2DD.tmp
2008-11-25 01:01:06 ----A---- C:\WINDOWS\system32\SET2DB.tmp
2008-11-25 01:01:05 ----A---- C:\WINDOWS\system32\SET2F7.tmp
2008-11-25 01:01:05 ----A---- C:\WINDOWS\system32\SET2F6.tmp
2008-11-25 01:01:05 ----A---- C:\WINDOWS\system32\SET2F5.tmp
2008-11-25 01:01:05 ----A---- C:\WINDOWS\system32\SET2F3.tmp
2008-11-25 01:01:05 ----A---- C:\WINDOWS\system32\SET2E9.tmp
2008-11-25 01:01:05 ----A---- C:\WINDOWS\system32\SET126D.tmp
2008-11-25 01:01:03 ----A---- C:\WINDOWS\system32\SET5F5.tmp
2008-11-25 01:01:03 ----A---- C:\WINDOWS\system32\SET300.tmp
2008-11-25 01:01:03 ----A---- C:\WINDOWS\system32\SET2FB.tmp
2008-11-25 01:01:02 ----A---- C:\WINDOWS\system32\SET5FB.tmp
2008-11-25 01:01:02 ----A---- C:\WINDOWS\system32\SET309.tmp
2008-11-25 01:01:02 ----A---- C:\WINDOWS\system32\SET303.tmp
2008-11-25 01:01:02 ----A---- C:\WINDOWS\system32\SET302.tmp
2008-11-25 01:01:01 ----N---- C:\WINDOWS\system32\mmcperf.exe
2008-11-25 01:01:01 ----N---- C:\WINDOWS\system32\mmcfxcommon.dll
2008-11-25 01:01:01 ----N---- C:\WINDOWS\system32\mmcex.dll
2008-11-25 01:01:01 ----N---- C:\WINDOWS\system32\microsoft.managementconsole.dll
2008-11-25 01:01:01 ----A---- C:\WINDOWS\system32\SET318.tmp
2008-11-25 01:01:01 ----A---- C:\WINDOWS\system32\SET314.tmp
2008-11-25 01:01:00 ----A---- C:\WINDOWS\system32\SET31C.tmp
2008-11-25 01:00:59 ----A---- C:\WINDOWS\system32\SET32D.tmp
2008-11-25 01:00:59 ----A---- C:\WINDOWS\system32\SET32B.tmp
2008-11-25 01:00:59 ----A---- C:\WINDOWS\system32\SET326.tmp
2008-11-25 01:00:59 ----A---- C:\WINDOWS\system32\SET324.tmp
2008-11-25 01:00:54 ----N---- C:\WINDOWS\system32\l2gpstore.dll
2008-11-25 01:00:54 ----N---- C:\WINDOWS\system32\kmsvc.dll
2008-11-25 01:00:54 ----N---- C:\WINDOWS\system32\kbdpash.dll
2008-11-25 01:00:54 ----N---- C:\WINDOWS\system32\kbdnepr.dll
2008-11-25 01:00:54 ----N---- C:\WINDOWS\system32\kbdiultn.dll
2008-11-25 01:00:54 ----N---- C:\WINDOWS\system32\kbdbhc.dll
2008-11-25 01:00:54 ----A---- C:\WINDOWS\system32\SET34D.tmp
2008-11-25 01:00:54 ----A---- C:\WINDOWS\system32\SET347.tmp
2008-11-25 01:00:54 ----A---- C:\WINDOWS\system32\SET338.tmp
2008-11-25 01:00:54 ----A---- C:\WINDOWS\system32\SET336.tmp
2008-11-25 01:00:53 ----A---- C:\WINDOWS\system32\SET355.tmp
2008-11-25 01:00:53 ----A---- C:\WINDOWS\system32\SET353.tmp
2008-11-25 01:00:53 ----A---- C:\WINDOWS\system32\SET351.tmp
2008-11-25 01:00:50 ----A---- C:\WINDOWS\system32\SET12EE.tmp
2008-11-25 01:00:48 ----N---- C:\WINDOWS\system32\comsdupd.exe
2008-11-25 01:00:48 ----A---- C:\WINDOWS\system32\SET35B.tmp
2008-11-25 01:00:47 ----A---- C:\WINDOWS\system32\SET608.tmp
2008-11-25 01:00:47 ----A---- C:\WINDOWS\system32\SET607.tmp
2008-11-25 01:00:47 ----A---- C:\WINDOWS\system32\SET36D.tmp
2008-11-25 01:00:47 ----A---- C:\WINDOWS\system32\SET36A.tmp
2008-11-25 01:00:47 ----A---- C:\WINDOWS\system32\SET35F.tmp
2008-11-25 01:00:47 ----A---- C:\WINDOWS\system32\SET1291.tmp
2008-11-25 01:00:46 ----N---- C:\WINDOWS\system32\hsfcisp2.dll
2008-11-25 01:00:46 ----A---- C:\WINDOWS\system32\SET37D.tmp
2008-11-25 01:00:46 ----A---- C:\WINDOWS\system32\SET379.tmp
2008-11-25 01:00:46 ----A---- C:\WINDOWS\system32\SET377.tmp
2008-11-25 01:00:46 ----A---- C:\WINDOWS\system32\SET376.tmp
2008-11-25 01:00:46 ----A---- C:\WINDOWS\system32\SET375.tmp
2008-11-25 01:00:46 ----A---- C:\WINDOWS\system32\SET373.tmp
2008-11-25 01:00:45 ----A---- C:\WINDOWS\system32\SET381.tmp
2008-11-25 01:00:44 ----N---- C:\WINDOWS\system32\faxpatch.exe
2008-11-25 01:00:44 ----A---- C:\WINDOWS\system32\SET614.tmp
2008-11-25 01:00:44 ----A---- C:\WINDOWS\system32\SET391.tmp
2008-11-25 01:00:44 ----A---- C:\WINDOWS\system32\SET38F.tmp
2008-11-25 01:00:44 ----A---- C:\WINDOWS\system32\SET1298.tmp
2008-11-25 01:00:44 ----A---- C:\WINDOWS\SET472.tmp
2008-11-25 01:00:44 ----A---- C:\WINDOWS\003277_.tmp
2008-11-25 01:00:43 ----N---- C:\WINDOWS\system32\eapsvc.dll
2008-11-25 01:00:43 ----N---- C:\WINDOWS\system32\eapqec.dll
2008-11-25 01:00:43 ----N---- C:\WINDOWS\system32\eappprxy.dll
2008-11-25 01:00:43 ----N---- C:\WINDOWS\system32\eapphost.dll
2008-11-25 01:00:43 ----N---- C:\WINDOWS\system32\eappgnui.dll
2008-11-25 01:00:43 ----N---- C:\WINDOWS\system32\eappcfg.dll
2008-11-25 01:00:43 ----N---- C:\WINDOWS\system32\eapp3hst.dll
2008-11-25 01:00:43 ----N---- C:\WINDOWS\system32\eapolqec.dll
2008-11-25 01:00:43 ----A---- C:\WINDOWS\system32\SET39F.tmp
2008-11-25 01:00:43 ----A---- C:\WINDOWS\system32\SET39B.tmp
2008-11-25 01:00:43 ----A---- C:\WINDOWS\system32\SET393.tmp
2008-11-25 01:00:42 ----N---- C:\WINDOWS\system32\dot3ui.dll
2008-11-25 01:00:42 ----N---- C:\WINDOWS\system32\dot3svc.dll
2008-11-25 01:00:42 ----N---- C:\WINDOWS\system32\dot3msm.dll
2008-11-25 01:00:42 ----N---- C:\WINDOWS\system32\dot3gpclnt.dll
2008-11-25 01:00:42 ----N---- C:\WINDOWS\system32\dot3dlg.dll
2008-11-25 01:00:42 ----N---- C:\WINDOWS\system32\dot3cfg.dll
2008-11-25 01:00:42 ----N---- C:\WINDOWS\system32\dot3api.dll
2008-11-25 01:00:42 ----A---- C:\WINDOWS\system32\SET3C3.tmp
2008-11-25 01:00:42 ----A---- C:\WINDOWS\system32\SET3BD.tmp
2008-11-25 01:00:42 ----A---- C:\WINDOWS\system32\SET3AB.tmp
2008-11-25 01:00:41 ----N---- C:\WINDOWS\system32\dimsroam.dll
2008-11-25 01:00:41 ----N---- C:\WINDOWS\system32\dimsntfy.dll
2008-11-25 01:00:41 ----N---- C:\WINDOWS\system32\dhcpqec.dll
2008-11-25 01:00:40 ----A---- C:\WINDOWS\system32\SET3EA.tmp
2008-11-25 01:00:39 ----N---- C:\WINDOWS\system32\credssp.dll
2008-11-25 01:00:39 ----A---- C:\WINDOWS\system32\SET3FF.tmp
2008-11-25 01:00:39 ----A---- C:\WINDOWS\system32\SET3FD.tmp
2008-11-25 01:00:39 ----A---- C:\WINDOWS\system32\SET3FC.tmp
2008-11-25 01:00:39 ----A---- C:\WINDOWS\system32\SET3FA.tmp
2008-11-25 01:00:39 ----A---- C:\WINDOWS\system32\SET3F8.tmp
2008-11-25 01:00:39 ----A---- C:\WINDOWS\system32\SET3F7.tmp
2008-11-25 01:00:39 ----A---- C:\WINDOWS\system32\SET3F6.tmp
2008-11-25 01:00:39 ----A---- C:\WINDOWS\system32\SET3F5.tmp
2008-11-25 01:00:39 ----A---- C:\WINDOWS\system32\SET3F3.tmp
2008-11-25 01:00:39 ----A---- C:\WINDOWS\system32\SET3F2.tmp
2008-11-25 01:00:39 ----A---- C:\WINDOWS\system32\SET3F1.tmp
2008-11-25 01:00:38 ----A---- C:\WINDOWS\system32\SET412.tmp
2008-11-25 01:00:38 ----A---- C:\WINDOWS\system32\SET40A.tmp
2008-11-25 01:00:38 ----A---- C:\WINDOWS\system32\SET409.tmp
2008-11-25 01:00:38 ----A---- C:\WINDOWS\system32\SET404.tmp
2008-11-25 01:00:38 ----A---- C:\WINDOWS\system32\SET402.tmp
2008-11-25 01:00:37 ----A---- C:\WINDOWS\system32\SET419.tmp
2008-11-25 01:00:36 ----A---- C:\WINDOWS\system32\SET421.tmp
2008-11-25 01:00:36 ----A---- C:\WINDOWS\system32\SET41E.tmp
2008-11-25 01:00:35 ----A---- C:\WINDOWS\system32\SET42A.tmp
2008-11-25 01:00:35 ----A---- C:\WINDOWS\system32\SET426.tmp
2008-11-25 01:00:35 ----A---- C:\WINDOWS\system32\SET424.tmp
2008-11-25 01:00:35 ----A---- C:\WINDOWS\system32\SET12B5.tmp
2008-11-25 01:00:34 ----N---- C:\WINDOWS\system32\bitsprx4.dll
2008-11-25 01:00:34 ----N---- C:\WINDOWS\system32\azroles.dll
2008-11-25 01:00:34 ----N---- C:\WINDOWS\system32\ativvaxx.dll
2008-11-25 01:00:34 ----N---- C:\WINDOWS\system32\ativtmxx.dll
2008-11-25 01:00:34 ----N---- C:\WINDOWS\system32\ati3duag.dll
2008-11-25 01:00:34 ----N---- C:\WINDOWS\system32\ati3d1ag.dll
2008-11-25 01:00:34 ----A---- C:\WINDOWS\system32\SET43D.tmp
2008-11-25 01:00:34 ----A---- C:\WINDOWS\system32\SET43B.tmp
2008-11-25 01:00:34 ----A---- C:\WINDOWS\system32\SET438.tmp
2008-11-25 01:00:34 ----A---- C:\WINDOWS\system32\SET437.tmp
2008-11-25 01:00:34 ----A---- C:\WINDOWS\system32\SET433.tmp
2008-11-25 01:00:34 ----A---- C:\WINDOWS\system32\SET432.tmp
2008-11-25 01:00:34 ----A---- C:\WINDOWS\system32\SET42F.tmp
2008-11-25 01:00:34 ----A---- C:\WINDOWS\system32\SET42E.tmp
2008-11-25 01:00:34 ----A---- C:\WINDOWS\system32\SET42D.tmp
2008-11-25 01:00:33 ----N---- C:\WINDOWS\system32\ati2dvag.dll
2008-11-25 01:00:33 ----N---- C:\WINDOWS\system32\ati2dvaa.dll
2008-11-25 01:00:33 ----N---- C:\WINDOWS\system32\ati2cqag.dll
2008-11-25 01:00:32 ----N---- C:\WINDOWS\system32\aaclient.dll
2008-11-25 01:00:32 ----A---- C:\WINDOWS\system32\SET620.tmp
2008-11-25 01:00:32 ----A---- C:\WINDOWS\system32\SET44D.tmp
2008-11-25 01:00:32 ----A---- C:\WINDOWS\system32\SET44B.tmp
2008-11-25 01:00:32 ----A---- C:\WINDOWS\system32\SET449.tmp
2008-11-25 01:00:32 ----A---- C:\WINDOWS\system32\SET445.tmp
2008-11-25 01:00:32 ----A---- C:\WINDOWS\system32\SET442.tmp
2008-11-25 01:00:15 ----HDC---- C:\WINDOWS\$NtUninstallKB956841_0$
2008-11-25 00:59:53 ----D---- C:\Program Files\MSXML 6.0
2008-11-25 00:59:44 ----HDC---- C:\WINDOWS\$NtUninstallKB953155_0$
2008-11-25 00:59:36 ----HDC---- C:\WINDOWS\$NtUninstallKB957097_0$
2008-11-25 00:59:26 ----HDC---- C:\WINDOWS\$NtUninstallKB951072-v2$
2008-11-25 00:59:15 ----HDC---- C:\WINDOWS\$NtUninstallKB952287_0$
2008-11-25 00:59:06 ----HDC---- C:\WINDOWS\$NtUninstallKB951066_0$
2008-11-25 00:59:00 ----HDC---- C:\WINDOWS\$NtUninstallKB938464_0$
2008-11-25 00:58:51 ----HDC---- C:\WINDOWS\$NtUninstallKB958644_0$
2008-11-25 00:58:23 ----HDC---- C:\WINDOWS\$NtUninstallKB955069_0$
2008-11-25 00:56:12 ----HDC---- C:\WINDOWS\$NtUninstallKB954154_WM11$
2008-11-21 18:07:53 ----D---- C:\WINDOWS\system32\NtmsData
2008-11-19 08:56:14 ----D---- C:\Documents and Settings\User\Application Data\ArcSoft
2008-11-19 08:51:15 ----D---- C:\Documents and Settings\User\Application Data\Canon
2008-11-16 00:33:00 ----N---- C:\WINDOWS\system32\SET1532.tmp
2008-11-16 00:32:26 ----A---- C:\WINDOWS\system32\SET1510.tmp
2008-11-15 19:32:12 ----D---- C:\WINDOWS\Minidump
2008-11-14 17:52:29 ----A---- C:\WINDOWS\system32\irmon.dll
2008-11-14 17:52:28 ----A---- C:\WINDOWS\system32\irftp.exe
2008-11-14 17:52:27 ----A---- C:\WINDOWS\system32\wshirda.dll
2008-11-14 13:09:44 ----A---- C:\WINDOWS\chess.ini
2008-11-12 17:22:00 ----A---- C:\WINDOWS\CSTBox.INI
2008-11-12 17:05:16 ----D---- C:\Program Files\Canon
2008-11-12 17:04:13 ----A---- C:\WINDOWS\MAXLINK.INI
2008-11-12 17:04:10 ----D---- C:\Documents and Settings\All Users\Application Data\InstallShield
2008-11-12 17:03:50 ----D---- C:\Program Files\Common Files\ScanSoft Shared
2008-11-12 17:03:50 ----D---- C:\Documents and Settings\All Users\Application Data\ScanSoft
2008-11-12 17:03:19 ----D---- C:\Program Files\ScanSoft
2008-11-12 17:01:20 ----A---- C:\WINDOWS\PCDLIB32.DLL
2008-11-12 17:01:19 ----D---- C:\Program Files\ArcSoft
2008-11-12 16:59:24 ----A---- C:\WINDOWS\system32\CNQU110.DLL
2008-11-12 16:59:23 ----HD---- C:\CanoScan
2008-11-12 16:59:23 ----A---- C:\WINDOWS\system32\CNQL1213.DLL
2008-11-06 20:01:33 ----D---- C:\Program Files\Microsoft Virtual PC
2008-11-05 22:43:57 ----N---- C:\WINDOWS\system32\spmsg.dll
2008-10-31 23:05:20 ----D---- C:\Program Files\Reference Assemblies
2008-10-31 23:02:40 ----D---- C:\WINDOWS\assembly
2008-10-31 23:02:01 ----D---- C:\WINDOWS\Microsoft.NET
2008-10-31 22:54:15 ----RHD---- C:\AHCache
2008-10-31 00:42:40 ----D---- C:\Documents and Settings\User\Application Data\Winamp
2008-10-31 00:38:09 ----D---- C:\Program Files\Uniblue
2008-10-31 00:38:09 ----D---- C:\Documents and Settings\All Users\Application Data\DriverScanner
2008-10-31 00:21:57 ----D---- C:\Documents and Settings\User\Application Data\Uniblue
2008-10-30 20:56:17 ----A---- C:\WINDOWS\system32\wmpns.dll

======List of files/folders modified in the last 1 months======

2008-11-25 02:44:31 ----RD---- C:\Program Files
2008-11-25 02:25:49 ----D---- C:\Program Files\Mozilla Firefox
2008-11-25 02:08:35 ----D---- C:\WINDOWS\system32
2008-11-25 02:08:33 ----D---- C:\WINDOWS
2008-11-25 02:07:34 ----A---- C:\WINDOWS\system.ini
2008-11-25 02:06:14 ----D---- C:\WINDOWS\system32\drivers
2008-11-25 02:06:14 ----D---- C:\WINDOWS\AppPatch
2008-11-25 02:06:14 ----D---- C:\Program Files\Common Files
2008-11-25 02:05:26 ----A---- C:\WINDOWS\OEWABLog.txt
2008-11-25 02:03:08 ----RASH---- C:\boot.ini
2008-11-25 02:02:43 ----D---- C:\WINDOWS\system32\inetsrv
2008-11-25 01:59:49 ----D---- C:\WINDOWS\system32\CatRoot
2008-11-25 01:58:14 ----HD---- C:\WINDOWS\inf
2008-11-25 01:58:14 ----D---- C:\WINDOWS\system32\CatRoot2
2008-11-25 01:58:12 ----RSHDC---- C:\WINDOWS\system32\dllcache
2008-11-25 01:56:16 ----D---- C:\WINDOWS\security
2008-11-25 01:52:17 ----D---- C:\Program Files\Messenger
2008-11-25 01:47:01 ----A---- C:\WINDOWS\setuplog.txt
2008-11-25 01:46:39 ----D---- C:\WINDOWS\WinSxS
2008-11-25 01:46:33 ----D---- C:\WINDOWS\system32\wbem
2008-11-25 01:46:33 ----D---- C:\WINDOWS\system32\Setup
2008-11-25 01:46:32 ----D---- C:\WINDOWS\ime
2008-11-25 01:46:32 ----D---- C:\WINDOWS\Help
2008-11-25 01:46:23 ----D---- C:\WINDOWS\system32\en-US
2008-11-25 01:46:22 ----SHD---- C:\WINDOWS\Installer
2008-11-25 01:46:22 ----D---- C:\WINDOWS\system32\usmt
2008-11-25 01:46:21 ----D---- C:\WINDOWS\PeerNet
2008-11-25 01:46:21 ----D---- C:\Program Files\Movie Maker
2008-11-25 01:43:49 ----A---- C:\WINDOWS\SchedLgU.Txt
2008-11-25 01:41:01 ----D---- C:\WINDOWS\system32\Restore
2008-11-25 01:40:59 ----D---- C:\WINDOWS\system32\npp
2008-11-25 01:40:57 ----D---- C:\WINDOWS\mui
2008-11-25 01:40:52 ----D---- C:\WINDOWS\msagent
2008-11-25 01:40:45 ----D---- C:\WINDOWS\srchasst
2008-11-25 01:40:38 ----D---- C:\Program Files\NetMeeting
2008-11-25 01:40:31 ----D---- C:\WINDOWS\system32\Com
2008-11-25 01:40:20 ----D---- C:\Program Files\Windows Media Player
2008-11-25 01:40:17 ----D---- C:\Program Files\Windows NT
2008-11-25 01:40:16 ----D---- C:\Program Files\Outlook Express
2008-11-25 01:40:04 ----D---- C:\Program Files\Common Files\System
2008-11-25 01:39:24 ----RSD---- C:\WINDOWS\Fonts
2008-11-25 01:39:19 ----D---- C:\WINDOWS\system32\oobe
2008-11-25 01:39:14 ----D---- C:\WINDOWS\system
2008-11-25 01:33:06 ----D---- C:\WINDOWS\system32\ReinstallBackups
2008-11-25 01:29:55 ----D---- C:\WINDOWS\ehome
2008-11-25 01:03:15 ----HD---- C:\WINDOWS\$hf_mig$
2008-11-25 01:02:46 ----D---- C:\Program Files\Internet Explorer
2008-11-24 22:47:47 ----D---- C:\Program Files\Google
2008-11-24 22:44:30 ----A---- C:\WINDOWS\win.ini
2008-11-24 22:41:05 ----RHD---- C:\Documents and Settings\User\Application Data\yahoo!
2008-11-15 19:37:54 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2008-11-12 17:19:01 ----D---- C:\WINDOWS\Media
2008-11-12 17:10:40 ----HD---- C:\Program Files\InstallShield Installation Information
2008-11-12 17:03:49 ----SD---- C:\WINDOWS\Downloaded Program Files
2008-11-12 17:03:49 ----D---- C:\Program Files\Common Files\InstallShield
2008-11-08 09:14:49 ----D---- C:\Documents and Settings
2008-11-07 17:39:43 ----SD---- C:\Documents and Settings\User\Application Data\Microsoft
2008-11-03 16:10:26 ----A---- C:\WINDOWS\system32\MRT.exe
2008-10-31 20:53:01 ----D---- C:\Documents and Settings\User\Application Data\U3
2008-10-31 13:06:00 ----D---- C:\WINDOWS\system32\config
2008-10-31 01:45:21 ----D---- C:\Program Files\VideoLAN

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2008-11-25 75072]
R1 eabfiltr;eabfiltr; C:\WINDOWS\system32\DRIVERS\eabfiltr.sys [2006-06-28 8192]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
R1 vmm;Virtual Machine Monitor; \??\C:\WINDOWS\system32\Drivers\vmm.sys []
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-13 8832]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2006-06-18 12672]
R2 NwlnkIpx;NWLink IPX/SPX/NetBIOS Compatible Transport Protocol; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2008-04-13 88320]
R2 NwlnkNb;NWLink NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2004-08-04 63232]
R2 NwlnkSpx;NWLink SPX/SPXII Protocol; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2004-08-04 55936]
R3 AR5211;Atheros Wireless Network Adapter Service; C:\WINDOWS\system32\DRIVERS\ar5211.sys [2007-05-02 546976]
R3 avgntflt;avgntflt; \??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgntflt.sys []
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2008-04-13 13952]
R3 HBtnKey;HBtnKey; C:\WINDOWS\system32\DRIVERS\cpqbttn.sys [2006-06-28 9472]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HSF_DPV;HSF_DPV; C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys [2006-12-20 988800]
R3 HSFHWAZL;HSFHWAZL; C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys [2006-12-20 209664]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2007-08-24 5776928]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 usbvideo;USB Video Device (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-13 121984]
R3 VPCNetS2;Virtual Machine Network Services Driver; C:\WINDOWS\system32\DRIVERS\VMNetSrv.sys [2008-02-05 59960]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2006-12-20 730112]
S1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2007-03-01 28352]
S3 BthEnum;Bluetooth Enumerator Service; C:\WINDOWS\system32\DRIVERS\BthEnum.sys [2008-04-13 17024]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\WINDOWS\system32\DRIVERS\bthpan.sys [2008-04-13 101120]
S3 BTHPORT;Bluetooth Port Driver; C:\WINDOWS\System32\Drivers\BTHport.sys [2008-06-13 272128]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2008-04-13 18944]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 gdrv;gdrv; \??\C:\WINDOWS\gdrv.sys []
S3 HdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\CHDAud.sys [2007-10-04 651776]
S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-05-31 4424192]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 Nokia USB Generic;Nokia USB Generic; C:\WINDOWS\system32\drivers\nmwcdc.sys [2006-05-29 8704]
S3 Nokia USB Modem;Nokia USB Modem; C:\WINDOWS\system32\drivers\nmwcdcm.sys [2006-05-29 13312]
S3 Nokia USB Phone Parent;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\nmwcd.sys [2006-05-29 127488]
S3 Nokia USB Port;Nokia USB Port; C:\WINDOWS\system32\drivers\nmwcdcj.sys [2006-05-29 13312]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\system32\DRIVERS\rfcomm.sys [2008-04-13 59136]
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-04 20992]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 SymIM;Symantec Network Security Intermediate Filter Service; C:\WINDOWS\system32\DRIVERS\SymIM.sys []
S3 SymIMMP;SymIMMP; C:\WINDOWS\system32\DRIVERS\SymIM.sys []
S3 UIUSys;Conexant Setup API; C:\WINDOWS\system32\DRIVERS\UIUSYS.SYS []
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirScheduler;Avira AntiVir Personal - Free Antivirus Scheduler; C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe [2008-10-15 68865]
R2 AntiVirService;Avira AntiVir Personal - Free Antivirus Guard; C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe [2008-10-15 151297]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2007-07-24 229376]
R2 BthServ;Bluetooth Support Service; C:\WINDOWS\system32\svchost.exe [2004-08-04 14336]
R2 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2006-05-02 135168]
R2 IISADMIN;IIS Admin; C:\WINDOWS\system32\inetsrv\inetinfo.exe [2006-02-28 15872]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 SMTPSVC;Simple Mail Transfer Protocol (SMTP); C:\WINDOWS\system32\inetsrv\inetinfo.exe [2006-02-28 15872]
R2 W3SVC;World Wide Web Publishing; C:\WINDOWS\system32\inetsrv\inetinfo.exe [2006-02-28 15872]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-04 14336]
R3 ServiceLayer;ServiceLayer; C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe [2006-06-05 174080]
S2 spupdsvc;Windows Service Pack Installer update service; C:\WINDOWS\system32\spupdsvc.exe [2007-08-10 26488]
S3 AddFiltr;AddFiltr; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe [2006-06-26 126976]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-30 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 usnjsvc;Messenger Sharing Folders USN Journal Reader service; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]

-----------------EOF-----------------


info.txt logfile of random's system information tool 1.04 2008-11-25 02:45:10

======Uninstall list======

-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Acrobat.com-->C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe -uninstall com.adobe.mauby 4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
Acrobat.com-->MsiExec.exe /I{77DCDCE3-2DED-62F3-8154-05E745472D07}
Adobe AIR-->C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR-->MsiExec.exe /I{00203668-8170-44A0-BE44-B632FA4D780F}
Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 9-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A90000000001}
Apple Software Update-->MsiExec.exe /I{02DFF6B1-1654-411C-8D7B-FD6052EF016F}
ArcSoft PhotoStudio 5.5-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{85309D89-7BE9-4094-BB17-24999C6118FC}\Setup.exe" -l0x9
Atheros for Acer Driver 5.3.0.45_Foxconn Installation Program-->C:\Program Files\InstallShield Installation Information\{F70D5D8C-C1AF-40B3-9E47-3BB5F19EEA3A}\setup.exe -runfromtemp -l0x0009 -removeonly
Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE
Bonjour-->MsiExec.exe /I{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}
CA Yahoo! Anti-Spy (remove only)-->"C:\Program Files\CA Yahoo! Anti-Spy\uninstall.exe"
Canon CanoScan Toolbox 4.9-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CA9BCD4D-B782-4637-8F1F-F9A328D3C244}\setup.exe" -l0x9 anything
Canon ScanGear Starter-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{18A5DFF2-8A95-49F3-873F-743CB5549F3D}\SETUP.EXE" -l0x9 anything
Conexant HD Audio-->C:\Program Files\CONEXANT\CNXT_AUDIO_HDA\UIU32a.exe -U -ILEOHER5a.INF
Conexant HD Audio-->C:\Program Files\CONEXANT\CNXT_HDAUDIO\HXFSETUP.EXE -U -IAt8VEN5a.inf
FoxyTunes for Firefox-->"C:\Program Files\Mozilla Firefox\firefox.exe" -chrome chrome://foxytunes/content/extras/uninstallExtension.xul
HDAUDIO Soft Data Fax Modem with SmartCP-->C:\Program Files\CONEXANT\CNXT_MODEM_HDAUDIO_SprtHD5m\UIU32m.exe -U -ISprtHD5m.inf
HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Hotfix for Windows Media Player 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
HP Quick Launch Buttons 6.10 B9-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{34D2AB40-150D-475D-AE32-BD23FB5EE355}\Setup.exe" -l0x9 -removeonly uninst
HP Update-->MsiExec.exe /X{AB40272D-92AB-4F30-B36B-22EDE16F8FE5}
Intel Performance Power Manager-->MsiExec.exe /I{E65E367B-B25C-4FF8-B270-D5277E7CF1B0}
Intel® Graphics Media Accelerator Driver-->C:\WINDOWS\system32\igxpun.exe -uninstall
Java™ 6 Update 4-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160040}
Java™ 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
Manual CanoScan LiDE 25-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C45EB9E5-7165-4FB0-8C31-77FC4743362F}\setup.exe" -l0x9
Microsoft .NET Framework 2.0 Client Service Pack 2-->MsiExec.exe /I{CAAFB8F9-F8D1-3D27-9AAA-6301A4429440}
Microsoft .NET Framework 3.0 Client Service Pack 2-->MsiExec.exe /I{1185566F-12ED-3EF0-89CC-38866DCE1EEE}
Microsoft .NET Framework 3.5 Client Service Pack 1-->MsiExec.exe /I{D617A4DC-C915-3F25-BE43-57E5FD99B441}
Microsoft .NET Framework Client Profile - PREVIEW-->C:\AHCache\All Users\Microsoft.Net.Client.3.5\setup.exe /remove "Microsoft.Net.Client.3.5"
Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office FrontPage 2003-->MsiExec.exe /I{90170409-6000-11D3-8CFE-0150048383C9}
Microsoft Office Professional Edition 2003-->MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
Microsoft Silverlight-->MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Virtual PC 2007 SP1-->MsiExec.exe /X{AD483998-2E9A-4405-83FF-6E503AF49CBB}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Mozilla Firefox (3.0.4)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSN-->C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 6 Service Pack 2 (KB954459)-->MsiExec.exe /I{1A528690-6A2D-4BC5-B143-8C4AE8D19D96}
MXit PC 1.3.0.5 BETA-->MsiExec.exe /X{E70EE2F5-4273-443D-ACAE-9C67EBC1CFEA}
Nokia Connectivity Cable Driver-->MsiExec.exe /X{6882DD11-33B8-4DEA-8305-7E765BF74BD3}
Nokia MTP driver-->MsiExec.exe /I{59359B3D-ABE7-46BF-AB55-43B67A64DC68}
Nokia N73 highlights-->MsiExec.exe /I{02B71D92-A84B-4DFB-9A10-D12BB01AC1F2}
Nokia Nseries Skin for Microsoft Windows Media Player-->MsiExec.exe /I{73E30715-9EC4-4DAE-BE67-64500AEB8012}
Nokia PC Connectivity Solution-->MsiExec.exe /I{0D80391C-0A72-43BB-9BC2-143F63CC111D}
Nokia PC Suite-->MsiExec.exe /I{531317A5-586A-4E36-87C1-CA823447B375}
Nokia themes for your device-->MsiExec.exe /I{77F5816C-64A6-4FBE-BBE5-52EFE5EB84E8}
Norton 360-->MsiExec.exe /I{63A6E9A9-A190-46D4-9430-2DB28654AFD8}
RealPlayer-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x9 -removeonly
ScanSoft OmniPage SE 4.0-->MsiExec.exe /I{C1E693A4-B1D5-4DCD-B68D-2087835B7184}
Security Update for Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Security Update for Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953155)-->"C:\WINDOWS\$NtUninstallKB953155$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Security Update for Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Skype™ 3.8-->MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
Update for Windows XP (KB942763)-->"C:\WINDOWS\$NtUninstallKB942763$\spuninst\spuninst.exe"
Update for Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
VLC media player 0.9.2-->C:\Program Files\VideoLAN\VLC\uninstall.exe
Windows Driver Package - Nokia Modem (06/12/2006 6.81.0.21)-->C:\PROGRA~1\DIFX\D6ACC4BE676423A2B130B78A4B627FC457D98997\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\nokbtmdm_62A340731F8930057B44B8864F236850B0D49D65\nokbtmdm.inf
Windows Imaging Component-->"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
Windows Live Messenger-->MsiExec.exe /X{508CE775-4BA4-4748-82DF-FE28DA9F03B0}
Windows Live Sign-in Assistant-->MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}
Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe
Yahoo! Messenger-->C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE /U C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG

======Security center information======

AV: Avira AntiVir PersonalEdition

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 13, GenuineIntel
"PROCESSOR_REVISION"=0f0d
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP

-----------------EOF-----------------


Just finished my Kaspersky Online scan and it says no malware has been detected

I also ran combo fix n if requested i'll gladly post the report. thank u 4 ur tym.

Edited by usm, 24 November 2008 - 08:56 PM.


BC AdBot (Login to Remove)

 


#2 Orange Blossom

Orange Blossom

    OBleepin Investigator


  • Moderator
  • 36,947 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Bloomington, IN
  • Local time:08:40 PM

Posted 13 December 2008 - 09:57 PM

Hello and welcome to Bleeping Computer

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help.

If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. If you have not done so, include a description of your problem, along with any steps you may have performed so far.

Upon completing the steps below a staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.


Thanks and again sorry for the delay.

We need to see some information about what is happening in your machine. Please perform the following scan:
  • Download DDS by sUBs from one of the following links. Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explaination about the tool. No input is needed, the scan is running.
  • Notepad will open with the results, click no to the Optional_Scan
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet. Information on A/V control HERE

Orange Blossom :thumbsup:
Help us help you. If HelpBot replies, you MUST follow step 1 in its reply so we know you need help.

Orange Blossom

An ounce of prevention is worth a pound of cure

SpywareBlaster, WinPatrol Plus, ESET Smart Security, Malwarebytes' Anti-Malware, NoScript Firefox ext., Norton noscript

#3 usm

usm
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:02:40 AM

Posted 15 December 2008 - 09:19 PM

no prob bout the late reply, lyf is hectic in general 4 all of us, jus got back 4rm a trip myself n hav bein busy throughout the 2 weeks, anyway below is the log file as requested, again thanks in advance orange blossom


DDS (Version 1.0.1) - NTFSx86
Run by User at 4:10:39.59 on Tue 12/16/2008
Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_07
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.2038.1286 [GMT 2:00]

============== Running Processes ===============

svchost.exe
svchost.exe
svchost.exe
svchost.exe
svchost.exe
svchost.exe
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Documents and Settings\User\Desktop\dds.com

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
uURLSearchHooks: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: {02478D38-C3F9-4EFB-9B51-7695ECA05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
BHO: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [avgnt] "c:\program files\avira\antivir personaledition classic\avgnt.exe" /min
mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
mRun: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\user\applic~1\mozilla\firefox\profiles\ldp6r4ox.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=

============= SERVICES / DRIVERS ===============

R1 avgio;avgio;\??\c:\program files\avira\antivir personaledition classic\avgio.sys [2008-11-25 11840]
R2 AntiVirScheduler;Avira AntiVir Personal - Free Antivirus Scheduler;"c:\program files\avira\antivir personaledition classic\sched.exe" [2008-11-25 68865]
R2 AntiVirService;Avira AntiVir Personal - Free Antivirus Guard;"c:\program files\avira\antivir personaledition classic\avguard.exe" [2008-11-25 151297]
R3 avgntflt;avgntflt;\??\c:\program files\avira\antivir personaledition classic\avgntflt.sys [2008-11-25 52032]

=============== Created Last 30 ================

2008-11-29 12:48 <DIR> --d----- C:\PerfLogs
2008-11-25 04:18 <DIR> --dsh--- c:\docume~1\user\applic~1\.#
2008-11-25 03:13 <DIR> --d----- c:\program files\CCleaner
2008-11-25 02:44 <DIR> --d----- c:\program files\trend micro
2008-11-25 02:03 <DIR> a-dshr-- C:\cmdcons
2008-11-25 02:02 <DIR> --d----- C:\ComboFix
2008-11-25 01:52 <DIR> --d----- c:\windows\system32\CatRoot_bak
2008-11-25 01:46 <DIR> --d----- c:\windows\system32\scripting
2008-11-25 01:46 <DIR> --d----- c:\windows\system32\en
2008-11-25 01:46 <DIR> --d----- c:\windows\l2schemas
2008-11-25 01:46 <DIR> --d----- c:\windows\system32\bits
2008-11-25 01:42 161,792 a------- c:\windows\SWREG.exe
2008-11-25 01:42 98,816 a------- c:\windows\sed.exe
2008-11-25 01:41 <DIR> --d----- c:\windows\ServicePackFiles
2008-11-25 01:36 <DIR> --d----- c:\windows\network diagnostic
2008-11-25 01:11 <DIR> --d----- c:\program files\Avira
2008-11-25 01:11 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Avira
2008-11-25 01:00 61,440 -------- c:\windows\system32\kmsvc.dll
2008-11-25 00:59 <DIR> --d----- c:\program files\MSXML 6.0
2008-11-21 18:07 <DIR> --d----- c:\windows\system32\NtmsData

==================== Find3M ====================

2008-10-24 13:21 455,296 a------- c:\windows\system32\drivers\mrxsmb.sys
2008-09-30 16:43 1,286,152 a------- c:\windows\system32\msxml4.dll

============= FINISH: 4:10:59.76 ===============

#4 PropagandaPanda

PropagandaPanda


  • Malware Response Team
  • 10,433 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:40 PM

Posted 15 December 2008 - 10:17 PM

Hello.

That log looks clean. Are you still having the issue originally discribed?

With Regards,
The Panda

#5 usm

usm
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:02:40 AM

Posted 17 December 2008 - 08:04 AM

the problem is fixed, the error doesn't pop up anymore, thanx alot 2 any1 who replied 2 my post. jus wanted 2 b certain its truly gone, combo fix removed the trojan 4 m. take care l8r.

#6 PropagandaPanda

PropagandaPanda


  • Malware Response Team
  • 10,433 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:40 PM

Posted 18 December 2008 - 02:38 AM

Hello.

For the future, refrain from using "chat speek". Some will consider it rude and refuse to help you.

Since this issue appears to be resolved, this topic is now closed.
If you are the topic starter and need this topic reopened, send me a message.

Everyone else, please begin a new topic.

With Regards,
The Panda




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users