Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Suspect Virtumonde infection


  • This topic is locked This topic is locked
18 replies to this topic

#1 hartsisk

hartsisk

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:03:04 AM

Posted 26 December 2008 - 04:12 PM

This is my kids laptop, they like to download lots of games. I was getting frequent popups for spyware removal and IEXPLORE.exe was being started by unknowns (we normally only use Firefox). Ran SpybotSD which said Virtumonde has taken up residency. I opted to "fix problems" but I can't seem to get rid of: ....\currentversion\run registry entry: "rahujosawo" and its trying to run a dll called: tojedela.dll on startup (rundll32.exe is being started at startup)
Thanks, Dave S.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:49:29 PM, on 12/26/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\Atievxx.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\HJT\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ares.mp3.es/start.php
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {82575e3d-6312-48c1-af84-6f6723bb18c7} - C:\WINDOWS\system32\muhavude.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [rahujosawo] Rundll32.exe "C:\WINDOWS\system32\tojedela.dll",s
O4 - HKUS\S-1-5-19\..\Run: [rahujosawo] Rundll32.exe "C:\WINDOWS\system32\tojedela.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [rahujosawo] Rundll32.exe "C:\WINDOWS\system32\tojedela.dll",s (User 'NETWORK SERVICE')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - AppInit_DLLs: C:\WINDOWS\system32\gefubeja.dll c:\windows\system32\dadeyisi.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\dadeyisi.dll (file missing)
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\dadeyisi.dll (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe

--
End of file - 4042 bytes

BC AdBot (Login to Remove)

 


#2 fenzodahl512

fenzodahl512

  • Members
  • 6,738 posts
  • OFFLINE
  •  
  • Local time:07:04 PM

Posted 05 January 2009 - 02:46 AM

Please download Malwarebytes' Anti-Malware from HERE or HERE

Note: If you already have Malwarebytes' Anti-Malware, just run and update it.. Then do a "Perform Full Scan"

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.




NEXT


Please download RSIT by random/random and save it to your Desktop.
  • Double click on RSIT.exe to run RSIT
  • Before you click "Continue", make sure you change the List files/folders created or modified in the last 3 months
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt and info.txt in your next reply.



NEXT


Please download GMER and unzip it to your Desktop.
  • Open the program and click on the Rootkit tab.
  • Make sure all the boxes on the right of the screen are checked, EXCEPT for ‘Show All’.
  • Click on Scan.
  • When the scan has run click Copy and paste the results into a Notepad >> save it and attach in this thread.


Post me these logs in your next reply.. Post each log in separate post..

1. Malwarebytes'
2. RSIT log.txt
3. RSIT info.txt
4. Attach GMER result..

Keep calm, make it simple, use your brain, don't freak out, and you'll be just fine..
Awesomeness: When I get sad, I stop being sad and be awesome instead.. True story - Barney Stinson
Posted Image Posted Image
Its gonna be legen.. wait for it.. dary! Cherish the pain, it means you're still alive


#3 hartsisk

hartsisk
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:03:04 AM

Posted 08 January 2009 - 12:34 AM

Thanks for helping , I am now in the process of following your instructions - may be a day or 2 , DS

#4 fenzodahl512

fenzodahl512

  • Members
  • 6,738 posts
  • OFFLINE
  •  
  • Local time:07:04 PM

Posted 08 January 2009 - 02:33 AM

Will wait for your reply :thumbsup:

Keep calm, make it simple, use your brain, don't freak out, and you'll be just fine..
Awesomeness: When I get sad, I stop being sad and be awesome instead.. True story - Barney Stinson
Posted Image Posted Image
Its gonna be legen.. wait for it.. dary! Cherish the pain, it means you're still alive


#5 hartsisk

hartsisk
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:03:04 AM

Posted 09 January 2009 - 01:00 AM

Malwarebytes log:

Malwarebytes' Anti-Malware 1.32
Database version: 1632
Windows 5.1.2600 Service Pack 2

1/8/2009 8:25:34 PM
mbam-log-2009-01-08 (20-25-34).txt

Scan type: Full Scan (C:\|)
Objects scanned: 82590
Time elapsed: 49 minute(s), 22 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 2
Registry Keys Infected: 6
Registry Values Infected: 3
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 27

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
C:\WINDOWS\system32\gefubeja.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\muhavude.dll (Trojan.Vundo.H) -> Delete on reboot.

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{82575e3d-6312-48c1-af84-6f6723bb18c7} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{82575e3d-6312-48c1-af84-6f6723bb18c7} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{82575e3d-6312-48c1-af84-6f6723bb18c7} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\rahujosawo (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\ssodl (Trojan.BHO) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: system32\gefubeja.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\gefubeja.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\gefubeja.dll -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\test\Local Settings\Temporary Internet Files\Content.IE5\ZO4TRD89\style[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{EC03704C-6751-4875-8FAB-936FD15B3FA4}\RP71\A0185608.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{EC03704C-6751-4875-8FAB-936FD15B3FA4}\RP71\A0185609.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{EC03704C-6751-4875-8FAB-936FD15B3FA4}\RP71\A0185610.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{EC03704C-6751-4875-8FAB-936FD15B3FA4}\RP73\A0190791.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{EC03704C-6751-4875-8FAB-936FD15B3FA4}\RP73\A0190792.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{EC03704C-6751-4875-8FAB-936FD15B3FA4}\RP73\A0192800.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{EC03704C-6751-4875-8FAB-936FD15B3FA4}\RP74\A0195058.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{EC03704C-6751-4875-8FAB-936FD15B3FA4}\RP74\A0195067.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{EC03704C-6751-4875-8FAB-936FD15B3FA4}\RP74\A0195068.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{EC03704C-6751-4875-8FAB-936FD15B3FA4}\RP74\A0195070.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\rundll32.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\baniwiki.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\gefubeja.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\getaviwi.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hiyusago.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\kizosewa.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\lejivaya.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ligutafo.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\logozama.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\muhavude.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\pinofivu.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\porevujo.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\puwukehe.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\wenijalu.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\yifulose.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\zazovera.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.

#6 hartsisk

hartsisk
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:03:04 AM

Posted 09 January 2009 - 01:05 AM

RSIT log.txt:

Logfile of random's system information tool 1.05 (written by random/random)
Run by test at 2009-01-08 20:40:28
Microsoft Windows XP Professional Service Pack 2
System drive C: has 9 GB (47%) free of 19 GB
Total RAM: 255 MB (26% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:40:35 PM, on 1/8/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\Atievxx.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\test\Desktop\RSIT.exe
C:\HJT\test.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ares.mp3.es/start.php
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKUS\S-1-5-19\..\Run: [rahujosawo] Rundll32.exe "C:\WINDOWS\system32\tojedela.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [rahujosawo] Rundll32.exe "C:\WINDOWS\system32\tojedela.dll",s (User 'NETWORK SERVICE')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - AppInit_DLLs: C:\WINDOWS\ c:\windows\system32\dadeyisi.dll,C:\WINDOWS\
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe

--
End of file - 3747 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2008-09-15 1562960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 501400]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe [2007-03-14 83608]
"TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2008-08-26 185896]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2008-09-06 413696]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2008-10-01 289576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\WINDOWS\ c:\windows\system32\dadeyisi.dll,C:\WINDOWS\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\WINDOWS\system32\usmt\migwiz.exe"="C:\WINDOWS\system32\usmt\migwiz.exe:*:Enabled:Files and Settings Transfer Wizard"
"C:\Program Files\DNA\btdna.exe"="C:\Program Files\DNA\btdna.exe:*:Enabled:DNA"
"C:\Program Files\BitTorrent\bittorrent.exe"="C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent"
"C:\WINDOWS\system32\mmc.exe"="C:\WINDOWS\system32\mmc.exe:*:Enabled:Microsoft Management Console"
"C:\Program Files\Real\RealPlayer\realplay.exe"="C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer"
"C:\Documents and Settings\test\Desktop\Sonic Roboblast II\srb2win.exe"="C:\Documents and Settings\test\Desktop\Sonic Roboblast II\srb2win.exe:*:Enabled:srb2win"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\WINDOWS\explorer.exe"="C:\WINDOWS\explorer.exe:*:Enabled:Explorer"
"C:\WINDOWS\system32\winlogon.exe"="C:\WINDOWS\system32\winlogon.exe:*:Enabled:winlogon"
"C:\WINDOWS\system32\rundll32.exe"="C:\WINDOWS\system32\rundll32.exe:*:Enabled:rundll32"
"C:\WINDOWS\system32\logonui.exe"="C:\WINDOWS\system32\logonui.exe:*:Enabled:logonui"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======List of files/folders created in the last 3 months======

2009-01-08 20:40:28 ----D---- C:\rsit
2009-01-08 19:16:02 ----D---- C:\Documents and Settings\test\Application Data\Malwarebytes
2009-01-08 19:15:53 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-01-08 19:15:52 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-01-07 21:21:49 ----A---- C:\WINDOWS\gmer.ini
2009-01-07 21:21:46 ----RA---- C:\WINDOWS\gmer.exe
2009-01-07 21:21:46 ----A---- C:\WINDOWS\gmer_uninstall.cmd
2009-01-07 21:21:46 ----A---- C:\WINDOWS\gmer.dll
2009-01-07 20:10:52 ----RA---- C:\WINDOWS\system32\WestCoIn.dll
2008-12-26 12:01:53 ----D---- C:\HJT
2008-12-22 11:28:45 ----A---- C:\WINDOWS\wininit.ini
2008-12-21 22:31:57 ----D---- C:\Program Files\Spybot - Search & Destroy
2008-12-21 22:31:57 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-19 13:58:15 ----D---- C:\Program Files\Super Mario All-Stars
2008-12-19 13:12:36 ----D---- C:\Program Files\Kirby Superstar
2008-12-14 17:59:17 ----D---- C:\Program Files\Donkey Kong Country (V1.1)
2008-12-14 14:58:27 ----D---- C:\Program Files\1964
2008-12-14 14:05:52 ----D---- C:\Program Files\Yoshi's Island (V1.1)
2008-12-14 14:00:24 ----D---- C:\Program Files\Super Mario All-Stars & World
2008-12-14 13:56:10 ----D---- C:\Program Files\Wario's Woods
2008-12-14 13:52:40 ----D---- C:\Program Files\Kirby's Dream Land 3
2008-12-14 13:47:31 ----D---- C:\Program Files\Sonic Blastman
2008-12-14 13:41:10 ----D---- C:\Program Files\Star Fox (V1.2)
2008-12-08 18:04:24 ----D---- C:\Program Files\Legend of Zelda, The
2008-12-08 17:46:18 ----D---- C:\Program Files\Super Mario RPG
2008-12-08 17:29:26 ----D---- C:\Program Files\Super Mario Kart
2008-12-03 19:37:47 ----D---- C:\Program Files\Super Mario World
2008-12-03 19:00:02 ----D---- C:\Documents and Settings\test\Application Data\.bsnes
2008-11-20 20:15:11 ----RHD---- C:\Documents and Settings\test\Application Data\SecuROM
2008-11-20 20:08:06 ----A---- C:\WINDOWS\system32\d3dx10_40.dll
2008-11-20 20:08:06 ----A---- C:\WINDOWS\system32\D3DCompiler_40.dll
2008-11-20 20:08:03 ----A---- C:\WINDOWS\system32\D3DX9_40.dll
2008-11-20 20:08:01 ----A---- C:\WINDOWS\system32\XAudio2_3.dll
2008-11-20 20:08:01 ----A---- C:\WINDOWS\system32\XAPOFX1_2.dll
2008-11-20 20:08:00 ----A---- C:\WINDOWS\system32\xactengine3_3.dll
2008-11-20 20:07:58 ----A---- C:\WINDOWS\system32\X3DAudio1_5.dll
2008-11-20 20:07:57 ----A---- C:\WINDOWS\system32\XAudio2_2.dll
2008-11-20 20:07:57 ----A---- C:\WINDOWS\system32\XAPOFX1_1.dll
2008-11-20 20:07:56 ----A---- C:\WINDOWS\system32\xactengine3_2.dll
2008-11-20 20:07:55 ----A---- C:\WINDOWS\system32\d3dx10_39.dll
2008-11-20 20:07:55 ----A---- C:\WINDOWS\system32\D3DCompiler_39.dll
2008-11-20 20:07:52 ----A---- C:\WINDOWS\system32\D3DX9_39.dll
2008-11-20 20:07:48 ----A---- C:\WINDOWS\system32\XAudio2_1.dll
2008-11-20 20:07:48 ----A---- C:\WINDOWS\system32\XAPOFX1_0.dll
2008-11-20 20:07:46 ----A---- C:\WINDOWS\system32\xactengine3_1.dll
2008-11-20 20:07:43 ----A---- C:\WINDOWS\system32\X3DAudio1_4.dll
2008-11-20 20:07:42 ----A---- C:\WINDOWS\system32\d3dx10_38.dll
2008-11-20 20:07:42 ----A---- C:\WINDOWS\system32\D3DCompiler_38.dll
2008-11-20 20:07:39 ----A---- C:\WINDOWS\system32\D3DX9_38.dll
2008-11-20 20:07:38 ----A---- C:\WINDOWS\system32\XAudio2_0.dll
2008-11-20 20:07:36 ----A---- C:\WINDOWS\system32\xactengine3_0.dll
2008-11-20 20:07:34 ----A---- C:\WINDOWS\system32\X3DAudio1_3.dll
2008-11-20 20:07:33 ----A---- C:\WINDOWS\system32\d3dx10_37.dll
2008-11-20 20:07:33 ----A---- C:\WINDOWS\system32\D3DCompiler_37.dll
2008-11-20 20:07:30 ----A---- C:\WINDOWS\system32\D3DX9_37.dll
2008-11-20 20:07:29 ----A---- C:\WINDOWS\system32\xactengine2_10.dll
2008-11-20 20:07:25 ----A---- C:\WINDOWS\system32\d3dx10_36.dll
2008-11-20 20:07:25 ----A---- C:\WINDOWS\system32\D3DCompiler_36.dll
2008-11-20 20:07:23 ----A---- C:\WINDOWS\system32\d3dx9_36.dll
2008-11-20 20:07:20 ----A---- C:\WINDOWS\system32\xactengine2_9.dll
2008-11-20 20:07:15 ----A---- C:\WINDOWS\system32\d3dx10_35.dll
2008-11-20 20:07:15 ----A---- C:\WINDOWS\system32\D3DCompiler_35.dll
2008-11-20 20:07:04 ----A---- C:\WINDOWS\system32\d3dx9_35.dll
2008-11-20 20:06:54 ----A---- C:\WINDOWS\system32\xactengine2_8.dll
2008-11-20 20:06:54 ----A---- C:\WINDOWS\system32\X3DAudio1_2.dll
2008-11-20 20:06:38 ----A---- C:\WINDOWS\system32\d3dx10_34.dll
2008-11-20 20:06:38 ----A---- C:\WINDOWS\system32\D3DCompiler_34.dll
2008-11-20 20:06:20 ----A---- C:\WINDOWS\system32\d3dx9_34.dll
2008-11-20 20:06:09 ----A---- C:\WINDOWS\system32\xinput1_3.dll
2008-11-20 20:05:59 ----A---- C:\WINDOWS\system32\xactengine2_7.dll
2008-11-20 20:05:49 ----A---- C:\WINDOWS\system32\d3dx10_33.dll
2008-11-20 20:05:49 ----A---- C:\WINDOWS\system32\D3DCompiler_33.dll
2008-11-20 20:05:28 ----A---- C:\WINDOWS\system32\d3dx9_33.dll
2008-11-20 20:05:25 ----A---- C:\WINDOWS\system32\xactengine2_6.dll
2008-11-20 20:05:24 ----A---- C:\WINDOWS\system32\xactengine2_5.dll
2008-11-20 20:05:22 ----A---- C:\WINDOWS\system32\d3dx9_32.dll
2008-11-20 20:05:21 ----A---- C:\WINDOWS\system32\xactengine2_4.dll
2008-11-20 20:05:20 ----A---- C:\WINDOWS\system32\x3daudio1_1.dll
2008-11-20 20:05:17 ----A---- C:\WINDOWS\system32\d3dx9_31.dll
2008-11-20 19:56:53 ----HD---- C:\WINDOWS\msdownld.tmp
2008-11-20 19:55:58 ----D---- C:\WINDOWS\Logs
2008-11-20 19:51:58 ----D---- C:\Program Files\Telltale Games
2008-11-20 16:55:46 ----D---- C:\Program Files\iPod
2008-11-20 16:55:17 ----D---- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-19 08:42:22 ----D---- C:\hegames
2008-10-15 15:44:16 ----A---- C:\not_used.txt
2008-10-15 15:30:21 ----D---- C:\Program Files\SRB2 MD2 installer interactive

======List of files/folders modified in the last 3 months======

2009-01-08 20:38:57 ----D---- C:\WINDOWS\Prefetch
2009-01-08 20:30:52 ----D---- C:\Program Files\Mozilla Firefox
2009-01-08 20:28:49 ----D---- C:\WINDOWS\system32
2009-01-08 20:28:48 ----RD---- C:\Program Files
2009-01-08 20:28:48 ----D---- C:\WINDOWS\system32\drivers
2009-01-08 20:27:41 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-01-08 20:25:33 ----D---- C:\WINDOWS
2009-01-08 20:09:21 ----D---- C:\WINDOWS\Temp
2009-01-08 14:40:27 ----SHD---- C:\WINDOWS\CSC
2009-01-07 20:12:07 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-01-07 20:10:52 ----HD---- C:\WINDOWS\inf
2009-01-07 20:10:24 ----D---- C:\WINDOWS\system32\CatRoot2
2009-01-01 11:03:31 ----D---- C:\tmp
2008-12-27 10:06:44 ----A---- C:\WINDOWS\ntbtlog.txt
2008-12-25 14:06:59 ----D---- C:\WINDOWS\Help
2008-12-22 22:14:34 ----D---- C:\WINDOWS\Minidump
2008-12-22 11:29:17 ----RSHDC---- C:\WINDOWS\system32\dllcache
2008-12-18 15:31:41 ----D---- C:\TOUCHE
2008-12-07 17:09:57 ----D---- C:\Documents and Settings\test\Application Data\OpenOffice.org2
2008-11-20 20:08:20 ----D---- C:\WINDOWS\system32\DirectX
2008-11-20 20:05:17 ----RSD---- C:\WINDOWS\assembly
2008-11-20 20:04:35 ----D---- C:\WINDOWS\Microsoft.NET
2008-11-20 17:00:07 ----SHD---- C:\WINDOWS\Installer
2008-11-20 16:57:46 ----D---- C:\Program Files\iTunes
2008-11-20 16:47:21 ----DC---- C:\WINDOWS\system32\DRVSTORE
2008-11-20 08:25:29 ----D---- C:\Program Files\Common Files
2008-11-03 09:35:23 ----A---- C:\WINDOWS\ModemLog_3Com 56K V.90 Mini PCI Modem.txt
2008-11-02 17:02:14 ----D---- C:\WINDOWS\system32\ias
2008-10-29 17:00:15 ----A---- C:\WINDOWS\HEGAMES.INI
2008-10-26 09:12:02 ----A---- C:\WINDOWS\mafosav.INI
2008-10-16 14:13:40 ----A---- C:\WINDOWS\system32\wuweb.dll
2008-10-16 14:13:40 ----A---- C:\WINDOWS\system32\wuaueng.dll
2008-10-16 14:12:22 ----A---- C:\WINDOWS\system32\wucltui.dll
2008-10-16 14:12:20 ----A---- C:\WINDOWS\system32\wuapi.dll
2008-10-16 14:09:44 ----A---- C:\WINDOWS\system32\wups2.dll
2008-10-16 14:09:44 ----A---- C:\WINDOWS\system32\wuauclt.exe
2008-10-16 14:09:44 ----A---- C:\WINDOWS\system32\cdm.dll
2008-10-16 14:09:40 ----A---- C:\WINDOWS\system32\wucltui.dll.mui
2008-10-16 14:08:58 ----A---- C:\WINDOWS\system32\wups.dll
2008-10-16 14:07:44 ----A---- C:\WINDOWS\system32\wuapi.dll.mui
2008-10-16 14:07:14 ----A---- C:\WINDOWS\system32\wuaueng.dll.mui
2008-10-14 16:33:59 ----D---- C:\Program Files\Windows Media Player

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 DCCAM;Kodak Camera Proxy; C:\WINDOWS\system32\DRIVERS\DcCam.sys [2004-05-20 36918]
R1 P3;Intel PentiumIII Processor Driver; C:\WINDOWS\system32\DRIVERS\p3.sys [2004-08-03 42496]
R2 DCFS2K;Kodak DCFS2K Driver; C:\WINDOWS\system32\drivers\dcfs2k.sys [2004-06-02 38705]
R3 atimtai;atimtai; C:\WINDOWS\system32\DRIVERS\atimtai.sys [2001-08-17 281600]
R3 CmBatt;Microsoft AC Adapter Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2004-08-03 14080]
R3 EL556ND5;3Com 10/100 MiniPCI Ethernet Adapter Driver; C:\WINDOWS\system32\DRIVERS\EL556ND5.sys [2001-08-17 55999]
R3 maestro;ESS Maestro 3 Audio Driver (WDM); C:\WINDOWS\system32\drivers\es198x.sys [2001-08-17 174464]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-03 20480]
R3 WDHAALBA;WDHAALBAMiniPCI Winmodem; C:\WINDOWS\system32\DRIVERS\WDHAALBA.sys [2001-08-17 701386]
S1 Exportit;Exportit; C:\WINDOWS\system32\DRIVERS\exportit.sys [2004-06-02 151985]
S1 OMCI;OMCI; \??\C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS []
S3 DcFpoint;DcFpoint; C:\WINDOWS\system32\DRIVERS\DcFpoint.sys [2004-05-20 61564]
S3 DcLps;Legacy Polling Service; C:\WINDOWS\system32\DRIVERS\DcLps.sys [2004-05-20 8022]
S3 DcPTP;dcptp; C:\WINDOWS\system32\DRIVERS\DcPTP.sys [2004-05-20 68950]
S3 FANTOM;LEGO MINDSTORMS NXT Driver; C:\WINDOWS\system32\DRIVERS\fantom.sys [2006-03-10 39424]
S3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys [2008-04-17 15464]
S3 gmer;gmer; C:\WINDOWS\System32\DRIVERS\gmer.sys [2009-01-07 85969]
S3 sermouse;Serial Mouse Driver; C:\WINDOWS\system32\DRIVERS\sermouse.sys [2001-08-17 17664]
S3 SWLD23;Netopia 802.11b WLAN Cardbus Card; C:\WINDOWS\system32\DRIVERS\swld23.sys [2004-01-15 68224]
S3 USB_RNDIS_XP;Westell WireSpeed Dual Connect Modem; C:\WINDOWS\system32\DRIVERS\usb8023.sys [2004-08-03 12672]
S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys [2008-10-01 32000]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-10-01 116040]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Atievxx.exe [2001-08-17 37376]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-08-29 238888]
R2 KodakCCS;Kodak Camera Connection Software; C:\WINDOWS\system32\drivers\KodakCCS.exe [2004-05-24 322104]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2008-10-01 536872]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-04-13 33632]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-04-13 68952]

-----------------EOF-----------------

#7 hartsisk

hartsisk
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:03:04 AM

Posted 09 January 2009 - 01:14 AM

RSIT info.txt:

info.txt logfile of random's system information tool 1.05 2009-01-08 20:40:41

======Uninstall list======

-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
3D Ultra Pinball Thrillride-->C:\WINDOWS\IsUninst.exe -fC:\Sierra\Thrillride\Uninst.isu
Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 8.1.2-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81200000003}
Apple Mobile Device Support-->MsiExec.exe /I{976C2B2A-CE59-4AB3-83FB-BF895E28F2E6}
Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
Ares Tube 3.2-->"c:\Ares Tube\unins000.exe"
BellSouth Wireless LAN MiniPCI/CardBus-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BB483CA4-82D0-4755-94FD-918F0E60218F}\setup.exe" -l0x9
BellSouth WLAN Configuration Utility-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{107D8634-8F2D-4D2A-8B9F-8527022D46BA}\setup.exe" -l0x9
Blender (remove only)-->"C:\Program Files\Blender Foundation\Blender\uninstall.exe"
Bonjour-->MsiExec.exe /I{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}
CCHelp-->MsiExec.exe /I{9D1CF8B6-17B3-4832-B062-2C2DD0B57B04}
CCScore-->MsiExec.exe /I{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}
Croc 2-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Fox\Croc 2\Uninst.isu"
Croc-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Fox\Croc\Uninst.isu"
Dell Resource CD-->MsiExec.exe /X{FCD9CD52-7222-4672-94A0-A722BA702FD0}
Disney Toontown Online-->C:\Program Files\Disney\Disney Online\ToontownOnline\uninst.exe
Donkey Kong Country (V1.1)-->"C:\Program Files\Donkey Kong Country (V1.1)\unins000.exe"
ESSAdpt-->MsiExec.exe /I{D15E9DB5-6BEB-4534-901E-80C0A29BAB97}
ESSANUP-->MsiExec.exe /I{A6F18A67-B771-4191-8A33-36D2E742D6D9}
ESSBrwr-->MsiExec.exe /I{643EAE81-920C-4931-9F0B-4B343B225CA6}
ESSCAM-->MsiExec.exe /I{469730CC-78DF-4CD3-B286-562D459EA619}
ESSCDBK-->MsiExec.exe /I{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}
ESScore-->MsiExec.exe /I{9D8FEE90-0377-49A9-AEFB-525BDE549BA4}
ESSCT-->MsiExec.exe /I{8BB4B58A-A402-4DE8-8FCD-287E60B88DD8}
ESSEMAIL-->MsiExec.exe /I{FEDE2483-87B7-44C1-A5BB-D75AEB8B6340}
ESSgui-->MsiExec.exe /I{91517631-A9F3-4B7C-B482-43E0068FD55A}
ESShelp-->MsiExec.exe /I{87843A41-7808-4F2E-B13F-25C1E67CF2FD}
ESSini-->MsiExec.exe /I{8E92D746-CD9F-4B90-9668-42B74C14F765}
ESSPCD-->MsiExec.exe /I{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}
ESSSONIC-->MsiExec.exe /I{4F677FC7-7AA8-412B-A957-F13CBE1C7331}
ESSTUTOR-->MsiExec.exe /I{CA60320D-6A16-49C8-A34F-84EEF4799567}
ESSvpaht-->MsiExec.exe /I{A5B3EB8A-4071-42F0-8E8E-7A8342AA8E69}
ESSvpot-->MsiExec.exe /I{48C82F7A-F100-4DAB-A310-8E18BF2159E1}
G4FON Koch Method Morse Trainer-->C:\Program Files\G4FON Software\Koch Morse Trainer\Uninstal.exe
HijackThis 2.0.2-->"C:\HJT\HijackThis.exe" /uninstall
HLPCCTR-->MsiExec.exe /I{F2D0C1B1-80FF-46F9-BA61-33B01A07FAFC}
HLPIndex-->MsiExec.exe /I{38441BE7-79B0-42B8-8297-833704F949FE}
HLPSFO-->MsiExec.exe /I{8DD94CA3-BCD2-49C0-B537-F3B5D95FF0C8}
Hotfix for Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
Indeo® software-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Intel\Indeo® software\Uninst.isu"
iTunes-->MsiExec.exe /I{DDDE0BE3-0CBE-4BF6-B75A-E3F69C947843}
Java™ SE Runtime Environment 6 Update 1-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
King's Bounty-->"C:\Program Files\King's Bounty\unins000.exe"
Kirby Superstar-->"C:\Program Files\Kirby Superstar\unins000.exe"
Kirby's Dream Land 3-->"C:\Program Files\Kirby's Dream Land 3\unins000.exe"
Kodak EasyShare software-->C:\Documents and Settings\All Users\Application Data\Kodak\EasyShareSetup\$SETUP_9_3d8f8\Setup.exe /APR-REMOVE
Legend of Zelda, The-->"C:\Program Files\Legend of Zelda, The\unins000.exe"
LEGO Creator Knights' Kingdom-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A637F36B-2B36-11D4-A322-0001020A6A3D}\setup.exe"
LEGO Island-->C:\PROGRA~1\LEGOIS~1\UNINST.EXE C:\PROGRA~1\LEGOIS~1\INSTALL.LOG
LEGO Racers-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\LEGO Media\Games\LEGO Racers\Uninst.isu"
LEGO Rock Raiders-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\LEGO Media\Games\Rock Raiders\Uninst.isu"
LEGO® MINDSTORMS® NXT - English Language Pack-->MsiExec.exe /I{3E4153AF-3D74-4062-8812-B1FDCE6B1F37}
LEGO® MINDSTORMS® NXT Driver-->MsiExec.exe /I{E14D4E88-DBBF-4AEE-A8EB-C4744E95EEEA}
LEGO® MINDSTORMS® NXT Software v1.0-->MsiExec.exe /I{4246326C-E861-43CA-B47D-2357454385F9}
LEGOLAND-->C:\WINDOWS\uninst.exe -f"C:\Program Files\LEGO Media\Games\LEGOLAND\DeIsL1.isu"
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Mario Forever v 2.16 !-->C:\Buziol Games\Mario Forever\UnMario.exe
Microsoft .NET Framework 2.0-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
Mozilla Firefox (2.0.0.18)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSN-->C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
Notifier-->MsiExec.exe /I{0008546E-DF6E-4CC1-AFD0-2CB8E16C95A2}
OfotoXMI-->MsiExec.exe /I{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}
OpenOffice.org 2.0-->MsiExec.exe /I{643318A4-8E95-4377-9254-E52BB763A1E7}
OTtBP-->MsiExec.exe /I{F71760CD-0F8B-4DCC-B7B7-6B223CC3843C}
OTtBPSDK-->MsiExec.exe /I{3CA39B0C-BA85-4D42-AC0F-1FF5F60C3353}
Parker Brothers Classic Card Games-->C:\Program Files\Hasbro Interactive\Classic Games\PBUninst.exe
PCDLNCH-->MsiExec.exe /I{69BD6399-3D8F-45B7-81D9-819361F5101D}
Pinball Science-->C:\WINDOWS\UNINST.EXE -r"DK Multimedia\Pinball Science\0.01.01.0002" -n"Pinball Science" -fC:\PROGRA~1\DKMULT~1\PINBAL~1\DeIsL1.isu -cC:\PROGRA~1\DKMULT~1\PINBAL~1\uninst.dll -oNT
Project64 1.6-->MsiExec.exe /X{9559F7CA-5E34-4237-A2D9-D856464AD727}
QuickTime-->MsiExec.exe /I{8DC42D05-680B-41B0-8878-6C14D24602DB}
RealPlayer-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
Security Update for Microsoft .NET Framework 2.0 (KB928365)-->C:\WINDOWS\system32\msiexec.exe /promptrestart /uninstall {8056AC9E-49C5-4375-9ADE-B2F862C9DF51} /package {7131646D-CD3C-40F4-97B9-CD9E4E6262EF}
Security Update for Windows Media Player (KB911564)-->"C:\WINDOWS\$NtUninstallKB911564$\spuninst\spuninst.exe"
Security Update for Windows Media Player 6.4 (KB925398)-->"C:\WINDOWS\$NtUninstallKB925398_WMP64$\spuninst\spuninst.exe"
Security Update for Windows XP (KB890046)-->"C:\WINDOWS\$NtUninstallKB890046$\spuninst\spuninst.exe"
Security Update for Windows XP (KB893756)-->"C:\WINDOWS\$NtUninstallKB893756$\spuninst\spuninst.exe"
Security Update for Windows XP (KB896358)-->"C:\WINDOWS\$NtUninstallKB896358$\spuninst\spuninst.exe"
Security Update for Windows XP (KB896423)-->"C:\WINDOWS\$NtUninstallKB896423$\spuninst\spuninst.exe"
Security Update for Windows XP (KB896428)-->"C:\WINDOWS\$NtUninstallKB896428$\spuninst\spuninst.exe"
Security Update for Windows XP (KB899587)-->"C:\WINDOWS\$NtUninstallKB899587$\spuninst\spuninst.exe"
Security Update for Windows XP (KB899591)-->"C:\WINDOWS\$NtUninstallKB899591$\spuninst\spuninst.exe"
Security Update for Windows XP (KB900725)-->"C:\WINDOWS\$NtUninstallKB900725$\spuninst\spuninst.exe"
Security Update for Windows XP (KB901017)-->"C:\WINDOWS\$NtUninstallKB901017$\spuninst\spuninst.exe"
Security Update for Windows XP (KB901214)-->"C:\WINDOWS\$NtUninstallKB901214$\spuninst\spuninst.exe"
Security Update for Windows XP (KB902400)-->"C:\WINDOWS\$NtUninstallKB902400$\spuninst\spuninst.exe"
Security Update for Windows XP (KB904706)-->"C:\WINDOWS\$NtUninstallKB904706$\spuninst\spuninst.exe"
Security Update for Windows XP (KB905414)-->"C:\WINDOWS\$NtUninstallKB905414$\spuninst\spuninst.exe"
Security Update for Windows XP (KB905749)-->"C:\WINDOWS\$NtUninstallKB905749$\spuninst\spuninst.exe"
Security Update for Windows XP (KB908519)-->"C:\WINDOWS\$NtUninstallKB908519$\spuninst\spuninst.exe"
Security Update for Windows XP (KB911562)-->"C:\WINDOWS\$NtUninstallKB911562$\spuninst\spuninst.exe"
Security Update for Windows XP (KB911927)-->"C:\WINDOWS\$NtUninstallKB911927$\spuninst\spuninst.exe"
Security Update for Windows XP (KB913580)-->"C:\WINDOWS\$NtUninstallKB913580$\spuninst\spuninst.exe"
Security Update for Windows XP (KB914388)-->"C:\WINDOWS\$NtUninstallKB914388$\spuninst\spuninst.exe"
Security Update for Windows XP (KB914389)-->"C:\WINDOWS\$NtUninstallKB914389$\spuninst\spuninst.exe"
Security Update for Windows XP (KB917344)-->"C:\WINDOWS\$NtUninstallKB917344$\spuninst\spuninst.exe"
Security Update for Windows XP (KB917953)-->"C:\WINDOWS\$NtUninstallKB917953$\spuninst\spuninst.exe"
Security Update for Windows XP (KB918118)-->"C:\WINDOWS\$NtUninstallKB918118$\spuninst\spuninst.exe"
Security Update for Windows XP (KB918439)-->"C:\WINDOWS\$NtUninstallKB918439$\spuninst\spuninst.exe"
Security Update for Windows XP (KB919007)-->"C:\WINDOWS\$NtUninstallKB919007$\spuninst\spuninst.exe"
Security Update for Windows XP (KB920213)-->"C:\WINDOWS\$NtUninstallKB920213$\spuninst\spuninst.exe"
Security Update for Windows XP (KB920670)-->"C:\WINDOWS\$NtUninstallKB920670$\spuninst\spuninst.exe"
Security Update for Windows XP (KB920683)-->"C:\WINDOWS\$NtUninstallKB920683$\spuninst\spuninst.exe"
Security Update for Windows XP (KB920685)-->"C:\WINDOWS\$NtUninstallKB920685$\spuninst\spuninst.exe"
Security Update for Windows XP (KB921503)-->"C:\WINDOWS\$NtUninstallKB921503$\spuninst\spuninst.exe"
Security Update for Windows XP (KB922819)-->"C:\WINDOWS\$NtUninstallKB922819$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923191)-->"C:\WINDOWS\$NtUninstallKB923191$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923414)-->"C:\WINDOWS\$NtUninstallKB923414$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923689)-->"C:\WINDOWS\$NtUninstallKB923689$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923980)-->"C:\WINDOWS\$NtUninstallKB923980$\spuninst\spuninst.exe"
Security Update for Windows XP (KB924270)-->"C:\WINDOWS\$NtUninstallKB924270$\spuninst\spuninst.exe"
Security Update for Windows XP (KB924496)-->"C:\WINDOWS\$NtUninstallKB924496$\spuninst\spuninst.exe"
Security Update for Windows XP (KB924667)-->"C:\WINDOWS\$NtUninstallKB924667$\spuninst\spuninst.exe"
Security Update for Windows XP (KB925902)-->"C:\WINDOWS\$NtUninstallKB925902$\spuninst\spuninst.exe"
Security Update for Windows XP (KB926255)-->"C:\WINDOWS\$NtUninstallKB926255$\spuninst\spuninst.exe"
Security Update for Windows XP (KB926436)-->"C:\WINDOWS\$NtUninstallKB926436$\spuninst\spuninst.exe"
Security Update for Windows XP (KB927779)-->"C:\WINDOWS\$NtUninstallKB927779$\spuninst\spuninst.exe"
Security Update for Windows XP (KB927802)-->"C:\WINDOWS\$NtUninstallKB927802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB928255)-->"C:\WINDOWS\$NtUninstallKB928255$\spuninst\spuninst.exe"
Security Update for Windows XP (KB928843)-->"C:\WINDOWS\$NtUninstallKB928843$\spuninst\spuninst.exe"
Security Update for Windows XP (KB929123)-->"C:\WINDOWS\$NtUninstallKB929123$\spuninst\spuninst.exe"
Security Update for Windows XP (KB930178)-->"C:\WINDOWS\$NtUninstallKB930178$\spuninst\spuninst.exe"
Security Update for Windows XP (KB931261)-->"C:\WINDOWS\$NtUninstallKB931261$\spuninst\spuninst.exe"
Security Update for Windows XP (KB931784)-->"C:\WINDOWS\$NtUninstallKB931784$\spuninst\spuninst.exe"
Security Update for Windows XP (KB932168)-->"C:\WINDOWS\$NtUninstallKB932168$\spuninst\spuninst.exe"
Security Update for Windows XP (KB933729)-->"C:\WINDOWS\$NtUninstallKB933729$\spuninst\spuninst.exe"
Security Update for Windows XP (KB935839)-->"C:\WINDOWS\$NtUninstallKB935839$\spuninst\spuninst.exe"
Security Update for Windows XP (KB935840)-->"C:\WINDOWS\$NtUninstallKB935840$\spuninst\spuninst.exe"
Security Update for Windows XP (KB936021)-->"C:\WINDOWS\$NtUninstallKB936021$\spuninst\spuninst.exe"
Security Update for Windows XP (KB937894)-->"C:\WINDOWS\$NtUninstallKB937894$\spuninst\spuninst.exe"
Security Update for Windows XP (KB938127)-->"C:\WINDOWS\$NtUninstallKB938127$\spuninst\spuninst.exe"
Security Update for Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB938829)-->"C:\WINDOWS\$NtUninstallKB938829$\spuninst\spuninst.exe"
Security Update for Windows XP (KB939653)-->"C:\WINDOWS\$NtUninstallKB939653$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941202)-->"C:\WINDOWS\$NtUninstallKB941202$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941568)-->"C:\WINDOWS\$NtUninstallKB941568$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941644)-->"C:\WINDOWS\$NtUninstallKB941644$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941693)-->"C:\WINDOWS\$NtUninstallKB941693$\spuninst\spuninst.exe"
Security Update for Windows XP (KB943055)-->"C:\WINDOWS\$NtUninstallKB943055$\spuninst\spuninst.exe"
Security Update for Windows XP (KB943460)-->"C:\WINDOWS\$NtUninstallKB943460$\spuninst\spuninst.exe"
Security Update for Windows XP (KB943485)-->"C:\WINDOWS\$NtUninstallKB943485$\spuninst\spuninst.exe"
Security Update for Windows XP (KB944338-v2)-->"C:\WINDOWS\$NtUninstallKB944338-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB944533)-->"C:\WINDOWS\$NtUninstallKB944533$\spuninst\spuninst.exe"
Security Update for Windows XP (KB944653)-->"C:\WINDOWS\$NtUninstallKB944653$\spuninst\spuninst.exe"
Security Update for Windows XP (KB945553)-->"C:\WINDOWS\$NtUninstallKB945553$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946026)-->"C:\WINDOWS\$NtUninstallKB946026$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB948590)-->"C:\WINDOWS\$NtUninstallKB948590$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950749)-->"C:\WINDOWS\$NtUninstallKB950749$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953838)-->"C:\WINDOWS\$NtUninstallKB953838$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
SFR-->MsiExec.exe /I{C354C9B6-A4E0-4BB0-A368-6DC6BCA0E314}
SFR2-->MsiExec.exe /I{A0AF08BA-3630-4505-BFB2-A41F3837B0D0}
Sonic Blastman-->"C:\Program Files\Sonic Blastman\unins000.exe"
Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
SRB2 MD2 installer interactive PRE ALPHA-->C:\Program Files\SRB2 MD2 installer interactive\uninst.exe
Star Fox (V1.2)-->"C:\Program Files\Star Fox (V1.2)\unins000.exe"
Super Mario All-Stars & World-->"C:\Program Files\Super Mario All-Stars & World\unins000.exe"
Super Mario All-Stars-->"C:\Program Files\Super Mario All-Stars\unins000.exe"
Super Mario Kart-->"C:\Program Files\Super Mario Kart\unins000.exe"
Super Mario RPG-->"C:\Program Files\Super Mario RPG\unins000.exe"
Super Mario World-->"C:\Program Files\Super Mario World\unins000.exe"
Update for Windows XP (KB894391)-->"C:\WINDOWS\$NtUninstallKB894391$\spuninst\spuninst.exe"
Update for Windows XP (KB898461)-->"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
Update for Windows XP (KB900485)-->"C:\WINDOWS\$NtUninstallKB900485$\spuninst\spuninst.exe"
Update for Windows XP (KB908531)-->"C:\WINDOWS\$NtUninstallKB908531$\spuninst\spuninst.exe"
Update for Windows XP (KB910437)-->"C:\WINDOWS\$NtUninstallKB910437$\spuninst\spuninst.exe"
Update for Windows XP (KB911280)-->"C:\WINDOWS\$NtUninstallKB911280$\spuninst\spuninst.exe"
Update for Windows XP (KB916595)-->"C:\WINDOWS\$NtUninstallKB916595$\spuninst\spuninst.exe"
Update for Windows XP (KB920872)-->"C:\WINDOWS\$NtUninstallKB920872$\spuninst\spuninst.exe"
Update for Windows XP (KB922582)-->"C:\WINDOWS\$NtUninstallKB922582$\spuninst\spuninst.exe"
Update for Windows XP (KB927891)-->"C:\WINDOWS\$NtUninstallKB927891$\spuninst\spuninst.exe"
Update for Windows XP (KB930916)-->"C:\WINDOWS\$NtUninstallKB930916$\spuninst\spuninst.exe"
Update for Windows XP (KB933360)-->"C:\WINDOWS\$NtUninstallKB933360$\spuninst\spuninst.exe"
Update for Windows XP (KB936357)-->"C:\WINDOWS\$NtUninstallKB936357$\spuninst\spuninst.exe"
Update for Windows XP (KB938828)-->"C:\WINDOWS\$NtUninstallKB938828$\spuninst\spuninst.exe"
Update for Windows XP (KB942763)-->"C:\WINDOWS\$NtUninstallKB942763$\spuninst\spuninst.exe"
Update for Windows XP (KB942840)-->"C:\WINDOWS\$NtUninstallKB942840$\spuninst\spuninst.exe"
VCAMCEN-->MsiExec.exe /I{10E98E14-832C-4AF7-A4D1-6A9EF83B282E}
VPRINTOL-->MsiExec.exe /I{999D43F4-9709-4887-9B1A-83EBB15A8370}
Wario's Woods-->"C:\Program Files\Wario's Woods\unins000.exe"
Windows Installer 3.1 (KB893803)-->"C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
Windows XP Hotfix - KB873339-->C:\WINDOWS\$NtUninstallKB873339$\spuninst\spuninst.exe
Windows XP Hotfix - KB885835-->C:\WINDOWS\$NtUninstallKB885835$\spuninst\spuninst.exe
Windows XP Hotfix - KB885836-->C:\WINDOWS\$NtUninstallKB885836$\spuninst\spuninst.exe
Windows XP Hotfix - KB886185-->C:\WINDOWS\$NtUninstallKB886185$\spuninst\spuninst.exe
Windows XP Hotfix - KB887472-->C:\WINDOWS\$NtUninstallKB887472$\spuninst\spuninst.exe
Windows XP Hotfix - KB888302-->C:\WINDOWS\$NtUninstallKB888302$\spuninst\spuninst.exe
Windows XP Hotfix - KB890859-->"C:\WINDOWS\$NtUninstallKB890859$\spuninst\spuninst.exe"
Windows XP Hotfix - KB891781-->C:\WINDOWS\$NtUninstallKB891781$\spuninst\spuninst.exe
Yoshi's Island (V1.1)-->"C:\Program Files\Yoshi's Island (V1.1)\unins000.exe"
Zelda Classic 2.10w-->C:\Program Files\ZC2.10\uninstall.exe

System event log

Computer Name: TEST-15B5C04E37
Event Code: 7036
Message: The SSDP Discovery Service service entered the running state.

Record Number: 30207
Source Name: Service Control Manager
Time Written: 20081215195234.000000-480
Event Type: information
User:

Computer Name: TEST-15B5C04E37
Event Code: 7035
Message: The Remote Access Connection Manager service was successfully sent a start control.

Record Number: 30206
Source Name: Service Control Manager
Time Written: 20081215195234.000000-480
Event Type: information
User: TEST-15B5C04E37\test

Computer Name: TEST-15B5C04E37
Event Code: 7036
Message: The Telephony service entered the running state.

Record Number: 30205
Source Name: Service Control Manager
Time Written: 20081215195234.000000-480
Event Type: information
User:

Computer Name: TEST-15B5C04E37
Event Code: 7036
Message: The iPod Service service entered the running state.

Record Number: 30204
Source Name: Service Control Manager
Time Written: 20081215195234.000000-480
Event Type: information
User:

Computer Name: TEST-15B5C04E37
Event Code: 7036
Message: The Network Location Awareness (NLA) service entered the running state.

Record Number: 30203
Source Name: Service Control Manager
Time Written: 20081215195234.000000-480
Event Type: information
User:

Application event log

Computer Name: TEST-15B5C04E37
Event Code: 1800
Message: The Windows Security Center Service has started.

Record Number: 1672
Source Name: SecurityCenter
Time Written: 20080226110126.000000-480
Event Type: information
User:

Computer Name: TEST-15B5C04E37
Event Code: 105
Message:
Record Number: 1671
Source Name: dcfssvc
Time Written: 20080226110102.000000-480
Event Type: information
User:

Computer Name: TEST-15B5C04E37
Event Code: 1517
Message: Windows saved user TEST-15B5C04E37\test registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use.


This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.

Record Number: 1670
Source Name: Userenv
Time Written: 20080225211630.000000-480
Event Type: warning
User: NT AUTHORITY\SYSTEM

Computer Name: TEST-15B5C04E37
Event Code: 1800
Message: The Windows Security Center Service has started.

Record Number: 1669
Source Name: SecurityCenter
Time Written: 20080225164311.000000-480
Event Type: information
User:

Computer Name: TEST-15B5C04E37
Event Code: 105
Message:
Record Number: 1668
Source Name: dcfssvc
Time Written: 20080225164223.000000-480
Event Type: information
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\VXIPNP\WinNT\Bin;C:\Program Files\QuickTime\QTSystem\
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 8 Stepping 6, GenuineIntel
"PROCESSOR_REVISION"=0806
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"VXIPNPPATH"=C:\VXIPNP\
"CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_01\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre1.6.0_01\lib\ext\QTJava.zip

-----------------EOF-----------------
Attached File  gmer1.txt   250bytes   26 downloads

#8 fenzodahl512

fenzodahl512

  • Members
  • 6,738 posts
  • OFFLINE
  •  
  • Local time:07:04 PM

Posted 09 January 2009 - 10:03 AM

IMPORTANT!! Uninstall these programs first (if present..) so that they won't interfere with our fixes..

1. Lavasoft Ad-Aware
2. Spybot - Search & Destroy
3. Viewpoint (all of them..)



Please download JavaRa to your desktop and unzip it to its own folder. <<MIRROR>>
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
Then, please download and install the latest Java from HERE




NEXT


Please re-open HijackThis and click on Do a system scan only. Check the boxes next to all the entries listed below.

O4 - HKUS\S-1-5-19\..\Run: [rahujosawo] Rundll32.exe "C:\WINDOWS\system32\tojedela.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [rahujosawo] Rundll32.exe "C:\WINDOWS\system32\tojedela.dll",s (User 'NETWORK SERVICE')
O20 - AppInit_DLLs: C:\WINDOWS\ c:\windows\system32\dadeyisi.dll,C:\WINDOWS\


Now close all windows other than HijackThis, then click Fix checked. Close HijackThis.




NEXT


Please download the OTMoveIt3 by OldTimer
  • Save it to your Desktop.
  • Please double-click OTMoveIt3.exe to run it. (Vista users, please right click on OTMoveit3.exe and select "Run as an Administrator")
  • Let the Unregister Dll's and Ocx's remain ticked and Zip Files After Moves remain unticked..
  • Copy the codebox contents and paste it to the "Paste List of Files/Folders to Move" window (under the light Yellow bar)

    :processes
    explorer.exe
    
    :services
    
    :files
    C:\WINDOWS\system32\tojedela.dll
    c:\windows\system32\dadeyisi.dll
    
    :reg
    
    :commands
    [purity]
    [emptytemp]
    [start explorer]
    [reboot]
  • Click the red Moveit! button.
  • A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.
  • Close OTMoveIt3
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.



Run RSIT again... Post these logs in your next reply..

1. OTMoveIt3
2. RSIT log.txt

Keep calm, make it simple, use your brain, don't freak out, and you'll be just fine..
Awesomeness: When I get sad, I stop being sad and be awesome instead.. True story - Barney Stinson
Posted Image Posted Image
Its gonna be legen.. wait for it.. dary! Cherish the pain, it means you're still alive


#9 hartsisk

hartsisk
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:03:04 AM

Posted 09 January 2009 - 11:18 PM

OTMoveIT3 log:

Error: Unable to interpret <processes> in the current context!
Error: Unable to interpret <explorer.exe> in the current context!
========== SERVICES/DRIVERS ==========
========== FILES ==========
File/Folder C:\WINDOWS\system32\tojedela.dll not found.
File/Folder c:\windows\system32\dadeyisi.dll not found.
========== REGISTRY ==========
========== COMMANDS ==========
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_170.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\test\Local Settings\Application Data\Mozilla\Firefox\Profiles\3jj3rrvp.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\test\Local Settings\Application Data\Mozilla\Firefox\Profiles\3jj3rrvp.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\test\Local Settings\Application Data\Mozilla\Firefox\Profiles\3jj3rrvp.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\test\Local Settings\Application Data\Mozilla\Firefox\Profiles\3jj3rrvp.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\test\Local Settings\Application Data\Mozilla\Firefox\Profiles\3jj3rrvp.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 01092009_194803

Files moved on Reboot...
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
File C:\WINDOWS\temp\Perflib_Perfdata_170.dat not found!
C:\Documents and Settings\test\Local Settings\Application Data\Mozilla\Firefox\Profiles\3jj3rrvp.default\Cache\_CACHE_001_ moved successfully.
C:\Documents and Settings\test\Local Settings\Application Data\Mozilla\Firefox\Profiles\3jj3rrvp.default\Cache\_CACHE_002_ moved successfully.
C:\Documents and Settings\test\Local Settings\Application Data\Mozilla\Firefox\Profiles\3jj3rrvp.default\Cache\_CACHE_003_ moved successfully.
C:\Documents and Settings\test\Local Settings\Application Data\Mozilla\Firefox\Profiles\3jj3rrvp.default\Cache\_CACHE_MAP_ moved successfully.
C:\Documents and Settings\test\Local Settings\Application Data\Mozilla\Firefox\Profiles\3jj3rrvp.default\XUL.mfl moved successfully.


RSIT log.txt:

Logfile of random's system information tool 1.05 (written by random/random)
Run by test at 2009-01-09 20:02:02
Microsoft Windows XP Professional Service Pack 2
System drive C: has 9 GB (47%) free of 19 GB
Total RAM: 255 MB (33% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:02:07 PM, on 1/9/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\Atievxx.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\notepad.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\test\Desktop\RSIT.exe
C:\HJT\test.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ares.mp3.es/start.php
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe

--
End of file - 3108 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java™ Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2009-01-09 320920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-01-09 34816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-01-09 73728]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2008-08-26 185896]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2008-09-06 413696]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2008-10-01 289576]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-01-09 136600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\WINDOWS\system32\usmt\migwiz.exe"="C:\WINDOWS\system32\usmt\migwiz.exe:*:Enabled:Files and Settings Transfer Wizard"
"C:\Program Files\DNA\btdna.exe"="C:\Program Files\DNA\btdna.exe:*:Enabled:DNA"
"C:\Program Files\BitTorrent\bittorrent.exe"="C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent"
"C:\WINDOWS\system32\mmc.exe"="C:\WINDOWS\system32\mmc.exe:*:Enabled:Microsoft Management Console"
"C:\Program Files\Real\RealPlayer\realplay.exe"="C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer"
"C:\Documents and Settings\test\Desktop\Sonic Roboblast II\srb2win.exe"="C:\Documents and Settings\test\Desktop\Sonic Roboblast II\srb2win.exe:*:Enabled:srb2win"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\WINDOWS\explorer.exe"="C:\WINDOWS\explorer.exe:*:Enabled:Explorer"
"C:\WINDOWS\system32\winlogon.exe"="C:\WINDOWS\system32\winlogon.exe:*:Enabled:winlogon"
"C:\WINDOWS\system32\rundll32.exe"="C:\WINDOWS\system32\rundll32.exe:*:Enabled:rundll32"
"C:\WINDOWS\system32\logonui.exe"="C:\WINDOWS\system32\logonui.exe:*:Enabled:logonui"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======List of files/folders created in the last 3 months======

2009-01-09 19:38:29 ----D---- C:\_OTMoveIt
2009-01-09 19:02:44 ----A---- C:\WINDOWS\system32\javaws.exe
2009-01-09 19:02:44 ----A---- C:\WINDOWS\system32\javaw.exe
2009-01-09 19:02:44 ----A---- C:\WINDOWS\system32\java.exe
2009-01-09 19:02:44 ----A---- C:\WINDOWS\system32\deploytk.dll
2009-01-08 20:40:28 ----D---- C:\rsit
2009-01-08 19:16:02 ----D---- C:\Documents and Settings\test\Application Data\Malwarebytes
2009-01-08 19:15:53 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-01-08 19:15:52 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-01-07 21:21:49 ----A---- C:\WINDOWS\gmer.ini
2009-01-07 21:21:46 ----RA---- C:\WINDOWS\gmer.exe
2009-01-07 21:21:46 ----A---- C:\WINDOWS\gmer_uninstall.cmd
2009-01-07 21:21:46 ----A---- C:\WINDOWS\gmer.dll
2009-01-07 20:10:52 ----RA---- C:\WINDOWS\system32\WestCoIn.dll
2008-12-26 12:01:53 ----D---- C:\HJT
2008-12-22 11:28:45 ----A---- C:\WINDOWS\wininit.ini
2008-12-21 22:31:57 ----D---- C:\Program Files\Spybot - Search & Destroy
2008-12-21 22:31:57 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-19 13:58:15 ----D---- C:\Program Files\Super Mario All-Stars
2008-12-19 13:12:36 ----D---- C:\Program Files\Kirby Superstar
2008-12-14 17:59:17 ----D---- C:\Program Files\Donkey Kong Country (V1.1)
2008-12-14 14:58:27 ----D---- C:\Program Files\1964
2008-12-14 14:05:52 ----D---- C:\Program Files\Yoshi's Island (V1.1)
2008-12-14 14:00:24 ----D---- C:\Program Files\Super Mario All-Stars & World
2008-12-14 13:56:10 ----D---- C:\Program Files\Wario's Woods
2008-12-14 13:52:40 ----D---- C:\Program Files\Kirby's Dream Land 3
2008-12-14 13:47:31 ----D---- C:\Program Files\Sonic Blastman
2008-12-14 13:41:10 ----D---- C:\Program Files\Star Fox (V1.2)
2008-12-08 18:04:24 ----D---- C:\Program Files\Legend of Zelda, The
2008-12-08 17:46:18 ----D---- C:\Program Files\Super Mario RPG
2008-12-08 17:29:26 ----D---- C:\Program Files\Super Mario Kart
2008-12-03 19:37:47 ----D---- C:\Program Files\Super Mario World
2008-12-03 19:00:02 ----D---- C:\Documents and Settings\test\Application Data\.bsnes
2008-11-20 20:15:11 ----RHD---- C:\Documents and Settings\test\Application Data\SecuROM
2008-11-20 20:08:06 ----A---- C:\WINDOWS\system32\d3dx10_40.dll
2008-11-20 20:08:06 ----A---- C:\WINDOWS\system32\D3DCompiler_40.dll
2008-11-20 20:08:03 ----A---- C:\WINDOWS\system32\D3DX9_40.dll
2008-11-20 20:08:01 ----A---- C:\WINDOWS\system32\XAudio2_3.dll
2008-11-20 20:08:01 ----A---- C:\WINDOWS\system32\XAPOFX1_2.dll
2008-11-20 20:08:00 ----A---- C:\WINDOWS\system32\xactengine3_3.dll
2008-11-20 20:07:58 ----A---- C:\WINDOWS\system32\X3DAudio1_5.dll
2008-11-20 20:07:57 ----A---- C:\WINDOWS\system32\XAudio2_2.dll
2008-11-20 20:07:57 ----A---- C:\WINDOWS\system32\XAPOFX1_1.dll
2008-11-20 20:07:56 ----A---- C:\WINDOWS\system32\xactengine3_2.dll
2008-11-20 20:07:55 ----A---- C:\WINDOWS\system32\d3dx10_39.dll
2008-11-20 20:07:55 ----A---- C:\WINDOWS\system32\D3DCompiler_39.dll
2008-11-20 20:07:52 ----A---- C:\WINDOWS\system32\D3DX9_39.dll
2008-11-20 20:07:48 ----A---- C:\WINDOWS\system32\XAudio2_1.dll
2008-11-20 20:07:48 ----A---- C:\WINDOWS\system32\XAPOFX1_0.dll
2008-11-20 20:07:46 ----A---- C:\WINDOWS\system32\xactengine3_1.dll
2008-11-20 20:07:43 ----A---- C:\WINDOWS\system32\X3DAudio1_4.dll
2008-11-20 20:07:42 ----A---- C:\WINDOWS\system32\d3dx10_38.dll
2008-11-20 20:07:42 ----A---- C:\WINDOWS\system32\D3DCompiler_38.dll
2008-11-20 20:07:39 ----A---- C:\WINDOWS\system32\D3DX9_38.dll
2008-11-20 20:07:38 ----A---- C:\WINDOWS\system32\XAudio2_0.dll
2008-11-20 20:07:36 ----A---- C:\WINDOWS\system32\xactengine3_0.dll
2008-11-20 20:07:34 ----A---- C:\WINDOWS\system32\X3DAudio1_3.dll
2008-11-20 20:07:33 ----A---- C:\WINDOWS\system32\d3dx10_37.dll
2008-11-20 20:07:33 ----A---- C:\WINDOWS\system32\D3DCompiler_37.dll
2008-11-20 20:07:30 ----A---- C:\WINDOWS\system32\D3DX9_37.dll
2008-11-20 20:07:29 ----A---- C:\WINDOWS\system32\xactengine2_10.dll
2008-11-20 20:07:25 ----A---- C:\WINDOWS\system32\d3dx10_36.dll
2008-11-20 20:07:25 ----A---- C:\WINDOWS\system32\D3DCompiler_36.dll
2008-11-20 20:07:23 ----A---- C:\WINDOWS\system32\d3dx9_36.dll
2008-11-20 20:07:20 ----A---- C:\WINDOWS\system32\xactengine2_9.dll
2008-11-20 20:07:15 ----A---- C:\WINDOWS\system32\d3dx10_35.dll
2008-11-20 20:07:15 ----A---- C:\WINDOWS\system32\D3DCompiler_35.dll
2008-11-20 20:07:04 ----A---- C:\WINDOWS\system32\d3dx9_35.dll
2008-11-20 20:06:54 ----A---- C:\WINDOWS\system32\xactengine2_8.dll
2008-11-20 20:06:54 ----A---- C:\WINDOWS\system32\X3DAudio1_2.dll
2008-11-20 20:06:38 ----A---- C:\WINDOWS\system32\d3dx10_34.dll
2008-11-20 20:06:38 ----A---- C:\WINDOWS\system32\D3DCompiler_34.dll
2008-11-20 20:06:20 ----A---- C:\WINDOWS\system32\d3dx9_34.dll
2008-11-20 20:06:09 ----A---- C:\WINDOWS\system32\xinput1_3.dll
2008-11-20 20:05:59 ----A---- C:\WINDOWS\system32\xactengine2_7.dll
2008-11-20 20:05:49 ----A---- C:\WINDOWS\system32\d3dx10_33.dll
2008-11-20 20:05:49 ----A---- C:\WINDOWS\system32\D3DCompiler_33.dll
2008-11-20 20:05:28 ----A---- C:\WINDOWS\system32\d3dx9_33.dll
2008-11-20 20:05:25 ----A---- C:\WINDOWS\system32\xactengine2_6.dll
2008-11-20 20:05:24 ----A---- C:\WINDOWS\system32\xactengine2_5.dll
2008-11-20 20:05:22 ----A---- C:\WINDOWS\system32\d3dx9_32.dll
2008-11-20 20:05:21 ----A---- C:\WINDOWS\system32\xactengine2_4.dll
2008-11-20 20:05:20 ----A---- C:\WINDOWS\system32\x3daudio1_1.dll
2008-11-20 20:05:17 ----A---- C:\WINDOWS\system32\d3dx9_31.dll
2008-11-20 19:56:53 ----HD---- C:\WINDOWS\msdownld.tmp
2008-11-20 19:55:58 ----D---- C:\WINDOWS\Logs
2008-11-20 19:51:58 ----D---- C:\Program Files\Telltale Games
2008-11-20 16:55:46 ----D---- C:\Program Files\iPod
2008-11-20 16:55:17 ----D---- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-19 08:42:22 ----D---- C:\hegames
2008-10-15 15:44:16 ----A---- C:\not_used.txt
2008-10-15 15:30:21 ----D---- C:\Program Files\SRB2 MD2 installer interactive

======List of files/folders modified in the last 3 months======

2009-01-09 19:54:34 ----D---- C:\Program Files\Mozilla Firefox
2009-01-09 19:51:35 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-01-09 19:48:13 ----D---- C:\WINDOWS\Temp
2009-01-09 19:42:33 ----D---- C:\WINDOWS\Prefetch
2009-01-09 19:09:26 ----D---- C:\Program Files\Java
2009-01-09 19:02:59 ----SHD---- C:\WINDOWS\Installer
2009-01-09 19:02:44 ----D---- C:\WINDOWS\system32
2009-01-09 18:01:04 ----D---- C:\Program Files\Common Files
2009-01-08 22:17:10 ----D---- C:\WINDOWS\system32\CatRoot2
2009-01-08 20:28:48 ----RD---- C:\Program Files
2009-01-08 20:28:48 ----D---- C:\WINDOWS\system32\drivers
2009-01-08 20:25:33 ----D---- C:\WINDOWS
2009-01-08 14:40:27 ----SHD---- C:\WINDOWS\CSC
2009-01-07 20:12:07 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-01-07 20:10:52 ----HD---- C:\WINDOWS\inf
2009-01-01 11:03:31 ----D---- C:\tmp
2008-12-27 10:06:44 ----A---- C:\WINDOWS\ntbtlog.txt
2008-12-25 14:06:59 ----D---- C:\WINDOWS\Help
2008-12-22 22:14:34 ----D---- C:\WINDOWS\Minidump
2008-12-22 11:29:17 ----RSHDC---- C:\WINDOWS\system32\dllcache
2008-12-18 15:31:41 ----D---- C:\TOUCHE
2008-12-07 17:09:57 ----D---- C:\Documents and Settings\test\Application Data\OpenOffice.org2
2008-11-20 20:08:20 ----D---- C:\WINDOWS\system32\DirectX
2008-11-20 20:05:17 ----RSD---- C:\WINDOWS\assembly
2008-11-20 20:04:35 ----D---- C:\WINDOWS\Microsoft.NET
2008-11-20 16:57:46 ----D---- C:\Program Files\iTunes
2008-11-20 16:47:21 ----DC---- C:\WINDOWS\system32\DRVSTORE
2008-11-03 09:35:23 ----A---- C:\WINDOWS\ModemLog_3Com 56K V.90 Mini PCI Modem.txt
2008-11-02 17:02:14 ----D---- C:\WINDOWS\system32\ias
2008-10-29 17:00:15 ----A---- C:\WINDOWS\HEGAMES.INI
2008-10-26 09:12:02 ----A---- C:\WINDOWS\mafosav.INI
2008-10-16 14:13:40 ----A---- C:\WINDOWS\system32\wuweb.dll
2008-10-16 14:13:40 ----A---- C:\WINDOWS\system32\wuaueng.dll
2008-10-16 14:12:22 ----A---- C:\WINDOWS\system32\wucltui.dll
2008-10-16 14:12:20 ----A---- C:\WINDOWS\system32\wuapi.dll
2008-10-16 14:09:44 ----A---- C:\WINDOWS\system32\wups2.dll
2008-10-16 14:09:44 ----A---- C:\WINDOWS\system32\wuauclt.exe
2008-10-16 14:09:44 ----A---- C:\WINDOWS\system32\cdm.dll
2008-10-16 14:09:40 ----A---- C:\WINDOWS\system32\wucltui.dll.mui
2008-10-16 14:08:58 ----A---- C:\WINDOWS\system32\wups.dll
2008-10-16 14:07:44 ----A---- C:\WINDOWS\system32\wuapi.dll.mui
2008-10-16 14:07:14 ----A---- C:\WINDOWS\system32\wuaueng.dll.mui
2008-10-14 16:33:59 ----D---- C:\Program Files\Windows Media Player

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 DCCAM;Kodak Camera Proxy; C:\WINDOWS\system32\DRIVERS\DcCam.sys [2004-05-20 36918]
R1 P3;Intel PentiumIII Processor Driver; C:\WINDOWS\system32\DRIVERS\p3.sys [2004-08-03 42496]
R2 DCFS2K;Kodak DCFS2K Driver; C:\WINDOWS\system32\drivers\dcfs2k.sys [2004-06-02 38705]
R3 atimtai;atimtai; C:\WINDOWS\system32\DRIVERS\atimtai.sys [2001-08-17 281600]
R3 CmBatt;Microsoft AC Adapter Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2004-08-03 14080]
R3 EL556ND5;3Com 10/100 MiniPCI Ethernet Adapter Driver; C:\WINDOWS\system32\DRIVERS\EL556ND5.sys [2001-08-17 55999]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys [2008-04-17 15464]
R3 maestro;ESS Maestro 3 Audio Driver (WDM); C:\WINDOWS\system32\drivers\es198x.sys [2001-08-17 174464]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-03 20480]
R3 WDHAALBA;WDHAALBAMiniPCI Winmodem; C:\WINDOWS\system32\DRIVERS\WDHAALBA.sys [2001-08-17 701386]
S1 Exportit;Exportit; C:\WINDOWS\system32\DRIVERS\exportit.sys [2004-06-02 151985]
S1 OMCI;OMCI; \??\C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS []
S3 DcFpoint;DcFpoint; C:\WINDOWS\system32\DRIVERS\DcFpoint.sys [2004-05-20 61564]
S3 DcLps;Legacy Polling Service; C:\WINDOWS\system32\DRIVERS\DcLps.sys [2004-05-20 8022]
S3 DcPTP;dcptp; C:\WINDOWS\system32\DRIVERS\DcPTP.sys [2004-05-20 68950]
S3 FANTOM;LEGO MINDSTORMS NXT Driver; C:\WINDOWS\system32\DRIVERS\fantom.sys [2006-03-10 39424]
S3 gmer;gmer; C:\WINDOWS\System32\DRIVERS\gmer.sys [2009-01-07 85969]
S3 sermouse;Serial Mouse Driver; C:\WINDOWS\system32\DRIVERS\sermouse.sys [2001-08-17 17664]
S3 SWLD23;Netopia 802.11b WLAN Cardbus Card; C:\WINDOWS\system32\DRIVERS\swld23.sys [2004-01-15 68224]
S3 USB_RNDIS_XP;Westell WireSpeed Dual Connect Modem; C:\WINDOWS\system32\DRIVERS\usb8023.sys [2004-08-03 12672]
S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys [2008-10-01 32000]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-10-01 116040]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Atievxx.exe [2001-08-17 37376]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-08-29 238888]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-01-09 152984]
R2 KodakCCS;Kodak Camera Connection Software; C:\WINDOWS\system32\drivers\KodakCCS.exe [2004-05-24 322104]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2008-10-01 536872]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-04-13 33632]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-04-13 68952]

-----------------EOF-----------------

#10 fenzodahl512

fenzodahl512

  • Members
  • 6,738 posts
  • OFFLINE
  •  
  • Local time:07:04 PM

Posted 10 January 2009 - 04:08 PM

Please run a free online scan with the ESET Online Scanner
Note: You will need to use Internet Explorer for this scan.
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  • Click Scan
    Wait for the scan to finish
  • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic

Keep calm, make it simple, use your brain, don't freak out, and you'll be just fine..
Awesomeness: When I get sad, I stop being sad and be awesome instead.. True story - Barney Stinson
Posted Image Posted Image
Its gonna be legen.. wait for it.. dary! Cherish the pain, it means you're still alive


#11 hartsisk

hartsisk
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:03:04 AM

Posted 10 January 2009 - 06:30 PM

EsetOnlineScanner log.txt:

# version=4
# OnlineScanner.ocx=1.0.0.56
# OnlineScannerDLLA.dll=1, 0, 0, 51
# OnlineScannerDLLW.dll=1, 0, 0, 51
# OnlineScannerUninstaller.exe=1, 0, 0, 49
# vers_standard_module=3756 (20090110)
# vers_arch_module=1.064 (20080214)
# vers_adv_heur_module=1.064 (20070717)
# EOSSerial=f92116614369594ca4f387986da5004d
# end=finished
# remove_checked=true
# unwanted_checked=true
# utc_time=2009-01-10 11:11:31
# local_time=2009-01-10 03:11:31 (-0800, Pacific Standard Time)
# country="United States"
# osver=5.1.2600 NT Service Pack 2
# scanned=228832
# found=2
# scan_time=2764
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde.zip Win32/Bagle.gen.zip worm (unable to clean - deleted) 00000000000000000000000000000000
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondeprx6.zip Win32/Bagle.gen.zip worm (unable to clean - deleted) 00000000000000000000000000000000

#12 fenzodahl512

fenzodahl512

  • Members
  • 6,738 posts
  • OFFLINE
  •  
  • Local time:07:04 PM

Posted 11 January 2009 - 12:21 AM

Looks good to me.. Lets do some cleanup...


Please download OTCleanIt and save it to Desktop.
  • Make sure you have internet connection..
  • Double-click OTCleanIt.exe
  • Click the CleanUp! button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes



Please read these excellent articles by miekiemoes :
Help! My computer is slow!
How to prevent Malware

Please reply to this thread once more and tell us about the computer behaviour before we can close this thread :thumbsup:



Have a safe and happy computing day!


Regards
fenzodahl512

Keep calm, make it simple, use your brain, don't freak out, and you'll be just fine..
Awesomeness: When I get sad, I stop being sad and be awesome instead.. True story - Barney Stinson
Posted Image Posted Image
Its gonna be legen.. wait for it.. dary! Cherish the pain, it means you're still alive


#13 hartsisk

hartsisk
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:03:04 AM

Posted 11 January 2009 - 01:02 PM

Thanks for your help fenzodahl512,
I ran OTCleanIt, the bad registry entries are gone, no more "rundll32.exe" message on startup.
I do see that the file entries EsetOnlineScanner found: "C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondeprx6.zip Win32/Bagle.gen.zip worm (unable to clean - deleted) 00000000000000000000000000000000" are still there(under that file path). Is this a problem? Should they be deleted?
DS

#14 hartsisk

hartsisk
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:03:04 AM

Posted 11 January 2009 - 01:09 PM

Also, I forgot to add I seem to no longer have my MS antivirus program, (not detected in security center) it seems to have disappeared during all this. Any thoughts?

#15 fenzodahl512

fenzodahl512

  • Members
  • 6,738 posts
  • OFFLINE
  •  
  • Local time:07:04 PM

Posted 12 January 2009 - 01:58 AM

"C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondeprx6.zip Win32/Bagle.gen.zip worm (unable to clean - deleted) 00000000000000000000000000000000" are still there(under that file path). Is this a problem? Should they be deleted?



Yup.. in fact, delete everything that you see under that Recovery folder..


Your computer is good to go now :thumbsup:

Anymore question? :)

Keep calm, make it simple, use your brain, don't freak out, and you'll be just fine..
Awesomeness: When I get sad, I stop being sad and be awesome instead.. True story - Barney Stinson
Posted Image Posted Image
Its gonna be legen.. wait for it.. dary! Cherish the pain, it means you're still alive





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users