Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected with Win32/Sality


  • This topic is locked This topic is locked
3 replies to this topic

#1 kaytees

kaytees

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:06:55 AM

Posted 05 February 2009 - 12:59 AM

Dear Friends..
It seems i have been infected with win32/sality virus. No matter how hard i try, i m not able to remove it from my computer. My taskmanager, regedit, safemode etc are all disabled. I tried rmsality but it did not detect the virus but no use.

I reinstalled windows but of no use. it again reappears....pls save my computer. i do not want to completely fromat it.

pls. find below the HijackThis log..and other ifo thru RSIT...
Logfile of random's system information tool 1.05 (written by random/random)
Run by Administrator at 2009-02-05 11:06:52
Microsoft Windows XP Professional Service Pack 2
System drive C: has 12 GB (58%) free of 20 GB
Total RAM: 1278 MB (67% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:06:56 AM, on 2/5/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\XP-C2A92E4C.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Registry Mechanic\RegMech.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Administrator\Desktop\RSIT.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\trend micro\Administrator.exe

F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [XP-C2A92E4C] C:\WINDOWS\system32\XP-C2A92E4C.EXE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [kamsoft] C:\WINDOWS\system32\ckvo.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /H
O4 - Startup:    .lnk = C:\WINDOWS\system32\XP-C2A92E4C.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

--
End of file - 3579 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"XP-C2A92E4C"=C:\WINDOWS\system32\XP-C2A92E4C.EXE [2009-02-04 1297523]
"McAfeeUpdaterUI"=C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe [2003-09-10 135251]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2006-11-17 651264]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2004-01-16 155648]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2004-01-16 118784]
"ShStatEXE"=C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE /STANDALONE []
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2007-05-11 113776]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe []
"RemoteControl"=C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2003-12-08 32768]
"ISTray"=C:\Program Files\Spyware Doctor\pctsTray.exe [2008-08-25 1168264]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"kamsoft"=C:\WINDOWS\system32\ckvo.exe []
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360]
"RegistryMechanic"=C:\Program Files\Registry Mechanic\RegMech.exe [2008-07-08 2828184]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE

C:\Documents and Settings\Administrator\Start Menu\Programs\Startup
   .lnk - C:\WINDOWS\system32\XP-C2A92E4C.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxsrvc.dll [2004-01-16 335872]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=1
"DisableRegistryTools"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLUA"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\download.exe"="D:\download.exe:*:Enabled:ipsec"
"C:\WINDOWS\Explorer.EXE"="C:\WINDOWS\Explorer.EXE:*:Enabled:ipsec"
"C:\WINDOWS\system32\XP-C2A92E4C.EXE"="C:\WINDOWS\system32\XP-C2A92E4C.EXE:*:Enabled:ipsec"
"C:\WINDOWS\system32\userinit.exe"="C:\WINDOWS\system32\userinit.exe:*:Enabled:ipsec"
"C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe"="C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe:*:Enabled:ipsec"
"C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE"="C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE:*:Enabled:ipsec"
"C:\WINDOWS\SOUNDMAN.EXE"="C:\WINDOWS\SOUNDMAN.EXE:*:Enabled:ipsec"
"C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\plunmb.exe"="C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\plunmb.exe:*:Enabled:ipsec"
"C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nrrcwi.exe"="C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nrrcwi.exe:*:Enabled:ipsec"
"C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jath.exe"="C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jath.exe:*:Enabled:ipsec"
"C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\winuxgm.exe"="C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\winuxgm.exe:*:Enabled:ipsec"
"C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rcav.exe"="C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rcav.exe:*:Enabled:ipsec"
"C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\winbrcoyd.exe"="C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\winbrcoyd.exe:*:Enabled:ipsec"
"C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\wrycm.exe"="C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\wrycm.exe:*:Enabled:ipsec"
"C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\winojwvm.exe"="C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\winojwvm.exe:*:Enabled:ipsec"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{83583dbe-f283-11dd-9aca-9194fa243c7a}]
shell\1\command - I:\Recycled.exe
shell\AutoRun\command - I:\Recycled.exe


======List of files/folders created in the last 1 months======

2009-02-04 16:32:54 ----D---- C:\Program Files\trend micro
2009-02-04 16:32:27 ----D---- C:\rsit
2009-02-04 14:53:38 ----D---- C:\Documents and Settings\All Users\Application Data\TEMP
2009-02-04 14:53:19 ----D---- C:\Program Files\Spyware Doctor
2009-02-04 14:53:19 ----D---- C:\Documents and Settings\Administrator\Application Data\PC Tools
2009-02-04 14:53:18 ----A---- C:\WINDOWS\system32\STKIT432.DLL
2009-02-04 14:53:15 ----D---- C:\Program Files\Registry Mechanic
2009-02-04 14:26:46 ----RSH---- C:\WINDOWS\system32\XP-C2A92E4C.EXE
2009-02-04 13:32:48 ----SHD---- C:\FOUND.000
2009-02-04 11:58:36 ----A---- C:\WINDOWS\NeroDigital.ini
2009-02-04 11:45:43 ----A---- C:\WINDOWS\system32\TwnLib20.dll
2009-02-04 11:45:41 ----N---- C:\WINDOWS\system32\ImagXRA7.dll
2009-02-04 11:45:41 ----N---- C:\WINDOWS\system32\ImagXR7.dll
2009-02-04 11:45:41 ----N---- C:\WINDOWS\system32\ImagXpr7.dll
2009-02-04 11:45:41 ----N---- C:\WINDOWS\system32\ImagX7.dll
2009-02-04 11:45:41 ----D---- C:\Program Files\Common Files\Ahead
2009-02-04 11:39:02 ----A---- C:\WINDOWS\ODBC.INI
2009-02-04 11:38:18 ----D---- C:\Program Files\Microsoft ActiveSync
2009-02-04 11:37:32 ----D---- C:\Program Files\Microsoft Visual Studio
2009-02-04 11:37:31 ----D---- C:\Program Files\Common Files\Designer
2009-02-03 20:23:47 ----D---- C:\Program Files\Common Files\Network Associates
2009-02-03 20:22:01 ----D---- C:\WINDOWS\system32\appmgmt
2009-02-03 20:14:37 ----D---- C:\tool3
2009-02-03 20:06:47 ----D---- C:\Config.Msi
2009-02-03 19:52:19 ----D---- C:\tool2
2009-02-03 19:34:49 ----D---- C:\WINDOWS\Minidump
2009-02-03 19:21:24 ----D---- C:\Documents and Settings\All Users\Application Data\CyberLink
2009-02-03 19:21:17 ----D---- C:\Program Files\CyberLink
2009-02-03 19:20:15 ----D---- C:\Documents and Settings\Administrator\Application Data\Adobe
2009-02-03 19:19:00 ----D---- C:\Program Files\Winamp
2009-02-03 19:17:51 ----D---- C:\Program Files\Ahead
2009-02-03 19:14:06 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2009-02-03 19:13:58 ----D---- C:\Program Files\Common Files\Adobe
2009-02-03 19:13:58 ----D---- C:\Program Files\Adobe
2009-02-03 19:09:53 ----D---- C:\WINDOWS\ShellNew
2009-02-03 19:09:51 ----D---- C:\Program Files\Common Files\L&H
2009-02-03 19:09:40 ----D---- C:\Program Files\Microsoft Office
2009-02-03 19:00:23 ----A---- C:\WINDOWS\system32\igfxres.dll
2009-02-03 18:59:18 ----D---- C:\WINDOWS\system32\ReinstallBackups
2009-02-03 18:59:09 ----A---- C:\WINDOWS\system32\igfxzoom.exe
2009-02-03 18:59:05 ----A---- C:\WINDOWS\system32\igfxress.dll
2009-02-03 18:58:54 ----A---- C:\WINDOWS\system32\iAlmCoIn_v3751.dll
2009-02-03 18:57:54 ----A---- C:\WINDOWS\IsUninst.exe
2009-02-03 18:50:26 ----A---- C:\WINDOWS\system32\igfxtray.exe
2009-02-03 18:46:00 ----A---- C:\WINDOWS\system32\igfxsrvc.dll
2009-02-03 18:45:22 ----RA---- C:\WINDOWS\system32\iAlmCoIn_v13.dll
2009-02-03 18:45:22 ----A---- C:\WINDOWS\system32\igfxexps.dll
2009-02-03 18:45:21 ----A---- C:\WINDOWS\system32\igfxpph.dll
2009-02-03 18:45:21 ----A---- C:\WINDOWS\system32\igfxhk.dll
2009-02-03 18:45:21 ----A---- C:\WINDOWS\system32\igfxext.exe
2009-02-03 18:45:21 ----A---- C:\WINDOWS\system32\igfxeud.dll
2009-02-03 18:45:21 ----A---- C:\WINDOWS\system32\igfxdo.dll
2009-02-03 18:45:21 ----A---- C:\WINDOWS\system32\igfxdiag.exe
2009-02-03 18:45:21 ----A---- C:\WINDOWS\system32\igfxdgps.dll
2009-02-03 18:45:21 ----A---- C:\WINDOWS\system32\igfxdev.dll
2009-02-03 18:45:21 ----A---- C:\WINDOWS\system32\igfxcfg.exe
2009-02-03 18:45:21 ----A---- C:\WINDOWS\system32\ialmrnt5.dll
2009-02-03 18:45:21 ----A---- C:\WINDOWS\system32\ialmrem.dll
2009-02-03 18:45:21 ----A---- C:\WINDOWS\system32\ialmgicd.dll
2009-02-03 18:45:21 ----A---- C:\WINDOWS\system32\ialmgdev.dll
2009-02-03 18:45:21 ----A---- C:\WINDOWS\system32\ialmdnt5.dll
2009-02-03 18:45:21 ----A---- C:\WINDOWS\system32\ialmdev5.dll
2009-02-03 18:45:21 ----A---- C:\WINDOWS\system32\ialmdd5.dll
2009-02-03 18:45:21 ----A---- C:\WINDOWS\system32\hkcmd.exe
2009-02-03 18:45:21 ----A---- C:\WINDOWS\system32\hccutils.dll
2009-02-03 18:44:14 ----D---- C:\WINDOWS\Drivers
2009-02-03 18:38:05 ----D---- C:\Program Files\Intel
2009-02-03 18:37:55 ----D---- C:\Intel
2009-02-03 18:36:03 ----A---- C:\WINDOWS\system32\ChCfg.exe
2009-02-03 18:35:31 ----A---- C:\WINDOWS\system32\ksuser.dll
2009-02-03 18:35:16 ----D---- C:\Program Files\Realtek AC97
2009-02-03 18:35:14 ----A---- C:\WINDOWS\system32\RTLCPL.exe
2009-02-03 18:35:12 ----HD---- C:\Program Files\InstallShield Installation Information
2009-02-03 18:35:12 ----A---- C:\WINDOWS\system32\RtlCPAPI.dll
2009-02-03 18:35:12 ----A---- C:\WINDOWS\soundman.exe
2009-02-03 18:35:12 ----A---- C:\WINDOWS\alcupd.exe
2009-02-03 18:35:12 ----A---- C:\WINDOWS\Alcrmv.exe
2009-02-03 18:34:55 ----D---- C:\Program Files\Common Files\InstallShield
2009-02-02 19:06:59 ----D---- C:\QUARANTINE
2009-02-02 18:38:18 ----SHD---- C:\Recycled
2009-02-02 18:34:56 ----D---- C:\Documents and Settings\All Users\Application Data\Network Associates
2009-02-02 18:34:43 ----D---- C:\Program Files\Network Associates
2009-02-02 18:25:12 ----D---- C:\Program Files\ADSL Router
2009-02-02 18:25:00 ----SH---- C:\WINDOWS\system32\ul.dll
2009-02-02 18:25:00 ----ASH---- C:\WINDOWS\system32\og.dll
2009-02-02 18:24:50 ----RSH---- C:\WINDOWS\system32\ckvo0.dll
2009-02-02 18:13:06 ----D---- C:\Documents and Settings\Administrator\Application Data\Identities
2009-02-02 18:13:04 ----HD---- C:\Program Files\Uninstall Information
2009-02-02 18:12:56 ----ASH---- C:\Documents and Settings\Administrator\Application Data\desktop.ini
2009-02-02 18:12:55 ----SD---- C:\Documents and Settings\Administrator\Application Data\Microsoft
2009-02-02 18:12:47 ----SHD---- C:\System Volume Information
2009-02-02 18:12:45 ----D---- C:\WINDOWS\SoftwareDistribution
2009-02-02 18:12:44 ----D---- C:\WINDOWS\Prefetch
2009-02-02 18:12:43 ----SD---- C:\WINDOWS\system32\Microsoft
2009-02-02 18:12:43 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-02-02 18:06:50 ----D---- C:\WINDOWS\system32\xircom
2009-02-02 18:06:50 ----D---- C:\Program Files\xerox
2009-02-02 18:06:50 ----D---- C:\Program Files\microsoft frontpage
2009-02-02 18:06:13 ----A---- C:\WINDOWS\control.ini
2009-02-02 18:06:13 ----A---- C:\AUTOEXEC.BAT
2009-02-02 18:05:56 ----A---- C:\WINDOWS\OEWABLog.txt
2009-02-02 18:05:51 ----A---- C:\WINDOWS\system32\mapi32.dll
2009-02-02 18:04:43 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-02-02 18:04:43 ----RD---- C:\WINDOWS\Offline Web Pages
2009-02-02 18:04:43 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest
2009-02-02 18:04:35 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest
2009-02-02 18:04:30 ----HD---- C:\Program Files\WindowsUpdate
2009-02-02 18:04:10 ----D---- C:\WINDOWS\system32\DirectX
2009-02-02 18:03:48 ----A---- C:\WINDOWS\system32\atrace.dll
2009-02-02 18:03:46 ----A---- C:\WINDOWS\system32\desktop.ini
2009-02-02 18:03:46 ----A---- C:\WINDOWS\desktop.ini
2009-02-02 18:03:39 ----A---- C:\WINDOWS\system32\nmevtmsg.dll
2009-02-02 18:03:38 ----D---- C:\Program Files\Common Files\Services
2009-02-02 18:03:38 ----A---- C:\WINDOWS\system32\acctres.dll
2009-02-02 18:03:35 ----SD---- C:\WINDOWS\Tasks
2009-02-02 18:03:35 ----A---- C:\WINDOWS\system32\icfgnt5.dll
2009-02-02 18:03:33 ----D---- C:\Program Files\Common Files\MSSoap
2009-02-02 18:03:30 ----D---- C:\WINDOWS\srchasst
2009-02-02 18:03:29 ----D---- C:\WINDOWS\system32\Macromed
2009-02-02 18:03:26 ----A---- C:\WINDOWS\system32\wuweb.dll
2009-02-02 18:03:26 ----A---- C:\WINDOWS\system32\wucltui.dll
2009-02-02 18:03:26 ----A---- C:\WINDOWS\system32\wuauserv.dll
2009-02-02 18:03:26 ----A---- C:\WINDOWS\system32\wuaueng1.dll
2009-02-02 18:03:25 ----A---- C:\WINDOWS\system32\wups.dll
2009-02-02 18:03:25 ----A---- C:\WINDOWS\system32\wuaueng.dll
2009-02-02 18:03:25 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2009-02-02 18:03:25 ----A---- C:\WINDOWS\system32\wuauclt.exe
2009-02-02 18:03:25 ----A---- C:\WINDOWS\system32\wuapi.dll
2009-02-02 18:03:25 ----A---- C:\WINDOWS\system32\bitsprx3.dll
2009-02-02 18:03:25 ----A---- C:\WINDOWS\system32\bitsprx2.dll
2009-02-02 18:03:24 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
2009-02-02 18:03:24 ----A---- C:\WINDOWS\system32\qmgr.dll
2009-02-02 18:03:20 ----D---- C:\Program Files\Movie Maker
2009-02-02 18:03:16 ----A---- C:\WINDOWS\system32\safrslv.dll
2009-02-02 18:03:16 ----A---- C:\WINDOWS\system32\safrdm.dll
2009-02-02 18:03:16 ----A---- C:\WINDOWS\system32\safrcdlg.dll
2009-02-02 18:03:16 ----A---- C:\WINDOWS\system32\racpldlg.dll
2009-02-02 18:03:13 ----A---- C:\WINDOWS\system32\fltMc.exe
2009-02-02 18:03:13 ----A---- C:\WINDOWS\system32\fltlib.dll
2009-02-02 18:03:12 ----D---- C:\WINDOWS\system32\Restore
2009-02-02 18:03:12 ----A---- C:\WINDOWS\system32\srsvc.dll
2009-02-02 18:03:12 ----A---- C:\WINDOWS\system32\srrstr.dll
2009-02-02 18:03:12 ----A---- C:\WINDOWS\system32\srclient.dll
2009-02-02 18:03:11 ----A---- C:\WINDOWS\system32\nmmkcert.dll
2009-02-02 18:03:11 ----A---- C:\WINDOWS\system32\msconf.dll
2009-02-02 18:03:11 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2009-02-02 18:03:11 ----A---- C:\WINDOWS\system32\mnmdd.dll
2009-02-02 18:03:11 ----A---- C:\WINDOWS\system32\isrdbg32.dll
2009-02-02 18:03:11 ----A---- C:\WINDOWS\system32\ils.dll
2009-02-02 18:03:08 ----D---- C:\Program Files\NetMeeting
2009-02-02 18:03:08 ----A---- C:\WINDOWS\system32\msoert2.dll
2009-02-02 18:03:08 ----A---- C:\WINDOWS\system32\msoeacct.dll
2009-02-02 18:03:07 ----A---- C:\WINDOWS\system32\inetres.dll
2009-02-02 18:03:07 ----A---- C:\WINDOWS\system32\inetcomm.dll
2009-02-02 18:03:06 ----D---- C:\Program Files\Outlook Express
2009-02-02 18:03:06 ----A---- C:\WINDOWS\system32\schedsvc.dll
2009-02-02 18:03:06 ----A---- C:\WINDOWS\system32\mstinit.exe
2009-02-02 18:03:06 ----A---- C:\WINDOWS\system32\mstask.dll
2009-02-02 18:03:05 ----A---- C:\WINDOWS\system32\isign32.dll
2009-02-02 18:03:05 ----A---- C:\WINDOWS\system32\inetcfg.dll
2009-02-02 18:03:05 ----A---- C:\WINDOWS\system32\icwphbk.dll
2009-02-02 18:03:05 ----A---- C:\WINDOWS\system32\icwdial.dll
2009-02-02 18:02:59 ----D---- C:\Program Files\Common Files\System
2009-02-02 18:02:54 ----D---- C:\Program Files\Internet Explorer
2009-02-02 18:02:05 ----D---- C:\Program Files\ComPlus Applications
2009-02-02 18:02:02 ----A---- C:\WINDOWS\vbaddin.ini
2009-02-02 18:02:02 ----A---- C:\WINDOWS\vb.ini
2009-02-02 18:01:57 ----D---- C:\WINDOWS\Registration
2009-02-02 18:01:50 ----D---- C:\Program Files\Online Services
2009-02-02 18:01:49 ----D---- C:\Program Files\Windows Media Player
2009-02-02 18:01:42 ----D---- C:\Program Files\Messenger
2009-02-02 18:01:39 ----D---- C:\Program Files\MSN Gaming Zone
2009-02-02 18:01:38 ----A---- C:\WINDOWS\system32\write.exe
2009-02-02 18:01:29 ----A---- C:\WINDOWS\system32\sndvol32.exe
2009-02-02 18:01:29 ----A---- C:\WINDOWS\system32\hticons.dll
2009-02-02 18:01:28 ----A---- C:\WINDOWS\system32\winchat.exe
2009-02-02 18:01:28 ----A---- C:\WINDOWS\system32\avwav.dll
2009-02-02 18:01:28 ----A---- C:\WINDOWS\system32\avtapi.dll
2009-02-02 18:01:28 ----A---- C:\WINDOWS\system32\avmeter.dll
2009-02-02 18:01:21 ----A---- C:\WINDOWS\system32\getuname.dll
2009-02-02 18:01:21 ----A---- C:\WINDOWS\system32\charmap.exe
2009-02-02 18:01:21 ----A---- C:\WINDOWS\system32\calc.exe
2009-02-02 18:01:20 ----A---- C:\WINDOWS\system32\winmine.exe
2009-02-02 18:01:20 ----A---- C:\WINDOWS\system32\sol.exe
2009-02-02 18:01:20 ----A---- C:\WINDOWS\system32\reset.exe
2009-02-02 18:01:20 ----A---- C:\WINDOWS\system32\mshearts.exe
2009-02-02 18:01:20 ----A---- C:\WINDOWS\system32\freecell.exe
2009-02-02 18:01:19 ----A---- C:\WINDOWS\system32\usrlogon.cmd
2009-02-02 18:01:19 ----A---- C:\WINDOWS\system32\tsshutdn.exe
2009-02-02 18:01:19 ----A---- C:\WINDOWS\system32\tslabels.ini
2009-02-02 18:01:19 ----A---- C:\WINDOWS\system32\tskill.exe
2009-02-02 18:01:19 ----A---- C:\WINDOWS\system32\tsdiscon.exe
2009-02-02 18:01:19 ----A---- C:\WINDOWS\system32\tscon.exe
2009-02-02 18:01:19 ----A---- C:\WINDOWS\system32\shadow.exe
2009-02-02 18:01:19 ----A---- C:\WINDOWS\system32\rwinsta.exe
2009-02-02 18:01:19 ----A---- C:\WINDOWS\system32\regini.exe
2009-02-02 18:01:19 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
2009-02-02 18:01:19 ----A---- C:\WINDOWS\system32\qwinsta.exe
2009-02-02 18:01:19 ----A---- C:\WINDOWS\system32\qappsrv.exe
2009-02-02 18:01:19 ----A---- C:\WINDOWS\system32\msg.exe
2009-02-02 18:01:19 ----A---- C:\WINDOWS\system32\logoff.exe
2009-02-02 18:01:18 ----A---- C:\WINDOWS\system32\msdtcprf.ini
2009-02-02 18:01:18 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2009-02-02 18:01:18 ----A---- C:\WINDOWS\system32\cdmodem.dll
2009-02-02 18:01:17 ----A---- C:\WINDOWS\system32\stclient.dll
2009-02-02 18:01:17 ----A---- C:\WINDOWS\system32\mtxlegih.dll
2009-02-02 18:01:17 ----A---- C:\WINDOWS\system32\mtxex.dll
2009-02-02 18:01:17 ----A---- C:\WINDOWS\system32\mtxdm.dll
2009-02-02 18:01:17 ----A---- C:\WINDOWS\system32\comsnap.dll
2009-02-02 18:01:17 ----A---- C:\WINDOWS\system32\comrepl.dll
2009-02-02 18:01:17 ----A---- C:\WINDOWS\system32\comaddin.dll
2009-02-02 18:01:11 ----A---- C:\WINDOWS\system32\wmimgmt.msc
2009-02-02 18:01:01 ----D---- C:\Program Files\MSN
2009-02-02 18:01:00 ----A---- C:\WINDOWS\system32\sndrec32.exe
2009-02-02 18:01:00 ----A---- C:\WINDOWS\system32\accwiz.exe
2009-02-02 18:00:59 ----D---- C:\Program Files\Windows NT
2009-02-02 18:00:59 ----A---- C:\WINDOWS\system32\mspaint.exe
2009-02-02 18:00:59 ----A---- C:\WINDOWS\system32\mplay32.exe
2009-02-02 18:00:59 ----A---- C:\WINDOWS\system32\hypertrm.dll
2009-02-02 18:00:59 ----A---- C:\WINDOWS\system32\clipbrd.exe
2009-02-02 18:00:58 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
2009-02-02 18:00:58 ----A---- C:\WINDOWS\system32\spider.exe
2009-02-02 18:00:58 ----A---- C:\WINDOWS\system32\mstscax.dll
2009-02-02 18:00:57 ----A---- C:\WINDOWS\system32\tscupgrd.exe
2009-02-02 18:00:57 ----A---- C:\WINDOWS\system32\termsrv.dll
2009-02-02 18:00:57 ----A---- C:\WINDOWS\system32\sessmgr.exe
2009-02-02 18:00:57 ----A---- C:\WINDOWS\system32\remotepg.dll
2009-02-02 18:00:57 ----A---- C:\WINDOWS\system32\rdshost.exe
2009-02-02 18:00:57 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2009-02-02 18:00:57 ----A---- C:\WINDOWS\system32\rdpwsx.dll
2009-02-02 18:00:57 ----A---- C:\WINDOWS\system32\rdpsnd.dll
2009-02-02 18:00:57 ----A---- C:\WINDOWS\system32\rdpclip.exe
2009-02-02 18:00:57 ----A---- C:\WINDOWS\system32\rdchost.dll
2009-02-02 18:00:57 ----A---- C:\WINDOWS\system32\mstsc.exe
2009-02-02 18:00:56 ----A---- C:\WINDOWS\system32\qprocess.exe
2009-02-02 18:00:55 ----D---- C:\WINDOWS\system32\MsDtc
2009-02-02 18:00:55 ----A---- C:\WINDOWS\system32\mtxoci.dll
2009-02-02 18:00:55 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
2009-02-02 18:00:55 ----A---- C:\WINDOWS\system32\msdtcprx.dll
2009-02-02 18:00:55 ----A---- C:\WINDOWS\system32\icaapi.dll
2009-02-02 18:00:55 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2009-02-02 18:00:54 ----A---- C:\WINDOWS\system32\xolehlp.dll
2009-02-02 18:00:54 ----A---- C:\WINDOWS\system32\msdtctm.dll
2009-02-02 18:00:54 ----A---- C:\WINDOWS\system32\msdtclog.dll
2009-02-02 18:00:54 ----A---- C:\WINDOWS\system32\msdtc.exe
2009-02-02 18:00:53 ----D---- C:\WINDOWS\system32\Com
2009-02-02 18:00:53 ----A---- C:\WINDOWS\system32\comsvcs.dll
2009-02-02 18:00:53 ----A---- C:\WINDOWS\system32\colbact.dll
2009-02-02 18:00:53 ----A---- C:\WINDOWS\system32\clbcatex.dll
2009-02-02 18:00:53 ----A---- C:\WINDOWS\system32\catsrvut.dll
2009-02-02 18:00:53 ----A---- C:\WINDOWS\system32\catsrvps.dll
2009-02-02 18:00:53 ----A---- C:\WINDOWS\system32\catsrv.dll
2009-02-02 18:00:52 ----A---- C:\WINDOWS\system32\comuid.dll
2009-02-02 18:00:52 ----A---- C:\WINDOWS\system32\clbcatq.dll
2009-02-02 18:00:47 ----A---- C:\WINDOWS\system32\servdeps.dll
2009-02-02 18:00:46 ----A---- C:\WINDOWS\system32\mmfutil.dll
2009-02-02 18:00:46 ----A---- C:\WINDOWS\system32\licwmi.dll
2009-02-02 18:00:46 ----A---- C:\WINDOWS\system32\cmprops.dll
2009-02-02 17:59:20 ----A---- C:\WINDOWS\system32\h323log.txt
2009-02-02 17:57:35 ----A---- C:\WINDOWS\system32\usbui.dll
2009-02-02 17:56:28 ----SHD---- C:\WINDOWS\Installer
2009-02-02 17:56:28 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-02-02 17:56:27 ----D---- C:\Program Files\Common Files\ODBC
2009-02-02 17:56:27 ----A---- C:\WINDOWS\ODBCINST.INI
2009-02-02 17:56:23 ----RD---- C:\Program Files
2009-02-02 17:56:23 ----D---- C:\Program Files\Common Files\SpeechEngines
2009-02-02 17:56:23 ----D---- C:\Program Files\Common Files\Microsoft Shared
2009-02-02 17:56:23 ----D---- C:\Program Files\Common Files
2009-02-02 17:56:20 ----RA---- C:\WINDOWS\system32\kbdtuq.dll
2009-02-02 17:56:20 ----RA---- C:\WINDOWS\system32\kbdtuf.dll
2009-02-02 17:56:20 ----RA---- C:\WINDOWS\system32\kbdazel.dll
2009-02-02 17:56:19 ----RA---- C:\WINDOWS\system32\kbdmon.dll
2009-02-02 17:56:19 ----RA---- C:\WINDOWS\system32\kbdkyr.dll
2009-02-02 17:56:18 ----RA---- C:\WINDOWS\system32\kbdycc.dll
2009-02-02 17:56:18 ----RA---- C:\WINDOWS\system32\kbduzb.dll
2009-02-02 17:56:18 ----RA---- C:\WINDOWS\system32\kbdur.dll
2009-02-02 17:56:18 ----RA---- C:\WINDOWS\system32\kbdtat.dll
2009-02-02 17:56:18 ----RA---- C:\WINDOWS\system32\kbdru1.dll
2009-02-02 17:56:18 ----RA---- C:\WINDOWS\system32\kbdru.dll
2009-02-02 17:56:18 ----RA---- C:\WINDOWS\system32\kbdkaz.dll
2009-02-02 17:56:18 ----RA---- C:\WINDOWS\system32\kbdbu.dll
2009-02-02 17:56:18 ----RA---- C:\WINDOWS\system32\kbdblr.dll
2009-02-02 17:56:18 ----RA---- C:\WINDOWS\system32\kbdaze.dll
2009-02-02 17:56:17 ----RA---- C:\WINDOWS\system32\kbdhept.dll
2009-02-02 17:56:17 ----RA---- C:\WINDOWS\system32\kbdhela3.dll
2009-02-02 17:56:17 ----RA---- C:\WINDOWS\system32\kbdhela2.dll
2009-02-02 17:56:17 ----RA---- C:\WINDOWS\system32\kbdhe319.dll
2009-02-02 17:56:17 ----RA---- C:\WINDOWS\system32\kbdhe220.dll
2009-02-02 17:56:17 ----RA---- C:\WINDOWS\system32\kbdhe.dll
2009-02-02 17:56:17 ----RA---- C:\WINDOWS\system32\kbdgkl.dll
2009-02-02 17:56:15 ----RA---- C:\WINDOWS\system32\kbdlv1.dll
2009-02-02 17:56:15 ----RA---- C:\WINDOWS\system32\kbdlv.dll
2009-02-02 17:56:15 ----RA---- C:\WINDOWS\system32\kbdlt1.dll
2009-02-02 17:56:15 ----RA---- C:\WINDOWS\system32\kbdlt.dll
2009-02-02 17:56:15 ----RA---- C:\WINDOWS\system32\kbdest.dll
2009-02-02 17:56:13 ----RA---- C:\WINDOWS\system32\kbdycl.dll
2009-02-02 17:56:13 ----RA---- C:\WINDOWS\system32\kbdsl1.dll
2009-02-02 17:56:13 ----RA---- C:\WINDOWS\system32\kbdsl.dll
2009-02-02 17:56:13 ----RA---- C:\WINDOWS\system32\kbdro.dll
2009-02-02 17:56:13 ----RA---- C:\WINDOWS\system32\kbdpl1.dll
2009-02-02 17:56:13 ----RA---- C:\WINDOWS\system32\kbdpl.dll
2009-02-02 17:56:13 ----RA---- C:\WINDOWS\system32\kbdhu1.dll
2009-02-02 17:56:13 ----RA---- C:\WINDOWS\system32\kbdhu.dll
2009-02-02 17:56:13 ----RA---- C:\WINDOWS\system32\kbdcz2.dll
2009-02-02 17:56:13 ----RA---- C:\WINDOWS\system32\kbdcz1.dll
2009-02-02 17:56:13 ----RA---- C:\WINDOWS\system32\kbdcz.dll
2009-02-02 17:56:13 ----RA---- C:\WINDOWS\system32\kbdcr.dll
2009-02-02 17:56:13 ----RA---- C:\WINDOWS\system32\KBDAL.DLL
2009-02-02 17:56:11 ----A---- C:\WINDOWS\system32\spxcoins.dll
2009-02-02 17:56:11 ----A---- C:\WINDOWS\system32\irclass.dll
2009-02-02 17:56:11 ----A---- C:\WINDOWS\system32\dgsetup.dll
2009-02-02 17:56:11 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
2009-02-02 17:56:10 ----A---- C:\WINDOWS\system32\EqnClass.Dll
2009-02-02 17:56:08 ----N---- C:\WINDOWS\system32\CONFIG.TMP
2009-02-02 17:56:08 ----A---- C:\WINDOWS\TASKMAN.EXE
2009-02-02 17:56:08 ----A---- C:\WINDOWS\system32\batt.dll
2009-02-02 17:56:07 ----A---- C:\WINDOWS\NOTEPAD.EXE
2009-02-02 17:56:06 ----A---- C:\WINDOWS\system32\storprop.dll
2009-02-02 17:55:58 ----ASH---- C:\Documents and Settings\All Users\Application Data\desktop.ini
2009-02-02 17:55:53 ----RA---- C:\WINDOWS\SET8.tmp
2009-02-02 17:55:49 ----RA---- C:\WINDOWS\SET4.tmp
2009-02-02 17:55:47 ----RA---- C:\WINDOWS\SET3.tmp
2009-02-02 17:55:39 ----D---- C:\WINDOWS\system32\CatRoot2
2009-02-02 17:55:39 ----D---- C:\WINDOWS\system32\CatRoot
2009-02-02 17:55:33 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2009-02-02 17:55:14 ----A---- C:\WINDOWS\setuplog.txt
2009-02-02 17:55:09 ----D---- C:\Documents and Settings
2009-02-02 17:54:15 ----SH---- C:\boot.ini
2009-02-02 17:49:36 ----RSHD---- C:\WINDOWS\system32\dllcache
2009-02-02 17:49:36 ----RSD---- C:\WINDOWS\Fonts
2009-02-02 17:49:36 ----RD---- C:\WINDOWS\Web
2009-02-02 17:49:36 ----HD---- C:\WINDOWS\inf
2009-02-02 17:49:36 ----D---- C:\WINDOWS\WinSxS
2009-02-02 17:49:36 ----D---- C:\WINDOWS\twain_32
2009-02-02 17:49:36 ----D---- C:\WINDOWS\Temp
2009-02-02 17:49:36 ----D---- C:\WINDOWS\system32\wins
2009-02-02 17:49:36 ----D---- C:\WINDOWS\system32\wbem
2009-02-02 17:49:36 ----D---- C:\WINDOWS\system32\usmt
2009-02-02 17:49:36 ----D---- C:\WINDOWS\system32\spool
2009-02-02 17:49:36 ----D---- C:\WINDOWS\system32\ShellExt
2009-02-02 17:49:36 ----D---- C:\WINDOWS\system32\Setup
2009-02-02 17:49:36 ----D---- C:\WINDOWS\system32\ras
2009-02-02 17:49:36 ----D---- C:\WINDOWS\system32\oobe
2009-02-02 17:49:36 ----D---- C:\WINDOWS\system32\npp
2009-02-02 17:49:36 ----D---- C:\WINDOWS\system32\mui
2009-02-02 17:49:36 ----D---- C:\WINDOWS\system32\inetsrv
2009-02-02 17:49:36 ----D---- C:\WINDOWS\system32\IME
2009-02-02 17:49:36 ----D---- C:\WINDOWS\system32\icsxml
2009-02-02 17:49:36 ----D---- C:\WINDOWS\system32\ias
2009-02-02 17:49:36 ----D---- C:\WINDOWS\system32\export
2009-02-02 17:49:36 ----D---- C:\WINDOWS\system32\drivers
2009-02-02 17:49:36 ----D---- C:\WINDOWS\system32\dhcp
2009-02-02 17:49:36 ----D---- C:\WINDOWS\system32\config
2009-02-02 17:49:36 ----D---- C:\WINDOWS\system32\3com_dmi
2009-02-02 17:49:36 ----D---- C:\WINDOWS\system32\3076
2009-02-02 17:49:36 ----D---- C:\WINDOWS\system32\2052
2009-02-02 17:49:36 ----D---- C:\WINDOWS\system32\1054
2009-02-02 17:49:36 ----D---- C:\WINDOWS\system32\1042
2009-02-02 17:49:36 ----D---- C:\WINDOWS\system32\1041
2009-02-02 17:49:36 ----D---- C:\WINDOWS\system32\1037
2009-02-02 17:49:36 ----D---- C:\WINDOWS\system32\1033
2009-02-02 17:49:36 ----D---- C:\WINDOWS\system32\1031
2009-02-02 17:49:36 ----D---- C:\WINDOWS\system32\1028
2009-02-02 17:49:36 ----D---- C:\WINDOWS\system32\1025
2009-02-02 17:49:36 ----D---- C:\WINDOWS\system32
2009-02-02 17:49:36 ----D---- C:\WINDOWS\system
2009-02-02 17:49:36 ----D---- C:\WINDOWS\security
2009-02-02 17:49:36 ----D---- C:\WINDOWS\Resources
2009-02-02 17:49:36 ----D---- C:\WINDOWS\repair
2009-02-02 17:49:36 ----D---- C:\WINDOWS\Provisioning
2009-02-02 17:49:36 ----D---- C:\WINDOWS\PeerNet
2009-02-02 17:49:36 ----D---- C:\WINDOWS\pchealth
2009-02-02 17:49:36 ----D---- C:\WINDOWS\mui
2009-02-02 17:49:36 ----D---- C:\WINDOWS\msapps
2009-02-02 17:49:36 ----D---- C:\WINDOWS\msagent
2009-02-02 17:49:36 ----D---- C:\WINDOWS\Media
2009-02-02 17:49:36 ----D---- C:\WINDOWS\java
2009-02-02 17:49:36 ----D---- C:\WINDOWS\ime
2009-02-02 17:49:36 ----D---- C:\WINDOWS\Help
2009-02-02 17:49:36 ----D---- C:\WINDOWS\ehome
2009-02-02 17:49:36 ----D---- C:\WINDOWS\Driver Cache
2009-02-02 17:49:36 ----D---- C:\WINDOWS\Debug
2009-02-02 17:49:36 ----D---- C:\WINDOWS\Cursors
2009-02-02 17:49:36 ----D---- C:\WINDOWS\Connection Wizard
2009-02-02 17:49:36 ----D---- C:\WINDOWS\Config
2009-02-02 17:49:36 ----D---- C:\WINDOWS\AppPatch
2009-02-02 17:49:36 ----D---- C:\WINDOWS\addins
2009-02-02 17:49:36 ----D---- C:\WINDOWS

======List of files/folders modified in the last 1 months======

2009-02-04 11:38:48 ----A---- C:\WINDOWS\win.ini
2009-02-02 19:18:56 ----A---- C:\WINDOWS\system.ini

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 IKSysFlt;System Filter Driver; C:\WINDOWS\system32\drivers\iksysflt.sys [2008-08-25 66952]
R1 IKSysSec;System Security Driver; C:\WINDOWS\system32\drivers\iksyssec.sys [2008-08-25 81288]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-04 36096]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2007-03-08 4027840]
R3 asc3360pr;asc3360pr; \??\C:\WINDOWS\system32\drivers\himmen.sys []
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\ialmnt5.sys [2004-01-16 666109]
R3 USB_NDIS_51;USB NDIS DSL Router Network Device Driver; C:\WINDOWS\system32\DRIVERS\bcmndis.sys [2006-04-11 21504]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-04 26624]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-04 57600]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-04 20480]
S3 autorun;autorun; \??\C:\huadio.tmp []
S3 NaiAvFilter1;NaiAvFilter1; C:\WINDOWS\system32\drivers\naiavf5x.sys [2003-09-29 83008]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe [2001-02-23 270336]
R2 sdAuxService;PC Tools Auxiliary Service; C:\Program Files\Spyware Doctor\pctsAuxs.exe [2008-06-13 356920]
R2 sdCoreService;PC Tools Security Service; C:\Program Files\Spyware Doctor\pctsSvc.exe [2008-10-09 1079176]

-----------------EOF-----------------

PLS HELP !!!!!!!!!

BC AdBot (Login to Remove)

 


#2 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:25 PM

Posted 14 February 2009 - 10:59 AM

Hello.

You have a very nasty infection present as you mentioned. Most experts think it's best to format because of this infection's nature. Take a read below please.

Posted ImageSality Infection Warning

Unfortunatly One or more of the identified infections is a backdoor trojan.

This allows hackers to remotely control your computer, steal critical system information and download and execute files.

I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Though the trojan has been identified and can be killed, because of it's backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information:

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?
When Should I Format, How Should I Reinstall

More information over here and here

Backup all your documents and important items (personal data, work documents, etc) only. DO NOT backup any executable files (softwares) and screensavers (*.scr). It attempts to infect any accessed .exe or .scr files by appending itself to the executable.

Also, try to avoid backing up compressed files (zip/cab/rar) files that have .exe or .scr files inside them. Virut can penetrate and infect .exe files inside compressed files too.

Tell me what you wish to do.

With Regards,
Extremeboy

Edited by extremeboy, 14 February 2009 - 11:02 AM.

Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#3 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:25 PM

Posted 17 February 2009 - 08:42 PM

Hello.

Are you still there?

If you are please follow the instructions in my previous post.

If you still need help, follow the instructions I have given in my response. If you have since had your problem solved, we would appreciate you letting us know so we can close the topic.

Please reply back telling us so. If you don't reply within 5-7 days the topic will need to be closed.

Thanks for understanding. :thumbup2:

With Regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#4 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:25 PM

Posted 19 February 2009 - 05:25 PM

Hello.

Due to Lack of feedback, this topic is now Closed.

If you need this topic reopened, please Send Me a Message. In your message please include the address of this thread in your request.
This applies only to the original topic starter.

Everyone else please start a new topic in the Hijackthis-Malware Removal forum.

With Regards,
Extremeboy

Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users