Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

clickcheck.ru redirect.... IMPOSSIBLE! (need pro help!)


  • This topic is locked This topic is locked
24 replies to this topic

#1 scarfacek1ngofny

scarfacek1ngofny

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:12:58 PM

Posted 14 May 2009 - 03:28 PM

I'm a pretty tech savy guy and have been removing my own viruses for many years. I have not had to this with this computer until recently. I'm running XPpro on an office computer (it's a workgroup with a computer being used as a server) and seem to have contracted a virus/malware. I struggled with this virus for almost a week (main symptom was being redirected from search engines to completely unrelated sites, usually fake AV sites). Other computers on the workgroup have been uneffected. Yesterday, I admited defeat and re-installed windows. Today I come in to find my browser still being redirected through clickcheck.ru to these other sites. I did not think this was possible after reinstalling windows. I am clearly out of my league with this one. I have run malware bytes (full scan comes up clean). Before formating AVG and malwarebytes and windows malware removal continously found instances of the same files to be removed upon reboot... and never did. If there's anymore information you guys need please feel free to ask. Here is my HJT log. Please help!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:43:40 PM, on 5/14/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSExplorer.EXE
C:Program FilesJavajre1.5.0_06binjusched.exe
C:WINDOWSsystem32igfxtray.exe
C:WINDOWSsystem32hkcmd.exe
C:WINDOWSsystem32igfxpers.exe
C:WINDOWSsystem32igfxsrvc.exe
C:PROGRA~1AVGAVG8avgtray.exe
C:WINDOWSsystem32ctfmon.exe
C:PROGRA~1AVGAVG8avgwdsvc.exe
C:Program FilesViewpointCommonViewpointService.exe
C:PROGRA~1AVGAVG8avgemc.exe
C:PROGRA~1AVGAVG8avgrsx.exe
C:PROGRA~1AVGAVG8avgnsx.exe
C:Program FilesAVGAVG8avgcsrvx.exe
C:Program FilesMozilla Firefoxfirefox.exe
C:Program FilesJavajre1.5.0_06binjucheck.exe
C:Program FilesInternet ExplorerIEXPLORE.EXE
C:Program FilesInternet ExplorerIEXPLORE.EXE
C:Program FilesTrend Micromatt1HijackThis.exe
C:Program FilesAVGAVG8avgui.exe
C:WINDOWSsystem32wscntfy.exe

R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:Program FilesAVGAVG8avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre1.5.0_06binssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:PROGRA~1AVGAVG8AVGTOO~1.DLL
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:PROGRA~1AVGAVG8AVGTOO~1.DLL
O4 - HKLM..Run: [SunJavaUpdateSched] C:Program FilesJavajre1.5.0_06binjusched.exe
O4 - HKLM..Run: [IgfxTray] C:WINDOWSsystem32igfxtray.exe
O4 - HKLM..Run: [HotKeysCmds] C:WINDOWSsystem32hkcmd.exe
O4 - HKLM..Run: [Persistence] C:WINDOWSsystem32igfxpers.exe
O4 - HKLM..Run: [hpbdfawep] C:Program FilesHPDfawepbinhpbdfawep.exe 1
O4 - HKLM..Run: [AVG8_TRAY] C:PROGRA~1AVGAVG8avgtray.exe
O4 - HKCU..Run: [ctfmon.exe] C:WINDOWSsystem32ctfmon.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_06binssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_06binssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MICROS~3OFFICE11REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1242245437031
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:Program FilesAVGAVG8avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:WINDOWSSYSTEM32avgrsstx.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:PROGRA~1AVGAVG8avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:PROGRA~1AVGAVG8avgwdsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:Program FilesViewpointCommonViewpointService.exe

--
End of file - 4278 bytes

Here's the DDS log really need some help... Hope to hear for you guys soon.


DDS (Ver_09-05-14.01) - NTFSx86
Run by Matt at 9:34:13.06 on Fri 05/15/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2037.1398 [GMT -4:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:WINDOWSsystem32svchost -k DcomLaunch
svchost.exe
C:WINDOWSSystem32svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSExplorer.EXE
C:Program FilesJavajre1.5.0_06binjusched.exe
C:WINDOWSsystem32igfxtray.exe
C:WINDOWSsystem32igfxpers.exe
C:WINDOWSsystem32igfxsrvc.exe
C:PROGRA~1AVGAVG8avgtray.exe
C:WINDOWSsystem32ctfmon.exe
svchost.exe
C:PROGRA~1AVGAVG8avgwdsvc.exe
C:Program FilesViewpointCommonViewpointService.exe
C:PROGRA~1AVGAVG8avgemc.exe
C:PROGRA~1AVGAVG8avgrsx.exe
C:Program FilesAVGAVG8avgcsrvx.exe
C:Program FilesJavajre1.5.0_06binjucheck.exe
C:PROGRA~1AVGAVG8avgnsx.exe
C:Program FilesMozilla Firefoxfirefox.exe
C:Documents and SettingsMatt.MCMATTDesktopdds.scr

============== Pseudo HJT Report ===============

BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:program filesavgavg8avgssie.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:program filesjavajre1.5.0_06binssv.dll
BHO: AVG Security Toolbar: {a057a204-bacc-4d26-9990-79a187e2698e} - c:progra~1avgavg8AVGTOO~1.DLL
TB: AVG Security Toolbar: {a057a204-bacc-4d26-9990-79a187e2698e} - c:progra~1avgavg8AVGTOO~1.DLL
uRun: [ctfmon.exe] c:windowssystem32ctfmon.exe
mRun: [SunJavaUpdateSched] c:program filesjavajre1.5.0_06binjusched.exe
mRun: [IgfxTray] c:windowssystem32igfxtray.exe
mRun: [HotKeysCmds] c:windowssystem32hkcmd.exe
mRun: [Persistence] c:windowssystem32igfxpers.exe
mRun: [hpbdfawep] c:program fileshpdfawepbinhpbdfawep.exe 1
mRun: [AVG8_TRAY] c:progra~1avgavg8avgtray.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%Network Diagnosticxpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:program filesmessengermsmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC} - c:program filesjavajre1.5.0_06binssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:progra~1micros~3office11REFIEBAR.DLL
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1242245437031
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:program filesavgavg8avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: igfxcui - igfxdev.dll

================= FIREFOX ===================

FF - ProfilePath - c:docume~1matt~1.mcmapplic~1mozillafirefoxprofilesw5lhayc9.default
FF - component: c:program filesavgavg8firefoxcomponentsavgssff.dll
FF - component: c:program filesavgavg8toolbarffcomponentsvmAVGConnector.dll
FF - plugin: c:program filesjavajre1.5.0_06binNPJava11.dll
FF - plugin: c:program filesjavajre1.5.0_06binNPJava12.dll
FF - plugin: c:program filesjavajre1.5.0_06binNPJava13.dll
FF - plugin: c:program filesjavajre1.5.0_06binNPJava14.dll
FF - plugin: c:program filesjavajre1.5.0_06binNPJava32.dll
FF - plugin: c:program filesjavajre1.5.0_06binNPJPI150_06.dll
FF - plugin: c:program filesjavajre1.5.0_06binNPOJI610.dll
FF - plugin: c:program filesmozilla firefoxpluginsnpViewpoint.dll
FF - plugin: c:program filesviewpointviewpoint media playernpViewpoint.dll

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:windowssystem32driversavgldx86.sys [2009-5-14 325896]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:windowssystem32driversavgmfx86.sys [2009-5-14 27784]
R1 AvgTdiX;AVG Free8 Network Redirector;c:windowssystem32driversavgtdix.sys [2009-5-14 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:progra~1avgavg8avgemc.exe [2009-5-7 908568]
R2 avg8wd;AVG Free8 WatchDog;c:progra~1avgavg8avgwdsvc.exe [2009-5-7 298776]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:program filesviewpointcommonViewpointService.exe [2009-5-14 24652]

=============== Created Last 30 ================

2009-05-14 14:41 <DIR> --d----- c:program filesTrend Micro
2009-05-14 13:14 <DIR> --d----- c:docume~1matt~1.mcmapplic~1Malwarebytes
2009-05-14 13:14 15,504 a------- c:windowssystem32driversmbam.sys
2009-05-14 13:14 38,496 a------- c:windowssystem32driversmbamswissarmy.sys
2009-05-14 13:14 <DIR> --d----- c:program filesMalwarebytes' Anti-Malware1
2009-05-14 13:14 <DIR> --d----- c:docume~1alluse~1.winapplic~1Malwarebytes
2009-05-14 13:07 <DIR> a-dshr-- C:cmdcons
2009-05-14 13:05 161,792 a------- c:windowsSWREG.exe
2009-05-14 13:05 98,816 a------- c:windowssed.exe
2009-05-14 13:02 <DIR> --dsh--- c:documents and settingsmatt.mcmattPrivacIE
2009-05-14 12:18 <DIR> --d----- c:docume~1alluse~1.winapplic~1Viewpoint
2009-05-14 12:18 <DIR> --d----- c:docume~1alluse~1.winapplic~1acccore
2009-05-14 11:47 11,952 a------- c:windowssystem32avgrsstx.dll
2009-05-14 11:47 108,552 a------- c:windowssystem32driversavgtdix.sys
2009-05-14 11:47 325,896 a------- c:windowssystem32driversavgldx86.sys
2009-05-14 11:47 <DIR> --d----- c:docume~1matt~1.mcmapplic~1AVGTOOLBAR
2009-05-14 11:47 <DIR> --d----- c:docume~1alluse~1.winapplic~1avg8
2009-05-14 11:42 <DIR> --dsh--- c:documents and settingsmatt.mcmattIETldCache
2009-05-14 11:40 102,400 -c------ c:windowssystem32dllcacheiecompat.dll
2009-05-14 11:24 221,184 a------- c:windowssystem32wmpns.dll
2009-05-14 11:08 701,440 -------- c:windowssystem32driversati2mtag.sys
2009-05-13 18:22 203,136 -c------ c:windowssystem32dllcachermcast.sys
2009-05-13 18:22 455,296 -c------ c:windowssystem32dllcachemrxsmb.sys
2009-05-13 18:22 333,952 -c------ c:windowssystem32dllcachesrv.sys
2009-05-13 18:21 691,712 -c------ c:windowssystem32dllcacheinetcomm.dll
2009-05-13 18:19 337,408 -c------ c:windowssystem32dllcachenetapi32.dll
2009-05-13 18:19 215,552 -c------ c:windowssystem32dllcachewordpad.exe
2009-05-13 18:19 2,560 -------- c:windowssystem32xpsp4res.dll
2009-05-13 16:13 26,144 a------- c:windowssystem32spupdsvc.exe
2009-05-13 16:11 31,768 a------- c:windowssystem32wucltui.dll.mui
2009-05-13 16:11 18,456 a------- c:windowssystem32wuaueng.dll.mui
2009-05-13 16:11 23,576 a------- c:windowssystem32wuaucpl.cpl.mui
2009-05-13 16:11 23,576 a------- c:windowssystem32wuapi.dll.mui
2009-05-13 16:10 <DIR> --ds---- c:documents and settingsmatt.mcmattUserData
2009-05-13 13:55 253,952 a------- c:windowssystem32HP1006LM.DLL
2009-05-13 13:55 65,536 a------- c:windowssystem32HPPLVS.dll
2009-05-13 13:44 376 a------- c:windowsODBC.INI
2009-05-13 13:20 172,032 a------- c:windowssystem32igfxres.dll
2009-05-13 13:17 1,904 -------- c:windowssystem32SetupBD.din
2009-05-13 13:15 <DIR> --d----- C:Intel
2009-05-13 13:13 49,265 a------- c:windowssystem32jpicpl32.cpl
2009-05-13 13:12 5 a------- c:windowssystem32driversDELL_XPS_Vostro 200.MRK
2009-05-13 13:12 5 a------- c:windowssystem32drivers1028_DELL_XPS_Vostro 200.MRK
2009-05-13 13:05 <DIR> --d----- c:documents and settingsMatt.MCMATT
2009-05-13 13:03 8,192 a------- c:windowsREGLOCS.OLD
2009-05-13 13:01 92,416 ac------ c:windowssystem32dllcachemga.sys
2009-05-13 13:00 49,664 ac------ c:windowssystem32dllcacheadrot.dll
2009-05-13 12:58 <DIR> --dsh--- c:documents and settingsall users.windowsDRM
2009-05-13 12:58 488 a---hr-- c:windowssystem32WindowsLogon.manifest
2009-05-13 12:58 488 a---hr-- c:windowssystem32logonui.exe.manifest
2009-05-13 12:58 749 a---hr-- c:windowsWindowsShell.Manifest
2009-05-13 12:58 749 a---hr-- c:windowssystem32wuaucpl.cpl.manifest
2009-05-13 12:58 749 a---hr-- c:windowssystem32sapi.cpl.manifest
2009-05-13 12:58 749 a---hr-- c:windowssystem32nwc.cpl.manifest
2009-05-13 12:58 749 a---hr-- c:windowssystem32ncpa.cpl.manifest
2009-05-13 12:58 749 a---hr-- c:windowssystem32cdplayer.exe.manifest
2009-05-13 12:58 4,399,505 ac------ c:windowssystem32dllcachenls302en.lex
2009-05-13 12:56 252,928 a------- c:windowssystem32msoeacct.dll
2009-05-13 12:56 105,984 a------- c:windowssystem32msoert2.dll
2009-05-13 12:56 691,712 a------- c:windowssystem32inetcomm.dll
2009-05-13 12:56 48,128 a------- c:windowssystem32inetres.dll
2009-05-13 12:56 192,512 a------- c:windowssystem32schedsvc.dll
2009-05-13 12:56 274,944 a------- c:windowssystem32mstask.dll
2009-05-13 12:56 81,920 a------- c:windowssystem32isign32.dll
2009-05-13 12:56 73,728 a------- c:windowssystem32icwdial.dll
2009-05-13 12:56 65,536 a------- c:windowssystem32icwphbk.dll
2009-05-13 12:56 12,288 a------- c:windowssystem32mstinit.exe
2009-05-13 12:56 274,432 a------- c:windowssystem32inetcfg.dll
2009-05-13 12:56 21,640 a------- c:windowssystem32emptyregdb.dat
2009-05-13 12:54 184,320 a------- c:windowssystem32accwiz.exe
2009-05-13 08:51 3,072 a------- c:windowssystem32driversaudstub.sys
2009-05-13 08:51 25,856 a------- c:windowssystem32driversusbprint.sys
2009-05-13 08:50 57,600 a------- c:windowssystem32driversredbook.sys
2009-05-13 08:50 74,240 a------- c:windowssystem32usbui.dll
2009-05-13 08:47 <DIR> --d--r-- c:documents and settingsall users.windowsDocuments
2009-05-13 08:45 261 a------- c:windowssystem32$winnt$.inf
2009-05-13 08:22 <DIR> --d----- c:windowsdell
2009-05-11 15:22 <DIR> --d----- c:program filesTMHJT
2009-05-11 12:25 <DIR> --d-h--- c:windowsPIF
2009-05-07 12:14 <DIR> --d-h--- C:$AVG8.VAULT$
2009-05-07 11:22 <DIR> --d----- c:windowssystem32driversAvg
2009-05-07 11:21 <DIR> --d----- c:program filesAVG
2009-05-06 15:23 <DIR> --d----- c:windowssystem32XPSViewer
2009-05-06 15:22 <DIR> --d----- C:2926076ff8ca37070f90
2009-05-06 12:24 <DIR> --d----- c:windowssystem32scripting
2009-05-06 12:24 <DIR> --d----- c:windowssystem32en
2009-05-06 12:24 <DIR> --d----- c:windowsl2schemas
2009-05-06 12:22 <DIR> --d----- c:windowsServicePackFiles
2009-05-06 12:21 <DIR> --d----- c:windowsnetwork diagnostic
2009-05-06 10:55 <DIR> --d----- c:program filesMatt
2009-05-05 15:51 <DIR> --d----- c:windowssystem32bits
2009-05-04 09:40 <DIR> --d----- c:windowsie8updates
2009-05-04 09:39 <DIR> -cd-h--- c:windowsie8
2009-05-01 08:34 <DIR> --d----- c:windowssystem32LogFiles
2009-04-30 15:28 254,872 a------- c:windowssystem32driverse1e5132.sys
2009-04-30 15:28 179,048 a------- c:windowssystem32e1000msg.dll
2009-04-30 15:28 154,496 a------- c:windowssystem32Prounstl.exe
2009-04-30 15:28 66,424 a------- c:windowssystem32NicEtCoE.dll
2009-04-30 15:28 62,840 a------- c:windowssystem32NicInstE.dll
2009-04-30 15:28 28,536 a------- c:windowssystem32NicCo.dll
2009-04-30 15:28 2,889 a------- c:windowssystem32e1e5132.din
2009-04-30 15:19 <DIR> --d----- c:windowsOPTIONS
2009-04-30 15:19 <DIR> --d----- c:program filesRealtek
2009-04-30 15:17 <DIR> --d----- c:windowssystem32vmm32
2009-04-30 13:27 <DIR> --d----- c:program filesViewpoint
2009-04-30 13:17 <DIR> --d-h--- c:windowssystem32GroupPolicy
2009-04-30 10:14 <DIR> --d----- c:windowssystem32appmgmt
2009-04-29 11:14 <DIR> --d----- c:windowspss

==================== Find3M ====================

2009-05-14 11:21 87,263 a------- c:windowspchealthhelpctrofflinecacheindex.dat
2009-03-08 04:34 914,944 a------- c:windowssystem32wininet.dll
2009-03-08 04:34 43,008 a------- c:windowssystem32licmgr10.dll
2009-03-08 04:33 18,944 a------- c:windowssystem32corpol.dll
2009-03-08 04:33 420,352 a------- c:windowssystem32vbscript.dll
2009-03-08 04:32 72,704 a------- c:windowssystem32admparse.dll
2009-03-08 04:32 71,680 a------- c:windowssystem32iesetup.dll
2009-03-08 04:31 34,816 a------- c:windowssystem32imgutil.dll
2009-03-08 04:31 48,128 a------- c:windowssystem32mshtmler.dll
2009-03-08 04:31 45,568 a------- c:windowssystem32mshta.exe
2009-03-08 04:22 156,160 a------- c:windowssystem32msls31.dll
2009-03-06 10:22 284,160 a------- c:windowssystem32pdh.dll

============= FINISH: 9:34:24.84 ===============

Merged posts. ~ OB

Attached Files


Edited by Orange Blossom, 15 May 2009 - 02:57 PM.


BC AdBot (Login to Remove)

 


#2 thewall

thewall

  • Malware Response Team
  • 6,425 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Florida
  • Local time:11:58 AM

Posted 15 May 2009 - 06:51 PM

Hello scarfacek1ngofny :thumbup2: Welcome to the BC HijackThis Log and Analysis forum. I will be assisting you as we work to figure out what is causing your problems and the best way to fix them if possible.

I ask that you refrain from running tools other than those we suggest to you while we are cleaning up your computer. The reason for this is so we know what is going on with the machine at any time. Some programs can interfere with others and hamper the recovery process.


In the upper right hand corner of the topic you will see a button called Options. If you click on this in the drop-down menu you can choose Track this topic. By doing this and then choosing Immediate E-Mail notification and then clicking on Proceed you will be advised when we respond the your topic and facilitate the cleaning of your machine.

After 5 days if a topic is not replied to we assume it has been abandoned and it is closed.





Please perform the following:



Do an online scan with Kaspersky WebScanner

Click on Kaspersky Online Scanner

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.



  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<<will be maximized) and info.txt (<<will be minimized)





When completed please both both logs fromRSIT as well as the one from Kaspersky.





Thanks,



thewall
If I have helped you then please consider donating so I can continue the fight against malware Posted Image
All donations go directly to the helper

Posted Image

Due to the large amount of backlogs we have I cannot respond to PMs for help unless I am already working with you

#3 scarfacek1ngofny

scarfacek1ngofny
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:12:58 PM

Posted 19 May 2009 - 08:30 AM

Sorry for the late reply. I have been away from my office computer. For some reason when I try to reply the words are appearing backwards in the browser (ie when I type "sorry" "yrros" appears. I have typed this message in notepad and will have those logs up ASAP

#4 scarfacek1ngofny

scarfacek1ngofny
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:12:58 PM

Posted 19 May 2009 - 09:37 AM

info.txt logfile of random's system information tool 1.06 2009-05-19 10:34:13

======Uninstall list======

-->MsiExec.exe /I{403EF592-953B-4794-BCEF-ECAB835C2095}
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
AIM 6-->C:\Program Files\AIM6\uninst.exe
AVG Free 8.5-->C:\Program Files\AVG\AVG8\setup.exe /UNINSTALL
Compatibility Pack for the 2007 Office system-->MsiExec.exe /X{90120000-0020-0409-0000-0000000FF1CE}
Dell Resource CD-->MsiExec.exe /X{42929F0F-CE14-47AF-9FC7-FF297A603021}
HijackThis 2.0.2-->"C:\Program Files\Trend Micro\matt1\HijackThis.exe" /uninstall
Hotfix for Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
HP LaserJet P1000 series-->C:\Program Files\Avago-HP\{969f9d80-c5a1-437a-9b6a-3832f5377844}\uninstall.exe SYSTEMHORNET "C:\Program Files\Avago-HP\{969f9d80-c5a1-437a-9b6a-3832f5377844}"
HPCarePackCore-->MsiExec.exe /I{7B02BF60-796D-4616-908B-B31A63CFDEFB}
HPCarePackProducts-->MsiExec.exe /I{ECA31632-C2AD-4774-A3CA-2813D47E4DD0}
HPSSupply-->MsiExec.exe /X{7902E313-FF0F-4493-ACB1-A8147B78DCD0}
Intel® Graphics Media Accelerator Driver-->C:\WINDOWS\system32\igxpun.exe -uninstall
Intel® PRO Network Connections 12.1.12.0-->MsiExec.exe /i{777CA40C-0206-4EF6-A0FC-618BF06BF8D0} ARPREMOVE=1
J2SE Runtime Environment 5.0 Update 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150060}
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware1\unins000.exe"
Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft Office PowerPoint Viewer 2007 (English)-->MsiExec.exe /X{95120000-00AF-0409-0000-0000000FF1CE}
Microsoft Office Word 2003-->MsiExec.exe /I{901B0409-6000-11D3-8CFE-0150048383C9}
Microsoft VC9 runtime libraries-->MsiExec.exe /I{C4124E95-5061-4776-8D5D-E3D931C778E1}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Works-->MsiExec.exe /I{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}
Mozilla Firefox (3.0.10)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MrvlUsgTracking-->MsiExec.exe /I{02C85EC5-E864-4847-AF55-42730861004C}
MSXML 6 Service Pack 2 (KB954459)-->MsiExec.exe /I{1A528690-6A2D-4BC5-B143-8C4AE8D19D96}
Security Update for Windows Media Player (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
Security Update for Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Security Update for Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
Security Update for Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
Security Update for Windows XP (KB963027)-->"C:\WINDOWS\$NtUninstallKB963027$\spuninst\spuninst.exe"
Update for Windows Internet Explorer 8 (KB969497)-->"C:\WINDOWS\ie8updates\KB969497-IE8\spuninst\spuninst.exe"
Update for Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Update for Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
Update for Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
Viewpoint Media Player-->C:\Program Files\Viewpoint\Viewpoint Media Player\mtsAxInstaller.exe /u
Windows Internet Explorer 8-->"C:\WINDOWS\ie8\spuninst\spuninst.exe"
Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"

======Security center information======

AV: AVG Anti-Virus Free (disabled)

======System event log======

Computer Name: MCMATT
Event Code: 1003
Message: Your computer was not able to renew its address from the network (from the
DHCP Server) for the Network Card with network address 00219B055935. The following
error occurred:
The semaphore timeout period has expired.
.
Your computer will continue to try and obtain an address on its own from
the network address (DHCP) server.

Record Number: 307
Source Name: Dhcp
Time Written: 20090514112509.000000-240
Event Type: warning
User:

Computer Name: MCMATT
Event Code: 36
Message: The time service has not been able to synchronize the system time
for 49152 seconds because none of the time providers has been able to
provide a usable time stamp. The system clock is unsynchronized.

Record Number: 250
Source Name: W32Time
Time Written: 20090514030910.000000-240
Event Type: warning
User:

Computer Name: MCMATT
Event Code: 20
Message: Printer Driver HP LaserJet P1006 for Windows NT x86 Version-3 was added or updated. Files:- HP1006K.DLL, HP1006U.DLL, HP1006K.DLL, HP1006H.CHM, P1006CLP.dll, HP1006C.DLL, HP1006D.DLL, HP1006J.DLL, HP1006LM.DLL, HP1006MC.EXE, HP1006MP.DLL, HP1006MT.DLL, HP1006P.DLL, HP1006S.DLL, HP1006SM.exe, HP1006SX.dll, P1006MAN.dll, P1006SSL.exe, P1006SIG.gif, P1006DEF.css, P1006BTN.js, P1006GLB.js, P1005DP.PRN, P1006DP.PRN, P1505DP.PRN, P1505nDP.PRN, P1006NFn.dll, P1006CLS.dll, HP1006L.DLL, HP1006LG.dll, HP1006S.CHM, P1006OS.htm, P1006IPS.dll, HP1006S.HLP, P1005.img, P1006.img, P1505.img.

Record Number: 117
Source Name: Print
Time Written: 20090513135554.000000-240
Event Type: warning
User: NT AUTHORITY\SYSTEM

Computer Name: MCMATT
Event Code: 20
Message: Printer Driver HP LaserJet 1200 Series PS (MS) for Windows NT x86 Version-3 was added or updated. Files:- PSCRIPT5.DLL, PS5UI.DLL, HP1200_7.PPD, PSCRIPT.HLP, PSCRIPT.NTF.

Record Number: 105
Source Name: Print
Time Written: 20090513134335.000000-240
Event Type: warning
User: NT AUTHORITY\SYSTEM

Computer Name: MCMATT
Event Code: 2504
Message: The server could not bind to the transport \Device\NetBT_Tcpip_{79D75780-1E07-46C5-B7A8-4CE1C1CABD52}.

Record Number: 40
Source Name: Server
Time Written: 20090513131814.000000-240
Event Type: warning
User:

=====Application event log=====

Computer Name: MCMATT
Event Code: 5603
Message: A provider, Rsop Planning Mode Provider, has been registered in the WMI namespace, root\RSOP, but did not specify the HostingModel property. This provider will be run using the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests. Ensure that provider has been reviewed for security behavior and update the HostingModel property of the provider registration to an account with the least privileges possible for the required functionality.

Record Number: 18
Source Name: WinMgmt
Time Written: 20090513125938.000000-240
Event Type: warning
User: NT AUTHORITY\SYSTEM

Computer Name: MCMATT
Event Code: 5603
Message: A provider, Rsop Planning Mode Provider, has been registered in the WMI namespace, root\RSOP, but did not specify the HostingModel property. This provider will be run using the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests. Ensure that provider has been reviewed for security behavior and update the HostingModel property of the provider registration to an account with the least privileges possible for the required functionality.

Record Number: 17
Source Name: WinMgmt
Time Written: 20090513125938.000000-240
Event Type: warning
User: NT AUTHORITY\SYSTEM

Computer Name: MCMATT
Event Code: 63
Message: A provider, CmdTriggerConsumer, has been registered in the WMI namespace, Root\cimv2, to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.

Record Number: 13
Source Name: WinMgmt
Time Written: 20090513125627.000000-240
Event Type: warning
User: NT AUTHORITY\SYSTEM

Computer Name: MCMATT
Event Code: 63
Message: A provider, CmdTriggerConsumer, has been registered in the WMI namespace, Root\cimv2, to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.

Record Number: 12
Source Name: WinMgmt
Time Written: 20090513125627.000000-240
Event Type: warning
User: NT AUTHORITY\SYSTEM

Computer Name: MCMATT
Event Code: 63
Message: A provider, HiPerfCooker_v1, has been registered in the WMI namespace, Root\WMI, to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.

Record Number: 11
Source Name: WinMgmt
Time Written: 20090513125625.000000-240
Event Type: warning
User: NT AUTHORITY\SYSTEM

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\Program Files\Intel\DMIX
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 13, GenuineIntel
"PROCESSOR_REVISION"=0f0d
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP

-----------------EOF-----------------Logfile of random's system information tool 1.06 (written by random/random)
Run by Matt at 2009-05-19 10:34:10
Microsoft Windows XP Professional Service Pack 3
System drive C: has 63 GB (83%) free of 76 GB
Total RAM: 2037 MB (68% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:34:12 AM, on 5/19/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Java\jre1.5.0_06\bin\jucheck.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Documents and Settings\Matt.MCMATT\Desktop\RSIT.exe
C:\Program Files\Trend Micro\matt1\Matt.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [hpbdfawep] C:\Program Files\HP\Dfawep\bin\hpbdfawep.exe 1
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1242245437031
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

--
End of file - 4194 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\HP WEP.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG8\avgssie.dll [2009-05-07 1107224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll [2005-11-10 184423]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
AVG Security Toolbar - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2009-05-07 2223872]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{A057A204-BACC-4D26-9990-79A187E2698E} - AVG Security Toolbar - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2009-05-07 2223872]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe [2005-11-10 36975]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2007-04-16 142104]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2007-04-16 162584]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2007-04-16 138008]
"hpbdfawep"=C:\Program Files\HP\Dfawep\bin\hpbdfawep.exe [2007-04-25 954368]
"AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe [2009-05-07 1947928]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgrsstarter]
C:\WINDOWS\system32\avgrsstx.dll [2009-05-14 11952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2007-04-16 204800]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 239496]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\WINDOWS\system32\spool\drivers\w32x86\3\HP1006MC.EXE"="C:\WINDOWS\system32\spool\drivers\w32x86\3\HP1006MC.EXE:*:Enabled:SMLMProxy Module - HP1006MC.EXE"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\AVG\AVG8\avgemc.exe"="C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe"
"C:\Program Files\AVG\AVG8\avgupd.exe"="C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe"
"C:\Program Files\AVG\AVG8\avgnsx.exe"="C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe"
"C:\Program Files\Common Files\AOL\Loader\aolload.exe"="C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader"
"C:\Program Files\AIM6\aim6.exe"="C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2009-05-19 10:34:10 ----D---- C:\rsit
2009-05-19 09:24:11 ----D---- C:\Documents and Settings\Matt.MCMATT\Application Data\Sun
2009-05-15 12:10:27 ----SHD---- C:\RECYCLER
2009-05-14 14:41:01 ----D---- C:\Program Files\Trend Micro
2009-05-14 14:22:38 ----D---- C:\WINDOWS\temp
2009-05-14 14:22:36 ----A---- C:\ComboFix.txt
2009-05-14 13:14:43 ----D---- C:\Documents and Settings\Matt.MCMATT\Application Data\Malwarebytes
2009-05-14 13:14:38 ----D---- C:\Program Files\Malwarebytes' Anti-Malware1
2009-05-14 13:14:38 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\Malwarebytes
2009-05-14 13:07:05 ----A---- C:\Boot.bak
2009-05-14 13:07:01 ----RASHD---- C:\cmdcons
2009-05-14 13:05:29 ----A---- C:\WINDOWS\zip.exe
2009-05-14 13:05:29 ----A---- C:\WINDOWS\vFind.exe
2009-05-14 13:05:29 ----A---- C:\WINDOWS\SWXCACLS.exe
2009-05-14 13:05:29 ----A---- C:\WINDOWS\SWSC.exe
2009-05-14 13:05:29 ----A---- C:\WINDOWS\SWREG.exe
2009-05-14 13:05:29 ----A---- C:\WINDOWS\sed.exe
2009-05-14 13:05:29 ----A---- C:\WINDOWS\NIRCMD.exe
2009-05-14 13:05:29 ----A---- C:\WINDOWS\grep.exe
2009-05-14 13:05:17 ----D---- C:\Qoobox
2009-05-14 12:18:15 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint
2009-05-14 12:18:13 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\acccore
2009-05-14 12:18:03 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\AOL OCP
2009-05-14 12:18:03 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\AOL
2009-05-14 11:47:26 ----A---- C:\WINDOWS\system32\avgrsstx.dll
2009-05-14 11:47:16 ----D---- C:\Documents and Settings\Matt.MCMATT\Application Data\AVGTOOLBAR
2009-05-14 11:47:12 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\avg8
2009-05-14 11:38:36 ----A---- C:\WINDOWS\system32\MRT.exe
2009-05-14 11:24:59 ----A---- C:\WINDOWS\system32\wmpns.dll
2009-05-14 11:24:41 ----D---- C:\WINDOWS\Prefetch
2009-05-14 11:22:44 ----HDC---- C:\WINDOWS\$NtUninstallKB963027$
2009-05-14 11:22:37 ----HDC---- C:\WINDOWS\$NtUninstallKB938464-v2$
2009-05-14 03:02:25 ----HDC---- C:\WINDOWS\$NtUninstallKB950760$
2009-05-14 03:00:22 ----HDC---- C:\WINDOWS\$NtUninstallKB944338-v2$
2009-05-13 18:19:07 ----N---- C:\WINDOWS\system32\xpsp4res.dll
2009-05-13 16:13:13 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\Windows Genuine Advantage
2009-05-13 16:13:02 ----A---- C:\WINDOWS\system32\spupdsvc.exe
2009-05-13 16:11:12 ----A---- C:\WINDOWS\system32\wups2.dll
2009-05-13 16:11:12 ----A---- C:\WINDOWS\system32\wucltui.dll.mui
2009-05-13 16:11:12 ----A---- C:\WINDOWS\system32\wuaueng.dll.mui
2009-05-13 16:11:11 ----A---- C:\WINDOWS\system32\wuapi.dll.mui
2009-05-13 13:59:59 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\HPSSUPPLY
2009-05-13 13:55:52 ----A---- C:\WINDOWS\system32\WRes1200.txt
2009-05-13 13:55:52 ----A---- C:\WINDOWS\system32\W600dpi.txt
2009-05-13 13:55:52 ----A---- C:\WINDOWS\system32\HRes600.txt
2009-05-13 13:55:52 ----A---- C:\WINDOWS\system32\HRes1200.txt
2009-05-13 13:55:52 ----A---- C:\WINDOWS\system32\HPPLVS.dll
2009-05-13 13:55:52 ----A---- C:\WINDOWS\system32\HP1006LM.DLL
2009-05-13 13:51:23 ----D---- C:\Documents and Settings\Matt.MCMATT\Application Data\Mozilla
2009-05-13 13:44:13 ----A---- C:\WINDOWS\ODBC.INI
2009-05-13 13:28:43 ----HDC---- C:\WINDOWS\$MSI31Uninstall_KB893803v2$
2009-05-13 13:20:43 ----A---- C:\WINDOWS\system32\igfxres.dll
2009-05-13 13:18:53 ----A---- C:\WINDOWS\system32\igxprd32.dll
2009-05-13 13:18:53 ----A---- C:\WINDOWS\system32\igxpgd32.dll
2009-05-13 13:18:53 ----A---- C:\WINDOWS\system32\igxpdx32.dll
2009-05-13 13:18:53 ----A---- C:\WINDOWS\system32\igxpdv32.dll
2009-05-13 13:18:53 ----A---- C:\WINDOWS\system32\iglicd32.dll
2009-05-13 13:18:53 ----A---- C:\WINDOWS\system32\igldev32.dll
2009-05-13 13:18:53 ----A---- C:\WINDOWS\system32\igfxzoom.exe
2009-05-13 13:18:53 ----A---- C:\WINDOWS\system32\igfxtray.exe
2009-05-13 13:18:53 ----A---- C:\WINDOWS\system32\igfxsrvc.exe
2009-05-13 13:18:53 ----A---- C:\WINDOWS\system32\igfxsrvc.dll
2009-05-13 13:18:53 ----A---- C:\WINDOWS\system32\igfxress.dll
2009-05-13 13:18:53 ----A---- C:\WINDOWS\system32\igfxpph.dll
2009-05-13 13:18:53 ----A---- C:\WINDOWS\system32\igfxpers.exe
2009-05-13 13:18:53 ----A---- C:\WINDOWS\system32\igfxext.exe
2009-05-13 13:18:53 ----A---- C:\WINDOWS\system32\igfxexps.dll
2009-05-13 13:18:53 ----A---- C:\WINDOWS\system32\igfxdo.dll
2009-05-13 13:18:53 ----A---- C:\WINDOWS\system32\igfxdev.dll
2009-05-13 13:18:53 ----A---- C:\WINDOWS\system32\igfxCoIn_v4820.dll
2009-05-13 13:18:53 ----A---- C:\WINDOWS\system32\igfxcfg.exe
2009-05-13 13:18:53 ----A---- C:\WINDOWS\system32\hkcmd.exe
2009-05-13 13:18:53 ----A---- C:\WINDOWS\system32\hccutils.dll
2009-05-13 13:18:52 ----A---- C:\WINDOWS\system32\igxpun.exe
2009-05-13 13:18:52 ----A---- C:\WINDOWS\system32\difxapi.dll
2009-05-13 13:15:24 ----D---- C:\Intel
2009-05-13 13:13:56 ----A---- C:\WINDOWS\system32\javaws.exe
2009-05-13 13:13:56 ----A---- C:\WINDOWS\system32\javaw.exe
2009-05-13 13:13:56 ----A---- C:\WINDOWS\system32\java.exe
2009-05-13 13:12:01 ----D---- C:\Documents and Settings\Matt.MCMATT\Application Data\InstallShield
2009-05-13 13:05:16 ----D---- C:\Documents and Settings\Matt.MCMATT\Application Data\Identities
2009-05-13 13:05:06 ----SD---- C:\Documents and Settings\Matt.MCMATT\Application Data\Microsoft
2009-05-13 13:05:06 ----ASH---- C:\Documents and Settings\Matt.MCMATT\Application Data\desktop.ini
2009-05-13 13:04:15 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-05-13 13:00:25 ----N---- C:\WINDOWS\system32\spmsg.dll
2009-05-13 13:00:22 ----A---- C:\WINDOWS\system32\xpsp3res.dll
2009-05-13 13:00:08 ----A---- C:\WINDOWS\control.ini
2009-05-13 12:59:55 ----A---- C:\WINDOWS\OEWABLog.txt
2009-05-13 12:59:49 ----A---- C:\WINDOWS\system32\mapi32.dll
2009-05-13 12:58:44 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest
2009-05-13 12:58:37 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest
2009-05-13 12:57:42 ----A---- C:\WINDOWS\system32\atrace.dll
2009-05-13 12:57:38 ----A---- C:\WINDOWS\system32\desktop.ini
2009-05-13 12:57:38 ----A---- C:\WINDOWS\desktop.ini
2009-05-13 12:57:31 ----A---- C:\WINDOWS\system32\nmevtmsg.dll
2009-05-13 12:57:30 ----A---- C:\WINDOWS\system32\acctres.dll
2009-05-13 12:57:29 ----A---- C:\WINDOWS\system32\icfgnt5.dll
2009-05-13 12:57:19 ----A---- C:\WINDOWS\system32\wuweb.dll
2009-05-13 12:57:19 ----A---- C:\WINDOWS\system32\wucltui.dll
2009-05-13 12:57:19 ----A---- C:\WINDOWS\system32\wuauserv.dll
2009-05-13 12:57:19 ----A---- C:\WINDOWS\system32\wuaueng1.dll
2009-05-13 12:57:18 ----A---- C:\WINDOWS\system32\wups.dll
2009-05-13 12:57:18 ----A---- C:\WINDOWS\system32\wuaueng.dll
2009-05-13 12:57:18 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2009-05-13 12:57:18 ----A---- C:\WINDOWS\system32\wuauclt.exe
2009-05-13 12:57:18 ----A---- C:\WINDOWS\system32\wuapi.dll
2009-05-13 12:57:18 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
2009-05-13 12:57:18 ----A---- C:\WINDOWS\system32\bitsprx3.dll
2009-05-13 12:57:18 ----A---- C:\WINDOWS\system32\bitsprx2.dll
2009-05-13 12:57:17 ----A---- C:\WINDOWS\system32\qmgr.dll
2009-05-13 12:57:10 ----A---- C:\WINDOWS\system32\safrslv.dll
2009-05-13 12:57:10 ----A---- C:\WINDOWS\system32\safrdm.dll
2009-05-13 12:57:10 ----A---- C:\WINDOWS\system32\safrcdlg.dll
2009-05-13 12:57:10 ----A---- C:\WINDOWS\system32\racpldlg.dll
2009-05-13 12:57:05 ----A---- C:\WINDOWS\system32\srsvc.dll
2009-05-13 12:57:05 ----A---- C:\WINDOWS\system32\srrstr.dll
2009-05-13 12:57:05 ----A---- C:\WINDOWS\system32\fltmc.exe
2009-05-13 12:57:05 ----A---- C:\WINDOWS\system32\fltlib.dll
2009-05-13 12:57:04 ----A---- C:\WINDOWS\system32\srclient.dll
2009-05-13 12:57:04 ----A---- C:\WINDOWS\system32\isrdbg32.dll
2009-05-13 12:57:04 ----A---- C:\WINDOWS\system32\ils.dll
2009-05-13 12:57:03 ----A---- C:\WINDOWS\system32\nmmkcert.dll
2009-05-13 12:57:03 ----A---- C:\WINDOWS\system32\msconf.dll
2009-05-13 12:57:03 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2009-05-13 12:57:03 ----A---- C:\WINDOWS\system32\mnmdd.dll
2009-05-13 12:56:58 ----A---- C:\WINDOWS\system32\msoert2.dll
2009-05-13 12:56:58 ----A---- C:\WINDOWS\system32\msoeacct.dll
2009-05-13 12:56:57 ----A---- C:\WINDOWS\system32\inetres.dll
2009-05-13 12:56:57 ----A---- C:\WINDOWS\system32\inetcomm.dll
2009-05-13 12:56:52 ----A---- C:\WINDOWS\system32\schedsvc.dll
2009-05-13 12:56:51 ----A---- C:\WINDOWS\system32\mstinit.exe
2009-05-13 12:56:51 ----A---- C:\WINDOWS\system32\mstask.dll
2009-05-13 12:56:51 ----A---- C:\WINDOWS\system32\isign32.dll
2009-05-13 12:56:51 ----A---- C:\WINDOWS\system32\icwphbk.dll
2009-05-13 12:56:51 ----A---- C:\WINDOWS\system32\icwdial.dll
2009-05-13 12:56:50 ----A---- C:\WINDOWS\system32\inetcfg.dll
2009-05-13 12:55:57 ----A---- C:\WINDOWS\vbaddin.ini
2009-05-13 12:55:57 ----A---- C:\WINDOWS\vb.ini
2009-05-13 12:55:32 ----A---- C:\WINDOWS\system32\write.exe
2009-05-13 12:55:26 ----A---- C:\WINDOWS\system32\sndvol32.exe
2009-05-13 12:55:25 ----A---- C:\WINDOWS\system32\hticons.dll
2009-05-13 12:55:25 ----A---- C:\WINDOWS\system32\avwav.dll
2009-05-13 12:55:25 ----A---- C:\WINDOWS\system32\avtapi.dll
2009-05-13 12:55:25 ----A---- C:\WINDOWS\system32\avmeter.dll
2009-05-13 12:55:24 ----A---- C:\WINDOWS\system32\winchat.exe
2009-05-13 12:55:16 ----A---- C:\WINDOWS\system32\getuname.dll
2009-05-13 12:55:15 ----A---- C:\WINDOWS\system32\sol.exe
2009-05-13 12:55:15 ----A---- C:\WINDOWS\system32\charmap.exe
2009-05-13 12:55:15 ----A---- C:\WINDOWS\system32\calc.exe
2009-05-13 12:55:10 ----A---- C:\WINDOWS\system32\winmine.exe
2009-05-13 12:55:09 ----A---- C:\WINDOWS\system32\usrlogon.cmd
2009-05-13 12:55:09 ----A---- C:\WINDOWS\system32\tsshutdn.exe
2009-05-13 12:55:09 ----A---- C:\WINDOWS\system32\tslabels.ini
2009-05-13 12:55:09 ----A---- C:\WINDOWS\system32\tskill.exe
2009-05-13 12:55:09 ----A---- C:\WINDOWS\system32\tsdiscon.exe
2009-05-13 12:55:09 ----A---- C:\WINDOWS\system32\tscon.exe
2009-05-13 12:55:09 ----A---- C:\WINDOWS\system32\reset.exe
2009-05-13 12:55:09 ----A---- C:\WINDOWS\system32\mshearts.exe
2009-05-13 12:55:09 ----A---- C:\WINDOWS\system32\freecell.exe
2009-05-13 12:55:08 ----A---- C:\WINDOWS\system32\shadow.exe
2009-05-13 12:55:08 ----A---- C:\WINDOWS\system32\rwinsta.exe
2009-05-13 12:55:08 ----A---- C:\WINDOWS\system32\regini.exe
2009-05-13 12:55:08 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
2009-05-13 12:55:08 ----A---- C:\WINDOWS\system32\qwinsta.exe
2009-05-13 12:55:08 ----A---- C:\WINDOWS\system32\qappsrv.exe
2009-05-13 12:55:08 ----A---- C:\WINDOWS\system32\msg.exe
2009-05-13 12:55:08 ----A---- C:\WINDOWS\system32\logoff.exe
2009-05-13 12:55:08 ----A---- C:\WINDOWS\system32\cdmodem.dll
2009-05-13 12:55:07 ----A---- C:\WINDOWS\system32\msdtcprf.ini
2009-05-13 12:55:07 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2009-05-13 12:55:06 ----A---- C:\WINDOWS\system32\stclient.dll
2009-05-13 12:55:06 ----A---- C:\WINDOWS\system32\mtxlegih.dll
2009-05-13 12:55:06 ----A---- C:\WINDOWS\system32\mtxex.dll
2009-05-13 12:55:06 ----A---- C:\WINDOWS\system32\mtxdm.dll
2009-05-13 12:55:06 ----A---- C:\WINDOWS\system32\comsnap.dll
2009-05-13 12:55:06 ----A---- C:\WINDOWS\system32\comrepl.dll
2009-05-13 12:55:06 ----A---- C:\WINDOWS\system32\comaddin.dll
2009-05-13 12:55:00 ----A---- C:\WINDOWS\system32\wmimgmt.msc
2009-05-13 12:54:58 ----A---- C:\WINDOWS\system32\sndrec32.exe
2009-05-13 12:54:58 ----A---- C:\WINDOWS\system32\accwiz.exe
2009-05-13 12:54:57 ----A---- C:\WINDOWS\system32\mplay32.exe
2009-05-13 12:54:57 ----A---- C:\WINDOWS\system32\hypertrm.dll
2009-05-13 12:54:56 ----A---- C:\WINDOWS\system32\spider.exe
2009-05-13 12:54:56 ----A---- C:\WINDOWS\system32\mspaint.exe
2009-05-13 12:54:56 ----A---- C:\WINDOWS\system32\clipbrd.exe
2009-05-13 12:54:55 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
2009-05-13 12:54:55 ----A---- C:\WINDOWS\system32\mstscax.dll
2009-05-13 12:54:54 ----A---- C:\WINDOWS\system32\tscupgrd.exe
2009-05-13 12:54:54 ----A---- C:\WINDOWS\system32\sessmgr.exe
2009-05-13 12:54:54 ----A---- C:\WINDOWS\system32\remotepg.dll
2009-05-13 12:54:54 ----A---- C:\WINDOWS\system32\rdshost.exe
2009-05-13 12:54:54 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2009-05-13 12:54:54 ----A---- C:\WINDOWS\system32\rdchost.dll
2009-05-13 12:54:54 ----A---- C:\WINDOWS\system32\mstsc.exe
2009-05-13 12:54:53 ----A---- C:\WINDOWS\system32\termsrv.dll
2009-05-13 12:54:53 ----A---- C:\WINDOWS\system32\rdpwsx.dll
2009-05-13 12:54:53 ----A---- C:\WINDOWS\system32\rdpsnd.dll
2009-05-13 12:54:53 ----A---- C:\WINDOWS\system32\rdpclip.exe
2009-05-13 12:54:53 ----A---- C:\WINDOWS\system32\qprocess.exe
2009-05-13 12:54:53 ----A---- C:\WINDOWS\system32\icaapi.dll
2009-05-13 12:54:53 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2009-05-13 12:54:52 ----A---- C:\WINDOWS\system32\mtxoci.dll
2009-05-13 12:54:52 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
2009-05-13 12:54:52 ----A---- C:\WINDOWS\system32\msdtctm.dll
2009-05-13 12:54:52 ----A---- C:\WINDOWS\system32\msdtcprx.dll
2009-05-13 12:54:51 ----A---- C:\WINDOWS\system32\xolehlp.dll
2009-05-13 12:54:51 ----A---- C:\WINDOWS\system32\msdtclog.dll
2009-05-13 12:54:51 ----A---- C:\WINDOWS\system32\msdtc.exe
2009-05-13 12:54:50 ----A---- C:\WINDOWS\system32\colbact.dll
2009-05-13 12:54:50 ----A---- C:\WINDOWS\system32\clbcatex.dll
2009-05-13 12:54:50 ----A---- C:\WINDOWS\system32\catsrvut.dll
2009-05-13 12:54:50 ----A---- C:\WINDOWS\system32\catsrvps.dll
2009-05-13 12:54:49 ----A---- C:\WINDOWS\system32\comsvcs.dll
2009-05-13 12:54:49 ----A---- C:\WINDOWS\system32\catsrv.dll
2009-05-13 12:54:48 ----A---- C:\WINDOWS\system32\comuid.dll
2009-05-13 12:54:48 ----A---- C:\WINDOWS\system32\clbcatq.dll
2009-05-13 12:54:41 ----A---- C:\WINDOWS\system32\servdeps.dll
2009-05-13 12:54:41 ----A---- C:\WINDOWS\system32\mmfutil.dll
2009-05-13 12:54:41 ----A---- C:\WINDOWS\system32\licwmi.dll
2009-05-13 12:54:41 ----A---- C:\WINDOWS\system32\cmprops.dll
2009-05-13 08:53:15 ----A---- C:\WINDOWS\system32\h323log.txt
2009-05-13 08:50:00 ----A---- C:\WINDOWS\system32\usbui.dll
2009-05-13 08:47:57 ----A---- C:\WINDOWS\imsins.BAK
2009-05-13 08:47:54 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-05-13 08:47:53 ----A---- C:\WINDOWS\ODBCINST.INI
2009-05-13 08:47:47 ----RA---- C:\WINDOWS\system32\kbdtuq.dll
2009-05-13 08:47:47 ----RA---- C:\WINDOWS\system32\kbdtuf.dll
2009-05-13 08:47:47 ----RA---- C:\WINDOWS\system32\kbdazel.dll
2009-05-13 08:47:45 ----RA---- C:\WINDOWS\system32\kbdtat.dll
2009-05-13 08:47:45 ----RA---- C:\WINDOWS\system32\kbdmon.dll
2009-05-13 08:47:45 ----RA---- C:\WINDOWS\system32\kbdkyr.dll
2009-05-13 08:47:45 ----RA---- C:\WINDOWS\system32\kbdaze.dll
2009-05-13 08:47:44 ----RA---- C:\WINDOWS\system32\kbdycc.dll
2009-05-13 08:47:44 ----RA---- C:\WINDOWS\system32\kbduzb.dll
2009-05-13 08:47:44 ----RA---- C:\WINDOWS\system32\kbdur.dll
2009-05-13 08:47:44 ----RA---- C:\WINDOWS\system32\kbdru1.dll
2009-05-13 08:47:44 ----RA---- C:\WINDOWS\system32\kbdru.dll
2009-05-13 08:47:44 ----RA---- C:\WINDOWS\system32\kbdkaz.dll
2009-05-13 08:47:44 ----RA---- C:\WINDOWS\system32\kbdbu.dll
2009-05-13 08:47:44 ----RA---- C:\WINDOWS\system32\kbdblr.dll
2009-05-13 08:47:42 ----RA---- C:\WINDOWS\system32\kbdhept.dll
2009-05-13 08:47:42 ----RA---- C:\WINDOWS\system32\kbdhela3.dll
2009-05-13 08:47:42 ----RA---- C:\WINDOWS\system32\kbdhela2.dll
2009-05-13 08:47:42 ----RA---- C:\WINDOWS\system32\kbdhe319.dll
2009-05-13 08:47:42 ----RA---- C:\WINDOWS\system32\kbdhe220.dll
2009-05-13 08:47:42 ----RA---- C:\WINDOWS\system32\kbdhe.dll
2009-05-13 08:47:42 ----RA---- C:\WINDOWS\system32\kbdgkl.dll
2009-05-13 08:47:35 ----RA---- C:\WINDOWS\system32\kbdlv1.dll
2009-05-13 08:47:35 ----RA---- C:\WINDOWS\system32\kbdlv.dll
2009-05-13 08:47:35 ----RA---- C:\WINDOWS\system32\kbdlt1.dll
2009-05-13 08:47:35 ----RA---- C:\WINDOWS\system32\kbdlt.dll
2009-05-13 08:47:35 ----RA---- C:\WINDOWS\system32\kbdest.dll
2009-05-13 08:47:32 ----RA---- C:\WINDOWS\system32\kbdsl1.dll
2009-05-13 08:47:32 ----RA---- C:\WINDOWS\system32\kbdsl.dll
2009-05-13 08:47:32 ----RA---- C:\WINDOWS\system32\kbdro.dll
2009-05-13 08:47:32 ----RA---- C:\WINDOWS\system32\kbdpl1.dll
2009-05-13 08:47:32 ----RA---- C:\WINDOWS\system32\kbdpl.dll
2009-05-13 08:47:32 ----RA---- C:\WINDOWS\system32\kbdhu1.dll
2009-05-13 08:47:32 ----RA---- C:\WINDOWS\system32\kbdhu.dll
2009-05-13 08:47:32 ----RA---- C:\WINDOWS\system32\kbdcz2.dll
2009-05-13 08:47:32 ----RA---- C:\WINDOWS\system32\kbdcz1.dll
2009-05-13 08:47:32 ----RA---- C:\WINDOWS\system32\kbdcz.dll
2009-05-13 08:47:32 ----RA---- C:\WINDOWS\system32\kbdcr.dll
2009-05-13 08:47:31 ----RA---- C:\WINDOWS\system32\kbdycl.dll
2009-05-13 08:47:31 ----RA---- C:\WINDOWS\system32\KBDAL.DLL
2009-05-13 08:47:28 ----A---- C:\WINDOWS\system32\spxcoins.dll
2009-05-13 08:47:28 ----A---- C:\WINDOWS\system32\irclass.dll
2009-05-13 08:47:28 ----A---- C:\WINDOWS\system32\EqnClass.Dll
2009-05-13 08:47:28 ----A---- C:\WINDOWS\system32\dgsetup.dll
2009-05-13 08:47:28 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
2009-05-13 08:47:25 ----N---- C:\WINDOWS\system32\CONFIG.TMP
2009-05-13 08:47:25 ----A---- C:\WINDOWS\TASKMAN.EXE
2009-05-13 08:47:24 ----A---- C:\WINDOWS\system32\batt.dll
2009-05-13 08:47:24 ----A---- C:\WINDOWS\notepad.exe
2009-05-13 08:47:23 ----A---- C:\WINDOWS\system32\storprop.dll
2009-05-13 08:47:12 ----ASH---- C:\Documents and Settings\All Users.WINDOWS\Application Data\desktop.ini
2009-05-13 08:47:11 ----RA---- C:\WINDOWS\SET2A.tmp
2009-05-13 08:47:11 ----RA---- C:\WINDOWS\SET29.tmp
2009-05-13 08:47:07 ----RA---- C:\WINDOWS\SET8.tmp
2009-05-13 08:47:04 ----RA---- C:\WINDOWS\SET4.tmp
2009-05-13 08:47:03 ----RA---- C:\WINDOWS\SET3.tmp
2009-05-13 08:46:52 ----SD---- C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft
2009-05-13 08:46:26 ----A---- C:\WINDOWS\setuplog.txt
2009-05-13 08:22:20 ----D---- C:\WINDOWS\dell
2009-05-11 16:50:49 ----D---- C:\WINDOWS\ERDNT
2009-05-11 15:22:54 ----D---- C:\Program Files\TMHJT
2009-05-11 12:25:08 ----HD---- C:\WINDOWS\PIF
2009-05-10 03:00:13 ----HDC---- C:\WINDOWS\$NtUninstallKB954459$
2009-05-07 12:14:33 ----HD---- C:\$AVG8.VAULT$
2009-05-07 11:21:45 ----D---- C:\Program Files\AVG
2009-05-07 03:00:20 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
2009-05-06 15:23:02 ----D---- C:\WINDOWS\system32\XPSViewer
2009-05-06 15:23:00 ----D---- C:\Program Files\MSBuild
2009-05-06 15:22:55 ----D---- C:\Program Files\Reference Assemblies
2009-05-06 15:22:34 ----D---- C:\2926076ff8ca37070f90
2009-05-06 14:10:02 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2009-05-06 14:09:56 ----HDC---- C:\WINDOWS\$NtUninstallKB938464-v2_0$
2009-05-06 12:28:55 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2009-05-06 12:28:49 ----HDC---- C:\WINDOWS\$NtUninstallKB961373$
2009-05-06 12:28:45 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2009-05-06 12:28:38 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2009-05-06 12:28:34 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2009-05-06 12:28:30 ----HDC---- C:\WINDOWS\$NtUninstallKB958690$
2009-05-06 12:28:26 ----HDC---- C:\WINDOWS\$NtUninstallKB958687$
2009-05-06 12:28:22 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2009-05-06 12:28:17 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
2009-05-06 12:28:13 ----HDC---- C:\WINDOWS\$NtUninstallKB957095$
2009-05-06 12:28:09 ----HDC---- C:\WINDOWS\$NtUninstallKB956841$
2009-05-06 12:28:04 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2009-05-06 12:28:00 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2009-05-06 12:27:52 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2009-05-06 12:27:45 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2009-05-06 12:27:41 ----HDC---- C:\WINDOWS\$NtUninstallKB954600$
2009-05-06 12:27:36 ----HDC---- C:\WINDOWS\$NtUninstallKB954211$
2009-05-06 12:27:31 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2009-05-06 12:27:26 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2009-05-06 12:27:21 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2009-05-06 12:27:17 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2009-05-06 12:27:13 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
2009-05-06 12:27:09 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2009-05-06 12:27:03 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2009-05-06 12:26:59 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2009-05-06 12:26:56 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2009-05-06 12:26:52 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2009-05-06 12:26:49 ----HDC---- C:\WINDOWS\$NtUninstallKB938464$
2009-05-06 12:26:44 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2009-05-06 12:24:05 ----D---- C:\WINDOWS\system32\scripting
2009-05-06 12:24:05 ----D---- C:\WINDOWS\system32\en
2009-05-06 12:24:05 ----D---- C:\WINDOWS\l2schemas
2009-05-06 12:22:37 ----D---- C:\WINDOWS\ServicePackFiles
2009-05-06 12:21:20 ----D---- C:\WINDOWS\network diagnostic
2009-05-06 12:18:54 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2009-05-06 10:55:15 ----D---- C:\Program Files\Matt
2009-05-05 15:51:53 ----D---- C:\WINDOWS\system32\bits
2009-05-05 15:51:49 ----HDC---- C:\WINDOWS\$NtUninstallKB923845$
2009-05-05 15:51:41 ----HDC---- C:\WINDOWS\$NtUninstallKB914882$
2009-05-05 15:26:44 ----HD---- C:\Config.Msi
2009-05-05 10:45:24 ----D---- C:\Program Files\Windows Live Safety Center
2009-05-04 09:40:34 ----D---- C:\WINDOWS\ie8updates
2009-05-04 09:40:03 ----D---- C:\WINDOWS\WBEM
2009-05-04 09:39:01 ----HDC---- C:\WINDOWS\ie8
2009-05-04 09:39:01 ----D---- C:\WINDOWS\system32\en-US
2009-05-04 09:34:48 ----HDC---- C:\WINDOWS\$NtUninstallKB932823-v3$
2009-05-01 08:34:36 ----D---- C:\WINDOWS\system32\LogFiles
2009-04-30 15:28:38 ----A---- C:\WINDOWS\system32\Prounstl.exe
2009-04-30 15:28:38 ----A---- C:\WINDOWS\system32\NicInstE.dll
2009-04-30 15:28:38 ----A---- C:\WINDOWS\system32\NicEtCoE.dll
2009-04-30 15:28:38 ----A---- C:\WINDOWS\system32\NicCo.dll
2009-04-30 15:28:38 ----A---- C:\WINDOWS\system32\e1000msg.dll
2009-04-30 15:19:33 ----D---- C:\WINDOWS\OPTIONS
2009-04-30 15:19:33 ----D---- C:\Program Files\Realtek
2009-04-30 15:17:49 ----D---- C:\WINDOWS\system32\vmm32
2009-04-30 13:27:03 ----D---- C:\Program Files\Viewpoint
2009-04-30 13:17:02 ----HD---- C:\WINDOWS\system32\GroupPolicy
2009-04-30 12:37:57 ----SHD---- C:\WINDOWS\CSC
2009-04-30 10:14:30 ----D---- C:\WINDOWS\system32\appmgmt
2009-04-29 11:14:45 ----D---- C:\WINDOWS\pss

======List of files/folders modified in the last 1 months======

2009-05-19 09:29:34 ----D---- C:\Program Files\Mozilla Firefox
2009-05-19 09:13:00 ----SD---- C:\WINDOWS\Tasks
2009-05-14 14:41:01 ----RD---- C:\Program Files
2009-05-14 14:22:38 ----D---- C:\WINDOWS\system32
2009-05-14 14:22:38 ----D---- C:\WINDOWS
2009-05-14 14:21:37 ----A---- C:\WINDOWS\system.ini
2009-05-14 14:21:09 ----D---- C:\WINDOWS\system32\drivers
2009-05-14 14:21:09 ----D---- C:\WINDOWS\AppPatch
2009-05-14 14:21:07 ----D---- C:\Program Files\Common Files
2009-05-14 14:20:12 ----D---- C:\WINDOWS\system32\CatRoot2
2009-05-14 13:07:05 ----RASH---- C:\boot.ini
2009-05-14 12:44:44 ----D---- C:\Program Files\AIM6
2009-05-14 12:18:05 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-05-14 12:17:50 ----SHD---- C:\WINDOWS\Installer
2009-05-14 12:17:50 ----D---- C:\WINDOWS\WinSxS
2009-05-14 11:47:09 ----D---- C:\Program Files\Common Files\Microsoft Shared
2009-05-14 11:43:29 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-05-14 11:43:11 ----HD---- C:\WINDOWS\inf
2009-05-14 11:41:55 ----D---- C:\Program Files\Internet Explorer
2009-05-14 11:41:54 ----D---- C:\WINDOWS\system32\wbem
2009-05-14 11:41:54 ----D---- C:\WINDOWS\Help
2009-05-14 11:40:24 ----HD---- C:\WINDOWS\$hf_mig$
2009-05-14 11:40:06 ----D---- C:\WINDOWS\Media
2009-05-14 11:38:38 ----D---- C:\WINDOWS\Debug
2009-05-14 11:38:06 ----D---- C:\WINDOWS\system32\CatRoot
2009-05-14 11:34:54 ----D---- C:\Program Files\Messenger
2009-05-14 11:24:20 ----D---- C:\WINDOWS\system32\Setup
2009-05-14 11:24:19 ----RD---- C:\WINDOWS\Fonts
2009-05-14 11:23:37 ----D---- C:\WINDOWS\security
2009-05-14 11:19:40 ----D---- C:\Program Files\Windows Media Player
2009-05-14 11:19:26 ----D---- C:\WINDOWS\system32\inetsrv
2009-05-14 11:19:26 ----D---- C:\WINDOWS\ime
2009-05-14 11:19:18 ----D---- C:\WINDOWS\system32\usmt
2009-05-14 11:19:16 ----D---- C:\WINDOWS\PeerNet
2009-05-14 11:19:16 ----D---- C:\Program Files\Movie Maker
2009-05-14 11:17:36 ----D---- C:\WINDOWS\system32\Restore
2009-05-14 11:17:35 ----D---- C:\WINDOWS\system32\npp
2009-05-14 11:17:35 ----D---- C:\WINDOWS\mui
2009-05-14 11:17:34 ----D---- C:\WINDOWS\msagent
2009-05-14 11:17:33 ----D---- C:\WINDOWS\srchasst
2009-05-14 11:17:33 ----D---- C:\Program Files\NetMeeting
2009-05-14 11:17:32 ----D---- C:\WINDOWS\system32\Com
2009-05-14 11:17:29 ----D---- C:\Program Files\Windows NT
2009-05-14 11:17:29 ----D---- C:\Program Files\Outlook Express
2009-05-14 11:17:26 ----D---- C:\Program Files\Common Files\System
2009-05-14 11:17:07 ----D---- C:\WINDOWS\system32\oobe
2009-05-14 11:17:05 ----D---- C:\WINDOWS\system
2009-05-14 11:12:51 ----D---- C:\WINDOWS\ehome
2009-05-14 09:17:43 ----D---- C:\WINDOWS\SoftwareDistribution
2009-05-14 03:02:59 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$
2009-05-14 03:02:06 ----D---- C:\WINDOWS\Registration
2009-05-14 03:00:30 ----HDC---- C:\WINDOWS\$NtUninstallKB963027_0$
2009-05-13 13:57:50 ----D---- C:\WINDOWS\system32\URTTemp
2009-05-13 13:57:27 ----RSD---- C:\WINDOWS\assembly
2009-05-13 13:37:45 ----D---- C:\Program Files\Microsoft Works
2009-05-13 13:18:53 ----DC---- C:\WINDOWS\system32\DRVSTORE
2009-05-13 13:18:13 ----D---- C:\Program Files\Intel
2009-05-13 13:13:55 ----D---- C:\Program Files\Java
2009-05-13 13:05:05 ----D---- C:\Documents and Settings
2009-05-13 13:04:17 ----SHD---- C:\System Volume Information
2009-05-13 13:03:28 ----D---- C:\WINDOWS\system32\config
2009-05-13 13:00:08 ----A---- C:\WINDOWS\win.ini
2009-05-13 12:58:48 ----RD---- C:\WINDOWS\Web
2009-05-13 12:55:49 ----D---- C:\WINDOWS\system32\MsDtc
2009-05-13 12:55:32 ----D---- C:\WINDOWS\Cursors
2009-05-13 08:41:29 ----D---- C:\WINDOWS\twain_32
2009-05-13 08:41:06 ----D---- C:\WINDOWS\system32\ras
2009-05-13 08:40:42 ----D---- C:\WINDOWS\system32\icsxml
2009-05-13 08:40:21 ----D---- C:\WINDOWS\system32\ias
2009-05-13 08:40:17 ----D---- C:\WINDOWS\system32\1033
2009-05-13 08:39:28 ----D---- C:\WINDOWS\system32\RTCOM
2009-05-13 08:39:26 ----D---- C:\WINDOWS\system32\Lang
2009-05-13 08:39:18 ----D---- C:\WINDOWS\system32\BWKDLogs
2009-05-13 08:39:16 ----HD---- C:\WINDOWS\ShellNew
2009-05-13 08:39:16 ----D---- C:\WINDOWS\repair
2009-05-13 08:39:15 ----RD---- C:\WINDOWS\Offline Web Pages
2009-05-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB967715_0$
2009-05-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB961373_0$
2009-05-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB960803_0$
2009-05-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB960715$
2009-05-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB960714$
2009-05-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB960225_0$
2009-05-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB959426_0$
2009-05-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB958690_0$
2009-05-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB958687_0$
2009-05-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB958644_0$
2009-05-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB958215$
2009-05-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB957097_0$
2009-05-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB957095_0$
2009-05-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB956841_0$
2009-05-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB956803_0$
2009-05-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB956802_0$
2009-05-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB956572_0$
2009-05-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB956391$
2009-05-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB956390$
2009-05-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB955839$
2009-05-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB955069_0$
2009-05-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB954600_0$
2009-05-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB954211_0$
2009-05-13 08:39:10 ----D---- C:\WINDOWS\addins
2009-05-13 08:39:09 ----HDC---- C:\WINDOWS\$NtUninstallKB953839$
2009-05-13 08:39:09 ----HDC---- C:\WINDOWS\$NtUninstallKB953838$
2009-05-13 08:39:09 ----HDC---- C:\WINDOWS\$NtUninstallKB952954_0$
2009-05-13 08:39:09 ----HDC---- C:\WINDOWS\$NtUninstallKB952287_0$
2009-05-13 08:39:09 ----HDC---- C:\WINDOWS\$NtUninstallKB952004_0$
2009-05-13 08:39:09 ----HDC---- C:\WINDOWS\$NtUninstallKB951748_0$
2009-05-13 08:39:09 ----HDC---- C:\WINDOWS\$NtUninstallKB951698_0$
2009-05-13 08:39:09 ----HDC---- C:\WINDOWS\$NtUninstallKB951072-v2$
2009-05-13 08:39:09 ----HDC---- C:\WINDOWS\$NtUninstallKB951066_0$
2009-05-13 08:39:09 ----HDC---- C:\WINDOWS\$NtUninstallKB950974_0$
2009-05-13 08:39:09 ----HDC---- C:\WINDOWS\$NtUninstallKB950762_0$
2009-05-13 08:39:09 ----HDC---- C:\WINDOWS\$NtUninstallKB946648_0$
2009-05-13 08:39:09 ----HDC---- C:\WINDOWS\$NtUninstallKB931784$
2009-05-13 08:39:09 ----HDC---- C:\WINDOWS\$NtUninstallKB923723$
2009-05-13 08:39:09 ----HDC---- C:\WINDOWS\$NtUninstallKB923561_0$
2009-05-13 08:39:09 ----HDC---- C:\WINDOWS\$NtUninstallKB896256$
2009-05-13 08:22:20 ----D---- C:\WINDOWS\Driver Cache
2009-05-12 16:23:33 ----D---- C:\i386
2009-05-11 16:26:13 ----HD---- C:\Program Files\InstallShield Installation Information
2009-05-11 15:14:31 ----D---- C:\Program Files\Common Files\Services
2009-05-06 15:37:31 ----D---- C:\WINDOWS\Microsoft.NET
2009-05-06 15:22:43 ----D---- C:\WINDOWS\system32\spool
2009-05-01 16:07:38 ----D---- C:\Program Files\Dell
2009-04-30 15:19:16 ----D---- C:\dell

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2009-05-14 325896]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2009-05-14 27784]
R1 AvgTdiX;AVG Free8 Network Redirector; C:\WINDOWS\System32\Drivers\avgtdix.sys [2009-05-14 108552]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
R3 e1express;Intel® PRO/1000 PCI Express Network Connection Driver; C:\WINDOWS\system32\DRIVERS\e1e5132.sys [2007-04-13 254872]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2007-04-16 5760096]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2004-08-04 12160]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 catchme;catchme; \??\C:\DOCUME~1\MATT~1.MCM\LOCALS~1\Temp\catchme.sys []
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avg8emc;AVG Free8 E-mail Scanner; C:\PROGRA~1\AVG\AVG8\avgemc.exe [2009-05-07 908568]
R2 avg8wd;AVG Free8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2009-05-07 298776]
R2 Viewpoint Manager Service;Viewpoint Manager Service; C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]

-----------------EOF-----------------

#5 scarfacek1ngofny

scarfacek1ngofny
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:12:58 PM

Posted 19 May 2009 - 09:39 AM

KASPERSKY ONLINE SCANNER 7.0 REPORT
Tuesday, May 19, 2009
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Tuesday, May 19, 2009 12:27:45
Records in database: 2196013
Scan settings
Scan using the following database extended
Scan archives yes
Scan mail databases yes
Scan area My Computer
C:\
D:\
Scan statistics
Files scanned 54836
Threat name 0
Infected objects 0
Suspicious objects 0
Duration of the scan 00:50:00

No malware has been detected. The scan area is clean.
The selected area was scanned.

#6 thewall

thewall

  • Malware Response Team
  • 6,425 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Florida
  • Local time:11:58 AM

Posted 19 May 2009 - 10:08 AM

I see that you have ComboFix installed on your machine. Did you run it and if you did can you provide me with the log it produced? Also just to double check I see your AVG is disabled, I am assuming you did that and are aware of it but I still need to ask you about it to be sure.
If I have helped you then please consider donating so I can continue the fight against malware Posted Image
All donations go directly to the helper

Posted Image

Due to the large amount of backlogs we have I cannot respond to PMs for help unless I am already working with you

#7 scarfacek1ngofny

scarfacek1ngofny
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:12:58 PM

Posted 19 May 2009 - 10:33 AM

I ran it prior to coming here and did not make note of where I saved the log. When i windows search it I find a few logs. I disabled AVG on purpose so it would not interfere with the other 2 scans and it is now re-enabled. Should I re-run combofix?

#8 thewall

thewall

  • Malware Response Team
  • 6,425 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Florida
  • Local time:11:58 AM

Posted 19 May 2009 - 10:45 AM

Look here for the text:

C:\ComboFix.txt.


No please do not run it again. I just wanted to see the log it had produced if you can find it.
If I have helped you then please consider donating so I can continue the fight against malware Posted Image
All donations go directly to the helper

Posted Image

Due to the large amount of backlogs we have I cannot respond to PMs for help unless I am already working with you

#9 scarfacek1ngofny

scarfacek1ngofny
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:12:58 PM

Posted 19 May 2009 - 10:53 AM

Bingo:

ComboFix 09-05-13.04 - Matt 05/14/2009 14:20.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2037.1533 [GMT -4:00]
Running from: c:\documents and settings\Matt.MCMATT\Desktop\Combo-Fix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((( Files Created from 2009-04-14 to 2009-05-14 )))))))))))))))))))))))))))))))
.

2009-05-14 17:14 . 2009-05-14 17:14 -------- d-----w c:\documents and settings\Matt.MCMATT\Application Data\Malwarebytes
2009-05-14 17:14 . 2009-04-06 19:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-05-14 17:14 . 2009-04-06 19:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-14 17:14 . 2009-05-14 17:14 -------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes
2009-05-14 17:14 . 2009-05-14 17:14 -------- d-----w c:\program files\Malwarebytes' Anti-Malware1
2009-05-14 17:02 . 2009-05-14 17:02 -------- d-sh--w c:\documents and settings\Matt.MCMATT\PrivacIE
2009-05-14 16:44 . 2009-05-14 16:44 -------- d-----w c:\documents and settings\Matt.MCMATT\Local Settings\Application Data\AOL OCP
2009-05-14 16:18 . 2009-05-14 16:18 -------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\Viewpoint
2009-05-14 16:18 . 2009-05-14 16:18 -------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\acccore
2009-05-14 16:18 . 2009-05-14 16:18 -------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\AOL OCP
2009-05-14 16:18 . 2009-05-14 16:18 -------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\AOL
2009-05-14 16:17 . 2009-05-14 16:17 -------- d-----w c:\documents and settings\Matt.MCMATT\Local Settings\Application Data\AOL
2009-05-14 15:47 . 2009-05-14 15:47 11952 ----a-w c:\windows\system32\avgrsstx.dll
2009-05-14 15:47 . 2009-05-14 15:47 108552 ----a-w c:\windows\system32\drivers\avgtdix.sys
2009-05-14 15:47 . 2009-05-14 15:47 325896 ----a-w c:\windows\system32\drivers\avgldx86.sys
2009-05-14 15:47 . 2009-05-14 17:02 -------- d-----w c:\documents and settings\Matt.MCMATT\Application Data\AVGTOOLBAR
2009-05-14 15:47 . 2009-05-14 15:47 -------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\avg8
2009-05-14 15:42 . 2009-05-14 15:42 -------- d-sh--w c:\documents and settings\Matt.MCMATT\IETldCache
2009-05-14 15:40 . 2009-04-25 05:30 102400 -c----w c:\windows\system32\dllcache\iecompat.dll
2009-05-14 15:33 . 2009-05-14 15:33 -------- d-----w c:\documents and settings\Matt.MCMATT\Local Settings\Application Data\ApplicationHistory
2009-05-14 15:24 . 2008-04-14 00:12 221184 ----a-w c:\windows\system32\wmpns.dll
2009-05-14 15:08 . 2004-08-04 02:29 12047 ------w c:\windows\system32\drivers\ati1pdxx.sys
2009-05-13 22:22 . 2008-05-08 14:02 203136 -c----w c:\windows\system32\dllcache\rmcast.sys
2009-05-13 22:22 . 2008-10-24 11:21 455296 -c----w c:\windows\system32\dllcache\mrxsmb.sys
2009-05-13 22:22 . 2008-12-11 10:57 333952 -c----w c:\windows\system32\dllcache\srv.sys
2009-05-13 22:21 . 2008-04-11 19:04 691712 -c----w c:\windows\system32\dllcache\inetcomm.dll
2009-05-13 22:19 . 2008-10-15 16:34 337408 -c----w c:\windows\system32\dllcache\netapi32.dll
2009-05-13 22:19 . 2008-05-03 11:55 2560 ------w c:\windows\system32\xpsp4res.dll
2009-05-13 22:19 . 2008-04-21 12:08 215552 -c----w c:\windows\system32\dllcache\wordpad.exe
2009-05-13 20:13 . 2009-01-07 22:21 26144 ----a-w c:\windows\system32\spupdsvc.exe
2009-05-13 20:11 . 2008-10-16 18:09 43544 ----a-w c:\windows\system32\wups2.dll
2009-05-13 20:10 . 2009-05-13 20:10 -------- d-s---w c:\documents and settings\Matt.MCMATT\UserData
2009-05-13 17:59 . 2009-05-13 17:59 -------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\HPSSUPPLY
2009-05-13 17:55 . 2007-08-23 14:34 65536 ----a-w c:\windows\system32\HPPLVS.dll
2009-05-13 17:55 . 2007-09-10 19:12 253952 ----a-w c:\windows\system32\HP1006LM.DLL
2009-05-13 17:51 . 2009-05-13 17:51 0 ----a-w c:\windows\nsreg.dat
2009-05-13 17:51 . 2009-05-13 17:51 -------- d-----w c:\documents and settings\Matt.MCMATT\Local Settings\Application Data\Mozilla
2009-05-13 17:48 . 2009-05-14 15:28 35760 ----a-w c:\documents and settings\Matt.MCMATT\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-13 17:20 . 2007-04-16 23:50 172032 ----a-w c:\windows\system32\igfxres.dll
2009-05-13 17:15 . 2009-05-13 17:15 -------- d-----w C:\Intel
2009-05-13 17:13 . 2009-05-13 17:13 -------- d-----w c:\documents and settings\Matt.MCMATT\Local Settings\Application Data\{3248F0A6-6813-11D6-A77B-00B0D0150060}
2009-05-13 17:12 . 2009-05-13 17:12 -------- d-----w c:\documents and settings\Matt.MCMATT\Application Data\InstallShield
2009-05-13 17:04 . 2009-05-14 15:25 -------- d-----w c:\documents and settings\LocalService.NT AUTHORITY\Local Settings\Application Data\Microsoft
2009-05-13 17:04 . 2009-05-13 17:04 -------- d-sh--w c:\documents and settings\LocalService.NT AUTHORITY
2009-05-13 17:03 . 2009-05-14 15:46 -------- d-----w c:\documents and settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Microsoft
2009-05-13 17:03 . 2009-05-13 17:03 -------- d-sh--w c:\documents and settings\NetworkService.NT AUTHORITY
2009-05-13 17:01 . 2004-08-04 05:00 92416 -c--a-w c:\windows\system32\dllcache\mga.sys
2009-05-13 17:00 . 2001-08-18 02:36 5632 -c--a-w c:\windows\system32\dllcache\EXCH_adsiisex.dll
2009-05-13 16:58 . 2009-05-13 16:58 -------- d-sh--w c:\documents and settings\All Users.WINDOWS\DRM
2009-05-13 16:56 . 2008-04-14 00:12 105984 ----a-w c:\windows\system32\msoert2.dll
2009-05-13 16:56 . 2008-04-14 00:12 252928 ----a-w c:\windows\system32\msoeacct.dll
2009-05-13 16:56 . 2008-04-13 16:22 48128 ----a-w c:\windows\system32\inetres.dll
2009-05-13 16:56 . 2008-04-11 19:04 691712 ----a-w c:\windows\system32\inetcomm.dll
2009-05-13 16:56 . 2008-04-14 00:12 192512 ----a-w c:\windows\system32\schedsvc.dll
2009-05-13 16:56 . 2008-04-14 00:12 12288 ----a-w c:\windows\system32\mstinit.exe
2009-05-13 16:56 . 2008-04-14 00:12 274944 ----a-w c:\windows\system32\mstask.dll
2009-05-13 16:56 . 2008-04-14 00:11 65536 ----a-w c:\windows\system32\icwphbk.dll
2009-05-13 16:56 . 2008-04-14 00:11 73728 ----a-w c:\windows\system32\icwdial.dll
2009-05-13 16:56 . 2008-04-14 00:11 81920 ----a-w c:\windows\system32\isign32.dll
2009-05-13 16:56 . 2008-04-14 00:11 274432 ----a-w c:\windows\system32\inetcfg.dll
2009-05-13 16:56 . 2009-05-13 16:56 21640 ----a-w c:\windows\system32\emptyregdb.dat
2009-05-13 16:54 . 2008-04-14 00:12 184320 ----a-w c:\windows\system32\accwiz.exe
2009-05-13 12:51 . 2001-08-17 13:59 3072 ----a-w c:\windows\system32\drivers\audstub.sys
2009-05-13 12:51 . 2008-04-13 18:47 25856 ----a-w c:\windows\system32\drivers\usbprint.sys
2009-05-13 12:50 . 2008-04-13 18:40 57600 ----a-w c:\windows\system32\drivers\redbook.sys
2009-05-13 12:50 . 2008-04-14 00:12 74240 ----a-w c:\windows\system32\usbui.dll
2009-05-13 12:46 . 2009-05-13 16:58 -------- d-----w c:\documents and settings\All Users.WINDOWS
2009-05-13 12:46 . 2009-05-14 15:25 -------- d--h--w c:\documents and settings\Default User.WINDOWS
2009-05-13 12:22 . 2009-05-13 12:22 -------- d-----w c:\windows\dell
2009-05-11 19:22 . 2009-05-11 19:22 -------- d-----w c:\program files\TMHJT
2009-05-11 16:25 . 2009-05-11 16:25 -------- d--h--w c:\windows\PIF
2009-05-07 18:28 . 2009-05-07 18:28 -------- d-----w c:\documents and settings\log
2009-05-07 16:14 . 2009-05-13 13:10 -------- d--h--w C:\$AVG8.VAULT$
2009-05-07 15:22 . 2009-05-14 16:01 -------- d-----w c:\windows\system32\drivers\Avg
2009-05-07 15:22 . 2009-05-07 15:22 -------- d-----w c:\documents and settings\Matt\Application Data\AVGTOOLBAR
2009-05-07 15:21 . 2009-05-07 15:21 -------- d-----w c:\program files\AVG
2009-05-07 14:51 . 2009-05-07 14:51 -------- d-----w c:\documents and settings\Matt\Application Data\AVG8
2009-05-06 19:23 . 2009-05-13 12:39 -------- d-----w c:\windows\system32\XPSViewer
2009-05-06 19:23 . 2009-05-06 19:23 -------- d-----w c:\program files\MSBuild
2009-05-06 19:22 . 2009-05-06 19:22 -------- d-----w c:\program files\Reference Assemblies
2009-05-06 19:22 . 2009-05-06 19:22 -------- d-----w C:\2926076ff8ca37070f90
2009-05-06 16:24 . 2009-05-14 15:19 -------- d-----w c:\windows\system32\scripting
2009-05-06 16:24 . 2009-05-14 15:19 -------- d-----w c:\windows\l2schemas
2009-05-06 16:24 . 2009-05-14 15:19 -------- d-----w c:\windows\system32\en
2009-05-06 16:22 . 2009-05-06 16:22 -------- d-----w c:\windows\ServicePackFiles
2009-05-06 14:55 . 2009-05-06 14:55 -------- d-----w c:\program files\Matt
2009-05-05 19:54 . 2009-05-05 19:54 -------- d-sh--w c:\documents and settings\LocalService\IETldCache
2009-05-05 19:51 . 2009-05-14 15:19 -------- d-----w c:\windows\system32\bits
2009-05-05 14:45 . 2009-05-07 15:39 -------- d-----w c:\program files\Windows Live Safety Center
2009-05-05 14:44 . 2009-05-05 14:44 -------- d-sh--w c:\documents and settings\Matt\PrivacIE
2009-05-04 13:41 . 2009-05-04 13:41 -------- d-sh--w c:\documents and settings\NetworkService\IETldCache
2009-05-04 13:41 . 2009-05-04 13:41 -------- d-sh--w c:\documents and settings\Matt\IETldCache
2009-05-04 13:40 . 2009-05-04 13:40 -------- d-----w c:\windows\ie8updates
2009-05-04 13:39 . 2009-05-14 15:40 -------- dc-h--w c:\windows\ie8
2009-05-01 12:34 . 2009-05-01 12:34 -------- d-----w c:\windows\system32\LogFiles
2009-04-30 19:28 . 2007-01-18 03:02 28536 ----a-w c:\windows\system32\NicCo.dll
2009-04-30 19:28 . 2007-01-18 03:02 66424 ----a-w c:\windows\system32\NicEtCoE.dll
2009-04-30 19:28 . 2007-01-30 01:36 62840 ----a-w c:\windows\system32\NicInstE.dll
2009-04-30 19:28 . 2007-04-12 22:47 154496 ----a-w c:\windows\system32\Prounstl.exe
2009-04-30 19:28 . 2007-04-14 00:33 254872 ----a-w c:\windows\system32\drivers\e1e5132.sys
2009-04-30 19:28 . 2007-01-18 02:59 179048 ----a-w c:\windows\system32\e1000msg.dll
2009-04-30 19:19 . 2009-04-30 19:19 -------- d-----w c:\windows\OPTIONS
2009-04-30 19:19 . 2009-04-30 19:19 -------- d-----w c:\program files\Realtek
2009-04-30 19:17 . 2009-05-13 12:39 -------- d-----w c:\windows\system32\vmm32
2009-04-30 17:27 . 2009-05-14 16:18 -------- d-----w c:\program files\Viewpoint
2009-04-30 17:17 . 2009-05-13 12:39 -------- d--h--w c:\windows\system32\GroupPolicy
2009-04-30 16:40 . 2009-04-30 16:40 -------- d-----w c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2009-04-30 14:18 . 2009-04-30 14:18 -------- d-----w c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-04-29 15:27 . 2009-04-29 15:27 -------- d-----w c:\documents and settings\Matt\Application Data\Malwarebytes
2009-04-29 15:19 . 2009-04-29 15:19 -------- d-----w c:\documents and settings\NetworkService\Local Settings\Application Data\Google

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-14 16:44 . 2008-10-02 14:12 -------- d-----w c:\program files\AIM6
2009-05-13 17:37 . 2008-08-12 05:06 -------- d-----w c:\program files\Microsoft Works
2009-05-13 17:18 . 2008-08-12 05:01 -------- d-----w c:\program files\Intel
2009-05-13 17:13 . 2008-08-12 04:59 -------- d-----w c:\program files\Java
2009-05-13 17:12 . 2009-05-13 17:12 5 ----a-w c:\windows\system32\drivers\DELL_XPS_Vostro 200.MRK
2009-05-13 17:12 . 2009-05-13 17:12 5 ----a-w c:\windows\system32\drivers\1028_DELL_XPS_Vostro 200.MRK
2009-05-11 20:26 . 2008-08-12 05:01 -------- d--h--w c:\program files\InstallShield Installation Information
2009-05-11 13:47 . 2008-10-22 13:48 960 ----a-w c:\documents and settings\Matt\Application Data\wklnhst.dat
2009-05-07 03:05 . 2008-08-12 05:10 37008 ----a-w c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-01 20:07 . 2008-08-12 05:05 -------- d-----w c:\program files\Dell
2009-04-17 15:06 . 2008-08-12 05:05 -------- d-----w c:\program files\Google
2009-04-10 07:00 . 2009-04-10 07:00 -------- d-----w c:\program files\MSXML 4.0
2009-04-09 14:27 . 2009-04-09 14:27 -------- d-----w c:\program files\QuickTime
2009-04-09 14:27 . 2009-04-09 14:25 -------- d-----w c:\program files\Kodak
2009-04-09 14:26 . 2009-04-09 14:26 -------- d-----w c:\program files\Common Files\Kodak
2009-03-08 08:34 . 2006-03-03 22:33 914944 ----a-w c:\windows\system32\wininet.dll
2009-03-08 08:34 . 2004-08-04 05:00 43008 ----a-w c:\windows\system32\licmgr10.dll
2009-03-08 08:33 . 2004-08-04 05:00 18944 ----a-w c:\windows\system32\corpol.dll
2009-03-08 08:33 . 2004-08-04 05:00 420352 ----a-w c:\windows\system32\vbscript.dll
2009-03-08 08:32 . 2004-08-04 05:00 72704 ----a-w c:\windows\system32\admparse.dll
2009-03-08 08:32 . 2004-08-04 05:00 71680 ----a-w c:\windows\system32\iesetup.dll
2009-03-08 08:31 . 2004-08-04 05:00 34816 ----a-w c:\windows\system32\imgutil.dll
2009-03-08 08:31 . 2004-08-04 05:00 48128 ----a-w c:\windows\system32\mshtmler.dll
2009-03-08 08:31 . 2004-08-04 05:00 45568 ----a-w c:\windows\system32\mshta.exe
2009-03-08 08:22 . 2004-08-04 05:00 156160 ----a-w c:\windows\system32\msls31.dll
2009-03-06 14:22 . 2004-08-04 05:00 284160 ----a-w c:\windows\system32\pdh.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 36975]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-04-16 142104]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-04-16 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-04-16 138008]
"hpbdfawep"="c:\program files\HP\Dfawep\bin\hpbdfawep.exe" [2007-04-25 954368]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-05-07 1947928]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-14 15:47 11952 ----a-w c:\windows\system32\avgrsstx.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\HP1006MC.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [5/14/2009 11:47 AM 325896]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [5/14/2009 11:47 AM 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [5/7/2009 11:58 AM 908568]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [5/7/2009 11:58 AM 298776]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [5/14/2009 12:18 PM 24652]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - VIEWPOINT_MANAGER_SERVICE

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-05-14 c:\windows\Tasks\HP WEP.job
- c:\program files\HP\Dfawep\bin\hpbdfawep.exe [2007-04-25 18:28]
.
.
------- Supplementary Scan -------
.
FF - ProfilePath - c:\documents and settings\Matt.MCMATT\Application Data\Mozilla\Firefox\Profiles\w5lhayc9.default\
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\ToolbarFF\components\vmAVGConnector.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-14 14:21
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(3832)
c:\windows\system32\ieframe.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
.
Completion time: 2009-05-14 14:22
ComboFix-quarantined-files.txt 2009-05-14 18:22
ComboFix2.txt 2009-05-14 17:09

Pre-Run: 66,052,513,792 bytes free
Post-Run: 66,043,371,520 bytes free

225 --- E O F --- 2009-05-14 07:04

#10 thewall

thewall

  • Malware Response Team
  • 6,425 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Florida
  • Local time:11:58 AM

Posted 19 May 2009 - 11:37 AM

Thanks, I'll study over them and get with a coach on what I see. I will get back as soon as I can but it may be tomorrow at least.
If I have helped you then please consider donating so I can continue the fight against malware Posted Image
All donations go directly to the helper

Posted Image

Due to the large amount of backlogs we have I cannot respond to PMs for help unless I am already working with you

#11 scarfacek1ngofny

scarfacek1ngofny
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:12:58 PM

Posted 19 May 2009 - 01:47 PM

Thanks, I appreciate it.

#12 thewall

thewall

  • Malware Response Team
  • 6,425 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Florida
  • Local time:11:58 AM

Posted 22 May 2009 - 07:35 AM

Sorry about the delay, we are always super busy here.


Please download GooredFix and save it to your Desktop. Double-click Goored.exe to run it. Select 1. Find Goored (no fix) by typing 1 and pressing Enter. A log will open, please post the contents of that log in your next reply (it can also be found on your desktop, called Goored.txt). Note: Do not run Option #2 yet.
If I have helped you then please consider donating so I can continue the fight against malware Posted Image
All donations go directly to the helper

Posted Image

Due to the large amount of backlogs we have I cannot respond to PMs for help unless I am already working with you

#13 scarfacek1ngofny

scarfacek1ngofny
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:12:58 PM

Posted 22 May 2009 - 09:06 AM

GooredFix v1.92 by jpshortstuff
Log created at 10:05 on 22/05/2009 running Option #1 (Matt)
Firefox version 3.0.10 (en-US)

=====Suspect Goored Entries=====

C:\Program Files\Mozilla Firefox\extensions\{D78714CB-5B44-4AAF-A9CE-FC456086BC26}

C:\Program Files\Mozilla Firefox\extensions\{B5FABD78-7C88-405A-ADF2-F12AC0286290}

C:\Program Files\Mozilla Firefox\extensions\{ACB539A9-AF2F-43BE-BD08-DA84ABAB6CE0}

C:\Program Files\Mozilla Firefox\extensions\{7A37BB6D-02EC-4E44-B5E1-78A5783DCA9A}

C:\Program Files\Mozilla Firefox\extensions\{5842EF10-E02A-4E2C-8656-3B995F41E1CC}

=====Dumping Registry Values=====

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.10\extensions]
"Plugins"="C:\Program Files\Mozilla Firefox\plugins"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.10\extensions]
"Components"="C:\Program Files\Mozilla Firefox\components"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"{1d5287d1-8a92-0001-1f31-1cec198018d8}"="C:\Program Files\AVG\AVG8\ToolbarFF"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"{3f963a5b-e555-4543-90e2-c3908898db71}"="C:\Program Files\AVG\AVG8\Firefox"

#14 thewall

thewall

  • Malware Response Team
  • 6,425 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Florida
  • Local time:11:58 AM

Posted 22 May 2009 - 09:41 AM

Please double-click GooredFix.exe on your Desktop to run it.
  • Select "2. Fix Goored" by typing 2 and pressing Enter.
  • Make sure all instances of Firefox are closed at this point.
  • Type y at the prompt and press Enter again.
  • A log will open, please post the contents of that log in your next reply (it can also be found on your desktop, called GooredLog.txt).
Note: If you receive a message saying that GooredFix needs your system to be restarted, please close all applications and reboot your system. Please also allow any registry changes that may be prompted by any of your security programs.



Along with the Goored log please post a new RSIT log and let me know how the computer is running.
If I have helped you then please consider donating so I can continue the fight against malware Posted Image
All donations go directly to the helper

Posted Image

Due to the large amount of backlogs we have I cannot respond to PMs for help unless I am already working with you

#15 scarfacek1ngofny

scarfacek1ngofny
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:12:58 PM

Posted 22 May 2009 - 09:51 AM

GooredFix v1.92 by jpshortstuff
Log created at 10:46 on 22/05/2009 running Option #2 (Matt)
Firefox version 3.0.10 (en-US)

=====Goored Deletions=====
C:\Program Files\Mozilla Firefox\extensions\{D78714CB-5B44-4AAF-A9CE-FC456086BC26}
->Backing up folder... Done.
->Emptying folder... Done.
->Deleting folder... Done.
C:\Program Files\Mozilla Firefox\extensions\{B5FABD78-7C88-405A-ADF2-F12AC0286290}
->Backing up folder... Done.
->Emptying folder... Done.
->Deleting folder... Done.
C:\Program Files\Mozilla Firefox\extensions\{ACB539A9-AF2F-43BE-BD08-DA84ABAB6CE0}
->Backing up folder... Done.
->Emptying folder... Done.
->Deleting folder... Done.
C:\Program Files\Mozilla Firefox\extensions\{7A37BB6D-02EC-4E44-B5E1-78A5783DCA9A}
->Backing up folder... Done.
->Emptying folder... Done.
->Deleting folder... Done.
C:\Program Files\Mozilla Firefox\extensions\{5842EF10-E02A-4E2C-8656-3B995F41E1CC}
->Backing up folder... Done.
->Emptying folder... Done.
->Deleting folder... Done.

=====Dumping Registry Values=====

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.10\extensions]
"Plugins"="C:\Program Files\Mozilla Firefox\plugins"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.10\extensions]
"Components"="C:\Program Files\Mozilla Firefox\components"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"{1d5287d1-8a92-0001-1f31-1cec198018d8}"="C:\Program Files\AVG\AVG8\ToolbarFF"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"{3f963a5b-e555-4543-90e2-c3908898db71}"="C:\Program Files\AVG\AVG8\Firefox"


Logfile of random's system information tool 1.06 (written by random/random)
Run by Matt at 2009-05-22 10:51:14
Microsoft Windows XP Professional Service Pack 3
System drive C: has 63 GB (83%) free of 76 GB
Total RAM: 2037 MB (67% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:51:15 AM, on 5/22/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Java\jre1.5.0_06\bin\jucheck.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Matt.MCMATT\Desktop\RSIT.exe
C:\Program Files\Trend Micro\matt1\Matt.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [hpbdfawep] C:\Program Files\HP\Dfawep\bin\hpbdfawep.exe 1
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1242245437031
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

--
End of file - 4251 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\HP WEP.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG8\avgssie.dll [2009-05-07 1107224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll [2005-11-10 184423]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
AVG Security Toolbar - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2009-05-07 2223872]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{A057A204-BACC-4D26-9990-79A187E2698E} - AVG Security Toolbar - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2009-05-07 2223872]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe [2005-11-10 36975]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2007-04-16 142104]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2007-04-16 162584]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2007-04-16 138008]
"hpbdfawep"=C:\Program Files\HP\Dfawep\bin\hpbdfawep.exe [2007-04-25 954368]
"AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe [2009-05-07 1947928]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]
"Aim6"=C:\Program Files\AIM6\aim6.exe [2009-04-27 49968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgrsstarter]
C:\WINDOWS\system32\avgrsstx.dll [2009-05-14 11952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2007-04-16 204800]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 239496]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\WINDOWS\system32\spool\drivers\w32x86\3\HP1006MC.EXE"="C:\WINDOWS\system32\spool\drivers\w32x86\3\HP1006MC.EXE:*:Enabled:SMLMProxy Module - HP1006MC.EXE"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\AVG\AVG8\avgemc.exe"="C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe"
"C:\Program Files\AVG\AVG8\avgupd.exe"="C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe"
"C:\Program Files\AVG\AVG8\avgnsx.exe"="C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe"
"C:\Program Files\Common Files\AOL\Loader\aolload.exe"="C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader"
"C:\Program Files\AIM6\aim6.exe"="C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2009-05-21 11:06:40 ----A---- C:\WINDOWS\pagebreeze.ini
2009-05-21 11:06:40 ----A---- C:\WINDOWS\formbreeze.ini
2009-05-21 11:06:36 ----A---- C:\WINDOWS\system32\vspell32.dll
2009-05-21 11:06:36 ----A---- C:\WINDOWS\system32\Vb6stkit.dll
2009-05-21 11:06:35 ----D---- C:\Program Files\PageBreeze
2009-05-21 11:06:35 ----A---- C:\WINDOWS\system32\Ledit32.dll
2009-05-21 11:06:35 ----A---- C:\WINDOWS\system32\ChilkatFTPx.dll
2009-05-19 16:37:41 ----D---- C:\Documents and Settings\Matt.MCMATT\Application Data\acccore
2009-05-19 10:34:10 ----D---- C:\rsit
2009-05-19 09:24:11 ----D---- C:\Documents and Settings\Matt.MCMATT\Application Data\Sun
2009-05-15 12:10:27 ----SHD---- C:\RECYCLER
2009-05-14 14:41:01 ----D---- C:\Program Files\Trend Micro
2009-05-14 14:22:38 ----D---- C:\WINDOWS\temp
2009-05-14 14:22:36 ----A---- C:\ComboFix.txt
2009-05-14 13:14:43 ----D---- C:\Documents and Settings\Matt.MCMATT\Application Data\Malwarebytes
2009-05-14 13:14:38 ----D---- C:\Program Files\Malwarebytes' Anti-Malware1
2009-05-14 13:14:38 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\Malwarebytes
2009-05-14 13:07:05 ----A---- C:\Boot.bak
2009-05-14 13:07:01 ----RASHD---- C:\cmdcons
2009-05-14 13:05:29 ----A---- C:\WINDOWS\zip.exe
2009-05-14 13:05:29 ----A---- C:\WINDOWS\vFind.exe
2009-05-14 13:05:29 ----A---- C:\WINDOWS\SWXCACLS.exe
2009-05-14 13:05:29 ----A---- C:\WINDOWS\SWSC.exe
2009-05-14 13:05:29 ----A---- C:\WINDOWS\SWREG.exe
2009-05-14 13:05:29 ----A---- C:\WINDOWS\sed.exe
2009-05-14 13:05:29 ----A---- C:\WINDOWS\NIRCMD.exe
2009-05-14 13:05:29 ----A---- C:\WINDOWS\grep.exe
2009-05-14 13:05:17 ----D---- C:\Qoobox
2009-05-14 12:18:15 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint
2009-05-14 12:18:13 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\acccore
2009-05-14 12:18:03 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\AOL OCP
2009-05-14 12:18:03 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\AOL
2009-05-14 11:47:26 ----A---- C:\WINDOWS\system32\avgrsstx.dll
2009-05-14 11:47:16 ----D---- C:\Documents and Settings\Matt.MCMATT\Application Data\AVGTOOLBAR
2009-05-14 11:47:12 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\avg8
2009-05-14 11:38:36 ----A---- C:\WINDOWS\system32\MRT.exe
2009-05-14 11:24:59 ----A---- C:\WINDOWS\system32\wmpns.dll
2009-05-14 11:24:41 ----D---- C:\WINDOWS\Prefetch
2009-05-14 11:22:44 ----HDC---- C:\WINDOWS\$NtUninstallKB963027$
2009-05-14 11:22:37 ----HDC---- C:\WINDOWS\$NtUninstallKB938464-v2$
2009-05-14 03:02:25 ----HDC---- C:\WINDOWS\$NtUninstallKB950760$
2009-05-14 03:00:22 ----HDC---- C:\WINDOWS\$NtUninstallKB944338-v2$
2009-05-13 18:19:07 ----N---- C:\WINDOWS\system32\xpsp4res.dll
2009-05-13 16:13:13 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\Windows Genuine Advantage
2009-05-13 16:13:02 ----A---- C:\WINDOWS\system32\spupdsvc.exe
2009-05-13 16:11:12 ----A---- C:\WINDOWS\system32\wups2.dll
2009-05-13 16:11:12 ----A---- C:\WINDOWS\system32\wucltui.dll.mui
2009-05-13 16:11:12 ----A---- C:\WINDOWS\system32\wuaueng.dll.mui
2009-05-13 16:11:11 ----A---- C:\WINDOWS\system32\wuapi.dll.mui
2009-05-13 13:59:59 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\HPSSUPPLY
2009-05-13 13:55:52 ----A---- C:\WINDOWS\system32\WRes1200.txt
2009-05-13 13:55:52 ----A---- C:\WINDOWS\system32\W600dpi.txt
2009-05-13 13:55:52 ----A---- C:\WINDOWS\system32\HRes600.txt
2009-05-13 13:55:52 ----A---- C:\WINDOWS\system32\HRes1200.txt
2009-05-13 13:55:52 ----A---- C:\WINDOWS\system32\HPPLVS.dll
2009-05-13 13:55:52 ----A---- C:\WINDOWS\system32\HP1006LM.DLL
2009-05-13 13:51:23 ----D---- C:\Documents and Settings\Matt.MCMATT\Application Data\Mozilla
2009-05-13 13:44:13 ----A---- C:\WINDOWS\ODBC.INI
2009-05-13 13:28:43 ----HDC---- C:\WINDOWS\$MSI31Uninstall_KB893803v2$
2009-05-13 13:20:43 ----A---- C:\WINDOWS\system32\igfxres.dll
2009-05-13 13:18:53 ----A---- C:\WINDOWS\system32\igxprd32.dll
2009-05-13 13:18:53 ----A---- C:\WINDOWS\system32\igxpgd32.dll
2009-05-13 13:18:53 ----A---- C:\WINDOWS\system32\igxpdx32.dll
2009-05-13 13:18:53 ----A---- C:\WINDOWS\system32\igxpdv32.dll
2009-05-13 13:18:53 ----A---- C:\WINDOWS\system32\iglicd32.dll
2009-05-13 13:18:53 ----A---- C:\WINDOWS\system32\igldev32.dll
2009-05-13 13:18:53 ----A---- C:\WINDOWS\system32\igfxzoom.exe
2009-05-13 13:18:53 ----A---- C:\WINDOWS\system32\igfxtray.exe
2009-05-13 13:18:53 ----A---- C:\WINDOWS\system32\igfxsrvc.exe
2009-05-13 13:18:53 ----A---- C:\WINDOWS\system32\igfxsrvc.dll
2009-05-13 13:18:53 ----A---- C:\WINDOWS\system32\igfxress.dll
2009-05-13 13:18:53 ----A---- C:\WINDOWS\system32\igfxpph.dll
2009-05-13 13:18:53 ----A---- C:\WINDOWS\system32\igfxpers.exe
2009-05-13 13:18:53 ----A---- C:\WINDOWS\system32\igfxext.exe
2009-05-13 13:18:53 ----A---- C:\WINDOWS\system32\igfxexps.dll
2009-05-13 13:18:53 ----A---- C:\WINDOWS\system32\igfxdo.dll
2009-05-13 13:18:53 ----A---- C:\WINDOWS\system32\igfxdev.dll
2009-05-13 13:18:53 ----A---- C:\WINDOWS\system32\igfxCoIn_v4820.dll
2009-05-13 13:18:53 ----A---- C:\WINDOWS\system32\igfxcfg.exe
2009-05-13 13:18:53 ----A---- C:\WINDOWS\system32\hkcmd.exe
2009-05-13 13:18:53 ----A---- C:\WINDOWS\system32\hccutils.dll
2009-05-13 13:18:52 ----A---- C:\WINDOWS\system32\igxpun.exe
2009-05-13 13:18:52 ----A---- C:\WINDOWS\system32\difxapi.dll
2009-05-13 13:15:24 ----D---- C:\Intel
2009-05-13 13:13:56 ----A---- C:\WINDOWS\system32\javaws.exe
2009-05-13 13:13:56 ----A---- C:\WINDOWS\system32\javaw.exe
2009-05-13 13:13:56 ----A---- C:\WINDOWS\system32\java.exe
2009-05-13 13:12:01 ----D---- C:\Documents and Settings\Matt.MCMATT\Application Data\InstallShield
2009-05-13 13:05:16 ----D---- C:\Documents and Settings\Matt.MCMATT\Application Data\Identities
2009-05-13 13:05:06 ----SD---- C:\Documents and Settings\Matt.MCMATT\Application Data\Microsoft
2009-05-13 13:05:06 ----ASH---- C:\Documents and Settings\Matt.MCMATT\Application Data\desktop.ini
2009-05-13 13:04:15 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-05-13 13:00:25 ----N---- C:\WINDOWS\system32\spmsg.dll
2009-05-13 13:00:22 ----A---- C:\WINDOWS\system32\xpsp3res.dll
2009-05-13 13:00:08 ----A---- C:\WINDOWS\control.ini
2009-05-13 12:59:55 ----A---- C:\WINDOWS\OEWABLog.txt
2009-05-13 12:59:49 ----A---- C:\WINDOWS\system32\mapi32.dll
2009-05-13 12:58:44 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest
2009-05-13 12:58:37 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest
2009-05-13 12:57:42 ----A---- C:\WINDOWS\system32\atrace.dll
2009-05-13 12:57:38 ----A---- C:\WINDOWS\system32\desktop.ini
2009-05-13 12:57:38 ----A---- C:\WINDOWS\desktop.ini
2009-05-13 12:57:31 ----A---- C:\WINDOWS\system32\nmevtmsg.dll
2009-05-13 12:57:30 ----A---- C:\WINDOWS\system32\acctres.dll
2009-05-13 12:57:29 ----A---- C:\WINDOWS\system32\icfgnt5.dll
2009-05-13 12:57:19 ----A---- C:\WINDOWS\system32\wuweb.dll
2009-05-13 12:57:19 ----A---- C:\WINDOWS\system32\wucltui.dll
2009-05-13 12:57:19 ----A---- C:\WINDOWS\system32\wuauserv.dll
2009-05-13 12:57:19 ----A---- C:\WINDOWS\system32\wuaueng1.dll
2009-05-13 12:57:18 ----A---- C:\WINDOWS\system32\wups.dll
2009-05-13 12:57:18 ----A---- C:\WINDOWS\system32\wuaueng.dll
2009-05-13 12:57:18 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2009-05-13 12:57:18 ----A---- C:\WINDOWS\system32\wuauclt.exe
2009-05-13 12:57:18 ----A---- C:\WINDOWS\system32\wuapi.dll
2009-05-13 12:57:18 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
2009-05-13 12:57:18 ----A---- C:\WINDOWS\system32\bitsprx3.dll
2009-05-13 12:57:18 ----A---- C:\WINDOWS\system32\bitsprx2.dll
2009-05-13 12:57:17 ----A---- C:\WINDOWS\system32\qmgr.dll
2009-05-13 12:57:10 ----A---- C:\WINDOWS\system32\safrslv.dll
2009-05-13 12:57:10 ----A---- C:\WINDOWS\system32\safrdm.dll
2009-05-13 12:57:10 ----A---- C:\WINDOWS\system32\safrcdlg.dll
2009-05-13 12:57:10 ----A---- C:\WINDOWS\system32\racpldlg.dll
2009-05-13 12:57:05 ----A---- C:\WINDOWS\system32\srsvc.dll
2009-05-13 12:57:05 ----A---- C:\WINDOWS\system32\srrstr.dll
2009-05-13 12:57:05 ----A---- C:\WINDOWS\system32\fltmc.exe
2009-05-13 12:57:05 ----A---- C:\WINDOWS\system32\fltlib.dll
2009-05-13 12:57:04 ----A---- C:\WINDOWS\system32\srclient.dll
2009-05-13 12:57:04 ----A---- C:\WINDOWS\system32\isrdbg32.dll
2009-05-13 12:57:04 ----A---- C:\WINDOWS\system32\ils.dll
2009-05-13 12:57:03 ----A---- C:\WINDOWS\system32\nmmkcert.dll
2009-05-13 12:57:03 ----A---- C:\WINDOWS\system32\msconf.dll
2009-05-13 12:57:03 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2009-05-13 12:57:03 ----A---- C:\WINDOWS\system32\mnmdd.dll
2009-05-13 12:56:58 ----A---- C:\WINDOWS\system32\msoert2.dll
2009-05-13 12:56:58 ----A---- C:\WINDOWS\system32\msoeacct.dll
2009-05-13 12:56:57 ----A---- C:\WINDOWS\system32\inetres.dll
2009-05-13 12:56:57 ----A---- C:\WINDOWS\system32\inetcomm.dll
2009-05-13 12:56:52 ----A---- C:\WINDOWS\system32\schedsvc.dll
2009-05-13 12:56:51 ----A---- C:\WINDOWS\system32\mstinit.exe
2009-05-13 12:56:51 ----A---- C:\WINDOWS\system32\mstask.dll
2009-05-13 12:56:51 ----A---- C:\WINDOWS\system32\isign32.dll
2009-05-13 12:56:51 ----A---- C:\WINDOWS\system32\icwphbk.dll
2009-05-13 12:56:51 ----A---- C:\WINDOWS\system32\icwdial.dll
2009-05-13 12:56:50 ----A---- C:\WINDOWS\system32\inetcfg.dll
2009-05-13 12:55:57 ----A---- C:\WINDOWS\vbaddin.ini
2009-05-13 12:55:57 ----A---- C:\WINDOWS\vb.ini
2009-05-13 12:55:32 ----A---- C:\WINDOWS\system32\write.exe
2009-05-13 12:55:26 ----A---- C:\WINDOWS\system32\sndvol32.exe
2009-05-13 12:55:25 ----A---- C:\WINDOWS\system32\hticons.dll
2009-05-13 12:55:25 ----A---- C:\WINDOWS\system32\avwav.dll
2009-05-13 12:55:25 ----A---- C:\WINDOWS\system32\avtapi.dll
2009-05-13 12:55:25 ----A---- C:\WINDOWS\system32\avmeter.dll
2009-05-13 12:55:24 ----A---- C:\WINDOWS\system32\winchat.exe
2009-05-13 12:55:16 ----A---- C:\WINDOWS\system32\getuname.dll
2009-05-13 12:55:15 ----A---- C:\WINDOWS\system32\sol.exe
2009-05-13 12:55:15 ----A---- C:\WINDOWS\system32\charmap.exe
2009-05-13 12:55:15 ----A---- C:\WINDOWS\system32\calc.exe
2009-05-13 12:55:10 ----A---- C:\WINDOWS\system32\winmine.exe
2009-05-13 12:55:09 ----A---- C:\WINDOWS\system32\usrlogon.cmd
2009-05-13 12:55:09 ----A---- C:\WINDOWS\system32\tsshutdn.exe
2009-05-13 12:55:09 ----A---- C:\WINDOWS\system32\tslabels.ini
2009-05-13 12:55:09 ----A---- C:\WINDOWS\system32\tskill.exe
2009-05-13 12:55:09 ----A---- C:\WINDOWS\system32\tsdiscon.exe
2009-05-13 12:55:09 ----A---- C:\WINDOWS\system32\tscon.exe
2009-05-13 12:55:09 ----A---- C:\WINDOWS\system32\reset.exe
2009-05-13 12:55:09 ----A---- C:\WINDOWS\system32\mshearts.exe
2009-05-13 12:55:09 ----A---- C:\WINDOWS\system32\freecell.exe
2009-05-13 12:55:08 ----A---- C:\WINDOWS\system32\shadow.exe
2009-05-13 12:55:08 ----A---- C:\WINDOWS\system32\rwinsta.exe
2009-05-13 12:55:08 ----A---- C:\WINDOWS\system32\regini.exe
2009-05-13 12:55:08 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
2009-05-13 12:55:08 ----A---- C:\WINDOWS\system32\qwinsta.exe
2009-05-13 12:55:08 ----A---- C:\WINDOWS\system32\qappsrv.exe
2009-05-13 12:55:08 ----A---- C:\WINDOWS\system32\msg.exe
2009-05-13 12:55:08 ----A---- C:\WINDOWS\system32\logoff.exe
2009-05-13 12:55:08 ----A---- C:\WINDOWS\system32\cdmodem.dll
2009-05-13 12:55:07 ----A---- C:\WINDOWS\system32\msdtcprf.ini
2009-05-13 12:55:07 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2009-05-13 12:55:06 ----A---- C:\WINDOWS\system32\stclient.dll
2009-05-13 12:55:06 ----A---- C:\WINDOWS\system32\mtxlegih.dll
2009-05-13 12:55:06 ----A---- C:\WINDOWS\system32\mtxex.dll
2009-05-13 12:55:06 ----A---- C:\WINDOWS\system32\mtxdm.dll
2009-05-13 12:55:06 ----A---- C:\WINDOWS\system32\comsnap.dll
2009-05-13 12:55:06 ----A---- C:\WINDOWS\system32\comrepl.dll
2009-05-13 12:55:06 ----A---- C:\WINDOWS\system32\comaddin.dll
2009-05-13 12:55:00 ----A---- C:\WINDOWS\system32\wmimgmt.msc
2009-05-13 12:54:58 ----A---- C:\WINDOWS\system32\sndrec32.exe
2009-05-13 12:54:58 ----A---- C:\WINDOWS\system32\accwiz.exe
2009-05-13 12:54:57 ----A---- C:\WINDOWS\system32\mplay32.exe
2009-05-13 12:54:57 ----A---- C:\WINDOWS\system32\hypertrm.dll
2009-05-13 12:54:56 ----A---- C:\WINDOWS\system32\spider.exe
2009-05-13 12:54:56 ----A---- C:\WINDOWS\system32\mspaint.exe
2009-05-13 12:54:56 ----A---- C:\WINDOWS\system32\clipbrd.exe
2009-05-13 12:54:55 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
2009-05-13 12:54:55 ----A---- C:\WINDOWS\system32\mstscax.dll
2009-05-13 12:54:54 ----A---- C:\WINDOWS\system32\tscupgrd.exe
2009-05-13 12:54:54 ----A---- C:\WINDOWS\system32\sessmgr.exe
2009-05-13 12:54:54 ----A---- C:\WINDOWS\system32\remotepg.dll
2009-05-13 12:54:54 ----A---- C:\WINDOWS\system32\rdshost.exe
2009-05-13 12:54:54 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2009-05-13 12:54:54 ----A---- C:\WINDOWS\system32\rdchost.dll
2009-05-13 12:54:54 ----A---- C:\WINDOWS\system32\mstsc.exe
2009-05-13 12:54:53 ----A---- C:\WINDOWS\system32\termsrv.dll
2009-05-13 12:54:53 ----A---- C:\WINDOWS\system32\rdpwsx.dll
2009-05-13 12:54:53 ----A---- C:\WINDOWS\system32\rdpsnd.dll
2009-05-13 12:54:53 ----A---- C:\WINDOWS\system32\rdpclip.exe
2009-05-13 12:54:53 ----A---- C:\WINDOWS\system32\qprocess.exe
2009-05-13 12:54:53 ----A---- C:\WINDOWS\system32\icaapi.dll
2009-05-13 12:54:53 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2009-05-13 12:54:52 ----A---- C:\WINDOWS\system32\mtxoci.dll
2009-05-13 12:54:52 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
2009-05-13 12:54:52 ----A---- C:\WINDOWS\system32\msdtctm.dll
2009-05-13 12:54:52 ----A---- C:\WINDOWS\system32\msdtcprx.dll
2009-05-13 12:54:51 ----A---- C:\WINDOWS\system32\xolehlp.dll
2009-05-13 12:54:51 ----A---- C:\WINDOWS\system32\msdtclog.dll
2009-05-13 12:54:51 ----A---- C:\WINDOWS\system32\msdtc.exe
2009-05-13 12:54:50 ----A---- C:\WINDOWS\system32\colbact.dll
2009-05-13 12:54:50 ----A---- C:\WINDOWS\system32\clbcatex.dll
2009-05-13 12:54:50 ----A---- C:\WINDOWS\system32\catsrvut.dll
2009-05-13 12:54:50 ----A---- C:\WINDOWS\system32\catsrvps.dll
2009-05-13 12:54:49 ----A---- C:\WINDOWS\system32\comsvcs.dll
2009-05-13 12:54:49 ----A---- C:\WINDOWS\system32\catsrv.dll
2009-05-13 12:54:48 ----A---- C:\WINDOWS\system32\comuid.dll
2009-05-13 12:54:48 ----A---- C:\WINDOWS\system32\clbcatq.dll
2009-05-13 12:54:41 ----A---- C:\WINDOWS\system32\servdeps.dll
2009-05-13 12:54:41 ----A---- C:\WINDOWS\system32\mmfutil.dll
2009-05-13 12:54:41 ----A---- C:\WINDOWS\system32\licwmi.dll
2009-05-13 12:54:41 ----A---- C:\WINDOWS\system32\cmprops.dll
2009-05-13 08:53:15 ----A---- C:\WINDOWS\system32\h323log.txt
2009-05-13 08:50:00 ----A---- C:\WINDOWS\system32\usbui.dll
2009-05-13 08:47:57 ----A---- C:\WINDOWS\imsins.BAK
2009-05-13 08:47:54 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-05-13 08:47:53 ----A---- C:\WINDOWS\ODBCINST.INI
2009-05-13 08:47:47 ----RA---- C:\WINDOWS\system32\kbdtuq.dll
2009-05-13 08:47:47 ----RA---- C:\WINDOWS\system32\kbdtuf.dll
2009-05-13 08:47:47 ----RA---- C:\WINDOWS\system32\kbdazel.dll
2009-05-13 08:47:45 ----RA---- C:\WINDOWS\system32\kbdtat.dll
2009-05-13 08:47:45 ----RA---- C:\WINDOWS\system32\kbdmon.dll
2009-05-13 08:47:45 ----RA---- C:\WINDOWS\system32\kbdkyr.dll
2009-05-13 08:47:45 ----RA---- C:\WINDOWS\system32\kbdaze.dll
2009-05-13 08:47:44 ----RA---- C:\WINDOWS\system32\kbdycc.dll
2009-05-13 08:47:44 ----RA---- C:\WINDOWS\system32\kbduzb.dll
2009-05-13 08:47:44 ----RA---- C:\WINDOWS\system32\kbdur.dll
2009-05-13 08:47:44 ----RA---- C:\WINDOWS\system32\kbdru1.dll
2009-05-13 08:47:44 ----RA---- C:\WINDOWS\system32\kbdru.dll
2009-05-13 08:47:44 ----RA---- C:\WINDOWS\system32\kbdkaz.dll
2009-05-13 08:47:44 ----RA---- C:\WINDOWS\system32\kbdbu.dll
2009-05-13 08:47:44 ----RA---- C:\WINDOWS\system32\kbdblr.dll
2009-05-13 08:47:42 ----RA---- C:\WINDOWS\system32\kbdhept.dll
2009-05-13 08:47:42 ----RA---- C:\WINDOWS\system32\kbdhela3.dll
2009-05-13 08:47:42 ----RA---- C:\WINDOWS\system32\kbdhela2.dll
2009-05-13 08:47:42 ----RA---- C:\WINDOWS\system32\kbdhe319.dll
2009-05-13 08:47:42 ----RA---- C:\WINDOWS\system32\kbdhe220.dll
2009-05-13 08:47:42 ----RA---- C:\WINDOWS\system32\kbdhe.dll
2009-05-13 08:47:42 ----RA---- C:\WINDOWS\system32\kbdgkl.dll
2009-05-13 08:47:35 ----RA---- C:\WINDOWS\system32\kbdlv1.dll
2009-05-13 08:47:35 ----RA---- C:\WINDOWS\system32\kbdlv.dll
2009-05-13 08:47:35 ----RA---- C:\WINDOWS\system32\kbdlt1.dll
2009-05-13 08:47:35 ----RA---- C:\WINDOWS\system32\kbdlt.dll
2009-05-13 08:47:35 ----RA---- C:\WINDOWS\system32\kbdest.dll
2009-05-13 08:47:32 ----RA---- C:\WINDOWS\system32\kbdsl1.dll
2009-05-13 08:47:32 ----RA---- C:\WINDOWS\system32\kbdsl.dll
2009-05-13 08:47:32 ----RA---- C:\WINDOWS\system32\kbdro.dll
2009-05-13 08:47:32 ----RA---- C:\WINDOWS\system32\kbdpl1.dll
2009-05-13 08:47:32 ----RA---- C:\WINDOWS\system32\kbdpl.dll
2009-05-13 08:47:32 ----RA---- C:\WINDOWS\system32\kbdhu1.dll
2009-05-13 08:47:32 ----RA---- C:\WINDOWS\system32\kbdhu.dll
2009-05-13 08:47:32 ----RA---- C:\WINDOWS\system32\kbdcz2.dll
2009-05-13 08:47:32 ----RA---- C:\WINDOWS\system32\kbdcz1.dll
2009-05-13 08:47:32 ----RA---- C:\WINDOWS\system32\kbdcz.dll
2009-05-13 08:47:32 ----RA---- C:\WINDOWS\system32\kbdcr.dll
2009-05-13 08:47:31 ----RA---- C:\WINDOWS\system32\kbdycl.dll
2009-05-13 08:47:31 ----RA---- C:\WINDOWS\system32\KBDAL.DLL
2009-05-13 08:47:28 ----A---- C:\WINDOWS\system32\spxcoins.dll
2009-05-13 08:47:28 ----A---- C:\WINDOWS\system32\irclass.dll
2009-05-13 08:47:28 ----A---- C:\WINDOWS\system32\EqnClass.Dll
2009-05-13 08:47:28 ----A---- C:\WINDOWS\system32\dgsetup.dll
2009-05-13 08:47:28 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
2009-05-13 08:47:25 ----N---- C:\WINDOWS\system32\CONFIG.TMP
2009-05-13 08:47:25 ----A---- C:\WINDOWS\TASKMAN.EXE
2009-05-13 08:47:24 ----A---- C:\WINDOWS\system32\batt.dll
2009-05-13 08:47:24 ----A---- C:\WINDOWS\notepad.exe
2009-05-13 08:47:23 ----A---- C:\WINDOWS\system32\storprop.dll
2009-05-13 08:47:12 ----ASH---- C:\Documents and Settings\All Users.WINDOWS\Application Data\desktop.ini
2009-05-13 08:47:11 ----RA---- C:\WINDOWS\SET2A.tmp
2009-05-13 08:47:11 ----RA---- C:\WINDOWS\SET29.tmp
2009-05-13 08:47:07 ----RA---- C:\WINDOWS\SET8.tmp
2009-05-13 08:47:04 ----RA---- C:\WINDOWS\SET4.tmp
2009-05-13 08:47:03 ----RA---- C:\WINDOWS\SET3.tmp
2009-05-13 08:46:52 ----SD---- C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft
2009-05-13 08:46:26 ----A---- C:\WINDOWS\setuplog.txt
2009-05-13 08:22:20 ----D---- C:\WINDOWS\dell
2009-05-11 16:50:49 ----D---- C:\WINDOWS\ERDNT
2009-05-11 15:22:54 ----D---- C:\Program Files\TMHJT
2009-05-11 12:25:08 ----HD---- C:\WINDOWS\PIF
2009-05-10 03:00:13 ----HDC---- C:\WINDOWS\$NtUninstallKB954459$
2009-05-07 12:14:33 ----HD---- C:\$AVG8.VAULT$
2009-05-07 11:21:45 ----D---- C:\Program Files\AVG
2009-05-07 03:00:20 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
2009-05-06 15:23:02 ----D---- C:\WINDOWS\system32\XPSViewer
2009-05-06 15:23:00 ----D---- C:\Program Files\MSBuild
2009-05-06 15:22:55 ----D---- C:\Program Files\Reference Assemblies
2009-05-06 15:22:34 ----D---- C:\2926076ff8ca37070f90
2009-05-06 14:10:02 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2009-05-06 14:09:56 ----HDC---- C:\WINDOWS\$NtUninstallKB938464-v2_0$
2009-05-06 12:28:55 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2009-05-06 12:28:49 ----HDC---- C:\WINDOWS\$NtUninstallKB961373$
2009-05-06 12:28:45 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2009-05-06 12:28:38 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2009-05-06 12:28:34 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2009-05-06 12:28:30 ----HDC---- C:\WINDOWS\$NtUninstallKB958690$
2009-05-06 12:28:26 ----HDC---- C:\WINDOWS\$NtUninstallKB958687$
2009-05-06 12:28:22 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2009-05-06 12:28:17 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
2009-05-06 12:28:13 ----HDC---- C:\WINDOWS\$NtUninstallKB957095$
2009-05-06 12:28:09 ----HDC---- C:\WINDOWS\$NtUninstallKB956841$
2009-05-06 12:28:04 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2009-05-06 12:28:00 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2009-05-06 12:27:52 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2009-05-06 12:27:45 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2009-05-06 12:27:41 ----HDC---- C:\WINDOWS\$NtUninstallKB954600$
2009-05-06 12:27:36 ----HDC---- C:\WINDOWS\$NtUninstallKB954211$
2009-05-06 12:27:31 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2009-05-06 12:27:26 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2009-05-06 12:27:21 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2009-05-06 12:27:17 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2009-05-06 12:27:13 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
2009-05-06 12:27:09 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2009-05-06 12:27:03 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2009-05-06 12:26:59 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2009-05-06 12:26:56 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2009-05-06 12:26:52 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2009-05-06 12:26:49 ----HDC---- C:\WINDOWS\$NtUninstallKB938464$
2009-05-06 12:26:44 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2009-05-06 12:24:05 ----D---- C:\WINDOWS\system32\scripting
2009-05-06 12:24:05 ----D---- C:\WINDOWS\system32\en
2009-05-06 12:24:05 ----D---- C:\WINDOWS\l2schemas
2009-05-06 12:22:37 ----D---- C:\WINDOWS\ServicePackFiles
2009-05-06 12:21:20 ----D---- C:\WINDOWS\network diagnostic
2009-05-06 12:18:54 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2009-05-06 10:55:15 ----D---- C:\Program Files\Matt
2009-05-05 15:51:53 ----D---- C:\WINDOWS\system32\bits
2009-05-05 15:51:49 ----HDC---- C:\WINDOWS\$NtUninstallKB923845$
2009-05-05 15:51:41 ----HDC---- C:\WINDOWS\$NtUninstallKB914882$
2009-05-05 15:26:44 ----HD---- C:\Config.Msi
2009-05-05 10:45:24 ----D---- C:\Program Files\Windows Live Safety Center
2009-05-04 09:40:34 ----D---- C:\WINDOWS\ie8updates
2009-05-04 09:40:03 ----D---- C:\WINDOWS\WBEM
2009-05-04 09:39:01 ----HDC---- C:\WINDOWS\ie8
2009-05-04 09:39:01 ----D---- C:\WINDOWS\system32\en-US
2009-05-04 09:34:48 ----HDC---- C:\WINDOWS\$NtUninstallKB932823-v3$
2009-05-01 08:34:36 ----D---- C:\WINDOWS\system32\LogFiles
2009-04-30 15:28:38 ----A---- C:\WINDOWS\system32\Prounstl.exe
2009-04-30 15:28:38 ----A---- C:\WINDOWS\system32\NicInstE.dll
2009-04-30 15:28:38 ----A---- C:\WINDOWS\system32\NicEtCoE.dll
2009-04-30 15:28:38 ----A---- C:\WINDOWS\system32\NicCo.dll
2009-04-30 15:28:38 ----A---- C:\WINDOWS\system32\e1000msg.dll
2009-04-30 15:19:33 ----D---- C:\WINDOWS\OPTIONS
2009-04-30 15:19:33 ----D---- C:\Program Files\Realtek
2009-04-30 15:17:49 ----D---- C:\WINDOWS\system32\vmm32
2009-04-30 13:27:03 ----D---- C:\Program Files\Viewpoint
2009-04-30 13:17:02 ----HD---- C:\WINDOWS\system32\GroupPolicy
2009-04-30 12:37:57 ----SHD---- C:\WINDOWS\CSC
2009-04-30 10:14:30 ----D---- C:\WINDOWS\system32\appmgmt
2009-04-29 11:14:45 ----D---- C:\WINDOWS\pss

======List of files/folders modified in the last 1 months======

2009-05-22 10:47:47 ----D---- C:\Program Files\Mozilla Firefox
2009-05-22 09:37:02 ----SD---- C:\WINDOWS\Tasks
2009-05-21 11:14:15 ----D---- C:\WINDOWS
2009-05-21 11:06:36 ----D---- C:\WINDOWS\system32
2009-05-21 11:06:35 ----RD---- C:\Program Files
2009-05-20 16:37:31 ----SHD---- C:\WINDOWS\Installer
2009-05-14 14:21:37 ----A---- C:\WINDOWS\system.ini
2009-05-14 14:21:09 ----D---- C:\WINDOWS\system32\drivers
2009-05-14 14:21:09 ----D---- C:\WINDOWS\AppPatch
2009-05-14 14:21:07 ----D---- C:\Program Files\Common Files
2009-05-14 14:20:12 ----D---- C:\WINDOWS\system32\CatRoot2
2009-05-14 13:07:05 ----RASH---- C:\boot.ini
2009-05-14 12:44:44 ----D---- C:\Program Files\AIM6
2009-05-14 12:18:05 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-05-14 12:17:50 ----D---- C:\WINDOWS\WinSxS
2009-05-14 11:47:09 ----D---- C:\Program Files\Common Files\Microsoft Shared
2009-05-14 11:43:29 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-05-14 11:43:11 ----HD---- C:\WINDOWS\inf
2009-05-14 11:41:55 ----D---- C:\Program Files\Internet Explorer
2009-05-14 11:41:54 ----D---- C:\WINDOWS\system32\wbem
2009-05-14 11:41:54 ----D---- C:\WINDOWS\Help
2009-05-14 11:40:24 ----HD---- C:\WINDOWS\$hf_mig$
2009-05-14 11:40:06 ----D---- C:\WINDOWS\Media
2009-05-14 11:38:38 ----D---- C:\WINDOWS\Debug
2009-05-14 11:38:06 ----D---- C:\WINDOWS\system32\CatRoot
2009-05-14 11:34:54 ----D---- C:\Program Files\Messenger
2009-05-14 11:24:20 ----D---- C:\WINDOWS\system32\Setup
2009-05-14 11:24:19 ----RD---- C:\WINDOWS\Fonts
2009-05-14 11:23:37 ----D---- C:\WINDOWS\security
2009-05-14 11:19:40 ----D---- C:\Program Files\Windows Media Player
2009-05-14 11:19:26 ----D---- C:\WINDOWS\system32\inetsrv
2009-05-14 11:19:26 ----D---- C:\WINDOWS\ime
2009-05-14 11:19:18 ----D---- C:\WINDOWS\system32\usmt
2009-05-14 11:19:16 ----D---- C:\WINDOWS\PeerNet
2009-05-14 11:19:16 ----D---- C:\Program Files\Movie Maker
2009-05-14 11:17:36 ----D---- C:\WINDOWS\system32\Restore
2009-05-14 11:17:35 ----D---- C:\WINDOWS\system32\npp
2009-05-14 11:17:35 ----D---- C:\WINDOWS\mui
2009-05-14 11:17:34 ----D---- C:\WINDOWS\msagent
2009-05-14 11:17:33 ----D---- C:\WINDOWS\srchasst
2009-05-14 11:17:33 ----D---- C:\Program Files\NetMeeting
2009-05-14 11:17:32 ----D---- C:\WINDOWS\system32\Com
2009-05-14 11:17:29 ----D---- C:\Program Files\Windows NT
2009-05-14 11:17:29 ----D---- C:\Program Files\Outlook Express
2009-05-14 11:17:26 ----D---- C:\Program Files\Common Files\System
2009-05-14 11:17:07 ----D---- C:\WINDOWS\system32\oobe
2009-05-14 11:17:05 ----D---- C:\WINDOWS\system
2009-05-14 11:12:51 ----D---- C:\WINDOWS\ehome
2009-05-14 09:17:43 ----D---- C:\WINDOWS\SoftwareDistribution
2009-05-14 03:02:59 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$
2009-05-14 03:02:06 ----D---- C:\WINDOWS\Registration
2009-05-14 03:00:30 ----HDC---- C:\WINDOWS\$NtUninstallKB963027_0$
2009-05-13 13:57:50 ----D---- C:\WINDOWS\system32\URTTemp
2009-05-13 13:57:27 ----RSD---- C:\WINDOWS\assembly
2009-05-13 13:37:45 ----D---- C:\Program Files\Microsoft Works
2009-05-13 13:18:53 ----DC---- C:\WINDOWS\system32\DRVSTORE
2009-05-13 13:18:13 ----D---- C:\Program Files\Intel
2009-05-13 13:13:55 ----D---- C:\Program Files\Java
2009-05-13 13:05:05 ----D---- C:\Documents and Settings
2009-05-13 13:04:17 ----SHD---- C:\System Volume Information
2009-05-13 13:03:28 ----D---- C:\WINDOWS\system32\config
2009-05-13 13:00:08 ----A---- C:\WINDOWS\win.ini
2009-05-13 12:58:48 ----RD---- C:\WINDOWS\Web
2009-05-13 12:55:49 ----D---- C:\WINDOWS\system32\MsDtc
2009-05-13 12:55:32 ----D---- C:\WINDOWS\Cursors
2009-05-13 08:41:29 ----D---- C:\WINDOWS\twain_32
2009-05-13 08:41:06 ----D---- C:\WINDOWS\system32\ras
2009-05-13 08:40:42 ----D---- C:\WINDOWS\system32\icsxml
2009-05-13 08:40:21 ----D---- C:\WINDOWS\system32\ias
2009-05-13 08:40:17 ----D---- C:\WINDOWS\system32\1033
2009-05-13 08:39:28 ----D---- C:\WINDOWS\system32\RTCOM
2009-05-13 08:39:26 ----D---- C:\WINDOWS\system32\Lang
2009-05-13 08:39:18 ----D---- C:\WINDOWS\system32\BWKDLogs
2009-05-13 08:39:16 ----HD---- C:\WINDOWS\ShellNew
2009-05-13 08:39:16 ----D---- C:\WINDOWS\repair
2009-05-13 08:39:15 ----RD---- C:\WINDOWS\Offline Web Pages
2009-05-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB967715_0$
2009-05-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB961373_0$
2009-05-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB960803_0$
2009-05-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB960715$
2009-05-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB960714$
2009-05-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB960225_0$
2009-05-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB959426_0$
2009-05-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB958690_0$
2009-05-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB958687_0$
2009-05-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB958644_0$
2009-05-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB958215$
2009-05-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB957097_0$
2009-05-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB957095_0$
2009-05-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB956841_0$
2009-05-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB956803_0$
2009-05-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB956802_0$
2009-05-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB956572_0$
2009-05-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB956391$
2009-05-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB956390$
2009-05-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB955839$
2009-05-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB955069_0$
2009-05-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB954600_0$
2009-05-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB954211_0$
2009-05-13 08:39:10 ----D---- C:\WINDOWS\addins
2009-05-13 08:39:09 ----HDC---- C:\WINDOWS\$NtUninstallKB953839$
2009-05-13 08:39:09 ----HDC---- C:\WINDOWS\$NtUninstallKB953838$
2009-05-13 08:39:09 ----HDC---- C:\WINDOWS\$NtUninstallKB952954_0$
2009-05-13 08:39:09 ----HDC---- C:\WINDOWS\$NtUninstallKB952287_0$
2009-05-13 08:39:09 ----HDC---- C:\WINDOWS\$NtUninstallKB952004_0$
2009-05-13 08:39:09 ----HDC---- C:\WINDOWS\$NtUninstallKB951748_0$
2009-05-13 08:39:09 ----HDC---- C:\WINDOWS\$NtUninstallKB951698_0$
2009-05-13 08:39:09 ----HDC---- C:\WINDOWS\$NtUninstallKB951072-v2$
2009-05-13 08:39:09 ----HDC---- C:\WINDOWS\$NtUninstallKB951066_0$
2009-05-13 08:39:09 ----HDC---- C:\WINDOWS\$NtUninstallKB950974_0$
2009-05-13 08:39:09 ----HDC---- C:\WINDOWS\$NtUninstallKB950762_0$
2009-05-13 08:39:09 ----HDC---- C:\WINDOWS\$NtUninstallKB946648_0$
2009-05-13 08:39:09 ----HDC---- C:\WINDOWS\$NtUninstallKB931784$
2009-05-13 08:39:09 ----HDC---- C:\WINDOWS\$NtUninstallKB923723$
2009-05-13 08:39:09 ----HDC---- C:\WINDOWS\$NtUninstallKB923561_0$
2009-05-13 08:39:09 ----HDC---- C:\WINDOWS\$NtUninstallKB896256$
2009-05-13 08:22:20 ----D---- C:\WINDOWS\Driver Cache
2009-05-12 16:23:33 ----D---- C:\i386
2009-05-11 16:26:13 ----HD---- C:\Program Files\InstallShield Installation Information
2009-05-11 15:14:31 ----D---- C:\Program Files\Common Files\Services
2009-05-06 15:37:31 ----D---- C:\WINDOWS\Microsoft.NET
2009-05-06 15:22:43 ----D---- C:\WINDOWS\system32\spool
2009-05-01 16:07:38 ----D---- C:\Program Files\Dell
2009-04-30 15:19:16 ----D---- C:\dell

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2009-05-14 325896]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2009-05-14 27784]
R1 AvgTdiX;AVG Free8 Network Redirector; C:\WINDOWS\System32\Drivers\avgtdix.sys [2009-05-14 108552]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
R3 e1express;Intel® PRO/1000 PCI Express Network Connection Driver; C:\WINDOWS\system32\DRIVERS\e1e5132.sys [2007-04-13 254872]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2007-04-16 5760096]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2004-08-04 12160]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 catchme;catchme; \??\C:\DOCUME~1\MATT~1.MCM\LOCALS~1\Temp\catchme.sys []
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avg8emc;AVG Free8 E-mail Scanner; C:\PROGRA~1\AVG\AVG8\avgemc.exe [2009-05-07 908568]
R2 avg8wd;AVG Free8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2009-05-07 298776]
R2 Viewpoint Manager Service;Viewpoint Manager Service; C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]

-----------------EOF-----------------




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users