Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Rootkit Stopping all Scans


  • This topic is locked This topic is locked
9 replies to this topic

#1 jakea333

jakea333

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:05:00 AM

Posted 05 September 2009 - 07:34 PM

I believe I have a form of the rootkit that stops all scans. Currently, my computer can only boot into safe mode without networking, so all files have to be transferred from another computer via flash drive. I was directed here from the Am I Infected forum.

So far I've only been able to run Win32kdiag.

Thanks for any help.

Original Thread: http://www.bleepingcomputer.com/forums/t/255020/infection-stopping-all-antivirus-task-manager-etc/

Win32kdiag Scan:

Log file is located at: C:\Users\Jake\Desktop\Win32kDiag.txt

WARNING: Could not get backup privileges!

Searching 'C:\Windows'...



Found mount point : C:\Windows\AppPatch\Custom\Custom

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP2DF2.tmp\ZAP2DF2.tmp

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP81A.tmp\ZAP81A.tmp

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPA3DE.tmp\ZAPA3DE.tmp

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPE752.tmp\ZAPE752.tmp

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPEEF0.tmp\ZAPEEF0.tmp

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\assembly\temp\temp

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\assembly\tmp\tmp

Mount point destination : \Device\__max++>\^

Cannot access: C:\Windows\bthservsdp.dat

[1] 2009-09-03 19:33:48 12 C:\Windows\bthservsdp.dat ()



Found mount point : C:\Windows\ehome\CreateDisc\style\style

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ftpcache\ftpcache

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\Globalization\Globalization

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\Help\Corporate\Corporate

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\Installer\$PatchCache$\Managed\000021091A0090400000000000F01FEC\12.0.6425\12.0.6425

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\Installer\$PatchCache$\Managed\00002109411090400000000000F01FEC\12.0.4518\12.0.4518

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\Installer\$PatchCache$\Managed\00002109440090400000000000F01FEC\12.0.6425\12.0.6425

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\Installer\$PatchCache$\Managed\00002109510090400000000000F01FEC\12.0.6425\12.0.6425

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\Installer\$PatchCache$\Managed\00002109511090400000000000F01FEC\12.0.4518\12.0.4518

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\Installer\$PatchCache$\Managed\00002109711090400000000000F01FEC\12.0.4518\12.0.4518

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\Installer\$PatchCache$\Managed\00002109910090400000000000F01FEC\12.0.6425\12.0.6425

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\Installer\$PatchCache$\Managed\00002109A10090400000000000F01FEC\12.0.6425\12.0.6425

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\Installer\$PatchCache$\Managed\7A6460EF0D914B142ABBC2536D4472D0\1.0.0\1.0.0

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\Installer\$PatchCache$\Managed\D7314F9862C648A4DB8BE2A5B47BE100\1.0.0\1.0.0

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\LiveKernelReports\LiveKernelReports

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\Microsoft.NET\authman\authman

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\nap\configuration\configuration

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\Panther\setup.exe\setup.exe

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\PCHEALTH\ERRORREP\QHEADLES\QHEADLES

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\PCHEALTH\ERRORREP\QSIGNOFF\QSIGNOFF

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\PLA\Templates\Templates

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\Registration\CRMLog\CRMLog

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SchCache\SchCache

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\security\templates\templates

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\GameExplorer\GameExplorer

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\TfsStore\Tfs_DAV\Tfs_DAV

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Media Center Programs\Media Center Programs

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Quick Launch

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\UPnP Device Host\Description Documents\Description Documents

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Network Shortcuts\Network Shortcuts

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\Printer Shortcuts

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Recent\Recent

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Templates\Templates

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\LocalService\Desktop\Desktop

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\LocalService\Documents\Documents

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\LocalService\Downloads\Downloads

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\LocalService\Favorites\Favorites

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\LocalService\Links\Links

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\LocalService\Music\Music

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\LocalService\Pictures\Pictures

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\LocalService\Saved Games\Saved Games

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\LocalService\Videos\Videos

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\GameExplorer\GameExplorer

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows Media Player NSS\3.0\SCPD\SCPD

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Media Center Programs\Media Center Programs

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Quick Launch

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\Certificates

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs\CRLs

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs\CTLs

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Network Shortcuts\Network Shortcuts

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\Printer Shortcuts

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Recent\Recent

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Templates\Templates

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\NetworkService\Desktop\Desktop

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\NetworkService\Documents\Documents

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\NetworkService\Downloads\Downloads

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\NetworkService\Favorites\Favorites

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\NetworkService\Links\Links

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\NetworkService\Music\Music

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\NetworkService\Pictures\Pictures

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\NetworkService\Saved Games\Saved Games

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\NetworkService\Videos\Videos

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\AuthCabs\Downloaded\Downloaded

Mount point destination : \Device\__max++>\^

Could not open reparse point C:\Windows\SoftwareDistribution\Download\d7480a065993d63dcab7527fa2107fee\x86_microsoft-windows-a..-experience-apphelp_31bf3856ad364e35_6.0.6000.16917_none_8017d2ec639e89ee\x86_microsoft-windows-a..-experience-apphelp_31bf3856ad364e35_6.0.6000.16917_none_8017d2ec639e89ee: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d7480a065993d63dcab7527fa2107fee\x86_microsoft-windows-a..-experience-apphelp_31bf3856ad364e35_6.0.6000.21117_none_80a147d97cbc5cfa\x86_microsoft-windows-a..-experience-apphelp_31bf3856ad364e35_6.0.6000.21117_none_80a147d97cbc5cfa: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d7480a065993d63dcab7527fa2107fee\x86_microsoft-windows-a..-experience-apphelp_31bf3856ad364e35_6.0.6001.18320_none_81ec3fa060d3856f\x86_microsoft-windows-a..-experience-apphelp_31bf3856ad364e35_6.0.6001.18320_none_81ec3fa060d3856f: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d7480a065993d63dcab7527fa2107fee\x86_microsoft-windows-a..-experience-apphelp_31bf3856ad364e35_6.0.6001.22509_none_829480c379d8ce8d\x86_microsoft-windows-a..-experience-apphelp_31bf3856ad364e35_6.0.6001.22509_none_829480c379d8ce8d: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d7480a065993d63dcab7527fa2107fee\x86_microsoft-windows-a..-experience-apphelp_31bf3856ad364e35_6.0.6002.18101_none_83e953905de8b92f\x86_microsoft-windows-a..-experience-apphelp_31bf3856ad364e35_6.0.6002.18101_none_83e953905de8b92f: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d7480a065993d63dcab7527fa2107fee\x86_microsoft-windows-a..-experience-apphelp_31bf3856ad364e35_6.0.6002.22213_none_846a2103770ca798\x86_microsoft-windows-a..-experience-apphelp_31bf3856ad364e35_6.0.6002.22213_none_846a2103770ca798: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d7480a065993d63dcab7527fa2107fee\x86_microsoft-windows-a..bility-assistant-db_31bf3856ad364e35_6.0.6000.16917_none_478cf445c1264c69\x86_microsoft-windows-a..bility-assistant-db_31bf3856ad364e35_6.0.6000.16917_none_478cf445c1264c69: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d7480a065993d63dcab7527fa2107fee\x86_microsoft-windows-a..bility-assistant-db_31bf3856ad364e35_6.0.6000.21117_none_48166932da441f75\x86_microsoft-windows-a..bility-assistant-db_31bf3856ad364e35_6.0.6000.21117_none_48166932da441f75: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d7480a065993d63dcab7527fa2107fee\x86_microsoft-windows-a..bility-assistant-db_31bf3856ad364e35_6.0.6001.18320_none_496160f9be5b47ea\x86_microsoft-windows-a..bility-assistant-db_31bf3856ad364e35_6.0.6001.18320_none_496160f9be5b47ea: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d7480a065993d63dcab7527fa2107fee\x86_microsoft-windows-a..bility-assistant-db_31bf3856ad364e35_6.0.6001.22509_none_4a09a21cd7609108\x86_microsoft-windows-a..bility-assistant-db_31bf3856ad364e35_6.0.6001.22509_none_4a09a21cd7609108: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d7480a065993d63dcab7527fa2107fee\x86_microsoft-windows-a..bility-assistant-db_31bf3856ad364e35_6.0.6002.18101_none_4b5e74e9bb707baa\x86_microsoft-windows-a..bility-assistant-db_31bf3856ad364e35_6.0.6002.18101_none_4b5e74e9bb707baa: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d7480a065993d63dcab7527fa2107fee\x86_microsoft-windows-a..bility-assistant-db_31bf3856ad364e35_6.0.6002.22213_none_4bdf425cd4946a13\x86_microsoft-windows-a..bility-assistant-db_31bf3856ad364e35_6.0.6002.22213_none_4bdf425cd4946a13: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d7480a065993d63dcab7527fa2107fee\x86_microsoft-windows-a..ence-mitigations-c1_31bf3856ad364e35_6.0.6000.16917_none_0a38314ff5279fa3\x86_microsoft-windows-a..ence-mitigations-c1_31bf3856ad364e35_6.0.6000.16917_none_0a38314ff5279fa3: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d7480a065993d63dcab7527fa2107fee\x86_microsoft-windows-a..ence-mitigations-c1_31bf3856ad364e35_6.0.6000.21117_none_0ac1a63d0e4572af\x86_microsoft-windows-a..ence-mitigations-c1_31bf3856ad364e35_6.0.6000.21117_none_0ac1a63d0e4572af: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d7480a065993d63dcab7527fa2107fee\x86_microsoft-windows-a..ence-mitigations-c1_31bf3856ad364e35_6.0.6001.18320_none_0c0c9e03f25c9b24\x86_microsoft-windows-a..ence-mitigations-c1_31bf3856ad364e35_6.0.6001.18320_none_0c0c9e03f25c9b24: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d7480a065993d63dcab7527fa2107fee\x86_microsoft-windows-a..ence-mitigations-c1_31bf3856ad364e35_6.0.6001.22509_none_0cb4df270b61e442\x86_microsoft-windows-a..ence-mitigations-c1_31bf3856ad364e35_6.0.6001.22509_none_0cb4df270b61e442: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d7480a065993d63dcab7527fa2107fee\x86_microsoft-windows-a..ence-mitigations-c1_31bf3856ad364e35_6.0.6002.18101_none_0e09b1f3ef71cee4\x86_microsoft-windows-a..ence-mitigations-c1_31bf3856ad364e35_6.0.6002.18101_none_0e09b1f3ef71cee4: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d7480a065993d63dcab7527fa2107fee\x86_microsoft-windows-a..ence-mitigations-c1_31bf3856ad364e35_6.0.6002.22213_none_0e8a7f670895bd4d\x86_microsoft-windows-a..ence-mitigations-c1_31bf3856ad364e35_6.0.6002.22213_none_0e8a7f670895bd4d: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d7480a065993d63dcab7527fa2107fee\x86_microsoft-windows-a..ence-mitigations-c2_31bf3856ad364e35_6.0.6000.16917_none_0a393199f526b8fa\x86_microsoft-windows-a..ence-mitigations-c2_31bf3856ad364e35_6.0.6000.16917_none_0a393199f526b8fa: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d7480a065993d63dcab7527fa2107fee\x86_microsoft-windows-a..ence-mitigations-c2_31bf3856ad364e35_6.0.6000.21117_none_0ac2a6870e448c06\x86_microsoft-windows-a..ence-mitigations-c2_31bf3856ad364e35_6.0.6000.21117_none_0ac2a6870e448c06: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d7480a065993d63dcab7527fa2107fee\x86_microsoft-windows-a..ence-mitigations-c2_31bf3856ad364e35_6.0.6001.18320_none_0c0d9e4df25bb47b\x86_microsoft-windows-a..ence-mitigations-c2_31bf3856ad364e35_6.0.6001.18320_none_0c0d9e4df25bb47b: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d7480a065993d63dcab7527fa2107fee\x86_microsoft-windows-a..ence-mitigations-c2_31bf3856ad364e35_6.0.6001.22509_none_0cb5df710b60fd99\x86_microsoft-windows-a..ence-mitigations-c2_31bf3856ad364e35_6.0.6001.22509_none_0cb5df710b60fd99: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d7480a065993d63dcab7527fa2107fee\x86_microsoft-windows-a..ence-mitigations-c2_31bf3856ad364e35_6.0.6002.18101_none_0e0ab23def70e83b\x86_microsoft-windows-a..ence-mitigations-c2_31bf3856ad364e35_6.0.6002.18101_none_0e0ab23def70e83b: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d7480a065993d63dcab7527fa2107fee\x86_microsoft-windows-a..ence-mitigations-c2_31bf3856ad364e35_6.0.6002.22213_none_0e8b7fb10894d6a4\x86_microsoft-windows-a..ence-mitigations-c2_31bf3856ad364e35_6.0.6002.22213_none_0e8b7fb10894d6a4: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d7480a065993d63dcab7527fa2107fee\x86_microsoft-windows-a..ence-mitigations-c3_31bf3856ad364e35_6.0.6000.16917_none_0a3a31e3f525d251\x86_microsoft-windows-a..ence-mitigations-c3_31bf3856ad364e35_6.0.6000.16917_none_0a3a31e3f525d251: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d7480a065993d63dcab7527fa2107fee\x86_microsoft-windows-a..ence-mitigations-c3_31bf3856ad364e35_6.0.6000.21117_none_0ac3a6d10e43a55d\x86_microsoft-windows-a..ence-mitigations-c3_31bf3856ad364e35_6.0.6000.21117_none_0ac3a6d10e43a55d: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d7480a065993d63dcab7527fa2107fee\x86_microsoft-windows-a..ence-mitigations-c3_31bf3856ad364e35_6.0.6001.18320_none_0c0e9e97f25acdd2\x86_microsoft-windows-a..ence-mitigations-c3_31bf3856ad364e35_6.0.6001.18320_none_0c0e9e97f25acdd2: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d7480a065993d63dcab7527fa2107fee\x86_microsoft-windows-a..ence-mitigations-c3_31bf3856ad364e35_6.0.6001.22509_none_0cb6dfbb0b6016f0\x86_microsoft-windows-a..ence-mitigations-c3_31bf3856ad364e35_6.0.6001.22509_none_0cb6dfbb0b6016f0: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d7480a065993d63dcab7527fa2107fee\x86_microsoft-windows-a..ence-mitigations-c3_31bf3856ad364e35_6.0.6002.18101_none_0e0bb287ef700192\x86_microsoft-windows-a..ence-mitigations-c3_31bf3856ad364e35_6.0.6002.18101_none_0e0bb287ef700192: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d7480a065993d63dcab7527fa2107fee\x86_microsoft-windows-a..ence-mitigations-c3_31bf3856ad364e35_6.0.6002.22213_none_0e8c7ffb0893effb\x86_microsoft-windows-a..ence-mitigations-c3_31bf3856ad364e35_6.0.6002.22213_none_0e8c7ffb0893effb: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d7480a065993d63dcab7527fa2107fee\x86_microsoft-windows-a..ence-mitigations-c4_31bf3856ad364e35_6.0.6000.16917_none_0a3b322df524eba8\x86_microsoft-windows-a..ence-mitigations-c4_31bf3856ad364e35_6.0.6000.16917_none_0a3b322df524eba8: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d7480a065993d63dcab7527fa2107fee\x86_microsoft-windows-a..ence-mitigations-c4_31bf3856ad364e35_6.0.6000.21117_none_0ac4a71b0e42beb4\x86_microsoft-windows-a..ence-mitigations-c4_31bf3856ad364e35_6.0.6000.21117_none_0ac4a71b0e42beb4: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d7480a065993d63dcab7527fa2107fee\x86_microsoft-windows-a..ence-mitigations-c4_31bf3856ad364e35_6.0.6001.18320_none_0c0f9ee1f259e729\x86_microsoft-windows-a..ence-mitigations-c4_31bf3856ad364e35_6.0.6001.18320_none_0c0f9ee1f259e729: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d7480a065993d63dcab7527fa2107fee\x86_microsoft-windows-a..ence-mitigations-c4_31bf3856ad364e35_6.0.6001.22509_none_0cb7e0050b5f3047\x86_microsoft-windows-a..ence-mitigations-c4_31bf3856ad364e35_6.0.6001.22509_none_0cb7e0050b5f3047: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d7480a065993d63dcab7527fa2107fee\x86_microsoft-windows-a..ence-mitigations-c4_31bf3856ad364e35_6.0.6002.18101_none_0e0cb2d1ef6f1ae9\x86_microsoft-windows-a..ence-mitigations-c4_31bf3856ad364e35_6.0.6002.18101_none_0e0cb2d1ef6f1ae9: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d7480a065993d63dcab7527fa2107fee\x86_microsoft-windows-a..ence-mitigations-c4_31bf3856ad364e35_6.0.6002.22213_none_0e8d804508930952\x86_microsoft-windows-a..ence-mitigations-c4_31bf3856ad364e35_6.0.6002.22213_none_0e8d804508930952: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d7480a065993d63dcab7527fa2107fee\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.0.6000.16917_none_0a3c3277f52404ff\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.0.6000.16917_none_0a3c3277f52404ff: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d7480a065993d63dcab7527fa2107fee\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.0.6000.21117_none_0ac5a7650e41d80b\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.0.6000.21117_none_0ac5a7650e41d80b: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d7480a065993d63dcab7527fa2107fee\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.0.6001.18320_none_0c109f2bf2590080\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.0.6001.18320_none_0c109f2bf2590080: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d7480a065993d63dcab7527fa2107fee\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.0.6001.22509_none_0cb8e04f0b5e499e\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.0.6001.22509_none_0cb8e04f0b5e499e: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d7480a065993d63dcab7527fa2107fee\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.0.6002.18101_none_0e0db31bef6e3440\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.0.6002.18101_none_0e0db31bef6e3440: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d7480a065993d63dcab7527fa2107fee\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.0.6002.22213_none_0e8e808f089222a9\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.0.6002.22213_none_0e8e808f089222a9: 3
Found mount point : C:\Windows\SoftwareDistribution\Download\d7480a065993d63dcab7527fa2107fee\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6000.16917_none_40164834c4183551\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6000.16917_none_40164834c4183551

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\d7480a065993d63dcab7527fa2107fee\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6000.21117_none_409fbd21dd36085d\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6000.21117_none_409fbd21dd36085d

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\d7480a065993d63dcab7527fa2107fee\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6001.18320_none_41eab4e8c14d30d2\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6001.18320_none_41eab4e8c14d30d2

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\d7480a065993d63dcab7527fa2107fee\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6001.22509_none_4292f60bda5279f0\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6001.22509_none_4292f60bda5279f0

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\d7480a065993d63dcab7527fa2107fee\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6002.18101_none_43e7c8d8be626492\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6002.18101_none_43e7c8d8be626492

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\d7480a065993d63dcab7527fa2107fee\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6002.22213_none_4468964bd78652fb\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6002.22213_none_4468964bd78652fb

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\f9870fa09c866a37752cd50336c30a22\x86_microsoft-windows-ie-iecompat_31bf3856ad364e35_8.0.6001.18819_none_83d6ded046b75eaf\x86_microsoft-windows-ie-iecompat_31bf3856ad364e35_8.0.6001.18819_none_83d6ded046b75eaf

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\f9870fa09c866a37752cd50336c30a22\x86_microsoft-windows-ie-iecompat_31bf3856ad364e35_8.0.6001.22909_none_846b4b875fcce288\x86_microsoft-windows-ie-iecompat_31bf3856ad364e35_8.0.6001.22909_none_846b4b875fcce288

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\PostRebootEventCache\PostRebootEventCache

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\ScanFile\ScanFile

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\Sun\Java\Deployment\Deployment

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\System32\0409\0409

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\System32\Adobe\update\update

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\System32\Branding\en-US\en-US

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\System32\catroot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}

Mount point destination : \Device\__max++>\^

Cannot access: C:\Windows\System32\cngaudit.dll

[1] 2006-11-02 05:46:03 61952 C:\Windows\System32\cngaudit.dll ()

[2] 2006-11-02 05:46:03 11776 C:\Windows\System32\logevent.dll (Microsoft Corporation)

[1] 2006-11-02 05:46:03 11776 C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll (Microsoft Corporation)



Found mount point : C:\Windows\System32\com\dmp\dmp

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\System32\config\Journal\Journal

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\IdentityCRL\production\temp\temp

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Messenger\Messenger

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\System32\config\systemprofile\AppData\Roaming\Intel\Wireless\Wireless

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\Certificates

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs\CRLs

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs\CTLs

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\System32\config\systemprofile\AppData\Roaming\Roxio\MediaManager9\MediaManager9

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\System32\ENU\ENU

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\System32\GroupPolicy\GroupPolicy

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\System32\GroupPolicyUsers\GroupPolicyUsers

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\System32\inetsrv\inetsrv

Mount point destination : \Device\__max++>\^

Cannot access: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDiagLog.etl

[1] 2009-09-05 13:02:50 64 C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDiagLog.etl ()



Cannot access: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-Application.etl

[1] 2009-09-05 12:31:13 0 C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-Application.etl ()



Cannot access: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventlog-Security.etl

[1] 2009-09-05 13:03:41 64 C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventlog-Security.etl ()



Cannot access: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-System.etl

[1] 2009-09-05 13:03:41 64 C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-System.etl ()



Found mount point : C:\Windows\System32\Microsoft\Crypto\RSA\MachineKeys\MachineKeys

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\System32\MUI\dispspec\dispspec

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\System32\setup\en-US\en-US

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\System32\SMI\Manifests\Manifests

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\System32\spool\drivers\IA64\IA64

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\System32\spool\drivers\x64\x64

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\System32\spool\PRINTERS\PRINTERS

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\System32\spool\SERVERS\SERVERS

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\System32\Tasks\Microsoft\Windows\SyncCenter\SyncCenter

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\System32\Tasks\Microsoft\Windows\WindowsCalendar\WindowsCalendar

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\System32\wbem\MOF\bad\bad

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\System32\wbem\MOF\good\good

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\System32\WDI\{a7a5847a-7511-4e4e-90b1-45ad2a002f51}\{a7a5847a-7511-4e4e-90b1-45ad2a002f51}

Mount point destination : \Device\__max++>\^

Cannot access: C:\Windows\System32\WerFault.exe

[1] 2008-01-19 03:33:35 217088 C:\Windows\System32\WerFault.exe ()

[1] 2006-11-02 05:45:54 216064 C:\Windows\winsxs\x86_microsoft-windows-errorreportingfaults_31bf3856ad364e35_6.0.6000.16386_none_6dd05aa63fde4065\WerFault.exe (Microsoft Corporation)

[1] 2008-01-19 03:33:35 217088 C:\Windows\winsxs\x86_microsoft-windows-errorreportingfaults_31bf3856ad364e35_6.0.6001.18000_none_70071ca23cc95139\WerFault.exe ()

[1] 2008-01-19 03:33:35 217088 C:\Windows\winsxs\x86_microsoft-windows-errorreportingfaults_31bf3856ad364e35_6.0.6001.18145_none_6fe0e04a3ce53cd7\WerFault.exe ()

[1] 2008-09-20 00:00:16 217088 C:\Windows\winsxs\x86_microsoft-windows-errorreportingfaults_31bf3856ad364e35_6.0.6001.22271_none_70460c29561ecb18\WerFault.exe (Microsoft Corporation)



Found mount point : C:\Windows\System32\winevt\TraceFormat\TraceFormat

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\Temp\AVSETUP_4a865ef9\AVSETUP_4a865ef9

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\tracing\tracing

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\winsxs\InstallTemp\InstallTemp

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\winsxs\Temp\PendingDeletes\PendingDeletes

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\winsxs\Temp\PendingRenames\PendingRenames

Mount point destination : \Device\__max++>\^

Cannot access: C:\Windows\winsxs\x86_microsoft-windows-errorreportingfaults_31bf3856ad364e35_6.0.6001.18000_none_70071ca23cc95139\WerFault.exe

[1] 2008-01-19 03:33:35 217088 C:\Windows\System32\WerFault.exe ()

[1] 2006-11-02 05:45:54 216064 C:\Windows\winsxs\x86_microsoft-windows-errorreportingfaults_31bf3856ad364e35_6.0.6000.16386_none_6dd05aa63fde4065\WerFault.exe (Microsoft Corporation)

[1] 2008-01-19 03:33:35 217088 C:\Windows\winsxs\x86_microsoft-windows-errorreportingfaults_31bf3856ad364e35_6.0.6001.18000_none_70071ca23cc95139\WerFault.exe ()

[1] 2008-01-19 03:33:35 217088 C:\Windows\winsxs\x86_microsoft-windows-errorreportingfaults_31bf3856ad364e35_6.0.6001.18145_none_6fe0e04a3ce53cd7\WerFault.exe ()

[1] 2008-09-20 00:00:16 217088 C:\Windows\winsxs\x86_microsoft-windows-errorreportingfaults_31bf3856ad364e35_6.0.6001.22271_none_70460c29561ecb18\WerFault.exe (Microsoft Corporation)



Cannot access: C:\Windows\winsxs\x86_microsoft-windows-errorreportingfaults_31bf3856ad364e35_6.0.6001.18145_none_6fe0e04a3ce53cd7\WerFault.exe

[1] 2008-01-19 03:33:35 217088 C:\Windows\System32\WerFault.exe ()

[1] 2006-11-02 05:45:54 216064 C:\Windows\winsxs\x86_microsoft-windows-errorreportingfaults_31bf3856ad364e35_6.0.6000.16386_none_6dd05aa63fde4065\WerFault.exe (Microsoft Corporation)

[1] 2008-01-19 03:33:35 217088 C:\Windows\winsxs\x86_microsoft-windows-errorreportingfaults_31bf3856ad364e35_6.0.6001.18000_none_70071ca23cc95139\WerFault.exe ()

[1] 2008-01-19 03:33:35 217088 C:\Windows\winsxs\x86_microsoft-windows-errorreportingfaults_31bf3856ad364e35_6.0.6001.18145_none_6fe0e04a3ce53cd7\WerFault.exe ()

[1] 2008-09-20 00:00:16 217088 C:\Windows\winsxs\x86_microsoft-windows-errorreportingfaults_31bf3856ad364e35_6.0.6001.22271_none_70460c29561ecb18\WerFault.exe (Microsoft Corporation)





Finished!

BC AdBot (Login to Remove)

 


#2 suebaby41

suebaby41

    W.A.M. (Women Against Malware)


  • Malware Response Team
  • 6,248 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:South Carolina, USA
  • Local time:06:00 AM

Posted 21 September 2009 - 12:53 PM

Welcome to the BleepingComputer Forums.

Since it has been a few days since you scanned your computer with HijackThis, we will need a new HijackThis log. If you have not already downloaded Random's System Information Tool (RSIT), please download Random's System Information Tool (RSIT) by random/random which includes a HijackThis log and save it to your desktop. If you have RSIT already on your computer, please run it again.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Please post the contents of log.txt.
Thank you for your patience.

Please see Preparation Guide for use before posting about your potential Malware problem.

If you have already posted this log at another forum or if you decide to seek help at another forum, please let us know. There is a shortage of helpers and taking the time of two volunteer helpers means that someone else may not be helped.

Please post your HijackThis log as a reply to this thread and not as an attachment. I am always leery of opening attachments so I always request that HijackThis logs are to be posted as a reply to the thread. I do not think that you are attaching anything scary but others may do so.

While we are working on your HijackThis log, please:
  • Reply to this thread; do not start another!
  • Do not make any changes on your computer during the cleaning process or download/add programs on your computer unless instructed to do so.
  • Do not run any other tool until instructed to do so!
  • Let me know if any of the links do not work or if any of the tools do not work.
  • Tell me about problems or symptoms that occur during the fix.
  • Do not run any other programs or open any other windows while doing a fix.
  • Ask any questions that you have regarding the fix(es), the infection(s), the performance of your computer, etc.
Thanks.
You don't stop laughing when you get old; you get old when you stop laughing.
A Member of U-N-I-T-E (Unified Network of Instructors and Trained Eliminators)
Malware Removal University Masters Graduate

Posted Image
Join The Fight Against Malware
No reply within 5 days will result in your topic being closed. If you need more time, please let me know by posting in this topic so that your topic will not be closed.

#3 jakea333

jakea333
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:05:00 AM

Posted 21 September 2009 - 04:58 PM

A little update on what has happened, since my post I have managed to remove the major problems and get the computer back to normal. I did this by running Avenger and replacing the cngaudit.dll file. Then I ran one run of Combofix (I realize I'm not supposed to without help), followed by several scans of Mbam and SAS until they came up clean. I also ran the Kaspersky online scanner which came back clean on my computer. My roommates computer was the machine that originally gave me the rootkit, through a flash drive. I cleaned it using the same general principles, but did not have time to run multiple scans of Mbam and SAS on it. His machine was much more infected than my own, and after the Combofix run it was possible to boot back into normal mode, but I had to revalidate Windows to do so.

Right now, both machines seem to be running fine; although, I'm not confident they are clean.

I am appreciative of any help.

Logfile of random's system information tool 1.06 (written by random/random)
Run by Jake at 2009-09-21 17:37:26
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 90 GB (64%) free of 140 GB
Total RAM: 2045 MB (46% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:37:44 PM, on 9/21/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\OEM02Mon.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Windows\sttray.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Dell\DELL Webcam Manager\DellWMgr.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Users\Jake\Desktop\RSIT.exe
C:\Program Files\trend micro\Jake.exe
C:\Windows\system32\SearchFilterHost.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [UpdReg] C:\Windows\UpdReg.EXE
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [MaxMenuMgr] "C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
O4 - HKLM\..\Run: [mumservice] C:\Program Files\Motorola\Software Update\mumservice.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DELL Webcam Manager] "C:\Program Files\Dell\DELL Webcam Manager\DellWMgr.exe" /s
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\Windows\system32\CTsvcCDA.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Seagate Service (FreeAgentGoNext Service) - Seagate Technology LLC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD DE\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: Remote Procedure Call (RPC) Net (rpcnet) - Absolute Software Corp. - C:\Windows\System32\rpcnet.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Windows\system32\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 9178 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-03-30 403824]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-09-14 41760]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-19 1008184]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-09-14 149280]
"OEM02Mon.exe"=C:\Windows\OEM02Mon.exe [2007-05-09 36864]
"Apoint"=C:\Program Files\DellTPad\Apoint.exe [2007-04-17 159744]
"IAAnotif"=C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [2007-02-12 174872]
"VolPanel"=C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe [2006-11-27 180224]
"UpdReg"=C:\Windows\UpdReg.EXE [2000-05-11 90112]
"RoxWatchTray"=C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe [2006-11-05 221184]
"ISUSPM Startup"=C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe [2006-10-03 221184]
"ISUSScheduler"=C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [2006-10-03 81920]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
"MaxMenuMgr"=C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe [2008-10-28 181544]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 35696]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2008-06-09 13543968]
"NvMediaCenter"=C:\Windows\system32\NvMcTray.dll [2008-06-09 92704]
"NVHotkey"=C:\Windows\system32\nvHotkey.dll [2008-06-09 96800]
"mumservice"=C:\Program Files\Motorola\Software Update\mumservice.exe [2009-03-25 996608]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-01-05 413696]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]
"Malwarebytes Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2009-09-10 1312080]
"SigmatelSysTrayApp"=C:\Windows\sttray.exe [2007-03-06 303104]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files\Skype\\Phone\Skype.exe [2009-04-16 24264488]
"MsnMsgr"=C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe [2009-02-06 3885408]
"DELL Webcam Manager"=C:\Program Files\Dell\DELL Webcam Manager\DellWMgr.exe [2007-06-07 118784]
"Aim6"=C:\Program Files\AIM6\aim6.exe [2009-05-19 49968]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2009-09-04 1994480]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-19 202240]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [2009-09-03 548352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\rootrepeal.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\rootrepeal2.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\rr.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\xx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\yy.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=
"BindDirectlyToPropertySetStorage"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{796401ba-9a39-11de-a282-c20a53a73b8f}]
shell\AutoRun\command - BOOTEX\thumbcache_131.exe
shell\explore\command - BOOTEX/thumbcache_131.exe
shell\open\command - .////BOOTEX/thumbcache_131.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7e3371c4-9ce2-11de-bc1e-00197edbe3c7}]
shell\AutoRun\command - G:\LaunchU3.exe -a


======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2009-09-21 17:37:26 ----D---- C:\rsit
2009-09-21 17:37:26 ----D---- C:\Program Files\trend micro
2009-09-14 22:20:10 ----A---- C:\Windows\system32\javaws.exe
2009-09-14 22:20:10 ----A---- C:\Windows\system32\javaw.exe
2009-09-14 22:20:10 ----A---- C:\Windows\system32\java.exe
2009-09-14 22:20:10 ----A---- C:\Windows\system32\deploytk.dll
2009-09-13 01:33:36 ----D---- C:\Windows\system32\eu-ES
2009-09-13 01:33:36 ----D---- C:\Windows\system32\ca-ES
2009-09-13 01:33:35 ----D---- C:\Windows\system32\vi-VN
2009-09-13 01:30:01 ----D---- C:\Windows\system32\SPReview
2009-09-13 01:17:09 ----A---- C:\Windows\system32\scavenge.dll
2009-09-13 01:16:56 ----A---- C:\Windows\system32\compcln.exe
2009-09-13 01:16:16 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2009-09-13 01:16:16 ----A---- C:\Windows\system32\secproc_ssp.dll
2009-09-13 01:16:16 ----A---- C:\Windows\system32\secproc_isv.dll
2009-09-13 01:16:16 ----A---- C:\Windows\system32\secproc.dll
2009-09-13 01:16:16 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2009-09-13 01:16:16 ----A---- C:\Windows\system32\SearchIndexer.exe
2009-09-13 01:16:16 ----A---- C:\Windows\system32\SearchFilterHost.exe
2009-09-13 01:16:16 ----A---- C:\Windows\system32\sdohlp.dll
2009-09-13 01:16:16 ----A---- C:\Windows\system32\sdclt.exe
2009-09-13 01:16:16 ----A---- C:\Windows\system32\samlib.dll
2009-09-13 01:16:16 ----A---- C:\Windows\system32\rtutils.dll
2009-09-13 01:16:16 ----A---- C:\Windows\system32\rtffilt.dll
2009-09-13 01:16:16 ----A---- C:\Windows\system32\rsaenh.dll
2009-09-13 01:16:16 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2009-09-13 01:16:16 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2009-09-13 01:16:16 ----A---- C:\Windows\system32\RMActivate_isv.exe
2009-09-13 01:16:16 ----A---- C:\Windows\system32\riched20.dll
2009-09-13 01:16:15 ----A---- C:\Windows\system32\rpcss.dll
2009-09-13 01:16:15 ----A---- C:\Windows\system32\RMActivate.exe
2009-09-13 01:16:14 ----A---- C:\Windows\system32\scrrun.dll
2009-09-13 01:16:14 ----A---- C:\Windows\system32\SCardSvr.dll
2009-09-13 01:16:14 ----A---- C:\Windows\system32\scansetting.dll
2009-09-13 01:16:14 ----A---- C:\Windows\system32\rpchttp.dll
2009-09-13 01:16:13 ----A---- C:\Windows\system32\scrobj.dll
2009-09-13 01:16:13 ----A---- C:\Windows\system32\scksp.dll
2009-09-13 01:16:13 ----A---- C:\Windows\system32\schedsvc.dll
2009-09-13 01:16:13 ----A---- C:\Windows\system32\scesrv.dll
2009-09-13 01:16:13 ----A---- C:\Windows\system32\scecli.dll
2009-09-13 01:16:13 ----A---- C:\Windows\system32\samsrv.dll
2009-09-13 01:16:10 ----A---- C:\Windows\system32\pdh.dll
2009-09-13 01:16:09 ----A---- C:\Windows\system32\powercpl.dll
2009-09-13 01:16:09 ----A---- C:\Windows\system32\PortableDeviceTypes.dll
2009-09-13 01:16:09 ----A---- C:\Windows\system32\PortableDeviceClassExtension.dll
2009-09-13 01:16:09 ----A---- C:\Windows\system32\PortableDeviceApi.dll
2009-09-13 01:16:09 ----A---- C:\Windows\system32\PNPXAssoc.dll
2009-09-13 01:16:09 ----A---- C:\Windows\system32\PnPutil.exe
2009-09-13 01:16:09 ----A---- C:\Windows\system32\PnPUnattend.exe
2009-09-13 01:16:09 ----A---- C:\Windows\system32\pnpui.dll
2009-09-13 01:16:09 ----A---- C:\Windows\system32\pnpsetup.dll
2009-09-13 01:16:09 ----A---- C:\Windows\system32\pnidui.dll
2009-09-13 01:16:09 ----A---- C:\Windows\system32\photowiz.dll
2009-09-13 01:16:09 ----A---- C:\Windows\system32\perfdisk.dll
2009-09-13 01:16:09 ----A---- C:\Windows\system32\PerfCenterCPL.dll
2009-09-13 01:16:09 ----A---- C:\Windows\system32\pcaui.dll
2009-09-13 01:16:09 ----A---- C:\Windows\system32\p2psvc.dll
2009-09-13 01:16:09 ----A---- C:\Windows\system32\P2PGraph.dll
2009-09-13 01:16:08 ----A---- C:\Windows\system32\PkgMgr.exe
2009-09-13 01:16:08 ----A---- C:\Windows\system32\pidgenx.dll
2009-09-13 01:16:08 ----A---- C:\Windows\system32\PhotoMetadataHandler.dll
2009-09-13 01:16:08 ----A---- C:\Windows\system32\ntkrnlpa.exe
2009-09-13 01:16:08 ----A---- C:\Windows\system32\ntdll.dll
2009-09-13 01:16:08 ----A---- C:\Windows\system32\nslookup.exe
2009-09-13 01:16:07 ----A---- C:\Windows\system32\oleaut32.dll
2009-09-13 01:16:07 ----A---- C:\Windows\system32\ole32.dll
2009-09-13 01:16:07 ----A---- C:\Windows\system32\offfilt.dll
2009-09-13 01:16:07 ----A---- C:\Windows\system32\NlsLexicons0009.dll
2009-09-13 01:16:07 ----A---- C:\Windows\system32\NlsLexicons0007.dll
2009-09-13 01:16:07 ----A---- C:\Windows\system32\nlhtml.dll
2009-09-13 01:16:06 ----A---- C:\Windows\system32\osk.exe
2009-09-13 01:16:06 ----A---- C:\Windows\system32\oobefldr.dll
2009-09-13 01:16:06 ----A---- C:\Windows\system32\onex.dll
2009-09-13 01:16:06 ----A---- C:\Windows\system32\olepro32.dll
2009-09-13 01:16:06 ----A---- C:\Windows\system32\oleprn.dll
2009-09-13 01:16:06 ----A---- C:\Windows\system32\odbccp32.dll
2009-09-13 01:16:06 ----A---- C:\Windows\system32\odbcconf.dll
2009-09-13 01:16:06 ----A---- C:\Windows\system32\odbc32.dll
2009-09-13 01:16:05 ----A---- C:\Windows\system32\ocsetup.exe
2009-09-13 01:16:05 ----A---- C:\Windows\system32\ntprint.dll
2009-09-13 01:16:05 ----A---- C:\Windows\system32\ntmarta.dll
2009-09-13 01:16:04 ----A---- C:\Windows\system32\rastls.dll
2009-09-13 01:16:04 ----A---- C:\Windows\system32\rastapi.dll
2009-09-13 01:16:04 ----A---- C:\Windows\system32\rasppp.dll
2009-09-13 01:16:04 ----A---- C:\Windows\system32\rasplap.dll
2009-09-13 01:16:04 ----A---- C:\Windows\system32\rasmontr.dll
2009-09-13 01:16:04 ----A---- C:\Windows\system32\rasmans.dll
2009-09-13 01:16:04 ----A---- C:\Windows\system32\rasgcw.dll
2009-09-13 01:16:04 ----A---- C:\Windows\system32\rasdlg.dll
2009-09-13 01:16:04 ----A---- C:\Windows\system32\rasdial.exe
2009-09-13 01:16:04 ----A---- C:\Windows\system32\rasdiag.dll
2009-09-13 01:16:04 ----A---- C:\Windows\system32\raschap.dll
2009-09-13 01:16:04 ----A---- C:\Windows\system32\rasapi32.dll
2009-09-13 01:16:04 ----A---- C:\Windows\system32\Query.dll
2009-09-13 01:16:04 ----A---- C:\Windows\system32\quartz.dll
2009-09-13 01:16:04 ----A---- C:\Windows\system32\qedit.dll
2009-09-13 01:16:04 ----A---- C:\Windows\system32\ntoskrnl.exe
2009-09-13 01:16:03 ----A---- C:\Windows\system32\regsvc.dll
2009-09-13 01:16:03 ----A---- C:\Windows\system32\RacEngn.dll
2009-09-13 01:16:03 ----A---- C:\Windows\system32\qmgr.dll
2009-09-13 01:16:02 ----A---- C:\Windows\system32\RelMon.dll
2009-09-13 01:16:02 ----A---- C:\Windows\system32\rekeywiz.exe
2009-09-13 01:16:02 ----A---- C:\Windows\system32\regapi.dll
2009-09-13 01:16:02 ----A---- C:\Windows\system32\reg.exe
2009-09-13 01:16:02 ----A---- C:\Windows\system32\rdpwsx.dll
2009-09-13 01:16:02 ----A---- C:\Windows\system32\rdpencom.dll
2009-09-13 01:16:02 ----A---- C:\Windows\system32\prnntfy.dll
2009-09-13 01:16:02 ----A---- C:\Windows\system32\printui.dll
2009-09-13 01:16:02 ----A---- C:\Windows\system32\PresentationSettings.exe
2009-09-13 01:16:02 ----A---- C:\Windows\system32\PresentationNative_v0300.dll
2009-09-13 01:16:02 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2009-09-13 01:16:02 ----A---- C:\Windows\system32\PresentationHost.exe
2009-09-13 01:16:01 ----A---- C:\Windows\system32\qdvd.dll
2009-09-13 01:16:01 ----A---- C:\Windows\system32\QAGENTRT.DLL
2009-09-13 01:16:01 ----A---- C:\Windows\system32\puiapi.dll
2009-09-13 01:16:01 ----A---- C:\Windows\system32\printfilterpipelinesvc.exe
2009-09-13 01:16:01 ----A---- C:\Windows\system32\printfilterpipelineprxy.dll
2009-09-13 01:16:01 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-09-13 01:16:01 ----A---- C:\Windows\system32\powrprof.dll
2009-09-13 01:15:59 ----A---- C:\Windows\system32\psisdecd.dll
2009-09-13 01:15:59 ----A---- C:\Windows\system32\PSHED.DLL
2009-09-13 01:15:59 ----A---- C:\Windows\system32\propsys.dll
2009-09-13 01:15:59 ----A---- C:\Windows\system32\propdefs.dll
2009-09-13 01:15:59 ----A---- C:\Windows\system32\profsvc.dll
2009-09-13 01:15:56 ----A---- C:\Windows\system32\shell32.dll
2009-09-13 01:15:56 ----A---- C:\Windows\system32\sendmail.dll
2009-09-13 01:15:55 ----A---- C:\Windows\system32\shlwapi.dll
2009-09-13 01:15:55 ----A---- C:\Windows\system32\shdocvw.dll
2009-09-13 01:15:55 ----A---- C:\Windows\system32\setupapi.dll
2009-09-13 01:15:55 ----A---- C:\Windows\system32\sethc.exe
2009-09-13 01:15:55 ----A---- C:\Windows\system32\services.exe
2009-09-13 01:15:46 ----A---- C:\Windows\system32\EhStorAPI.dll
2009-09-13 01:15:46 ----A---- C:\Windows\system32\eapphost.dll
2009-09-13 01:15:46 ----A---- C:\Windows\system32\eappgnui.dll
2009-09-13 01:15:46 ----A---- C:\Windows\system32\eappcfg.dll
2009-09-13 01:15:46 ----A---- C:\Windows\system32\eapp3hst.dll
2009-09-13 01:15:45 ----A---- C:\Windows\system32\ExplorerFrame.dll
2009-09-13 01:15:45 ----A---- C:\Windows\system32\evr.dll
2009-09-13 01:15:45 ----A---- C:\Windows\system32\eudcedit.exe
2009-09-13 01:15:45 ----A---- C:\Windows\system32\esent.dll
2009-09-13 01:15:45 ----A---- C:\Windows\system32\dwm.exe
2009-09-13 01:15:45 ----A---- C:\Windows\system32\dsprop.dll
2009-09-13 01:15:45 ----A---- C:\Windows\system32\dsound.dll
2009-09-13 01:15:45 ----A---- C:\Windows\explorer.exe
2009-09-13 01:15:44 ----A---- C:\Windows\system32\f3ahvoas.dll
2009-09-13 01:15:44 ----A---- C:\Windows\system32\EncDec.dll
2009-09-13 01:15:44 ----A---- C:\Windows\system32\emdmgmt.dll
2009-09-13 01:15:44 ----A---- C:\Windows\system32\EhStorPwdMgr.dll
2009-09-13 01:15:44 ----A---- C:\Windows\system32\EhStorAuthn.dll
2009-09-13 01:15:43 ----A---- C:\Windows\system32\es.dll
2009-09-13 01:15:43 ----A---- C:\Windows\system32\EhStorShell.dll
2009-09-13 01:15:43 ----A---- C:\Windows\system32\diskraid.exe
2009-09-13 01:15:43 ----A---- C:\Windows\system32\diskpart.exe
2009-09-13 01:15:43 ----A---- C:\Windows\system32\dimsroam.dll
2009-09-13 01:15:43 ----A---- C:\Windows\system32\diagperf.dll
2009-09-13 01:15:43 ----A---- C:\Windows\system32\dhcpcsvc6.dll
2009-09-13 01:15:43 ----A---- C:\Windows\system32\dhcpcsvc.dll
2009-09-13 01:15:43 ----A---- C:\Windows\system32\dfsr.exe
2009-09-13 01:15:43 ----A---- C:\Windows\system32\dfshim.dll
2009-09-13 01:15:43 ----A---- C:\Windows\system32\devmgr.dll
2009-09-13 01:15:42 ----A---- C:\Windows\system32\drvstore.dll
2009-09-13 01:15:42 ----A---- C:\Windows\system32\drvinst.exe
2009-09-13 01:15:42 ----A---- C:\Windows\system32\drmv2clt.dll
2009-09-13 01:15:42 ----A---- C:\Windows\system32\drmmgrtn.dll
2009-09-13 01:15:42 ----A---- C:\Windows\system32\dpapimig.exe
2009-09-13 01:15:42 ----A---- C:\Windows\system32\dot3svc.dll
2009-09-13 01:15:42 ----A---- C:\Windows\system32\dot3msm.dll
2009-09-13 01:15:42 ----A---- C:\Windows\system32\dot3cfg.dll
2009-09-13 01:15:41 ----A---- C:\Windows\system32\dmusic.dll
2009-09-13 01:15:41 ----A---- C:\Windows\system32\dmsynth.dll
2009-09-13 01:15:40 ----A---- C:\Windows\system32\hbaapi.dll
2009-09-13 01:15:40 ----A---- C:\Windows\system32\gpresult.exe
2009-09-13 01:15:40 ----A---- C:\Windows\system32\dnsrslvr.dll
2009-09-13 01:15:40 ----A---- C:\Windows\system32\dnsapi.dll
2009-09-13 01:15:39 ----A---- C:\Windows\system32\iashlpr.dll
2009-09-13 01:15:39 ----A---- C:\Windows\system32\iasdatastore.dll
2009-09-13 01:15:39 ----A---- C:\Windows\system32\iasads.dll
2009-09-13 01:15:39 ----A---- C:\Windows\system32\iasacct.dll
2009-09-13 01:15:39 ----A---- C:\Windows\system32\gpupdate.exe
2009-09-13 01:15:39 ----A---- C:\Windows\system32\gpsvc.dll
2009-09-13 01:15:38 ----A---- C:\Windows\system32\iasnap.dll
2009-09-13 01:15:38 ----A---- C:\Windows\system32\IasMigReader.exe
2009-09-13 01:15:38 ----A---- C:\Windows\system32\IasMigPlugin.dll
2009-09-13 01:15:37 ----A---- C:\Windows\system32\hidserv.dll
2009-09-13 01:15:37 ----A---- C:\Windows\system32\hdwwiz.exe
2009-09-13 01:15:36 ----A---- C:\Windows\system32\gpapi.dll
2009-09-13 01:15:36 ----A---- C:\Windows\system32\gdi32.dll
2009-09-13 01:15:36 ----A---- C:\Windows\system32\fontext.dll
2009-09-13 01:15:36 ----A---- C:\Windows\system32\findstr.exe
2009-09-13 01:15:36 ----A---- C:\Windows\system32\feclient.dll
2009-09-13 01:15:36 ----A---- C:\Windows\system32\fdWSD.dll
2009-09-13 01:15:36 ----A---- C:\Windows\system32\fdWCN.dll
2009-09-13 01:15:36 ----A---- C:\Windows\system32\fdSSDP.dll
2009-09-13 01:15:36 ----A---- C:\Windows\system32\fdProxy.dll
2009-09-13 01:15:36 ----A---- C:\Windows\system32\fdeploy.dll
2009-09-13 01:15:36 ----A---- C:\Windows\system32\fdBthProxy.dll
2009-09-13 01:15:36 ----A---- C:\Windows\system32\fdBth.dll
2009-09-13 01:15:36 ----A---- C:\Windows\system32\fc.exe
2009-09-13 01:15:36 ----A---- C:\Windows\system32\Faultrep.dll
2009-09-13 01:15:35 ----A---- C:\Windows\system32\gpedit.dll
2009-09-13 01:15:35 ----A---- C:\Windows\system32\fundisc.dll
2009-09-13 01:15:35 ----A---- C:\Windows\system32\ftp.exe
2009-09-13 01:15:35 ----A---- C:\Windows\system32\fsquirt.exe
2009-09-13 01:15:34 ----A---- C:\Windows\system32\FunctionDiscoveryFolder.dll
2009-09-13 01:15:33 ----A---- C:\Windows\system32\FwRemoteSvr.dll
2009-09-13 01:15:33 ----A---- C:\Windows\system32\FWPUCLNT.DLL
2009-09-13 01:15:31 ----A---- C:\Windows\system32\AuxiliaryDisplayServices.dll
2009-09-13 01:15:31 ----A---- C:\Windows\system32\AuxiliaryDisplayDriverLib.dll
2009-09-13 01:15:31 ----A---- C:\Windows\system32\AuxiliaryDisplayCpl.dll
2009-09-13 01:15:31 ----A---- C:\Windows\system32\autoplay.dll
2009-09-13 01:15:31 ----A---- C:\Windows\system32\autofmt.exe
2009-09-13 01:15:31 ----A---- C:\Windows\system32\autoconv.exe
2009-09-13 01:15:31 ----A---- C:\Windows\system32\autochk.exe
2009-09-13 01:15:31 ----A---- C:\Windows\system32\authz.dll
2009-09-13 01:15:31 ----A---- C:\Windows\system32\authui.dll
2009-09-13 01:15:31 ----A---- C:\Windows\system32\audiosrv.dll
2009-09-13 01:15:31 ----A---- C:\Windows\system32\AudioSes.dll
2009-09-13 01:15:31 ----A---- C:\Windows\system32\audiodg.exe
2009-09-13 01:15:29 ----A---- C:\Windows\system32\bthci.dll
2009-09-13 01:15:29 ----A---- C:\Windows\system32\browseui.dll
2009-09-13 01:15:29 ----A---- C:\Windows\system32\brcpl.dll
2009-09-13 01:15:29 ----A---- C:\Windows\system32\blackbox.dll
2009-09-13 01:15:29 ----A---- C:\Windows\system32\bitsigd.dll
2009-09-13 01:15:29 ----A---- C:\Windows\system32\bcrypt.dll
2009-09-13 01:15:29 ----A---- C:\Windows\system32\basecsp.dll
2009-09-13 01:15:29 ----A---- C:\Windows\system32\azroles.dll
2009-09-13 01:15:28 ----A---- C:\Windows\system32\BFE.DLL
2009-09-13 01:15:28 ----A---- C:\Windows\system32\accessibilitycpl.dll
2009-09-13 01:15:26 ----A---- C:\Windows\system32\apphelp.dll
2009-09-13 01:15:26 ----A---- C:\Windows\system32\apds.dll
2009-09-13 01:15:25 ----A---- C:\Windows\system32\advapi32.dll
2009-09-13 01:15:25 ----A---- C:\Windows\system32\adtschema.dll
2009-09-13 01:15:25 ----A---- C:\Windows\system32\adsmsext.dll
2009-09-13 01:15:25 ----A---- C:\Windows\system32\adsldpc.dll
2009-09-13 01:15:24 ----A---- C:\Windows\system32\crypt32.dll
2009-09-13 01:15:24 ----A---- C:\Windows\system32\credui.dll
2009-09-13 01:15:24 ----A---- C:\Windows\system32\conime.exe
2009-09-13 01:15:24 ----A---- C:\Windows\system32\comuid.dll
2009-09-13 01:15:24 ----A---- C:\Windows\system32\comsvcs.dll
2009-09-13 01:15:23 ----A---- C:\Windows\system32\connect.dll
2009-09-13 01:15:23 ----A---- C:\Windows\system32\comdlg32.dll
2009-09-13 01:15:23 ----A---- C:\Windows\system32\cmdial32.dll
2009-09-13 01:15:22 ----A---- C:\Windows\system32\cmmon32.exe
2009-09-13 01:15:21 ----A---- C:\Windows\system32\DevicePairingWizard.exe
2009-09-13 01:15:21 ----A---- C:\Windows\system32\DevicePairingProxy.dll
2009-09-13 01:15:21 ----A---- C:\Windows\system32\DevicePairing.dll
2009-09-13 01:15:21 ----A---- C:\Windows\system32\DeviceEject.exe
2009-09-13 01:15:21 ----A---- C:\Windows\system32\dbgeng.dll
2009-09-13 01:15:21 ----A---- C:\Windows\system32\davclnt.dll
2009-09-13 01:15:21 ----A---- C:\Windows\system32\dataclen.dll
2009-09-13 01:15:21 ----A---- C:\Windows\system32\d3d9.dll
2009-09-13 01:15:21 ----A---- C:\Windows\system32\csrstub.exe
2009-09-13 01:15:21 ----A---- C:\Windows\system32\cscript.exe
2009-09-13 01:15:21 ----A---- C:\Windows\system32\cscdll.dll
2009-09-13 01:15:21 ----A---- C:\Windows\system32\cscapi.dll
2009-09-13 01:15:21 ----A---- C:\Windows\system32\cryptui.dll
2009-09-13 01:15:21 ----A---- C:\Windows\system32\cryptsvc.dll
2009-09-13 01:15:21 ----A---- C:\Windows\system32\cdd.dll
2009-09-13 01:15:20 ----A---- C:\Windows\system32\ci.dll
2009-09-13 01:15:20 ----A---- C:\Windows\system32\certmgr.dll
2009-09-13 01:15:20 ----A---- C:\Windows\system32\CertEnrollUI.dll
2009-09-13 01:15:20 ----A---- C:\Windows\system32\CertEnroll.dll
2009-09-13 01:15:20 ----A---- C:\Windows\system32\certcli.dll
2009-09-13 01:15:20 ----A---- C:\Windows\system32\cbsra.exe
2009-09-13 01:15:20 ----A---- C:\Windows\system32\bthudtask.exe
2009-09-13 01:15:20 ----A---- C:\Windows\system32\bthserv.dll
2009-09-13 01:15:19 ----A---- C:\Windows\system32\cipher.exe
2009-09-13 01:15:19 ----A---- C:\Windows\system32\CHxReadingStringIME.dll
2009-09-13 01:15:19 ----A---- C:\Windows\system32\chtbrkr.dll
2009-09-13 01:15:19 ----A---- C:\Windows\system32\chsbrkr.dll
2009-09-13 01:15:18 ----A---- C:\Windows\system32\msftedit.dll
2009-09-13 01:15:18 ----A---- C:\Windows\system32\msexcl40.dll
2009-09-13 01:15:18 ----A---- C:\Windows\system32\msdtctm.dll
2009-09-13 01:15:18 ----A---- C:\Windows\system32\certutil.exe
2009-09-13 01:15:18 ----A---- C:\Windows\system32\certreq.exe
2009-09-13 01:15:18 ----A---- C:\Windows\system32\certprop.dll
2009-09-13 01:15:17 ----A---- C:\Windows\system32\msihnd.dll
2009-09-13 01:15:17 ----A---- C:\Windows\system32\msiexec.exe
2009-09-13 01:15:17 ----A---- C:\Windows\system32\msi.dll
2009-09-13 01:15:17 ----A---- C:\Windows\system32\msexch40.dll
2009-09-13 01:15:16 ----A---- C:\Windows\system32\msdrm.dll
2009-09-13 01:15:15 ----A---- C:\Windows\system32\msimsg.dll
2009-09-13 01:15:15 ----A---- C:\Windows\system32\msdtcprx.dll
2009-09-13 01:15:15 ----A---- C:\Windows\system32\msctfui.dll
2009-09-13 01:15:15 ----A---- C:\Windows\system32\msctfp.dll
2009-09-13 01:15:15 ----A---- C:\Windows\system32\MsCtfMonitor.dll
2009-09-13 01:15:15 ----A---- C:\Windows\system32\msctf.dll
2009-09-13 01:15:14 ----A---- C:\Windows\system32\MPSSVC.dll
2009-09-13 01:15:14 ----A---- C:\Windows\system32\mprapi.dll
2009-09-13 01:15:14 ----A---- C:\Windows\system32\mpr.dll
2009-09-13 01:15:14 ----A---- C:\Windows\system32\modemui.dll
2009-09-13 01:15:14 ----A---- C:\Windows\system32\MMDevAPI.dll
2009-09-13 01:15:12 ----A---- C:\Windows\system32\mscories.dll
2009-09-13 01:15:12 ----A---- C:\Windows\system32\mscorier.dll
2009-09-13 01:15:12 ----A---- C:\Windows\system32\mscoree.dll
2009-09-13 01:15:12 ----A---- C:\Windows\system32\mscms.dll
2009-09-13 01:15:12 ----A---- C:\Windows\system32\mscandui.dll
2009-09-13 01:15:11 ----A---- C:\Windows\system32\netcenter.dll
2009-09-13 01:15:11 ----A---- C:\Windows\system32\netapi32.dll
2009-09-13 01:15:10 ----A---- C:\Windows\system32\NetProjW.dll
2009-09-13 01:15:10 ----A---- C:\Windows\system32\netplwiz.dll
2009-09-13 01:15:10 ----A---- C:\Windows\system32\netlogon.dll
2009-09-13 01:15:10 ----A---- C:\Windows\system32\ncryptui.dll
2009-09-13 01:15:10 ----A---- C:\Windows\system32\ncrypt.dll
2009-09-13 01:15:10 ----A---- C:\Windows\system32\mtxclu.dll
2009-09-13 01:15:08 ----A---- C:\Windows\system32\msxml6.dll
2009-09-13 01:15:07 ----A---- C:\Windows\system32\newdev.exe
2009-09-13 01:15:07 ----A---- C:\Windows\system32\newdev.dll
2009-09-13 01:15:07 ----A---- C:\Windows\system32\netshell.dll
2009-09-13 01:15:07 ----A---- C:\Windows\system32\NcdProp.dll
2009-09-13 01:15:07 ----A---- C:\Windows\system32\NaturalLanguage6.dll
2009-09-13 01:15:07 ----A---- C:\Windows\system32\msxml3.dll
2009-09-13 01:15:06 ----A---- C:\Windows\system32\networkmap.dll
2009-09-13 01:15:06 ----A---- C:\Windows\system32\networkitemfactory.dll
2009-09-13 01:15:06 ----A---- C:\Windows\system32\networkexplorer.dll
2009-09-13 01:15:06 ----A---- C:\Windows\system32\msscntrs.dll
2009-09-13 01:15:06 ----A---- C:\Windows\system32\msscb.dll
2009-09-13 01:15:06 ----A---- C:\Windows\system32\msrepl40.dll
2009-09-13 01:15:06 ----A---- C:\Windows\system32\msrd3x40.dll
2009-09-13 01:15:06 ----A---- C:\Windows\system32\msrd2x40.dll
2009-09-13 01:15:06 ----A---- C:\Windows\system32\mspbde40.dll
2009-09-13 01:15:06 ----A---- C:\Windows\system32\msnetobj.dll
2009-09-13 01:15:06 ----A---- C:\Windows\system32\MSMPEG2VDEC.DLL
2009-09-13 01:15:06 ----A---- C:\Windows\system32\msltus40.dll
2009-09-13 01:15:06 ----A---- C:\Windows\system32\msinfo32.exe
2009-09-13 01:15:06 ----A---- C:\Windows\system32\msimtf.dll
2009-09-13 01:15:05 ----A---- C:\Windows\system32\msxbde40.dll
2009-09-13 01:15:05 ----A---- C:\Windows\system32\mswstr10.dll
2009-09-13 01:15:05 ----A---- C:\Windows\system32\mswsock.dll
2009-09-13 01:15:05 ----A---- C:\Windows\system32\mswdat10.dll
2009-09-13 01:15:05 ----A---- C:\Windows\system32\MSVidCtl.dll
2009-09-13 01:15:05 ----A---- C:\Windows\system32\msvcrt.dll
2009-09-13 01:15:05 ----A---- C:\Windows\system32\msvcp60.dll
2009-09-13 01:15:05 ----A---- C:\Windows\system32\msutb.dll
2009-09-13 01:15:05 ----A---- C:\Windows\system32\mssrch.dll
2009-09-13 01:15:05 ----A---- C:\Windows\system32\mssprxy.dll
2009-09-13 01:15:05 ----A---- C:\Windows\system32\mssphtb.dll
2009-09-13 01:15:05 ----A---- C:\Windows\system32\mssph.dll
2009-09-13 01:15:05 ----A---- C:\Windows\system32\msshooks.dll
2009-09-13 01:15:05 ----A---- C:\Windows\system32\msjtes40.dll
2009-09-13 01:15:05 ----A---- C:\Windows\system32\msjter40.dll
2009-09-13 01:15:05 ----A---- C:\Windows\system32\msjint40.dll
2009-09-13 01:15:05 ----A---- C:\Windows\system32\msjetoledb40.dll
2009-09-13 01:15:05 ----A---- C:\Windows\system32\msjet40.dll
2009-09-13 01:15:05 ----A---- C:\Windows\system32\msisip.dll
2009-09-13 01:15:04 ----A---- C:\Windows\system32\mstsc.exe
2009-09-13 01:15:04 ----A---- C:\Windows\system32\mstlsapi.dll
2009-09-13 01:15:04 ----A---- C:\Windows\system32\mstext40.dll
2009-09-13 01:15:04 ----A---- C:\Windows\system32\mssvp.dll
2009-09-13 01:15:04 ----A---- C:\Windows\system32\msstrc.dll
2009-09-13 01:15:04 ----A---- C:\Windows\system32\mssitlb.dll
2009-09-13 01:15:04 ----A---- C:\Windows\system32\msshsq.dll
2009-09-13 01:15:04 ----A---- C:\Windows\system32\msscp.dll
2009-09-13 01:15:03 ----A---- C:\Windows\system32\InkEd.dll
2009-09-13 01:15:03 ----A---- C:\Windows\system32\infocardapi.dll
2009-09-13 01:15:03 ----A---- C:\Windows\system32\inetppui.dll
2009-09-13 01:15:03 ----A---- C:\Windows\system32\inetpp.dll
2009-09-13 01:15:03 ----A---- C:\Windows\system32\inetcomm.dll
2009-09-13 01:15:02 ----A---- C:\Windows\system32\iscsilog.dll
2009-09-13 01:15:02 ----A---- C:\Windows\system32\ipsmsnap.dll
2009-09-13 01:15:02 ----A---- C:\Windows\system32\IPSECSVC.DLL
2009-09-13 01:15:02 ----A---- C:\Windows\system32\imm32.dll
2009-09-13 01:15:01 ----A---- C:\Windows\system32\ipsecsnp.dll
2009-09-13 01:15:01 ----A---- C:\Windows\system32\iphlpsvc.dll
2009-09-13 01:15:01 ----A---- C:\Windows\system32\IPHLPAPI.DLL
2009-09-13 01:15:01 ----A---- C:\Windows\system32\ipconfig.exe
2009-09-13 01:15:01 ----A---- C:\Windows\system32\input.dll
2009-09-13 01:15:00 ----A---- C:\Windows\system32\IMJP10K.DLL
2009-09-13 01:15:00 ----A---- C:\Windows\system32\ifmon.dll
2009-09-13 01:15:00 ----A---- C:\Windows\system32\icardres.dll
2009-09-13 01:15:00 ----A---- C:\Windows\system32\icardagt.exe
2009-09-13 01:15:00 ----A---- C:\Windows\system32\iassvcs.dll
2009-09-13 01:15:00 ----A---- C:\Windows\system32\iassdo.dll
2009-09-13 01:15:00 ----A---- C:\Windows\system32\iassam.dll
2009-09-13 01:15:00 ----A---- C:\Windows\system32\iasrecst.dll
2009-09-13 01:15:00 ----A---- C:\Windows\system32\iasrad.dll
2009-09-13 01:15:00 ----A---- C:\Windows\system32\iaspolcy.dll
2009-09-13 01:14:59 ----A---- C:\Windows\system32\imapi2fs.dll
2009-09-13 01:14:59 ----A---- C:\Windows\system32\imapi2.dll
2009-09-13 01:14:59 ----A---- C:\Windows\system32\imapi.dll
2009-09-13 01:14:59 ----A---- C:\Windows\system32\IKEEXT.DLL
2009-09-13 01:14:56 ----A---- C:\Windows\system32\mfplat.dll
2009-09-13 01:14:56 ----A---- C:\Windows\system32\mfc42.dll
2009-09-13 01:14:55 ----A---- C:\Windows\system32\mimefilt.dll
2009-09-13 01:14:55 ----A---- C:\Windows\system32\milcore.dll
2009-09-13 01:14:55 ----A---- C:\Windows\system32\mfc42u.dll
2009-09-13 01:14:54 ----A---- C:\Windows\system32\mmcndmgr.dll
2009-09-13 01:14:54 ----A---- C:\Windows\system32\mmcico.dll
2009-09-13 01:14:54 ----A---- C:\Windows\system32\mmci.dll
2009-09-13 01:14:54 ----A---- C:\Windows\system32\mmc.exe
2009-09-13 01:14:54 ----A---- C:\Windows\system32\midimap.dll
2009-09-13 01:14:53 ----A---- C:\Windows\system32\korwbrkr.dll
2009-09-13 01:14:51 ----A---- C:\Windows\system32\l2nacp.dll
2009-09-13 01:14:51 ----A---- C:\Windows\system32\kd1394.dll
2009-09-13 01:14:50 ----A---- C:\Windows\system32\MediaMetadataHandler.dll
2009-09-13 01:14:50 ----A---- C:\Windows\system32\mcupdate_GenuineIntel.dll
2009-09-13 01:14:50 ----A---- C:\Windows\system32\mcmde.dll
2009-09-13 01:14:50 ----A---- C:\Windows\system32\mblctr.exe
2009-09-13 01:14:50 ----A---- C:\Windows\system32\kernel32.dll
2009-09-13 01:14:50 ----A---- C:\Windows\system32\kdusb.dll
2009-09-13 01:14:50 ----A---- C:\Windows\system32\kdcom.dll
2009-09-13 01:14:49 ----A---- C:\Windows\system32\logman.exe
2009-09-13 01:14:49 ----A---- C:\Windows\system32\logagent.exe
2009-09-13 01:14:46 ----A---- C:\Windows\system32\Magnify.exe
2009-09-13 01:14:44 ----A---- C:\Windows\system32\WebClnt.dll
2009-09-13 01:14:44 ----A---- C:\Windows\system32\shsetup.dll
2009-09-13 01:14:42 ----A---- C:\Windows\system32\wercon.exe
2009-09-13 01:14:42 ----A---- C:\Windows\system32\wer.dll
2009-09-13 01:14:42 ----A---- C:\Windows\system32\wdscore.dll
2009-09-13 01:14:41 ----A---- C:\Windows\system32\wdc.dll
2009-09-13 01:14:39 ----A---- C:\Windows\system32\WindowsCodecsExt.dll
2009-09-13 01:14:39 ----A---- C:\Windows\system32\WindowsCodecs.dll
2009-09-13 01:14:36 ----A---- C:\Windows\system32\winhttp.dll
2009-09-13 01:14:36 ----A---- C:\Windows\system32\WindowsAnytimeUpgradeCPL.dll
2009-09-13 01:14:34 ----A---- C:\Windows\system32\wevtutil.exe
2009-09-13 01:14:33 ----A---- C:\Windows\system32\whealogr.dll
2009-09-13 01:14:33 ----A---- C:\Windows\system32\wevtsvc.dll
2009-09-13 01:14:33 ----A---- C:\Windows\system32\wevtapi.dll
2009-09-13 01:14:33 ----A---- C:\Windows\system32\WerFaultSecure.exe
2009-09-13 01:14:33 ----A---- C:\Windows\system32\WerFault.exe
2009-09-13 01:14:32 ----A---- C:\Windows\system32\wersvc.dll
2009-09-13 01:14:30 ----A---- C:\Windows\system32\win32spl.dll
2009-09-13 01:14:29 ----A---- C:\Windows\system32\wiaaut.dll
2009-09-13 01:14:28 ----A---- C:\Windows\system32\wiaservc.dll
2009-09-13 01:14:28 ----A---- C:\Windows\system32\version.dll
2009-09-13 01:14:28 ----A---- C:\Windows\system32\vdmdbg.dll
2009-09-13 01:14:27 ----A---- C:\Windows\system32\vdsutil.dll
2009-09-13 01:14:27 ----A---- C:\Windows\system32\vdsdyn.dll
2009-09-13 01:14:27 ----A---- C:\Windows\system32\vds.exe
2009-09-13 01:14:26 ----A---- C:\Windows\system32\user32.dll
2009-09-13 01:14:25 ----A---- C:\Windows\system32\uxsms.dll
2009-09-13 01:14:25 ----A---- C:\Windows\system32\Utilman.exe
2009-09-13 01:14:24 ----A---- C:\Windows\system32\userenv.dll
2009-09-13 01:14:24 ----A---- C:\Windows\system32\usercpl.dll
2009-09-13 01:14:23 ----A---- C:\Windows\system32\usp10.dll
2009-09-13 01:14:21 ----A---- C:\Windows\system32\wcncsvc.dll
2009-09-13 01:14:20 ----A---- C:\Windows\system32\WcnNetsh.dll
2009-09-13 01:14:19 ----A---- C:\Windows\system32\wcnwiz2.dll
2009-09-13 01:14:16 ----A---- C:\Windows\system32\wcnwiz.dll
2009-09-13 01:14:10 ----A---- C:\Windows\system32\w32time.dll
2009-09-13 01:14:10 ----A---- C:\Windows\system32\VSSVC.exe
2009-09-13 01:14:09 ----A---- C:\Windows\system32\vssapi.dll
2009-09-13 01:14:07 ----A---- C:\Windows\system32\WscEapPr.dll
2009-09-13 01:14:07 ----A---- C:\Windows\system32\wscapi.dll
2009-09-13 01:14:06 ----A---- C:\Windows\system32\wscisvif.dll
2009-09-13 01:14:05 ----A---- C:\Windows\system32\WSDMon.dll
2009-09-13 01:14:05 ----A---- C:\Windows\system32\wsdchngr.dll
2009-09-13 01:14:05 ----A---- C:\Windows\system32\WSDApi.dll
2009-09-13 01:14:04 ----A---- C:\Windows\system32\wscript.exe
2009-09-13 01:14:04 ----A---- C:\Windows\system32\wscntfy.dll
2009-09-13 01:14:03 ----A---- C:\Windows\system32\xmlfilter.dll
2009-09-13 01:14:03 ----A---- C:\Windows\system32\wusa.exe
2009-09-13 01:14:03 ----A---- C:\Windows\system32\wscsvc.dll
2009-09-13 01:14:03 ----A---- C:\Windows\system32\wpcsvc.dll
2009-09-13 01:14:03 ----A---- C:\Windows\system32\wpccpl.dll
2009-09-13 01:14:03 ----A---- C:\Windows\system32\wpcao.dll
2009-09-13 01:14:03 ----A---- C:\Windows\system32\wow32.dll
2009-09-13 01:14:03 ----A---- C:\Windows\system32\WMVXENCD.DLL
2009-09-13 01:14:03 ----A---- C:\Windows\system32\WMVSDECD.DLL
2009-09-13 01:14:03 ----A---- C:\Windows\system32\WMVENCOD.DLL
2009-09-13 01:14:02 ----A---- C:\Windows\system32\wsnmp32.dll
2009-09-13 01:14:02 ----A---- C:\Windows\system32\WsmSvc.dll
2009-09-13 01:14:02 ----A---- C:\Windows\system32\wshext.dll
2009-09-13 01:14:02 ----A---- C:\Windows\system32\wshbth.dll
2009-09-13 01:14:02 ----A---- C:\Windows\system32\wsepno.dll
2009-09-13 01:14:02 ----A---- C:\Windows\system32\wlgpclnt.dll
2009-09-13 01:14:02 ----A---- C:\Windows\system32\Wldap32.dll
2009-09-13 01:14:02 ----A---- C:\Windows\system32\wlanui.dll
2009-09-13 01:14:02 ----A---- C:\Windows\system32\wlanpref.dll
2009-09-13 01:14:02 ----A---- C:\Windows\system32\wlangpui.dll
2009-09-13 01:14:02 ----A---- C:\Windows\system32\wisptis.exe
2009-09-13 01:14:02 ----A---- C:\Windows\system32\WinSCard.dll
2009-09-13 01:14:02 ----A---- C:\Windows\system32\winrnr.dll
2009-09-13 01:14:02 ----A---- C:\Windows\system32\winresume.exe
2009-09-13 01:14:01 ----A---- C:\Windows\system32\wmpmde.dll
2009-09-13 01:14:01 ----A---- C:\Windows\system32\WMPhoto.dll
2009-09-13 01:14:01 ----A---- C:\Windows\system32\wmpeffects.dll
2009-09-13 01:14:01 ----A---- C:\Windows\system32\WMNetMgr.dll
2009-09-13 01:14:01 ----A---- C:\Windows\system32\winsrv.dll
2009-09-13 01:14:01 ----A---- C:\Windows\system32\WinSAT.exe
2009-09-13 01:14:01 ----A---- C:\Windows\system32\winmm.dll
2009-09-13 01:14:01 ----A---- C:\Windows\system32\winlogon.exe
2009-09-13 01:14:01 ----A---- C:\Windows\system32\winload.exe
2009-09-13 01:13:59 ----A---- C:\Windows\system32\wmicmiplugin.dll
2009-09-13 01:13:59 ----A---- C:\Windows\system32\wmdrmsdk.dll
2009-09-13 01:13:59 ----A---- C:\Windows\system32\sud.dll
2009-09-13 01:13:59 ----A---- C:\Windows\system32\Storprop.dll
2009-09-13 01:13:59 ----A---- C:\Windows\system32\stobject.dll
2009-09-13 01:13:59 ----A---- C:\Windows\system32\srvsvc.dll
2009-09-13 01:13:59 ----A---- C:\Windows\system32\srcore.dll
2009-09-13 01:13:59 ----A---- C:\Windows\system32\srchadmin.dll
2009-09-13 01:13:58 ----A---- C:\Windows\system32\sysmain.dll
2009-09-13 01:13:58 ----A---- C:\Windows\system32\sysclass.dll
2009-09-13 01:13:58 ----A---- C:\Windows\system32\SyncCenter.dll
2009-09-13 01:13:58 ----A---- C:\Windows\system32\swprv.dll
2009-09-13 01:13:58 ----A---- C:\Windows\system32\smss.exe
2009-09-13 01:13:58 ----A---- C:\Windows\system32\SmiEngine.dll
2009-09-13 01:13:58 ----A---- C:\Windows\system32\SMBHelperClass.dll
2009-09-13 01:13:58 ----A---- C:\Windows\system32\SmartcardCredentialProvider.dll
2009-09-13 01:13:58 ----A---- C:\Windows\system32\slwmi.dll
2009-09-13 01:13:58 ----A---- C:\Windows\system32\slcc.dll
2009-09-13 01:13:58 ----A---- C:\Windows\system32\SLC.dll
2009-09-13 01:13:58 ----A---- C:\Windows\system32\shwebsvc.dll
2009-09-13 01:13:58 ----A---- C:\Windows\system32\shsvcs.dll
2009-09-13 01:13:57 ----A---- C:\Windows\system32\TsWpfWrp.exe
2009-09-13 01:13:57 ----A---- C:\Windows\system32\TSTheme.exe
2009-09-13 01:13:57 ----A---- C:\Windows\system32\sqlsrv32.dll
2009-09-13 01:13:57 ----A---- C:\Windows\system32\spwizui.dll
2009-09-13 01:13:57 ----A---- C:\Windows\system32\spwinsat.dll
2009-09-13 01:13:57 ----A---- C:\Windows\system32\spreview.exe
2009-09-13 01:13:57 ----A---- C:\Windows\system32\spp.dll
2009-09-13 01:13:57 ----A---- C:\Windows\system32\spoolsv.exe
2009-09-13 01:13:57 ----A---- C:\Windows\system32\spoolss.dll
2009-09-13 01:13:57 ----A---- C:\Windows\system32\spinstall.exe
2009-09-13 01:13:57 ----A---- C:\Windows\system32\sperror.dll
2009-09-13 01:13:57 ----A---- C:\Windows\system32\spcmsg.dll
2009-09-13 01:13:57 ----A---- C:\Windows\system32\softkbd.dll
2009-09-13 01:13:57 ----A---- C:\Windows\system32\SnippingTool.exe
2009-09-13 01:13:57 ----A---- C:\Windows\system32\SndVol.exe
2009-09-13 01:13:57 ----A---- C:\Windows\system32\slwga.dll
2009-09-13 01:13:57 ----A---- C:\Windows\system32\SLUINotify.dll
2009-09-13 01:13:57 ----A---- C:\Windows\system32\SLUI.exe
2009-09-13 01:13:57 ----A---- C:\Windows\system32\SLsvc.exe
2009-09-13 01:13:57 ----A---- C:\Windows\system32\slmgr.vbs
2009-09-13 01:13:57 ----A---- C:\Windows\system32\SLLUA.exe
2009-09-13 01:13:57 ----A---- C:\Windows\system32\SLCommDlg.dll
2009-09-13 01:13:57 ----A---- C:\Windows\system32\slcinst.dll
2009-09-13 01:13:57 ----A---- C:\Windows\system32\SLCExt.dll
2009-09-13 01:13:56 ----A---- C:\Windows\system32\zipfldr.dll
2009-09-13 01:13:56 ----A---- C:\Windows\system32\untfs.dll
2009-09-13 01:13:56 ----A---- C:\Windows\system32\uDWM.dll
2009-09-13 01:13:56 ----A---- C:\Windows\system32\tscupgrd.exe
2009-09-13 01:13:55 ----A---- C:\Windows\system32\umpnpmgr.dll
2009-09-13 01:13:55 ----A---- C:\Windows\system32\ulib.dll
2009-09-13 01:13:55 ----A---- C:\Windows\system32\systemcpl.dll
2009-09-13 01:13:48 ----A---- C:\Windows\system32\tsbyuv.dll
2009-09-13 01:13:48 ----A---- C:\Windows\system32\tquery.dll
2009-09-13 01:13:48 ----A---- C:\Windows\system32\themeui.dll
2009-09-13 01:13:48 ----A---- C:\Windows\system32\themecpl.dll
2009-09-13 01:13:48 ----A---- C:\Windows\system32\thawbrkr.dll
2009-09-13 01:13:48 ----A---- C:\Windows\system32\termsrv.dll
2009-09-13 01:13:48 ----A---- C:\Windows\system32\tcpmon.dll
2009-09-13 01:13:48 ----A---- C:\Windows\system32\tcpipcfg.dll
2009-09-13 01:13:48 ----A---- C:\Windows\system32\taskeng.exe
2009-09-13 01:13:48 ----A---- C:\Windows\system32\taskcomp.dll
2009-09-13 01:13:48 ----A---- C:\Windows\system32\tapisrv.dll
2009-09-13 01:10:26 ----D---- C:\Windows\system32\EventProviders
2009-09-08 21:47:11 ----D---- C:\ProgramData\Office Genuine Advantage
2009-09-08 19:20:44 ----A---- C:\Windows\system32\jscript.dll
2009-09-08 19:20:43 ----A---- C:\Windows\system32\wlansvc.dll
2009-09-08 19:20:43 ----A---- C:\Windows\system32\wlanmsm.dll
2009-09-08 19:20:43 ----A---- C:\Windows\system32\wlanhlp.dll
2009-09-08 19:20:43 ----A---- C:\Windows\system32\L2SecHC.dll
2009-09-08 19:20:42 ----A---- C:\Windows\system32\wlansec.dll
2009-09-08 19:20:42 ----A---- C:\Windows\system32\wlanapi.dll
2009-09-08 19:20:30 ----A---- C:\Windows\system32\netiohlp.dll
2009-09-08 19:20:27 ----A---- C:\Windows\system32\TCPSVCS.EXE
2009-09-08 19:20:27 ----A---- C:\Windows\system32\NETSTAT.EXE
2009-09-08 19:20:27 ----A---- C:\Windows\system32\MRINFO.EXE
2009-09-08 19:20:27 ----A---- C:\Windows\system32\HOSTNAME.EXE
2009-09-08 19:20:27 ----A---- C:\Windows\system32\finger.exe
2009-09-08 19:20:27 ----A---- C:\Windows\system32\ARP.EXE
2009-09-08 19:20:26 ----A---- C:\Windows\system32\ROUTE.EXE
2009-09-08 19:20:25 ----A---- C:\Windows\system32\netevent.dll
2009-09-08 19:19:43 ----A---- C:\Windows\system32\WMVCORE.DLL
2009-09-08 19:19:41 ----A---- C:\Windows\system32\mf.dll
2009-09-08 19:19:39 ----A---- C:\Windows\system32\rrinstaller.exe
2009-09-08 19:19:39 ----A---- C:\Windows\system32\mfps.dll
2009-09-08 19:19:39 ----A---- C:\Windows\system32\mfpmp.exe
2009-09-08 19:19:38 ----A---- C:\Windows\system32\mferror.dll
2009-09-08 01:54:15 ----D---- C:\ProgramData\Avira
2009-09-08 01:54:15 ----D---- C:\Program Files\Avira
2009-09-08 00:27:16 ----A---- C:\Windows\junction.exe
2009-09-07 23:58:23 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2009-09-07 21:13:37 ----SHD---- C:\$RECYCLE.BIN
2009-09-07 20:59:18 ----D---- C:\Windows\ERDNT
2009-09-06 15:31:54 ----A---- C:\Windows\system32\cngaudit.dll
2009-09-05 13:03:17 ----D---- C:\Windows\Minidump
2009-09-03 19:59:10 ----D---- C:\Windows\pss
2009-09-02 17:46:04 ----A---- C:\Windows\system32\gameux.dll
2009-09-02 17:46:03 ----A---- C:\Windows\system32\GameUXLegacyGDFs.dll
2009-09-02 17:46:03 ----A---- C:\Windows\system32\Apphlpdm.dll
2009-09-02 15:32:05 ----D---- C:\Program Files\Combined Community Codec Pack
2009-08-29 19:55:11 ----D---- C:\Program Files\Xvid
2009-08-29 19:55:11 ----A---- C:\Windows\system32\xvidvfw.dll
2009-08-29 19:55:11 ----A---- C:\Windows\system32\xvidcore.dll
2009-08-28 03:00:49 ----A---- C:\Windows\system32\tzres.dll

======List of files/folders modified in the last 1 months======

2009-09-21 17:37:38 ----D---- C:\Windows\Prefetch
2009-09-21 17:37:33 ----D---- C:\Windows\Temp
2009-09-21 17:37:26 ----RD---- C:\Program Files
2009-09-21 17:35:46 ----SHD---- C:\System Volume Information
2009-09-21 17:34:16 ----D---- C:\Program Files\Mozilla Firefox
2009-09-21 17:32:42 ----A---- C:\Windows\system32\rpcnetp.exe
2009-09-20 16:39:45 ----D---- C:\Windows\System32
2009-09-20 16:39:45 ----D---- C:\Windows\inf
2009-09-20 16:39:45 ----A---- C:\Windows\system32\PerfStringBackup.INI
2009-09-20 16:34:08 ----A---- C:\Windows\system32\rpcnet.dll
2009-09-20 04:42:06 ----AD---- C:\ProgramData\TEMP
2009-09-20 04:41:54 ----D---- C:\Program Files\SpywareBlaster
2009-09-14 22:20:25 ----SHD---- C:\Windows\Installer
2009-09-14 22:19:47 ----D---- C:\Program Files\Java
2009-09-13 01:46:02 ----D---- C:\Windows\Microsoft.NET
2009-09-13 01:46:01 ----RSD---- C:\Windows\assembly
2009-09-13 01:41:59 ----D---- C:\Windows
2009-09-13 01:41:56 ----SHD---- C:\Boot
2009-09-13 01:39:47 ----D---- C:\Windows\system32\catroot
2009-09-13 01:38:38 ----D---- C:\Windows\system32\catroot2
2009-09-13 01:34:13 ----D---- C:\Program Files\Windows Sidebar
2009-09-13 01:34:13 ----D---- C:\Program Files\Windows Photo Gallery
2009-09-13 01:34:13 ----D---- C:\Program Files\Windows Media Player
2009-09-13 01:34:13 ----D---- C:\Program Files\Windows Mail
2009-09-13 01:34:13 ----D---- C:\Program Files\Windows Journal
2009-09-13 01:34:13 ----D---- C:\Program Files\Windows Collaboration
2009-09-13 01:34:13 ----D---- C:\Program Files\Windows Calendar
2009-09-13 01:34:13 ----D---- C:\Program Files\Movie Maker
2009-09-13 01:34:13 ----D---- C:\Program Files\Internet Explorer
2009-09-13 01:34:13 ----D---- C:\Program Files\Common Files\System
2009-09-13 01:34:11 ----D---- C:\Windows\servicing
2009-09-13 01:34:11 ----D---- C:\Windows\ehome
2009-09-13 01:34:11 ----D---- C:\Program Files\Windows Defender
2009-09-13 01:34:06 ----D---- C:\Windows\system32\XPSViewer
2009-09-13 01:34:06 ----D---- C:\Windows\IME
2009-09-13 01:34:05 ----D---- C:\Windows\system32\sk-SK
2009-09-13 01:34:05 ----D---- C:\Windows\system32\lv-LV
2009-09-13 01:34:05 ----D---- C:\Windows\system32\ko-KR
2009-09-13 01:34:05 ----D---- C:\Windows\system32\hr-HR
2009-09-13 01:34:05 ----D---- C:\Windows\system32\et-EE
2009-09-13 01:34:05 ----D---- C:\Windows\system32\da-DK
2009-09-13 01:34:04 ----D---- C:\Windows\system32\en-US
2009-09-13 01:34:03 ----D---- C:\Windows\system32\oobe
2009-09-13 01:34:03 ----D---- C:\Windows\system32\migration
2009-09-13 01:34:03 ----D---- C:\Windows\system32\it-IT
2009-09-13 01:34:03 ----D---- C:\Windows\system32\el-GR
2009-09-13 01:34:03 ----D---- C:\Windows\system32\de-DE
2009-09-13 01:34:02 ----D---- C:\Windows\system32\sv-SE
2009-09-13 01:34:02 ----D---- C:\Windows\system32\ru-RU
2009-09-13 01:34:02 ----D---- C:\Windows\system32\he-IL
2009-09-13 01:34:02 ----D---- C:\Windows\system32\fr-FR
2009-09-13 01:34:02 ----D---- C:\Windows\system32\AdvancedInstallers
2009-09-13 01:34:01 ----D---- C:\Windows\system32\zh-TW
2009-09-13 01:34:01 ----D---- C:\Windows\system32\zh-CN
2009-09-13 01:34:01 ----D---- C:\Windows\system32\uk-UA
2009-09-13 01:34:01 ----D---- C:\Windows\system32\sr-Latn-CS
2009-09-13 01:34:01 ----D---- C:\Windows\system32\SLUI
2009-09-13 01:34:01 ----D---- C:\Windows\system32\sl-SI
2009-09-13 01:34:01 ----D---- C:\Windows\system32\setup
2009-09-13 01:34:01 ----D---- C:\Windows\system32\pt-PT
2009-09-13 01:34:01 ----D---- C:\Windows\system32\pl-PL
2009-09-13 01:34:01 ----D---- C:\Windows\system32\manifeststore
2009-09-13 01:34:01 ----D---- C:\Windows\system32\ja-JP
2009-09-13 01:34:01 ----D---- C:\Windows\system32\hu-HU
2009-09-13 01:34:01 ----D---- C:\Windows\system32\fi-FI
2009-09-13 01:34:01 ----D---- C:\Windows\system32\es-ES
2009-09-13 01:34:01 ----D---- C:\Windows\system32\en
2009-09-13 01:34:01 ----D---- C:\Windows\system32\cs-CZ
2009-09-13 01:34:01 ----D---- C:\Windows\system32\bg-BG
2009-09-13 01:34:00 ----D---- C:\Windows\system32\tr-TR
2009-09-13 01:34:00 ----D---- C:\Windows\system32\th-TH
2009-09-13 01:34:00 ----D---- C:\Windows\system32\ro-RO
2009-09-13 01:34:00 ----D---- C:\Windows\system32\drivers
2009-09-13 01:33:59 ----D---- C:\Windows\system32\wbem
2009-09-13 01:33:59 ----D---- C:\Windows\system32\pt-BR
2009-09-13 01:33:59 ----D---- C:\Windows\system32\nl-NL
2009-09-13 01:33:59 ----D---- C:\Windows\system32\nb-NO
2009-09-13 01:33:59 ----D---- C:\Windows\system32\migwiz
2009-09-13 01:33:59 ----D---- C:\Windows\system32\lt-LT
2009-09-13 01:33:59 ----D---- C:\Windows\system32\ar-SA
2009-09-13 01:33:44 ----RSD---- C:\Windows\Fonts
2009-09-13 01:33:44 ----D---- C:\Windows\AppPatch
2009-09-13 01:33:35 ----D---- C:\Windows\system32\Boot
2009-09-13 01:29:20 ----D---- C:\Windows\winsxs
2009-09-13 00:13:15 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-09-08 22:02:54 ----D---- C:\Windows\rescache
2009-09-08 21:47:11 ----HD---- C:\ProgramData
2009-09-08 21:45:59 ----D---- C:\Program Files\Microsoft Silverlight
2009-09-08 19:45:42 ----D---- C:\Program Files\Adobe
2009-09-08 19:24:26 ----D---- C:\Windows\system32\zh-HK
2009-09-08 19:23:08 ----D---- C:\ProgramData\Microsoft Help
2009-09-08 01:52:51 ----D---- C:\Program Files\Common Files\microsoft shared
2009-09-08 00:37:41 ----D---- C:\Program Files\SUPERAntiSpyware
2009-09-08 00:19:53 ----D---- C:\Windows\system32\GroupPolicyUsers
2009-09-08 00:19:53 ----D---- C:\Windows\system32\GroupPolicy
2009-09-08 00:19:53 ----D---- C:\Windows\system32\ENU
2009-09-08 00:19:49 ----D---- C:\Windows\SchCache
2009-09-08 00:19:48 ----D---- C:\Windows\LiveKernelReports
2009-09-08 00:19:47 ----SHD---- C:\Windows\ftpcache
2009-09-07 23:58:23 ----D---- C:\Program Files\Common Files
2009-09-07 21:18:02 ----D---- C:\Windows\Tasks
2009-09-07 21:14:59 ----D---- C:\Windows\system32\WDI
2009-09-07 21:13:24 ----A---- C:\Windows\system.ini
2009-09-07 21:11:34 ----D---- C:\Windows\system32\config
2009-09-07 21:01:58 ----A---- C:\Windows\system32\rpcnetp.dll
2009-09-07 21:00:31 ----A---- C:\Windows\ntbtlog.txt
2009-09-07 20:49:18 ----D---- C:\Windows\system32\Tasks
2009-09-03 19:30:41 ----D---- C:\Windows\tracing
2009-09-03 19:30:40 ----D---- C:\Windows\system32\inetsrv
2009-09-03 19:30:20 ----D---- C:\Windows\system32\0409
2009-09-03 19:29:57 ----D---- C:\Windows\Globalization
2009-09-03 03:06:04 ----D---- C:\Users\Jake\AppData\Roaming\uTorrent
2009-08-28 17:38:20 ----A---- C:\Windows\system32\mrt.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys [2009-02-13 11608]
R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2009-03-30 96104]
R1 DLACDBHM;DLACDBHM; C:\Windows\System32\Drivers\DLACDBHM.SYS [2007-02-08 12856]
R1 DLARTL_M;DLARTL_M; C:\Windows\System32\Drivers\DLARTL_M.SYS [2007-02-08 28120]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [2009-09-04 9968]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys [2009-09-04 74480]
R1 ssmdrv;ssmdrv; C:\Windows\system32\DRIVERS\ssmdrv.sys [2009-05-11 28520]
R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2009-07-28 55656]
R2 DLABMFSM;DLABMFSM; C:\Windows\System32\DLA\DLABMFSM.SYS [2006-10-26 35096]
R2 DLABOIOM;DLABOIOM; C:\Windows\System32\DLA\DLABOIOM.SYS [2006-10-26 32472]
R2 DLADResM;DLADResM; C:\Windows\System32\DLA\DLADResM.SYS [2006-10-26 9400]
R2 DLAIFS_M;DLAIFS_M; C:\Windows\System32\DLA\DLAIFS_M.SYS [2006-10-26 104536]
R2 DLAOPIOM;DLAOPIOM; C:\Windows\System32\DLA\DLAOPIOM.SYS [2006-10-26 26296]
R2 DLAPoolM;DLAPoolM; C:\Windows\System32\DLA\DLAPoolM.SYS [2006-10-26 14520]
R2 DLAUDF_M;DLAUDF_M; C:\Windows\System32\DLA\DLAUDF_M.SYS [2006-10-26 97848]
R2 DLAUDFAM;DLAUDFAM; C:\Windows\System32\DLA\DLAUDFAM.SYS [2006-10-26 94648]
R2 DRVNDDM;DRVNDDM; C:\Windows\System32\Drivers\DRVNDDM.SYS [2007-02-09 51768]
R2 mdmxsdk;mdmxsdk; C:\Windows\system32\DRIVERS\mdmxsdk.sys [2006-06-19 12672]
R2 rimmptsk;rimmptsk; C:\Windows\system32\DRIVERS\rimmptsk.sys [2006-11-15 32256]
R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimsptsk.sys [2006-11-14 43520]
R2 rismxdp;Ricoh xD-Picture Card Driver; C:\Windows\system32\DRIVERS\rixdptsk.sys [2006-11-14 37376]
R2 XAudio;XAudio; C:\Windows\system32\DRIVERS\xaudio.sys [2006-08-04 8192]
R3 ApfiltrService;Alps Touch Pad Filter Driver for Windows 2000/XP/Vista; C:\Windows\system32\DRIVERS\Apfiltr.sys [2007-04-12 157184]
R3 bcm4sbxp;Broadcom 440x 10/100 Integrated Controller XP Driver; C:\Windows\system32\DRIVERS\bcm4sbxp.sys [2006-11-21 45568]
R3 BthEnum;Bluetooth Enumerator Service; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-04-10 22528]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-19 92160]
R3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2009-04-10 29696]
R3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2006-11-06 78128]
R3 btwavdt;Bluetooth AVDT; C:\Windows\system32\drivers\btwavdt.sys [2006-11-06 80176]
R3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2006-11-06 16560]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-01-19 14208]
R3 HSF_DPV;HSF_DPV; C:\Windows\system32\DRIVERS\HSX_DPV.sys [2006-11-02 986624]
R3 HSXHWAZL;HSXHWAZL; C:\Windows\system32\DRIVERS\HSXHWAZL.sys [2006-11-02 206848]
R3 NETw4v32;Intel® Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw4v32.sys [2007-09-26 2251776]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2008-06-09 7522624]
R3 OEM02Dev;Creative Camera OEM002 Driver; C:\Windows\system32\DRIVERS\OEM02Dev.sys [2007-10-10 235648]
R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver; C:\Windows\system32\DRIVERS\OEM02Vfx.sys [2007-03-05 7424]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-04-10 148992]
R3 SASENUM;SASENUM; \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS [2009-09-04 7408]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2009-04-10 89088]
R3 STHDA;SigmaTel High Definition Audio CODEC; C:\Windows\system32\drivers\stwrt.sys [2007-03-06 323584]
R3 winachsf;winachsf; C:\Windows\system32\DRIVERS\HSX_CNXT.sys [2006-11-02 659968]
R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2008-01-19 11264]
S3 BTCFilterService;USB Networking Driver Filter Service; C:\Windows\system32\DRIVERS\motfilt.sys [2009-01-29 6016]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2009-04-10 507904]
S3 catchme;catchme; \??\C:\Combo-Fix\catchme.sys []
S3 DFUBTUSB;WIDCOMM USB Bluetooth Driver in DFU State; C:\Windows\System32\Drivers\frmupgr.sys []
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-19 5632]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 HSFHWAZL;HSFHWAZL; C:\Windows\system32\DRIVERS\VSTAZL3.SYS [2006-11-02 200704]
S3 motccgp;Motorola USB Composite Device Driver; C:\Windows\system32\DRIVERS\motccgp.sys [2009-01-29 18688]
S3 motccgpfl;MotCcgpFlService; C:\Windows\system32\DRIVERS\motccgpfl.sys [2009-01-29 8320]
S3 MotDev;Motorola Inc. USB Device; C:\Windows\system32\DRIVERS\motodrv.sys []
S3 motmodem;Motorola USB CDC ACM Driver; C:\Windows\system32\DRIVERS\motmodem.sys [2009-01-29 23680]
S3 MotoSwitchService;MotoSwitch Service; C:\Windows\system32\DRIVERS\motswch.sys [2007-11-02 6400]
S3 Motousbnet;Motorola USB Networking Driver Service; C:\Windows\system32\DRIVERS\Motousbnet.sys [2009-01-29 23296]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-19 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-19 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 6016]
S3 rootrepeal2;rootrepeal2; \??\C:\Windows\system32\drivers\rootrepeal2.sys [2009-09-04 34816]
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-19 35328]
S3 usbvideo;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2006-11-02 132352]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2008-01-19 39936]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-19 83328]
S3 xx;xx; \??\C:\Windows\system32\drivers\xx.sys [2009-09-03 34816]
S3 yy;yy; \??\C:\Windows\system32\drivers\yy.sys [2009-09-03 34816]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2009-05-13 108289]
R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2009-07-21 185089]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-19 21504]
R2 Creative Labs Licensing Service;Creative Labs Licensing Service; C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe [2008-12-29 72704]
R2 Creative Service for CDROM Access;Creative Service for CDROM Access; C:\Windows\system32\CTsvcCDA.exe [1999-12-13 44032]
R2 EvtEng;Intel® PROSet/Wireless Event Log; C:\Program Files\Intel\Wireless\Bin\EvtEng.exe [2007-02-21 643072]
R2 FreeAgentGoNext Service;Seagate Service; C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe [2008-10-28 156968]
R2 IAANTMON;Intel® Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe [2007-02-12 355096]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2008-06-09 196608]
R2 RegSrvc;Intel® PROSet/Wireless Registry Service; C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe [2007-02-21 327680]
R2 RoxWatch9;Roxio Hard Drive Watcher 9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe [2006-11-05 159744]
R2 rpcnet;Remote Procedure Call (RPC) Net; C:\Windows\System32\rpcnet.exe [2009-05-29 56680]
R2 STacSV;SigmaTel Audio Service; C:\Windows\system32\STacSV.exe [2007-03-06 90112]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-03-30 1533808]
R2 XAudioService;XAudioService; C:\Windows\system32\DRIVERS\xaudio.exe [2006-08-04 386560]
R3 RoxMediaDB9;RoxMediaDB9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe [2006-11-05 880640]
S3 getPlus® Helper;getPlus® Helper; C:\Program Files\NOS\bin\getPlus_HelperSvc.exe [2008-12-01 33752]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Roxio\Roxio MyDVD DE\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 stllssvr;stllssvr; C:\Program Files\Common Files\SureThing Shared\stllssvr.exe [2006-09-14 73728]

-----------------EOF-----------------

#4 suebaby41

suebaby41

    W.A.M. (Women Against Malware)


  • Malware Response Team
  • 6,248 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:South Carolina, USA
  • Local time:06:00 AM

Posted 22 September 2009 - 02:20 PM

Although you believe your computer may be clean, I feel I must give you this warning.

IMPORTANT NOTE: Rootkits and backdoor Trojans are very dangerous because they use advanced techniques (backdoors) as a means of accessing a computer system that bypasses security mechanisms and steal sensitive information which they send back to the hacker. Many rootkits can hook into the Windows 32-bit kernel, and patch several APIs to hide new registry keys and files they install. Remote attackers use backdoor Trojans and rootkits as part of an exploit to gain unauthorized access to a computer and take control of it without your knowledge.
If your computer was used for online banking, has credit card information or other sensitive data on it, you should immediately disconnect from the Internet until your system is cleaned. All passwords should be changed immediately to include those used for banking, email, eBay, paypal and online forums. You should consider them to be compromised. You should change each password by using a different computer and not the infected one. If not, an attacker may get the new passwords and transaction information. If using a router, you need to reset it with a strong logon/password so the malware cannot gain control before connecting again. Banking and credit card institutions should be notified of the possible security breach. Because your computer was compromised please read How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

Although the rootkit has been identified and may be removed, your PC has likely been compromised and there is no way to be sure the computer can ever be trusted again. It is dangerous and incorrect to assume that because this malware has been removed the computer is secure. In some instances, an infection may have caused so much damage to your system that it cannot be completely cleaned or repaired. The malware may leave so many remnants behind that security tools cannot find them. Many experts in the security community believe that once infected with this type of malware, the best course of action is to wipe the drive clean, reformat and reinstall the OS. Please read:
When should I re-format? How should I reinstall?
Help: I Got Hacked. Now What Do I Do?
Where to draw the line? When to recommend a format and reinstall?
Should you decide not to follow that advice, we will do our best to help clean the computer of any infections but we cannot guarantee it to be trustworthy or that the removal will be successful. Tell me what you want to do.
You don't stop laughing when you get old; you get old when you stop laughing.
A Member of U-N-I-T-E (Unified Network of Instructors and Trained Eliminators)
Malware Removal University Masters Graduate

Posted Image
Join The Fight Against Malware
No reply within 5 days will result in your topic being closed. If you need more time, please let me know by posting in this topic so that your topic will not be closed.

#5 jakea333

jakea333
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:05:00 AM

Posted 22 September 2009 - 03:08 PM

Thank you for the warning, I will take your advice on changing the passwords. I would, however, like to avoid reformatting. So, I'll preceed with cleaning anything left over.

#6 suebaby41

suebaby41

    W.A.M. (Women Against Malware)


  • Malware Response Team
  • 6,248 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:South Carolina, USA
  • Local time:06:00 AM

Posted 23 September 2009 - 03:41 PM

NOTE: If for some reason you are unable to complete a step(s), skip that step and continue with the rest of the steps. Please describe your problem with the step in your next reply.

Step 1

You may want to print this page. Make sure to work through the fixes in the order it is mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes.

Step 2

TFC (Temp File Cleaner) will clear out all temp folders for all user accounts (temp, IE temp, java, FF, Opera, Chrome, Safari), including Administrator, All Users, LocalService, NetworkService, and any other accounts in the user folder. It also cleans out the %systemroot%\temp folder and checks for .tmp files in the %systemdrive% root folder, %systemroot%, and the system32 folder (both 32bit and 64bit on 64bit OSs). It shows the amount removed for each location found (in bytes) and the total removed (in MB). Before running, it will stop Explorer and all other running apps. When finished, if a reboot is required the user must reboot to finish clearing any in-use temp files.

TFC only cleans temp folders. TFC will not clean URL history, prefetch, or cookies. Depending on how often someone cleans their temp folders, their system hardware, and how many accounts are present, it can take anywhere from a few seconds to a minute or more. TFC will completely clear all temp files where other temp file cleaners may fail. TFC requires a reboot immediately after running. Be sure to save any unsaved work before running TFC.
  • Please download TFC by OldTimer to your desktop.
  • Open the file and close any other windows.
  • It will close all programs itself when run; make sure to let it run uninterrupted.
  • Click the Start button to begin the process. The program should not take long to finish its job.
  • After it is finished, it should reboot your machine, if not, do this yourself to ensure a complete clean.
Step 3

In normal mode, run an online antivirus check from at least two and preferably three of the following sites
BitDefender
Computer Associates Online Virus Scan
Panda's ActiveScan
Trend Micro Housecall
Windows Live Safety Center Free Online Scan
This scanner from Trend does not require an Active X to run.
  • Detects and removes malware ( viruses, worms, trojans, etc. )
  • Detects and removes grayware and spyware
  • Restores damage caused by malware to your system.
  • Notifies about vulnerabilities in installed programs and connected network services.
  • Multi-platform support for: Windows, Linux, Solaris.
  • Easy-to-use with the Microsoft Internet Explorer and Mozilla Firefox.
When you have completed the scans, if you get a report of files that can’t be cleaned / deleted, make a note of the file location of anything that cannot be deleted so you can delete it yourself. Please post that list in your next reply.

Step 4

Please download Spybot-S&D©® and install Spybot-S&D©® .
  • Be sure to UNCHECK TeaTimer when presented with the option to install. You can enable it after you are clean.
  • Run Spybot-S&D©® , go to the Menu Bar at the top choose Mode and make certain that "Default mode" has a check mark beside it.
  • Click the button "Search for Updates".
  • If any updates are found, install them by placing a check mark next to each one and clicking "Download Updates".
  • If you encounter any error messages while downloading the updates, manually download them from here.
  • Click on "Immunize". When it detects what has or has not been blocked, block all remaining items by clicking the green plus sign next to immunize at the top.
  • Click the button "Check for Problems".
  • When Spybot-S&D©® is complete, it will be showing RED entries, bold BLACK entries and GREEN entries in the window.
  • Make certain there is a check mark beside all of the RED entries ONLY.
  • Choose "Fix Selected Problems" and allow Spybot-S&D©® to fix the RED entries.
  • REBOOT to complete the scan and clear memory.
Note: After Windows loads, Spybot-S&D©® may run again to clean some files that it could not clean during the prior session. Follow the same procedure.

Step 5
  • Please download Ad-Aware Free - Anniversary Edition to your desktop. The Ad-Aware Free - Anniversary Edition installation file will be Ad-AwareAE.exe.
  • Double-click the file and follow the on-screen instructions in the Installation Wizard to install.
  • When the Please Enter Your License Information screen appears, click Cancel and Ad-Aware Free - Anniversary Edition will be installed.
  • When the Ad-Aware Free - Anniversary Edition Has Been Successfully Installed Screen appears, click Finish to complete the installation and to launch Ad-Aware Free - Anniversary Edition.
  • The Status screen will appear. You will see four sections.
    • System Protection Status section where you will see Real Time Protection with a check in the Off dialog box and Automatic Updates with a check in the On dialog box.
    • Update Status section
    • System Scan section
    • License Status section where you will see that the Type: will be Free Edition and License Expires in: Never.
  • In the list on the left of the screen, click Scan. You will be given a choice of Smart Scan, Full Scan, and Custom Scan. (Scheduler on the right of the screen is only available in Ad-Aware 2008 Plus and Ad-Aware Pro.)
  • In the list on the left of the screen, click Settings > Scanning tab. Use the default settings unless you see some changes that you want to make.
  • In the list on the left of the screen, click Status. In the System Scan section, click Scan Now.
  • When the scan finishes, the Critical Objects tab window appears.
  • Under Scan Results, you will see the list of Critical Objects that Ad-Aware Free - Anniversary Edition found. You are given three choices, Add to ignore, Quarantine, Remove, and System Restore. You may choose to create a System Restore Point prior to removing any objects that you are unsure of removing or after a scan when you know the system is clean. If Critical Objects are found, select all objects found (right click anywhere in the list of found objects and click "Select All Objects").
  • Click Remove.
  • If no Critical Objects are found, click the Privacy Objects tab.
  • If there are Privacy Objects listed, select all objects found (right click anywhere in the list of found objects and click "Select All Objects"). Select Add to ignore or Remove..
  • Click Remove.
  • If no Privacy Objects are found, click the Log File tab to see the statistics of the Ad-Aware Free - Anniversary Edition scan.
  • Click Finish.
  • The next screen shows you the Scan Summary in the left panel and System Restore in the right panel.
    • You may choose to create a System Restore Point prior to removing any objects that you are unsure of removing or after a scan when you know the system is clean. If you choose to create a System Restore Point, click Set.
    • You may want to export the results Click Export and save the log on your computer .
    • Click Scan Again to repeat the scan.
  • You will be returned to the Status screen. Click on the X in the upper right corner to exit Ad-Aware Free - Anniversary Edition.
Step 6

I recommend using Spyware Blaster.
  • Please download SpywareBlaster and save it to your desktop.
  • Double click on it to install the program.
  • Follow the prompts and choose the default locations when installing the program.
  • When the program is installed, it will place an icon on your desktop.
  • Double click on the SpywareBlaster icon and you will be presented with a brief tutorial. On the first page of this tutorial, you will see some of the SpywareBlaster features
  • Click on the Next button to proceed to the second page of the tutorial.
  • If you want to purchase the software, then you should select Automatic Updating. If you do not plan on purchasing the software, then you should select the option for Manual Updating. Press the Next button.
  • At the next screen, click Finish.
  • At the next screen, Protection Status, click Enable All Protection.
  • Click Download Latest Protection Updates. This will ensure that SpywareBlaster has the latest definitions so that it can protect your browser more efficiently. You should update SpywareBlaster regularly, as much as every few days, in order to provide the best protection. Each time you update, be sure to click Enable All Protection.
Step 7

We need to disconnect your computer from the Internet. By doing this, it prevents any further Internet activity until the removal of malware is complete. You need to make it impossible for viruses, trojan horses, worms and spyware to call for backup once you start to dismantle them. They will continue to infect your computer with new variants while you are connected to the Internet. We also need to prevent hackers from controlling your system and they will try to prevent you from removing the pests they installed on your computer.

Close ALL browser windows (including this one). Exit all processes and items in your System tray.

According to how your computer connects to the Internet, please disconnect your computer from the Internet. Possible means of disconnecting your computer from the Internet include:
  • Physically remove the cable for your broadband Internet service “Always On” Connection from your computer.
  • Turn your modem off.
  • Disconnect your modem cable from your computer.
  • Turn the device off for Hand-held wireless connections.
  • Some laptops have a switch that will disconnect the laptop from the Internet.
Step 8

During the process of removing malware from your computer, there are times you may need to use specialized fix tools. Certain embedded files that are part of these specialized fix tools may be detected by your antivirus or anti-malware scanner as a RiskTool, Hacking tool, Potentially unwanted tool, a virus or a Trojan when that is not the case.
These tools have been carefully created and tested by security experts so if your antivirus or anti-malware program flags them as malware, then it is a False Positive. Antivirus scanners cannot distinguish between good and malicious use of such programs; therefore, they may alert you or even automatically remove them. In these cases, the removal of these files can have unpredictable results and unintentional results.
To avoid any problems while using a specialized fix tool, it is very important that you temporarily disable your antivirus and/or anti-malware programs before using the specialized fix tool.
When your system has been cleaned, it is important that you enable your security programs to avoid reinfection.
Please disable the following program(s):

SUPERAntiSpyware

We need to disable SUPERAntiSpyware as it may interfere with the fixes that we need to make.
  • Right click on the icon in your System Tray.
  • Click Exit
  • Make sure that the program, SUPERAntiSpyware itself, is also closed/not running.
Windows Defender
  • Click Start > Programs > Windows Defender or launch from the system tray icon.
  • Click on Tools
  • Click on General Settings
  • Scroll down to Real-time protection options
  • Uncheck Turn on Real-time protection (recommended)
  • Click Save
  • Go to Start > Control Panel > Security > Windows Defender, at the bottom of the Window Defender's page, uncheck under Administrator Options, use Windows Defender and then Save.
  • Exit the program.
Note: After all of the fixes are complete, it is very important that you enable Real-time Protection again.

Step 9

Now we will address the HijackThis fixes.
  • If you have not already done so, please download Trend Micro - HijackThis.
  • Double click HJTInstall.exe to begin installation.
  • Accept the installation location, which by default is C:\Program Files\Trend Micro\HijackThis or click the Browse... button if you want to save it in another location.
  • Click Install.
  • A shortcut will be created on your Desktop and HijackThis will run automatically.
  • Click the button labeled Do a system scan only.
  • Click the Scan button in the lower left hand corner of the interface and HijackThis will quickly scan your system.
  • Click in the boxes to the left of the following entries to place check marks (make sure not to miss any):

    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
  • Close all browsers and other windows except for HijackThis, and click Fix Checked to have HijackThis fix the entries you checked.
Step 10

Optional Fixes is the name that we use for fixes for unnecessary programs that load during startup and run in the background. These programs are not required to start automatically as you can start them manually if you need them. You would be removing the program from your startup but you would not be removing the program itself.

Your computer may be sluggish due to the many programs loading during startup and running in the background that are not necessary. Windows has a facility for starting programs at startup time. Some of these programs are required for your computer and the applications installed on it to run correctly. A good example of such a program is a virus-checking application that must always run, constantly checking for and isolating or removing files with viruses. Other such programs are not strictly required, or are optional. In some cases, you can gain significant performance enhancements by disabling the automatic startup of these programs. In many cases, the functionality offered by the programs is still available by starting the programs manually by, for example, starting the program from the Windows Start->Programs menu. Media players and instant messaging programs often fall into this category. In fact, it is common for many modern software applications, when installed, to add programs at startup that add items to the system tray or shortcut (context) menus in Windows Explorer to provide quick access to the features and functions of these applications. While they may be useful, they do increase boot time and consume system resources. It is advised that you disable these programs so that they do not take up necessary resources or slow the boot time.

Other than ScanRegistry, SystemTray, StateMgr, antivirus program entries, and firewall program entries, very few others need to load and run.

Read the articles below to see if it applies to your computer problem with being slow to respond.
Slow Computer/browser? Check Here First; It May Not Be Malware
What to do if your Computer is running slowly
Help! My computer is slow!
50 Tips for a Super Fast PC
4 Ways to Speed Up Your Computer's Performance
It's not always malware: How to fix the top 10 Internet Explorer issues

If you decide that you want to stop the Optional Fixes in your startup, let me know and I will give you a list with instructions. You would be removing the program from your startup but you would not be removing the program itself.

Step 11

Please download and scan with Dr.Web CureIt. Follow the instructions here for performing a scan in "Safe Mode" .
-- Post the log in your next reply.

Perform an anti-rootkit (ARK) scan with one of the following:Before performing an ARK scan it is recommended to do the following to ensure more accurate results and avoid common issues that may cause false detections.
  • Disconnect from the Internet or physically unplug your Internet cable connection.
  • Clean out your temporary files.
  • Close all open programs, scheduling/updating tasks and background processes that might activate during the scan including the screensaver.
  • Temporarily disable your anti-virus and real-time anti-spyware protection.
  • After starting the scan, do not use the computer until the scan has completed.
  • When finished, enable your anti-virus/anti-malware (or reboot) and then you can reconnect to the Internet.
Note: Not all hidden components detected by ARKs are malicious. It is normal for a Firewall, some Anti-virus and Anti-malware software (ProcessGuard, Prevx1, AVG AS), sandboxes, virtual machines and Host based Intrusion Prevention Systems (HIPS) to hook into the OS kernal/SSDT in order to protect your system. You should not be alarmed if you see any hidden entries created by these software programs after performing a scan.

Step 12

Check to see if you have insecure applications with
Secunia Software Inspector. Secunia Software Inspector:
  • Detects insecure versions of common/popular programs installed on your computer.
  • Verifies that all Microsoft patches are applied.
  • Assists you in updating, patching, and protecting your computer.
  • Activates additional security features in Sun Java.
  • Runs through your browser. No installation or download is required.
Step 13

Please run HijackThis in Normal Mode and post a new HijackThis log so I can make sure that all the malware was deleted according to plan.

Please post:
  • the list of file names and locations for any files that cannot be cleaned / deleted that were reported after you completed the online scans.
  • a new HijackThis log
Please advise me of any problems you still have.
You don't stop laughing when you get old; you get old when you stop laughing.
A Member of U-N-I-T-E (Unified Network of Instructors and Trained Eliminators)
Malware Removal University Masters Graduate

Posted Image
Join The Fight Against Malware
No reply within 5 days will result in your topic being closed. If you need more time, please let me know by posting in this topic so that your topic will not be closed.

#7 jakea333

jakea333
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:05:00 AM

Posted 24 September 2009 - 03:57 PM

Hi, thanks for the help.

-TFC ran fine.
-Online scans came up with nothing.
-Spybot and Ad-Aware came up clean minus some cookies.
-Spyware Blaster has been in repertoire for a while now.
-HijackThis fix ran fine.
-Dr.Web CureIt would not run correctly, each time it locked my machine up and auto-restarted. Once after doing this, it auto-performed a chkdsk.
-I ran RootRepeal fine, the log is attached.
-Secunia reported a few out of date programs. I downloaded the updates, but even the new versions show as being out of date.
-An updated HijackThis log is attached.

ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/09/24 01:12
Program Version: Version 1.3.5.0
Windows Version: Windows Vista SP2
==================================================

Drivers
-------------------
Name: dump_iaStor.sys
Image Path: C:\Windows\System32\Drivers\dump_iaStor.sys
Address: 0x88109000 Size: 778240 File Visible: No Signed: -
Status: -

Name: rootrepeal.sys
Image Path: C:\Windows\system32\drivers\rootrepeal.sys
Address: 0xA5167000 Size: 49152 File Visible: No Signed: -
Status: -

Hidden/Locked Files
-------------------
Path: C:\hiberfil.sys
Status: Locked to the Windows API!

Path: C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{64b6ed6f-a885-11de-be2d-00197edbe3c7}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{64b6ed9b-a885-11de-be2d-00197edbe3c7}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{64b6ed9f-a885-11de-be2d-00197edbe3c7}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{7e3371e5-9ce2-11de-bc1e-00197edbe3c7}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{7e3371ef-9ce2-11de-bc1e-00197edbe3c7}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{84e7e066-a02b-11de-8fc1-00197edbe3c7}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{84e7e06b-a02b-11de-8fc1-00197edbe3c7}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{84e7e07c-a02b-11de-8fc1-00197edbe3c7}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{84e7e08c-a02b-11de-8fc1-00197edbe3c7}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{e0662f63-a624-11de-91c7-00197edbe3c7}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{e0662f76-a624-11de-91c7-00197edbe3c7}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{e0662fc4-a624-11de-91c7-00197edbe3c7}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{f1a7ecaf-a01c-11de-bd8f-00197edbe3c7}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\Windows\tracing\tracing
Status: Locked to the Windows API!

Path: C:\Windows\Globalization\Globalization
Status: Locked to the Windows API!

Path: C:\Windows\AppPatch\Custom\Custom
Status: Locked to the Windows API!

Path: C:\Windows\Microsoft.NET\authman\authman
Status: Locked to the Windows API!

Path: C:\Windows\System32\0409\0409
Status: Locked to the Windows API!

Path: C:\Windows\System32\inetsrv\inetsrv
Status: Locked to the Windows API!

Path: C:\Windows\System32\wbem\PRINTF~1.MOF
Status: Locked to the Windows API!

Path: C:\Windows\System32\XPSViewer\XPSVIE~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.762_none_9193a620671dde41.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_818f59bf601aa775.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_dcc7eae99ad0d9cf.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.openmp_1fc8b3b9a1e18e3b_8.0.50727.42_none_7658964504b9f3b6.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.42_none_54c11df268b7c6d9.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.4.20.microsoft.msxml2_6bd6b9abf345378f_4.20.9870.0_none_a6dea5dc0ea08098.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.msxml2_6bd6b9abf345378f_4.20.9818.0_none_b7e811947b297f6d.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_99b61f5e8371c1d4.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_e163563597edeada.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.762_none_10b2f55f9bffb8f8.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.openmp_1fc8b3b9a1e18e3b_9.0.21022.8_none_ecdf8c290e547f39.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.42_none_5c4003bc63e949f6.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.42_none_0e9c2a8d74fd3ce6.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.openmp_1fc8b3b9a1e18e3b_8.0.50727.42_none_45e008191e507087.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\amd64_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_3da38fdebd0e6822.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_7dd1e0ebd6590e0b.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.4148_none_51ca66a2bbe76806.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.msxml2r_6bd6b9abf345378f_4.1.0.0_none_3658456fda6654f6.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.762_none_43efccf17831d131.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.4148_none_f0efb442f8a0f46c.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.762_none_11ecb0ab9b2caf3c.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.42_none_58843c41d2730d3f.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.1_none_e29d1181971ae11e.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.msxml2_6bd6b9abf345378f_4.20.9870.0_none_b7e00e6c7b30b69b.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.762_none_8dd7dea5d5a7a18a.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.4.1.microsoft.msxml2r_6bd6b9abf345378f_4.1.1.0_none_8b7b15c031cda6db.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_0c178a139ee2a7ed.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.msxml2r_6bd6b9abf345378f_4.1.1.0_none_365945b9da656e4d.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.42_none_d6c3e7af9bae13a2.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.762_none_8e053e8c6967ba9d.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.21022.8_none_bcb86ed6ac711f91.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_8550c6b5d18a9128.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.21022.8_none_60a5df56e60dc5df.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.1_none_81c25f21d3d46d84.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.42_none_58b19c2866332652.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.42_none_dc990e4797f81af1.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_8a14c0566bec5b24.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.42_none_db5f52fb98cb24ad.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.openmp_1fc8b3b9a1e18e3b_9.0.21022.8_none_7ab8cc63a6e4c2a3.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_fdproxy_31bf3856ad364e35_6.0.6000.16386_none_792f8ff471a64e3b\$$DeleteMe.fdProxy.dll.01ca3433c474d6e1.0026
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_fdssdp_31bf3856ad364e35_6.0.6001.18000_none_3addf297743e6161\$$DeleteMe.fdSSDP.dll.01ca3433c6b8d371.005a
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_fdwsd_31bf3856ad364e35_6.0.6001.18000_none_7da88373c225d895\$$DeleteMe.fdWSD.dll.01ca3433c9d13701.00ab
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-a..dcredentialprovider_31bf3856ad364e35_6.0.6001.18000_none_420aa4b9c28d5162\$$DeleteMe.SmartcardCredentialProvider.dll.01ca3433c89c3971.0080
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-a..ence-infrastructure_31bf3856ad364e35_6.0.6001.18000_none_d51103be4cb9d6c3\$$DeleteMe.apphelp.dll.01ca3433c9f316e1.00ae
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-a..terface-ldapc-layer_31bf3856ad364e35_6.0.6001.18000_none_5f327439667d597c\$$DeleteMe.adsldpc.dll.01ca3433c60eb0c1.0041
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-atl_31bf3856ad364e35_6.0.6001.18293_none_aac1f52459f8aeb3\$$DeleteMe.atl.dll.01ca3433c8b16f21.0082
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-audio-dsound_31bf3856ad364e35_6.0.6001.18000_none_589bbe5841e2df00\$$DeleteMe.dsound.dll.01ca3433c80c5581.006d
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-authentication-authui_31bf3856ad364e35_6.0.6001.18000_none_0bf37d16f567e1f7\$$DeleteMe.authui.dll.01ca3433c83bf101.0074
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-audio-mmecore-base_31bf3856ad364e35_6.0.6001.18000_none_b5dfbc3a51b01b87\$$DeleteMe.winmm.dll.01ca3433c90ef871.0094
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..ager-pcat.resources_31bf3856ad364e35_6.0.6000.16386_da-dk_772e9c8b38518962\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..ager-pcat.resources_31bf3856ad364e35_6.0.6000.16386_de-de_745a31c73a27ddfc\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..ager-pcat.resources_31bf3856ad364e35_6.0.6000.16386_el-gr_1cf05f5a293d468a\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..ager-pcat.resources_31bf3856ad364e35_6.0.6000.16386_en-us_1d4b07c02905e9c1\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..ager-pcat.resources_31bf3856ad364e35_6.0.6000.16386_es-es_1d1664a4292cdb66\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..ager-pcat.resources_31bf3856ad364e35_6.0.6000.16386_fi-fi_bc3169511e46cd90\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..ager-pcat.resources_31bf3856ad364e35_6.0.6000.16386_fr-fr_bfcddaa31bfef1c8\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..ager-pcat.resources_31bf3856ad364e35_6.0.6000.16386_it-it_a9f5d0e9f330d746\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..ager-pcat.resources_31bf3856ad364e35_6.0.6000.16386_ja-jp_4c1b4ff6e64be921\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..ager-pcat.resources_31bf3856ad364e35_6.0.6000.16386_ko-kr_ef852cabd8bcb037\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..ager-pcat.resources_31bf3856ad364e35_6.0.6000.16386_nb-no_d817ade0b0e1dbf3\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..ager-pcat.resources_31bf3856ad364e35_6.0.6000.16386_nl-nl_d656f91eb20de5c8\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..ager-pcat.resources_31bf3856ad364e35_6.0.6000.16386_pl-pl_1c9353a09730537c\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..ager-pcat.resources_31bf3856ad364e35_6.0.6000.16386_pt-br_1ee73e4495b9e760\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..ager-pcat.resources_31bf3856ad364e35_6.0.6000.16386_ru-ru_666c1f747a0ae568\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..ager-pcat.resources_31bf3856ad364e35_6.0.6000.16386_sv-se_026709e97133efc3\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..ager-pcat.resources_31bf3856ad364e35_6.0.6000.16386_tr-tr_ab7454305feff1b4\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..ager-pcat.resources_31bf3856ad364e35_6.0.6000.16386_zh-cn_7cd1722e1027c3d3\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..ager-pcat.resources_31bf3856ad364e35_6.0.6000.16386_zh-hk_7b7c6abc11033663\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..ager-pcat.resources_31bf3856ad364e35_6.0.6000.16386_zh-tw_80cdaf840d98a043\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..nment-pxe.resources_31bf3856ad364e35_6.0.6000.16386_cs-cz_7388dcab642949ec\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..nment-pxe.resources_31bf3856ad364e35_6.0.6000.16386_da-dk_10c2bcd25a6f45eb\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..nment-pxe.resources_31bf3856ad364e35_6.0.6000.16386_el-gr_b6847fa14b5b0313\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..nment-pxe.resources_31bf3856ad364e35_6.0.6000.16386_en-us_b6df28074b23a64a\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..nment-pxe.resources_31bf3856ad364e35_6.0.6000.16386_es-es_b6aa84eb4b4a97ef\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..nment-pxe.resources_31bf3856ad364e35_6.0.6000.16386_fi-fi_55c5899840648a19\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..nment-pxe.resources_31bf3856ad364e35_6.0.6000.16386_fr-fr_5961faea3e1cae51\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..nment-pxe.resources_31bf3856ad364e35_6.0.6000.16386_hu-hu_a0d27b32227c7d6d\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..nment-pxe.resources_31bf3856ad364e35_6.0.6000.16386_it-it_4389f131154e93cf\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..ager-pcat.resources_31bf3856ad364e35_6.0.6000.16386_hu-hu_073e5aeb005ec0e4\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..ager-pcat.resources_31bf3856ad364e35_6.0.6000.16386_pt-pt_1fc90db09529573c\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..nment-pxe.resources_31bf3856ad364e35_6.0.6000.16386_de-de_0dee520e5c459a85\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..nment-pxe.resources_31bf3856ad364e35_6.0.6000.16386_ja-jp_e5af703e0869a5aa\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..nment-pxe.resources_31bf3856ad364e35_6.0.6000.16386_ko-kr_89194cf2fada6cc0\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..nment-pxe.resources_31bf3856ad364e35_6.0.6000.16386_nb-no_71abce27d2ff987c\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..nment-pxe.resources_31bf3856ad364e35_6.0.6000.16386_nl-nl_6feb1965d42ba251\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..nment-pxe.resources_31bf3856ad364e35_6.0.6000.16386_pl-pl_b62773e7b94e1005\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..nment-pxe.resources_31bf3856ad364e35_6.0.6000.16386_pt-br_b87b5e8bb7d7a3e9\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..nment-pxe.resources_31bf3856ad364e35_6.0.6000.16386_pt-pt_b95d2df7b74713c5\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..nment-pxe.resources_31bf3856ad364e35_6.0.6000.16386_ru-ru_00003fbb9c28a1f1\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..nment-pxe.resources_31bf3856ad364e35_6.0.6000.16386_tr-tr_45087477820dae3d\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..nment-pxe.resources_31bf3856ad364e35_6.0.6000.16386_zh-cn_166592753245805c\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..nment-pxe.resources_31bf3856ad364e35_6.0.6000.16386_zh-hk_15108b033320f2ec\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..nment-pxe.resources_31bf3856ad364e35_6.0.6000.16386_zh-tw_1a61cfcb2fb65ccc\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-bcrypt-dll_31bf3856ad364e35_6.0.6001.18000_none_ee8c936cef65a88f\$$DeleteMe.bcrypt.dll.01ca3433c4207551.0024
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-bits-igdsearcher_31bf3856ad364e35_6.0.6001.18000_none_b16c3d098f004f58\$$DeleteMe.bitsigd.dll.01ca3433c6f36b71.005f
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-c..ent-indexing-common_31bf3856ad364e35_6.0.6001.18000_none_06b40dcad71051f6\$$DeleteMe.Query.dll.01ca3433c7bef8d1.0063
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-c..rformance-xperfcore_31bf3856ad364e35_6.0.6001.18000_none_d71173946e986845\$$DeleteMe.diagperf.dll.01ca3433ca821071.00c4
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-c..tionauthorityclient_31bf3856ad364e35_6.0.6001.18000_none_d77db57c3ca78826\$$DeleteMe.certcli.dll.01ca3433c62c71f1.0047
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-cmi_31bf3856ad364e35_6.0.6001.18000_none_a9ce4a485a8ade99\$$DeleteMe.cmiv2.dll.01ca3433cd483551.00d8
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\logevent.dll
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-com-dtc-client_31bf3856ad364e35_6.0.6001.18085_none_4ca16fc8b98a26e2\$$DeleteMe.xolehlp.dll.01ca3433ca686df1.00c1
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-content-filter-html_31bf3856ad364e35_7.0.6001.16503_none_13ff1de93d266b97\$$DeleteMe.xmlfilter.dll.01ca3433c5347d61.0032
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-coreusermodepnp_31bf3856ad364e35_6.0.6001.18000_none_7701ab362cebf905\$$DeleteMe.umpnpmgr.dll.01ca3433ca1b5f61.00b9
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-credui_31bf3856ad364e35_6.0.6001.18000_none_db374cc18eed7408\$$DeleteMe.credui.dll.01ca3433c2aa01f1.000b
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-crypt32-dll_31bf3856ad364e35_6.0.6001.18000_none_5b6fc1dbddd3c6da\$$DeleteMe.crypt32.dll.01ca3433c8b8e931.0089
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6001.18000_none_75ff99649acf4de9\$$DeleteMe.cryptsvc.dll.01ca3433c6854051.0050
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-cryptui-dll_31bf3856ad364e35_6.0.6001.18000_none_85ee5b5e98235317\$$DeleteMe.cryptui.dll.01ca3433c80f14a1.006f
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-d..files-x64.resources_31bf3856ad364e35_6.0.6000.16386_el-gr_9c85d8321884ca1a\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-d..files-x64.resources_31bf3856ad364e35_6.0.6000.16386_en-us_9ce08098184d6d51\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-d..files-x64.resources_31bf3856ad364e35_6.0.6000.16386_es-es_9cabdd7c18745ef6\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-d..files-x64.resources_31bf3856ad364e35_6.0.6000.16386_fi-fi_3bc6e2290d8e5120\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-d..files-x64.resources_31bf3856ad364e35_6.0.6000.16386_fr-fr_3f63537b0b467558\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-d..files-x64.resources_31bf3856ad364e35_6.0.6000.16386_hu-hu_86d3d3c2efa64474\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-d..files-x64.resources_31bf3856ad364e35_6.0.6000.16386_it-it_298b49c1e2785ad6\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-d..files-x64.resources_31bf3856ad364e35_6.0.6000.16386_de-de_f3efaa9f296f618c\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-d..files-x64.resources_31bf3856ad364e35_6.0.6000.16386_ja-jp_cbb0c8ced5936cb1\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-d..files-x64.resources_31bf3856ad364e35_6.0.6000.16386_sv-se_81fc82c1607b7353\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-d..files-x64.resources_31bf3856ad364e35_6.0.6000.16386_ko-kr_6f1aa583c80433c7\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-d..files-x64.resources_31bf3856ad364e35_6.0.6000.16386_nb-no_57ad26b8a0295f83\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-d..files-x64.resources_31bf3856ad364e35_6.0.6000.16386_nl-nl_55ec71f6a1556958\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-d..files-x64.resources_31bf3856ad364e35_6.0.6000.16386_pl-pl_9c28cc788677d70c\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-d..files-x64.resources_31bf3856ad364e35_6.0.6000.16386_pt-br_9e7cb71c85016af0\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-d..files-x64.resources_31bf3856ad364e35_6.0.6000.16386_pt-pt_9f5e86888470dacc\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-d..files-x64.resources_31bf3856ad364e35_6.0.6000.16386_ru-ru_e601984c695268f8\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-d..files-x64.resources_31bf3856ad364e35_6.0.6000.16386_tr-tr_2b09cd084f377544\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-d..files-x64.resources_31bf3856ad364e35_6.0.6000.16386_zh-cn_fc66eb05ff6f4763\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-d..files-x64.resources_31bf3856ad364e35_6.0.6000.16386_zh-hk_fb11e394004ab9f3\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-d..files-x64.resources_31bf3856ad364e35_6.0.6000.16386_zh-tw_0063285bfce023d3\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-dhcp-client-dll_31bf3856ad364e35_6.0.6001.18000_none_d75a29a02e8fcf7a\$$DeleteMe.dhcpcsvc.dll.01ca3433ca09fa41.00b4
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-dhcp-client-dll_31bf3856ad364e35_6.0.6001.18000_none_d75a29a02e8fcf7a\$$DeleteMe.dhcpcsvc6.dll.01ca3433c30197d1.000e
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-directory-services-sam_31bf3856ad364e35_6.0.6001.18000_none_b1ee595da0f48e64\$$DeleteMe.samlib.dll.01ca3433c7ba64f1.0061
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-directory-services-sam_31bf3856ad364e35_6.0.6001.18000_none_b1ee595da0f48e64\$$DeleteMe.samsrv.dll.01ca3433c3b6b701.001b
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-dns-client-winrnr_31bf3856ad364e35_6.0.6000.16386_none_571790f3532b2696\$$DeleteMe.winrnr.dll.01ca3433cafeba81.00c8
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-e..-protocol-host-peer_31bf3856ad364e35_6.0.6001.18000_none_64138b2cc36a286b\$$DeleteMe.eappcfg.dll.01ca3433c3042fe1.000f
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-e..-protocol-host-peer_31bf3856ad364e35_6.0.6001.18000_none_64138b2cc36a286b\$$DeleteMe.eapphost.dll.01ca3433ca7f9f71.00c3
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-dns-client_31bf3856ad364e35_6.0.6001.18000_none_e1e27cdd8259636b\$$DeleteMe.dnsapi.dll.01ca3433c352c511.0017
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-dns-client_31bf3856ad364e35_6.0.6001.18000_none_e1e27cdd8259636b\$$DeleteMe.dnsrslvr.dll.01ca3433c5b9b2f1.0039
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-e..emorydevicesservice_31bf3856ad364e35_6.0.6001.18098_none_9e329f52f6fc276d\$$DeleteMe.emdmgmt.dll.01ca3433c8bf78e1.008b
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-e..estorageengine-isam_31bf3856ad364e35_6.0.6001.18000_none_f1e446e12c0bbf09\$$DeleteMe.esent.dll.01ca3433c84bcf81.0078
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-enhancedvideorenderer_31bf3856ad364e35_6.0.6001.18000_none_8fa27dabcc867f14\$$DeleteMe.evr.dll.01ca3433c9cf3b31.00aa
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-eventlog-api_31bf3856ad364e35_6.0.6001.18000_none_ac31021c654a3267\$$DeleteMe.wevtapi.dll.01ca3433c309fc41.0010
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-eventlog_31bf3856ad364e35_6.0.6001.18000_none_dcc45c1a12d92f84\$$DeleteMe.wevtsvc.dll.01ca3433c3d78571.001d
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-grouppolicy-base_31bf3856ad364e35_6.0.6001.18000_none_282361dee702a605\$$DeleteMe.gpapi.dll.01ca3433c7c4c531.0066
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-grouppolicy-base_31bf3856ad364e35_6.0.6001.18000_none_282361dee702a605\$$DeleteMe.gpsvc.dll.01ca3433c8dbda81.0091
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-hid-user_31bf3856ad364e35_6.0.6000.16386_none_d47586718a839763\$$DeleteMe.hidserv.dll.01ca3433c9167281.0095
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-i..oexistencemigration_31bf3856ad364e35_6.0.6001.18000_none_11e312d27c5a6ba6\$$DeleteMe.iphlpsvc.dll.01ca3433bd4e6521.0004
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-icm-base_31bf3856ad364e35_6.0.6001.18000_none_22c7ea5489633945\$$DeleteMe.mscms.dll.01ca3433c7c401e1.0065
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-imm32_31bf3856ad364e35_6.0.6001.18000_none_5c561e167a6afd02\$$DeleteMe.imm32.dll.01ca3433c4e46191.002e
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-kernel32_31bf3856ad364e35_6.0.6001.18215_none_93b81a93564f1da0\$$DeleteMe.kernel32.dll.01ca3433c4d82c91.002d
Status: Locked to the Windows API!

Path: CProcesses
-------------------
Path: System
PID: 4 Status: Locked to the Windows API!

Path: C:\Windows\System32\audiodg.exe
PID: 1176 Status: Locked to the Windows API!

SSDT
-------------------
#: 021 Function Name: NtAlpcConnectPort
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x9109f880

#: 054 Function Name: NtConnectPort
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x9109f4e0

#: 060 Function Name: NtCreateFile
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x9109c828

#: 064 Function Name: NtCreateKey
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x910b2d9c

#: 071 Function Name: NtCreatePort
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x9109fc36

#: 072 Function Name: NtCreateProcess
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x910b0af8

#: 073 Function Name: NtCreateProcessEx
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x910b0d12

#: 075 Function Name: NtCreateSection
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x910b4780

#: 078 Function Name: NtCreateThread
Status: Hooked by "<unknown>" at address 0x9edb4bc4

#: 115 Function Name: NtCreateWaitablePort
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x9109fcde

#: 122 Function Name: NtDeleteFile
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x9109cd0a

#: 123 Function Name: NtDeleteKey
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x910b3698

#: 126 Function Name: NtDeleteValueKey
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x910b3414

#: 129 Function Name: NtDuplicateObject
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x910b04f8

#: 166 Function Name: NtLoadKey
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x910b3bc6

#: 167 Function Name: NtLoadKey2
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x910b3c3e

#: 168 Function Name: NtLoadKeyEx
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x910b3d2e

#: 186 Function Name: NtOpenFile
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x9109cba2

#: 194 Function Name: NtOpenProcess
Status: Hooked by "<unknown>" at address 0x9edb4bb0

#: 201 Function Name: NtOpenThread
Status: Hooked by "<unknown>" at address 0x9edb4bb5

#: 267 Function Name: NtRenameKey
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x910b4370

#: 268 Function Name: NtReplaceKey
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x910b3da6

#: 276 Function Name: NtRequestWaitReplyPort
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x9109f16a

#: 280 Function Name: NtRestoreKey
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x910b41b0

#: 286 Function Name: NtSecureConnectPort
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x9109f680

#: 301 Function Name: NtSetInformationFile
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x9109cef8

#: 324 Function Name: NtSetValueKey
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x910b311a

#: 332 Function Name: NtSystemDebugControl
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x910b1486

#: 334 Function Name: NtTerminateProcess
Status: Hooked by "C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys" at address 0x911290b0

#: 383 Function Name: NtCreateUserProcess
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x910b0f30

Stealth Objects
-------------------
Object: Hidden Module [Name: msgsres.dll]
Process: msnmsgr.exe (PID: 3976) Address: 0x6b8a0000 Size: 11403264

Object: Hidden Module [Name: msgslang.14.0.8064.0206.dll]
Process: msnmsgr.exe (PID: 3976) Address: 0x6e000000 Size: 315392

Object: Hidden Module [Name: msgrvsta.thm]
Process: msnmsgr.exe (PID: 3976) Address: 0x6f860000 Size: 20480

==EOF==

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:55:29 PM, on 9/24/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\OEM02Mon.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Windows\sttray.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Dell\DELL Webcam Manager\DellWMgr.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\Jake\Downloads\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [UpdReg] C:\Windows\UpdReg.EXE
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [MaxMenuMgr] "C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
O4 - HKLM\..\Run: [mumservice] C:\Program Files\Motorola\Software Update\mumservice.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DELL Webcam Manager] "C:\Program Files\Dell\DELL Webcam Manager\DellWMgr.exe" /s
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} (Windows Live OneCare safety scanner control) - http://cdn.scan.onecare.live.com/resource/...S/wlscctrl2.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/...can8/oscan8.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\Windows\system32\CTsvcCDA.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Seagate Service (FreeAgentGoNext Service) - Seagate Technology LLC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD DE\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: Remote Procedure Call (RPC) Net (rpcnet) - Absolute Software Corp. - C:\Windows\System32\rpcnet.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Windows\system32\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 9670 bytes


Thanks for the help,
Jake

#8 suebaby41

suebaby41

    W.A.M. (Women Against Malware)


  • Malware Response Team
  • 6,248 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:South Carolina, USA
  • Local time:06:00 AM

Posted 25 September 2009 - 10:14 AM

I would not use this computer for online banking, etc. There are no obvious signs of malware on your computer but I repeat the warning:

It is dangerous and incorrect to assume that because this malware has been removed, the computer is secure. In some instances, an infection may have caused so much damage to your system that it cannot be completely cleaned or repaired. Some infections are difficult to remove completely because of their morphing characteristics which allows the malware to regenerate itself. Sometimes there is another hidden piece of malware which has not been detected by your security tools that protects malicious files and registry keys (which have been detected) so they cannot be permanently deleted. The malware may leave so many remnants behind that security tools cannot find them. Most experts in the security community believe that once infected with this type of malware, the best course of action is to wipe the drive clean, reformat and reinstall the OS.

Tips To Protect Your Computer
  • Avoid clicking on links in instant messages.
  • Avoid opening email attachments.
  • Avoid visiting every poker site on the net.
  • Avoid downloading all that free cute junk.
  • Avoid using the peer-to-peer file sharing.
  • Avoid getting those handy toolbar doodads for your browsers.
  • Malware is out there just waiting to pounce on your system if you only pass by where they are lurking which may be at some seemingly innocent web site. Be careful because some of the malware are so vicious that no one can possibly save you once you let them in.
  • Remember that new malware emerges every week of the year. Take responsibility for protecting your system because you are its first and best defense.
Please take the time to read the "Steps To Keep Your Computer Clean And Secure" below.

STEPS TO KEEP YOUR COMPUTER CLEAN AND SECURE:

Please follow these simple steps in order to keep your computer clean and secure:
  • Disable and Enable System Restore. After cleaning, you will need to disable the System Restore function For Windows XP.
    Files placed in the System volume information folder are source files for the System Restore function that is available in Windows XP operating system. Files that were healed were moved in their original INFECTED state into this folder and it is necessary to DELETE them by following these steps:
    • Close all open programs. Then right-click My Computer on the Windows' desktop
    • Click on Properties.
    • Click on the System Restore tab.
    • Check Turn off System Restore on all drives.
    • Restart the system.
    • Enable System Restore by going through the first four steps again and uncheck the item mentioned in Step d.
    • You can find instructions on how to disable and enable system restore in the Windows XP System Restore Guide.
  • Make your Internet Explorer more secure: This can be done by following these simple instructions:
    • From within Internet Explorer click on the Tools menu and then click on Options.
    • Click once on the Security tab
    • Click once on the Internet icon so it becomes highlighted.
    • Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialize and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub frames across different domains to Prompt
    • When all these settings have been made, click on the OK button.
    • If it asks you if you want to save the settings, press the Yes button.
    • Click Apply > OK button and then the OK to exit the Internet Properties page.
  • Use a Firewall: - I cannot stress how important it is that you use a Firewall on your computer.  Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. For an article on Firewalls and a listing of some available ones see the link below:
    Computer Safety On line - Software Firewalls. For more information about firewalls, and why a two-way firewall is better than the Windows XP one-way firewall, please read Understanding and Using Firewalls.
  • Use An Antivirus Software and Keep It Updated: - It is very important that your computer has an antivirus software running on your machine.  This alone can save you a lot of trouble with malware in the future.  It is imperative that you update your antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software, then it will not be able to catch any of the new variants that may come out. For an article on antivirus programs and a listing of some available ones see the link below:
    Computer Safety On line - Anti-Virus
  • Visit Microsoft's Windows Update Site Frequently: It is important that you visit Microsoft Windows Update regularly. This will ensure your computer has the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
  • You should scan your computer with Spybot S&D on a regular basis just as you would an anti- virus software. A tutorial on installing & using this product can be found here:
    Using Spybot - Search & Destroy to remove Spyware from Your Computer
  • You should scan your computer with Ad-Aware 2007/2008 as well as Spybot S&D and your anti-virus program on a regular basis. A tutorial on installing & using this product can be found here:
    Ad-Aware 2008.
  • Update SpywareBlaster (at least weekly): SpywareBlaster will add a large list of programs and sites into your Internet Explorer and Firec settings that will protect you from running and downloading known malicious programs. An article on anti-malware products with links for this program and others can be found here:
    Computer Safety on line Anti Malware
  • Use the hosts file: Every version of windows has a hosts file as part of them. In a very basic sense, they are used to locate web pages. We can customize a hosts file so that it blocks certain web pages. However, it can slow down certain computers. This is why using a hosts file is optional. Download mvps hosts file Make sure you read the instructions on how to install the hosts file. There is a good tutorial HERE If you decide to download the hosts file, the slowdown problems can usually be avoided by following these steps:
    • Click the start button on the task bar at the bottom of your screen
    • Click run
    • In the dialog box, type services.msc
    • hit enter, then locate dns client
    • Highlight it, then doubleclick it.
    • On the dropdown box, change the setting from automatic to manual.
    • Click OK.
  • Use an alternative instant messenger program:.Trillian and Miranda IM These are Malware free Instant Messenger programs which allow you to connect to multiple IM services in one program! (AOL, Yahoo, ICQ, IRC, MSN)
  • Please read Tony Klein's excellent article: How I got Infected in the First Place
  • Please read Understanding Spyware, Browser Hijackers, and Dialers
  • Please read Simple and easy ways to keep your computer safe and secure on the Internet.
  • If you are using Internet Explorer, please consider using an alternate browser: Mozilla's Firefox browser is fantastic; it is much more secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built in popup blocker (as an added benefit!) that I have ever seen.
    Another good browser is Opera . Opera 9 comes loaded with the tools to keep you productive and safe. Try it today, it's absolutely free. Some of the Opera features are: Customization, BitTorrent, Content blocker, Add your favorite search engines, Thumbnail preview of tabs, Widgets, Transfer manager, Tabbed browsing, Password manager, Sessions (You can save a collection of open tabs as a session, for later retrieval, or start with the pages you had open when Opera was last closed.), Keyboard Shortcuts, Cookie control, a multitude of languages, Validate code, Toggle graphics and style sheets, and Special features such as Full-screen mode, Kiosk mode.
  • Update all these programs regularly: Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
  • If your computer was infected by a website, a program, IM, MSN, or p2p, check this site because it is Time To Fight Back.
Follow these steps and your potential for being infected again will reduce dramatically.
Good luck!
You don't stop laughing when you get old; you get old when you stop laughing.
A Member of U-N-I-T-E (Unified Network of Instructors and Trained Eliminators)
Malware Removal University Masters Graduate

Posted Image
Join The Fight Against Malware
No reply within 5 days will result in your topic being closed. If you need more time, please let me know by posting in this topic so that your topic will not be closed.

#9 jakea333

jakea333
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:05:00 AM

Posted 25 September 2009 - 11:22 PM

Thanks for your help!

#10 suebaby41

suebaby41

    W.A.M. (Women Against Malware)


  • Malware Response Team
  • 6,248 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:South Carolina, USA
  • Local time:06:00 AM

Posted 26 September 2009 - 02:21 PM

You are welcome.

This subject is now closed. If you need this topic reopened, please contact a member of the HJT Team and we will reopen it for you. Include the address of this thread in your request. If you should have a new issue, please start a new topic. This applies only to the original topic starter. Everyone else please begin a New Topic.
You don't stop laughing when you get old; you get old when you stop laughing.
A Member of U-N-I-T-E (Unified Network of Instructors and Trained Eliminators)
Malware Removal University Masters Graduate

Posted Image
Join The Fight Against Malware
No reply within 5 days will result in your topic being closed. If you need more time, please let me know by posting in this topic so that your topic will not be closed.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users