Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected with Net-Worm.Win32.Kolabc.hki


  • This topic is locked This topic is locked
9 replies to this topic

#1 ursaminor

ursaminor

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:07:22 AM

Posted 25 October 2009 - 11:54 PM

I run my computer and at first I got a pop up alarm from kaspersky internet security :

" System is trying to get access to malicious software. "

Object:
C:\WINDOWS\Fonts\unwise_.exe

Virus:
Net-Worm.Win32.Kolabc.hki


Here is my log


DDS (Ver_09-10-26.01) - FAT32x86
Run by user at 11:16:20,45 on 26/10/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_16
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.479.162 [GMT 7:00]

AV: Kaspersky Internet Security *On-access scanning enabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *enabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\InstaTrader\terminal.exe
C:\Program Files\Novativa Streamster\Streamster.exe
C:\Documents and Settings\user\My Documents\Unduhan\dds.scr

============== Pseudo HJT Report ===============

uStart Page = about:blank
uSearch Page = hxxp://www.google.com
BHO: IDMIEHlprObj Class: {0055c089-8582-441b-a0bf-17b458c2a3a8} - c:\program files\internet download manager\IDMIECC.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: KeyScramblerBHO Class: {2b9f5787-88a5-4945-90e7-c4b18563bc5e} - c:\program files\keyscrambler\KeyScramblerIE.dll
BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files\kaspersky lab\kaspersky internet security 2010\ievkbd.dll
BHO: MSN Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.1203.0\msneshellx.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - c:\program files\kaspersky lab\kaspersky internet security 2010\klwtbbho.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: MSN Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.1203.0\msneshellx.dll
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
uRun: [Messenger (Yahoo!)] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
uRun: [IDMan] c:\program files\internet download manager\IDMan.exe /onboot
mRun: [avp] "c:\program files\kaspersky lab\kaspersky internet security 2010\avp.exe"
mRun: [WinampAgent] "c:\program files\winamp\winampa.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
IE: Add to Anti-Banner - c:\program files\kaspersky lab\kaspersky internet security 2010\ie_banner_deny.htm
IE: Download all links with IDM - c:\program files\internet download manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\internet download manager\IEGetVL.htm
IE: Download with IDM - c:\program files\internet download manager\IEExt.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - c:\program files\kaspersky lab\kaspersky internet security 2010\klwtbbho.dll
IE: {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - {B745F984-EF2E-40D6-A9AC-D8CED7230E61} - c:\program files\keyscrambler\KeyScramblerIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - c:\program files\kaspersky lab\kaspersky internet security 2010\klwtbbho.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1256467696781
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1256467669250
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
TCP: {29B380CF-7269-44CF-AC61-C55A932FF918} = 203.130.208.18 202.134.0.61
Notify: KeyScrambler - KeyScramblerLogon.dll
Notify: klogon - c:\windows\system32\klogon.dll
AppInit_DLLs: c:\progra~1\kasper~1\kasper~1\mzvkbd3.dll,c:\progra~1\kasper~1\kasper~1\kloehk.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\user\applic~1\mozilla\firefox\profiles\sdparei9.default\
FF - component: c:\documents and settings\user\application data\idm\idmmzcc3\components\idmmzcc.dll
FF - component: c:\program files\mozilla firefox\extensions\linkfilter@kaspersky.ru\components\KavLinkFilter.dll
FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nprpjplug.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}

============= SERVICES / DRIVERS ===============

R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-12-15 33808]
R3 KeyScramblerDrv;KeyScramblerDrv;c:\windows\system32\drivers\keyscrambler.sys [2009-10-17 113896]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2009-5-16 19472]
S2 Windows Hosts Controller;Windows Hosts Controller;c:\windows\fonts\unwise_.exe [2009-10-25 141454]

=============== Created Last 30 ================

2009-10-25 13:53:02 141454 ----a-w- c:\windows\system32\man8.exe
2009-10-25 13:52:59 81 ----a-w- c:\windows\system32\asr_ndqsm
2009-10-25 13:45:15 81 ----a-w- c:\windows\system32\asr_yptje
2009-10-25 12:58:08 81 ----a-w- c:\windows\system32\asr_ascso
2009-10-25 12:22:09 7208 ----a-w- c:\windows\system32\dllcache\secupd.sig
2009-10-25 12:22:09 7208 ------w- c:\windows\system32\secupd.sig
2009-10-25 12:22:09 4569 ----a-w- c:\windows\system32\dllcache\secupd.dat
2009-10-25 12:22:09 4569 ------w- c:\windows\system32\secupd.dat
2009-10-25 11:34:32 0 d-----w- c:\windows\system32\CatRoot_bak
2009-10-25 11:13:01 0 d-----w- c:\windows\system32\PreInstall
2009-10-25 11:12:59 0 d--h--w- c:\windows\$hf_mig$
2009-10-25 10:49:37 31768 ----a-w- c:\windows\system32\wucltui.dll.mui
2009-10-25 10:49:37 0 d-----w- c:\windows\system32\SoftwareDistribution
2009-10-25 10:49:36 23576 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2009-10-25 10:49:36 18456 ----a-w- c:\windows\system32\wuaueng.dll.mui
2009-10-25 10:49:35 23576 ----a-w- c:\windows\system32\wuapi.dll.mui
2009-10-25 10:31:27 0 d--h--w- c:\windows\ie8
2009-10-25 09:40:42 5 ----a-w- c:\windows\system32\Band4
2009-10-25 09:40:40 6 ----a-w- c:\windows\system32\ClassU
2009-10-25 08:15:56 0 d-sh--w- C:\FOUND.001
2009-10-24 11:08:23 0 d-----w- c:\program files\Forex Strategy Builder
2009-10-23 03:32:31 0 d-----w- c:\program files\common files\NSV
2009-10-22 15:31:02 0 d-sh--w- C:\FOUND.000
2009-10-22 14:42:03 9072 ------w- c:\windows\system32\drivers\cdr4_xp.sys
2009-10-22 14:42:01 9200 ------w- c:\windows\system32\drivers\cdralw2k.sys
2009-10-22 14:42:00 129520 ------w- c:\windows\system32\pxafs.dll
2009-10-21 15:09:35 0 d-----w- c:\docume~1\user\applic~1\IDM
2009-10-21 15:09:34 0 d-----w- c:\docume~1\user\applic~1\DMCache
2009-10-21 15:09:19 0 d-----w- c:\program files\Internet Download Manager
2009-10-20 05:48:40 0 d-----w- c:\program files\PowerArchiver
2009-10-20 05:35:55 0 d-----w- c:\docume~1\alluse~1\applic~1\ConeXware
2009-10-20 03:47:52 73728 ----a-w- c:\windows\system32\javacpl.cpl
2009-10-19 13:31:56 604140 --sha-w- c:\windows\system32\drivers\ISwift3.dat
2009-10-19 13:30:51 95259 ----a-w- c:\windows\system32\drivers\klick.dat
2009-10-19 13:30:51 108059 ----a-w- c:\windows\system32\drivers\klin.dat
2009-10-19 13:30:08 0 d-----w- c:\program files\Kaspersky Lab
2009-10-19 13:30:08 0 d-----w- c:\docume~1\alluse~1\applic~1\Kaspersky Lab
2009-10-19 13:29:06 0 d-----w- c:\docume~1\alluse~1\applic~1\Kaspersky Lab Setup Files
2009-10-19 08:52:54 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-19 00:44:15 35925 ----a-w- c:\windows\system32\oodbs.lor
2009-10-18 22:40:39 0 d-----w- c:\docume~1\user\applic~1\mIRC
2009-10-18 22:40:38 0 d-----w- c:\program files\mIRC
2009-10-18 17:25:14 80 ----a-w- c:\windows\system32\asr_tyuoo
2009-10-18 17:13:53 80 ----a-w- c:\windows\system32\asr_kzfgm
2009-10-18 14:32:06 0 d-sh--w- c:\documents and settings\user\IECompatCache
2009-10-18 14:31:30 0 d-sh--w- c:\documents and settings\user\PrivacIE
2009-10-18 14:27:34 0 d-sh--w- c:\documents and settings\user\IETldCache
2009-10-18 14:25:02 26144 ----a-w- c:\windows\system32\spupdsvc.exe
2009-10-18 14:23:00 0 d--h--w- c:\windows\msdownld.tmp
2009-10-17 12:27:19 96 ----a-w- c:\windows\system32\pdfl.dat
2009-10-17 12:27:19 80 ----a-w- c:\windows\system32\ibfl.dat
2009-10-17 12:27:19 144 ----a-w- c:\windows\system32\lkfl.dat
2009-10-17 12:26:57 0 d-----w- c:\windows\system32\ZoneLabs
2009-10-17 12:25:55 0 d-----w- c:\windows\Internet Logs
2009-10-17 10:57:36 0 d-----w- c:\docume~1\user\applic~1\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2009-10-17 09:43:17 113896 ----a-w- c:\windows\system32\drivers\keyscrambler.sys
2009-10-17 09:43:16 0 d-----w- c:\program files\KeyScrambler
2009-10-17 08:22:50 0 d-----w- c:\program files\CCleaner
2009-10-17 05:02:34 42 ----a-w- c:\windows\system32\AK083E209605E394C.lie
2009-10-16 12:09:42 0 d-----w- c:\documents and settings\user\Downloads
2009-10-16 11:59:44 0 d-----w- c:\docume~1\alluse~1\applic~1\Kaspersky SDK
2009-10-16 11:50:34 0 d-----w- c:\docume~1\user\applic~1\CheckPoint
2009-10-16 11:50:01 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2009-10-16 11:46:16 0 d-----w- c:\program files\Perfect Uninstaller
2009-10-16 11:45:28 0 d-----w- c:\docume~1\alluse~1\applic~1\RegCure
2009-10-16 10:34:00 0 d-----w- c:\program files\WGA
2009-10-16 10:28:05 0 d-----w- c:\program files\Novativa Streamster
2009-10-16 10:19:59 0 d-----w- c:\program files\InstaTrader
2009-10-16 10:09:07 26496 ----a-w- c:\windows\system32\dllcache\usbstor.sys
2009-10-16 08:34:36 0 d-----w- c:\program files\Yahoo!
2009-10-16 08:11:43 2516 --sha-w- c:\windows\system32\KGyGaAvL.sys
2009-10-16 08:04:08 0 d-----w- c:\program files\Corel
2009-10-16 08:04:08 0 d-----w- c:\program files\common files\Corel
2009-10-16 08:01:01 54156 ---ha-w- c:\windows\QTFont.qfn
2009-10-16 08:01:01 1409 ----a-w- c:\windows\QTFont.for
2009-10-16 07:52:51 0 d-----w- c:\program files\common files\Adobe Systems Shared
2009-10-16 07:49:50 0 d-----w- c:\docume~1\user\applic~1\ACD Systems
2009-10-16 07:46:59 0 d-sh--w- C:\Recycled
2009-10-16 07:32:33 0 d-----w- c:\docume~1\alluse~1\applic~1\ACD Systems
2009-10-16 07:32:32 0 d-----w- c:\program files\common files\ACD Systems
2009-10-16 07:32:32 0 d-----w- c:\program files\ACD Systems
2009-10-16 07:32:06 0 d-----w- c:\windows\Downloaded Installations
2009-10-16 07:29:34 0 d-sh--w- c:\documents and settings\all users\DRM
2009-10-16 07:29:20 0 d-----w- c:\program files\K-Lite Codec Pack
2009-10-16 07:27:19 44944 ------w- c:\windows\system32\drivers\pxhelp20.sys
2009-10-16 07:21:49 376 ----a-w- c:\windows\ODBC.INI
2009-10-16 07:21:44 17920 ----a-w- c:\windows\system32\mdimon.dll
2009-10-16 07:21:02 0 d-----w- c:\program files\common files\L&H
2009-10-16 07:20:41 0 d-----w- c:\program files\Microsoft ActiveSync
2009-10-16 07:16:04 0 d-----w- c:\windows\SHELLNEW
2009-10-16 07:11:00 42496 ----a-r- c:\windows\system32\drivers\fetnd5b.sys
2009-10-16 07:08:59 60288 ----a-w- c:\windows\system32\drivers\drmk.sys
2009-10-16 07:08:59 60288 ----a-w- c:\windows\system32\dllcache\drmk.sys
2009-10-16 07:08:59 130048 ----a-w- c:\windows\system32\ksproxy.ax
2009-10-16 07:08:59 130048 ----a-w- c:\windows\system32\dllcache\ksproxy.ax
2009-10-16 07:08:52 92 ----a-w- c:\windows\CMISETUP.INI
2009-10-16 07:08:51 26 ----a-w- c:\windows\CMCDPLAY.INI
2009-10-16 07:08:49 171 ----a-w- c:\windows\system\CmiCnfg.ini
2009-10-16 07:08:49 0 ----a-w- c:\windows\Wininit.ini
2009-10-16 07:08:45 132864 ------r- c:\windows\Cmuda.ini
2009-10-16 07:08:39 28672 ----a-w- c:\windows\CMIRmDriver.dll
2009-10-16 07:08:39 266240 ----a-w- c:\windows\CMIUninstall.exe
2009-10-16 07:08:39 225280 ----a-w- c:\windows\CmiRmRedundDir.exe
2009-10-16 07:08:39 0 d-----w- c:\program files\C-Media 3D Audio
2009-10-16 07:05:45 0 d-----w- c:\program files\S3
2009-10-16 07:04:26 0 d-----w- c:\documents and settings\user\WINDOWS
2009-10-16 07:02:37 0 d-----w- c:\windows\system32\ReinstallBackups
2009-10-16 07:00:54 306688 ----a-w- c:\windows\IsUninst.exe
2009-10-16 07:00:01 0 d-----w- c:\windows\system32\Tools
2009-10-16 06:44:36 0 d--h--w- c:\program files\WindowsUpdate
2009-10-16 06:43:59 0 d-----w- c:\program files\common files\MSSoap
2009-10-16 06:42:34 0 d-----w- c:\program files\Online Services
2009-10-16 06:42:26 0 d-----w- c:\program files\Messenger
2009-10-16 06:42:23 0 d-----w- c:\program files\MSN Gaming Zone
2009-10-16 06:41:54 0 d-----w- c:\program files\Windows NT
2009-10-16 06:31:16 0 d-----w- c:\program files\common files\ODBC
2009-10-16 06:31:13 0 d-----w- c:\program files\common files\SpeechEngines
2009-10-16 06:30:52 0 d-----r- c:\documents and settings\all users\Documents

==================== Find3M ====================

2009-10-25 13:45:30 141454 ------w- c:\windows\fonts\unwise_.exe
2009-10-16 06:43:02 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2004-09-03 03:32:50 3488 ----a-w- c:\windows\inf\other\CMIAINFO.SYS

============= FINISH: 11:20:21,46 ===============

Attached Files



BC AdBot (Login to Remove)

 


#2 syler

syler

  • Malware Response Team
  • 8,150 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Warrington, UK
  • Local time:01:22 AM

Posted 01 November 2009 - 05:32 PM

Hello,

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and
we are trying our best to keep up.

My name is Syler and I will be helping you to solve your Malware issues. If you have since resolved your issues I would appreciate if you
would let me no so I can close this topic, if you still need help please let me no what issues you are still having, in your next reply.

  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<<will be maximized) and info.txt (<<will be minimized)
Then please post back here with the following:
  • log.txt
  • info.txt
Thanks

unite.jpg


#3 ursaminor

ursaminor
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:07:22 AM

Posted 04 November 2009 - 06:30 AM

Hi syler..

here my log:

Logfile of random's system information tool 1.06 (written by random/random)
Run by user at 2009-11-04 18:23:47
Microsoft Windows XP Professional Service Pack 2
System drive C: has 6 GB (41%) free of 15 GB
Total RAM: 479 MB (31% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:24:40, on 04/11/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Novativa Streamster\Streamster.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\InstaTrader\terminal.exe
F:\RSIT.exe
C:\Program Files\trend micro\user.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: QFX Software KeyScrambler - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [avp] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: &Virtual keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O9 - Extra button: (no name) - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O9 - Extra 'Tools' menuitem: &KeyScrambler... - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1256467696781
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1256467669250
O17 - HKLM\System\CCS\Services\Tcpip\..\{29B380CF-7269-44CF-AC61-C55A932FF918}: NameServer = 203.130.208.18 202.134.0.61
O17 - HKLM\System\CS1\Services\Tcpip\..\{29B380CF-7269-44CF-AC61-C55A932FF918}: NameServer = 203.130.208.18 202.134.0.61
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
O20 - Winlogon Notify: KeyScrambler - C:\WINDOWS\SYSTEM32\KeyScramblerLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

--
End of file - 6036 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job
C:\WINDOWS\tasks\{7B02EF0B-A410-4938-8480-9BA26420A627}.job
C:\WINDOWS\tasks\RegCure.job
C:\WINDOWS\tasks\RegCure Startup.job
C:\WINDOWS\tasks\RegCure Program Check.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{71DA9882-EFFC-423C-B0D4-4018C41983FD}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}]
IDMIEHlprObj Class - C:\Program Files\Internet Download Manager\IDMIECC.dll [2009-05-07 169392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2B9F5787-88A5-4945-90E7-C4B18563BC5E}]
KeyScramblerBHO Class - C:\Program Files\KeyScrambler\KeyScramblerIE.dll [2009-10-17 829928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C}]
IEVkbdBHO Class - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll [2009-07-03 68112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-20 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E33CF602-D945-461A-83F0-819F76A199F8}]
FilterBHO Class - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll [2009-10-19 264720]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-10-20 73728]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avp"=C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe [2009-07-03 303376]
"WinampAgent"=C:\Program Files\Winamp\winampa.exe [2009-07-01 37888]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2005-06-14 15360]
"IDMan"=C:\Program Files\Internet Download Manager\IDMan.exe [2009-10-21 2815408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\KeyScrambler]
C:\WINDOWS\system32\KeyScramblerLogon.dll [2008-11-21 109032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
C:\WINDOWS\system32\klogon.dll [2009-07-03 219664]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\WINDOWS\System32\ZoneLabs\vsmon.exe"="C:\WINDOWS\System32\ZoneLabs\vsmon.exe:*:Enabled:TrueVector Service"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"unwise_.exe"="unwise_.exe:*:Enabled:SYSTEM"
"C:\WINDOWS\Fonts\unwise_.exe"="C:\WINDOWS\Fonts\unwise_.exe:*:Enabled:workstation"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"unwise_.exe"="unwise_.exe:*:Enabled:SYSTEM"

======List of files/folders created in the last 1 months======

2009-11-04 18:23:53 ----D---- C:\Program Files\trend micro
2009-11-04 18:23:47 ----D---- C:\rsit
2009-11-04 11:50:17 ----D---- C:\Program Files\WSS Package
2009-11-01 17:10:17 ----D---- C:\Program Files\InstaTrader
2009-10-27 18:55:14 ----D---- C:\WINDOWS\system32\XPSViewer
2009-10-27 18:55:10 ----D---- C:\Program Files\MSBuild
2009-10-27 18:55:00 ----D---- C:\Program Files\Reference Assemblies
2009-10-27 18:54:24 ----N---- C:\WINDOWS\system32\xpsshhdr.dll
2009-10-27 18:54:24 ----N---- C:\WINDOWS\system32\prntvpt.dll
2009-10-27 18:54:23 ----N---- C:\WINDOWS\system32\xpssvcs.dll
2009-10-27 18:47:19 ----HD---- C:\WINDOWS\$NtUninstallWIC$
2009-10-27 18:47:07 ----D---- C:\Program Files\MSXML 6.0
2009-10-27 10:02:20 ----D---- C:\Documents and Settings\user\Application Data\Media Player Classic
2009-10-26 19:49:58 ----D---- C:\WINDOWS\ServicePackFiles
2009-10-26 19:49:07 ----D---- C:\WINDOWS\ie8updates
2009-10-26 19:47:19 ----D---- C:\Program Files\MSXML 4.0
2009-10-26 15:51:24 ----HD---- C:\WINDOWS\PIF
2009-10-26 13:39:48 ----A---- C:\WINDOWS\system32\mucltui.dll.mui
2009-10-26 13:39:44 ----A---- C:\WINDOWS\system32\mucltui.dll
2009-10-26 13:29:21 ----N---- C:\WINDOWS\system32\tzchange.exe
2009-10-25 18:34:32 ----D---- C:\WINDOWS\system32\CatRoot_bak
2009-10-25 18:30:33 ----D---- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2009-10-25 18:13:01 ----D---- C:\WINDOWS\system32\PreInstall
2009-10-25 18:12:59 ----HD---- C:\WINDOWS\$hf_mig$
2009-10-25 17:49:37 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2009-10-25 17:49:37 ----A---- C:\WINDOWS\system32\wups2.dll
2009-10-25 17:49:37 ----A---- C:\WINDOWS\system32\wucltui.dll.mui
2009-10-25 17:49:36 ----A---- C:\WINDOWS\system32\wuaueng.dll.mui
2009-10-25 17:49:35 ----A---- C:\WINDOWS\system32\wuapi.dll.mui
2009-10-25 17:31:27 ----HD---- C:\WINDOWS\ie8
2009-10-25 17:30:29 ----D---- C:\Program Files\Microsoft Silverlight
2009-10-25 15:15:56 ----SHD---- C:\FOUND.001
2009-10-24 18:22:48 ----RSD---- C:\WINDOWS\assembly
2009-10-24 18:21:35 ----D---- C:\WINDOWS\Microsoft.NET
2009-10-24 18:08:23 ----D---- C:\Program Files\Forex Strategy Builder
2009-10-23 10:32:31 ----D---- C:\Program Files\Common Files\NSV
2009-10-23 10:23:14 ----D---- C:\Program Files\Winamp
2009-10-22 22:31:02 ----SHD---- C:\FOUND.000
2009-10-22 21:42:01 ----N---- C:\WINDOWS\system32\pxcpya64.exe
2009-10-22 21:42:00 ----N---- C:\WINDOWS\system32\pxsfs.dll
2009-10-22 21:42:00 ----N---- C:\WINDOWS\system32\pxinsa64.exe
2009-10-22 21:42:00 ----N---- C:\WINDOWS\system32\pxafs.dll
2009-10-22 21:41:50 ----D---- C:\Documents and Settings\user\Application Data\Winamp
2009-10-21 22:09:35 ----D---- C:\Documents and Settings\user\Application Data\IDM
2009-10-21 22:09:34 ----D---- C:\Documents and Settings\user\Application Data\DMCache
2009-10-21 22:09:19 ----D---- C:\Program Files\Internet Download Manager
2009-10-20 13:13:12 ----D---- C:\Program Files\FLV Player
2009-10-20 12:48:40 ----D---- C:\Program Files\PowerArchiver
2009-10-20 12:35:55 ----D---- C:\Documents and Settings\All Users\Application Data\ConeXware
2009-10-20 10:47:52 ----A---- C:\WINDOWS\system32\javaws.exe
2009-10-20 10:47:51 ----A---- C:\WINDOWS\system32\javaw.exe
2009-10-20 10:47:51 ----A---- C:\WINDOWS\system32\java.exe
2009-10-20 10:47:22 ----D---- C:\Program Files\Java
2009-10-19 20:30:08 ----D---- C:\Program Files\Kaspersky Lab
2009-10-19 20:30:08 ----D---- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2009-10-19 20:29:06 ----D---- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-10-19 20:24:24 ----A---- C:\WINDOWS\system32\wininet.dll
2009-10-19 20:24:24 ----A---- C:\WINDOWS\system32\shdocvw.dll
2009-10-19 20:24:24 ----A---- C:\WINDOWS\system32\pngfilt.dll
2009-10-19 20:24:24 ----A---- C:\WINDOWS\system32\occache.dll
2009-10-19 20:24:24 ----A---- C:\WINDOWS\system32\mstime.dll
2009-10-19 20:24:24 ----A---- C:\WINDOWS\system32\msrating.dll
2009-10-19 20:24:24 ----A---- C:\WINDOWS\system32\msls31.dll
2009-10-19 20:24:24 ----A---- C:\WINDOWS\system32\mshtmler.dll
2009-10-19 20:24:24 ----A---- C:\WINDOWS\system32\mshtmled.dll
2009-10-19 20:24:24 ----A---- C:\WINDOWS\system32\mshtml.dll
2009-10-19 20:24:24 ----A---- C:\WINDOWS\system32\mshta.exe
2009-10-19 20:24:24 ----A---- C:\WINDOWS\system32\licmgr10.dll
2009-10-19 20:24:24 ----A---- C:\WINDOWS\system32\jsproxy.dll
2009-10-19 20:24:24 ----A---- C:\WINDOWS\system32\jscript.dll
2009-10-19 20:24:24 ----A---- C:\WINDOWS\system32\inseng.dll
2009-10-19 20:24:24 ----A---- C:\WINDOWS\system32\imgutil.dll
2009-10-19 17:10:12 ----D---- C:\WINDOWS\Sun
2009-10-19 15:52:54 ----A---- C:\WINDOWS\system32\deploytk.dll
2009-10-19 15:46:02 ----D---- C:\Documents and Settings\user\Application Data\Sun
2009-10-19 05:40:39 ----D---- C:\Documents and Settings\user\Application Data\mIRC
2009-10-19 05:40:38 ----D---- C:\Program Files\mIRC
2009-10-18 21:25:30 ----D---- C:\WINDOWS\WBEM
2009-10-18 21:25:02 ----A---- C:\WINDOWS\system32\spupdsvc.exe
2009-10-18 21:24:10 ----D---- C:\WINDOWS\system32\en-US
2009-10-18 21:23:00 ----HD---- C:\WINDOWS\msdownld.tmp
2009-10-17 20:42:38 ----A---- C:\WINDOWS\system32\homepage.txt
2009-10-17 19:26:57 ----D---- C:\WINDOWS\system32\ZoneLabs
2009-10-17 19:25:55 ----D---- C:\WINDOWS\Internet Logs
2009-10-17 16:43:16 ----D---- C:\Program Files\KeyScrambler
2009-10-17 15:22:50 ----D---- C:\Program Files\CCleaner
2009-10-16 18:59:44 ----D---- C:\Documents and Settings\All Users\Application Data\Kaspersky SDK
2009-10-16 18:46:16 ----D---- C:\Program Files\Perfect Uninstaller
2009-10-16 18:45:28 ----D---- C:\Program Files\RegCure
2009-10-16 18:45:28 ----D---- C:\Documents and Settings\All Users\Application Data\RegCure
2009-10-16 17:34:00 ----D---- C:\Program Files\WGA
2009-10-16 17:28:05 ----D---- C:\Program Files\Novativa Streamster
2009-10-16 15:36:38 ----D---- C:\Documents and Settings\user\Application Data\Mozilla
2009-10-16 15:35:41 ----D---- C:\Program Files\Mozilla Firefox
2009-10-16 15:34:40 ----D---- C:\Documents and Settings\All Users\Application Data\Yahoo!
2009-10-16 15:34:36 ----D---- C:\Program Files\Yahoo!
2009-10-16 15:06:35 ----D---- C:\Documents and Settings\All Users\Application Data\InstallShield
2009-10-16 15:01:28 ----A---- C:\WINDOWS\system32\msisip.dll
2009-10-16 15:01:28 ----A---- C:\WINDOWS\system32\msimsg.dll
2009-10-16 15:01:28 ----A---- C:\WINDOWS\system32\msihnd.dll
2009-10-16 15:01:28 ----A---- C:\WINDOWS\system32\msiexec.exe
2009-10-16 15:01:28 ----A---- C:\WINDOWS\system32\msi.dll
2009-10-16 14:53:43 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe Systems
2009-10-16 14:52:51 ----D---- C:\Program Files\Common Files\Adobe Systems Shared
2009-10-16 14:46:59 ----SHD---- C:\Recycled
2009-10-16 14:36:22 ----D---- C:\Documents and Settings\user\Application Data\Macromedia
2009-10-16 14:36:21 ----D---- C:\Documents and Settings\user\Application Data\Adobe
2009-10-16 14:34:10 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2009-10-16 14:34:03 ----D---- C:\Program Files\Common Files\Adobe
2009-10-16 14:34:03 ----D---- C:\Program Files\Adobe
2009-10-16 14:32:32 ----D---- C:\Program Files\Common Files\ACD Systems
2009-10-16 14:32:06 ----D---- C:\WINDOWS\Downloaded Installations
2009-10-16 14:29:30 ----D---- C:\WINDOWS\system32\QuickTime
2009-10-16 14:29:30 ----A---- C:\WINDOWS\system32\qtmlClient.dll
2009-10-16 14:29:27 ----D---- C:\WINDOWS\RegisteredPackages
2009-10-16 14:29:26 ----A---- C:\WINDOWS\system32\rmoc3260.dll
2009-10-16 14:29:26 ----A---- C:\WINDOWS\system32\pndx5032.dll
2009-10-16 14:29:26 ----A---- C:\WINDOWS\system32\pndx5016.dll
2009-10-16 14:29:26 ----A---- C:\WINDOWS\system32\pncrt.dll
2009-10-16 14:29:25 ----A---- C:\WINDOWS\system32\vp6vfw.dll
2009-10-16 14:29:25 ----A---- C:\WINDOWS\system32\vp31vfw.dll
2009-10-16 14:29:25 ----A---- C:\WINDOWS\system32\MACDec.dll
2009-10-16 14:29:22 ----A---- C:\WINDOWS\system32\xvidvfw.dll
2009-10-16 14:29:22 ----A---- C:\WINDOWS\system32\xvidcore.dll
2009-10-16 14:29:22 ----A---- C:\WINDOWS\system32\vsfilter.dll
2009-10-16 14:29:22 ----A---- C:\WINDOWS\system32\vorbisfile.dll
2009-10-16 14:29:22 ----A---- C:\WINDOWS\system32\vorbisenc.dll
2009-10-16 14:29:22 ----A---- C:\WINDOWS\system32\vorbis.dll
2009-10-16 14:29:22 ----A---- C:\WINDOWS\system32\vobsub.dll
2009-10-16 14:29:22 ----A---- C:\WINDOWS\system32\unrar.dll
2009-10-16 14:29:22 ----A---- C:\WINDOWS\system32\OpenQuicktimeLib.dll
2009-10-16 14:29:22 ----A---- C:\WINDOWS\system32\OggDS.dll
2009-10-16 14:29:22 ----A---- C:\WINDOWS\system32\ogg.dll
2009-10-16 14:29:22 ----A---- C:\WINDOWS\system32\mpg4c32.dll
2009-10-16 14:29:22 ----A---- C:\WINDOWS\system32\huffyuv.dll
2009-10-16 14:29:22 ----A---- C:\WINDOWS\system32\3ivxVfWCodec.dll
2009-10-16 14:29:22 ----A---- C:\WINDOWS\system32\3ivx.dll
2009-10-16 14:29:21 ----A---- C:\WINDOWS\system32\WMV9VCM.dll
2009-10-16 14:29:21 ----A---- C:\WINDOWS\system32\divx.dll
2009-10-16 14:29:20 ----D---- C:\Program Files\K-Lite Codec Pack
2009-10-16 14:29:20 ----D---- C:\Documents and Settings\user\Application Data\Real
2009-10-16 14:29:20 ----D---- C:\Documents and Settings\All Users\Application Data\Real
2009-10-16 14:29:20 ----A---- C:\WINDOWS\system32\unicows.dll
2009-10-16 14:29:20 ----A---- C:\WINDOWS\system32\cpuinf32.dll
2009-10-16 14:27:19 ----N---- C:\WINDOWS\system32\vxblock.dll
2009-10-16 14:27:19 ----N---- C:\WINDOWS\system32\pxwave.dll
2009-10-16 14:27:19 ----N---- C:\WINDOWS\system32\pxmas.dll
2009-10-16 14:27:19 ----N---- C:\WINDOWS\system32\pxhpinst.exe
2009-10-16 14:27:19 ----N---- C:\WINDOWS\system32\pxdrv.dll
2009-10-16 14:27:18 ----N---- C:\WINDOWS\system32\px.dll
2009-10-16 14:21:49 ----A---- C:\WINDOWS\ODBC.INI
2009-10-16 14:21:44 ----A---- C:\WINDOWS\system32\mdimon.dll
2009-10-16 14:21:02 ----D---- C:\Program Files\Common Files\L&H
2009-10-16 14:20:51 ----D---- C:\Program Files\Microsoft.NET
2009-10-16 14:20:41 ----D---- C:\Program Files\Microsoft ActiveSync
2009-10-16 14:20:08 ----D---- C:\Program Files\Common Files\DESIGNER
2009-10-16 14:16:48 ----D---- C:\Program Files\Microsoft Works
2009-10-16 14:16:33 ----D---- C:\Program Files\Microsoft Visual Studio
2009-10-16 14:16:04 ----D---- C:\WINDOWS\SHELLNEW
2009-10-16 14:15:51 ----D---- C:\Program Files\Microsoft Office
2009-10-16 14:09:01 ----RA---- C:\WINDOWS\system32\udaprop.dll
2009-10-16 14:09:01 ----RA---- C:\WINDOWS\system32\cmuda.dll
2009-10-16 14:09:01 ----RA---- C:\WINDOWS\system32\cmirmdrv.exe
2009-10-16 14:09:01 ----RA---- C:\WINDOWS\system32\cmirmdrv.dll
2009-10-16 14:09:01 ----RA---- C:\WINDOWS\system32\Audio3D.dll
2009-10-16 14:09:01 ----RA---- C:\WINDOWS\system32\a3d.dll
2009-10-16 14:09:00 ----A---- C:\WINDOWS\system32\ksuser.dll
2009-10-16 14:08:52 ----A---- C:\WINDOWS\CMISETUP.INI
2009-10-16 14:08:51 ----A---- C:\WINDOWS\CMCDPLAY.INI
2009-10-16 14:08:49 ----A---- C:\WINDOWS\Wininit.ini
2009-10-16 14:08:45 ----R---- C:\WINDOWS\Cmuda.ini
2009-10-16 14:08:39 ----D---- C:\Program Files\C-Media 3D Audio
2009-10-16 14:08:39 ----A---- C:\WINDOWS\CMIUninstall.exe
2009-10-16 14:08:39 ----A---- C:\WINDOWS\CmiRmRedundDir.exe
2009-10-16 14:08:39 ----A---- C:\WINDOWS\CMIRmDriver.dll
2009-10-16 14:05:54 ----RA---- C:\WINDOWS\system32\VTuninst.exe
2009-10-16 14:05:54 ----RA---- C:\WINDOWS\system32\VTTimer.exe
2009-10-16 14:05:54 ----RA---- C:\WINDOWS\system32\VTovrlay.dll
2009-10-16 14:05:54 ----RA---- C:\WINDOWS\system32\VTInfo2.dll
2009-10-16 14:05:53 ----RA---- C:\WINDOWS\system32\VTGamma2.dll
2009-10-16 14:05:52 ----RA---- C:\WINDOWS\system32\VTDisply.dll
2009-10-16 14:05:51 ----RA---- C:\WINDOWS\system32\vticd.dll
2009-10-16 14:05:49 ----RA---- C:\WINDOWS\system32\vtdisp.dll
2009-10-16 14:05:45 ----D---- C:\Program Files\S3
2009-10-16 14:02:37 ----D---- C:\WINDOWS\system32\ReinstallBackups
2009-10-16 14:00:54 ----A---- C:\WINDOWS\IsUninst.exe
2009-10-16 14:00:20 ----HD---- C:\Program Files\InstallShield Installation Information
2009-10-16 14:00:01 ----D---- C:\WINDOWS\system32\Tools
2009-10-16 13:59:54 ----D---- C:\Program Files\Common Files\InstallShield
2009-10-16 13:59:12 ----RA---- C:\DBI.EXE
2009-10-16 13:54:49 ----D---- C:\Documents and Settings\user\Application Data\Identities
2009-10-16 13:54:48 ----HD---- C:\Program Files\Uninstall Information
2009-10-16 13:54:40 ----SD---- C:\Documents and Settings\user\Application Data\Microsoft
2009-10-16 13:54:40 ----ASH---- C:\Documents and Settings\user\Application Data\desktop.ini
2009-10-16 13:54:05 ----SHD---- C:\System Volume Information
2009-10-16 13:54:05 ----D---- C:\WINDOWS\SoftwareDistribution
2009-10-16 13:54:04 ----SD---- C:\WINDOWS\system32\Microsoft
2009-10-16 13:54:04 ----N---- C:\WINDOWS\SchedLgU.Txt
2009-10-16 13:54:04 ----D---- C:\WINDOWS\Prefetch
2009-10-16 13:47:57 ----D---- C:\WINDOWS\system32\xircom
2009-10-16 13:47:57 ----D---- C:\Program Files\xerox
2009-10-16 13:47:57 ----D---- C:\Program Files\windows media player
2009-10-16 13:47:57 ----D---- C:\Program Files\microsoft frontpage
2009-10-16 13:46:13 ----N---- C:\WINDOWS\system32\spmsg.dll
2009-10-16 13:46:10 ----A---- C:\WINDOWS\system32\xpsp3res.dll
2009-10-16 13:46:08 ----N---- C:\WINDOWS\system32\setupn.exe
2009-10-16 13:45:50 ----A---- C:\WINDOWS\control.ini
2009-10-16 13:45:50 ----A---- C:\AUTOEXEC.BAT
2009-10-16 13:45:44 ----A---- C:\WINDOWS\system32\mapi32.dll
2009-10-16 13:44:46 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-10-16 13:44:46 ----RD---- C:\WINDOWS\Offline Web Pages
2009-10-16 13:44:46 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest
2009-10-16 13:44:40 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest
2009-10-16 13:44:36 ----HD---- C:\Program Files\WindowsUpdate
2009-10-16 13:44:19 ----D---- C:\WINDOWS\system32\DirectX
2009-10-16 13:44:09 ----A---- C:\WINDOWS\system32\atrace.dll
2009-10-16 13:44:08 ----A---- C:\WINDOWS\system32\desktop.ini
2009-10-16 13:44:08 ----A---- C:\WINDOWS\desktop.ini
2009-10-16 13:44:03 ----A---- C:\WINDOWS\system32\nmevtmsg.dll
2009-10-16 13:44:02 ----A---- C:\WINDOWS\system32\acctres.dll
2009-10-16 13:44:01 ----D---- C:\Program Files\Common Files\Services
2009-10-16 13:44:00 ----SD---- C:\WINDOWS\Tasks
2009-10-16 13:44:00 ----A---- C:\WINDOWS\system32\icfgnt5.dll
2009-10-16 13:43:59 ----D---- C:\Program Files\Common Files\MSSoap
2009-10-16 13:43:56 ----D---- C:\WINDOWS\srchasst
2009-10-16 13:43:55 ----D---- C:\WINDOWS\system32\Macromed
2009-10-16 13:43:55 ----A---- C:\WINDOWS\system32\wuweb.dll
2009-10-16 13:43:55 ----A---- C:\WINDOWS\system32\wups.dll
2009-10-16 13:43:55 ----A---- C:\WINDOWS\system32\wucltui.dll
2009-10-16 13:43:55 ----A---- C:\WINDOWS\system32\wuauserv.dll
2009-10-16 13:43:55 ----A---- C:\WINDOWS\system32\wuaueng1.dll
2009-10-16 13:43:55 ----A---- C:\WINDOWS\system32\wuaueng.dll
2009-10-16 13:43:55 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2009-10-16 13:43:55 ----A---- C:\WINDOWS\system32\wuauclt.exe
2009-10-16 13:43:55 ----A---- C:\WINDOWS\system32\wuapi.dll
2009-10-16 13:43:54 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
2009-10-16 13:43:54 ----A---- C:\WINDOWS\system32\qmgr.dll
2009-10-16 13:43:54 ----A---- C:\WINDOWS\system32\bitsprx3.dll
2009-10-16 13:43:54 ----A---- C:\WINDOWS\system32\bitsprx2.dll
2009-10-16 13:43:51 ----SHD---- C:\Program Files\Movie Maker
2009-10-16 13:43:48 ----A---- C:\WINDOWS\system32\safrslv.dll
2009-10-16 13:43:48 ----A---- C:\WINDOWS\system32\safrdm.dll
2009-10-16 13:43:48 ----A---- C:\WINDOWS\system32\safrcdlg.dll
2009-10-16 13:43:48 ----A---- C:\WINDOWS\system32\racpldlg.dll
2009-10-16 13:43:45 ----D---- C:\WINDOWS\system32\Restore
2009-10-16 13:43:45 ----A---- C:\WINDOWS\system32\srsvc.dll
2009-10-16 13:43:45 ----A---- C:\WINDOWS\system32\srrstr.dll
2009-10-16 13:43:45 ----A---- C:\WINDOWS\system32\srclient.dll
2009-10-16 13:43:45 ----A---- C:\WINDOWS\system32\fltMc.exe
2009-10-16 13:43:45 ----A---- C:\WINDOWS\system32\fltlib.dll
2009-10-16 13:43:44 ----A---- C:\WINDOWS\system32\nmmkcert.dll
2009-10-16 13:43:44 ----A---- C:\WINDOWS\system32\msconf.dll
2009-10-16 13:43:44 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2009-10-16 13:43:44 ----A---- C:\WINDOWS\system32\mnmdd.dll
2009-10-16 13:43:44 ----A---- C:\WINDOWS\system32\isrdbg32.dll
2009-10-16 13:43:44 ----A---- C:\WINDOWS\system32\ils.dll
2009-10-16 13:43:42 ----D---- C:\Program Files\NetMeeting
2009-10-16 13:43:42 ----A---- C:\WINDOWS\system32\msoert2.dll
2009-10-16 13:43:42 ----A---- C:\WINDOWS\system32\msoeacct.dll
2009-10-16 13:43:41 ----A---- C:\WINDOWS\system32\inetres.dll
2009-10-16 13:43:41 ----A---- C:\WINDOWS\system32\inetcomm.dll
2009-10-16 13:43:39 ----D---- C:\Program Files\Outlook Express
2009-10-16 13:43:39 ----A---- C:\WINDOWS\system32\schedsvc.dll
2009-10-16 13:43:39 ----A---- C:\WINDOWS\system32\mstinit.exe
2009-10-16 13:43:39 ----A---- C:\WINDOWS\system32\mstask.dll
2009-10-16 13:43:39 ----A---- C:\WINDOWS\system32\isign32.dll
2009-10-16 13:43:39 ----A---- C:\WINDOWS\system32\inetcfg.dll
2009-10-16 13:43:39 ----A---- C:\WINDOWS\system32\icwphbk.dll
2009-10-16 13:43:39 ----A---- C:\WINDOWS\system32\icwdial.dll
2009-10-16 13:43:35 ----D---- C:\Program Files\Common Files\System
2009-10-16 13:43:33 ----D---- C:\Program Files\Internet Explorer
2009-10-16 13:42:45 ----A---- C:\WINDOWS\vbaddin.ini
2009-10-16 13:42:45 ----A---- C:\WINDOWS\vb.ini
2009-10-16 13:42:41 ----D---- C:\WINDOWS\Registration
2009-10-16 13:42:34 ----D---- C:\Program Files\Online Services
2009-10-16 13:42:26 ----D---- C:\Program Files\Messenger
2009-10-16 13:42:23 ----D---- C:\Program Files\MSN Gaming Zone
2009-10-16 13:42:23 ----A---- C:\WINDOWS\system32\write.exe
2009-10-16 13:42:16 ----A---- C:\WINDOWS\system32\sndvol32.exe
2009-10-16 13:42:16 ----A---- C:\WINDOWS\system32\hticons.dll
2009-10-16 13:42:16 ----A---- C:\WINDOWS\system32\avwav.dll
2009-10-16 13:42:16 ----A---- C:\WINDOWS\system32\avtapi.dll
2009-10-16 13:42:16 ----A---- C:\WINDOWS\system32\avmeter.dll
2009-10-16 13:42:15 ----A---- C:\WINDOWS\system32\winchat.exe
2009-10-16 13:42:11 ----A---- C:\WINDOWS\system32\getuname.dll
2009-10-16 13:42:10 ----A---- C:\WINDOWS\system32\winmine.exe
2009-10-16 13:42:10 ----A---- C:\WINDOWS\system32\sol.exe
2009-10-16 13:42:10 ----A---- C:\WINDOWS\system32\mshearts.exe
2009-10-16 13:42:10 ----A---- C:\WINDOWS\system32\freecell.exe
2009-10-16 13:42:10 ----A---- C:\WINDOWS\system32\charmap.exe
2009-10-16 13:42:10 ----A---- C:\WINDOWS\system32\calc.exe
2009-10-16 13:42:09 ----A---- C:\WINDOWS\system32\usrlogon.cmd
2009-10-16 13:42:09 ----A---- C:\WINDOWS\system32\tsshutdn.exe
2009-10-16 13:42:09 ----A---- C:\WINDOWS\system32\tslabels.ini
2009-10-16 13:42:09 ----A---- C:\WINDOWS\system32\tskill.exe
2009-10-16 13:42:09 ----A---- C:\WINDOWS\system32\tsdiscon.exe
2009-10-16 13:42:09 ----A---- C:\WINDOWS\system32\tscon.exe
2009-10-16 13:42:09 ----A---- C:\WINDOWS\system32\shadow.exe
2009-10-16 13:42:09 ----A---- C:\WINDOWS\system32\rwinsta.exe
2009-10-16 13:42:09 ----A---- C:\WINDOWS\system32\reset.exe
2009-10-16 13:42:09 ----A---- C:\WINDOWS\system32\regini.exe
2009-10-16 13:42:09 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
2009-10-16 13:42:09 ----A---- C:\WINDOWS\system32\qwinsta.exe
2009-10-16 13:42:09 ----A---- C:\WINDOWS\system32\qappsrv.exe
2009-10-16 13:42:09 ----A---- C:\WINDOWS\system32\msg.exe
2009-10-16 13:42:09 ----A---- C:\WINDOWS\system32\logoff.exe
2009-10-16 13:42:09 ----A---- C:\WINDOWS\system32\cdmodem.dll
2009-10-16 13:42:08 ----A---- C:\WINDOWS\system32\mtxlegih.dll
2009-10-16 13:42:08 ----A---- C:\WINDOWS\system32\mtxex.dll
2009-10-16 13:42:08 ----A---- C:\WINDOWS\system32\mtxdm.dll
2009-10-16 13:42:08 ----A---- C:\WINDOWS\system32\msdtcprf.ini
2009-10-16 13:42:08 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2009-10-16 13:42:08 ----A---- C:\WINDOWS\system32\comrepl.dll
2009-10-16 13:42:08 ----A---- C:\WINDOWS\system32\comaddin.dll
2009-10-16 13:42:07 ----A---- C:\WINDOWS\system32\stclient.dll
2009-10-16 13:42:07 ----A---- C:\WINDOWS\system32\comsnap.dll
2009-10-16 13:42:04 ----A---- C:\WINDOWS\system32\wmimgmt.msc
2009-10-16 13:41:55 ----D---- C:\Program Files\MSN
2009-10-16 13:41:55 ----A---- C:\WINDOWS\system32\accwiz.exe
2009-10-16 13:41:54 ----D---- C:\Program Files\Windows NT
2009-10-16 13:41:54 ----A---- C:\WINDOWS\system32\sndrec32.exe
2009-10-16 13:41:54 ----A---- C:\WINDOWS\system32\mspaint.exe
2009-10-16 13:41:54 ----A---- C:\WINDOWS\system32\hypertrm.dll
2009-10-16 13:41:54 ----A---- C:\WINDOWS\system32\clipbrd.exe
2009-10-16 13:41:53 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
2009-10-16 13:41:53 ----A---- C:\WINDOWS\system32\spider.exe
2009-10-16 13:41:53 ----A---- C:\WINDOWS\system32\sessmgr.exe
2009-10-16 13:41:53 ----A---- C:\WINDOWS\system32\remotepg.dll
2009-10-16 13:41:53 ----A---- C:\WINDOWS\system32\rdshost.exe
2009-10-16 13:41:53 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2009-10-16 13:41:53 ----A---- C:\WINDOWS\system32\mstscax.dll
2009-10-16 13:41:53 ----A---- C:\WINDOWS\system32\mstsc.exe
2009-10-16 13:41:52 ----D---- C:\WINDOWS\system32\MsDtc
2009-10-16 13:41:52 ----A---- C:\WINDOWS\system32\tscupgrd.exe
2009-10-16 13:41:52 ----A---- C:\WINDOWS\system32\termsrv.dll
2009-10-16 13:41:52 ----A---- C:\WINDOWS\system32\rdpwsx.dll
2009-10-16 13:41:52 ----A---- C:\WINDOWS\system32\rdpsnd.dll
2009-10-16 13:41:52 ----A---- C:\WINDOWS\system32\rdpclip.exe
2009-10-16 13:41:52 ----A---- C:\WINDOWS\system32\rdchost.dll
2009-10-16 13:41:52 ----A---- C:\WINDOWS\system32\qprocess.exe
2009-10-16 13:41:52 ----A---- C:\WINDOWS\system32\mtxoci.dll
2009-10-16 13:41:52 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
2009-10-16 13:41:52 ----A---- C:\WINDOWS\system32\icaapi.dll
2009-10-16 13:41:52 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2009-10-16 13:41:51 ----A---- C:\WINDOWS\system32\xolehlp.dll
2009-10-16 13:41:51 ----A---- C:\WINDOWS\system32\msdtctm.dll
2009-10-16 13:41:51 ----A---- C:\WINDOWS\system32\msdtcprx.dll
2009-10-16 13:41:51 ----A---- C:\WINDOWS\system32\msdtclog.dll
2009-10-16 13:41:51 ----A---- C:\WINDOWS\system32\msdtc.exe
2009-10-16 13:41:50 ----D---- C:\WINDOWS\system32\Com
2009-10-16 13:41:50 ----A---- C:\WINDOWS\system32\comuid.dll
2009-10-16 13:41:50 ----A---- C:\WINDOWS\system32\comsvcs.dll
2009-10-16 13:41:50 ----A---- C:\WINDOWS\system32\colbact.dll
2009-10-16 13:41:50 ----A---- C:\WINDOWS\system32\clbcatex.dll
2009-10-16 13:41:50 ----A---- C:\WINDOWS\system32\catsrvut.dll
2009-10-16 13:41:50 ----A---- C:\WINDOWS\system32\catsrvps.dll
2009-10-16 13:41:50 ----A---- C:\WINDOWS\system32\catsrv.dll
2009-10-16 13:41:49 ----A---- C:\WINDOWS\system32\clbcatq.dll
2009-10-16 13:41:45 ----A---- C:\WINDOWS\system32\servdeps.dll
2009-10-16 13:41:45 ----A---- C:\WINDOWS\system32\mmfutil.dll
2009-10-16 13:41:45 ----A---- C:\WINDOWS\system32\licwmi.dll
2009-10-16 13:41:45 ----A---- C:\WINDOWS\system32\cmprops.dll
2009-10-16 13:38:25 ----A---- C:\WINDOWS\system32\h323log.txt
2009-10-16 13:32:19 ----A---- C:\WINDOWS\system32\usbui.dll
2009-10-16 13:31:17 ----SHD---- C:\WINDOWS\Installer
2009-10-16 13:31:17 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-10-16 13:31:16 ----D---- C:\Program Files\Common Files\ODBC
2009-10-16 13:31:16 ----A---- C:\WINDOWS\ODBCINST.INI
2009-10-16 13:31:13 ----RD---- C:\Program Files
2009-10-16 13:31:13 ----D---- C:\Program Files\Common Files\SpeechEngines
2009-10-16 13:31:13 ----D---- C:\Program Files\Common Files\Microsoft Shared
2009-10-16 13:31:13 ----D---- C:\Program Files\Common Files
2009-10-16 13:31:10 ----RA---- C:\WINDOWS\system32\kbdtuq.dll
2009-10-16 13:31:10 ----RA---- C:\WINDOWS\system32\kbdtuf.dll
2009-10-16 13:31:10 ----RA---- C:\WINDOWS\system32\kbdazel.dll
2009-10-16 13:31:09 ----RA---- C:\WINDOWS\system32\kbdycc.dll
2009-10-16 13:31:09 ----RA---- C:\WINDOWS\system32\kbduzb.dll
2009-10-16 13:31:09 ----RA---- C:\WINDOWS\system32\kbdur.dll
2009-10-16 13:31:09 ----RA---- C:\WINDOWS\system32\kbdtat.dll
2009-10-16 13:31:09 ----RA---- C:\WINDOWS\system32\kbdru1.dll
2009-10-16 13:31:09 ----RA---- C:\WINDOWS\system32\kbdru.dll
2009-10-16 13:31:09 ----RA---- C:\WINDOWS\system32\kbdmon.dll
2009-10-16 13:31:09 ----RA---- C:\WINDOWS\system32\kbdkyr.dll
2009-10-16 13:31:09 ----RA---- C:\WINDOWS\system32\kbdkaz.dll
2009-10-16 13:31:09 ----RA---- C:\WINDOWS\system32\kbdbu.dll
2009-10-16 13:31:09 ----RA---- C:\WINDOWS\system32\kbdblr.dll
2009-10-16 13:31:09 ----RA---- C:\WINDOWS\system32\kbdaze.dll
2009-10-16 13:31:07 ----RA---- C:\WINDOWS\system32\kbdhept.dll
2009-10-16 13:31:07 ----RA---- C:\WINDOWS\system32\kbdhela3.dll
2009-10-16 13:31:07 ----RA---- C:\WINDOWS\system32\kbdhela2.dll
2009-10-16 13:31:07 ----RA---- C:\WINDOWS\system32\kbdhe319.dll
2009-10-16 13:31:07 ----RA---- C:\WINDOWS\system32\kbdhe220.dll
2009-10-16 13:31:07 ----RA---- C:\WINDOWS\system32\kbdhe.dll
2009-10-16 13:31:07 ----RA---- C:\WINDOWS\system32\kbdgkl.dll
2009-10-16 13:31:06 ----RA---- C:\WINDOWS\system32\kbdlv1.dll
2009-10-16 13:31:06 ----RA---- C:\WINDOWS\system32\kbdlv.dll
2009-10-16 13:31:06 ----RA---- C:\WINDOWS\system32\kbdlt1.dll
2009-10-16 13:31:06 ----RA---- C:\WINDOWS\system32\kbdlt.dll
2009-10-16 13:31:06 ----RA---- C:\WINDOWS\system32\kbdest.dll
2009-10-16 13:31:05 ----RA---- C:\WINDOWS\system32\kbdycl.dll
2009-10-16 13:31:05 ----RA---- C:\WINDOWS\system32\kbdsl1.dll
2009-10-16 13:31:05 ----RA---- C:\WINDOWS\system32\kbdsl.dll
2009-10-16 13:31:05 ----RA---- C:\WINDOWS\system32\kbdro.dll
2009-10-16 13:31:05 ----RA---- C:\WINDOWS\system32\kbdpl1.dll
2009-10-16 13:31:05 ----RA---- C:\WINDOWS\system32\kbdpl.dll
2009-10-16 13:31:05 ----RA---- C:\WINDOWS\system32\kbdhu1.dll
2009-10-16 13:31:05 ----RA---- C:\WINDOWS\system32\kbdhu.dll
2009-10-16 13:31:05 ----RA---- C:\WINDOWS\system32\kbdcz2.dll
2009-10-16 13:31:05 ----RA---- C:\WINDOWS\system32\kbdcz1.dll
2009-10-16 13:31:05 ----RA---- C:\WINDOWS\system32\kbdcz.dll
2009-10-16 13:31:05 ----RA---- C:\WINDOWS\system32\kbdcr.dll
2009-10-16 13:31:05 ----RA---- C:\WINDOWS\system32\KBDAL.DLL
2009-10-16 13:31:03 ----A---- C:\WINDOWS\system32\irclass.dll
2009-10-16 13:31:03 ----A---- C:\WINDOWS\system32\dgsetup.dll
2009-10-16 13:31:03 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
2009-10-16 13:31:02 ----A---- C:\WINDOWS\system32\spxcoins.dll
2009-10-16 13:31:02 ----A---- C:\WINDOWS\system32\EqnClass.Dll
2009-10-16 13:31:01 ----N---- C:\WINDOWS\system32\CONFIG.TMP
2009-10-16 13:31:01 ----A---- C:\WINDOWS\TASKMAN.EXE
2009-10-16 13:31:00 ----A---- C:\WINDOWS\system32\batt.dll
2009-10-16 13:31:00 ----A---- C:\WINDOWS\NOTEPAD.EXE
2009-10-16 13:30:59 ----A---- C:\WINDOWS\system32\storprop.dll
2009-10-16 13:30:52 ----RA---- C:\WINDOWS\SET28.tmp
2009-10-16 13:30:52 ----ASH---- C:\Documents and Settings\All Users\Application Data\desktop.ini
2009-10-16 13:30:51 ----RA---- C:\WINDOWS\SET27.tmp
2009-10-16 13:30:48 ----RA---- C:\WINDOWS\SET8.tmp
2009-10-16 13:30:46 ----RA---- C:\WINDOWS\SET4.tmp
2009-10-16 13:30:44 ----RA---- C:\WINDOWS\SET3.tmp
2009-10-16 13:30:38 ----D---- C:\WINDOWS\system32\CatRoot2
2009-10-16 13:30:38 ----D---- C:\WINDOWS\system32\CatRoot
2009-10-16 13:30:33 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2009-10-16 13:30:12 ----D---- C:\Documents and Settings
2009-10-16 13:29:20 ----N---- C:\boot.ini
2009-10-16 13:24:16 ----RSHD---- C:\WINDOWS\system32\dllcache
2009-10-16 13:24:16 ----RSD---- C:\WINDOWS\Fonts
2009-10-16 13:24:16 ----RD---- C:\WINDOWS\Web
2009-10-16 13:24:16 ----HD---- C:\WINDOWS\inf
2009-10-16 13:24:16 ----D---- C:\WINDOWS\WinSxS
2009-10-16 13:24:16 ----D---- C:\WINDOWS\twain_32
2009-10-16 13:24:16 ----D---- C:\WINDOWS\Temp
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\wins
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\wbem
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\usmt
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\spool
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\ShellExt
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\Setup
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\ras
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\oobe
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\npp
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\mui
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\inetsrv
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\IME
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\icsxml
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\ias
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\export
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\drivers
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\dhcp
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\config
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\3com_dmi
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\3076
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\2052
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\1054
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\1042
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\1041
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\1037
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\1033
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\1031
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\1028
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\1025
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system
2009-10-16 13:24:16 ----D---- C:\WINDOWS\security
2009-10-16 13:24:16 ----D---- C:\WINDOWS\Resources
2009-10-16 13:24:16 ----D---- C:\WINDOWS\repair
2009-10-16 13:24:16 ----D---- C:\WINDOWS\Provisioning
2009-10-16 13:24:16 ----D---- C:\WINDOWS\PeerNet
2009-10-16 13:24:16 ----D---- C:\WINDOWS\pchealth
2009-10-16 13:24:16 ----D---- C:\WINDOWS\mui
2009-10-16 13:24:16 ----D---- C:\WINDOWS\msapps
2009-10-16 13:24:16 ----D---- C:\WINDOWS\msagent
2009-10-16 13:24:16 ----D---- C:\WINDOWS\Media
2009-10-16 13:24:16 ----D---- C:\WINDOWS\java
2009-10-16 13:24:16 ----D---- C:\WINDOWS\ime
2009-10-16 13:24:16 ----D---- C:\WINDOWS\Help
2009-10-16 13:24:16 ----D---- C:\WINDOWS\ehome
2009-10-16 13:24:16 ----D---- C:\WINDOWS\Driver Cache
2009-10-16 13:24:16 ----D---- C:\WINDOWS\Debug
2009-10-16 13:24:16 ----D---- C:\WINDOWS\Cursors
2009-10-16 13:24:16 ----D---- C:\WINDOWS\Connection Wizard
2009-10-16 13:24:16 ----D---- C:\WINDOWS\Config
2009-10-16 13:24:16 ----D---- C:\WINDOWS\AppPatch
2009-10-16 13:24:16 ----D---- C:\WINDOWS\addins
2009-10-16 13:24:16 ----D---- C:\WINDOWS

======List of files/folders modified in the last 1 months======

2009-11-04 12:44:28 ----A---- C:\WINDOWS\win.ini
2009-10-16 13:31:14 ----A---- C:\WINDOWS\system.ini

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AmdK7;AMD K7 Processor Driver; C:\WINDOWS\system32\DRIVERS\amdk7.sys [2005-06-14 37376]
R1 KLIF;Kaspersky Lab Driver; C:\WINDOWS\system32\DRIVERS\klif.sys [2009-10-19 296976]
R3 cmuda;C-Media WDM Audio Interface; C:\WINDOWS\system32\drivers\cmuda.sys [2004-08-23 821760]
R3 FETND5BV;VIA Rhine-Family Fast Ethernet Adapter Driver Service; C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [2004-12-16 42496]
R3 KeyScramblerDrv;KeyScramblerDrv; C:\WINDOWS\System32\drivers\keyscrambler.sys [2008-06-25 113896]
R3 klmouflt;Kaspersky Lab KLMOUFLT; C:\WINDOWS\system32\DRIVERS\klmouflt.sys [2009-05-16 19472]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2005-06-14 26624]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2005-06-14 57600]
R3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2005-06-14 20480]
R3 viagfx;viagfx; C:\WINDOWS\system32\DRIVERS\vtmini.sys [2004-09-27 173440]
S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\fetnd5.sys [2001-08-17 27165]
S3 FETNDISB;VIA Rhine Family Fast Ethernet Adapter Driver Service; C:\WINDOWS\system32\DRIVERS\fetnd5b.sys [2004-01-09 42496]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AVP;Kaspersky Internet Security; C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe [2009-07-03 303376]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-10-20 153376]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2009-10-16 72704]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------


here my info :

info.txt logfile of random's system information tool 1.06 2009-11-04 18:24:45

======Uninstall list======

-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
-->VTUninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Timer'
Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 9.2-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A92000000001}
CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
C-Media 3D Audio-->C:\WINDOWS\CMIUnInstall.exe
Diner Dash-->D:\Games\Diner Dash\UNWISE.EXE D:\Games\Diner Dash\INSTALL.LOG
FeedingFrenzy-->D:\Games\FeedingFrenzy\UNWISE.EXE D:\Games\FeedingFrenzy\INSTALL.LOG
FLV Player 2.0 (build 25)-->C:\Program Files\FLV Player\uninst.exe
Forex Strategy Builder v2.9.1.0-->"C:\Program Files\Forex Strategy Builder\unins000.exe"
HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
Holiday Express-->D:\Games\Holiday Express\UNWISE.EXE D:\Games\Holiday Express\INSTALL.LOG
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
Iggle Pop-->D:\GAMES\IGGLEP~1\UNWISE.EXE D:\GAMES\IGGLEP~1\INSTALL.LOG
Incadia-->D:\Games\Incadia\UNWISE.EXE D:\Games\Incadia\INSTALL.LOG
Insaniquarium-->D:\Games\Insaniquarium\UNWISE.EXE D:\Games\Insaniquarium\INSTALL.LOG
InstaTrader 4.00-->"C:\Program Files\InstaTrader\Uninstall.exe" "C:\Program Files\InstaTrader\install.log"
Internet Download Manager-->C:\Program Files\Internet Download Manager\Uninstall.exe
Java™ 6 Update 16-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216016FF}
Jewel Quest-->D:\Games\Jewel Quest\UNWISE.EXE D:\Games\Jewel Quest\INSTALL.LOG
Kaspersky Internet Security 2010-->MsiExec.exe /I{9D8B0949-7C47-476F-9F06-F900D3B078EA}
Kaspersky Internet Security 2010-->MsiExec.exe /I{9D8B0949-7C47-476F-9F06-F900D3B078EA}
KeyScrambler-->C:\Program Files\KeyScrambler\uninstall.exe
K-Lite Mega Codec Pack 1.34-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
Luxor-->D:\Games\Luxor\UNWISE.EXE D:\Games\Luxor\INSTALL.LOG
MadCaps-->D:\Games\MadCaps\UNWISE.EXE D:\Games\MadCaps\INSTALL.LOG
Magic Vines-->D:\Games\Magic Vines\UNWISE.EXE D:\Games\Magic Vines\INSTALL.LOG
Marketiva-->C:\Program Files\Novativa Streamster\Uninstall.exe
Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Office Professional Edition 2003-->MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
mIRC-->C:\Program Files\mIRC\uninstall.exe _?=C:\Program Files\mIRC
Mozilla Firefox (3.5.4)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 6.0 Parser (KB933579)-->MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
Perfect Uninstaller v6.3.3.6-->"C:\Program Files\Perfect Uninstaller\unins000.exe"
Pizza Frenzy-->D:\Games\Pizza Frenzy\UNWISE.EXE D:\Games\Pizza Frenzy\INSTALL.LOG
Platypus-->D:\Games\Platypus\UNWISE.EXE D:\Games\Platypus\INSTALL.LOG
PowerArchiver 2010-->MsiExec.exe /I{AE244460-D063-44A6-8DAE-DA451837AC2C}
RegCure 2.0.0.0-->C:\Program Files\RegCure\uninst.exe
S3 S3Display-->vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Display'
S3 S3Gamma2-->vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Gamma2'
S3 S3Info2-->vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Info2'
S3 S3Overlay-->vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Overlay'
Security Update for Windows Internet Explorer 8 (KB971961)-->"C:\WINDOWS\ie8updates\KB971961-IE8\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 8 (KB974455)-->"C:\WINDOWS\ie8updates\KB974455-IE8\spuninst\spuninst.exe"
UniChrome IGP Driver and Utilities-->C:\PROGRA~1\S3\S3\s3setvga.exe -s -fC:\PROGRA~1\S3\S3\S3.uns
VIA Rhine-Family Fast Ethernet Adapter-->Rundll32.exe vuins32.dll,vuins32Ex $Rhine $VIA
Winamp-->"C:\Program Files\Winamp\UninstWA.exe"
Windows Imaging Component-->"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
Windows Internet Explorer 8-->"C:\WINDOWS\ie8\spuninst\spuninst.exe"
Windows Media Format Runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Player 10-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Yahoo! Messenger-->C:\PROGRA~1\YAHOO!\MESSEN~1\UNWISE.EXE /U C:\PROGRA~1\YAHOO!\MESSEN~1\INSTALL.LOG
Zuma-->D:\Games\Zuma\UNWISE.EXE D:\Games\Zuma\INSTALL.LOG

======Security center information======

AV: Kaspersky Internet Security
FW: Kaspersky Internet Security

======System event log======

Computer Name: USER-C9461CA0E9
Event Code: 1003
Message: Your computer was not able to renew its address from the network (from the
DHCP Server) for the Network Card with network address 00142A32B1FE. The following
error occurred:
The operation was canceled by the user.
.
Your computer will continue to try and obtain an address on its own from
the network address (DHCP) server.

Record Number: 288
Source Name: Dhcp
Time Written: 20091026222829.000000+420
Event Type: warning
User:

Computer Name: USER-C9461CA0E9
Event Code: 1003
Message: Your computer was not able to renew its address from the network (from the
DHCP Server) for the Network Card with network address 00142A32B1FE. The following
error occurred:
The operation was canceled by the user.
.
Your computer will continue to try and obtain an address on its own from
the network address (DHCP) server.

Record Number: 285
Source Name: Dhcp
Time Written: 20091026222821.000000+420
Event Type: warning
User:

Computer Name: USER-C9461CA0E9
Event Code: 20
Message: Installation Failure: Windows failed to install the following update with error 0x87ff054f: Windows XP Service Pack 3 (KB936929).

Record Number: 264
Source Name: Windows Update Agent
Time Written: 20091026213114.000000+420
Event Type: error
User:

Computer Name: USER-C9461CA0E9
Event Code: 4373
Message: Windows XP Service Pack 3 installation failed.
An internal error occurred.


Record Number: 263
Source Name: NtServicePack
Time Written: 20091026210759.000000+420
Event Type: error
User: USER-C9461CA0E9\user

Computer Name: USER-C9461CA0E9
Event Code: 7031
Message: The Windows Hosts Controller service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 3000 milliseconds: Restart the service.

Record Number: 17
Source Name: Service Control Manager
Time Written: 20091026104225.000000+420
Event Type: error
User:

=====Application event log=====

Computer Name: USER-C9461CA0E9
Event Code: 8
Message: Failed auto update retrieval of third-party root list sequence number from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: This operation returned because the timeout period expired.


Record Number: 19
Source Name: crypt32
Time Written: 20091026200935.000000+420
Event Type: error
User:

Computer Name: USER-C9461CA0E9
Event Code: 1517
Message: Windows saved user USER-C9461CA0E9\user registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use.


This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.

Record Number: 9
Source Name: Userenv
Time Written: 20091026194456.000000+420
Event Type: warning
User: NT AUTHORITY\SYSTEM

Computer Name: USER-C9461CA0E9
Event Code: 1517
Message: Windows saved user USER-C9461CA0E9\user registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use.


This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.

Record Number: 6
Source Name: Userenv
Time Written: 20091026170616.000000+420
Event Type: warning
User: NT AUTHORITY\SYSTEM

Computer Name: USER-C9461CA0E9
Event Code: 1002
Message: Hanging application RootRepeal.exe, version 1.3.5.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

Record Number: 4
Source Name: Application Hang
Time Written: 20091026112900.000000+420
Event Type: error
User:

Computer Name: USER-C9461CA0E9
Event Code: 8
Message: Failed auto update retrieval of third-party root list sequence number from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: This operation returned because the timeout period expired.


Record Number: 2
Source Name: crypt32
Time Written: 20091026102246.000000+420
Event Type: error
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 10 Stepping 0, AuthenticAMD
"PROCESSOR_REVISION"=0a00
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP

-----------------EOF-----------------

#4 syler

syler

  • Malware Response Team
  • 8,150 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Warrington, UK
  • Local time:01:22 AM

Posted 04 November 2009 - 10:23 AM

Hi ursaminor,


Please download Malwarebytes' Anti-Malware from Here

Note: If you already have Malwarebytes' Anti-Malware, just update then run it.
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan (the scan may take some time to finish, so please be patient).
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and Paste the entire report in your next reply .
Note: If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.


  • Please download GMER from one of the following locations, and save it to your desktop:
    • Main Mirror
      This version will download a randomly named file (Recommended)
    • Zip Mirror
      This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Disconnect from the Internet and close all running programs, as this process may crash your computer.
  • Temporarily disable any real-time active protection so your security program drivers will not conflict with gmer's driver.
  • Double click on Gmer to run it.
  • Allow the gmer.sys driver to load if asked.
  • You may see a rootkit warning window, If you do, click No.
  • Click on Posted Image and wait for the scan to finish.
  • If you see a rootkit warning window, click OK.
  • Push Posted Image and save the logfile to your desktop.
  • Copy and Paste the contents of that file in your next post.



Please post back here with the following logs:
  • MBAM log
  • Gmer log
  • New Rsit log
Thanks

unite.jpg


#5 ursaminor

ursaminor
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:07:22 AM

Posted 05 November 2009 - 06:49 AM

here they are ... :(


•MBAM log ( Quick Scan ):

Malwarebytes' Anti-Malware 1.41
Database version: 3103
Windows 5.1.2600 Service Pack 2

05/11/2009 17:23:03
mbam-log-2009-11-05 (17-23-03).txt

Scan type: Quick Scan
Objects scanned: 103307
Time elapsed: 8 minute(s), 3 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 3
Registry Values Infected: 5
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\NordBull (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Windows Hosts Controller (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\poprock (Trojan.Downloader) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\intime (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\reup (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\WaitToKillServiceT (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\unwise_.exe (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\unwise_.exe (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\Tasks\{7B02EF0B-A410-4938-8480-9BA26420A627}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job (Trojan.Downloader) -> Quarantined and deleted successfully.


•MBAM log ( Full Scan ):

Malwarebytes' Anti-Malware 1.41
Database version: 3103
Windows 5.1.2600 Service Pack 2

05/11/2009 18:00:08
mbam-log-2009-11-05 (18-00-08).txt

Scan type: Full Scan (C:\|D:\|F:\|)
Objects scanned: 139787
Time elapsed: 32 minute(s), 25 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 4

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
D:\Microsoft\Make Your Windows Genuine - For XP,Server 2003, Vista - iNGEn\WINDOWS XP and Server 2003\4) Keygens - Checkers\Windows Keygen.exe (Malware.Tool) -> Quarantined and deleted successfully.
D:\OODefrag12ProfessionalEnu\keygen.exe (Malware.Tool) -> Quarantined and deleted successfully.
D:\Nullsoft.Winamp.Pro.v5.56.Incl.Keygen-Lz0\nfoviewer.exe (Trojan.Agent) -> Quarantined and deleted successfully.
D:\Nullsoft.Winamp.Pro.v5.56.Incl.Keygen-Lz0\Lz0\KeyGen.exe (Trojan.Downloader) -> Quarantined and deleted successfully.


•Gmer log:

GMER 1.0.15.15163 - http://www.gmer.net
Rootkit scan 2009-11-05 18:22:55
Windows 5.1.2600 Service Pack 2
Running: gmer.exe; Driver: C:\DOCUME~1\user\LOCALS~1\Temp\afpcrpow.sys


---- System - GMER 1.0.15 ----

SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwAdjustPrivilegesToken [0xF5C1B36E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwClose [0xF5C1BA86]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwConnectPort [0xF5C1C60C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateEvent [0xF5C1CB40]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateFile [0xF5C1BD78]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateKey [0xF5C1A460]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateMutant [0xF5C1CA18]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateNamedPipeFile [0xF5C19D0A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreatePort [0xF5C1C8D4]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateSection [0xF5C1B102]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateSemaphore [0xF5C1CC72]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateSymbolicLinkObject [0xF5C1E40E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateThread [0xF5C1B886]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateWaitablePort [0xF5C1C976]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDeleteKey [0xF5C1AA20]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDeleteValueKey [0xF5C1ACF8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDeviceIoControlFile [0xF5C1C21C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDuplicateObject [0xF5C1E980]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwEnumerateKey [0xF5C1AE3A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwEnumerateValueKey [0xF5C1AEE4]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwFsControlFile [0xF5C1C016]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwLoadDriver [0xF5C1DEA6]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwLoadKey [0xF5C1A43C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwLoadKey2 [0xF5C1A44E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwNotifyChangeKey [0xF5C1B030]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenEvent [0xF5C1CBE2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenFile [0xF5C1BB08]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenKey [0xF5C1A604]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenMutant [0xF5C1CAB0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenProcess [0xF5C1B56E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenSection [0xF5C1E438]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenSemaphore [0xF5C1CD14]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenThread [0xF5C1B492]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueryKey [0xF5C1AF8E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueryMultipleValueKey [0xF5C1ABB6]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueryValueKey [0xF5C1A8BC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueueApcThread [0xF5C1E128]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwRenameKey [0xF5C1AB34]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwReplaceKey [0xF5C1A0C2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwReplyPort [0xF5C1D09E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwReplyWaitReceivePort [0xF5C1CF64]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwRequestWaitReplyPort [0xF5C1DC30]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwRestoreKey [0xF5C1A224]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwResumeThread [0xF5C1E860]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSaveKey [0xF5C19EC4]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSecureConnectPort [0xF5C1C312]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetContextThread [0xF5C1B984]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetInformationToken [0xF5C1D5F2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetSecurityObject [0xF5C1DFA0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetSystemInformation [0xF5C1E4C2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetValueKey [0xF5C1A744]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSuspendProcess [0xF5C1E5A6]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSuspendThread [0xF5C1E6D2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSystemDebugControl [0xF5C1DDD2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwTerminateProcess [0xF5C1B6EA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwTerminateThread [0xF5C1B63C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwWriteVirtualMemory [0xF5C1B7C8]

Code \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) FsRtlCheckLockForReadAccess
Code \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) IoIsOperationSynchronous

---- Kernel code sections - GMER 1.0.15 ----

.text ntoskrnl.exe!_abnormal_termination + 114 804E2770 16 Bytes [02, B1, C1, F5, 72, CC, C1, ...]
.text ntoskrnl.exe!_abnormal_termination + 15C 804E27B8 4 Bytes JMP 66D91D7E
.text ntoskrnl.exe!_abnormal_termination + 1D9 804E2835 3 Bytes [A4, C1, F5]
.text ntoskrnl.exe!_abnormal_termination + 34C 804E29A8 16 Bytes [34, AB, C1, F5, C2, A0, C1, ...]
.text ntoskrnl.exe!_abnormal_termination + 384 804E29E0 8 Bytes CALL 1F131FA6
.text ...
.text ntoskrnl.exe!IoIsOperationSynchronous 804E8752 5 Bytes JMP F5C107DE \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)
.text ntoskrnl.exe!FsRtlCheckLockForReadAccess 80503C29 5 Bytes JMP F5C10424 \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)

---- User code sections - GMER 1.0.15 ----

.text C:\Program Files\Internet Explorer\iexplore.exe[2260] USER32.dll!CreateWindowExW 77D51AD5 5 Bytes JMP 3E2ED67C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2260] USER32.dll!DialogBoxParamW 77D56702 5 Bytes JMP 3E215435 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2260] USER32.dll!DialogBoxParamA 77D588E1 5 Bytes JMP 3E3E412C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2260] USER32.dll!DialogBoxIndirectParamW 77D62598 5 Bytes JMP 3E3E418F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2260] USER32.dll!MessageBoxIndirectA 77D6AEF1 5 Bytes JMP 3E3E40C1 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2260] USER32.dll!MessageBoxExW 77D80559 5 Bytes JMP 3E3E3F92 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2260] USER32.dll!MessageBoxExA 77D8057D 5 Bytes JMP 3E3E3FF4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2260] USER32.dll!DialogBoxIndirectParamA 77D86CED 5 Bytes JMP 3E3E41F2 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2260] USER32.dll!MessageBoxIndirectW 77D960B7 5 Bytes JMP 3E3E4056 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2608] USER32.dll!CallNextHookEx 77D4ED6E 5 Bytes JMP 3E2DCE79 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2608] USER32.dll!CreateWindowExW 77D51AD5 5 Bytes JMP 3E2ED67C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2608] USER32.dll!DialogBoxParamW 77D56702 5 Bytes JMP 3E215435 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2608] USER32.dll!DialogBoxParamA 77D588E1 5 Bytes JMP 3E3E412C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2608] USER32.dll!DialogBoxIndirectParamW 77D62598 5 Bytes JMP 3E3E418F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2608] USER32.dll!MessageBoxIndirectA 77D6AEF1 5 Bytes JMP 3E3E40C1 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2608] USER32.dll!SetWindowsHookExW 77D6E621 5 Bytes JMP 3E2E97F5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2608] USER32.dll!UnhookWindowsHookEx 77D6F29F 5 Bytes JMP 3E25466C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2608] USER32.dll!MessageBoxExW 77D80559 5 Bytes JMP 3E3E3F92 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2608] USER32.dll!MessageBoxExA 77D8057D 5 Bytes JMP 3E3E3FF4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2608] USER32.dll!DialogBoxIndirectParamA 77D86CED 5 Bytes JMP 3E3E41F2 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2608] USER32.dll!MessageBoxIndirectW 77D960B7 5 Bytes JMP 3E3E4056 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2608] ole32.dll!OleLoadFromStream 77518C62 5 Bytes JMP 3E3E44F7 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2608] ole32.dll!CoCreateInstance 77526009 5 Bytes JMP 3E2ED6D8 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3900] USER32.dll!CallNextHookEx 77D4ED6E 5 Bytes JMP 3E2DCE79 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3900] USER32.dll!CreateWindowExW 77D51AD5 5 Bytes JMP 3E2ED67C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3900] USER32.dll!DialogBoxParamW 77D56702 5 Bytes JMP 3E215435 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3900] USER32.dll!DialogBoxParamA 77D588E1 5 Bytes JMP 3E3E412C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3900] USER32.dll!DialogBoxIndirectParamW 77D62598 5 Bytes JMP 3E3E418F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3900] USER32.dll!MessageBoxIndirectA 77D6AEF1 5 Bytes JMP 3E3E40C1 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3900] USER32.dll!SetWindowsHookExW 77D6E621 5 Bytes JMP 3E2E97F5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3900] USER32.dll!UnhookWindowsHookEx 77D6F29F 5 Bytes JMP 3E25466C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3900] USER32.dll!MessageBoxExW 77D80559 5 Bytes JMP 3E3E3F92 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3900] USER32.dll!MessageBoxExA 77D8057D 5 Bytes JMP 3E3E3FF4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3900] USER32.dll!DialogBoxIndirectParamA 77D86CED 5 Bytes JMP 3E3E41F2 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3900] USER32.dll!MessageBoxIndirectW 77D960B7 5 Bytes JMP 3E3E4056 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3900] ole32.dll!OleLoadFromStream 77518C62 5 Bytes JMP 3E3E44F7 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3900] ole32.dll!CoCreateInstance 77526009 5 Bytes JMP 3E2ED6D8 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)

---- Kernel IAT/EAT - GMER 1.0.15 ----

IAT \SystemRoot\system32\DRIVERS\tcpip.sys[ntoskrnl.exe!IoCreateDevice] [F70946D0] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[TDI.SYS!TdiRegisterDeviceObject] [F7094820] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\system32\DRIVERS\netbt.sys[ntoskrnl.exe!IoCreateDevice] [F70946D0] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\system32\DRIVERS\netbt.sys[TDI.SYS!TdiRegisterDeviceObject] [F7094820] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\System32\drivers\afd.sys[ntoskrnl.exe!IoCreateDevice] [F70946D0] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\system32\DRIVERS\netbios.sys[ntoskrnl.exe!IoCreateDevice] [F70946D0] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\system32\DRIVERS\rdbss.sys[ntoskrnl.exe!IoCreateDevice] [F70946D0] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\system32\DRIVERS\mrxsmb.sys[ntoskrnl.exe!IoCreateDevice] [F70946D0] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\System32\Drivers\Fips.SYS[ntoskrnl.exe!IoCreateDevice] [F70946D0] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\system32\DRIVERS\ipnat.sys[ntoskrnl.exe!IoCreateDevice] [F70946D0] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[ntoskrnl.exe!IoCreateDevice] [F70946D0] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\System32\Drivers\Cdfs.SYS[ntoskrnl.exe!IoCreateDevice] [F70946D0] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\system32\DRIVERS\USBSTOR.SYS[ntoskrnl.exe!IoCreateDevice] [F70946D0] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[ntoskrnl.exe!IoCreateDevice] [F70946D0] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\system32\drivers\wdmaud.sys[ntoskrnl.exe!IoCreateDevice] [F70946D0] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\system32\drivers\sysaudio.sys[ntoskrnl.exe!IoCreateDevice] [F70946D0] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\system32\DRIVERS\mrxdav.sys[ntoskrnl.exe!IoCreateDevice] [F70946D0] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\System32\Drivers\ParVdm.SYS[ntoskrnl.exe!IoCreateDevice] [F70946D0] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\system32\DRIVERS\srv.sys[ntoskrnl.exe!IoCreateDevice] [F70946D0] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\System32\Drivers\HTTP.sys[ntoskrnl.exe!IoCreateDevice] [F70946D0] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\system32\drivers\kmixer.sys[ntoskrnl.exe!IoCreateDevice] [F70946D0] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)

---- User IAT/EAT - GMER 1.0.15 ----

IAT C:\Program Files\Internet Explorer\iexplore.exe[2608] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [451F1ACB] C:\Program Files\Internet Explorer\xpshims.dll (Internet Explorer Compatibility Shims for XP/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3900] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [451F1ACB] C:\Program Files\Internet Explorer\xpshims.dll (Internet Explorer Compatibility Shims for XP/Microsoft Corporation)

---- Devices - GMER 1.0.15 ----

AttachedDevice \Driver\Tcpip \Device\Ip kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \Driver\Tcpip \Device\Tcp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \Driver\Tcpip \Device\Udp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \Driver\Tcpip \Device\RawIp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

---- Registry - GMER 1.0.15 ----

Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System@OODEFRAG12.00.00.01PROFESSIONAL 209A3FF9D0F0B958FC04EDD7EF024E7669D189B021F6C260FC18BFC3D92DB22EB88303C5D50A30616C9EC04F23C959A7F226D970815D3BB137F36E4696DA888C90717CA9EAF89F9E679E4C623F2057A2312CA9FA27082D3DB49B7594FBE53420A8FDFC539FAB59B794B12BD98A54F97790BE82512C47C720C73DE9881B407E2BD6C747989854643B6E8570A2FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933C038D530D6EB3452A6A0AC4980AC7933FEBC9E127BECC74C14210123A904576AB2953B943DA494C03463B9DC39DBED39C3B7D4C8AB1CB3DE4080B50499458231B6E95D89A4AB296035EC7228082C6A166C6C6C94DD5406521E66850B3899985260327C018A9EC30DA94AB06AE10A30BE35B17B896CEB5481355D71D252B793F94BB7D9DF61C52E8CE0A60FEF7EED75B0C6B3997D752CE1439FB32E5C8C59E6F62889E4EFF06BA4C7C272DCEB6AD4650E59E2942B6963E5938E7AA588D9BDF23EBC7C465B5260D8CBC6619D7304BE1D1D3C76EA310C638B8F43087620852792E6DE265733757770C87BEC0A7F01312F48D0655212F880F1FB16F7F0CF2DDC10ADFA6227ED9D09021500CF8C6DE7B4209B0F6FB2339916AB3D72A61BA5C228ABF1145178E1DF719DA78A0B457F9455EBC97E93A960B07FC0E057B72F9

---- EOF - GMER 1.0.15 ----


•New Rsit log:

Log:

Logfile of random's system information tool 1.06 (written by random/random)
Run by user at 2009-11-05 18:23:37
Microsoft Windows XP Professional Service Pack 2
System drive C: has 6 GB (42%) free of 15 GB
Total RAM: 479 MB (31% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:23:39, on 05/11/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\KeyScrambler\KeyScrambler.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtblfs.exe
F:\RSIT.exe
C:\Program Files\trend micro\user.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: QFX Software KeyScrambler - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [avp] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: &Virtual keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O9 - Extra button: (no name) - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O9 - Extra 'Tools' menuitem: &KeyScrambler... - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1256467696781
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1256467669250
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
O20 - Winlogon Notify: KeyScrambler - C:\WINDOWS\SYSTEM32\KeyScramblerLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

--
End of file - 5865 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\RegCure.job
C:\WINDOWS\tasks\RegCure Startup.job
C:\WINDOWS\tasks\RegCure Program Check.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{71DA9882-EFFC-423C-B0D4-4018C41983FD}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}]
IDMIEHlprObj Class - C:\Program Files\Internet Download Manager\IDMIECC.dll [2009-05-07 169392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2B9F5787-88A5-4945-90E7-C4B18563BC5E}]
KeyScramblerBHO Class - C:\Program Files\KeyScrambler\KeyScramblerIE.dll [2009-10-17 829928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C}]
IEVkbdBHO Class - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll [2009-07-03 68112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-20 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E33CF602-D945-461A-83F0-819F76A199F8}]
FilterBHO Class - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll [2009-10-19 264720]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-10-20 73728]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avp"=C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe [2009-07-03 303376]
"WinampAgent"=C:\Program Files\Winamp\winampa.exe [2009-07-01 37888]
"Malwarebytes Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2009-09-10 1312080]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2005-06-14 15360]
"IDMan"=C:\Program Files\Internet Download Manager\IDMan.exe [2009-10-21 2815408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\KeyScrambler]
C:\WINDOWS\system32\KeyScramblerLogon.dll [2008-11-21 109032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
C:\WINDOWS\system32\klogon.dll [2009-07-03 219664]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\WINDOWS\System32\ZoneLabs\vsmon.exe"="C:\WINDOWS\System32\ZoneLabs\vsmon.exe:*:Enabled:TrueVector Service"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======List of files/folders created in the last 1 months======

2009-11-05 18:23:37 ----D---- C:\rsit
2009-11-05 15:14:39 ----D---- C:\Documents and Settings\user\Application Data\Malwarebytes
2009-11-05 15:14:28 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-11-05 15:14:16 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-11-05 10:09:35 ----D---- C:\Program Files\InstaTrader-Demo
2009-11-04 18:23:53 ----D---- C:\Program Files\trend micro
2009-11-04 11:50:17 ----D---- C:\Program Files\WSS Package
2009-11-01 17:10:17 ----D---- C:\Program Files\InstaTrader
2009-10-27 18:55:14 ----D---- C:\WINDOWS\system32\XPSViewer
2009-10-27 18:55:10 ----D---- C:\Program Files\MSBuild
2009-10-27 18:55:00 ----D---- C:\Program Files\Reference Assemblies
2009-10-27 18:54:24 ----N---- C:\WINDOWS\system32\xpsshhdr.dll
2009-10-27 18:54:24 ----N---- C:\WINDOWS\system32\prntvpt.dll
2009-10-27 18:54:23 ----N---- C:\WINDOWS\system32\xpssvcs.dll
2009-10-27 18:47:19 ----HD---- C:\WINDOWS\$NtUninstallWIC$
2009-10-27 18:47:07 ----D---- C:\Program Files\MSXML 6.0
2009-10-27 10:02:20 ----D---- C:\Documents and Settings\user\Application Data\Media Player Classic
2009-10-26 19:49:58 ----D---- C:\WINDOWS\ServicePackFiles
2009-10-26 19:49:07 ----D---- C:\WINDOWS\ie8updates
2009-10-26 19:47:19 ----D---- C:\Program Files\MSXML 4.0
2009-10-26 15:51:24 ----HD---- C:\WINDOWS\PIF
2009-10-26 13:39:48 ----A---- C:\WINDOWS\system32\mucltui.dll.mui
2009-10-26 13:39:44 ----A---- C:\WINDOWS\system32\mucltui.dll
2009-10-26 13:29:21 ----N---- C:\WINDOWS\system32\tzchange.exe
2009-10-25 18:34:32 ----D---- C:\WINDOWS\system32\CatRoot_bak
2009-10-25 18:30:33 ----D---- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2009-10-25 18:13:01 ----D---- C:\WINDOWS\system32\PreInstall
2009-10-25 18:12:59 ----HD---- C:\WINDOWS\$hf_mig$
2009-10-25 17:49:37 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2009-10-25 17:49:37 ----A---- C:\WINDOWS\system32\wups2.dll
2009-10-25 17:49:37 ----A---- C:\WINDOWS\system32\wucltui.dll.mui
2009-10-25 17:49:36 ----A---- C:\WINDOWS\system32\wuaueng.dll.mui
2009-10-25 17:49:35 ----A---- C:\WINDOWS\system32\wuapi.dll.mui
2009-10-25 17:31:27 ----HD---- C:\WINDOWS\ie8
2009-10-25 17:30:29 ----D---- C:\Program Files\Microsoft Silverlight
2009-10-25 15:15:56 ----SHD---- C:\FOUND.001
2009-10-24 18:22:48 ----RSD---- C:\WINDOWS\assembly
2009-10-24 18:21:35 ----D---- C:\WINDOWS\Microsoft.NET
2009-10-24 18:08:23 ----D---- C:\Program Files\Forex Strategy Builder
2009-10-23 10:32:31 ----D---- C:\Program Files\Common Files\NSV
2009-10-23 10:23:14 ----D---- C:\Program Files\Winamp
2009-10-22 22:31:02 ----SHD---- C:\FOUND.000
2009-10-22 21:42:01 ----N---- C:\WINDOWS\system32\pxcpya64.exe
2009-10-22 21:42:00 ----N---- C:\WINDOWS\system32\pxsfs.dll
2009-10-22 21:42:00 ----N---- C:\WINDOWS\system32\pxinsa64.exe
2009-10-22 21:42:00 ----N---- C:\WINDOWS\system32\pxafs.dll
2009-10-22 21:41:50 ----D---- C:\Documents and Settings\user\Application Data\Winamp
2009-10-21 22:09:35 ----D---- C:\Documents and Settings\user\Application Data\IDM
2009-10-21 22:09:34 ----D---- C:\Documents and Settings\user\Application Data\DMCache
2009-10-21 22:09:19 ----D---- C:\Program Files\Internet Download Manager
2009-10-20 13:13:12 ----D---- C:\Program Files\FLV Player
2009-10-20 12:48:40 ----D---- C:\Program Files\PowerArchiver
2009-10-20 12:35:55 ----D---- C:\Documents and Settings\All Users\Application Data\ConeXware
2009-10-20 10:47:52 ----A---- C:\WINDOWS\system32\javaws.exe
2009-10-20 10:47:51 ----A---- C:\WINDOWS\system32\javaw.exe
2009-10-20 10:47:51 ----A---- C:\WINDOWS\system32\java.exe
2009-10-20 10:47:22 ----D---- C:\Program Files\Java
2009-10-19 20:30:08 ----D---- C:\Program Files\Kaspersky Lab
2009-10-19 20:30:08 ----D---- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2009-10-19 20:29:06 ----D---- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-10-19 20:24:24 ----A---- C:\WINDOWS\system32\wininet.dll
2009-10-19 20:24:24 ----A---- C:\WINDOWS\system32\shdocvw.dll
2009-10-19 20:24:24 ----A---- C:\WINDOWS\system32\pngfilt.dll
2009-10-19 20:24:24 ----A---- C:\WINDOWS\system32\occache.dll
2009-10-19 20:24:24 ----A---- C:\WINDOWS\system32\mstime.dll
2009-10-19 20:24:24 ----A---- C:\WINDOWS\system32\msrating.dll
2009-10-19 20:24:24 ----A---- C:\WINDOWS\system32\msls31.dll
2009-10-19 20:24:24 ----A---- C:\WINDOWS\system32\mshtmler.dll
2009-10-19 20:24:24 ----A---- C:\WINDOWS\system32\mshtmled.dll
2009-10-19 20:24:24 ----A---- C:\WINDOWS\system32\mshtml.dll
2009-10-19 20:24:24 ----A---- C:\WINDOWS\system32\mshta.exe
2009-10-19 20:24:24 ----A---- C:\WINDOWS\system32\licmgr10.dll
2009-10-19 20:24:24 ----A---- C:\WINDOWS\system32\jsproxy.dll
2009-10-19 20:24:24 ----A---- C:\WINDOWS\system32\jscript.dll
2009-10-19 20:24:24 ----A---- C:\WINDOWS\system32\inseng.dll
2009-10-19 20:24:24 ----A---- C:\WINDOWS\system32\imgutil.dll
2009-10-19 17:10:12 ----D---- C:\WINDOWS\Sun
2009-10-19 15:52:54 ----A---- C:\WINDOWS\system32\deploytk.dll
2009-10-19 15:46:02 ----D---- C:\Documents and Settings\user\Application Data\Sun
2009-10-19 05:40:39 ----D---- C:\Documents and Settings\user\Application Data\mIRC
2009-10-19 05:40:38 ----D---- C:\Program Files\mIRC
2009-10-18 21:25:30 ----D---- C:\WINDOWS\WBEM
2009-10-18 21:25:02 ----A---- C:\WINDOWS\system32\spupdsvc.exe
2009-10-18 21:24:10 ----D---- C:\WINDOWS\system32\en-US
2009-10-18 21:23:00 ----HD---- C:\WINDOWS\msdownld.tmp
2009-10-17 20:42:38 ----A---- C:\WINDOWS\system32\homepage.txt
2009-10-17 19:26:57 ----D---- C:\WINDOWS\system32\ZoneLabs
2009-10-17 19:25:55 ----D---- C:\WINDOWS\Internet Logs
2009-10-17 16:43:16 ----D---- C:\Program Files\KeyScrambler
2009-10-17 15:22:50 ----D---- C:\Program Files\CCleaner
2009-10-16 18:59:44 ----D---- C:\Documents and Settings\All Users\Application Data\Kaspersky SDK
2009-10-16 18:46:16 ----D---- C:\Program Files\Perfect Uninstaller
2009-10-16 18:45:28 ----D---- C:\Program Files\RegCure
2009-10-16 18:45:28 ----D---- C:\Documents and Settings\All Users\Application Data\RegCure
2009-10-16 17:34:00 ----D---- C:\Program Files\WGA
2009-10-16 17:28:05 ----D---- C:\Program Files\Novativa Streamster
2009-10-16 15:36:38 ----D---- C:\Documents and Settings\user\Application Data\Mozilla
2009-10-16 15:35:41 ----D---- C:\Program Files\Mozilla Firefox
2009-10-16 15:34:40 ----D---- C:\Documents and Settings\All Users\Application Data\Yahoo!
2009-10-16 15:34:36 ----D---- C:\Program Files\Yahoo!
2009-10-16 15:06:35 ----D---- C:\Documents and Settings\All Users\Application Data\InstallShield
2009-10-16 15:01:28 ----A---- C:\WINDOWS\system32\msisip.dll
2009-10-16 15:01:28 ----A---- C:\WINDOWS\system32\msimsg.dll
2009-10-16 15:01:28 ----A---- C:\WINDOWS\system32\msihnd.dll
2009-10-16 15:01:28 ----A---- C:\WINDOWS\system32\msiexec.exe
2009-10-16 15:01:28 ----A---- C:\WINDOWS\system32\msi.dll
2009-10-16 14:53:43 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe Systems
2009-10-16 14:52:51 ----D---- C:\Program Files\Common Files\Adobe Systems Shared
2009-10-16 14:46:59 ----SHD---- C:\Recycled
2009-10-16 14:36:22 ----D---- C:\Documents and Settings\user\Application Data\Macromedia
2009-10-16 14:36:21 ----D---- C:\Documents and Settings\user\Application Data\Adobe
2009-10-16 14:34:10 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2009-10-16 14:34:03 ----D---- C:\Program Files\Common Files\Adobe
2009-10-16 14:34:03 ----D---- C:\Program Files\Adobe
2009-10-16 14:32:32 ----D---- C:\Program Files\Common Files\ACD Systems
2009-10-16 14:32:06 ----D---- C:\WINDOWS\Downloaded Installations
2009-10-16 14:29:30 ----D---- C:\WINDOWS\system32\QuickTime
2009-10-16 14:29:30 ----A---- C:\WINDOWS\system32\qtmlClient.dll
2009-10-16 14:29:27 ----D---- C:\WINDOWS\RegisteredPackages
2009-10-16 14:29:26 ----A---- C:\WINDOWS\system32\rmoc3260.dll
2009-10-16 14:29:26 ----A---- C:\WINDOWS\system32\pndx5032.dll
2009-10-16 14:29:26 ----A---- C:\WINDOWS\system32\pndx5016.dll
2009-10-16 14:29:26 ----A---- C:\WINDOWS\system32\pncrt.dll
2009-10-16 14:29:25 ----A---- C:\WINDOWS\system32\vp6vfw.dll
2009-10-16 14:29:25 ----A---- C:\WINDOWS\system32\vp31vfw.dll
2009-10-16 14:29:25 ----A---- C:\WINDOWS\system32\MACDec.dll
2009-10-16 14:29:22 ----A---- C:\WINDOWS\system32\xvidvfw.dll
2009-10-16 14:29:22 ----A---- C:\WINDOWS\system32\xvidcore.dll
2009-10-16 14:29:22 ----A---- C:\WINDOWS\system32\vsfilter.dll
2009-10-16 14:29:22 ----A---- C:\WINDOWS\system32\vorbisfile.dll
2009-10-16 14:29:22 ----A---- C:\WINDOWS\system32\vorbisenc.dll
2009-10-16 14:29:22 ----A---- C:\WINDOWS\system32\vorbis.dll
2009-10-16 14:29:22 ----A---- C:\WINDOWS\system32\vobsub.dll
2009-10-16 14:29:22 ----A---- C:\WINDOWS\system32\unrar.dll
2009-10-16 14:29:22 ----A---- C:\WINDOWS\system32\OpenQuicktimeLib.dll
2009-10-16 14:29:22 ----A---- C:\WINDOWS\system32\OggDS.dll
2009-10-16 14:29:22 ----A---- C:\WINDOWS\system32\ogg.dll
2009-10-16 14:29:22 ----A---- C:\WINDOWS\system32\mpg4c32.dll
2009-10-16 14:29:22 ----A---- C:\WINDOWS\system32\huffyuv.dll
2009-10-16 14:29:22 ----A---- C:\WINDOWS\system32\3ivxVfWCodec.dll
2009-10-16 14:29:22 ----A---- C:\WINDOWS\system32\3ivx.dll
2009-10-16 14:29:21 ----A---- C:\WINDOWS\system32\WMV9VCM.dll
2009-10-16 14:29:21 ----A---- C:\WINDOWS\system32\divx.dll
2009-10-16 14:29:20 ----D---- C:\Program Files\K-Lite Codec Pack
2009-10-16 14:29:20 ----D---- C:\Documents and Settings\user\Application Data\Real
2009-10-16 14:29:20 ----D---- C:\Documents and Settings\All Users\Application Data\Real
2009-10-16 14:29:20 ----A---- C:\WINDOWS\system32\unicows.dll
2009-10-16 14:29:20 ----A---- C:\WINDOWS\system32\cpuinf32.dll
2009-10-16 14:27:19 ----N---- C:\WINDOWS\system32\vxblock.dll
2009-10-16 14:27:19 ----N---- C:\WINDOWS\system32\pxwave.dll
2009-10-16 14:27:19 ----N---- C:\WINDOWS\system32\pxmas.dll
2009-10-16 14:27:19 ----N---- C:\WINDOWS\system32\pxhpinst.exe
2009-10-16 14:27:19 ----N---- C:\WINDOWS\system32\pxdrv.dll
2009-10-16 14:27:18 ----N---- C:\WINDOWS\system32\px.dll
2009-10-16 14:21:49 ----A---- C:\WINDOWS\ODBC.INI
2009-10-16 14:21:44 ----A---- C:\WINDOWS\system32\mdimon.dll
2009-10-16 14:21:02 ----D---- C:\Program Files\Common Files\L&H
2009-10-16 14:20:51 ----D---- C:\Program Files\Microsoft.NET
2009-10-16 14:20:41 ----D---- C:\Program Files\Microsoft ActiveSync
2009-10-16 14:20:08 ----D---- C:\Program Files\Common Files\DESIGNER
2009-10-16 14:16:48 ----D---- C:\Program Files\Microsoft Works
2009-10-16 14:16:33 ----D---- C:\Program Files\Microsoft Visual Studio
2009-10-16 14:16:04 ----D---- C:\WINDOWS\SHELLNEW
2009-10-16 14:15:51 ----D---- C:\Program Files\Microsoft Office
2009-10-16 14:09:01 ----RA---- C:\WINDOWS\system32\udaprop.dll
2009-10-16 14:09:01 ----RA---- C:\WINDOWS\system32\cmuda.dll
2009-10-16 14:09:01 ----RA---- C:\WINDOWS\system32\cmirmdrv.exe
2009-10-16 14:09:01 ----RA---- C:\WINDOWS\system32\cmirmdrv.dll
2009-10-16 14:09:01 ----RA---- C:\WINDOWS\system32\Audio3D.dll
2009-10-16 14:09:01 ----RA---- C:\WINDOWS\system32\a3d.dll
2009-10-16 14:09:00 ----A---- C:\WINDOWS\system32\ksuser.dll
2009-10-16 14:08:52 ----A---- C:\WINDOWS\CMISETUP.INI
2009-10-16 14:08:51 ----A---- C:\WINDOWS\CMCDPLAY.INI
2009-10-16 14:08:49 ----A---- C:\WINDOWS\Wininit.ini
2009-10-16 14:08:45 ----R---- C:\WINDOWS\Cmuda.ini
2009-10-16 14:08:39 ----D---- C:\Program Files\C-Media 3D Audio
2009-10-16 14:08:39 ----A---- C:\WINDOWS\CMIUninstall.exe
2009-10-16 14:08:39 ----A---- C:\WINDOWS\CmiRmRedundDir.exe
2009-10-16 14:08:39 ----A---- C:\WINDOWS\CMIRmDriver.dll
2009-10-16 14:05:54 ----RA---- C:\WINDOWS\system32\VTuninst.exe
2009-10-16 14:05:54 ----RA---- C:\WINDOWS\system32\VTTimer.exe
2009-10-16 14:05:54 ----RA---- C:\WINDOWS\system32\VTovrlay.dll
2009-10-16 14:05:54 ----RA---- C:\WINDOWS\system32\VTInfo2.dll
2009-10-16 14:05:53 ----RA---- C:\WINDOWS\system32\VTGamma2.dll
2009-10-16 14:05:52 ----RA---- C:\WINDOWS\system32\VTDisply.dll
2009-10-16 14:05:51 ----RA---- C:\WINDOWS\system32\vticd.dll
2009-10-16 14:05:49 ----RA---- C:\WINDOWS\system32\vtdisp.dll
2009-10-16 14:05:45 ----D---- C:\Program Files\S3
2009-10-16 14:02:37 ----D---- C:\WINDOWS\system32\ReinstallBackups
2009-10-16 14:00:54 ----A---- C:\WINDOWS\IsUninst.exe
2009-10-16 14:00:20 ----HD---- C:\Program Files\InstallShield Installation Information
2009-10-16 14:00:01 ----D---- C:\WINDOWS\system32\Tools
2009-10-16 13:59:54 ----D---- C:\Program Files\Common Files\InstallShield
2009-10-16 13:59:12 ----RA---- C:\DBI.EXE
2009-10-16 13:54:49 ----D---- C:\Documents and Settings\user\Application Data\Identities
2009-10-16 13:54:48 ----HD---- C:\Program Files\Uninstall Information
2009-10-16 13:54:40 ----SD---- C:\Documents and Settings\user\Application Data\Microsoft
2009-10-16 13:54:40 ----ASH---- C:\Documents and Settings\user\Application Data\desktop.ini
2009-10-16 13:54:05 ----SHD---- C:\System Volume Information
2009-10-16 13:54:05 ----D---- C:\WINDOWS\SoftwareDistribution
2009-10-16 13:54:04 ----SD---- C:\WINDOWS\system32\Microsoft
2009-10-16 13:54:04 ----N---- C:\WINDOWS\SchedLgU.Txt
2009-10-16 13:54:04 ----D---- C:\WINDOWS\Prefetch
2009-10-16 13:47:57 ----D---- C:\WINDOWS\system32\xircom
2009-10-16 13:47:57 ----D---- C:\Program Files\xerox
2009-10-16 13:47:57 ----D---- C:\Program Files\windows media player
2009-10-16 13:47:57 ----D---- C:\Program Files\microsoft frontpage
2009-10-16 13:46:13 ----N---- C:\WINDOWS\system32\spmsg.dll
2009-10-16 13:46:10 ----A---- C:\WINDOWS\system32\xpsp3res.dll
2009-10-16 13:46:08 ----N---- C:\WINDOWS\system32\setupn.exe
2009-10-16 13:45:50 ----A---- C:\WINDOWS\control.ini
2009-10-16 13:45:50 ----A---- C:\AUTOEXEC.BAT
2009-10-16 13:45:44 ----A---- C:\WINDOWS\system32\mapi32.dll
2009-10-16 13:44:46 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-10-16 13:44:46 ----RD---- C:\WINDOWS\Offline Web Pages
2009-10-16 13:44:46 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest
2009-10-16 13:44:40 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest
2009-10-16 13:44:36 ----HD---- C:\Program Files\WindowsUpdate
2009-10-16 13:44:19 ----D---- C:\WINDOWS\system32\DirectX
2009-10-16 13:44:09 ----A---- C:\WINDOWS\system32\atrace.dll
2009-10-16 13:44:08 ----A---- C:\WINDOWS\system32\desktop.ini
2009-10-16 13:44:08 ----A---- C:\WINDOWS\desktop.ini
2009-10-16 13:44:03 ----A---- C:\WINDOWS\system32\nmevtmsg.dll
2009-10-16 13:44:02 ----A---- C:\WINDOWS\system32\acctres.dll
2009-10-16 13:44:01 ----D---- C:\Program Files\Common Files\Services
2009-10-16 13:44:00 ----SD---- C:\WINDOWS\Tasks
2009-10-16 13:44:00 ----A---- C:\WINDOWS\system32\icfgnt5.dll
2009-10-16 13:43:59 ----D---- C:\Program Files\Common Files\MSSoap
2009-10-16 13:43:56 ----D---- C:\WINDOWS\srchasst
2009-10-16 13:43:55 ----D---- C:\WINDOWS\system32\Macromed
2009-10-16 13:43:55 ----A---- C:\WINDOWS\system32\wuweb.dll
2009-10-16 13:43:55 ----A---- C:\WINDOWS\system32\wups.dll
2009-10-16 13:43:55 ----A---- C:\WINDOWS\system32\wucltui.dll
2009-10-16 13:43:55 ----A---- C:\WINDOWS\system32\wuauserv.dll
2009-10-16 13:43:55 ----A---- C:\WINDOWS\system32\wuaueng1.dll
2009-10-16 13:43:55 ----A---- C:\WINDOWS\system32\wuaueng.dll
2009-10-16 13:43:55 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2009-10-16 13:43:55 ----A---- C:\WINDOWS\system32\wuauclt.exe
2009-10-16 13:43:55 ----A---- C:\WINDOWS\system32\wuapi.dll
2009-10-16 13:43:54 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
2009-10-16 13:43:54 ----A---- C:\WINDOWS\system32\qmgr.dll
2009-10-16 13:43:54 ----A---- C:\WINDOWS\system32\bitsprx3.dll
2009-10-16 13:43:54 ----A---- C:\WINDOWS\system32\bitsprx2.dll
2009-10-16 13:43:51 ----SHD---- C:\Program Files\Movie Maker
2009-10-16 13:43:48 ----A---- C:\WINDOWS\system32\safrslv.dll
2009-10-16 13:43:48 ----A---- C:\WINDOWS\system32\safrdm.dll
2009-10-16 13:43:48 ----A---- C:\WINDOWS\system32\safrcdlg.dll
2009-10-16 13:43:48 ----A---- C:\WINDOWS\system32\racpldlg.dll
2009-10-16 13:43:45 ----D---- C:\WINDOWS\system32\Restore
2009-10-16 13:43:45 ----A---- C:\WINDOWS\system32\srsvc.dll
2009-10-16 13:43:45 ----A---- C:\WINDOWS\system32\srrstr.dll
2009-10-16 13:43:45 ----A---- C:\WINDOWS\system32\srclient.dll
2009-10-16 13:43:45 ----A---- C:\WINDOWS\system32\fltMc.exe
2009-10-16 13:43:45 ----A---- C:\WINDOWS\system32\fltlib.dll
2009-10-16 13:43:44 ----A---- C:\WINDOWS\system32\nmmkcert.dll
2009-10-16 13:43:44 ----A---- C:\WINDOWS\system32\msconf.dll
2009-10-16 13:43:44 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2009-10-16 13:43:44 ----A---- C:\WINDOWS\system32\mnmdd.dll
2009-10-16 13:43:44 ----A---- C:\WINDOWS\system32\isrdbg32.dll
2009-10-16 13:43:44 ----A---- C:\WINDOWS\system32\ils.dll
2009-10-16 13:43:42 ----D---- C:\Program Files\NetMeeting
2009-10-16 13:43:42 ----A---- C:\WINDOWS\system32\msoert2.dll
2009-10-16 13:43:42 ----A---- C:\WINDOWS\system32\msoeacct.dll
2009-10-16 13:43:41 ----A---- C:\WINDOWS\system32\inetres.dll
2009-10-16 13:43:41 ----A---- C:\WINDOWS\system32\inetcomm.dll
2009-10-16 13:43:39 ----D---- C:\Program Files\Outlook Express
2009-10-16 13:43:39 ----A---- C:\WINDOWS\system32\schedsvc.dll
2009-10-16 13:43:39 ----A---- C:\WINDOWS\system32\mstinit.exe
2009-10-16 13:43:39 ----A---- C:\WINDOWS\system32\mstask.dll
2009-10-16 13:43:39 ----A---- C:\WINDOWS\system32\isign32.dll
2009-10-16 13:43:39 ----A---- C:\WINDOWS\system32\inetcfg.dll
2009-10-16 13:43:39 ----A---- C:\WINDOWS\system32\icwphbk.dll
2009-10-16 13:43:39 ----A---- C:\WINDOWS\system32\icwdial.dll
2009-10-16 13:43:35 ----D---- C:\Program Files\Common Files\System
2009-10-16 13:43:33 ----D---- C:\Program Files\Internet Explorer
2009-10-16 13:42:45 ----A---- C:\WINDOWS\vbaddin.ini
2009-10-16 13:42:45 ----A---- C:\WINDOWS\vb.ini
2009-10-16 13:42:41 ----D---- C:\WINDOWS\Registration
2009-10-16 13:42:34 ----D---- C:\Program Files\Online Services
2009-10-16 13:42:26 ----D---- C:\Program Files\Messenger
2009-10-16 13:42:23 ----D---- C:\Program Files\MSN Gaming Zone
2009-10-16 13:42:23 ----A---- C:\WINDOWS\system32\write.exe
2009-10-16 13:42:16 ----A---- C:\WINDOWS\system32\sndvol32.exe
2009-10-16 13:42:16 ----A---- C:\WINDOWS\system32\hticons.dll
2009-10-16 13:42:16 ----A---- C:\WINDOWS\system32\avwav.dll
2009-10-16 13:42:16 ----A---- C:\WINDOWS\system32\avtapi.dll
2009-10-16 13:42:16 ----A---- C:\WINDOWS\system32\avmeter.dll
2009-10-16 13:42:15 ----A---- C:\WINDOWS\system32\winchat.exe
2009-10-16 13:42:11 ----A---- C:\WINDOWS\system32\getuname.dll
2009-10-16 13:42:10 ----A---- C:\WINDOWS\system32\winmine.exe
2009-10-16 13:42:10 ----A---- C:\WINDOWS\system32\sol.exe
2009-10-16 13:42:10 ----A---- C:\WINDOWS\system32\mshearts.exe
2009-10-16 13:42:10 ----A---- C:\WINDOWS\system32\freecell.exe
2009-10-16 13:42:10 ----A---- C:\WINDOWS\system32\charmap.exe
2009-10-16 13:42:10 ----A---- C:\WINDOWS\system32\calc.exe
2009-10-16 13:42:09 ----A---- C:\WINDOWS\system32\usrlogon.cmd
2009-10-16 13:42:09 ----A---- C:\WINDOWS\system32\tsshutdn.exe
2009-10-16 13:42:09 ----A---- C:\WINDOWS\system32\tslabels.ini
2009-10-16 13:42:09 ----A---- C:\WINDOWS\system32\tskill.exe
2009-10-16 13:42:09 ----A---- C:\WINDOWS\system32\tsdiscon.exe
2009-10-16 13:42:09 ----A---- C:\WINDOWS\system32\tscon.exe
2009-10-16 13:42:09 ----A---- C:\WINDOWS\system32\shadow.exe
2009-10-16 13:42:09 ----A---- C:\WINDOWS\system32\rwinsta.exe
2009-10-16 13:42:09 ----A---- C:\WINDOWS\system32\reset.exe
2009-10-16 13:42:09 ----A---- C:\WINDOWS\system32\regini.exe
2009-10-16 13:42:09 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
2009-10-16 13:42:09 ----A---- C:\WINDOWS\system32\qwinsta.exe
2009-10-16 13:42:09 ----A---- C:\WINDOWS\system32\qappsrv.exe
2009-10-16 13:42:09 ----A---- C:\WINDOWS\system32\msg.exe
2009-10-16 13:42:09 ----A---- C:\WINDOWS\system32\logoff.exe
2009-10-16 13:42:09 ----A---- C:\WINDOWS\system32\cdmodem.dll
2009-10-16 13:42:08 ----A---- C:\WINDOWS\system32\mtxlegih.dll
2009-10-16 13:42:08 ----A---- C:\WINDOWS\system32\mtxex.dll
2009-10-16 13:42:08 ----A---- C:\WINDOWS\system32\mtxdm.dll
2009-10-16 13:42:08 ----A---- C:\WINDOWS\system32\msdtcprf.ini
2009-10-16 13:42:08 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2009-10-16 13:42:08 ----A---- C:\WINDOWS\system32\comrepl.dll
2009-10-16 13:42:08 ----A---- C:\WINDOWS\system32\comaddin.dll
2009-10-16 13:42:07 ----A---- C:\WINDOWS\system32\stclient.dll
2009-10-16 13:42:07 ----A---- C:\WINDOWS\system32\comsnap.dll
2009-10-16 13:42:04 ----A---- C:\WINDOWS\system32\wmimgmt.msc
2009-10-16 13:41:55 ----D---- C:\Program Files\MSN
2009-10-16 13:41:55 ----A---- C:\WINDOWS\system32\accwiz.exe
2009-10-16 13:41:54 ----D---- C:\Program Files\Windows NT
2009-10-16 13:41:54 ----A---- C:\WINDOWS\system32\sndrec32.exe
2009-10-16 13:41:54 ----A---- C:\WINDOWS\system32\mspaint.exe
2009-10-16 13:41:54 ----A---- C:\WINDOWS\system32\hypertrm.dll
2009-10-16 13:41:54 ----A---- C:\WINDOWS\system32\clipbrd.exe
2009-10-16 13:41:53 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
2009-10-16 13:41:53 ----A---- C:\WINDOWS\system32\spider.exe
2009-10-16 13:41:53 ----A---- C:\WINDOWS\system32\sessmgr.exe
2009-10-16 13:41:53 ----A---- C:\WINDOWS\system32\remotepg.dll
2009-10-16 13:41:53 ----A---- C:\WINDOWS\system32\rdshost.exe
2009-10-16 13:41:53 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2009-10-16 13:41:53 ----A---- C:\WINDOWS\system32\mstscax.dll
2009-10-16 13:41:53 ----A---- C:\WINDOWS\system32\mstsc.exe
2009-10-16 13:41:52 ----D---- C:\WINDOWS\system32\MsDtc
2009-10-16 13:41:52 ----A---- C:\WINDOWS\system32\tscupgrd.exe
2009-10-16 13:41:52 ----A---- C:\WINDOWS\system32\termsrv.dll
2009-10-16 13:41:52 ----A---- C:\WINDOWS\system32\rdpwsx.dll
2009-10-16 13:41:52 ----A---- C:\WINDOWS\system32\rdpsnd.dll
2009-10-16 13:41:52 ----A---- C:\WINDOWS\system32\rdpclip.exe
2009-10-16 13:41:52 ----A---- C:\WINDOWS\system32\rdchost.dll
2009-10-16 13:41:52 ----A---- C:\WINDOWS\system32\qprocess.exe
2009-10-16 13:41:52 ----A---- C:\WINDOWS\system32\mtxoci.dll
2009-10-16 13:41:52 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
2009-10-16 13:41:52 ----A---- C:\WINDOWS\system32\icaapi.dll
2009-10-16 13:41:52 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2009-10-16 13:41:51 ----A---- C:\WINDOWS\system32\xolehlp.dll
2009-10-16 13:41:51 ----A---- C:\WINDOWS\system32\msdtctm.dll
2009-10-16 13:41:51 ----A---- C:\WINDOWS\system32\msdtcprx.dll
2009-10-16 13:41:51 ----A---- C:\WINDOWS\system32\msdtclog.dll
2009-10-16 13:41:51 ----A---- C:\WINDOWS\system32\msdtc.exe
2009-10-16 13:41:50 ----D---- C:\WINDOWS\system32\Com
2009-10-16 13:41:50 ----A---- C:\WINDOWS\system32\comuid.dll
2009-10-16 13:41:50 ----A---- C:\WINDOWS\system32\comsvcs.dll
2009-10-16 13:41:50 ----A---- C:\WINDOWS\system32\colbact.dll
2009-10-16 13:41:50 ----A---- C:\WINDOWS\system32\clbcatex.dll
2009-10-16 13:41:50 ----A---- C:\WINDOWS\system32\catsrvut.dll
2009-10-16 13:41:50 ----A---- C:\WINDOWS\system32\catsrvps.dll
2009-10-16 13:41:50 ----A---- C:\WINDOWS\system32\catsrv.dll
2009-10-16 13:41:49 ----A---- C:\WINDOWS\system32\clbcatq.dll
2009-10-16 13:41:45 ----A---- C:\WINDOWS\system32\servdeps.dll
2009-10-16 13:41:45 ----A---- C:\WINDOWS\system32\mmfutil.dll
2009-10-16 13:41:45 ----A---- C:\WINDOWS\system32\licwmi.dll
2009-10-16 13:41:45 ----A---- C:\WINDOWS\system32\cmprops.dll
2009-10-16 13:38:25 ----A---- C:\WINDOWS\system32\h323log.txt
2009-10-16 13:32:19 ----A---- C:\WINDOWS\system32\usbui.dll
2009-10-16 13:31:17 ----SHD---- C:\WINDOWS\Installer
2009-10-16 13:31:17 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-10-16 13:31:16 ----D---- C:\Program Files\Common Files\ODBC
2009-10-16 13:31:16 ----A---- C:\WINDOWS\ODBCINST.INI
2009-10-16 13:31:13 ----RD---- C:\Program Files
2009-10-16 13:31:13 ----D---- C:\Program Files\Common Files\SpeechEngines
2009-10-16 13:31:13 ----D---- C:\Program Files\Common Files\Microsoft Shared
2009-10-16 13:31:13 ----D---- C:\Program Files\Common Files
2009-10-16 13:31:10 ----RA---- C:\WINDOWS\system32\kbdtuq.dll
2009-10-16 13:31:10 ----RA---- C:\WINDOWS\system32\kbdtuf.dll
2009-10-16 13:31:10 ----RA---- C:\WINDOWS\system32\kbdazel.dll
2009-10-16 13:31:09 ----RA---- C:\WINDOWS\system32\kbdycc.dll
2009-10-16 13:31:09 ----RA---- C:\WINDOWS\system32\kbduzb.dll
2009-10-16 13:31:09 ----RA---- C:\WINDOWS\system32\kbdur.dll
2009-10-16 13:31:09 ----RA---- C:\WINDOWS\system32\kbdtat.dll
2009-10-16 13:31:09 ----RA---- C:\WINDOWS\system32\kbdru1.dll
2009-10-16 13:31:09 ----RA---- C:\WINDOWS\system32\kbdru.dll
2009-10-16 13:31:09 ----RA---- C:\WINDOWS\system32\kbdmon.dll
2009-10-16 13:31:09 ----RA---- C:\WINDOWS\system32\kbdkyr.dll
2009-10-16 13:31:09 ----RA---- C:\WINDOWS\system32\kbdkaz.dll
2009-10-16 13:31:09 ----RA---- C:\WINDOWS\system32\kbdbu.dll
2009-10-16 13:31:09 ----RA---- C:\WINDOWS\system32\kbdblr.dll
2009-10-16 13:31:09 ----RA---- C:\WINDOWS\system32\kbdaze.dll
2009-10-16 13:31:07 ----RA---- C:\WINDOWS\system32\kbdhept.dll
2009-10-16 13:31:07 ----RA---- C:\WINDOWS\system32\kbdhela3.dll
2009-10-16 13:31:07 ----RA---- C:\WINDOWS\system32\kbdhela2.dll
2009-10-16 13:31:07 ----RA---- C:\WINDOWS\system32\kbdhe319.dll
2009-10-16 13:31:07 ----RA---- C:\WINDOWS\system32\kbdhe220.dll
2009-10-16 13:31:07 ----RA---- C:\WINDOWS\system32\kbdhe.dll
2009-10-16 13:31:07 ----RA---- C:\WINDOWS\system32\kbdgkl.dll
2009-10-16 13:31:06 ----RA---- C:\WINDOWS\system32\kbdlv1.dll
2009-10-16 13:31:06 ----RA---- C:\WINDOWS\system32\kbdlv.dll
2009-10-16 13:31:06 ----RA---- C:\WINDOWS\system32\kbdlt1.dll
2009-10-16 13:31:06 ----RA---- C:\WINDOWS\system32\kbdlt.dll
2009-10-16 13:31:06 ----RA---- C:\WINDOWS\system32\kbdest.dll
2009-10-16 13:31:05 ----RA---- C:\WINDOWS\system32\kbdycl.dll
2009-10-16 13:31:05 ----RA---- C:\WINDOWS\system32\kbdsl1.dll
2009-10-16 13:31:05 ----RA---- C:\WINDOWS\system32\kbdsl.dll
2009-10-16 13:31:05 ----RA---- C:\WINDOWS\system32\kbdro.dll
2009-10-16 13:31:05 ----RA---- C:\WINDOWS\system32\kbdpl1.dll
2009-10-16 13:31:05 ----RA---- C:\WINDOWS\system32\kbdpl.dll
2009-10-16 13:31:05 ----RA---- C:\WINDOWS\system32\kbdhu1.dll
2009-10-16 13:31:05 ----RA---- C:\WINDOWS\system32\kbdhu.dll
2009-10-16 13:31:05 ----RA---- C:\WINDOWS\system32\kbdcz2.dll
2009-10-16 13:31:05 ----RA---- C:\WINDOWS\system32\kbdcz1.dll
2009-10-16 13:31:05 ----RA---- C:\WINDOWS\system32\kbdcz.dll
2009-10-16 13:31:05 ----RA---- C:\WINDOWS\system32\kbdcr.dll
2009-10-16 13:31:05 ----RA---- C:\WINDOWS\system32\KBDAL.DLL
2009-10-16 13:31:03 ----A---- C:\WINDOWS\system32\irclass.dll
2009-10-16 13:31:03 ----A---- C:\WINDOWS\system32\dgsetup.dll
2009-10-16 13:31:03 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
2009-10-16 13:31:02 ----A---- C:\WINDOWS\system32\spxcoins.dll
2009-10-16 13:31:02 ----A---- C:\WINDOWS\system32\EqnClass.Dll
2009-10-16 13:31:01 ----N---- C:\WINDOWS\system32\CONFIG.TMP
2009-10-16 13:31:01 ----A---- C:\WINDOWS\TASKMAN.EXE
2009-10-16 13:31:00 ----A---- C:\WINDOWS\system32\batt.dll
2009-10-16 13:31:00 ----A---- C:\WINDOWS\NOTEPAD.EXE
2009-10-16 13:30:59 ----A---- C:\WINDOWS\system32\storprop.dll
2009-10-16 13:30:52 ----RA---- C:\WINDOWS\SET28.tmp
2009-10-16 13:30:52 ----ASH---- C:\Documents and Settings\All Users\Application Data\desktop.ini
2009-10-16 13:30:51 ----RA---- C:\WINDOWS\SET27.tmp
2009-10-16 13:30:48 ----RA---- C:\WINDOWS\SET8.tmp
2009-10-16 13:30:46 ----RA---- C:\WINDOWS\SET4.tmp
2009-10-16 13:30:44 ----RA---- C:\WINDOWS\SET3.tmp
2009-10-16 13:30:38 ----D---- C:\WINDOWS\system32\CatRoot2
2009-10-16 13:30:38 ----D---- C:\WINDOWS\system32\CatRoot
2009-10-16 13:30:33 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2009-10-16 13:30:12 ----D---- C:\Documents and Settings
2009-10-16 13:29:20 ----N---- C:\boot.ini
2009-10-16 13:24:16 ----RSHD---- C:\WINDOWS\system32\dllcache
2009-10-16 13:24:16 ----RSD---- C:\WINDOWS\Fonts
2009-10-16 13:24:16 ----RD---- C:\WINDOWS\Web
2009-10-16 13:24:16 ----HD---- C:\WINDOWS\inf
2009-10-16 13:24:16 ----D---- C:\WINDOWS\WinSxS
2009-10-16 13:24:16 ----D---- C:\WINDOWS\twain_32
2009-10-16 13:24:16 ----D---- C:\WINDOWS\Temp
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\wins
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\wbem
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\usmt
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\spool
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\ShellExt
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\Setup
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\ras
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\oobe
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\npp
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\mui
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\inetsrv
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\IME
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\icsxml
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\ias
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\export
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\drivers
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\dhcp
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\config
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\3com_dmi
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\3076
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\2052
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\1054
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\1042
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\1041
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\1037
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\1033
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\1031
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\1028
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\1025
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system
2009-10-16 13:24:16 ----D---- C:\WINDOWS\security
2009-10-16 13:24:16 ----D---- C:\WINDOWS\Resources
2009-10-16 13:24:16 ----D---- C:\WINDOWS\repair
2009-10-16 13:24:16 ----D---- C:\WINDOWS\Provisioning
2009-10-16 13:24:16 ----D---- C:\WINDOWS\PeerNet
2009-10-16 13:24:16 ----D---- C:\WINDOWS\pchealth
2009-10-16 13:24:16 ----D---- C:\WINDOWS\mui
2009-10-16 13:24:16 ----D---- C:\WINDOWS\msapps
2009-10-16 13:24:16 ----D---- C:\WINDOWS\msagent
2009-10-16 13:24:16 ----D---- C:\WINDOWS\Media
2009-10-16 13:24:16 ----D---- C:\WINDOWS\java
2009-10-16 13:24:16 ----D---- C:\WINDOWS\ime
2009-10-16 13:24:16 ----D---- C:\WINDOWS\Help
2009-10-16 13:24:16 ----D---- C:\WINDOWS\ehome
2009-10-16 13:24:16 ----D---- C:\WINDOWS\Driver Cache
2009-10-16 13:24:16 ----D---- C:\WINDOWS\Debug
2009-10-16 13:24:16 ----D---- C:\WINDOWS\Cursors
2009-10-16 13:24:16 ----D---- C:\WINDOWS\Connection Wizard
2009-10-16 13:24:16 ----D---- C:\WINDOWS\Config
2009-10-16 13:24:16 ----D---- C:\WINDOWS\AppPatch
2009-10-16 13:24:16 ----D---- C:\WINDOWS\addins
2009-10-16 13:24:16 ----D---- C:\WINDOWS

======List of files/folders modified in the last 1 months======

2009-11-04 12:44:28 ----A---- C:\WINDOWS\win.ini
2009-10-16 13:31:14 ----A---- C:\WINDOWS\system.ini

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AmdK7;AMD K7 Processor Driver; C:\WINDOWS\system32\DRIVERS\amdk7.sys [2005-06-14 37376]
R1 KLIF;Kaspersky Lab Driver; C:\WINDOWS\system32\DRIVERS\klif.sys [2009-10-19 296976]
R3 cmuda;C-Media WDM Audio Interface; C:\WINDOWS\system32\drivers\cmuda.sys [2004-08-23 821760]
R3 FETND5BV;VIA Rhine-Family Fast Ethernet Adapter Driver Service; C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [2004-12-16 42496]
R3 KeyScramblerDrv;KeyScramblerDrv; C:\WINDOWS\System32\drivers\keyscrambler.sys [2008-06-25 113896]
R3 klmouflt;Kaspersky Lab KLMOUFLT; C:\WINDOWS\system32\DRIVERS\klmouflt.sys [2009-05-16 19472]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2005-06-14 26624]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2005-06-14 57600]
R3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2005-06-14 20480]
R3 viagfx;viagfx; C:\WINDOWS\system32\DRIVERS\vtmini.sys [2004-09-27 173440]
S3 afpcrpow;afpcrpow; \??\C:\DOCUME~1\user\LOCALS~1\Temp\afpcrpow.sys []
S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\fetnd5.sys [2001-08-17 27165]
S3 FETNDISB;VIA Rhine Family Fast Ethernet Adapter Driver Service; C:\WINDOWS\system32\DRIVERS\fetnd5b.sys [2004-01-09 42496]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-10-20 153376]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
S2 AVP;Kaspersky Internet Security; C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe [2009-07-03 303376]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2009-10-16 72704]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------


Info:

info.txt logfile of random's system information tool 1.06 2009-11-05 18:23:41

======Uninstall list======

-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
-->VTUninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Timer'
Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 9.2-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A92000000001}
CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
C-Media 3D Audio-->C:\WINDOWS\CMIUnInstall.exe
Diner Dash-->D:\Games\Diner Dash\UNWISE.EXE D:\Games\Diner Dash\INSTALL.LOG
FeedingFrenzy-->D:\Games\FeedingFrenzy\UNWISE.EXE D:\Games\FeedingFrenzy\INSTALL.LOG
FLV Player 2.0 (build 25)-->C:\Program Files\FLV Player\uninst.exe
Forex Strategy Builder v2.9.1.0-->"C:\Program Files\Forex Strategy Builder\unins000.exe"
HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
Holiday Express-->D:\Games\Holiday Express\UNWISE.EXE D:\Games\Holiday Express\INSTALL.LOG
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
Iggle Pop-->D:\GAMES\IGGLEP~1\UNWISE.EXE D:\GAMES\IGGLEP~1\INSTALL.LOG
Incadia-->D:\Games\Incadia\UNWISE.EXE D:\Games\Incadia\INSTALL.LOG
Insaniquarium-->D:\Games\Insaniquarium\UNWISE.EXE D:\Games\Insaniquarium\INSTALL.LOG
InstaTrader 4.00-->"C:\Program Files\InstaTrader-Demo\Uninstall.exe" "C:\Program Files\InstaTrader-Demo\install.log"
Internet Download Manager-->C:\Program Files\Internet Download Manager\Uninstall.exe
Java™ 6 Update 16-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216016FF}
Jewel Quest-->D:\Games\Jewel Quest\UNWISE.EXE D:\Games\Jewel Quest\INSTALL.LOG
Kaspersky Internet Security 2010-->MsiExec.exe /I{9D8B0949-7C47-476F-9F06-F900D3B078EA}
Kaspersky Internet Security 2010-->MsiExec.exe /I{9D8B0949-7C47-476F-9F06-F900D3B078EA}
KeyScrambler-->C:\Program Files\KeyScrambler\uninstall.exe
K-Lite Mega Codec Pack 1.34-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
Luxor-->D:\Games\Luxor\UNWISE.EXE D:\Games\Luxor\INSTALL.LOG
MadCaps-->D:\Games\MadCaps\UNWISE.EXE D:\Games\MadCaps\INSTALL.LOG
Magic Vines-->D:\Games\Magic Vines\UNWISE.EXE D:\Games\Magic Vines\INSTALL.LOG
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Marketiva-->C:\Program Files\Novativa Streamster\Uninstall.exe
Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Office Professional Edition 2003-->MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
mIRC-->C:\Program Files\mIRC\uninstall.exe _?=C:\Program Files\mIRC
Mozilla Firefox (3.5.4)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 6.0 Parser (KB933579)-->MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
Perfect Uninstaller v6.3.3.6-->"C:\Program Files\Perfect Uninstaller\unins000.exe"
Pizza Frenzy-->D:\Games\Pizza Frenzy\UNWISE.EXE D:\Games\Pizza Frenzy\INSTALL.LOG
Platypus-->D:\Games\Platypus\UNWISE.EXE D:\Games\Platypus\INSTALL.LOG
PowerArchiver 2010-->MsiExec.exe /I{AE244460-D063-44A6-8DAE-DA451837AC2C}
RegCure 2.0.0.0-->C:\Program Files\RegCure\uninst.exe
S3 S3Display-->vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Display'
S3 S3Gamma2-->vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Gamma2'
S3 S3Info2-->vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Info2'
S3 S3Overlay-->vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Overlay'
Security Update for Windows Internet Explorer 8 (KB971961)-->"C:\WINDOWS\ie8updates\KB971961-IE8\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 8 (KB974455)-->"C:\WINDOWS\ie8updates\KB974455-IE8\spuninst\spuninst.exe"
UniChrome IGP Driver and Utilities-->C:\PROGRA~1\S3\S3\s3setvga.exe -s -fC:\PROGRA~1\S3\S3\S3.uns
VIA Rhine-Family Fast Ethernet Adapter-->Rundll32.exe vuins32.dll,vuins32Ex $Rhine $VIA
Winamp-->"C:\Program Files\Winamp\UninstWA.exe"
Windows Imaging Component-->"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
Windows Internet Explorer 8-->"C:\WINDOWS\ie8\spuninst\spuninst.exe"
Windows Media Format Runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Player 10-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Yahoo! Messenger-->C:\PROGRA~1\YAHOO!\MESSEN~1\UNWISE.EXE /U C:\PROGRA~1\YAHOO!\MESSEN~1\INSTALL.LOG
Zuma-->D:\Games\Zuma\UNWISE.EXE D:\Games\Zuma\INSTALL.LOG

======Security center information======

AV: Kaspersky Internet Security (disabled)
FW: Kaspersky Internet Security (disabled)

======System event log======

Computer Name: USER-C9461CA0E9
Event Code: 1003
Message: Your computer was not able to renew its address from the network (from the
DHCP Server) for the Network Card with network address 00142A32B1FE. The following
error occurred:
The operation was canceled by the user.
.
Your computer will continue to try and obtain an address on its own from
the network address (DHCP) server.

Record Number: 288
Source Name: Dhcp
Time Written: 20091026222829.000000+420
Event Type: warning
User:

Computer Name: USER-C9461CA0E9
Event Code: 1003
Message: Your computer was not able to renew its address from the network (from the
DHCP Server) for the Network Card with network address 00142A32B1FE. The following
error occurred:
The operation was canceled by the user.
.
Your computer will continue to try and obtain an address on its own from
the network address (DHCP) server.

Record Number: 285
Source Name: Dhcp
Time Written: 20091026222821.000000+420
Event Type: warning
User:

Computer Name: USER-C9461CA0E9
Event Code: 20
Message: Installation Failure: Windows failed to install the following update with error 0x87ff054f: Windows XP Service Pack 3 (KB936929).

Record Number: 264
Source Name: Windows Update Agent
Time Written: 20091026213114.000000+420
Event Type: error
User:

Computer Name: USER-C9461CA0E9
Event Code: 4373
Message: Windows XP Service Pack 3 installation failed.
An internal error occurred.


Record Number: 263
Source Name: NtServicePack
Time Written: 20091026210759.000000+420
Event Type: error
User: USER-C9461CA0E9\user

Computer Name: USER-C9461CA0E9
Event Code: 7031
Message: The Windows Hosts Controller service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 3000 milliseconds: Restart the service.

Record Number: 17
Source Name: Service Control Manager
Time Written: 20091026104225.000000+420
Event Type: error
User:

=====Application event log=====

Computer Name: USER-C9461CA0E9
Event Code: 8
Message: Failed auto update retrieval of third-party root list sequence number from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: This operation returned because the timeout period expired.


Record Number: 19
Source Name: crypt32
Time Written: 20091026200935.000000+420
Event Type: error
User:

Computer Name: USER-C9461CA0E9
Event Code: 1517
Message: Windows saved user USER-C9461CA0E9\user registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use.


This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.

Record Number: 9
Source Name: Userenv
Time Written: 20091026194456.000000+420
Event Type: warning
User: NT AUTHORITY\SYSTEM

Computer Name: USER-C9461CA0E9
Event Code: 1517
Message: Windows saved user USER-C9461CA0E9\user registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use.


This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.

Record Number: 6
Source Name: Userenv
Time Written: 20091026170616.000000+420
Event Type: warning
User: NT AUTHORITY\SYSTEM

Computer Name: USER-C9461CA0E9
Event Code: 1002
Message: Hanging application RootRepeal.exe, version 1.3.5.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

Record Number: 4
Source Name: Application Hang
Time Written: 20091026112900.000000+420
Event Type: error
User:

Computer Name: USER-C9461CA0E9
Event Code: 8
Message: Failed auto update retrieval of third-party root list sequence number from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: This operation returned because the timeout period expired.


Record Number: 2
Source Name: crypt32
Time Written: 20091026102246.000000+420
Event Type: error
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 10 Stepping 0, AuthenticAMD
"PROCESSOR_REVISION"=0a00
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP

-----------------EOF-----------------

#6 syler

syler

  • Malware Response Team
  • 8,150 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Warrington, UK
  • Local time:01:22 AM

Posted 05 November 2009 - 03:52 PM

Your logs show that you have a few keygens on your machine.

D:\Microsoft\Make Your Windows Genuine - For XP,Server 2003, Vista - iNGEn\WINDOWS XP and Server 2003\4) Keygens - Checkers\Windows Keygen.exe (Malware.Tool) -> Quarantined and deleted successfully.
D:\OODefrag12ProfessionalEnu\keygen.exe (Malware.Tool) -> Quarantined and deleted successfully.
D:\Nullsoft.Winamp.Pro.v5.56.Incl.Keygen-Lz0\nfoviewer.exe (Trojan.Agent) -> Quarantined and deleted successfully.
D:\Nullsoft.Winamp.Pro.v5.56.Incl.Keygen-Lz0\Lz0\KeyGen.exe (Trojan.Downloader) -> Quarantined and deleted successfully.



IMPORTANT NOTE: Your scan log results indicate you are using keygens/crack tools.

The practice of using cracking tools, keygens, warez or any pirated software is not only considered illegal activity but it is a serious security risk.

...warez/piracy sites ranked the highest in downloading spyware...just opening the web page usually sets off an exploit, never mind actually downloading anything. And by the time the malware is finished downloading, often the machine is trashed and rendered useless.

University of Washington spyware study

...One of the most aggressive and intrusive of all bad websites on the Internet are serial, warez, software cracking type sites...they sneak malware onto your system...Where do trojan viruses originate? One of the biggest malware distributors on the Internet are serial/warez/code cracking sites.

Bad Web Sites: Malware

When you use these kind of programs, be forewarned that some of the worst types of malware infections can be contracted and spread by visiting crack, keygen, warez and other pirated software sites. In many cases, those sites are infested with a smörgåsbord of malware and an increasing source of system infection. Those who attempt to get software for free can end up with a computer system so badly damaged that recovery is not possible and it cannot be repaired. When that happens there is nothing you can do besides reformatting and reinstalling the OS.



Download and Run Rooter SD

Please download Rooter.exe and save it to your desktop
  • Double-click it to start the tool. If you are using Vista, please right-click and choose Run As Administrator
  • Alow it to run when you get a Security Warning
  • A black Command Windows will open saying: "Please Wait..."
  • It will now begin to scan, please be paitent. The scan should not take more than 2 minutes
  • A Notepad file containing the report will open soon. It can also be found at %systemdrive%\Rooter.txt
  • Please post the contents of that log in your next reply


Please run a BitDefender Online Scan

Note: Only works with internet explorer
  • Click on the Start Scanner button.
  • Check I Agree to agree to the EULA, then click start here.
  • Allow the ActiveX control to install when prompted.
  • Click Start scan to begin scanning.
  • Please refrain from using the computer until the scan is finished. This might take a while to run, but it is important that nothing else is running while you scan.
  • When the scan is finished, click on Click here to export the scan results.
  • Save the report to your desktop as results.txt and post it in your next reply.

Please post back here with the following logs:
  • Rooter.txt
  • Bitdefender report
  • New Rsit log
Thanks

unite.jpg


#7 ursaminor

ursaminor
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:07:22 AM

Posted 06 November 2009 - 03:19 AM

Thank you syler for help me :(

here the logs,

•Rooter.txt:


Rooter.exe (v1.0.2) by Eric_71
.
SeDebugPrivilege granted successfully ...
.
Windows XP . (5.1.2600) Service Pack 2
[32_bits] - x86 Family 6 Model 10 Stepping 0, AuthenticAMD
.
[wscsvc] (Security Center) RUNNING (state:4)
[SharedAccess] RUNNING (state:4)
Windows Firewall -> Disabled !
.
Internet Explorer 8.0.6001.18702
Mozilla Firefox 3.5.4 (id)
.
C:\ [Fixed-FAT32] .. ( Total:14 Go - Free:6 Go )
D:\ [Fixed-FAT32] .. ( Total:23 Go - Free:23 Go )
E:\ [CD_Rom]
F:\ [Removable]
.
Scan : 09:05.54
Path : C:\Documents and Settings\user\Desktop\Rooter.exe
User : user ( Administrator -> YES )
.
----------------------\\ Processes
.
Locked [System Process] (0)
______ System (4)
______ \SystemRoot\System32\smss.exe (408)
______ \??\C:\WINDOWS\system32\csrss.exe (464)
______ \??\C:\WINDOWS\system32\winlogon.exe (488)
______ C:\WINDOWS\system32\services.exe (540)
______ C:\WINDOWS\system32\lsass.exe (552)
______ C:\WINDOWS\system32\svchost.exe (716)
______ C:\WINDOWS\system32\svchost.exe (768)
______ C:\WINDOWS\System32\svchost.exe (848)
______ C:\WINDOWS\system32\svchost.exe (936)
______ C:\WINDOWS\system32\svchost.exe (1060)
______ C:\WINDOWS\system32\spoolsv.exe (1392)
______ C:\WINDOWS\Explorer.EXE (1456)
______ C:\WINDOWS\system32\svchost.exe (1508)
Locked AVP.EXE (1580)
______ C:\Program Files\Java\jre6\bin\jqs.exe (1648)
______ C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (1680)
______ C:\WINDOWS\system32\wdfmgr.exe (1820)
______ C:\WINDOWS\System32\alg.exe (1752)
Locked AVP.EXE (2448)
______ C:\Program Files\Winamp\winampa.exe (2788)
______ C:\WINDOWS\system32\ctfmon.exe (2928)
______ C:\Program Files\Internet Download Manager\IDMan.exe (2936)
______ C:\Program Files\Internet Download Manager\IEMonitor.exe (3132)
______ C:\WINDOWS\system32\wuauclt.exe (3572)
______ C:\Program Files\InstaTrader\terminal.exe (3736)
______ C:\Program Files\Internet Explorer\iexplore.exe (2600)
______ C:\Program Files\Internet Explorer\iexplore.exe (2996)
Locked klwtblfs.exe (3968)
Locked AVP.EXE (1032)
______ C:\Documents and Settings\user\Desktop\Rooter.exe (2968)
.
----------------------\\ Device\Harddisk0\
.
\Device\Harddisk0 [Sectors : 63 x 512 Bytes]
.
\Device\Harddisk0\Partition1 --[ MBR ]-- (Start_Offset:32256 | Length:15726703104)
\Device\Harddisk0\Partition0 (Start_Offset:15726735360 | Length:25374988800)
\Device\Harddisk0\Partition2 (Start_Offset:15726767616 | Length:25374956544)
.
----------------------\\ Scheduled Tasks
.
C:\WINDOWS\Tasks\desktop.ini
C:\WINDOWS\Tasks\SA.DAT
C:\WINDOWS\Tasks\RegCure.job
C:\WINDOWS\Tasks\RegCure Startup.job
C:\WINDOWS\Tasks\RegCure Program Check.job
C:\WINDOWS\Tasks\User_Feed_Synchronization-{71DA9882-EFFC-423C-B0D4-4018C41983FD}.job
.
----------------------\\ Registry
.
.
----------------------\\ Files & Folders
.
C:\DOCUME~1\user\My Documents\Unduhan\Expert Advisor\FAB Turbo V4.7 cracked.rar
C:\DOCUME~1\user\My Documents\Unduhan\Expert Advisor\FAB Turbo V4.7 cracked1.rar
==> Cracks & Keygens <==
.
----------------------\\ Scan completed at 09:06.05
.
C:\Rooter$\Rooter_1.txt - (06/11/2009 | 09:06.05).c



•Bitdefender report:


BitDefender Online Scanner



Scan report generated at: Fri, Nov 06, 2009 - 14:58:58





Scan path: C:\;D:\;E:\;F:\;







Statistics

Time
00:48:55

Files
105072

Folders
3149

Boot Sectors
0

Archives
1214

Packed Files
4309




Results

Identified Viruses
0

Infected Files
0

Suspect Files
0

Warnings
0

Disinfected
0

Deleted Files
0




Engines Info

Virus Definitions
4481748

Engine build
AVCORE v2.1 Windows/i386 11.0.0.26 (Oct 20 2009)

Scan plugins
17

Archive plugins
44

Unpack plugins
8

E-mail plugins
6

System plugins
4




Scan Settings

First Action
Disinfect

Second Action
Delete

Heuristics
Yes

Enable Warnings
Yes

Scanned Extensions
*;

Exclude Extensions


Scan Emails
Yes

Scan Archives
Yes

Scan Packed
Yes

Scan Files
Yes

Scan Boot
Yes




Scanned File
Status

No virus found.



•New Rsit log:


Info:

info.txt logfile of random's system information tool 1.06 2009-11-06 15:08:48

======Uninstall list======

-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
-->VTUninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Timer'
Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 9.2-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A92000000001}
CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
C-Media 3D Audio-->C:\WINDOWS\CMIUnInstall.exe
Diner Dash-->D:\Games\Diner Dash\UNWISE.EXE D:\Games\Diner Dash\INSTALL.LOG
FeedingFrenzy-->D:\Games\FeedingFrenzy\UNWISE.EXE D:\Games\FeedingFrenzy\INSTALL.LOG
FLV Player 2.0 (build 25)-->C:\Program Files\FLV Player\uninst.exe
Forex Strategy Builder v2.9.1.0-->"C:\Program Files\Forex Strategy Builder\unins000.exe"
HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
Holiday Express-->D:\Games\Holiday Express\UNWISE.EXE D:\Games\Holiday Express\INSTALL.LOG
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
Iggle Pop-->D:\GAMES\IGGLEP~1\UNWISE.EXE D:\GAMES\IGGLEP~1\INSTALL.LOG
Incadia-->D:\Games\Incadia\UNWISE.EXE D:\Games\Incadia\INSTALL.LOG
Insaniquarium-->D:\Games\Insaniquarium\UNWISE.EXE D:\Games\Insaniquarium\INSTALL.LOG
InstaTrader 4.00-->"C:\Program Files\InstaTrader-Demo\Uninstall.exe" "C:\Program Files\InstaTrader-Demo\install.log"
Internet Download Manager-->C:\Program Files\Internet Download Manager\Uninstall.exe
Java™ 6 Update 16-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216016FF}
Jewel Quest-->D:\Games\Jewel Quest\UNWISE.EXE D:\Games\Jewel Quest\INSTALL.LOG
Kaspersky Internet Security 2010-->MsiExec.exe /I{9D8B0949-7C47-476F-9F06-F900D3B078EA}
Kaspersky Internet Security 2010-->MsiExec.exe /I{9D8B0949-7C47-476F-9F06-F900D3B078EA}
KeyScrambler-->C:\Program Files\KeyScrambler\uninstall.exe
K-Lite Mega Codec Pack 1.34-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
Luxor-->D:\Games\Luxor\UNWISE.EXE D:\Games\Luxor\INSTALL.LOG
MadCaps-->D:\Games\MadCaps\UNWISE.EXE D:\Games\MadCaps\INSTALL.LOG
Magic Vines-->D:\Games\Magic Vines\UNWISE.EXE D:\Games\Magic Vines\INSTALL.LOG
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Marketiva-->C:\Program Files\Novativa Streamster\Uninstall.exe
Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Office Professional Edition 2003-->MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
mIRC-->C:\Program Files\mIRC\uninstall.exe _?=C:\Program Files\mIRC
Mozilla Firefox (3.5.4)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 6.0 Parser (KB933579)-->MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
Perfect Uninstaller v6.3.3.6-->"C:\Program Files\Perfect Uninstaller\unins000.exe"
Pizza Frenzy-->D:\Games\Pizza Frenzy\UNWISE.EXE D:\Games\Pizza Frenzy\INSTALL.LOG
Platypus-->D:\Games\Platypus\UNWISE.EXE D:\Games\Platypus\INSTALL.LOG
PowerArchiver 2010-->MsiExec.exe /I{AE244460-D063-44A6-8DAE-DA451837AC2C}
RegCure 2.0.0.0-->C:\Program Files\RegCure\uninst.exe
S3 S3Display-->vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Display'
S3 S3Gamma2-->vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Gamma2'
S3 S3Info2-->vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Info2'
S3 S3Overlay-->vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Overlay'
Security Update for Windows Internet Explorer 8 (KB971961)-->"C:\WINDOWS\ie8updates\KB971961-IE8\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 8 (KB974455)-->"C:\WINDOWS\ie8updates\KB974455-IE8\spuninst\spuninst.exe"
UniChrome IGP Driver and Utilities-->C:\PROGRA~1\S3\S3\s3setvga.exe -s -fC:\PROGRA~1\S3\S3\S3.uns
VIA Rhine-Family Fast Ethernet Adapter-->Rundll32.exe vuins32.dll,vuins32Ex $Rhine $VIA
Winamp-->"C:\Program Files\Winamp\UninstWA.exe"
Windows Imaging Component-->"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
Windows Internet Explorer 8-->"C:\WINDOWS\ie8\spuninst\spuninst.exe"
Windows Media Format Runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Player 10-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Yahoo! Messenger-->C:\PROGRA~1\YAHOO!\MESSEN~1\UNWISE.EXE /U C:\PROGRA~1\YAHOO!\MESSEN~1\INSTALL.LOG
Zuma-->D:\Games\Zuma\UNWISE.EXE D:\Games\Zuma\INSTALL.LOG

======Security center information======

AV: Kaspersky Internet Security
FW: Kaspersky Internet Security

======System event log======

Computer Name: USER-C9461CA0E9
Event Code: 1003
Message: Your computer was not able to renew its address from the network (from the
DHCP Server) for the Network Card with network address 00142A32B1FE. The following
error occurred:
The operation was canceled by the user.
.
Your computer will continue to try and obtain an address on its own from
the network address (DHCP) server.

Record Number: 288
Source Name: Dhcp
Time Written: 20091026222829.000000+420
Event Type: warning
User:

Computer Name: USER-C9461CA0E9
Event Code: 1003
Message: Your computer was not able to renew its address from the network (from the
DHCP Server) for the Network Card with network address 00142A32B1FE. The following
error occurred:
The operation was canceled by the user.
.
Your computer will continue to try and obtain an address on its own from
the network address (DHCP) server.

Record Number: 285
Source Name: Dhcp
Time Written: 20091026222821.000000+420
Event Type: warning
User:

Computer Name: USER-C9461CA0E9
Event Code: 20
Message: Installation Failure: Windows failed to install the following update with error 0x87ff054f: Windows XP Service Pack 3 (KB936929).

Record Number: 264
Source Name: Windows Update Agent
Time Written: 20091026213114.000000+420
Event Type: error
User:

Computer Name: USER-C9461CA0E9
Event Code: 4373
Message: Windows XP Service Pack 3 installation failed.
An internal error occurred.


Record Number: 263
Source Name: NtServicePack
Time Written: 20091026210759.000000+420
Event Type: error
User: USER-C9461CA0E9\user

Computer Name: USER-C9461CA0E9
Event Code: 7031
Message: The Windows Hosts Controller service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 3000 milliseconds: Restart the service.

Record Number: 17
Source Name: Service Control Manager
Time Written: 20091026104225.000000+420
Event Type: error
User:

=====Application event log=====

Computer Name: USER-C9461CA0E9
Event Code: 8
Message: Failed auto update retrieval of third-party root list sequence number from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: This operation returned because the timeout period expired.


Record Number: 19
Source Name: crypt32
Time Written: 20091026200935.000000+420
Event Type: error
User:

Computer Name: USER-C9461CA0E9
Event Code: 1517
Message: Windows saved user USER-C9461CA0E9\user registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use.


This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.

Record Number: 9
Source Name: Userenv
Time Written: 20091026194456.000000+420
Event Type: warning
User: NT AUTHORITY\SYSTEM

Computer Name: USER-C9461CA0E9
Event Code: 1517
Message: Windows saved user USER-C9461CA0E9\user registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use.


This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.

Record Number: 6
Source Name: Userenv
Time Written: 20091026170616.000000+420
Event Type: warning
User: NT AUTHORITY\SYSTEM

Computer Name: USER-C9461CA0E9
Event Code: 1002
Message: Hanging application RootRepeal.exe, version 1.3.5.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

Record Number: 4
Source Name: Application Hang
Time Written: 20091026112900.000000+420
Event Type: error
User:

Computer Name: USER-C9461CA0E9
Event Code: 8
Message: Failed auto update retrieval of third-party root list sequence number from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: This operation returned because the timeout period expired.


Record Number: 2
Source Name: crypt32
Time Written: 20091026102246.000000+420
Event Type: error
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 10 Stepping 0, AuthenticAMD
"PROCESSOR_REVISION"=0a00
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP

-----------------EOF-----------------


log:

Logfile of random's system information tool 1.06 (written by random/random)
Run by user at 2009-11-06 15:08:25
Microsoft Windows XP Professional Service Pack 2
System drive C: has 6 GB (43%) free of 15 GB
Total RAM: 479 MB (49% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:08:44, on 06/11/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\InstaTrader\terminal.exe
F:\RSIT.exe
C:\Program Files\trend micro\user.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: QFX Software KeyScrambler - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [avp] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: &Virtual keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O9 - Extra button: (no name) - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O9 - Extra 'Tools' menuitem: &KeyScrambler... - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/...can8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1256467696781
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1256467669250
O17 - HKLM\System\CCS\Services\Tcpip\..\{29B380CF-7269-44CF-AC61-C55A932FF918}: NameServer = 203.130.208.18 202.134.0.61
O17 - HKLM\System\CS1\Services\Tcpip\..\{29B380CF-7269-44CF-AC61-C55A932FF918}: NameServer = 203.130.208.18 202.134.0.61
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
O20 - Winlogon Notify: KeyScrambler - C:\WINDOWS\SYSTEM32\KeyScramblerLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

--
End of file - 6501 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\RegCure.job
C:\WINDOWS\tasks\RegCure Startup.job
C:\WINDOWS\tasks\RegCure Program Check.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{71DA9882-EFFC-423C-B0D4-4018C41983FD}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}]
IDMIEHlprObj Class - C:\Program Files\Internet Download Manager\IDMIECC.dll [2009-05-07 169392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2B9F5787-88A5-4945-90E7-C4B18563BC5E}]
KeyScramblerBHO Class - C:\Program Files\KeyScrambler\KeyScramblerIE.dll [2009-10-17 829928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C}]
IEVkbdBHO Class - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll [2009-07-03 68112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-20 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E33CF602-D945-461A-83F0-819F76A199F8}]
FilterBHO Class - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll [2009-10-19 264720]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-10-20 73728]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avp"=C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe [2009-07-03 303376]
"WinampAgent"=C:\Program Files\Winamp\winampa.exe [2009-07-01 37888]
"Malwarebytes Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2009-09-10 1312080]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2005-06-14 15360]
"IDMan"=C:\Program Files\Internet Download Manager\IDMan.exe [2009-10-21 2815408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\KeyScrambler]
C:\WINDOWS\system32\KeyScramblerLogon.dll [2008-11-21 109032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
C:\WINDOWS\system32\klogon.dll [2009-07-03 219664]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskmgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\WINDOWS\System32\ZoneLabs\vsmon.exe"="C:\WINDOWS\System32\ZoneLabs\vsmon.exe:*:Enabled:TrueVector Service"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======List of files/folders created in the last 1 months======

2009-11-06 15:08:25 ----D---- C:\rsit
2009-11-06 09:11:43 ----D---- C:\WINDOWS\BDOSCAN8
2009-11-06 09:06:00 ----D---- C:\Rooter$
2009-11-05 22:09:52 ----D---- C:\Program Files\Free Offers from Freeze.com
2009-11-05 15:14:39 ----D---- C:\Documents and Settings\user\Application Data\Malwarebytes
2009-11-05 15:14:28 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-11-05 15:14:16 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-11-05 10:09:35 ----D---- C:\Program Files\InstaTrader-Demo
2009-11-04 18:23:53 ----D---- C:\Program Files\trend micro
2009-11-04 11:50:17 ----D---- C:\Program Files\WSS Package
2009-11-01 17:10:17 ----D---- C:\Program Files\InstaTrader
2009-10-27 18:55:14 ----D---- C:\WINDOWS\system32\XPSViewer
2009-10-27 18:55:10 ----D---- C:\Program Files\MSBuild
2009-10-27 18:55:00 ----D---- C:\Program Files\Reference Assemblies
2009-10-27 18:54:24 ----N---- C:\WINDOWS\system32\xpsshhdr.dll
2009-10-27 18:54:24 ----N---- C:\WINDOWS\system32\prntvpt.dll
2009-10-27 18:54:23 ----N---- C:\WINDOWS\system32\xpssvcs.dll
2009-10-27 18:47:19 ----HD---- C:\WINDOWS\$NtUninstallWIC$
2009-10-27 18:47:07 ----D---- C:\Program Files\MSXML 6.0
2009-10-27 10:02:20 ----D---- C:\Documents and Settings\user\Application Data\Media Player Classic
2009-10-26 19:49:58 ----D---- C:\WINDOWS\ServicePackFiles
2009-10-26 19:49:07 ----D---- C:\WINDOWS\ie8updates
2009-10-26 19:47:19 ----D---- C:\Program Files\MSXML 4.0
2009-10-26 15:51:24 ----HD---- C:\WINDOWS\PIF
2009-10-26 13:39:48 ----A---- C:\WINDOWS\system32\mucltui.dll.mui
2009-10-26 13:39:44 ----A---- C:\WINDOWS\system32\mucltui.dll
2009-10-26 13:29:21 ----N---- C:\WINDOWS\system32\tzchange.exe
2009-10-25 18:34:32 ----D---- C:\WINDOWS\system32\CatRoot_bak
2009-10-25 18:30:33 ----D---- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2009-10-25 18:13:01 ----D---- C:\WINDOWS\system32\PreInstall
2009-10-25 18:12:59 ----HD---- C:\WINDOWS\$hf_mig$
2009-10-25 17:49:37 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2009-10-25 17:49:37 ----A---- C:\WINDOWS\system32\wups2.dll
2009-10-25 17:49:37 ----A---- C:\WINDOWS\system32\wucltui.dll.mui
2009-10-25 17:49:36 ----A---- C:\WINDOWS\system32\wuaueng.dll.mui
2009-10-25 17:49:35 ----A---- C:\WINDOWS\system32\wuapi.dll.mui
2009-10-25 17:31:27 ----HD---- C:\WINDOWS\ie8
2009-10-25 17:30:29 ----D---- C:\Program Files\Microsoft Silverlight
2009-10-25 15:15:56 ----SHD---- C:\FOUND.001
2009-10-24 18:22:48 ----RSD---- C:\WINDOWS\assembly
2009-10-24 18:21:35 ----D---- C:\WINDOWS\Microsoft.NET
2009-10-24 18:08:23 ----D---- C:\Program Files\Forex Strategy Builder
2009-10-23 10:32:31 ----D---- C:\Program Files\Common Files\NSV
2009-10-23 10:23:14 ----D---- C:\Program Files\Winamp
2009-10-22 22:31:02 ----SHD---- C:\FOUND.000
2009-10-22 21:42:01 ----N---- C:\WINDOWS\system32\pxcpya64.exe
2009-10-22 21:42:00 ----N---- C:\WINDOWS\system32\pxsfs.dll
2009-10-22 21:42:00 ----N---- C:\WINDOWS\system32\pxinsa64.exe
2009-10-22 21:42:00 ----N---- C:\WINDOWS\system32\pxafs.dll
2009-10-22 21:41:50 ----D---- C:\Documents and Settings\user\Application Data\Winamp
2009-10-21 22:09:35 ----D---- C:\Documents and Settings\user\Application Data\IDM
2009-10-21 22:09:34 ----D---- C:\Documents and Settings\user\Application Data\DMCache
2009-10-21 22:09:19 ----D---- C:\Program Files\Internet Download Manager
2009-10-20 13:13:12 ----D---- C:\Program Files\FLV Player
2009-10-20 12:48:40 ----D---- C:\Program Files\PowerArchiver
2009-10-20 12:35:55 ----D---- C:\Documents and Settings\All Users\Application Data\ConeXware
2009-10-20 10:47:52 ----A---- C:\WINDOWS\system32\javaws.exe
2009-10-20 10:47:51 ----A---- C:\WINDOWS\system32\javaw.exe
2009-10-20 10:47:51 ----A---- C:\WINDOWS\system32\java.exe
2009-10-20 10:47:22 ----D---- C:\Program Files\Java
2009-10-19 20:30:08 ----D---- C:\Program Files\Kaspersky Lab
2009-10-19 20:30:08 ----D---- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2009-10-19 20:29:06 ----D---- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-10-19 20:24:24 ----A---- C:\WINDOWS\system32\wininet.dll
2009-10-19 20:24:24 ----A---- C:\WINDOWS\system32\shdocvw.dll
2009-10-19 20:24:24 ----A---- C:\WINDOWS\system32\pngfilt.dll
2009-10-19 20:24:24 ----A---- C:\WINDOWS\system32\occache.dll
2009-10-19 20:24:24 ----A---- C:\WINDOWS\system32\mstime.dll
2009-10-19 20:24:24 ----A---- C:\WINDOWS\system32\msrating.dll
2009-10-19 20:24:24 ----A---- C:\WINDOWS\system32\msls31.dll
2009-10-19 20:24:24 ----A---- C:\WINDOWS\system32\mshtmler.dll
2009-10-19 20:24:24 ----A---- C:\WINDOWS\system32\mshtmled.dll
2009-10-19 20:24:24 ----A---- C:\WINDOWS\system32\mshtml.dll
2009-10-19 20:24:24 ----A---- C:\WINDOWS\system32\mshta.exe
2009-10-19 20:24:24 ----A---- C:\WINDOWS\system32\licmgr10.dll
2009-10-19 20:24:24 ----A---- C:\WINDOWS\system32\jsproxy.dll
2009-10-19 20:24:24 ----A---- C:\WINDOWS\system32\jscript.dll
2009-10-19 20:24:24 ----A---- C:\WINDOWS\system32\inseng.dll
2009-10-19 20:24:24 ----A---- C:\WINDOWS\system32\imgutil.dll
2009-10-19 17:10:12 ----D---- C:\WINDOWS\Sun
2009-10-19 15:52:54 ----A---- C:\WINDOWS\system32\deploytk.dll
2009-10-19 15:46:02 ----D---- C:\Documents and Settings\user\Application Data\Sun
2009-10-19 05:40:39 ----D---- C:\Documents and Settings\user\Application Data\mIRC
2009-10-19 05:40:38 ----D---- C:\Program Files\mIRC
2009-10-18 21:25:30 ----D---- C:\WINDOWS\WBEM
2009-10-18 21:25:02 ----A---- C:\WINDOWS\system32\spupdsvc.exe
2009-10-18 21:24:10 ----D---- C:\WINDOWS\system32\en-US
2009-10-18 21:23:00 ----HD---- C:\WINDOWS\msdownld.tmp
2009-10-17 20:42:38 ----A---- C:\WINDOWS\system32\homepage.txt
2009-10-17 19:26:57 ----D---- C:\WINDOWS\system32\ZoneLabs
2009-10-17 19:25:55 ----D---- C:\WINDOWS\Internet Logs
2009-10-17 16:43:16 ----D---- C:\Program Files\KeyScrambler
2009-10-17 15:22:50 ----D---- C:\Program Files\CCleaner
2009-10-16 18:59:44 ----D---- C:\Documents and Settings\All Users\Application Data\Kaspersky SDK
2009-10-16 18:46:16 ----D---- C:\Program Files\Perfect Uninstaller
2009-10-16 18:45:28 ----D---- C:\Program Files\RegCure
2009-10-16 18:45:28 ----D---- C:\Documents and Settings\All Users\Application Data\RegCure
2009-10-16 17:34:00 ----D---- C:\Program Files\WGA
2009-10-16 17:28:05 ----D---- C:\Program Files\Novativa Streamster
2009-10-16 15:36:38 ----D---- C:\Documents and Settings\user\Application Data\Mozilla
2009-10-16 15:35:41 ----D---- C:\Program Files\Mozilla Firefox
2009-10-16 15:34:40 ----D---- C:\Documents and Settings\All Users\Application Data\Yahoo!
2009-10-16 15:34:36 ----D---- C:\Program Files\Yahoo!
2009-10-16 15:06:35 ----D---- C:\Documents and Settings\All Users\Application Data\InstallShield
2009-10-16 15:01:28 ----A---- C:\WINDOWS\system32\msisip.dll
2009-10-16 15:01:28 ----A---- C:\WINDOWS\system32\msimsg.dll
2009-10-16 15:01:28 ----A---- C:\WINDOWS\system32\msihnd.dll
2009-10-16 15:01:28 ----A---- C:\WINDOWS\system32\msiexec.exe
2009-10-16 15:01:28 ----A---- C:\WINDOWS\system32\msi.dll
2009-10-16 14:53:43 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe Systems
2009-10-16 14:52:51 ----D---- C:\Program Files\Common Files\Adobe Systems Shared
2009-10-16 14:46:59 ----SHD---- C:\Recycled
2009-10-16 14:36:22 ----D---- C:\Documents and Settings\user\Application Data\Macromedia
2009-10-16 14:36:21 ----D---- C:\Documents and Settings\user\Application Data\Adobe
2009-10-16 14:34:10 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2009-10-16 14:34:03 ----D---- C:\Program Files\Common Files\Adobe
2009-10-16 14:34:03 ----D---- C:\Program Files\Adobe
2009-10-16 14:32:32 ----D---- C:\Program Files\Common Files\ACD Systems
2009-10-16 14:32:06 ----D---- C:\WINDOWS\Downloaded Installations
2009-10-16 14:29:30 ----D---- C:\WINDOWS\system32\QuickTime
2009-10-16 14:29:30 ----A---- C:\WINDOWS\system32\qtmlClient.dll
2009-10-16 14:29:27 ----D---- C:\WINDOWS\RegisteredPackages
2009-10-16 14:29:26 ----A---- C:\WINDOWS\system32\rmoc3260.dll
2009-10-16 14:29:26 ----A---- C:\WINDOWS\system32\pndx5032.dll
2009-10-16 14:29:26 ----A---- C:\WINDOWS\system32\pndx5016.dll
2009-10-16 14:29:26 ----A---- C:\WINDOWS\system32\pncrt.dll
2009-10-16 14:29:25 ----A---- C:\WINDOWS\system32\vp6vfw.dll
2009-10-16 14:29:25 ----A---- C:\WINDOWS\system32\vp31vfw.dll
2009-10-16 14:29:25 ----A---- C:\WINDOWS\system32\MACDec.dll
2009-10-16 14:29:22 ----A---- C:\WINDOWS\system32\xvidvfw.dll
2009-10-16 14:29:22 ----A---- C:\WINDOWS\system32\xvidcore.dll
2009-10-16 14:29:22 ----A---- C:\WINDOWS\system32\vsfilter.dll
2009-10-16 14:29:22 ----A---- C:\WINDOWS\system32\vorbisfile.dll
2009-10-16 14:29:22 ----A---- C:\WINDOWS\system32\vorbisenc.dll
2009-10-16 14:29:22 ----A---- C:\WINDOWS\system32\vorbis.dll
2009-10-16 14:29:22 ----A---- C:\WINDOWS\system32\vobsub.dll
2009-10-16 14:29:22 ----A---- C:\WINDOWS\system32\unrar.dll
2009-10-16 14:29:22 ----A---- C:\WINDOWS\system32\OpenQuicktimeLib.dll
2009-10-16 14:29:22 ----A---- C:\WINDOWS\system32\OggDS.dll
2009-10-16 14:29:22 ----A---- C:\WINDOWS\system32\ogg.dll
2009-10-16 14:29:22 ----A---- C:\WINDOWS\system32\mpg4c32.dll
2009-10-16 14:29:22 ----A---- C:\WINDOWS\system32\huffyuv.dll
2009-10-16 14:29:22 ----A---- C:\WINDOWS\system32\3ivxVfWCodec.dll
2009-10-16 14:29:22 ----A---- C:\WINDOWS\system32\3ivx.dll
2009-10-16 14:29:21 ----A---- C:\WINDOWS\system32\WMV9VCM.dll
2009-10-16 14:29:21 ----A---- C:\WINDOWS\system32\divx.dll
2009-10-16 14:29:20 ----D---- C:\Program Files\K-Lite Codec Pack
2009-10-16 14:29:20 ----D---- C:\Documents and Settings\user\Application Data\Real
2009-10-16 14:29:20 ----D---- C:\Documents and Settings\All Users\Application Data\Real
2009-10-16 14:29:20 ----A---- C:\WINDOWS\system32\unicows.dll
2009-10-16 14:29:20 ----A---- C:\WINDOWS\system32\cpuinf32.dll
2009-10-16 14:27:19 ----N---- C:\WINDOWS\system32\vxblock.dll
2009-10-16 14:27:19 ----N---- C:\WINDOWS\system32\pxwave.dll
2009-10-16 14:27:19 ----N---- C:\WINDOWS\system32\pxmas.dll
2009-10-16 14:27:19 ----N---- C:\WINDOWS\system32\pxhpinst.exe
2009-10-16 14:27:19 ----N---- C:\WINDOWS\system32\pxdrv.dll
2009-10-16 14:27:18 ----N---- C:\WINDOWS\system32\px.dll
2009-10-16 14:21:49 ----A---- C:\WINDOWS\ODBC.INI
2009-10-16 14:21:44 ----A---- C:\WINDOWS\system32\mdimon.dll
2009-10-16 14:21:02 ----D---- C:\Program Files\Common Files\L&H
2009-10-16 14:20:51 ----D---- C:\Program Files\Microsoft.NET
2009-10-16 14:20:41 ----D---- C:\Program Files\Microsoft ActiveSync
2009-10-16 14:20:08 ----D---- C:\Program Files\Common Files\DESIGNER
2009-10-16 14:16:48 ----D---- C:\Program Files\Microsoft Works
2009-10-16 14:16:33 ----D---- C:\Program Files\Microsoft Visual Studio
2009-10-16 14:16:04 ----D---- C:\WINDOWS\SHELLNEW
2009-10-16 14:15:51 ----D---- C:\Program Files\Microsoft Office
2009-10-16 14:09:01 ----RA---- C:\WINDOWS\system32\udaprop.dll
2009-10-16 14:09:01 ----RA---- C:\WINDOWS\system32\cmuda.dll
2009-10-16 14:09:01 ----RA---- C:\WINDOWS\system32\cmirmdrv.exe
2009-10-16 14:09:01 ----RA---- C:\WINDOWS\system32\cmirmdrv.dll
2009-10-16 14:09:01 ----RA---- C:\WINDOWS\system32\Audio3D.dll
2009-10-16 14:09:01 ----RA---- C:\WINDOWS\system32\a3d.dll
2009-10-16 14:09:00 ----A---- C:\WINDOWS\system32\ksuser.dll
2009-10-16 14:08:52 ----A---- C:\WINDOWS\CMISETUP.INI
2009-10-16 14:08:51 ----A---- C:\WINDOWS\CMCDPLAY.INI
2009-10-16 14:08:49 ----A---- C:\WINDOWS\Wininit.ini
2009-10-16 14:08:45 ----R---- C:\WINDOWS\Cmuda.ini
2009-10-16 14:08:39 ----D---- C:\Program Files\C-Media 3D Audio
2009-10-16 14:08:39 ----A---- C:\WINDOWS\CMIUninstall.exe
2009-10-16 14:08:39 ----A---- C:\WINDOWS\CmiRmRedundDir.exe
2009-10-16 14:08:39 ----A---- C:\WINDOWS\CMIRmDriver.dll
2009-10-16 14:05:54 ----RA---- C:\WINDOWS\system32\VTuninst.exe
2009-10-16 14:05:54 ----RA---- C:\WINDOWS\system32\VTTimer.exe
2009-10-16 14:05:54 ----RA---- C:\WINDOWS\system32\VTovrlay.dll
2009-10-16 14:05:54 ----RA---- C:\WINDOWS\system32\VTInfo2.dll
2009-10-16 14:05:53 ----RA---- C:\WINDOWS\system32\VTGamma2.dll
2009-10-16 14:05:52 ----RA---- C:\WINDOWS\system32\VTDisply.dll
2009-10-16 14:05:51 ----RA---- C:\WINDOWS\system32\vticd.dll
2009-10-16 14:05:49 ----RA---- C:\WINDOWS\system32\vtdisp.dll
2009-10-16 14:05:45 ----D---- C:\Program Files\S3
2009-10-16 14:02:37 ----D---- C:\WINDOWS\system32\ReinstallBackups
2009-10-16 14:00:54 ----A---- C:\WINDOWS\IsUninst.exe
2009-10-16 14:00:20 ----HD---- C:\Program Files\InstallShield Installation Information
2009-10-16 14:00:01 ----D---- C:\WINDOWS\system32\Tools
2009-10-16 13:59:54 ----D---- C:\Program Files\Common Files\InstallShield
2009-10-16 13:59:12 ----RA---- C:\DBI.EXE
2009-10-16 13:54:49 ----D---- C:\Documents and Settings\user\Application Data\Identities
2009-10-16 13:54:48 ----HD---- C:\Program Files\Uninstall Information
2009-10-16 13:54:40 ----SD---- C:\Documents and Settings\user\Application Data\Microsoft
2009-10-16 13:54:40 ----ASH---- C:\Documents and Settings\user\Application Data\desktop.ini
2009-10-16 13:54:05 ----SHD---- C:\System Volume Information
2009-10-16 13:54:05 ----D---- C:\WINDOWS\SoftwareDistribution
2009-10-16 13:54:04 ----SD---- C:\WINDOWS\system32\Microsoft
2009-10-16 13:54:04 ----D---- C:\WINDOWS\Prefetch
2009-10-16 13:54:04 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-10-16 13:47:57 ----D---- C:\WINDOWS\system32\xircom
2009-10-16 13:47:57 ----D---- C:\Program Files\xerox
2009-10-16 13:47:57 ----D---- C:\Program Files\windows media player
2009-10-16 13:47:57 ----D---- C:\Program Files\microsoft frontpage
2009-10-16 13:46:13 ----N---- C:\WINDOWS\system32\spmsg.dll
2009-10-16 13:46:10 ----A---- C:\WINDOWS\system32\xpsp3res.dll
2009-10-16 13:46:08 ----N---- C:\WINDOWS\system32\setupn.exe
2009-10-16 13:45:50 ----A---- C:\WINDOWS\control.ini
2009-10-16 13:45:50 ----A---- C:\AUTOEXEC.BAT
2009-10-16 13:45:44 ----A---- C:\WINDOWS\system32\mapi32.dll
2009-10-16 13:44:46 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-10-16 13:44:46 ----RD---- C:\WINDOWS\Offline Web Pages
2009-10-16 13:44:46 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest
2009-10-16 13:44:40 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest
2009-10-16 13:44:36 ----HD---- C:\Program Files\WindowsUpdate
2009-10-16 13:44:19 ----D---- C:\WINDOWS\system32\DirectX
2009-10-16 13:44:09 ----A---- C:\WINDOWS\system32\atrace.dll
2009-10-16 13:44:08 ----A---- C:\WINDOWS\system32\desktop.ini
2009-10-16 13:44:08 ----A---- C:\WINDOWS\desktop.ini
2009-10-16 13:44:03 ----A---- C:\WINDOWS\system32\nmevtmsg.dll
2009-10-16 13:44:02 ----A---- C:\WINDOWS\system32\acctres.dll
2009-10-16 13:44:01 ----D---- C:\Program Files\Common Files\Services
2009-10-16 13:44:00 ----SD---- C:\WINDOWS\Tasks
2009-10-16 13:44:00 ----A---- C:\WINDOWS\system32\icfgnt5.dll
2009-10-16 13:43:59 ----D---- C:\Program Files\Common Files\MSSoap
2009-10-16 13:43:56 ----D---- C:\WINDOWS\srchasst
2009-10-16 13:43:55 ----D---- C:\WINDOWS\system32\Macromed
2009-10-16 13:43:55 ----A---- C:\WINDOWS\system32\wuweb.dll
2009-10-16 13:43:55 ----A---- C:\WINDOWS\system32\wups.dll
2009-10-16 13:43:55 ----A---- C:\WINDOWS\system32\wucltui.dll
2009-10-16 13:43:55 ----A---- C:\WINDOWS\system32\wuauserv.dll
2009-10-16 13:43:55 ----A---- C:\WINDOWS\system32\wuaueng1.dll
2009-10-16 13:43:55 ----A---- C:\WINDOWS\system32\wuaueng.dll
2009-10-16 13:43:55 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2009-10-16 13:43:55 ----A---- C:\WINDOWS\system32\wuauclt.exe
2009-10-16 13:43:55 ----A---- C:\WINDOWS\system32\wuapi.dll
2009-10-16 13:43:54 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
2009-10-16 13:43:54 ----A---- C:\WINDOWS\system32\qmgr.dll
2009-10-16 13:43:54 ----A---- C:\WINDOWS\system32\bitsprx3.dll
2009-10-16 13:43:54 ----A---- C:\WINDOWS\system32\bitsprx2.dll
2009-10-16 13:43:51 ----SHD---- C:\Program Files\Movie Maker
2009-10-16 13:43:48 ----A---- C:\WINDOWS\system32\safrslv.dll
2009-10-16 13:43:48 ----A---- C:\WINDOWS\system32\safrdm.dll
2009-10-16 13:43:48 ----A---- C:\WINDOWS\system32\safrcdlg.dll
2009-10-16 13:43:48 ----A---- C:\WINDOWS\system32\racpldlg.dll
2009-10-16 13:43:45 ----D---- C:\WINDOWS\system32\Restore
2009-10-16 13:43:45 ----A---- C:\WINDOWS\system32\srsvc.dll
2009-10-16 13:43:45 ----A---- C:\WINDOWS\system32\srrstr.dll
2009-10-16 13:43:45 ----A---- C:\WINDOWS\system32\srclient.dll
2009-10-16 13:43:45 ----A---- C:\WINDOWS\system32\fltMc.exe
2009-10-16 13:43:45 ----A---- C:\WINDOWS\system32\fltlib.dll
2009-10-16 13:43:44 ----A---- C:\WINDOWS\system32\nmmkcert.dll
2009-10-16 13:43:44 ----A---- C:\WINDOWS\system32\msconf.dll
2009-10-16 13:43:44 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2009-10-16 13:43:44 ----A---- C:\WINDOWS\system32\mnmdd.dll
2009-10-16 13:43:44 ----A---- C:\WINDOWS\system32\isrdbg32.dll
2009-10-16 13:43:44 ----A---- C:\WINDOWS\system32\ils.dll
2009-10-16 13:43:42 ----D---- C:\Program Files\NetMeeting
2009-10-16 13:43:42 ----A---- C:\WINDOWS\system32\msoert2.dll
2009-10-16 13:43:42 ----A---- C:\WINDOWS\system32\msoeacct.dll
2009-10-16 13:43:41 ----A---- C:\WINDOWS\system32\inetres.dll
2009-10-16 13:43:41 ----A---- C:\WINDOWS\system32\inetcomm.dll
2009-10-16 13:43:39 ----D---- C:\Program Files\Outlook Express
2009-10-16 13:43:39 ----A---- C:\WINDOWS\system32\schedsvc.dll
2009-10-16 13:43:39 ----A---- C:\WINDOWS\system32\mstinit.exe
2009-10-16 13:43:39 ----A---- C:\WINDOWS\system32\mstask.dll
2009-10-16 13:43:39 ----A---- C:\WINDOWS\system32\isign32.dll
2009-10-16 13:43:39 ----A---- C:\WINDOWS\system32\inetcfg.dll
2009-10-16 13:43:39 ----A---- C:\WINDOWS\system32\icwphbk.dll
2009-10-16 13:43:39 ----A---- C:\WINDOWS\system32\icwdial.dll
2009-10-16 13:43:35 ----D---- C:\Program Files\Common Files\System
2009-10-16 13:43:33 ----D---- C:\Program Files\Internet Explorer
2009-10-16 13:42:45 ----A---- C:\WINDOWS\vbaddin.ini
2009-10-16 13:42:45 ----A---- C:\WINDOWS\vb.ini
2009-10-16 13:42:41 ----D---- C:\WINDOWS\Registration
2009-10-16 13:42:34 ----D---- C:\Program Files\Online Services
2009-10-16 13:42:26 ----D---- C:\Program Files\Messenger
2009-10-16 13:42:23 ----D---- C:\Program Files\MSN Gaming Zone
2009-10-16 13:42:23 ----A---- C:\WINDOWS\system32\write.exe
2009-10-16 13:42:16 ----A---- C:\WINDOWS\system32\sndvol32.exe
2009-10-16 13:42:16 ----A---- C:\WINDOWS\system32\hticons.dll
2009-10-16 13:42:16 ----A---- C:\WINDOWS\system32\avwav.dll
2009-10-16 13:42:16 ----A---- C:\WINDOWS\system32\avtapi.dll
2009-10-16 13:42:16 ----A---- C:\WINDOWS\system32\avmeter.dll
2009-10-16 13:42:15 ----A---- C:\WINDOWS\system32\winchat.exe
2009-10-16 13:42:11 ----A---- C:\WINDOWS\system32\getuname.dll
2009-10-16 13:42:10 ----A---- C:\WINDOWS\system32\winmine.exe
2009-10-16 13:42:10 ----A---- C:\WINDOWS\system32\sol.exe
2009-10-16 13:42:10 ----A---- C:\WINDOWS\system32\mshearts.exe
2009-10-16 13:42:10 ----A---- C:\WINDOWS\system32\freecell.exe
2009-10-16 13:42:10 ----A---- C:\WINDOWS\system32\charmap.exe
2009-10-16 13:42:10 ----A---- C:\WINDOWS\system32\calc.exe
2009-10-16 13:42:09 ----A---- C:\WINDOWS\system32\usrlogon.cmd
2009-10-16 13:42:09 ----A---- C:\WINDOWS\system32\tsshutdn.exe
2009-10-16 13:42:09 ----A---- C:\WINDOWS\system32\tslabels.ini
2009-10-16 13:42:09 ----A---- C:\WINDOWS\system32\tskill.exe
2009-10-16 13:42:09 ----A---- C:\WINDOWS\system32\tsdiscon.exe
2009-10-16 13:42:09 ----A---- C:\WINDOWS\system32\tscon.exe
2009-10-16 13:42:09 ----A---- C:\WINDOWS\system32\shadow.exe
2009-10-16 13:42:09 ----A---- C:\WINDOWS\system32\rwinsta.exe
2009-10-16 13:42:09 ----A---- C:\WINDOWS\system32\reset.exe
2009-10-16 13:42:09 ----A---- C:\WINDOWS\system32\regini.exe
2009-10-16 13:42:09 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
2009-10-16 13:42:09 ----A---- C:\WINDOWS\system32\qwinsta.exe
2009-10-16 13:42:09 ----A---- C:\WINDOWS\system32\qappsrv.exe
2009-10-16 13:42:09 ----A---- C:\WINDOWS\system32\msg.exe
2009-10-16 13:42:09 ----A---- C:\WINDOWS\system32\logoff.exe
2009-10-16 13:42:09 ----A---- C:\WINDOWS\system32\cdmodem.dll
2009-10-16 13:42:08 ----A---- C:\WINDOWS\system32\mtxlegih.dll
2009-10-16 13:42:08 ----A---- C:\WINDOWS\system32\mtxex.dll
2009-10-16 13:42:08 ----A---- C:\WINDOWS\system32\mtxdm.dll
2009-10-16 13:42:08 ----A---- C:\WINDOWS\system32\msdtcprf.ini
2009-10-16 13:42:08 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2009-10-16 13:42:08 ----A---- C:\WINDOWS\system32\comrepl.dll
2009-10-16 13:42:08 ----A---- C:\WINDOWS\system32\comaddin.dll
2009-10-16 13:42:07 ----A---- C:\WINDOWS\system32\stclient.dll
2009-10-16 13:42:07 ----A---- C:\WINDOWS\system32\comsnap.dll
2009-10-16 13:42:04 ----A---- C:\WINDOWS\system32\wmimgmt.msc
2009-10-16 13:41:55 ----D---- C:\Program Files\MSN
2009-10-16 13:41:55 ----A---- C:\WINDOWS\system32\accwiz.exe
2009-10-16 13:41:54 ----D---- C:\Program Files\Windows NT
2009-10-16 13:41:54 ----A---- C:\WINDOWS\system32\sndrec32.exe
2009-10-16 13:41:54 ----A---- C:\WINDOWS\system32\mspaint.exe
2009-10-16 13:41:54 ----A---- C:\WINDOWS\system32\hypertrm.dll
2009-10-16 13:41:54 ----A---- C:\WINDOWS\system32\clipbrd.exe
2009-10-16 13:41:53 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
2009-10-16 13:41:53 ----A---- C:\WINDOWS\system32\spider.exe
2009-10-16 13:41:53 ----A---- C:\WINDOWS\system32\sessmgr.exe
2009-10-16 13:41:53 ----A---- C:\WINDOWS\system32\remotepg.dll
2009-10-16 13:41:53 ----A---- C:\WINDOWS\system32\rdshost.exe
2009-10-16 13:41:53 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2009-10-16 13:41:53 ----A---- C:\WINDOWS\system32\mstscax.dll
2009-10-16 13:41:53 ----A---- C:\WINDOWS\system32\mstsc.exe
2009-10-16 13:41:52 ----D---- C:\WINDOWS\system32\MsDtc
2009-10-16 13:41:52 ----A---- C:\WINDOWS\system32\tscupgrd.exe
2009-10-16 13:41:52 ----A---- C:\WINDOWS\system32\termsrv.dll
2009-10-16 13:41:52 ----A---- C:\WINDOWS\system32\rdpwsx.dll
2009-10-16 13:41:52 ----A---- C:\WINDOWS\system32\rdpsnd.dll
2009-10-16 13:41:52 ----A---- C:\WINDOWS\system32\rdpclip.exe
2009-10-16 13:41:52 ----A---- C:\WINDOWS\system32\rdchost.dll
2009-10-16 13:41:52 ----A---- C:\WINDOWS\system32\qprocess.exe
2009-10-16 13:41:52 ----A---- C:\WINDOWS\system32\mtxoci.dll
2009-10-16 13:41:52 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
2009-10-16 13:41:52 ----A---- C:\WINDOWS\system32\icaapi.dll
2009-10-16 13:41:52 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2009-10-16 13:41:51 ----A---- C:\WINDOWS\system32\xolehlp.dll
2009-10-16 13:41:51 ----A---- C:\WINDOWS\system32\msdtctm.dll
2009-10-16 13:41:51 ----A---- C:\WINDOWS\system32\msdtcprx.dll
2009-10-16 13:41:51 ----A---- C:\WINDOWS\system32\msdtclog.dll
2009-10-16 13:41:51 ----A---- C:\WINDOWS\system32\msdtc.exe
2009-10-16 13:41:50 ----D---- C:\WINDOWS\system32\Com
2009-10-16 13:41:50 ----A---- C:\WINDOWS\system32\comuid.dll
2009-10-16 13:41:50 ----A---- C:\WINDOWS\system32\comsvcs.dll
2009-10-16 13:41:50 ----A---- C:\WINDOWS\system32\colbact.dll
2009-10-16 13:41:50 ----A---- C:\WINDOWS\system32\clbcatex.dll
2009-10-16 13:41:50 ----A---- C:\WINDOWS\system32\catsrvut.dll
2009-10-16 13:41:50 ----A---- C:\WINDOWS\system32\catsrvps.dll
2009-10-16 13:41:50 ----A---- C:\WINDOWS\system32\catsrv.dll
2009-10-16 13:41:49 ----A---- C:\WINDOWS\system32\clbcatq.dll
2009-10-16 13:41:45 ----A---- C:\WINDOWS\system32\servdeps.dll
2009-10-16 13:41:45 ----A---- C:\WINDOWS\system32\mmfutil.dll
2009-10-16 13:41:45 ----A---- C:\WINDOWS\system32\licwmi.dll
2009-10-16 13:41:45 ----A---- C:\WINDOWS\system32\cmprops.dll
2009-10-16 13:38:25 ----A---- C:\WINDOWS\system32\h323log.txt
2009-10-16 13:32:19 ----A---- C:\WINDOWS\system32\usbui.dll
2009-10-16 13:31:17 ----SHD---- C:\WINDOWS\Installer
2009-10-16 13:31:17 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-10-16 13:31:16 ----D---- C:\Program Files\Common Files\ODBC
2009-10-16 13:31:16 ----A---- C:\WINDOWS\ODBCINST.INI
2009-10-16 13:31:13 ----RD---- C:\Program Files
2009-10-16 13:31:13 ----D---- C:\Program Files\Common Files\SpeechEngines
2009-10-16 13:31:13 ----D---- C:\Program Files\Common Files\Microsoft Shared
2009-10-16 13:31:13 ----D---- C:\Program Files\Common Files
2009-10-16 13:31:10 ----RA---- C:\WINDOWS\system32\kbdtuq.dll
2009-10-16 13:31:10 ----RA---- C:\WINDOWS\system32\kbdtuf.dll
2009-10-16 13:31:10 ----RA---- C:\WINDOWS\system32\kbdazel.dll
2009-10-16 13:31:09 ----RA---- C:\WINDOWS\system32\kbdycc.dll
2009-10-16 13:31:09 ----RA---- C:\WINDOWS\system32\kbduzb.dll
2009-10-16 13:31:09 ----RA---- C:\WINDOWS\system32\kbdur.dll
2009-10-16 13:31:09 ----RA---- C:\WINDOWS\system32\kbdtat.dll
2009-10-16 13:31:09 ----RA---- C:\WINDOWS\system32\kbdru1.dll
2009-10-16 13:31:09 ----RA---- C:\WINDOWS\system32\kbdru.dll
2009-10-16 13:31:09 ----RA---- C:\WINDOWS\system32\kbdmon.dll
2009-10-16 13:31:09 ----RA---- C:\WINDOWS\system32\kbdkyr.dll
2009-10-16 13:31:09 ----RA---- C:\WINDOWS\system32\kbdkaz.dll
2009-10-16 13:31:09 ----RA---- C:\WINDOWS\system32\kbdbu.dll
2009-10-16 13:31:09 ----RA---- C:\WINDOWS\system32\kbdblr.dll
2009-10-16 13:31:09 ----RA---- C:\WINDOWS\system32\kbdaze.dll
2009-10-16 13:31:07 ----RA---- C:\WINDOWS\system32\kbdhept.dll
2009-10-16 13:31:07 ----RA---- C:\WINDOWS\system32\kbdhela3.dll
2009-10-16 13:31:07 ----RA---- C:\WINDOWS\system32\kbdhela2.dll
2009-10-16 13:31:07 ----RA---- C:\WINDOWS\system32\kbdhe319.dll
2009-10-16 13:31:07 ----RA---- C:\WINDOWS\system32\kbdhe220.dll
2009-10-16 13:31:07 ----RA---- C:\WINDOWS\system32\kbdhe.dll
2009-10-16 13:31:07 ----RA---- C:\WINDOWS\system32\kbdgkl.dll
2009-10-16 13:31:06 ----RA---- C:\WINDOWS\system32\kbdlv1.dll
2009-10-16 13:31:06 ----RA---- C:\WINDOWS\system32\kbdlv.dll
2009-10-16 13:31:06 ----RA---- C:\WINDOWS\system32\kbdlt1.dll
2009-10-16 13:31:06 ----RA---- C:\WINDOWS\system32\kbdlt.dll
2009-10-16 13:31:06 ----RA---- C:\WINDOWS\system32\kbdest.dll
2009-10-16 13:31:05 ----RA---- C:\WINDOWS\system32\kbdycl.dll
2009-10-16 13:31:05 ----RA---- C:\WINDOWS\system32\kbdsl1.dll
2009-10-16 13:31:05 ----RA---- C:\WINDOWS\system32\kbdsl.dll
2009-10-16 13:31:05 ----RA---- C:\WINDOWS\system32\kbdro.dll
2009-10-16 13:31:05 ----RA---- C:\WINDOWS\system32\kbdpl1.dll
2009-10-16 13:31:05 ----RA---- C:\WINDOWS\system32\kbdpl.dll
2009-10-16 13:31:05 ----RA---- C:\WINDOWS\system32\kbdhu1.dll
2009-10-16 13:31:05 ----RA---- C:\WINDOWS\system32\kbdhu.dll
2009-10-16 13:31:05 ----RA---- C:\WINDOWS\system32\kbdcz2.dll
2009-10-16 13:31:05 ----RA---- C:\WINDOWS\system32\kbdcz1.dll
2009-10-16 13:31:05 ----RA---- C:\WINDOWS\system32\kbdcz.dll
2009-10-16 13:31:05 ----RA---- C:\WINDOWS\system32\kbdcr.dll
2009-10-16 13:31:05 ----RA---- C:\WINDOWS\system32\KBDAL.DLL
2009-10-16 13:31:03 ----A---- C:\WINDOWS\system32\irclass.dll
2009-10-16 13:31:03 ----A---- C:\WINDOWS\system32\dgsetup.dll
2009-10-16 13:31:03 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
2009-10-16 13:31:02 ----A---- C:\WINDOWS\system32\spxcoins.dll
2009-10-16 13:31:02 ----A---- C:\WINDOWS\system32\EqnClass.Dll
2009-10-16 13:31:01 ----N---- C:\WINDOWS\system32\CONFIG.TMP
2009-10-16 13:31:01 ----A---- C:\WINDOWS\TASKMAN.EXE
2009-10-16 13:31:00 ----A---- C:\WINDOWS\system32\batt.dll
2009-10-16 13:31:00 ----A---- C:\WINDOWS\NOTEPAD.EXE
2009-10-16 13:30:59 ----A---- C:\WINDOWS\system32\storprop.dll
2009-10-16 13:30:52 ----RA---- C:\WINDOWS\SET28.tmp
2009-10-16 13:30:52 ----ASH---- C:\Documents and Settings\All Users\Application Data\desktop.ini
2009-10-16 13:30:51 ----RA---- C:\WINDOWS\SET27.tmp
2009-10-16 13:30:48 ----RA---- C:\WINDOWS\SET8.tmp
2009-10-16 13:30:46 ----RA---- C:\WINDOWS\SET4.tmp
2009-10-16 13:30:44 ----RA---- C:\WINDOWS\SET3.tmp
2009-10-16 13:30:38 ----D---- C:\WINDOWS\system32\CatRoot2
2009-10-16 13:30:38 ----D---- C:\WINDOWS\system32\CatRoot
2009-10-16 13:30:33 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2009-10-16 13:30:12 ----D---- C:\Documents and Settings
2009-10-16 13:29:20 ----N---- C:\boot.ini
2009-10-16 13:24:16 ----RSHD---- C:\WINDOWS\system32\dllcache
2009-10-16 13:24:16 ----RSD---- C:\WINDOWS\Fonts
2009-10-16 13:24:16 ----RD---- C:\WINDOWS\Web
2009-10-16 13:24:16 ----HD---- C:\WINDOWS\inf
2009-10-16 13:24:16 ----D---- C:\WINDOWS\WinSxS
2009-10-16 13:24:16 ----D---- C:\WINDOWS\twain_32
2009-10-16 13:24:16 ----D---- C:\WINDOWS\Temp
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\wins
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\wbem
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\usmt
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\spool
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\ShellExt
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\Setup
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\ras
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\oobe
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\npp
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\mui
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\inetsrv
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\IME
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\icsxml
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\ias
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\export
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\drivers
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\dhcp
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\config
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\3com_dmi
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\3076
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\2052
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\1054
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\1042
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\1041
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\1037
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\1033
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\1031
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\1028
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32\1025
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system32
2009-10-16 13:24:16 ----D---- C:\WINDOWS\system
2009-10-16 13:24:16 ----D---- C:\WINDOWS\security
2009-10-16 13:24:16 ----D---- C:\WINDOWS\Resources
2009-10-16 13:24:16 ----D---- C:\WINDOWS\repair
2009-10-16 13:24:16 ----D---- C:\WINDOWS\Provisioning
2009-10-16 13:24:16 ----D---- C:\WINDOWS\PeerNet
2009-10-16 13:24:16 ----D---- C:\WINDOWS\pchealth
2009-10-16 13:24:16 ----D---- C:\WINDOWS\mui
2009-10-16 13:24:16 ----D---- C:\WINDOWS\msapps
2009-10-16 13:24:16 ----D---- C:\WINDOWS\msagent
2009-10-16 13:24:16 ----D---- C:\WINDOWS\Media
2009-10-16 13:24:16 ----D---- C:\WINDOWS\java
2009-10-16 13:24:16 ----D---- C:\WINDOWS\ime
2009-10-16 13:24:16 ----D---- C:\WINDOWS\Help
2009-10-16 13:24:16 ----D---- C:\WINDOWS\ehome
2009-10-16 13:24:16 ----D---- C:\WINDOWS\Driver Cache
2009-10-16 13:24:16 ----D---- C:\WINDOWS\Debug
2009-10-16 13:24:16 ----D---- C:\WINDOWS\Cursors
2009-10-16 13:24:16 ----D---- C:\WINDOWS\Connection Wizard
2009-10-16 13:24:16 ----D---- C:\WINDOWS\Config
2009-10-16 13:24:16 ----D---- C:\WINDOWS\AppPatch
2009-10-16 13:24:16 ----D---- C:\WINDOWS\addins
2009-10-16 13:24:16 ----D---- C:\WINDOWS

======List of files/folders modified in the last 1 months======

2009-11-04 12:44:28 ----A---- C:\WINDOWS\win.ini
2009-10-16 13:31:14 ----A---- C:\WINDOWS\system.ini

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AmdK7;AMD K7 Processor Driver; C:\WINDOWS\system32\DRIVERS\amdk7.sys [2005-06-14 37376]
R1 KLIF;Kaspersky Lab Driver; C:\WINDOWS\system32\DRIVERS\klif.sys [2009-10-19 296976]
R3 cmuda;C-Media WDM Audio Interface; C:\WINDOWS\system32\drivers\cmuda.sys [2004-08-23 821760]
R3 FETND5BV;VIA Rhine-Family Fast Ethernet Adapter Driver Service; C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [2004-12-16 42496]
R3 KeyScramblerDrv;KeyScramblerDrv; C:\WINDOWS\System32\drivers\keyscrambler.sys [2008-06-25 113896]
R3 klmouflt;Kaspersky Lab KLMOUFLT; C:\WINDOWS\system32\DRIVERS\klmouflt.sys [2009-05-16 19472]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2005-06-14 26624]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2005-06-14 57600]
R3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2005-06-14 20480]
R3 viagfx;viagfx; C:\WINDOWS\system32\DRIVERS\vtmini.sys [2004-09-27 173440]
S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\fetnd5.sys [2001-08-17 27165]
S3 FETNDISB;VIA Rhine Family Fast Ethernet Adapter Driver Service; C:\WINDOWS\system32\DRIVERS\fetnd5b.sys [2004-01-09 42496]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AVP;Kaspersky Internet Security; C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe [2009-07-03 303376]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-10-20 153376]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2009-10-16 72704]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

#8 syler

syler

  • Malware Response Team
  • 8,150 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Warrington, UK
  • Local time:01:22 AM

Posted 06 November 2009 - 02:55 PM

ursaminor,

Your logs look ok to me, except for the program crack that you have, I suggest you delete this folder.

C:\DOCUME~1\user\My Documents\Unduhan\Expert Advisor


Download and Run OTC

We will now remove the tools we used during this fix using OTC.
  • Download OTC by OldTimer and save it to your desktop.
  • Double click Posted Image icon to start the program. If you are using Vista, please right-click and choose run as administrator
  • Then Click the big Posted Image button.
  • You will get a prompt saying "Being Cleanup Process". Please select Yes.
  • Restart your computer when prompted.
Congratulations! You now appear clean! :(

Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:

Cleaning and creating restore points
  • Click Start, right click My Computer and select properties.
  • Select the System Restore tab then check the box "Turn off System Restore".
  • Click Apply then Ok, then restart your computer
  • Now follow these steps again, but instead of checking "Turn off System Restore" Uncheck it.
Now that you have cleaned out you restore points you need to set a new restore point
  • Go to Start > Programs > Accessories > System Tools and click "System Restore".
  • Select "Create a restore point" then click Next.
  • Type a name under Restore point description then click Create.
Additional instructions can be found here if needed.

Note: This does not need to be done on a regular basis.

Updated Windows
You don't have the latest service pack for windows, The service packs patch security vulnerabilities found in windows. You should
keep these upto date to keep you protected against malware, that can take advantage of these security vulnerabilities to attack
your system.The latest service pack is SP3, Click on Start >> All programs >> Windows update then select Express
and allow it to install all updates including SP3.
Note: If it prompts you to install an ActiveX control allow it to install it.

To do this Click on Start >> Control Panel >> Automatic updates and click Automatic (recommended) then Apply and Ok

Update your AntiVirus Software
It is imperative that you update your Antivirus software at least once a week (Even more if you wish). If you do not
update your antivirus software then it will not be able to catch any of the new variants that may come out. If you
use a commercial antivirus program you must make sure you keep renewing your subscription. Otherwise, once your
subscription runs out, you may not be able to update the programs virus definitions.

Make sure your applications have all of their updates
It is also possible for other programs on your computer to have security vulnerability that can allow malware to infect you.
Therefore, it is also a good idea to check for the latest versions of commonly installed applications that are regularly
patched to fix vulnerabilities. You can check these by visiting Secunia Software Inspector and Calendar of Updates.

Install an AntiSpyware Program
A highly recommended AntiSpyware program is SuperAntiSpyware. You can download the free Home Version. or the Pro version for a 15 day trial period.
Other recommended, and free, AntiSpyware programs are Spybot - Search and Destroy and Ad-Aware Personal.
Installing these programs will provide spyware & hijacker protection on your computer alongside your virus protection. You should scan your computer with an AntiSpyware program on a regular basis just as you would an antivirus software.
Tutorials on using these programs can be found below:
Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers
Using Ad-aware to remove Spyware, Malware, & Hijackers from Your Computer

Install SpywareBlaster
SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you
from running and downloading known malicious programs.

A tutorial on installing & using this product can be found here:
Using SpywareBlaster to protect your computer from Spyware and Malware

Use MVPS hosts file
Using a custom host file like the MVPS HOSTS file can help to block ads, banners, 3rd party Cookies,
3rd party page counters, web bugs, and even most hijackers. It doesn't use up any extra system resources
and may even speed up the loading of web pages. You can download and find instructions below.

http://www.mvps.org/winhelp2002/hosts.htm

Update all these programs regularly
Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.

Follow this list and your potential for being infected again will reduce dramatically.

Happy surfing :(
Syler

Edited by syler, 06 November 2009 - 02:56 PM.

unite.jpg


#9 ursaminor

ursaminor
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:07:22 AM

Posted 07 November 2009 - 05:31 AM

Thank you.. thank you.. :(
Now my computer clean and more faster than before.

Thank you syler for your help :(

#10 syler

syler

  • Malware Response Team
  • 8,150 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Warrington, UK
  • Local time:01:22 AM

Posted 07 November 2009 - 01:24 PM

Your welcome.

Since this issue appears resolved ... this Topic is closed. Glad we could help.

If you need this topic reopened, please request this by sending me a PM
with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic.

unite.jpg





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users