Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Trojan Agent_R.OT


  • This topic is locked This topic is locked
4 replies to this topic

#1 atencorps

atencorps

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:06:30 PM

Posted 09 November 2009 - 01:07 PM

Hello,

I had a virus/trojan installed on my PC yesterday. I tried smartscan by trendmicro and it didnt find a thing.

I tried avg anti-virus and that popped up about 56 files infected. After using AVG i restarted the PC and the virus/trojan is still there.

The trojan / virus has deleted several of windows links ( ie link on toolbar to notepad, link on toolbar to control panel etc )..

I have used the RSIT.exe tool mentioned when I found this forum (strangely googlesearch brought me here whilst looking for solution but the other thread had yet to post their logs ).


Oh AVG tells me its (trojan horse agent_r.ot


Thanks in advance for your help.
____
Info
____
info.txt logfile of random's system information tool 1.06 2009-11-09 18:35:29

======Uninstall list======

-->C:Program FilesCommon FilesRealUpdate_OBr1puninst.exe RealNetworks|RealPlayer|6.0
-->C:Program FilesConexantSmartAudioSETUP.EXE -U -ISmartAudio -SM=SMAUDIO.EXE,1801
-->C:Program FilesDivXDivXConverterUninstall.exe /CONVERTER
32 Bit HP CIO Components Installer-->MsiExec.exe /I{2614F54E-A828-49FA-93BA-45A3F756BFAA}
Activation Assistant for the 2007 Microsoft Office suites-->"C:ProgramData{174892B1-CBE7-44F5-86FF-AB555EFD73A3}Microsoft Office Activation Assistant.exe" REMOVE=TRUE MODIFY=FALSE
ActiveCheck component for HP Active Support Library-->MsiExec.exe /X{254C37AA-6B72-4300-84F6-98A82419187E}
ActiveState ActivePython 2.6.0.0-->MsiExec.exe /I{A1D14FC8-FF6E-4700-A501-BCAFD22B7D15}
ActiveState Komodo IDE 5.0.3-->MsiExec.exe /I{5E63FDF8-59A1-4276-BB26-3783A59CECE2}
Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)-->MsiExec.exe /X{6846389C-BAC0-4374-808E-B120F86AF5D7}
Adobe Flash Player 10 ActiveX-->C:Windowssystem32MacromedFlashuninstall_activeX.exe
Adobe Flash Player 10 Plugin-->C:Windowssystem32MacromedFlashuninstall_plugin.exe
Adobe Reader 8.1.2-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81200000003}
Adobe Shockwave Player 11-->C:Windowssystem32adobeSHOCKW~1UNWISE.EXE C:Windowssystem32AdobeSHOCKW~1Install.log
Adobe Shockwave Player-->MsiExec.exe /X{1BDC9633-895B-4842-BCB6-8FA1EC2A3C5A}
Apple Software Update-->MsiExec.exe /I{02DFF6B1-1654-411C-8D7B-FD6052EF016F}
Atheros Driver Installation Program-->RunDll32 C:PROGRA~1COMMON~1INSTAL~1PROFES~1RunTime1150Intel32Ctor.dll,LaunchSetup "C:Program FilesInstallShield Installation Information{28006915-2739-4EBE-B5E8-49B25D32EB33}setup.exe" -l0x9 -removeonly
AVG Free 9.0-->C:Program FilesAVGAVG9setup.exe /UNINSTALL
AVIcodec (remove only)-->"C:Program FilesAVIcodecuninst.exe"
Bulk Image Downloader v2.15.0.4-->"C:Program FilesBulk Image Downloaderunins000.exe"
CCleaner-->"C:Program FilesCCleaneruninst.exe"
Championship Manager 2007-->RunDll32 C:PROGRA~1COMMON~1INSTAL~1PROFES~1RunTime1000Intel32Ctor.dll,LaunchSetup "C:Program FilesInstallShield Installation Information{25FED2B8-57D5-4A0D-98BF-973411E0D43E}setup.exe" -l0x9 -removeonly
Compatibility Pack for the 2007 Office system-->MsiExec.exe /X{90120000-0020-0409-0000-0000000FF1CE}
Conexant HD Audio-->C:Program FilesCONEXANTCNXT_AUDIO_HDAUIU32a.exe -U -IQh30CFza.INF
CyberLink YouCam-->"C:Program FilesInstallShield Installation Information{01FB4998-33C4-4431-85ED-079E3EEFE75D}setup.exe" /z-uninstall
Defraggler (remove only)-->"C:Program FilesDefraggleruninst.exe"
DivX Codec-->C:Program FilesDivXDivXCodecUninstall.exe /CODEC
DivX Converter-->C:Program FilesDivXDivXConverterUninstall.exe /CONVERTER
DivX Player-->C:Program FilesDivXDivXPlayerUninstall.exe /PLAYER
DivX Plus DirectShow Filters-->C:Program FilesDivXDivXDSFiltersUninstall.exe /DSFILTERS
DivX Web Player-->C:Program FilesDivXDivXWebPlayerUninstall.exe /PLUGIN
DVD Suite-->RunDll32 C:PROGRA~1COMMON~1INSTAL~1engine6INTEL3~1Ctor.dll,LaunchSetup "C:Program FilesInstallShield Installation Information{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}setup.exe" -uninstall
FileZilla Client 3.2.2.1-->C:Program FilesFileZilla FTP Clientuninstall.exe
FLV Player 2.0 (build 25)-->C:Program FilesFLV Playeruninst.exe
FrostWire 4.17.2-->C:Program FilesFrostWireUninstall.exe
GIMP 2.4.7-->"C:Program FilesGIMP-2.0setupunins000.exe"
GlassFish V2.1-->"C:Program Filesglassfish-v2.1uninstall.exe"
GlassFish v3 Prelude-->"C:Program Filesglassfish-v3-preludeuninstall.exe"
Hauppauge MCE XP/Vista Software Encoder (2.0.25149)-->C:PROGRA~1WinTVUNSftMCE.EXE C:PROGRA~1WinTVsoftMCE.LOG
HDAUDIO Soft Data Fax Modem with SmartCP-->C:Program FilesCONEXANTCNXT_MODEM_HDA_HSFUIU32m.exe -U -I*.INF
HijackThis 2.0.2-->"C:Program Filestrend microHijackThis.exe" /uninstall
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:Windowssystem32msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:Windowssystem32msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
HouseCall 6.6-->"C:UsersesiaboniAppDataRoamingHouseCall 6.6uninstaller.exe"
HP Active Support Library-->C:Program FilesInstallShield Installation Information{5DAA9C36-8F8B-462F-8CCA-E205BC3751F5}setup.exe -runfromtemp -l0x0409
HP Customer Experience Enhancements-->RunDll32 C:PROGRA~1COMMON~1INSTAL~1PROFES~1RunTime1100Intel32Ctor.dll,LaunchSetup "C:Program FilesInstallShield Installation Information{BD0E2B92-3814-46F0-893B-4612EA010C7E}setup.exe" -l0x9 -removeonly
HP Doc Viewer-->MsiExec.exe /I{082702D5-5DD8-4600-BCE5-48B15174687F}
HP Easy Setup - Frontend-->RunDll32 C:PROGRA~1COMMON~1INSTAL~1PROFES~1RunTime1100Intel32Ctor.dll,LaunchSetup "C:Program FilesInstallShield Installation Information{9885A11E-60E4-417C-B58B-8B31B21C0B8A}setup.exe" -l0x9 -removeonly
HP Help and Support-->MsiExec.exe /X{31216452-5540-4C96-B754-94890A63D5AB}
HP Integrated Module with Bluetooth wireless technology 6.0.1.5500-->MsiExec.exe /X{03D1988F-469F-4843-8E6E-E5FE9D17889D}
HP Photosmart Essential 2.5-->C:Program FilesHPDigital ImagingPhotoSmartEssentialhpzscr01.exe -datfile hpqbud13.dat
HP Product Detection-->MsiExec.exe /X{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}
HP Quick Launch Buttons 6.30 E1-->C:Program FilesInstallShield Installation Information{34D2AB40-150D-475D-AE32-BD23FB5EE355}setup.exe -runfromtemp -l0x0009 uninst
HP QuickPlay 3.6-->RunDll32 C:PROGRA~1COMMON~1INSTAL~1engine6INTEL3~1Ctor.dll,LaunchSetup "C:Program FilesInstallShield Installation Information{45D707E9-F3C4-11D9-A373-0050BAE317E1}Setup.exe" -uninstall
HP QuickTouch 1.00 C4-->MsiExec.exe /I{7DC4A410-9986-4329-9E5D-687B2C42CA39}
HP Smart Web Printing-->msiexec /i{082F8ABA-84D5-4837-9DFC-F365D91A07D4}
HP Total Care Advisor-->MsiExec.exe /X{b02df929-29a7-4fd2-9a70-81a644b635f7}
HP Update-->MsiExec.exe /X{7059BDA7-E1DB-442C-B7A1-6144596720A4}
HP User Guides 0087-->MsiExec.exe /I{4D49757C-367A-4333-BDB3-68966162B14E}
HP Wireless Assistant-->MsiExec.exe /I{CBAE4F50-9FC9-4557-AB36-9826DF3C103C}
HPAsset component for HP Active Support Library-->MsiExec.exe /X{669D4A35-146B-4314-89F1-1AC3D7B88367}
HPNetworkAssistant-->MsiExec.exe /I{228C6B46-64E2-404E-898A-EF0830603EF4}
ImgBurn-->"C:Program FilesImgBurnuninstall.exe"
IrfanView (remove only)-->C:Program FilesIrfanViewiv_uninstall.exe
Java DB 10.4.2.1-->MsiExec.exe /X{926C96FB-9D0A-4504-8000-C6D3A4A3118E}
Java™ 6 Update 14-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216014FF}
Java™ 6 Update 2-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
Java™ SE Development Kit 6 Update 14-->MsiExec.exe /I{32A3A4F4-B792-11D6-A78A-00B0D0160140}
Juniper Networks Setup Client Activex Control-->C:WindowsDownloaded Program FilesJuniperSetupClientCtrlUninstaller.exe
Mercurial snapshot-->"C:Program FilesMercurialunins000.exe"
Microsoft .NET Framework 3.5 SP1-->c:WindowsMicrosoft.NETFrameworkv3.5Microsoft .NET Framework 3.5 SP1setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
Microsoft Office PowerPoint Viewer 2007 (English)-->MsiExec.exe /X{95120000-00AF-0409-0000-0000000FF1CE}
Microsoft Office Professional Edition 2003-->MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
Microsoft Office Project Professional 2003-->MsiExec.exe /I{913B0409-6000-11D3-8CFE-0150048383C9}
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{837b34e3-7c30-493c-8f6a-2b0f04e2912c}
Microsoft Works-->MsiExec.exe /I{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}
Mozilla Firefox (3.5.5)-->C:Program FilesMozilla Firefoxuninstallhelper.exe
MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB941833)-->MsiExec.exe /I{C523D256-313D-4866-B36A-F3DE528246EF}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
muvee autoProducer 6.1-->C:Program FilesInstallShield Installation Information{250E9609-E830-43EB-B379-DAB7546A2422}muveesetup.exe -removeonly -runfromtemp
NetBeans IDE 6.5.1-->"C:Program FilesNetBeans 6.5.1uninstall.exe"
NVIDIA Drivers-->C:Windowssystem32NVUNINST.EXE UninstallGUI
Nvu 1.0PR-->"C:Program FilesNvuunins000.exe"
Opera 9.63-->MsiExec.exe /X{1BC4026B-1957-4514-9058-2B542557F143}
Orbit Downloader-->"C:Program FilesOrbitdownloaderunins000.exe"
Power2Go-->RunDll32 C:PROGRA~1COMMON~1INSTAL~1engine6INTEL3~1Ctor.dll,LaunchSetup "C:Program FilesInstallShield Installation Information{40BF1E83-20EB-11D8-97C5-0009C5020658}setup.exe" -uninstall
PowerDirector-->"C:Program FilesInstallShield Installation Information{CB099890-1D5F-11D5-9EA9-0050BAE317E1}setup.exe" /z-uninstall
QuickPlay SlingPlayer 0.4.6-->"C:Program FilesHPQuickPlayunins000.exe"
QuickTime-->MsiExec.exe /I{08CA9554-B5FE-4313-938F-D4A417B81175}
QuickTime-->MsiExec.exe /I{E0D51394-1D45-460A-B62D-383BC4F8B335}
RealPlayer-->C:Program FilesCommon FilesRealUpdate_OBr1puninst.exe RealNetworks|RealPlayer|6.0
Registry Mechanic 9.0-->"C:Program FilesRegistry Mechanicunins000.exe" /Log
RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01-->RunDll32 C:PROGRA~1COMMON~1INSTAL~1PROFES~1RunTime0701Intel32Ctor.dll,LaunchSetup "C:Program FilesInstallShield Installation Information{59F6A514-9813-47A3-948C-8A155460CC2A}setup.exe" -l0x9 anything
Scribus 1.3.3.13-->C:Program FilesScribus 1.3.3.13uninst.exe
Skype™ 4.1-->MsiExec.exe /X{D103C4BA-F905-437A-8049-DB24763BBE36}
Slingbox Flash Tour-->MsiExec.exe /I{38EAC694-0D90-445F-8C17-8B50ADFE3162}
SlingPlayer-->C:PROGRA~1COMMON~1INSTAL~1Driver1150INTEL3~1IDriver.exe /M{004B0DCB-4C60-465B-8F01-44B0A4111187} /l1033
Spybot - Search & Destroy-->"C:Program FilesSpybot - Search & Destroyunins000.exe"
Synaptics Pointing Device Driver-->rundll32.exe "C:Program FilesSynapticsSynTPSynISDLL.dll",standAloneUninstall
Ubuntu-->C:ubuntuUninstall-Ubuntu.exe
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:Windowssystem32msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
VC80CRTRedist - 8.0.50727.762-->MsiExec.exe /I{767CC44C-9BBC-438D-BAD3-FD4595DD148B}
VideoLAN VLC media player 0.8.6i-->C:Program FilesVideoLANVLCuninstall.exe
WeatherBug Gadget-->MsiExec.exe /I{209CDA54-D390-46A2-A97C-7BF61734418D}
Windows Live Call-->MsiExec.exe /I{F6BD194C-4190-4D73-B1B1-C48C99921BFE}
Windows Live Communications Platform-->MsiExec.exe /I{ED00D08A-3C5F-488D-93A0-A04F21F23956}
Windows Live Essentials-->C:Program FilesWindows LiveInstallerwlarp.exe
Windows Live Essentials-->MsiExec.exe /I{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}
Windows Live Messenger-->MsiExec.exe /X{A85FD55B-891B-4314-97A5-EA96C0BD80B5}
Windows Live Sign-in Assistant-->MsiExec.exe /I{45338B07-A236-4270-9A77-EBB4115517B5}
Windows Live Upload Tool-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
WinRAR archiver-->C:Program FilesWinRARuninstall.exe
Yahoo! Messenger-->C:PROGRA~1Yahoo!MESSEN~1UNWISE.EXE /U C:PROGRA~1Yahoo!MESSEN~1INSTALL.LOG

======Security center information======

AV: AVG Anti-Virus Free
AS: AVG Anti-Virus Free (disabled)
AS: Windows Defender

======System event log======

Computer Name: esiaboni-PC
Event Code: 7000
Message: The Parallel port driver service failed to start due to the following error:
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
Record Number: 27796
Source Name: Service Control Manager
Time Written: 20081124182154.000000-000
Event Type: Error
User:

Computer Name: esiaboni-PC
Event Code: 19
Message: A corrected hardware error occurred.

Error Source: Corrected Machine Check

Error Type: Bus/Interconnect Error

Processor ID Valid: Yes
Processor ID: 0x1
Bank Number: 2
Transaction Type: N/A
Processor Participation: Local node originated the request
Request Type: Prefetch
Memory/Io: Memory
Memory Hierarchy Level: Generic
Timeout: No
Record Number: 27839
Source Name: Microsoft-Windows-WHEA-Logger
Time Written: 20081124182245.564806-000
Event Type: Warning
User: NT AUTHORITYLOCAL SERVICE

Computer Name: esiaboni-PC
Event Code: 4226
Message: TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.
Record Number: 27878
Source Name: Tcpip
Time Written: 20081124195955.224206-000
Event Type: Warning
User:

Computer Name: esiaboni-PC
Event Code: 4226
Message: TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.
Record Number: 27879
Source Name: Tcpip
Time Written: 20081124205349.770006-000
Event Type: Warning
User:

Computer Name: esiaboni-PC
Event Code: 6008
Message: The previous system shutdown at 22:35:46 on 24/11/2008 was unexpected.
Record Number: 27880
Source Name: EventLog
Time Written: 20081125190346.000000-000
Event Type: Error
User:

=====Application event log=====

Computer Name: esiaboni-PC
Event Code: 8193
Message: Failed to create restore point on volume (Process = C:Program FilesAVGAVG9avgupd.exe /aspam=0 /pri=4 /sched=3 /source=inet /path=""; Descripton = Avg8 Update; Hr = 0x800423f4).
Record Number: 32878
Source Name: System Restore
Time Written: 20091109173104.000000-000
Event Type: Error
User:

Computer Name: esiaboni-PC
Event Code: 8194
Message: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface. hr = 0x80070005. This is often caused by incorrect security settings in either the writer or requestor process.

Operation:
Gathering Writer Data

Context:
Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
Writer Name: System Writer
Writer Instance ID: {973e79a6-a29e-49a6-832e-2acf376e0900}
Record Number: 32879
Source Name: VSS
Time Written: 20091109173201.000000-000
Event Type: Error
User:

Computer Name: esiaboni-PC
Event Code: 12290
Message: Volume Shadow Copy Service warning: ASR writer Error 0x80070057. hr = 0x00000000.

Operation:
PrepareForBackup event
PrepareForBackup event

Context:
Execution Context: ASR Writer
Execution Context: Writer
Writer Class Id: {be000cbe-11fe-4426-9c58-531aa6355fc4}
Writer Name: ASR Writer
Writer Instance ID: {33a8cfca-8076-452b-a308-bf6a96dd7f61}
Record Number: 32880
Source Name: VSS
Time Written: 20091109173206.000000-000
Event Type: Warning
User:

Computer Name: esiaboni-PC
Event Code: 16387
Message: Shadow copy creation failed because of error reported by ASR Writer. More info: The parameter is incorrect. (0x80070057).
Record Number: 32881
Source Name: SPP
Time Written: 20091109173206.000000-000
Event Type: Error
User:

Computer Name: esiaboni-PC
Event Code: 8193
Message: Failed to create restore point on volume (Process = C:Program FilesAVGAVG9avgupd.exe /session=-1 /source=inet /pri=4 /log=1 /sched=3 /aspam=0 /path="" /url="" /dns=-1 /updver=704 /SU=0 /SL=semiupdate_log.xml; Descripton = Avg8 Update; Hr = 0x800423f4).
Record Number: 32882
Source Name: System Restore
Time Written: 20091109173206.000000-000
Event Type: Error
User:

=====Security event log=====

Computer Name: esiaboni-PC
Event Code: 5038
Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.

File Name: DeviceHarddiskVolume1WindowsSystem32driverstcpip.sys
Record Number: 36991
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20091109173524.199212-000
Event Type: Audit Failure
User:

Computer Name: esiaboni-PC
Event Code: 5038
Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.

File Name: DeviceHarddiskVolume1WindowsSystem32driverstcpip.sys
Record Number: 36992
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20091109173524.277212-000
Event Type: Audit Failure
User:

Computer Name: esiaboni-PC
Event Code: 5038
Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.

File Name: DeviceHarddiskVolume1WindowsSystem32driverstcpip.sys
Record Number: 36993
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20091109173524.355212-000
Event Type: Audit Failure
User:

Computer Name: esiaboni-PC
Event Code: 5038
Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.

File Name: DeviceHarddiskVolume1WindowsSystem32driverstcpip.sys
Record Number: 36994
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20091109173524.417612-000
Event Type: Audit Failure
User:

Computer Name: esiaboni-PC
Event Code: 5038
Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.

File Name: DeviceHarddiskVolume1WindowsSystem32driverstcpip.sys
Record Number: 36995
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20091109173524.495612-000
Event Type: Audit Failure
User:

======Environment variables======

"ComSpec"=%SystemRoot%system32cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=C:Program FilesActiveState Komodo IDE 5;C:Python26;%SystemRoot%system32;%SystemRoot%;%SystemRoot%System32Wbem;C:Program FilesCyberLinkPower2Go;C:Program FilesQuickTimeQTSystem;C:Program FilesBitvise Tunnelier;C:Program FilesCommon FilesDivX Shared
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC;.py;.pyw
"PROCESSOR_ARCHITECTURE"=x86
"TEMP"=%SystemRoot%TEMP
"TMP"=%SystemRoot%TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 104 Stepping 2, AuthenticAMD
"PROCESSOR_REVISION"=6802
"NUMBER_OF_PROCESSORS"=2
"TRACE_FORMAT_SEARCH_PATH"=NTREL202.ntdev.corp.microsoft.com4F18C3A5-CA09-4DBD-B6FC-219FDD4C6BE0TraceFormat
"DFSTRACINGON"=FALSE
"PLATFORM"=MCD
"PCBRAND"=Pavilion
"OnlineServices"=Online Services
"USERPART"=E:
"CLASSPATH"=.;C:Program FilesJavajre1.6.0_02libextQTJava.zip
"QTJAVA"=C:Program FilesJavajre1.6.0_02libextQTJava.zip

-----------------EOF----------------


__-____
Log
_______

Logfile of random's system information tool 1.06 (written by random/random)
Run by esiaboni at 2009-11-09 18:34:21
Microsoft® Windows Vista™ Home Premium Service Pack 1
System drive C: has 3 GB (2%) free of 179 GB
Total RAM: 3006 MB (61% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:35:26, on 09/11/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18372)
Boot mode: Normal

Running processes:
C:Windowssystem32taskeng.exe
C:Windowssystem32Dwm.exe
C:WindowsExplorer.EXE
C:Program FilesSynapticsSynTPSynTPEnh.exe
C:Program FilesHPQuickPlayQPService.exe
C:Program FilesHewlett-PackardHP Quick Launch ButtonsQLBCTRL.exe
C:Program FilesHewlett-PackardHP QuickTouchHPKBDAPP.exe
C:Program FilesHPDigital ImagingbinHpqSRmon.exe
C:Program FilesHewlett-PackardHP Wireless AssistantHPWAMain.exe
C:Program FilesHewlett-PackardHP Wireless AssistantWiFiMsg.exe
C:Program FilesHPHP Software UpdatehpwuSchd2.exe
C:Program FilesCommon FilesRealUpdate_OBrealsched.exe
C:WindowsSystem32rundll32.exe
C:Program FilesJavajre6binjusched.exe
C:Program FilesAVGAVG9avgtray.exe
C:Program FilesCommon FilesPC ToolssMonitorSSDMonitor.exe
C:Program FilesWindows Sidebarsidebar.exe
C:Program FilesCommon FilesLightScribeLightScribeControlPanel.exe
C:Program FilesRegistry MechanicRMTray.exe
C:Program FilesWIDCOMMBluetooth SoftwareBTTray.exe
C:Windowssystem32wbemunsecapp.exe
C:Program FilesHewlett-PackardSharedHpqToaster.exe
C:Program FilesWIDCOMMBluetooth SoftwareBtStackServer.exe
C:Program FilesSynapticsSynTPSynTPHelper.exe
C:Program FilesMozilla Firefoxfirefox.exe
C:Windowssystem32wuauclt.exe
C:Program FilesAdobeReader 8.0ReaderAcroRd32.exe
C:Program FilesAVGAVG9avgui.exe
C:Program FilesAVGAVG9avgscanx.exe
C:Program FilesAVGAVG9avgcsrvx.exe
C:UsersesiaboniDownloadsSugarCE-5.5.0beta2OtherRSIT.exe
C:Windowssystem32SearchFilterHost.exe
C:Program Filestrend microesiaboni.exe

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...n&pf=laptop
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.bing.com/
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...n&pf=laptop
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...n&pf=laptop
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyServer = 91.204.208.184:27272
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Octh Class - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:Program FilesOrbitdownloaderorbitcth.dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:Program FilesAVGAVG9avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:Program FilesSpybot - Search & DestroySDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program FilesCommon FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:Program FilesJavajre6binjp2ssv.dll
O2 - BHO: HP Print Clips - {FFFFFFFF-FF12-44C5-91EC-068E3AA1B2D7} - c:Program FilesHPSmart Web Printinghpswp_framework.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:Program FilesOrbitdownloaderGrabPro.dll
O4 - HKLM..Run: [SynTPEnh] C:Program FilesSynapticsSynTPSynTPEnh.exe
O4 - HKLM..Run: [QPService] "C:Program FilesHPQuickPlayQPService.exe"
O4 - HKLM..Run: [QlbCtrl] %ProgramFiles%Hewlett-PackardHP Quick Launch ButtonsQlbCtrl.exe /Start
O4 - HKLM..Run: [OnScreenDisplay] C:Program FilesHewlett-PackardHP QuickTouchHPKBDAPP.exe
O4 - HKLM..Run: [UCam_Menu] "C:Program FilesCyberLinkYouCamMUITransferMUIStartMenu.exe" "C:Program FilesCyberLinkYouCam" update "SoftwareCyberLinkYouCam1.0"
O4 - HKLM..Run: [Windows Defender] %ProgramFiles%Windows DefenderMSASCui.exe -hide
O4 - HKLM..Run: [hpqSRMon] C:Program FilesHPDigital ImagingbinhpqSRMon.exe
O4 - HKLM..Run: [HP Health Check Scheduler] c:Program FilesHewlett-PackardHP Health CheckHPHC_Scheduler.exe
O4 - HKLM..Run: [hpWirelessAssistant] C:Program FilesHewlett-PackardHP Wireless AssistantHPWAMain.exe
O4 - HKLM..Run: [WAWifiMessage] C:Program FilesHewlett-PackardHP Wireless AssistantWiFiMsg.exe
O4 - HKLM..Run: [HP Software Update] C:Program FilesHpHP Software UpdateHPWuSchd2.exe
O4 - HKLM..Run: [TkBellExe] "C:Program FilesCommon FilesRealUpdate_OBrealsched.exe" -osboot
O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:Windowssystem32NvCpl.dll,NvStartup
O4 - HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:Windowssystem32NvMcTray.dll,NvTaskbarInit
O4 - HKLM..Run: [SunJavaUpdateSched] "C:Program FilesJavajre6binjusched.exe"
O4 - HKLM..Run: [AVG9_TRAY] C:PROGRA~1AVGAVG9avgtray.exe
O4 - HKLM..Run: [SSDMonitor] C:Program FilesCommon FilesPC ToolssMonitorSSDMonitor.exe
O4 - HKCU..Run: [Sidebar] C:Program FilesWindows Sidebarsidebar.exe /autoRun
O4 - HKCU..Run: [LightScribe Control Panel] C:Program FilesCommon FilesLightScribeLightScribeControlPanel.exe -hidden
O4 - HKCU..Run: [SpybotSD TeaTimer] C:Program FilesSpybot - Search & DestroyTeaTimer.exe
O4 - HKCU..Run: [RegistryMechanic] C:Program FilesRegistry MechanicRMTray.exe /H
O4 - HKUSS-1-5-19..Run: [Sidebar] %ProgramFiles%Windows SidebarSidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUSS-1-5-19..Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUSS-1-5-20..Run: [Sidebar] %ProgramFiles%Windows SidebarSidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: hpzrcv01.LNK = ?
O8 - Extra context menu item: &Download by Orbit - res://C:Program FilesOrbitdownloaderorbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:Program FilesOrbitdownloaderorbitmxt.dll/204
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:Program FilesOrbitdownloaderorbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:Program FilesOrbitdownloaderorbitmxt.dll/202
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:PROGRA~1MICROS~3OFFICE11EXCEL.EXE/3000
O8 - Extra context menu item: En&queue current page with BID - file://C:Program FilesBulk Image Downloaderiemenuiebidqueue.htm
O8 - Extra context menu item: Enqueue link tar&get with BID - file://C:Program FilesBulk Image Downloaderiemenuiebidlinkqueue.htm
O8 - Extra context menu item: Open &link target with BID - file://C:Program FilesBulk Image Downloaderiemenuiebidlink.htm
O8 - Extra context menu item: Open current page with BI&D - file://C:Program FilesBulk Image Downloaderiemenuiebid.htm
O8 - Extra context menu item: Open current page with BID Link Explorer - file://C:Program FilesBulk Image Downloaderiemenuiebidlinkexplorer.htm
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:Program FilesWIDCOMMBluetooth Softwarebtsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:Program FilesWIDCOMMBluetooth Softwarebtsendto_ie.htm
O9 - Extra button: HP Smart Select - {58ECB495-38F0-49cb-A538-10282ABF65E7} - c:Program FilesHPSmart Web Printinghpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MICROS~3OFFICE11REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:Program FilesWIDCOMMBluetooth Softwarebtsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:Program FilesWIDCOMMBluetooth Softwarebtsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:Program FilesSpybot - Search & DestroySDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:Program FilesSpybot - Search & DestroySDHelper.dll
O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:UsersesiaboniAppDataRoamingMicrosoftWindowsStart MenuProgramsAbsolute PokerAbsolute Poker.lnk (HKCU)
O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:UsersesiaboniAppDataRoamingMicrosoftWindowsStart MenuProgramsAbsolute PokerAbsolute Poker.lnk (HKCU)
O13 - Gopher Prefix:
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} (JuniperSetupClientControl Class) - https://juniper.net/dana-cached/sc/JuniperSetupClient.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:Program FilesAVGAVG9avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:PROGRA~1COMMON~1SkypeSKYPE4~1.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:Program FilesAVGAVG9avgwdsvc.exe
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:Program FilesHewlett-PackardHP Quick Launch ButtonsCom4Qlb.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:Program FilesHewlett-PackardHP Health Checkhphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:Program FilesHewlett-PackardSharedhpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:Program FilesCommon FilesInstallShieldDriver11Intel 32IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:Program FilesCommon FilesLightScribeLSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:Windowssystem32nvvsvc.exe
O23 - Service: PC Tools Startup and Shutdown Monitor service (PCToolsSSDMonitorSvc) - PC Tools - C:Program FilesCommon FilesPC ToolssMonitorStartManSvc.exe
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:Program FilesHPQuickPlayKernelTVQPCapSvc.exe
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:Program FilesHPQuickPlayKernelTVQPSched.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:Program FilesCyberLinkShared FilesRichVideo.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:Windowssystem32DRIVERSxaudio.exe

--
End of file - 11716 bytes

======Registry dump======

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{000123B4-9B42-4900-B3F7-F4B073EFC214}]
Octh Class - C:Program FilesOrbitdownloaderorbitcth.dll [2008-11-24 134344]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{02478D38-C3F9-4efb-9B51-7695ECA05670}]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:Program FilesAVGAVG9avgssie.dll [2009-11-08 1471768]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:Program FilesSpybot - Search & DestroySDHelper.dll [2008-09-15 1562960]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{5C255C8A-E604-49b4-9D64-90988571CECB}]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:Program FilesCommon FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:Program FilesJavajre6binjp2ssv.dll [2009-06-01 41368]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{FFFFFFFF-FF12-44C5-91EC-068E3AA1B2D7}]
HP Print Clips - c:Program FilesHPSmart Web Printinghpswp_framework.dll [2007-08-31 177504]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerToolbar]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}
{C55BBCD6-41AD-48AD-9953-3609C48EACC7} - Grab Pro - C:Program FilesOrbitdownloaderGrabPro.dll [2008-11-24 445560]

[HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun]
"SynTPEnh"=C:Program FilesSynapticsSynTPSynTPEnh.exe [2008-01-18 1033512]
"QPService"=C:Program FilesHPQuickPlayQPService.exe [2007-12-20 468264]
"QlbCtrl"=C:Program FilesHewlett-PackardHP Quick Launch ButtonsQlbCtrl.exe [2007-09-19 202032]
"OnScreenDisplay"=C:Program FilesHewlett-PackardHP QuickTouchHPKBDAPP.exe [2007-09-04 554320]
"UCam_Menu"=C:Program FilesCyberLinkYouCamMUITransferMUIStartMenu.exe [2007-08-17 218408]
"Windows Defender"=C:Program FilesWindows DefenderMSASCui.exe [2008-01-21 1008184]
"hpqSRMon"=C:Program FilesHPDigital ImagingbinhpqSRMon.exe [2008-06-02 80896]
"HP Health Check Scheduler"=c:Program FilesHewlett-PackardHP Health CheckHPHC_Scheduler.exe [2008-06-16 75008]
"hpWirelessAssistant"=C:Program FilesHewlett-PackardHP Wireless AssistantHPWAMain.exe [2007-09-13 480560]
"WAWifiMessage"=C:Program FilesHewlett-PackardHP Wireless AssistantWiFiMsg.exe [2007-01-08 311296]
"HP Software Update"=C:Program FilesHpHP Software UpdateHPWuSchd2.exe [2007-05-08 54840]
"TkBellExe"=C:Program FilesCommon FilesRealUpdate_OBrealsched.exe [2008-09-19 185896]
"NvCplDaemon"=C:Windowssystem32NvCpl.dll [2008-12-04 13556256]
"NvMediaCenter"=C:Windowssystem32NvMcTray.dll [2008-12-04 92704]
"SunJavaUpdateSched"=C:Program FilesJavajre6binjusched.exe [2009-06-01 148888]
"AVG9_TRAY"=C:PROGRA~1AVGAVG9avgtray.exe [2009-11-08 2010904]
"SSDMonitor"=C:Program FilesCommon FilesPC ToolssMonitorSSDMonitor.exe [2009-10-14 104408]

[HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun]
"Sidebar"=C:Program FilesWindows Sidebarsidebar.exe [2008-01-21 1233920]
"LightScribe Control Panel"=C:Program FilesCommon FilesLightScribeLightScribeControlPanel.exe [2007-08-23 455968]
"SpybotSD TeaTimer"=C:Program FilesSpybot - Search & DestroyTeaTimer.exe [2009-03-05 2280448]
"RegistryMechanic"=C:Program FilesRegistry MechanicRMTray.exe [2009-10-14 292824]

C:ProgramDataMicrosoftWindowsStart MenuProgramsStartup
Bluetooth.lnk - C:Program FilesWIDCOMMBluetooth SoftwareBTTray.exe
hpzrcv01.LNK - C:Program FilesHPTemp{B2C61EBB-F47C-48ba-B375-27A40F8F48F7}setuphpzstub.exe

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWindows]
"AppInit_DLLS"="avgrsstx.dll"

[HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesSystem]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicystandardprofileauthorizedapplicationslist]
"C:Program FilesEarthLink TotalAccessTaskPanl.exe"="C:Program FilesEarthLink TotalAccessTaskPanl.exe:*:Enabled:Earthlink"
"C:Program FilesOrbitdownloaderorbitdm.exe"="C:Program FilesOrbitdownloaderorbitdm.exe:*:Enabled:Orbit"
"C:Program FilesOrbitdownloaderorbitnet.exe"="C:Program FilesOrbitdownloaderorbitnet.exe:*:Enabled:Orbit"
"C:Windowssystem32winlogon.exe"="C:Windowssystem32winlogon.exe:*:enabled:@shell32.dll,-1"

[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicydomainprofileauthorizedapplicationslist]

[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{ada1c0d3-ef72-11dd-93a1-002186658af6}]
shellAutoRuncommand - F:InstallTomTomHOME.exe


======File associations======

.js - edit - C:WindowsSystem32Notepad.exe %1
.js - open - C:WindowsSystem32WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2009-11-09 18:34:22 ----D---- C:Program Filestrend micro
2009-11-09 18:34:21 ----D---- C:rsit
2009-11-09 07:15:26 ----AD---- C:ProgramDataTEMP
2009-11-09 07:15:03 ----A---- C:Windowssystem32msxml.dll
2009-11-09 07:15:01 ----D---- C:Program FilesCommon FilesPC Tools
2009-11-09 07:15:00 ----D---- C:Program FilesRegistry Mechanic
2009-11-08 18:46:39 ----HD---- C:$AVG
2009-11-08 18:46:23 ----D---- C:ProgramDataavg9
2009-11-08 12:05:15 ----A---- C:Windowssystem324B5F.tmp
2009-11-08 11:45:10 ----A---- C:Windowssystem32E665.tmp
2009-11-08 11:27:29 ----A---- C:Windowssystem32B853.tmp
2009-11-08 11:11:23 ----A---- C:Windowssystem32reader_s.exe
2009-11-08 11:11:22 ----A---- C:Windowssystem32F5A3.tmp
2009-11-08 11:11:17 ----A---- C:Windowssystem32E02E.tmp
2009-11-08 11:11:10 ----SHD---- C:Windowssystem32%APPDATA%
2009-11-07 22:30:46 ----D---- C:UsersesiaboniAppDataRoamingNeoDownloader
2009-11-07 22:14:45 ----D---- C:Program FilesMercurial
2009-11-07 10:57:46 ----D---- C:UsersesiaboniAppDataRoamingYahoo!
2009-11-06 16:37:26 ----D---- C:Program FilesMicrosoft
2009-11-06 16:36:58 ----D---- C:Program FilesWindows Live SkyDrive
2009-11-06 16:34:50 ----D---- C:Program FilesCommon FilesWindows Live
2009-11-05 19:04:09 ----D---- C:Program FilesCommon FilesSkype
2009-11-05 19:04:08 ----RD---- C:Program FilesSkype
2009-10-29 17:29:10 ----A---- C:Windowssystem32wups2.dll
2009-10-29 17:29:10 ----A---- C:Windowssystem32wucltux.dll
2009-10-29 17:29:10 ----A---- C:Windowssystem32wuaueng.dll
2009-10-29 17:29:10 ----A---- C:Windowssystem32wuauclt.exe
2009-10-29 17:28:21 ----A---- C:Windowssystem32wups.dll
2009-10-29 17:28:21 ----A---- C:Windowssystem32wudriver.dll
2009-10-29 17:28:21 ----A---- C:Windowssystem32wuapi.dll
2009-10-29 17:28:11 ----A---- C:Windowssystem32wuwebv.dll
2009-10-29 17:28:11 ----A---- C:Windowssystem32wuapp.exe
2009-10-27 18:45:07 ----A---- C:Windowssystem32wmp.dll
2009-10-27 18:45:07 ----A---- C:Windowssystem32unregmp2.exe
2009-10-27 18:45:05 ----A---- C:Windowssystem32wmploc.DLL
2009-10-25 18:44:37 ----A---- C:Windowssystem32msv1_0.dll
2009-10-25 18:44:27 ----A---- C:Windowssystem32ntkrnlpa.exe
2009-10-25 18:44:26 ----A---- C:Windowssystem32ntoskrnl.exe
2009-10-25 18:43:41 ----A---- C:Windowssystem32EncDec.dll
2009-10-25 18:43:31 ----A---- C:Windowssystem32psisdecd.dll
2009-10-25 18:42:42 ----A---- C:Windowssystem32msasn1.dll
2009-10-25 18:42:25 ----A---- C:Windowssystem32WMSPDMOD.DLL

======List of files/folders modified in the last 1 months======

2009-11-09 18:34:22 ----D---- C:Program Files
2009-11-09 18:34:09 ----D---- C:WindowsTemp
2009-11-09 18:32:10 ----D---- C:Windowssystem32drivers
2009-11-09 18:26:32 ----D---- C:Windowssystem32catroot2
2009-11-09 07:15:50 ----D---- C:Windows
2009-11-09 07:15:26 ----HD---- C:ProgramData
2009-11-09 07:15:03 ----D---- C:WindowsSystem32
2009-11-09 07:15:01 ----D---- C:Program FilesCommon Files
2009-11-08 18:51:46 ----D---- C:WindowsPrefetch
2009-11-08 18:46:31 ----D---- C:Program FilesAVG
2009-11-08 18:46:29 ----A---- C:Windowssystem32avgrsstx.dll
2009-11-08 18:46:06 ----SHD---- C:WindowsInstaller
2009-11-08 18:46:05 ----D---- C:Windowswinsxs
2009-11-08 18:45:51 ----D---- C:Program FilesCommon Filesmicrosoft shared
2009-11-08 18:45:00 ----SD---- C:UsersesiaboniAppDataRoamingMicrosoft
2009-11-08 13:59:55 ----D---- C:ProgramDataSpybot - Search & Destroy
2009-11-08 11:48:27 ----D---- C:UsersesiaboniAppDataRoaminguTorrent
2009-11-08 01:53:55 ----SHD---- C:System Volume Information
2009-11-07 22:24:31 ----D---- C:UsersesiaboniAppDataRoamingBID
2009-11-07 10:57:39 ----D---- C:Program FilesCCleaner
2009-11-07 10:53:51 ----D---- C:Program FilesSpybot - Search & Destroy
2009-11-06 21:35:14 ----D---- C:Program FilesMozilla Firefox
2009-11-06 21:34:45 ----D---- C:UsersesiaboniAppDataRoamingSkype
2009-11-06 21:06:16 ----D---- C:Windowsinf
2009-11-06 21:06:16 ----A---- C:Windowssystem32PerfStringBackup.INI
2009-11-06 16:37:21 ----D---- C:Windowssystem32catroot
2009-11-06 16:37:07 ----D---- C:UsersesiaboniAppDataRoamingskypePM
2009-11-06 16:36:29 ----D---- C:Program FilesWindows Live
2009-11-06 16:34:49 ----SD---- C:ProgramDataMicrosoft
2009-11-05 19:04:15 ----D---- C:Windowssystem32Tasks
2009-11-05 19:04:07 ----D---- C:ProgramDataSkype
2009-11-03 20:41:28 ----D---- C:UsersesiaboniAppDataRoamingdvdcss
2009-11-03 18:45:45 ----D---- C:Windowsrescache
2009-11-03 18:29:27 ----D---- C:Windowssystem32en-US
2009-11-02 20:42:06 ----N---- C:Windowssystem32MpSigStub.exe
2009-10-28 03:01:56 ----D---- C:Program FilesWindows Media Player
2009-10-26 22:05:07 ----D---- C:WindowsDebug
2009-10-26 07:37:18 ----D---- C:WindowsMicrosoft.NET
2009-10-26 07:37:10 ----RSD---- C:Windowsassembly
2009-10-26 03:14:07 ----D---- C:Program FilesWindows Mail
2009-10-26 03:14:05 ----D---- C:Windowsehome
2009-10-25 19:22:32 ----D---- C:Downloads

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:WindowsSystem32Driversavgldx86.sys [2009-11-08 333192]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:WindowsSystem32Driversavgmfx86.sys [2009-11-08 28424]
R1 AvgTdiX;AVG Free8 Network Redirector; C:WindowsSystem32Driversavgtdix.sys [2009-11-09 360584]
R2 mdmxsdk;mdmxsdk; C:Windowssystem32DRIVERSmdmxsdk.sys [2006-06-19 12672]
R2 rimmptsk;rimmptsk; C:Windowssystem32DRIVERSrimmptsk.sys [2007-02-24 39936]
R2 rimsptsk;rimsptsk; C:Windowssystem32DRIVERSrimsptsk.sys [2007-01-24 42496]
R2 rismxdp;Ricoh xD-Picture Card Driver; C:Windowssystem32DRIVERSrixdptsk.sys [2007-03-22 37376]
R2 XAudio;XAudio; C:Windowssystem32DRIVERSxaudio.sys [2007-07-10 8704]
R3 athr;Atheros Extensible Wireless LAN device driver; C:Windowssystem32DRIVERSathr.sys [2007-12-06 761856]
R3 BthEnum;Bluetooth Enumerator Service; C:Windowssystem32DRIVERSBthEnum.sys [2008-01-21 19456]
R3 BthPan;Bluetooth Device (Personal Area Network); C:Windowssystem32DRIVERSbthpan.sys [2008-01-21 92160]
R3 BTHUSB;Bluetooth Radio USB Driver; C:WindowsSystem32DriversBTHUSB.sys [2008-04-29 29184]
R3 btwaudio;Bluetooth Audio Device Service; C:Windowssystem32driversbtwaudio.sys [2007-09-18 80424]
R3 btwavdt;Bluetooth AVDT; C:Windowssystem32driversbtwavdt.sys [2007-09-18 80936]
R3 btwrchid;btwrchid; C:Windowssystem32DRIVERSbtwrchid.sys [2007-09-18 16168]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:Windowssystem32DRIVERSCmBatt.sys [2008-01-21 14208]
R3 HdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service; C:Windowssystem32driversCHDART.sys [2007-09-09 176640]
R3 HpqKbFiltr;HpqKbFilter Driver; C:Windowssystem32DRIVERSHpqKbFiltr.sys [2007-06-19 16768]
R3 HpqRemHid;HP Remote Control HID Device; C:Windowssystem32DRIVERSHpqRemHid.sys [2007-07-11 7168]
R3 HSF_DPV;HSF_DPV; C:Windowssystem32DRIVERSHSX_DPV.sys [2007-06-20 984064]
R3 HSXHWAZL;HSXHWAZL; C:Windowssystem32DRIVERSHSXHWAZL.sys [2007-06-20 208896]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:Windowssystem32DRIVERSnvmfdx32.sys [2007-03-07 1059112]
R3 nvlddmkm;nvlddmkm; C:Windowssystem32DRIVERSnvlddmkm.sys [2008-12-04 7606688]
R3 nvsmu;nvsmu; C:Windowssystem32DRIVERSnvsmu.sys [2007-02-16 12032]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:Windowssystem32DRIVERSrfcomm.sys [2008-01-21 49664]
R3 sdbus;sdbus; C:Windowssystem32DRIVERSsdbus.sys [2008-01-21 88576]
R3 SynTP;Synaptics TouchPad Driver; C:Windowssystem32DRIVERSSynTP.sys [2008-01-18 196784]
R3 usbvideo;USB Video Device (WDM); C:WindowsSystem32Driversusbvideo.sys [2008-01-21 134016]
R3 winachsf;winachsf; C:Windowssystem32DRIVERSHSX_CNXT.sys [2007-06-20 660480]
R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:Windowssystem32DRIVERSwmiacpi.sys [2008-01-21 11264]
S3 BCM43XV;Broadcom Extensible 802.11 Network Adapter Driver; C:Windowssystem32DRIVERSbcmwl6.sys [2006-11-02 464384]
S3 BTHPORT;Bluetooth Port Driver; C:WindowsSystem32DriversBTHport.sys [2008-04-29 220160]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:Windowssystem32driversdrmkaud.sys [2008-01-21 5632]
S3 HSFHWAZL;HSFHWAZL; C:Windowssystem32DRIVERSVSTAZL3.SYS [2008-01-21 200704]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:Windowssystem32driversMSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:Windowssystem32driversMSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:Windowssystem32driversMSPQM.sys [2008-01-21 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:Windowssystem32driversMSTEE.sys [2008-01-21 6016]
S3 RimUsb;BlackBerry Smartphone; C:WindowsSystem32DriversRimUsb.sys [2008-04-16 22784]
S3 SymIMMP;SymIMMP; C:Windowssystem32DRIVERSSymIM.sys []
S3 usbscan;USB Scanner Driver; C:Windowssystem32DRIVERSusbscan.sys [2008-01-21 35328]
S3 WUDFRd;WUDFRd; C:Windowssystem32DRIVERSWUDFRd.sys [2008-01-21 83328]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:Windowssystem32driverserrdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:Windowssystem32driversmegasr.sys [2008-01-21 386616]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avg9wd;AVG Free WatchDog; C:Program FilesAVGAVG9avgwdsvc.exe [2009-11-08 285392]
R2 BthServ;@%SystemRoot%System32bthserv.dll,-101; C:Windowssystem32svchost.exe [2008-01-21 21504]
R2 HP Health Check Service;HP Health Check Service; c:Program FilesHewlett-PackardHP Health Checkhphc_service.exe [2008-06-16 94208]
R2 hpqwmiex;hpqwmiex; C:Program FilesHewlett-PackardSharedhpqwmiex.exe [2006-05-02 135168]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:Program FilesCommon FilesLightScribeLSSrvc.exe [2007-08-23 79136]
R2 Net Driver HPZ12;Net Driver HPZ12; C:WindowsSystem32svchost.exe [2008-01-21 21504]
R2 nvsvc;NVIDIA Display Driver Service; C:Windowssystem32nvvsvc.exe [2008-12-04 203296]
R2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service; C:Program FilesCommon FilesPC ToolssMonitorStartManSvc.exe [2009-10-14 583640]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:WindowsSystem32svchost.exe [2008-01-21 21504]
R2 QPCapSvc;QuickPlay Background Capture Service (QBCS); C:Program FilesHPQuickPlayKernelTVQPCapSvc.exe [2007-12-20 271760]
R2 QPSched;QuickPlay Task Scheduler (QTS); C:Program FilesHPQuickPlayKernelTVQPSched.exe [2007-12-20 112016]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:Program FilesCyberLinkShared FilesRichVideo.exe [2007-01-09 272024]
R2 XAudioService;XAudioService; C:Windowssystem32DRIVERSxaudio.exe [2007-07-10 386560]
S3 Com4Qlb;Com4Qlb; C:Program FilesHewlett-PackardHP Quick Launch ButtonsCom4Qlb.exe [2007-03-05 110592]
S3 IDriverT;InstallDriver Table Manager; C:Program FilesCommon FilesInstallShieldDriver11Intel 32IDriverT.exe [2005-04-04 69632]
S3 ose;Office Source Engine; C:Program FilesCommon FilesMicrosoft SharedSource EngineOSE.EXE [2006-10-26 145184]

-----------------EOF-------------

hijack this log

Merged posts. ~ OB

Attached Files


Edited by Orange Blossom, 09 November 2009 - 10:13 PM.


BC AdBot (Login to Remove)

 


#2 etavares

etavares

    Bleepin' Remover


  • Malware Response Team
  • 15,514 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:07:30 PM

Posted 15 November 2009 - 06:45 AM

Hello and welcome to Bleeping Computer

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine.

If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.

Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.

If you have already posted an RSIT log, please do so again, as your situation may have changed.
Use the 'Add Reply' and add the new log to this thread.


Thanks and again sorry for the delay.

We need to see some information about what is happening in your machine. Please post an updated RSIT scan.

Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Also, please subscribe to this topic, so you are notified when someone replies. Please continue to check manually on occasion, as every now and then the email may be caught by your spam filter.
To enable topic notifications you should do the following:
  • Click on the My Controls link at the top of the page to enter your control panel.
  • Scroll down to the Options category in the left hand side menu bar and click on the Email Settings link.
  • Put a checkmark in the checkbox labeled Enable 'Email Notification' by default?.
  • Set the If ticked, choose default type: menu option to Immediate Email Notification to have an email sent immediately when someone replied.
Information on A/V control HERE

Edited by etavares, 15 November 2009 - 06:46 AM.


If I don't respond within 2 days, please feel free to PM me.
Please don't ask for help via PM. The forums are there for a reason. Please post in the forums so others may benefit as well.

Posted Image
Unified Network of Instructors and Trusted Eliminators
 


#3 atencorps

atencorps
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:06:30 PM

Posted 15 November 2009 - 03:42 PM

Hello,

Please find updated RSIT scan

---------------
---------------
Logfile of random's system information tool 1.06 (written by random/random)
Run by esiaboni at 2009-11-15 21:40:00
Microsoft® Windows Vista™ Home Premium Service Pack 1
System drive C: has 5 GB (3%) free of 179 GB
Total RAM: 3006 MB (46% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:40:11, on 15/11/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18372)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\AVG\AVG9\avgtray.exe
C:\Program Files\Common Files\PC Tools\sMonitor\SSDMonitor.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Registry Mechanic\RMTray.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\explorer.exe
C:\Users\esiaboni\Downloads\SugarCE-5.5.0beta2\Other\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\esiaboni.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...n&pf=laptop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...n&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...n&pf=laptop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 91.204.208.184:27272
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Octh Class - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Print Clips - {FFFFFFFF-FF12-44C5-91EC-068E3AA1B2D7} - c:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0"
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [SSDMonitor] C:\Program Files\Common Files\PC Tools\sMonitor\SSDMonitor.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RMTray.exe /H
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: hpzrcv01.LNK = ?
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: En&queue current page with BID - file://C:\Program Files\Bulk Image Downloader\iemenu\iebidqueue.htm
O8 - Extra context menu item: Enqueue link tar&get with BID - file://C:\Program Files\Bulk Image Downloader\iemenu\iebidlinkqueue.htm
O8 - Extra context menu item: Open &link target with BID - file://C:\Program Files\Bulk Image Downloader\iemenu\iebidlink.htm
O8 - Extra context menu item: Open current page with BI&D - file://C:\Program Files\Bulk Image Downloader\iemenu\iebid.htm
O8 - Extra context menu item: Open current page with BID Link Explorer - file://C:\Program Files\Bulk Image Downloader\iemenu\iebidlinkexplorer.htm
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: HP Smart Select - {58ECB495-38F0-49cb-A538-10282ABF65E7} - c:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Users\esiaboni\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (HKCU)
O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Users\esiaboni\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (HKCU)
O13 - Gopher Prefix:
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PC Tools Startup and Shutdown Monitor service (PCToolsSSDMonitorSvc) - PC Tools - C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 11669 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000123B4-9B42-4900-B3F7-F4B073EFC214}]
Octh Class - C:\Program Files\Orbitdownloader\orbitcth.dll [2008-11-24 134344]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG9\avgssie.dll [2009-11-09 1475864]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2008-09-15 1562960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-06-01 41368]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-FF12-44C5-91EC-068E3AA1B2D7}]
HP Print Clips - c:\Program Files\HP\Smart Web Printing\hpswp_framework.dll [2007-08-31 177504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}
{C55BBCD6-41AD-48AD-9953-3609C48EACC7} - Grab Pro - C:\Program Files\Orbitdownloader\GrabPro.dll [2008-11-24 445560]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-01-18 1033512]
"QPService"=C:\Program Files\HP\QuickPlay\QPService.exe [2007-12-20 468264]
"QlbCtrl"=C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2007-09-19 202032]
"OnScreenDisplay"=C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe [2007-09-04 554320]
"UCam_Menu"=C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [2007-08-17 218408]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"hpqSRMon"=C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe [2008-06-02 80896]
"HP Health Check Scheduler"=c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [2008-06-16 75008]
"hpWirelessAssistant"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [2007-09-13 480560]
"WAWifiMessage"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe [2007-01-08 311296]
"HP Software Update"=C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [2007-05-08 54840]
"TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2008-09-19 185896]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2008-12-04 13556256]
"NvMediaCenter"=C:\Windows\system32\NvMcTray.dll [2008-12-04 92704]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-06-01 148888]
"AVG9_TRAY"=C:\PROGRA~1\AVG\AVG9\avgtray.exe [2009-11-12 2020120]
"SSDMonitor"=C:\Program Files\Common Files\PC Tools\sMonitor\SSDMonitor.exe [2009-10-14 104408]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2008-01-21 1233920]
"LightScribe Control Panel"=C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2007-08-23 455968]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-03-05 2280448]
"RegistryMechanic"=C:\Program Files\Registry Mechanic\RMTray.exe [2009-10-14 292824]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
hpzrcv01.LNK - C:\Program Files\HP\Temp\{B2C61EBB-F47C-48ba-B375-27A40F8F48F7}\setup\hpzstub.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="avgrsstx.dll"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe"="C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink"
"C:\Program Files\Orbitdownloader\orbitdm.exe"="C:\Program Files\Orbitdownloader\orbitdm.exe:*:Enabled:Orbit"
"C:\Program Files\Orbitdownloader\orbitnet.exe"="C:\Program Files\Orbitdownloader\orbitnet.exe:*:Enabled:Orbit"
"C:\Windows\system32\winlogon.exe"="C:\Windows\system32\winlogon.exe:*:enabled:@shell32.dll,-1"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ada1c0d3-ef72-11dd-93a1-002186658af6}]
shell\AutoRun\command - F:\InstallTomTomHOME.exe


======File associations======

.bat - edit -
.cmd - edit -
.inf - open -
.ini - open -
.js - edit -
.js - open -
.reg - edit -
.txt - open -
.vbs - edit -
.vbs - open -
.cpl - cplopen -

======List of files/folders created in the last 1 months======

2009-11-14 21:38:31 ----A---- C:\Windows\system32\avgrep.txt
2009-11-11 21:21:34 ----A---- C:\Windows\system32\WSDApi.dll
2009-11-09 18:34:22 ----D---- C:\Program Files\trend micro
2009-11-09 18:34:21 ----D---- C:\rsit
2009-11-09 07:15:26 ----AD---- C:\ProgramData\TEMP
2009-11-09 07:15:03 ----A---- C:\Windows\system32\msxml.dll
2009-11-09 07:15:01 ----D---- C:\Program Files\Common Files\PC Tools
2009-11-09 07:15:00 ----D---- C:\Program Files\Registry Mechanic
2009-11-08 18:46:39 ----HD---- C:\$AVG
2009-11-08 18:46:23 ----D---- C:\ProgramData\avg9
2009-11-08 12:05:15 ----A---- C:\Windows\system32\4B5F.tmp
2009-11-08 11:45:10 ----A---- C:\Windows\system32\E665.tmp
2009-11-08 11:27:29 ----A---- C:\Windows\system32\B853.tmp
2009-11-08 11:11:22 ----A---- C:\Windows\system32\F5A3.tmp
2009-11-08 11:11:17 ----A---- C:\Windows\system32\E02E.tmp
2009-11-08 11:11:10 ----SHD---- C:\Windows\system32\%APPDATA%
2009-11-07 22:30:46 ----D---- C:\Users\esiaboni\AppData\Roaming\NeoDownloader
2009-11-07 22:14:45 ----D---- C:\Program Files\Mercurial
2009-11-07 10:57:46 ----D---- C:\Users\esiaboni\AppData\Roaming\Yahoo!
2009-11-06 16:37:26 ----D---- C:\Program Files\Microsoft
2009-11-06 16:36:58 ----D---- C:\Program Files\Windows Live SkyDrive
2009-11-06 16:34:50 ----D---- C:\Program Files\Common Files\Windows Live
2009-11-05 19:04:09 ----D---- C:\Program Files\Common Files\Skype
2009-11-05 19:04:08 ----RD---- C:\Program Files\Skype
2009-10-29 17:29:10 ----A---- C:\Windows\system32\wups2.dll
2009-10-29 17:29:10 ----A---- C:\Windows\system32\wucltux.dll
2009-10-29 17:29:10 ----A---- C:\Windows\system32\wuaueng.dll
2009-10-29 17:29:10 ----A---- C:\Windows\system32\wuauclt.exe
2009-10-29 17:28:21 ----A---- C:\Windows\system32\wups.dll
2009-10-29 17:28:21 ----A---- C:\Windows\system32\wudriver.dll
2009-10-29 17:28:21 ----A---- C:\Windows\system32\wuapi.dll
2009-10-29 17:28:11 ----A---- C:\Windows\system32\wuwebv.dll
2009-10-29 17:28:11 ----A---- C:\Windows\system32\wuapp.exe
2009-10-27 18:45:07 ----A---- C:\Windows\system32\wmp.dll
2009-10-27 18:45:07 ----A---- C:\Windows\system32\unregmp2.exe
2009-10-27 18:45:05 ----A---- C:\Windows\system32\wmploc.DLL
2009-10-25 18:44:37 ----A---- C:\Windows\system32\msv1_0.dll
2009-10-25 18:44:27 ----A---- C:\Windows\system32\ntkrnlpa.exe
2009-10-25 18:44:26 ----A---- C:\Windows\system32\ntoskrnl.exe
2009-10-25 18:43:41 ----A---- C:\Windows\system32\EncDec.dll
2009-10-25 18:43:31 ----A---- C:\Windows\system32\psisdecd.dll
2009-10-25 18:42:42 ----A---- C:\Windows\system32\msasn1.dll
2009-10-25 18:42:25 ----A---- C:\Windows\system32\WMSPDMOD.DLL

======List of files/folders modified in the last 1 months======

2009-11-15 21:39:52 ----D---- C:\Windows\Temp
2009-11-15 21:37:10 ----D---- C:\Users\esiaboni\AppData\Roaming\uTorrent
2009-11-15 09:33:02 ----D---- C:\Windows\Prefetch
2009-11-15 08:39:40 ----D---- C:\ProgramData\Spybot - Search & Destroy
2009-11-14 21:38:31 ----D---- C:\Windows\System32
2009-11-14 21:37:00 ----SHD---- C:\Windows\Installer
2009-11-14 21:36:53 ----D---- C:\Windows\winsxs
2009-11-14 21:36:51 ----D---- C:\Program Files\Microsoft Works
2009-11-14 21:36:51 ----D---- C:\Program Files\Common Files\microsoft shared
2009-11-14 21:32:32 ----D---- C:\Windows\Debug
2009-11-14 21:32:32 ----D---- C:\Windows
2009-11-14 16:22:35 ----SD---- C:\Windows\Downloaded Program Files
2009-11-12 07:39:56 ----D---- C:\Windows\system32\catroot
2009-11-12 07:39:55 ----D---- C:\Windows\system32\catroot2
2009-11-12 07:36:23 ----D---- C:\Program Files\Windows Mail
2009-11-12 07:20:42 ----A---- C:\Windows\win.ini
2009-11-09 18:34:22 ----D---- C:\Program Files
2009-11-09 18:32:10 ----D---- C:\Windows\system32\drivers
2009-11-09 07:15:26 ----HD---- C:\ProgramData
2009-11-09 07:15:01 ----D---- C:\Program Files\Common Files
2009-11-08 18:46:31 ----D---- C:\Program Files\AVG
2009-11-08 18:46:29 ----A---- C:\Windows\system32\avgrsstx.dll
2009-11-08 18:45:00 ----SD---- C:\Users\esiaboni\AppData\Roaming\Microsoft
2009-11-08 01:53:55 ----SHD---- C:\System Volume Information
2009-11-07 22:24:31 ----D---- C:\Users\esiaboni\AppData\Roaming\BID
2009-11-07 10:57:39 ----D---- C:\Program Files\CCleaner
2009-11-07 10:53:51 ----D---- C:\Program Files\Spybot - Search & Destroy
2009-11-06 21:35:14 ----D---- C:\Program Files\Mozilla Firefox
2009-11-06 21:34:45 ----D---- C:\Users\esiaboni\AppData\Roaming\Skype
2009-11-06 21:06:16 ----D---- C:\Windows\inf
2009-11-06 21:06:16 ----A---- C:\Windows\system32\PerfStringBackup.INI
2009-11-06 16:37:07 ----D---- C:\Users\esiaboni\AppData\Roaming\skypePM
2009-11-06 16:36:29 ----D---- C:\Program Files\Windows Live
2009-11-06 16:34:49 ----SD---- C:\ProgramData\Microsoft
2009-11-05 19:04:15 ----D---- C:\Windows\system32\Tasks
2009-11-05 19:04:07 ----D---- C:\ProgramData\Skype
2009-11-05 18:36:21 ----A---- C:\Windows\system32\mrt.exe
2009-11-03 20:41:28 ----D---- C:\Users\esiaboni\AppData\Roaming\dvdcss
2009-11-03 18:45:45 ----D---- C:\Windows\rescache
2009-11-03 18:29:27 ----D---- C:\Windows\system32\en-US
2009-11-02 20:42:06 ----N---- C:\Windows\system32\MpSigStub.exe
2009-10-28 03:01:56 ----D---- C:\Program Files\Windows Media Player
2009-10-26 07:37:18 ----D---- C:\Windows\Microsoft.NET
2009-10-26 07:37:10 ----RSD---- C:\Windows\assembly
2009-10-26 03:14:05 ----D---- C:\Windows\ehome
2009-10-25 19:22:32 ----D---- C:\Downloads

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\Windows\System32\Drivers\avgldx86.sys [2009-11-08 333192]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\Windows\System32\Drivers\avgmfx86.sys [2009-11-08 28424]
R1 AvgTdiX;AVG Free8 Network Redirector; C:\Windows\System32\Drivers\avgtdix.sys [2009-11-09 360584]
R2 mdmxsdk;mdmxsdk; C:\Windows\system32\DRIVERS\mdmxsdk.sys [2006-06-19 12672]
R2 rimmptsk;rimmptsk; C:\Windows\system32\DRIVERS\rimmptsk.sys [2007-02-24 39936]
R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimsptsk.sys [2007-01-24 42496]
R2 rismxdp;Ricoh xD-Picture Card Driver; C:\Windows\system32\DRIVERS\rixdptsk.sys [2007-03-22 37376]
R2 XAudio;XAudio; C:\Windows\system32\DRIVERS\xaudio.sys [2007-07-10 8704]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2007-12-06 761856]
R3 BthEnum;Bluetooth Enumerator Service; C:\Windows\system32\DRIVERS\BthEnum.sys [2008-01-21 19456]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-21 92160]
R3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2008-04-29 29184]
R3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2007-09-18 80424]
R3 btwavdt;Bluetooth AVDT; C:\Windows\system32\drivers\btwavdt.sys [2007-09-18 80936]
R3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2007-09-18 16168]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-01-21 14208]
R3 HdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDART.sys [2007-09-09 176640]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\Windows\system32\DRIVERS\HpqKbFiltr.sys [2007-06-19 16768]
R3 HpqRemHid;HP Remote Control HID Device; C:\Windows\system32\DRIVERS\HpqRemHid.sys [2007-07-11 7168]
R3 HSF_DPV;HSF_DPV; C:\Windows\system32\DRIVERS\HSX_DPV.sys [2007-06-20 984064]
R3 HSXHWAZL;HSXHWAZL; C:\Windows\system32\DRIVERS\HSXHWAZL.sys [2007-06-20 208896]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvmfdx32.sys [2007-03-07 1059112]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2008-12-04 7606688]
R3 nvsmu;nvsmu; C:\Windows\system32\DRIVERS\nvsmu.sys [2007-02-16 12032]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2008-01-21 49664]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2008-01-21 88576]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2008-01-18 196784]
R3 usbvideo;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-21 134016]
R3 winachsf;winachsf; C:\Windows\system32\DRIVERS\HSX_CNXT.sys [2007-06-20 660480]
R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2008-01-21 11264]
S3 BCM43XV;Broadcom Extensible 802.11 Network Adapter Driver; C:\Windows\system32\DRIVERS\bcmwl6.sys [2006-11-02 464384]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2008-04-29 220160]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 HSFHWAZL;HSFHWAZL; C:\Windows\system32\DRIVERS\VSTAZL3.SYS [2008-01-21 200704]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 RimUsb;BlackBerry Smartphone; C:\Windows\System32\Drivers\RimUsb.sys [2008-04-16 22784]
S3 SymIMMP;SymIMMP; C:\Windows\system32\DRIVERS\SymIM.sys []
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-21 35328]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avg9wd;AVG Free WatchDog; C:\Program Files\AVG\AVG9\avgwdsvc.exe [2009-11-08 285392]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 HP Health Check Service;HP Health Check Service; c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [2008-06-16 94208]
R2 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2006-05-02 135168]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2007-08-23 79136]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2008-12-04 203296]
R2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service; C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe [2009-10-14 583640]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 QPCapSvc;QuickPlay Background Capture Service (QBCS); C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe [2007-12-20 271760]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared Files\RichVideo.exe [2007-01-09 272024]
R2 XAudioService;XAudioService; C:\Windows\system32\DRIVERS\xaudio.exe [2007-07-10 386560]
S2 QPSched;QuickPlay Task Scheduler (QTS); C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe [2007-12-20 112016]
S3 Com4Qlb;Com4Qlb; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe [2007-03-05 110592]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]

-----------------EOF-----------------

#4 Elise

Elise

    Bleepin' Blonde


  • Malware Study Hall Admin
  • 60,816 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Romania
  • Local time:02:30 AM

Posted 17 November 2009 - 04:47 AM

Hello atencorps,

And :( to the Bleeping Computer Malware Removal Forum
, My name is Elise. I'll be glad to help you with your computer problems.


I will be working on your malware issues, this may or may not solve other issues you may have with your machine.

Please note that whatever repairs we make, are for fixing your computer problems only and by no means should be used on another computer.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the button at the top bar of this topic and Track this Topic, where you can choose email notifications. The topics you are tracking are shown here.
-----------------------------------------------------------
Please be patient and I'd be grateful if you would note the following:
  • The cleaning process is not instant. DDS logs can take some time to research, so please be patient with me. I know that you need your computer working as quickly as possible, and I will work hard to help see that happen.
  • Please reply using the Add/Reply button in the lower right hand corner of your screen. Do not start a new topic.
  • The logs that you post should be pasted directly into the reply. Only attach them if requested or if they do not fit into the post.
  • Unfortunately, if I do not hear back from you within 5 days, I will be forced to close your topic. If you still need help after I have closed your topic, send me or a moderator a personal message with the address of the thread or feel free to create a new one.
In the meantime please, do NOT install any new programs or update anything unless told to do so while we are fixing your problem.


I notice the presence of name here Registry Cleaner on your pc.

I don't personally recommend the use of ANY registry cleaners.
Here is an excerpt from a discussion on regcleaners

Most reg cleaners aren't "bad" as such, but they aren't perfect and even the best have been known to cause problems.
The point we are trying to make is that the risk of using one far outweighs any benefit.
If it does work perfectly you will not see any difference
If it doesn't work properly you may end up with an expensive doorstop.


http://miekiemoes.blogspot.com/2008/02/reg...weaking_13.html
http://forums.whatthetech.com/Regcleaner_t42862.html

In order to safeguard your system from problems that can be brought on by a half finished fix, we need to disable TeaTimer. We can reenable it when we're done if you like.
  • Open SpyBot Search and Destroy by going to Start -> All Programs -> Spybot Search and Destroy -> Spybot Search and Destroy.
  • If prompted with a legal dialog, accept the warning.
  • Click Posted Image and then on "Advanced Mode"
    Posted Image
  • You may be presented with a warning dialog. If so, press Posted Image
  • Click on Posted Image
  • Click on Posted Image
  • Uncheck this checkbox:
    Posted Image
  • Close/Exit Spybot Search and Destroy
COMBOFIX
---------------
Please download ComboFix from one of these locations:Bleepingcomputer
ForoSpyware
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. (Click on this link to see a list of programs that should be disabled. The list is not all inclusive.)
  • Double click on Combofix.exe and follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Posted Image


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Posted Image


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


In your next reply, please include the following:
  • Combofix.txt

regards, Elise


"Now faith is the substance of things hoped for, the evidence of things not seen."

 

Follow BleepingComputer on: Facebook | Twitter | Google+ | lockerdome

 

Malware analyst @ Emsisoft


#5 Elise

Elise

    Bleepin' Blonde


  • Malware Study Hall Admin
  • 60,816 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Romania
  • Local time:02:30 AM

Posted 22 November 2009 - 08:58 AM

Due to lack of feedback, this topic is now closed.

If you are the original topic starter and you need this topic to be re-opened, please send me a PM.

Everyone else, please start a new topic.

regards, Elise


"Now faith is the substance of things hoped for, the evidence of things not seen."

 

Follow BleepingComputer on: Facebook | Twitter | Google+ | lockerdome

 

Malware analyst @ Emsisoft





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users