Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected w/ jgdw400R.exe and/or rimakani/namopiya


  • This topic is locked This topic is locked
8 replies to this topic

#1 thestuman

thestuman

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:12:19 AM

Posted 14 December 2009 - 09:41 PM

Hello all and thanks in advance!

After browsing the web (Firefox) this morning, I found that I was being redirected and/or had pop ups come up randomly. I also had the AntiMalware "program" installed on my computer. I was able to remove this and I ran my antivirus (AVG) and Windows Defender and was told I had several infections. I attempted to remove/fix these infections and think I was somewhat succesful. However, the symptoms still exist when I run FireFox and to a lesser degree IE. When I run the TaskManager I can see the jgdw400R.exe process running, which I know is not normal. I also have seen the rimakani and namopiya names when I run HJT and can't remove them.

My log is below and I've attached the appropriate files. Thanks again in advance for your help! Please let me know what else you might need from me.


DDS (Ver_09-12-01.01) - NTFSx86
Run by Stuart at 20:13:28.25 on Mon 12/14/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_17
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.216 [GMT -6:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: AntiMalware *On-access scanning enabled* (Outdated) {28e00e3b-806e-4533-925c-f4c3d79514b9}

============== Running Processes ===============

C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
C:\WINDOWS\system32\Ati2evxx.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\jgdw400R.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe
C:\Program Files\Lenovo\Zoom\TpScrex.exe
C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
C:\Program Files\Dell Printers\Additional Color Laser Software\Status Monitor\DLSDBNT.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\Astaro\Astaro SSL VPN Client\bin\openvpn-gui.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe
C:\Program Files\Dell Printers\paperport\pptd40nt.exe
C:\Program Files\Dell Printers\Additional Color Laser Software\Status Monitor\DLPSP.EXE
C:\Program Files\Dell Printers\Additional Color Laser Software\Updater\DLUPDR.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Dell AIO Printer A940\dlbabmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.5.0.20081031-1700\soffice.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Program Files\Dell Printers\Additional Color Laser Software\Status Monitor\DLPWDNT.EXE
C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Stuart\Desktop\dds.scr

============== Pseudo HJT Report ===============

BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [SODCPreLoad] c:\program files\ibm\lotus\symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.5.0.20081031-1700\preload.exe c:\docume~1\stuart\ibm\lotus\symphony\.sodc\
mRun: [TPHOTKEY] c:\program files\lenovo\hotkey\TPOSDSVC.exe
mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [PSQLLauncher] "c:\program files\thinkvantage fingerprint software\launcher.exe" /startup
mRun: [ACTray] c:\program files\thinkpad\connectutilities\ACTray.exe
mRun: [ACWLIcon] c:\program files\thinkpad\connectutilities\ACWLIcon.exe
mRun: [IntelZeroConfig] "c:\program files\intel\wifi\bin\ZCfgSvc.exe"
mRun: [IntelWireless] "c:\program files\common files\intel\wirelesscommon\iFrmewrk.exe" /tf Intel Wireless Tray
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [TPFNF7] c:\program files\lenovo\npdirect\TPFNF7SP.exe /r
mRun: [EZEJMNAP] c:\progra~1\thinkpad\utilit~1\EzEjMnAp.Exe
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [Acrobat Assistant 7.0] "c:\program files\adobe\acrobat 7.0\distillr\Acrotray.exe"
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mRun: [openvpn-gui] c:\program files\astaro\astaro ssl vpn client\bin\openvpn-gui.exe
mRun: [AT&T Communication Manager] "c:\program files\at&t\communication manager\ATTCM.exe" -a
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [Dell AIO Printer A940] "c:\program files\dell aio printer a940\dlbabmgr.exe"
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [PaperPort PTD] "c:\program files\dell printers\paperport\pptd40nt.exe"
mRun: [IndexSearch] "c:\program files\dell printers\paperport\IndexSearch.exe"
mRun: [DLPSP] "c:\program files\dell printers\additional color laser software\status monitor\DLPSP.EXE"
mRun: [DLUPDR] "c:\program files\dell printers\additional color laser software\updater\DLUPDR.EXE"
mRun: [DLQLU] "c:\program files\dell printers\additional color laser software\launcher\DLQLU.EXE" /S
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [bozijoheb] Rundll32.exe "c:\windows\system32\rimakani.dll",a
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobea~1.lnk - c:\windows\installer\{ac76ba86-1033-f400-ba7e-100000000002}\SC_Acrobat.exe
IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
LSP: bmnet.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
TCP: {734D0AAD-F387-4623-8A6B-4E9344E6AFCD} = 193.104.110.38,4.2.2.1
TCP: {8EE9D6AD-E75D-4D41-A2DA-BCC6F162095D} = 193.104.110.38,4.2.2.1,192.168.2.1
TCP: {EBA56B4A-D6BB-4326-86A1-B7771430CCD2} = 193.104.110.38,4.2.2.1,184.48.206.1 64.134.255.2 64.134.255.10
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: psfus - c:\program files\thinkvantage fingerprint software\psqlpwd.dll
Notify: tpfnf2 - c:\program files\lenovo\hotkey\notifyf2.dll
Notify: tphotkey - c:\program files\lenovo\hotkey\tphklock.dll
AppInit_DLLs: c:\windows\system32\rimakani.dll,namopiya.dll
SSODL: buhahayar - {ee9afd20-b8ca-4a0b-a129-47a3c22471e0} - c:\windows\system32\rimakani.dll
STS: kupuhivus: {ee9afd20-b8ca-4a0b-a129-47a3c22471e0} - c:\windows\system32\rimakani.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll
LSA: Notification Packages = scecli c:\program files\thinkvantage fingerprint software\psqlpwd.dll ACGina towusozo.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\stuart\applic~1\mozilla\firefox\profiles\5hrxf786.default\
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============

R0 ssfs0bbc;ssfs0bbc;c:\windows\system32\drivers\ssfs0bbc.sys [2009-11-6 29808]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-11-30 333192]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-11-30 28424]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-11-30 360584]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2009-11-30 906520]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2009-11-30 285392]
R2 DLSDB;Dell Printer Status Database;c:\program files\dell printers\additional color laser software\status monitor\dlsdbnt.exe [2009-12-1 140184]
R2 smihlp;SMI Helper Driver (smihlp);c:\program files\common files\thinkvantage fingerprint software\drivers\smihlp.sys [2008-11-21 12560]
R2 WebrootSpySweeperService;Webroot Spy Sweeper Engine;c:\program files\webroot\webrootsecurity\SpySweeper.exe [2009-11-6 4048240]
R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
S3 ATTRcAppSvc;AT&T RcAppSvc;c:\program files\at&t\communication manager\RcAppSvc.exe [2008-11-20 113152]
S3 SWNC8U80;Sierra Wireless MUX NDIS Driver (UMTS80);c:\windows\system32\drivers\swnc8u80.sys [2008-8-20 168192]
S3 SWUMX80;Sierra Wireless USB MUX Driver (UMTS80);c:\windows\system32\drivers\swumx80.sys [2008-8-20 142976]

=============== Created Last 30 ================

2009-12-15 01:46:10 0 d-----w- c:\program files\MSSOAP
2009-12-15 01:45:32 1563008 ----a-w- c:\windows\WRSetup.dll
2009-12-15 01:45:32 0 d-----w- c:\docume~1\stuart\applic~1\Webroot
2009-12-15 01:45:32 0 d-----w- c:\docume~1\alluse~1\applic~1\Webroot
2009-12-15 01:45:31 0 d-----w- c:\program files\Webroot
2009-12-15 01:45:03 164 ----a-w- c:\windows\install.dat
2009-12-15 01:36:36 0 d-----w- C:\_backupD
2009-12-15 01:36:30 53248 ----a-w- c:\windows\system32\process.exe
2009-12-15 01:36:30 4096 ----a-w- c:\windows\system32\reboot.exe
2009-12-15 01:36:30 280286 ----a-w- C:\win32delfkil.exe
2009-12-15 01:36:30 16384 ----a-w- c:\windows\system32\restart.exe
2009-12-15 01:36:29 42496 ----a-w- c:\windows\system32\swreg.exe
2009-12-15 01:36:28 90112 ----a-w- c:\windows\system32\regdacl.exe
2009-12-15 01:36:28 0 d-----w- c:\windows\system32\regdacl
2009-12-14 21:07:47 0 d-----w- c:\program files\TrendMicro
2009-12-14 20:09:25 0 d-----w- c:\docume~1\stuart\applic~1\Malwarebytes
2009-12-14 19:49:24 0 d-----w- c:\windows\pss
2009-12-14 17:40:06 0 d-sh--w- c:\documents and settings\stuart\IECompatCache
2009-12-14 17:29:18 93184 ------w- c:\windows\system32\rimakani.dll
2009-12-14 17:23:57 32768 ----a-w- c:\windows\system32\msilojzb.dll
2009-12-14 17:23:22 84480 --sha-r- c:\windows\system32\jgdw400R.exe
2009-12-14 17:23:20 52736 ----a-w- C:\enhs.exe
2009-12-14 17:23:18 8704 ----a-w- C:\acad.exe
2009-12-14 17:21:27 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-12-11 03:09:46 0 d-----w- c:\program files\Microsoft SQL Server
2009-12-11 03:09:24 0 d-----w- c:\program files\common files\WexTech Shared
2009-12-11 03:09:24 0 d-----w- c:\program files\common files\LHSPF
2009-12-11 03:09:09 0 d-----w- c:\windows\system32\Scanning
2009-12-11 03:09:09 0 d-----w- c:\program files\Tigerpaw CRM+
2009-12-11 03:09:09 0 d-----w- c:\program files\Business Objects
2009-12-10 23:28:21 0 d-----w- c:\program files\common files\Wise Installation Wizard
2009-12-09 19:52:58 0 d-----w- C:\2Wire_DSL_Setup_Tool
2009-12-02 17:29:48 0 d-----w- c:\program files\Yahoo!
2009-12-02 17:02:26 139359 ------w- c:\windows\system32\dlfgozil.dll
2009-12-02 17:02:03 139355 ------w- c:\windows\system32\dlxgozil.dll
2009-12-01 19:18:27 0 d-----w- c:\program files\MSECache
2009-12-01 19:17:56 0 d-----w- c:\program files\MSXML 4.0
2009-12-01 17:15:56 177456 ----a-w- c:\windows\system32\dlsrm.dll
2009-12-01 17:11:50 0 ----a-w- c:\documents and settings\stuart\New Bitmap Image.bmp
2009-12-01 16:38:03 31561 ----a-w- c:\windows\maxlink.ini
2009-12-01 16:36:54 0 d-----w- c:\program files\common files\ScanSoft Shared
2009-12-01 16:34:40 0 d-----w- c:\program files\Dell Printers
2009-12-01 16:30:35 3252 ----a-w- c:\windows\system32\wbem\Outlook_01ca72a39bfd3e82.mof
2009-12-01 16:30:23 0 d-----w- c:\program files\Dell Inc
2009-12-01 16:13:55 452 ----a-w- c:\windows\DELLSTAT.INI
2009-12-01 16:13:32 73728 ----a-w- c:\windows\system32\dlbapwr.dll
2009-12-01 16:13:32 40960 ----a-w- c:\windows\system32\dlbavs.dll
2009-12-01 16:13:32 303104 ----a-w- c:\windows\system32\LEXBCES.EXE
2009-12-01 16:13:32 201216 ----a-w- c:\windows\system32\LEXP2P32.DLL
2009-12-01 16:13:32 196096 ----a-w- c:\windows\system32\LEX2KUSB.DLL
2009-12-01 16:13:32 174592 ----a-w- c:\windows\system32\LEXPPS.EXE
2009-12-01 16:13:32 147456 ----a-w- c:\windows\system32\LEXBCE.DLL
2009-12-01 16:13:31 286720 ----a-w- c:\windows\system32\dlbacomm.dll
2009-12-01 16:13:28 192512 ----a-w- c:\windows\system32\lexlmpm.dll
2009-12-01 16:13:12 0 d-----w- c:\program files\Dell AIO Printer A940
2009-12-01 16:13:11 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys
2009-12-01 16:13:11 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2009-12-01 16:12:59 87040 -c--a-w- c:\windows\system32\dllcache\wiafbdrv.dll
2009-12-01 16:12:59 87040 ----a-w- c:\windows\system32\wiafbdrv.dll
2009-12-01 16:12:45 69632 ----a-w- c:\windows\system32\dlbascin.dll
2009-12-01 16:12:45 57344 ----a-w- c:\windows\system32\dlbacinf.dll
2009-12-01 16:12:45 49152 ----a-w- c:\windows\system32\dlbacoin.dll
2009-12-01 16:12:45 177 ----a-w- c:\windows\system32\dlbacoin.ini
2009-12-01 16:12:44 0 d-----w- c:\program files\Dell A940
2009-12-01 16:12:39 25856 -c--a-w- c:\windows\system32\dllcache\usbprint.sys
2009-12-01 16:12:39 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2009-12-01 16:11:43 299520 ----a-w- c:\windows\uninst.exe
2009-12-01 16:11:38 0 d-----w- c:\documents and settings\stuart\WINDOWS
2009-12-01 16:09:04 376 ----a-w- c:\windows\ODBC.INI
2009-12-01 16:08:49 24816 ----a-w- c:\windows\system32\mdimon.dll
2009-12-01 16:07:05 0 d-----w- c:\program files\common files\L&H
2009-12-01 16:05:19 0 d-----w- c:\program files\Microsoft ActiveSync
2009-12-01 16:00:14 0 d-----w- c:\windows\SHELLNEW
2009-11-30 21:55:39 0 d-sh--w- c:\documents and settings\stuart\PrivacIE
2009-11-30 21:23:54 0 d-----w- c:\docume~1\stuart\applic~1\Bytemobile
2009-11-30 21:23:45 0 d-----w- c:\docume~1\stuart\applic~1\DBUpdater
2009-11-30 21:23:40 27072 ----a-w- c:\windows\system32\drivers\PCASp50.sys
2009-11-30 21:23:38 0 d-----w- c:\docume~1\stuart\applic~1\AT&T
2009-11-30 21:23:33 32128 -c--a-w- c:\windows\system32\dllcache\usbccgp.sys
2009-11-30 21:23:33 32128 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2009-11-30 21:23:26 26760 ----a-w- c:\windows\system32\drivers\swmsflt.sys
2009-11-30 21:19:12 26496 ----a-r- c:\windows\system32\drivers\RimSerial.sys
2009-11-30 21:18:59 0 d-----w- c:\program files\common files\Motorola Shared
2009-11-30 21:18:37 0 d-----w- C:\Research in Motion
2009-11-30 21:18:37 0 d-----w- c:\program files\common files\Research in Motion
2009-11-30 21:18:36 0 d-----w- c:\program files\AT&T
2009-11-30 21:18:36 0 d-----w- c:\docume~1\alluse~1\applic~1\AT&T
2009-11-30 21:17:43 0 d-----w- c:\program files\Option
2009-11-30 21:15:43 0 d-----w- c:\program files\Sierra Wireless Inc
2009-11-30 21:15:43 0 d-----w- c:\docume~1\stuart\applic~1\Sierra Wireless
2009-11-30 20:51:28 0 d-----w- c:\docume~1\stuart\applic~1\OpenOffice.org
2009-11-30 20:38:13 2560 ------w- c:\windows\system32\xpsp4res.dll
2009-11-30 20:36:30 0 d-----w- c:\windows\system32\PreInstall
2009-11-30 20:36:27 0 d--h--w- c:\windows\$hf_mig$
2009-11-30 20:33:44 0 d-----w- c:\docume~1\stuart\applic~1\Intel
2009-11-30 20:31:51 12540 ----a-w- c:\windows\system32\wpa.bak
2009-11-30 20:30:13 0 d-----w- c:\windows\system32\SoftwareDistribution
2009-11-30 20:25:55 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2009-11-30 20:25:52 10368 ----a-w- c:\windows\system32\drivers\hidusb.sys
2009-11-30 20:20:21 0 d-----w- c:\program files\JRE
2009-11-30 20:19:53 0 d-----w- c:\program files\OpenOffice.org 3
2009-11-30 20:19:30 73728 ----a-w- c:\windows\system32\javacpl.cpl
2009-11-30 20:19:30 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-11-30 20:04:06 0 d-----w- C:\e738b4732769588c8f6ba40d66a96e44
2009-11-30 18:35:52 0 d-sh--w- c:\documents and settings\stuart\IETldCache
2009-11-30 18:24:05 92160 -c----w- c:\windows\system32\dllcache\iecompat.dll
2009-11-30 18:23:38 0 d-----w- c:\windows\ie8updates
2009-11-30 18:23:05 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-11-30 18:23:03 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-11-30 18:23:02 594432 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2009-11-30 18:23:00 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-11-30 18:23:00 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll
2009-11-30 18:22:57 11069952 -c----w- c:\windows\system32\dllcache\ieframe.dll
2009-11-30 18:20:43 0 dc-h--w- c:\windows\ie8
2009-11-30 18:13:55 0 d-----w- c:\program files\Astaro
2009-11-30 18:12:30 0 d--h--w- C:\$AVG
2009-11-30 18:12:18 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2009-11-30 18:12:17 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-11-30 18:12:11 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-11-30 18:12:04 0 d-----w- c:\windows\system32\drivers\Avg
2009-11-30 18:11:46 0 d-----w- c:\program files\AVG
2009-11-30 18:11:45 0 d-----w- c:\docume~1\alluse~1\applic~1\avg9
2009-11-30 18:11:25 9464 ------w- c:\windows\system32\drivers\cdralw2k.sys
2009-11-30 18:11:25 9336 ------w- c:\windows\system32\drivers\cdr4_xp.sys
2009-11-30 18:11:25 129784 ------w- c:\windows\system32\pxafs.dll
2009-11-30 18:11:25 120056 ------w- c:\windows\system32\pxcpyi64.exe
2009-11-30 18:11:25 118520 ------w- c:\windows\system32\pxinsi64.exe
2009-11-30 18:10:53 0 d-----w- c:\program files\DivX
2009-11-30 18:10:53 0 d-----w- c:\program files\common files\DivX Shared
2009-11-30 17:53:53 38 ----a-w- c:\windows\avisplitter.ini
2009-11-30 17:53:53 178176 ----a-w- c:\windows\system32\unrar.dll
2009-11-30 17:53:52 839680 ----a-w- c:\windows\system32\lameACM.acm
2009-11-30 17:53:52 414 ----a-w- c:\windows\system32\lame_acm.xml
2009-11-30 17:53:51 881664 ----a-w- c:\windows\system32\xvidcore.dll
2009-11-30 17:53:51 630784 ----a-w- c:\windows\system32\vp7vfw.dll
2009-11-30 17:53:51 39936 ----a-w- c:\windows\system32\huffyuv.dll
2009-11-30 17:53:51 217088 ----a-w- c:\windows\system32\yv12vfw.dll
2009-11-30 17:53:51 205824 ----a-w- c:\windows\system32\xvidvfw.dll
2009-11-30 17:53:51 118784 ----a-w- c:\windows\system32\ac3acm.acm
2009-11-30 17:53:49 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2009-11-30 17:53:49 547 ----a-w- c:\windows\system32\ff_vfw.dll.manifest
2009-11-30 17:53:47 0 d-----w- c:\program files\K-Lite Codec Pack
2009-11-30 17:43:42 455296 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2009-11-30 17:40:37 0 d-----w- c:\program files\CCleaner
2009-11-30 17:39:09 2145280 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-11-30 17:39:08 2023936 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-11-30 17:39:07 2066048 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe

==================== Find3M ====================

2009-12-14 18:20:01 277784 ----a-w- c:\windows\system32\drivers\iaStor.sys
2009-11-14 00:49:00 43528 ------w- c:\windows\system32\drivers\pxhelp20.sys
2009-11-14 00:47:32 90112 ----a-w- c:\windows\system32\dpl100.dll
2009-11-14 00:47:28 856064 ----a-w- c:\windows\system32\divx_xx0c.dll
2009-11-14 00:47:28 856064 ----a-w- c:\windows\system32\divx_xx07.dll
2009-11-14 00:47:28 847872 ----a-w- c:\windows\system32\divx_xx0a.dll
2009-11-14 00:47:28 843776 ----a-w- c:\windows\system32\divx_xx16.dll
2009-11-14 00:47:28 839680 ----a-w- c:\windows\system32\divx_xx11.dll
2009-11-14 00:47:28 696320 ----a-w- c:\windows\system32\DivX.dll
2009-11-06 18:00:36 23152 ----a-w- c:\windows\system32\drivers\sshrmd.sys
2009-11-06 18:00:36 176752 ----a-w- c:\windows\system32\drivers\ssidrv.sys
2009-11-06 18:00:34 29808 ----a-w- c:\windows\system32\drivers\ssfs0bbc.sys
2009-10-29 07:45:38 916480 ----a-w- c:\windows\system32\wininet.dll
2009-10-21 05:38:36 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38:36 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20:16 265728 ----a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30:16 270336 ----a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38:19 149504 ----a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38:18 79872 ----a-w- c:\windows\system32\raschap.dll
2009-09-25 05:37:09 81920 ------w- c:\windows\system32\ieencode.dll
2009-09-14 17:29:03 39424 --sha-w- c:\windows\system32\gakikedo.dll
2009-09-14 17:29:03 45568 --sha-w- c:\windows\system32\guhukene.dll
2009-09-14 17:23:33 52736 --sha-w- c:\windows\system32\halihupe.dll
2009-09-14 17:29:03 19456 --sha-w- c:\windows\system32\lipemeye.dll

============= FINISH: 20:15:22.42 ===============

Attached Files



BC AdBot (Login to Remove)

 


#2 thestuman

thestuman
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:12:19 AM

Posted 22 December 2009 - 10:33 AM

I understand that the board is extremely busy and I'm not trying to "bump" my topic, but I wanted to give a quick update. I think I have just enough knowledge to be extremely dangerous, so I've run a couple of other tools and was actually able to improve the situation.

My biggest symptom now is occasional pop ups that offer customer satisfaction surveys, etc when I'm browsing the web using Firefox or IE. This usually only happens after my computer (and/or browser) has been running for several hours.

I have rerun the programs I was originally asked to and the logs are below and/or attached. Thanks for any help you might be able to give.


DDS (Ver_09-12-01.01) - NTFSx86
Run by Stuart at 13:28:21.12 on Mon 12/21/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_17
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.207 [GMT -6:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: AntiMalware *On-access scanning enabled* (Outdated) {28e00e3b-806e-4533-925c-f4c3d79514b9}

============== Running Processes ===============

C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
svchost.exe
C:\Program Files\Dell Printers\Additional Color Laser Software\Status Monitor\DLSDBNT.EXE
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\Dell Printers\Additional Color Laser Software\Status Monitor\DLPWDNT.EXE
C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
C:\Program Files\Lenovo\Zoom\TpScrex.exe
C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe
C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\Astaro\Astaro SSL VPN Client\bin\openvpn-gui.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe
C:\Program Files\Dell Printers\paperport\pptd40nt.exe
C:\Program Files\Dell Printers\Additional Color Laser Software\Status Monitor\DLPSP.EXE
C:\Program Files\Dell Printers\Additional Color Laser Software\Updater\DLUPDR.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Dell AIO Printer A940\dlbabmon.exe
C:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.5.0.20081031-1700\soffice.exe
C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Stuart\Desktop\dds.scr

============== Pseudo HJT Report ===============

BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [SODCPreLoad] c:\program files\ibm\lotus\symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.5.0.20081031-1700\preload.exe c:\docume~1\stuart\ibm\lotus\symphony\.sodc\
uRun: [Messenger (Yahoo!)] "c:\progra~1\yahoo!\messenger\YahooMessenger.exe" -quiet
mRun: [TPHOTKEY] c:\program files\lenovo\hotkey\TPOSDSVC.exe
mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [PSQLLauncher] "c:\program files\thinkvantage fingerprint software\launcher.exe" /startup
mRun: [ACTray] c:\program files\thinkpad\connectutilities\ACTray.exe
mRun: [ACWLIcon] c:\program files\thinkpad\connectutilities\ACWLIcon.exe
mRun: [IntelZeroConfig] "c:\program files\intel\wifi\bin\ZCfgSvc.exe"
mRun: [IntelWireless] "c:\program files\common files\intel\wirelesscommon\iFrmewrk.exe" /tf Intel Wireless Tray
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [TPFNF7] c:\program files\lenovo\npdirect\TPFNF7SP.exe /r
mRun: [EZEJMNAP] c:\progra~1\thinkpad\utilit~1\EzEjMnAp.Exe
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [Acrobat Assistant 7.0] "c:\program files\adobe\acrobat 7.0\distillr\Acrotray.exe"
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mRun: [openvpn-gui] c:\program files\astaro\astaro ssl vpn client\bin\openvpn-gui.exe
mRun: [AT&T Communication Manager] "c:\program files\at&t\communication manager\ATTCM.exe" -a
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [Dell AIO Printer A940] "c:\program files\dell aio printer a940\dlbabmgr.exe"
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [PaperPort PTD] "c:\program files\dell printers\paperport\pptd40nt.exe"
mRun: [IndexSearch] "c:\program files\dell printers\paperport\IndexSearch.exe"
mRun: [DLPSP] "c:\program files\dell printers\additional color laser software\status monitor\DLPSP.EXE"
mRun: [DLUPDR] "c:\program files\dell printers\additional color laser software\updater\DLUPDR.EXE"
mRun: [DLQLU] "c:\program files\dell printers\additional color laser software\launcher\DLQLU.EXE" /S
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [Pgizeriyonido] rundll32.exe "c:\windows\iwupocit.dll",Startup
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobea~1.lnk - c:\windows\installer\{ac76ba86-1033-f400-ba7e-100000000002}\SC_Acrobat.exe
IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
LSP: bmnet.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: psfus - c:\program files\thinkvantage fingerprint software\psqlpwd.dll
Notify: tpfnf2 - c:\program files\lenovo\hotkey\notifyf2.dll
Notify: tphotkey - c:\program files\lenovo\hotkey\tphklock.dll
AppInit_DLLs: namopiya.dll c:\windows\system32\rimakani.dll
SSODL: buhahayar - {ee9afd20-b8ca-4a0b-a129-47a3c22471e0} - No File
STS: {ee9afd20-b8ca-4a0b-a129-47a3c22471e0} - No File
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll
LSA: Notification Packages = scecli c:\program files\thinkvantage fingerprint software\psqlpwd.dll ACGina towusozo.dll mscodbdy.dll
Hosts: 127.0.0.1 www.spywareinfo.com

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\stuart\applic~1\mozilla\firefox\profiles\5hrxf786.default\
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: XULRunner: {CFD8C744-6DB0-499C-9FEF-AD4D6794012E} - c:\documents and settings\stuart\local settings\application data\{cfd8c744-6db0-499c-9fef-ad4d6794012e}\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-11-30 333192]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-11-30 28424]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-11-30 360584]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2009-11-30 906520]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2009-11-30 285392]
R2 DLSDB;Dell Printer Status Database;c:\program files\dell printers\additional color laser software\status monitor\dlsdbnt.exe [2009-12-1 140184]
R2 smihlp;SMI Helper Driver (smihlp);c:\program files\common files\thinkvantage fingerprint software\drivers\smihlp.sys [2008-11-21 12560]
S2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
S3 ATTRcAppSvc;AT&T RcAppSvc;c:\program files\at&t\communication manager\RcAppSvc.exe [2008-11-20 113152]
S3 SWNC8U80;Sierra Wireless MUX NDIS Driver (UMTS80);c:\windows\system32\drivers\swnc8u80.sys [2008-8-20 168192]
S3 SWUMX80;Sierra Wireless USB MUX Driver (UMTS80);c:\windows\system32\drivers\swumx80.sys [2008-8-20 142976]

=============== Created Last 30 ================

2009-12-21 18:20:22 0 ----a-w- c:\windows\Udaxecu.bin
2009-12-21 18:20:21 120 ----a-w- c:\windows\Ywuwodafuveli.dat
2009-12-18 20:44:00 0 d--h--w- c:\windows\PIF
2009-12-18 17:01:36 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-18 17:01:34 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-12-18 17:01:32 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-18 17:01:32 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-12-16 19:37:46 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-12-15 18:18:21 0 d-----w- c:\program files\Spybot - Search & Destroy
2009-12-15 18:18:21 0 d-----w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2009-12-15 01:46:10 0 d-----w- c:\program files\MSSOAP
2009-12-15 01:45:32 1563008 ----a-w- c:\windows\WRSetup.dll
2009-12-15 01:45:32 0 d-----w- c:\docume~1\stuart\applic~1\Webroot
2009-12-15 01:45:32 0 d-----w- c:\docume~1\alluse~1\applic~1\Webroot
2009-12-15 01:45:31 0 d-----w- c:\program files\Webroot
2009-12-15 01:45:03 164 ----a-w- c:\windows\install.dat
2009-12-15 01:36:30 53248 ----a-w- c:\windows\system32\process.exe
2009-12-15 01:36:30 4096 ----a-w- c:\windows\system32\reboot.exe
2009-12-15 01:36:30 16384 ----a-w- c:\windows\system32\restart.exe
2009-12-15 01:36:29 42496 ----a-w- c:\windows\system32\swreg.exe
2009-12-15 01:36:28 90112 ----a-w- c:\windows\system32\regdacl.exe
2009-12-15 01:36:28 0 d-----w- c:\windows\system32\regdacl
2009-12-14 21:07:47 0 d-----w- c:\program files\TrendMicro
2009-12-14 20:09:25 0 d-----w- c:\docume~1\stuart\applic~1\Malwarebytes
2009-12-14 19:49:24 0 d-----w- c:\windows\pss
2009-12-14 17:40:06 0 d-sh--w- c:\documents and settings\stuart\IECompatCache
2009-12-14 17:21:27 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-12-11 03:09:46 0 d-----w- c:\program files\Microsoft SQL Server
2009-12-11 03:09:24 0 d-----w- c:\program files\common files\WexTech Shared
2009-12-11 03:09:24 0 d-----w- c:\program files\common files\LHSPF
2009-12-11 03:09:09 0 d-----w- c:\windows\system32\Scanning
2009-12-11 03:09:09 0 d-----w- c:\program files\Tigerpaw CRM+
2009-12-11 03:09:09 0 d-----w- c:\program files\Business Objects
2009-12-10 23:28:21 0 d-----w- c:\program files\common files\Wise Installation Wizard
2009-12-09 19:52:58 0 d-----w- C:\2Wire_DSL_Setup_Tool
2009-12-02 17:29:48 0 d-----w- c:\program files\Yahoo!
2009-12-02 17:02:26 139359 ------w- c:\windows\system32\dlfgozil.dll
2009-12-02 17:02:03 139355 ------w- c:\windows\system32\dlxgozil.dll
2009-12-01 19:18:27 0 d-----w- c:\program files\MSECache
2009-12-01 19:17:56 0 d-----w- c:\program files\MSXML 4.0
2009-12-01 17:15:56 177456 ----a-w- c:\windows\system32\dlsrm.dll
2009-12-01 17:11:50 0 ----a-w- c:\documents and settings\stuart\New Bitmap Image.bmp
2009-12-01 16:38:03 31561 ----a-w- c:\windows\maxlink.ini
2009-12-01 16:36:54 0 d-----w- c:\program files\common files\ScanSoft Shared
2009-12-01 16:34:40 0 d-----w- c:\program files\Dell Printers
2009-12-01 16:30:35 3252 ----a-w- c:\windows\system32\wbem\Outlook_01ca72a39bfd3e82.mof
2009-12-01 16:30:23 0 d-----w- c:\program files\Dell Inc
2009-12-01 16:13:55 452 ----a-w- c:\windows\DELLSTAT.INI
2009-12-01 16:13:32 73728 ----a-w- c:\windows\system32\dlbapwr.dll
2009-12-01 16:13:32 40960 ----a-w- c:\windows\system32\dlbavs.dll
2009-12-01 16:13:32 303104 ----a-w- c:\windows\system32\LEXBCES.EXE
2009-12-01 16:13:32 201216 ----a-w- c:\windows\system32\LEXP2P32.DLL
2009-12-01 16:13:32 196096 ----a-w- c:\windows\system32\LEX2KUSB.DLL
2009-12-01 16:13:32 174592 ----a-w- c:\windows\system32\LEXPPS.EXE
2009-12-01 16:13:32 147456 ----a-w- c:\windows\system32\LEXBCE.DLL
2009-12-01 16:13:31 286720 ----a-w- c:\windows\system32\dlbacomm.dll
2009-12-01 16:13:28 192512 ----a-w- c:\windows\system32\lexlmpm.dll
2009-12-01 16:13:12 0 d-----w- c:\program files\Dell AIO Printer A940
2009-12-01 16:13:11 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys
2009-12-01 16:13:11 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2009-12-01 16:12:59 87040 -c--a-w- c:\windows\system32\dllcache\wiafbdrv.dll
2009-12-01 16:12:59 87040 ----a-w- c:\windows\system32\wiafbdrv.dll
2009-12-01 16:12:45 69632 ----a-w- c:\windows\system32\dlbascin.dll
2009-12-01 16:12:45 57344 ----a-w- c:\windows\system32\dlbacinf.dll
2009-12-01 16:12:45 49152 ----a-w- c:\windows\system32\dlbacoin.dll
2009-12-01 16:12:45 177 ----a-w- c:\windows\system32\dlbacoin.ini
2009-12-01 16:12:44 0 d-----w- c:\program files\Dell A940
2009-12-01 16:12:39 25856 -c--a-w- c:\windows\system32\dllcache\usbprint.sys
2009-12-01 16:12:39 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2009-12-01 16:11:43 299520 ----a-w- c:\windows\uninst.exe
2009-12-01 16:11:38 0 d-----w- c:\documents and settings\stuart\WINDOWS
2009-12-01 16:09:04 376 ----a-w- c:\windows\ODBC.INI
2009-12-01 16:08:49 24816 ----a-w- c:\windows\system32\mdimon.dll
2009-12-01 16:07:05 0 d-----w- c:\program files\common files\L&H
2009-12-01 16:05:19 0 d-----w- c:\program files\Microsoft ActiveSync
2009-12-01 16:00:14 0 d-----w- c:\windows\SHELLNEW
2009-11-30 21:55:39 0 d-sh--w- c:\documents and settings\stuart\PrivacIE
2009-11-30 21:23:54 0 d-----w- c:\docume~1\stuart\applic~1\Bytemobile
2009-11-30 21:23:45 0 d-----w- c:\docume~1\stuart\applic~1\DBUpdater
2009-11-30 21:23:40 27072 ----a-w- c:\windows\system32\drivers\PCASp50.sys
2009-11-30 21:23:38 0 d-----w- c:\docume~1\stuart\applic~1\AT&T
2009-11-30 21:23:33 32128 -c--a-w- c:\windows\system32\dllcache\usbccgp.sys
2009-11-30 21:23:33 32128 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2009-11-30 21:23:26 26760 ----a-w- c:\windows\system32\drivers\swmsflt.sys
2009-11-30 21:19:12 26496 ----a-r- c:\windows\system32\drivers\RimSerial.sys
2009-11-30 21:18:59 0 d-----w- c:\program files\common files\Motorola Shared
2009-11-30 21:18:37 0 d-----w- C:\Research in Motion
2009-11-30 21:18:37 0 d-----w- c:\program files\common files\Research in Motion
2009-11-30 21:18:36 0 d-----w- c:\program files\AT&T
2009-11-30 21:18:36 0 d-----w- c:\docume~1\alluse~1\applic~1\AT&T
2009-11-30 21:17:43 0 d-----w- c:\program files\Option
2009-11-30 21:15:43 0 d-----w- c:\program files\Sierra Wireless Inc
2009-11-30 21:15:43 0 d-----w- c:\docume~1\stuart\applic~1\Sierra Wireless
2009-11-30 20:51:28 0 d-----w- c:\docume~1\stuart\applic~1\OpenOffice.org
2009-11-30 20:38:13 2560 ------w- c:\windows\system32\xpsp4res.dll
2009-11-30 20:36:30 0 d-----w- c:\windows\system32\PreInstall
2009-11-30 20:36:27 0 d--h--w- c:\windows\$hf_mig$
2009-11-30 20:33:44 0 d-----w- c:\docume~1\stuart\applic~1\Intel
2009-11-30 20:31:51 12540 ----a-w- c:\windows\system32\wpa.bak
2009-11-30 20:30:13 0 d-----w- c:\windows\system32\SoftwareDistribution
2009-11-30 20:25:55 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2009-11-30 20:25:52 10368 ----a-w- c:\windows\system32\drivers\hidusb.sys
2009-11-30 20:20:21 0 d-----w- c:\program files\JRE
2009-11-30 20:19:53 0 d-----w- c:\program files\OpenOffice.org 3
2009-11-30 20:19:30 73728 ----a-w- c:\windows\system32\javacpl.cpl
2009-11-30 20:19:30 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-11-30 20:04:06 0 d-----w- C:\e738b4732769588c8f6ba40d66a96e44
2009-11-30 18:35:52 0 d-sh--w- c:\documents and settings\stuart\IETldCache
2009-11-30 18:24:05 92160 -c----w- c:\windows\system32\dllcache\iecompat.dll
2009-11-30 18:23:38 0 d-----w- c:\windows\ie8updates
2009-11-30 18:23:05 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-11-30 18:23:03 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-11-30 18:23:02 594432 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2009-11-30 18:23:00 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-11-30 18:23:00 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll
2009-11-30 18:22:57 11069952 -c----w- c:\windows\system32\dllcache\ieframe.dll
2009-11-30 18:20:43 0 dc-h--w- c:\windows\ie8
2009-11-30 18:13:55 0 d-----w- c:\program files\Astaro
2009-11-30 18:12:30 0 d--h--w- C:\$AVG
2009-11-30 18:12:18 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2009-11-30 18:12:17 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-11-30 18:12:11 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-11-30 18:12:04 0 d-----w- c:\windows\system32\drivers\Avg
2009-11-30 18:11:46 0 d-----w- c:\program files\AVG
2009-11-30 18:11:45 0 d-----w- c:\docume~1\alluse~1\applic~1\avg9
2009-11-30 18:11:25 9464 ------w- c:\windows\system32\drivers\cdralw2k.sys
2009-11-30 18:11:25 9336 ------w- c:\windows\system32\drivers\cdr4_xp.sys
2009-11-30 18:11:25 129784 ------w- c:\windows\system32\pxafs.dll
2009-11-30 18:11:25 120056 ------w- c:\windows\system32\pxcpyi64.exe
2009-11-30 18:11:25 118520 ------w- c:\windows\system32\pxinsi64.exe
2009-11-30 18:10:53 0 d-----w- c:\program files\DivX
2009-11-30 18:10:53 0 d-----w- c:\program files\common files\DivX Shared
2009-11-30 17:53:53 38 ----a-w- c:\windows\avisplitter.ini
2009-11-30 17:53:53 178176 ----a-w- c:\windows\system32\unrar.dll
2009-11-30 17:53:52 839680 ----a-w- c:\windows\system32\lameACM.acm
2009-11-30 17:53:52 414 ----a-w- c:\windows\system32\lame_acm.xml
2009-11-30 17:53:51 881664 ----a-w- c:\windows\system32\xvidcore.dll
2009-11-30 17:53:51 630784 ----a-w- c:\windows\system32\vp7vfw.dll
2009-11-30 17:53:51 39936 ----a-w- c:\windows\system32\huffyuv.dll
2009-11-30 17:53:51 217088 ----a-w- c:\windows\system32\yv12vfw.dll
2009-11-30 17:53:51 205824 ----a-w- c:\windows\system32\xvidvfw.dll
2009-11-30 17:53:51 118784 ----a-w- c:\windows\system32\ac3acm.acm
2009-11-30 17:53:49 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2009-11-30 17:53:49 547 ----a-w- c:\windows\system32\ff_vfw.dll.manifest
2009-11-30 17:53:47 0 d-----w- c:\program files\K-Lite Codec Pack
2009-11-30 17:43:42 455296 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2009-11-30 17:40:37 0 d-----w- c:\program files\CCleaner
2009-11-30 17:39:09 2145280 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-11-30 17:39:08 2023936 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-11-30 17:39:07 2066048 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe

==================== Find3M ====================

2009-12-18 19:01:04 277784 ----a-w- c:\windows\system32\drivers\iaStor.sys
2009-11-14 00:49:00 43528 ------w- c:\windows\system32\drivers\pxhelp20.sys
2009-11-14 00:47:32 90112 ----a-w- c:\windows\system32\dpl100.dll
2009-11-14 00:47:28 856064 ----a-w- c:\windows\system32\divx_xx0c.dll
2009-11-14 00:47:28 856064 ----a-w- c:\windows\system32\divx_xx07.dll
2009-11-14 00:47:28 847872 ----a-w- c:\windows\system32\divx_xx0a.dll
2009-11-14 00:47:28 843776 ----a-w- c:\windows\system32\divx_xx16.dll
2009-11-14 00:47:28 839680 ----a-w- c:\windows\system32\divx_xx11.dll
2009-11-14 00:47:28 696320 ----a-w- c:\windows\system32\DivX.dll
2009-10-29 07:45:38 916480 ----a-w- c:\windows\system32\wininet.dll
2009-10-21 05:38:36 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38:36 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-13 10:30:16 270336 ----a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38:19 149504 ----a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38:18 79872 ----a-w- c:\windows\system32\raschap.dll
2009-09-25 05:37:09 81920 ------w- c:\windows\system32\ieencode.dll

============= FINISH: 13:30:02.03 ===============

Attached Files



#3 suebaby41

suebaby41

    W.A.M. (Women Against Malware)


  • Malware Response Team
  • 6,248 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:South Carolina, USA
  • Local time:02:19 AM

Posted 26 December 2009 - 03:13 PM

Welcome to the BleepingComputer Forums.

Since it has been a few days since you scanned your computer with HijackThis, we will need a new HijackThis log. If you have not already downloaded Random's System Information Tool (RSIT), please download Random's System Information Tool (RSIT) by random/random which includes a HijackThis log and save it to your desktop. If you have RSIT already on your computer, please run it again.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Please post the contents of log.txt.
Thank you for your patience.

Please see Preparation Guide for use before posting about your potential Malware problem.

If you have already posted this log at another forum or if you decide to seek help at another forum, please let us know. There is a shortage of helpers and taking the time of two volunteer helpers means that someone else may not be helped.

Please post your HijackThis log as a reply to this thread and not as an attachment. I am always leery of opening attachments so I always request that HijackThis logs are to be posted as a reply to the thread. I do not think that you are attaching anything scary but others may do so.

While we are working on your HijackThis log, please:
  • Reply to this thread; do not start another!
  • Do not make any changes on your computer during the cleaning process or download/add programs on your computer unless instructed to do so.
  • Do not run any other tool until instructed to do so!
  • Let me know if any of the links do not work or if any of the tools do not work.
  • Tell me about problems or symptoms that occur during the fix.
  • Do not run any other programs or open any other windows while doing a fix.
  • Ask any questions that you have regarding the fix(es), the infection(s), the performance of your computer, etc.
Thanks.
You don't stop laughing when you get old; you get old when you stop laughing.
A Member of U-N-I-T-E (Unified Network of Instructors and Trained Eliminators)
Malware Removal University Masters Graduate

Posted Image
Join The Fight Against Malware
No reply within 5 days will result in your topic being closed. If you need more time, please let me know by posting in this topic so that your topic will not be closed.

#4 thestuman

thestuman
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:12:19 AM

Posted 26 December 2009 - 06:36 PM

Sue,

Thank you so much for your help...I haven't solicited help from anyone else...

As an FYI, my computer is now running the fake "Internet Security 2010" and I actually had to run Spybot and my anti-virus to even get it to the point where I could open a browser without being redirected. I also disabled startup of a couple of items in the system configuration utility.

Thanks again for any help you may be able to offer! How could I not be patient, you volunteers are doing this out of the goodness of your heart and I applaud you!


My log is pasted below.

Logfile of random's system information tool 1.06 (written by random/random)
Run by Stuart at 2009-12-26 17:27:15
Microsoft Windows XP Professional Service Pack 3
System drive C: has 41 GB (76%) free of 53 GB
Total RAM: 1022 MB (13% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:27:49 PM, on 12/26/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Dell Printers\Additional Color Laser Software\Status Monitor\DLSDBNT.EXE
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\Dell Printers\Additional Color Laser Software\Status Monitor\DLPWDNT.EXE
C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe
C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
C:\Program Files\Lenovo\Zoom\TpScrex.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\Astaro\Astaro SSL VPN Client\bin\openvpn-gui.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe
C:\Program Files\Dell Printers\paperport\pptd40nt.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Dell Printers\Additional Color Laser Software\Status Monitor\DLPSP.EXE
C:\Program Files\Dell Printers\Additional Color Laser Software\Updater\DLUPDR.EXE
C:\Program Files\Dell AIO Printer A940\dlbabmon.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\WINDOWS\system32\winupdate86.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.5.0.20081031-1700\soffice.exe
C:\Program Files\InternetSecurity2010\IS2010.exe
C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Stuart\Desktop\RSIT.exe
C:\Program Files\trend micro\Stuart.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\winlogon86.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [PSQLLauncher] "C:\Program Files\ThinkVantage Fingerprint Software\launcher.exe" /startup
O4 - HKLM\..\Run: [ACTray] C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
O4 - HKLM\..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel Wireless Tray
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TPFNF7] C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe /r
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [openvpn-gui] C:\Program Files\Astaro\Astaro SSL VPN Client\bin\openvpn-gui.exe
O4 - HKLM\..\Run: [AT&T Communication Manager] "C:\Program Files\AT&T\Communication Manager\ATTCM.exe" -a
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Dell AIO Printer A940] "C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\Dell Printers\paperport\pptd40nt.exe"
O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\Dell Printers\paperport\IndexSearch.exe"
O4 - HKLM\..\Run: [DLPSP] "C:\Program Files\Dell Printers\Additional Color Laser Software\Status Monitor\DLPSP.EXE"
O4 - HKLM\..\Run: [DLUPDR] "C:\Program Files\Dell Printers\Additional Color Laser Software\Updater\DLUPDR.EXE"
O4 - HKLM\..\Run: [DLQLU] "C:\Program Files\Dell Printers\Additional Color Laser Software\Launcher\DLQLU.EXE" /S
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [winupdate86.exe] C:\WINDOWS\system32\winupdate86.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SODCPreLoad] C:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.5.0.20081031-1700\preload.exe C:\DOCUME~1\Stuart\IBM\Lotus\Symphony\.sodc\
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Internet Security 2010] C:\Program Files\InternetSecurity2010\IS2010.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: bmnet.dll
O10 - Unknown file in Winsock LSP: bmnet.dll
O10 - Unknown file in Winsock LSP: bmnet.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{734D0AAD-F387-4623-8A6B-4E9344E6AFCD}: NameServer = 193.104.110.38,4.2.2.1,192.168.0.5
O17 - HKLM\System\CCS\Services\Tcpip\..\{8EE9D6AD-E75D-4D41-A2DA-BCC6F162095D}: NameServer = 193.104.110.38,4.2.2.1,172.16.0.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{EBA56B4A-D6BB-4326-86A1-B7771430CCD2}: NameServer = 193.104.110.38,4.2.2.1,172.16.0.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{734D0AAD-F387-4623-8A6B-4E9344E6AFCD}: NameServer = 193.104.110.38,4.2.2.1,192.168.0.5
O17 - HKLM\System\CS2\Services\Tcpip\..\{734D0AAD-F387-4623-8A6B-4E9344E6AFCD}: NameServer = 193.104.110.38,4.2.2.1,192.168.0.5
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - AppInit_DLLs: namopiya.dll c:\windows\system32\rimakani.dll ,zudijovu.dll c:\windows\system32\jijeruwa.dll
O21 - SSODL: buhahayar - {ee9afd20-b8ca-4a0b-a129-47a3c22471e0} - (no file)
O21 - SSODL: goluzefus - {4bd40670-119f-4d7a-b2f6-727f6ee5eb7e} - c:\windows\system32\jijeruwa.dll (file missing)
O22 - SharedTaskScheduler: kupuhivus - {ee9afd20-b8ca-4a0b-a129-47a3c22471e0} - (no file)
O22 - SharedTaskScheduler: jugezatag - {4bd40670-119f-4d7a-b2f6-727f6ee5eb7e} - c:\windows\system32\jijeruwa.dll (file missing)
O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AT&T RcAppSvc (ATTRcAppSvc) - SmithMicro Inc. - C:\Program Files\AT&T\Communication Manager\RcAppSvc.exe
O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Dell Printer Status Watcher (DLPWD) - Dell Inc. - C:\Program Files\Dell Printers\Additional Color Laser Software\Status Monitor\DLPWDNT.EXE
O23 - Service: Dell Printer Status Database (DLSDB) - Dell Inc. - C:\Program Files\Dell Printers\Additional Color Laser Software\Status Monitor\DLSDBNT.EXE
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: OpenVPN Service (OpenVPNService) - Unknown owner - C:\Program Files\Astaro\Astaro SSL VPN Client\bin\openvpnserv.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel® Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless WiFi Service (S24EventMonitor) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\S24EvMon.exe

--
End of file - 13711 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\ZUAFIQOUTS.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-12-18 59032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2009-01-26 1879896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2006-12-18 231160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-11 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-10-11 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2006-12-18 231160]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"TPHOTKEY"=C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe [2008-09-30 68976]
"BluetoothAuthenticationAgent"=bthprops.cpl,,BluetoothAuthenticationAgent []
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2008-04-24 1036288]
"PSQLLauncher"=C:\Program Files\ThinkVantage Fingerprint Software\launcher.exe [2008-11-21 49928]
"ACTray"=C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe [2009-01-20 425984]
"ACWLIcon"=C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe [2009-01-20 159744]
"IntelZeroConfig"=C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe [2009-02-27 1368064]
"IntelWireless"=C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [2009-02-27 1202448]
"ISUSPM Startup"=C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe [2004-07-27 221184]
"ISUSScheduler"=C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [2005-02-16 81920]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-10-06 1323008]
"TPFNF7"=C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe [2009-01-07 60704]
"EZEJMNAP"=C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe [2008-10-08 256576]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2006-11-03 866584]
"Acrobat Assistant 7.0"=C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe [2008-04-23 483328]
"AVG9_TRAY"=C:\PROGRA~1\AVG\AVG9\avgtray.exe [2009-12-11 2033432]
"openvpn-gui"=C:\Program Files\Astaro\Astaro SSL VPN Client\bin\openvpn-gui.exe [2007-10-05 90112]
"AT&T Communication Manager"=C:\Program Files\AT&T\Communication Manager\ATTCM.exe [2008-12-01 33280]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-10-11 149280]
"Dell AIO Printer A940"=C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe [2003-06-25 294998]
"SSBkgdUpdate"=C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [2006-10-25 210472]
"PaperPort PTD"=C:\Program Files\Dell Printers\paperport\pptd40nt.exe [2008-04-02 29984]
"IndexSearch"=C:\Program Files\Dell Printers\paperport\IndexSearch.exe [2008-04-02 46368]
"DLPSP"=C:\Program Files\Dell Printers\Additional Color Laser Software\Status Monitor\DLPSP.EXE [2009-07-08 406840]
"DLUPDR"=C:\Program Files\Dell Printers\Additional Color Laser Software\Updater\DLUPDR.EXE [2009-07-08 243008]
"DLQLU"=C:\Program Files\Dell Printers\Additional Color Laser Software\Launcher\DLQLU.EXE [2009-07-08 816368]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2009-11-10 417792]
"winupdate86.exe"=C:\WINDOWS\system32\winupdate86.exe [2009-09-24 22016]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-08-21 15360]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-03-05 2260480]
"SODCPreLoad"=C:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.5.0.20081031-1700\preload.exe [2009-04-28 40960]
"Messenger (Yahoo!)"=C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe [2009-11-10 5244216]
"Internet Security 2010"=C:\Program Files\InternetSecurity2010\IS2010.exe [2009-12-24 915968]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\bozijoheb]
c:\windows\system32\jijeruwa.dll,a []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Internet Security 2010]
C:\Program Files\InternetSecurity2010\IS2010.exe [2009-12-24 915968]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pgizeriyonido]
C:\WINDOWS\iwupocit.dll,Startup []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2008-08-01 61440]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-F400-BA7E-100000000002}\SC_Acrobat.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="namopiya.dll c:\windows\system32\rimakani.dll ,zudijovu.dll c:\windows\system32\jijeruwa.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2008-11-10 143360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\psfus]
C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll [2008-11-21 95496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tpfnf2]
C:\Program Files\Lenovo\HOTKEY\notifyf2.dll [2006-09-06 34344]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tphotkey]
C:\Program Files\Lenovo\HOTKEY\tphklock.dll [2008-08-08 28672]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 239496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
buhahayar - {ee9afd20-b8ca-4a0b-a129-47a3c22471e0}
goluzefus - {4bd40670-119f-4d7a-b2f6-727f6ee5eb7e} - c:\windows\system32\jijeruwa.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
kupuhivus - {ee9afd20-b8ca-4a0b-a129-47a3c22471e0}
jugezatag - {4bd40670-119f-4d7a-b2f6-727f6ee5eb7e} - c:\windows\system32\jijeruwa.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"=C:\PROGRA~1\WINDOW~4\MpShHook.dll [2006-11-03 83224]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=scecli
C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll
ACGina
towusozo.dll
mscodbdy.dll
mohureha.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoSetActiveDesktop"=1
"NoActiveDesktopChanges"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoSetActiveDesktop"=
"NoActiveDesktopChanges"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\WINDOWS\system32\winlogon.exe"="C:\WINDOWS\system32\winlogon.exe:*:Enabled:winlogon"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{28010f9e-ddea-11de-ac2a-0018de19a419}]
shell\AutoRun\command - E:\WIN\setup.exe


======List of files/folders created in the last 3 months======

2009-12-26 17:27:17 ----D---- C:\Program Files\trend micro
2009-12-26 17:27:15 ----D---- C:\rsit
2009-12-26 11:18:26 ----A---- C:\WINDOWS\system32\10383.exe
2009-12-26 10:58:26 ----A---- C:\WINDOWS\system32\27753.exe
2009-12-26 10:38:26 ----A---- C:\WINDOWS\system32\12287.exe
2009-12-26 10:18:26 ----A---- C:\WINDOWS\system32\15457.exe
2009-12-26 09:58:26 ----A---- C:\WINDOWS\system32\11337.exe
2009-12-26 09:38:26 ----A---- C:\WINDOWS\system32\18007.exe
2009-12-26 09:18:26 ----A---- C:\WINDOWS\system32\30191.exe
2009-12-26 08:58:26 ----A---- C:\WINDOWS\system32\31107.exe
2009-12-26 08:38:26 ----A---- C:\WINDOWS\system32\3430.exe
2009-12-26 08:18:26 ----A---- C:\WINDOWS\system32\13966.exe
2009-12-26 07:58:26 ----A---- C:\WINDOWS\system32\21724.exe
2009-12-26 07:38:26 ----A---- C:\WINDOWS\system32\16941.exe
2009-12-26 07:18:26 ----A---- C:\WINDOWS\system32\1150.exe
2009-12-26 06:58:26 ----A---- C:\WINDOWS\system32\27350.exe
2009-12-26 06:38:26 ----A---- C:\WINDOWS\system32\12052.exe
2009-12-26 06:18:26 ----A---- C:\WINDOWS\system32\4031.exe
2009-12-26 05:58:26 ----A---- C:\WINDOWS\system32\15574.exe
2009-12-26 05:38:26 ----A---- C:\WINDOWS\system32\23655.exe
2009-12-26 05:18:26 ----A---- C:\WINDOWS\system32\24767.exe
2009-12-26 04:58:26 ----A---- C:\WINDOWS\system32\22355.exe
2009-12-26 04:38:26 ----A---- C:\WINDOWS\system32\18636.exe
2009-12-26 04:18:26 ----A---- C:\WINDOWS\system32\9161.exe
2009-12-26 03:58:26 ----A---- C:\WINDOWS\system32\13290.exe
2009-12-26 03:38:26 ----A---- C:\WINDOWS\system32\23986.exe
2009-12-26 03:18:26 ----A---- C:\WINDOWS\system32\16512.exe
2009-12-26 02:58:26 ----A---- C:\WINDOWS\system32\5097.exe
2009-12-26 02:38:26 ----A---- C:\WINDOWS\system32\15573.exe
2009-12-26 02:18:26 ----A---- C:\WINDOWS\system32\26777.exe
2009-12-26 01:58:26 ----A---- C:\WINDOWS\system32\5829.exe
2009-12-26 01:38:26 ----A---- C:\WINDOWS\system32\6270.exe
2009-12-26 01:18:26 ----A---- C:\WINDOWS\system32\19072.exe
2009-12-26 00:58:26 ----A---- C:\WINDOWS\system32\26924.exe
2009-12-26 00:38:26 ----A---- C:\WINDOWS\system32\28745.exe
2009-12-26 00:18:26 ----A---- C:\WINDOWS\system32\5021.exe
2009-12-25 23:58:26 ----A---- C:\WINDOWS\system32\22386.exe
2009-12-25 23:38:26 ----A---- C:\WINDOWS\system32\31673.exe
2009-12-25 23:28:37 ----SH---- C:\WINDOWS\system32\hugezese.exe
2009-12-25 23:18:26 ----A---- C:\WINDOWS\system32\2306.exe
2009-12-25 22:58:26 ----A---- C:\WINDOWS\system32\13977.exe
2009-12-25 22:38:26 ----A---- C:\WINDOWS\system32\9930.exe
2009-12-25 22:18:26 ----A---- C:\WINDOWS\system32\22704.exe
2009-12-25 21:58:26 ----A---- C:\WINDOWS\system32\29658.exe
2009-12-25 21:38:26 ----A---- C:\WINDOWS\system32\4639.exe
2009-12-25 21:18:26 ----A---- C:\WINDOWS\system32\31115.exe
2009-12-25 20:58:26 ----A---- C:\WINDOWS\system32\4833.exe
2009-12-25 20:38:25 ----A---- C:\WINDOWS\system32\16541.exe
2009-12-25 20:18:25 ----A---- C:\WINDOWS\system32\22929.exe
2009-12-25 19:58:25 ----A---- C:\WINDOWS\system32\2082.exe
2009-12-25 19:38:25 ----A---- C:\WINDOWS\system32\16118.exe
2009-12-25 19:18:25 ----A---- C:\WINDOWS\system32\21538.exe
2009-12-25 18:58:25 ----A---- C:\WINDOWS\system32\5537.exe
2009-12-25 18:38:25 ----A---- C:\WINDOWS\system32\11323.exe
2009-12-25 18:18:25 ----A---- C:\WINDOWS\system32\24626.exe
2009-12-25 17:58:25 ----A---- C:\WINDOWS\system32\32439.exe
2009-12-25 17:38:25 ----A---- C:\WINDOWS\system32\16944.exe
2009-12-25 17:18:25 ----A---- C:\WINDOWS\system32\26308.exe
2009-12-25 16:58:25 ----A---- C:\WINDOWS\system32\13931.exe
2009-12-25 16:38:25 ----A---- C:\WINDOWS\system32\7376.exe
2009-12-25 16:18:25 ----A---- C:\WINDOWS\system32\4966.exe
2009-12-25 15:58:25 ----A---- C:\WINDOWS\system32\11840.exe
2009-12-25 15:38:25 ----A---- C:\WINDOWS\system32\18756.exe
2009-12-25 15:18:25 ----A---- C:\WINDOWS\system32\19954.exe
2009-12-25 14:58:25 ----A---- C:\WINDOWS\system32\24084.exe
2009-12-25 14:38:25 ----A---- C:\WINDOWS\system32\12623.exe
2009-12-25 14:18:25 ----A---- C:\WINDOWS\system32\19629.exe
2009-12-25 13:58:25 ----A---- C:\WINDOWS\system32\3548.exe
2009-12-25 13:38:25 ----A---- C:\WINDOWS\system32\24393.exe
2009-12-25 13:18:25 ----A---- C:\WINDOWS\system32\31101.exe
2009-12-25 12:58:25 ----A---- C:\WINDOWS\system32\15006.exe
2009-12-25 12:38:25 ----A---- C:\WINDOWS\system32\15350.exe
2009-12-25 12:18:25 ----A---- C:\WINDOWS\system32\24370.exe
2009-12-25 11:58:25 ----A---- C:\WINDOWS\system32\6729.exe
2009-12-25 11:38:25 ----A---- C:\WINDOWS\system32\15890.exe
2009-12-25 11:18:25 ----A---- C:\WINDOWS\system32\23805.exe
2009-12-25 10:58:25 ----A---- C:\WINDOWS\system32\27446.exe
2009-12-25 10:38:25 ----A---- C:\WINDOWS\system32\22648.exe
2009-12-25 10:18:25 ----A---- C:\WINDOWS\system32\19264.exe
2009-12-25 09:58:25 ----A---- C:\WINDOWS\system32\8942.exe
2009-12-25 09:38:25 ----A---- C:\WINDOWS\system32\9040.exe
2009-12-25 09:18:24 ----A---- C:\WINDOWS\system32\30106.exe
2009-12-25 08:58:24 ----A---- C:\WINDOWS\system32\288.exe
2009-12-25 08:38:24 ----A---- C:\WINDOWS\system32\1842.exe
2009-12-25 08:18:24 ----A---- C:\WINDOWS\system32\22190.exe
2009-12-25 07:58:24 ----A---- C:\WINDOWS\system32\3035.exe
2009-12-25 07:38:24 ----A---- C:\WINDOWS\system32\12316.exe
2009-12-25 07:18:24 ----A---- C:\WINDOWS\system32\778.exe
2009-12-25 06:58:24 ----A---- C:\WINDOWS\system32\27529.exe
2009-12-25 06:38:24 ----A---- C:\WINDOWS\system32\9741.exe
2009-12-25 06:18:24 ----A---- C:\WINDOWS\system32\8723.exe
2009-12-25 05:58:24 ----A---- C:\WINDOWS\system32\12859.exe
2009-12-25 05:38:24 ----A---- C:\WINDOWS\system32\20037.exe
2009-12-25 05:27:04 ----SH---- C:\WINDOWS\system32\feronina.exe
2009-12-25 05:18:24 ----A---- C:\WINDOWS\system32\32757.exe
2009-12-25 04:58:24 ----A---- C:\WINDOWS\system32\32662.exe
2009-12-25 04:38:24 ----A---- C:\WINDOWS\system32\27644.exe
2009-12-25 04:18:24 ----A---- C:\WINDOWS\system32\25547.exe
2009-12-25 03:58:24 ----A---- C:\WINDOWS\system32\6868.exe
2009-12-25 03:38:24 ----A---- C:\WINDOWS\system32\28253.exe
2009-12-25 03:18:24 ----A---- C:\WINDOWS\system32\7711.exe
2009-12-25 02:58:24 ----A---- C:\WINDOWS\system32\15141.exe
2009-12-25 02:38:24 ----A---- C:\WINDOWS\system32\4664.exe
2009-12-25 02:18:24 ----A---- C:\WINDOWS\system32\17673.exe
2009-12-25 01:58:24 ----A---- C:\WINDOWS\system32\30333.exe
2009-12-25 01:38:24 ----A---- C:\WINDOWS\system32\31322.exe
2009-12-25 01:18:24 ----A---- C:\WINDOWS\system32\23811.exe
2009-12-25 00:58:24 ----A---- C:\WINDOWS\system32\28703.exe
2009-12-25 00:38:24 ----A---- C:\WINDOWS\system32\9894.exe
2009-12-25 00:18:24 ----A---- C:\WINDOWS\system32\17035.exe
2009-12-24 23:58:24 ----A---- C:\WINDOWS\system32\26299.exe
2009-12-24 23:38:24 ----A---- C:\WINDOWS\system32\25667.exe
2009-12-24 23:18:23 ----A---- C:\WINDOWS\system32\19912.exe
2009-12-24 22:58:23 ----A---- C:\WINDOWS\system32\1869.exe
2009-12-24 22:38:23 ----A---- C:\WINDOWS\system32\11538.exe
2009-12-24 22:18:23 ----A---- C:\WINDOWS\system32\14771.exe
2009-12-24 21:58:23 ----A---- C:\WINDOWS\system32\21726.exe
2009-12-24 21:38:23 ----A---- C:\WINDOWS\system32\5447.exe
2009-12-24 21:18:23 ----A---- C:\WINDOWS\system32\19895.exe
2009-12-24 20:58:23 ----A---- C:\WINDOWS\system32\19718.exe
2009-12-24 20:38:23 ----A---- C:\WINDOWS\system32\18716.exe
2009-12-24 20:18:23 ----A---- C:\WINDOWS\system32\17421.exe
2009-12-24 19:58:23 ----A---- C:\WINDOWS\system32\12382.exe
2009-12-24 19:38:23 ----A---- C:\WINDOWS\system32\292.exe
2009-12-24 19:18:23 ----A---- C:\WINDOWS\system32\153.exe
2009-12-24 18:58:23 ----A---- C:\WINDOWS\system32\3902.exe
2009-12-24 18:38:23 ----A---- C:\WINDOWS\system32\14604.exe
2009-12-24 18:18:23 ----A---- C:\WINDOWS\system32\32391.exe
2009-12-24 17:58:23 ----A---- C:\WINDOWS\system32\5436.exe
2009-12-24 17:38:23 ----A---- C:\WINDOWS\system32\4827.exe
2009-12-24 17:18:23 ----A---- C:\WINDOWS\system32\11942.exe
2009-12-24 16:58:23 ----A---- C:\WINDOWS\system32\2995.exe
2009-12-24 16:38:23 ----A---- C:\WINDOWS\system32\491.exe
2009-12-24 16:18:23 ----A---- C:\WINDOWS\system32\9961.exe
2009-12-24 15:58:23 ----A---- C:\WINDOWS\system32\16827.exe
2009-12-24 15:38:23 ----A---- C:\WINDOWS\system32\23281.exe
2009-12-24 15:18:23 ----A---- C:\WINDOWS\system32\28145.exe
2009-12-24 14:58:23 ----A---- C:\WINDOWS\system32\5705.exe
2009-12-24 14:38:23 ----A---- C:\WINDOWS\system32\24464.exe
2009-12-24 14:18:23 ----A---- C:\WINDOWS\system32\26962.exe
2009-12-24 13:58:23 ----A---- C:\WINDOWS\system32\29358.exe
2009-12-24 13:38:23 ----A---- C:\WINDOWS\system32\11478.exe
2009-12-24 13:18:23 ----A---- C:\WINDOWS\system32\15724.exe
2009-12-24 13:14:41 ----D---- C:\Documents and Settings\Stuart\Application Data\AVG9
2009-12-24 12:58:23 ----A---- C:\WINDOWS\system32\19169.exe
2009-12-24 12:38:23 ----A---- C:\WINDOWS\system32\26500.exe
2009-12-24 12:18:23 ----A---- C:\WINDOWS\system32\6334.exe
2009-12-24 11:58:22 ----A---- C:\WINDOWS\system32\18467.exe
2009-12-24 11:38:50 ----D---- C:\Program Files\InternetSecurity2010
2009-12-24 11:38:22 ----A---- C:\WINDOWS\system32\41.exe
2009-12-24 11:25:46 ----SH---- C:\WINDOWS\system32\lesetate.dll
2009-12-24 11:25:42 ----SH---- C:\WINDOWS\system32\kihugali.dll
2009-12-24 11:25:38 ----A---- C:\WINDOWS\system32\winhelper86.dll
2009-12-24 11:24:47 ----ASH---- C:\WINDOWS\system32\winupdate86.exe
2009-12-24 11:24:47 ----ASH---- C:\WINDOWS\system32\winlogon86.exe
2009-12-24 11:24:43 ----A---- C:\uwlwfa.exe
2009-12-24 11:24:41 ----A---- C:\oqnqso.exe
2009-12-24 11:24:38 ----A---- C:\waxfhosk.exe
2009-12-23 13:42:08 ----D---- C:\Documents and Settings\Stuart\Application Data\Fraqtive
2009-12-23 13:41:24 ----D---- C:\Program Files\Fraqtive
2009-12-21 13:38:54 ----A---- C:\RootRepeal report 12-21-09 (13-38-54).txt
2009-12-18 14:44:00 ----HD---- C:\WINDOWS\PIF
2009-12-18 11:01:34 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-12-18 11:01:32 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-12-16 16:40:34 ----D---- C:\Documents and Settings\All Users\Application Data\Yahoo!
2009-12-15 12:18:21 ----D---- C:\Program Files\Spybot - Search & Destroy
2009-12-15 12:18:21 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2009-12-14 19:46:10 ----D---- C:\Program Files\MSSOAP
2009-12-14 19:45:32 ----D---- C:\Documents and Settings\Stuart\Application Data\Webroot
2009-12-14 19:45:32 ----D---- C:\Documents and Settings\All Users\Application Data\Webroot
2009-12-14 19:45:32 ----A---- C:\WINDOWS\WRSetup.dll
2009-12-14 19:45:31 ----D---- C:\Program Files\Webroot
2009-12-14 19:38:56 ----A---- C:\look1.txt
2009-12-14 19:36:36 ----A---- C:\windelf.txt
2009-12-14 19:36:30 ----A---- C:\WINDOWS\system32\swsc.exe
2009-12-14 19:36:30 ----A---- C:\WINDOWS\system32\restart.exe
2009-12-14 19:36:30 ----A---- C:\WINDOWS\system32\reboot.exe
2009-12-14 19:36:30 ----A---- C:\WINDOWS\system32\process.exe
2009-12-14 19:36:29 ----A---- C:\WINDOWS\system32\swreg.exe
2009-12-14 19:36:28 ----D---- C:\WINDOWS\system32\regdacl
2009-12-14 19:36:28 ----A---- C:\WINDOWS\system32\regdacl.exe
2009-12-14 15:07:47 ----D---- C:\Program Files\TrendMicro
2009-12-14 14:09:25 ----D---- C:\Documents and Settings\Stuart\Application Data\Malwarebytes
2009-12-14 13:49:24 ----D---- C:\WINDOWS\pss
2009-12-14 13:39:31 ----D---- C:\Documents and Settings\Stuart\Application Data\Mozilla
2009-12-14 11:21:27 ----N---- C:\WINDOWS\system32\MpSigStub.exe
2009-12-10 21:09:46 ----D---- C:\Program Files\Microsoft SQL Server
2009-12-10 21:09:24 ----D---- C:\Program Files\Common Files\WexTech Shared
2009-12-10 21:09:24 ----D---- C:\Program Files\Common Files\LHSPF
2009-12-10 21:09:09 ----D---- C:\WINDOWS\system32\Scanning
2009-12-10 21:09:09 ----D---- C:\Program Files\Tigerpaw CRM+
2009-12-10 21:09:09 ----D---- C:\Program Files\Business Objects
2009-12-10 17:28:21 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2009-12-09 13:52:58 ----D---- C:\2Wire_DSL_Setup_Tool
2009-12-04 15:45:02 ----D---- C:\WINDOWS\Sun
2009-12-02 17:11:59 ----D---- C:\Documents and Settings\Stuart\Application Data\DivX
2009-12-02 17:11:56 ----D---- C:\Documents and Settings\Stuart\Application Data\Media Player Classic
2009-12-02 11:35:19 ----D---- C:\Documents and Settings\Stuart\Application Data\Yahoo!
2009-12-02 11:29:48 ----D---- C:\Program Files\Yahoo!
2009-12-02 11:02:26 ----N---- C:\WINDOWS\system32\dlfgozil.dll
2009-12-02 11:02:03 ----N---- C:\WINDOWS\system32\dlxgozil.dll
2009-12-02 09:55:14 ----D---- C:\Program Files\QuickTime
2009-12-02 09:55:05 ----D---- C:\Documents and Settings\All Users\Application Data\Apple Computer
2009-12-02 09:54:07 ----D---- C:\Program Files\Common Files\Apple
2009-12-02 09:53:32 ----D---- C:\Program Files\Apple Software Update
2009-12-02 09:53:32 ----D---- C:\Documents and Settings\All Users\Application Data\Apple
2009-12-01 13:18:27 ----D---- C:\Program Files\MSECache
2009-12-01 13:17:56 ----D---- C:\Program Files\MSXML 4.0
2009-12-01 11:15:56 ----A---- C:\WINDOWS\system32\dlsrm.dll
2009-12-01 10:49:27 ----D---- C:\Documents and Settings\Stuart\Application Data\ScanSoft
2009-12-01 10:38:03 ----A---- C:\WINDOWS\maxlink.ini
2009-12-01 10:36:54 ----D---- C:\Program Files\Common Files\ScanSoft Shared
2009-12-01 10:36:37 ----D---- C:\Documents and Settings\All Users\Application Data\ScanSoft
2009-12-01 10:34:40 ----D---- C:\Program Files\Dell Printers
2009-12-01 10:30:23 ----D---- C:\Program Files\Dell Inc
2009-12-01 10:13:55 ----A---- C:\WINDOWS\DELLSTAT.INI
2009-12-01 10:13:32 ----A---- C:\WINDOWS\system32\LEXPPS.EXE
2009-12-01 10:13:32 ----A---- C:\WINDOWS\system32\LEXP2P32.DLL
2009-12-01 10:13:32 ----A---- C:\WINDOWS\system32\LEXBCES.EXE
2009-12-01 10:13:32 ----A---- C:\WINDOWS\system32\LEXBCE.DLL
2009-12-01 10:13:32 ----A---- C:\WINDOWS\system32\LEX2KUSB.DLL
2009-12-01 10:13:32 ----A---- C:\WINDOWS\system32\dlbavs.dll
2009-12-01 10:13:32 ----A---- C:\WINDOWS\system32\dlbapwr.dll
2009-12-01 10:13:31 ----A---- C:\WINDOWS\system32\dlbacomm.dll
2009-12-01 10:13:28 ----A---- C:\WINDOWS\system32\lexlmpm.dll
2009-12-01 10:13:12 ----D---- C:\Program Files\Dell AIO Printer A940
2009-12-01 10:12:59 ----A---- C:\WINDOWS\system32\wiafbdrv.dll
2009-12-01 10:12:45 ----A---- C:\WINDOWS\system32\dlbascin.dll
2009-12-01 10:12:45 ----A---- C:\WINDOWS\system32\dlbacoin.ini
2009-12-01 10:12:45 ----A---- C:\WINDOWS\system32\dlbacoin.dll
2009-12-01 10:12:45 ----A---- C:\WINDOWS\system32\dlbacinf.dll
2009-12-01 10:12:44 ----D---- C:\Program Files\Dell A940
2009-12-01 10:11:43 ----A---- C:\WINDOWS\uninst.exe
2009-12-01 10:09:04 ----A---- C:\WINDOWS\ODBC.INI
2009-12-01 10:08:49 ----A---- C:\WINDOWS\system32\mdimon.dll
2009-12-01 10:07:05 ----D---- C:\Program Files\Common Files\L&H
2009-12-01 10:05:19 ----D---- C:\Program Files\Microsoft ActiveSync
2009-12-01 10:03:08 ----D---- C:\Program Files\Common Files\DESIGNER
2009-12-01 10:02:39 ----D---- C:\Program Files\Microsoft Works
2009-12-01 10:01:46 ----D---- C:\Program Files\Microsoft Visual Studio
2009-12-01 10:00:14 ----D---- C:\WINDOWS\SHELLNEW
2009-12-01 09:59:37 ----D---- C:\Program Files\Microsoft.NET
2009-12-01 09:59:37 ----D---- C:\Program Files\Microsoft Office
2009-11-30 15:45:08 ----A---- C:\WINDOWS\system32\javaws.exe
2009-11-30 15:45:08 ----A---- C:\WINDOWS\system32\javaw.exe
2009-11-30 15:45:08 ----A---- C:\WINDOWS\system32\java.exe
2009-11-30 15:23:54 ----D---- C:\Documents and Settings\Stuart\Application Data\Bytemobile
2009-11-30 15:23:45 ----D---- C:\Documents and Settings\Stuart\Application Data\DBUpdater
2009-11-30 15:23:38 ----D---- C:\Documents and Settings\Stuart\Application Data\AT&T
2009-11-30 15:18:59 ----D---- C:\Program Files\Common Files\Motorola Shared
2009-11-30 15:18:37 ----D---- C:\Research in Motion
2009-11-30 15:18:37 ----D---- C:\Program Files\Common Files\Research in Motion
2009-11-30 15:18:36 ----D---- C:\Program Files\AT&T
2009-11-30 15:18:36 ----D---- C:\Documents and Settings\All Users\Application Data\AT&T
2009-11-30 15:17:43 ----D---- C:\Program Files\Option
2009-11-30 15:15:43 ----D---- C:\Program Files\Sierra Wireless Inc
2009-11-30 15:15:43 ----D---- C:\Documents and Settings\Stuart\Application Data\Sierra Wireless
2009-11-30 14:51:28 ----D---- C:\Documents and Settings\Stuart\Application Data\OpenOffice.org
2009-11-30 14:38:13 ----N---- C:\WINDOWS\system32\xpsp4res.dll
2009-11-30 14:37:59 ----D---- C:\Program Files\Mozilla Firefox
2009-11-30 14:36:30 ----D---- C:\WINDOWS\system32\PreInstall
2009-11-30 14:36:29 ----N---- C:\WINDOWS\system32\spmsg.dll
2009-11-30 14:36:27 ----HD---- C:\WINDOWS\$hf_mig$
2009-11-30 14:33:46 ----ASH---- C:\Documents and Settings\Stuart\Application Data\desktop.ini
2009-11-30 14:33:44 ----SD---- C:\Documents and Settings\Stuart\Application Data\Microsoft
2009-11-30 14:33:44 ----D---- C:\Documents and Settings\Stuart\Application Data\Intel
2009-11-30 14:33:44 ----D---- C:\Documents and Settings\Stuart\Application Data\InstallShield
2009-11-30 14:33:44 ----D---- C:\Documents and Settings\Stuart\Application Data\Identities
2009-11-30 14:33:44 ----D---- C:\Documents and Settings\Stuart\Application Data\ATI
2009-11-30 14:31:51 ----A---- C:\WINDOWS\system32\wpa.bak
2009-11-30 14:30:13 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2009-11-30 14:20:21 ----D---- C:\Program Files\JRE
2009-11-30 14:19:53 ----D---- C:\Program Files\OpenOffice.org 3
2009-11-30 14:19:30 ----A---- C:\WINDOWS\system32\deploytk.dll
2009-11-30 14:19:11 ----D---- C:\Program Files\Java
2009-11-30 14:18:55 ----D---- C:\Documents and Settings\Stuart\Application Data\Sun
2009-11-30 14:11:10 ----D---- C:\Documents and Settings\Stuart\Application Data\AdobeUM
2009-11-30 14:04:06 ----D---- C:\e738b4732769588c8f6ba40d66a96e44
2009-11-30 12:23:38 ----D---- C:\WINDOWS\ie8updates
2009-11-30 12:22:16 ----D---- C:\WINDOWS\WBEM
2009-11-30 12:20:43 ----HDC---- C:\WINDOWS\ie8
2009-11-30 12:13:55 ----D---- C:\Program Files\Astaro
2009-11-30 12:12:30 ----HD---- C:\$AVG
2009-11-30 12:12:18 ----A---- C:\WINDOWS\system32\avgrsstx.dll
2009-11-30 12:11:46 ----D---- C:\Program Files\AVG
2009-11-30 12:11:45 ----D---- C:\Documents and Settings\All Users\Application Data\avg9
2009-11-30 12:11:25 ----N---- C:\WINDOWS\system32\pxinsi64.exe
2009-11-30 12:11:25 ----N---- C:\WINDOWS\system32\pxinsa64.exe
2009-11-30 12:11:25 ----N---- C:\WINDOWS\system32\pxhpinst.exe
2009-11-30 12:11:25 ----N---- C:\WINDOWS\system32\pxcpyi64.exe
2009-11-30 12:11:25 ----N---- C:\WINDOWS\system32\pxcpya64.exe
2009-11-30 12:11:25 ----N---- C:\WINDOWS\system32\pxafs.dll
2009-11-30 12:10:53 ----D---- C:\Program Files\DivX
2009-11-30 12:10:53 ----D---- C:\Program Files\Common Files\DivX Shared
2009-11-30 11:59:10 ----D---- C:\Program Files\Common Files\Adobe
2009-11-30 11:58:14 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2009-11-30 11:57:45 ----D---- C:\Program Files\Adobe
2009-11-30 11:53:53 ----A---- C:\WINDOWS\system32\unrar.dll
2009-11-30 11:53:53 ----A---- C:\WINDOWS\avisplitter.ini
2009-11-30 11:53:51 ----A---- C:\WINDOWS\system32\yv12vfw.dll
2009-11-30 11:53:51 ----A---- C:\WINDOWS\system32\xvidvfw.dll
2009-11-30 11:53:51 ----A---- C:\WINDOWS\system32\xvidcore.dll
2009-11-30 11:53:51 ----A---- C:\WINDOWS\system32\vp7vfw.dll
2009-11-30 11:53:51 ----A---- C:\WINDOWS\system32\huffyuv.dll
2009-11-30 11:53:49 ----A---- C:\WINDOWS\system32\ff_vfw.dll.manifest
2009-11-30 11:53:49 ----A---- C:\WINDOWS\system32\ff_vfw.dll
2009-11-30 11:53:47 ----D---- C:\Program Files\K-Lite Codec Pack
2009-11-30 11:48:09 ----D---- C:\Documents and Settings\Stuart\Application Data\Macromedia
2009-11-30 11:48:09 ----D---- C:\Documents and Settings\Stuart\Application Data\Adobe
2009-11-30 11:47:30 ----D---- C:\Program Files\Windows Defender
2009-11-30 11:46:55 ----D---- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2009-11-30 11:41:13 ----D---- C:\Program Files\7-Zip
2009-11-30 11:40:37 ----D---- C:\Program Files\CCleaner
2009-11-13 18:47:32 ----A---- C:\WINDOWS\system32\dpl100.dll
2009-11-13 18:47:28 ----A---- C:\WINDOWS\system32\divx_xx16.dll
2009-11-13 18:47:28 ----A---- C:\WINDOWS\system32\divx_xx11.dll
2009-11-13 18:47:28 ----A---- C:\WINDOWS\system32\divx_xx0c.dll
2009-11-13 18:47:28 ----A---- C:\WINDOWS\system32\divx_xx0a.dll
2009-11-13 18:47:28 ----A---- C:\WINDOWS\system32\divx_xx07.dll
2009-11-13 18:47:28 ----A---- C:\WINDOWS\system32\DivX.dll

======List of files/folders modified in the last 3 months======

2009-12-26 17:27:17 ----RD---- C:\Program Files
2009-12-26 16:58:44 ----D---- C:\WINDOWS\Temp
2009-12-26 16:56:38 ----D---- C:\WINDOWS\system32
2009-12-26 16:53:50 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-12-26 16:30:33 ----SD---- C:\WINDOWS\Tasks
2009-12-26 16:27:28 ----RASH---- C:\boot.ini
2009-12-26 16:27:28 ----A---- C:\WINDOWS\win.ini
2009-12-26 16:27:28 ----A---- C:\WINDOWS\system.ini
2009-12-26 16:00:52 ----A---- C:\WINDOWS\WININIT.INI
2009-12-26 14:45:52 ----D---- C:\WINDOWS
2009-12-26 11:22:15 ----D---- C:\WINDOWS\Prefetch
2009-12-21 13:33:34 ----D---- C:\WINDOWS\system32\drivers
2009-12-21 10:01:54 ----SHD---- C:\WINDOWS\Installer
2009-12-21 09:51:58 ----D---- C:\WINDOWS\system32\CatRoot2
2009-12-18 11:53:23 ----D---- C:\WINDOWS\addins
2009-12-14 20:00:50 ----D---- C:\WINDOWS\system32\Restore
2009-12-14 19:57:05 ----HD---- C:\WINDOWS\inf
2009-12-14 13:33:18 ----D---- C:\WINDOWS\Debug
2009-12-14 13:11:43 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-12-14 13:07:13 ----SHD---- C:\System Volume Information
2009-12-10 21:09:36 ----RSD---- C:\WINDOWS\Fonts
2009-12-10 21:09:24 ----D---- C:\Program Files\Common Files
2009-12-08 14:07:16 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-12-08 14:06:55 ----D---- C:\Program Files\Internet Explorer
2009-12-02 17:33:59 ----D---- C:\Documents and Settings
2009-12-01 13:28:01 ----D---- C:\WINDOWS\WinSxS
2009-12-01 13:16:30 ----D---- C:\WINDOWS\SoftwareDistribution
2009-12-01 12:40:25 ----D---- C:\WINDOWS\Microsoft.NET
2009-12-01 12:40:23 ----RSD---- C:\WINDOWS\assembly
2009-12-01 11:15:44 ----HD---- C:\Program Files\InstallShield Installation Information
2009-12-01 10:36:54 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-12-01 10:35:41 ----D---- C:\Program Files\Common Files\InstallShield
2009-12-01 10:30:35 ----D---- C:\WINDOWS\system32\wbem
2009-12-01 10:16:46 ----D---- C:\WINDOWS\system32\CatRoot
2009-12-01 10:13:15 ----D---- C:\WINDOWS\twain_32
2009-12-01 10:07:49 ----D---- C:\Program Files\Common Files\Microsoft Shared
2009-12-01 10:00:40 ----D---- C:\Program Files\Common Files\System
2009-12-01 09:59:57 ----D---- C:\WINDOWS\Help
2009-12-01 09:58:30 ----D---- C:\WINDOWS\system
2009-11-30 14:35:23 ----SHD---- C:\RECYCLER
2009-11-30 14:30:49 ----D---- C:\WINDOWS\Registration
2009-11-30 14:05:14 ----D---- C:\WINDOWS\system32\XPSViewer
2009-11-30 14:05:09 ----D---- C:\WINDOWS\system32\en-US
2009-11-30 12:34:42 ----D---- C:\WINDOWS\AppPatch
2009-11-30 12:34:03 ----D---- C:\WINDOWS\security
2009-11-30 12:26:55 ----D---- C:\Program Files\Messenger
2009-11-30 12:22:19 ----D---- C:\WINDOWS\system32\config
2009-11-30 12:22:00 ----D---- C:\WINDOWS\Media
2009-11-30 12:08:19 ----D---- C:\Program Files\Outlook Express
2009-11-30 11:47:30 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2009-11-13 18:49:00 ----N---- C:\WINDOWS\system32\VXBLOCK.dll
2009-11-13 18:49:00 ----N---- C:\WINDOWS\system32\PxWave.dll
2009-11-13 18:49:00 ----N---- C:\WINDOWS\system32\PxSFS.DLL
2009-11-13 18:49:00 ----N---- C:\WINDOWS\system32\PxMas.dll
2009-11-13 18:49:00 ----N---- C:\WINDOWS\system32\pxdrv.dll
2009-11-13 18:49:00 ----N---- C:\WINDOWS\system32\Px.dll
2009-10-29 01:45:38 ----A---- C:\WINDOWS\system32\wininet.dll
2009-10-29 01:45:37 ----N---- C:\WINDOWS\system32\occache.dll
2009-10-29 01:45:37 ----A---- C:\WINDOWS\system32\urlmon.dll
2009-10-29 01:45:37 ----A---- C:\WINDOWS\system32\mshtml.dll
2009-10-29 01:45:35 ----N---- C:\WINDOWS\system32\jsproxy.dll
2009-10-29 01:45:35 ----A---- C:\WINDOWS\system32\msfeedsbs.dll
2009-10-29 01:45:35 ----A---- C:\WINDOWS\system32\msfeeds.dll
2009-10-29 01:45:34 ----N---- C:\WINDOWS\system32\iepeers.dll
2009-10-29 01:45:34 ----A---- C:\WINDOWS\system32\iertutil.dll
2009-10-29 01:45:33 ----A---- C:\WINDOWS\system32\ieframe.dll
2009-10-29 01:45:32 ----N---- C:\WINDOWS\system32\iedkcs32.dll
2009-10-28 09:07:15 ----A---- C:\WINDOWS\system32\tzchange.exe
2009-10-28 08:40:47 ----N---- C:\WINDOWS\system32\ie4uinit.exe
2009-10-20 23:38:36 ----A---- C:\WINDOWS\system32\strmfilt.dll
2009-10-20 23:38:36 ----A---- C:\WINDOWS\system32\httpapi.dll
2009-10-13 04:30:16 ----A---- C:\WINDOWS\system32\oakley.dll
2009-10-12 07:38:19 ----A---- C:\WINDOWS\system32\rastls.dll
2009-10-12 07:38:18 ----A---- C:\WINDOWS\system32\raschap.dll

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 ANC;ANC; C:\WINDOWS\System32\drivers\ANC.SYS [2005-09-28 11520]
R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2009-11-30 333192]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2009-11-30 28424]
R1 AvgTdiX;AVG Free Network Redirector; C:\WINDOWS\System32\Drivers\avgtdix.sys [2009-11-30 360584]
R1 IBMTPCHK;IBMTPCHK; \??\C:\WINDOWS\system32\Drivers\IBMBLDID.sys []
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-08-21 36352]
R1 tcpipBM;Bytemobile Kernel Network Provider; C:\WINDOWS\system32\drivers\tcpipBM.sys [2008-11-20 18816]
R1 TPHKDRV;TPHKDRV; C:\WINDOWS\system32\DRIVERS\TPHKDRV.sys [2008-05-12 17844]
R1 TSMAPIP;TSMAPIP; C:\WINDOWS\System32\drivers\TSMAPIP.SYS [2009-01-07 4608]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2008-08-21 12032]
R2 irda;IrDA Protocol; C:\WINDOWS\system32\DRIVERS\irda.sys [2008-04-13 88192]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2006-06-18 12672]
R2 s24trans;WLAN Transport; C:\WINDOWS\system32\DRIVERS\s24trans.sys [2008-08-13 11904]
R2 smihlp;SMI Helper Driver (smihlp); \??\C:\Program Files\Common Files\ThinkVantage Fingerprint Software\Drivers\smihlp.sys []
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2008-04-24 308736]
R3 AEAudio;AE Audio Service; C:\WINDOWS\system32\drivers\AEAudio.sys [2008-04-24 103424]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2008-11-11 3301888]
R3 atmeltpm;atmeltpm; C:\WINDOWS\system32\DRIVERS\atmeltpm.sys [2005-05-17 15872]
R3 CmBatt;Microsoft AC Adapter Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2008-04-13 13952]
R3 e1express;Intel® PRO/1000 PCI Express Network Connection Driver; C:\WINDOWS\system32\DRIVERS\e1e5132.sys [2007-10-12 252048]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-08-21 144384]
R3 HSF_DPV;HSF_DPV; C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys [2006-12-21 988800]
R3 HSFHWAZL;HSFHWAZL; C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys [2006-12-21 209664]
R3 IBMPMDRV;IBMPMDRV; C:\WINDOWS\system32\DRIVERS\ibmpmdrv.sys [2008-09-29 23848]
R3 NETw5x32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows XP 32 Bit; C:\WINDOWS\system32\DRIVERS\NETw5x32.sys [2009-03-04 4202496]
R3 NSCIRDA;NSC Infrared Device Driver; C:\WINDOWS\system32\DRIVERS\nscirda.sys [2008-04-13 28672]
R3 Rasirda;WAN Miniport (IrDA); C:\WINDOWS\system32\DRIVERS\rasirda.sys [2001-08-17 19584]
R3 RimVSerPort;RIM Virtual Serial Port v2; C:\WINDOWS\system32\DRIVERS\RimSerial.sys [2007-01-18 26496]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2008-08-21 5888]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2008-10-06 225696]
R3 tap0901;Astaro SSL VPN Adapter; C:\WINDOWS\system32\DRIVERS\tap0901.sys [2007-10-05 25600]
R3 TcUsb;TC USB Kernel Driver; C:\WINDOWS\System32\Drivers\tcusb.sys [2008-08-08 50704]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2006-12-21 730112]
S3 BthEnum;Bluetooth Request Block Driver; C:\WINDOWS\system32\DRIVERS\BthEnum.sys [2008-04-14 17024]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\WINDOWS\system32\DRIVERS\bthpan.sys [2008-04-14 101120]
S3 BTHPORT;Bluetooth Port Driver; C:\WINDOWS\System32\Drivers\BTHport.sys [2008-06-13 272128]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2008-04-14 18944]
S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
S3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
S3 PCASp50;PCASp50 NDIS Protocol Driver; C:\WINDOWS\System32\Drivers\PCASp50.sys [2008-11-20 27072]
S3 PCTINDIS5;PCTINDIS5 NDIS Protocol Driver; \??\C:\WINDOWS\system32\PCTINDIS5.SYS []
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\system32\DRIVERS\rfcomm.sys [2008-04-14 59136]
S3 RimUsb;BlackBerry Smartphone; C:\WINDOWS\System32\Drivers\RimUsb.sys [2008-05-20 22784]
S3 swmsflt;swmsflt; C:\WINDOWS\System32\drivers\swmsflt.sys [2008-08-22 26760]
S3 SWNC8U80;Sierra Wireless MUX NDIS Driver (UMTS80); C:\WINDOWS\system32\DRIVERS\swnc8u80.sys [2008-08-20 168192]
S3 SWUMX80;Sierra Wireless USB MUX Driver (UMTS80); C:\WINDOWS\system32\DRIVERS\swumx80.sys [2008-08-20 142976]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 sr;System Restore Filter Driver; C:\WINDOWS\system32\DRIVERS\sr.sys [2008-08-21 73472]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AcPrfMgrSvc;Ac Profile Manager Service; C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe [2009-01-20 98304]
R2 AcSvc;Access Connections Main Service; C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe [2009-01-20 217088]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2008-11-10 573440]
R2 avg9emc;AVG Free E-mail Scanner; C:\Program Files\AVG\AVG9\avgemc.exe [2009-11-30 906520]
R2 avg9wd;AVG Free WatchDog; C:\Program Files\AVG\AVG9\avgwdsvc.exe [2009-11-30 285392]
R2 BthServ;Bluetooth Support Service; C:\WINDOWS\system32\svchost.exe [2008-08-21 14336]
R2 DLPWD;Dell Printer Status Watcher; C:\Program Files\Dell Printers\Additional Color Laser Software\Status Monitor\DLPWDNT.EXE [2009-08-28 116032]
R2 DLSDB;Dell Printer Status Database; C:\Program Files\Dell Printers\Additional Color Laser Software\Status Monitor\DLSDBNT.EXE [2006-12-07 140184]
R2 EvtEng;Intel® PROSet/Wireless Event Log; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [2009-02-27 870672]
R2 IBMPMSVC;ThinkPad PM Service; C:\WINDOWS\system32\ibmpmsvc.exe [2008-09-29 38176]
R2 Irmon;Infrared Monitor; C:\WINDOWS\system32\svchost.exe [2008-08-21 14336]
R2 IviRegMgr;IviRegMgr; C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe [2007-01-04 112152]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-10-11 153376]
R2 LexBceS;LexBce Server; C:\WINDOWS\system32\LEXBCES.EXE [2003-06-25 303104]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 RegSrvc;Intel® PROSet/Wireless Registry Service; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [2009-02-27 473360]
R2 S24EventMonitor;Intel® PROSet/Wireless WiFi Service; C:\Program Files\Intel\WiFi\bin\S24EvMon.exe [2009-02-27 909312]
S2 WinDefend;Windows Defender; C:\Program Files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 ATTRcAppSvc;AT&T RcAppSvc; C:\Program Files\AT&T\Communication Manager\RcAppSvc.exe [2008-11-20 113152]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 OpenVPNService;OpenVPN Service; C:\Program Files\Astaro\Astaro SSL VPN Client\bin\openvpnserv.exe [2007-10-05 422512]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

#5 suebaby41

suebaby41

    W.A.M. (Women Against Malware)


  • Malware Response Team
  • 6,248 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:South Carolina, USA
  • Local time:02:19 AM

Posted 27 December 2009 - 12:55 PM

I have some bad news for you. Your computer is seriously infected.

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\winlogon86.exe

Unfortunately, one or more of the identified infections is a Rootkit/backdoor trojan.

IMPORTANT NOTE: Rootkits, backdoor Trojans, Botnets, and IRCBots are very dangerous because they use advanced techniques (backdoors) as a means of accessing a computer system that bypasses security mechanisms and steal sensitive information which they send back to the hacker. Many rootkits can hook into the Windows 32-bit kernel, and patch several APIs to hide new registry keys and files they install. Remote attackers use backdoor Trojans and rootkits as part of an exploit to gain unauthorized access to a computer and take control of it without your knowledge.

If your computer was used for online banking, has credit card information or other sensitive data on it, you should immediately disconnect from the Internet until your system is cleaned. All passwords should be changed immediately to include those used for banking, email, eBay, paypal and online forums. You should consider them to be compromised. You should change each password by using a different computer and not the infected one. If not, an attacker may get the new passwords and transaction information. If using a router, you need to reset it with a strong logon/password so the malware cannot gain control before connecting again. Banking and credit card institutions should be notified of the possible security breach. Because your computer was compromised, please read How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

Although the rootkit has been identified and may be removed, your computer has likely been compromised and there is no way to be sure the computer can ever be trusted again. It is dangerous and incorrect to assume that because this malware has been removed, the computer is secure. In some instances, an infection may have caused so much damage to your system that it cannot be completely cleaned or repaired. Some infections are difficult to remove completely because of their morphing characteristics which allows the malware to regenerate itself. Sometimes there is another hidden piece of malware which has not been detected by your security tools that protects malicious files and registry keys (which have been detected) so they cannot be permanently deleted. The malware may leave so many remnants behind that security tools cannot find them. Most experts in the security community believe that once infected with this type of malware, the best course of action is to wipe the drive clean, reformat and reinstall the OS. Please read:
When should I re-format? How should I reinstall?
Help: I Got Hacked. Now What Do I Do?
Where to draw the line? When to recommend a format and reinstall?

I strongly recommend that you reformat your computer. Even if we were able to clean the computer of some of the infections, your computer is not trustworthy and the removal of all affected files may not be successful. Tell me what you want to do.
You don't stop laughing when you get old; you get old when you stop laughing.
A Member of U-N-I-T-E (Unified Network of Instructors and Trained Eliminators)
Malware Removal University Masters Graduate

Posted Image
Join The Fight Against Malware
No reply within 5 days will result in your topic being closed. If you need more time, please let me know by posting in this topic so that your topic will not be closed.

#6 thestuman

thestuman
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:12:19 AM

Posted 27 December 2009 - 01:17 PM

That obviously wasn't the news I wanted to hear, but I'm not surprised. I guess I'll go ahead and wipe the drive and reload windows. What steps do I need to go through before reloading my OS? Also, Can I use the recovery console that came with my machine or do I need to load from another disc or location? Thanks for your help!

#7 suebaby41

suebaby41

    W.A.M. (Women Against Malware)


  • Malware Response Team
  • 6,248 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:South Carolina, USA
  • Local time:02:19 AM

Posted 28 December 2009 - 10:06 AM

Save your documents. You can do a Repair Install : A Repair Install will replace the system files with the files on the XP CD used for the Repair Install. It will leave your applications and settings intact, but Windows updates will need to be reapplied. A Repair Install will replace files altered by adware and malware, but will not fix an adware, malware problem.
  • Boot the computer using the XP CD. You may need to change the boot order in the system BIOS so the CD boots before the hard drive. Check your system documentation for steps to access the BIOS and change the boot order.
  • When you see the "Welcome To Setup" screen, you will see the options below

    This portion of the Setup program prepares Microsoft
    Windows XP to run on your computer:

    To setup Windows XP now, press ENTER.

    To repair a Windows XP installation using Recovery Console, press R.

    To quit Setup without installing Windows XP, press F3.

  • Press Enter to start the Windows Setup.
  • To setup Windows XP now and Repair Install , press ENTER. do not choose To repair a Windows XP installation using the Recovery Console, press R", (you Do Not want to load Recovery Console). I repeat, do not choose "To repair a Windows XP installation using the Recovery Console, press R".
  • Accept the License Agreement and Windows will search for existing Windows installations.
  • Select the XP installation you want to repair from the list and press R to start the repair. If Repair is not one of the options, END setup.
  • Setup will copy the necessary files to the hard drive and reboot. Do not press any key to boot from CD when the message appears. Setup will continue as if it were doing a clean install, but your applications and settings will remain intact.
    Do not immediately activate over the internet when asked, enable the XP firewall before connecting to the internet. You can activate after the firewall is enabled. Control Panel - Network Connections. Right click the connection you use, Properties and there is a check box on the Advanced page.
  • Reapply updates or service packs applied since initial Windows XP installation. Please note that a Repair Install using an Original pre service pack 1 or 2 XP CD used as the install media will remove SP1/SP2 respectively and service packs plus updates issued after the service packs will need to be reapplied.

You don't stop laughing when you get old; you get old when you stop laughing.
A Member of U-N-I-T-E (Unified Network of Instructors and Trained Eliminators)
Malware Removal University Masters Graduate

Posted Image
Join The Fight Against Malware
No reply within 5 days will result in your topic being closed. If you need more time, please let me know by posting in this topic so that your topic will not be closed.

#8 suebaby41

suebaby41

    W.A.M. (Women Against Malware)


  • Malware Response Team
  • 6,248 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:South Carolina, USA
  • Local time:02:19 AM

Posted 28 December 2009 - 10:07 AM

Save your documents. You can do a Repair Install : A Repair Install will replace the system files with the files on the XP CD used for the Repair Install. It will leave your applications and settings intact, but Windows updates will need to be reapplied. A Repair Install will replace files altered by adware and malware, but will not fix an adware, malware problem.
  • Boot the computer using the XP CD. You may need to change the boot order in the system BIOS so the CD boots before the hard drive. Check your system documentation for steps to access the BIOS and change the boot order.
  • When you see the "Welcome To Setup" screen, you will see the options below

    This portion of the Setup program prepares Microsoft
    Windows XP to run on your computer:

    To setup Windows XP now, press ENTER.

    To repair a Windows XP installation using Recovery Console, press R.

    To quit Setup without installing Windows XP, press F3.

  • Press Enter to start the Windows Setup.
  • To setup Windows XP now and Repair Install , press ENTER. do not choose To repair a Windows XP installation using the Recovery Console, press R", (you Do Not want to load Recovery Console). I repeat, do not choose "To repair a Windows XP installation using the Recovery Console, press R".
  • Accept the License Agreement and Windows will search for existing Windows installations.
  • Select the XP installation you want to repair from the list and press R to start the repair. If Repair is not one of the options, END setup.
  • Setup will copy the necessary files to the hard drive and reboot. Do not press any key to boot from CD when the message appears. Setup will continue as if it were doing a clean install, but your applications and settings will remain intact.
    Do not immediately activate over the internet when asked, enable the XP firewall before connecting to the internet. You can activate after the firewall is enabled. Control Panel - Network Connections. Right click the connection you use, Properties and there is a check box on the Advanced page.
  • Reapply updates or service packs applied since initial Windows XP installation. Please note that a Repair Install using an Original pre service pack 1 or 2 XP CD used as the install media will remove SP1/SP2 respectively and service packs plus updates issued after the service packs will need to be reapplied.
Save your documents. You can do a Repair Install : A Repair Install will replace the system files with the files on the XP CD used for the Repair Install. It will leave your applications and settings intact, but Windows updates will need to be reapplied. A Repair Install will replace files altered by adware and malware, but will not fix an adware, malware problem.
  • Boot the computer using the XP CD. You may need to change the boot order in the system BIOS so the CD boots before the hard drive. Check your system documentation for steps to access the BIOS and change the boot order.
  • When you see the "Welcome To Setup" screen, you will see the options below

    This portion of the Setup program prepares Microsoft
    Windows XP to run on your computer:

    To setup Windows XP now, press ENTER.

    To repair a Windows XP installation using Recovery Console, press R.

    To quit Setup without installing Windows XP, press F3.

  • Press Enter to start the Windows Setup.
  • To setup Windows XP now and Repair Install , press ENTER. do not choose To repair a Windows XP installation using the Recovery Console, press R", (you Do Not want to load Recovery Console). I repeat, do not choose "To repair a Windows XP installation using the Recovery Console, press R".
  • Accept the License Agreement and Windows will search for existing Windows installations.
  • Select the XP installation you want to repair from the list and press R to start the repair. If Repair is not one of the options, END setup.
  • Setup will copy the necessary files to the hard drive and reboot. Do not press any key to boot from CD when the message appears. Setup will continue as if it were doing a clean install, but your applications and settings will remain intact.
    Do not immediately activate over the internet when asked, enable the XP firewall before connecting to the internet. You can activate after the firewall is enabled. Control Panel - Network Connections. Right click the connection you use, Properties and there is a check box on the Advanced page.
  • Reapply updates or service packs applied since initial Windows XP installation. Please note that a Repair Install using an Original pre service pack 1 or 2 XP CD used as the install media will remove SP1/SP2 respectively and service packs plus updates issued after the service packs will need to be reapplied.

You don't stop laughing when you get old; you get old when you stop laughing.
A Member of U-N-I-T-E (Unified Network of Instructors and Trained Eliminators)
Malware Removal University Masters Graduate

Posted Image
Join The Fight Against Malware
No reply within 5 days will result in your topic being closed. If you need more time, please let me know by posting in this topic so that your topic will not be closed.

#9 suebaby41

suebaby41

    W.A.M. (Women Against Malware)


  • Malware Response Team
  • 6,248 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:South Carolina, USA
  • Local time:02:19 AM

Posted 28 December 2009 - 10:10 AM

Tips To Protect Your Computer
  • Avoid clicking on links in instant messages.
  • Avoid opening email attachments.
  • Avoid visiting every poker site on the net.
  • Avoid downloading all that free cute junk.
  • Avoid using the peer-to-peer file sharing.
  • Avoid getting those handy toolbar doodads for your browsers.
  • Malware is out there just waiting to pounce on your system if you only pass by where they are lurking which may be at some seemingly innocent web site. Be careful because some of the malware are so vicious that no one can possibly save you once you let them in.
  • Remember that new malware emerges every week of the year. Take responsibility for protecting your system because you are its first and best defense.
Tools Downloaded To Clean Your Computer

I may have asked you to install some tools. Whether or not you need to keep these programs must be decided by you. If you choose to uninstall them, follow these directions:
  • Click Start > Control Panel.
  • In Control Panel, double-click Add or Remove Programs.
  • In Add or Remove Programs, highlight the program, click Remove.
  • Close the Add or Remove Programs and the Control Panel windows.
Optional Tools:
  • Ad-Aware 2008 scans, detects, and removes spyware on your computer.
  • ATF-Cleaner cleans all user temp folders, Java cache, (which seems to be harboring more and more malware), the cache, cookies, history, download history, visited links and saved passwords. Scan weekly if you have high Internet use.
  • Trend Micro's HijackThis or random's System Information Tool (RSIT) may be uninstalled; however, if you should ever encounter another problem and seek help in this forum or others like it, you will need to download this application.
  • SUPERAntiSpyware scans, detects, and removes spyware on your computer.
  • Malwarebytes ' Anti-Malware scans, detects, and removes malware on your computer.
  • a-squared Free scans, detects, and removes trojans, worms, spyware on your computer.
  • Spybot S&D scans, detects, and removes malware on your computer.
If you have changed the default settings for files/folders, please restore the default settings for files/folders.
  • Go to My Computer.
  • Select the Tools menu and click Folder Options.
  • Click the View tab.
  • Under Advanced Settings, click the Restore Defaults button in the lower right corner.
  • Click Apply and then the OK and close My Computer.
Please take the time to read the "Steps To Keep Your Computer Clean And Secure" below.

STEPS TO KEEP YOUR COMPUTER CLEAN AND SECURE:

Please follow these simple steps in order to keep your computer clean and secure:
  • Disable and Enable System Restore. After cleaning, you will need to disable the System Restore function For Windows XP.
    Files placed in the System volume information folder are source files for the System Restore function that is available in Windows XP operating system. Files that were healed were moved in their original INFECTED state into this folder and it is necessary to DELETE them by following these steps:
    • Close all open programs. Then right-click My Computer on the Windows' desktop
    • Click on Properties.
    • Click on the System Restore tab.
    • Check Turn off System Restore on all drives.
    • Restart the system.
    • Enable System Restore by going through the first four steps again and uncheck the item mentioned in Step d.
    • You can find instructions on how to disable and enable system restore in the Windows XP System Restore Guide.
  • Make your Internet Explorer more secure: This can be done by following these simple instructions:
    • From within Internet Explorer click on the Tools menu and then click on Options.
    • Click once on the Security tab
    • Click once on the Internet icon so it becomes highlighted.
    • Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialize and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub frames across different domains to Prompt
    • When all these settings have been made, click on the OK button.
    • If it asks you if you want to save the settings, press the Yes button.
    • Click Apply > OK button and then the OK to exit the Internet Properties page.
  • Use a Firewall: - I cannot stress how important it is that you use a Firewall on your computer.  Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. For an article on Firewalls and a listing of some available ones see the link below:
    Computer Safety On line - Software Firewalls. For more information about firewalls, and why a two-way firewall is better than the Windows XP one-way firewall, please read Understanding and Using Firewalls.
  • Use An Antivirus Software and Keep It Updated: - It is very important that your computer has an antivirus software running on your machine.  This alone can save you a lot of trouble with malware in the future.  It is imperative that you update your antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software, then it will not be able to catch any of the new variants that may come out. For an article on antivirus programs and a listing of some available ones see the link below:
    Computer Safety On line - Anti-Virus
  • Visit Microsoft's Windows Update Site Frequently: It is important that you visit Microsoft Windows Update regularly. This will ensure your computer has the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
  • You should scan your computer with Spybot S&D on a regular basis just as you would an anti- virus software. A tutorial on installing & using this product can be found here:
    Using Spybot - Search & Destroy to remove Spyware from Your Computer
  • You should scan your computer with Ad-Aware 2007/2008 as well as Spybot S&D and your anti-virus program on a regular basis. A tutorial on installing & using this product can be found here:
    Ad-Aware 2008.
  • Update SpywareBlaster (at least weekly): SpywareBlaster will add a large list of programs and sites into your Internet Explorer and Firec settings that will protect you from running and downloading known malicious programs. An article on anti-malware products with links for this program and others can be found here:
    Computer Safety on line Anti Malware
  • Use the hosts file: Every version of windows has a hosts file as part of them. In a very basic sense, they are used to locate web pages. We can customize a hosts file so that it blocks certain web pages. However, it can slow down certain computers. This is why using a hosts file is optional. Download mvps hosts file Make sure you read the instructions on how to install the hosts file. There is a good tutorial HERE If you decide to download the hosts file, the slowdown problems can usually be avoided by following these steps:
    • Click the start button on the task bar at the bottom of your screen
    • Click run
    • In the dialog box, type services.msc
    • hit enter, then locate dns client
    • Highlight it, then doubleclick it.
    • On the dropdown box, change the setting from automatic to manual.
    • Click OK.
  • Use an alternative instant messenger program:.Trillian and Miranda IM These are Malware free Instant Messenger programs which allow you to connect to multiple IM services in one program! (AOL, Yahoo, ICQ, IRC, MSN)
  • Please read Tony Klein's excellent article: How I got Infected in the First Place
  • Please read Understanding Spyware, Browser Hijackers, and Dialers
  • Please read Simple and easy ways to keep your computer safe and secure on the Internet.
  • If you are using Internet Explorer, please consider using an alternate browser: Mozilla's Firefox browser is fantastic; it is much more secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built in popup blocker (as an added benefit!) that I have ever seen.
    Another good browser is Opera . Opera 9 comes loaded with the tools to keep you productive and safe. Try it today, it's absolutely free. Some of the Opera features are: Customization, BitTorrent, Content blocker, Add your favorite search engines, Thumbnail preview of tabs, Widgets, Transfer manager, Tabbed browsing, Password manager, Sessions (You can save a collection of open tabs as a session, for later retrieval, or start with the pages you had open when Opera was last closed.), Keyboard Shortcuts, Cookie control, a multitude of languages, Validate code, Toggle graphics and style sheets, and Special features such as Full-screen mode, Kiosk mode.
  • Update all these programs regularly: Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
  • If your computer was infected by a website, a program, IM, MSN, or p2p, check this site because it is Time To Fight Back.
Follow these steps and your potential for being infected again will reduce dramatically.
Good luck!

This subject is now closed. If you need this topic reopened, please contact a member of the HJT Team and we will reopen it for you. Include the address of this thread in your request. If you should have a new issue, please start a new topic. This applies only to the original topic starter. Everyone else please begin a New Topic.
You don't stop laughing when you get old; you get old when you stop laughing.
A Member of U-N-I-T-E (Unified Network of Instructors and Trained Eliminators)
Malware Removal University Masters Graduate

Posted Image
Join The Fight Against Malware
No reply within 5 days will result in your topic being closed. If you need more time, please let me know by posting in this topic so that your topic will not be closed.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users