Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected with Win32/Tanatos


  • This topic is locked This topic is locked
2 replies to this topic

#1 iFreaker

iFreaker

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:03:06 PM

Posted 14 January 2010 - 06:53 PM

Hello,
i've been infected with Win32/Tanatos. AVG shows mostly of Win32/Tanatos.J but other variants also have been detected. I used the rmtanat tool by AVG but it couldnt help. So i have reformatted and ran the rmtanat tool again. It scanned and cleaned all the files apparently. AVG just showed be an alert again so i realized that rmtanat tool gave me false positives. I fear the virus may still be lurking around even after the fresh install of XP. I know so far that it attaches itself to .exe files. So i think i might be infected again because i've run executables that the Tanatos Remover showed as clean but might not be actually clean.
Here is a RSIT Log.

QUOTE
Logfile of random's system information tool 1.06 (written by random/random)
Run by Admin at 2010-01-15 04:51:27
Microsoft Windows XP Professional Service Pack 2
System drive C: has 35 GB (90%) free of 39 GB
Total RAM: 509 MB (17% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:52:18 AM, on 1/15/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\AVG\AVG9\avgam.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\slserv.exe
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\AVG\AVG9\avgscanx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\AVG\AVG9\avgui.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Admin\Desktop\RSIT.exe
C:\DOCUME~1\Admin\LOCALS~1\Temp\Rar$EX02.312\Admin.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe
O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\WINDOWS\system32\STacSV.exe

--
End of file - 4593 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}]
IDMIEHlprObj Class - C:\Program Files\Internet Download Manager\IDMIECC.dll [2009-11-11 173488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG9\avgssie.dll [2010-01-15 1484056]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-01-15 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-01-15 73728]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG9_TRAY"=C:\PROGRA~1\AVG\AVG9\avgtray.exe [2010-01-15 2033432]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2010-01-15 149280]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2008-05-02 13529088]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2008-05-02 86016]
"SigmatelSysTrayApp"=C:\WINDOWS\sttray.exe [2007-05-06 405504]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-03 15360]
"IDMan"=C:\Program Files\Internet Download Manager\IDMan.exe [2009-11-12 3171760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgrsstarter]
C:\WINDOWS\system32\avgrsstx.dll [2010-01-15 12464]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\AVG\AVG9\avgam.exe"="C:\Program Files\AVG\AVG9\avgam.exe:*:Enabled:avgam.exe"
"C:\Program Files\AVG\AVG9\avgdiagex.exe"="C:\Program Files\AVG\AVG9\avgdiagex.exe:*:Enabled:avgdiagex.exe"
"C:\Program Files\AVG\AVG9\avgnsx.exe"="C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe"
"C:\Program Files\AVG\AVG9\avgemc.exe"="C:\Program Files\AVG\AVG9\avgemc.exe:*:Enabled:avgemc.exe"
"C:\Program Files\AVG\AVG9\avgupd.exe"="C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{35d41858-0140-11df-bc9b-8c16b9467364}]
shell\AutoRun\command - BOOTEX\thumbcache_131.exe
shell\explore\command - BOOTEX/thumbcache_131.exe
shell\open\command - .////BOOTEX/thumbcache_131.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8dd6eda3-0162-11df-bf3d-806d6172696f}]
shell\AutoRun\command - BOOTEX\thumbcache_131.exe
shell\explore\command - BOOTEX/thumbcache_131.exe
shell\open\command - .////BOOTEX/thumbcache_131.exe


======List of files/folders created in the last 1 months======

2010-01-15 04:51:27 ----D---- C:\rsit
2010-01-15 04:44:37 ----A---- C:\WINDOWS\system32\h323log.txt
2010-01-15 04:42:14 ----A---- C:\WINDOWS\system32\ksuser.dll
2010-01-15 04:41:12 ----A---- C:\WINDOWS\system32\slserv.exe
2010-01-15 04:41:12 ----A---- C:\WINDOWS\system32\slrundll.exe
2010-01-15 04:41:12 ----A---- C:\WINDOWS\system32\SLGen.dll
2010-01-15 04:41:12 ----A---- C:\WINDOWS\system32\slextspk.dll
2010-01-15 04:41:12 ----A---- C:\WINDOWS\system32\slcoinst.dll
2010-01-15 04:41:03 ----A---- C:\WINDOWS\system32\usbui.dll
2010-01-15 04:39:46 ----A---- C:\WINDOWS\imsins.BAK
2010-01-15 04:39:43 ----SHD---- C:\WINDOWS\Installer
2010-01-15 04:39:43 ----D---- C:\Program Files\Common Files\ODBC
2010-01-15 04:39:43 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-01-15 04:39:43 ----A---- C:\WINDOWS\ODBCINST.INI
2010-01-15 04:39:40 ----D---- C:\Program Files\Common Files\SpeechEngines
2010-01-15 04:39:39 ----RD---- C:\Program Files
2010-01-15 04:39:39 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-01-15 04:39:39 ----D---- C:\Program Files\Common Files
2010-01-15 04:39:36 ----RA---- C:\WINDOWS\system32\kbdtuq.dll
2010-01-15 04:39:36 ----RA---- C:\WINDOWS\system32\kbdtuf.dll
2010-01-15 04:39:36 ----RA---- C:\WINDOWS\system32\kbdazel.dll
2010-01-15 04:39:35 ----RA---- C:\WINDOWS\system32\kbdycc.dll
2010-01-15 04:39:35 ----RA---- C:\WINDOWS\system32\kbduzb.dll
2010-01-15 04:39:35 ----RA---- C:\WINDOWS\system32\kbdur.dll
2010-01-15 04:39:35 ----RA---- C:\WINDOWS\system32\kbdtat.dll
2010-01-15 04:39:35 ----RA---- C:\WINDOWS\system32\kbdru1.dll
2010-01-15 04:39:35 ----RA---- C:\WINDOWS\system32\kbdru.dll
2010-01-15 04:39:35 ----RA---- C:\WINDOWS\system32\kbdmon.dll
2010-01-15 04:39:35 ----RA---- C:\WINDOWS\system32\kbdkyr.dll
2010-01-15 04:39:35 ----RA---- C:\WINDOWS\system32\kbdkaz.dll
2010-01-15 04:39:35 ----RA---- C:\WINDOWS\system32\kbdaze.dll
2010-01-15 04:39:34 ----RA---- C:\WINDOWS\system32\kbdbu.dll
2010-01-15 04:39:34 ----RA---- C:\WINDOWS\system32\kbdblr.dll
2010-01-15 04:39:33 ----RA---- C:\WINDOWS\system32\kbdhept.dll
2010-01-15 04:39:33 ----RA---- C:\WINDOWS\system32\kbdhela3.dll
2010-01-15 04:39:33 ----RA---- C:\WINDOWS\system32\kbdhela2.dll
2010-01-15 04:39:33 ----RA---- C:\WINDOWS\system32\kbdhe319.dll
2010-01-15 04:39:33 ----RA---- C:\WINDOWS\system32\kbdhe220.dll
2010-01-15 04:39:33 ----RA---- C:\WINDOWS\system32\kbdhe.dll
2010-01-15 04:39:33 ----RA---- C:\WINDOWS\system32\kbdgkl.dll
2010-01-15 04:39:31 ----RA---- C:\WINDOWS\system32\kbdlv1.dll
2010-01-15 04:39:31 ----RA---- C:\WINDOWS\system32\kbdlv.dll
2010-01-15 04:39:31 ----RA---- C:\WINDOWS\system32\kbdlt1.dll
2010-01-15 04:39:31 ----RA---- C:\WINDOWS\system32\kbdlt.dll
2010-01-15 04:39:31 ----RA---- C:\WINDOWS\system32\kbdest.dll
2010-01-15 04:39:30 ----RA---- C:\WINDOWS\system32\kbdsl1.dll
2010-01-15 04:39:30 ----RA---- C:\WINDOWS\system32\kbdsl.dll
2010-01-15 04:39:30 ----RA---- C:\WINDOWS\system32\kbdro.dll
2010-01-15 04:39:30 ----RA---- C:\WINDOWS\system32\kbdpl1.dll
2010-01-15 04:39:30 ----RA---- C:\WINDOWS\system32\kbdpl.dll
2010-01-15 04:39:29 ----RA---- C:\WINDOWS\system32\kbdycl.dll
2010-01-15 04:39:29 ----RA---- C:\WINDOWS\system32\kbdhu1.dll
2010-01-15 04:39:29 ----RA---- C:\WINDOWS\system32\kbdhu.dll
2010-01-15 04:39:29 ----RA---- C:\WINDOWS\system32\kbdcz2.dll
2010-01-15 04:39:29 ----RA---- C:\WINDOWS\system32\kbdcz1.dll
2010-01-15 04:39:29 ----RA---- C:\WINDOWS\system32\kbdcz.dll
2010-01-15 04:39:29 ----RA---- C:\WINDOWS\system32\kbdcr.dll
2010-01-15 04:39:29 ----RA---- C:\WINDOWS\system32\KBDAL.DLL
2010-01-15 04:39:27 ----A---- C:\WINDOWS\system32\spxcoins.dll
2010-01-15 04:39:27 ----A---- C:\WINDOWS\system32\irclass.dll
2010-01-15 04:39:27 ----A---- C:\WINDOWS\system32\EqnClass.Dll
2010-01-15 04:39:27 ----A---- C:\WINDOWS\system32\dgsetup.dll
2010-01-15 04:39:27 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
2010-01-15 04:39:25 ----N---- C:\WINDOWS\system32\CONFIG.TMP
2010-01-15 04:39:25 ----A---- C:\WINDOWS\TASKMAN.EXE
2010-01-15 04:39:24 ----A---- C:\WINDOWS\system32\batt.dll
2010-01-15 04:39:24 ----A---- C:\WINDOWS\NOTEPAD.EXE
2010-01-15 04:39:23 ----A---- C:\WINDOWS\system32\storprop.dll
2010-01-15 04:39:15 ----ASH---- C:\Documents and Settings\All Users\Application Data\desktop.ini
2010-01-15 04:39:10 ----RA---- C:\WINDOWS\SET8.tmp
2010-01-15 04:39:08 ----RA---- C:\WINDOWS\SET4.tmp
2010-01-15 04:39:06 ----RA---- C:\WINDOWS\SET3.tmp
2010-01-15 04:39:02 ----D---- C:\WINDOWS\system32\CatRoot2
2010-01-15 04:39:02 ----D---- C:\WINDOWS\system32\CatRoot
2010-01-15 04:38:56 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2010-01-15 04:38:00 ----A---- C:\WINDOWS\setuplog.txt
2010-01-15 04:37:57 ----D---- C:\Documents and Settings
2010-01-15 04:37:17 ----SH---- C:\boot.ini
2010-01-15 04:31:08 ----SHD---- C:\System Volume Information
2010-01-15 04:28:18 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-01-15 04:28:18 ----RSD---- C:\WINDOWS\Fonts
2010-01-15 04:28:18 ----RD---- C:\WINDOWS\Web
2010-01-15 04:28:18 ----HD---- C:\WINDOWS\inf
2010-01-15 04:28:18 ----D---- C:\WINDOWS\WinSxS
2010-01-15 04:28:18 ----D---- C:\WINDOWS\twain_32
2010-01-15 04:28:18 ----D---- C:\WINDOWS\Temp
2010-01-15 04:28:18 ----D---- C:\WINDOWS\system32\wins
2010-01-15 04:28:18 ----D---- C:\WINDOWS\system32\wbem
2010-01-15 04:28:18 ----D---- C:\WINDOWS\system32\usmt
2010-01-15 04:28:18 ----D---- C:\WINDOWS\system32\spool
2010-01-15 04:28:18 ----D---- C:\WINDOWS\system32\ShellExt
2010-01-15 04:28:18 ----D---- C:\WINDOWS\system32\Setup
2010-01-15 04:28:18 ----D---- C:\WINDOWS\system32\ras
2010-01-15 04:28:18 ----D---- C:\WINDOWS\system32\oobe
2010-01-15 04:28:18 ----D---- C:\WINDOWS\system32\npp
2010-01-15 04:28:18 ----D---- C:\WINDOWS\system32\mui
2010-01-15 04:28:18 ----D---- C:\WINDOWS\system32\inetsrv
2010-01-15 04:28:18 ----D---- C:\WINDOWS\system32\IME
2010-01-15 04:28:18 ----D---- C:\WINDOWS\system32\icsxml
2010-01-15 04:28:18 ----D---- C:\WINDOWS\system32\ias
2010-01-15 04:28:18 ----D---- C:\WINDOWS\system32\export
2010-01-15 04:28:18 ----D---- C:\WINDOWS\system32\drivers
2010-01-15 04:28:18 ----D---- C:\WINDOWS\system32\dhcp
2010-01-15 04:28:18 ----D---- C:\WINDOWS\system32\config
2010-01-15 04:28:18 ----D---- C:\WINDOWS\system32\3com_dmi
2010-01-15 04:28:18 ----D---- C:\WINDOWS\system32\3076
2010-01-15 04:28:18 ----D---- C:\WINDOWS\system32\2052
2010-01-15 04:28:18 ----D---- C:\WINDOWS\system32\1054
2010-01-15 04:28:18 ----D---- C:\WINDOWS\system32\1042
2010-01-15 04:28:18 ----D---- C:\WINDOWS\system32\1041
2010-01-15 04:28:18 ----D---- C:\WINDOWS\system32\1037
2010-01-15 04:28:18 ----D---- C:\WINDOWS\system32\1033
2010-01-15 04:28:18 ----D---- C:\WINDOWS\system32\1031
2010-01-15 04:28:18 ----D---- C:\WINDOWS\system32\1028
2010-01-15 04:28:18 ----D---- C:\WINDOWS\system32\1025
2010-01-15 04:28:18 ----D---- C:\WINDOWS\system32
2010-01-15 04:28:18 ----D---- C:\WINDOWS\system
2010-01-15 04:28:18 ----D---- C:\WINDOWS\security
2010-01-15 04:28:18 ----D---- C:\WINDOWS\Resources
2010-01-15 04:28:18 ----D---- C:\WINDOWS\repair
2010-01-15 04:28:18 ----D---- C:\WINDOWS\Provisioning
2010-01-15 04:28:18 ----D---- C:\WINDOWS\PeerNet
2010-01-15 04:28:18 ----D---- C:\WINDOWS\pchealth
2010-01-15 04:28:18 ----D---- C:\WINDOWS\mui
2010-01-15 04:28:18 ----D---- C:\WINDOWS\msapps
2010-01-15 04:28:18 ----D---- C:\WINDOWS\msagent
2010-01-15 04:28:18 ----D---- C:\WINDOWS\Media
2010-01-15 04:28:18 ----D---- C:\WINDOWS\java
2010-01-15 04:28:18 ----D---- C:\WINDOWS\ime
2010-01-15 04:28:18 ----D---- C:\WINDOWS\Help
2010-01-15 04:28:18 ----D---- C:\WINDOWS\ehome
2010-01-15 04:28:18 ----D---- C:\WINDOWS\Driver Cache
2010-01-15 04:28:18 ----D---- C:\WINDOWS\Debug
2010-01-15 04:28:18 ----D---- C:\WINDOWS\Cursors
2010-01-15 04:28:18 ----D---- C:\WINDOWS\Connection Wizard
2010-01-15 04:28:18 ----D---- C:\WINDOWS\Config
2010-01-15 04:28:18 ----D---- C:\WINDOWS\AppPatch
2010-01-15 04:28:18 ----D---- C:\WINDOWS\addins
2010-01-15 04:28:18 ----D---- C:\WINDOWS
2010-01-15 04:24:06 ----D---- C:\Documents and Settings\Admin\Application Data\TeraCopy
2010-01-15 04:24:03 ----D---- C:\Program Files\TeraCopy
2010-01-15 04:22:22 ----D---- C:\Program Files\MagicISO
2010-01-15 04:19:29 ----D---- C:\Documents and Settings\Admin\Application Data\Xilisoft Corporation
2010-01-15 04:18:50 ----D---- C:\Program Files\Xilisoft
2010-01-15 04:17:56 ----D---- C:\Program Files\Internet Download Manager
2010-01-15 04:14:44 ----D---- C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2010-01-15 04:06:08 ----D---- C:\Documents and Settings\Admin\Application Data\Songbird2
2010-01-15 04:06:03 ----A---- C:\WINDOWS\system32\GEARAspi.dll
2010-01-15 04:05:44 ----D---- C:\Program Files\Songbird
2010-01-15 03:27:07 ----D---- C:\Program Files\LogMeIn Hamachi
2010-01-15 03:23:12 ----A---- C:\WINDOWS\system32\unrar.dll
2010-01-15 03:23:12 ----A---- C:\WINDOWS\avisplitter.ini
2010-01-15 03:23:11 ----A---- C:\WINDOWS\system32\yv12vfw.dll
2010-01-15 03:23:10 ----A---- C:\WINDOWS\system32\xvidvfw.dll
2010-01-15 03:23:10 ----A---- C:\WINDOWS\system32\xvidcore.dll
2010-01-15 03:23:09 ----A---- C:\WINDOWS\system32\ff_vfw.dll.manifest
2010-01-15 03:23:09 ----A---- C:\WINDOWS\system32\ff_vfw.dll
2010-01-15 03:23:07 ----D---- C:\Program Files\K-Lite Codec Pack
2010-01-15 03:21:44 ----D---- C:\Program Files\Notepad++
2010-01-15 03:21:44 ----D---- C:\Documents and Settings\Admin\Application Data\Notepad++
2010-01-15 03:21:15 ----D---- C:\Documents and Settings\Admin\Application Data\Adobe
2010-01-15 03:12:45 ----A---- C:\WINDOWS\system32\stacsv.exe
2010-01-15 03:12:44 ----A---- C:\WINDOWS\system32\stlang.dll
2010-01-15 03:12:44 ----A---- C:\WINDOWS\sttray.exe
2010-01-15 03:12:34 ----A---- C:\WINDOWS\system32\staco.dll
2010-01-15 03:11:56 ----A---- C:\WINDOWS\system32\spupdsvc.exe
2010-01-15 03:11:54 ----HDC---- C:\WINDOWS\$NtUninstallKB888111WXPSP2$
2010-01-15 03:11:35 ----A---- C:\WINDOWS\system32\stacapi.dll
2010-01-15 03:11:21 ----HD---- C:\Program Files\InstallShield Installation Information
2010-01-15 03:11:21 ----D---- C:\Program Files\SigmaTel
2010-01-15 03:10:55 ----D---- C:\Program Files\Messenger Plus! Live
2010-01-15 03:05:21 ----D---- C:\Program Files\Microsoft
2010-01-15 03:05:01 ----D---- C:\Program Files\Windows Live SkyDrive
2010-01-15 03:04:36 ----D---- C:\Program Files\Windows Live
2010-01-15 03:02:07 ----D---- C:\Program Files\Common Files\Windows Live
2010-01-15 03:00:43 ----HDC---- C:\WINDOWS\$MSI31Uninstall_KB893803v2$
2010-01-15 02:48:30 ----D---- C:\WINDOWS\nvidia icons
2010-01-15 02:48:08 ----D---- C:\WINDOWS\nview
2010-01-15 02:48:07 ----A---- C:\WINDOWS\system32\nvudisp.exe
2010-01-15 02:47:55 ----A---- C:\WINDOWS\system32\NVUNINST.EXE
2010-01-15 02:47:51 ----D---- C:\Program Files\Common Files\InstallShield
2010-01-15 02:47:45 ----D---- C:\NVIDIA
2010-01-15 02:26:54 ----D---- C:\Documents and Settings\Admin\Application Data\IDM
2010-01-15 02:26:54 ----D---- C:\Documents and Settings\Admin\Application Data\DMCache
2010-01-15 02:17:04 ----A---- C:\WINDOWS\system32\javaws.exe
2010-01-15 02:17:04 ----A---- C:\WINDOWS\system32\javaw.exe
2010-01-15 02:17:04 ----A---- C:\WINDOWS\system32\java.exe
2010-01-15 02:03:28 ----D---- C:\WINDOWS\system32\appmgmt
2010-01-15 02:00:29 ----D---- C:\Program Files\Sun
2010-01-15 02:00:19 ----A---- C:\WINDOWS\system32\deploytk.dll
2010-01-15 01:59:16 ----D---- C:\Program Files\Java
2010-01-15 01:58:47 ----D---- C:\Documents and Settings\Admin\Application Data\Sun
2010-01-15 01:48:56 ----RA---- C:\WINDOWS\system32\kbdintel.dll
2010-01-15 01:48:56 ----RA---- C:\WINDOWS\system32\kbdintam.dll
2010-01-15 01:48:56 ----RA---- C:\WINDOWS\system32\kbdinpun.dll
2010-01-15 01:48:56 ----RA---- C:\WINDOWS\system32\kbdinmar.dll
2010-01-15 01:48:56 ----RA---- C:\WINDOWS\system32\kbdinkan.dll
2010-01-15 01:48:56 ----RA---- C:\WINDOWS\system32\kbdinhin.dll
2010-01-15 01:48:56 ----RA---- C:\WINDOWS\system32\kbdinguj.dll
2010-01-15 01:48:56 ----RA---- C:\WINDOWS\system32\kbdindev.dll
2010-01-15 01:48:56 ----RA---- C:\WINDOWS\system32\kbdgeo.dll
2010-01-15 01:48:56 ----RA---- C:\WINDOWS\system32\kbdarmw.dll
2010-01-15 01:48:56 ----RA---- C:\WINDOWS\system32\kbdarme.dll
2010-01-15 01:48:56 ----A---- C:\WINDOWS\system32\Thawbrkr.dll
2010-01-15 01:48:55 ----RA---- C:\WINDOWS\system32\kbdvntc.dll
2010-01-15 01:48:55 ----A---- C:\WINDOWS\system32\c_iscii.dll
2010-01-15 01:48:53 ----RA---- C:\WINDOWS\system32\kbdurdu.dll
2010-01-15 01:48:53 ----RA---- C:\WINDOWS\system32\kbdsyr2.dll
2010-01-15 01:48:53 ----RA---- C:\WINDOWS\system32\kbdsyr1.dll
2010-01-15 01:48:53 ----RA---- C:\WINDOWS\system32\kbdfa.dll
2010-01-15 01:48:53 ----RA---- C:\WINDOWS\system32\kbddiv2.dll
2010-01-15 01:48:53 ----RA---- C:\WINDOWS\system32\kbddiv1.dll
2010-01-15 01:48:53 ----RA---- C:\WINDOWS\system32\kbda3.dll
2010-01-15 01:48:53 ----RA---- C:\WINDOWS\system32\kbda2.dll
2010-01-15 01:48:53 ----RA---- C:\WINDOWS\system32\kbda1.dll
2010-01-15 01:48:53 ----A---- C:\WINDOWS\system32\kbdusa.dll
2010-01-15 01:48:50 ----RA---- C:\WINDOWS\system32\kbdheb.dll
2010-01-15 01:48:47 ----RA---- C:\WINDOWS\system32\kbdth3.dll
2010-01-15 01:48:47 ----RA---- C:\WINDOWS\system32\kbdth2.dll
2010-01-15 01:48:47 ----RA---- C:\WINDOWS\system32\kbdth1.dll
2010-01-15 01:48:47 ----RA---- C:\WINDOWS\system32\kbdth0.dll
2010-01-15 01:48:47 ----A---- C:\WINDOWS\system32\ftlx041e.dll
2010-01-15 01:40:49 ----D---- C:\Documents and Settings\Admin\Application Data\Macromedia
2010-01-15 01:18:40 ----D---- C:\Documents and Settings\Admin\Application Data\Mozilla
2010-01-15 01:18:29 ----D---- C:\Program Files\Mozilla Firefox
2010-01-15 01:04:22 ----HD---- C:\WINDOWS\system32\GroupPolicy
2010-01-15 00:57:44 ----D---- C:\PNP
2010-01-15 00:57:44 ----A---- C:\WINDOWS\system32\Prounstl.exe
2010-01-15 00:57:44 ----A---- C:\WINDOWS\system32\NicInst.dll
2010-01-15 00:57:44 ----A---- C:\WINDOWS\system32\NicCo.dll
2010-01-15 00:57:44 ----A---- C:\WINDOWS\system32\e100bmsg.dll
2010-01-15 00:56:53 ----HD---- C:\$AVG
2010-01-15 00:56:40 ----A---- C:\WINDOWS\system32\avgrsstx.dll
2010-01-15 00:56:29 ----D---- C:\Program Files\AVG
2010-01-15 00:56:29 ----D---- C:\Documents and Settings\All Users\Application Data\avg9
2010-01-15 00:53:44 ----D---- C:\Documents and Settings\Admin\Application Data\WinRAR
2010-01-15 00:52:34 ----D---- C:\Program Files\WinRAR
2010-01-15 00:08:38 ----D---- C:\Documents and Settings\Admin\Application Data\Identities
2010-01-15 00:08:37 ----HD---- C:\Program Files\Uninstall Information
2010-01-15 00:08:31 ----ASH---- C:\Documents and Settings\Admin\Application Data\desktop.ini
2010-01-15 00:08:30 ----SD---- C:\Documents and Settings\Admin\Application Data\Microsoft
2010-01-15 00:07:33 ----D---- C:\WINDOWS\SoftwareDistribution
2010-01-15 00:07:31 ----D---- C:\WINDOWS\Prefetch
2010-01-15 00:07:30 ----SD---- C:\WINDOWS\system32\Microsoft
2010-01-15 00:07:30 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-01-15 00:03:22 ----D---- C:\WINDOWS\system32\xircom
2010-01-15 00:03:22 ----D---- C:\Program Files\xerox
2010-01-15 00:03:22 ----D---- C:\Program Files\microsoft frontpage
2010-01-15 00:03:05 ----A---- C:\WINDOWS\control.ini
2010-01-15 00:03:05 ----A---- C:\AUTOEXEC.BAT
2010-01-15 00:02:55 ----A---- C:\WINDOWS\OEWABLog.txt
2010-01-15 00:02:52 ----A---- C:\WINDOWS\system32\mapi32.dll
2010-01-15 00:02:05 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-01-15 00:02:05 ----RD---- C:\WINDOWS\Offline Web Pages
2010-01-15 00:02:05 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest
2010-01-15 00:01:59 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest
2010-01-15 00:01:55 ----HD---- C:\Program Files\WindowsUpdate
2010-01-15 00:01:39 ----D---- C:\WINDOWS\system32\DirectX
2010-01-14 23:54:12 ----A---- C:\WINDOWS\system32\atrace.dll
2010-01-14 23:54:06 ----A---- C:\WINDOWS\system32\desktop.ini
2010-01-14 23:54:06 ----A---- C:\WINDOWS\desktop.ini
2010-01-14 23:53:53 ----A---- C:\WINDOWS\system32\nmevtmsg.dll
2010-01-14 23:53:51 ----A---- C:\WINDOWS\system32\acctres.dll
2010-01-14 23:53:50 ----D---- C:\Program Files\Common Files\Services
2010-01-14 23:53:46 ----SD---- C:\WINDOWS\Tasks
2010-01-14 23:53:46 ----A---- C:\WINDOWS\system32\icfgnt5.dll
2010-01-14 23:53:44 ----D---- C:\Program Files\Common Files\MSSoap
2010-01-14 23:53:34 ----D---- C:\WINDOWS\srchasst
2010-01-14 23:53:32 ----D---- C:\WINDOWS\system32\Macromed
2010-01-14 23:53:26 ----A---- C:\WINDOWS\system32\wuweb.dll
2010-01-14 23:53:26 ----A---- C:\WINDOWS\system32\wucltui.dll
2010-01-14 23:53:26 ----A---- C:\WINDOWS\system32\wuauserv.dll
2010-01-14 23:53:26 ----A---- C:\WINDOWS\system32\wuaueng1.dll
2010-01-14 23:53:25 ----A---- C:\WINDOWS\system32\wuaueng.dll
2010-01-14 23:53:24 ----A---- C:\WINDOWS\system32\wups.dll
2010-01-14 23:53:24 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2010-01-14 23:53:24 ----A---- C:\WINDOWS\system32\wuauclt.exe
2010-01-14 23:53:23 ----A---- C:\WINDOWS\system32\wuapi.dll
2010-01-14 23:53:23 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
2010-01-14 23:53:23 ----A---- C:\WINDOWS\system32\bitsprx3.dll
2010-01-14 23:53:23 ----A---- C:\WINDOWS\system32\bitsprx2.dll
2010-01-14 23:53:22 ----A---- C:\WINDOWS\system32\qmgr.dll
2010-01-14 23:50:52 ----D---- C:\Program Files\Movie Maker
2010-01-14 23:50:46 ----A---- C:\WINDOWS\system32\safrslv.dll
2010-01-14 23:50:46 ----A---- C:\WINDOWS\system32\safrdm.dll
2010-01-14 23:50:46 ----A---- C:\WINDOWS\system32\safrcdlg.dll
2010-01-14 23:50:45 ----A---- C:\WINDOWS\system32\racpldlg.dll
2010-01-14 23:50:35 ----A---- C:\WINDOWS\system32\fltMc.exe
2010-01-14 23:50:35 ----A---- C:\WINDOWS\system32\fltlib.dll
2010-01-14 23:50:34 ----D---- C:\WINDOWS\system32\Restore
2010-01-14 23:50:34 ----A---- C:\WINDOWS\system32\srsvc.dll
2010-01-14 23:50:34 ----A---- C:\WINDOWS\system32\srrstr.dll
2010-01-14 23:50:34 ----A---- C:\WINDOWS\system32\srclient.dll
2010-01-14 23:50:32 ----A---- C:\WINDOWS\system32\nmmkcert.dll
2010-01-14 23:50:32 ----A---- C:\WINDOWS\system32\mnmdd.dll
2010-01-14 23:50:32 ----A---- C:\WINDOWS\system32\isrdbg32.dll
2010-01-14 23:50:32 ----A---- C:\WINDOWS\system32\ils.dll
2010-01-14 23:50:31 ----A---- C:\WINDOWS\system32\msconf.dll
2010-01-14 23:50:31 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2010-01-14 23:50:26 ----D---- C:\Program Files\NetMeeting
2010-01-14 23:50:25 ----A---- C:\WINDOWS\system32\msoert2.dll
2010-01-14 23:50:25 ----A---- C:\WINDOWS\system32\msoeacct.dll
2010-01-14 23:50:23 ----A---- C:\WINDOWS\system32\inetres.dll
2010-01-14 23:50:22 ----A---- C:\WINDOWS\system32\inetcomm.dll
2010-01-14 23:50:17 ----D---- C:\Program Files\Outlook Express
2010-01-14 23:50:17 ----A---- C:\WINDOWS\system32\schedsvc.dll
2010-01-14 23:50:16 ----A---- C:\WINDOWS\system32\mstinit.exe
2010-01-14 23:50:16 ----A---- C:\WINDOWS\system32\mstask.dll
2010-01-14 23:50:15 ----A---- C:\WINDOWS\system32\isign32.dll
2010-01-14 23:50:15 ----A---- C:\WINDOWS\system32\inetcfg.dll
2010-01-14 23:50:15 ----A---- C:\WINDOWS\system32\icwphbk.dll
2010-01-14 23:50:15 ----A---- C:\WINDOWS\system32\icwdial.dll
2010-01-14 23:50:03 ----D---- C:\Program Files\Common Files\System
2010-01-14 23:50:01 ----D---- C:\Program Files\Internet Explorer
2010-01-14 23:49:32 ----D---- C:\Program Files\ComPlus Applications
2010-01-14 23:49:30 ----A---- C:\WINDOWS\vbaddin.ini
2010-01-14 23:49:30 ----A---- C:\WINDOWS\vb.ini
2010-01-14 23:49:26 ----D---- C:\WINDOWS\Registration
2010-01-14 23:49:20 ----D---- C:\Program Files\Windows Media Player
2010-01-14 23:49:20 ----D---- C:\Program Files\Online Services
2010-01-14 23:49:13 ----D---- C:\Program Files\Messenger
2010-01-14 23:49:05 ----D---- C:\Program Files\MSN Gaming Zone
2010-01-14 23:49:05 ----A---- C:\WINDOWS\system32\write.exe
2010-01-14 23:48:53 ----A---- C:\WINDOWS\system32\sndvol32.exe
2010-01-14 23:48:53 ----A---- C:\WINDOWS\system32\hticons.dll
2010-01-14 23:48:53 ----A---- C:\WINDOWS\system32\avwav.dll
2010-01-14 23:48:52 ----A---- C:\WINDOWS\system32\avtapi.dll
2010-01-14 23:48:52 ----A---- C:\WINDOWS\system32\avmeter.dll
2010-01-14 23:48:51 ----A---- C:\WINDOWS\system32\winchat.exe
2010-01-14 23:48:41 ----A---- C:\WINDOWS\system32\getuname.dll
2010-01-14 23:48:40 ----A---- C:\WINDOWS\system32\charmap.exe
2010-01-14 23:48:39 ----A---- C:\WINDOWS\system32\sol.exe
2010-01-14 23:48:39 ----A---- C:\WINDOWS\system32\calc.exe
2010-01-14 23:48:38 ----A---- C:\WINDOWS\system32\winmine.exe
2010-01-14 23:48:38 ----A---- C:\WINDOWS\system32\mshearts.exe
2010-01-14 23:48:37 ----A---- C:\WINDOWS\system32\usrlogon.cmd
2010-01-14 23:48:37 ----A---- C:\WINDOWS\system32\tsshutdn.exe
2010-01-14 23:48:37 ----A---- C:\WINDOWS\system32\tslabels.ini
2010-01-14 23:48:37 ----A---- C:\WINDOWS\system32\tskill.exe
2010-01-14 23:48:37 ----A---- C:\WINDOWS\system32\tsdiscon.exe
2010-01-14 23:48:37 ----A---- C:\WINDOWS\system32\reset.exe
2010-01-14 23:48:37 ----A---- C:\WINDOWS\system32\freecell.exe
2010-01-14 23:48:36 ----A---- C:\WINDOWS\system32\tscon.exe
2010-01-14 23:48:36 ----A---- C:\WINDOWS\system32\shadow.exe
2010-01-14 23:48:36 ----A---- C:\WINDOWS\system32\rwinsta.exe
2010-01-14 23:48:36 ----A---- C:\WINDOWS\system32\regini.exe
2010-01-14 23:48:36 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
2010-01-14 23:48:36 ----A---- C:\WINDOWS\system32\qwinsta.exe
2010-01-14 23:48:36 ----A---- C:\WINDOWS\system32\qappsrv.exe
2010-01-14 23:48:35 ----A---- C:\WINDOWS\system32\msg.exe
2010-01-14 23:48:35 ----A---- C:\WINDOWS\system32\msdtcprf.ini
2010-01-14 23:48:35 ----A---- C:\WINDOWS\system32\logoff.exe
2010-01-14 23:48:35 ----A---- C:\WINDOWS\system32\cdmodem.dll
2010-01-14 23:48:33 ----A---- C:\WINDOWS\system32\mtxlegih.dll
2010-01-14 23:48:33 ----A---- C:\WINDOWS\system32\mtxex.dll
2010-01-14 23:48:33 ----A---- C:\WINDOWS\system32\mtxdm.dll
2010-01-14 23:48:33 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2010-01-14 23:48:33 ----A---- C:\WINDOWS\system32\comrepl.dll
2010-01-14 23:48:33 ----A---- C:\WINDOWS\system32\comaddin.dll
2010-01-14 23:48:32 ----A---- C:\WINDOWS\system32\stclient.dll
2010-01-14 23:48:32 ----A---- C:\WINDOWS\system32\comsnap.dll
2010-01-14 23:48:24 ----A---- C:\WINDOWS\system32\wmimgmt.msc
2010-01-14 23:46:13 ----D---- C:\Program Files\MSN
2010-01-14 23:46:11 ----D---- C:\Program Files\Windows NT
2010-01-14 23:46:11 ----A---- C:\WINDOWS\system32\sndrec32.exe
2010-01-14 23:46:11 ----A---- C:\WINDOWS\system32\mplay32.exe
2010-01-14 23:46:11 ----A---- C:\WINDOWS\system32\hypertrm.dll
2010-01-14 23:46:11 ----A---- C:\WINDOWS\system32\accwiz.exe
2010-01-14 23:46:10 ----A---- C:\WINDOWS\system32\spider.exe
2010-01-14 23:46:10 ----A---- C:\WINDOWS\system32\mspaint.exe
2010-01-14 23:46:10 ----A---- C:\WINDOWS\system32\clipbrd.exe
2010-01-14 23:46:09 ----A---- C:\WINDOWS\system32\tscupgrd.exe
2010-01-14 23:46:09 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
2010-01-14 23:46:09 ----A---- C:\WINDOWS\system32\sessmgr.exe
2010-01-14 23:46:09 ----A---- C:\WINDOWS\system32\remotepg.dll
2010-01-14 23:46:09 ----A---- C:\WINDOWS\system32\rdshost.exe
2010-01-14 23:46:09 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2010-01-14 23:46:09 ----A---- C:\WINDOWS\system32\rdchost.dll
2010-01-14 23:46:09 ----A---- C:\WINDOWS\system32\mstscax.dll
2010-01-14 23:46:09 ----A---- C:\WINDOWS\system32\mstsc.exe
2010-01-14 23:46:08 ----D---- C:\WINDOWS\system32\MsDtc
2010-01-14 23:46:08 ----A---- C:\WINDOWS\system32\termsrv.dll
2010-01-14 23:46:08 ----A---- C:\WINDOWS\system32\rdpwsx.dll
2010-01-14 23:46:08 ----A---- C:\WINDOWS\system32\rdpsnd.dll
2010-01-14 23:46:08 ----A---- C:\WINDOWS\system32\rdpclip.exe
2010-01-14 23:46:08 ----A---- C:\WINDOWS\system32\qprocess.exe
2010-01-14 23:46:08 ----A---- C:\WINDOWS\system32\mtxoci.dll
2010-01-14 23:46:08 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
2010-01-14 23:46:08 ----A---- C:\WINDOWS\system32\icaapi.dll
2010-01-14 23:46:08 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2010-01-14 23:46:07 ----A---- C:\WINDOWS\system32\xolehlp.dll
2010-01-14 23:46:07 ----A---- C:\WINDOWS\system32\msdtctm.dll
2010-01-14 23:46:07 ----A---- C:\WINDOWS\system32\msdtcprx.dll
2010-01-14 23:46:07 ----A---- C:\WINDOWS\system32\msdtclog.dll
2010-01-14 23:46:07 ----A---- C:\WINDOWS\system32\msdtc.exe
2010-01-14 23:46:06 ----D---- C:\WINDOWS\system32\Com
2010-01-14 23:46:06 ----A---- C:\WINDOWS\system32\colbact.dll
2010-01-14 23:46:06 ----A---- C:\WINDOWS\system32\clbcatex.dll
2010-01-14 23:46:06 ----A---- C:\WINDOWS\system32\catsrvut.dll
2010-01-14 23:46:06 ----A---- C:\WINDOWS\system32\catsrvps.dll
2010-01-14 23:46:06 ----A---- C:\WINDOWS\system32\catsrv.dll
2010-01-14 23:46:05 ----A---- C:\WINDOWS\system32\comuid.dll
2010-01-14 23:46:05 ----A---- C:\WINDOWS\system32\comsvcs.dll
2010-01-14 23:46:05 ----A---- C:\WINDOWS\system32\clbcatq.dll
2010-01-14 23:45:59 ----A---- C:\WINDOWS\system32\servdeps.dll
2010-01-14 23:45:59 ----A---- C:\WINDOWS\system32\mmfutil.dll
2010-01-14 23:45:59 ----A---- C:\WINDOWS\system32\licwmi.dll
2010-01-14 23:45:59 ----A---- C:\WINDOWS\system32\cmprops.dll

======List of files/folders modified in the last 1 months======

2010-01-15 04:39:39 ----A---- C:\WINDOWS\system.ini
2010-01-15 00:03:05 ----A---- C:\WINDOWS\win.ini

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AvgLdx86;AVG AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2010-01-15 333192]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2010-01-15 28424]
R1 AvgTdiX;AVG Network Redirector; C:\WINDOWS\System32\Drivers\avgtdix.sys [2010-01-15 360584]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-03 36096]
R3 E100B;Intel® PRO Network Connection Driver; C:\WINDOWS\system32\DRIVERS\e100b325.sys [2006-01-12 163328]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys [2009-12-23 15664]
R3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2009-09-23 26176]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-23 9600]
R3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-23 12160]
R3 Mtlmnt5;Mtlmnt5; C:\WINDOWS\system32\DRIVERS\Mtlmnt5.sys [2004-08-04 126686]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-05-02 6554496]
R3 Slntamr;Smart Link 56K Modem Driver; C:\WINDOWS\system32\DRIVERS\slntamr.sys [2004-08-04 404990]
R3 SlWdmSup;SlWdmSup; C:\WINDOWS\system32\DRIVERS\SlWdmSup.sys [2004-08-04 13240]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-03 26624]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbstor;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-03 20480]
S3 Mtlstrm;Mtlstrm; C:\WINDOWS\system32\DRIVERS\Mtlstrm.sys [2004-08-04 1309184]
S3 NtMtlFax;NtMtlFax; C:\WINDOWS\system32\DRIVERS\NtMtlFax.sys [2004-08-04 180360]
S3 SlNtHal;SlNtHal; C:\WINDOWS\system32\DRIVERS\Slnthal.sys [2004-08-04 95424]
S3 STHDA;SigmaTel High Definition Audio CODEC; C:\WINDOWS\system32\drivers\sthda.sys [2007-05-06 1222840]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avg9emc;AVG E-mail Scanner; C:\Program Files\AVG\AVG9\avgemc.exe [2010-01-15 906520]
R2 avg9wd;AVG WatchDog; C:\Program Files\AVG\AVG9\avgwdsvc.exe [2010-01-15 285392]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [2009-10-29 1074568]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-01-15 153376]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-05-02 159812]
R2 SLService;SmartLinkService; C:\WINDOWS\system32\slserv.exe [2004-08-04 73796]
S2 STacSV;SigmaTel Audio Service; C:\WINDOWS\system32\STacSV.exe [2007-05-06 94208]

-----------------EOF-----------------


Am i clean so far?

BC AdBot (Login to Remove)

 


#2 myrti

myrti

    Sillyberry


  • Malware Study Hall Admin
  • 33,774 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:At home
  • Local time:10:06 PM

Posted 20 January 2010 - 04:28 PM

Hello and welcome to Bleeping Computer

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine.

Please include a clear description of the problems you're having, along with any steps you may have performed so far.

Please refrain from running tools or applying updates other than those we suggest while we are cleaning up your computer. The reason for this is so we know what is going on with the machine at any time. Some programs can interfere with others and hamper the recovery process.

Even if you have already provided information about your PC, we need a new log to see what has changed since you originally posted your problem.
  1. Please download OTL from following mirror:
  2. Save it to your desktop.
  3. Double click on the icon on your desktop.
  4. Click the "Scan All Users" checkbox.
  5. Push the button.
  6. Two reports will open, copy and paste them in a reply here:
    • OTL.txt <-- Will be opened
    • Extra.txt <-- Will be minimized

In the upper right hand corner of the topic you will see a button called Options. If you click on this in the drop-down menu you can choose Track this topic. I suggest you do this and select Immediate E-Mail notification and click on Proceed. This way you will be advised when we respond to your topic and facilitate the cleaning of your machine.

After 5 days if a topic is not replied to we assume it has been abandoned and it is closed.

regards myrti

is that a bird?  a plane? nooo it's the flying blueberry!

If I have been helping you and haven't replied in 2 days, feel free to shoot me a PM! Please don't send help request via PM, unless I am already helping you. Use the forums!

 

Follow BleepingComputer on: Facebook | Twitter | Google+


#3 myrti

myrti

    Sillyberry


  • Malware Study Hall Admin
  • 33,774 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:At home
  • Local time:10:06 PM

Posted 25 January 2010 - 08:56 AM

Due to lack of feedback, this topic is now Closed

If you need this topic reopened, please send me a PM.
Please include the address of this thread in your request.
This applies only to the original topic starter.

Everyone else please start a new topic.

With Regards,
myrti

Due to lack of feedback, this topic is now Closed

If you need this topic reopened, please send me a PM.
Please include the address of this thread in your request.
This applies only to the original topic starter.

Everyone else please start a new topic.

With Regards,
myrti

is that a bird?  a plane? nooo it's the flying blueberry!

If I have been helping you and haven't replied in 2 days, feel free to shoot me a PM! Please don't send help request via PM, unless I am already helping you. Use the forums!

 

Follow BleepingComputer on: Facebook | Twitter | Google+





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users