PDA

View Full Version : having trouble please assist



Freeloader
2009-07-13, 23:55
Hey everyone im new to this so please stick with me

spybot picked up a nasty infection about 3 weeks ago and its been a pain to get rid of ever since. It goes by the names of virtumonde and sopidkc All for having ago myself i did some reading and used a combination of avg, malwarebytes and spybot i tried to remove it but im not convinced its gone heres the hjt log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:12:37, on 13/07/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16850)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ATKKBService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.virtuagirl.com/us/freegirls.php3
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {94885D65-4728-419E-85AE-0E5DB797D50E} - C:\WINDOWS\system32\tuvVMdBT.dll (file missing)
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [SpybotDeletingA9706] command.com /c del "C:\WINDOWS\system32\comsa32.sys"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7551] cmd.exe /c del "C:\WINDOWS\system32\comsa32.sys"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3990] command.com /c del "C:\WINDOWS\system32\sopidkc.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4053] cmd.exe /c del "C:\WINDOWS\system32\sopidkc.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingB4893] command.com /c del "C:\WINDOWS\system32\comsa32.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingD972] cmd.exe /c del "C:\WINDOWS\system32\comsa32.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8048] command.com /c del "C:\WINDOWS\system32\sopidkc.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7358] cmd.exe /c del "C:\WINDOWS\system32\sopidkc.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9994] command.com /c del "C:\WINDOWS\system32\comsa32.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1418] command.com /c del "C:\WINDOWS\system32\comsa32.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4345] cmd.exe /c del "C:\WINDOWS\system32\comsa32.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3178] command.com /c del "C:\WINDOWS\system32\sopidkc.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6692] cmd.exe /c del "C:\WINDOWS\system32\sopidkc.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7903] command.com /c del "C:\WINDOWS\system32\comsa32.sys"
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1246469442578
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1246469429984
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: C:\DOCUME~1\Andy\LOCALS~1\Temp\4249062155mxx.dll C:\WINDOWS\system32\ c:\windows\system32\ c:\windows\system32\
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

--
End of file - 6450 bytes

please assist

Shaba
2009-07-14, 14:48
Hi Freeloader

Please post next spybot report :)

Freeloader
2009-07-14, 23:41
hey shaba thanks for answering the call

spybot report is as follows.


--- Search result list ---
Congratulations!: No immediate threats were found. (Status)



--- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---

2009-01-26 blindman.exe (1.0.0.8)
2009-01-26 SDFiles.exe (1.6.1.7)
2009-01-26 SDMain.exe (1.0.0.6)
2009-01-26 SDShred.exe (1.0.2.5)
2009-01-26 SDUpdate.exe (1.6.0.12)
2009-01-26 SpybotSD.exe (1.6.2.46)
2009-03-05 TeaTimer.exe (1.6.6.32)
2009-07-01 unins000.exe (51.49.0.0)
2009-01-26 Update.exe (1.6.0.7)
2009-01-26 advcheck.dll (1.6.2.15)
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2009-01-26 SDHelper.dll (1.6.2.14)
2008-06-19 sqlite3.dll
2009-01-26 Tools.dll (2.1.6.10)
2009-01-16 UninsSrv.dll (1.0.0.0)
2009-05-19 Includes\Adware.sbi (*)
2009-06-02 Includes\AdwareC.sbi (*)
2009-01-22 Includes\Cookies.sbi (*)
2009-05-19 Includes\Dialer.sbi (*)
2009-06-02 Includes\DialerC.sbi (*)
2009-01-22 Includes\HeavyDuty.sbi (*)
2009-05-26 Includes\Hijackers.sbi (*)
2009-07-07 Includes\HijackersC.sbi (*)
2009-06-23 Includes\Keyloggers.sbi (*)
2009-07-07 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2009-06-30 Includes\Malware.sbi (*)
2009-07-07 Includes\MalwareC.sbi (*)
2009-03-25 Includes\PUPS.sbi (*)
2009-07-07 Includes\PUPSC.sbi (*)
2009-01-22 Includes\Revision.sbi (*)
2009-01-13 Includes\Security.sbi (*)
2009-06-02 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2009-04-07 Includes\Spyware.sbi (*)
2009-07-07 Includes\SpywareC.sbi (*)
2009-06-08 Includes\Tracks.uti
2009-07-07 Includes\Trojans.sbi (*)
2009-07-08 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll



--- System information ---
Windows XP (Build: 2600) Service Pack 3 (5.1.2600)
/ .NETFramework / 1.1: Microsoft .NET Framework 1.1 Hotfix (KB928366)
/ .NETFramework / 1.1: Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
/ Windows / SP1: Microsoft Internationalized Domain Names Mitigation APIs
/ Windows / SP1: Microsoft National Language Support Downlevel APIs
/ Windows Media Player: Security Update for Windows Media Player (KB952069)
/ Windows Media Player 10: Security Update for Windows Media Player 10 (KB936782)
/ Windows Media Player 6.4: Security Update for Windows Media Player 6.4 (KB925398)
/ Windows XP: Security Update for Windows XP (KB923689)
/ Windows XP: Security Update for Windows XP (KB941569)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB938127-v2)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB969897)
/ Windows XP / SP3: Windows XP Service Pack 3
/ Windows XP / SP4: Security Update for Windows XP (KB923561)
/ Windows XP / SP4: Security Update for Windows XP (KB938464-v2)
/ Windows XP / SP4: Security Update for Windows XP (KB946648)
/ Windows XP / SP4: Security Update for Windows XP (KB950759)
/ Windows XP / SP4: Security Update for Windows XP (KB950760)
/ Windows XP / SP4: Security Update for Windows XP (KB950762)
/ Windows XP / SP4: Security Update for Windows XP (KB950974)
/ Windows XP / SP4: Security Update for Windows XP (KB951066)
/ Windows XP / SP4: Security Update for Windows XP (KB951376)
/ Windows XP / SP4: Security Update for Windows XP (KB951376-v2)
/ Windows XP / SP4: Security Update for Windows XP (KB951698)
/ Windows XP / SP4: Security Update for Windows XP (KB951748)
/ Windows XP / SP4: Update for Windows XP (KB951978)
/ Windows XP / SP4: Security Update for Windows XP (KB952004)
/ Windows XP / SP4: Hotfix for Windows XP (KB952287)
/ Windows XP / SP4: Security Update for Windows XP (KB952954)
/ Windows XP / SP4: Security Update for Windows XP (KB954459)
/ Windows XP / SP4: Security Update for Windows XP (KB954600)
/ Windows XP / SP4: Security Update for Windows XP (KB955069)
/ Windows XP / SP4: Update for Windows XP (KB955839)
/ Windows XP / SP4: Security Update for Windows XP (KB956572)
/ Windows XP / SP4: Security Update for Windows XP (KB956802)
/ Windows XP / SP4: Security Update for Windows XP (KB956803)
/ Windows XP / SP4: Security Update for Windows XP (KB957097)
/ Windows XP / SP4: Security Update for Windows XP (KB958644)
/ Windows XP / SP4: Security Update for Windows XP (KB958687)
/ Windows XP / SP4: Security Update for Windows XP (KB959426)
/ Windows XP / SP4: Security Update for Windows XP (KB960225)
/ Windows XP / SP4: Security Update for Windows XP (KB960803)
/ Windows XP / SP4: Security Update for Windows XP (KB961373)
/ Windows XP / SP4: Security Update for Windows XP (KB961501)
/ Windows XP / SP4: Update for Windows XP (KB967715)
/ Windows XP / SP4: Security Update for Windows XP (KB968537)
/ Windows XP / SP4: Security Update for Windows XP (KB969897)
/ Windows XP / SP4: Security Update for Windows XP (KB969898)
/ Windows XP / SP4: Security Update for Windows XP (KB970238)


--- Startup entries list ---
Located: HK_LM:Run, AVG8_TRAY
command: C:\PROGRA~1\AVG\AVG8\avgtray.exe
file: C:\PROGRA~1\AVG\AVG8\avgtray.exe
size: 1948440
MD5: 2588B441E5B22691E0610CF710865441

Located: HK_LM:RunOnce, Spybot - Search & Destroy
command: "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
file: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
size: 5365592
MD5: 0477C2F9171599CA5BC3307FDFBA8D89

Located: HK_LM:RunOnce, SpybotDeletingA3990
command: command.com /c del "C:\WINDOWS\system32\sopidkc.exe"
file: command.com /c del "C:\WINDOWS\system32\sopidkc.exe
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: HK_LM:RunOnce, SpybotDeletingA9706
command: command.com /c del "C:\WINDOWS\system32\comsa32.sys"
file: command.com /c del "C:\WINDOWS\system32\comsa32.sys"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: HK_LM:RunOnce, SpybotDeletingC4053
command: cmd.exe /c del "C:\WINDOWS\system32\sopidkc.exe"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C

Located: HK_LM:RunOnce, SpybotDeletingC7551
command: cmd.exe /c del "C:\WINDOWS\system32\comsa32.sys"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C

Located: HK_CU:Run, SpybotSD TeaTimer
where: S-1-5-21-484763869-436374069-725345543-1003...
command: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
file: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
size: 2260480
MD5: 390679F7A217A5E73D756276C40AE887

Located: HK_CU:RunOnce, SpybotDeletingB1418
where: S-1-5-21-484763869-436374069-725345543-1003...
command: command.com /c del "C:\WINDOWS\system32\comsa32.sys"
file: command.com /c del "C:\WINDOWS\system32\comsa32.sys"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: HK_CU:RunOnce, SpybotDeletingB3178
where: S-1-5-21-484763869-436374069-725345543-1003...
command: command.com /c del "C:\WINDOWS\system32\sopidkc.exe"
file: command.com /c del "C:\WINDOWS\system32\sopidkc.exe
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: HK_CU:RunOnce, SpybotDeletingB4893
where: S-1-5-21-484763869-436374069-725345543-1003...
command: command.com /c del "C:\WINDOWS\system32\comsa32.sys"
file: command.com /c del "C:\WINDOWS\system32\comsa32.sys"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: HK_CU:RunOnce, SpybotDeletingB7903
where: S-1-5-21-484763869-436374069-725345543-1003...
command: command.com /c del "C:\WINDOWS\system32\comsa32.sys"
file: command.com /c del "C:\WINDOWS\system32\comsa32.sys"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: HK_CU:RunOnce, SpybotDeletingB8048
where: S-1-5-21-484763869-436374069-725345543-1003...
command: command.com /c del "C:\WINDOWS\system32\sopidkc.exe"
file: command.com /c del "C:\WINDOWS\system32\sopidkc.exe
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: HK_CU:RunOnce, SpybotDeletingB9994
where: S-1-5-21-484763869-436374069-725345543-1003...
command: command.com /c del "C:\WINDOWS\system32\comsa32.sys"
file: command.com /c del "C:\WINDOWS\system32\comsa32.sys"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: HK_CU:RunOnce, SpybotDeletingD4345
where: S-1-5-21-484763869-436374069-725345543-1003...
command: cmd.exe /c del "C:\WINDOWS\system32\comsa32.sys"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C

Located: HK_CU:RunOnce, SpybotDeletingD6692
where: S-1-5-21-484763869-436374069-725345543-1003...
command: cmd.exe /c del "C:\WINDOWS\system32\sopidkc.exe"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C

Located: HK_CU:RunOnce, SpybotDeletingD7358
where: S-1-5-21-484763869-436374069-725345543-1003...
command: cmd.exe /c del "C:\WINDOWS\system32\sopidkc.exe"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C

Located: HK_CU:RunOnce, SpybotDeletingD972
where: S-1-5-21-484763869-436374069-725345543-1003...
command: cmd.exe /c del "C:\WINDOWS\system32\comsa32.sys"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C

Located: WinLogon, AtiExtEvent
command: Ati2evxx.dll
file: Ati2evxx.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, avgrsstarter
command: avgrsstx.dll
file: avgrsstx.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, crypt32chain
command: crypt32.dll
file: crypt32.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, cryptnet
command: cryptnet.dll
file: cryptnet.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, cscdll
command: cscdll.dll
file: cscdll.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, dimsntfy
command: %SystemRoot%\System32\dimsntfy.dll
file: %SystemRoot%\System32\dimsntfy.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, ScCertProp
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, Schedule
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, sclgntfy
command: sclgntfy.dll
file: sclgntfy.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, SensLogn
command: WlNotify.dll
file: WlNotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, termsrv
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, WgaLogon
command: WgaLogon.dll
file: WgaLogon.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, wlballoon
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!



--- Browser helper object list ---
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: Adobe PDF Reader Link Helper
description: Adobe Acrobat reader
classification: Legitimate
known filename: AcroIEhelper.ocx<br>AcroIEhelper.dll
info link: http://www.adobe.com/products/acrobat/readstep2.html
info source: TonyKlein
Path: C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\
Long name: AcroIEHelper.dll
Short name: ACROIE~1.DLL
Date (created): 22/10/2006 23:08:42
Date (last access): 14/07/2009 21:22:20
Date (last write): 22/10/2006 23:08:42
Filesize: 62080
Attributes: archive
MD5: C11F6A1F61481E24BE3FDC06EA6F7D2A
CRC32: E388508F
Version: 8.0.0.456

{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} (WormRadar.com IESiteBlocker.NavFilter)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name: WormRadar.com IESiteBlocker.NavFilter
CLSID name: AVG Safe Search
Path: C:\Program Files\AVG\AVG8\
Long name: avgssie.dll
Short name:
Date (created): 06/07/2009 15:20:58
Date (last access): 14/07/2009 21:17:20
Date (last write): 06/07/2009 15:20:58
Filesize: 1107224
Attributes: archive
MD5: 0E973A31F29162137959DBD4B07D38C9
CRC32: 03627923
Version: 8.5.0.310

{53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: Spybot-S&D IE Protection
description: Spybot-S&D IE Browser plugin
classification: Legitimate
known filename: SDhelper.dll
info link: http://spybot.eon.net.au/
info source: Patrick M. Kolla
Path: C:\PROGRA~1\SPYBOT~1\
Long name: SDHelper.dll
Short name:
Date (created): 01/07/2009 18:46:50
Date (last access): 14/07/2009 21:34:50
Date (last write): 26/01/2009 15:31:02
Filesize: 1879896
Attributes: archive
MD5: 022C2F6DCCDFA0AD73024D254E62AFAC
CRC32: 5BA24007
Version: 1.6.2.14

{94885D65-4728-419E-85AE-0E5DB797D50E} ()
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name:
Path: C:\WINDOWS\system32\
Long name: tuvVMdBT.dll



--- ActiveX list ---
{215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6)
DPF name:
CLSID name: Trend Micro ActiveX Scan Agent 6.6
Installer: C:\WINDOWS\Downloaded Program Files\hcImpl.inf
Codebase: http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
description:
classification: Legitimate
known filename: Housecall_ActiveX.dll
info link:
info source: Safer Networking Ltd.
Path: C:\WINDOWS\Downloaded Program Files\
Long name: Housecall_ActiveX.dll
Short name: HOUSEC~1.DLL
Date (created): 24/12/2008 15:38:24
Date (last access): 11/07/2009 11:41:36
Date (last write): 24/12/2008 15:38:24
Filesize: 386048
Attributes: archive
MD5: 0B2F27052DB8183ADE4822DFD140F9F6
CRC32: E5D10C59
Version: 6.51.0.1030

{6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class)
DPF name:
CLSID name: WUWebControl Class
Installer: C:\WINDOWS\Downloaded Program Files\wuweb.inf
Codebase: http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1246469442578
description:
classification: Legitimate
known filename: wuweb.dll
info link:
info source: Safer Networking Ltd.
Path: C:\WINDOWS\system32\
Long name: wuweb.dll
Short name:
Date (created): 23/01/2007 02:08:54
Date (last access): 14/07/2009 21:22:00
Date (last write): 16/10/2008 14:12:24
Filesize: 202776
Attributes: archive
MD5: 0006DE8037F5A562F96B461B3C557C3C
CRC32: 9B107DED
Version: 7.2.6001.788

{6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class)
DPF name:
CLSID name: MUWebControl Class
Installer: C:\WINDOWS\Downloaded Program Files\muweb.inf
Codebase: http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1246469429984
description:
classification: Legitimate
known filename: muweb.dll
info link:
info source: Safer Networking Ltd.
Path: C:\WINDOWS\system32\
Long name: muweb.dll
Short name:
Date (created): 16/10/2008 14:07:48
Date (last access): 14/07/2009 21:21:58
Date (last write): 16/10/2008 14:07:48
Filesize: 208744
Attributes: archive
MD5: 90058C2AD9FC43A3B3D59F82FFC6AEA7
CRC32: 7D5F90FA
Version: 7.2.6001.788

{8FFBE65D-2C9C-4669-84BD-5829DC0B603C} ()
DPF name:
CLSID name:
Installer: C:\WINDOWS\Downloaded Program Files\erma.inf
Codebase: http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
description:
classification: Open for discussion
known filename:
info link:
info source: Safer Networking Ltd.



--- Process list ---
PID: 0 ( 0) [System]
PID: 556 ( 4) \SystemRoot\System32\smss.exe
size: 50688
PID: 604 ( 556) \??\C:\WINDOWS\system32\csrss.exe
size: 6144
PID: 632 ( 556) \??\C:\WINDOWS\system32\winlogon.exe
size: 507904
PID: 676 ( 632) C:\WINDOWS\system32\services.exe
size: 110592
MD5: 65DF52F5B8B6E9BBD183505225C37315
PID: 688 ( 632) C:\WINDOWS\system32\lsass.exe
size: 13312
MD5: BF2466B3E18E970D8A976FB95FC1CA85
PID: 868 ( 676) C:\WINDOWS\system32\Ati2evxx.exe
size: 413696
MD5: A2EAEB497CA29ECAEAF0DF66AD85C57D
PID: 884 ( 676) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 940 ( 676) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 984 ( 676) C:\WINDOWS\System32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 1072 ( 676) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 1100 ( 676) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 1468 ( 676) C:\WINDOWS\system32\spoolsv.exe
size: 57856
MD5: D8E14A61ACC1D4A6CD0D38AEBAC7FA3B
PID: 1532 ( 676) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 1564 ( 676) C:\WINDOWS\ATKKBService.exe
size: 241664
MD5: CA517080B3808E17019E26855FDD0F5F
PID: 1584 ( 676) C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
size: 298776
MD5: BFC093C2DDDE8FCE5DA078E663B4515B
PID: 1596 ( 676) C:\WINDOWS\system32\CTsvcCDA.exe
size: 44032
MD5: 3C8B6609712F4FF78E521F6DCFC4032B
PID: 1664 ( 676) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 1788 ( 676) C:\WINDOWS\system32\wdfmgr.exe
size: 38912
MD5: AB0A7CA90D9E3D6A193905DC1715DED0
PID: 1880 ( 676) C:\PROGRA~1\AVG\AVG8\avgemc.exe
size: 906520
MD5: 5E484022DDBF9C69F0F6F3F8FD95BEF1
PID: 1912 (1584) C:\Program Files\AVG\AVG8\avgrsx.exe
size: 486680
MD5: 95E1D555542D5F6031E756751C6FF3F4
PID: 192 (1880) C:\Program Files\AVG\AVG8\avgcsrvx.exe
size: 692504
MD5: 4CAA24310158014FC9F6CC87BA50D5A6
PID: 1128 ( 676) C:\WINDOWS\System32\alg.exe
size: 44544
MD5: 8C515081584A38AA007909CD02020B3D
PID: 1336 ( 632) C:\WINDOWS\system32\Ati2evxx.exe
size: 413696
MD5: A2EAEB497CA29ECAEAF0DF66AD85C57D
PID: 1652 (1116) C:\WINDOWS\Explorer.EXE
size: 1033728
MD5: 12896823FB95BFB3DC9B46BCAEDC9923
PID: 2600 (1652) C:\PROGRA~1\AVG\AVG8\avgtray.exe
size: 1948440
MD5: 2588B441E5B22691E0610CF710865441
PID: 2804 (1652) C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
size: 2260480
MD5: 390679F7A217A5E73D756276C40AE887
PID: 3136 ( 676) C:\WINDOWS\System32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 3688 (1652) C:\Program Files\Internet Explorer\iexplore.exe
size: 636088
MD5: 092A7F2B49A19ECCE5369D3CB2276148
PID: 3744 (3688) C:\WINDOWS\system32\ctfmon.exe
size: 15360
MD5: 5F1D5F88303D4A4DBC8E5F97BA967CC3
PID: 1364 (1584) C:\PROGRA~1\AVG\AVG8\avgnsx.exe
size: 594712
MD5: 8F97675F10D4AF073FCFAB85ACEA1906
PID: 3000 (1652) C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
size: 5365592
MD5: 0477C2F9171599CA5BC3307FDFBA8D89
PID: 488 (1652) C:\Program Files\Windows NT\Accessories\wordpad.exe
size: 215552
MD5: 14F8175B68DBD65266A77E96E0ABAEF6
PID: 4 ( 0) System


--- Browser start & search pages list ---
Spybot - Search & Destroy browser pages report, 14/07/2009 21:34:50

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page
C:\WINDOWS\system32\blank.htm
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page
http://go.microsoft.com/fwlink/?LinkId=54896
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
http://www.google.co.uk/
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Local Page
%SystemRoot%\system32\blank.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Page
http://go.microsoft.com/fwlink/?LinkId=54896
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page
http://go.microsoft.com/fwlink/?LinkId=69157
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
http://go.microsoft.com/fwlink/?LinkId=69157
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
http://go.microsoft.com/fwlink/?LinkId=54896


--- Winsock Layered Service Provider list ---
Protocol 0: MSAFD Tcpip [TCP/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip

Protocol 1: MSAFD Tcpip [UDP/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip

Protocol 2: MSAFD Tcpip [RAW/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip

Protocol 3: RSVP UDP Service Provider
GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Filename: %SystemRoot%\system32\rsvpsp.dll
Description: Microsoft Windows NT/2k/XP RVSP
DB filename: %SystemRoot%\system32\rsvpsp.dll
DB protocol: RSVP * Service Provider

Protocol 4: RSVP TCP Service Provider
GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Filename: %SystemRoot%\system32\rsvpsp.dll
Description: Microsoft Windows NT/2k/XP RVSP
DB filename: %SystemRoot%\system32\rsvpsp.dll
DB protocol: RSVP * Service Provider

Protocol 5: MSAFD NetBIOS [\Device\NetBT_Tcpip_{70989FA8-EE50-426A-B50F-C8AFD6340848}] SEQPACKET 8
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 6: MSAFD NetBIOS [\Device\NetBT_Tcpip_{70989FA8-EE50-426A-B50F-C8AFD6340848}] DATAGRAM 8
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 7: MSAFD NetBIOS [\Device\NetBT_Tcpip_{0EC94607-F67D-443D-AD40-511A5A1FB9B9}] SEQPACKET 11
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 8: MSAFD NetBIOS [\Device\NetBT_Tcpip_{0EC94607-F67D-443D-AD40-511A5A1FB9B9}] DATAGRAM 11
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 9: MSAFD NetBIOS [\Device\NetBT_Tcpip_{678C9419-9882-46E5-BF17-1CF063C2ACA9}] SEQPACKET 10
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 10: MSAFD NetBIOS [\Device\NetBT_Tcpip_{678C9419-9882-46E5-BF17-1CF063C2ACA9}] DATAGRAM 10
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 11: MSAFD NetBIOS [\Device\NetBT_Tcpip_{BA2635CA-5703-4002-B4CB-1CBE9CB8D797}] SEQPACKET 9
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 12: MSAFD NetBIOS [\Device\NetBT_Tcpip_{BA2635CA-5703-4002-B4CB-1CBE9CB8D797}] DATAGRAM 9
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 13: MSAFD NetBIOS [\Device\NetBT_Tcpip_{1805B440-8E55-444A-B832-7E94D1AE18B6}] SEQPACKET 7
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 14: MSAFD NetBIOS [\Device\NetBT_Tcpip_{1805B440-8E55-444A-B832-7E94D1AE18B6}] DATAGRAM 7
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 15: MSAFD NetBIOS [\Device\NetBT_Tcpip_{93E8A318-C8EE-4482-A365-90D296468143}] SEQPACKET 6
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 16: MSAFD NetBIOS [\Device\NetBT_Tcpip_{93E8A318-C8EE-4482-A365-90D296468143}] DATAGRAM 6
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 17: MSAFD NetBIOS [\Device\NetBT_Tcpip_{9EC0B9B7-4BDC-41BF-B94A-676DB5B86666}] SEQPACKET 5
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 18: MSAFD NetBIOS [\Device\NetBT_Tcpip_{9EC0B9B7-4BDC-41BF-B94A-676DB5B86666}] DATAGRAM 5
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 19: MSAFD NetBIOS [\Device\NetBT_Tcpip_{E0C35195-AD99-4338-8AEA-0DE9C416C8E0}] SEQPACKET 4
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 20: MSAFD NetBIOS [\Device\NetBT_Tcpip_{E0C35195-AD99-4338-8AEA-0DE9C416C8E0}] DATAGRAM 4
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 21: MSAFD NetBIOS [\Device\NetBT_Tcpip_{ECF841E8-5D80-4C69-8432-7825BA378F45}] SEQPACKET 3
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 22: MSAFD NetBIOS [\Device\NetBT_Tcpip_{ECF841E8-5D80-4C69-8432-7825BA378F45}] DATAGRAM 3
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 23: MSAFD NetBIOS [\Device\NetBT_Tcpip_{0AB66E4B-CA54-4BC0-A5C5-6291CFE41075}] SEQPACKET 0
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 24: MSAFD NetBIOS [\Device\NetBT_Tcpip_{0AB66E4B-CA54-4BC0-A5C5-6291CFE41075}] DATAGRAM 0
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 25: MSAFD NetBIOS [\Device\NetBT_Tcpip_{0F1A4715-69D5-4C13-9F3C-D7995A905D95}] SEQPACKET 1
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 26: MSAFD NetBIOS [\Device\NetBT_Tcpip_{0F1A4715-69D5-4C13-9F3C-D7995A905D95}] DATAGRAM 1
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 27: MSAFD NetBIOS [\Device\NetBT_Tcpip_{237FA01E-EF9F-4F0E-9F64-3662018C9E95}] SEQPACKET 2
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 28: MSAFD NetBIOS [\Device\NetBT_Tcpip_{237FA01E-EF9F-4F0E-9F64-3662018C9E95}] DATAGRAM 2
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Namespace Provider 0: Tcpip
GUID: {22059D40-7E9E-11CF-AE5A-00AA00A7112B}
Filename: %SystemRoot%\System32\mswsock.dll
Description: Microsoft Windows NT/2k/XP TCP/IP name space provider
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: TCP/IP

Namespace Provider 1: NTDS
GUID: {3B2637EE-E580-11CF-A555-00C04FD8D4AC}
Filename: %SystemRoot%\System32\winrnr.dll
Description: Microsoft Windows NT/2k/XP name space provider
DB filename: %SystemRoot%\system32\winrnr.dll
DB protocol: NTDS

Namespace Provider 2: Network Location Awareness (NLA) Namespace
GUID: {6642243A-3BA8-4AA6-BAA5-2E0BD71FDD83}
Filename: %SystemRoot%\System32\mswsock.dll
Description: Microsoft Windows NT/2k/XP name space provider
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: NLA-Namespace

thanks again :bigthumb:

Shaba
2009-07-15, 07:06
Download random's system information tool (RSIT) by random/random from here (http://images.malwareremoval.com/random/RSIT.exe) and save it to your desktop.
Double click on RSIT.exe to run RSIT.
Click Continue at the disclaimer screen.
Once it has finished, two logs will open. Please post the contents of both log.txt (<< will be maximized) and info.txt (<< will be minimized)

Freeloader
2009-07-15, 13:22
all done as follows

log file

Logfile of random's system information tool 1.06 (written by random/random)
Run by Andy at 2009-07-15 11:17:49
Microsoft Windows XP Professional Service Pack 3
System drive C: has 201 GB (84%) free of 238 GB
Total RAM: 3071 MB (80% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:18:09, on 15/07/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16850)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ATKKBService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Andy\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Andy.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.virtuagirl.com/us/freegirls.php3
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {94885D65-4728-419E-85AE-0E5DB797D50E} - C:\WINDOWS\system32\tuvVMdBT.dll (file missing)
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [SpybotDeletingA9706] command.com /c del "C:\WINDOWS\system32\comsa32.sys"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7551] cmd.exe /c del "C:\WINDOWS\system32\comsa32.sys"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3990] command.com /c del "C:\WINDOWS\system32\sopidkc.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4053] cmd.exe /c del "C:\WINDOWS\system32\sopidkc.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingB4893] command.com /c del "C:\WINDOWS\system32\comsa32.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingD972] cmd.exe /c del "C:\WINDOWS\system32\comsa32.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8048] command.com /c del "C:\WINDOWS\system32\sopidkc.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7358] cmd.exe /c del "C:\WINDOWS\system32\sopidkc.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9994] command.com /c del "C:\WINDOWS\system32\comsa32.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1418] command.com /c del "C:\WINDOWS\system32\comsa32.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4345] cmd.exe /c del "C:\WINDOWS\system32\comsa32.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3178] command.com /c del "C:\WINDOWS\system32\sopidkc.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6692] cmd.exe /c del "C:\WINDOWS\system32\sopidkc.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7903] command.com /c del "C:\WINDOWS\system32\comsa32.sys"
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1246469442578
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1246469429984
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: C:\DOCUME~1\Andy\LOCALS~1\Temp\4249062155mxx.dll C:\WINDOWS\system32\ c:\windows\system32\ c:\windows\system32\
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

--
End of file - 6526 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG8\avgssie.dll [2009-07-06 1107224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2009-01-26 1879896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{94885D65-4728-419E-85AE-0E5DB797D50E}]
C:\WINDOWS\system32\tuvVMdBT.dll []

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe [2009-07-06 1948440]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Spybot - Search & Destroy"=C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe [2009-01-26 5365592]
"SpybotDeletingA9706"=command.com /c del C:\WINDOWS\system32\comsa32.sys []
"SpybotDeletingC7551"=cmd.exe /c del C:\WINDOWS\system32\comsa32.sys []
"SpybotDeletingA3990"=command.com /c del C:\WINDOWS\system32\sopidkc.exe []
"SpybotDeletingC4053"=cmd.exe /c del C:\WINDOWS\system32\sopidkc.exe []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-03-05 2260480]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SpybotDeletingB4893"=command.com /c del C:\WINDOWS\system32\comsa32.sys []
"SpybotDeletingD972"=cmd.exe /c del C:\WINDOWS\system32\comsa32.sys []
"SpybotDeletingB8048"=command.com /c del C:\WINDOWS\system32\sopidkc.exe []
"SpybotDeletingD7358"=cmd.exe /c del C:\WINDOWS\system32\sopidkc.exe []
"SpybotDeletingB9994"=command.com /c del C:\WINDOWS\system32\comsa32.sys []
"SpybotDeletingB1418"=command.com /c del C:\WINDOWS\system32\comsa32.sys []
"SpybotDeletingD4345"=cmd.exe /c del C:\WINDOWS\system32\comsa32.sys []
"SpybotDeletingB3178"=command.com /c del C:\WINDOWS\system32\sopidkc.exe []
"SpybotDeletingD6692"=cmd.exe /c del C:\WINDOWS\system32\sopidkc.exe []
"SpybotDeletingB7903"=command.com /c del C:\WINDOWS\system32\comsa32.sys []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-10-15 39792]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcWzrd]
C:\WINDOWS\ALCWZRD.EXE [2005-09-21 2807808]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS SmartDoctor]
C:\Program Files\ASUS\SmartDoctor\SmartDoctor.exe [2006-05-18 1081344]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe [2006-01-02 45056]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CPMdf54a6dc]
C:\WINDOWS\system32\sumopuwu.dll,a []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSysVol]
C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe [2005-10-31 57344]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dc679540]
C:\WINDOWS\system32\yedonuse.dll,b []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GameFace Messenger]
C:\Program Files\GameFace Messenger\GameFace.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
C:\Program Files\CyberLink\PowerDVD\Language\Language.exe [2006-05-18 49152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\P17Helper]
Rundll32 P17.dll,P17Helper []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2005-12-07 30208]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
C:\WINDOWS\RTHDCPL.EXE [2005-09-22 14854144]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
C:\WINDOWS\SOUNDMAN.EXE [2005-09-21 86016]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
C:\WINDOWS\UpdReg.EXE [2000-05-11 90112]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vurawalake]
C:\WINDOWS\system32\zetoyago.dll,s []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"sopidkc"=2
"RichVideo"=2

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\DOCUME~1\Andy\LOCALS~1\Temp\4249062155mxx.dll C:\WINDOWS\system32\ c:\windows\system32\ c:\windows\system32\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2006-05-03 61440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgrsstarter]
C:\WINDOWS\system32\avgrsstx.dll [2009-07-06 11952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 239496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
C:\WINDOWS\system32\tuvVMdBT
"notification packages"=scecli
C:\WINDOWS\system32\yemopego.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=Warning
"legalnoticetext"=This Machine is protected by Hand Grenades
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\Program Files\THQ\Dawn of War - Dark Crusade\DarkCrusade.exe"="C:\Program Files\THQ\Dawn of War - Dark Crusade\DarkCrusade.exe:*:Disabled:DarkCrusade"
"C:\Program Files\Internet Explorer\IEXPLORE.EXE"="C:\Program Files\Internet Explorer\IEXPLORE.EXE:*:Enabled:Internet Explorer"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\THQ\Dawn of War - Soulstorm\Soulstorm.exe"="C:\Program Files\THQ\Dawn of War - Soulstorm\Soulstorm.exe:*:Enabled:Soulstorm"
"C:\Documents and Settings\Andy\My Documents\Halo\halo.exe"="C:\Documents and Settings\Andy\My Documents\Halo\halo.exe:*:Enabled:Halo"
"C:\Program Files\AVG\AVG8\avgemc.exe"="C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe"
"C:\Program Files\AVG\AVG8\avgupd.exe"="C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe"
"C:\Program Files\AVG\AVG8\avgnsx.exe"="C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2009-07-15 11:17:49 ----D---- C:\rsit
2009-07-14 22:05:53 ----HDC---- C:\WINDOWS\$NtUninstallKB973346$
2009-07-14 22:05:49 ----HDC---- C:\WINDOWS\$NtUninstallKB971633$
2009-07-14 22:04:47 ----HDC---- C:\WINDOWS\$NtUninstallKB961371$
2009-07-09 00:28:39 ----D---- C:\VideoSec
2009-07-08 01:38:14 ----A---- C:\WINDOWS\irc.txt
2009-07-08 01:18:25 ----D---- C:\Program Files\Trend Micro
2009-07-08 01:11:33 ----D---- C:\Documents and Settings\Andy\Application Data\Malwarebytes
2009-07-08 01:11:28 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-07-08 01:11:28 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-07-06 15:23:46 ----HD---- C:\$AVG8.VAULT$
2009-07-06 15:21:15 ----A---- C:\WINDOWS\system32\avgrsstx.dll
2009-07-06 15:20:51 ----D---- C:\Program Files\AVG
2009-07-06 15:20:50 ----D---- C:\Documents and Settings\All Users\Application Data\avg8
2009-07-06 14:01:52 ----D---- C:\WINDOWS\ie7updates
2009-07-06 14:01:02 ----D---- C:\WINDOWS\WBEM
2009-07-06 14:00:11 ----HDC---- C:\WINDOWS\ie7
2009-07-06 14:00:00 ----HDC---- C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$
2009-07-06 13:59:35 ----HDC---- C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$
2009-07-06 11:01:23 ----D---- C:\WINDOWS\system32\Lang
2009-07-05 13:44:46 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2009-07-05 13:44:41 ----HDC---- C:\WINDOWS\$NtUninstallKB954459$
2009-07-05 12:56:05 ----D---- C:\Program Files\Adobe
2009-07-05 12:36:50 ----D---- C:\WINDOWS\system32\RTCOM
2009-07-05 12:32:07 ----A---- C:\WINDOWS\system32\mucltui.dll.mui
2009-07-05 12:32:07 ----A---- C:\WINDOWS\system32\mucltui.dll
2009-07-05 12:30:56 ----D---- C:\WINDOWS\Prefetch
2009-07-05 00:45:36 ----A---- C:\WINDOWS\system32\MRT.exe
2009-07-05 00:02:19 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2009-07-05 00:02:14 ----HDC---- C:\WINDOWS\$NtUninstallKB954600$
2009-07-05 00:02:10 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2009-07-05 00:02:06 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2009-07-05 00:02:01 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2009-07-05 00:01:56 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2009-07-05 00:01:52 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
2009-07-05 00:01:48 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2009-07-05 00:01:44 ----HDC---- C:\WINDOWS\$NtUninstallKB951376$
2009-07-05 00:01:39 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2009-07-05 00:01:35 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2009-07-05 00:01:31 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2009-07-05 00:01:25 ----HDC---- C:\WINDOWS\$NtUninstallKB950759$
2009-07-05 00:01:21 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2009-07-05 00:01:18 ----HDC---- C:\WINDOWS\$NtUninstallKB938464-v2$
2009-07-05 00:01:13 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2009-07-04 23:58:51 ----D---- C:\WINDOWS\system32\scripting
2009-07-04 23:58:51 ----D---- C:\WINDOWS\system32\en-us
2009-07-04 23:58:51 ----D---- C:\WINDOWS\l2schemas
2009-07-04 23:58:50 ----D---- C:\WINDOWS\system32\en
2009-07-04 23:58:50 ----D---- C:\WINDOWS\system32\bits
2009-07-04 23:57:10 ----D---- C:\WINDOWS\ServicePackFiles
2009-07-04 23:55:26 ----D---- C:\WINDOWS\network diagnostic
2009-07-04 23:52:48 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2009-07-04 18:21:05 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2009-07-03 10:35:47 ----HDC---- C:\WINDOWS\$NtUninstallKB952954_0$
2009-07-03 10:35:42 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2009-07-03 10:35:37 ----HDC---- C:\WINDOWS\$NtUninstallKB946648_0$
2009-07-03 10:35:32 ----HDC---- C:\WINDOWS\$NtUninstallKB961373$
2009-07-03 10:35:28 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2009-07-03 10:35:24 ----HDC---- C:\WINDOWS\$NtUninstallKB955839_0$
2009-07-03 10:35:10 ----HDC---- C:\WINDOWS\$NtUninstallKB950974_0$
2009-07-03 10:35:05 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2009-07-03 10:34:53 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2009-07-03 10:34:46 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2009-07-03 10:34:34 ----HDC---- C:\WINDOWS\$NtUninstallKB969897$
2009-07-03 10:34:29 ----HDC---- C:\WINDOWS\$NtUninstallKB938464-v2_0$
2009-07-03 10:34:25 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$
2009-07-03 10:34:20 ----HDC---- C:\WINDOWS\$NtUninstallKB952004_0$
2009-07-03 10:34:16 ----HDC---- C:\WINDOWS\$NtUninstallKB969898$
2009-07-03 10:34:12 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
2009-07-03 10:34:07 ----HDC---- C:\WINDOWS\$NtUninstallKB958687$
2009-07-03 10:34:03 ----HDC---- C:\WINDOWS\$NtUninstallKB952287_0$
2009-07-03 10:33:55 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2009-07-03 10:33:50 ----HDC---- C:\WINDOWS\$NtUninstallKB951066_0$
2009-07-03 10:33:44 ----HDC---- C:\WINDOWS\$NtUninstallKB951748_0$
2009-07-03 10:33:39 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
2009-07-03 10:33:34 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2009-07-03 10:33:30 ----HDC---- C:\WINDOWS\$NtUninstallKB968537$
2009-07-03 10:33:25 ----HDC---- C:\WINDOWS\$NtUninstallKB954600_0$
2009-07-03 10:33:15 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2009-07-03 10:32:56 ----HDC---- C:\WINDOWS\$NtUninstallKB955069_0$
2009-07-03 10:32:50 ----N---- C:\WINDOWS\system32\xmllite.dll
2009-07-03 10:32:50 ----N---- C:\WINDOWS\system32\wmphoto.dll
2009-07-03 10:32:49 ----N---- C:\WINDOWS\system32\wlanapi.dll
2009-07-03 10:32:48 ----N---- C:\WINDOWS\system32\windowscodecsext.dll
2009-07-03 10:32:48 ----N---- C:\WINDOWS\system32\windowscodecs.dll
2009-07-03 10:32:46 ----N---- C:\WINDOWS\system32\tspkg.dll
2009-07-03 10:32:46 ----N---- C:\WINDOWS\system32\tsgqec.dll
2009-07-03 10:32:44 ----N---- C:\WINDOWS\system32\spupdwxp.exe
2009-07-03 10:32:43 ----N---- C:\WINDOWS\system32\slserv.exe
2009-07-03 10:32:43 ----N---- C:\WINDOWS\system32\slrundll.exe
2009-07-03 10:32:43 ----N---- C:\WINDOWS\slrundll.exe
2009-07-03 10:32:43 ----A---- C:\WINDOWS\system32\spdwnwxp.exe
2009-07-03 10:32:42 ----N---- C:\WINDOWS\system32\slgen.dll
2009-07-03 10:32:42 ----N---- C:\WINDOWS\system32\slextspk.dll
2009-07-03 10:32:42 ----N---- C:\WINDOWS\system32\slcoinst.dll
2009-07-03 10:32:41 ----N---- C:\WINDOWS\system32\setupn.exe
2009-07-03 10:32:41 ----N---- C:\WINDOWS\system32\s3gnb.dll
2009-07-03 10:32:40 ----N---- C:\WINDOWS\system32\rhttpaa.dll
2009-07-03 10:32:39 ----N---- C:\WINDOWS\system32\rasqec.dll
2009-07-03 10:32:39 ----N---- C:\WINDOWS\system32\qutil.dll
2009-07-03 10:32:39 ----N---- C:\WINDOWS\system32\qcliprov.dll
2009-07-03 10:32:39 ----N---- C:\WINDOWS\system32\qagentrt.dll
2009-07-03 10:32:39 ----N---- C:\WINDOWS\system32\qagent.dll
2009-07-03 10:32:38 ----N---- C:\WINDOWS\system32\photometadatahandler.dll
2009-07-03 10:32:38 ----N---- C:\WINDOWS\system32\onex.dll
2009-07-03 10:32:37 ----N---- C:\WINDOWS\system32\nv4_disp.dll
2009-07-03 10:32:34 ----N---- C:\WINDOWS\system32\napstat.exe
2009-07-03 10:32:34 ----N---- C:\WINDOWS\system32\napmontr.dll
2009-07-03 10:32:34 ----N---- C:\WINDOWS\system32\napipsec.dll
2009-07-03 10:32:34 ----N---- C:\WINDOWS\system32\mtxparhd.dll
2009-07-03 10:32:34 ----N---- C:\WINDOWS\system32\msxml6r.dll
2009-07-03 10:32:34 ----N---- C:\WINDOWS\system32\msxml6.dll
2009-07-03 10:32:33 ----N---- C:\WINDOWS\system32\msshavmsg.dll
2009-07-03 10:32:33 ----N---- C:\WINDOWS\system32\mssha.dll
2009-07-03 10:32:28 ----N---- C:\WINDOWS\system32\mmcperf.exe
2009-07-03 10:32:28 ----N---- C:\WINDOWS\system32\mmcfxcommon.dll
2009-07-03 10:32:28 ----N---- C:\WINDOWS\system32\mmcex.dll
2009-07-03 10:32:28 ----N---- C:\WINDOWS\system32\microsoft.managementconsole.dll
2009-07-03 10:32:27 ----N---- C:\WINDOWS\system32\mdmxsdk.dll
2009-07-03 10:32:23 ----N---- C:\WINDOWS\system32\l2gpstore.dll
2009-07-03 10:32:23 ----N---- C:\WINDOWS\system32\kmsvc.dll
2009-07-03 10:32:23 ----N---- C:\WINDOWS\system32\kbdpash.dll
2009-07-03 10:32:23 ----N---- C:\WINDOWS\system32\kbdnepr.dll
2009-07-03 10:32:23 ----N---- C:\WINDOWS\system32\kbdiultn.dll
2009-07-03 10:32:23 ----N---- C:\WINDOWS\system32\kbdbhc.dll
2009-07-03 10:32:19 ----N---- C:\WINDOWS\system32\smtpapi.dll
2009-07-03 10:32:19 ----N---- C:\WINDOWS\system32\rwnh.dll
2009-07-03 10:32:17 ----N---- C:\WINDOWS\system32\comsdupd.exe
2009-07-03 10:32:16 ----N---- C:\WINDOWS\system32\hsfcisp2.dll
2009-07-03 10:32:14 ----N---- C:\WINDOWS\system32\faxpatch.exe
2009-07-03 10:32:14 ----N---- C:\WINDOWS\system32\eapsvc.dll
2009-07-03 10:32:14 ----N---- C:\WINDOWS\system32\eapqec.dll
2009-07-03 10:32:14 ----N---- C:\WINDOWS\system32\eappprxy.dll
2009-07-03 10:32:14 ----N---- C:\WINDOWS\system32\eapphost.dll
2009-07-03 10:32:14 ----N---- C:\WINDOWS\system32\eappgnui.dll
2009-07-03 10:32:14 ----N---- C:\WINDOWS\system32\eappcfg.dll
2009-07-03 10:32:14 ----N---- C:\WINDOWS\system32\eapp3hst.dll
2009-07-03 10:32:14 ----N---- C:\WINDOWS\system32\eapolqec.dll
2009-07-03 10:32:14 ----A---- C:\WINDOWS\003031_.tmp
2009-07-03 10:32:13 ----N---- C:\WINDOWS\system32\dot3ui.dll
2009-07-03 10:32:13 ----N---- C:\WINDOWS\system32\dot3svc.dll
2009-07-03 10:32:13 ----N---- C:\WINDOWS\system32\dot3msm.dll
2009-07-03 10:32:13 ----N---- C:\WINDOWS\system32\dot3gpclnt.dll
2009-07-03 10:32:13 ----N---- C:\WINDOWS\system32\dot3dlg.dll
2009-07-03 10:32:13 ----N---- C:\WINDOWS\system32\dot3cfg.dll
2009-07-03 10:32:13 ----N---- C:\WINDOWS\system32\dot3api.dll
2009-07-03 10:32:13 ----N---- C:\WINDOWS\system32\dimsroam.dll
2009-07-03 10:32:13 ----N---- C:\WINDOWS\system32\dimsntfy.dll
2009-07-03 10:32:12 ----N---- C:\WINDOWS\system32\dhcpqec.dll
2009-07-03 10:32:12 ----N---- C:\WINDOWS\system32\credssp.dll
2009-07-03 10:32:08 ----N---- C:\WINDOWS\system32\bitsprx4.dll
2009-07-03 10:32:08 ----N---- C:\WINDOWS\system32\azroles.dll
2009-07-03 10:32:08 ----N---- C:\WINDOWS\system32\ativtmxx.dll
2009-07-03 10:32:07 ----N---- C:\WINDOWS\system32\ati3d1ag.dll
2009-07-03 10:32:07 ----N---- C:\WINDOWS\system32\ati2dvaa.dll
2009-07-03 10:32:06 ----N---- C:\WINDOWS\system32\aaclient.dll
2009-07-03 10:31:55 ----HDC---- C:\WINDOWS\$NtUninstallKB923561_0$
2009-07-03 10:08:40 ----N---- C:\WINDOWS\system32\xpsp4res.dll
2009-07-02 11:19:15 ----D---- C:\WINDOWS\Minidump
2009-07-01 19:13:06 ----A---- C:\WINDOWS\wininit.ini
2009-07-01 18:31:23 ----A---- C:\WINDOWS\system32\wuapi.dll.mui
2009-07-01 17:12:38 ----A---- C:\WINDOWS\system32\d744513e-.txt
2009-07-01 16:02:33 ----D---- C:\spoolerlogs

======List of files/folders modified in the last 1 months======

2009-07-15 11:15:25 ----D---- C:\WINDOWS\Temp
2009-07-15 11:14:47 ----D---- C:\WINDOWS
2009-07-14 22:06:00 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-07-14 22:05:55 ----HD---- C:\WINDOWS\inf
2009-07-14 22:05:54 ----D---- C:\WINDOWS\system32
2009-07-14 22:05:52 ----HD---- C:\WINDOWS\$hf_mig$
2009-07-14 22:05:51 ----A---- C:\WINDOWS\imsins.BAK
2009-07-14 22:05:50 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-07-14 21:18:46 ----D---- C:\WINDOWS\system32\CatRoot2
2009-07-11 10:21:30 ----D---- C:\WINDOWS\system32\drivers
2009-07-10 10:44:07 ----RD---- C:\Program Files
2009-07-07 09:47:36 ----RSH---- C:\boot.ini
2009-07-07 09:47:36 ----A---- C:\WINDOWS\win.ini
2009-07-07 09:47:36 ----A---- C:\WINDOWS\system.ini
2009-07-06 17:27:58 ----D---- C:\WINDOWS\system32\CatRoot
2009-07-06 17:08:55 ----A---- C:\WINDOWS\system32\CmdLineExt.dll
2009-07-06 16:14:16 ----SD---- C:\WINDOWS\Tasks
2009-07-06 15:20:47 ----SHD---- C:\WINDOWS\Installer
2009-07-06 15:20:41 ----HD---- C:\Config.Msi
2009-07-06 15:19:39 ----SD---- C:\Documents and Settings\Andy\Application Data\Microsoft
2009-07-06 14:05:39 ----D---- C:\WINDOWS\Help
2009-07-06 14:05:39 ----D---- C:\Program Files\Internet Explorer
2009-07-06 14:00:57 ----D---- C:\WINDOWS\Media
2009-07-05 12:56:15 ----D---- C:\Program Files\Common Files\Adobe
2009-07-05 12:56:14 ----D---- C:\WINDOWS\WinSxS
2009-07-05 12:56:12 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2009-07-05 12:34:46 ----A---- C:\WINDOWS\OEWABLog.txt
2009-07-05 12:32:21 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-07-05 12:31:05 ----A---- C:\WINDOWS\setuplog.txt
2009-07-05 12:30:26 ----D---- C:\WINDOWS\system32\Setup
2009-07-05 12:30:26 ----D---- C:\WINDOWS\AppPatch
2009-07-05 12:30:25 ----D---- C:\WINDOWS\system32\wbem
2009-07-05 12:30:24 ----RSD---- C:\WINDOWS\Fonts
2009-07-05 00:47:01 ----D---- C:\WINDOWS\security
2009-07-05 00:01:23 ----D---- C:\Program Files\Messenger
2009-07-04 23:58:59 ----D---- C:\WINDOWS\system32\inetsrv
2009-07-04 23:58:59 ----D---- C:\WINDOWS\ime
2009-07-04 23:58:51 ----D---- C:\WINDOWS\system32\usmt
2009-07-04 23:58:50 ----D---- C:\WINDOWS\PeerNet
2009-07-04 23:58:50 ----D---- C:\Program Files\Movie Maker
2009-07-04 23:57:01 ----D---- C:\WINDOWS\system32\Restore
2009-07-04 23:57:01 ----D---- C:\WINDOWS\system32\npp
2009-07-04 23:57:01 ----D---- C:\WINDOWS\mui
2009-07-04 23:57:00 ----D---- C:\WINDOWS\msagent
2009-07-04 23:56:59 ----D---- C:\WINDOWS\srchasst
2009-07-04 23:56:59 ----D---- C:\Program Files\NetMeeting
2009-07-04 23:56:58 ----D---- C:\WINDOWS\system32\Com
2009-07-04 23:56:56 ----D---- C:\Program Files\Windows NT
2009-07-04 23:56:56 ----D---- C:\Program Files\Windows Media Player
2009-07-04 23:56:56 ----D---- C:\Program Files\Outlook Express
2009-07-04 23:56:53 ----D---- C:\Program Files\Common Files\System
2009-07-04 23:56:39 ----D---- C:\WINDOWS\system32\oobe
2009-07-04 23:56:37 ----D---- C:\WINDOWS\system
2009-07-04 23:52:47 ----D---- C:\WINDOWS\ehome
2009-07-04 20:08:50 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-07-03 10:14:18 ----D---- C:\WINDOWS\Debug
2009-07-01 18:48:03 ----D---- C:\Program Files\Spybot - Search & Destroy
2009-07-01 18:47:59 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2009-07-01 18:30:36 ----D---- C:\WINDOWS\SoftwareDistribution
2009-07-01 16:11:01 ----D---- C:\Documents and Settings\Andy\Application Data\Hamachi
2009-07-01 16:10:27 ----D---- C:\temp
2009-06-16 15:36:30 ----A---- C:\WINDOWS\system32\t2embed.dll
2009-06-16 15:36:30 ----A---- C:\WINDOWS\system32\fontsub.dll

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AmdK8;AMD Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2005-03-09 36352]
R1 AsIO;AsIO; C:\WINDOWS\system32\drivers\AsIO.sys [2005-12-22 5685]
R1 asuskbnt;Enhanced Display Driver Helper Service; C:\WINDOWS\system32\drivers\atkkbnt.sys [2005-10-18 11008]
R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2009-07-06 327688]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2009-07-06 27784]
R1 AvgTdiX;AVG Free8 Network Redirector; C:\WINDOWS\System32\Drivers\avgtdix.sys [2009-07-06 108552]
R2 EIO;EIO; \??\C:\WINDOWS\system32\drivers\EIO.sys []
R2 tmcomm;tmcomm; \??\C:\WINDOWS\system32\drivers\tmcomm.sys []
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2006-05-03 1540608]
R3 ctsfm2k;Creative SoundFont Management Device Driver; C:\WINDOWS\system32\DRIVERS\ctsfm2k.sys [2005-01-10 138752]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2004-06-22 51088]
R3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2004-06-22 16496]
R3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2004-06-22 21744]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 ossrv;Creative OS Services Driver; C:\WINDOWS\system32\DRIVERS\ctoss2k.sys [2005-01-10 106496]
R3 P17;Sound Blaster Audigy; C:\WINDOWS\system32\drivers\P17.sys [2005-07-07 1389056]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 ZY202_XP;ZyXEL 802.11g XG202 1211 Driver; C:\WINDOWS\system32\DRIVERS\WlanUZXP.sys [2006-06-20 437760]
S3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Adapter; C:\WINDOWS\system32\DRIVERS\atl01_xp.sys [2006-05-12 31104]
S3 BRGSp50;BRGSp50 NDIS Protocol Driver; C:\WINDOWS\System32\Drivers\BRGSp50.sys [2006-06-20 20608]
S3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2007-08-26 15440]
S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2005-09-23 3966976]
S3 tunmp;Microsoft Tun Miniport Adapter Driver; C:\WINDOWS\system32\DRIVERS\tunmp.sys [2008-04-13 12288]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 Video3D;ASUS Video3D Service; C:\WINDOWS\System32\Drivers\Video3D32.sys []
S3 ZDPSp50;ZDPSp50 NDIS Protocol Driver; C:\WINDOWS\System32\Drivers\ZDPSp50.sys [2006-06-20 17664]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2006-05-03 413696]
R2 ATKKeyboardService;ATK Keyboard Service; C:\WINDOWS\ATKKBService.exe [2006-04-10 241664]
R2 avg8emc;AVG Free8 E-mail Scanner; C:\PROGRA~1\AVG\AVG8\avgemc.exe [2009-07-06 906520]
R2 avg8wd;AVG Free8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2009-07-06 298776]
R2 Creative Service for CDROM Access;Creative Service for CDROM Access; C:\WINDOWS\system32\CTsvcCDA.exe [1999-12-13 44032]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S4 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared files\RichVideo.exe [2005-08-08 167936]

-----------------EOF-----------------
info log

info.txt logfile of random's system information tool 1.06 2009-07-15 11:18:11

======Uninstall list======

-->"C:\Program Files\Creative Installation Information\CREATIVE_MEDIASOURCE_U\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\CTCMSGO\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\E-CENTER_NET_CONTENT_U\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_CDBURNER_U\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_MINIDISC_U\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_ONLINESTORE_U\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\MEDIASOURCE_PLAYER_SKINPACK_U\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative\SBAudigy\Program\Setup.exe" /S /U /W
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2670895A-4E6C-4450-B868-7B7DB80A3357}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2670895A-4E6C-4450-B868-7B7DB80A3357}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{32B4B536-4443-42F0-9676-98373BE9114F}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{32B4B536-4443-42F0-9676-98373BE9114F}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{34EBD418-B8E6-4E86-89C4-33B72CF5663F}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{34EBD418-B8E6-4E86-89C4-33B72CF5663F}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{52338F65-A1C3-4CDC-B733-50051682B297}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{52338F65-A1C3-4CDC-B733-50051682B297}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{700932B3-A964-4878-82A2-96054622A1F7}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{700932B3-A964-4878-82A2-96054622A1F7}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{73919E2B-725C-4FAA-8473-45E063A3575F}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{73919E2B-725C-4FAA-8473-45E063A3575F}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{84F573D3-0F71-4768-978A-D35310E3FBA6}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{84F573D3-0F71-4768-978A-D35310E3FBA6}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{88B1984E-36F0-47B8-B8DC-728966807A9C}\SETUP.EXE" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9194237B-7B58-40B4-A739-184AD59531A2}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9194237B-7B58-40B4-A739-184AD59531A2}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A82F10CB-18B5-4EAC-AEF2-FA49CD565626}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BD6928A2-9F8F-4AA7-9A3A-FD4A271712EE}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BD6928A2-9F8F-4AA7-9A3A-FD4A271712EE}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C64409FA-42A7-49C6-837A-D2E5D813BD57}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C64409FA-42A7-49C6-837A-D2E5D813BD57}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DE4A4C48-2232-4CCB-AD61-490ACD29BA85}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DE4A4C48-2232-4CCB-AD61-490ACD29BA85}\setup.exe" -l0x9 /remove
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 8.1.3-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81300000003}
ASUS Enhanced Display Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{315ACD04-BCEB-478B-9B1D-5431D0E6CB11}\setup.exe" -l0x9 -removeonly
ASUS GameLiveShow-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{04726714-8286-43B8-AFD6-2DF92EC49995}
ASUS SmartDoctor-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{12E11FBB-7CA6-4A86-834D-5E6390D51009} /l1033
ASUS Utilities-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{43C67D92-F56E-4729-8673-9A2D5A6036F8} /l1033
ASUS VideoSecurity Online-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{7A529246-912F-4C40-A82A-E608DB702FD7}
Athlon 64 Processor Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C151CE54-E7EA-4804-854B-F515368B0798}\setup.exe" -l0x9
ATI - Software Uninstall Utility-->C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
ATI Catalyst Control Center-->MsiExec.exe /I{31A5C940-3B58-439B-B539-C2B24FE65DB1}
ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
ATI Parental Control & Encoder-->MsiExec.exe /I{8D70145A-3BD3-4DBF-9CBF-223EF4A43257}
Attansic Ethernet Utility-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0700\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1F698102-5739-441E-96F0-74F4EA540F06}\setup.exe" -l0x9
Attansic L1 Gigabit Ethernet Driver-->rundll32.exe C:\WINDOWS\system32\Attansic\L1\atcInst.dll,AtcUninst C:\WINDOWS\system32\Attansic\L1 x86 1969 1048 L1
AVG Free 8.5-->C:\Program Files\AVG\AVG8\setup.exe /UNINSTALL
Black and White-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E51B4CD9-A0A6-4324-B26A-31B3F2DE26CE}\Setup.exe"
Command & Conquer Generals-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{06F80017-8F98-4C94-B868-52358569FC32}
Company of Heroes-->MsiExec.exe /X{66F78C51-D108-4F0C-A93C-1CBE74CE338F}
Cool & Quiet-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1ADE1AA0-7F82-4BB1-B1BD-727DE438057B}\setup.exe" -l0x9
Creative MediaSource 5-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}\SETUP.EXE" -l0x9 /remove
Creative Software AutoUpdate-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{88B1984E-36F0-47B8-B8DC-728966807A9C}\SETUP.EXE" -l0x9 /remove
Dawn of War - Dark Crusade-->C:\Program Files\InstallShield Installation Information\{FF39FC01-819B-42E4-AE49-1968AF12DDD4}\setup.exe -runfromtemp -l0x0009 -removeonly
Dawn of War - Soulstorm-->"C:\Program Files\InstallShield Installation Information\{20533183-D42D-4261-A125-956736FBEA8C}\setup.exe" -runfromtemp -l0x0009 -removeonly
Google Earth-->MsiExec.exe /I{97C0EA4A-1A0B-4C53-ACEB-49984DA79C90}
HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
HP Image Zone 4.2-->C:\Program Files\HP\Digital Imaging\uninstall\hpzscr01.exe -datfile hpqscr01.dat
HP PSC & OfficeJet 4.2-->"C:\Program Files\HP\Digital Imaging\{A1062847-0846-427A-92A1-BB8251A91E91}\setup\hpzscr01.exe" -datfile hposcr04.dat
Imperial Glory-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1FCC8C70-66B9-420D-942C-2C2A8441C744}\Setup.exe" -l0x9 -removeonly
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft Age of Empires Gold-->"C:\Program Files\Microsoft Games\Age of Empires\UNINSTAL.EXE" /runtemp
Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
PC Probe II-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F7338FA3-DAB5-49B2-900D-0AFB5760C166}\setup.exe" -l0x9
PowerDVD-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\Setup.exe" -uninstall
Realtek High Definition Audio Driver-->RtlUpd.exe -r
Rome - Total War(TM)-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{A642BB6B-CA1D-4142-8DD4-318C3F3DC834} /l2057
Security Update for Windows Internet Explorer 7 (KB938127-v2)-->"C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB969897)-->"C:\WINDOWS\ie7updates\KB969897-IE7\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player 10 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP10$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
Security Update for Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950759)-->"C:\WINDOWS\$NtUninstallKB950759$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Security Update for Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
Security Update for Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB961371)-->"C:\WINDOWS\$NtUninstallKB961371$\spuninst\spuninst.exe"
Security Update for Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
Security Update for Windows XP (KB961501)-->"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
Security Update for Windows XP (KB968537)-->"C:\WINDOWS\$NtUninstallKB968537$\spuninst\spuninst.exe"
Security Update for Windows XP (KB969897)-->"C:\WINDOWS\$NtUninstallKB969897$\spuninst\spuninst.exe"
Security Update for Windows XP (KB969898)-->"C:\WINDOWS\$NtUninstallKB969898$\spuninst\spuninst.exe"
Security Update for Windows XP (KB970238)-->"C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971633)-->"C:\WINDOWS\$NtUninstallKB971633$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973346)-->"C:\WINDOWS\$NtUninstallKB973346$\spuninst\spuninst.exe"
SimCity 3000-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Maxis\SimCity 3000\Uninst.isu"
Sound Blaster Audigy-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1B1DDAD2-C704-49F8-8FC2-18DAAD9A87C5}\SETUP.EXE" -l0x9 /remove
Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
Update for Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Update for Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
Update for Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
Warhammer Mark of Chaos-->C:\Program Files\InstallShield Installation Information\{5F374D5D-DB43-4263-9C29-BAB2C93FEFE6}\Setup.exe -runfromtemp -l0x0009 -removeonly
Windows Internet Explorer 7-->"C:\WINDOWS\ie7\spuninst\spuninst.exe"
Windows Media Format Runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Player 10-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
XviD MPEG-4 Video Codec-->C:\WINDOWS\system32\rundll32.exe setupapi,InstallHinfSection Remove_XviD 132 C:\WINDOWS\INF\xvid.inf

=====HijackThis Backups=====

O4 - HKCU\..\RunOnce: [SpybotDeletingB3178] command.com /c del "C:\WINDOWS\system32\sopidkc.exe" [2009-07-13]
O4 - HKCU\..\RunOnce: [SpybotDeletingB7903] command.com /c del "C:\WINDOWS\system32\comsa32.sys" [2009-07-13]
O4 - HKCU\..\RunOnce: [SpybotDeletingD4345] cmd.exe /c del "C:\WINDOWS\system32\comsa32.sys" [2009-07-13]
O4 - HKLM\..\RunOnce: [SpybotDeletingA3990] command.com /c del "C:\WINDOWS\system32\sopidkc.exe" [2009-07-13]
O4 - HKCU\..\RunOnce: [SpybotDeletingD972] cmd.exe /c del "C:\WINDOWS\system32\comsa32.sys" [2009-07-13]
O4 - HKCU\..\RunOnce: [SpybotDeletingB1418] command.com /c del "C:\WINDOWS\system32\comsa32.sys" [2009-07-13]
O4 - HKCU\..\RunOnce: [SpybotDeletingB9994] command.com /c del "C:\WINDOWS\system32\comsa32.sys" [2009-07-13]
O4 - HKCU\..\RunOnce: [SpybotDeletingD6692] cmd.exe /c del "C:\WINDOWS\system32\sopidkc.exe" [2009-07-13]
O4 - HKCU\..\RunOnce: [SpybotDeletingB4893] command.com /c del "C:\WINDOWS\system32\comsa32.sys" [2009-07-13]
O4 - HKLM\..\RunOnce: [SpybotDeletingC7551] cmd.exe /c del "C:\WINDOWS\system32\comsa32.sys" [2009-07-13]
O4 - HKCU\..\RunOnce: [SpybotDeletingB8048] command.com /c del "C:\WINDOWS\system32\sopidkc.exe" [2009-07-13]
O4 - HKLM\..\RunOnce: [SpybotDeletingA9706] command.com /c del "C:\WINDOWS\system32\comsa32.sys" [2009-07-13]
O4 - HKLM\..\RunOnce: [SpybotDeletingC4053] cmd.exe /c del "C:\WINDOWS\system32\sopidkc.exe" [2009-07-13]
O4 - HKCU\..\RunOnce: [SpybotDeletingD7358] cmd.exe /c del "C:\WINDOWS\system32\sopidkc.exe" [2009-07-13]

======Hosts File======

127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com

======Security center information======

AV: AVG Anti-Virus Free

======System event log======

Computer Name: PEGASIS
Event Code: 16
Message: Unable to Connect: Windows is unable to connect to the automatic updates service and therefore cannot download and install updates according to the set schedule. Windows will continue to try to establish a connection.

Record Number: 1842
Source Name: Windows Update Agent
Time Written: 20090608204854.000000+060
Event Type: error
User:

Computer Name: PEGASIS
Event Code: 16
Message: Unable to Connect: Windows is unable to connect to the automatic updates service and therefore cannot download and install updates according to the set schedule. Windows will continue to try to establish a connection.

Record Number: 1693
Source Name: Windows Update Agent
Time Written: 20090606150337.000000+060
Event Type: error
User:

Computer Name: PEGASIS
Event Code: 16
Message: Unable to Connect: Windows is unable to connect to the automatic updates service and therefore cannot download and install updates according to the set schedule. Windows will continue to try to establish a connection.

Record Number: 1652
Source Name: Windows Update Agent
Time Written: 20090604102019.000000+060
Event Type: error
User:

Computer Name: PEGASIS
Event Code: 16
Message: Unable to Connect: Windows is unable to connect to the automatic updates service and therefore cannot download and install updates according to the set schedule. Windows will continue to try to establish a connection.

Record Number: 1571
Source Name: Windows Update Agent
Time Written: 20090601165043.000000+060
Event Type: error
User:

Computer Name: PEGASIS
Event Code: 16
Message: Unable to Connect: Windows is unable to connect to the automatic updates service and therefore cannot download and install updates according to the set schedule. Windows will continue to try to establish a connection.

Record Number: 1535
Source Name: Windows Update Agent
Time Written: 20090530103752.000000+060
Event Type: error
User:

=====Application event log=====

Computer Name: PEGASIS
Event Code: 2002
Message: Unable to open the Redirector service. Redirector performance data
will not be returned. Error code returned is in data DWORD 0.

Record Number: 1065
Source Name: PerfNet
Time Written: 20090701160734.000000+060
Event Type: error
User:

Computer Name: PEGASIS
Event Code: 2002
Message: Unable to open the Redirector service. Redirector performance data
will not be returned. Error code returned is in data DWORD 0.

Record Number: 1064
Source Name: PerfNet
Time Written: 20090701160727.000000+060
Event Type: error
User:

Computer Name: PEGASIS
Event Code: 1517
Message: Windows saved user PEGASIS\Andy registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use.


This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.

Record Number: 1060
Source Name: Userenv
Time Written: 20090701160435.000000+060
Event Type: warning
User: NT AUTHORITY\SYSTEM

Computer Name: PEGASIS
Event Code: 1000
Message: Faulting application spoolsv.exe, version 5.1.2600.2696, faulting module ntdll.dll, version 5.1.2600.2180, fault address 0x0003426d.

Record Number: 1057
Source Name: Application Error
Time Written: 20090701160236.000000+060
Event Type: error
User:

Computer Name: PEGASIS
Event Code: 1517
Message: Windows saved user PEGASIS\Andy registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use.


This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.

Record Number: 1049
Source Name: Userenv
Time Written: 20090701135415.000000+060
Event Type: warning
User: NT AUTHORITY\SYSTEM

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"NUMBER_OF_PROCESSORS"=2
"OS"=Windows_NT
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\ATI Technologies\ATI.ACE\
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 75 Stepping 2, AuthenticAMD
"PROCESSOR_LEVEL"=15
"PROCESSOR_REVISION"=4b02
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"windir"=%SystemRoot%

-----------------EOF-----------------

:thanks:

Freeloader
2009-07-17, 17:12
i have looked into some of the sites listed in the host file and some are linked with known malware site, does this mean virtumonde or sopidkc is still on my machine?????

Shaba
2009-07-17, 22:32
Sorry, I have missed your reply.

Those are bad sites but they are blocked in hosts.

Please update Malwarebytes and run full scan with it.

Post back malwarebytes log and fresh rsit logs, please.

Freeloader
2009-07-19, 02:38
new malwarebytes report

Malwarebytes' Anti-Malware 1.39
Database version: 2461
Windows 5.1.2600 Service Pack 3

19/07/2009 00:35:42
mbam-log-2009-07-19 (00-35-42).txt

Scan type: Full Scan (C:\|)
Objects scanned: 151440
Time elapsed: 31 minute(s), 56 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Freeloader
2009-07-19, 02:42
RSIT LOG FILE

Logfile of random's system information tool 1.06 (written by random/random)
Run by Andy at 2009-07-19 00:39:26
Microsoft Windows XP Professional Service Pack 3
System drive C: has 201 GB (84%) free of 238 GB
Total RAM: 3071 MB (75% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 00:39:39, on 19/07/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16850)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ATKKBService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Andy\Desktop\New Tools\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Andy.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.virtuagirl.com/us/freegirls.php3
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {94885D65-4728-419E-85AE-0E5DB797D50E} - C:\WINDOWS\system32\tuvVMdBT.dll (file missing)
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [SpybotDeletingA9706] command.com /c del "C:\WINDOWS\system32\comsa32.sys"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7551] cmd.exe /c del "C:\WINDOWS\system32\comsa32.sys"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3990] command.com /c del "C:\WINDOWS\system32\sopidkc.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4053] cmd.exe /c del "C:\WINDOWS\system32\sopidkc.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Andy\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\RunOnce: [SpybotDeletingB4893] command.com /c del "C:\WINDOWS\system32\comsa32.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingD972] cmd.exe /c del "C:\WINDOWS\system32\comsa32.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8048] command.com /c del "C:\WINDOWS\system32\sopidkc.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7358] cmd.exe /c del "C:\WINDOWS\system32\sopidkc.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9994] command.com /c del "C:\WINDOWS\system32\comsa32.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1418] command.com /c del "C:\WINDOWS\system32\comsa32.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4345] cmd.exe /c del "C:\WINDOWS\system32\comsa32.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3178] command.com /c del "C:\WINDOWS\system32\sopidkc.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6692] cmd.exe /c del "C:\WINDOWS\system32\sopidkc.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7903] command.com /c del "C:\WINDOWS\system32\comsa32.sys"
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1246469442578
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1246469429984
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: C:\DOCUME~1\Andy\LOCALS~1\Temp\4249062155mxx.dll C:\WINDOWS\system32\ c:\windows\system32\ c:\windows\system32\
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

--
End of file - 6637 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-484763869-436374069-725345543-1003Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-484763869-436374069-725345543-1003UA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG8\avgssie.dll [2009-07-17 1111320]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2009-01-26 1879896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{94885D65-4728-419E-85AE-0E5DB797D50E}]
C:\WINDOWS\system32\tuvVMdBT.dll []

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe [2009-07-06 1948440]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Spybot - Search & Destroy"=C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe [2009-01-26 5365592]
"SpybotDeletingA9706"=command.com /c del C:\WINDOWS\system32\comsa32.sys []
"SpybotDeletingC7551"=cmd.exe /c del C:\WINDOWS\system32\comsa32.sys []
"SpybotDeletingA3990"=command.com /c del C:\WINDOWS\system32\sopidkc.exe []
"SpybotDeletingC4053"=cmd.exe /c del C:\WINDOWS\system32\sopidkc.exe []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-03-05 2260480]
"Google Update"=C:\Documents and Settings\Andy\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-07-15 133104]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SpybotDeletingB4893"=command.com /c del C:\WINDOWS\system32\comsa32.sys []
"SpybotDeletingD972"=cmd.exe /c del C:\WINDOWS\system32\comsa32.sys []
"SpybotDeletingB8048"=command.com /c del C:\WINDOWS\system32\sopidkc.exe []
"SpybotDeletingD7358"=cmd.exe /c del C:\WINDOWS\system32\sopidkc.exe []
"SpybotDeletingB9994"=command.com /c del C:\WINDOWS\system32\comsa32.sys []
"SpybotDeletingB1418"=command.com /c del C:\WINDOWS\system32\comsa32.sys []
"SpybotDeletingD4345"=cmd.exe /c del C:\WINDOWS\system32\comsa32.sys []
"SpybotDeletingB3178"=command.com /c del C:\WINDOWS\system32\sopidkc.exe []
"SpybotDeletingD6692"=cmd.exe /c del C:\WINDOWS\system32\sopidkc.exe []
"SpybotDeletingB7903"=command.com /c del C:\WINDOWS\system32\comsa32.sys []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-10-15 39792]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcWzrd]
C:\WINDOWS\ALCWZRD.EXE [2005-09-21 2807808]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS SmartDoctor]
C:\Program Files\ASUS\SmartDoctor\SmartDoctor.exe [2006-05-18 1081344]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe [2006-01-02 45056]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CPMdf54a6dc]
C:\WINDOWS\system32\sumopuwu.dll,a []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSysVol]
C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe [2005-10-31 57344]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dc679540]
C:\WINDOWS\system32\yedonuse.dll,b []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GameFace Messenger]
C:\Program Files\GameFace Messenger\GameFace.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
C:\Program Files\CyberLink\PowerDVD\Language\Language.exe [2006-05-18 49152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\P17Helper]
Rundll32 P17.dll,P17Helper []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2005-12-07 30208]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
C:\WINDOWS\RTHDCPL.EXE [2005-09-22 14854144]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
C:\WINDOWS\SOUNDMAN.EXE [2005-09-21 86016]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
C:\WINDOWS\UpdReg.EXE [2000-05-11 90112]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vurawalake]
C:\WINDOWS\system32\zetoyago.dll,s []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"sopidkc"=2
"RichVideo"=2

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\DOCUME~1\Andy\LOCALS~1\Temp\4249062155mxx.dll C:\WINDOWS\system32\ c:\windows\system32\ c:\windows\system32\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2006-05-03 61440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgrsstarter]
C:\WINDOWS\system32\avgrsstx.dll [2009-07-06 11952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 239496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
C:\WINDOWS\system32\tuvVMdBT
"notification packages"=scecli
C:\WINDOWS\system32\yemopego.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=Warning
"legalnoticetext"=This Machine is protected by Hand Grenades
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\Program Files\THQ\Dawn of War - Dark Crusade\DarkCrusade.exe"="C:\Program Files\THQ\Dawn of War - Dark Crusade\DarkCrusade.exe:*:Disabled:DarkCrusade"
"C:\Program Files\Internet Explorer\IEXPLORE.EXE"="C:\Program Files\Internet Explorer\IEXPLORE.EXE:*:Enabled:Internet Explorer"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\THQ\Dawn of War - Soulstorm\Soulstorm.exe"="C:\Program Files\THQ\Dawn of War - Soulstorm\Soulstorm.exe:*:Enabled:Soulstorm"
"C:\Documents and Settings\Andy\My Documents\Halo\halo.exe"="C:\Documents and Settings\Andy\My Documents\Halo\halo.exe:*:Enabled:Halo"
"C:\Program Files\AVG\AVG8\avgemc.exe"="C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe"
"C:\Program Files\AVG\AVG8\avgupd.exe"="C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe"
"C:\Program Files\AVG\AVG8\avgnsx.exe"="C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2009-07-15 11:17:49 ----D---- C:\rsit
2009-07-14 22:05:53 ----HDC---- C:\WINDOWS\$NtUninstallKB973346$
2009-07-14 22:05:49 ----HDC---- C:\WINDOWS\$NtUninstallKB971633$
2009-07-14 22:04:47 ----HDC---- C:\WINDOWS\$NtUninstallKB961371$
2009-07-09 00:28:39 ----D---- C:\VideoSec
2009-07-08 01:38:14 ----A---- C:\WINDOWS\irc.txt
2009-07-08 01:18:25 ----D---- C:\Program Files\Trend Micro
2009-07-08 01:11:33 ----D---- C:\Documents and Settings\Andy\Application Data\Malwarebytes
2009-07-08 01:11:28 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-07-08 01:11:28 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-07-06 15:23:46 ----HD---- C:\$AVG8.VAULT$
2009-07-06 15:21:15 ----A---- C:\WINDOWS\system32\avgrsstx.dll
2009-07-06 15:20:51 ----D---- C:\Program Files\AVG
2009-07-06 15:20:50 ----D---- C:\Documents and Settings\All Users\Application Data\avg8
2009-07-06 14:01:52 ----D---- C:\WINDOWS\ie7updates
2009-07-06 14:01:02 ----D---- C:\WINDOWS\WBEM
2009-07-06 14:00:11 ----HDC---- C:\WINDOWS\ie7
2009-07-06 14:00:00 ----HDC---- C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$
2009-07-06 13:59:35 ----HDC---- C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$
2009-07-06 11:01:23 ----D---- C:\WINDOWS\system32\Lang
2009-07-05 13:44:46 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2009-07-05 13:44:41 ----HDC---- C:\WINDOWS\$NtUninstallKB954459$
2009-07-05 12:56:05 ----D---- C:\Program Files\Adobe
2009-07-05 12:36:50 ----D---- C:\WINDOWS\system32\RTCOM
2009-07-05 12:32:07 ----A---- C:\WINDOWS\system32\mucltui.dll.mui
2009-07-05 12:32:07 ----A---- C:\WINDOWS\system32\mucltui.dll
2009-07-05 12:30:56 ----D---- C:\WINDOWS\Prefetch
2009-07-05 00:45:36 ----A---- C:\WINDOWS\system32\MRT.exe
2009-07-05 00:02:19 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2009-07-05 00:02:14 ----HDC---- C:\WINDOWS\$NtUninstallKB954600$
2009-07-05 00:02:10 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2009-07-05 00:02:06 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2009-07-05 00:02:01 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2009-07-05 00:01:56 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2009-07-05 00:01:52 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
2009-07-05 00:01:48 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2009-07-05 00:01:44 ----HDC---- C:\WINDOWS\$NtUninstallKB951376$
2009-07-05 00:01:39 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2009-07-05 00:01:35 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2009-07-05 00:01:31 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2009-07-05 00:01:25 ----HDC---- C:\WINDOWS\$NtUninstallKB950759$
2009-07-05 00:01:21 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2009-07-05 00:01:18 ----HDC---- C:\WINDOWS\$NtUninstallKB938464-v2$
2009-07-05 00:01:13 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2009-07-04 23:58:51 ----D---- C:\WINDOWS\system32\scripting
2009-07-04 23:58:51 ----D---- C:\WINDOWS\system32\en-us
2009-07-04 23:58:51 ----D---- C:\WINDOWS\l2schemas
2009-07-04 23:58:50 ----D---- C:\WINDOWS\system32\en
2009-07-04 23:58:50 ----D---- C:\WINDOWS\system32\bits
2009-07-04 23:57:10 ----D---- C:\WINDOWS\ServicePackFiles
2009-07-04 23:55:26 ----D---- C:\WINDOWS\network diagnostic
2009-07-04 23:52:48 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2009-07-04 18:21:05 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2009-07-03 10:35:47 ----HDC---- C:\WINDOWS\$NtUninstallKB952954_0$
2009-07-03 10:35:42 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2009-07-03 10:35:37 ----HDC---- C:\WINDOWS\$NtUninstallKB946648_0$
2009-07-03 10:35:32 ----HDC---- C:\WINDOWS\$NtUninstallKB961373$
2009-07-03 10:35:28 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2009-07-03 10:35:24 ----HDC---- C:\WINDOWS\$NtUninstallKB955839_0$
2009-07-03 10:35:10 ----HDC---- C:\WINDOWS\$NtUninstallKB950974_0$
2009-07-03 10:35:05 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2009-07-03 10:34:53 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2009-07-03 10:34:46 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2009-07-03 10:34:34 ----HDC---- C:\WINDOWS\$NtUninstallKB969897$
2009-07-03 10:34:29 ----HDC---- C:\WINDOWS\$NtUninstallKB938464-v2_0$
2009-07-03 10:34:25 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$
2009-07-03 10:34:20 ----HDC---- C:\WINDOWS\$NtUninstallKB952004_0$
2009-07-03 10:34:16 ----HDC---- C:\WINDOWS\$NtUninstallKB969898$
2009-07-03 10:34:12 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
2009-07-03 10:34:07 ----HDC---- C:\WINDOWS\$NtUninstallKB958687$
2009-07-03 10:34:03 ----HDC---- C:\WINDOWS\$NtUninstallKB952287_0$
2009-07-03 10:33:55 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2009-07-03 10:33:50 ----HDC---- C:\WINDOWS\$NtUninstallKB951066_0$
2009-07-03 10:33:44 ----HDC---- C:\WINDOWS\$NtUninstallKB951748_0$
2009-07-03 10:33:39 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
2009-07-03 10:33:34 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2009-07-03 10:33:30 ----HDC---- C:\WINDOWS\$NtUninstallKB968537$
2009-07-03 10:33:25 ----HDC---- C:\WINDOWS\$NtUninstallKB954600_0$
2009-07-03 10:33:15 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2009-07-03 10:32:56 ----HDC---- C:\WINDOWS\$NtUninstallKB955069_0$
2009-07-03 10:32:50 ----N---- C:\WINDOWS\system32\xmllite.dll
2009-07-03 10:32:50 ----N---- C:\WINDOWS\system32\wmphoto.dll
2009-07-03 10:32:49 ----N---- C:\WINDOWS\system32\wlanapi.dll
2009-07-03 10:32:48 ----N---- C:\WINDOWS\system32\windowscodecsext.dll
2009-07-03 10:32:48 ----N---- C:\WINDOWS\system32\windowscodecs.dll
2009-07-03 10:32:46 ----N---- C:\WINDOWS\system32\tspkg.dll
2009-07-03 10:32:46 ----N---- C:\WINDOWS\system32\tsgqec.dll
2009-07-03 10:32:44 ----N---- C:\WINDOWS\system32\spupdwxp.exe
2009-07-03 10:32:43 ----N---- C:\WINDOWS\system32\slserv.exe
2009-07-03 10:32:43 ----N---- C:\WINDOWS\system32\slrundll.exe
2009-07-03 10:32:43 ----N---- C:\WINDOWS\slrundll.exe
2009-07-03 10:32:43 ----A---- C:\WINDOWS\system32\spdwnwxp.exe
2009-07-03 10:32:42 ----N---- C:\WINDOWS\system32\slgen.dll
2009-07-03 10:32:42 ----N---- C:\WINDOWS\system32\slextspk.dll
2009-07-03 10:32:42 ----N---- C:\WINDOWS\system32\slcoinst.dll
2009-07-03 10:32:41 ----N---- C:\WINDOWS\system32\setupn.exe
2009-07-03 10:32:41 ----N---- C:\WINDOWS\system32\s3gnb.dll
2009-07-03 10:32:40 ----N---- C:\WINDOWS\system32\rhttpaa.dll
2009-07-03 10:32:39 ----N---- C:\WINDOWS\system32\rasqec.dll
2009-07-03 10:32:39 ----N---- C:\WINDOWS\system32\qutil.dll
2009-07-03 10:32:39 ----N---- C:\WINDOWS\system32\qcliprov.dll
2009-07-03 10:32:39 ----N---- C:\WINDOWS\system32\qagentrt.dll
2009-07-03 10:32:39 ----N---- C:\WINDOWS\system32\qagent.dll
2009-07-03 10:32:38 ----N---- C:\WINDOWS\system32\photometadatahandler.dll
2009-07-03 10:32:38 ----N---- C:\WINDOWS\system32\onex.dll
2009-07-03 10:32:37 ----N---- C:\WINDOWS\system32\nv4_disp.dll
2009-07-03 10:32:34 ----N---- C:\WINDOWS\system32\napstat.exe
2009-07-03 10:32:34 ----N---- C:\WINDOWS\system32\napmontr.dll
2009-07-03 10:32:34 ----N---- C:\WINDOWS\system32\napipsec.dll
2009-07-03 10:32:34 ----N---- C:\WINDOWS\system32\mtxparhd.dll
2009-07-03 10:32:34 ----N---- C:\WINDOWS\system32\msxml6r.dll
2009-07-03 10:32:34 ----N---- C:\WINDOWS\system32\msxml6.dll
2009-07-03 10:32:33 ----N---- C:\WINDOWS\system32\msshavmsg.dll
2009-07-03 10:32:33 ----N---- C:\WINDOWS\system32\mssha.dll
2009-07-03 10:32:28 ----N---- C:\WINDOWS\system32\mmcperf.exe
2009-07-03 10:32:28 ----N---- C:\WINDOWS\system32\mmcfxcommon.dll
2009-07-03 10:32:28 ----N---- C:\WINDOWS\system32\mmcex.dll
2009-07-03 10:32:28 ----N---- C:\WINDOWS\system32\microsoft.managementconsole.dll
2009-07-03 10:32:27 ----N---- C:\WINDOWS\system32\mdmxsdk.dll
2009-07-03 10:32:23 ----N---- C:\WINDOWS\system32\l2gpstore.dll
2009-07-03 10:32:23 ----N---- C:\WINDOWS\system32\kmsvc.dll
2009-07-03 10:32:23 ----N---- C:\WINDOWS\system32\kbdpash.dll
2009-07-03 10:32:23 ----N---- C:\WINDOWS\system32\kbdnepr.dll
2009-07-03 10:32:23 ----N---- C:\WINDOWS\system32\kbdiultn.dll
2009-07-03 10:32:23 ----N---- C:\WINDOWS\system32\kbdbhc.dll
2009-07-03 10:32:19 ----N---- C:\WINDOWS\system32\smtpapi.dll
2009-07-03 10:32:19 ----N---- C:\WINDOWS\system32\rwnh.dll
2009-07-03 10:32:17 ----N---- C:\WINDOWS\system32\comsdupd.exe
2009-07-03 10:32:16 ----N---- C:\WINDOWS\system32\hsfcisp2.dll
2009-07-03 10:32:14 ----N---- C:\WINDOWS\system32\faxpatch.exe
2009-07-03 10:32:14 ----N---- C:\WINDOWS\system32\eapsvc.dll
2009-07-03 10:32:14 ----N---- C:\WINDOWS\system32\eapqec.dll
2009-07-03 10:32:14 ----N---- C:\WINDOWS\system32\eappprxy.dll
2009-07-03 10:32:14 ----N---- C:\WINDOWS\system32\eapphost.dll
2009-07-03 10:32:14 ----N---- C:\WINDOWS\system32\eappgnui.dll
2009-07-03 10:32:14 ----N---- C:\WINDOWS\system32\eappcfg.dll
2009-07-03 10:32:14 ----N---- C:\WINDOWS\system32\eapp3hst.dll
2009-07-03 10:32:14 ----N---- C:\WINDOWS\system32\eapolqec.dll
2009-07-03 10:32:14 ----A---- C:\WINDOWS\003031_.tmp
2009-07-03 10:32:13 ----N---- C:\WINDOWS\system32\dot3ui.dll
2009-07-03 10:32:13 ----N---- C:\WINDOWS\system32\dot3svc.dll
2009-07-03 10:32:13 ----N---- C:\WINDOWS\system32\dot3msm.dll
2009-07-03 10:32:13 ----N---- C:\WINDOWS\system32\dot3gpclnt.dll
2009-07-03 10:32:13 ----N---- C:\WINDOWS\system32\dot3dlg.dll
2009-07-03 10:32:13 ----N---- C:\WINDOWS\system32\dot3cfg.dll
2009-07-03 10:32:13 ----N---- C:\WINDOWS\system32\dot3api.dll
2009-07-03 10:32:13 ----N---- C:\WINDOWS\system32\dimsroam.dll
2009-07-03 10:32:13 ----N---- C:\WINDOWS\system32\dimsntfy.dll
2009-07-03 10:32:12 ----N---- C:\WINDOWS\system32\dhcpqec.dll
2009-07-03 10:32:12 ----N---- C:\WINDOWS\system32\credssp.dll
2009-07-03 10:32:08 ----N---- C:\WINDOWS\system32\bitsprx4.dll
2009-07-03 10:32:08 ----N---- C:\WINDOWS\system32\azroles.dll
2009-07-03 10:32:08 ----N---- C:\WINDOWS\system32\ativtmxx.dll
2009-07-03 10:32:07 ----N---- C:\WINDOWS\system32\ati3d1ag.dll
2009-07-03 10:32:07 ----N---- C:\WINDOWS\system32\ati2dvaa.dll
2009-07-03 10:32:06 ----N---- C:\WINDOWS\system32\aaclient.dll
2009-07-03 10:31:55 ----HDC---- C:\WINDOWS\$NtUninstallKB923561_0$
2009-07-03 10:08:40 ----N---- C:\WINDOWS\system32\xpsp4res.dll
2009-07-02 11:19:15 ----D---- C:\WINDOWS\Minidump
2009-07-01 19:13:06 ----A---- C:\WINDOWS\wininit.ini
2009-07-01 18:31:23 ----A---- C:\WINDOWS\system32\wuapi.dll.mui
2009-07-01 17:12:38 ----A---- C:\WINDOWS\system32\d744513e-.txt
2009-07-01 16:02:33 ----D---- C:\spoolerlogs

======List of files/folders modified in the last 1 months======

2009-07-19 00:31:38 ----D---- C:\WINDOWS\system32\CatRoot2
2009-07-18 23:53:14 ----D---- C:\WINDOWS\Temp
2009-07-18 10:49:13 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-07-17 20:20:51 ----D---- C:\WINDOWS\system32\drivers
2009-07-15 15:46:12 ----SD---- C:\WINDOWS\Tasks
2009-07-15 11:14:47 ----D---- C:\WINDOWS
2009-07-14 22:05:55 ----HD---- C:\WINDOWS\inf
2009-07-14 22:05:54 ----D---- C:\WINDOWS\system32
2009-07-14 22:05:52 ----HD---- C:\WINDOWS\$hf_mig$
2009-07-14 22:05:51 ----A---- C:\WINDOWS\imsins.BAK
2009-07-14 22:05:50 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-07-10 10:44:07 ----RD---- C:\Program Files
2009-07-07 09:47:36 ----RSH---- C:\boot.ini
2009-07-07 09:47:36 ----A---- C:\WINDOWS\win.ini
2009-07-07 09:47:36 ----A---- C:\WINDOWS\system.ini
2009-07-06 17:27:58 ----D---- C:\WINDOWS\system32\CatRoot
2009-07-06 17:08:55 ----A---- C:\WINDOWS\system32\CmdLineExt.dll
2009-07-06 15:20:47 ----SHD---- C:\WINDOWS\Installer
2009-07-06 15:20:41 ----HD---- C:\Config.Msi
2009-07-06 15:19:39 ----SD---- C:\Documents and Settings\Andy\Application Data\Microsoft
2009-07-06 14:05:39 ----D---- C:\WINDOWS\Help
2009-07-06 14:05:39 ----D---- C:\Program Files\Internet Explorer
2009-07-06 14:00:57 ----D---- C:\WINDOWS\Media
2009-07-05 12:56:15 ----D---- C:\Program Files\Common Files\Adobe
2009-07-05 12:56:14 ----D---- C:\WINDOWS\WinSxS
2009-07-05 12:56:12 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2009-07-05 12:34:46 ----A---- C:\WINDOWS\OEWABLog.txt
2009-07-05 12:32:21 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-07-05 12:31:05 ----A---- C:\WINDOWS\setuplog.txt
2009-07-05 12:30:26 ----D---- C:\WINDOWS\system32\Setup
2009-07-05 12:30:26 ----D---- C:\WINDOWS\AppPatch
2009-07-05 12:30:25 ----D---- C:\WINDOWS\system32\wbem
2009-07-05 12:30:24 ----RSD---- C:\WINDOWS\Fonts
2009-07-05 00:47:01 ----D---- C:\WINDOWS\security
2009-07-05 00:01:23 ----D---- C:\Program Files\Messenger
2009-07-04 23:58:59 ----D---- C:\WINDOWS\system32\inetsrv
2009-07-04 23:58:59 ----D---- C:\WINDOWS\ime
2009-07-04 23:58:51 ----D---- C:\WINDOWS\system32\usmt
2009-07-04 23:58:50 ----D---- C:\WINDOWS\PeerNet
2009-07-04 23:58:50 ----D---- C:\Program Files\Movie Maker
2009-07-04 23:57:01 ----D---- C:\WINDOWS\system32\Restore
2009-07-04 23:57:01 ----D---- C:\WINDOWS\system32\npp
2009-07-04 23:57:01 ----D---- C:\WINDOWS\mui
2009-07-04 23:57:00 ----D---- C:\WINDOWS\msagent
2009-07-04 23:56:59 ----D---- C:\WINDOWS\srchasst
2009-07-04 23:56:59 ----D---- C:\Program Files\NetMeeting
2009-07-04 23:56:58 ----D---- C:\WINDOWS\system32\Com
2009-07-04 23:56:56 ----D---- C:\Program Files\Windows NT
2009-07-04 23:56:56 ----D---- C:\Program Files\Windows Media Player
2009-07-04 23:56:56 ----D---- C:\Program Files\Outlook Express
2009-07-04 23:56:53 ----D---- C:\Program Files\Common Files\System
2009-07-04 23:56:39 ----D---- C:\WINDOWS\system32\oobe
2009-07-04 23:56:37 ----D---- C:\WINDOWS\system
2009-07-04 23:52:47 ----D---- C:\WINDOWS\ehome
2009-07-04 20:08:50 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-07-03 10:14:18 ----D---- C:\WINDOWS\Debug
2009-07-01 18:48:03 ----D---- C:\Program Files\Spybot - Search & Destroy
2009-07-01 18:47:59 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2009-07-01 18:30:36 ----D---- C:\WINDOWS\SoftwareDistribution
2009-07-01 16:11:01 ----D---- C:\Documents and Settings\Andy\Application Data\Hamachi
2009-07-01 16:10:27 ----D---- C:\temp

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AmdK8;AMD Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2005-03-09 36352]
R1 AsIO;AsIO; C:\WINDOWS\system32\drivers\AsIO.sys [2005-12-22 5685]
R1 asuskbnt;Enhanced Display Driver Helper Service; C:\WINDOWS\system32\drivers\atkkbnt.sys [2005-10-18 11008]
R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2009-07-17 335752]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2009-07-06 27784]
R1 AvgTdiX;AVG Free8 Network Redirector; C:\WINDOWS\System32\Drivers\avgtdix.sys [2009-07-06 108552]
R2 EIO;EIO; \??\C:\WINDOWS\system32\drivers\EIO.sys []
R2 tmcomm;tmcomm; \??\C:\WINDOWS\system32\drivers\tmcomm.sys []
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2006-05-03 1540608]
R3 ctsfm2k;Creative SoundFont Management Device Driver; C:\WINDOWS\system32\DRIVERS\ctsfm2k.sys [2005-01-10 138752]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2004-06-22 51088]
R3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2004-06-22 16496]
R3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2004-06-22 21744]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 ossrv;Creative OS Services Driver; C:\WINDOWS\system32\DRIVERS\ctoss2k.sys [2005-01-10 106496]
R3 P17;Sound Blaster Audigy; C:\WINDOWS\system32\drivers\P17.sys [2005-07-07 1389056]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 ZY202_XP;ZyXEL 802.11g XG202 1211 Driver; C:\WINDOWS\system32\DRIVERS\WlanUZXP.sys [2006-06-20 437760]
S3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Adapter; C:\WINDOWS\system32\DRIVERS\atl01_xp.sys [2006-05-12 31104]
S3 BRGSp50;BRGSp50 NDIS Protocol Driver; C:\WINDOWS\System32\Drivers\BRGSp50.sys [2006-06-20 20608]
S3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2007-08-26 15440]
S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2005-09-23 3966976]
S3 tunmp;Microsoft Tun Miniport Adapter Driver; C:\WINDOWS\system32\DRIVERS\tunmp.sys [2008-04-13 12288]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 Video3D;ASUS Video3D Service; C:\WINDOWS\System32\Drivers\Video3D32.sys []
S3 ZDPSp50;ZDPSp50 NDIS Protocol Driver; C:\WINDOWS\System32\Drivers\ZDPSp50.sys [2006-06-20 17664]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2006-05-03 413696]
R2 ATKKeyboardService;ATK Keyboard Service; C:\WINDOWS\ATKKBService.exe [2006-04-10 241664]
R2 avg8emc;AVG Free8 E-mail Scanner; C:\PROGRA~1\AVG\AVG8\avgemc.exe [2009-07-17 907032]
R2 avg8wd;AVG Free8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2009-07-06 298776]
R2 Creative Service for CDROM Access;Creative Service for CDROM Access; C:\WINDOWS\system32\CTsvcCDA.exe [1999-12-13 44032]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S4 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared files\RichVideo.exe [2005-08-08 167936]

-----------------EOF-----------------

No info file given on this one ??????????

Shaba
2009-07-19, 15:03
Yes that is normal.

We need first to disable TeaTimer that it doesn't interfere with fixes. You can re-enable it when you're clean again:

1. Run Spybot-S&D in Advanced Mode.
2. If it is not already set to do this Go to the Mode menu select "Advanced Mode"
3. On the left hand side, Click on Tools
4. Then click on the Resident Icon in the List
5. Uncheck "Resident TeaTimer" and OK any prompts.
6. Restart your computer.

Download OTMoveIt (http://oldtimer.geekstogo.com/OTM.exe) by Old Timer and save it to your Desktop.
Double-click OTM.exe. (Vista users, please right click on OTM.exe and select "Run as an Administrator")
Copy the lines in the codebox below.


:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{94885D65-4728-419E-85AE-0E5DB797D50E}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SpybotDeletingA9706"=-
"SpybotDeletingC7551"=-
"SpybotDeletingA3990"=-
"SpybotDeletingC4053"=-

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SpybotDeletingB4893"=-
"SpybotDeletingD972"=-
"SpybotDeletingB8048"=-
"SpybotDeletingD7358"=-
"SpybotDeletingB9994"=-
"SpybotDeletingB1418"=-
"SpybotDeletingD4345"=-
"SpybotDeletingB3178"=-
"SpybotDeletingD6692"=-
"SpybotDeletingB7903"=-

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CPMdf54a6dc]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dc679540]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vurawalake]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"sopidkc"=-

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Authentication Packages"=hex(7):"msv1_0"
"Notification Packages"=hex(7):"scecli"

Return to OTMoveIt, right click in the Paste Instructions for Items to be Moved window (under the yellow bar) and choose Paste.
Click the red Moveit! button.
Copy everything in the Results window (under the green bar), and paste it in your next reply.
Close OTMoveIt
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.


Post:

- a fresh rsit log
- otmoveit3 log

Freeloader
2009-07-19, 19:06
okedoke, results are as follows

RSIT log

Logfile of random's system information tool 1.06 (written by random/random)
Run by Andy at 2009-07-19 17:02:28
Microsoft Windows XP Professional Service Pack 3
System drive C: has 201 GB (84%) free of 238 GB
Total RAM: 3071 MB (84% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:02:40, on 19/07/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16850)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ATKKBService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Andy\Desktop\OTM.exe
C:\WINDOWS\notepad.exe
C:\Documents and Settings\Andy\Desktop\New Tools\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Andy.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.virtuagirl.com/us/freegirls.php3
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Andy\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1246469442578
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1246469429984
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: C:\DOCUME~1\Andy\LOCALS~1\Temp\4249062155mxx.dll C:\WINDOWS\system32\ c:\windows\system32\ c:\windows\system32\
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

--
End of file - 5074 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-484763869-436374069-725345543-1003Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-484763869-436374069-725345543-1003UA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG8\avgssie.dll [2009-07-17 1111320]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2009-01-26 1879896]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe [2009-07-06 1948440]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Documents and Settings\Andy\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-07-15 133104]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-10-15 39792]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcWzrd]
C:\WINDOWS\ALCWZRD.EXE [2005-09-21 2807808]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS SmartDoctor]
C:\Program Files\ASUS\SmartDoctor\SmartDoctor.exe [2006-05-18 1081344]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe [2006-01-02 45056]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSysVol]
C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe [2005-10-31 57344]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GameFace Messenger]
C:\Program Files\GameFace Messenger\GameFace.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
C:\Program Files\CyberLink\PowerDVD\Language\Language.exe [2006-05-18 49152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\P17Helper]
Rundll32 P17.dll,P17Helper []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2005-12-07 30208]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
C:\WINDOWS\RTHDCPL.EXE [2005-09-22 14854144]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
C:\WINDOWS\SOUNDMAN.EXE [2005-09-21 86016]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
C:\WINDOWS\UpdReg.EXE [2000-05-11 90112]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"RichVideo"=2

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\DOCUME~1\Andy\LOCALS~1\Temp\4249062155mxx.dll C:\WINDOWS\system32\ c:\windows\system32\ c:\windows\system32\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2006-05-03 61440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgrsstarter]
C:\WINDOWS\system32\avgrsstx.dll [2009-07-06 11952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 239496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=Warning
"legalnoticetext"=This Machine is protected by Hand Grenades
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\Program Files\THQ\Dawn of War - Dark Crusade\DarkCrusade.exe"="C:\Program Files\THQ\Dawn of War - Dark Crusade\DarkCrusade.exe:*:Disabled:DarkCrusade"
"C:\Program Files\Internet Explorer\IEXPLORE.EXE"="C:\Program Files\Internet Explorer\IEXPLORE.EXE:*:Enabled:Internet Explorer"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\THQ\Dawn of War - Soulstorm\Soulstorm.exe"="C:\Program Files\THQ\Dawn of War - Soulstorm\Soulstorm.exe:*:Enabled:Soulstorm"
"C:\Documents and Settings\Andy\My Documents\Halo\halo.exe"="C:\Documents and Settings\Andy\My Documents\Halo\halo.exe:*:Enabled:Halo"
"C:\Program Files\AVG\AVG8\avgemc.exe"="C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe"
"C:\Program Files\AVG\AVG8\avgupd.exe"="C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe"
"C:\Program Files\AVG\AVG8\avgnsx.exe"="C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2009-07-19 17:00:50 ----D---- C:\_OTM
2009-07-15 11:17:49 ----D---- C:\rsit
2009-07-14 22:05:53 ----HDC---- C:\WINDOWS\$NtUninstallKB973346$
2009-07-14 22:05:49 ----HDC---- C:\WINDOWS\$NtUninstallKB971633$
2009-07-14 22:04:47 ----HDC---- C:\WINDOWS\$NtUninstallKB961371$
2009-07-09 00:28:39 ----D---- C:\VideoSec
2009-07-08 01:38:14 ----A---- C:\WINDOWS\irc.txt
2009-07-08 01:18:25 ----D---- C:\Program Files\Trend Micro
2009-07-08 01:11:33 ----D---- C:\Documents and Settings\Andy\Application Data\Malwarebytes
2009-07-08 01:11:28 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-07-08 01:11:28 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-07-06 15:23:46 ----HD---- C:\$AVG8.VAULT$
2009-07-06 15:21:15 ----A---- C:\WINDOWS\system32\avgrsstx.dll
2009-07-06 15:20:51 ----D---- C:\Program Files\AVG
2009-07-06 15:20:50 ----D---- C:\Documents and Settings\All Users\Application Data\avg8
2009-07-06 14:01:52 ----D---- C:\WINDOWS\ie7updates
2009-07-06 14:01:02 ----D---- C:\WINDOWS\WBEM
2009-07-06 14:00:11 ----HDC---- C:\WINDOWS\ie7
2009-07-06 14:00:00 ----HDC---- C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$
2009-07-06 13:59:35 ----HDC---- C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$
2009-07-06 11:01:23 ----D---- C:\WINDOWS\system32\Lang
2009-07-05 13:44:46 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2009-07-05 13:44:41 ----HDC---- C:\WINDOWS\$NtUninstallKB954459$
2009-07-05 12:56:05 ----D---- C:\Program Files\Adobe
2009-07-05 12:36:50 ----D---- C:\WINDOWS\system32\RTCOM
2009-07-05 12:32:07 ----A---- C:\WINDOWS\system32\mucltui.dll.mui
2009-07-05 12:32:07 ----A---- C:\WINDOWS\system32\mucltui.dll
2009-07-05 12:30:56 ----D---- C:\WINDOWS\Prefetch
2009-07-05 00:45:36 ----A---- C:\WINDOWS\system32\MRT.exe
2009-07-05 00:02:19 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2009-07-05 00:02:14 ----HDC---- C:\WINDOWS\$NtUninstallKB954600$
2009-07-05 00:02:10 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2009-07-05 00:02:06 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2009-07-05 00:02:01 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2009-07-05 00:01:56 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2009-07-05 00:01:52 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
2009-07-05 00:01:48 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2009-07-05 00:01:44 ----HDC---- C:\WINDOWS\$NtUninstallKB951376$
2009-07-05 00:01:39 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2009-07-05 00:01:35 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2009-07-05 00:01:31 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2009-07-05 00:01:25 ----HDC---- C:\WINDOWS\$NtUninstallKB950759$
2009-07-05 00:01:21 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2009-07-05 00:01:18 ----HDC---- C:\WINDOWS\$NtUninstallKB938464-v2$
2009-07-05 00:01:13 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2009-07-04 23:58:51 ----D---- C:\WINDOWS\system32\scripting
2009-07-04 23:58:51 ----D---- C:\WINDOWS\system32\en-us
2009-07-04 23:58:51 ----D---- C:\WINDOWS\l2schemas
2009-07-04 23:58:50 ----D---- C:\WINDOWS\system32\en
2009-07-04 23:58:50 ----D---- C:\WINDOWS\system32\bits
2009-07-04 23:57:10 ----D---- C:\WINDOWS\ServicePackFiles
2009-07-04 23:55:26 ----D---- C:\WINDOWS\network diagnostic
2009-07-04 23:52:48 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2009-07-04 18:21:05 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2009-07-03 10:35:47 ----HDC---- C:\WINDOWS\$NtUninstallKB952954_0$
2009-07-03 10:35:42 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2009-07-03 10:35:37 ----HDC---- C:\WINDOWS\$NtUninstallKB946648_0$
2009-07-03 10:35:32 ----HDC---- C:\WINDOWS\$NtUninstallKB961373$
2009-07-03 10:35:28 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2009-07-03 10:35:24 ----HDC---- C:\WINDOWS\$NtUninstallKB955839_0$
2009-07-03 10:35:10 ----HDC---- C:\WINDOWS\$NtUninstallKB950974_0$
2009-07-03 10:35:05 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2009-07-03 10:34:53 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2009-07-03 10:34:46 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2009-07-03 10:34:34 ----HDC---- C:\WINDOWS\$NtUninstallKB969897$
2009-07-03 10:34:29 ----HDC---- C:\WINDOWS\$NtUninstallKB938464-v2_0$
2009-07-03 10:34:25 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$
2009-07-03 10:34:20 ----HDC---- C:\WINDOWS\$NtUninstallKB952004_0$
2009-07-03 10:34:16 ----HDC---- C:\WINDOWS\$NtUninstallKB969898$
2009-07-03 10:34:12 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
2009-07-03 10:34:07 ----HDC---- C:\WINDOWS\$NtUninstallKB958687$
2009-07-03 10:34:03 ----HDC---- C:\WINDOWS\$NtUninstallKB952287_0$
2009-07-03 10:33:55 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2009-07-03 10:33:50 ----HDC---- C:\WINDOWS\$NtUninstallKB951066_0$
2009-07-03 10:33:44 ----HDC---- C:\WINDOWS\$NtUninstallKB951748_0$
2009-07-03 10:33:39 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
2009-07-03 10:33:34 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2009-07-03 10:33:30 ----HDC---- C:\WINDOWS\$NtUninstallKB968537$
2009-07-03 10:33:25 ----HDC---- C:\WINDOWS\$NtUninstallKB954600_0$
2009-07-03 10:33:15 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2009-07-03 10:32:56 ----HDC---- C:\WINDOWS\$NtUninstallKB955069_0$
2009-07-03 10:32:50 ----N---- C:\WINDOWS\system32\xmllite.dll
2009-07-03 10:32:50 ----N---- C:\WINDOWS\system32\wmphoto.dll
2009-07-03 10:32:49 ----N---- C:\WINDOWS\system32\wlanapi.dll
2009-07-03 10:32:48 ----N---- C:\WINDOWS\system32\windowscodecsext.dll
2009-07-03 10:32:48 ----N---- C:\WINDOWS\system32\windowscodecs.dll
2009-07-03 10:32:46 ----N---- C:\WINDOWS\system32\tspkg.dll
2009-07-03 10:32:46 ----N---- C:\WINDOWS\system32\tsgqec.dll
2009-07-03 10:32:44 ----N---- C:\WINDOWS\system32\spupdwxp.exe
2009-07-03 10:32:43 ----N---- C:\WINDOWS\system32\slserv.exe
2009-07-03 10:32:43 ----N---- C:\WINDOWS\system32\slrundll.exe
2009-07-03 10:32:43 ----N---- C:\WINDOWS\slrundll.exe
2009-07-03 10:32:43 ----A---- C:\WINDOWS\system32\spdwnwxp.exe
2009-07-03 10:32:42 ----N---- C:\WINDOWS\system32\slgen.dll
2009-07-03 10:32:42 ----N---- C:\WINDOWS\system32\slextspk.dll
2009-07-03 10:32:42 ----N---- C:\WINDOWS\system32\slcoinst.dll
2009-07-03 10:32:41 ----N---- C:\WINDOWS\system32\setupn.exe
2009-07-03 10:32:41 ----N---- C:\WINDOWS\system32\s3gnb.dll
2009-07-03 10:32:40 ----N---- C:\WINDOWS\system32\rhttpaa.dll
2009-07-03 10:32:39 ----N---- C:\WINDOWS\system32\rasqec.dll
2009-07-03 10:32:39 ----N---- C:\WINDOWS\system32\qutil.dll
2009-07-03 10:32:39 ----N---- C:\WINDOWS\system32\qcliprov.dll
2009-07-03 10:32:39 ----N---- C:\WINDOWS\system32\qagentrt.dll
2009-07-03 10:32:39 ----N---- C:\WINDOWS\system32\qagent.dll
2009-07-03 10:32:38 ----N---- C:\WINDOWS\system32\photometadatahandler.dll
2009-07-03 10:32:38 ----N---- C:\WINDOWS\system32\onex.dll
2009-07-03 10:32:37 ----N---- C:\WINDOWS\system32\nv4_disp.dll
2009-07-03 10:32:34 ----N---- C:\WINDOWS\system32\napstat.exe
2009-07-03 10:32:34 ----N---- C:\WINDOWS\system32\napmontr.dll
2009-07-03 10:32:34 ----N---- C:\WINDOWS\system32\napipsec.dll
2009-07-03 10:32:34 ----N---- C:\WINDOWS\system32\mtxparhd.dll
2009-07-03 10:32:34 ----N---- C:\WINDOWS\system32\msxml6r.dll
2009-07-03 10:32:34 ----N---- C:\WINDOWS\system32\msxml6.dll
2009-07-03 10:32:33 ----N---- C:\WINDOWS\system32\msshavmsg.dll
2009-07-03 10:32:33 ----N---- C:\WINDOWS\system32\mssha.dll
2009-07-03 10:32:28 ----N---- C:\WINDOWS\system32\mmcperf.exe
2009-07-03 10:32:28 ----N---- C:\WINDOWS\system32\mmcfxcommon.dll
2009-07-03 10:32:28 ----N---- C:\WINDOWS\system32\mmcex.dll
2009-07-03 10:32:28 ----N---- C:\WINDOWS\system32\microsoft.managementconsole.dll
2009-07-03 10:32:27 ----N---- C:\WINDOWS\system32\mdmxsdk.dll
2009-07-03 10:32:23 ----N---- C:\WINDOWS\system32\l2gpstore.dll
2009-07-03 10:32:23 ----N---- C:\WINDOWS\system32\kmsvc.dll
2009-07-03 10:32:23 ----N---- C:\WINDOWS\system32\kbdpash.dll
2009-07-03 10:32:23 ----N---- C:\WINDOWS\system32\kbdnepr.dll
2009-07-03 10:32:23 ----N---- C:\WINDOWS\system32\kbdiultn.dll
2009-07-03 10:32:23 ----N---- C:\WINDOWS\system32\kbdbhc.dll
2009-07-03 10:32:19 ----N---- C:\WINDOWS\system32\smtpapi.dll
2009-07-03 10:32:19 ----N---- C:\WINDOWS\system32\rwnh.dll
2009-07-03 10:32:17 ----N---- C:\WINDOWS\system32\comsdupd.exe
2009-07-03 10:32:16 ----N---- C:\WINDOWS\system32\hsfcisp2.dll
2009-07-03 10:32:14 ----N---- C:\WINDOWS\system32\faxpatch.exe
2009-07-03 10:32:14 ----N---- C:\WINDOWS\system32\eapsvc.dll
2009-07-03 10:32:14 ----N---- C:\WINDOWS\system32\eapqec.dll
2009-07-03 10:32:14 ----N---- C:\WINDOWS\system32\eappprxy.dll
2009-07-03 10:32:14 ----N---- C:\WINDOWS\system32\eapphost.dll
2009-07-03 10:32:14 ----N---- C:\WINDOWS\system32\eappgnui.dll
2009-07-03 10:32:14 ----N---- C:\WINDOWS\system32\eappcfg.dll
2009-07-03 10:32:14 ----N---- C:\WINDOWS\system32\eapp3hst.dll
2009-07-03 10:32:14 ----N---- C:\WINDOWS\system32\eapolqec.dll
2009-07-03 10:32:14 ----A---- C:\WINDOWS\003031_.tmp
2009-07-03 10:32:13 ----N---- C:\WINDOWS\system32\dot3ui.dll
2009-07-03 10:32:13 ----N---- C:\WINDOWS\system32\dot3svc.dll
2009-07-03 10:32:13 ----N---- C:\WINDOWS\system32\dot3msm.dll
2009-07-03 10:32:13 ----N---- C:\WINDOWS\system32\dot3gpclnt.dll
2009-07-03 10:32:13 ----N---- C:\WINDOWS\system32\dot3dlg.dll
2009-07-03 10:32:13 ----N---- C:\WINDOWS\system32\dot3cfg.dll
2009-07-03 10:32:13 ----N---- C:\WINDOWS\system32\dot3api.dll
2009-07-03 10:32:13 ----N---- C:\WINDOWS\system32\dimsroam.dll
2009-07-03 10:32:13 ----N---- C:\WINDOWS\system32\dimsntfy.dll
2009-07-03 10:32:12 ----N---- C:\WINDOWS\system32\dhcpqec.dll
2009-07-03 10:32:12 ----N---- C:\WINDOWS\system32\credssp.dll
2009-07-03 10:32:08 ----N---- C:\WINDOWS\system32\bitsprx4.dll
2009-07-03 10:32:08 ----N---- C:\WINDOWS\system32\azroles.dll
2009-07-03 10:32:08 ----N---- C:\WINDOWS\system32\ativtmxx.dll
2009-07-03 10:32:07 ----N---- C:\WINDOWS\system32\ati3d1ag.dll
2009-07-03 10:32:07 ----N---- C:\WINDOWS\system32\ati2dvaa.dll
2009-07-03 10:32:06 ----N---- C:\WINDOWS\system32\aaclient.dll
2009-07-03 10:31:55 ----HDC---- C:\WINDOWS\$NtUninstallKB923561_0$
2009-07-03 10:08:40 ----N---- C:\WINDOWS\system32\xpsp4res.dll
2009-07-02 11:19:15 ----D---- C:\WINDOWS\Minidump
2009-07-01 19:13:06 ----A---- C:\WINDOWS\wininit.ini
2009-07-01 18:31:23 ----A---- C:\WINDOWS\system32\wuapi.dll.mui
2009-07-01 17:12:38 ----A---- C:\WINDOWS\system32\d744513e-.txt
2009-07-01 16:02:33 ----D---- C:\spoolerlogs

======List of files/folders modified in the last 1 months======

2009-07-19 16:58:25 ----D---- C:\WINDOWS\Temp
2009-07-19 16:56:50 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-07-19 00:31:38 ----D---- C:\WINDOWS\system32\CatRoot2
2009-07-17 20:20:51 ----D---- C:\WINDOWS\system32\drivers
2009-07-15 15:46:12 ----SD---- C:\WINDOWS\Tasks
2009-07-15 11:14:47 ----D---- C:\WINDOWS
2009-07-14 22:05:55 ----HD---- C:\WINDOWS\inf
2009-07-14 22:05:54 ----D---- C:\WINDOWS\system32
2009-07-14 22:05:52 ----HD---- C:\WINDOWS\$hf_mig$
2009-07-14 22:05:51 ----A---- C:\WINDOWS\imsins.BAK
2009-07-14 22:05:50 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-07-10 10:44:07 ----RD---- C:\Program Files
2009-07-07 09:47:36 ----RSH---- C:\boot.ini
2009-07-07 09:47:36 ----A---- C:\WINDOWS\win.ini
2009-07-07 09:47:36 ----A---- C:\WINDOWS\system.ini
2009-07-06 17:27:58 ----D---- C:\WINDOWS\system32\CatRoot
2009-07-06 17:08:55 ----A---- C:\WINDOWS\system32\CmdLineExt.dll
2009-07-06 15:20:47 ----SHD---- C:\WINDOWS\Installer
2009-07-06 15:20:41 ----HD---- C:\Config.Msi
2009-07-06 15:19:39 ----SD---- C:\Documents and Settings\Andy\Application Data\Microsoft
2009-07-06 14:05:39 ----D---- C:\WINDOWS\Help
2009-07-06 14:05:39 ----D---- C:\Program Files\Internet Explorer
2009-07-06 14:00:57 ----D---- C:\WINDOWS\Media
2009-07-05 12:56:15 ----D---- C:\Program Files\Common Files\Adobe
2009-07-05 12:56:14 ----D---- C:\WINDOWS\WinSxS
2009-07-05 12:56:12 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2009-07-05 12:34:46 ----A---- C:\WINDOWS\OEWABLog.txt
2009-07-05 12:32:21 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-07-05 12:31:05 ----A---- C:\WINDOWS\setuplog.txt
2009-07-05 12:30:26 ----D---- C:\WINDOWS\system32\Setup
2009-07-05 12:30:26 ----D---- C:\WINDOWS\AppPatch
2009-07-05 12:30:25 ----D---- C:\WINDOWS\system32\wbem
2009-07-05 12:30:24 ----RSD---- C:\WINDOWS\Fonts
2009-07-05 00:47:01 ----D---- C:\WINDOWS\security
2009-07-05 00:01:23 ----D---- C:\Program Files\Messenger
2009-07-04 23:58:59 ----D---- C:\WINDOWS\system32\inetsrv
2009-07-04 23:58:59 ----D---- C:\WINDOWS\ime
2009-07-04 23:58:51 ----D---- C:\WINDOWS\system32\usmt
2009-07-04 23:58:50 ----D---- C:\WINDOWS\PeerNet
2009-07-04 23:58:50 ----D---- C:\Program Files\Movie Maker
2009-07-04 23:57:01 ----D---- C:\WINDOWS\system32\Restore
2009-07-04 23:57:01 ----D---- C:\WINDOWS\system32\npp
2009-07-04 23:57:01 ----D---- C:\WINDOWS\mui
2009-07-04 23:57:00 ----D---- C:\WINDOWS\msagent
2009-07-04 23:56:59 ----D---- C:\WINDOWS\srchasst
2009-07-04 23:56:59 ----D---- C:\Program Files\NetMeeting
2009-07-04 23:56:58 ----D---- C:\WINDOWS\system32\Com
2009-07-04 23:56:56 ----D---- C:\Program Files\Windows NT
2009-07-04 23:56:56 ----D---- C:\Program Files\Windows Media Player
2009-07-04 23:56:56 ----D---- C:\Program Files\Outlook Express
2009-07-04 23:56:53 ----D---- C:\Program Files\Common Files\System
2009-07-04 23:56:39 ----D---- C:\WINDOWS\system32\oobe
2009-07-04 23:56:37 ----D---- C:\WINDOWS\system
2009-07-04 23:52:47 ----D---- C:\WINDOWS\ehome
2009-07-04 20:08:50 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-07-03 10:14:18 ----D---- C:\WINDOWS\Debug
2009-07-01 18:48:03 ----D---- C:\Program Files\Spybot - Search & Destroy
2009-07-01 18:47:59 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2009-07-01 18:30:36 ----D---- C:\WINDOWS\SoftwareDistribution
2009-07-01 16:11:01 ----D---- C:\Documents and Settings\Andy\Application Data\Hamachi
2009-07-01 16:10:27 ----D---- C:\temp

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AmdK8;AMD Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2005-03-09 36352]
R1 AsIO;AsIO; C:\WINDOWS\system32\drivers\AsIO.sys [2005-12-22 5685]
R1 asuskbnt;Enhanced Display Driver Helper Service; C:\WINDOWS\system32\drivers\atkkbnt.sys [2005-10-18 11008]
R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2009-07-17 335752]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2009-07-06 27784]
R1 AvgTdiX;AVG Free8 Network Redirector; C:\WINDOWS\System32\Drivers\avgtdix.sys [2009-07-06 108552]
R2 EIO;EIO; \??\C:\WINDOWS\system32\drivers\EIO.sys []
R2 tmcomm;tmcomm; \??\C:\WINDOWS\system32\drivers\tmcomm.sys []
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2006-05-03 1540608]
R3 ctsfm2k;Creative SoundFont Management Device Driver; C:\WINDOWS\system32\DRIVERS\ctsfm2k.sys [2005-01-10 138752]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2004-06-22 51088]
R3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2004-06-22 16496]
R3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2004-06-22 21744]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 ossrv;Creative OS Services Driver; C:\WINDOWS\system32\DRIVERS\ctoss2k.sys [2005-01-10 106496]
R3 P17;Sound Blaster Audigy; C:\WINDOWS\system32\drivers\P17.sys [2005-07-07 1389056]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 ZY202_XP;ZyXEL 802.11g XG202 1211 Driver; C:\WINDOWS\system32\DRIVERS\WlanUZXP.sys [2006-06-20 437760]
S3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Adapter; C:\WINDOWS\system32\DRIVERS\atl01_xp.sys [2006-05-12 31104]
S3 BRGSp50;BRGSp50 NDIS Protocol Driver; C:\WINDOWS\System32\Drivers\BRGSp50.sys [2006-06-20 20608]
S3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2007-08-26 15440]
S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2005-09-23 3966976]
S3 tunmp;Microsoft Tun Miniport Adapter Driver; C:\WINDOWS\system32\DRIVERS\tunmp.sys [2008-04-13 12288]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 Video3D;ASUS Video3D Service; C:\WINDOWS\System32\Drivers\Video3D32.sys []
S3 ZDPSp50;ZDPSp50 NDIS Protocol Driver; C:\WINDOWS\System32\Drivers\ZDPSp50.sys [2006-06-20 17664]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2006-05-03 413696]
R2 ATKKeyboardService;ATK Keyboard Service; C:\WINDOWS\ATKKBService.exe [2006-04-10 241664]
R2 avg8emc;AVG Free8 E-mail Scanner; C:\PROGRA~1\AVG\AVG8\avgemc.exe [2009-07-17 907032]
R2 avg8wd;AVG Free8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2009-07-06 298776]
R2 Creative Service for CDROM Access;Creative Service for CDROM Access; C:\WINDOWS\system32\CTsvcCDA.exe [1999-12-13 44032]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S4 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared files\RichVideo.exe [2005-08-08 167936]

-----------------EOF-----------------

OTM log

========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{94885D65-4728-419E-85AE-0E5DB797D50E}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{94885D65-4728-419E-85AE-0E5DB797D50E}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA9706 not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC7551 not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA3990 not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC4053 not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingB4893 not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingD972 not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingB8048 not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingD7358 not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingB9994 not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingB1418 not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingD4345 not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingB3178 not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingD6692 not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingB7903 not found.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CPMdf54a6dc\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dc679540\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vurawalake\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services\\sopidkc deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\"Authentication Packages"|hex(7):"msv1_0" /E : value set successfully!
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\"Notification Packages"|hex(7):"scecli" /E : value set successfully!

OTM by OldTimer - Version 3.0.0.5 log created on 07192009_170050

Fingers Crossed

Freeloader
2009-07-19, 19:10
The forum isnt posting the new info????

Freeloader
2009-07-19, 19:13
The forum isnt posting the new info????

dont worry bout that post, i coudnt see the last report i posted but its fine now

:thanks: andy

Shaba
2009-07-19, 21:08
Please go to Kaspersky website (http://www.kaspersky.com/kos/eng/partner/default/kavwebscan.html) and perform an online antivirus scan.

Read through the requirements and privacy statement and click on Accept button.
It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
When the downloads have finished, click on Settings.
Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button: Spyware, Adware, Dialers, and other potentially dangerous programs
Archives
Click on My Computer under Scan.
Once the scan is complete, it will display the results. Click on View Scan Report.
You will see a list of infected items there. Click on Save Report As....
Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
Please post this log in your next reply along with a fresh HijackThis log.

Freeloader
2009-07-20, 00:21
new logs coming up

Kaspersky log

--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0 REPORT
Sunday, July 19, 2009
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Sunday, July 19, 2009 20:59:50
Records in database: 2496264
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\

Scan statistics:
Files scanned: 61279
Threat name: 5
Infected objects: 7
Suspicious objects: 2
Duration of the scan: 00:54:00


File name / Threat name / Threats count
C:\Documents and Settings\Andy\.housecall6.6\Quarantine\32[1].bac_a01680 Infected: Trojan.Win32.Stuh.pnf 1
C:\Documents and Settings\Andy\.housecall6.6\Quarantine\Autorun.exe.bac_a01680 Suspicious: Trojan-Downloader.JS.gen 1
C:\Documents and Settings\Andy\.housecall6.6\Quarantine\CA7I8Z3H.bac_a01680 Infected: Trojan.Win32.Monder.cgym 1
C:\Documents and Settings\Andy\.housecall6.6\Quarantine\CDSetup.exe.bac_a01680 Suspicious: Trojan-Downloader.JS.gen 1
C:\Documents and Settings\Andy\.housecall6.6\Quarantine\i[1].bac_a01680 Infected: Trojan-Downloader.Win32.PepperPaper.hs 1
C:\Documents and Settings\Andy\.housecall6.6\Quarantine\nrjtskgc.dll.bac_a01680 Infected: Trojan.Win32.Stuh.pnf 1
C:\Documents and Settings\Andy\.housecall6.6\Quarantine\tmp0_59841142664.bk.old.bac_a01680 Infected: Trojan-Downloader.Win32.DlfBfkg.dx 1
C:\Documents and Settings\Andy\.housecall6.6\Quarantine\tpsaxyd.exe.bac_a01680 Infected: Trojan-Downloader.Win32.DlfBfkg.dx 1
C:\Documents and Settings\Andy\.housecall6.6\Quarantine\w[1].bin.bac_a01680 Infected: Trojan-Downloader.Win32.DlfBfkg.dx 1

The selected area was scanned.

HJT log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:20:42, on 19/07/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16850)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ATKKBService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.virtuagirl.com/us/freegirls.php3
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Andy\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1246469442578
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1246469429984
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: C:\DOCUME~1\Andy\LOCALS~1\Temp\4249062155mxx.dll C:\WINDOWS\system32\ c:\windows\system32\ c:\windows\system32\
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

--
End of file - 5472 bytes

Shaba
2009-07-20, 07:03
Empty this folder:

C:\Documents and Settings\Andy\.housecall6.6\Quarantine

Empty Recycle Bin.

Still problems?

Freeloader
2009-07-20, 12:40
think its clean now, none of the scans show any infection and from wot i can make out the hjt log give no indication that there are any nasties left.

Thanks for your help shaba you have saved me from an almost certain format an reinstall (which would be a bit tricky as in lost my copy of XP)

Many thanks

Andy

Shaba
2009-07-20, 17:32
Good :)

Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:

Looking over your log, it seems you don't have any evidence of a third party firewall.

As the term conveys, a firewall is an extra layer of security installed onto computers, which restricts access to systems from the outside world. Firewalls protect against hackers and malicious intruders. I want you to download a free firewall NOW from one of these excellent vendors:

1) Comodo (http://www.personalfirewall.comodo.com/download_firewall.html) (Uncheck during installation "Install COMODO Antivirus (Recommended)"!, "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage")
2) Online Armor (http://www.tallemu.com/online_armor_free.html)
3) PC Tools (http://www.pctools.com/firewall/download/)
4) Sunbelt/Kerio (http://www.sunbelt-software.com/Kerio-Download.cfm)
5) ZoneAlarm (http://www.zonelabs.com/store/content/catalog/products/sku_list_za.jsp?dc=12bms&ctry=US&lang=en&lid=nav_za) (uncheck ZoneAlarm Spy Blocker during installation if you choose this one)

If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.

You can fix these, they are leftovers:

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O20 - AppInit_DLLs: C:\DOCUME~1\Andy\LOCALS~1\Temp\4249062155mxx.dll C:\WINDOWS\system32\ c:\windows\system32\ c:\windows\system32\

Next we remove all used tools.

Please download OTCleanIt (http://oldtimer.geekstogo.com/OTC.exe) and save it to desktop.

Double-click OTC.exe.
Click the CleanUp! button.
Select Yes when the "Begin cleanup Process?" prompt appears.
If you are prompted to Reboot during the cleanup, select Yes.
The tool will delete itself once it finishes, if not delete it by yourself.


Note: If you receive a warning from your firewall or other security programs regarding OTCleanIt attempting to contact the internet, please allow it to do so.

Disable and Enable System Restore. - If you are using Windows XP then you should disable and re-enable system restore to make sure there are no infected files found in a restore point.

You can find instructions on how to enable and re-enable system restore here:

Windows XP System Restore Guide (http://www.bleepingcomputer.com/forums/tutorial56.html)

Re-enable system restore with instructions from tutorial above

Make your Internet Explorer more secure - This can be done by following these simple instructions:
From within Internet Explorer click on the Tools menu and then click on Options.
Click once on the Security tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt

Change the Download unsigned ActiveX controls to Disable

Change the Initialize and script ActiveX controls not marked as safe to Disable

Change the Installation of desktop items to Prompt

Change the Launching programs and files in an IFRAME to Prompt

Change the Navigate sub-frames across different domains to Prompt

When all these settings have been made, click on the OK button.

If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.

Update your AntiVirus Software and keep your other programs up-to-date Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.
You can use one of these sites to check if any updates are needed for your pc.
Secunia Software Inspector (http://secunia.com/software_inspector/)
F-secure Health Check (http://www.f-secure.com/weblog/archives/00001356.html)

Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com (http://www.windowsupdate.com) regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

Install Malwarebytes' Anti-Malware - Malwarebytes''Anti-Malware is a new and powerful anti-malware tool. It is
totally free but for real-time protection you will have to pay a small one-time fee. Tutorial on installing & using this product can be found below:

Malwarebytes' Anti-Malware Setup Guide (http://www.lognrock.com/forum/index.php?showtopic=6926)

Malwarebytes' Anti-Malware Scanning Guide (http://www.lognrock.com/forum/index.php?showtopic=6913)


Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

A tutorial on installing & using this product can be found here:

Using SpywareBlaster to protect your computer from Spyware and Malware (http://www.bleepingcomputer.com/tutorials/tutorial49.html)


Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.

Here are some additional utilities that will enhance your safety

MVPS Hosts file (http://mvps.org/winhelp2002/hosts.htm) <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer. See also a hosts file tutorial here (http://malwareremoval.com/forum/viewtopic.php?t=22187)
Winpatrol (http://www.winpatrol.com/) <= Download and install the free version of Winpatrol. a tutorial for this product is located here:
Using Winpatrol to protect your computer from malicious software (http://www.winpatrol.com/features.html)

Stand Up and Be Counted ---> Malware Complaints (http://www.malwarecomplaints.info/index.php) <--- where you can make difference!

The site offers people who have been (or are) victims of malware the opportunity to document their story and, in that way, launch a complaint against the malware and the makers of the malware.

Also, please read this great article by Tony Klein So How Did I Get Infected In First Place (http://forums.spybot.info/showthread.php?t=279)

Happy surfing and stay clean! :bigthumb:

Shaba
2009-07-25, 12:15
Since this issue appears to be resolved ... this Topic has been closed. Glad I could help.

Note: If it has been four days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.

If it has been less than four days since your last response and you need the thread re-opened, please send me or your helper a private message (pm). A valid, working link to the closed topic is required.