xcentrik
2009-08-10, 02:51
Hello to all and thank you for all you do.
I am having trouble with the annoying Win32.TDSS.rtk as many other are appearing to have. The entries from Spybot I am getting are posted first. I will also post my RSIT and ANtiroot logs after the SB logs. I am sure the process I will follow is pretty much the same as in other posts, such as http://forums.spybot.info/showthread.php?t=50594, and if so please let me know. If there is anything else I should do I would appreciate all the help. Thank you very much in advance!
Spybot Logs:
I have run spybot numerous time, both while processes are running and before startup, always keeps coming back.
--- Search result list ---
Win32.TDSS.rtk: [SBI $79B0E3AB] File (File, fixed)
C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys
Properties.size=0
Properties.md5=70F8852B4B8973BDE59A19330B14EE23
Win32.TDSS.rtk: [SBI $49F1C28A] File (File, fixed)
C:\WINDOWS\system32\SKYNETknbavmho.dll
Properties.size=0
Properties.md5=031C6BC3EDB0513A8FF3E38640BC95EF
Win32.TDSS.rtk: [SBI $49F1C28A] File (File, fixed)
C:\WINDOWS\system32\SKYNETqdeiqomq.dll
Properties.size=0
Properties.md5=3F40CC2D50A4B51C76F1657CF57B8E96
Win32.TDSS.rtk: [SBI $1A7ABF3C] File (File, fixed)
C:\WINDOWS\system32\SKYNETksrteoaf.dat
Properties.size=0
Properties.md5=3ECBF3A70FCFCA3D32AD547788B697CF
Win32.TDSS.rtk: [SBI $1A7ABF3C] File (File, fixed)
C:\WINDOWS\system32\SKYNETlwpvruwk.dat
Properties.size=0
Properties.md5=17890E5122ACB2D5A248BE63D7247F7F
--- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---
2009-01-26 blindman.exe (1.0.0.8)
2009-01-26 SDFiles.exe (1.6.1.7)
2009-01-26 SDMain.exe (1.0.0.6)
2009-01-26 SDShred.exe (1.0.2.5)
2009-01-26 SDUpdate.exe (1.6.0.12)
2008-07-07 SDWinSec.exe (1.0.0.12)
2009-01-26 SpybotSD.exe (1.6.2.46)
2009-03-05 TeaTimer.exe (1.6.6.32)
2009-03-20 unins000.exe (51.49.0.0)
2009-01-26 Update.exe (1.6.0.7)
2009-07-28 advcheck.dll (1.6.3.17)
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2009-01-26 SDHelper.dll (1.6.2.14)
2008-06-19 sqlite3.dll
2009-01-26 Tools.dll (2.1.6.10)
2009-01-16 UninsSrv.dll (1.0.0.0)
2009-05-19 Includes\Adware.sbi (*)
2009-07-30 Includes\AdwareC.sbi (*)
2009-01-22 Includes\Cookies.sbi (*)
2009-05-19 Includes\Dialer.sbi (*)
2009-08-04 Includes\DialerC.sbi (*)
2009-01-22 Includes\HeavyDuty.sbi (*)
2009-05-26 Includes\Hijackers.sbi (*)
2009-08-04 Includes\HijackersC.sbi (*)
2009-06-23 Includes\Keyloggers.sbi (*)
2009-07-30 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2009-07-14 Includes\Malware.sbi (*)
2009-08-05 Includes\MalwareC.sbi (*)
2009-03-25 Includes\PUPS.sbi (*)
2009-08-04 Includes\PUPSC.sbi (*)
2009-01-22 Includes\Revision.sbi (*)
2009-01-13 Includes\Security.sbi (*)
2009-07-30 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2009-04-07 Includes\Spyware.sbi (*)
2009-08-04 Includes\SpywareC.sbi (*)
2009-06-08 Includes\Tracks.uti
2009-07-22 Includes\Trojans.sbi (*)
2009-08-05 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll
--- System information ---
Windows XP (Build: 2600) Service Pack 3 (5.1.2600)
/ .NETFramework / 1.1: Microsoft .NET Framework 1.1 Hotfix (KB928366)
/ .NETFramework / 1.1: Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
/ MSXML4SP2: Security update for MSXML4 SP2 (KB954430)
/ Windows / SP1: Microsoft Internationalized Domain Names Mitigation APIs
/ Windows / SP1: Microsoft National Language Support Downlevel APIs
/ Windows Media Format 11 SDK: Hotfix for Windows Media Format 11 SDK (KB929399)
/ Windows Media Player: Security Update for Windows Media Player (KB952069)
/ Windows Media Player 11: Security Update for Windows Media Player 11 (KB936782)
/ Windows Media Player 11: Hotfix for Windows Media Player 11 (KB939683)
/ Windows Media Player 11: Security Update for Windows Media Player 11 (KB954154)
/ Windows Media Player 11: Critical Update for Windows Media Player 11 (KB959772)
/ Windows Presentation Foundation: This Hotfix is for Microsoft .NET Framework 3.0. If you later install a more recent service pack, this Hotfix will be uninstalled automatically. For more information, visit http://support.microsoft.com/kb/932471
/ Windows XP: Security Update for Windows XP (KB941569)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB928090)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB938127)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB950759)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB953838)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB956390)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB958215)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB960714)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB961260)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB963027)
/ Windows XP / SP0: Update for Windows Internet Explorer 8 (KB969497)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 8 (KB969897)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 8 (KB972260)
/ Windows XP / SP10: Microsoft Compression Client Pack 1.0 for Windows XP
/ Windows XP / SP3: Update for Windows XP (KB898461)
/ Windows XP / SP4: Security Update for Windows XP (KB923561)
/ Windows XP / SP4: Security Update for Windows XP (KB938464)
/ Windows XP / SP4: Security Update for Windows XP (KB950762)
/ Windows XP / SP4: Security Update for Windows XP (KB950974)
/ Windows XP / SP4: Security Update for Windows XP (KB951066)
/ Windows XP / SP4: Update for Windows XP (KB951072-v2)
/ Windows XP / SP4: Security Update for Windows XP (KB951376-v2)
/ Windows XP / SP4: Security Update for Windows XP (KB951698)
/ Windows XP / SP4: Security Update for Windows XP (KB951748)
/ Windows XP / SP4: Update for Windows XP (KB951978)
/ Windows XP / SP4: Security Update for Windows XP (KB952004)
/ Windows XP / SP4: Hotfix for Windows XP (KB952287)
/ Windows XP / SP4: Security Update for Windows XP (KB952954)
/ Windows XP / SP4: Security Update for Windows XP (KB953839)
/ Windows XP / SP4: Security Update for Windows XP (KB954211)
/ Windows XP / SP4: Security Update for Windows XP (KB954459)
/ Windows XP / SP4: Hotfix for Windows XP (KB954550-v5)
/ Windows XP / SP4: Security Update for Windows XP (KB954600)
/ Windows XP / SP4: Security Update for Windows XP (KB955069)
/ Windows XP / SP4: Update for Windows XP (KB955839)
/ Windows XP / SP4: Security Update for Windows XP (KB956391)
/ Windows XP / SP4: Security Update for Windows XP (KB956572)
/ Windows XP / SP4: Security Update for Windows XP (KB956802)
/ Windows XP / SP4: Security Update for Windows XP (KB956803)
/ Windows XP / SP4: Security Update for Windows XP (KB956841)
/ Windows XP / SP4: Security Update for Windows XP (KB957095)
/ Windows XP / SP4: Security Update for Windows XP (KB957097)
/ Windows XP / SP4: Security Update for Windows XP (KB958644)
/ Windows XP / SP4: Security Update for Windows XP (KB958687)
/ Windows XP / SP4: Security Update for Windows XP (KB958690)
/ Windows XP / SP4: Security Update for Windows XP (KB959426)
/ Windows XP / SP4: Security Update for Windows XP (KB960225)
/ Windows XP / SP4: Security Update for Windows XP (KB960715)
/ Windows XP / SP4: Security Update for Windows XP (KB960803)
/ Windows XP / SP4: Hotfix for Windows XP (KB961118)
/ Windows XP / SP4: Security Update for Windows XP (KB961371)
/ Windows XP / SP4: Security Update for Windows XP (KB961373)
/ Windows XP / SP4: Security Update for Windows XP (KB961501)
/ Windows XP / SP4: Update for Windows XP (KB967715)
/ Windows XP / SP4: Security Update for Windows XP (KB968537)
/ Windows XP / SP4: Security Update for Windows XP (KB969898)
/ Windows XP / SP4: Security Update for Windows XP (KB970238)
/ Windows XP / SP4: Security Update for Windows XP (KB971633)
/ Windows XP / SP4: Security Update for Windows XP (KB973346)
/ XML Paper Specification Shared Components Pack 1.0: XML Paper Specification Shared Components Pack 1.0
--- Startup entries list ---
Located: HK_LM:Run,
command:
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:Run, Acrobat Assistant 8.0
command: "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
file: C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
size: 624248
MD5: 4D042B1F1375CF371AFBE0E0276BA627
Located: HK_LM:Run, Adobe Reader Speed Launcher
command: "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
file: C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
size: 34672
MD5: 69B16C7B7746BA5C642FC05B3561FC73
Located: HK_LM:Run, Adobe_ID0EYTHM
command: C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
file: C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
size: 1884160
MD5: C1873D880786B6B03AF781E23835D925
Located: HK_LM:Run, Alcmtr
command: ALCMTR.EXE
file: C:\WINDOWS\ALCMTR.EXE
size: 69632
MD5: 8B4CBBA1EA526830C7F97E7822E2493A
Located: HK_LM:Run, ASUSGamerOSD
command: C:\Program Files\ASUS\GamerOSD\GamerOSD.exe
file: C:\Program Files\ASUS\GamerOSD\GamerOSD.exe
size: 380928
MD5: 3986FF03F6C3DD063D05B6193EA360FA
Located: HK_LM:Run, GrooveMonitor
command: "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
file: C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
size: 33648
MD5: 35DCD380D4D579D8B8EA91D5D8AE444C
Located: HK_LM:Run, Kernel and Hardware Abstraction Layer
command: KHALMNPR.EXE
file: C:\WINDOWS\KHALMNPR.EXE
size: 76304
MD5: E6A9F68D26A094FB78B98180A40A29FC
Located: HK_LM:Run, NBKeyScan
command: "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
file: C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
size: 2221352
MD5: DE9BD75FADB913F4E418CFBA381D7198
Located: HK_LM:Run, NeroFilterCheck
command: C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
file: C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
size: 570664
MD5: 925659214E5E6749C4B6B6E87B3A82D6
Located: HK_LM:Run, NvCplDaemon
command: RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
file: C:\WINDOWS\system32\NvCpl.dll
size: 13529088
MD5: 2C6E14603D984A9724AE7E6D037D4A6A
Located: HK_LM:Run, NvMediaCenter
command: RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
file: C:\WINDOWS\system32\NvMcTray.dll
size: 86016
MD5: BEAA778E2B6285E465143DD2519A75A5
Located: HK_LM:Run, nwiz
command: nwiz.exe /install
file: C:\WINDOWS\system32\nwiz.exe
size: 1630208
MD5: 03EAD6EC9D5D9D26A6845FAA35343889
Located: HK_LM:Run, RTHDCPL
command: RTHDCPL.EXE
file: C:\WINDOWS\RTHDCPL.EXE
size: 16857600
MD5: A6543BD31E3B48F70DA57FB01F13D934
Located: HK_LM:Run, SunJavaUpdateSched
command: "C:\Program Files\Java\jre6\bin\jusched.exe"
file: C:\Program Files\Java\jre6\bin\jusched.exe
size: 136600
MD5: B98FFA8288EFAABC436C30D198608345
Located: HK_LM:Run, UnlockerAssistant
command: "C:\Program Files\Unlocker\UnlockerAssistant.exe"
file: C:\Program Files\Unlocker\UnlockerAssistant.exe
size: 15872
MD5: 3FFE8752B77382C5050006C31781D05A
Located: HK_LM:Run, UserFaultCheck
command: %systemroot%\system32\dumprep 0 -u
file: C:\WINDOWS\system32\dumprep 0 -u
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:Run, WinampAgent
command: "C:\Program Files\Winamp\winampa.exe"
file: C:\Program Files\Winamp\winampa.exe
size: 36352
MD5: E7DEADB409CD8A4552C91ABF624F138F
Located: HK_LM:RunOnce, SpybotDeletingA2594
command: command.com /c del "C:\WINDOWS\system32\SKYNETlwpvruwk.dat_old"
file: command.com /c del "C:\WINDOWS\system32\SKYNETlwpvruwk.dat_old"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:RunOnce, SpybotDeletingA2730
command: command.com /c del "C:\WINDOWS\system32\SKYNETknbavmho.dll"
file: command.com /c del "C:\WINDOWS\system32\SKYNETknbavmho.dll"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:RunOnce, SpybotDeletingA2775
command: command.com /c del "C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys"
file: command.com /c del "C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:RunOnce, SpybotDeletingA2797
command: command.com /c del "C:\WINDOWS\system32\SKYNETqdeiqomq.dll"
file: command.com /c del "C:\WINDOWS\system32\SKYNETqdeiqomq.dll"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:RunOnce, SpybotDeletingA3415
command: command.com /c del "C:\WINDOWS\system32\SKYNETlwpvruwk.dat"
file: command.com /c del "C:\WINDOWS\system32\SKYNETlwpvruwk.dat"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:RunOnce, SpybotDeletingA4381
command: command.com /c del "C:\WINDOWS\system32\SKYNETknbavmho.dll"
file: command.com /c del "C:\WINDOWS\system32\SKYNETknbavmho.dll"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:RunOnce, SpybotDeletingA4430
command: command.com /c del "C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys"
file: command.com /c del "C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:RunOnce, SpybotDeletingA4440
command: command.com /c del "C:\WINDOWS\system32\SKYNETqdeiqomq.dll_old"
file: command.com /c del "C:\WINDOWS\system32\SKYNETqdeiqomq.dll_old"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:RunOnce, SpybotDeletingA515
command: command.com /c del "C:\WINDOWS\system32\SKYNETqdeiqomq.dll_old"
file: command.com /c del "C:\WINDOWS\system32\SKYNETqdeiqomq.dll_old"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:RunOnce, SpybotDeletingA5832
command: command.com /c del "C:\WINDOWS\system32\SKYNETlwpvruwk.dat_old"
file: command.com /c del "C:\WINDOWS\system32\SKYNETlwpvruwk.dat_old"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:RunOnce, SpybotDeletingA5927
command: command.com /c del "C:\WINDOWS\system32\SKYNETknbavmho.dll_old"
file: command.com /c del "C:\WINDOWS\system32\SKYNETknbavmho.dll_old"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:RunOnce, SpybotDeletingA6115
command: command.com /c del "C:\WINDOWS\system32\SKYNETksrteoaf.dat"
file: command.com /c del "C:\WINDOWS\system32\SKYNETksrteoaf.dat"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:RunOnce, SpybotDeletingA6138
command: command.com /c del "C:\WINDOWS\system32\SKYNETksrteoaf.dat_old"
file: command.com /c del "C:\WINDOWS\system32\SKYNETksrteoaf.dat_old"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:RunOnce, SpybotDeletingA7415
command: command.com /c del "C:\WINDOWS\system32\SKYNETlwpvruwk.dat"
file: command.com /c del "C:\WINDOWS\system32\SKYNETlwpvruwk.dat"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:RunOnce, SpybotDeletingA7613
command: command.com /c del "C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys_old"
file: command.com /c del "C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys_old"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:RunOnce, SpybotDeletingA7726
command: command.com /c del "C:\WINDOWS\system32\SKYNETksrteoaf.dat"
file: command.com /c del "C:\WINDOWS\system32\SKYNETksrteoaf.dat"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:RunOnce, SpybotDeletingA7792
command: command.com /c del "C:\WINDOWS\system32\SKYNETknbavmho.dll_old"
file: command.com /c del "C:\WINDOWS\system32\SKYNETknbavmho.dll_old"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:RunOnce, SpybotDeletingA796
command: command.com /c del "C:\WINDOWS\system32\SKYNETksrteoaf.dat_old"
file: command.com /c del "C:\WINDOWS\system32\SKYNETksrteoaf.dat_old"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:RunOnce, SpybotDeletingA8355
command: command.com /c del "C:\WINDOWS\system32\SKYNETqdeiqomq.dll"
file: command.com /c del "C:\WINDOWS\system32\SKYNETqdeiqomq.dll"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:RunOnce, SpybotDeletingA9586
command: command.com /c del "C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys_old"
file: command.com /c del "C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys_old"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:RunOnce, SpybotDeletingC112
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETksrteoaf.dat_old"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_LM:RunOnce, SpybotDeletingC1402
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETlwpvruwk.dat_old"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_LM:RunOnce, SpybotDeletingC1457
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETqdeiqomq.dll"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_LM:RunOnce, SpybotDeletingC1622
command: cmd.exe /c del "C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys_old"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_LM:RunOnce, SpybotDeletingC1976
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETqdeiqomq.dll"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_LM:RunOnce, SpybotDeletingC2245
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETqdeiqomq.dll_old"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_LM:RunOnce, SpybotDeletingC291
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETksrteoaf.dat"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_LM:RunOnce, SpybotDeletingC5003
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETknbavmho.dll"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_LM:RunOnce, SpybotDeletingC5242
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETlwpvruwk.dat_old"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_LM:RunOnce, SpybotDeletingC6167
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETksrteoaf.dat"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_LM:RunOnce, SpybotDeletingC6317
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETksrteoaf.dat_old"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_LM:RunOnce, SpybotDeletingC6442
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETlwpvruwk.dat"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_LM:RunOnce, SpybotDeletingC6457
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETqdeiqomq.dll_old"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_LM:RunOnce, SpybotDeletingC6808
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETknbavmho.dll_old"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_LM:RunOnce, SpybotDeletingC7088
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETknbavmho.dll_old"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_LM:RunOnce, SpybotDeletingC7531
command: cmd.exe /c del "C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_LM:RunOnce, SpybotDeletingC7569
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETknbavmho.dll"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_LM:RunOnce, SpybotDeletingC7710
command: cmd.exe /c del "C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_LM:RunOnce, SpybotDeletingC7743
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETlwpvruwk.dat"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_LM:RunOnce, SpybotDeletingC8079
command: cmd.exe /c del "C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys_old"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_CU:RunOnce, nltide_3
where: .DEFAULT...
command: rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N
file: C:\WINDOWS\system32\advpack.dll
size: 128512
MD5: 8FED1E0A491D4990853D23F21C59C730
Located: HK_CU:RunOnce, ShowDeskFix
where: .DEFAULT...
command: regsvr32 /s /n /i:u shell32
file: regsvr32 /s /n /i:u shell32
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:RunOnce, nltide_3
where: S-1-5-20...
command: rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N
file: C:\WINDOWS\system32\advpack.dll
size: 128512
MD5: 8FED1E0A491D4990853D23F21C59C730
Located: HK_CU:RunOnce, ShowDeskFix
where: S-1-5-20...
command: regsvr32 /s /n /i:u shell32
file: regsvr32 /s /n /i:u shell32
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:Run, Aim6
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
file: C:\Program Files\AIM6\aim6.exe
size: 49968
MD5: 5B4AF27E83DA8385A9B08E76DA730C91
Located: HK_CU:Run, Creative Detector U
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: "C:\Program Files\Creative\MediaSource5\CTDetctu.exe" /R
file: C:\Program Files\Creative\MediaSource5\CTDetctu.exe
size: 188416
MD5: 0BD5218D5A8C5598E75E8614938F9948
Located: HK_CU:Run, ctfmon.exe
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: C:\WINDOWS\system32\ctfmon.exe
file: C:\WINDOWS\system32\ctfmon.exe
size: 15360
MD5: 5F1D5F88303D4A4DBC8E5F97BA967CC3
Located: HK_CU:Run, IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
file: C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
size: 1840424
MD5: C44031488DED58FCE58E5D94BC345D30
Located: HK_CU:Run, SpybotSD TeaTimer
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
file: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
size: 2260480
MD5: 390679F7A217A5E73D756276C40AE887
Located: HK_CU:RunOnce, SpybotDeletingB1865
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: command.com /c del "C:\WINDOWS\system32\SKYNETqdeiqomq.dll_old"
file: command.com /c del "C:\WINDOWS\system32\SKYNETqdeiqomq.dll_old"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:RunOnce, SpybotDeletingB2372
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: command.com /c del "C:\WINDOWS\system32\SKYNETqdeiqomq.dll_old"
file: command.com /c del "C:\WINDOWS\system32\SKYNETqdeiqomq.dll_old"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:RunOnce, SpybotDeletingB2902
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: command.com /c del "C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys_old"
file: command.com /c del "C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys_old"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:RunOnce, SpybotDeletingB2981
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: command.com /c del "C:\WINDOWS\system32\SKYNETknbavmho.dll"
file: command.com /c del "C:\WINDOWS\system32\SKYNETknbavmho.dll"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:RunOnce, SpybotDeletingB2982
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: command.com /c del "C:\WINDOWS\system32\SKYNETksrteoaf.dat"
file: command.com /c del "C:\WINDOWS\system32\SKYNETksrteoaf.dat"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:RunOnce, SpybotDeletingB4035
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: command.com /c del "C:\WINDOWS\system32\SKYNETlwpvruwk.dat_old"
file: command.com /c del "C:\WINDOWS\system32\SKYNETlwpvruwk.dat_old"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:RunOnce, SpybotDeletingB466
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: command.com /c del "C:\WINDOWS\system32\SKYNETlwpvruwk.dat_old"
file: command.com /c del "C:\WINDOWS\system32\SKYNETlwpvruwk.dat_old"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:RunOnce, SpybotDeletingB4908
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: command.com /c del "C:\WINDOWS\system32\SKYNETqdeiqomq.dll"
file: command.com /c del "C:\WINDOWS\system32\SKYNETqdeiqomq.dll"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:RunOnce, SpybotDeletingB5805
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: command.com /c del "C:\WINDOWS\system32\SKYNETknbavmho.dll"
file: command.com /c del "C:\WINDOWS\system32\SKYNETknbavmho.dll"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:RunOnce, SpybotDeletingB6431
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: command.com /c del "C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys"
file: command.com /c del "C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:RunOnce, SpybotDeletingB6849
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: command.com /c del "C:\WINDOWS\system32\SKYNETqdeiqomq.dll"
file: command.com /c del "C:\WINDOWS\system32\SKYNETqdeiqomq.dll"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:RunOnce, SpybotDeletingB7485
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: command.com /c del "C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys"
file: command.com /c del "C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:RunOnce, SpybotDeletingB7906
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: command.com /c del "C:\WINDOWS\system32\SKYNETknbavmho.dll_old"
file: command.com /c del "C:\WINDOWS\system32\SKYNETknbavmho.dll_old"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:RunOnce, SpybotDeletingB7932
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: command.com /c del "C:\WINDOWS\system32\SKYNETlwpvruwk.dat"
file: command.com /c del "C:\WINDOWS\system32\SKYNETlwpvruwk.dat"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:RunOnce, SpybotDeletingB8298
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: command.com /c del "C:\WINDOWS\system32\SKYNETknbavmho.dll_old"
file: command.com /c del "C:\WINDOWS\system32\SKYNETknbavmho.dll_old"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:RunOnce, SpybotDeletingB8460
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: command.com /c del "C:\WINDOWS\system32\SKYNETlwpvruwk.dat"
file: command.com /c del "C:\WINDOWS\system32\SKYNETlwpvruwk.dat"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:RunOnce, SpybotDeletingB9225
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: command.com /c del "C:\WINDOWS\system32\SKYNETksrteoaf.dat_old"
file: command.com /c del "C:\WINDOWS\system32\SKYNETksrteoaf.dat_old"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:RunOnce, SpybotDeletingB9708
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: command.com /c del "C:\WINDOWS\system32\SKYNETksrteoaf.dat_old"
file: command.com /c del "C:\WINDOWS\system32\SKYNETksrteoaf.dat_old"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:RunOnce, SpybotDeletingB9867
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: command.com /c del "C:\WINDOWS\system32\SKYNETksrteoaf.dat"
file: command.com /c del "C:\WINDOWS\system32\SKYNETksrteoaf.dat"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:RunOnce, SpybotDeletingB9997
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: command.com /c del "C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys_old"
file: command.com /c del "C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys_old"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:RunOnce, SpybotDeletingD1488
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETlwpvruwk.dat_old"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_CU:RunOnce, SpybotDeletingD1624
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: cmd.exe /c del "C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys_old"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_CU:RunOnce, SpybotDeletingD2033
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETlwpvruwk.dat"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_CU:RunOnce, SpybotDeletingD2319
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETqdeiqomq.dll_old"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_CU:RunOnce, SpybotDeletingD255
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETknbavmho.dll_old"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_CU:RunOnce, SpybotDeletingD2679
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETqdeiqomq.dll_old"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_CU:RunOnce, SpybotDeletingD3100
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETknbavmho.dll"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_CU:RunOnce, SpybotDeletingD3112
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETknbavmho.dll_old"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_CU:RunOnce, SpybotDeletingD3392
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETknbavmho.dll"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_CU:RunOnce, SpybotDeletingD4267
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: cmd.exe /c del "C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys_old"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_CU:RunOnce, SpybotDeletingD483
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETksrteoaf.dat"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_CU:RunOnce, SpybotDeletingD5113
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETqdeiqomq.dll"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_CU:RunOnce, SpybotDeletingD6523
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETqdeiqomq.dll"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_CU:RunOnce, SpybotDeletingD6549
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETksrteoaf.dat_old"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_CU:RunOnce, SpybotDeletingD6773
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: cmd.exe /c del "C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_CU:RunOnce, SpybotDeletingD7026
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETksrteoaf.dat_old"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_CU:RunOnce, SpybotDeletingD7882
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETlwpvruwk.dat"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_CU:RunOnce, SpybotDeletingD809
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETksrteoaf.dat"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_CU:RunOnce, SpybotDeletingD9122
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: cmd.exe /c del "C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_CU:RunOnce, SpybotDeletingD9308
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETlwpvruwk.dat_old"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_CU:RunOnce, nltide_3
where: S-1-5-18...
command: rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N
file: C:\WINDOWS\system32\advpack.dll
size: 128512
MD5: 8FED1E0A491D4990853D23F21C59C730
Located: HK_CU:RunOnce, ShowDeskFix
where: S-1-5-18...
command: regsvr32 /s /n /i:u shell32
file: regsvr32 /s /n /i:u shell32
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: Startup (common), Logitech SetPoint.lnk
where: C:\Documents and Settings\All Users\Start Menu\Programs\Startup...
command: C:\Program Files\Logitech\SetPoint\SetPoint.exe
file: C:\Program Files\Logitech\SetPoint\SetPoint.exe
size: 805392
MD5: D0948BE9B3547B9669195D7F84FC09F7
Located: Startup (user), Styler.lnk
where: C:\Documents and Settings\Joshua\Start Menu\Programs\Startup...
command: C:\Documents and Settings\Joshua\Application Data\Microsoft\Installer\{E9ECF354-2422-4FDB-9ABF-D8ADAC0EF941}\_585b207a.exe
file: C:\Documents and Settings\Joshua\Application Data\Microsoft\Installer\{E9ECF354-2422-4FDB-9ABF-D8ADAC0EF941}\_585b207a.exe
size: 15086
MD5: 8588D2403599C1E7D1F6C9EA458CEB39
Located: Startup (disabled), OneNote 2007 Screen Clipper and Launcher (DISABLED)
command: C:\PROGRA~1\MICROS~2\Office12\ONENOTEM.EXE /tsr
file: C:\PROGRA~1\MICROS~2\Office12\ONENOTEM.EXE
size: 101440
MD5: 9D0EEBDA40D5C33BC63FB8BB984F7681
Located: WinLogon, avgrsstarter
command: avgrsstx.dll
file: avgrsstx.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, crypt32chain
command: crypt32.dll
file: crypt32.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, cryptnet
command: cryptnet.dll
file: cryptnet.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, cscdll
command: cscdll.dll
file: cscdll.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, dimsntfy
command: %SystemRoot%\System32\dimsntfy.dll
file: %SystemRoot%\System32\dimsntfy.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, LBTWlgn
command: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
file: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
size: 72208
MD5: 2ACBFEF9984F0FE9849DA857206CCECC
Located: WinLogon, ScCertProp
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, Schedule
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, sclgntfy
command: sclgntfy.dll
file: sclgntfy.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, SensLogn
command: WlNotify.dll
file: WlNotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, termsrv
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, WgaLogon
command: WgaLogon.dll
file: WgaLogon.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, wlballoon
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
--- Browser helper object list ---
{074C1DC5-9320-4A9A-947D-C042949C6216} (ContributeBHO Class)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: ContributeBHO Class
Path: C:\Program Files\Adobe\
Long name: contributeieplugin.dll
Short name: CONTRI~1.DLL
Date (created): 3/16/2007 3:13:06 PM
Date (last access): 8/9/2009 3:42:56 PM
Date (last write): 3/16/2007 3:13:06 PM
Filesize: 118784
Attributes: archive
MD5: E23691A98928CE49586753982B8402A2
CRC32: 2CAFCB5A
Version: 1.0.0.0
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} (AcroIEHelperStub)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name: AcroIEHelperStub
CLSID name: Adobe PDF Link Helper
Path: C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\
Long name: AcroIEHelperShim.dll
Short name: ACROIE~2.DLL
Date (created): 6/11/2008 11:33:16 PM
Date (last access): 8/9/2009 3:39:48 PM
Date (last write): 6/11/2008 11:33:16 PM
Filesize: 75128
Attributes: archive
MD5: E96C752BBA0E22330A43258FC800200E
CRC32: E5D72083
Version: 9.0.0.332
{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} (WormRadar.com IESiteBlocker.NavFilter)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name: WormRadar.com IESiteBlocker.NavFilter
CLSID name: AVG Safe Search
Path: C:\Program Files\AVG\AVG8\
Long name: avgssie.dll
Short name:
Date (created): 2/4/2009 10:21:00 AM
Date (last access): 8/9/2009 4:15:10 PM
Date (last write): 7/19/2009 11:43:04 PM
Filesize: 1111320
Attributes: archive
MD5: A8F964A2FB9400B81E1483AA5A8B39F5
CRC32: E3F2A2F4
Version: 8.5.0.392
{72853161-30C5-4D22-B7F9-0BBC1D38A37E} (Groove GFS Browser Helper)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: Groove GFS Browser Helper
Path: C:\Program Files\Microsoft Office\Office12\
Long name: GrooveShellExtensions.dll
Short name: GRA8E1~1.DLL
Date (created): 8/24/2007 8:01:22 AM
Date (last access): 8/9/2009 4:12:24 PM
Date (last write): 8/24/2007 8:01:22 AM
Filesize: 2212224
Attributes: archive
MD5: 32C4927E013C018A13D8DFBDA4148812
CRC32: 9A9F3D8B
Version: 12.0.6211.1000
{b0cda128-b425-4eef-a174-61a11ac5dbf8} (AIM Toolbar Loader)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name: AIM Toolbar Loader
CLSID name: AIM Toolbar Loader
Path: C:\Program Files\AIM Toolbar\
Long name: aimtb.dll
Short name:
Date (created): 5/6/2009 11:14:26 AM
Date (last access): 8/9/2009 4:15:10 PM
Date (last write): 5/6/2009 11:14:26 AM
Filesize: 1279272
Attributes: archive
MD5: 4BD0311F7E4F1A6010CCC1D263128443
CRC32: 71974D6A
Version: 5.25.24.1
{DBC80044-A445-435b-BC74-9C25C1C588A9} (Java(tm) Plug-In 2 SSV Helper)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: Java(tm) Plug-In 2 SSV Helper
Path: C:\Program Files\Java\jre6\bin\
Long name: jp2ssv.dll
Short name:
Date (created): 12/27/2008 9:40:58 PM
Date (last access): 8/9/2009 3:49:10 PM
Date (last write): 12/27/2008 9:40:58 PM
Filesize: 34816
Attributes: archive
MD5: 5D57FD3DF32DC69CEC3D1D54B4C43162
CRC32: D7C13FB2
Version: 6.0.110.3
{E7E6F031-17CE-4C07-BC86-EABFE594F69C} (JQSIEStartDetectorImpl)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name: JQSIEStartDetectorImpl
CLSID name: JQSIEStartDetectorImpl Class
Path: C:\Program Files\Java\jre6\lib\deploy\jqs\ie\
Long name: jqs_plugin.dll
Short name: JQS_PL~1.DLL
Date (created): 12/27/2008 9:41:02 PM
Date (last access): 8/9/2009 3:49:10 PM
Date (last write): 12/27/2008 9:41:02 PM
Filesize: 73728
Attributes: archive
MD5: F68EDAFE003F2B3523C0742CD3B8D673
CRC32: 9C709350
Version: 6.0.110.3
--- ActiveX list ---
{8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0)
DPF name: Java Runtime Environment 1.6.0
CLSID name: Java Plug-in 1.6.0_11
Installer:
Codebase: http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
description: Sun Java
classification: Legitimate
known filename: %PROGRAM FILES%\JabaSoft\JRE\*\Bin\npjava131.dll
info link:
info source: Patrick M. Kolla
Path: C:\Program Files\Java\jre6\bin\
Long name: npjpi160_11.dll
Short name: NPJPI1~1.DLL
Date (created): 12/27/2008 9:41:00 PM
Date (last access): 8/9/2009 2:47:20 PM
Date (last write): 12/27/2008 9:41:00 PM
Filesize: 132504
Attributes: archive
MD5: D400116F6776ACB6EDB6B1F5EEB9F92D
CRC32: CECB5751
Version: 6.0.110.3
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C} ()
DPF name:
CLSID name:
Installer: C:\WINDOWS\Downloaded Program Files\erma.inf
Codebase: http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
description:
classification: Open for discussion
known filename:
info link:
info source: Safer Networking Ltd.
{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
DPF name: Java Runtime Environment 1.6.0
CLSID name: Java Plug-in 1.6.0_06
Installer:
Codebase: http://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
Path: C:\Program Files\Java\jre1.6.0_06\bin\
Long name: npjpi160_06.dll
Short name: NPJPI1~1.DLL
Date (created): 3/25/2008 2:37:02 AM
Date (last access): 8/9/2009 2:47:00 PM
Date (last write): 3/25/2008 4:28:02 AM
Filesize: 132496
Attributes: archive
MD5: 5522AFEAB77DD6D401F3FE5C0A46122E
CRC32: F643B062
Version: 6.0.60.2
{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
DPF name: Java Runtime Environment 1.6.0
CLSID name: Java Plug-in 1.6.0_07
Installer:
Codebase: http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
Path: C:\Program Files\Java\jre1.6.0_07\bin\
Long name: npjpi160_07.dll
Short name: NPJPI1~1.DLL
Date (created): 6/10/2008 3:32:34 AM
Date (last access): 8/9/2009 2:47:10 PM
Date (last write): 6/10/2008 5:27:02 AM
Filesize: 132496
Attributes: archive
MD5: 7C83A2809E13950359189767AC9D5DB8
CRC32: 925C2A88
Version: 6.0.70.6
{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
DPF name: Java Runtime Environment 1.6.0
CLSID name: Java Plug-in 1.6.0_11
Installer:
Codebase: http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
Path: C:\Program Files\Java\jre6\bin\
Long name: npjpi160_11.dll
Short name: NPJPI1~1.DLL
Date (created): 12/27/2008 9:41:00 PM
Date (last access): 8/9/2009 4:36:10 PM
Date (last write): 12/27/2008 9:41:00 PM
Filesize: 132504
Attributes: archive
MD5: D400116F6776ACB6EDB6B1F5EEB9F92D
CRC32: CECB5751
Version: 6.0.110.3
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
DPF name: Java Runtime Environment 1.6.0
CLSID name: Java Plug-in 1.6.0_11
Installer:
Codebase: http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
description:
classification: Legitimate
known filename: npjpi150_06.dll
info link:
info source: Safer Networking Ltd.
Path: C:\Program Files\Java\jre6\bin\
Long name: npjpi160_11.dll
Short name: NPJPI1~1.DLL
Date (created): 12/27/2008 9:41:00 PM
Date (last access): 8/9/2009 4:36:10 PM
Date (last write): 12/27/2008 9:41:00 PM
Filesize: 132504
Attributes: archive
MD5: D400116F6776ACB6EDB6B1F5EEB9F92D
CRC32: CECB5751
Version: 6.0.110.3
--- Process list ---
PID: 0 ( 0) [System]
PID: 812 ( 4) \SystemRoot\System32\smss.exe
size: 50688
PID: 868 ( 812) \??\C:\WINDOWS\system32\csrss.exe
size: 6144
PID: 892 ( 812) \??\C:\WINDOWS\system32\winlogon.exe
size: 507904
PID: 940 ( 892) C:\WINDOWS\system32\services.exe
size: 110592
MD5: 65DF52F5B8B6E9BBD183505225C37315
PID: 952 ( 892) C:\WINDOWS\system32\lsass.exe
size: 13312
MD5: BF2466B3E18E970D8A976FB95FC1CA85
PID: 1100 ( 940) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 1212 ( 940) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 1268 ( 940) C:\WINDOWS\System32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 1316 ( 940) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 1460 ( 940) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 1540 ( 940) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 1880 ( 940) C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
size: 611664
MD5: 17067069B9A7865028C1F2E6971D0CCC
PID: 2044 ( 940) C:\WINDOWS\system32\spoolsv.exe
size: 57856
MD5: D8E14A61ACC1D4A6CD0D38AEBAC7FA3B
PID: 560 ( 440) C:\WINDOWS\Explorer.EXE
size: 1033728
MD5: 12896823FB95BFB3DC9B46BCAEDC9923
PID: 248 ( 560) C:\Program Files\Unlocker\UnlockerAssistant.exe
size: 15872
MD5: 3FFE8752B77382C5050006C31781D05A
PID: 628 ( 560) C:\Program Files\Java\jre6\bin\jusched.exe
size: 136600
MD5: B98FFA8288EFAABC436C30D198608345
PID: 644 ( 560) C:\WINDOWS\RTHDCPL.EXE
size: 16857600
MD5: A6543BD31E3B48F70DA57FB01F13D934
PID: 692 ( 560) C:\WINDOWS\system32\RUNDLL32.EXE
size: 33280
MD5: 037B1E7798960E0420003D05BB577EE6
PID: 720 ( 560) C:\Program Files\ASUS\GamerOSD\GamerOSD.exe
size: 380928
MD5: 3986FF03F6C3DD063D05B6193EA360FA
PID: 832 ( 560) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
size: 33648
MD5: 35DCD380D4D579D8B8EA91D5D8AE444C
PID: 1012 ( 940) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 1160 ( 560) C:\Program Files\Winamp\winampa.exe
size: 36352
MD5: E7DEADB409CD8A4552C91ABF624F138F
PID: 1412 ( 940) C:\WINDOWS\ATKKBService.exe
size: 262144
MD5: DF70303547E59F09DCD32983100EDCD1
PID: 1408 ( 560) C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
size: 624248
MD5: 4D042B1F1375CF371AFBE0E0276BA627
PID: 1452 ( 940) C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
size: 298776
MD5: BFC093C2DDDE8FCE5DA078E663B4515B
PID: 1552 ( 560) C:\WINDOWS\system32\ctfmon.exe
size: 15360
MD5: 5F1D5F88303D4A4DBC8E5F97BA967CC3
PID: 1064 ( 560) C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
size: 2260480
MD5: 390679F7A217A5E73D756276C40AE887
PID: 1628 ( 940) C:\Program Files\Bonjour\mDNSResponder.exe
size: 229376
MD5: 73686FE0B2E0469F89FD2075BE724704
PID: 1632 ( 560) C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
size: 1840424
MD5: C44031488DED58FCE58E5D94BC345D30
PID: 1676 ( 560) C:\Program Files\Creative\MediaSource5\CTDetctu.exe
size: 188416
MD5: 0BD5218D5A8C5598E75E8614938F9948
PID: 1704 ( 940) C:\WINDOWS\system32\CTsvcCDA.exe
size: 44032
MD5: 3C8B6609712F4FF78E521F6DCFC4032B
PID: 1960 ( 940) C:\Program Files\Java\jre6\bin\jqs.exe
size: 152984
MD5: 32192B4EBE8720ED8D49A455C962CB91
PID: 1956 ( 940) C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
size: 877864
MD5: 2AAE889742376EDC5C3203DFB74F28FD
PID: 360 ( 560) C:\Program Files\Logitech\SetPoint\SetPoint.exe
size: 805392
MD5: D0948BE9B3547B9669195D7F84FC09F7
PID: 728 ( 560) C:\Program Files\Styler\Styler.exe
size: 307200
MD5: D68AE8C031B370538F917AF176A947F6
PID: 1800 ( 940) C:\WINDOWS\system32\nvsvc32.exe
size: 159812
MD5: 93972E943623635A47DC33D312B6A378
PID: 1840 (1452) C:\Program Files\AVG\AVG8\avgrsx.exe
size: 486680
MD5: 95E1D555542D5F6031E756751C6FF3F4
PID: 2124 ( 360) C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
size: 76304
MD5: 19E0D28FE38F55CA4C63F77D3657959A
PID: 2156 ( 940) C:\WINDOWS\system32\IoctlSvc.exe
size: 81920
MD5: 875E4E0661F3A5994DF9E5E3A0A4F96B
PID: 2264 ( 940) C:\WINDOWS\system32\PnkBstrA.exe
size: 75064
MD5: A1DD33D16F277CE34124EE52AB2C0F14
PID: 2396 ( 940) C:\WINDOWS\system32\PnkBstrB.exe
size: 189104
MD5: 10652913B563B6376B5C25DB63FA72E3
PID: 2464 ( 940) C:\Program Files\Viewpoint\Common\ViewpointService.exe
size: 24652
MD5: 5F974FDE801C73952770736BECDE11E7
PID: 3148 ( 940) C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
size: 537896
MD5: CB992AE1506985D9167E85883B4C3240
PID: 3236 ( 940) C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
size: 654848
MD5: 227846995AFEEFA70D328BF5334A86A5
PID: 3764 ( 940) C:\WINDOWS\System32\alg.exe
size: 44544
MD5: 8C515081584A38AA007909CD02020B3D
PID: 2744 ( 560) C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
size: 5365592
MD5: 0477C2F9171599CA5BC3307FDFBA8D89
PID: 3260 ( 560) C:\Program Files\Mozilla Firefox\firefox.exe
size: 307704
MD5: 457441B04089CF16784D698B4B4EA8AF
PID: 4 ( 0) System
I am having trouble with the annoying Win32.TDSS.rtk as many other are appearing to have. The entries from Spybot I am getting are posted first. I will also post my RSIT and ANtiroot logs after the SB logs. I am sure the process I will follow is pretty much the same as in other posts, such as http://forums.spybot.info/showthread.php?t=50594, and if so please let me know. If there is anything else I should do I would appreciate all the help. Thank you very much in advance!
Spybot Logs:
I have run spybot numerous time, both while processes are running and before startup, always keeps coming back.
--- Search result list ---
Win32.TDSS.rtk: [SBI $79B0E3AB] File (File, fixed)
C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys
Properties.size=0
Properties.md5=70F8852B4B8973BDE59A19330B14EE23
Win32.TDSS.rtk: [SBI $49F1C28A] File (File, fixed)
C:\WINDOWS\system32\SKYNETknbavmho.dll
Properties.size=0
Properties.md5=031C6BC3EDB0513A8FF3E38640BC95EF
Win32.TDSS.rtk: [SBI $49F1C28A] File (File, fixed)
C:\WINDOWS\system32\SKYNETqdeiqomq.dll
Properties.size=0
Properties.md5=3F40CC2D50A4B51C76F1657CF57B8E96
Win32.TDSS.rtk: [SBI $1A7ABF3C] File (File, fixed)
C:\WINDOWS\system32\SKYNETksrteoaf.dat
Properties.size=0
Properties.md5=3ECBF3A70FCFCA3D32AD547788B697CF
Win32.TDSS.rtk: [SBI $1A7ABF3C] File (File, fixed)
C:\WINDOWS\system32\SKYNETlwpvruwk.dat
Properties.size=0
Properties.md5=17890E5122ACB2D5A248BE63D7247F7F
--- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---
2009-01-26 blindman.exe (1.0.0.8)
2009-01-26 SDFiles.exe (1.6.1.7)
2009-01-26 SDMain.exe (1.0.0.6)
2009-01-26 SDShred.exe (1.0.2.5)
2009-01-26 SDUpdate.exe (1.6.0.12)
2008-07-07 SDWinSec.exe (1.0.0.12)
2009-01-26 SpybotSD.exe (1.6.2.46)
2009-03-05 TeaTimer.exe (1.6.6.32)
2009-03-20 unins000.exe (51.49.0.0)
2009-01-26 Update.exe (1.6.0.7)
2009-07-28 advcheck.dll (1.6.3.17)
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2009-01-26 SDHelper.dll (1.6.2.14)
2008-06-19 sqlite3.dll
2009-01-26 Tools.dll (2.1.6.10)
2009-01-16 UninsSrv.dll (1.0.0.0)
2009-05-19 Includes\Adware.sbi (*)
2009-07-30 Includes\AdwareC.sbi (*)
2009-01-22 Includes\Cookies.sbi (*)
2009-05-19 Includes\Dialer.sbi (*)
2009-08-04 Includes\DialerC.sbi (*)
2009-01-22 Includes\HeavyDuty.sbi (*)
2009-05-26 Includes\Hijackers.sbi (*)
2009-08-04 Includes\HijackersC.sbi (*)
2009-06-23 Includes\Keyloggers.sbi (*)
2009-07-30 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2009-07-14 Includes\Malware.sbi (*)
2009-08-05 Includes\MalwareC.sbi (*)
2009-03-25 Includes\PUPS.sbi (*)
2009-08-04 Includes\PUPSC.sbi (*)
2009-01-22 Includes\Revision.sbi (*)
2009-01-13 Includes\Security.sbi (*)
2009-07-30 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2009-04-07 Includes\Spyware.sbi (*)
2009-08-04 Includes\SpywareC.sbi (*)
2009-06-08 Includes\Tracks.uti
2009-07-22 Includes\Trojans.sbi (*)
2009-08-05 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll
--- System information ---
Windows XP (Build: 2600) Service Pack 3 (5.1.2600)
/ .NETFramework / 1.1: Microsoft .NET Framework 1.1 Hotfix (KB928366)
/ .NETFramework / 1.1: Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
/ MSXML4SP2: Security update for MSXML4 SP2 (KB954430)
/ Windows / SP1: Microsoft Internationalized Domain Names Mitigation APIs
/ Windows / SP1: Microsoft National Language Support Downlevel APIs
/ Windows Media Format 11 SDK: Hotfix for Windows Media Format 11 SDK (KB929399)
/ Windows Media Player: Security Update for Windows Media Player (KB952069)
/ Windows Media Player 11: Security Update for Windows Media Player 11 (KB936782)
/ Windows Media Player 11: Hotfix for Windows Media Player 11 (KB939683)
/ Windows Media Player 11: Security Update for Windows Media Player 11 (KB954154)
/ Windows Media Player 11: Critical Update for Windows Media Player 11 (KB959772)
/ Windows Presentation Foundation: This Hotfix is for Microsoft .NET Framework 3.0. If you later install a more recent service pack, this Hotfix will be uninstalled automatically. For more information, visit http://support.microsoft.com/kb/932471
/ Windows XP: Security Update for Windows XP (KB941569)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB928090)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB938127)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB950759)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB953838)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB956390)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB958215)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB960714)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB961260)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB963027)
/ Windows XP / SP0: Update for Windows Internet Explorer 8 (KB969497)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 8 (KB969897)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 8 (KB972260)
/ Windows XP / SP10: Microsoft Compression Client Pack 1.0 for Windows XP
/ Windows XP / SP3: Update for Windows XP (KB898461)
/ Windows XP / SP4: Security Update for Windows XP (KB923561)
/ Windows XP / SP4: Security Update for Windows XP (KB938464)
/ Windows XP / SP4: Security Update for Windows XP (KB950762)
/ Windows XP / SP4: Security Update for Windows XP (KB950974)
/ Windows XP / SP4: Security Update for Windows XP (KB951066)
/ Windows XP / SP4: Update for Windows XP (KB951072-v2)
/ Windows XP / SP4: Security Update for Windows XP (KB951376-v2)
/ Windows XP / SP4: Security Update for Windows XP (KB951698)
/ Windows XP / SP4: Security Update for Windows XP (KB951748)
/ Windows XP / SP4: Update for Windows XP (KB951978)
/ Windows XP / SP4: Security Update for Windows XP (KB952004)
/ Windows XP / SP4: Hotfix for Windows XP (KB952287)
/ Windows XP / SP4: Security Update for Windows XP (KB952954)
/ Windows XP / SP4: Security Update for Windows XP (KB953839)
/ Windows XP / SP4: Security Update for Windows XP (KB954211)
/ Windows XP / SP4: Security Update for Windows XP (KB954459)
/ Windows XP / SP4: Hotfix for Windows XP (KB954550-v5)
/ Windows XP / SP4: Security Update for Windows XP (KB954600)
/ Windows XP / SP4: Security Update for Windows XP (KB955069)
/ Windows XP / SP4: Update for Windows XP (KB955839)
/ Windows XP / SP4: Security Update for Windows XP (KB956391)
/ Windows XP / SP4: Security Update for Windows XP (KB956572)
/ Windows XP / SP4: Security Update for Windows XP (KB956802)
/ Windows XP / SP4: Security Update for Windows XP (KB956803)
/ Windows XP / SP4: Security Update for Windows XP (KB956841)
/ Windows XP / SP4: Security Update for Windows XP (KB957095)
/ Windows XP / SP4: Security Update for Windows XP (KB957097)
/ Windows XP / SP4: Security Update for Windows XP (KB958644)
/ Windows XP / SP4: Security Update for Windows XP (KB958687)
/ Windows XP / SP4: Security Update for Windows XP (KB958690)
/ Windows XP / SP4: Security Update for Windows XP (KB959426)
/ Windows XP / SP4: Security Update for Windows XP (KB960225)
/ Windows XP / SP4: Security Update for Windows XP (KB960715)
/ Windows XP / SP4: Security Update for Windows XP (KB960803)
/ Windows XP / SP4: Hotfix for Windows XP (KB961118)
/ Windows XP / SP4: Security Update for Windows XP (KB961371)
/ Windows XP / SP4: Security Update for Windows XP (KB961373)
/ Windows XP / SP4: Security Update for Windows XP (KB961501)
/ Windows XP / SP4: Update for Windows XP (KB967715)
/ Windows XP / SP4: Security Update for Windows XP (KB968537)
/ Windows XP / SP4: Security Update for Windows XP (KB969898)
/ Windows XP / SP4: Security Update for Windows XP (KB970238)
/ Windows XP / SP4: Security Update for Windows XP (KB971633)
/ Windows XP / SP4: Security Update for Windows XP (KB973346)
/ XML Paper Specification Shared Components Pack 1.0: XML Paper Specification Shared Components Pack 1.0
--- Startup entries list ---
Located: HK_LM:Run,
command:
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:Run, Acrobat Assistant 8.0
command: "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
file: C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
size: 624248
MD5: 4D042B1F1375CF371AFBE0E0276BA627
Located: HK_LM:Run, Adobe Reader Speed Launcher
command: "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
file: C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
size: 34672
MD5: 69B16C7B7746BA5C642FC05B3561FC73
Located: HK_LM:Run, Adobe_ID0EYTHM
command: C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
file: C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
size: 1884160
MD5: C1873D880786B6B03AF781E23835D925
Located: HK_LM:Run, Alcmtr
command: ALCMTR.EXE
file: C:\WINDOWS\ALCMTR.EXE
size: 69632
MD5: 8B4CBBA1EA526830C7F97E7822E2493A
Located: HK_LM:Run, ASUSGamerOSD
command: C:\Program Files\ASUS\GamerOSD\GamerOSD.exe
file: C:\Program Files\ASUS\GamerOSD\GamerOSD.exe
size: 380928
MD5: 3986FF03F6C3DD063D05B6193EA360FA
Located: HK_LM:Run, GrooveMonitor
command: "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
file: C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
size: 33648
MD5: 35DCD380D4D579D8B8EA91D5D8AE444C
Located: HK_LM:Run, Kernel and Hardware Abstraction Layer
command: KHALMNPR.EXE
file: C:\WINDOWS\KHALMNPR.EXE
size: 76304
MD5: E6A9F68D26A094FB78B98180A40A29FC
Located: HK_LM:Run, NBKeyScan
command: "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
file: C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
size: 2221352
MD5: DE9BD75FADB913F4E418CFBA381D7198
Located: HK_LM:Run, NeroFilterCheck
command: C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
file: C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
size: 570664
MD5: 925659214E5E6749C4B6B6E87B3A82D6
Located: HK_LM:Run, NvCplDaemon
command: RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
file: C:\WINDOWS\system32\NvCpl.dll
size: 13529088
MD5: 2C6E14603D984A9724AE7E6D037D4A6A
Located: HK_LM:Run, NvMediaCenter
command: RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
file: C:\WINDOWS\system32\NvMcTray.dll
size: 86016
MD5: BEAA778E2B6285E465143DD2519A75A5
Located: HK_LM:Run, nwiz
command: nwiz.exe /install
file: C:\WINDOWS\system32\nwiz.exe
size: 1630208
MD5: 03EAD6EC9D5D9D26A6845FAA35343889
Located: HK_LM:Run, RTHDCPL
command: RTHDCPL.EXE
file: C:\WINDOWS\RTHDCPL.EXE
size: 16857600
MD5: A6543BD31E3B48F70DA57FB01F13D934
Located: HK_LM:Run, SunJavaUpdateSched
command: "C:\Program Files\Java\jre6\bin\jusched.exe"
file: C:\Program Files\Java\jre6\bin\jusched.exe
size: 136600
MD5: B98FFA8288EFAABC436C30D198608345
Located: HK_LM:Run, UnlockerAssistant
command: "C:\Program Files\Unlocker\UnlockerAssistant.exe"
file: C:\Program Files\Unlocker\UnlockerAssistant.exe
size: 15872
MD5: 3FFE8752B77382C5050006C31781D05A
Located: HK_LM:Run, UserFaultCheck
command: %systemroot%\system32\dumprep 0 -u
file: C:\WINDOWS\system32\dumprep 0 -u
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:Run, WinampAgent
command: "C:\Program Files\Winamp\winampa.exe"
file: C:\Program Files\Winamp\winampa.exe
size: 36352
MD5: E7DEADB409CD8A4552C91ABF624F138F
Located: HK_LM:RunOnce, SpybotDeletingA2594
command: command.com /c del "C:\WINDOWS\system32\SKYNETlwpvruwk.dat_old"
file: command.com /c del "C:\WINDOWS\system32\SKYNETlwpvruwk.dat_old"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:RunOnce, SpybotDeletingA2730
command: command.com /c del "C:\WINDOWS\system32\SKYNETknbavmho.dll"
file: command.com /c del "C:\WINDOWS\system32\SKYNETknbavmho.dll"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:RunOnce, SpybotDeletingA2775
command: command.com /c del "C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys"
file: command.com /c del "C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:RunOnce, SpybotDeletingA2797
command: command.com /c del "C:\WINDOWS\system32\SKYNETqdeiqomq.dll"
file: command.com /c del "C:\WINDOWS\system32\SKYNETqdeiqomq.dll"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:RunOnce, SpybotDeletingA3415
command: command.com /c del "C:\WINDOWS\system32\SKYNETlwpvruwk.dat"
file: command.com /c del "C:\WINDOWS\system32\SKYNETlwpvruwk.dat"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:RunOnce, SpybotDeletingA4381
command: command.com /c del "C:\WINDOWS\system32\SKYNETknbavmho.dll"
file: command.com /c del "C:\WINDOWS\system32\SKYNETknbavmho.dll"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:RunOnce, SpybotDeletingA4430
command: command.com /c del "C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys"
file: command.com /c del "C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:RunOnce, SpybotDeletingA4440
command: command.com /c del "C:\WINDOWS\system32\SKYNETqdeiqomq.dll_old"
file: command.com /c del "C:\WINDOWS\system32\SKYNETqdeiqomq.dll_old"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:RunOnce, SpybotDeletingA515
command: command.com /c del "C:\WINDOWS\system32\SKYNETqdeiqomq.dll_old"
file: command.com /c del "C:\WINDOWS\system32\SKYNETqdeiqomq.dll_old"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:RunOnce, SpybotDeletingA5832
command: command.com /c del "C:\WINDOWS\system32\SKYNETlwpvruwk.dat_old"
file: command.com /c del "C:\WINDOWS\system32\SKYNETlwpvruwk.dat_old"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:RunOnce, SpybotDeletingA5927
command: command.com /c del "C:\WINDOWS\system32\SKYNETknbavmho.dll_old"
file: command.com /c del "C:\WINDOWS\system32\SKYNETknbavmho.dll_old"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:RunOnce, SpybotDeletingA6115
command: command.com /c del "C:\WINDOWS\system32\SKYNETksrteoaf.dat"
file: command.com /c del "C:\WINDOWS\system32\SKYNETksrteoaf.dat"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:RunOnce, SpybotDeletingA6138
command: command.com /c del "C:\WINDOWS\system32\SKYNETksrteoaf.dat_old"
file: command.com /c del "C:\WINDOWS\system32\SKYNETksrteoaf.dat_old"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:RunOnce, SpybotDeletingA7415
command: command.com /c del "C:\WINDOWS\system32\SKYNETlwpvruwk.dat"
file: command.com /c del "C:\WINDOWS\system32\SKYNETlwpvruwk.dat"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:RunOnce, SpybotDeletingA7613
command: command.com /c del "C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys_old"
file: command.com /c del "C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys_old"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:RunOnce, SpybotDeletingA7726
command: command.com /c del "C:\WINDOWS\system32\SKYNETksrteoaf.dat"
file: command.com /c del "C:\WINDOWS\system32\SKYNETksrteoaf.dat"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:RunOnce, SpybotDeletingA7792
command: command.com /c del "C:\WINDOWS\system32\SKYNETknbavmho.dll_old"
file: command.com /c del "C:\WINDOWS\system32\SKYNETknbavmho.dll_old"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:RunOnce, SpybotDeletingA796
command: command.com /c del "C:\WINDOWS\system32\SKYNETksrteoaf.dat_old"
file: command.com /c del "C:\WINDOWS\system32\SKYNETksrteoaf.dat_old"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:RunOnce, SpybotDeletingA8355
command: command.com /c del "C:\WINDOWS\system32\SKYNETqdeiqomq.dll"
file: command.com /c del "C:\WINDOWS\system32\SKYNETqdeiqomq.dll"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:RunOnce, SpybotDeletingA9586
command: command.com /c del "C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys_old"
file: command.com /c del "C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys_old"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:RunOnce, SpybotDeletingC112
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETksrteoaf.dat_old"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_LM:RunOnce, SpybotDeletingC1402
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETlwpvruwk.dat_old"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_LM:RunOnce, SpybotDeletingC1457
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETqdeiqomq.dll"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_LM:RunOnce, SpybotDeletingC1622
command: cmd.exe /c del "C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys_old"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_LM:RunOnce, SpybotDeletingC1976
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETqdeiqomq.dll"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_LM:RunOnce, SpybotDeletingC2245
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETqdeiqomq.dll_old"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_LM:RunOnce, SpybotDeletingC291
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETksrteoaf.dat"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_LM:RunOnce, SpybotDeletingC5003
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETknbavmho.dll"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_LM:RunOnce, SpybotDeletingC5242
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETlwpvruwk.dat_old"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_LM:RunOnce, SpybotDeletingC6167
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETksrteoaf.dat"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_LM:RunOnce, SpybotDeletingC6317
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETksrteoaf.dat_old"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_LM:RunOnce, SpybotDeletingC6442
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETlwpvruwk.dat"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_LM:RunOnce, SpybotDeletingC6457
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETqdeiqomq.dll_old"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_LM:RunOnce, SpybotDeletingC6808
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETknbavmho.dll_old"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_LM:RunOnce, SpybotDeletingC7088
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETknbavmho.dll_old"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_LM:RunOnce, SpybotDeletingC7531
command: cmd.exe /c del "C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_LM:RunOnce, SpybotDeletingC7569
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETknbavmho.dll"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_LM:RunOnce, SpybotDeletingC7710
command: cmd.exe /c del "C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_LM:RunOnce, SpybotDeletingC7743
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETlwpvruwk.dat"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_LM:RunOnce, SpybotDeletingC8079
command: cmd.exe /c del "C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys_old"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_CU:RunOnce, nltide_3
where: .DEFAULT...
command: rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N
file: C:\WINDOWS\system32\advpack.dll
size: 128512
MD5: 8FED1E0A491D4990853D23F21C59C730
Located: HK_CU:RunOnce, ShowDeskFix
where: .DEFAULT...
command: regsvr32 /s /n /i:u shell32
file: regsvr32 /s /n /i:u shell32
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:RunOnce, nltide_3
where: S-1-5-20...
command: rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N
file: C:\WINDOWS\system32\advpack.dll
size: 128512
MD5: 8FED1E0A491D4990853D23F21C59C730
Located: HK_CU:RunOnce, ShowDeskFix
where: S-1-5-20...
command: regsvr32 /s /n /i:u shell32
file: regsvr32 /s /n /i:u shell32
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:Run, Aim6
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
file: C:\Program Files\AIM6\aim6.exe
size: 49968
MD5: 5B4AF27E83DA8385A9B08E76DA730C91
Located: HK_CU:Run, Creative Detector U
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: "C:\Program Files\Creative\MediaSource5\CTDetctu.exe" /R
file: C:\Program Files\Creative\MediaSource5\CTDetctu.exe
size: 188416
MD5: 0BD5218D5A8C5598E75E8614938F9948
Located: HK_CU:Run, ctfmon.exe
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: C:\WINDOWS\system32\ctfmon.exe
file: C:\WINDOWS\system32\ctfmon.exe
size: 15360
MD5: 5F1D5F88303D4A4DBC8E5F97BA967CC3
Located: HK_CU:Run, IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
file: C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
size: 1840424
MD5: C44031488DED58FCE58E5D94BC345D30
Located: HK_CU:Run, SpybotSD TeaTimer
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
file: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
size: 2260480
MD5: 390679F7A217A5E73D756276C40AE887
Located: HK_CU:RunOnce, SpybotDeletingB1865
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: command.com /c del "C:\WINDOWS\system32\SKYNETqdeiqomq.dll_old"
file: command.com /c del "C:\WINDOWS\system32\SKYNETqdeiqomq.dll_old"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:RunOnce, SpybotDeletingB2372
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: command.com /c del "C:\WINDOWS\system32\SKYNETqdeiqomq.dll_old"
file: command.com /c del "C:\WINDOWS\system32\SKYNETqdeiqomq.dll_old"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:RunOnce, SpybotDeletingB2902
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: command.com /c del "C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys_old"
file: command.com /c del "C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys_old"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:RunOnce, SpybotDeletingB2981
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: command.com /c del "C:\WINDOWS\system32\SKYNETknbavmho.dll"
file: command.com /c del "C:\WINDOWS\system32\SKYNETknbavmho.dll"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:RunOnce, SpybotDeletingB2982
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: command.com /c del "C:\WINDOWS\system32\SKYNETksrteoaf.dat"
file: command.com /c del "C:\WINDOWS\system32\SKYNETksrteoaf.dat"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:RunOnce, SpybotDeletingB4035
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: command.com /c del "C:\WINDOWS\system32\SKYNETlwpvruwk.dat_old"
file: command.com /c del "C:\WINDOWS\system32\SKYNETlwpvruwk.dat_old"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:RunOnce, SpybotDeletingB466
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: command.com /c del "C:\WINDOWS\system32\SKYNETlwpvruwk.dat_old"
file: command.com /c del "C:\WINDOWS\system32\SKYNETlwpvruwk.dat_old"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:RunOnce, SpybotDeletingB4908
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: command.com /c del "C:\WINDOWS\system32\SKYNETqdeiqomq.dll"
file: command.com /c del "C:\WINDOWS\system32\SKYNETqdeiqomq.dll"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:RunOnce, SpybotDeletingB5805
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: command.com /c del "C:\WINDOWS\system32\SKYNETknbavmho.dll"
file: command.com /c del "C:\WINDOWS\system32\SKYNETknbavmho.dll"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:RunOnce, SpybotDeletingB6431
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: command.com /c del "C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys"
file: command.com /c del "C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:RunOnce, SpybotDeletingB6849
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: command.com /c del "C:\WINDOWS\system32\SKYNETqdeiqomq.dll"
file: command.com /c del "C:\WINDOWS\system32\SKYNETqdeiqomq.dll"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:RunOnce, SpybotDeletingB7485
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: command.com /c del "C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys"
file: command.com /c del "C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:RunOnce, SpybotDeletingB7906
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: command.com /c del "C:\WINDOWS\system32\SKYNETknbavmho.dll_old"
file: command.com /c del "C:\WINDOWS\system32\SKYNETknbavmho.dll_old"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:RunOnce, SpybotDeletingB7932
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: command.com /c del "C:\WINDOWS\system32\SKYNETlwpvruwk.dat"
file: command.com /c del "C:\WINDOWS\system32\SKYNETlwpvruwk.dat"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:RunOnce, SpybotDeletingB8298
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: command.com /c del "C:\WINDOWS\system32\SKYNETknbavmho.dll_old"
file: command.com /c del "C:\WINDOWS\system32\SKYNETknbavmho.dll_old"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:RunOnce, SpybotDeletingB8460
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: command.com /c del "C:\WINDOWS\system32\SKYNETlwpvruwk.dat"
file: command.com /c del "C:\WINDOWS\system32\SKYNETlwpvruwk.dat"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:RunOnce, SpybotDeletingB9225
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: command.com /c del "C:\WINDOWS\system32\SKYNETksrteoaf.dat_old"
file: command.com /c del "C:\WINDOWS\system32\SKYNETksrteoaf.dat_old"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:RunOnce, SpybotDeletingB9708
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: command.com /c del "C:\WINDOWS\system32\SKYNETksrteoaf.dat_old"
file: command.com /c del "C:\WINDOWS\system32\SKYNETksrteoaf.dat_old"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:RunOnce, SpybotDeletingB9867
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: command.com /c del "C:\WINDOWS\system32\SKYNETksrteoaf.dat"
file: command.com /c del "C:\WINDOWS\system32\SKYNETksrteoaf.dat"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:RunOnce, SpybotDeletingB9997
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: command.com /c del "C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys_old"
file: command.com /c del "C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys_old"
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:RunOnce, SpybotDeletingD1488
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETlwpvruwk.dat_old"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_CU:RunOnce, SpybotDeletingD1624
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: cmd.exe /c del "C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys_old"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_CU:RunOnce, SpybotDeletingD2033
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETlwpvruwk.dat"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_CU:RunOnce, SpybotDeletingD2319
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETqdeiqomq.dll_old"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_CU:RunOnce, SpybotDeletingD255
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETknbavmho.dll_old"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_CU:RunOnce, SpybotDeletingD2679
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETqdeiqomq.dll_old"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_CU:RunOnce, SpybotDeletingD3100
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETknbavmho.dll"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_CU:RunOnce, SpybotDeletingD3112
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETknbavmho.dll_old"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_CU:RunOnce, SpybotDeletingD3392
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETknbavmho.dll"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_CU:RunOnce, SpybotDeletingD4267
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: cmd.exe /c del "C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys_old"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_CU:RunOnce, SpybotDeletingD483
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETksrteoaf.dat"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_CU:RunOnce, SpybotDeletingD5113
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETqdeiqomq.dll"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_CU:RunOnce, SpybotDeletingD6523
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETqdeiqomq.dll"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_CU:RunOnce, SpybotDeletingD6549
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETksrteoaf.dat_old"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_CU:RunOnce, SpybotDeletingD6773
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: cmd.exe /c del "C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_CU:RunOnce, SpybotDeletingD7026
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETksrteoaf.dat_old"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_CU:RunOnce, SpybotDeletingD7882
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETlwpvruwk.dat"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_CU:RunOnce, SpybotDeletingD809
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETksrteoaf.dat"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_CU:RunOnce, SpybotDeletingD9122
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: cmd.exe /c del "C:\WINDOWS\system32\drivers\SKYNETbwpwcmqi.sys"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_CU:RunOnce, SpybotDeletingD9308
where: S-1-5-21-854245398-1500820517-682003330-1004...
command: cmd.exe /c del "C:\WINDOWS\system32\SKYNETlwpvruwk.dat_old"
file: C:\WINDOWS\system32\cmd.exe
size: 389120
MD5: 6D778E0F95447E6546553EEEA709D03C
Located: HK_CU:RunOnce, nltide_3
where: S-1-5-18...
command: rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N
file: C:\WINDOWS\system32\advpack.dll
size: 128512
MD5: 8FED1E0A491D4990853D23F21C59C730
Located: HK_CU:RunOnce, ShowDeskFix
where: S-1-5-18...
command: regsvr32 /s /n /i:u shell32
file: regsvr32 /s /n /i:u shell32
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: Startup (common), Logitech SetPoint.lnk
where: C:\Documents and Settings\All Users\Start Menu\Programs\Startup...
command: C:\Program Files\Logitech\SetPoint\SetPoint.exe
file: C:\Program Files\Logitech\SetPoint\SetPoint.exe
size: 805392
MD5: D0948BE9B3547B9669195D7F84FC09F7
Located: Startup (user), Styler.lnk
where: C:\Documents and Settings\Joshua\Start Menu\Programs\Startup...
command: C:\Documents and Settings\Joshua\Application Data\Microsoft\Installer\{E9ECF354-2422-4FDB-9ABF-D8ADAC0EF941}\_585b207a.exe
file: C:\Documents and Settings\Joshua\Application Data\Microsoft\Installer\{E9ECF354-2422-4FDB-9ABF-D8ADAC0EF941}\_585b207a.exe
size: 15086
MD5: 8588D2403599C1E7D1F6C9EA458CEB39
Located: Startup (disabled), OneNote 2007 Screen Clipper and Launcher (DISABLED)
command: C:\PROGRA~1\MICROS~2\Office12\ONENOTEM.EXE /tsr
file: C:\PROGRA~1\MICROS~2\Office12\ONENOTEM.EXE
size: 101440
MD5: 9D0EEBDA40D5C33BC63FB8BB984F7681
Located: WinLogon, avgrsstarter
command: avgrsstx.dll
file: avgrsstx.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, crypt32chain
command: crypt32.dll
file: crypt32.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, cryptnet
command: cryptnet.dll
file: cryptnet.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, cscdll
command: cscdll.dll
file: cscdll.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, dimsntfy
command: %SystemRoot%\System32\dimsntfy.dll
file: %SystemRoot%\System32\dimsntfy.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, LBTWlgn
command: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
file: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
size: 72208
MD5: 2ACBFEF9984F0FE9849DA857206CCECC
Located: WinLogon, ScCertProp
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, Schedule
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, sclgntfy
command: sclgntfy.dll
file: sclgntfy.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, SensLogn
command: WlNotify.dll
file: WlNotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, termsrv
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, WgaLogon
command: WgaLogon.dll
file: WgaLogon.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, wlballoon
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
--- Browser helper object list ---
{074C1DC5-9320-4A9A-947D-C042949C6216} (ContributeBHO Class)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: ContributeBHO Class
Path: C:\Program Files\Adobe\
Long name: contributeieplugin.dll
Short name: CONTRI~1.DLL
Date (created): 3/16/2007 3:13:06 PM
Date (last access): 8/9/2009 3:42:56 PM
Date (last write): 3/16/2007 3:13:06 PM
Filesize: 118784
Attributes: archive
MD5: E23691A98928CE49586753982B8402A2
CRC32: 2CAFCB5A
Version: 1.0.0.0
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} (AcroIEHelperStub)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name: AcroIEHelperStub
CLSID name: Adobe PDF Link Helper
Path: C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\
Long name: AcroIEHelperShim.dll
Short name: ACROIE~2.DLL
Date (created): 6/11/2008 11:33:16 PM
Date (last access): 8/9/2009 3:39:48 PM
Date (last write): 6/11/2008 11:33:16 PM
Filesize: 75128
Attributes: archive
MD5: E96C752BBA0E22330A43258FC800200E
CRC32: E5D72083
Version: 9.0.0.332
{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} (WormRadar.com IESiteBlocker.NavFilter)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name: WormRadar.com IESiteBlocker.NavFilter
CLSID name: AVG Safe Search
Path: C:\Program Files\AVG\AVG8\
Long name: avgssie.dll
Short name:
Date (created): 2/4/2009 10:21:00 AM
Date (last access): 8/9/2009 4:15:10 PM
Date (last write): 7/19/2009 11:43:04 PM
Filesize: 1111320
Attributes: archive
MD5: A8F964A2FB9400B81E1483AA5A8B39F5
CRC32: E3F2A2F4
Version: 8.5.0.392
{72853161-30C5-4D22-B7F9-0BBC1D38A37E} (Groove GFS Browser Helper)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: Groove GFS Browser Helper
Path: C:\Program Files\Microsoft Office\Office12\
Long name: GrooveShellExtensions.dll
Short name: GRA8E1~1.DLL
Date (created): 8/24/2007 8:01:22 AM
Date (last access): 8/9/2009 4:12:24 PM
Date (last write): 8/24/2007 8:01:22 AM
Filesize: 2212224
Attributes: archive
MD5: 32C4927E013C018A13D8DFBDA4148812
CRC32: 9A9F3D8B
Version: 12.0.6211.1000
{b0cda128-b425-4eef-a174-61a11ac5dbf8} (AIM Toolbar Loader)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name: AIM Toolbar Loader
CLSID name: AIM Toolbar Loader
Path: C:\Program Files\AIM Toolbar\
Long name: aimtb.dll
Short name:
Date (created): 5/6/2009 11:14:26 AM
Date (last access): 8/9/2009 4:15:10 PM
Date (last write): 5/6/2009 11:14:26 AM
Filesize: 1279272
Attributes: archive
MD5: 4BD0311F7E4F1A6010CCC1D263128443
CRC32: 71974D6A
Version: 5.25.24.1
{DBC80044-A445-435b-BC74-9C25C1C588A9} (Java(tm) Plug-In 2 SSV Helper)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: Java(tm) Plug-In 2 SSV Helper
Path: C:\Program Files\Java\jre6\bin\
Long name: jp2ssv.dll
Short name:
Date (created): 12/27/2008 9:40:58 PM
Date (last access): 8/9/2009 3:49:10 PM
Date (last write): 12/27/2008 9:40:58 PM
Filesize: 34816
Attributes: archive
MD5: 5D57FD3DF32DC69CEC3D1D54B4C43162
CRC32: D7C13FB2
Version: 6.0.110.3
{E7E6F031-17CE-4C07-BC86-EABFE594F69C} (JQSIEStartDetectorImpl)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name: JQSIEStartDetectorImpl
CLSID name: JQSIEStartDetectorImpl Class
Path: C:\Program Files\Java\jre6\lib\deploy\jqs\ie\
Long name: jqs_plugin.dll
Short name: JQS_PL~1.DLL
Date (created): 12/27/2008 9:41:02 PM
Date (last access): 8/9/2009 3:49:10 PM
Date (last write): 12/27/2008 9:41:02 PM
Filesize: 73728
Attributes: archive
MD5: F68EDAFE003F2B3523C0742CD3B8D673
CRC32: 9C709350
Version: 6.0.110.3
--- ActiveX list ---
{8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0)
DPF name: Java Runtime Environment 1.6.0
CLSID name: Java Plug-in 1.6.0_11
Installer:
Codebase: http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
description: Sun Java
classification: Legitimate
known filename: %PROGRAM FILES%\JabaSoft\JRE\*\Bin\npjava131.dll
info link:
info source: Patrick M. Kolla
Path: C:\Program Files\Java\jre6\bin\
Long name: npjpi160_11.dll
Short name: NPJPI1~1.DLL
Date (created): 12/27/2008 9:41:00 PM
Date (last access): 8/9/2009 2:47:20 PM
Date (last write): 12/27/2008 9:41:00 PM
Filesize: 132504
Attributes: archive
MD5: D400116F6776ACB6EDB6B1F5EEB9F92D
CRC32: CECB5751
Version: 6.0.110.3
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C} ()
DPF name:
CLSID name:
Installer: C:\WINDOWS\Downloaded Program Files\erma.inf
Codebase: http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
description:
classification: Open for discussion
known filename:
info link:
info source: Safer Networking Ltd.
{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
DPF name: Java Runtime Environment 1.6.0
CLSID name: Java Plug-in 1.6.0_06
Installer:
Codebase: http://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
Path: C:\Program Files\Java\jre1.6.0_06\bin\
Long name: npjpi160_06.dll
Short name: NPJPI1~1.DLL
Date (created): 3/25/2008 2:37:02 AM
Date (last access): 8/9/2009 2:47:00 PM
Date (last write): 3/25/2008 4:28:02 AM
Filesize: 132496
Attributes: archive
MD5: 5522AFEAB77DD6D401F3FE5C0A46122E
CRC32: F643B062
Version: 6.0.60.2
{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
DPF name: Java Runtime Environment 1.6.0
CLSID name: Java Plug-in 1.6.0_07
Installer:
Codebase: http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
Path: C:\Program Files\Java\jre1.6.0_07\bin\
Long name: npjpi160_07.dll
Short name: NPJPI1~1.DLL
Date (created): 6/10/2008 3:32:34 AM
Date (last access): 8/9/2009 2:47:10 PM
Date (last write): 6/10/2008 5:27:02 AM
Filesize: 132496
Attributes: archive
MD5: 7C83A2809E13950359189767AC9D5DB8
CRC32: 925C2A88
Version: 6.0.70.6
{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
DPF name: Java Runtime Environment 1.6.0
CLSID name: Java Plug-in 1.6.0_11
Installer:
Codebase: http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
Path: C:\Program Files\Java\jre6\bin\
Long name: npjpi160_11.dll
Short name: NPJPI1~1.DLL
Date (created): 12/27/2008 9:41:00 PM
Date (last access): 8/9/2009 4:36:10 PM
Date (last write): 12/27/2008 9:41:00 PM
Filesize: 132504
Attributes: archive
MD5: D400116F6776ACB6EDB6B1F5EEB9F92D
CRC32: CECB5751
Version: 6.0.110.3
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
DPF name: Java Runtime Environment 1.6.0
CLSID name: Java Plug-in 1.6.0_11
Installer:
Codebase: http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
description:
classification: Legitimate
known filename: npjpi150_06.dll
info link:
info source: Safer Networking Ltd.
Path: C:\Program Files\Java\jre6\bin\
Long name: npjpi160_11.dll
Short name: NPJPI1~1.DLL
Date (created): 12/27/2008 9:41:00 PM
Date (last access): 8/9/2009 4:36:10 PM
Date (last write): 12/27/2008 9:41:00 PM
Filesize: 132504
Attributes: archive
MD5: D400116F6776ACB6EDB6B1F5EEB9F92D
CRC32: CECB5751
Version: 6.0.110.3
--- Process list ---
PID: 0 ( 0) [System]
PID: 812 ( 4) \SystemRoot\System32\smss.exe
size: 50688
PID: 868 ( 812) \??\C:\WINDOWS\system32\csrss.exe
size: 6144
PID: 892 ( 812) \??\C:\WINDOWS\system32\winlogon.exe
size: 507904
PID: 940 ( 892) C:\WINDOWS\system32\services.exe
size: 110592
MD5: 65DF52F5B8B6E9BBD183505225C37315
PID: 952 ( 892) C:\WINDOWS\system32\lsass.exe
size: 13312
MD5: BF2466B3E18E970D8A976FB95FC1CA85
PID: 1100 ( 940) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 1212 ( 940) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 1268 ( 940) C:\WINDOWS\System32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 1316 ( 940) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 1460 ( 940) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 1540 ( 940) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 1880 ( 940) C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
size: 611664
MD5: 17067069B9A7865028C1F2E6971D0CCC
PID: 2044 ( 940) C:\WINDOWS\system32\spoolsv.exe
size: 57856
MD5: D8E14A61ACC1D4A6CD0D38AEBAC7FA3B
PID: 560 ( 440) C:\WINDOWS\Explorer.EXE
size: 1033728
MD5: 12896823FB95BFB3DC9B46BCAEDC9923
PID: 248 ( 560) C:\Program Files\Unlocker\UnlockerAssistant.exe
size: 15872
MD5: 3FFE8752B77382C5050006C31781D05A
PID: 628 ( 560) C:\Program Files\Java\jre6\bin\jusched.exe
size: 136600
MD5: B98FFA8288EFAABC436C30D198608345
PID: 644 ( 560) C:\WINDOWS\RTHDCPL.EXE
size: 16857600
MD5: A6543BD31E3B48F70DA57FB01F13D934
PID: 692 ( 560) C:\WINDOWS\system32\RUNDLL32.EXE
size: 33280
MD5: 037B1E7798960E0420003D05BB577EE6
PID: 720 ( 560) C:\Program Files\ASUS\GamerOSD\GamerOSD.exe
size: 380928
MD5: 3986FF03F6C3DD063D05B6193EA360FA
PID: 832 ( 560) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
size: 33648
MD5: 35DCD380D4D579D8B8EA91D5D8AE444C
PID: 1012 ( 940) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 1160 ( 560) C:\Program Files\Winamp\winampa.exe
size: 36352
MD5: E7DEADB409CD8A4552C91ABF624F138F
PID: 1412 ( 940) C:\WINDOWS\ATKKBService.exe
size: 262144
MD5: DF70303547E59F09DCD32983100EDCD1
PID: 1408 ( 560) C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
size: 624248
MD5: 4D042B1F1375CF371AFBE0E0276BA627
PID: 1452 ( 940) C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
size: 298776
MD5: BFC093C2DDDE8FCE5DA078E663B4515B
PID: 1552 ( 560) C:\WINDOWS\system32\ctfmon.exe
size: 15360
MD5: 5F1D5F88303D4A4DBC8E5F97BA967CC3
PID: 1064 ( 560) C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
size: 2260480
MD5: 390679F7A217A5E73D756276C40AE887
PID: 1628 ( 940) C:\Program Files\Bonjour\mDNSResponder.exe
size: 229376
MD5: 73686FE0B2E0469F89FD2075BE724704
PID: 1632 ( 560) C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
size: 1840424
MD5: C44031488DED58FCE58E5D94BC345D30
PID: 1676 ( 560) C:\Program Files\Creative\MediaSource5\CTDetctu.exe
size: 188416
MD5: 0BD5218D5A8C5598E75E8614938F9948
PID: 1704 ( 940) C:\WINDOWS\system32\CTsvcCDA.exe
size: 44032
MD5: 3C8B6609712F4FF78E521F6DCFC4032B
PID: 1960 ( 940) C:\Program Files\Java\jre6\bin\jqs.exe
size: 152984
MD5: 32192B4EBE8720ED8D49A455C962CB91
PID: 1956 ( 940) C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
size: 877864
MD5: 2AAE889742376EDC5C3203DFB74F28FD
PID: 360 ( 560) C:\Program Files\Logitech\SetPoint\SetPoint.exe
size: 805392
MD5: D0948BE9B3547B9669195D7F84FC09F7
PID: 728 ( 560) C:\Program Files\Styler\Styler.exe
size: 307200
MD5: D68AE8C031B370538F917AF176A947F6
PID: 1800 ( 940) C:\WINDOWS\system32\nvsvc32.exe
size: 159812
MD5: 93972E943623635A47DC33D312B6A378
PID: 1840 (1452) C:\Program Files\AVG\AVG8\avgrsx.exe
size: 486680
MD5: 95E1D555542D5F6031E756751C6FF3F4
PID: 2124 ( 360) C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
size: 76304
MD5: 19E0D28FE38F55CA4C63F77D3657959A
PID: 2156 ( 940) C:\WINDOWS\system32\IoctlSvc.exe
size: 81920
MD5: 875E4E0661F3A5994DF9E5E3A0A4F96B
PID: 2264 ( 940) C:\WINDOWS\system32\PnkBstrA.exe
size: 75064
MD5: A1DD33D16F277CE34124EE52AB2C0F14
PID: 2396 ( 940) C:\WINDOWS\system32\PnkBstrB.exe
size: 189104
MD5: 10652913B563B6376B5C25DB63FA72E3
PID: 2464 ( 940) C:\Program Files\Viewpoint\Common\ViewpointService.exe
size: 24652
MD5: 5F974FDE801C73952770736BECDE11E7
PID: 3148 ( 940) C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
size: 537896
MD5: CB992AE1506985D9167E85883B4C3240
PID: 3236 ( 940) C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
size: 654848
MD5: 227846995AFEEFA70D328BF5334A86A5
PID: 3764 ( 940) C:\WINDOWS\System32\alg.exe
size: 44544
MD5: 8C515081584A38AA007909CD02020B3D
PID: 2744 ( 560) C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
size: 5365592
MD5: 0477C2F9171599CA5BC3307FDFBA8D89
PID: 3260 ( 560) C:\Program Files\Mozilla Firefox\firefox.exe
size: 307704
MD5: 457441B04089CF16784D698B4B4EA8AF
PID: 4 ( 0) System