Need help with virus that takes over admin powers
urbane New Member Date Joined Nov 2009 Total Posts : 30 Posted 11-21-2009 7:38 (GMT +2) Ok I have some bizarre virus that has these properties * Disables both Task Manager and Regedit * Does not allow me to get into Safe Mode (either get blue screen or comp just restarts) * The virus always comes back even after format! * Using a VBS file or whatever to remove registry values such as disable task manger and disable reg edit is useless because the second they get removed, they come back again. Though I have just enough time to open task manager... not much seems out of order in processes * I cannot use gpedit.msc, dunno if it is my old version of windows or the virus causing that. * I cannot open many things with the virus active (Yahoo, Raid service, MSN, Spybot, malware bytes etc all get the message "has encountered a problem and needs to close. We are sorry for the inconvenience) * The virus seems to malfunction when I use msconfig and use diagnostic start up (ei When I delete the disable task manager values in regedit, they don't come back while in diagnostic start up). This makes me beleive it is a running service or start up that is causing the problems I have 3 hard drives btw, all has been formatted (c:, d: and e:). I have beaten a lot of virus before but this one has me stumped, I dunno what to do. It is my first time here so please forgive me if I have done anything wrong. What should I do? Back to Top
Jintan Senior Member Date Joined Dec 2006 Total Posts : 1424 Posted 11-22-2009 3:35 (GMT +2) Welcome to BG forums urbane, Infection that returns even after a reformat suggests an autorun worm, that has infected some external drive you use (including usb/flash/thumb etc.). Once any infected drive is returned to the computer it infects it anew. Let's get some details and take a look. The malware has included an autorun type component, so if any external drives have been used on this computer recently be sure to install them now, and leave them installed until ALL repairs on it are completed. If not, they will remain infected and can re-infect the computer (or others). To keep them from interfering with the repairs, be sure to temporarily disable all antivirus/anti-spyware softwares while these steps are being completed. This can usually be done through right clicking the software's Taskbar icons, or accessing each software through Start - Programs.[Version] Signature="$Windows NT$" [DefaultInstall] DelReg=RemoveRestrictions AddReg=ResetRegChanges [ResetRegChanges] HKCU,Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced,Start_ShowControlPanel,0x10001,0x00000002 HKCU,Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced,Start_ShowHelp,0x10001,0x00000001 HKCU,Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced,Start_ShowMyComputer,0x10001,0x00000002 HKCU,Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced,Start_ShowMyDocs,0x10001,0x00000001 HKCU,Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced,Start_ShowMyMusic,0x10001,0x00000001 HKCU,Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced,Start_ShowMyPics,0x10001,0x00000001 HKCU,Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced,Start_ShowNetPlaces,0x10001,0x00000001 HKCU,Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced,Start_ShowRun,0x10001,0x00000001 HKCU,Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced,Start_ShowSearch,0x10001,0x00000001 HKCU,Software\Microsoft\Windows\CurrentVersion\Policies\Explorer,NoDrives,0x10001,0x00000000 [RemoveRestrictions] HKCU, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer","NoSetFolders" HKLM, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer","NoSetFolders" HKCU, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer","NoStartMenuMorePrograms" HKLM, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer","NoStartMenuMorePrograms" HKCU, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer","NoToolbarCustomize" HKLM, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer","NoToolbarCustomize" HKCU, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer","StartMenuLogoff" HKLM, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer","StartMenuLogoff" HKCU, "Software\Microsoft\Windows\CurrentVersion\Policies\System","DisableCMD" HKLM, "Software\Microsoft\Windows\CurrentVersion\Policies\System","DisableCMD" HKCU, "Software\Microsoft\Windows\CurrentVersion\Policies\System","DisableRegistryTools" HKLM, "Software\Microsoft\Windows\CurrentVersion\Policies\System","DisableRegistryTools" HKCU, "Software\Microsoft\Windows\CurrentVersion\Policies\System","DisableTaskMgr" HKLM, "Software\Microsoft\Windows\CurrentVersion\Policies\System","DisableTaskMgr" HKCU, "Software\Microsoft\Windows\CurrentVersion\Policies\System","NoDispCPL" HKLM, "Software\Microsoft\Windows\CurrentVersion\Policies\System","NoDispCPL" HKCU, "Software\Microsoft\Windows\CurrentVersion\Policies\System","NoDispBackgroundPage" HKLM, "Software\Microsoft\Windows\CurrentVersion\Policies\System","NoDispBackgroundPage" HKCU, "Software\Microsoft\Windows\CurrentVersion\Policies\System","NoDispScrSavPage" HKLM, "Software\Microsoft\Windows\CurrentVersion\Policies\System","NoDispScrSavPage" HKCU, "Software\Policies\Microsoft\Internet Explorer\Restrictions","NoBrowserOptions" HKLM, "Software\Policies\Microsoft\Internet Explorer\Restrictions","NoBrowserOptions" HKCU, "Software\Policies\Microsoft\Windows\system","DisableCMD" HKLM, "Software\Policies\Microsoft\Windows\system","DisableCMD"
Open Notepad (Start - Run, type Notepad then press OK), and copy the text inside the Code box above and paste it into the open Notepad textbox. Save this to your desktop as correct.inf Be sure to include the "" quotes in the name. Then right-click on correct.inf and select Install. This may provide some Task Manager and other access improvements there. You can rerun this as needed for now. --------------- Download RSIT (random's system information tool) from here to your desktop. Then click on the RSIT.exe to open the RSIT display, and click the Continue button. If necessary allow it to locate or download a copy of HijackThis as needed. Once the scan completes a textbox will open - copy/paste those contents here for review please. The log can also be found at C:\rsit\log.txt.RSIT will also create a second log , info.txt, which will be minimized to your taskbar. Post that here as well please (it will also be stored at C:\rsit\info.txt). You can break logs into parts and use separate posts here when replying and posting the log files, if needed.
Click here and help my friend help stop leukemia, lymphoma, Hodgkin lymphoma and myeloma from taking more lives. Back to Top
urbane New Member Date Joined Nov 2009 Total Posts : 30 Posted 11-22-2009 9:09 (GMT +2) The INF folder allows me 0.1 seconds to hit ctrl alt delete, if i dont then task manager disabled again lol. My logs is a lot of info. I accidentally closed the second log info.txt and i cant get it back. Here is the first log Logfile of random's system information tool 1.06 (written by random/random) Run by Owner at 2009-11-22 17:56:46 Microsoft Windows XP Home Edition Service Pack 2 System drive C: has 55 GB (72%) free of 76 GB Total RAM: 2047 MB (77% free) Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 5:56:46 PM, on 11/22/2009 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\explorer.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\taskmgr.exe C:\Documents and Settings\Owner\Desktop\RSIT.exe C:\Program Files\trend micro\Owner.exe R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file) O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet O4 - HKLM\..\Run: [NVRaidService] C:\WINDOWS\system32\nvraidservice.exe O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [D-Link D-Link Wireless G DWA-110] C:\Program Files\D-Link\D-Link Wireless G DWA-110\AirGCFG.exe O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe" -quiet O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Wireless Service - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Sony Ericsson OMSI download service (OMSI download service) - Unknown owner - C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe -- End of file - 2801 bytes ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}] Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "Malwarebytes Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2009-09-10 1385808] "SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2004-11-15 155648] "nwiz"=nwiz.exe /installquiet [] "NVRaidService"=C:\WINDOWS\system32\nvraidservice.exe [2004-11-02 166400] "NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2004-11-15 86016] "NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2004-11-15 4620288] "D-Link D-Link Wireless G DWA-110"=C:\Program Files\D-Link\D-Link Wireless G DWA-110\AirGCFG.exe [2007-05-04 1736704] "ANIWZCS2Service"=C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe [2007-01-19 131072] "Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-10-03 113520] "Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-09-04 1009016] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Messenger (Yahoo!)"=C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe [2009-11-10 5317944] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableTaskMgr"=1 "DisableRegistryTools"=1 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 "EnableLUA"=0 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoDriveTypeAutoRun"=145 "NoDrives"=0 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\Documents and Settings\Owner\Desktop\Firefox Setup 3.5.5.exe"="C:\Documents and Settings\Owner\Desktop\Firefox Setup 3.5.5.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\nfar.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\nfar.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\xpjpt.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\xpjpt.exe:*:Enabled:ipsec" "C:\WINDOWS\system32\wscntfy.exe"="C:\WINDOWS\system32\wscntfy.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\winbqqft.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winbqqft.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\obpmv.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\obpmv.exe:*:Enabled:ipsec" "C:\WINDOWS\system32\DllHost.exe"="C:\WINDOWS\system32\DllHost.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\wincucadj.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\wincucadj.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\vsnp.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\vsnp.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\winkgacr.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winkgacr.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\epfoo.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\epfoo.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\ranjd.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\ranjd.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\winlwesrk.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winlwesrk.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\xgqsjp.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\xgqsjp.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\dslrc.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\dslrc.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\winpaglux.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winpaglux.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\wineryhy.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\wineryhy.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\winkstil.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winkstil.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\winnrgaa.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winnrgaa.exe:*:Enabled:ipsec" "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger" "C:\DOCUME~1\Owner\LOCALS~1\Temp\winudpi.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winudpi.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\fwqvh.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\fwqvh.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\winyfhxw.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winyfhxw.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\winlvksf.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winlvksf.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\jnvky.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\jnvky.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\winnlycq.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winnlycq.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\windsttv.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\windsttv.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\winwoeivm.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winwoeivm.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\winomhryb.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winomhryb.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\winuwup.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winuwup.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\winfogs.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winfogs.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\delj.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\delj.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\xtus.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\xtus.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\vrfwc.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\vrfwc.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\wxar.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\wxar.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\winvoksk.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winvoksk.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\wbpl.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\wbpl.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\wineyjxd.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\wineyjxd.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\winlfxo.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winlfxo.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\winjjco.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winjjco.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\wincefjy.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\wincefjy.exe:*:Enabled:ipsec" "C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe"="C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe:*:Enabled:ipsec" "C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe"="C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\winyhgce.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winyhgce.exe:*:Enabled:ipsec" "C:\SamRO\RO\VanRO.exe"="C:\SamRO\RO\VanRO.exe:*:Enabled:ipsec" "C:\WINDOWS\system32\taskmgr.exe"="C:\WINDOWS\system32\taskmgr.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\winktolbk.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winktolbk.exe:*:Enabled:ipsec" "C:\Program Files\D-Link\D-Link Wireless G DWA-110\AirGCFG.exe"="C:\Program Files\D-Link\D-Link Wireless G DWA-110\AirGCFG.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\lmtey.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\lmtey.exe:*:Enabled:ipsec" "D:\My Documents\VanRO\RO\VanRO.exe"="D:\My Documents\VanRO\RO\VanRO.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\winwblb.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winwblb.exe:*:Enabled:ipsec" "C:\WINDOWS\explorer.exe"="C:\WINDOWS\explorer.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\winxcqanp.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winxcqanp.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\winqlqhyo.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winqlqhyo.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\pjamp.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\pjamp.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\wingniq.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\wingniq.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\windxfik.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\windxfik.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\cqexd.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\cqexd.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\yfey.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\yfey.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\iime.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\iime.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\xdvjfp.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\xdvjfp.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\winvxakgt.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winvxakgt.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\qqfki.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\qqfki.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\winbeega.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winbeega.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\winrkyjiw.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winrkyjiw.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\winomcfmm.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winomcfmm.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\winspybl.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winspybl.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\winhjmks.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winhjmks.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\winmjllk.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winmjllk.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\winyyhdou.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winyyhdou.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\winqowk.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winqowk.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\nxffp.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\nxffp.exe:*:Enabled:ipsec" "C:\WINDOWS\SOUNDMAN.EXE"="C:\WINDOWS\SOUNDMAN.EXE:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\winkrpmd.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winkrpmd.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\winmiyriv.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winmiyriv.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\winmgplpi.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winmgplpi.exe:*:Enabled:ipsec" "C:\SamRO\RO\SamRO.exe"="C:\SamRO\RO\SamRO.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\gcpid.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\gcpid.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\winjbxov.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winjbxov.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\winacrpkd.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winacrpkd.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\winkluqd.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winkluqd.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\cmvu.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\cmvu.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\winpalh.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winpalh.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\rmftc.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\rmftc.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\pusuu.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\pusuu.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\wincbrjrm.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\wincbrjrm.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\onxjo.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\onxjo.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\lyphqq.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\lyphqq.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\cdkpmp.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\cdkpmp.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\winvrlvh.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winvrlvh.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\bmnwgu.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\bmnwgu.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\yjxqv.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\yjxqv.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\rxyb.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\rxyb.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\winhvnm.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winhvnm.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\winbolo.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winbolo.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\winiqvfxo.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winiqvfxo.exe:*:Enabled:ipsec" "C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\winlgusds.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winlgusds.exe:*:Enabled:ipsec" "C:\DOCUME~1\Owner\LOCALS~1\Temp\uvyiew.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\uvyiew.exe:*:Enabled:ipsec" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f1c5b506-d4cd-11de-a144-806d6172696f}] shell\AutoRun\command - E:\autorun.exe ======List of files/folders created in the last 1 months====== 2009-11-22 17:56:07 ----D---- C:\rsit 2009-11-22 17:56:07 ----D---- C:\Program Files\trend micro 2009-11-21 04:52:20 ----DC---- C:\WINDOWS\system32\DRVSTORE 2009-11-21 04:52:19 ----A---- C:\Documents and Settings\All Users\Application Data\hpeED.dll 2009-11-21 04:52:13 ----D---- C:\Program Files\Sony Ericsson 2009-11-21 04:52:13 ----D---- C:\Documents and Settings\All Users\Application Data\Sony Ericsson 2009-11-20 19:25:04 ----D---- C:\Documents and Settings\Owner\Application Data\vlc 2009-11-20 19:24:21 ----D---- C:\Program Files\VideoLAN 2009-11-20 18:16:05 ----D---- C:\SamRO 2009-11-20 17:50:48 ----D---- C:\Program Files\Spybot - Search & Destroy 2009-11-20 17:50:48 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy 2009-11-20 17:11:05 ----D---- C:\Documents and Settings\Owner\Application Data\AVG8 2009-11-20 17:10:24 ----D---- C:\Documents and Settings\Owner\Application Data\Malwarebytes 2009-11-20 17:10:20 ----D---- C:\Program Files\Malwarebytes' Anti-Malware 2009-11-20 17:10:20 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes 2009-11-20 17:00:27 ----D---- C:\WINDOWS\pss 2009-11-20 03:20:41 ----A---- C:\WINDOWS\system32\h323log.txt 2009-11-20 03:18:26 ----A---- C:\WINDOWS\system32\irmon.dll 2009-11-20 03:18:26 ----A---- C:\WINDOWS\system32\irftp.exe 2009-11-20 03:18:25 ----A---- C:\WINDOWS\system32\wshirda.dll 2009-11-20 03:18:12 ----A---- C:\WINDOWS\system32\usbui.dll 2009-11-20 03:17:17 ----A---- C:\WINDOWS\imsins.BAK 2009-11-20 03:17:15 ----SHD---- C:\WINDOWS\Installer 2009-11-20 03:17:15 ----D---- C:\Program Files\Common Files\ODBC 2009-11-20 03:17:15 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI 2009-11-20 03:17:15 ----A---- C:\WINDOWS\ODBCINST.INI 2009-11-20 03:17:12 ----D---- C:\Program Files\Common Files\SpeechEngines 2009-11-20 03:17:11 ----RD---- C:\Program Files 2009-11-20 03:17:11 ----D---- C:\Program Files\Common Files\Microsoft Shared 2009-11-20 03:17:11 ----D---- C:\Program Files\Common Files 2009-11-20 03:17:08 ----RA---- C:\WINDOWS\system32\kbdtuq.dll 2009-11-20 03:17:08 ----RA---- C:\WINDOWS\system32\kbdtuf.dll 2009-11-20 03:17:08 ----RA---- C:\WINDOWS\system32\kbdazel.dll 2009-11-20 03:17:06 ----RA---- C:\WINDOWS\system32\kbduzb.dll 2009-11-20 03:17:06 ----RA---- C:\WINDOWS\system32\kbdur.dll 2009-11-20 03:17:06 ----RA---- C:\WINDOWS\system32\kbdtat.dll 2009-11-20 03:17:06 ----RA---- C:\WINDOWS\system32\kbdmon.dll 2009-11-20 03:17:06 ----RA---- C:\WINDOWS\system32\kbdkyr.dll 2009-11-20 03:17:06 ----RA---- C:\WINDOWS\system32\kbdkaz.dll 2009-11-20 03:17:06 ----RA---- C:\WINDOWS\system32\kbdaze.dll 2009-11-20 03:17:05 ----RA---- C:\WINDOWS\system32\kbdycc.dll 2009-11-20 03:17:05 ----RA---- C:\WINDOWS\system32\kbdru1.dll 2009-11-20 03:17:05 ----RA---- C:\WINDOWS\system32\kbdru.dll 2009-11-20 03:17:05 ----RA---- C:\WINDOWS\system32\kbdbu.dll 2009-11-20 03:17:05 ----RA---- C:\WINDOWS\system32\kbdblr.dll 2009-11-20 03:17:03 ----RA---- C:\WINDOWS\system32\kbdhept.dll 2009-11-20 03:17:03 ----RA---- C:\WINDOWS\system32\kbdhela3.dll 2009-11-20 03:17:03 ----RA---- C:\WINDOWS\system32\kbdhela2.dll 2009-11-20 03:17:03 ----RA---- C:\WINDOWS\system32\kbdhe319.dll 2009-11-20 03:17:03 ----RA---- C:\WINDOWS\system32\kbdhe220.dll 2009-11-20 03:17:03 ----RA---- C:\WINDOWS\system32\kbdhe.dll 2009-11-20 03:17:03 ----RA---- C:\WINDOWS\system32\kbdgkl.dll 2009-11-20 03:17:01 ----RA---- C:\WINDOWS\system32\kbdlv1.dll 2009-11-20 03:17:01 ----RA---- C:\WINDOWS\system32\kbdlv.dll 2009-11-20 03:17:01 ----RA---- C:\WINDOWS\system32\kbdlt1.dll 2009-11-20 03:17:01 ----RA---- C:\WINDOWS\system32\kbdlt.dll 2009-11-20 03:17:01 ----RA---- C:\WINDOWS\system32\kbdest.dll 2009-11-20 03:16:59 ----RA---- C:\WINDOWS\system32\kbdsl1.dll 2009-11-20 03:16:58 ----RA---- C:\WINDOWS\system32\kbdycl.dll 2009-11-20 03:16:58 ----RA---- C:\WINDOWS\system32\kbdsl.dll 2009-11-20 03:16:58 ----RA---- C:\WINDOWS\system32\kbdro.dll 2009-11-20 03:16:58 ----RA---- C:\WINDOWS\system32\kbdpl1.dll 2009-11-20 03:16:58 ----RA---- C:\WINDOWS\system32\kbdpl.dll 2009-11-20 03:16:58 ----RA---- C:\WINDOWS\system32\kbdhu1.dll 2009-11-20 03:16:58 ----RA---- C:\WINDOWS\system32\kbdhu.dll 2009-11-20 03:16:58 ----RA---- C:\WINDOWS\system32\kbdcz2.dll 2009-11-20 03:16:58 ----RA---- C:\WINDOWS\system32\kbdcz1.dll 2009-11-20 03:16:58 ----RA---- C:\WINDOWS\system32\kbdcz.dll 2009-11-20 03:16:58 ----RA---- C:\WINDOWS\system32\kbdcr.dll 2009-11-20 03:16:58 ----RA---- C:\WINDOWS\system32\KBDAL.DLL 2009-11-20 03:16:56 ----A---- C:\WINDOWS\system32\irclass.dll 2009-11-20 03:16:56 ----A---- C:\WINDOWS\system32\dgsetup.dll 2009-11-20 03:16:56 ----A---- C:\WINDOWS\system32\dgrpsetu.dll 2009-11-20 03:16:55 ----A---- C:\WINDOWS\system32\spxcoins.dll 2009-11-20 03:16:55 ----A---- C:\WINDOWS\system32\EqnClass.Dll 2009-11-20 03:16:53 ----N---- C:\WINDOWS\system32\CONFIG.TMP 2009-11-20 03:16:53 ----A---- C:\WINDOWS\TASKMAN.EXE 2009-11-20 03:16:52 ----A---- C:\WINDOWS\system32\batt.dll 2009-11-20 03:16:52 ----A---- C:\WINDOWS\NOTEPAD.EXE 2009-11-20 03:16:51 ----A---- C:\WINDOWS\system32\storprop.dll 2009-11-20 03:16:44 ----ASH---- C:\Documents and Settings\All Users\Application Data\desktop.ini 2009-11-20 03:16:39 ----RA---- C:\WINDOWS\SET8.tmp 2009-11-20 03:16:37 ----RA---- C:\WINDOWS\SET4.tmp 2009-11-20 03:16:35 ----RA---- C:\WINDOWS\SET3.tmp 2009-11-20 03:16:30 ----D---- C:\WINDOWS\system32\CatRoot2 2009-11-20 03:16:30 ----D---- C:\WINDOWS\system32\CatRoot 2009-11-20 03:16:25 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft 2009-11-20 03:16:04 ----A---- C:\WINDOWS\setuplog.txt 2009-11-20 03:16:00 ----SHD---- C:\System Volume Information 2009-11-20 03:16:00 ----D---- C:\Documents and Settings 2009-11-20 03:14:31 ----SH---- C:\boot.ini 2009-11-20 03:08:54 ----RSHDC---- C:\WINDOWS\system32\dllcache 2009-11-20 03:08:54 ----RSD---- C:\WINDOWS\Fonts 2009-11-20 03:08:54 ----RD---- C:\WINDOWS\Web 2009-11-20 03:08:54 ----HD---- C:\WINDOWS\inf 2009-11-20 03:08:54 ----D---- C:\WINDOWS\WinSxS 2009-11-20 03:08:54 ----D---- C:\WINDOWS\twain_32 2009-11-20 03:08:54 ----D---- C:\WINDOWS\Temp 2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\wins 2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\wbem 2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\usmt 2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\spool 2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\ShellExt 2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\Setup 2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\ras 2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\oobe 2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\npp 2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\mui 2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\inetsrv 2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\IME 2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\icsxml 2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\ias 2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\export 2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\drivers 2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\dhcp 2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\config 2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\3com_dmi 2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\3076 2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\2052 2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\1054 2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\1042 2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\1041 2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\1037 2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\1033 2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\1031 2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\1028 2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\1025 2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32 2009-11-20 03:08:54 ----D---- C:\WINDOWS\system 2009-11-20 03:08:54 ----D---- C:\WINDOWS\security 2009-11-20 03:08:54 ----D---- C:\WINDOWS\Resources 2009-11-20 03:08:54 ----D---- C:\WINDOWS\repair 2009-11-20 03:08:54 ----D---- C:\WINDOWS\Provisioning 2009-11-20 03:08:54 ----D---- C:\WINDOWS\PeerNet 2009-11-20 03:08:54 ----D---- C:\WINDOWS\pchealth 2009-11-20 03:08:54 ----D---- C:\WINDOWS\mui 2009-11-20 03:08:54 ----D---- C:\WINDOWS\msapps 2009-11-20 03:08:54 ----D---- C:\WINDOWS\msagent 2009-11-20 03:08:54 ----D---- C:\WINDOWS\Media 2009-11-20 03:08:54 ----D---- C:\WINDOWS\java 2009-11-20 03:08:54 ----D---- C:\WINDOWS\ime 2009-11-20 03:08:54 ----D---- C:\WINDOWS\Help 2009-11-20 03:08:54 ----D---- C:\WINDOWS\Driver Cache 2009-11-20 03:08:54 ----D---- C:\WINDOWS\Debug 2009-11-20 03:08:54 ----D---- C:\WINDOWS\Cursors 2009-11-20 03:08:54 ----D---- C:\WINDOWS\Connection Wizard 2009-11-20 03:08:54 ----D---- C:\WINDOWS\Config 2009-11-20 03:08:54 ----D---- C:\WINDOWS\AppPatch 2009-11-20 03:08:54 ----D---- C:\WINDOWS\addins 2009-11-20 03:08:54 ----D---- C:\WINDOWS 2009-11-20 01:44:57 ----D---- C:\Documents and Settings\Owner\Application Data\Yahoo! 2009-11-20 01:42:32 ----D---- C:\Documents and Settings\All Users\Application Data\Yahoo! 2009-11-20 01:37:02 ----D---- C:\Program Files\Yahoo! 2009-11-19 18:57:50 ----D---- C:\Documents and Settings\Owner\Application Data\WinRAR 2009-11-19 18:03:41 ----D---- C:\POV pervert disc 1 2009-11-19 17:52:25 ----D---- C:\POV pervert disc 2 2009-11-19 17:43:08 ----D---- C:\Documents and Settings\Owner\Application Data\Media Player Classic 2009-11-19 17:32:32 ----D---- C:\Documents and Settings\Owner\Application Data\Leadertech 2009-11-19 17:28:17 ----D---- C:\Documents and Settings\Owner\Application Data\Macromedia 2009-11-19 17:28:16 ----D---- C:\Documents and Settings\Owner\Application Data\Adobe 2009-11-19 17:25:23 ----D---- C:\NeverwinterNights 2009-11-19 17:24:37 ----D---- C:\WINDOWS\system32\Lang 2009-11-19 17:22:05 ----D---- C:\Program Files\WinRAR 2009-11-19 17:20:38 ----SHD---- C:\RECYCLER 2009-11-19 17:20:10 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe 2009-11-19 17:20:05 ----D---- C:\Program Files\Common Files\Adobe 2009-11-19 17:20:05 ----D---- C:\Program Files\Adobe 2009-11-19 17:19:13 ----A---- C:\WINDOWS\system32\unrar.dll 2009-11-19 17:19:13 ----A---- C:\WINDOWS\avisplitter.ini 2009-11-19 17:19:12 ----A---- C:\WINDOWS\system32\yv12vfw.dll 2009-11-19 17:19:12 ----A---- C:\WINDOWS\system32\xvidvfw.dll 2009-11-19 17:19:12 ----A---- C:\WINDOWS\system32\xvidcore.dll 2009-11-19 17:19:11 ----A---- C:\WINDOWS\system32\ff_vfw.dll.manifest 2009-11-19 17:19:11 ----A---- C:\WINDOWS\system32\ff_vfw.dll 2009-11-19 17:19:10 ----D---- C:\Program Files\K-Lite Codec Pack 2009-11-19 17:02:53 ----HDC---- C:\WINDOWS\$NtUninstallKB926239$ 2009-11-19 17:02:50 ----N---- C:\WINDOWS\system32\spmsg.dll 2009-11-19 17:02:48 ----HDC---- C:\WINDOWS\$NtUninstallMSCompPackV1$ 2009-11-19 17:02:42 ----D---- C:\Program Files\Windows Media Connect 2 2009-11-19 17:02:37 ----HDC---- C:\WINDOWS\$NtUninstallwmp11$ 2009-11-19 17:02:17 ----HDC---- C:\WINDOWS\$NtUninstallWMFDist11$ 2009-11-19 17:02:03 ----D---- C:\WINDOWS\system32\LogFiles 2009-11-19 17:02:02 ----A---- C:\WINDOWS\system32\spupdsvc.exe 2009-11-19 17:02:01 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$ 2009-11-19 17:01:45 ----D---- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage 2009-11-19 17:01:33 ----A---- C:\WINDOWS\system32\wpa.bak 2009-11-19 17:00:24 ----D---- C:\Documents and Settings\Owner\Application Data\Mozilla 2009-11-19 17:00:17 ----D---- C:\Program Files\Mozilla Firefox 2009-11-19 16:51:43 ----A---- C:\WINDOWS\system32\wnicapi.dll 2009-11-19 16:51:43 ----A---- C:\WINDOWS\system32\WlanApp.dll 2009-11-19 16:51:43 ----A---- C:\WINDOWS\system32\odSupp_M.dll 2009-11-19 16:51:43 ----A---- C:\WINDOWS\system32\JJAKEn.dll 2009-11-19 16:51:43 ----A---- C:\WINDOWS\system32\AQCKGen.dll 2009-11-19 16:51:43 ----A---- C:\WINDOWS\system32\ANIWZCS2.dll 2009-11-19 16:51:43 ----A---- C:\WINDOWS\system32\ANICtl.dll 2009-11-19 16:51:43 ----A---- C:\WINDOWS\system32\aIPH.dll 2009-11-19 16:51:29 ----D---- C:\Program Files\ANI 2009-11-19 16:51:29 ----A---- C:\WINDOWS\system32\ANIOApi.dll 2009-11-19 16:51:02 ----D---- C:\Program Files\D-Link 2009-11-19 16:50:57 ----D---- C:\Documents and Settings\Owner\Application Data\InstallShield 2009-11-19 16:44:07 ----D---- C:\WINDOWS\nview 2009-11-19 16:44:06 ----A---- C:\WINDOWS\system32\nvudisp.exe 2009-11-19 16:44:00 ----A---- C:\WINDOWS\system32\nwiz.exe 2009-11-19 16:43:59 ----A---- C:\WINDOWS\system32\nvwimg.dll 2009-11-19 16:43:59 ----A---- C:\WINDOWS\system32\nvwdmcpl.dll 2009-11-19 16:43:59 ----A---- C:\WINDOWS\system32\nvwddi.dll 2009-11-19 16:43:59 ----A---- C:\WINDOWS\system32\nvsvc32.exe 2009-11-19 16:43:58 ----A---- C:\WINDOWS\system32\nvshell.dll 2009-11-19 16:43:58 ----A---- C:\WINDOWS\system32\nvoglnt.dll 2009-11-19 16:43:58 ----A---- C:\WINDOWS\system32\nvnt4cpl.dll 2009-11-19 16:43:58 ----A---- C:\WINDOWS\system32\nvcodins.dll 2009-11-19 16:43:58 ----A---- C:\WINDOWS\system32\nvcod.dll 2009-11-19 16:43:57 ----A---- C:\WINDOWS\system32\nvdspsch.exe 2009-11-19 16:43:57 ----A---- C:\WINDOWS\system32\nvappbar.exe 2009-11-19 16:43:56 ----A---- C:\WINDOWS\system32\nview.dll 2009-11-19 16:43:56 ----A---- C:\WINDOWS\system32\nv4_disp.dll 2009-11-19 16:43:56 ----A---- C:\WINDOWS\system32\keystone.exe 2009-11-19 16:43:55 ----A---- C:\WINDOWS\system32\nvmctray.dll 2009-11-19 16:43:55 ----A---- C:\WINDOWS\system32\nvcpl.dll 2009-11-19 16:43:54 ----A---- C:\WINDOWS\system32\nvwrszht.dll 2009-11-19 16:43:54 ----A---- C:\WINDOWS\system32\nvwrszhc.dll 2009-11-19 16:43:54 ----A---- C:\WINDOWS\system32\nvwrsptb.dll 2009-11-19 16:43:54 ----A---- C:\WINDOWS\system32\nvwrsko.dll 2009-11-19 16:43:54 ----A---- C:\WINDOWS\system32\nvwrsja.dll 2009-11-19 16:43:54 ----A---- C:\WINDOWS\system32\nvwrsit.dll 2009-11-19 16:43:54 ----A---- C:\WINDOWS\system32\nvwrsfr.dll 2009-11-19 16:43:54 ----A---- C:\WINDOWS\system32\nvwrses.dll 2009-11-19 16:43:54 ----A---- C:\WINDOWS\system32\nvwrsde.dll 2009-11-19 16:43:53 ----A---- C:\WINDOWS\system32\nvrszht.dll 2009-11-19 16:43:53 ----A---- C:\WINDOWS\system32\nvrszhc.dll 2009-11-19 16:43:53 ----A---- C:\WINDOWS\system32\nvrsptb.dll 2009-11-19 16:43:53 ----A---- C:\WINDOWS\system32\nvrsko.dll 2009-11-19 16:43:53 ----A---- C:\WINDOWS\system32\nvrsja.dll 2009-11-19 16:43:53 ----A---- C:\WINDOWS\system32\nvrsit.dll 2009-11-19 16:43:53 ----A---- C:\WINDOWS\system32\nvrsfr.dll 2009-11-19 16:43:53 ----A---- C:\WINDOWS\system32\nvrses.dll 2009-11-19 16:43:53 ----A---- C:\WINDOWS\system32\nvrsde.dll 2009-11-19 16:43:49 ----D---- C:\WINDOWS\system32\WinFast 2009-11-19 16:42:54 ----D---- C:\WINDOWS\system32\WinFox 2009-11-19 16:38:32 ----RA---- C:\WINDOWS\system32\NvSataConnectionzht.dll 2009-11-19 16:38:32 ----RA---- C:\WINDOWS\system32\NvRaidWizardzht.dll 2009-11-19 16:38:32 ----A---- C:\WINDOWS\system32\nvuide.exe 2009-11-19 16:38:31 ----RA---- C:\WINDOWS\system32\NvSataConnectionzhc.dll 2009-11-19 16:38:31 ----RA---- C:\WINDOWS\system32\NvSataConnectiontr.dll 2009-11-19 16:38:31 ----RA---- C:\WINDOWS\system32\NvSataConnectionth.dll 2009-11-19 16:38:31 ----RA---- C:\WINDOWS\system32\NvSataConnectionsv.dll 2009-11-19 16:38:31 ----RA---- C:\WINDOWS\system32\NvRaidzht.dll 2009-11-19 16:38:31 ----RA---- C:\WINDOWS\system32\NvRaidzhc.dll 2009-11-19 16:38:31 ----RA---- C:\WINDOWS\system32\NvRaidWizardzhc.dll 2009-11-19 16:38:31 ----RA---- C:\WINDOWS\system32\NvRaidWizardtr.dll 2009-11-19 16:38:31 ----RA---- C:\WINDOWS\system32\NvRaidWizardth.dll 2009-11-19 16:38:31 ----RA---- C:\WINDOWS\system32\NvRaidtr.dll 2009-11-19 16:38:31 ----RA---- C:\WINDOWS\system32\NvRaidth.dll 2009-11-19 16:38:31 ----RA---- C:\WINDOWS\system32\NvRaidSvzht.dll 2009-11-19 16:38:31 ----RA---- C:\WINDOWS\system32\NvRaidSvzhc.dll 2009-11-19 16:38:31 ----RA---- C:\WINDOWS\system32\NvRaidSvtr.dll 2009-11-19 16:38:31 ----RA---- C:\WINDOWS\system32\NvRaidSvth.dll 2009-11-19 16:38:30 ----RA---- C:\WINDOWS\system32\NvSataConnectionsl.dll 2009-11-19 16:38:30 ----RA---- C:\WINDOWS\system32\NvSataConnectionsk.dll 2009-11-19 16:38:30 ----RA---- C:\WINDOWS\system32\NvSataConnectionru.dll 2009-11-19 16:38:30 ----RA---- C:\WINDOWS\system32\NvSataConnectionptb.dll 2009-11-19 16:38:30 ----RA---- C:\WINDOWS\system32\NvRaidWizardsv.dll 2009-11-19 16:38:30 ----RA---- C:\WINDOWS\system32\NvRaidWizardsl.dll 2009-11-19 16:38:30 ----RA---- C:\WINDOWS\system32\NvRaidWizardsk.dll 2009-11-19 16:38:30 ----RA---- C:\WINDOWS\system32\NvRaidWizardru.dll 2009-11-19 16:38:30 ----RA---- C:\WINDOWS\system32\NvRaidSvsv.dll 2009-11-19 16:38:30 ----RA---- C:\WINDOWS\system32\NvRaidSvsl.dll 2009-11-19 16:38:30 ----RA---- C:\WINDOWS\system32\NvRaidSvsk.dll 2009-11-19 16:38:30 ----RA---- C:\WINDOWS\system32\NvRaidSvru.dll 2009-11-19 16:38:30 ----RA---- C:\WINDOWS\system32\NvRaidsv.dll 2009-11-19 16:38:30 ----RA---- C:\WINDOWS\system32\NvRaidsl.dll 2009-11-19 16:38:30 ----RA---- C:\WINDOWS\system32\NvRaidsk.dll 2009-11-19 16:38:30 ----RA---- C:\WINDOWS\system32\NvRaidru.dll 2009-11-19 16:38:29 ----RA---- C:\WINDOWS\system32\NvSataConnectionpt.dll 2009-11-19 16:38:29 ----RA---- C:\WINDOWS\system32\NvSataConnectionpl.dll 2009-11-19 16:38:29 ----RA---- C:\WINDOWS\system32\NvSataConnectionno.dll 2009-11-19 16:38:29 ----RA---- C:\WINDOWS\system32\NvRaidWizardptb.dll 2009-11-19 16:38:29 ----RA---- C:\WINDOWS\system32\NvRaidWizardpt.dll 2009-11-19 16:38:29 ----RA---- C:\WINDOWS\system32\NvRaidWizardpl.dll 2009-11-19 16:38:29 ----RA---- C:\WINDOWS\system32\NvRaidSvptb.dll 2009-11-19 16:38:29 ----RA---- C:\WINDOWS\system32\NvRaidSvpt.dll 2009-11-19 16:38:29 ----RA---- C:\WINDOWS\system32\NvRaidSvpl.dll 2009-11-19 16:38:29 ----RA---- C:\WINDOWS\system32\NvRaidptb.dll 2009-11-19 16:38:29 ----RA---- C:\WINDOWS\system32\NvRaidpt.dll 2009-11-19 16:38:29 ----RA---- C:\WINDOWS\system32\NvRaidpl.dll 2009-11-19 16:38:28 ----RA---- C:\WINDOWS\system32\NvSataConnectionnl.dll 2009-11-19 16:38:28 ----RA---- C:\WINDOWS\system32\NvSataConnectionko.dll 2009-11-19 16:38:28 ----RA---- C:\WINDOWS\system32\NvSataConnectionja.dll 2009-11-19 16:38:28 ----RA---- C:\WINDOWS\system32\NvRaidWizardno.dll 2009-11-19 16:38:28 ----RA---- C:\WINDOWS\system32\NvRaidWizardnl.dll 2009-11-19 16:38:28 ----RA---- C:\WINDOWS\system32\NvRaidWizardko.dll 2009-11-19 16:38:28 ----RA---- C:\WINDOWS\system32\NvRaidWizardja.dll 2009-11-19 16:38:28 ----RA---- C:\WINDOWS\system32\NvRaidSvno.dll 2009-11-19 16:38:28 ----RA---- C:\WINDOWS\system32\NvRaidSvnl.dll 2009-11-19 16:38:28 ----RA---- C:\WINDOWS\system32\NvRaidSvko.dll 2009-11-19 16:38:28 ----RA---- C:\WINDOWS\system32\NvRaidSvja.dll 2009-11-19 16:38:28 ----RA---- C:\WINDOWS\system32\NvRaidno.dll 2009-11-19 16:38:28 ----RA---- C:\WINDOWS\system32\NvRaidnl.dll 2009-11-19 16:38:28 ----RA---- C:\WINDOWS\system32\NvRaidko.dll 2009-11-19 16:38:27 ----RA---- C:\WINDOWS\system32\NvSataConnectionit.dll 2009-11-19 16:38:27 ----RA---- C:\WINDOWS\system32\NvSataConnectionhu.dll 2009-11-19 16:38:27 ----RA---- C:\WINDOWS\system32\NvSataConnectionhe.dll 2009-11-19 16:38:27 ----RA---- C:\WINDOWS\system32\NvSataConnectionfr.dll 2009-11-19 16:38:27 ----RA---- C:\WINDOWS\system32\NvRaidWizardit.dll 2009-11-19 16:38:27 ----RA---- C:\WINDOWS\system32\NvRaidWizardhu.dll 2009-11-19 16:38:27 ----RA---- C:\WINDOWS\system32\NvRaidWizardhe.dll 2009-11-19 16:38:27 ----RA---- C:\WINDOWS\system32\NvRaidSvit.dll 2009-11-19 16:38:27 ----RA---- C:\WINDOWS\system32\NvRaidSvhu.dll 2009-11-19 16:38:27 ----RA---- C:\WINDOWS\system32\NvRaidSvhe.dll 2009-11-19 16:38:27 ----RA---- C:\WINDOWS\system32\NvRaidja.dll 2009-11-19 16:38:27 ----RA---- C:\WINDOWS\system32\NvRaidit.dll 2009-11-19 16:38:27 ----RA---- C:\WINDOWS\system32\NvRaidhu.dll 2009-11-19 16:38:27 ----RA---- C:\WINDOWS\system32\NvRaidhe.dll 2009-11-19 16:38:26 ----RA---- C:\WINDOWS\system32\NvSataConnectionfi.dll 2009-11-19 16:38:26 ----RA---- C:\WINDOWS\system32\NvSataConnectiones.dll 2009-11-19 16:38:26 ----RA---- C:\WINDOWS\system32\NvSataConnectioneng.dll 2009-11-19 16:38:26 ----RA---- C:\WINDOWS\system32\NvRaidWizardfr.dll 2009-11-19 16:38:26 ----RA---- C:\WINDOWS\system32\NvRaidWizardfi.dll 2009-11-19 16:38:26 ----RA---- C:\WINDOWS\system32\NvRaidWizardes.dll 2009-11-19 16:38:26 ----RA---- C:\WINDOWS\system32\NvRaidWizardeng.dll 2009-11-19 16:38:26 ----RA---- C:\WINDOWS\system32\NvRaidSvfr.dll 2009-11-19 16:38:26 ----RA---- C:\WINDOWS\system32\NvRaidSvfi.dll 2009-11-19 16:38:26 ----RA---- C:\WINDOWS\system32\NvRaidSves.dll 2009-11-19 16:38:26 ----RA---- C:\WINDOWS\system32\NvRaidSveng.dll 2009-11-19 16:38:26 ----RA---- C:\WINDOWS\system32\NvRaidfr.dll 2009-11-19 16:38:26 ----RA---- C:\WINDOWS\system32\NvRaidfi.dll 2009-11-19 16:38:26 ----RA---- C:\WINDOWS\system32\NvRaides.dll 2009-11-19 16:38:26 ----RA---- C:\WINDOWS\system32\NvRaideng.dll 2009-11-19 16:38:25 ----RA---- C:\WINDOWS\system32\NvSataConnectionel.dll 2009-11-19 16:38:25 ----RA---- C:\WINDOWS\system32\NvSataConnectionde.dll 2009-11-19 16:38:25 ----RA---- C:\WINDOWS\system32\NvSataConnectionda.dll 2009-11-19 16:38:25 ----RA---- C:\WINDOWS\system32\NvSataConnectioncs.dll 2009-11-19 16:38:25 ----RA---- C:\WINDOWS\system32\NvRaidWizardel.dll 2009-11-19 16:38:25 ----RA---- C:\WINDOWS\system32\NvRaidWizardde.dll 2009-11-19 16:38:25 ----RA---- C:\WINDOWS\system32\NvRaidWizardda.dll 2009-11-19 16:38:25 ----RA---- C:\WINDOWS\system32\NvRaidWizardcs.dll 2009-11-19 16:38:25 ----RA---- C:\WINDOWS\system32\NvRaidSvel.dll 2009-11-19 16:38:25 ----RA---- C:\WINDOWS\system32\NvRaidSvde.dll 2009-11-19 16:38:25 ----RA---- C:\WINDOWS\system32\NvRaidSvda.dll 2009-11-19 16:38:25 ----RA---- C:\WINDOWS\system32\NvRaidel.dll 2009-11-19 16:38:25 ----RA---- C:\WINDOWS\system32\NvRaidde.dll 2009-11-19 16:38:25 ----RA---- C:\WINDOWS\system32\NvRaidda.dll 2009-11-19 16:38:24 ----RA---- C:\WINDOWS\system32\NvSataConnectionEnu.dll 2009-11-19 16:38:24 ----RA---- C:\WINDOWS\system32\NvSataConnectionar.dll 2009-11-19 16:38:24 ----RA---- C:\WINDOWS\system32\nvsataconnection.exe 2009-11-19 16:38:24 ----RA---- C:\WINDOWS\system32\NvRaidWizardEnu.dll 2009-11-19 16:38:24 ----RA---- C:\WINDOWS\system32\NvRaidWizardar.dll 2009-11-19 16:38:24 ----RA---- C:\WINDOWS\system32\NvRaidSvEnu.dll 2009-11-19 16:38:24 ----RA---- C:\WINDOWS\system32\NvRaidSvcs.dll 2009-11-19 16:38:24 ----RA---- C:\WINDOWS\system32\NvRaidSvar.dll 2009-11-19 16:38:24 ----RA---- C:\WINDOWS\system32\nvraidservice.exe 2009-11-19 16:38:24 ----RA---- C:\WINDOWS\system32\NvRaidEnu.dll 2009-11-19 16:38:24 ----RA---- C:\WINDOWS\system32\NvRaidcs.dll 2009-11-19 16:38:24 ----RA---- C:\WINDOWS\system32\NvRaidar.dll 2009-11-19 16:38:23 ----RA---- C:\WINDOWS\system32\NvRaidWizard.dll 2009-11-19 16:38:23 ----RA---- C:\WINDOWS\system32\NvRaidMan.exe 2009-11-19 16:38:17 ----RA---- C:\WINDOWS\system32\nvraidco.dll 2009-11-19 16:38:17 ----A---- C:\WINDOWS\system32\nvraiins.dll 2009-11-19 16:38:11 ----RA---- C:\WINDOWS\system32\idecoi.dll 2009-11-19 16:36:34 ----A---- C:\WINDOWS\system32\ksuser.dll 2009-11-19 16:36:31 ----D---- C:\Program Files\Realtek Sound Manager 2009-11-19 16:36:28 ----N---- C:\WINDOWS\avrack.ini 2009-11-19 16:36:28 ----D---- C:\Program Files\AvRack 2009-11-19 16:36:23 ----A---- C:\WINDOWS\system32\RTLCPAPI.dll 2009-11-19 16:36:22 ----N---- C:\WINDOWS\system32\ChCfg.exe 2009-11-19 16:36:22 ----A---- C:\WINDOWS\SOUNDMAN.EXE 2009-11-19 16:36:17 ----A---- C:\WINDOWS\system32\RTLCPL.EXE 2009-11-19 16:36:08 ----N---- C:\WINDOWS\alcupd.exe 2009-11-19 16:36:08 ----N---- C:\WINDOWS\alcrmv.exe 2009-11-19 16:36:07 ----HD---- C:\Program Files\InstallShield Installation Information 2009-11-19 16:33:49 ----RA---- C:\WINDOWS\system32\fdco1ins.dll 2009-11-19 16:33:49 ----RA---- C:\WINDOWS\system32\fdco1.dll 2009-11-19 16:33:47 ----RA---- C:\WINDOWS\system32\nvconrm.dll 2009-11-19 16:33:47 ----RA---- C:\WINDOWS\system32\bdco1ins.dll 2009-11-19 16:33:47 ----RA---- C:\WINDOWS\system32\bdco1.dll 2009-11-19 16:33:47 ----A---- C:\WINDOWS\system32\nvunrm.exe 2009-11-19 16:33:46 ----RA---- C:\WINDOWS\system32\nvusmb.exe 2009-11-19 16:33:46 ----A---- C:\WINDOWS\system32\NVUNINST.EXE 2009-11-19 16:33:36 ----D---- C:\WINDOWS\system32\ReinstallBackups 2009-11-19 16:33:29 ----D---- C:\Program Files\Common Files\InstallShield 2009-11-19 16:30:26 ----D---- C:\Documents and Settings\Owner\Application Data\Identities 2009-11-19 16:30:24 ----HD---- C:\Program Files\Uninstall Information 2009-11-19 16:30:20 ----ASH---- C:\Documents and Settings\Owner\Application Data\desktop.ini 2009-11-19 16:30:19 ----SD---- C:\Documents and Settings\Owner\Application Data\Microsoft 2009-11-19 16:30:13 ----D---- C:\WINDOWS\SoftwareDistribution 2009-11-19 16:30:12 ----SD---- C:\WINDOWS\system32\Microsoft 2009-11-19 16:30:12 ----D---- C:\WINDOWS\Prefetch 2009-11-19 16:30:12 ----A---- C:\WINDOWS\SchedLgU.Txt 2009-11-19 16:26:34 ----D---- C:\WINDOWS\system32\xircom 2009-11-19 16:26:34 ----D---- C:\Program Files\xerox 2009-11-19 16:26:34 ----D---- C:\Program Files\microsoft frontpage 2009-11-19 16:26:26 ----A---- C:\WINDOWS\control.ini 2009-11-19 16:26:26 ----A---- C:\AUTOEXEC.BAT 2009-11-19 16:26:13 ----A---- C:\WINDOWS\OEWABLog.txt 2009-11-19 16:26:09 ----A---- C:\WINDOWS\system32\mapi32.dll 2009-11-19 16:25:35 ----SD---- C:\WINDOWS\Downloaded Program Files 2009-11-19 16:25:35 ----RD---- C:\WINDOWS\Offline Web Pages 2009-11-19 16:25:35 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest 2009-11-19 16:25:30 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest 2009-11-19 16:25:27 ----HD---- C:\Program Files\WindowsUpdate 2009-11-19 16:25:07 ----D---- C:\WINDOWS\system32\DirectX 2009-11-19 16:24:44 ----A---- C:\WINDOWS\system32\atrace.dll 2009-11-19 16:24:41 ----A---- C:\WINDOWS\system32\desktop.ini 2009-11-19 16:24:41 ----A---- C:\WINDOWS\desktop.ini 2009-11-19 16:24:33 ----A---- C:\WINDOWS\system32\nmevtmsg.dll 2009-11-19 16:24:32 ----A---- C:\WINDOWS\system32\acctres.dll 2009-11-19 16:24:31 ----D---- C:\Program Files\Common Files\Services 2009-11-19 16:24:28 ----SD---- C:\WINDOWS\Tasks 2009-11-19 16:24:28 ----A---- C:\WINDOWS\system32\icfgnt5.dll 2009-11-19 16:24:26 ----D---- C:\Program Files\Common Files\MSSoap 2009-11-19 16:24:22 ----D---- C:\WINDOWS\srchasst 2009-11-19 16:24:21 ----D---- C:\WINDOWS\system32\Macromed 2009-11-19 16:24:17 ----A---- C:\WINDOWS\system32\wuweb.dll 2009-11-19 16:24:17 ----A---- C:\WINDOWS\system32\wups.dll 2009-11-19 16:24:17 ----A---- C:\WINDOWS\system32\wucltui.dll 2009-11-19 16:24:17 ----A---- C:\WINDOWS\system32\wuauserv.dll 2009-11-19 16:24:17 ----A---- C:\WINDOWS\system32\wuaueng1.dll 2009-11-19 16:24:17 ----A---- C:\WINDOWS\system32\wuaueng.dll 2009-11-19 16:24:17 ----A---- C:\WINDOWS\system32\wuauclt1.exe 2009-11-19 16:24:17 ----A---- C:\WINDOWS\system32\wuauclt.exe 2009-11-19 16:24:16 ----A---- C:\WINDOWS\system32\wuapi.dll 2009-11-19 16:24:16 ----A---- C:\WINDOWS\system32\qmgrprxy.dll 2009-11-19 16:24:16 ----A---- C:\WINDOWS\system32\qmgr.dll 2009-11-19 16:24:16 ----A---- C:\WINDOWS\system32\bitsprx3.dll 2009-11-19 16:24:16 ----A---- C:\WINDOWS\system32\bitsprx2.dll 2009-11-19 16:24:12 ----D---- C:\Program Files\Movie Maker 2009-11-19 16:24:07 ----A---- C:\WINDOWS\system32\safrslv.dll 2009-11-19 16:24:07 ----A---- C:\WINDOWS\system32\safrdm.dll 2009-11-19 16:24:07 ----A---- C:\WINDOWS\system32\safrcdlg.dll 2009-11-19 16:24:07 ----A---- C:\WINDOWS\system32\racpldlg.dll 2009-11-19 16:24:04 ----A---- C:\WINDOWS\system32\fltMc.exe 2009-11-19 16:24:04 ----A---- C:\WINDOWS\system32\fltlib.dll 2009-11-19 16:24:03 ----D---- C:\WINDOWS\system32\Restore 2009-11-19 16:24:03 ----A---- C:\WINDOWS\system32\srsvc.dll 2009-11-19 16:24:03 ----A---- C:\WINDOWS\system32\srrstr.dll 2009-11-19 16:24:03 ----A---- C:\WINDOWS\system32\srclient.dll 2009-11-19 16:24:02 ----A---- C:\WINDOWS\system32\mnmdd.dll 2009-11-19 16:24:02 ----A---- C:\WINDOWS\system32\isrdbg32.dll 2009-11-19 16:24:02 ----A---- C:\WINDOWS\system32\ils.dll 2009-11-19 16:24:01 ----A---- C:\WINDOWS\system32\nmmkcert.dll 2009-11-19 16:24:01 ----A---- C:\WINDOWS\system32\msconf.dll 2009-11-19 16:24:01 ----A---- C:\WINDOWS\system32\mnmsrvc.exe 2009-11-19 16:23:58 ----D---- C:\Program Files\NetMeeting 2009-11-19 16:23:58 ----A---- C:\WINDOWS\system32\msoert2.dll 2009-11-19 16:23:58 ----A---- C:\WINDOWS\system32\msoeacct.dll 2009-11-19 16:23:57 ----A---- C:\WINDOWS\system32\inetres.dll 2009-11-19 16:23:56 ----A---- C:\WINDOWS\system32\inetcomm.dll 2009-11-19 16:23:54 ----D---- C:\Program Files\Outlook Express 2009-11-19 16:23:54 ----A---- C:\WINDOWS\system32\schedsvc.dll 2009-11-19 16:23:54 ----A---- C:\WINDOWS\system32\mstinit.exe 2009-11-19 16:23:54 ----A---- C:\WINDOWS\system32\mstask.dll 2009-11-19 16:23:53 ----A---- C:\WINDOWS\system32\isign32.dll 2009-11-19 16:23:53 ----A---- C:\WINDOWS\system32\inetcfg.dll 2009-11-19 16:23:53 ----A---- C:\WINDOWS\system32\icwphbk.dll 2009-11-19 16:23:53 ----A---- C:\WINDOWS\system32\icwdial.dll 2009-11-19 16:23:46 ----D---- C:\Program Files\Common Files\System 2009-11-19 16:23:45 ----D---- C:\Program Files\Internet Explorer 2009-11-19 16:23:33 ----D---- C:\Program Files\ComPlus Applications 2009-11-19 16:23:31 ----A---- C:\WINDOWS\vbaddin.ini 2009-11-19 16:23:31 ----A---- C:\WINDOWS\vb.ini 2009-11-19 16:23:27 ----D---- C:\WINDOWS\Registration 2009-11-19 16:23:05 ----D---- C:\Program Files\Online Services 2009-11-19 16:23:04 ----D---- C:\Program Files\Windows Media Player 2009-11-19 16:23:00 ----D---- C:\Program Files\Messenger 2009-11-19 16:22:56 ----D---- C:\Program Files\MSN Gaming Zone 2009-11-19 16:22:56 ----A---- C:\WINDOWS\system32\write.exe 2009-11-19 16:22:45 ----A---- C:\WINDOWS\system32\sndvol32.exe 2009-11-19 16:22:45 ----A---- C:\WINDOWS\system32\hticons.dll 2009-11-19 16:22:44 ----A---- C:\WINDOWS\system32\winchat.exe 2009-11-19 16:22:44 ----A---- C:\WINDOWS\system32\avwav.dll 2009-11-19 16:22:44 ----A---- C:\WINDOWS\system32\avtapi.dll 2009-11-19 16:22:44 ----A---- C:\WINDOWS\system32\avmeter.dll 2009-11-19 16:22:35 ----A---- C:\WINDOWS\system32\getuname.dll 2009-11-19 16:22:35 ----A---- C:\WINDOWS\system32\charmap.exe 2009-11-19 16:22:35 ----A---- C:\WINDOWS\system32\calc.exe 2009-11-19 16:22:34 ----A---- C:\WINDOWS\system32\winmine.exe 2009-11-19 16:22:34 ----A---- C:\WINDOWS\system32\sol.exe 2009-11-19 16:22:34 ----A---- C:\WINDOWS\system32\mshearts.exe 2009-11-19 16:22:33 ----A---- C:\WINDOWS\system32\usrlogon.cmd 2009-11-19 16:22:33 ----A---- C:\WINDOWS\system32\tsshutdn.exe 2009-11-19 16:22:33 ----A---- C:\WINDOWS\system32\tslabels.ini 2009-11-19 16:22:33 ----A---- C:\WINDOWS\system32\tskill.exe 2009-11-19 16:22:33 ----A---- C:\WINDOWS\system32\tsdiscon.exe 2009-11-19 16:22:33 ----A---- C:\WINDOWS\system32\tscon.exe 2009-11-19 16:22:33 ----A---- C:\WINDOWS\system32\shadow.exe 2009-11-19 16:22:33 ----A---- C:\WINDOWS\system32\reset.exe 2009-11-19 16:22:33 ----A---- C:\WINDOWS\system32\freecell.exe 2009-11-19 16:22:32 ----A---- C:\WINDOWS\system32\rwinsta.exe 2009-11-19 16:22:32 ----A---- C:\WINDOWS\system32\regini.exe 2009-11-19 16:22:32 ----A---- C:\WINDOWS\system32\rdpcfgex.dll 2009-11-19 16:22:32 ----A---- C:\WINDOWS\system32\qwinsta.exe 2009-11-19 16:22:32 ----A---- C:\WINDOWS\system32\qappsrv.exe 2009-11-19 16:22:32 ----A---- C:\WINDOWS\system32\msg.exe 2009-11-19 16:22:32 ----A---- C:\WINDOWS\system32\logoff.exe 2009-11-19 16:22:32 ----A---- C:\WINDOWS\system32\cdmodem.dll 2009-11-19 16:22:31 ----A---- C:\WINDOWS\system32\msdtcprf.ini 2009-11-19 16:22:31 ----A---- C:\WINDOWS\system32\dcomcnfg.exe 2009-11-19 16:22:30 ----A---- C:\WINDOWS\system32\mtxlegih.dll 2009-11-19 16:22:30 ----A---- C:\WINDOWS\system32\mtxex.dll 2009-11-19 16:22:30 ----A---- C:\WINDOWS\system32\mtxdm.dll 2009-11-19 16:22:30 ----A---- C:\WINDOWS\system32\comrepl.dll 2009-11-19 16:22:30 ----A---- C:\WINDOWS\system32\comaddin.dll 2009-11-19 16:22:29 ----A---- C:\WINDOWS\system32\stclient.dll 2009-11-19 16:22:29 ----A---- C:\WINDOWS\system32\comsnap.dll 2009-11-19 16:22:24 ----A---- C:\WINDOWS\system32\wmimgmt.msc 2009-11-19 16:22:14 ----D---- C:\Program Files\MSN 2009-11-19 16:22:13 ----A---- C:\WINDOWS\system32\sndrec32.exe 2009-11-19 16:22:13 ----A---- C:\WINDOWS\system32\accwiz.exe 2009-11-19 16:22:12 ----D---- C:\Program Files\Windows NT 2009-11-19 16:22:12 ----A---- C:\WINDOWS\system32\mspaint.exe 2009-11-19 16:22:12 ----A---- C:\WINDOWS\system32\mplay32.exe 2009-11-19 16:22:12 ----A---- C:\WINDOWS\system32\hypertrm.dll 2009-11-19 16:22:11 ----A---- C:\WINDOWS\system32\spider.exe 2009-11-19 16:22:11 ----A---- C:\WINDOWS\system32\clipbrd.exe 2009-11-19 16:22:10 ----A---- C:\WINDOWS\system32\tscfgwmi.dll 2009-11-19 16:22:10 ----A---- C:\WINDOWS\system32\remotepg.dll 2009-11-19 16:22:10 ----A---- C:\WINDOWS\system32\rdsaddin.exe 2009-11-19 16:22:10 ----A---- C:\WINDOWS\system32\mstscax.dll 2009-11-19 16:22:10 ----A---- C:\WINDOWS\system32\mstsc.exe 2009-11-19 16:22:09 ----A---- C:\WINDOWS\system32\tscupgrd.exe 2009-11-19 16:22:09 ----A---- C:\WINDOWS\system32\termsrv.dll 2009-11-19 16:22:09 ----A---- C:\WINDOWS\system32\sessmgr.exe 2009-11-19 16:22:09 ----A---- C:\WINDOWS\system32\rdshost.exe 2009-11-19 16:22:09 ----A---- C:\WINDOWS\system32\rdpwsx.dll 2009-11-19 16:22:09 ----A---- C:\WINDOWS\system32\rdpsnd.dll 2009-11-19 16:22:09 ----A---- C:\WINDOWS\system32\rdpclip.exe 2009-11-19 16:22:09 ----A---- C:\WINDOWS\system32\rdchost.dll 2009-11-19 16:22:08 ----D---- C:\WINDOWS\system32\MsDtc 2009-11-19 16:22:08 ----A---- C:\WINDOWS\system32\qprocess.exe 2009-11-19 16:22:08 ----A---- C:\WINDOWS\system32\mtxoci.dll 2009-11-19 16:22:08 ----A---- C:\WINDOWS\system32\msdtcuiu.dll 2009-11-19 16:22:08 ----A---- C:\WINDOWS\system32\icaapi.dll 2009-11-19 16:22:08 ----A---- C:\WINDOWS\system32\cfgbkend.dll 2009-11-19 16:22:07 ----A---- C:\WINDOWS\system32\xolehlp.dll 2009-11-19 16:22:07 ----A---- C:\WINDOWS\system32\msdtctm.dll 2009-11-19 16:22:07 ----A---- C:\WINDOWS\system32\msdtcprx.dll 2009-11-19 16:22:07 ----A---- C:\WINDOWS\system32\msdtclog.dll 2009-11-19 16:22:07 ----A---- C:\WINDOWS\system32\msdtc.exe 2009-11-19 16:22:06 ----D---- C:\WINDOWS\system32\Com 2009-11-19 16:22:06 ----A---- C:\WINDOWS\system32\colbact.dll 2009-11-19 16:22:06 ----A---- C:\WINDOWS\system32\catsrvps.dll 2009-11-19 16:22:05 ----A---- C:\WINDOWS\system32\clbcatex.dll 2009-11-19 16:22:05 ----A---- C:\WINDOWS\system32\catsrvut.dll 2009-11-19 16:22:05 ----A---- C:\WINDOWS\system32\catsrv.dll 2009-11-19 16:22:04 ----A---- C:\WINDOWS\system32\comuid.dll 2009-11-19 16:22:04 ----A---- C:\WINDOWS\system32\comsvcs.dll 2009-11-19 16:22:04 ----A---- C:\WINDOWS\system32\clbcatq.dll 2009-11-19 16:21:58 ----A---- C:\WINDOWS\system32\servdeps.dll 2009-11-19 16:21:58 ----A---- C:\WINDOWS\system32\mmfutil.dll 2009-11-19 16:21:58 ----A---- C:\WINDOWS\system32\licwmi.dll 2009-11-19 16:21:58 ----A---- C:\WINDOWS\system32\cmprops.dll ======List of files/folders modified in the last 1 months====== 2009-11-20 17:45:34 ----A---- C:\WINDOWS\win.ini 2009-11-20 17:45:34 ----A---- C:\WINDOWS\system.ini ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 ANIO;ANIO Service; \??\C:\WINDOWS\system32\ANIO.SYS [] R2 irda;IrDA Protocol; C:\WINDOWS\system32\DRIVERS\irda.sys [2004-08-04 87424] R3 abp470n5;abp470n5; \??\C:\WINDOWS\system32\drivers\nhnjln.sys [] R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2004-11-17 2297664] R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-04 60800] R3 irsir;Microsoft Serial Infrared Driver; C:\WINDOWS\system32\DRIVERS\irsir.sys [2001-08-18 18688] R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-04 61824] R3 npkcrypt;npkcrypt; \??\D:\My Documents\VanRO\RO\npkcrypt.sys [] R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-11-15 2826944] R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2004-10-20 33280] R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2004-10-20 12928] R3 Rasirda;WAN Miniport (IrDA); C:\WINDOWS\system32\DRIVERS\rasirda.sys [2001-08-18 19584] R3 RT73;D-Link USB Wireless LAN Card Driver; C:\WINDOWS\system32\DRIVERS\Dr71WU.sys [2006-12-21 429440] R3 seehcri;Sony Ericsson seehcri Device Driver; C:\WINDOWS\system32\DRIVERS\seehcri.sys [2008-01-09 27632] R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-04 26624] R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-03 57600] R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2004-08-04 17024] R3 usbstor;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 26496] R3 yukonwxp;NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller; C:\WINDOWS\system32\DRIVERS\yk51x86.sys [2004-10-27 223104] S3 s1018bus;Sony Ericsson Device 1018 driver (WDM); C:\WINDOWS\system32\DRIVERS\s1018bus.sys [2009-03-25 86824] S3 s1018mdfl;Sony Ericsson Device 1018 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\s1018mdfl.sys [2009-03-25 15016] S3 s1018mdm;Sony Ericsson Device 1018 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\s1018mdm.sys [2009-03-25 114728] S3 s1018mgmt;Sony Ericsson Device 1018 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\s1018mgmt.sys [2009-03-25 106208] S3 s1018nd5;Sony Ericsson Device 1018 USB Ethernet Emulation (NDIS); C:\WINDOWS\system32\DRIVERS\s1018nd5.sys [2009-03-25 26024] S3 s1018obex;Sony Ericsson Device 1018 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\s1018obex.sys [2009-03-25 104744] S3 s1018unic;Sony Ericsson Device 1018 USB Ethernet Emulation (WDM); C:\WINDOWS\system32\DRIVERS\s1018unic.sys [2009-03-25 109864] S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528] S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944] S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys [] S4 sr;System Restore Filter Driver; C:\WINDOWS\system32\DRIVERS\sr.sys [2004-08-04 73472] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 Irmon;Infrared Monitor; C:\WINDOWS\system32\svchost.exe [2004-08-04 14336] R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2004-11-15 127043] R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-04 14336] S2 ANIWZCSdService;ANIWZCSd Service; C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe [2007-01-19 126976] S2 OMSI download service;Sony Ericsson OMSI download service; C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [2009-04-30 172032] S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 987136] -----------------EOF----------------- Back to Top
Jintan Senior Member Date Joined Dec 2006 Total Posts : 1424 Posted 11-22-2009 4:12 (GMT +2) Very active infection. See if you can do the following repair scan, and if not, we will have to go through some manual change steps instead. To keep them from interfering with the repairs, be sure to temporarily disable all antivirus/anti-spyware softwares while these steps are being completed. This can usually be done through right clicking the software's Taskbar icons, or accessing each software through Start - Programs. Download ComboFix.exe from here to your desktop, but I would like you to rename the file as you download it (do not download it directly without renaming it - use right click "Save Target/Link As" ). For this, rename the downloading file to 456out.com , then click the renamed 456out.com to run that scan. Be sure to install the Recovery Console if you are asked to do so. When the scan completes, a text window with your log will open. Please copy and paste that log back here. A caution - do not touch your mouse/keyboard until the scan has completed. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop. Allow the scan to run. When completed a text window will appear - please copy/paste the contents back here. This log can also be found at C:\ComboFix.txt.
Click here and help my friend help stop leukemia, lymphoma, Hodgkin lymphoma and myeloma from taking more lives. Back to Top
urbane New Member Date Joined Nov 2009 Total Posts : 30 Posted 11-23-2009 9:33 (GMT +2) Done, here it is ComboFix 09-11-22.04 - Owner 11/23/2009 18:22.1.1 - x86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2047.1659 [GMT 11:00] Running from: c:\documents and settings\Owner\Desktop\456out.com.exe . ((((((((((((((((((((((((( Files Created from 2009-10-23 to 2009-11-23 ))))))))))))))))))))))))))))))) . 2009-11-22 06:56 . 2009-11-22 07:08 -------- d-----w- c:\program files\trend micro 2009-11-22 06:56 . 2009-11-22 06:56 -------- d-----w- C:\rsit 2009-11-20 21:11 . 2009-11-23 06:57 11289 ----a-w- c:\windows\system32\nvModes.dat 2009-11-20 08:25 . 2009-11-23 07:00 -------- d-----w- c:\documents and settings\Owner\Application Data\vlc 2009-11-20 08:24 . 2009-11-20 08:24 -------- d-----w- c:\program files\VideoLAN 2009-11-20 07:16 . 2009-11-20 07:16 -------- d-----w- C:\SamRO 2009-11-20 06:50 . 2009-11-20 07:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy 2009-11-20 06:50 . 2009-11-20 06:56 -------- d-----w- c:\program files\Spybot - Search & Destroy 2009-11-20 06:11 . 2009-11-20 06:11 -------- d-----w- c:\documents and settings\Owner\Application Data\AVG8 2009-11-20 06:10 . 2009-11-20 06:10 -------- d-----w- c:\documents and settings\Owner\Application Data\Malwarebytes 2009-11-20 06:10 . 2009-09-10 03:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-11-20 06:10 . 2009-11-20 06:10 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-11-20 06:10 . 2009-11-20 06:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-11-20 06:10 . 2009-09-10 03:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-11-21 20:16 . 2009-11-19 05:25 76487 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat 2009-11-20 20:01 . 2009-11-19 14:37 -------- d-----w- c:\program files\Yahoo! 2009-11-20 17:52 . 2009-11-20 17:52 148736 ----a-w- c:\documents and settings\All Users\Application Data\hpeED.dll 2009-11-20 17:52 . 2009-11-20 17:52 148736 ----a-w- c:\documents and settings\All Users\Application Data\hpeED.dll 2009-11-20 17:52 . 2009-11-20 17:52 -------- d-----w- c:\program files\Sony Ericsson 2009-11-20 17:52 . 2009-11-20 17:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Sony Ericsson 2009-11-20 17:52 . 2009-11-19 05:36 -------- d--h--w- c:\program files\InstallShield Installation Information 2009-11-19 14:45 . 2009-11-19 14:44 -------- d-----w- c:\documents and settings\Owner\Application Data\Yahoo! 2009-11-19 14:44 . 2009-11-19 14:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! 2009-11-19 06:43 . 2009-11-19 06:43 -------- d-----w- c:\documents and settings\Owner\Application Data\Media Player Classic 2009-11-19 06:35 . 2009-11-19 06:35 12328 ----a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-11-19 06:32 . 2009-11-19 06:32 -------- d-----w- c:\documents and settings\Owner\Application Data\Leadertech 2009-11-19 06:20 . 2009-11-19 06:20 -------- d-----w- c:\program files\Common Files\Adobe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Messenger (Yahoo!)"="c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe" [2009-11-10 5317944] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1385808] "NVRaidService"="c:\windows\system32\nvraidservice.exe" [2004-11-01 166400] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2004-11-14 86016] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-11-14 4620288] "D-Link D-Link Wireless G DWA-110"="c:\program files\D-Link\D-Link Wireless G DWA-110\AirGCFG.exe" [2007-05-03 1736704] "ANIWZCS2Service"="c:\program files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2007-01-19 131072] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-02 113520] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 1009016] "SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2004-11-15 155648] "nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2004-11-14 995328] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableLUA"= 0 (0x0) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system] "DisableTaskMgr"= 1 (0x1) "DisableRegistryTools"= 1 (0x1) [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 "FirewallOverride"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc] "AntiVirusOverride"=dword:00000001 "AntiVirusDisableNotify"=dword:00000001 "FirewallDisableNotify"=dword:00000001 "FirewallOverride"=dword:00000001 "UpdatesDisableNotify"=dword:00000001 "UacDisableNotify"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Documents and Settings\\Owner\\Desktop\\Firefox Setup 3.5.5.exe"= "c:\\WINDOWS\\system32\\wscntfy.exe"= "c:\\WINDOWS\\system32\\DllHost.exe"= "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "c:\\Program Files\\ANI\\ANIWZCS2 Service\\ANIWZCSdS.exe"= "c:\\Program Files\\ANI\\ANIWZCS2 Service\\WZCSLDR2.exe"= "c:\\SamRO\\RO\\VanRO.exe"= "c:\\WINDOWS\\system32\\taskmgr.exe"= "c:\\Program Files\\D-Link\\D-Link Wireless G DWA-110\\AirGCFG.exe"= "d:\\My Documents\\VanRO\\RO\\VanRO.exe"= "c:\\WINDOWS\\SOUNDMAN.EXE"= "c:\\SamRO\\RO\\SamRO.exe"= "c:\\Program Files\\Mozilla Firefox\\firefox.exe"= "c:\\Program Files\\Sony Ericsson\\Sony Ericsson PC Suite\\SupServ.exe"= R3 abp470n5;abp470n5;\??\c:\windows\system32\drivers\nhnjln.sys --> c:\windows\system32\drivers\nhnjln.sys [?] R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [11/21/2009 4:52 AM 27632] S2 OMSI download service;Sony Ericsson OMSI download service;c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [11/21/2009 4:52 AM 172032] S3 s1018bus;Sony Ericsson Device 1018 driver (WDM);c:\windows\system32\drivers\s1018bus.sys [11/21/2009 4:52 AM 86824] S3 s1018mdfl;Sony Ericsson Device 1018 USB WMC Modem Filter;c:\windows\system32\drivers\s1018mdfl.sys [11/21/2009 4:52 AM 15016] S3 s1018mdm;Sony Ericsson Device 1018 USB WMC Modem Driver;c:\windows\system32\drivers\s1018mdm.sys [11/21/2009 4:52 AM 114728] S3 s1018mgmt;Sony Ericsson Device 1018 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s1018mgmt.sys [11/21/2009 4:52 AM 106208] S3 s1018nd5;Sony Ericsson Device 1018 USB Ethernet Emulation (NDIS);c:\windows\system32\drivers\s1018nd5.sys [11/21/2009 4:52 AM 26024] S3 s1018obex;Sony Ericsson Device 1018 USB WMC OBEX Interface;c:\windows\system32\drivers\s1018obex.sys [11/21/2009 4:52 AM 104744] S3 s1018unic;Sony Ericsson Device 1018 USB Ethernet Emulation (WDM);c:\windows\system32\drivers\s1018unic.sys [11/21/2009 4:52 AM 109864] --- Other Services/Drivers In Memory --- *NewlyCreated* - NPKCRYPT . . ------- Supplementary Scan ------- . FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\ra4q4zbh.default\ FF - prefs.js: browser.startup.homepage - www.google.com FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll ---- FIREFOX POLICIES ---- c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-11-23 18:24 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'explorer.exe'(628) c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . Completion time: 2009-11-23 18:25 ComboFix-quarantined-files.txt 2009-11-23 07:25 Pre-Run: 60,800,569,344 bytes free Post-Run: 60,957,458,432 bytes free WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect - - End Of File - - 11E3F9634207DBD20F0D7336091B4A55 Back to Top
Jintan Senior Member Date Joined Dec 2006 Total Posts : 1424 Posted 11-23-2009 3:12 (GMT +2) Not seeing any actual changes by ComboFix just then. But let's act on what shows now, and check one unusual service as well. Be sure to continue to temporarily disable any protective software when running the scan tools we use here. Open notepad (go to Start, Run, type notepad and press Enter) and copy/paste the text in the codebox below into it:KillAll:: Driver:: abp470n5 File:: c:\windows\system32\drivers\nhnjln.sys c:\documents and settings\All Users\Application Data\hpeED.dll Registry:: [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "c:\\Documents and Settings\\Owner\\Desktop\\Firefox Setup 3.5.5.exe"=- "c:\\WINDOWS\\system32\\wscntfy.exe"=- "c:\\WINDOWS\\system32\\DllHost.exe"=- "c:\\WINDOWS\\system32\\taskmgr.exe"=- "c:\\WINDOWS\\SOUNDMAN.EXE"=- "c:\\Program Files\\Mozilla Firefox\\firefox.exe"=- [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system] "DisableTaskMgr"=- "DisableRegistryTools"=- [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000000 "FirewallOverride"=dword:00000000 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc] "AntiVirusOverride"=dword:00000000 "AntiVirusDisableNotify"=dword:00000000 "FirewallDisableNotify"=dword:00000000 "FirewallOverride"=dword:00000000 "UpdatesDisableNotify"=dword:00000000 "UacDisableNotify"=- [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableLUA"=-
Save this to your desktop as CFScript.txt You should now have both ComboFix and that CFScript.txt on the desktop. Just left click/hold on the CFScript.txt file, and drag it into ComboFix to start the scan. ComboFix will now run as it did before. Allow the scan to run. When completed a text window will appear - please copy/paste the contents back here. This log can also be found at C:\ComboFix.txt. A caution - do not touch your mouse/keyboard until the scan has completed. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop. ---------------@ECHO OFF if exist winkey.txt del winkey.txt REG QUERY "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Irmon\Parameters" /v ServiceDll > winkey.txt notepad winkey.txt
Open Notepad (Start - Run, type notepad and press Enter). Copy/paste the above text into the open text box, then save this to your desktop as "cfgcheck.bat" Be sure to include the "" quotes in the name. Then click on cfgcheck.bat. When the scan completes a textbox will open - copy/paste those contents back here please. Post that and the new C:\ComboFix.txt log please.
Click here and help my friend help stop leukemia, lymphoma, Hodgkin lymphoma and myeloma from taking more lives. Back to Top
urbane New Member Date Joined Nov 2009 Total Posts : 30 Posted 11-23-2009 7:52 (GMT +2) here is the new combo fix with GFScript ComboFix 09-11-22.08 - Owner 11/24/2009 4:38.2.1 - x86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2047.1692 [GMT 11:00] Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt FILE :: "c:\documents and settings\All Users\Application Data\hpeED.dll" "c:\windows\system32\drivers\nhnjln.sys" . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\All Users\Application Data\hpeED.dll . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_ABP470N5 -------\Service_abp470n5 ((((((((((((((((((((((((( Files Created from 2009-10-23 to 2009-11-23 ))))))))))))))))))))))))))))))) . 2009-11-22 06:56 . 2009-11-22 07:08 -------- d-----w- c:\program files\trend micro 2009-11-22 06:56 . 2009-11-22 06:56 -------- d-----w- C:\rsit 2009-11-20 21:11 . 2009-11-23 17:27 11289 ----a-w- c:\windows\system32\nvModes.dat 2009-11-20 08:25 . 2009-11-23 14:33 -------- d-----w- c:\documents and settings\Owner\Application Data\vlc 2009-11-20 08:24 . 2009-11-20 08:24 -------- d-----w- c:\program files\VideoLAN 2009-11-20 07:16 . 2009-11-20 07:16 -------- d-----w- C:\SamRO 2009-11-20 06:50 . 2009-11-20 07:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy 2009-11-20 06:50 . 2009-11-20 06:56 -------- d-----w- c:\program files\Spybot - Search & Destroy 2009-11-20 06:11 . 2009-11-20 06:11 -------- d-----w- c:\documents and settings\Owner\Application Data\AVG8 2009-11-20 06:10 . 2009-11-20 06:10 -------- d-----w- c:\documents and settings\Owner\Application Data\Malwarebytes 2009-11-20 06:10 . 2009-09-10 03:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-11-20 06:10 . 2009-11-20 06:10 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-11-20 06:10 . 2009-11-20 06:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-11-20 06:10 . 2009-09-10 03:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-11-21 20:16 . 2009-11-19 05:25 76487 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat 2009-11-20 20:01 . 2009-11-19 14:37 -------- d-----w- c:\program files\Yahoo! 2009-11-20 17:52 . 2009-11-20 17:52 -------- d-----w- c:\program files\Sony Ericsson 2009-11-20 17:52 . 2009-11-20 17:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Sony Ericsson 2009-11-20 17:52 . 2009-11-19 05:36 -------- d--h--w- c:\program files\InstallShield Installation Information 2009-11-19 14:45 . 2009-11-19 14:44 -------- d-----w- c:\documents and settings\Owner\Application Data\Yahoo! 2009-11-19 14:44 . 2009-11-19 14:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! 2009-11-19 06:43 . 2009-11-19 06:43 -------- d-----w- c:\documents and settings\Owner\Application Data\Media Player Classic 2009-11-19 06:35 . 2009-11-19 06:35 12328 ----a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-11-19 06:32 . 2009-11-19 06:32 -------- d-----w- c:\documents and settings\Owner\Application Data\Leadertech 2009-11-19 06:20 . 2009-11-19 06:20 -------- d-----w- c:\program files\Common Files\Adobe . ((((((((((((((((((((((((((((( SnapShot@2009-11-23_07.24.21 ))))))))))))))))))))))))))))))))))))))))) . + 2009-11-23 17:42 . 2009-11-23 17:42 16384 c:\windows\temp\Perflib_Perfdata_378.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Messenger (Yahoo!)"="c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe" [2009-11-10 5317944] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NVRaidService"="c:\windows\system32\nvraidservice.exe" [2004-11-01 166400] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2004-11-14 86016] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-11-14 4620288] "Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1385808] "D-Link D-Link Wireless G DWA-110"="c:\program files\D-Link\D-Link Wireless G DWA-110\AirGCFG.exe" [2007-05-03 1736704] "ANIWZCS2Service"="c:\program files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2007-01-19 131072] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-02 113520] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 1009016] "SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2004-11-15 155648] "nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2004-11-14 995328] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableLUA"= 0 (0x0) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system] "DisableTaskMgr"= 1 (0x1) "DisableRegistryTools"= 1 (0x1) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "c:\\Program Files\\ANI\\ANIWZCS2 Service\\ANIWZCSdS.exe"= "c:\\Program Files\\ANI\\ANIWZCS2 Service\\WZCSLDR2.exe"= "c:\\SamRO\\RO\\VanRO.exe"= "c:\\Program Files\\D-Link\\D-Link Wireless G DWA-110\\AirGCFG.exe"= "d:\\My Documents\\VanRO\\RO\\VanRO.exe"= "c:\\SamRO\\RO\\SamRO.exe"= "c:\\Program Files\\Sony Ericsson\\Sony Ericsson PC Suite\\SupServ.exe"= "c:\\Program Files\\Adobe\\Reader 9.0\\Reader\\Reader_sl.exe"= R2 OMSI download service;Sony Ericsson OMSI download service;c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [11/21/2009 4:52 AM 172032] R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [11/21/2009 4:52 AM 27632] S3 s1018bus;Sony Ericsson Device 1018 driver (WDM);c:\windows\system32\drivers\s1018bus.sys [11/21/2009 4:52 AM 86824] S3 s1018mdfl;Sony Ericsson Device 1018 USB WMC Modem Filter;c:\windows\system32\drivers\s1018mdfl.sys [11/21/2009 4:52 AM 15016] S3 s1018mdm;Sony Ericsson Device 1018 USB WMC Modem Driver;c:\windows\system32\drivers\s1018mdm.sys [11/21/2009 4:52 AM 114728] S3 s1018mgmt;Sony Ericsson Device 1018 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s1018mgmt.sys [11/21/2009 4:52 AM 106208] S3 s1018nd5;Sony Ericsson Device 1018 USB Ethernet Emulation (NDIS);c:\windows\system32\drivers\s1018nd5.sys [11/21/2009 4:52 AM 26024] S3 s1018obex;Sony Ericsson Device 1018 USB WMC OBEX Interface;c:\windows\system32\drivers\s1018obex.sys [11/21/2009 4:52 AM 104744] S3 s1018unic;Sony Ericsson Device 1018 USB Ethernet Emulation (WDM);c:\windows\system32\drivers\s1018unic.sys [11/21/2009 4:52 AM 109864] --- Other Services/Drivers In Memory --- *NewlyCreated* - ABP470N5 . . ------- Supplementary Scan ------- . FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\ra4q4zbh.default\ FF - prefs.js: browser.startup.homepage - www.google.com FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll ---- FIREFOX POLICIES ---- c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-11-24 04:42 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'explorer.exe'(948) c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll c:\docume~1\Owner\LOCALS~1\Temp\catchme.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\nvsvc32.exe c:\windows\system32\dwwin.exe . ************************************************************************** . Completion time: 2009-11-24 04:45 - machine was rebooted ComboFix-quarantined-files.txt 2009-11-23 17:44 ComboFix2.txt 2009-11-23 07:25 Pre-Run: 60,823,932,928 bytes free Post-Run: 60,883,009,536 bytes free - - End Of File - - 8C83C9A969FB46AE435B0A975A8F1AB2 Back to Top
Jintan Senior Member Date Joined Dec 2006 Total Posts : 1424 Posted 11-24-2009 12:30 (GMT +2) Progress. That Registry check shows that service is legit. Let's see what might be still interfering there. Click here and download the installer for Gmer to your desktop, then click that file to run Gmer. If on it's opening scan Gmer locates items shown in red or indicates "hidden " or "rootkit ", stop there, and click on the Copy button and rightclick on your Desktop, choose "New" > Text document. Once the file is created, open it and rightclick again and choose Paste. Copy the information and post it here please. We don't want any crashes just from taking an initial look at things. If not, then click on Scan (before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while this scan completes. Also do not use your computer during the scan). When completed, click on the Copy button and rightclick on your Desktop, choose "New" > Text document. Once the file is created, open it and rightclick again and choose Paste. Copy the information and post it here please.
Click here and help my friend help stop leukemia, lymphoma, Hodgkin lymphoma and myeloma from taking more lives. Back to Top
urbane New Member Date Joined Nov 2009 Total Posts : 30 Posted 11-26-2009 3:27 (GMT +2) ok Regedit and Task manager are disabled again, seems the virus is back in full action. Ok i hope i did this right GMER 1.0.15.15252 - http://www.gmer.net Rootkit scan 2009-11-27 00:20:42 Windows 5.1.2600 Service Pack 2 Running: l0tkxmho.exe; Driver: C:\DOCUME~1\Owner\LOCALS~1\Temp\kxtdipow.sys ---- Kernel code sections - GMER 1.0.15 ---- ? C:\WINDOWS\system32\drivers\nhnjln.sys The system cannot find the file specified. ! ---- Devices - GMER 1.0.15 ---- AttachedDevice \FileSystem\Ntfs \Ntfs SiWinAcc.sys (Windows Accelerator Driver/Silicon Image, Inc.) ---- EOF - GMER 1.0.15 ---- Back to Top
urbane New Member Date Joined Nov 2009 Total Posts : 30 Posted 11-28-2009 10:18 (GMT +2) The command batch servcheck.bat worked... The command c:\windows\servicelook.txt didnt work... Back to Top
urbane New Member Date Joined Nov 2009 Total Posts : 30 Posted 11-28-2009 8:24 (GMT +2) Well I don't know, I did your instructions. batch servcheck.bat worked and it came up with a long list The other one didnt work tho, there was no servicelook.txt either. Back to Top
urbane New Member Date Joined Nov 2009 Total Posts : 30 Posted 11-30-2009 10:29 (GMT +2) Oh I thought they were 2 different commands batch servcheck.bat c:\windows\servicelook.txt sorry >.> Ok here it is: Abiosdsk Disabled abp470n5 Manual abp470n5 abp480n5 Disabled ACPI Boot Microsoft ACPI Driver ACPIEC Disabled adpu160m Disabled aec Manual Microsoft Kernel Acoustic Echo Canceller AFD System AFD Aha154x Disabled aic78u2 Disabled aic78xx Disabled ALCXWDM Manual Service for Realtek AC97 Audio (WDM) Alerter Disabled Alerter AliIde Disabled amsint Disabled ANIO Auto ANIO Service ANIWZCSdService Disabled ANIWZCSd Service AppMgmt Disabled Application Management Arp1394 Manual 1394 ARP Client Protocol asc Disabled asc3350p Disabled asc3550 Disabled AsyncMac Manual RAS Asynchronous Media Driver atapi Boot Standard IDE/ESDI Hard Disk Controller Atdisk Disabled Atmarpc Manual ATM ARP Client Protocol AudioSrv Disabled Windows Audio audstub Manual Audio Stub Driver Beep System BITS Disabled Background Intelligent Transfer Service Browser Disabled Computer Browser catchme Manual cbidf2k Disabled cd20xrnt Disabled Cdaudio System Cdfs Disabled Cdrom System CD-ROM Driver Changer System CiSvc Disabled Indexing Service ClipSrv Disabled ClipBook CmdIde Disabled COMSysApp Disabled COM+ System Application Cpqarray Disabled CryptSvc Disabled CryptSvc dac2w2k Disabled dac960nt Disabled DcomLaunch Auto DCOM Server Process Launcher Dhcp Disabled DHCP Client Disk Boot Disk Driver dmadmin Disabled Logical Disk Manager Administrative Service dmboot Disabled dmio Disabled dmload Disabled dmserver Disabled Logical Disk Manager DMusic Manual Microsoft Kernel DLS Syntheiszer Dnscache Disabled DNS Client dpti2o Disabled drmkaud Manual Microsoft Kernel DRM Audio Descrambler ERSvc Disabled Error Reporting Service Eventlog Disabled Event Log EventSystem Disabled COM+ Event System Fastfat Disabled FastUserSwitchingCompatibility Disabled Fast User Switching Compatibility Fdc Manual Floppy Disk Controller Driver Fips System Flpydisk Manual Floppy Disk Driver FltMgr Boot FltMgr Fs_Rec System Ftdisk Boot Volume Manager Driver Gpc Manual Generic Packet Classifier helpsvc Disabled Help and Support HidServ Disabled Human Interface Device Access hpn Disabled HTTP Manual HTTP HTTPFilter Disabled HTTP SSL i2omgmt System i2omp Disabled i8042prt System i8042 Keyboard and PS/2 Mouse Port Driver Imapi System CD-Burning Filter Driver ImapiService Disabled IMAPI CD-Burning COM Service ini910u Disabled IntelIde Disabled Ip6Fw Manual IPv6 Windows Firewall Driver IpFilterDriver Manual IP Traffic Filter Driver IpInIp Manual IP in IP Tunnel Driver IpNat Manual IP Network Address Translator IPSec System IPSEC driver irda Auto IrDA Protocol IRENUM Manual IR Enumerator Service Irmon Disabled Infrared Monitor irsir Manual Microsoft Serial Infrared Driver isapnp Boot PnP ISA/EISA Bus Driver Kbdclass System Keyboard Class Driver kmixer Manual Microsoft Kernel Wave Audio Mixer KSecDD Boot lanmanserver Disabled Server lanmanworkstation Disabled Workstation lbrtfdc System LmHosts Disabled TCP/IP NetBIOS Helper Messenger Disabled Messenger mnmdd System mnmsrvc Disabled NetMeeting Remote Desktop Sharing Modem Manual Mouclass System Mouse Class Driver MountMgr Boot mraid35x Disabled MRxDAV Manual WebDav Client Redirector MRxSmb System MRXSMB MSDTC Disabled Distributed Transaction Coordinator Msfs System MSIServer Disabled Windows Installer MSKSSRV Manual Microsoft Streaming Service Proxy MSPCLOCK Manual Microsoft Streaming Clock Proxy MSPQM Manual Microsoft Streaming Quality Manager Proxy mssmbios Manual Microsoft System Management BIOS Driver Mup Boot Mup NDIS Boot NDIS System Driver NdisTapi Manual Remote Access NDIS TAPI Driver Ndisuio Manual NDIS Usermode I/O Protocol NdisWan Manual Remote Access NDIS WAN Driver NDProxy Manual NDIS Proxy NetBIOS System NetBIOS Interface NetBT System NetBios over Tcpip NetDDE Disabled Network DDE NetDDEdsdm Disabled Network DDE DSDM Netlogon Disabled Net Logon Netman Disabled Network Connections NIC1394 Manual 1394 Net Driver Nla Disabled Network Location Awareness (NLA) Npfs System npkcrypt Manual npkcrypt Ntfs Disabled NtLmSsp Disabled NT LM Security Support Provider NtmsSvc Disabled Removable Storage Null System nv Manual nvatabus Boot NVENETFD Manual NVIDIA nForce Networking Controller Driver nvnetbus Manual NVIDIA Network Bus Enumerator nvraid Boot NVIDIA nForce(tm) RAID Class Driver NVSvc Disabled NVIDIA Display Driver Service NwlnkFlt Manual IPX Traffic Filter Driver NwlnkFwd Manual IPX Traffic Forwarder Driver ohci1394 Boot Texas Instruments OHCI Compliant IEEE 1394 Host Controller OMSI download service Disabled Sony Ericsson OMSI download service Parport Manual Parallel port driver PartMgr Boot ParVdm Auto PCI Boot PCI Bus Driver PCIDump System PCIIde Boot Pcmcia Disabled PDCOMP Manual PDFRAME Manual PDRELI Manual PDRFRAME Manual perc2 Disabled perc2hib Disabled PlugPlay Disabled Plug and Play PolicyAgent Disabled IPSEC Services PptpMiniport Manual WAN Miniport (PPTP) Processor System Processor Driver ProtectedStorage Disabled Protected Storage PSched Manual QoS Packet Scheduler Ptilink Manual Direct Parallel Link Driver ql1080 Disabled Ql10wnt Disabled ql12160 Disabled ql1240 Disabled ql1280 Disabled RasAcd System Remote Access Auto Connection Driver RasAuto Disabled Remote Access Auto Connection Manager Rasirda Manual WAN Miniport (IrDA) Rasl2tp Manual WAN Miniport (L2TP) RasMan Disabled Remote Access Connection Manager RasPppoe Manual Remote Access PPPOE Driver Raspti Manual Direct Parallel Rdbss System Rdbss RDPCDD System RDPWD Manual RDSessMgr Disabled Remote Desktop Help Session Manager redbook System Digital CD Audio Playback Filter Driver RemoteAccess Disabled Routing and Remote Access RpcLocator Manual Remote Procedure Call (RPC) Locator RpcSs Auto Remote Procedure Call (RPC) RSVP Disabled QoS RSVP RT73 Manual D-Link USB Wireless LAN Card Driver s1018bus Manual Sony Ericsson Device 1018 driver (WDM) s1018mdfl Manual Sony Ericsson Device 1018 USB WMC Modem Filter s1018mdm Manual Sony Ericsson Device 1018 USB WMC Modem Driver s1018mgmt Manual Sony Ericsson Device 1018 USB WMC Device Management Drivers (WDM) s1018nd5 Manual Sony Ericsson Device 1018 USB Ethernet Emulation (NDIS) s1018obex Manual Sony Ericsson Device 1018 USB WMC OBEX Interface s1018unic Manual Sony Ericsson Device 1018 USB Ethernet Emulation (WDM) SamSs Disabled Security Accounts Manager SCardSvr Disabled Smart Card Schedule Disabled Task Scheduler Secdrv Manual Secdrv seclogon Disabled Secondary Logon seehcri Manual Sony Ericsson seehcri Device Driver SENS Disabled System Event Notification serenum Manual Serenum Filter Driver Serial System Serial port driver Sfloppy System SharedAccess Disabled Windows Firewall/Internet Connection Sharing (ICS) ShellHWDetection Disabled Shell Hardware Detection Si3114r5 Boot SiI-3114 SoftRaid 5 Controller SiFilter Boot SATALink driver accelerator Simbad Disabled Sparrow Disabled splitter Manual Microsoft Kernel Audio Splitter Spooler Disabled Print Spooler sr Disabled System Restore Filter Driver srservice Disabled System Restore Service Srv Manual Srv SSDPSRV Disabled SSDP Discovery Service stisvc Disabled Windows Image Acquisition (WIA) swenum Manual Software Bus Driver swmidi Manual Microsoft Kernel GS Wavetable Synthesizer SwPrv Disabled MS Software Shadow Copy Provider symc810 Disabled symc8xx Disabled sym_hi Disabled sym_u3 Disabled sysaudio Manual Microsoft Kernel System Audio Device SysmonLog Disabled Performance Logs and Alerts TapiSrv Disabled Telephony Tcpip System TCP/IP Protocol Driver TDPIPE Manual TDTCP Manual TermDD System Terminal Device Driver TermService Disabled Terminal Services Themes Disabled Themes TosIde Disabled TrkWks Disabled Distributed Link Tracking Client Udfs Disabled ultra Disabled Update Manual Microcode Update Driver upnphost Disabled Universal Plug and Play Device Host UPS Disabled Uninterruptible Power Supply usbehci Manual Microsoft USB 2.0 Enhanced Host Controller Miniport Driver usbhub Manual USB2 Enabled Hub usbohci Manual Microsoft USB Open Host Controller Miniport Driver usbstor Manual USB Mass Storage Driver VgaSave System ViaIde Disabled VolSnap Boot VSS Disabled Volume Shadow Copy W32Time Disabled Windows Time Wanarp Manual Remote Access IP ARP Driver WDICA Manual wdmaud Manual Microsoft WINMM WDM Audio Compatibility Driver WebClient Disabled WebClient winmgmt Disabled Windows Management Instrumentation Winsock Manual WmdmPmSN Disabled Portable Media Serial Number Service WmiApSrv Disabled WMI Performance Adapter WMPNetworkSvc Disabled Windows Media Player Network Sharing Service WpdUsb Manual WpdUsb WS2IFSL System wscsvc Disabled Security Center wuauserv Disabled Automatic Updates WudfPf Boot Windows Driver Foundation - User-mode Driver Framework Platform Driver WudfRd Manual Windows Driver Foundation - User-mode Driver Framework Reflector WudfSvc Disabled Windows Driver Foundation - User-mode Driver Framework WZCSVC Disabled Wireless Zero Configuration xmlprov Disabled Network Provisioning Service yukonwxp Manual NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller Back to Top
Jintan Senior Member Date Joined Dec 2006 Total Posts : 1424 Posted 12-2-2009 2:21 (GMT +2) Good you got that worked out. But no infection services showing here, and the last Gmer log indicating something loading itself. Download Gmer's mbr.exe from here and place it on your C drive (so the file is then C:\mbr.exe). Go to Start - Run, type cmd (and press OK). At the prompt type or copy/paste the following, pressing Enter after each:cd\ mbr.exe -t Then type exit and press Enter to close the command window. The report created in the command window will have been saved to C:\mbr.log. Locate that and post it here please. ----------------- Open Gmer again. This time just right click in the white space in the display and select Options - Only non MS files . Then click Scan and allow Gmer to run a different scan. Once that completes click on the Copy button and rightclick on your Desktop, choose "New" > Text document. Once the file is created, open it and rightclick again and choose Paste. Copy the information and post it here please. Back to Top
urbane New Member Date Joined Nov 2009 Total Posts : 30 Posted 12-2-2009 7:53 (GMT +2) Can you post another link please, that doesn't work Back to Top
Jintan Senior Member Date Joined Dec 2006 Total Posts : 1424 Posted 12-3-2009 1:08 (GMT +2) Sorry - some of my pre-made steps include links that don't work in this forum's software. This is the download for that. Back to Top
urbane New Member Date Joined Nov 2009 Total Posts : 30 Posted 12-4-2009 6:29 (GMT +2) Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net device: opened successfully user: MBR read successfully called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll nvatabus.sys kernel: MBR read successfully user & kernel MBR OK Back to Top
Jintan Senior Member Date Joined Dec 2006 Total Posts : 1424 Posted 12-5-2009 1:57 (GMT +2) That indicates none of the newer boot level driver files being misused, so okay in that area. I did not answer this earlier: "I cannot use gpedit.msc" That would only be with CP Pro, not the Home version you have there. "When I delete the disable task manager values in regedit" What did you mean by that please? More curious what steps those were for what results. Post back on all that, and run and post a new Gmer scan log please. I sense the earlier file it showed might be part of some tool that was run there, that would have been removed once the system reboots. Back to Top
urbane New Member Date Joined Nov 2009 Total Posts : 30 Posted 12-5-2009 8:03 (GMT +2) The virus makes these registries HKEY_CURRENT_USER/software/Microsoft/Windows/Currentversion/Policies/system DisableRegistryTools Reg Dword 0x00000001 (1) HKEY_CURRENT_USER/software/Microsoft/Windows/Currentversion/Policies/system DisableTaskMgr Reg Dword 0x00000001 (1) Thus disabling both Task manager and regedit Here is what I use to get into task manager... i need to somehow delete this registry without being in regedit: HKEY_CURRENT_USER/software/Microsoft/Windows/Currentversion/Policies/system DisableRegistryTools Reg Dword 0x00000001 (1) I use regtools.vbs to do this, here is the link with the code: http://www.dougknox.com/security/scripts/regtools.vbs That allows me about 2 seconds to quickly go run>regedit before the virus remakes the disableregistrytools Then when I am in regedit I delete the 2 registries in the picture above. The virus remakes them in about 2 seconds or less, so I have about 2 seconds or less to hit ctrl+alt+del before the virus remakes those registries and disables Task Manager. That is how I get into Task manager... ok here is you re-scan: GMER 1.0.15.15252 - http://www.gmer.net Rootkit scan 2009-12-05 17:02:28 Windows 5.1.2600 Service Pack 2 Running: l0tkxmho.exe; Driver: C:\DOCUME~1\Owner\LOCALS~1\Temp\kxtdipow.sys ---- Kernel code sections - GMER 1.0.15 ---- ? C:\WINDOWS\system32\drivers\flnipn.sys The system cannot find the file specified. ! ? C:\DOCUME~1\Owner\LOCALS~1\Temp\mbr.sys The system cannot find the file specified. ! ---- Devices - GMER 1.0.15 ---- AttachedDevice \FileSystem\Ntfs \Ntfs SiWinAcc.sys (Windows Accelerator Driver/Silicon Image, Inc.) ---- EOF - GMER 1.0.15 ---- Back to Top
Jintan Senior Member Date Joined Dec 2006 Total Posts : 1424 Posted 12-6-2009 12:49 (GMT +2) Thanks for clearing that up. Gmer shows the malware driver file changed names, which suggests a change during reboot procedure. No malware services being located, to pinpoint what is using the file. Which we truly need right now, to get the repairs going there. Open Gmer again. This time just right click in the white space in the display and select Options - Only non MS files . Then click Scan and allow Gmer to run a different scan. Once that completes click on the Copy button and rightclick on your Desktop, choose "New" > Text document. Once the file is created, open it and rightclick again and choose Paste. Copy the information and post it here please. --------------- Go here and download reglooks.exe to your Desktop. Doubleclick on it to run it and when it has finished scanning, a log named result.txt will open in Notepad. Copy the log and post it in this thread. Back to Top
urbane New Member Date Joined Nov 2009 Total Posts : 30 Posted 12-6-2009 3:31 (GMT +2) Here is GMER: GMER 1.0.15.15252 - http://www.gmer.net Rootkit scan 2009-12-06 12:27:15 Windows 5.1.2600 Service Pack 2 Running: l0tkxmho.exe; Driver: C:\DOCUME~1\Owner\LOCALS~1\Temp\kxtdipow.sys ---- Modules - GMER 1.0.15 ---- Module nvraid.sys (NVIDIA® nForce(TM) RAID Driver/NVIDIA Corporation) BA738000-BA749000 (69632 bytes) Module Si3114r5.sys (SATA SoftRAID 5 miniport driver/Silicon Image, Inc) BA6F3000-BA720000 (184320 bytes) Module nvatabus.sys (NVIDIA® nForce(TM) IDE Performance Driver/NVIDIA Corporation) BA6C6000-BA6DB000 (86016 bytes) Module SiWinAcc.sys (Windows Accelerator Driver/Silicon Image, Inc.) BACBC000-BACBF000 (12288 bytes) Module PxHelp20.sys (Px Engine Device Driver for Windows 2000/XP/Sonic Solutions) BA918000-BA922000 (40960 bytes) Module \SystemRoot\system32\drivers\ALCXWDM.SYS (Realtek AC'97 Audio Driver (WDM)/Realtek Semiconductor Corp.) B99DF000-B9C10000 (2297856 bytes) Module \SystemRoot\system32\DRIVERS\nvnetbus.sys (NVIDIA Networking Bus Driver./NVIDIA Corporation) BAD78000-BAD7C000 (16384 bytes) Module \SystemRoot\system32\DRIVERS\NVNRM.SYS (NVIDIA Network Resource Manager./NVIDIA Corporation) B9958000-B9998000 (262144 bytes) Module \SystemRoot\system32\DRIVERS\NVSNPU.SYS (NVIDIA Networking Soft-NPU Driver./NVIDIA Corporation) B9925000-B9958000 (208896 bytes) Module \SystemRoot\system32\DRIVERS\yk51x86.sys (NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller/Marvell) B98EE000-B9925000 (225280 bytes) Module \SystemRoot\system32\DRIVERS\nv4_mini.sys (NVIDIA Compatible Windows 2000 Miniport Driver, Version 66.93 /NVIDIA Corporation) B963B000-B98EE000 (2830336 bytes) Module \SystemRoot\system32\DRIVERS\ptilink.sys (Parallel Technologies DirectParallel IO Library/Parallel Technologies, Inc.) BAB90000-BAB95000 (20480 bytes) Module \SystemRoot\system32\DRIVERS\seehcri.sys (seehcri Driver/Sony Ericsson Mobile Communications) BABA0000-BABA6000 (24576 bytes) Module \SystemRoot\system32\DRIVERS\NVENETFD.sys (NVIDIA Networking Function Driver./NVIDIA Corporation) B6D74000-B6D7D000 (36864 bytes) Module \SystemRoot\system32\DRIVERS\Dr71WU.sys (Ralink 802.11 USB Wireless Adapter Driver/Ralink Technology, Corp.) AED7D000-AEDE6000 (430080 bytes) Module \SystemRoot\System32\nv4_disp.dll (NVIDIA Compatible Windows 2000 Display driver, Version 66.93 /NVIDIA Corporation) BF9D3000-BFD64000 (3739648 bytes) Module \??\C:\WINDOWS\system32\ANIO.SYS (ANIO (NT5) Driver /Alpha Networks Inc.) AF900000-AF907000 (28672 bytes) Module \??\C:\WINDOWS\system32\drivers\flnipn.sys BADDE000-BADE0000 (8192 bytes) Module \??\D:\My_Documents\VanRO\RO\npkcrypt.sys (nProtect KeyCrypt Driver/INCA Internet Co., Ltd.) AF3AF000-AF3B4000 (20480 bytes) Module \??\C:\DOCUME~1\Owner\LOCALS~1\Temp\kxtdipow.sys (GMER) 9D5CA000-9D5E1000 (94208 bytes) ---- Processes - GMER 1.0.15 ---- Process C:\WINDOWS\explorer.exe (Windows Explorer/Microsoft Corporation) 356 Library C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll (PDF Shell Extension/Adobe Systems, Inc.) 0x10000000 Library C:\WINDOWS\system32\dxmasf.dll 0x6BF50000 Library C:\WINDOWS\system32\lameACM.acm (Lame MP3 codec engine/http://www.mp3dev.org/) 0x039D0000 Process C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Driver Helper Service, Version 66.93/NVIDIA Corporation) 468 Library C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Driver Helper Service, Version 66.93/NVIDIA Corporation) 0x00400000 Process C:\WINDOWS\System32\svchost.exe (Generic Host Process for Win32 Services/Microsoft Corporation) 1072 Library C:\WINDOWS\System32\strmfilt.dll (Stream Filter Library/Microsoft Corporation) 0x6F290000 Process C:\Program Files\Skype\Plugin Manager\skypePM.exe (Skype Extras Manager/Skype Technologies) 2832 Library C:\Program Files\Skype\Plugin Manager\skypePM.exe (Skype Extras Manager/Skype Technologies) 0x00400000 Library C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll (Skype Extras Manager Utilites/EasyBits Media AS) 0x00970000 Process C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation) 3612 Library C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation) 0x00400000 Library C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) 0x10000000 Library C:\Program Files\Mozilla Firefox\sqlite3.dll (SQLite Database Library/sqlite.org) 0x00270000 Library C:\Program Files\Mozilla Firefox\MOZCRT19.dll (User-Generated Microsoft (R) C/C++ Runtime Library/Mozilla Foundation) 0x78130000 Library C:\Program Files\Mozilla Firefox\js3250.dll (Netscape 32-bit JavaScript Module/Netscape Communications Corporation) 0x002F0000 Library C:\Program Files\Mozilla Firefox\nspr4.dll (NSPR Library/Mozilla Foundation) 0x004E0000 Library C:\Program Files\Mozilla Firefox\smime3.dll (NSS S/MIME Library/Mozilla Foundation) 0x003E0000 Library C:\Program Files\Mozilla Firefox\nss3.dll (NSS Base Library/Mozilla Foundation) 0x00510000 Library C:\Program Files\Mozilla Firefox\nssutil3.dll (NSS Utility Library/Mozilla Foundation) 0x005B0000 Library C:\Program Files\Mozilla Firefox\plc4.dll (PLC Library/Mozilla Foundation) 0x005D0000 Library C:\Program Files\Mozilla Firefox\plds4.dll (PLDS Library/Mozilla Foundation) 0x005E0000 Library C:\Program Files\Mozilla Firefox\ssl3.dll (NSS SSL Library/Mozilla Foundation) 0x005F0000 Library C:\WINDOWS\system32\USP10.dll (Uniscribe Unicode script processor/Microsoft Corporation) 0x74D90000 Library C:\Program Files\Mozilla Firefox\xpcom.dll (Mozilla Foundation) 0x00610000 Library C:\Program Files\Mozilla Firefox\components\browserdirprovider.dll (Mozilla Foundation) 0x01240000 Library C:\Program Files\Mozilla Firefox\components\brwsrcmp.dll (Mozilla Foundation) 0x015B0000 Library C:\Program Files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\PNRComponent.dll (Skype phone number parser helper library for FireFox browser addon/Skype Technologies S.A.) 0x02450000 Library C:\Program Files\Skype\Toolbars\Shared\SkypePnr.dll (Skype Phone number parser/Skype Technologies S.A.) 0x02600000 Library C:\Program Files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll (Name parser helper object for Skype Firefox addon/Skype Technologies S.A.) 0x02A20000 Library C:\Program Files\Mozilla Firefox\softokn3.dll (NSS PKCS #11 Library/Mozilla Foundation) 0x03310000 Library C:\Program Files\Mozilla Firefox\nssdbm3.dll (Legacy Database Driver/Mozilla Foundation) 0x03340000 Library C:\Program Files\Mozilla Firefox\freebl3.dll (NSS freebl Library/Mozilla Foundation) 0x03360000 Library C:\Program Files\Mozilla Firefox\nssckbi.dll (NSS Builtin Trusted Root CAs/Mozilla Foundation) 0x033B0000 Library C:\Program Files\Skype\Toolbars\Shared\SkypeBrowserOptions.dll (Skype plug-in settings dialog/Skype Technologies S.A.) 0x0A610000 Library C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll 0x06900000 Process C:\Program Files\Skype\Phone\Skype.exe (Skype /Skype Technologies S.A.) 4652 Library C:\Program Files\Skype\Phone\Skype.exe (Skype /Skype Technologies S.A.) 0x00400000 Library C:\WINDOWS\system32\devenum.dll 0x75F40000 Library C:\WINDOWS\system32\msdmo.dll 0x736B0000 Process C:\DOCUME~1\Owner\LOCALS~1\Temp\ccda.exe 4876 Library C:\DOCUME~1\Owner\LOCALS~1\Temp\ccda.exe 0x00400000 Process C:\Documents and Settings\Owner\Desktop\l0tkxmho.exe 5400 Library C:\Documents and Settings\Owner\Desktop\l0tkxmho.exe 0x00400000 ---- Services - GMER 1.0.15 ---- Service C:\WINDOWS\system32\drivers\flnipn.sys [MANUAL] abp470n5 Service C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek AC'97 Audio Driver (WDM)/Realtek Semiconductor Corp.) [MANUAL] ALCXWDM Service C:\WINDOWS\system32\ANIO.SYS (ANIO (NT5) Driver /Alpha Networks Inc.) [AUTO] ANIO Service C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe (ANIWZCS2 Service Launcher/Wireless Service) [AUTO] ANIWZCSdService Service C:\ComboFix\catchme.sys [MANUAL] catchme Service D:\My Documents\VanRO\RO\npkcrypt.sys (nProtect KeyCrypt Driver/INCA Internet Co., Ltd.) [MANUAL] npkcrypt Service C:\WINDOWS\system32\DRIVERS\nv4_mini.sys (NVIDIA Compatible Windows 2000 Miniport Driver, Version 66.93 /NVIDIA Corporation) [MANUAL] nv Service C:\WINDOWS\system32\DRIVERS\nvatabus.sys (NVIDIA® nForce(TM) IDE Performance Driver/NVIDIA Corporation) [BOOT] nvatabus Service C:\WINDOWS\system32\DRIVERS\NVENETFD.sys (NVIDIA Networking Function Driver./NVIDIA Corporation) [MANUAL] NVENETFD Service C:\WINDOWS\system32\DRIVERS\nvnetbus.sys (NVIDIA Networking Bus Driver./NVIDIA Corporation) [MANUAL] nvnetbus Service C:\WINDOWS\system32\DRIVERS\nvraid.sys (NVIDIA® nForce(TM) RAID Driver/NVIDIA Corporation) [BOOT] nvraid Service C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Driver Helper Service, Version 66.93/NVIDIA Corporation) [AUTO] NVSvc Service C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [AUTO] OMSI download service Service C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies DirectParallel IO Library/Parallel Technologies, Inc.) [MANUAL] Ptilink Service C:\WINDOWS\System32\Drivers\PxHelp20.sys (Px Engine Device Driver for Windows 2000/XP/Sonic Solutions) [BOOT] PxHelp20 Service C:\WINDOWS\system32\DRIVERS\Dr71WU.sys (Ralink 802.11 USB Wireless Adapter Driver/Ralink Technology, Corp.) [MANUAL] RT73 Service C:\WINDOWS\system32\DRIVERS\s1018bus.sys (Sony Ericsson Device 1018 Driver/MCCI Corporation) [MANUAL] s1018bus Service C:\WINDOWS\system32\DRIVERS\s1018mdfl.sys (Sony Ericsson Device 1018 USB WMC Modem Filter Driver/MCCI Corporation) [MANUAL] s1018mdfl Service C:\WINDOWS\system32\DRIVERS\s1018mdm.sys (Sony Ericsson Device 1018 USB WMC Modem WDM Driver/MCCI Corporation) [MANUAL] s1018mdm Service C:\WINDOWS\system32\DRIVERS\s1018mgmt.sys (Sony Ericsson Device 1018 USB WMC Device Management Driver/MCCI Corporation) [MANUAL] s1018mgmt Service C:\WINDOWS\system32\DRIVERS\s1018nd5.sys (Ericsson Mobile Platform S1018 USB WMC Extended Ethernet (NDIS 5 Miniport)/MCCI Corporation) [MANUAL] s1018nd5 Service C:\WINDOWS\system32\DRIVERS\s1018obex.sys (Sony Ericsson Device 1018 USB WMC OBEX Interface Device Driver/MCCI Corporation) [MANUAL] s1018obex Service C:\WINDOWS\system32\DRIVERS\s1018unic.sys (Sony Ericsson Device 1018 USB Ethernet Emulation/MCCI Corporation) [MANUAL] s1018unic Service C:\WINDOWS\system32\DRIVERS\secdrv.sys [MANUAL] Secdrv Service C:\WINDOWS\system32\DRIVERS\seehcri.sys (seehcri Driver/Sony Ericsson Mobile Communications) [MANUAL] seehcri Service C:\WINDOWS\system32\DRIVERS\Si3114r5.sys (SATA SoftRAID 5 miniport driver/Silicon Image, Inc) [BOOT] Si3114r5 Service C:\WINDOWS\system32\DRIVERS\SiWinAcc.sys (Windows Accelerator Driver/Silicon Image, Inc.) [BOOT] SiFilter Service C:\WINDOWS\system32\DRIVERS\yk51x86.sys (NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller/Marvell) [MANUAL] yukonwxp ---- EOF - GMER 1.0.15 ---- here is the reglooks: REGLOOKS logfile - version 0.983 Scan started: Sun 12/06/2009 12:29:25.03 --- INFORMATION --- Manufacturer: NVIDIA - Model: AWRDACPI Operating System: Microsoft Windows XP Home Edition -- 5.1.2600 -- Service Pack 2 -- Processor: AMD Athlon(tm) 64 Processor 3500+ Work Station Bootmode: Normal boot Total RAM: 2047 MB (free 1468 MB - 71%) Computername: TYLER Domain: MSHOME User: Owner (Administrator account) Bootdevice: \Device\HarddiskVolume1 Systemdrive: C: Windowsdirectory: C:\WINDOWS Systemdirectory: C:\WINDOWS\system32 Internet Explorer Version: 6.0.2900.2180 --- SIGCHECK --- C:\WINDOWS\explorer.exe -- [1032192] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\appmgmts.dll NOT found C:\WINDOWS\system32\browser.dll -- [77312] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\comres.dll -- [792064] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\comctl32.dll -- [611328] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\cryptsvc.dll -- [60416] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\ctfmon.exe -- [15360] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\es.dll -- [243200] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\eventlog.dll -- [55808] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\ias.dll NOT found C:\WINDOWS\system32\imm32.dll -- [110080] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\kernel32.dll -- [983552] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\linkinfo.dll -- [18944] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\lpk.dll -- [22016] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\lsass.exe -- [13312] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\mfc40u.dll -- [924432] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\msgsvc.dll -- [33792] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\mshtml.dll -- [3003392] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\mspmsnsv.dll -- [27136] -- [10/18/2006 09:47 PM] -- sigcheck OK C:\WINDOWS\system32\mswsock.dll -- [245248] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\netlogon.dll -- [407040] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\netman.dll -- [198144] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\ntkrnlpa.exe -- [2056832] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\ntmssvc.dll -- [435200] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\ntoskrnl.exe -- [2180992] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\pchsvc.dll NOT found C:\WINDOWS\system32\powrprof.dll -- [17408] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\qmgr.dll -- [382464] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\rasauto.dll -- [89088] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\regsvc.dll -- [59904] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\rpcss.dll -- [395776] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\scecli.dll -- [180224] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\schedsvc.dll -- [190976] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\services.exe -- [108032] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\sfc.dll -- [5120] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\sfcfiles.dll -- [1580544] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\spoolsv.exe -- [57856] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\srsvc.dll -- [170496] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\ssdpsrv.dll -- [71680] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\svchost.exe -- [14336] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\tapisrv.dll -- [246272] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\termsrv.dll -- [295424] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\upnphost.dll -- [185344] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\user32.dll -- [577024] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\userinit.exe -- [24576] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\wininet.dll -- [656384] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\winlogon.exe -- [502272] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\ws2_32.dll -- [82944] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\wscntfy.exe -- [13824] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\wuauclt.exe -- [111104] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\xmlprov.dll -- [129536] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\drivers\acpiec.sys -- [11648] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\drivers\aec.sys -- [142464] -- [08/03/2004 10:39 PM] -- sigcheck OK C:\WINDOWS\system32\drivers\asyncmac.sys -- [14336] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\drivers\beep.sys -- [4224] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\drivers\ip6fw.sys -- [29056] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\drivers\kbdclass.sys -- [24576] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\drivers\ndis.sys -- [182912] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\drivers\ntfs.sys -- [574592] -- [08/04/2004 11:00 PM] -- sigcheck OK C:\WINDOWS\system32\drivers\tcpip.sys -- [359040] -- [08/04/2004 11:00 PM] -- sigcheck OK --- SSODL regkeys --- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] "PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}" -- File: %SystemRoot%\system32\SHELL32.dll -- [?] "CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}" -- File: %SystemRoot%\system32\SHELL32.dll -- [?] "WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" -- File: %Systemroot%\system32\webcheck.dll -- [?] "SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}" -- File: %systemroot%\system32\stobject.dll -- [?] "WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}" -- File: C:\WINDOWS\system32\WPDShServiceObj.dll -- [133632] -- [10/18/2006 09:47 PM] --- STS regkeys --- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader" -- File: %SystemRoot%\system32\browseui.dll -- [?] "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon" -- File: %SystemRoot%\system32\browseui.dll -- [?] --- USERINIT regkey --- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "Userinit"="C:\\WINDOWS\\system32\\userinit.exe," File: C:\WINDOWS\system32\userinit.exe -- [24576] -- [08/04/2004 11:00 PM] --- SHELL regkey --- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "Shell"="Explorer.exe" File: C:\WINDOWS\Explorer.exe -- [1032192] -- [08/04/2004 11:00 PM] --- SYSTEM regkey --- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" --- APPINIT_DLLS regkey --- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] no AppInit_DLLs regkey found --- NOTIFY regkey --- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain] -- File: C:\WINDOWS\system32\crypt32.dll -- [597504] -- [08/04/2004 11:00 PM] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet] -- File: C:\WINDOWS\system32\cryptnet.dll -- [63488] -- [08/04/2004 11:00 PM] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll] -- File: C:\WINDOWS\system32\cscdll.dll -- [101888] -- [08/04/2004 11:00 PM] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp] -- File: C:\WINDOWS\system32\wlnotify.dll -- [92672] -- [08/04/2004 11:00 PM] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule] -- File: C:\WINDOWS\system32\wlnotify.dll -- [92672] -- [08/04/2004 11:00 PM] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy] -- File: C:\WINDOWS\system32\sclgntfy.dll -- [20992] -- [08/04/2004 11:00 PM] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn] -- File: C:\WINDOWS\system32\WlNotify.dll -- [92672] -- [08/04/2004 11:00 PM] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv] -- File: C:\WINDOWS\system32\wlnotify.dll -- [92672] -- [08/04/2004 11:00 PM] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon] -- File: C:\WINDOWS\system32\wlnotify.dll -- [92672] -- [08/04/2004 11:00 PM] --- RUN / LOAD regkeys --- [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows] no run / load keys found --- SHELLEXECUTEHOOKS regkey --- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"="" -- File: shell32.dll -- [?] --- HKLM AUTORUN regkeys --- [HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor] no AutoRun regkey found --- HKCU AUTORUN regkeys --- [HKEY_CURRENT_USER\Software\Microsoft\Command Processor] no AutoRun regkey found --- HKLM\RUN regkey --- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SoundMan" -- File: SOUNDMAN.EXE -- [?] "nwiz" -- File: nwiz.exe /installquiet -- [?] "NVRaidService" -- File C:\WINDOWS\system32\nvraidservice.exe -- [166400] -- [11/02/2004 09:55 AM] "NvMediaCenter" -- File: RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit -- [?] "NvCplDaemon" -- File: RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup -- [?] "Malwarebytes Anti-Malware (reboot)" -- File: "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript -- [?] "D-Link D-Link Wireless G DWA-110" -- File: C:\Program Files\D-Link\D-Link Wireless G DWA-110\AirGCFG.exe -- [?] "ANIWZCS2Service" -- File C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe -- [131072] -- [01/19/2007 11:49 AM] "Adobe Reader Speed Launcher" -- File "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" -- [113520] -- [10/03/2009 04:08 AM] "Adobe ARM" -- File "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" -- [1009016] -- [09/04/2009 12:08 PM] "QuickTime Task" -- File: "C:\Program Files\QuickTime\QTTask.exe" -atboottime -- [?] "WinampAgent" -- File "C:\Program Files\Winamp\winampa.exe" -- [107520] -- [07/02/2009 03:37 AM] --- HKLM\RUNONCE regkey --- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] no runonce values found --- HKLM\RUNONCEEX regkey --- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx] no runonceex values found --- HKLM\RUNSERVICES regkey --- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices] no runservices values found --- HKLM\RUNSERVICESONCE regkey --- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce] no runservicesonce values found --- HKCU\RUN regkey --- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Messenger (Yahoo!)" -- File: "C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe" -quiet -- [?] --- HKCU\RUNONCE regkey --- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] no runonce values found --- HKCU\RUNONCEEX regkey --- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx] key not found --- HKCU\RUNSERVICES regkey --- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices] no runservices values found --- HKCU\RUNSERVICESONCE regkey --- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce] no runservicesonce values found --- HKU\.DEFAULT\Run regkeys - Default user --- [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] no run values found --- HKU\S-1-5-18\Run regkeys - user SYSTEM --- [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] no run values found --- HKU\S-1-5-19\Run regkeys - User Lokale service --- [HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] key not found --- HKU\S-1-5-20\Run regkeys - User Lokale service --- [HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] key not found --- HKLM\Explorer\Run regkeys --- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] no run values found --- HKCU\Explorer\Run regkeys --- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] no run values found --- Image File Execution regkeys --- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options] no debuggers found --- BROWSER HELPER OBJECTS regkeys --- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}] -- CLSID not found [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}] -- File: C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll -- [75128] -- [02/27/2009 01:07 PM] --- TOOLBAR regkeys --- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] no toolbars found --- HKLM\URLSEARCHHOOKS regkeys --- [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\URLSearchHooks] no urlsearchhooks found --- HKCU\URLSEARCHHOOKS regkeys --- [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] {CFBFAE00-17A6-11D0-99CB-00C04FD64497} -- File: %SystemRoot%\system32\shdocvw.dll -- [?] {EF99BD32-C1FB-11D2-892F-0090271D4F88} -- CLSID not found --- SRCEENSAVER regkey --- [HKEY_CURRENT_USER\Control Panel\Desktop] scrnsave.exe value not found --- ALTERNATESHELL regkey --- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot] no AlternateShell value found --- SECURITYPROVIDERS regkey --- [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll" File: C:\WINDOWS\system32\msapsspc.dll -- [86016] -- [08/04/2004 11:00 PM] File: C:\WINDOWS\system32\schannel.dll -- [144896] -- [08/04/2004 11:00 PM] File: C:\WINDOWS\system32\digest.dll -- [68608] -- [08/04/2004 11:00 PM] File: C:\WINDOWS\system32\msnsspc.dll -- [290816] -- [08/04/2004 11:00 PM] --- Active Setup\Installed Components regkey --- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}] -- File: %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE -- [?] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] -- File: RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP -- [?] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] -- File: %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE -- [?] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] -- File: %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll -- [?] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] -- File: "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install -- [?] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] -- File: rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT -- [?] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{4b218e3e-bc98-4770-93d3-2731b9329278}] -- File: %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection MarketplaceLinkInstall 896 %systemroot%\inf\ie.inf -- [?] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}] -- File: rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser -- [?] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] -- File: rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp11.inf,PerUserStub -- [?] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}] -- File: regsvr32.exe /s /n /i:U shell32.dll -- [?] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}] -- File: %SystemRoot%\system32\ie4uinit.exe -- [?] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}] -- File: %SystemRoot%\system32\ie4uinit.exe -- [?] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96}] -- filepath not found --- Services regkey --- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\abp470n5] -- File: \??\C:\WINDOWS\system32\drivers\flnipn.sys -- [?] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\abp480n5] -- filepath not found [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\adpu160m] -- filepath not found [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\aec] -- File: system32\drivers\aec.sys -- [?] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\aic78u2] -- filepath not found [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\aic78xx] -- filepath not found [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\amsint] -- filepath not found [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ANIO] -- File: \??\C:\WINDOWS\system32\ANIO.SYS -- [?] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ANIWZCSdService] -- File: C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe -- [126976] -- [01/19/2007 11:49 AM] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\asc] -- filepath not found [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\asc3350p] -- filepath not found [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\asc3550] -- filepath not found [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\atapi] -- File: system32\DRIVERS\atapi.sys -- [?] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\audstub] -- File: system32\DRIVERS\audstub.sys -- [?] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\i2omgmt] -- filepath not found [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\i2omp] -- filepath not found [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\i8042prt] -- File: system32\DRIVERS\i8042prt.sys -- [?] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\inetaccs] -- filepath not found [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ini910u] -- filepath not found [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\irda] -- File: system32\DRIVERS\irda.sys -- [?] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\irsir] -- File: system32\DRIVERS\irsir.sys -- [?] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\isapnp] -- File: system32\DRIVERS\isapnp.sys -- [?] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\npkcrypt] -- File: \??\D:\My Documents\VanRO\RO\npkcrypt.sys -- [?] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ohci1394] -- File: system32\DRIVERS\ohci1394.sys -- [?] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\OMSI download service] -- File: C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe -- [172032] -- [04/30/2009 12:23 PM] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\s1018bus] -- File: system32\DRIVERS\s1018bus.sys -- [?] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\s1018mdfl] -- File: system32\DRIVERS\s1018mdfl.sys -- [?] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\s1018mgmt] -- File: system32\DRIVERS\s1018mgmt.sys -- [?] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\s1018nd5] -- File: system32\DRIVERS\s1018nd5.sys -- [?] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\s1018obex] -- File: system32\DRIVERS\s1018obex.sys -- [?] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\s1018unic] -- File: system32\DRIVERS\s1018unic.sys -- [?] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\seehcri] -- File: system32\DRIVERS\seehcri.sys -- [?] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ultra] -- filepath not found [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\upnphost] -- File: %SystemRoot%\system32\svchost.exe -k LocalService -- [?] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\usbehci] -- File: system32\DRIVERS\usbehci.sys -- [?] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\usbhub] -- File: system32\DRIVERS\usbhub.sys -- [?] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\usbohci] -- File: system32\DRIVERS\usbohci.sys -- [?] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\usbstor] -- File: system32\DRIVERS\USBSTOR.SYS -- [?] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\yukonwxp] -- File: system32\DRIVERS\yk51x86.sys -- [?] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{0A088315-C8DE-4EEF-B02E-065DB21B2E51}] -- filepath not found [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{472CA9A7-544B-4C06-B16E-6AE35D88C7EC}] -- filepath not found [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{977F7CC0-6ED7-4D79-B0D1-7DD3D9727859}] -- filepath not found [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{E4B884A5-4CB7-4B70-B230-39FD9A24852E}] -- filepath not found [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{F5600E9E-F754-4AEE-81D3-68BA1E3AFE09}] -- filepath not found --- SAFEBOOT MINIMAL SERVICES --- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal no unknown services found --- SAFEBOOT Network SERVICES --- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network no unknown services found --- BOOTEXECUTE regkey --- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager] "BootExecute"= autocheck autochk *\0\0 --- PENDINGFILERENAMEOPERATIONS regkey --- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager] PendingFileRenameOperations key not found --- WOW-CMDLINE regkeys --- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WOW] "cmdline" = %SystemRoot%\system32\ntvdm.exe "cmdline" = %SystemRoot%\system32\ntvdm.exe -a %SystemRoot%\system32\krnl386 --- NETSVCS regkey --- [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost] -- NETSVCS 0WmdmPmSN --- DNS SERVER regkeys --- no "NameServer" values found --- File associations --- .BAT files: ("%1" %*) .COM files: ("%1" %*) .EXE files: ("%1" %*) .HLP files: (%SystemRoot%\System32\winhlp32.exe %1) .INF files: (%SystemRoot%\System32\NOTEPAD.EXE %1) .INI files: (%SystemRoot%\System32\NOTEPAD.EXE %1) .JS files: (%SystemRoot%\System32\WScript.exe "%1" %*) .PIF files: ("%1" %*) .REG files: (regedit.exe "%1") .SCR files: ("%1" /S) .TXT files: (%SystemRoot%\system32\NOTEPAD.EXE %1) .VBS files: (%SystemRoot%\System32\WScript.exe "%1" %*) --- STARTUP FOLDERS --- C:\Documents and Settings\Owner\Start Menu\Programs\Startup\desktop.ini -- [84] -- [11/19/2009 04:26 PM] C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini -- [84] -- [11/19/2009 04:26 PM] C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\desktop.ini -- [84] -- [11/19/2009 04:26 PM] C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\desktop.ini -- [84] -- [11/19/2009 04:26 PM] --- TASK SCHEDULER JOBS --- C:\WINDOWS\tasks\AppleSoftwareUpdate.job -- [284] -- [12/04/2009 03:25 PM] Scan completed: Sun 12/06/2009 12:29:50.07 FINISHED Back to Top
37 posts in this thread. Viewing Page : 1 2
Forum Information Currently it is Friday, July 30, 2010 2:00 PM (GMT +2) There are a total of 79.134 posts in 17.897 threads. In the last 3 days there were 8 new threads and 53 reply posts. View Active Threads Who's Online This forum has 31950 registered members. Please welcome our newest member, Willow . 33 Guest(s), 1 Registered Member(s) are currently online. Details tanisstray 5 Latest Threads