mattp
Topic Starter
Hi I was hoping you could help with a trojan or some kind of program I have on my computer. This program lbfckhf.dll keeps trying to install as an IE add-on. My trojan and virus programs (Avira, Spybot, Malware bytes) keep picking it up, but they can't get rid of it. I haven't been able to delete it manually either. Could you please tell me what it is and how to get rid of it?
Thanks,
Matt
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/08/24 21:42
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================
Drivers
——————-
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xF4A45000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF8AD2000 Size: 8192 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xF1DEA000 Size: 49152 File Visible: No Signed: -
Status: -
Name: srescan.sys
Image Path: srescan.sys
Address: 0xF8362000 Size: 81920 File Visible: No Signed: -
Status: -
Hidden Services
——————-
Service Name: hjgruiarstjxjn
Image Path: C:\WINDOWS\system32\drivers\hjgruirklqbdvb.sys
Service Name: kbiwkmcaxldbnr
Image Path: C:\WINDOWS\system32\drivers\kbiwkmrknwociv.sys
Service Name: TDSSserv.sys
Image Path: C:\WINDOWS\system32\drivers\TDSSmqlt.sys
==EOF==
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 21:37:26.75 on 2009-08-24
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_07
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.144 [GMT -4:00]
AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
svchost.exe
C:\Program Files\Dell\OpenManage\Client\ActionAgent.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\DMI\WIN32\bin\DellDmi.exe
C:\Program Files\Dell\OpenManage\Client\EventAgt.exe
C:\Program Files\Dell\OpenManage\Client\DLT.exe
C:\Program Files\Dell\OpenManage\Client\Iap.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\dmi\win32\bin\Win32sl.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Winamp3\winamp3.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avcenter.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\matt pierce\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = https://www.republicbank.com/home/home
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uInternet Settings,ProxyServer = localhost:8080
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com
mSearchAssistant = hxxp://www.google.com
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: : {798b0ee8-ba14-4bae-b1b3-a3af07fddb48} - c:\windows\system32\lbfckhf.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
mRun: [WinPatrol] c:\program files\billp studios\winpatrol\winpatrol.exe -expressboot
mRun: [avgnt] "c:\program files\avira\antivir personaledition classic\avgnt.exe" /min
mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
uPolicies-explorer: =
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {0000000A-9980-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/wmsp9dmo.cab
DPF: {00000075-9980-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/voxacm.CAB
DPF: {00000161-0000-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/msaudio.cab
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {33564D57-9980-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/wmv9dmo.cab
DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - hxxp://www.eset.eu/buxus/docs/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - hxxp://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37874.7009722222
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
TCP: NameServer = 208.67.220.220,208.67.222.222
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
Notify: gpkbkvda - lbfckhf.dll
AppInit_DLLs: karna.dat
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\mattpi~1\applic~1\mozilla\firefox\profiles\mextpe8f.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - plugin: c:\program files\mozilla firefox\plugins\npmozax.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npmusicn.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
============= SERVICES / DRIVERS ===============
R0 nppoohfm;nppoohfm;c:\windows\system32\drivers\nppoohfm.sys [2001-8-18 23424]
R1 avgio;avgio;c:\program files\avira\antivir personaledition classic\avgio.sys [2008-11-12 11608]
R1 fwdrv;Kerio Personal Firewall Driver;c:\windows\system32\drivers\FWDRV.SYS [2003-8-24 102912]
R1 KLIF;KLIF;c:\windows\system32\drivers\klif.sys [2009-4-2 127768]
R1 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2009-4-2 394952]
R2 ActionAgent;ActionAgent;c:\program files\dell\openmanage\client\ActionAgent.exe [2002-7-23 118784]
R2 AntiVirScheduler;Avira AntiVir Personal - Free Antivirus Scheduler;c:\program files\avira\antivir personaledition classic\sched.exe [2008-11-12 68865]
R2 AntiVirService;Avira AntiVir Personal - Free Antivirus Guard;c:\program files\avira\antivir personaledition classic\avguard.exe [2008-11-12 151297]
R2 DLT;DLT;c:\program files\dell\openmanage\client\DLT.exe [2002-7-23 131072]
R2 vsmon;TrueVector Internet Monitor;c:\windows\system32\zonelabs\vsmon.exe -service –> c:\windows\system32\zonelabs\vsmon.exe -service [?]
R2 WinDriver;WinDriver;c:\windows\system32\drivers\windrvr.sys [2002-11-3 205220]
R3 avgntflt;avgntflt;c:\program files\avira\antivir personaledition classic\avgntflt.sys [2008-11-12 52056]
S3 ati2mpaa;ati2mpaa;c:\windows\system32\drivers\ati2mpaa.sys [2002-7-23 281856]
=============== Created Last 30 ================
2009-08-24 05:00 1,089,593 ——– c:\windows\system32\dllcache\ntprint.cat
2009-08-23 11:47 –d—– c:\windows\system32\XPSViewer
2009-08-23 11:46 597,504 ——– c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-23 11:46 575,488 ——– c:\windows\system32\xpsshhdr.dll
2009-08-23 11:46 575,488 ——– c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-23 11:46 117,760 ——– c:\windows\system32\prntvpt.dll
2009-08-23 11:46 89,088 ——– c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-23 11:46 –d—– C:\69fe10220d065dbda413
2009-08-23 11:46 1,676,288 ——– c:\windows\system32\xpssvcs.dll
2009-08-23 11:46 1,676,288 ——– c:\windows\system32\dllcache\xpssvcs.dll
2009-08-22 03:01 –d—– C:\533a3b3e857ea81155806544
2009-08-22 03:00 –d—– C:\5813fd62a60c6788bd
2009-08-22 01:03 –d—– c:\docume~1\mattpi~1\applic~1\jblzjpsc
2009-08-17 22:55 71,168 a——- c:\windows\system32\drivers\iqrapbwtsplyfucm.sys
2009-08-11 16:30 128,512 ——– c:\windows\system32\dllcache\dhtmled.ocx
2009-08-11 16:29 1,315,328 ——– c:\windows\system32\dllcache\msoe.dll
2009-08-05 05:01 204,800 ——– c:\windows\system32\dllcache\mswebdvd.dll
==================== Find3M ====================
2009-08-17 22:53 10,154,016 a–sh— c:\windows\system32\drivers\fidbox.dat
2009-08-12 13:45 376,534 a——- c:\windows\system32\hjgruimpdrwqqp.dat
2009-08-05 05:01 204,800 a——- c:\windows\system32\mswebdvd.dll
2009-08-03 13:36 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-03 13:36 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-07-30 15:19 512 a——- C:\drmHeader.bin
2009-07-19 18:48 11,067,392 a——- c:\windows\system32\dllcache\ieframe.dll
2009-07-19 09:18 5,937,152 a——- c:\windows\system32\dllcache\mshtml.dll
2009-07-17 15:01 58,880 a——- c:\windows\system32\atl.dll
2009-07-17 15:01 58,880 ——– c:\windows\system32\dllcache\atl.dll
2009-07-13 23:43 10,841,088 a——- c:\windows\system32\dllcache\wmp.dll
2009-07-13 23:43 286,208 a——- c:\windows\system32\wmpdxm.dll
2009-07-13 23:43 286,208 a——- c:\windows\system32\dllcache\wmpdxm.dll
2009-07-09 18:18 114,476 a–sh— c:\windows\system32\drivers\fidbox.idx
2009-07-03 13:09 915,456 a——- c:\windows\system32\wininet.dll
2009-07-03 13:09 915,456 a——- c:\windows\system32\dllcache\wininet.dll
2009-07-03 13:09 12,800 ——– c:\windows\system32\dllcache\xpshims.dll
2009-07-03 13:09 1,208,832 a——- c:\windows\system32\dllcache\urlmon.dll
2009-07-03 13:09 206,848 a——- c:\windows\system32\dllcache\occache.dll
2009-07-03 13:09 594,432 a——- c:\windows\system32\dllcache\msfeeds.dll
2009-07-03 13:09 55,296 a——- c:\windows\system32\dllcache\msfeedsbs.dll
2009-07-03 13:09 1,985,536 a——- c:\windows\system32\dllcache\iertutil.dll
2009-07-03 13:09 25,600 a——- c:\windows\system32\dllcache\jsproxy.dll
2009-07-03 13:09 184,320 a——- c:\windows\system32\dllcache\iepeers.dll
2009-07-03 13:09 246,272 ——– c:\windows\system32\dllcache\ieproxy.dll
2009-07-03 13:09 386,048 a——- c:\windows\system32\dllcache\iedkcs32.dll
2009-07-03 07:01 173,056 a——- c:\windows\system32\dllcache\ie4uinit.exe
2009-06-16 10:36 119,808 a——- c:\windows\system32\t2embed.dll
2009-06-16 10:36 81,920 a——- c:\windows\system32\fontsub.dll
2009-06-16 10:36 119,808 ——– c:\windows\system32\dllcache\t2embed.dll
2009-06-16 10:36 81,920 ——– c:\windows\system32\dllcache\fontsub.dll
2009-06-12 08:31 80,896 a——- c:\windows\system32\tlntsess.exe
2009-06-12 08:31 80,896 ——– c:\windows\system32\dllcache\tlntsess.exe
2009-06-12 08:31 76,288 a——- c:\windows\system32\telnet.exe
2009-06-12 08:31 76,288 ——– c:\windows\system32\dllcache\telnet.exe
2009-06-10 10:13 84,992 a——- c:\windows\system32\dllcache\avifil32.dll
2009-06-10 10:13 84,992 a——- c:\windows\system32\avifil32.dll
2009-06-10 09:19 2,066,432 a——- c:\windows\system32\mstscax.dll
2009-06-10 09:19 2,066,432 ——– c:\windows\system32\dllcache\mstscax.dll
2009-06-10 02:14 132,096 a——- c:\windows\system32\wkssvc.dll
2009-06-10 02:14 132,096 ——– c:\windows\system32\dllcache\wkssvc.dll
2009-06-05 11:42 2,060,288 a——- c:\windows\system32\usbaaplrc.dll
2009-06-03 15:09 1,291,264 a——- c:\windows\system32\quartz.dll
2009-06-03 15:09 1,291,264 ——– c:\windows\system32\dllcache\quartz.dll
2008-11-08 14:38 18,747 a——- c:\program files\common files\fanyqidip.ban
2008-11-08 14:38 19,397 a——- c:\docume~1\mattpi~1\applic~1\uqaq.pif
2008-11-08 14:38 15,852 a——- c:\program files\common files\cyfeg.pif
2008-11-08 14:38 14,905 a——- c:\docume~1\alluse~1\applic~1\xehoqaz.dll
2008-11-08 14:38 13,328 a——- c:\docume~1\mattpi~1\applic~1\ozoqi.pif
2008-11-08 14:38 11,072 a——- c:\docume~1\alluse~1\applic~1\urug.bat
2008-11-08 14:38 10,267 a——- c:\docume~1\mattpi~1\applic~1\owumagexib.scr
2008-10-13 16:26 43,280 ac—— c:\docume~1\mattpi~1\applic~1\GDIPFONTCACHEV1.DAT
2008-03-27 14:21 87,608 a——- c:\docume~1\mattpi~1\applic~1\inst.exe
2008-03-27 14:21 47,360 a——- c:\docume~1\mattpi~1\applic~1\pcouffin.sys
2005-12-22 15:39 88,576 a—h— c:\docume~1\mattpi~1\applic~1\rbap550.dll
2005-12-22 15:39 59,392 a—h— c:\docume~1\mattpi~1\applic~1\MBSQTImporterPlugin8680.dll
2005-12-22 15:39 48,640 a—h— c:\docume~1\mattpi~1\applic~1\eSelleratePlugin.DLL
2005-12-22 15:39 44,032 a—h— c:\docume~1\mattpi~1\applic~1\MBSMainPlugin8841.dll
2005-12-22 15:39 38,912 a—h— c:\docume~1\mattpi~1\applic~1\RBShell550.dll
2005-12-22 15:39 26,624 a—h— c:\docume~1\mattpi~1\applic~1\MBSRegistrationPlugin8816.dll
2005-12-22 15:39 74,240 a—h— c:\docume~1\mattpi~1\applic~1\rbqt550.DLL
2006-12-28 02:20 10,022 a–sh— c:\windows\system32\KGyGaAvL.sys
2008-09-07 15:08 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008090720080908\index.dat
2008-11-11 15:17 16,384 a–sh— c:\windows\temp\cookies\index.dat
2008-11-11 15:17 32,768 a–sh— c:\windows\temp\history\history.ie5\index.dat
2008-11-11 15:17 49,152 a–sh— c:\windows\temp\temporary internet files\content.ie5\index.dat
============= FINISH: 21:40:36.92 ===============
Thanks,
Matt
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/08/24 21:42
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================
Drivers
——————-
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xF4A45000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF8AD2000 Size: 8192 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xF1DEA000 Size: 49152 File Visible: No Signed: -
Status: -
Name: srescan.sys
Image Path: srescan.sys
Address: 0xF8362000 Size: 81920 File Visible: No Signed: -
Status: -
Hidden Services
——————-
Service Name: hjgruiarstjxjn
Image Path: C:\WINDOWS\system32\drivers\hjgruirklqbdvb.sys
Service Name: kbiwkmcaxldbnr
Image Path: C:\WINDOWS\system32\drivers\kbiwkmrknwociv.sys
Service Name: TDSSserv.sys
Image Path: C:\WINDOWS\system32\drivers\TDSSmqlt.sys
==EOF==
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 21:37:26.75 on 2009-08-24
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_07
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.144 [GMT -4:00]
AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
svchost.exe
C:\Program Files\Dell\OpenManage\Client\ActionAgent.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\DMI\WIN32\bin\DellDmi.exe
C:\Program Files\Dell\OpenManage\Client\EventAgt.exe
C:\Program Files\Dell\OpenManage\Client\DLT.exe
C:\Program Files\Dell\OpenManage\Client\Iap.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\dmi\win32\bin\Win32sl.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Winamp3\winamp3.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avcenter.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\matt pierce\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = https://www.republicbank.com/home/home
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uInternet Settings,ProxyServer = localhost:8080
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com
mSearchAssistant = hxxp://www.google.com
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: : {798b0ee8-ba14-4bae-b1b3-a3af07fddb48} - c:\windows\system32\lbfckhf.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
mRun: [WinPatrol] c:\program files\billp studios\winpatrol\winpatrol.exe -expressboot
mRun: [avgnt] "c:\program files\avira\antivir personaledition classic\avgnt.exe" /min
mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
uPolicies-explorer: =
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {0000000A-9980-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/wmsp9dmo.cab
DPF: {00000075-9980-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/voxacm.CAB
DPF: {00000161-0000-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/msaudio.cab
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {33564D57-9980-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/wmv9dmo.cab
DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - hxxp://www.eset.eu/buxus/docs/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - hxxp://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37874.7009722222
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
TCP: NameServer = 208.67.220.220,208.67.222.222
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
Notify: gpkbkvda - lbfckhf.dll
AppInit_DLLs: karna.dat
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\mattpi~1\applic~1\mozilla\firefox\profiles\mextpe8f.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - plugin: c:\program files\mozilla firefox\plugins\npmozax.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npmusicn.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
============= SERVICES / DRIVERS ===============
R0 nppoohfm;nppoohfm;c:\windows\system32\drivers\nppoohfm.sys [2001-8-18 23424]
R1 avgio;avgio;c:\program files\avira\antivir personaledition classic\avgio.sys [2008-11-12 11608]
R1 fwdrv;Kerio Personal Firewall Driver;c:\windows\system32\drivers\FWDRV.SYS [2003-8-24 102912]
R1 KLIF;KLIF;c:\windows\system32\drivers\klif.sys [2009-4-2 127768]
R1 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2009-4-2 394952]
R2 ActionAgent;ActionAgent;c:\program files\dell\openmanage\client\ActionAgent.exe [2002-7-23 118784]
R2 AntiVirScheduler;Avira AntiVir Personal - Free Antivirus Scheduler;c:\program files\avira\antivir personaledition classic\sched.exe [2008-11-12 68865]
R2 AntiVirService;Avira AntiVir Personal - Free Antivirus Guard;c:\program files\avira\antivir personaledition classic\avguard.exe [2008-11-12 151297]
R2 DLT;DLT;c:\program files\dell\openmanage\client\DLT.exe [2002-7-23 131072]
R2 vsmon;TrueVector Internet Monitor;c:\windows\system32\zonelabs\vsmon.exe -service –> c:\windows\system32\zonelabs\vsmon.exe -service [?]
R2 WinDriver;WinDriver;c:\windows\system32\drivers\windrvr.sys [2002-11-3 205220]
R3 avgntflt;avgntflt;c:\program files\avira\antivir personaledition classic\avgntflt.sys [2008-11-12 52056]
S3 ati2mpaa;ati2mpaa;c:\windows\system32\drivers\ati2mpaa.sys [2002-7-23 281856]
=============== Created Last 30 ================
2009-08-24 05:00 1,089,593 ——– c:\windows\system32\dllcache\ntprint.cat
2009-08-23 11:47 –d—– c:\windows\system32\XPSViewer
2009-08-23 11:46 597,504 ——– c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-23 11:46 575,488 ——– c:\windows\system32\xpsshhdr.dll
2009-08-23 11:46 575,488 ——– c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-23 11:46 117,760 ——– c:\windows\system32\prntvpt.dll
2009-08-23 11:46 89,088 ——– c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-23 11:46 –d—– C:\69fe10220d065dbda413
2009-08-23 11:46 1,676,288 ——– c:\windows\system32\xpssvcs.dll
2009-08-23 11:46 1,676,288 ——– c:\windows\system32\dllcache\xpssvcs.dll
2009-08-22 03:01 –d—– C:\533a3b3e857ea81155806544
2009-08-22 03:00 –d—– C:\5813fd62a60c6788bd
2009-08-22 01:03 –d—– c:\docume~1\mattpi~1\applic~1\jblzjpsc
2009-08-17 22:55 71,168 a——- c:\windows\system32\drivers\iqrapbwtsplyfucm.sys
2009-08-11 16:30 128,512 ——– c:\windows\system32\dllcache\dhtmled.ocx
2009-08-11 16:29 1,315,328 ——– c:\windows\system32\dllcache\msoe.dll
2009-08-05 05:01 204,800 ——– c:\windows\system32\dllcache\mswebdvd.dll
==================== Find3M ====================
2009-08-17 22:53 10,154,016 a–sh— c:\windows\system32\drivers\fidbox.dat
2009-08-12 13:45 376,534 a——- c:\windows\system32\hjgruimpdrwqqp.dat
2009-08-05 05:01 204,800 a——- c:\windows\system32\mswebdvd.dll
2009-08-03 13:36 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-03 13:36 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-07-30 15:19 512 a——- C:\drmHeader.bin
2009-07-19 18:48 11,067,392 a——- c:\windows\system32\dllcache\ieframe.dll
2009-07-19 09:18 5,937,152 a——- c:\windows\system32\dllcache\mshtml.dll
2009-07-17 15:01 58,880 a——- c:\windows\system32\atl.dll
2009-07-17 15:01 58,880 ——– c:\windows\system32\dllcache\atl.dll
2009-07-13 23:43 10,841,088 a——- c:\windows\system32\dllcache\wmp.dll
2009-07-13 23:43 286,208 a——- c:\windows\system32\wmpdxm.dll
2009-07-13 23:43 286,208 a——- c:\windows\system32\dllcache\wmpdxm.dll
2009-07-09 18:18 114,476 a–sh— c:\windows\system32\drivers\fidbox.idx
2009-07-03 13:09 915,456 a——- c:\windows\system32\wininet.dll
2009-07-03 13:09 915,456 a——- c:\windows\system32\dllcache\wininet.dll
2009-07-03 13:09 12,800 ——– c:\windows\system32\dllcache\xpshims.dll
2009-07-03 13:09 1,208,832 a——- c:\windows\system32\dllcache\urlmon.dll
2009-07-03 13:09 206,848 a——- c:\windows\system32\dllcache\occache.dll
2009-07-03 13:09 594,432 a——- c:\windows\system32\dllcache\msfeeds.dll
2009-07-03 13:09 55,296 a——- c:\windows\system32\dllcache\msfeedsbs.dll
2009-07-03 13:09 1,985,536 a——- c:\windows\system32\dllcache\iertutil.dll
2009-07-03 13:09 25,600 a——- c:\windows\system32\dllcache\jsproxy.dll
2009-07-03 13:09 184,320 a——- c:\windows\system32\dllcache\iepeers.dll
2009-07-03 13:09 246,272 ——– c:\windows\system32\dllcache\ieproxy.dll
2009-07-03 13:09 386,048 a——- c:\windows\system32\dllcache\iedkcs32.dll
2009-07-03 07:01 173,056 a——- c:\windows\system32\dllcache\ie4uinit.exe
2009-06-16 10:36 119,808 a——- c:\windows\system32\t2embed.dll
2009-06-16 10:36 81,920 a——- c:\windows\system32\fontsub.dll
2009-06-16 10:36 119,808 ——– c:\windows\system32\dllcache\t2embed.dll
2009-06-16 10:36 81,920 ——– c:\windows\system32\dllcache\fontsub.dll
2009-06-12 08:31 80,896 a——- c:\windows\system32\tlntsess.exe
2009-06-12 08:31 80,896 ——– c:\windows\system32\dllcache\tlntsess.exe
2009-06-12 08:31 76,288 a——- c:\windows\system32\telnet.exe
2009-06-12 08:31 76,288 ——– c:\windows\system32\dllcache\telnet.exe
2009-06-10 10:13 84,992 a——- c:\windows\system32\dllcache\avifil32.dll
2009-06-10 10:13 84,992 a——- c:\windows\system32\avifil32.dll
2009-06-10 09:19 2,066,432 a——- c:\windows\system32\mstscax.dll
2009-06-10 09:19 2,066,432 ——– c:\windows\system32\dllcache\mstscax.dll
2009-06-10 02:14 132,096 a——- c:\windows\system32\wkssvc.dll
2009-06-10 02:14 132,096 ——– c:\windows\system32\dllcache\wkssvc.dll
2009-06-05 11:42 2,060,288 a——- c:\windows\system32\usbaaplrc.dll
2009-06-03 15:09 1,291,264 a——- c:\windows\system32\quartz.dll
2009-06-03 15:09 1,291,264 ——– c:\windows\system32\dllcache\quartz.dll
2008-11-08 14:38 18,747 a——- c:\program files\common files\fanyqidip.ban
2008-11-08 14:38 19,397 a——- c:\docume~1\mattpi~1\applic~1\uqaq.pif
2008-11-08 14:38 15,852 a——- c:\program files\common files\cyfeg.pif
2008-11-08 14:38 14,905 a——- c:\docume~1\alluse~1\applic~1\xehoqaz.dll
2008-11-08 14:38 13,328 a——- c:\docume~1\mattpi~1\applic~1\ozoqi.pif
2008-11-08 14:38 11,072 a——- c:\docume~1\alluse~1\applic~1\urug.bat
2008-11-08 14:38 10,267 a——- c:\docume~1\mattpi~1\applic~1\owumagexib.scr
2008-10-13 16:26 43,280 ac—— c:\docume~1\mattpi~1\applic~1\GDIPFONTCACHEV1.DAT
2008-03-27 14:21 87,608 a——- c:\docume~1\mattpi~1\applic~1\inst.exe
2008-03-27 14:21 47,360 a——- c:\docume~1\mattpi~1\applic~1\pcouffin.sys
2005-12-22 15:39 88,576 a—h— c:\docume~1\mattpi~1\applic~1\rbap550.dll
2005-12-22 15:39 59,392 a—h— c:\docume~1\mattpi~1\applic~1\MBSQTImporterPlugin8680.dll
2005-12-22 15:39 48,640 a—h— c:\docume~1\mattpi~1\applic~1\eSelleratePlugin.DLL
2005-12-22 15:39 44,032 a—h— c:\docume~1\mattpi~1\applic~1\MBSMainPlugin8841.dll
2005-12-22 15:39 38,912 a—h— c:\docume~1\mattpi~1\applic~1\RBShell550.dll
2005-12-22 15:39 26,624 a—h— c:\docume~1\mattpi~1\applic~1\MBSRegistrationPlugin8816.dll
2005-12-22 15:39 74,240 a—h— c:\docume~1\mattpi~1\applic~1\rbqt550.DLL
2006-12-28 02:20 10,022 a–sh— c:\windows\system32\KGyGaAvL.sys
2008-09-07 15:08 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008090720080908\index.dat
2008-11-11 15:17 16,384 a–sh— c:\windows\temp\cookies\index.dat
2008-11-11 15:17 32,768 a–sh— c:\windows\temp\history\history.ie5\index.dat
2008-11-11 15:17 49,152 a–sh— c:\windows\temp\temporary internet files\content.ie5\index.dat
============= FINISH: 21:40:36.92 ===============