This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Log Check-Trojan Horse/Keylogger

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I recently had a keylogger on my computer (Certain, as the leylogger himself was talking to me through opening a NOTEPAD file). I was given suggestios to reformat my computer, I have done that but am not sure if the Keylog was removed through the process. Thus using Hijackthis, I have a log which I would greatly appreciate you guys to have a look at to let me know if I am now safe.

Thanks in Advace.

———————————————————————————————————————————————————————————
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:57:39 PM, on 8/25/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

–
End of file - 2043 bytes
:welcome:

Sorry for the delay , the forums are very busy.

Log looks fine, but run this tool and lets look a bit deeper.

  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<info.txt (<
Okay here it is, sorry for being a bit late was busy this weekend.

First Log-Log.Txt:

Logfile of random's system information tool 1.06 (written by random/random)
Run by [removed] at 2009-08-30 11:08:17
Microsoft Windows XP Home Edition Service Pack 2
System drive C: has 148 GB (97%) free of 153 GB
Total RAM: 511 MB (21% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:08:32 AM, on 8/30/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Jasdeep Singh\Desktop\RSIT.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Trend Micro\HijackThis\Jasdeep Singh.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

–
End of file - 3421 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG8\avgssie.dll [2009-08-25 1111320]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
AVG Security Toolbar BHO - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll [2009-07-24 1090816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - AVG Security Toolbar - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll [2009-07-24 1090816]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AlcxMonitor"=C:\WINDOWS\ALCXMNTR.EXE [2004-09-07 57344]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2008-05-16 13529088]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2008-05-16 86016]
"AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe [2009-08-25 2007832]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgrsstarter]
C:\WINDOWS\system32\avgrsstx.dll [2009-08-25 11952]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\AVG\AVG8\avgemc.exe"="C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe"
"C:\Program Files\AVG\AVG8\avgupd.exe"="C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe"
"C:\Program Files\AVG\AVG8\avgnsx.exe"="C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======List of files/folders created in the last 1 months======

2009-08-30 11:08:17 —-D—- C:\rsit
2009-08-26 09:21:27 —-HDC—- C:\WINDOWS\$NtUninstallKB951376-v2$
2009-08-26 09:21:20 —-HDC—- C:\WINDOWS\$NtUninstallKB952954$
2009-08-26 09:21:14 —-HDC—- C:\WINDOWS\$NtUninstallKB959426$
2009-08-26 09:21:09 —-HDC—- C:\WINDOWS\$NtUninstallKB946648$
2009-08-26 09:20:57 —-HDC—- C:\WINDOWS\$NtUninstallKB956803$
2009-08-26 09:20:48 —-HDC—- C:\WINDOWS\$NtUninstallKB960859$
2009-08-26 09:20:42 —-HDC—- C:\WINDOWS\$NtUninstallKB885626$
2009-08-26 09:20:36 —-HDC—- C:\WINDOWS\$NtUninstallKB961371-v2$
2009-08-26 09:20:29 —-HDC—- C:\WINDOWS\$NtUninstallKB950974$
2009-08-26 09:20:25 —-HDC—- C:\WINDOWS\$NtUninstallKB971657$
2009-08-26 09:20:20 —-HDC—- C:\WINDOWS\$NtUninstallKB971557$
2009-08-26 09:20:15 —-HDC—- C:\WINDOWS\$NtUninstallKB960225$
2009-08-26 09:20:10 —-HDC—- C:\WINDOWS\$NtUninstallKB973346$
2009-08-26 09:19:36 —-HDC—- C:\WINDOWS\$NtUninstallKB956572$
2009-08-26 09:19:23 —-HDC—- C:\WINDOWS\$NtUninstallKB961501$
2009-08-26 09:19:17 —-HDC—- C:\WINDOWS\$NtUninstallKB938464-v2$
2009-08-26 09:19:10 —-HDC—- C:\WINDOWS\$NtUninstallKB971633$
2009-08-26 09:19:05 —-HDC—- C:\WINDOWS\$NtUninstallKB973869$
2009-08-26 09:18:58 —-HDC—- C:\WINDOWS\$NtUninstallKB973540_WM9L$
2009-08-26 09:18:52 —-HDC—- C:\WINDOWS\$NtUninstallKB952004$
2009-08-26 09:18:45 —-HDC—- C:\WINDOWS\$NtUninstallKB973507$
2009-08-26 09:18:41 —-HDC—- C:\WINDOWS\$NtUninstallKB950762$
2009-08-26 09:18:36 —-HDC—- C:\WINDOWS\$NtUninstallKB957097$
2009-08-26 09:18:30 —-HDC—- C:\WINDOWS\$NtUninstallKB958687$
2009-08-25 14:10:12 —-HDC—- C:\WINDOWS\$NtUninstallKB952287$
2009-08-25 14:10:07 —-HDC—- C:\WINDOWS\$NtUninstallKB973354$
2009-08-25 14:09:57 —-HDC—- C:\WINDOWS\$NtUninstallKB967715$
2009-08-25 14:09:51 —-HDC—- C:\WINDOWS\$NtUninstallKB951066$
2009-08-25 14:09:40 —-HDC—- C:\WINDOWS\$NtUninstallKB951748$
2009-08-25 14:09:35 —-HDC—- C:\WINDOWS\$NtUninstallKB970238$
2009-08-25 14:09:26 —-HDC—- C:\WINDOWS\$NtUninstallKB958470$
2009-08-25 14:09:20 —-HDC—- C:\WINDOWS\$NtUninstallKB960803$
2009-08-25 14:09:15 —-HDC—- C:\WINDOWS\$NtUninstallKB973815$
2009-08-25 14:09:10 —-HDC—- C:\WINDOWS\$NtUninstallKB968537$
2009-08-25 14:09:05 —-HDC—- C:\WINDOWS\$NtUninstallKB954600$
2009-08-25 14:09:00 —-HDC—- C:\WINDOWS\$NtUninstallKB958644$
2009-08-25 14:08:55 —-HDC—- C:\WINDOWS\$NtUninstallKB955069$
2009-08-25 14:08:50 —-HDC—- C:\WINDOWS\$NtUninstallKB956802$
2009-08-25 14:08:38 —-HDC—- C:\WINDOWS\$NtUninstallKB923561$
2009-08-25 14:08:28 —-HDC—- C:\WINDOWS\$NtUninstallKB970653-v3$
2009-08-25 14:03:37 —-A—- C:\WINDOWS\system32\avgrsstx.dll
2009-08-25 14:03:14 —-D—- C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
2009-08-25 14:03:06 —-D—- C:\Program Files\AVG
2009-08-25 14:03:05 —-D—- C:\Documents and Settings\All Users\Application Data\avg8
2009-08-25 14:00:13 —-D—- C:\Documents and Settings\Jasdeep Singh\Application Data\AVG8
2009-08-25 13:44:33 —-A—- C:\WINDOWS\system32\xpsp3res.dll
2009-08-25 13:42:38 —-D—- C:\WINDOWS\ie8updates
2009-08-25 13:42:16 —-D—- C:\WINDOWS\WBEM
2009-08-25 13:41:52 —-D—- C:\Program Files\Trend Micro
2009-08-25 13:41:18 —-HDC—- C:\WINDOWS\ie8
2009-08-25 13:41:18 —-D—- C:\WINDOWS\system32\en-US
2009-08-25 13:39:35 —-N—- C:\WINDOWS\system32\tzchange.exe
2009-08-25 13:36:38 —-HDC—- C:\WINDOWS\$MSI31Uninstall_KB893803v2$
2009-08-25 13:36:28 —-D—- C:\WINDOWS\system32\PreInstall
2009-08-25 13:36:26 —-HDC—- C:\WINDOWS\$NtUninstallKB898461$
2009-08-25 13:33:20 —-SHD—- C:\RECYCLER
2009-08-25 13:32:52 —-D—- C:\WINDOWS\nview
2009-08-25 13:32:51 —-A—- C:\WINDOWS\system32\nvudisp.exe
2009-08-25 13:32:38 —-A—- C:\WINDOWS\system32\ksuser.dll
2009-08-25 13:32:32 —-N—- C:\WINDOWS\system32\RtlCPAPI.dll
2009-08-25 13:32:32 —-N—- C:\WINDOWS\system32\ChCfg.exe
2009-08-25 13:32:32 —-N—- C:\WINDOWS\soundman.exe
2009-08-25 13:32:32 —-A—- C:\WINDOWS\ALCXMNTR.EXE
2009-08-25 13:32:30 —-N—- C:\WINDOWS\system32\RTLCPL.exe
2009-08-25 13:32:30 —-N—- C:\WINDOWS\alcupd.exe
2009-08-25 13:32:30 —-N—- C:\WINDOWS\alcrmv.exe
2009-08-25 13:32:30 —-HD—- C:\Program Files\InstallShield Installation Information
2009-08-25 13:32:27 —-A—- C:\WINDOWS\system32\NVUNINST.EXE
2009-08-25 13:32:20 —-D—- C:\Program Files\Common Files\InstallShield
2009-08-25 13:32:12 —-D—- C:\NVIDIA
2009-08-25 13:31:31 —-A—- C:\WINDOWS\system32\MRT.exe
2009-08-25 13:31:24 —-HDC—- C:\WINDOWS\$NtUninstallKB932823-v3$
2009-08-25 13:31:24 —-HD—- C:\WINDOWS\$hf_mig$
2009-08-25 13:28:12 —-D—- C:\WINDOWS\system32\SoftwareDistribution
2009-08-25 13:27:17 —-D—- C:\WINDOWS\SoftwareDistribution
2009-08-25 13:27:14 —-D—- C:\WINDOWS\Prefetch
2009-08-25 13:26:22 —-SD—- C:\WINDOWS\system32\Microsoft
2009-08-25 13:21:00 —-N—- C:\WINDOWS\system32\proxycfg.exe
2009-08-25 13:21:00 —-N—- C:\WINDOWS\system32\logman.exe
2009-08-25 13:20:53 —-N—- C:\WINDOWS\system32\ativtmxx.dll
2009-08-25 13:20:53 —-N—- C:\WINDOWS\system32\ati3duag.dll
2009-08-25 13:20:53 —-N—- C:\WINDOWS\system32\ati3d1ag.dll
2009-08-25 13:20:53 —-N—- C:\WINDOWS\system32\ati2dvag.dll
2009-08-25 13:20:53 —-N—- C:\WINDOWS\system32\ati2dvaa.dll
2009-08-25 13:20:53 —-N—- C:\WINDOWS\system32\ati2cqag.dll
2009-08-25 13:20:52 —-N—- C:\WINDOWS\system32\httpapi.dll
2009-08-25 13:20:52 —-N—- C:\WINDOWS\system32\hsfcisp2.dll
2009-08-25 13:20:52 —-N—- C:\WINDOWS\system32\fwcfg.dll
2009-08-25 13:20:52 —-N—- C:\WINDOWS\system32\fsquirt.exe
2009-08-25 13:20:52 —-N—- C:\WINDOWS\system32\fltmc.exe
2009-08-25 13:20:52 —-N—- C:\WINDOWS\system32\fltlib.dll
2009-08-25 13:20:52 —-N—- C:\WINDOWS\system32\extmgr.dll
2009-08-25 13:20:52 —-N—- C:\WINDOWS\system32\dxdiagn.dll
2009-08-25 13:20:52 —-N—- C:\WINDOWS\system32\d3d9.dll
2009-08-25 13:20:52 —-N—- C:\WINDOWS\system32\cmsetacl.dll
2009-08-25 13:20:52 —-N—- C:\WINDOWS\system32\btpanui.dll
2009-08-25 13:20:52 —-N—- C:\WINDOWS\system32\bthserv.dll
2009-08-25 13:20:52 —-N—- C:\WINDOWS\system32\bthci.dll
2009-08-25 13:20:52 —-N—- C:\WINDOWS\system32\blastcln.exe
2009-08-25 13:20:52 —-N—- C:\WINDOWS\system32\bitsprx3.dll
2009-08-25 13:20:52 —-N—- C:\WINDOWS\system32\bitsprx2.dll
2009-08-25 13:20:52 —-N—- C:\WINDOWS\system32\auditusr.exe
2009-08-25 13:20:52 —-N—- C:\WINDOWS\system32\ativvaxx.dll
2009-08-25 13:20:51 —-N—- C:\WINDOWS\system32\kbdfi1.dll
2009-08-25 13:20:51 —-N—- C:\WINDOWS\system32\ir50_qcx.dll
2009-08-25 13:20:51 —-N—- C:\WINDOWS\system32\ir50_qc.dll
2009-08-25 13:20:51 —-N—- C:\WINDOWS\system32\ir50_32.dll
2009-08-25 13:20:51 —-N—- C:\WINDOWS\system32\ir41_qcx.dll
2009-08-25 13:20:51 —-N—- C:\WINDOWS\system32\ir41_qc.dll
2009-08-25 13:20:50 —-N—- C:\WINDOWS\system32\mp4sdmod.dll
2009-08-25 13:20:50 —-N—- C:\WINDOWS\system32\mp43dmod.dll
2009-08-25 13:20:50 —-N—- C:\WINDOWS\system32\mdmxsdk.dll
2009-08-25 13:20:50 —-N—- C:\WINDOWS\system32\kbdukx.dll
2009-08-25 13:20:50 —-N—- C:\WINDOWS\system32\kbdsmsno.dll
2009-08-25 13:20:50 —-N—- C:\WINDOWS\system32\kbdsmsfi.dll
2009-08-25 13:20:50 —-N—- C:\WINDOWS\system32\kbdno1.dll
2009-08-25 13:20:50 —-N—- C:\WINDOWS\system32\kbdmlt48.dll
2009-08-25 13:20:50 —-N—- C:\WINDOWS\system32\kbdmlt47.dll
2009-08-25 13:20:50 —-N—- C:\WINDOWS\system32\kbdmaori.dll
2009-08-25 13:20:50 —-N—- C:\WINDOWS\system32\kbdinmal.dll
2009-08-25 13:20:50 —-N—- C:\WINDOWS\system32\kbdinben.dll
2009-08-25 13:20:50 —-N—- C:\WINDOWS\system32\kbdinbe1.dll
2009-08-25 13:20:49 —-N—- C:\WINDOWS\system32\mtxparhd.dll
2009-08-25 13:20:49 —-N—- C:\WINDOWS\system32\mspmsnsv.dll
2009-08-25 13:20:49 —-N—- C:\WINDOWS\system32\msdadiag.dll
2009-08-25 13:20:48 —-N—- C:\WINDOWS\system32\s3gnb.dll
2009-08-25 13:20:48 —-N—- C:\WINDOWS\system32\powercfg.exe
2009-08-25 13:20:48 —-N—- C:\WINDOWS\system32\pnrpnsp.dll
2009-08-25 13:20:48 —-N—- C:\WINDOWS\system32\p2psvc.dll
2009-08-25 13:20:48 —-N—- C:\WINDOWS\system32\p2pnetsh.dll
2009-08-25 13:20:48 —-N—- C:\WINDOWS\system32\p2pgraph.dll
2009-08-25 13:20:48 —-N—- C:\WINDOWS\system32\p2pgasvc.dll
2009-08-25 13:20:48 —-N—- C:\WINDOWS\system32\p2p.dll
2009-08-25 13:20:48 —-A—- C:\WINDOWS\system32\nv4_disp.dll
2009-08-25 13:20:47 —-N—- C:\WINDOWS\system32\wmp.dll
2009-08-25 13:20:47 —-N—- C:\WINDOWS\system32\wmidx.dll
2009-08-25 13:20:47 —-N—- C:\WINDOWS\system32\wmerror.dll
2009-08-25 13:20:47 —-N—- C:\WINDOWS\system32\winshfhc.dll
2009-08-25 13:20:47 —-N—- C:\WINDOWS\system32\w3ssl.dll
2009-08-25 13:20:47 —-N—- C:\WINDOWS\system32\twext.dll
2009-08-25 13:20:47 —-N—- C:\WINDOWS\system32\strmfilt.dll
2009-08-25 13:20:47 —-N—- C:\WINDOWS\system32\smbinst.exe
2009-08-25 13:20:47 —-N—- C:\WINDOWS\system32\slserv.exe
2009-08-25 13:20:47 —-N—- C:\WINDOWS\system32\slrundll.exe
2009-08-25 13:20:47 —-N—- C:\WINDOWS\system32\slgen.dll
2009-08-25 13:20:47 —-N—- C:\WINDOWS\system32\slextspk.dll
2009-08-25 13:20:47 —-N—- C:\WINDOWS\system32\slcoinst.dll
2009-08-25 13:20:47 —-N—- C:\WINDOWS\system32\sdhcinst.dll
2009-08-25 13:20:46 —-N—- C:\WINDOWS\system32\wuauclt1.exe
2009-08-25 13:20:46 —-N—- C:\WINDOWS\system32\wshbth.dll
2009-08-25 13:20:46 —-N—- C:\WINDOWS\system32\wscsvc.dll
2009-08-25 13:20:46 —-N—- C:\WINDOWS\system32\wscntfy.exe
2009-08-25 13:20:46 —-N—- C:\WINDOWS\system32\wmvdmoe2.dll
2009-08-25 13:20:46 —-N—- C:\WINDOWS\system32\wmspdmoe.dll
2009-08-25 13:20:46 —-N—- C:\WINDOWS\system32\wmspdmod.dll
2009-08-25 13:20:46 —-N—- C:\WINDOWS\system32\wmsdmoe2.dll
2009-08-25 13:20:46 —-N—- C:\WINDOWS\system32\wmpdxm.dll
2009-08-25 13:20:46 —-N—- C:\WINDOWS\system32\wmpasf.dll
2009-08-25 13:20:46 —-A—- C:\WINDOWS\system32\wuapi.dll
2009-08-25 13:20:45 —-N—- C:\WINDOWS\system32\xpob2res.dll
2009-08-25 13:20:45 —-N—- C:\WINDOWS\system32\xmlprovi.dll
2009-08-25 13:20:45 —-N—- C:\WINDOWS\system32\xmlprov.dll
2009-08-25 13:20:45 —-N—- C:\WINDOWS\system32\wuaueng1.dll
2009-08-25 13:20:45 —-N—- C:\WINDOWS\slrundll.exe
2009-08-25 13:20:45 —-A—- C:\WINDOWS\system32\wuweb.dll
2009-08-25 13:20:45 —-A—- C:\WINDOWS\system32\wups.dll
2009-08-25 13:20:45 —-A—- C:\WINDOWS\system32\wucltui.dll
2009-08-25 13:20:44 —-D—- C:\WINDOWS\peernet
2009-08-25 13:20:43 —-D—- C:\WINDOWS\provisioning
2009-08-25 13:18:58 —-D—- C:\WINDOWS\ServicePackFiles
2009-08-25 13:17:21 —-N—- C:\WINDOWS\system32\xpsp2res.dll
2009-08-25 13:16:38 —-N—- C:\WINDOWS\system32\spmsg.dll
2009-08-25 13:16:38 —-A—- C:\WINDOWS\002038_.tmp
2009-08-25 13:16:33 —-D—- C:\WINDOWS\system32\ReinstallBackups
2009-08-25 13:16:16 —-A—- C:\WINDOWS\system32\spupdsvc.exe
2009-08-25 13:14:49 —-HDC—- C:\WINDOWS\$NtServicePackUninstall$
2009-08-25 13:14:46 —-D—- C:\WINDOWS\EHome
2009-08-25 13:11:00 —-SHD—- C:\WINDOWS\Installer
2009-08-25 13:10:58 —-D—- C:\Documents and Settings\Jasdeep Singh\Application Data\Identities
2009-08-25 13:10:55 —-HD—- C:\Program Files\Uninstall Information
2009-08-25 13:10:52 —-SD—- C:\Documents and Settings\Jasdeep Singh\Application Data\Microsoft
2009-08-25 13:10:52 —-ASH—- C:\Documents and Settings\Jasdeep Singh\Application Data\desktop.ini
2009-08-25 13:10:32 —-A—- C:\WINDOWS\system32\wpa.bak
2009-08-25 13:09:49 —-SHD—- C:\System Volume Information
2009-08-25 13:09:40 —-A—- C:\WINDOWS\SchedLgU.Txt
2009-08-25 13:07:13 —-D—- C:\Program Files\xerox
2009-08-25 13:07:12 —-D—- C:\WINDOWS\system32\xircom
2009-08-25 13:07:12 —-D—- C:\Program Files\microsoft frontpage
2009-08-25 13:07:08 —-A—- C:\WINDOWS\control.ini
2009-08-25 13:07:08 —-A—- C:\AUTOEXEC.BAT
2009-08-25 13:07:03 —-A—- C:\WINDOWS\OEWABLog.txt
2009-08-25 13:06:58 —-A—- C:\WINDOWS\system32\mapi32.dll
2009-08-25 13:06:21 —-SD—- C:\WINDOWS\Downloaded Program Files
2009-08-25 13:06:21 —-RD—- C:\WINDOWS\Offline Web Pages
2009-08-25 13:06:21 —-RAH—- C:\WINDOWS\system32\logonui.exe.manifest
2009-08-25 13:06:16 —-RAH—- C:\WINDOWS\system32\cdplayer.exe.manifest
2009-08-25 13:06:03 —-D—- C:\WINDOWS\system32\DirectX
2009-08-25 13:05:46 —-A—- C:\WINDOWS\system32\safrslv.dll
2009-08-25 13:05:46 —-A—- C:\WINDOWS\system32\safrdm.dll
2009-08-25 13:05:46 —-A—- C:\WINDOWS\system32\safrcdlg.dll
2009-08-25 13:05:46 —-A—- C:\WINDOWS\system32\racpldlg.dll
2009-08-25 13:05:46 —-A—- C:\WINDOWS\system32\atrace.dll
2009-08-25 13:05:44 —-A—- C:\WINDOWS\system32\desktop.ini
2009-08-25 13:05:44 —-A—- C:\WINDOWS\desktop.ini
2009-08-25 13:05:39 —-A—- C:\WINDOWS\system32\nmevtmsg.dll
2009-08-25 13:05:39 —-A—- C:\WINDOWS\system32\mnmsrvc.exe
2009-08-25 13:05:39 —-A—- C:\WINDOWS\system32\isrdbg32.dll
2009-08-25 13:05:38 —-D—- C:\Program Files\Common Files\Services
2009-08-25 13:05:38 —-A—- C:\WINDOWS\system32\acctres.dll
2009-08-25 13:05:37 —-A—- C:\WINDOWS\system32\inetres.dll
2009-08-25 13:05:35 —-SD—- C:\WINDOWS\Tasks
2009-08-25 13:05:35 —-A—- C:\WINDOWS\system32\isign32.dll
2009-08-25 13:05:35 —-A—- C:\WINDOWS\system32\inetcfg.dll
2009-08-25 13:05:35 —-A—- C:\WINDOWS\system32\icwphbk.dll
2009-08-25 13:05:35 —-A—- C:\WINDOWS\system32\icwdial.dll
2009-08-25 13:05:35 —-A—- C:\WINDOWS\system32\icfgnt5.dll
2009-08-25 13:05:34 —-D—- C:\Program Files\Common Files\MSSoap
2009-08-25 13:05:31 —-D—- C:\WINDOWS\srchasst
2009-08-25 13:05:30 —-D—- C:\WINDOWS\system32\Macromed
2009-08-25 13:05:30 —-A—- C:\WINDOWS\system32\qmgrprxy.dll
2009-08-25 13:05:30 —-A—- C:\WINDOWS\system32\qmgr.dll
2009-08-25 13:05:29 —-D—- C:\Program Files\Movie Maker
2009-08-25 13:05:27 —-D—- C:\WINDOWS\PCHealth
2009-08-25 13:05:26 —-D—- C:\WINDOWS\system32\Restore
2009-08-25 13:05:26 —-A—- C:\WINDOWS\system32\srsvc.dll
2009-08-25 13:05:26 —-A—- C:\WINDOWS\system32\srrstr.dll
2009-08-25 13:05:26 —-A—- C:\WINDOWS\system32\srclient.dll
2009-08-25 13:05:26 —-A—- C:\WINDOWS\system32\nmmkcert.dll
2009-08-25 13:05:26 —-A—- C:\WINDOWS\system32\msconf.dll
2009-08-25 13:05:26 —-A—- C:\WINDOWS\system32\mnmdd.dll
2009-08-25 13:05:26 —-A—- C:\WINDOWS\system32\ils.dll
2009-08-25 13:05:24 —-D—- C:\Program Files\NetMeeting
2009-08-25 13:05:24 —-A—- C:\WINDOWS\system32\msoert2.dll
2009-08-25 13:05:24 —-A—- C:\WINDOWS\system32\msoeacct.dll
2009-08-25 13:05:24 —-A—- C:\WINDOWS\system32\inetcomm.dll
2009-08-25 13:05:23 —-D—- C:\Program Files\Outlook Express
2009-08-25 13:05:23 —-A—- C:\WINDOWS\system32\schedsvc.dll
2009-08-25 13:05:23 —-A—- C:\WINDOWS\system32\mstinit.exe
2009-08-25 13:05:23 —-A—- C:\WINDOWS\system32\mstask.dll
2009-08-25 13:05:19 —-D—- C:\Program Files\Internet Explorer
2009-08-25 13:05:19 —-D—- C:\Program Files\Common Files\System
2009-08-25 13:05:12 —-D—- C:\Program Files\ComPlus Applications
2009-08-25 13:05:12 —-A—- C:\WINDOWS\vbaddin.ini
2009-08-25 13:05:12 —-A—- C:\WINDOWS\vb.ini
2009-08-25 13:05:10 —-D—- C:\WINDOWS\Registration
2009-08-25 13:04:55 —-HD—- C:\Program Files\WindowsUpdate
2009-08-25 13:04:55 —-D—- C:\Program Files\Online Services
2009-08-25 13:04:54 —-D—- C:\Program Files\Windows Media Player
2009-08-25 13:04:52 —-D—- C:\Program Files\Messenger
2009-08-25 13:04:49 —-D—- C:\Program Files\MSN Gaming Zone
2009-08-25 13:04:49 —-A—- C:\WINDOWS\system32\write.exe
2009-08-25 13:04:43 —-A—- C:\WINDOWS\system32\sndvol32.exe
2009-08-25 13:04:43 —-A—- C:\WINDOWS\system32\sndrec32.exe
2009-08-25 13:04:43 —-A—- C:\WINDOWS\system32\hypertrm.dll
2009-08-25 13:04:43 —-A—- C:\WINDOWS\system32\hticons.dll
2009-08-25 13:04:43 —-A—- C:\WINDOWS\system32\avwav.dll
2009-08-25 13:04:43 —-A—- C:\WINDOWS\system32\avtapi.dll
2009-08-25 13:04:43 —-A—- C:\WINDOWS\system32\avmeter.dll
2009-08-25 13:04:43 —-A—- C:\WINDOWS\system32\accwiz.exe
2009-08-25 13:04:42 —-A—- C:\WINDOWS\system32\winchat.exe
2009-08-25 13:04:38 —-A—- C:\WINDOWS\system32\winmine.exe
2009-08-25 13:04:38 —-A—- C:\WINDOWS\system32\sol.exe
2009-08-25 13:04:38 —-A—- C:\WINDOWS\system32\mshearts.exe
2009-08-25 13:04:38 —-A—- C:\WINDOWS\system32\getuname.dll
2009-08-25 13:04:38 —-A—- C:\WINDOWS\system32\freecell.exe
2009-08-25 13:04:38 —-A—- C:\WINDOWS\system32\charmap.exe
2009-08-25 13:04:38 —-A—- C:\WINDOWS\system32\calc.exe
2009-08-25 13:04:37 —-A—- C:\WINDOWS\system32\usrlogon.cmd
2009-08-25 13:04:37 —-A—- C:\WINDOWS\system32\tsshutdn.exe
2009-08-25 13:04:37 —-A—- C:\WINDOWS\system32\tslabels.ini
2009-08-25 13:04:37 —-A—- C:\WINDOWS\system32\tskill.exe
2009-08-25 13:04:37 —-A—- C:\WINDOWS\system32\tsdiscon.exe
2009-08-25 13:04:37 —-A—- C:\WINDOWS\system32\tscon.exe
2009-08-25 13:04:37 —-A—- C:\WINDOWS\system32\shadow.exe
2009-08-25 13:04:37 —-A—- C:\WINDOWS\system32\rwinsta.exe
2009-08-25 13:04:37 —-A—- C:\WINDOWS\system32\reset.exe
2009-08-25 13:04:37 —-A—- C:\WINDOWS\system32\regini.exe
2009-08-25 13:04:37 —-A—- C:\WINDOWS\system32\rdshost.exe
2009-08-25 13:04:37 —-A—- C:\WINDOWS\system32\rdpcfgex.dll
2009-08-25 13:04:37 —-A—- C:\WINDOWS\system32\qwinsta.exe
2009-08-25 13:04:37 —-A—- C:\WINDOWS\system32\qprocess.exe
2009-08-25 13:04:37 —-A—- C:\WINDOWS\system32\qappsrv.exe
2009-08-25 13:04:37 —-A—- C:\WINDOWS\system32\msg.exe
2009-08-25 13:04:37 —-A—- C:\WINDOWS\system32\msdtcuiu.dll
2009-08-25 13:04:37 —-A—- C:\WINDOWS\system32\logoff.exe
2009-08-25 13:04:37 —-A—- C:\WINDOWS\system32\cdmodem.dll
2009-08-25 13:04:36 —-A—- C:\WINDOWS\system32\xolehlp.dll
2009-08-25 13:04:36 —-A—- C:\WINDOWS\system32\mtxoci.dll
2009-08-25 13:04:36 —-A—- C:\WINDOWS\system32\msdtctm.dll
2009-08-25 13:04:36 —-A—- C:\WINDOWS\system32\msdtcprf.ini
2009-08-25 13:04:36 —-A—- C:\WINDOWS\system32\msdtclog.dll
2009-08-25 13:04:36 —-A—- C:\WINDOWS\system32\msdtc.exe
2009-08-25 13:04:35 —-A—- C:\WINDOWS\system32\stclient.dll
2009-08-25 13:04:35 —-A—- C:\WINDOWS\system32\mtxlegih.dll
2009-08-25 13:04:35 —-A—- C:\WINDOWS\system32\mtxex.dll
2009-08-25 13:04:35 —-A—- C:\WINDOWS\system32\mtxdm.dll
2009-08-25 13:04:35 —-A—- C:\WINDOWS\system32\dcomcnfg.exe
2009-08-25 13:04:35 —-A—- C:\WINDOWS\system32\comrepl.dll
2009-08-25 13:04:35 —-A—- C:\WINDOWS\system32\comaddin.dll
2009-08-25 13:04:35 —-A—- C:\WINDOWS\system32\colbact.dll
2009-08-25 13:04:35 —-A—- C:\WINDOWS\system32\clbcatex.dll
2009-08-25 13:04:35 —-A—- C:\WINDOWS\system32\catsrvps.dll
2009-08-25 13:04:35 —-A—- C:\WINDOWS\system32\catsrv.dll
2009-08-25 13:04:34 —-A—- C:\WINDOWS\system32\comuid.dll
2009-08-25 13:04:34 —-A—- C:\WINDOWS\system32\comsnap.dll
2009-08-25 13:04:34 —-A—- C:\WINDOWS\system32\clbcatq.dll
2009-08-25 13:04:30 —-A—- C:\WINDOWS\system32\wmimgmt.msc
2009-08-25 13:04:30 —-A—- C:\WINDOWS\system32\servdeps.dll
2009-08-25 13:04:30 —-A—- C:\WINDOWS\system32\mmfutil.dll
2009-08-25 13:04:30 —-A—- C:\WINDOWS\system32\cmprops.dll
2009-08-25 13:04:26 —-D—- C:\Program Files\Windows NT
2009-08-25 13:04:26 —-D—- C:\Program Files\MSN
2009-08-25 13:04:26 —-A—- C:\WINDOWS\system32\wuauserv.dll
2009-08-25 13:04:26 —-A—- C:\WINDOWS\system32\wuaueng.dll
2009-08-25 13:04:26 —-A—- C:\WINDOWS\system32\wuauclt.exe
2009-08-25 13:04:26 —-A—- C:\WINDOWS\system32\spider.exe
2009-08-25 13:04:26 —-A—- C:\WINDOWS\system32\mspaint.exe
2009-08-25 13:04:26 —-A—- C:\WINDOWS\system32\mplay32.exe
2009-08-25 13:04:26 —-A—- C:\WINDOWS\system32\clipbrd.exe
2009-08-25 13:04:25 —-A—- C:\WINDOWS\system32\tscupgrd.exe
2009-08-25 13:04:25 —-A—- C:\WINDOWS\system32\tscfgwmi.dll
2009-08-25 13:04:25 —-A—- C:\WINDOWS\system32\termsrv.dll
2009-08-25 13:04:25 —-A—- C:\WINDOWS\system32\sessmgr.exe
2009-08-25 13:04:25 —-A—- C:\WINDOWS\system32\remotepg.dll
2009-08-25 13:04:25 —-A—- C:\WINDOWS\system32\rdsaddin.exe
2009-08-25 13:04:25 —-A—- C:\WINDOWS\system32\rdpwsx.dll
2009-08-25 13:04:25 —-A—- C:\WINDOWS\system32\rdpsnd.dll
2009-08-25 13:04:25 —-A—- C:\WINDOWS\system32\rdpclip.exe
2009-08-25 13:04:25 —-A—- C:\WINDOWS\system32\rdchost.dll
2009-08-25 13:04:25 —-A—- C:\WINDOWS\system32\mstscax.dll
2009-08-25 13:04:25 —-A—- C:\WINDOWS\system32\mstsc.exe
2009-08-25 13:04:24 —-D—- C:\WINDOWS\system32\MsDtc
2009-08-25 13:04:24 —-D—- C:\WINDOWS\system32\Com
2009-08-25 13:04:24 —-A—- C:\WINDOWS\system32\msdtcprx.dll
2009-08-25 13:04:24 —-A—- C:\WINDOWS\system32\icaapi.dll
2009-08-25 13:04:24 —-A—- C:\WINDOWS\system32\comsvcs.dll
2009-08-25 13:04:24 —-A—- C:\WINDOWS\system32\cfgbkend.dll
2009-08-25 13:04:24 —-A—- C:\WINDOWS\system32\catsrvut.dll
2009-08-25 13:04:22 —-A—- C:\WINDOWS\system32\licwmi.dll
2009-08-25 09:03:32 —-A—- C:\WINDOWS\system32\h323log.txt
2009-08-25 09:01:50 —-A—- C:\WINDOWS\system32\usbui.dll
2009-08-25 09:01:17 —-A—- C:\WINDOWS\imsins.BAK
2009-08-25 09:01:15 —-A—- C:\WINDOWS\system32\PerfStringBackup.INI
2009-08-25 09:01:14 —-D—- C:\Program Files\Common Files\ODBC
2009-08-25 09:01:14 —-A—- C:\WINDOWS\ODBCINST.INI
2009-08-25 09:01:11 —-RD—- C:\Program Files
2009-08-25 09:01:11 —-D—- C:\Program Files\Common Files\SpeechEngines
2009-08-25 09:01:11 —-D—- C:\Program Files\Common Files\Microsoft Shared
2009-08-25 09:01:11 —-D—- C:\Program Files\Common Files
2009-08-25 09:01:09 —-RA—- C:\WINDOWS\system32\kbdtuq.dll
2009-08-25 09:01:09 —-RA—- C:\WINDOWS\system32\kbdtuf.dll
2009-08-25 09:01:09 —-RA—- C:\WINDOWS\system32\kbdazel.dll
2009-08-25 09:01:08 —-RA—- C:\WINDOWS\system32\kbdycc.dll
2009-08-25 09:01:08 —-RA—- C:\WINDOWS\system32\kbduzb.dll
2009-08-25 09:01:08 —-RA—- C:\WINDOWS\system32\kbdur.dll
2009-08-25 09:01:08 —-RA—- C:\WINDOWS\system32\kbdtat.dll
2009-08-25 09:01:08 —-RA—- C:\WINDOWS\system32\kbdru1.dll
2009-08-25 09:01:08 —-RA—- C:\WINDOWS\system32\kbdru.dll
2009-08-25 09:01:08 —-RA—- C:\WINDOWS\system32\kbdmon.dll
2009-08-25 09:01:08 —-RA—- C:\WINDOWS\system32\kbdkyr.dll
2009-08-25 09:01:08 —-RA—- C:\WINDOWS\system32\kbdkaz.dll
2009-08-25 09:01:08 —-RA—- C:\WINDOWS\system32\kbdbu.dll
2009-08-25 09:01:08 —-RA—- C:\WINDOWS\system32\kbdblr.dll
2009-08-25 09:01:08 —-RA—- C:\WINDOWS\system32\kbdaze.dll
2009-08-25 09:01:06 —-RA—- C:\WINDOWS\system32\kbdhept.dll
2009-08-25 09:01:06 —-RA—- C:\WINDOWS\system32\kbdhela3.dll
2009-08-25 09:01:06 —-RA—- C:\WINDOWS\system32\kbdhela2.dll
2009-08-25 09:01:06 —-RA—- C:\WINDOWS\system32\kbdhe319.dll
2009-08-25 09:01:06 —-RA—- C:\WINDOWS\system32\kbdhe220.dll
2009-08-25 09:01:06 —-RA—- C:\WINDOWS\system32\kbdhe.dll
2009-08-25 09:01:06 —-RA—- C:\WINDOWS\system32\kbdgkl.dll
2009-08-25 09:01:05 —-RA—- C:\WINDOWS\system32\kbdlv1.dll
2009-08-25 09:01:05 —-RA—- C:\WINDOWS\system32\kbdlv.dll
2009-08-25 09:01:05 —-RA—- C:\WINDOWS\system32\kbdlt1.dll
2009-08-25 09:01:05 —-RA—- C:\WINDOWS\system32\kbdlt.dll
2009-08-25 09:01:05 —-RA—- C:\WINDOWS\system32\kbdest.dll
2009-08-25 09:01:04 —-RA—- C:\WINDOWS\system32\kbdycl.dll
2009-08-25 09:01:04 —-RA—- C:\WINDOWS\system32\kbdsl1.dll
2009-08-25 09:01:04 —-RA—- C:\WINDOWS\system32\kbdsl.dll
2009-08-25 09:01:04 —-RA—- C:\WINDOWS\system32\kbdro.dll
2009-08-25 09:01:04 —-RA—- C:\WINDOWS\system32\kbdpl1.dll
2009-08-25 09:01:04 —-RA—- C:\WINDOWS\system32\kbdpl.dll
2009-08-25 09:01:04 —-RA—- C:\WINDOWS\system32\kbdhu1.dll
2009-08-25 09:01:04 —-RA—- C:\WINDOWS\system32\kbdhu.dll
2009-08-25 09:01:04 —-RA—- C:\WINDOWS\system32\kbdcz2.dll
2009-08-25 09:01:04 —-RA—- C:\WINDOWS\system32\kbdcz1.dll
2009-08-25 09:01:04 —-RA—- C:\WINDOWS\system32\kbdcz.dll
2009-08-25 09:01:04 —-RA—- C:\WINDOWS\system32\kbdcr.dll
2009-08-25 09:01:04 —-RA—- C:\WINDOWS\system32\KBDAL.DLL
2009-08-25 09:01:02 —-A—- C:\WINDOWS\system32\spxcoins.dll
2009-08-25 09:01:02 —-A—- C:\WINDOWS\system32\irclass.dll
2009-08-25 09:01:02 —-A—- C:\WINDOWS\system32\EqnClass.Dll
2009-08-25 09:01:02 —-A—- C:\WINDOWS\system32\dgsetup.dll
2009-08-25 09:01:02 —-A—- C:\WINDOWS\system32\dgrpsetu.dll
2009-08-25 09:01:00 —-N—- C:\WINDOWS\system32\CONFIG.TMP
2009-08-25 09:01:00 —-A—- C:\WINDOWS\TASKMAN.EXE
2009-08-25 09:01:00 —-A—- C:\WINDOWS\system32\storprop.dll
2009-08-25 09:01:00 —-A—- C:\WINDOWS\system32\batt.dll
2009-08-25 09:01:00 —-A—- C:\WINDOWS\notepad.exe
2009-08-25 09:00:56 —-ASH—- C:\Documents and Settings\All Users\Application Data\desktop.ini
2009-08-25 09:00:52 —-RA—- C:\WINDOWS\SETA.tmp
2009-08-25 09:00:49 —-RA—- C:\WINDOWS\SET3.tmp
2009-08-25 09:00:45 —-D—- C:\WINDOWS\system32\CatRoot2
2009-08-25 09:00:45 —-D—- C:\WINDOWS\system32\CatRoot
2009-08-25 09:00:39 —-SD—- C:\Documents and Settings\All Users\Application Data\Microsoft
2009-08-25 09:00:27 —-A—- C:\WINDOWS\setuplog.txt
2009-08-25 09:00:24 —-D—- C:\Documents and Settings
2009-08-25 08:59:34 —-RASH—- C:\boot.ini
2009-08-25 08:57:14 —-RSHDC—- C:\WINDOWS\system32\dllcache
2009-08-25 08:57:14 —-RSD—- C:\WINDOWS\Fonts
2009-08-25 08:57:14 —-RD—- C:\WINDOWS\Web
2009-08-25 08:57:14 —-HD—- C:\WINDOWS\inf
2009-08-25 08:57:14 —-D—- C:\WINDOWS\WinSxS
2009-08-25 08:57:14 —-D—- C:\WINDOWS\twain_32
2009-08-25 08:57:14 —-D—- C:\WINDOWS\Temp
2009-08-25 08:57:14 —-D—- C:\WINDOWS\system32\wins
2009-08-25 08:57:14 —-D—- C:\WINDOWS\system32\wbem
2009-08-25 08:57:14 —-D—- C:\WINDOWS\system32\usmt
2009-08-25 08:57:14 —-D—- C:\WINDOWS\system32\spool
2009-08-25 08:57:14 —-D—- C:\WINDOWS\system32\ShellExt
2009-08-25 08:57:14 —-D—- C:\WINDOWS\system32\Setup
2009-08-25 08:57:14 —-D—- C:\WINDOWS\system32\ras
2009-08-25 08:57:14 —-D—- C:\WINDOWS\system32\oobe
2009-08-25 08:57:14 —-D—- C:\WINDOWS\system32\npp
2009-08-25 08:57:14 —-D—- C:\WINDOWS\system32\mui
2009-08-25 08:57:14 —-D—- C:\WINDOWS\system32\inetsrv
2009-08-25 08:57:14 —-D—- C:\WINDOWS\system32\IME
2009-08-25 08:57:14 —-D—- C:\WINDOWS\system32\icsxml
2009-08-25 08:57:14 —-D—- C:\WINDOWS\system32\ias
2009-08-25 08:57:14 —-D—- C:\WINDOWS\system32\export
2009-08-25 08:57:14 —-D—- C:\WINDOWS\system32\drivers
2009-08-25 08:57:14 —-D—- C:\WINDOWS\system32\dhcp
2009-08-25 08:57:14 —-D—- C:\WINDOWS\system32\config
2009-08-25 08:57:14 —-D—- C:\WINDOWS\system32\3com_dmi
2009-08-25 08:57:14 —-D—- C:\WINDOWS\system32\3076
2009-08-25 08:57:14 —-D—- C:\WINDOWS\system32\2052
2009-08-25 08:57:14 —-D—- C:\WINDOWS\system32\1054
2009-08-25 08:57:14 —-D—- C:\WINDOWS\system32\1042
2009-08-25 08:57:14 —-D—- C:\WINDOWS\system32\1041
2009-08-25 08:57:14 —-D—- C:\WINDOWS\system32\1037
2009-08-25 08:57:14 —-D—- C:\WINDOWS\system32\1033
2009-08-25 08:57:14 —-D—- C:\WINDOWS\system32\1031
2009-08-25 08:57:14 —-D—- C:\WINDOWS\system32\1028
2009-08-25 08:57:14 —-D—- C:\WINDOWS\system32\1025
2009-08-25 08:57:14 —-D—- C:\WINDOWS\system32
2009-08-25 08:57:14 —-D—- C:\WINDOWS\system
2009-08-25 08:57:14 —-D—- C:\WINDOWS\security
2009-08-25 08:57:14 —-D—- C:\WINDOWS\Resources
2009-08-25 08:57:14 —-D—- C:\WINDOWS\repair
2009-08-25 08:57:14 —-D—- C:\WINDOWS\mui
2009-08-25 08:57:14 —-D—- C:\WINDOWS\msapps
2009-08-25 08:57:14 —-D—- C:\WINDOWS\msagent
2009-08-25 08:57:14 —-D—- C:\WINDOWS\Media
2009-08-25 08:57:14 —-D—- C:\WINDOWS\java
2009-08-25 08:57:14 —-D—- C:\WINDOWS\ime
2009-08-25 08:57:14 —-D—- C:\WINDOWS\Help
2009-08-25 08:57:14 —-D—- C:\WINDOWS\Driver Cache
2009-08-25 08:57:14 —-D—- C:\WINDOWS\Debug
2009-08-25 08:57:14 —-D—- C:\WINDOWS\Cursors
2009-08-25 08:57:14 —-D—- C:\WINDOWS\Connection Wizard
2009-08-25 08:57:14 —-D—- C:\WINDOWS\Config
2009-08-25 08:57:14 —-D—- C:\WINDOWS\AppPatch
2009-08-25 08:57:14 —-D—- C:\WINDOWS\addins
2009-08-25 08:57:14 —-D—- C:\WINDOWS

======List of files/folders modified in the last 1 months======

2009-08-25 13:21:36 —-A—- C:\WINDOWS\win.ini
2009-08-25 13:17:12 —-RASH—- C:\NTDETECT.COM
2009-08-25 09:01:11 —-A—- C:\WINDOWS\system.ini
2009-08-05 05:11:47 —-A—- C:\WINDOWS\system32\mswebdvd.dll

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2009-08-25 335240]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2009-08-25 27784]
R1 AvgTdiX;AVG Free8 Network Redirector; C:\WINDOWS\System32\Drivers\avgtdix.sys [2009-08-25 108552]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2004-08-03 36096]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2004-10-01 2279424]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\System32\DRIVERS\arp1394.sys [2004-08-03 60800]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2002-08-29 9600]
R3 ltmodem5;LT Modem Driver; C:\WINDOWS\System32\DRIVERS\ltmdmnt.sys [2004-08-03 606684]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2002-08-29 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\System32\DRIVERS\nic1394.sys [2004-08-03 61824]
R3 nv;nv; C:\WINDOWS\System32\DRIVERS\nv4_mini.sys [2008-05-16 6557408]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2004-08-03 26624]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbstor;USB Mass Storage Driver; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2004-08-03 20480]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avg8emc;AVG Free8 E-mail Scanner; C:\PROGRA~1\AVG\AVG8\avgemc.exe [2009-08-25 908056]
R2 avg8wd;AVG Free8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2009-08-25 297752]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-05-16 159812]

—————–EOF—————–

2nd Log-Info.txt:

info.txt logfile of random's system information tool 1.06 2009-08-30 11:08:34

======Uninstall list======

–>rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
AVG Free 8.5–>C:\Program Files\AVG\AVG8\setup.exe /UNINSTALL
HijackThis 2.0.2–>"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Windows XP (KB970653-v3)–>"C:\WINDOWS\$NtUninstallKB970653-v3$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable–>MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
NVIDIA Drivers–>C:\WINDOWS\system32\nvuninst.exe UninstallGUI
Realtek AC'97 Audio–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" REMOVE
Security Update for Windows Internet Explorer 8 (KB972260)–>"C:\WINDOWS\ie8updates\KB972260-IE8\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB973540)–>"C:\WINDOWS\$NtUninstallKB973540_WM9L$\spuninst\spuninst.exe"
Security Update for Windows XP (KB938464-v2)–>"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)–>"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)–>"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)–>"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)–>"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952004)–>"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)–>"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956572)–>"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)–>"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957097)–>"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958687)–>"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
Security Update for Windows XP (KB959426)–>"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960225)–>"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960859)–>"C:\WINDOWS\$NtUninstallKB960859$\spuninst\spuninst.exe"
Security Update for Windows XP (KB961371-v2)–>"C:\WINDOWS\$NtUninstallKB961371-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB961501)–>"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971557)–>"C:\WINDOWS\$NtUninstallKB971557$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971633)–>"C:\WINDOWS\$NtUninstallKB971633$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971657)–>"C:\WINDOWS\$NtUninstallKB971657$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973346)–>"C:\WINDOWS\$NtUninstallKB973346$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973507)–>"C:\WINDOWS\$NtUninstallKB973507$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973869)–>"C:\WINDOWS\$NtUninstallKB973869$\spuninst\spuninst.exe"
Update for Windows Internet Explorer 8 (KB973874)–>"C:\WINDOWS\ie8updates\KB973874-IE8\spuninst\spuninst.exe"
Update for Windows XP (KB898461)–>"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
Update for Windows XP (KB932823-v3)–>"C:\WINDOWS\$NtUninstallKB932823-v3$\spuninst\spuninst.exe"
Update for Windows XP (KB967715)–>"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
Windows Installer 3.1 (KB893803)–>"C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
Windows Internet Explorer 8–>"C:\WINDOWS\ie8\spuninst\spuninst.exe"
Windows XP Hotfix - KB885626–>C:\WINDOWS\$NtUninstallKB885626$\spuninst\spuninst.exe
Windows XP Service Pack 2–>C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe

======Security center information======

AV: AVG Anti-Virus Free

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
"windir"=%SystemRoot%
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 3 Stepping 3, GenuineIntel
"PROCESSOR_REVISION"=0303
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"FP_NO_HOST_CHECK"=NO

—————–EOF—————–


There you go.
Hi, Your logs look fine. If you would have done a system repair, installing the Operating System on top of the current installation its possible that whatever bad was installed could still be there but reformatting and doing a clean install would have gotten rid of any bad stuff that was installed. How are things running now ?
Well I did install a fresh copy, first I deleted the old partion to insure everything was wiped,then created a new one. I had a feeling it would be clean now, computers running perfectly clean. Just wanted some insurance from the pros. =) Thanks alot.
Your more than Welcome Jassi

Go ahead and install Service Pack 3 , it will help keep the bad guys out. Open IE and go to Tools> Windows Updates and download and install all critical updates.

  • How did I get infected in the first place ?
    Read these links and find out how to prevent getting infected again.
  • Tutorial for System Restore <– Do this first to prevent yourself from being reinfected.
  • WhattheTech
  • Grinler BleepingComputer
  • GeeksTo Go
  • Dslreports



Keep in mind if you install some of these programs. Only ONE Anti Virus and only ONE Firewall is recommended, more is overkill and can cause you problems. You can install all the Spyware programs I have listed without any problems. If you install Spyware Blaster and Spyware Guard, they will conflict with the TeaTimer in Spybot , you can still install Spybot Search and Destroy but do not enable the TeaTimer .



Here are some free programs to install, all free and highly regarded by the fine people in the Malware Removal Community
  • Spybot Search and Destroy 1.6
    Check for Updates/ Immunize and run a Full System Scan on a regular basis. If you install Spyware Blaster ( Recommended ) then do not enable the TeaTimer in Spybot Search and Destroy.
  • Spyware Blaster It will prevent most spyware from ever being installed. No scan to run, just update about once a week and enable all protection.
  • Spyware Guard It offers realtime protection from spyware installation attempts, again, no scan to run, just install it and let it do its thing.
  • IE-Spyad
    IE-Spyad places over 6000 web sites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • Firefox 3 It has more features and is a lot more secure than IE. It is a very easy and painless download and install, it will no way interfere with IE, you can use them both.


Safe Surfn
Ken
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI