verveg1
Topic Starter
Cant remove Trojan horse Generic16.AGDS C:\Windows\system32\drivers\atmarpc.sys
Malwarebytes' Anti-Malware 1.44
Database version: 3595
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
1/18/2010 6:11:20 PM
mbam-log-2010-01-18 (18-11-20).txt
Scan type: Quick Scan
Objects scanned: 116747
Time elapsed: 9 minute(s), 20 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a078f691-9c07-4af2-bf43-35e79eecf8b7} (Adware.Softomate) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system32\spool\prtprocs\w32x86\00002a46.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\spool\prtprocs\w32x86\00006d85.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\k\rundll32.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-18 20:15:24
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\k\LOCALS~1\Temp\kwaoifob.sys
—- System - GMER 1.0.15 —-
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xEE5000B0]
—- Devices - GMER 1.0.15 —-
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 mouclass.sys (Mouse Class Driver/Microsoft Corporation)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
Device \FileSystem\Fastfat \Fat ECBFBD20
Device \FileSystem\Fastfat \Fat ECC028C1
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Cdfs \Cdfs tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
—- Files - GMER 1.0.15 —-
File C:\WINDOWS\system32\mobsync.dll (size mismatch) 32768/207360 bytes executable
—- EOF - GMER 1.0.15 —-
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-06-26.01)
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 12/24/2008 6:13:34 PM
System Uptime: 1/18/2010 6:12:44 PM (2 hours ago)
Motherboard: IBM | | 2888WQ4
Processor: Intel® Pentium® M processor 1.70GHz | None | 1698/400mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 33 GiB total, 7.796 GiB free.
D: is CDROM ()
==== Disabled Device Manager Items =============
==== System Restore Points ===================
RP2: 1/12/2010 1:09:36 PM - System Checkpoint
RP3: 1/12/2010 6:10:55 PM - Software Distribution Service 3.0
RP4: 1/12/2010 11:20:36 PM - Installed MSN Toolbar
RP5: 1/13/2010 1:00:06 AM - Software Distribution Service 3.0
RP6: 1/14/2010 5:35:16 AM - System Checkpoint
RP7: 1/15/2010 5:04:18 AM - Installed Java™ 6 Update 17
RP8: 1/15/2010 2:15:28 PM - Removed MSN Toolbar
RP9: 1/16/2010 6:12:47 PM - System Checkpoint
RP10: 1/16/2010 7:06:26 PM - OTS Restore Point
RP11: 1/16/2010 7:09:09 PM - OTS Restore Point
RP12: 1/17/2010 7:23:06 PM - System Checkpoint
RP13: 1/18/2010 5:43:53 PM - Avg8 Update
==== Installed Programs ======================
Access IBM
Access IBM Message Center
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 7.0
Apple Application Support
Apple Mobile Device Support
Apple Software Update
AVG Free 9.0
AVI Media Player 1.0
Bonjour
CCScore
Cisco Network Magic
ERUNT 1.1j
ESSCDBK
ESScore
ESSgui
ESSini
ESSPCD
ESSSONIC
ESSTOOLS
essvatgt
Google Toolbar for Internet Explorer
HijackThis 2.0.2
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
IBM 32-bit Runtime Environment for Java 2, v1.4.1
IBM Active Protection System
IBM DLA
IBM Integrated 56K Modem
IBM RecordNow!
IBM Rescue and Recovery with Rapid Restore
IBM Themes
IBM ThinkPad Battery MaxiMiser and Power Management Features
IBM ThinkPad Configuration
IBM ThinkPad EasyEject Utility
IBM ThinkPad Keyboard Customizer Utility
IBM ThinkPad Power Management Driver
IBM ThinkPad Presentation Director
IBM ThinkPad UltraNav Driver
IBM ThinkPad UltraNav Wizard
IBM ThinkVantage Technologies Welcome Message
IBM TrackPoint Accessibility Features
IBM Update Connector
Intel® Extreme Graphics 2 Driver
Intel® PRO Network Adapters and Drivers
Intel® PROSet/Wireless WiFi Software
Intel® Sebring API
iTunes
Java™ 6 Update 16
kgcbaby
kgcbase
kgchday
kgchlwn
kgcinvt
kgckids
kgcmove
kgcvday
Kodak EasyShare software
KSU
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Professional Edition 2003
Microsoft Silverlight
Microsoft VC9 runtime libraries
Microsoft Visual C++ 2005 Redistributable
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
netbrdg
Network Magic
Notifier
OfotoXMI
PCDADDIN
PCDHELP
Pure Networks Platform
QuickTime
RealPlayer
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960714)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
SFR
SHASTA
SKIN0001
SKINXSDK
Sonic Update Manager
Spybot - Search & Destroy
staticcr
SUPERAntiSpyware Free Edition
ThinkPad FullScreen Magnifier
ThinkPad Software Installer
tooltips
Update for Windows Internet Explorer 8 (KB971930)
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Viewpoint Media Player
VLC media player 0.9.2
VPRINTOL
Vuze
Vuze Toolbar
Wallpapers
WebEx Support Manager for Internet Explorer
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Internet Explorer 8
Windows XP Service Pack 3
WIRELESS
Yahoo! Software Update
Yahoo! Toolbar
==== Event Viewer Messages From Past Week ========
1/16/2010 7:59:11 AM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000043' while processing the file 'wmpscfgs.exe' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.
1/16/2010 5:26:40 PM, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\ctfmon.exe. This file was restored to the original version to maintain system stability. The file version of the system file is 5.1.2600.5512.
1/16/2010 5:04:30 PM, error: Service Control Manager [7034] - The IBM KCU Service service terminated unexpectedly. It has done this 1 time(s).
1/16/2010 2:10:40 PM, error: Service Control Manager [7000] - The Intel® PROSet/Wireless Event Log service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
1/16/2010 2:10:39 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the Spooler service.
1/16/2010 2:10:39 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Intel® PROSet/Wireless Event Log service to connect.
1/16/2010 2:10:39 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Apple Mobile Device service to connect.
1/16/2010 2:10:39 PM, error: Service Control Manager [7000] - The Apple Mobile Device service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
1/16/2010 12:11:34 AM, error: Service Control Manager [7000] - The SASDIFSV service failed to start due to the following error: Cannot create a file when that file already exists.
1/16/2010 12:02:36 AM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000243' while processing the file 'is2010.exe' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.
1/15/2010 6:50:53 PM, error: Service Control Manager [7034] - The Terminal Services service terminated unexpectedly. It has done this 1 time(s).
1/15/2010 6:50:53 PM, error: Service Control Manager [7031] - The DCOM Server Process Launcher service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Reboot the machine.
1/15/2010 4:54:48 AM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000243' while processing the file 'wmpscfgs.exe' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.
1/15/2010 10:04:40 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the avg9wd service.
1/14/2010 9:01:51 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Google Software Updater service to connect.
1/14/2010 9:01:46 PM, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service gusvc with arguments "" in order to run the server: {89DAE4CD-9F17-4980-902A-99BA84A8F5C8}
1/14/2010 3:18:01 PM, error: Ftdisk [49] - Configuring the Page file for crash dump failed. Make sure there is a page file on the boot partition and that is large enough to contain all physical memory.
1/14/2010 3:18:01 PM, error: Ftdisk [45] - The system could not sucessfully load the crash dump driver.
1/14/2010 2:02:15 AM, information: Windows File Protection [64002] - File replacement was attempted on the protected system file aec.sys. This file was restored to the original version to maintain system stability. The file version of the system file is 5.1.2601.3142.
1/14/2010 2:02:15 AM, information: Windows File Protection [64002] - File replacement was attempted on the protected system file ac97intc.sys. This file was restored to the original version to maintain system stability. The file version of the system file is 5.10.0.3523.
1/14/2010 2:00:02 AM, error: Service Control Manager [7000] - The Microsoft Kernel Acoustic Echo Canceller service failed to start due to the following error: Access is denied.
1/14/2010 1:59:58 AM, error: Service Control Manager [7000] - The Intel® 82801 Audio Driver Install Service (WDM) service failed to start due to the following error: Access is denied.
1/13/2010 1:33:56 AM, error: Service Control Manager [7023] - The Network Security service terminated with the following error: The system cannot find the file specified.
1/13/2010 1:33:56 AM, error: Service Control Manager [7003] - The Spectrum24 Event Monitor service depends on the following nonexistent service: s24trans
1/12/2010 12:53:34 AM, error: Dhcp [1002] - The IP address lease 192.168.1.44 for the Network Card with network address 0012F0E904B4 has been denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message).
1/11/2010 3:40:49 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.
1/11/2010 12:44:11 PM, error: Service Control Manager [7034] - The fastnetsrv Service service terminated unexpectedly. It has done this 1 time(s).
==== End Of File ===========================
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 20:22:28.41 on Mon 01/18/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.590 [GMT -5:00]
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Internet Antivirus *On-access scanning enabled* (Outdated) {18B0AD40-E077-4625-850C-DDD3EB0FF925}
============== Running Processes ===============
C:\WINDOWS\System32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
svchost.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AskBarDis\bar\bin\AskService.exe
C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\system32\TpKmpSVC.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\TpShocks.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Documents and Settings\k\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://my.yahoo.com/linksys
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride =
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: {C26CD490-5F01-41E3-B150-EB29F19DA056} - No File
BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - No File
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ibmmessages] c:\program files\ibm\messages by ibm\ibmmessages .exe
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [S3TRAY2] S3Tray2.exe
mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [TPKMAPHELPER] c:\program files\thinkpad\utilities\TpKmapAp.exe -helper
mRun: [TpShocks] TpShocks.exe
mRun: [TPHOTKEY] c:\progra~1\thinkpad\pkgmgr\hotkey\TPHKMGR.exe
mRun: [TP4EX] tp4ex.exe
mRun: [EZEJMNAP] c:\progra~1\thinkpad\utilit~1\EzEjMnAp.Exe
mRun: [UC_Start] c:\program files\ibm\updater\\ucstartup.exe
mRun: [UC_SMB]
mRun: [UpdateManager] "c:\program files\common files\sonic\update manager\sgtray.exe" /r
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [ibmmessages] c:\program files\ibm\messages by ibm\\ibmmessages.exe
mRun: [IBMPRC] c:\ibmtools\utils\ibmprc.exe
mRun: [BMMGAG] RunDll32 c:\progra~1\thinkpad\utilit~1\pwrmonit.dll,StartPwrMonitor
mRun: [BMMLREF] c:\program files\thinkpad\utilities\BMMLREF.EXE
mRun: [BMMMONWND] rundll32.exe c:\progra~1\thinkpad\utilit~1\BatInfEx.dll,BMMAutonomicMonitor
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask .exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [nmctxth] "c:\program files\common files\pure networks shared\platform\nmctxth.exe"
mRun: [nmapp] "c:\program files\pure networks\network magic\nmapp.exe" -autorun -nosplash
StartupFolder: c:\docume~1\k\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\kodake~1.lnk - c:\program files\kodak\kodak easyshare software\bin\EasyShare.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\kodaks~1.lnk - c:\program files\kodak\kodak software updater\7288971\program\Kodak Software Updater.exe
dPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
IE: E&xport to Microsoft Excel
IE: Google Sidewiki…
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/1.4.1/jinstall-141-win.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Handler: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - c:\program files\common files\pure networks shared\platform\puresp4.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: igfxcui - igfxsrvc.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
============= SERVICES / DRIVERS ===============
R0 Shockprf;Shockprf;c:\windows\system32\drivers\shockprf.sys [2008-8-20 59520]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-1-3 333192]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-1-3 28424]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-1-3 360584]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-10-12 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-10-12 74480]
R1 ShockMgr;ShockMgr;c:\windows\system32\drivers\ShockMgr.sys [2008-8-20 4608]
R1 TPPWR;TPPWR;c:\windows\system32\drivers\TPPWR.SYS [2008-8-20 16384]
R2 ASKService;ASKService;c:\program files\askbardis\bar\bin\AskService.exe [2010-1-3 464264]
R2 ASKUpgrade;ASKUpgrade;c:\program files\askbardis\bar\bin\ASKUpgrade.exe [2010-1-3 234888]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-1-3 285392]
R2 ibmfilter;ibmfilter;c:\windows\system32\drivers\ibmfilter.sys [2004-9-23 64256]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-3-30 24652]
R2 YahooAUService;Yahoo! Updater;c:\program files\yahoo!\softwareupdate\YahooAUService.exe [2008-11-9 602392]
R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-10-12 7408]
=============== Created Last 30 ================
2010-01-18 20:19 –d—– c:\docume~1\k\applic~1\AVG9
2010-01-18 17:47 4 a——- c:\program files\84409163.dat
2010-01-17 18:46 –d—– c:\program files\Trend Micro
2010-01-16 18:43 a-dshr– C:\autorun.inf
2010-01-16 17:04 4 a——- c:\program files\6466157.dat
2010-01-16 17:04 0 a——- c:\program files\6465346.dat
2010-01-16 17:02 a-dshr– C:\cmdcons
2010-01-16 17:00 261,632 a——- c:\windows\PEV.exe
2010-01-16 17:00 77,312 a——- c:\windows\MBR.exe
2010-01-16 13:58 4 a——- c:\program files\10261194.dat
2010-01-16 11:06 4 a——- c:\program files\11303333.dat
2010-01-16 07:56 4 a——- c:\program files\28497537.dat
2010-01-15 20:47 –d—– c:\docume~1\k\applic~1\AVG8
2010-01-15 18:52 4 a——- c:\program files\3489958.dat
2010-01-15 18:52 4 a——- c:\program files\3489687.dat
2010-01-15 18:52 0 a——- c:\program files\3489527.dat
2010-01-15 10:05 4 a——- c:\program files\18712176.dat
2010-01-15 10:05 4 a——- c:\program files\18711956.dat
2010-01-15 10:05 4 a——- c:\program files\18711585.dat
2010-01-15 10:05 4 a——- c:\program files\18711205.dat
2010-01-15 04:52 4 a——- c:\program files\5971276.dat
2010-01-15 04:52 4 a——- c:\program files\5970344.dat
2010-01-15 04:52 4 a——- c:\program files\5967951.dat
2010-01-15 01:42 4 a——- c:\program files\650445.dat
2010-01-15 01:42 4 a——- c:\program files\649443.dat
2010-01-15 01:29 4 a——- c:\program files\9405304.dat
2010-01-15 01:29 4 a——- c:\program files\9404913.dat
2010-01-14 18:17 4 a——- c:\program files\10799649.dat
2010-01-14 18:16 4 a——- c:\program files\10751399.dat
2010-01-14 12:27 221,184 a——- c:\windows\system32\wmpns.dll
2010-01-14 12:06 4 a——- c:\program files\64140889.dat
2010-01-14 12:06 4 a——- c:\program files\64139768.dat
2010-01-14 12:06 4 a——- c:\program files\64138966.dat
2010-01-14 02:02 142,592 a——- c:\windows\system32\dllcache\aec.sys
2010-01-14 02:02 142,592 ——– c:\windows\system32\drivers\aec.sys
2010-01-13 21:59 4 a——- c:\program files\13301236.dat
2010-01-13 21:59 4 a——- c:\program files\13300505.dat
2010-01-13 19:24 –d—– c:\docume~1\k\applic~1\LimeWire
2010-01-13 19:23 411,368 a——- c:\windows\system32\deploytk.dll
2010-01-13 19:23 73,728 a——- c:\windows\system32\javacpl.cpl
2010-01-13 19:21 –d—– c:\program files\LimeWire
2010-01-13 18:14 4 a——- c:\program files\60104165.dat
2010-01-13 10:47 –d—– c:\program files\AVI Media Player
2010-01-12 23:31 0 a——- c:\program files\19116958.dat
2010-01-12 23:25 –d-h— c:\windows\msdownld.tmp
2010-01-12 14:29 471,552 ——– c:\windows\system32\dllcache\aclayers.dll
2010-01-12 08:28 4 a——- c:\program files\21875695.dat
2010-01-11 11:09 4 a——- c:\program files\5236139.dat
2010-01-11 10:44 40,448 a——- C:\ujsjy.exe
2010-01-07 21:22 –d—– c:\docume~1\alluse~1\applic~1\Norton
2010-01-07 21:22 –d—– c:\docume~1\alluse~1\applic~1\NortonInstaller
2010-01-07 21:21 –d—– c:\docume~1\k\applic~1\WeatherBug
2010-01-07 21:21 –d—– c:\program files\ffdshow
2010-01-05 09:51 –d—– c:\program files\VideoLAN
2010-01-05 09:44 –d—– c:\docume~1\alluse~1\applic~1\EmailNotifier
2010-01-05 09:44 –d—– c:\docume~1\k\applic~1\myfreezetoolbar
2010-01-05 09:44 –d—– c:\program files\Free Offers from Freeze.com
2010-01-04 15:59 –d—– c:\program files\Linksys
2010-01-04 15:37 –d—– c:\program files\Pure Networks
2010-01-04 15:36 –d—– c:\program files\WebEx
2010-01-04 15:35 23,984 a——- c:\windows\system32\drivers\pnarp.sys
2010-01-04 15:35 25,264 a——- c:\windows\system32\drivers\purendis.sys
2010-01-04 15:35 –d—– c:\program files\common files\Pure Networks Shared
2010-01-04 15:34 –d—– c:\docume~1\alluse~1\applic~1\Pure Networks
2010-01-04 02:26 249 a——- c:\windows\cdplayer.ini
2010-01-04 01:08 –d—– c:\documents and settings\k\C
2010-01-03 21:48 107,368 a——- c:\windows\system32\GEARAspi.dll
2010-01-03 21:48 26,600 a——- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-01-03 21:47 –d—– c:\program files\iPod
2010-01-03 21:47 –d—– c:\program files\iTunes
2010-01-03 21:47 –d—– c:\docume~1\alluse~1\applic~1\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2010-01-03 21:47 –d—– c:\program files\Bonjour
2010-01-03 21:42 2,065,696 a——- c:\windows\system32\usbaaplrc.dll
2010-01-03 21:22 –d—– c:\docume~1\alluse~1\applic~1\Azureus
2010-01-03 21:22 –d—– c:\docume~1\k\applic~1\Hotbar_Icons
2010-01-03 21:22 –d—– c:\docume~1\k\applic~1\Azureus
2010-01-03 21:20 –d—– c:\program files\common files\i4j_jres
2010-01-03 21:20 –d—– c:\program files\AskBarDis
2010-01-03 21:20 –d—– c:\program files\Vuze
2010-01-03 17:49 –d—– C:\$AVG
2010-01-03 17:49 12,464 a——- c:\windows\system32\avgrsstx.dll
2010-01-03 17:49 360,584 a——- c:\windows\system32\drivers\avgtdix.sys
2010-01-03 17:49 333,192 a——- c:\windows\system32\drivers\avgldx86.sys
2010-01-03 17:49 –d—– c:\windows\system32\drivers\Avg
2010-01-03 17:49 –d—– c:\docume~1\alluse~1\applic~1\AVG Security Toolbar
2010-01-03 17:48 –d—– c:\program files\AVG
2010-01-03 17:48 –d—– c:\docume~1\alluse~1\applic~1\avg9
2010-01-03 16:01 –d—– c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2010-01-03 16:00 –d—– c:\program files\SUPERAntiSpyware
2010-01-03 16:00 –d—– c:\docume~1\k\applic~1\SUPERAntiSpyware.com
2010-01-03 16:00 –d—– c:\program files\common files\Wise Installation Wizard
2010-01-03 15:46 –d—– c:\program files\Spybot - Search & Destroy
2010-01-03 15:46 –d—– c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2010-01-03 15:43 –d—– c:\docume~1\k\applic~1\Malwarebytes
2010-01-03 15:43 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-03 15:43 19,160 a——- c:\windows\system32\drivers\mbam.sys
2010-01-03 15:43 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-01-03 15:43 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-12-31 06:20 –d—– c:\windows\system32\appmgmt
==================== Find3M ====================
2010-01-16 01:00 5,776 a——- c:\windows\system32\drivers\atmarpc.sys
2010-01-15 07:00 96,512 a——- c:\windows\system32\dllcache\atapi.sys
2010-01-15 07:00 96,512 ——– c:\windows\system32\drivers\atapi.sys
2009-11-21 10:51 471,552 a——- c:\windows\apppatch\aclayers.dll
2009-10-28 09:40 173,056 ——– c:\windows\system32\dllcache\ie4uinit.exe
2009-10-21 00:38 75,776 a——- c:\windows\system32\strmfilt.dll
2009-10-21 00:38 25,088 a——- c:\windows\system32\httpapi.dll
2009-10-21 00:38 75,776 ——– c:\windows\system32\dllcache\strmfilt.dll
2009-10-21 00:38 25,088 ——– c:\windows\system32\dllcache\httpapi.dll
============= FINISH: 20:22:51.76 ===============
Malwarebytes' Anti-Malware 1.44
Database version: 3595
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
1/18/2010 6:11:20 PM
mbam-log-2010-01-18 (18-11-20).txt
Scan type: Quick Scan
Objects scanned: 116747
Time elapsed: 9 minute(s), 20 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a078f691-9c07-4af2-bf43-35e79eecf8b7} (Adware.Softomate) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system32\spool\prtprocs\w32x86\00002a46.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\spool\prtprocs\w32x86\00006d85.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\k\rundll32.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-18 20:15:24
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\k\LOCALS~1\Temp\kwaoifob.sys
—- System - GMER 1.0.15 —-
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xEE5000B0]
—- Devices - GMER 1.0.15 —-
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 mouclass.sys (Mouse Class Driver/Microsoft Corporation)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
Device \FileSystem\Fastfat \Fat ECBFBD20
Device \FileSystem\Fastfat \Fat ECC028C1
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Cdfs \Cdfs tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
—- Files - GMER 1.0.15 —-
File C:\WINDOWS\system32\mobsync.dll (size mismatch) 32768/207360 bytes executable
—- EOF - GMER 1.0.15 —-
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-06-26.01)
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 12/24/2008 6:13:34 PM
System Uptime: 1/18/2010 6:12:44 PM (2 hours ago)
Motherboard: IBM | | 2888WQ4
Processor: Intel® Pentium® M processor 1.70GHz | None | 1698/400mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 33 GiB total, 7.796 GiB free.
D: is CDROM ()
==== Disabled Device Manager Items =============
==== System Restore Points ===================
RP2: 1/12/2010 1:09:36 PM - System Checkpoint
RP3: 1/12/2010 6:10:55 PM - Software Distribution Service 3.0
RP4: 1/12/2010 11:20:36 PM - Installed MSN Toolbar
RP5: 1/13/2010 1:00:06 AM - Software Distribution Service 3.0
RP6: 1/14/2010 5:35:16 AM - System Checkpoint
RP7: 1/15/2010 5:04:18 AM - Installed Java™ 6 Update 17
RP8: 1/15/2010 2:15:28 PM - Removed MSN Toolbar
RP9: 1/16/2010 6:12:47 PM - System Checkpoint
RP10: 1/16/2010 7:06:26 PM - OTS Restore Point
RP11: 1/16/2010 7:09:09 PM - OTS Restore Point
RP12: 1/17/2010 7:23:06 PM - System Checkpoint
RP13: 1/18/2010 5:43:53 PM - Avg8 Update
==== Installed Programs ======================
Access IBM
Access IBM Message Center
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 7.0
Apple Application Support
Apple Mobile Device Support
Apple Software Update
AVG Free 9.0
AVI Media Player 1.0
Bonjour
CCScore
Cisco Network Magic
ERUNT 1.1j
ESSCDBK
ESScore
ESSgui
ESSini
ESSPCD
ESSSONIC
ESSTOOLS
essvatgt
Google Toolbar for Internet Explorer
HijackThis 2.0.2
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
IBM 32-bit Runtime Environment for Java 2, v1.4.1
IBM Active Protection System
IBM DLA
IBM Integrated 56K Modem
IBM RecordNow!
IBM Rescue and Recovery with Rapid Restore
IBM Themes
IBM ThinkPad Battery MaxiMiser and Power Management Features
IBM ThinkPad Configuration
IBM ThinkPad EasyEject Utility
IBM ThinkPad Keyboard Customizer Utility
IBM ThinkPad Power Management Driver
IBM ThinkPad Presentation Director
IBM ThinkPad UltraNav Driver
IBM ThinkPad UltraNav Wizard
IBM ThinkVantage Technologies Welcome Message
IBM TrackPoint Accessibility Features
IBM Update Connector
Intel® Extreme Graphics 2 Driver
Intel® PRO Network Adapters and Drivers
Intel® PROSet/Wireless WiFi Software
Intel® Sebring API
iTunes
Java™ 6 Update 16
kgcbaby
kgcbase
kgchday
kgchlwn
kgcinvt
kgckids
kgcmove
kgcvday
Kodak EasyShare software
KSU
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Professional Edition 2003
Microsoft Silverlight
Microsoft VC9 runtime libraries
Microsoft Visual C++ 2005 Redistributable
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
netbrdg
Network Magic
Notifier
OfotoXMI
PCDADDIN
PCDHELP
Pure Networks Platform
QuickTime
RealPlayer
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960714)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
SFR
SHASTA
SKIN0001
SKINXSDK
Sonic Update Manager
Spybot - Search & Destroy
staticcr
SUPERAntiSpyware Free Edition
ThinkPad FullScreen Magnifier
ThinkPad Software Installer
tooltips
Update for Windows Internet Explorer 8 (KB971930)
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Viewpoint Media Player
VLC media player 0.9.2
VPRINTOL
Vuze
Vuze Toolbar
Wallpapers
WebEx Support Manager for Internet Explorer
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Internet Explorer 8
Windows XP Service Pack 3
WIRELESS
Yahoo! Software Update
Yahoo! Toolbar
==== Event Viewer Messages From Past Week ========
1/16/2010 7:59:11 AM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000043' while processing the file 'wmpscfgs.exe' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.
1/16/2010 5:26:40 PM, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\ctfmon.exe. This file was restored to the original version to maintain system stability. The file version of the system file is 5.1.2600.5512.
1/16/2010 5:04:30 PM, error: Service Control Manager [7034] - The IBM KCU Service service terminated unexpectedly. It has done this 1 time(s).
1/16/2010 2:10:40 PM, error: Service Control Manager [7000] - The Intel® PROSet/Wireless Event Log service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
1/16/2010 2:10:39 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the Spooler service.
1/16/2010 2:10:39 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Intel® PROSet/Wireless Event Log service to connect.
1/16/2010 2:10:39 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Apple Mobile Device service to connect.
1/16/2010 2:10:39 PM, error: Service Control Manager [7000] - The Apple Mobile Device service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
1/16/2010 12:11:34 AM, error: Service Control Manager [7000] - The SASDIFSV service failed to start due to the following error: Cannot create a file when that file already exists.
1/16/2010 12:02:36 AM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000243' while processing the file 'is2010.exe' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.
1/15/2010 6:50:53 PM, error: Service Control Manager [7034] - The Terminal Services service terminated unexpectedly. It has done this 1 time(s).
1/15/2010 6:50:53 PM, error: Service Control Manager [7031] - The DCOM Server Process Launcher service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Reboot the machine.
1/15/2010 4:54:48 AM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000243' while processing the file 'wmpscfgs.exe' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.
1/15/2010 10:04:40 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the avg9wd service.
1/14/2010 9:01:51 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Google Software Updater service to connect.
1/14/2010 9:01:46 PM, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service gusvc with arguments "" in order to run the server: {89DAE4CD-9F17-4980-902A-99BA84A8F5C8}
1/14/2010 3:18:01 PM, error: Ftdisk [49] - Configuring the Page file for crash dump failed. Make sure there is a page file on the boot partition and that is large enough to contain all physical memory.
1/14/2010 3:18:01 PM, error: Ftdisk [45] - The system could not sucessfully load the crash dump driver.
1/14/2010 2:02:15 AM, information: Windows File Protection [64002] - File replacement was attempted on the protected system file aec.sys. This file was restored to the original version to maintain system stability. The file version of the system file is 5.1.2601.3142.
1/14/2010 2:02:15 AM, information: Windows File Protection [64002] - File replacement was attempted on the protected system file ac97intc.sys. This file was restored to the original version to maintain system stability. The file version of the system file is 5.10.0.3523.
1/14/2010 2:00:02 AM, error: Service Control Manager [7000] - The Microsoft Kernel Acoustic Echo Canceller service failed to start due to the following error: Access is denied.
1/14/2010 1:59:58 AM, error: Service Control Manager [7000] - The Intel® 82801 Audio Driver Install Service (WDM) service failed to start due to the following error: Access is denied.
1/13/2010 1:33:56 AM, error: Service Control Manager [7023] - The Network Security service terminated with the following error: The system cannot find the file specified.
1/13/2010 1:33:56 AM, error: Service Control Manager [7003] - The Spectrum24 Event Monitor service depends on the following nonexistent service: s24trans
1/12/2010 12:53:34 AM, error: Dhcp [1002] - The IP address lease 192.168.1.44 for the Network Card with network address 0012F0E904B4 has been denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message).
1/11/2010 3:40:49 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.
1/11/2010 12:44:11 PM, error: Service Control Manager [7034] - The fastnetsrv Service service terminated unexpectedly. It has done this 1 time(s).
==== End Of File ===========================
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 20:22:28.41 on Mon 01/18/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.590 [GMT -5:00]
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Internet Antivirus *On-access scanning enabled* (Outdated) {18B0AD40-E077-4625-850C-DDD3EB0FF925}
============== Running Processes ===============
C:\WINDOWS\System32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
svchost.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AskBarDis\bar\bin\AskService.exe
C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\system32\TpKmpSVC.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\TpShocks.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Documents and Settings\k\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://my.yahoo.com/linksys
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride =
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: {C26CD490-5F01-41E3-B150-EB29F19DA056} - No File
BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - No File
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ibmmessages] c:\program files\ibm\messages by ibm\ibmmessages .exe
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [S3TRAY2] S3Tray2.exe
mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [TPKMAPHELPER] c:\program files\thinkpad\utilities\TpKmapAp.exe -helper
mRun: [TpShocks] TpShocks.exe
mRun: [TPHOTKEY] c:\progra~1\thinkpad\pkgmgr\hotkey\TPHKMGR.exe
mRun: [TP4EX] tp4ex.exe
mRun: [EZEJMNAP] c:\progra~1\thinkpad\utilit~1\EzEjMnAp.Exe
mRun: [UC_Start] c:\program files\ibm\updater\\ucstartup.exe
mRun: [UC_SMB]
mRun: [UpdateManager] "c:\program files\common files\sonic\update manager\sgtray.exe" /r
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [ibmmessages] c:\program files\ibm\messages by ibm\\ibmmessages.exe
mRun: [IBMPRC] c:\ibmtools\utils\ibmprc.exe
mRun: [BMMGAG] RunDll32 c:\progra~1\thinkpad\utilit~1\pwrmonit.dll,StartPwrMonitor
mRun: [BMMLREF] c:\program files\thinkpad\utilities\BMMLREF.EXE
mRun: [BMMMONWND] rundll32.exe c:\progra~1\thinkpad\utilit~1\BatInfEx.dll,BMMAutonomicMonitor
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask .exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [nmctxth] "c:\program files\common files\pure networks shared\platform\nmctxth.exe"
mRun: [nmapp] "c:\program files\pure networks\network magic\nmapp.exe" -autorun -nosplash
StartupFolder: c:\docume~1\k\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\kodake~1.lnk - c:\program files\kodak\kodak easyshare software\bin\EasyShare.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\kodaks~1.lnk - c:\program files\kodak\kodak software updater\7288971\program\Kodak Software Updater.exe
dPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
IE: E&xport to Microsoft Excel
IE: Google Sidewiki…
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/1.4.1/jinstall-141-win.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Handler: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - c:\program files\common files\pure networks shared\platform\puresp4.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: igfxcui - igfxsrvc.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
============= SERVICES / DRIVERS ===============
R0 Shockprf;Shockprf;c:\windows\system32\drivers\shockprf.sys [2008-8-20 59520]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-1-3 333192]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-1-3 28424]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-1-3 360584]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-10-12 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-10-12 74480]
R1 ShockMgr;ShockMgr;c:\windows\system32\drivers\ShockMgr.sys [2008-8-20 4608]
R1 TPPWR;TPPWR;c:\windows\system32\drivers\TPPWR.SYS [2008-8-20 16384]
R2 ASKService;ASKService;c:\program files\askbardis\bar\bin\AskService.exe [2010-1-3 464264]
R2 ASKUpgrade;ASKUpgrade;c:\program files\askbardis\bar\bin\ASKUpgrade.exe [2010-1-3 234888]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-1-3 285392]
R2 ibmfilter;ibmfilter;c:\windows\system32\drivers\ibmfilter.sys [2004-9-23 64256]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-3-30 24652]
R2 YahooAUService;Yahoo! Updater;c:\program files\yahoo!\softwareupdate\YahooAUService.exe [2008-11-9 602392]
R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-10-12 7408]
=============== Created Last 30 ================
2010-01-18 20:19 –d—– c:\docume~1\k\applic~1\AVG9
2010-01-18 17:47 4 a——- c:\program files\84409163.dat
2010-01-17 18:46 –d—– c:\program files\Trend Micro
2010-01-16 18:43 a-dshr– C:\autorun.inf
2010-01-16 17:04 4 a——- c:\program files\6466157.dat
2010-01-16 17:04 0 a——- c:\program files\6465346.dat
2010-01-16 17:02 a-dshr– C:\cmdcons
2010-01-16 17:00 261,632 a——- c:\windows\PEV.exe
2010-01-16 17:00 77,312 a——- c:\windows\MBR.exe
2010-01-16 13:58 4 a——- c:\program files\10261194.dat
2010-01-16 11:06 4 a——- c:\program files\11303333.dat
2010-01-16 07:56 4 a——- c:\program files\28497537.dat
2010-01-15 20:47 –d—– c:\docume~1\k\applic~1\AVG8
2010-01-15 18:52 4 a——- c:\program files\3489958.dat
2010-01-15 18:52 4 a——- c:\program files\3489687.dat
2010-01-15 18:52 0 a——- c:\program files\3489527.dat
2010-01-15 10:05 4 a——- c:\program files\18712176.dat
2010-01-15 10:05 4 a——- c:\program files\18711956.dat
2010-01-15 10:05 4 a——- c:\program files\18711585.dat
2010-01-15 10:05 4 a——- c:\program files\18711205.dat
2010-01-15 04:52 4 a——- c:\program files\5971276.dat
2010-01-15 04:52 4 a——- c:\program files\5970344.dat
2010-01-15 04:52 4 a——- c:\program files\5967951.dat
2010-01-15 01:42 4 a——- c:\program files\650445.dat
2010-01-15 01:42 4 a——- c:\program files\649443.dat
2010-01-15 01:29 4 a——- c:\program files\9405304.dat
2010-01-15 01:29 4 a——- c:\program files\9404913.dat
2010-01-14 18:17 4 a——- c:\program files\10799649.dat
2010-01-14 18:16 4 a——- c:\program files\10751399.dat
2010-01-14 12:27 221,184 a——- c:\windows\system32\wmpns.dll
2010-01-14 12:06 4 a——- c:\program files\64140889.dat
2010-01-14 12:06 4 a——- c:\program files\64139768.dat
2010-01-14 12:06 4 a——- c:\program files\64138966.dat
2010-01-14 02:02 142,592 a——- c:\windows\system32\dllcache\aec.sys
2010-01-14 02:02 142,592 ——– c:\windows\system32\drivers\aec.sys
2010-01-13 21:59 4 a——- c:\program files\13301236.dat
2010-01-13 21:59 4 a——- c:\program files\13300505.dat
2010-01-13 19:24 –d—– c:\docume~1\k\applic~1\LimeWire
2010-01-13 19:23 411,368 a——- c:\windows\system32\deploytk.dll
2010-01-13 19:23 73,728 a——- c:\windows\system32\javacpl.cpl
2010-01-13 19:21 –d—– c:\program files\LimeWire
2010-01-13 18:14 4 a——- c:\program files\60104165.dat
2010-01-13 10:47 –d—– c:\program files\AVI Media Player
2010-01-12 23:31 0 a——- c:\program files\19116958.dat
2010-01-12 23:25 –d-h— c:\windows\msdownld.tmp
2010-01-12 14:29 471,552 ——– c:\windows\system32\dllcache\aclayers.dll
2010-01-12 08:28 4 a——- c:\program files\21875695.dat
2010-01-11 11:09 4 a——- c:\program files\5236139.dat
2010-01-11 10:44 40,448 a——- C:\ujsjy.exe
2010-01-07 21:22 –d—– c:\docume~1\alluse~1\applic~1\Norton
2010-01-07 21:22 –d—– c:\docume~1\alluse~1\applic~1\NortonInstaller
2010-01-07 21:21 –d—– c:\docume~1\k\applic~1\WeatherBug
2010-01-07 21:21 –d—– c:\program files\ffdshow
2010-01-05 09:51 –d—– c:\program files\VideoLAN
2010-01-05 09:44 –d—– c:\docume~1\alluse~1\applic~1\EmailNotifier
2010-01-05 09:44 –d—– c:\docume~1\k\applic~1\myfreezetoolbar
2010-01-05 09:44 –d—– c:\program files\Free Offers from Freeze.com
2010-01-04 15:59 –d—– c:\program files\Linksys
2010-01-04 15:37 –d—– c:\program files\Pure Networks
2010-01-04 15:36 –d—– c:\program files\WebEx
2010-01-04 15:35 23,984 a——- c:\windows\system32\drivers\pnarp.sys
2010-01-04 15:35 25,264 a——- c:\windows\system32\drivers\purendis.sys
2010-01-04 15:35 –d—– c:\program files\common files\Pure Networks Shared
2010-01-04 15:34 –d—– c:\docume~1\alluse~1\applic~1\Pure Networks
2010-01-04 02:26 249 a——- c:\windows\cdplayer.ini
2010-01-04 01:08 –d—– c:\documents and settings\k\C
2010-01-03 21:48 107,368 a——- c:\windows\system32\GEARAspi.dll
2010-01-03 21:48 26,600 a——- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-01-03 21:47 –d—– c:\program files\iPod
2010-01-03 21:47 –d—– c:\program files\iTunes
2010-01-03 21:47 –d—– c:\docume~1\alluse~1\applic~1\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2010-01-03 21:47 –d—– c:\program files\Bonjour
2010-01-03 21:42 2,065,696 a——- c:\windows\system32\usbaaplrc.dll
2010-01-03 21:22 –d—– c:\docume~1\alluse~1\applic~1\Azureus
2010-01-03 21:22 –d—– c:\docume~1\k\applic~1\Hotbar_Icons
2010-01-03 21:22 –d—– c:\docume~1\k\applic~1\Azureus
2010-01-03 21:20 –d—– c:\program files\common files\i4j_jres
2010-01-03 21:20 –d—– c:\program files\AskBarDis
2010-01-03 21:20 –d—– c:\program files\Vuze
2010-01-03 17:49 –d—– C:\$AVG
2010-01-03 17:49 12,464 a——- c:\windows\system32\avgrsstx.dll
2010-01-03 17:49 360,584 a——- c:\windows\system32\drivers\avgtdix.sys
2010-01-03 17:49 333,192 a——- c:\windows\system32\drivers\avgldx86.sys
2010-01-03 17:49 –d—– c:\windows\system32\drivers\Avg
2010-01-03 17:49 –d—– c:\docume~1\alluse~1\applic~1\AVG Security Toolbar
2010-01-03 17:48 –d—– c:\program files\AVG
2010-01-03 17:48 –d—– c:\docume~1\alluse~1\applic~1\avg9
2010-01-03 16:01 –d—– c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2010-01-03 16:00 –d—– c:\program files\SUPERAntiSpyware
2010-01-03 16:00 –d—– c:\docume~1\k\applic~1\SUPERAntiSpyware.com
2010-01-03 16:00 –d—– c:\program files\common files\Wise Installation Wizard
2010-01-03 15:46 –d—– c:\program files\Spybot - Search & Destroy
2010-01-03 15:46 –d—– c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2010-01-03 15:43 –d—– c:\docume~1\k\applic~1\Malwarebytes
2010-01-03 15:43 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-03 15:43 19,160 a——- c:\windows\system32\drivers\mbam.sys
2010-01-03 15:43 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-01-03 15:43 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-12-31 06:20 –d—– c:\windows\system32\appmgmt
==================== Find3M ====================
2010-01-16 01:00 5,776 a——- c:\windows\system32\drivers\atmarpc.sys
2010-01-15 07:00 96,512 a——- c:\windows\system32\dllcache\atapi.sys
2010-01-15 07:00 96,512 ——– c:\windows\system32\drivers\atapi.sys
2009-11-21 10:51 471,552 a——- c:\windows\apppatch\aclayers.dll
2009-10-28 09:40 173,056 ——– c:\windows\system32\dllcache\ie4uinit.exe
2009-10-21 00:38 75,776 a——- c:\windows\system32\strmfilt.dll
2009-10-21 00:38 25,088 a——- c:\windows\system32\httpapi.dll
2009-10-21 00:38 75,776 ——– c:\windows\system32\dllcache\strmfilt.dll
2009-10-21 00:38 25,088 ——– c:\windows\system32\dllcache\httpapi.dll
============= FINISH: 20:22:51.76 ===============