This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] antivirus 2009

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

I have been infected with something I am unable to get off of my system. Spybot shows a smitfraud infection and appears to clean it up but after a restart it seems to be back. When I get online I get the antivirus 2009 warning and it starts scanning my system. I found some things and removed them but I an still infected. here is my hijack this log file. Thanks for any help.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:49:54 AM, on 10/13/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\ORL\VNC\WinVNC.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\ICO.EXE
C:\WINDOWS\System32\FSRremoS.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\WINDOWS\System32\umonit.exe
C:\program files\dell\traytool.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\WINDOWS\System32\LVComS.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.goact.net/
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [UC_Start] C:\IBMTools\Updater\ucstartup.exe
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\ORL\VNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [UMonit] C:\WINDOWS\System32\umonit.exe
O4 - HKLM\..\Run: [ToolExe] c:\program files\dell\traytool.exe
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Spark] C:\Program Files\Spark\Spark.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - Startup: Launch Microsoft Office Outlook.lnk = C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: APC UPS Status.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O11 - Options group: [JAVA_IBM] Java (IBM)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl.sun.com/webapps/download/AutoDL?BundleId=23100
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://finjan.webex.com/client/v_mywebex-t…bex/ieatgpc.cab
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetup Control) - https://216.16.42.51/dana-cached/setup/JuniperSetup.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{463477A3-3C65-4DE6-83BC-26DDA4AF0B31}: NameServer = 192.168.3.5
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Juniper Network Connect Service (dsNcService) - Juniper Networks - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: VNC Server (winvnc) - AT&T Research Labs Cambridge - C:\Program Files\ORL\VNC\WinVNC.exe

–
End of file - 7693 bytes
Hello

Please run the MGA Diagnostic Tool and post back the report it shall produce:
  • Download MGADiag to your desktop.
  • Double-click on MGADiag.exe to launch the program
  • Click "Continue"
  • Ensure that the "Windows" tab is selected (it should be by default).
  • Click the "Copy" button to copy the MGA Diagnostic Report to the Windows clipboard.
  • Paste the MGA Diagnostic Report back here in your next reply.
Here is the result of the MGADiag tool…. Diagnostic Report (1.7.0095.0): —————————————– WGA Data–> Validation Status: Validation Control not Installed Validation Code: 0 Online Validation Code: N/A Cached Validation Code: N/A Windows Product Key: *****-*****-RY7BM-HM3KT-BKVRW Windows Product Key Hash: 6994t4LQCbvkXhtNbqQCL4+auQs= Windows Product ID: 55274-OEM-2211906-00107 Windows Product ID Type: 2 Windows License Type: OEM SLP Windows OS version: 5.1.2600.2.00010100.1.0.pro CSVLK Server: N/A CSVLK PID: N/A ID: {EB94BB5E-5F83-4D2B-8E83-73D33C3067FA}(1) Is Admin: Yes TestCab: 0x0 WGA Version: N/A, hr = 0x80070002 Signed By: N/A, hr = 0x80070002 Product Name: N/A Architecture: N/A Build lab: N/A TTS Error: N/A Validation Diagnostic: 025D1FF3-171-1 Resolution Status: N/A WgaER Data–> ThreatID(s): N/A Version: N/A WGA Notifications Data–> Cached Result: N/A, hr = 0x80070002 File Exists: No Version: N/A, hr = 0x80070002 WgaTray.exe Signed By: N/A, hr = 0x80070002 WgaLogon.dll Signed By: N/A, hr = 0x80070002 OGA Notifications Data–> Cached Result: N/A, hr = 0x80070002 Version: N/A, hr = 0x80070002 WGATray.exe Signed By: N/A, hr = 0x80070002 OGAAddin.dll Signed By: N/A, hr = 0x80070002 OGA Data–> Office Status: 100 Genuine Microsoft Office Professional Edition 2003 - 100 Genuine OGA Version: N/A, 0x80070002 Signed By: N/A, hr = 0x80070002 Office Diagnostics: 025D1FF3-171-1 Browser Data–> Proxy settings: N/A User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Win32) Default Browser: C:\Program Files\Internet Explorer\iexplore.exe Download signed ActiveX controls: Prompt Download unsigned ActiveX controls: Disabled Run ActiveX controls and plug-ins: Allowed Initialize and script ActiveX controls not marked as safe: Disabled Allow scripting of Internet Explorer Webbrowser control: Disabled Active scripting: Allowed Script ActiveX controls marked as safe for scripting: Allowed File Scan Data–> Other data–> Office Details: {EB94BB5E-5F83-4D2B-8E83-73D33C3067FA}1.7.0095.05.1.2600.2.00010100.1.0.prox32*****-*****-*****-*****-BKVRW55274-OEM-2211906-001072S-1-5-21-3363304447-1588219682-831737545IBM843397UIBM2AKT39AUS20040520******.******+***IBM CORPORATION,IBM CORPORATION253936570184607204090409Central Standard Time(GMT-06:00)12IBM Corporation 100
We cant help you here until you validate your windows. An unvalidated Windows is an indication of a pirated OS, which is against the rules here
I'm not sure why it showed not Genuine but it is. Diagnostic Report (1.7.0095.0): —————————————– WGA Data–> Validation Status: Genuine Validation Code: 0 Online Validation Code: N/A Cached Validation Code: N/A Windows Product Key: *****-*****-RY7BM-HM3KT-BKVRW Windows Product Key Hash: 6994t4LQCbvkXhtNbqQCL4+auQs= Windows Product ID: 55274-OEM-2211906-00107 Windows Product ID Type: 2 Windows License Type: OEM SLP Windows OS version: 5.1.2600.2.00010100.1.0.pro CSVLK Server: N/A CSVLK PID: N/A ID: {EB94BB5E-5F83-4D2B-8E83-73D33C3067FA}(3) Is Admin: Yes TestCab: 0x0 WGA Version: Registered, 1.7.69.2 Signed By: Microsoft Product Name: N/A Architecture: N/A Build lab: N/A TTS Error: N/A Validation Diagnostic: 025D1FF3-171-1 Resolution Status: N/A WgaER Data–> ThreatID(s): N/A Version: N/A WGA Notifications Data–> Cached Result: N/A, hr = 0x80070002 File Exists: No Version: N/A, hr = 0x80070002 WgaTray.exe Signed By: N/A, hr = 0x80070002 WgaLogon.dll Signed By: N/A, hr = 0x80070002 OGA Notifications Data–> Cached Result: N/A, hr = 0x80070002 Version: N/A, hr = 0x80070002 WGATray.exe Signed By: N/A, hr = 0x80070002 OGAAddin.dll Signed By: N/A, hr = 0x80070002 OGA Data–> Office Status: 100 Genuine Microsoft Office Professional Edition 2003 - 100 Genuine OGA Version: N/A, 0x80070002 Signed By: N/A, hr = 0x80070002 Office Diagnostics: 025D1FF3-171-1 Browser Data–> Proxy settings: N/A User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Win32) Default Browser: C:\Program Files\Internet Explorer\iexplore.exe Download signed ActiveX controls: Prompt Download unsigned ActiveX controls: Disabled Run ActiveX controls and plug-ins: Allowed Initialize and script ActiveX controls not marked as safe: Disabled Allow scripting of Internet Explorer Webbrowser control: Disabled Active scripting: Allowed Script ActiveX controls marked as safe for scripting: Allowed File Scan Data–> Other data–> Office Details: {EB94BB5E-5F83-4D2B-8E83-73D33C3067FA}1.7.0095.05.1.2600.2.00010100.1.0.prox32*****-*****-*****-*****-BKVRW55274-OEM-2211906-001072S-1-5-21-3363304447-1588219682-831737545IBM843397UIBM2AKT39AUS20040520******.******+***IBM CORPORATION,IBM CORPORATION253936570184607204090409Central Standard Time(GMT-06:00)12IBM Corporation 100
Hello

* It's extremely important and essential that you update Windows to Service Pack 2, you can do that here.
Make sure you download Service Pack 2 and any other important updates.


Post a new HJT log once you have done that
Here is a log file from Hijack this renamed… The dll associated with the BHO will not go away. I can't delete them even in safe mode.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:57:15 AM, on 10/13/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\ORL\VNC\WinVNC.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\ICO.EXE
C:\WINDOWS\System32\FSRremoS.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\WINDOWS\System32\umonit.exe
C:\program files\dell\traytool.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\System32\LVComS.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Trend Micro\HijackThis\check.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.goact.net/
O2 - BHO: pl - {3DC8CA1D-D31A-474b-979A-A3823FA34ED8} - C:\WINDOWS\System32\dccplus.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: {437fb881-310b-4c0a-cff4-d6ef07fc6438} - {8346cf70-fe6d-4ffc-a0c4-b013188bf734} - C:\WINDOWS\System32\jdqadx.dll
O2 - BHO: (no name) - {9E91EF7B-6846-45C3-A8AB-67CF7C900783} - C:\WINDOWS\System32\ssqPjjgg.dll
O2 - BHO: (no name) - {C8D2BC71-CEEC-4892-B1E2-739BCAEFA3D9} - C:\WINDOWS\System32\jkkLCvts.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [UC_Start] C:\IBMTools\Updater\ucstartup.exe
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\ORL\VNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [UMonit] C:\WINDOWS\System32\umonit.exe
O4 - HKLM\..\Run: [ToolExe] c:\program files\dell\traytool.exe
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [fc6d3a34] rundll32.exe "C:\WINDOWS\System32\lvpyxosu.dll",b
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Spark] C:\Program Files\Spark\Spark.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - Startup: Launch Microsoft Office Outlook.lnk = C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: APC UPS Status.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O11 - Options group: [JAVA_IBM] Java (IBM)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl.sun.com/webapps/download/AutoDL?BundleId=23100
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://finjan.webex.com/client/v_mywebex-t…bex/ieatgpc.cab
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetup Control) - https://216.16.42.51/dana-cached/setup/JuniperSetup.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{463477A3-3C65-4DE6-83BC-26DDA4AF0B31}: NameServer = 192.168.3.5
O20 - AppInit_DLLs: jdqadx.dll
O20 - Winlogon Notify: ssqPjjgg - C:\WINDOWS\SYSTEM32\ssqPjjgg.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Juniper Network Connect Service (dsNcService) - Juniper Networks - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: VNC Server (winvnc) - AT&T Research Labs Cambridge - C:\Program Files\ORL\VNC\WinVNC.exe

–
End of file - 8526 bytes
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:49:06 AM, on 10/13/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\ORL\VNC\WinVNC.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\msiexec.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\system32\ICO.EXE
C:\WINDOWS\system32\FSRremoS.EXE
\?\C:\WINDOWS\system32\WBEM\WMIADAP.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\WINDOWS\System32\umonit.exe
C:\WINDOWS\System32\LVComS.exe
C:\program files\dell\traytool.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Symantec AntiVirus\DoScan.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
\?\C:\WINDOWS\system32\WBEM\WMIADAP.EXE
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Trend Micro\HijackThis\check.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.goact.net/
O2 - BHO: pl - {3DC8CA1D-D31A-474b-979A-A3823FA34ED8} - C:\WINDOWS\System32\dccplus.dll
O2 - BHO: (no name) - {6E38293A-C70A-4F23-A154-AC2E3330106C} - C:\WINDOWS\System32\jkkLCvts.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: {437fb881-310b-4c0a-cff4-d6ef07fc6438} - {8346cf70-fe6d-4ffc-a0c4-b013188bf734} - C:\WINDOWS\System32\jdqadx.dll
O2 - BHO: (no name) - {9E91EF7B-6846-45C3-A8AB-67CF7C900783} - C:\WINDOWS\System32\ssqPjjgg.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [UC_Start] C:\IBMTools\Updater\ucstartup.exe
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\ORL\VNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [UMonit] C:\WINDOWS\System32\umonit.exe
O4 - HKLM\..\Run: [ToolExe] c:\program files\dell\traytool.exe
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [fc6d3a34] rundll32.exe "C:\WINDOWS\System32\lvpyxosu.dll",b
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Spark] C:\Program Files\Spark\Spark.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - Startup: Launch Microsoft Office Outlook.lnk = C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: APC UPS Status.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [JAVA_IBM] Java (IBM)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl.sun.com/webapps/download/AutoDL?BundleId=23100
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://finjan.webex.com/client/v_mywebex-t…bex/ieatgpc.cab
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetup Control) - https://216.16.42.51/dana-cached/setup/JuniperSetup.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{463477A3-3C65-4DE6-83BC-26DDA4AF0B31}: NameServer = 192.168.3.5
O20 - AppInit_DLLs: jdqadx.dll
O20 - Winlogon Notify: ssqPjjgg - C:\WINDOWS\SYSTEM32\ssqPjjgg.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Juniper Network Connect Service (dsNcService) - Juniper Networks - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: VNC Server (winvnc) - AT&T Research Labs Cambridge - C:\Program Files\ORL\VNC\WinVNC.exe

–
End of file - 8739 bytes
Hello


Disable resident protections (Antivirus…); you'll re-enable them after the scan

Download Lop S&D < here

Double-click Lop S&D.exe
Choose the language, then choose Option 1 (Search)
Wait till the end of the scan
Post the log which is created: (%SystemDrive%\lopR.txt)
Hello,

Here is the LopSD log…


——————–\\ Lop S&D; 4.2.4-5 XP/Vista

Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : Intel® Pentium® 4 CPU 2.80GHz )
BIOS : Phoenix FirstBios™ Desktop Pro Version 2.0 for IBM ThinkCentre.
USER : rstone ( Administrator )
BOOT : Normal boot
Antivirus : Symantec AntiVirus Corporate Edition 10.0.0.359 (Not Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total : 34 Go Free : 15 Go
D:\ (CD or DVD)
E:\ (CD or DVD)
H:\ (Disque réseau) - NTFS - Total : 341 Go Free : 113 Go
M:\ (Disque réseau) - NTFS - Total : 47 Go Free : 29 Go
P:\ (Disque réseau) - NTFS - Total : 341 Go Free : 113 Go
V:\ (Disque réseau) - NTFS - Total : 3 Go Free : 2 Go
X:\ (Disque réseau) - NTFS - Total : 47 Go Free : 29 Go
Y:\ (Disque réseau) - NTFS - Total : 11 Go Free : 6 Go

"C:\Lop SD" ( MAJ : 02-10-2008|23:42 )
Option : [1] ( 10/13/2008|13:02 )

——————–\\ Listing folders in APPLIC~1

[02/19/2003|03:35] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Identities
[02/19/2003|03:19] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Microsoft
[06/25/2004|04:20] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Symantec

[02/19/2003|03:35] C:\DOCUME~1\ADMINI~1.ACT\APPLIC~1\ Identities
[02/19/2003|03:19] C:\DOCUME~1\ADMINI~1.ACT\APPLIC~1\ Microsoft
[04/22/2008|08:17] C:\DOCUME~1\ADMINI~1.ACT\APPLIC~1\ Sonic
[06/25/2004|04:20] C:\DOCUME~1\ADMINI~1.ACT\APPLIC~1\ Symantec

[05/03/2007|09:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Adobe
[07/21/2006|08:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Apple Computer
[08/02/2007|08:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Google
[11/29/2006|03:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ IBM
[10/12/2008|10:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Lavasoft
[10/12/2008|10:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Microsoft
[04/20/2007|10:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ nView_Profiles
[10/13/2008|10:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Office Genuine Advantage
[02/19/2003|03:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SBSI
[04/22/2008|09:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Spybot - Search & Destroy
[03/19/2007|10:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Symantec
[05/29/2008|02:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ VMware
[10/13/2008|10:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Windows Genuine Advantage

[02/19/2003|03:35] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Identities
[02/19/2003|03:19] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Microsoft
[06/25/2004|04:20] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Symantec

[01/04/2008|12:54] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Juniper Networks
[02/19/2003|03:19] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Microsoft

[02/19/2003|03:19] C:\DOCUME~1\NETWOR~1\APPLIC~1\ Microsoft

[02/19/2003|03:35] C:\DOCUME~1\Owner\APPLIC~1\ Identities
[08/12/2004|10:27] C:\DOCUME~1\Owner\APPLIC~1\ Microsoft
[06/25/2004|04:20] C:\DOCUME~1\Owner\APPLIC~1\ Symantec

[11/08/2006|11:02] C:\DOCUME~1\rstone\APPLIC~1\ Adobe
[05/03/2007|09:42] C:\DOCUME~1\rstone\APPLIC~1\ AdobeUM
[02/19/2007|09:16] C:\DOCUME~1\rstone\APPLIC~1\ APC
[07/21/2006|08:45] C:\DOCUME~1\rstone\APPLIC~1\ Apple Computer
[03/08/2006|02:51] C:\DOCUME~1\rstone\APPLIC~1\ Google
[04/04/2007|09:18] C:\DOCUME~1\rstone\APPLIC~1\ gtk-2.0
[12/21/2006|11:17] C:\DOCUME~1\rstone\APPLIC~1\ Help
[04/01/2005|12:39] C:\DOCUME~1\rstone\APPLIC~1\ IBM
[04/23/2008|12:04] C:\DOCUME~1\rstone\APPLIC~1\ Identities
[01/04/2008|12:54] C:\DOCUME~1\rstone\APPLIC~1\ Juniper Networks
[10/12/2008|10:09] C:\DOCUME~1\rstone\APPLIC~1\ Lavasoft
[04/08/2005|10:50] C:\DOCUME~1\rstone\APPLIC~1\ Leadertech
[08/31/2005|10:24] C:\DOCUME~1\rstone\APPLIC~1\ Macromedia
[10/13/2008|11:47] C:\DOCUME~1\rstone\APPLIC~1\ Microsoft
[11/27/2007|04:13] C:\DOCUME~1\rstone\APPLIC~1\ paradisepoker
[04/08/2005|10:50] C:\DOCUME~1\rstone\APPLIC~1\ Sonic
[07/24/2008|02:15] C:\DOCUME~1\rstone\APPLIC~1\ Sun
[06/25/2004|04:20] C:\DOCUME~1\rstone\APPLIC~1\ Symantec
[09/22/2008|10:10] C:\DOCUME~1\rstone\APPLIC~1\ U3
[02/28/2008|09:03] C:\DOCUME~1\rstone\APPLIC~1\ Uniblue
[10/10/2008|08:23] C:\DOCUME~1\rstone\APPLIC~1\ VMware
[09/04/2008|01:57] C:\DOCUME~1\rstone\APPLIC~1\ WebEx
[09/09/2008|03:52] C:\DOCUME~1\rstone\APPLIC~1\ Wireshark

[02/19/2003|03:35] C:\DOCUME~1\shop\APPLIC~1\ Identities
[04/11/2006|03:36] C:\DOCUME~1\shop\APPLIC~1\ Macromedia
[04/11/2006|03:35] C:\DOCUME~1\shop\APPLIC~1\ Microsoft
[06/25/2004|04:20] C:\DOCUME~1\shop\APPLIC~1\ Symantec

——————–\\ Scheduled Tasks located in C:\WINDOWS\Tasks

[10/13/2008 01:00 PM][–a——] C:\WINDOWS\tasks\meuvguie.job
[10/13/2008 01:00 PM][–a——] C:\WINDOWS\tasks\mniyzrqc.job
[10/13/2008 01:00 PM][–a——] C:\WINDOWS\tasks\gulchdcm.job
[10/08/2008 12:00 PM][–a——] C:\WINDOWS\tasks\Schedule Task Weekly.job
[10/13/2008 12:30 AM][–a——] C:\WINDOWS\tasks\Restart.job
[10/13/2008 11:45 AM][–a——] C:\WINDOWS\tasks\Email Projector Schedule.job
[10/13/2008 11:41 AM][–ah—–] C:\WINDOWS\tasks\SA.DAT
[08/18/2001 04:00 AM][-r-h—–] C:\WINDOWS\tasks\desktop.ini

——————–\\ Listing Folders in C:\Program Files

[09/29/2006|08:37] C:\Program Files\ 7188E
[04/12/2007|02:49] C:\Program Files\ activePDF
[07/18/2008|03:53] C:\Program Files\ Admiresoft
[04/21/2006|09:05] C:\Program Files\ Adobe
[06/25/2004|04:12] C:\Program Files\ Analog Devices
[01/16/2008|10:39] C:\Program Files\ APC
[04/18/2005|03:26] C:\Program Files\ BUFFALO
[07/24/2008|02:13] C:\Program Files\ Common Files
[02/19/2003|03:24] C:\Program Files\ ComPlus Applications
[10/05/2006|09:47] C:\Program Files\ Dell
[09/27/2006|11:07] C:\Program Files\ EPSON
[07/22/2008|08:16] C:\Program Files\ Error Expert
[08/24/2004|08:06] C:\Program Files\ Fourth Shift
[07/25/2008|10:57] C:\Program Files\ GanttProject
[08/03/2007|12:31] C:\Program Files\ Google
[07/18/2008|03:59] C:\Program Files\ Hewlett-Packard
[06/28/2007|03:33] C:\Program Files\ HP
[06/25/2004|04:21] C:\Program Files\ IBM
[04/08/2005|10:47] C:\Program Files\ IBM RecordNow!
[01/16/2008|09:54] C:\Program Files\ IDP Corporation
[01/16/2008|10:39] C:\Program Files\ InstallShield Installation Information
[02/13/2006|02:14] C:\Program Files\ Intel
[10/13/2008|11:41] C:\Program Files\ Internet Explorer
[10/05/2004|11:14] C:\Program Files\ IrfanView
[07/24/2008|02:15] C:\Program Files\ Java
[01/04/2008|12:54] C:\Program Files\ Juniper Networks
[10/12/2008|10:09] C:\Program Files\ Lavasoft
[08/31/2006|11:08] C:\Program Files\ LEI
[03/02/2005|05:10] C:\Program Files\ Logitech
[10/13/2008|11:15] C:\Program Files\ Messenger
[08/12/2004|10:24] C:\Program Files\ Microsoft ActiveSync
[02/19/2003|03:29] C:\Program Files\ microsoft frontpage
[06/27/2006|02:06] C:\Program Files\ Microsoft Office
[01/04/2005|03:16] C:\Program Files\ Microsoft TechNet
[08/24/2004|02:50] C:\Program Files\ Microsoft Windows Script
[09/19/2006|02:29] C:\Program Files\ Microsoft Works
[08/12/2004|10:23] C:\Program Files\ Microsoft.NET
[10/13/2008|11:15] C:\Program Files\ Movie Maker
[02/19/2003|03:24] C:\Program Files\ MSN
[02/19/2003|03:24] C:\Program Files\ MSN Gaming Zone
[03/13/2007|10:07] C:\Program Files\ MSN Messenger
[02/16/2006|10:48] C:\Program Files\ MSN Password Recovery
[10/13/2008|11:11] C:\Program Files\ NetMeeting
[03/29/2005|04:29] C:\Program Files\ OfficeUpdate11
[02/19/2003|03:24] C:\Program Files\ Online Services
[08/23/2004|03:04] C:\Program Files\ ORL
[10/13/2008|11:11] C:\Program Files\ Outlook Express
[09/29/2006|08:35] C:\Program Files\ PaceSetter 4000 Plus
[11/27/2007|04:13] C:\Program Files\ ParadisePoker
[06/25/2004|04:25] C:\Program Files\ PC-Doctor for Windows
[10/13/2008|12:17] C:\Program Files\ PokerStars
[12/05/2007|03:42] C:\Program Files\ PokerStars.TEST
[07/21/2006|08:43] C:\Program Files\ QuickTime
[06/25/2004|04:19] C:\Program Files\ SBApps
[12/10/2007|04:09] C:\Program Files\ SHARP
[01/31/2005|02:55] C:\Program Files\ SJLabs
[04/08/2005|10:47] C:\Program Files\ Sonic
[09/24/2008|04:03] C:\Program Files\ Spark
[10/10/2008|03:24] C:\Program Files\ Spybot - Search & Destroy
[11/29/2006|03:30] C:\Program Files\ Support.com
[08/31/2007|01:25] C:\Program Files\ svhost
[03/19/2007|10:16] C:\Program Files\ Symantec
[10/13/2008|01:01] C:\Program Files\ Symantec AntiVirus
[10/23/2007|12:41] C:\Program Files\ Trend Micro
[04/19/2007|10:16] C:\Program Files\ Trillian
[03/14/2007|10:55] C:\Program Files\ TZEdit
[08/23/2004|02:47] C:\Program Files\ Uninstall Information
[12/04/2006|10:33] C:\Program Files\ Unlocker
[05/29/2008|01:59] C:\Program Files\ VMware
[02/08/2008|02:22] C:\Program Files\ Whizlabs Suite
[10/13/2008|11:15] C:\Program Files\ Windows Media Player
[10/13/2008|11:11] C:\Program Files\ Windows NT
[08/23/2004|02:23] C:\Program Files\ WindowsUpdate
[03/19/2008|03:37] C:\Program Files\ WinPcap
[06/23/2008|10:58] C:\Program Files\ WinSCP
[03/19/2008|03:37] C:\Program Files\ Wireshark
[02/19/2003|03:29] C:\Program Files\ xerox
[07/26/2007|02:21] C:\Program Files\ Zenographics

——————–\\ Listing Folders in C:\Program Files\Common Files

[04/21/2006|09:05] C:\Program Files\Common Files\ Adobe
[08/12/2004|10:23] C:\Program Files\Common Files\ DESIGNER
[03/08/2006|02:50] C:\Program Files\Common Files\ InstallShield
[07/24/2008|02:13] C:\Program Files\Common Files\ Java
[03/02/2005|05:09] C:\Program Files\Common Files\ Labtec
[03/19/2007|10:16] C:\Program Files\Common Files\ Microsoft Shared
[02/19/2003|03:26] C:\Program Files\Common Files\ MSSoap
[02/19/2003|03:19] C:\Program Files\Common Files\ ODBC
[02/19/2003|03:26] C:\Program Files\Common Files\ Services
[04/08/2005|10:48] C:\Program Files\Common Files\ Sonic
[02/19/2003|03:19] C:\Program Files\Common Files\ SpeechEngines
[04/08/2005|10:47] C:\Program Files\Common Files\ SureThing Shared
[01/13/2006|12:15] C:\Program Files\Common Files\ SWF Studio
[04/22/2008|09:51] C:\Program Files\Common Files\ Symantec Shared
[10/13/2008|11:11] C:\Program Files\Common Files\ System
[10/12/2008|10:08] C:\Program Files\Common Files\ Wise Installation Wizard

——————–\\ Process

( 49 Processes )

iexplore.exe ~ [PID:3060]

——————–\\ Searching with S_Lop

No Lop folder found !

——————–\\ Searching for Lop Files - Folders

C:\DOCUME~1\rstone\Cookies\[removed][1].txt
C:\DOCUME~1\rstone\Cookies\[removed][1].txt

——————–\\ Searching within the Registry

….. OK !

——————–\\ Checking the Hosts file

Hosts file CLEAN


——————–\\ Searching for hidden files with Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-13 13:06:35
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden files: 0

——————–\\ Searching for other infections

C:\WINDOWS\system32\stvCLkkj.ini
C:\WINDOWS\system32\stvCLkkj.ini2
==> VUNDO <==



[F:431][D:177]-> C:\DOCUME~1\rstone\LOCALS~1\Temp
[F:1425][D:0]-> C:\DOCUME~1\rstone\Cookies
[F:1735][D:5]-> C:\DOCUME~1\rstone\LOCALS~1\TEMPOR~1\content.IE5
[F:2][D:0]-> C:\Recycled

1 - "C:\Lop SD\LopR_1.txt" - 10/13/2008|13:09 - Option : [1]

——————–\\ Scan completed at 13:09:34
Hello

Please download the OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    
    :Files
    C:\WINDOWS\tasks\meuvguie.job
    C:\WINDOWS\tasks\mniyzrqc.job
    C:\WINDOWS\tasks\gulchdcm.job
    C:\WINDOWS\system32\stvCLkkj.ini
    C:\WINDOWS\system32\stvCLkkj.ini2
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.




  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<info.txt (<
Hello,

Here are the 3 log files…

10132008_132043.log

========== PROCESSES ==========
Process explorer.exe killed successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
C:\WINDOWS\tasks\meuvguie.job moved successfully.
C:\WINDOWS\tasks\mniyzrqc.job moved successfully.
C:\WINDOWS\tasks\gulchdcm.job moved successfully.
C:\WINDOWS\system32\stvCLkkj.ini moved successfully.
C:\WINDOWS\system32\stvCLkkj.ini2 moved successfully.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\rstone\LOCALS~1\Temp\~DF4E35.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\rstone\LOCALS~1\Temp\~DF5060.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
Java cache emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.5.0 log created on 10132008_132043

Files moved on Reboot…
File C:\DOCUME~1\rstone\LOCALS~1\Temp\~DF4E35.tmp not found!
File C:\DOCUME~1\rstone\LOCALS~1\Temp\~DF5060.tmp not found!
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.

log.txt

Logfile of random's system information tool 1.04 (written by random/random)
Run by [removed] at 2008-10-13 13:29:59
Microsoft Windows XP Professional Service Pack 2
System drive C: has 16 GB (45%) free of 36 GB
Total RAM: 1783 MB (70% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:30:06 PM, on 10/13/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\ORL\VNC\WinVNC.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\system32\ICO.EXE
C:\WINDOWS\system32\FSRremoS.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\WINDOWS\System32\LVComS.exe
C:\WINDOWS\System32\umonit.exe
C:\program files\dell\traytool.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\System32\msiexec.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Documents and Settings\rstone\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\rstone.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.goact.net/
O2 - BHO: (no name) - {393B9CD9-A700-41FE-8942-666E22E42C17} - C:\WINDOWS\System32\jkkLCvts.dll
O2 - BHO: pl - {3DC8CA1D-D31A-474b-979A-A3823FA34ED8} - C:\WINDOWS\System32\dccplus.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {9E91EF7B-6846-45C3-A8AB-67CF7C900783} - C:\WINDOWS\System32\ssqPjjgg.dll
O2 - BHO: {d98900d5-1ece-a479-6134-70c8adac368e} - {e863cada-8c07-4316-974a-ece15d00989d} - C:\WINDOWS\system32\tuohey.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [UC_Start] C:\IBMTools\Updater\ucstartup.exe
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\ORL\VNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [UMonit] C:\WINDOWS\System32\umonit.exe
O4 - HKLM\..\Run: [ToolExe] c:\program files\dell\traytool.exe
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [fc6d3a34] rundll32.exe "C:\WINDOWS\system32\hxubjduq.dll",b
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Spark] C:\Program Files\Spark\Spark.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - Startup: Launch Microsoft Office Outlook.lnk = C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: APC UPS Status.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [JAVA_IBM] Java (IBM)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl.sun.com/webapps/download/AutoDL?BundleId=23100
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://finjan.webex.com/client/v_mywebex-t…bex/ieatgpc.cab
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetup Control) - https://216.16.42.51/dana-cached/setup/JuniperSetup.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{463477A3-3C65-4DE6-83BC-26DDA4AF0B31}: NameServer = 192.168.3.5
O20 - AppInit_DLLs: tuohey.dll
O20 - Winlogon Notify: ssqPjjgg - C:\WINDOWS\SYSTEM32\ssqPjjgg.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Juniper Network Connect Service (dsNcService) - Juniper Networks - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: VNC Server (winvnc) - AT&T Research Labs Cambridge - C:\Program Files\ORL\VNC\WinVNC.exe

–
End of file - 8727 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Email Projector Schedule.job
C:\WINDOWS\tasks\Restart.job
C:\WINDOWS\tasks\Schedule Task Weekly.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{393B9CD9-A700-41FE-8942-666E22E42C17}]
C:\WINDOWS\System32\jkkLCvts.dll [2008-10-10 339456]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3DC8CA1D-D31A-474b-979A-A3823FA34ED8}]
pl - C:\WINDOWS\System32\dccplus.dll [2008-08-28 22016]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9E91EF7B-6846-45C3-A8AB-67CF7C900783}]
C:\WINDOWS\System32\ssqPjjgg.dll [2008-10-10 104448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e863cada-8c07-4316-974a-ece15d00989d}]
C:\WINDOWS\system32\tuohey.dll [2008-10-13 123904]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"BluetoothAuthenticationAgent"=C:\WINDOWS\system32\irprops.cpl [2004-08-04 380416]
"IgfxTray"=C:\WINDOWS\System32\igfxtray.exe [2003-07-10 155648]
"HotKeysCmds"=C:\WINDOWS\System32\hkcmd.exe [2003-07-10 114688]
"tgcmd"= []
"UC_Start"=C:\IBMTools\Updater\ucstartup.exe [2003-03-17 32768]
"Mouse Suite 98 Daemon"=C:\WINDOWS\system32\ICO.EXE [2003-11-20 57344]
"WinVNC"=C:\Program Files\ORL\VNC\WinVNC.exe [2000-05-23 208896]
"LogitechVideoRepair"=C:\Program Files\Logitech\Video\ISStart.exe [2004-02-12 188416]
"LogitechVideoTray"=C:\Program Files\Logitech\Video\LogiTray.exe [2004-02-12 77824]
"UpdateManager"=C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe [2003-08-19 110592]
"PRONoMgr.exe"=C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe [2003-03-11 86016]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2006-07-21 282624]
"UMonit"=C:\WINDOWS\System32\umonit.exe [2004-01-05 53248]
"ToolExe"=c:\program files\dell\traytool.exe [2003-04-18 180224]
"UnlockerAssistant"=C:\Program Files\Unlocker\UnlockerAssistant.exe [2006-09-07 15872]
"ccApp"=C:\Program Files\Common Files\Symantec Shared\ccApp.exe [2005-04-08 48752]
"vptray"=C:\PROGRA~1\SYMANT~1\VPTray.exe [2005-04-17 85184]
"NvCplDaemon"=C:\WINDOWS\System32\NvCpl.dll [2005-07-20 7110656]
"NvMediaCenter"=C:\WINDOWS\System32\NvMcTray.dll [2005-07-20 86016]
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]
"fc6d3a34"=C:\WINDOWS\system32\hxubjduq.dll [2008-10-13 71680]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"=C:\Program Files\MSN Messenger\MsnMsgr.Exe [2007-01-19 5674352]
"tgcmd"= []
"Spark"=C:\Program Files\Spark\Spark.exe []
"updateMgr"=C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe [2006-03-30 313472]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
APC UPS Status.lnk - C:\Program Files\APC\APC PowerChute Personal Edition\Display.exe

C:\Documents and Settings\rstone\Start Menu\Programs\Startup
Launch Microsoft Office Outlook.lnk - C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="tuohey.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxsrvc.dll [2003-07-10 319488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon]
C:\WINDOWS\System32\NavLogon.dll [2005-04-17 43712]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssqPjjgg]
C:\WINDOWS\system32\ssqPjjgg.dll [2008-10-10 104448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{9E91EF7B-6846-45C3-A8AB-67CF7C900783}"=C:\WINDOWS\System32\ssqPjjgg.dll [2008-10-10 104448]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
C:\WINDOWS\System32\jkkLCvts

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"ForceStartMenuLogOff"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

======File associations======

.js - edit - C:\WINDOWS\System32\Notepad.exe %1
.js - open - C:\WINDOWS\System32\WScript.exe "%1" %*
.vbs - edit - C:\WINDOWS\System32\Notepad.exe %1
.vbs - open - C:\WINDOWS\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2008-10-13 13:29:59 —-D—- C:\rsit
2008-10-13 13:25:30 —-A—- C:\WINDOWS\system32\tuohey.dll
2008-10-13 13:25:28 —-A—- C:\WINDOWS\system32\npxmsora.dll
2008-10-13 13:21:39 —-SH—- C:\WINDOWS\system32\qudjbuxh.ini
2008-10-13 13:21:38 —-A—- C:\WINDOWS\system32\hxubjduq.dll
2008-10-13 13:20:58 —-ASH—- C:\WINDOWS\system32\stvCLkkj.ini2
2008-10-13 13:20:57 —-ASH—- C:\WINDOWS\system32\stvCLkkj.ini
2008-10-13 13:20:43 —-D—- C:\_OTMoveIt
2008-10-13 13:02:32 —-A—- C:\lopR.txt
2008-10-13 13:01:57 —-D—- C:\Lop SD
2008-10-13 11:43:36 —-D—- C:\WINDOWS\LastGood
2008-10-13 11:41:53 —-D—- C:\WINDOWS\Prefetch
2008-10-13 11:38:30 —-HDC—- C:\WINDOWS\$NtUninstallKB912919$
2008-10-13 11:37:50 —-HDC—- C:\WINDOWS\$NtUninstallKB910437$
2008-10-13 11:37:01 —-HDC—- C:\WINDOWS\$NtUninstallKB908519$
2008-10-13 11:36:29 —-HDC—- C:\WINDOWS\$NtUninstallKB905749$
2008-10-13 11:35:53 —-HDC—- C:\WINDOWS\$NtUninstallKB905414$
2008-10-13 11:34:54 —-HDC—- C:\WINDOWS\$NtUninstallKB902400$
2008-10-13 11:33:16 —-HDC—- C:\WINDOWS\$NtUninstallKB901214$
2008-10-13 11:32:33 —-HDC—- C:\WINDOWS\$NtUninstallKB901017$
2008-10-13 11:31:59 —-HDC—- C:\WINDOWS\$NtUninstallKB900725$
2008-10-13 11:31:26 —-HDC—- C:\WINDOWS\$NtUninstallKB899591$
2008-10-13 11:30:55 —-HDC—- C:\WINDOWS\$NtUninstallKB899589$
2008-10-13 11:30:23 —-HDC—- C:\WINDOWS\$NtUninstallKB899587$
2008-10-13 11:29:50 —-HDC—- C:\WINDOWS\$NtUninstallKB896428$
2008-10-13 11:29:13 —-HDC—- C:\WINDOWS\$NtUninstallKB896424$
2008-10-13 11:28:41 —-HDC—- C:\WINDOWS\$NtUninstallKB896423$
2008-10-13 11:28:08 —-HDC—- C:\WINDOWS\$NtUninstallKB896422$
2008-10-13 11:27:35 —-HDC—- C:\WINDOWS\$NtUninstallKB896358$
2008-10-13 11:27:01 —-HDC—- C:\WINDOWS\$NtUninstallKB893756$
2008-10-13 11:26:27 —-HDC—- C:\WINDOWS\$NtUninstallKB893066$
2008-10-13 11:25:54 —-HDC—- C:\WINDOWS\$NtUninstallKB891781$
2008-10-13 11:25:17 —-HDC—- C:\WINDOWS\$NtUninstallKB890859$
2008-10-13 11:24:41 —-HDC—- C:\WINDOWS\$NtUninstallKB890046$
2008-10-13 11:24:04 —-HDC—- C:\WINDOWS\$NtUninstallKB888302$
2008-10-13 11:23:24 —-HDC—- C:\WINDOWS\$NtUninstallKB888113$
2008-10-13 11:22:53 —-HDC—- C:\WINDOWS\$NtUninstallKB885836$
2008-10-13 11:22:20 —-HDC—- C:\WINDOWS\$NtUninstallKB885835$
2008-10-13 11:21:41 —-HDC—- C:\WINDOWS\$NtUninstallKB873339$
2008-10-13 11:17:42 —-A—- C:\WINDOWS\system32\wmpns.dll
2008-10-13 11:15:32 —-N—- C:\WINDOWS\system32\comsdupd.exe
2008-10-13 11:15:23 —-N—- C:\WINDOWS\system32\ati3d1ag.dll
2008-10-13 11:15:23 —-N—- C:\WINDOWS\system32\ati2dvag.dll
2008-10-13 11:15:23 —-N—- C:\WINDOWS\system32\ati2dvaa.dll
2008-10-13 11:15:23 —-N—- C:\WINDOWS\system32\ati2cqag.dll
2008-10-13 11:15:22 —-N—- C:\WINDOWS\system32\cmsetacl.dll
2008-10-13 11:15:22 —-N—- C:\WINDOWS\system32\btpanui.dll
2008-10-13 11:15:22 —-N—- C:\WINDOWS\system32\blastcln.exe
2008-10-13 11:15:22 —-N—- C:\WINDOWS\system32\auditusr.exe
2008-10-13 11:15:22 —-N—- C:\WINDOWS\system32\ativvaxx.dll
2008-10-13 11:15:22 —-N—- C:\WINDOWS\system32\ativtmxx.dll
2008-10-13 11:15:22 —-N—- C:\WINDOWS\system32\ati3duag.dll
2008-10-13 11:15:21 —-N—- C:\WINDOWS\system32\ieencode.dll
2008-10-13 11:15:21 —-N—- C:\WINDOWS\system32\httpapi.dll
2008-10-13 11:15:21 —-N—- C:\WINDOWS\system32\hsfcisp2.dll
2008-10-13 11:15:21 —-N—- C:\WINDOWS\system32\fwcfg.dll
2008-10-13 11:15:21 —-N—- C:\WINDOWS\system32\fsquirt.exe
2008-10-13 11:15:21 —-N—- C:\WINDOWS\system32\fltmc.exe
2008-10-13 11:15:21 —-N—- C:\WINDOWS\system32\fltlib.dll
2008-10-13 11:15:21 —-N—- C:\WINDOWS\system32\extmgr.dll
2008-10-13 11:15:20 —-N—- C:\WINDOWS\system32\mdmxsdk.dll
2008-10-13 11:15:20 —-N—- C:\WINDOWS\system32\kbdukx.dll
2008-10-13 11:15:20 —-N—- C:\WINDOWS\system32\kbdsmsno.dll
2008-10-13 11:15:20 —-N—- C:\WINDOWS\system32\kbdsmsfi.dll
2008-10-13 11:15:20 —-N—- C:\WINDOWS\system32\kbdno1.dll
2008-10-13 11:15:20 —-N—- C:\WINDOWS\system32\kbdmlt48.dll
2008-10-13 11:15:20 —-N—- C:\WINDOWS\system32\kbdmlt47.dll
2008-10-13 11:15:20 —-N—- C:\WINDOWS\system32\kbdmaori.dll
2008-10-13 11:15:20 —-N—- C:\WINDOWS\system32\kbdinmal.dll
2008-10-13 11:15:20 —-N—- C:\WINDOWS\system32\kbdinben.dll
2008-10-13 11:15:20 —-N—- C:\WINDOWS\system32\kbdinbe1.dll
2008-10-13 11:15:20 —-N—- C:\WINDOWS\system32\kbdfi1.dll
2008-10-13 11:15:19 —-N—- C:\WINDOWS\system32\s3gnb.dll
2008-10-13 11:15:19 —-N—- C:\WINDOWS\system32\powercfg.exe
2008-10-13 11:15:19 —-N—- C:\WINDOWS\system32\pnrpnsp.dll
2008-10-13 11:15:19 —-N—- C:\WINDOWS\system32\p2psvc.dll
2008-10-13 11:15:19 —-N—- C:\WINDOWS\system32\p2pnetsh.dll
2008-10-13 11:15:19 —-N—- C:\WINDOWS\system32\p2pgraph.dll
2008-10-13 11:15:19 —-N—- C:\WINDOWS\system32\p2pgasvc.dll
2008-10-13 11:15:19 —-N—- C:\WINDOWS\system32\p2p.dll
2008-10-13 11:15:19 —-N—- C:\WINDOWS\system32\mtxparhd.dll
2008-10-13 11:15:19 —-N—- C:\WINDOWS\system32\msdadiag.dll
2008-10-13 11:15:18 —-N—- C:\WINDOWS\system32\wscsvc.dll
2008-10-13 11:15:18 —-N—- C:\WINDOWS\system32\wscntfy.exe
2008-10-13 11:15:18 —-N—- C:\WINDOWS\system32\winshfhc.dll
2008-10-13 11:15:18 —-N—- C:\WINDOWS\system32\w3ssl.dll
2008-10-13 11:15:18 —-N—- C:\WINDOWS\system32\twext.dll
2008-10-13 11:15:18 —-N—- C:\WINDOWS\system32\strmfilt.dll
2008-10-13 11:15:18 —-N—- C:\WINDOWS\system32\smbinst.exe
2008-10-13 11:15:18 —-N—- C:\WINDOWS\system32\slserv.exe
2008-10-13 11:15:18 —-N—- C:\WINDOWS\system32\slrundll.exe
2008-10-13 11:15:18 —-N—- C:\WINDOWS\system32\slgen.dll
2008-10-13 11:15:18 —-N—- C:\WINDOWS\system32\slextspk.dll
2008-10-13 11:15:18 —-N—- C:\WINDOWS\system32\slcoinst.dll
2008-10-13 11:15:18 —-N—- C:\WINDOWS\system32\sdhcinst.dll
2008-10-13 11:15:17 —-N—- C:\WINDOWS\system32\xmlprovi.dll
2008-10-13 11:15:17 —-N—- C:\WINDOWS\system32\xmlprov.dll
2008-10-13 11:15:17 —-N—- C:\WINDOWS\slrundll.exe
2008-10-13 11:15:16 —-D—- C:\WINDOWS\peernet
2008-10-13 11:15:15 —-D—- C:\WINDOWS\provisioning
2008-10-13 11:12:23 —-D—- C:\WINDOWS\ServicePackFiles
2008-10-13 11:08:16 —-A—- C:\WINDOWS\002424_.tmp
2008-10-13 11:05:19 —-HDC—- C:\WINDOWS\$NtServicePackUninstall$
2008-10-13 11:05:07 —-D—- C:\WINDOWS\EHome
2008-10-13 10:41:57 —-A—- C:\WINDOWS\system32\qhnbiusu.dll
2008-10-13 10:41:57 —-A—- C:\WINDOWS\system32\jdqadx.dll
2008-10-13 10:39:49 —-SH—- C:\WINDOWS\system32\usoxypvl.ini
2008-10-13 10:25:58 —-D—- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-10-13 10:25:55 —-D—- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2008-10-13 09:45:55 —-A—- C:\WINDOWS\system32\mcrh.tmp
2008-10-13 07:42:52 —-A—- C:\freespace.txt
2008-10-12 10:09:23 —-D—- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-10-11 17:19:38 —-SH—- C:\WINDOWS\system32\ysunxwwo.ini
2008-10-11 17:19:38 —-A—- C:\WINDOWS\system32\owwxnusy.dll
2008-10-11 17:16:39 —-A—- C:\WINDOWS\system32\mehqbm.dll
2008-10-11 17:16:38 —-A—- C:\WINDOWS\system32\lbptsaae.dll
2008-10-11 09:52:27 —-ASH—- C:\WINDOWS\system32\vtUlLBsp.dll
2008-10-10 17:19:15 —-SH—- C:\WINDOWS\system32\dnonpsqt.ini
2008-10-10 17:16:13 —-A—- C:\WINDOWS\system32\xipwfm.dll
2008-10-10 17:16:12 —-A—- C:\WINDOWS\system32\xyifueqg.dll
2008-10-10 15:14:07 —-SH—- C:\WINDOWS\system32\tlvaqnfw.ini
2008-10-10 15:14:07 —-A—- C:\WINDOWS\system32\pxghhb.dll
2008-10-10 15:14:06 —-A—- C:\WINDOWS\system32\cdrjlcdl.dll
2008-10-10 15:14:04 —-A—- C:\WINDOWS\system32\wfnqavlt.dll
2008-10-10 15:13:37 —-A—- C:\WINDOWS\system32\f74efe4a-.txt
2008-10-10 15:12:44 —-A—- C:\WINDOWS\system32\jkkLCvts.dll
2008-10-10 14:57:55 —-A—- C:\WINDOWS\system32\urqpqnkh.dll
2008-10-10 14:57:37 —-ASH—- C:\WINDOWS\system32\awtSJYRj.dll
2008-10-10 14:57:34 —-A—- C:\WINDOWS\system32\ssqPjjgg.dll
2008-09-22 10:02:06 —-D—- C:\Documents and Settings\rstone\Application Data\U3

======List of files/folders modified in the last 1 months======

2008-10-13 13:28:08 —-D—- C:\WINDOWS\Temp
2008-10-13 13:27:55 —-D—- C:\Program Files\Symantec AntiVirus
2008-10-13 13:27:07 —-AD—- C:\WINDOWS\system32
2008-10-13 13:27:06 —-A—- C:\WINDOWS\system32\PerfStringBackup.INI
2008-10-13 13:26:37 —-HD—- C:\Config.Msi
2008-10-13 13:26:35 —-SHD—- C:\WINDOWS\Installer
2008-10-13 13:26:25 —-D—- C:\Program Files\MSN Messenger
2008-10-13 13:24:33 —-AD—- C:\WINDOWS
2008-10-13 13:24:16 —-D—- C:\WINDOWS\Debug
2008-10-13 13:22:47 —-A—- C:\WINDOWS\SchedLgU.Txt
2008-10-13 13:20:44 —-SD—- C:\WINDOWS\Tasks
2008-10-13 12:17:35 —-D—- C:\Program Files\PokerStars
2008-10-13 11:47:27 —-SD—- C:\Documents and Settings\rstone\Application Data\Microsoft
2008-10-13 11:44:49 —-A—- C:\WINDOWS\OEWABLog.txt
2008-10-13 11:43:37 —-D—- C:\WINDOWS\system32\inetsrv
2008-10-13 11:42:56 —-D—- C:\WINDOWS\system32\wbem
2008-10-13 11:42:42 —-D—- C:\WINDOWS\system32\CatRoot2
2008-10-13 11:42:38 —-HD—- C:\WINDOWS\inf
2008-10-13 11:42:19 —-A—- C:\WINDOWS\setuplog.txt
2008-10-13 11:41:10 —-SHD—- C:\System Volume Information
2008-10-13 11:41:01 —-D—- C:\WINDOWS\msagent
2008-10-13 11:41:00 —-D—- C:\WINDOWS\AppPatch
2008-10-13 11:41:00 —-D—- C:\Program Files\Internet Explorer
2008-10-13 11:40:55 —-RSD—- C:\WINDOWS\Fonts
2008-10-13 11:40:30 —-D—- C:\WINDOWS\system32\drivers
2008-10-13 11:39:11 —-A—- C:\WINDOWS\imsins.BAK
2008-10-13 11:38:50 —-D—- C:\WINDOWS\system32\CatRoot
2008-10-13 11:35:34 —-D—- C:\WINDOWS\system32\Com
2008-10-13 11:17:45 —-RASH—- C:\BOOT.INI
2008-10-13 11:16:45 —-D—- C:\WINDOWS\security
2008-10-13 11:15:46 —-D—- C:\WINDOWS\WinSxS
2008-10-13 11:15:40 —-D—- C:\Program Files\Messenger
2008-10-13 11:15:32 —-D—- C:\WINDOWS\system32\Setup
2008-10-13 11:15:32 —-D—- C:\WINDOWS\Help
2008-10-13 11:15:31 —-D—- C:\WINDOWS\ime
2008-10-13 11:15:17 —-D—- C:\Program Files\Windows Media Player
2008-10-13 11:15:17 —-AD—- C:\WINDOWS\system32\oobe
2008-10-13 11:15:16 —-D—- C:\Program Files\Movie Maker
2008-10-13 11:15:15 —-D—- C:\WINDOWS\Media
2008-10-13 11:12:03 —-D—- C:\WINDOWS\system32\Restore
2008-10-13 11:12:02 —-D—- C:\WINDOWS\system32\npp
2008-10-13 11:12:02 —-D—- C:\WINDOWS\mui
2008-10-13 11:11:56 —-D—- C:\WINDOWS\srchasst
2008-10-13 11:11:55 —-D—- C:\Program Files\NetMeeting
2008-10-13 11:11:49 —-D—- C:\Program Files\Windows NT
2008-10-13 11:11:49 —-D—- C:\Program Files\Outlook Express
2008-10-13 11:11:41 —-D—- C:\Program Files\Common Files\System
2008-10-13 11:11:26 —-D—- C:\WINDOWS\system32\usmt
2008-10-13 11:11:24 —-D—- C:\WINDOWS\system
2008-10-13 11:09:28 —-RD—- C:\WINDOWS\Web
2008-10-13 11:09:01 —-RASH—- C:\NTDETECT.COM
2008-10-13 11:08:56 —-RSHD—- C:\WINDOWS\system32\dllcache
2008-10-13 11:08:15 —-D—- C:\WINDOWS\system32\ReinstallBackups
2008-10-13 10:54:40 —-SD—- C:\WINDOWS\Downloaded Program Files
2008-10-13 10:35:07 —-D—- C:\WINDOWS\system32\config
2008-10-13 10:34:58 —-D—- C:\WINDOWS\Registration
2008-10-13 09:48:35 —-A—- C:\WINDOWS\ntbtlog.txt
2008-10-13 09:10:16 —-D—- C:\ACT Databases
2008-10-12 10:09:52 —-D—- C:\Program Files\Lavasoft
2008-10-12 10:09:50 —-SD—- C:\Documents and Settings\All Users\Application Data\Microsoft
2008-10-12 10:09:50 —-D—- C:\Documents and Settings\rstone\Application Data\Lavasoft
2008-10-12 10:08:33 —-D—- C:\Program Files\Common Files\Wise Installation Wizard
2008-10-10 15:24:26 —-D—- C:\Program Files\Spybot - Search & Destroy
2008-10-10 08:23:09 —-D—- C:\Documents and Settings\rstone\Application Data\VMware
2008-10-08 09:31:51 —-A—- C:\WINDOWS\fsmss.ini
2008-10-06 08:36:36 —-D—- C:\fsuser
2008-09-24 16:03:46 —-D—- C:\Program Files\Spark
2008-09-23 09:08:20 —-A—- C:\Phonelog.txt

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys []
R1 intelppm;Intel Processor Driver; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2004-08-03 36096]
R1 SAVRT;SAVRT; \??\C:\Program Files\Symantec AntiVirus\savrt.sys []
R1 SAVRTPEL;SAVRTPEL; \??\C:\Program Files\Symantec AntiVirus\Savrtpel.sys []
R1 SYMTDI;SYMTDI; \??\C:\WINDOWS\System32\Drivers\SYMTDI.SYS []
R2 EGATHDRV;IBM Access Support; \??\C:\WINDOWS\SYSTEM32\EGATHDRV.SYS []
R2 PMEM;PMEM; \??\C:\WINDOWS\system32\drivers\PMEMNT.SYS []
R2 Ynsernet;Ynsernet; C:\WINDOWS\system32\drivers\Ynsernet.sys [2002-08-19 59736]
R3 {6080A529-897E-4629-A488-ABA0C29B635E};Intel® Graphics Platform (SoftBIOS) Driver; C:\WINDOWS\system32\drivers\ialmsbw.sys [2003-07-22 120062]
R3 {D31A0762-0CEB-444e-ACFF-B049A1F6FE91};Intel® Graphics Chipset (KCH) Driver; C:\WINDOWS\system32\drivers\ialmkchw.sys [2003-07-22 96858]
R3 aeaudio;aeaudio; C:\WINDOWS\system32\drivers\aeaudio.sys [2002-08-22 98752]
R3 dsNcAdpt;Juniper Network Connect Adapter; C:\WINDOWS\System32\DRIVERS\dsNcAdpt.sys [2005-11-09 23552]
R3 E100B;Intel® PRO Adapter Driver; C:\WINDOWS\System32\DRIVERS\e100b325.sys [2003-03-04 145408]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2001-08-17 9600]
R3 ialm;ialm; C:\WINDOWS\System32\DRIVERS\ialmnt5.sys [2003-07-22 91419]
R3 NAVENG;NAVENG; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20081011.003\naveng.sys []
R3 NAVEX15;NAVEX15; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20081011.003\navex15.sys []
R3 nv;nv; C:\WINDOWS\System32\DRIVERS\nv4_mini.sys [2005-07-20 3198368]
R3 pepifilter;Volume Adapter; C:\WINDOWS\System32\DRIVERS\lv302af.sys [2004-01-20 5915]
R3 PID_08A0;Labtec WebCam Pro(PID_08A0); C:\WINDOWS\System32\DRIVERS\LV302AV.SYS [2004-01-20 271360]
R3 smwdm;smwdm; C:\WINDOWS\system32\drivers\smwdm.sys [2002-11-25 537152]
R3 SYMREDRV;SYMREDRV; \??\C:\WINDOWS\System32\Drivers\SYMREDRV.SYS []
R3 usbaudio;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-03 59264]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2004-08-03 31616]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2004-08-03 26624]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2004-08-03 20480]
R4 SymEvent;SymEvent; \??\C:\Program Files\Symantec\SYMEVENT.SYS []
S2 Aspi32;Aspi32; C:\WINDOWS\System32\drivers\aspi32.sys []
S3 ac97intc;Intel® 82801 Audio Driver Install Service (WDM); C:\WINDOWS\system32\drivers\ac97intc.sys [2001-08-17 96256]
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 EraserUtilDrvI7;EraserUtilDrvI7; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrvI7.sys []
S3 fixustor;fixustor; C:\WINDOWS\system32\drivers\fixustor.sys [2004-01-05 6016]
S3 HidBatt;HID UPS Battery Driver; C:\WINDOWS\System32\DRIVERS\HidBatt.sys [2001-08-17 19200]
S3 mouhid;Mouse HID Driver; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-08-17 12160]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\System32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 nm;Network Monitor Driver; C:\WINDOWS\System32\DRIVERS\NMnt.sys [2004-08-03 40320]
S3 NPF;NetGroup Packet Filter Driver; C:\WINDOWS\system32\drivers\npf.sys [2007-11-06 34064]
S3 pelmouse;Mouse Suite Driver; C:\WINDOWS\System32\DRIVERS\pelmouse.sys [2003-01-10 16384]
S3 pelusblf;USB Mouse Low Filter Driver; C:\WINDOWS\System32\DRIVERS\pelusblf.sys [2003-02-11 9216]
S3 psadd;IBM PSA Access Driver; \??\C:\WINDOWS\system32\Drivers\psadd.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\System32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 SPBBCDrv;SPBBCDrv; \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys []
S3 streamip;BDA IPSink; C:\WINDOWS\System32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 tgiul50;tgiul50; C:\WINDOWS\System32\DRIVERS\tgiulnt5.sys [2001-08-17 138528]
S3 TVICHW32;TVICHW32; \??\C:\WINDOWS\System32\DRIVERS\TVICHW32.SYS []
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\System32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\System32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S4 agp440;Intel AGP Bus Filter; C:\WINDOWS\System32\DRIVERS\agp440.sys [2004-08-03 42368]
S4 agpCPQ;Compaq AGP Bus Filter; C:\WINDOWS\System32\DRIVERS\agpCPQ.sys [2004-08-03 44928]
S4 alim1541;ALI AGP Bus Filter; C:\WINDOWS\System32\DRIVERS\alim1541.sys [2004-08-03 42752]
S4 amdagp;AMD AGP Bus Filter Driver; C:\WINDOWS\System32\DRIVERS\amdagp.sys [2004-08-03 43008]
S4 cbidf;cbidf; C:\WINDOWS\System32\DRIVERS\cbidf2k.sys [2001-08-17 13952]
S4 IntelIde;IntelIde; C:\WINDOWS\System32\DRIVERS\intelide.sys [2004-08-03 5504]
S4 sisagp;SIS AGP Bus Filter; C:\WINDOWS\System32\DRIVERS\sisagp.sys [2004-08-03 41088]
S4 viaagp;VIA AGP Bus Filter; C:\WINDOWS\System32\DRIVERS\viaagp.sys [2004-08-03 42240]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2008-10-12 611664]
R2 APC UPS Service;APC UPS Service; C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe [2005-12-12 176193]
R2 ccEvtMgr;Symantec Event Manager; C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe [2005-04-08 185968]
R2 ccSetMgr;Symantec Settings Manager; C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe [2005-04-08 161392]
R2 DefWatch;Symantec AntiVirus Definition Watcher; C:\Program Files\Symantec AntiVirus\DefWatch.exe [2005-04-17 19648]
R2 dsNcService;Juniper Network Connect Service; C:\Program Files\Juniper Networks\Common Files\dsNcService.exe [2005-11-09 335872]
R2 LexBceS;LexBce Server; C:\WINDOWS\system32\LEXBCES.EXE [2003-04-18 286720]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\System32\nvsvc32.exe [2005-07-20 127043]
R2 SoundMAX Agent Service (default);SoundMAX Agent Service; C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe [2002-09-20 45056]
R2 Symantec AntiVirus;Symantec AntiVirus; C:\Program Files\Symantec AntiVirus\Rtvscan.exe [2005-04-17 1706176]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\System32\wdfmgr.exe [2004-09-22 38912]
R2 winvnc;VNC Server; C:\Program Files\ORL\VNC\WinVNC.exe [2000-05-23 208896]
R3 usnjsvc;Messenger Sharing Folders USN Journal Reader service; C:\Program Files\MSN Messenger\usnsvc.exe [2007-01-19 97136]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2003-02-20 32768]
S3 ccPwdSvc;Symantec Password Validation; C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe [2005-04-08 83568]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 NetSvc;Intel NCS NetService; C:\Program Files\Intel\NCS\Sync\NetSvc.exe [2003-03-03 143360]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 PsaSrv;IBM PSA Access Driver Control; C:\WINDOWS\system32\PsaSrv.exe [2002-08-12 26624]
S3 rpcapd;Remote Packet Capture Protocol v.0 (experimental); C:\Program Files\WinPcap\rpcapd.exe [2007-11-06 92792]
S3 SavRoam;SAVRoam; C:\Program Files\Symantec AntiVirus\SavRoam.exe [2005-04-17 124608]
S3 SNDSrvc;Symantec Network Drivers Service; C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe [2005-04-05 206552]
S3 SPBBCSvc;Symantec SPBBCSvc; C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe [2005-03-30 992864]

—————–EOF—————–

info.txt

info.txt logfile of random's system information tool 1.04 2008-10-13 13:30:09

======Uninstall list======

–>C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu
–>C:\WINDOWS\System32\\MSIEXEC.EXE /I {09DA4F91-2A09-4232-AB8C-6BC740096DE3} REMOVE=UpdateMgrFeature
–>C:\WINDOWS\System32\\MSIEXEC.EXE /x {9541FED0-327F-4df0-8B96-EF57EF622F19}
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{39DA87A1-0B26-4562-A70C-2A6147366E47}\SETUP.EXE"
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9F765BD0-B900-4EDE-A90B-61C8A9E95C42}\SETUP.EXE"
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BAD59025-5B73-4E12-B789-0028C5A573C2}\SETUP.EXE"
–>rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Access IBM Cleanup Utility–>MsiExec.exe /I{CF44C7A5-5705-41E4-BE84-A9A42977AB05}
Access IBM Message Center–>MsiExec.exe /X{710C0BB2-FE39-484E-BB23-C9B96835A14A}
Access IBM Tools–>C:\Program Files\IBM\Access IBM\IBMUINST.EXE
Access IBM–>MsiExec.exe /X{B5599ECB-DA72-43EE-8A30-2C80396FF8BB}
Ad-Aware–>MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
Adobe Download Manager 2.0 (Remove Only)–>"C:\Program Files\Common Files\Adobe\ESD\uninst.exe"
Adobe Flash Player 9 ActiveX–>C:\WINDOWS\System32\Macromed\Flash\UninstFl.exe -q
Adobe Reader 7.0.9–>MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70900000002}
APC PowerChute Business Edition Console–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0F86FD09-BA63-4E45-A70B-604C1106C2F2}\setup.exe" -l0x9 AnyText -removeonly
APC PowerChute Personal Edition–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5A0C892E-FD1C-4203-941E-0956AED20A6A}\Setup.exe" -l0x9
AR-M450U PCL6–>C:\WINDOWS\ISUNINST.EXE -fC:\WINDOWS\arm45u6.isu -cC:\WINDOWS\System32\uarm45u6.dll
BUFFALO LinkStation Utility–>C:\WINDOWS\UN021217.EXE /U
Dell Printer Software Uninstall–>C:\Program Files\Dell\Install\uninstall.exe
EPSON Printer Software–>C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R
Fourth Shift Workstation 7.11–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4F1A8D93-5D78-11D4-8058-009027AFCDD7}\Setup.exe" Uninstall
GanttProject–>"C:\Program Files\GanttProject\uninstall.exe"
Google Earth–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3DE5E7D4-7B88-403C-A3FD-2017A8240C5B}\setup.exe" -l0x9 -removeonly
HijackThis 2.0.2–>"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Windows XP (KB928388)–>"C:\WINDOWS\$NtUninstallKB928388$\spuninst\spuninst.exe"
HP Officejet Pro K550 Series–>C:\Program Files\HP\Digital Imaging\{D2355E6F-5004-4e44-B63C-2E58DCB4C29B}\setup\hpzscr01.exe -datfile hpwscr03.dat -forcereboot
IBM 32-bit SDK for Java 2, v1.4.1–>C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{6C72E14A-C1F3-45E5-8810-83CE3C19ED63} /l1033
IBM Access Support–>wscript "C:\Program Files\Support.com\bin\uninstall.vbs" -uninstall -release1
IBM RecordNow!–>MsiExec.exe /I{9541FED0-327F-4DF0-8B96-EF57EF622F19}
IBM Update Connector–>MsiExec.exe /X{31C2FBAC-67CF-4093-8F36-15A146613747}
Intel® Extreme Graphics 2 Driver–>RUNDLL32.EXE C:\WINDOWS\System32\ialmrem.dll,UninstallW2KIGfx PCI\VEN_8086&DEV_2572
Intel® PRO Network Adapters and Drivers–>Prounstl.exe
Intel® PROSet–>MsiExec.exe /I{A790BEB1-BCCF-4EC6-807B-5708B36E8A79}
Java™ 6 Update 7–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
Juniper Networks Network Connect 5.2.0–>"C:\Program Files\Juniper Networks\Network Connect 5.2.0\uninstall.exe"
Labtec WebCam–>MsiExec.exe /I{58E653BE-BD68-4D68-BB2E-3AE1B925AAD0}
Labtec® WebCam Driver–>"C:\Program Files\Common Files\Labtec\QCDRV\BIN\SETUP.EXE" UNINSTALL REMOVEPROMPT
LaserJet 1020 series–>C:\Program Files\Zenographics\{AF0559A0-1BB2-4325-A526-8D395CA01B92}\SETUP.EXE -u "HPLJInstaller.dll=Hplj1020.inf"
LiveUpdate 2.6 (Symantec Corporation)–>C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE /U
Macromedia Shockwave Player–>C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
Microsoft .NET Framework 1.1–>MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft Data Access Components KB870669–>C:\WINDOWS\muninst.exe C:\WINDOWS\INF\KB870669.inf
Microsoft Office Live Meeting 2005–>MsiExec.exe /I{7228CB73-80E9-48D3-A7FD-C2A242686AB3}
Microsoft Office Professional Edition 2003–>MsiExec.exe /I{91110409-6000-11D3-8CFE-0150048383C9}
Mouse Suite–>PMUninst.exe MouseSuite98
NVIDIA Drivers–>C:\WINDOWS\System32\nvudisp.exe UninstallGUI
PaceSetter 4000 Plus Config. Software–>C:\WINDOWS\st6unst.exe -n "C:\Program Files\PaceSetter 4000 Plus\ST6UNST.LOG"
PC-Doctor for Windows–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1F7CCFA3-D926-4882-B2A5-A0217ED25597}\SETUP.EXE"
PokerStars–>C:\Program Files\PokerStars\Uninstall.EXE /u:"PokerStars"
PostgreSQL ODBC Driver–>C:\WINDOWS\uninst.exe -fC:\WINDOWS\System32\DeIsL2.isu
QuickTime–>C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{C21D5524-A970-42FA-AC8A-59B8C7CDCA31} /l1033
Security Update for Step By Step Interactive Training (KB898458)–>"C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
Security Update for Windows XP (KB890046)–>"C:\WINDOWS\$NtUninstallKB890046$\spuninst\spuninst.exe"
Security Update for Windows XP (KB893066)–>"C:\WINDOWS\$NtUninstallKB893066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB893756)–>"C:\WINDOWS\$NtUninstallKB893756$\spuninst\spuninst.exe"
Security Update for Windows XP (KB896358)–>"C:\WINDOWS\$NtUninstallKB896358$\spuninst\spuninst.exe"
Security Update for Windows XP (KB896422)–>"C:\WINDOWS\$NtUninstallKB896422$\spuninst\spuninst.exe"
Security Update for Windows XP (KB896423)–>"C:\WINDOWS\$NtUninstallKB896423$\spuninst\spuninst.exe"
Security Update for Windows XP (KB896424)–>"C:\WINDOWS\$NtUninstallKB896424$\spuninst\spuninst.exe"
Security Update for Windows XP (KB896428)–>"C:\WINDOWS\$NtUninstallKB896428$\spuninst\spuninst.exe"
Security Update for Windows XP (KB899587)–>"C:\WINDOWS\$NtUninstallKB899587$\spuninst\spuninst.exe"
Security Update for Windows XP (KB899589)–>"C:\WINDOWS\$NtUninstallKB899589$\spuninst\spuninst.exe"
Security Update for Windows XP (KB899591)–>"C:\WINDOWS\$NtUninstallKB899591$\spuninst\spuninst.exe"
Security Update for Windows XP (KB900725)–>"C:\WINDOWS\$NtUninstallKB900725$\spuninst\spuninst.exe"
Security Update for Windows XP (KB901017)–>"C:\WINDOWS\$NtUninstallKB901017$\spuninst\spuninst.exe"
Security Update for Windows XP (KB901214)–>"C:\WINDOWS\$NtUninstallKB901214$\spuninst\spuninst.exe"
Security Update for Windows XP (KB902400)–>"C:\WINDOWS\$NtUninstallKB902400$\spuninst\spuninst.exe"
Security Update for Windows XP (KB904706)–>"C:\WINDOWS\$NtUninstallKB904706$\spuninst\spuninst.exe"
Security Update for Windows XP (KB905414)–>"C:\WINDOWS\$NtUninstallKB905414$\spuninst\spuninst.exe"
Security Update for Windows XP (KB905749)–>"C:\WINDOWS\$NtUninstallKB905749$\spuninst\spuninst.exe"
Security Update for Windows XP (KB908519)–>"C:\WINDOWS\$NtUninstallKB908519$\spuninst\spuninst.exe"
Security Update for Windows XP (KB912919)–>"C:\WINDOWS\$NtUninstallKB912919$\spuninst\spuninst.exe"
SHARP AR-351/355/451/455 Series PCL Printer Driver–>C:\WINDOWS\ISUNINST.EXE -fC:\WINDOWS\ush2.isu -cC:\WINDOWS\System32\ush2.dll
SJphone–>MsiExec.exe /X{0ADA31DA-3A6E-4DAC-899E-4E9E0CBB13E5}
Sonic Update Manager–>MsiExec.exe /I{09DA4F91-2A09-4232-AB8C-6BC740096DE3}
SoundMAX–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F0A37341-D692-11D4-A984-009027EC0A9C}\SETUP.EXE"
Spybot - Search & Destroy 1.5.2.20–>"C:\WINDOWS\unins000.exe"
Spybot - Search & Destroy–>"C:\Program Files\Spybot - Search & Destroy\unins001.exe"
Symantec AntiVirus–>MsiExec.exe /I{5A633ED0-E5D7-4D65-AB8D-53ED43510284}
Technical Information August 2001–>MsiExec.exe /I{206FC9B0-6C8E-48E6-B711-41074553C467}
TestPokerStars.com–>C:\Program Files\PokerStars.TEST\Uninstall.EXE /u:"TestPokerStars.com"
ThinkCentre Wallpaper–>MsiExec.exe /I{80380166-A872-4B78-B98A-33447A032BDF}
Unlocker 1.8.5–>C:\Program Files\Unlocker\uninst.exe
Update for Windows XP (KB898461)–>"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
Update for Windows XP (KB910437)–>"C:\WINDOWS\$NtUninstallKB910437$\spuninst\spuninst.exe"
USB 2.0 MMC/SD Card Reader–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B4BF87C8-3EEC-4774-82A2-584F109187B1}\Setup.exe"
VMware Server Console–>MsiExec.exe /I{0FD23E02-2BFB-4BEC-8823-FE984F83F161}
VxComm Driver for Win2K–>C:\WINDOWS\IsUninst.exe -f"C:\Program Files\7188E\VxComm2K\Uninst.isu"
WebEx–>C:\WINDOWS\DOWNLO~1\atcliun.exe
Whizlabs CCNA-640-801 Preparation Kit version 6.0.1–>"C:\Program Files\Whizlabs Suite\CCNA-640-801\unins000.exe"
Win2PDF 1.84–>C:\WINDOWS\System32\spool\drivers\w32x86\2\Win2PDF\unins000.exe
Windows Installer 3.1 (KB893803)–>"C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
Windows Live Messenger–>MsiExec.exe /I{571700F0-DB9D-4B3A-B03D-35A14BB5939F}
Windows Media Format Runtime–>"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Player 10–>"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Script V5.6 Documentation–>RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\scrdoc56.inf, Uninstall
Windows XP Hotfix - KB873339–>C:\WINDOWS\$NtUninstallKB873339$\spuninst\spuninst.exe
Windows XP Hotfix - KB885835–>C:\WINDOWS\$NtUninstallKB885835$\spuninst\spuninst.exe
Windows XP Hotfix - KB885836–>C:\WINDOWS\$NtUninstallKB885836$\spuninst\spuninst.exe
Windows XP Hotfix - KB888113–>C:\WINDOWS\$NtUninstallKB888113$\spuninst\spuninst.exe
Windows XP Hotfix - KB888302–>C:\WINDOWS\$NtUninstallKB888302$\spuninst\spuninst.exe
Windows XP Hotfix - KB890859–>"C:\WINDOWS\$NtUninstallKB890859$\spuninst\spuninst.exe"
Windows XP Hotfix - KB891781–>C:\WINDOWS\$NtUninstallKB891781$\spuninst\spuninst.exe
Windows XP Service Pack 2–>C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe
WinPcap 4.0.2–>C:\Program Files\WinPcap\uninstall.exe
WinSCP 4.0.7–>"C:\Program Files\WinSCP\unins000.exe"
WinVNC 3.3.3–>C:\WINDOWS\IsUninst.exe -f"C:\Program Files\ORL\VNC\Uninst.isu"
Wireshark 0.99.8–>"C:\Program Files\Wireshark\uninstall.exe"

=====HijackThis Backups=====

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O20 - AppInit_DLLs: mehqbm.dll
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKLM\..\Run: [fc6d3a34] rundll32.exe "C:\WINDOWS\System32\owwxnusy.dll",b
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O20 - Winlogon Notify: ssqPjjgg - C:\WINDOWS\SYSTEM32\ssqPjjgg.dll
O2 - BHO: pl - {3DC8CA1D-D31A-474b-979A-A3823FA34ED8} - C:\WINDOWS\System32\dccplus.dll
O2 - BHO: (no name) - {9E91EF7B-6846-45C3-A8AB-67CF7C900783} - C:\WINDOWS\System32\ssqPjjgg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {CBEC7F30-7579-4B64-8267-DD9D159F0B89} - C:\WINDOWS\System32\jkkLCvts.dll
O2 - BHO: {b7e7e3d8-1e46-ac0a-4fc4-8267528bc43c} - {c34cb825-7628-4cf4-a0ca-64e18d3e7e7b} - (no file)
O20 - Winlogon Notify: ssqPjjgg - C:\WINDOWS\SYSTEM32\ssqPjjgg.dll
O2 - BHO: (no name) - {CBEC7F30-7579-4B64-8267-DD9D159F0B89} - C:\WINDOWS\System32\jkkLCvts.dll
O2 - BHO: (no name) - {9E91EF7B-6846-45C3-A8AB-67CF7C900783} - C:\WINDOWS\system32\ssqPjjgg.dll

======Security center information======

AV: Symantec AntiVirus Corporate Edition

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\PC-Doctor for Windows\services;C:\Program Files\QuickTime\QTSystem\;M:\Mfgsys\System
"windir"=%SystemRoot%
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 2 Stepping 9, GenuineIntel
"PROCESSOR_REVISION"=0209
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"FSCFG"=M:\Mfgsys\FS.CFG
"CLASSPATH"=.;C:\Program Files\IBM\Java141\jre\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\IBM\Java141\jre\lib\ext\QTJava.zip
"FP_NO_HOST_CHECK"=NO

—————–EOF—————–
hello

Please download the OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    aawservice.exe
    
    :Services
    
    :Reg
    
    :Files
    C:\WINDOWS\system32\tuohey.dll
    C:\WINDOWS\system32\npxmsora.dll
    C:\WINDOWS\system32\qudjbuxh.ini
    C:\WINDOWS\system32\hxubjduq.dll
    C:\WINDOWS\system32\stvCLkkj.ini2
    C:\WINDOWS\system32\stvCLkkj.ini
    C:\WINDOWS\system32\qhnbiusu.dll
    C:\WINDOWS\system32\jdqadx.dll
    C:\WINDOWS\system32\usoxypvl.ini
    C:\WINDOWS\system32\mcrh.tmp
    C:\WINDOWS\system32\ysunxwwo.ini
    C:\WINDOWS\system32\owwxnusy.dll
    C:\WINDOWS\system32\mehqbm.dll
    C:\WINDOWS\system32\lbptsaae.dll
    C:\WINDOWS\system32\vtUlLBsp.dll
    C:\WINDOWS\system32\dnonpsqt.ini
    C:\WINDOWS\system32\xipwfm.dll
    C:\WINDOWS\system32\xyifueqg.dll
    C:\WINDOWS\system32\tlvaqnfw.ini
    C:\WINDOWS\system32\pxghhb.dll
    C:\WINDOWS\system32\cdrjlcdl.dll
    C:\WINDOWS\system32\wfnqavlt.dll
    C:\WINDOWS\system32\f74efe4a-.txt
    C:\WINDOWS\system32\jkkLCvts.dll
    C:\WINDOWS\system32\urqpqnkh.dll
    C:\WINDOWS\system32\awtSJYRj.dll
    C:\WINDOWS\system32\ssqPjjgg.dll
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.



Also post a new Rsit log
OK, there wasn't a new Movit log. I got the error Access violation at address 77FE1DD4, read of address 77FE1DD4. I had to close it and restart. This was in the results window when the system restarted.

Files moved on Reboot…
DllUnregisterServer procedure not found in C:\WINDOWS\system32\ssqPjjgg.dll
C:\WINDOWS\system32\ssqPjjgg.dll NOT unregistered.
File move failed. C:\WINDOWS\system32\ssqPjjgg.dll scheduled to be moved on reboot.
File C:\DOCUME~1\rstone\LOCALS~1\Temp\~DF1635.tmp not found!
File C:\DOCUME~1\rstone\LOCALS~1\Temp\~DF1641.tmp not found!
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.


Here is the RIST log.

Logfile of random's system information tool 1.04 (written by random/random)
Run by [removed] at 2008-10-13 13:48:40
Microsoft Windows XP Professional Service Pack 2
System drive C: has 16 GB (45%) free of 36 GB
Total RAM: 1783 MB (71% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:48:52 PM, on 10/13/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\ORL\VNC\WinVNC.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\system32\ICO.EXE
C:\WINDOWS\system32\FSRremoS.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\WINDOWS\System32\LVComS.exe
C:\WINDOWS\System32\umonit.exe
C:\program files\dell\traytool.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\rundll32.exe
C:\Documents and Settings\rstone\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\rstone.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.goact.net/
O2 - BHO: (no name) - {393B9CD9-A700-41FE-8942-666E22E42C17} - C:\WINDOWS\System32\jkkLCvts.dll (file missing)
O2 - BHO: (no name) - {3BFFA4A4-6F01-43AC-8232-F3B899BC97D6} - C:\WINDOWS\system32\vtUolIyA.dll
O2 - BHO: pl - {3DC8CA1D-D31A-474b-979A-A3823FA34ED8} - C:\WINDOWS\System32\dccplus.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {9E91EF7B-6846-45C3-A8AB-67CF7C900783} - C:\WINDOWS\System32\ssqPjjgg.dll
O2 - BHO: {d98900d5-1ece-a479-6134-70c8adac368e} - {e863cada-8c07-4316-974a-ece15d00989d} - C:\WINDOWS\system32\tuohey.dll (file missing)
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [UC_Start] C:\IBMTools\Updater\ucstartup.exe
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\ORL\VNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [UMonit] C:\WINDOWS\System32\umonit.exe
O4 - HKLM\..\Run: [ToolExe] c:\program files\dell\traytool.exe
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [fc6d3a34] rundll32.exe "C:\WINDOWS\system32\hxubjduq.dll",b
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Spark] C:\Program Files\Spark\Spark.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - Startup: Launch Microsoft Office Outlook.lnk = C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: APC UPS Status.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [JAVA_IBM] Java (IBM)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl.sun.com/webapps/download/AutoDL?BundleId=23100
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://finjan.webex.com/client/v_mywebex-t…bex/ieatgpc.cab
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetup Control) - https://216.16.42.51/dana-cached/setup/JuniperSetup.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{463477A3-3C65-4DE6-83BC-26DDA4AF0B31}: NameServer = 192.168.3.5
O20 - AppInit_DLLs: tuohey.dll
O20 - Winlogon Notify: ssqPjjgg - C:\WINDOWS\SYSTEM32\ssqPjjgg.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Juniper Network Connect Service (dsNcService) - Juniper Networks - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: VNC Server (winvnc) - AT&T Research Labs Cambridge - C:\Program Files\ORL\VNC\WinVNC.exe

–
End of file - 8787 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Email Projector Schedule.job
C:\WINDOWS\tasks\Restart.job
C:\WINDOWS\tasks\Schedule Task Weekly.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{393B9CD9-A700-41FE-8942-666E22E42C17}]
C:\WINDOWS\System32\jkkLCvts.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3BFFA4A4-6F01-43AC-8232-F3B899BC97D6}]
C:\WINDOWS\system32\vtUolIyA.dll [2008-10-13 317440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3DC8CA1D-D31A-474b-979A-A3823FA34ED8}]
pl - C:\WINDOWS\System32\dccplus.dll [2008-08-28 22016]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9E91EF7B-6846-45C3-A8AB-67CF7C900783}]
C:\WINDOWS\System32\ssqPjjgg.dll [2008-10-10 104448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e863cada-8c07-4316-974a-ece15d00989d}]
C:\WINDOWS\system32\tuohey.dll []

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"BluetoothAuthenticationAgent"=C:\WINDOWS\system32\irprops.cpl [2004-08-04 380416]
"IgfxTray"=C:\WINDOWS\System32\igfxtray.exe [2003-07-10 155648]
"HotKeysCmds"=C:\WINDOWS\System32\hkcmd.exe [2003-07-10 114688]
"tgcmd"= []
"UC_Start"=C:\IBMTools\Updater\ucstartup.exe [2003-03-17 32768]
"Mouse Suite 98 Daemon"=C:\WINDOWS\system32\ICO.EXE [2003-11-20 57344]
"WinVNC"=C:\Program Files\ORL\VNC\WinVNC.exe [2000-05-23 208896]
"LogitechVideoRepair"=C:\Program Files\Logitech\Video\ISStart.exe [2004-02-12 188416]
"LogitechVideoTray"=C:\Program Files\Logitech\Video\LogiTray.exe [2004-02-12 77824]
"UpdateManager"=C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe [2003-08-19 110592]
"PRONoMgr.exe"=C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe [2003-03-11 86016]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2006-07-21 282624]
"UMonit"=C:\WINDOWS\System32\umonit.exe [2004-01-05 53248]
"ToolExe"=c:\program files\dell\traytool.exe [2003-04-18 180224]
"UnlockerAssistant"=C:\Program Files\Unlocker\UnlockerAssistant.exe [2006-09-07 15872]
"ccApp"=C:\Program Files\Common Files\Symantec Shared\ccApp.exe [2005-04-08 48752]
"vptray"=C:\PROGRA~1\SYMANT~1\VPTray.exe [2005-04-17 85184]
"NvCplDaemon"=C:\WINDOWS\System32\NvCpl.dll [2005-07-20 7110656]
"NvMediaCenter"=C:\WINDOWS\System32\NvMcTray.dll [2005-07-20 86016]
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]
"fc6d3a34"=C:\WINDOWS\system32\hxubjduq.dll []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"=C:\Program Files\MSN Messenger\MsnMsgr.Exe [2007-01-19 5674352]
"tgcmd"= []
"Spark"=C:\Program Files\Spark\Spark.exe []
"updateMgr"=C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe [2006-03-30 313472]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
APC UPS Status.lnk - C:\Program Files\APC\APC PowerChute Personal Edition\Display.exe

C:\Documents and Settings\rstone\Start Menu\Programs\Startup
Launch Microsoft Office Outlook.lnk - C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="tuohey.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxsrvc.dll [2003-07-10 319488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon]
C:\WINDOWS\System32\NavLogon.dll [2005-04-17 43712]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssqPjjgg]
C:\WINDOWS\system32\ssqPjjgg.dll [2008-10-10 104448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{9E91EF7B-6846-45C3-A8AB-67CF7C900783}"=C:\WINDOWS\System32\ssqPjjgg.dll [2008-10-10 104448]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
C:\WINDOWS\system32\vtUolIyA

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"ForceStartMenuLogOff"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

======File associations======

.js - edit - C:\WINDOWS\System32\Notepad.exe %1
.js - open - C:\WINDOWS\System32\WScript.exe "%1" %*
.vbs - edit - C:\WINDOWS\System32\Notepad.exe %1
.vbs - open - C:\WINDOWS\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2008-10-13 13:48:09 —-A—- C:\WINDOWS\system32\f74efe4a-.txt
2008-10-13 13:47:57 —-ASH—- C:\WINDOWS\system32\AyIloUtv.ini2
2008-10-13 13:47:57 —-ASH—- C:\WINDOWS\system32\AyIloUtv.ini
2008-10-13 13:47:51 —-A—- C:\WINDOWS\system32\vtUolIyA.dll
2008-10-13 13:29:59 —-D—- C:\rsit
2008-10-13 13:20:43 —-D—- C:\_OTMoveIt
2008-10-13 13:02:32 —-A—- C:\lopR.txt
2008-10-13 13:01:57 —-D—- C:\Lop SD
2008-10-13 11:41:53 —-D—- C:\WINDOWS\Prefetch
2008-10-13 11:38:30 —-HDC—- C:\WINDOWS\$NtUninstallKB912919$
2008-10-13 11:37:50 —-HDC—- C:\WINDOWS\$NtUninstallKB910437$
2008-10-13 11:37:01 —-HDC—- C:\WINDOWS\$NtUninstallKB908519$
2008-10-13 11:36:29 —-HDC—- C:\WINDOWS\$NtUninstallKB905749$
2008-10-13 11:35:53 —-HDC—- C:\WINDOWS\$NtUninstallKB905414$
2008-10-13 11:34:54 —-HDC—- C:\WINDOWS\$NtUninstallKB902400$
2008-10-13 11:33:16 —-HDC—- C:\WINDOWS\$NtUninstallKB901214$
2008-10-13 11:32:33 —-HDC—- C:\WINDOWS\$NtUninstallKB901017$
2008-10-13 11:31:59 —-HDC—- C:\WINDOWS\$NtUninstallKB900725$
2008-10-13 11:31:26 —-HDC—- C:\WINDOWS\$NtUninstallKB899591$
2008-10-13 11:30:55 —-HDC—- C:\WINDOWS\$NtUninstallKB899589$
2008-10-13 11:30:23 —-HDC—- C:\WINDOWS\$NtUninstallKB899587$
2008-10-13 11:29:50 —-HDC—- C:\WINDOWS\$NtUninstallKB896428$
2008-10-13 11:29:13 —-HDC—- C:\WINDOWS\$NtUninstallKB896424$
2008-10-13 11:28:41 —-HDC—- C:\WINDOWS\$NtUninstallKB896423$
2008-10-13 11:28:08 —-HDC—- C:\WINDOWS\$NtUninstallKB896422$
2008-10-13 11:27:35 —-HDC—- C:\WINDOWS\$NtUninstallKB896358$
2008-10-13 11:27:01 —-HDC—- C:\WINDOWS\$NtUninstallKB893756$
2008-10-13 11:26:27 —-HDC—- C:\WINDOWS\$NtUninstallKB893066$
2008-10-13 11:25:54 —-HDC—- C:\WINDOWS\$NtUninstallKB891781$
2008-10-13 11:25:17 —-HDC—- C:\WINDOWS\$NtUninstallKB890859$
2008-10-13 11:24:41 —-HDC—- C:\WINDOWS\$NtUninstallKB890046$
2008-10-13 11:24:04 —-HDC—- C:\WINDOWS\$NtUninstallKB888302$
2008-10-13 11:23:24 —-HDC—- C:\WINDOWS\$NtUninstallKB888113$
2008-10-13 11:22:53 —-HDC—- C:\WINDOWS\$NtUninstallKB885836$
2008-10-13 11:22:20 —-HDC—- C:\WINDOWS\$NtUninstallKB885835$
2008-10-13 11:21:41 —-HDC—- C:\WINDOWS\$NtUninstallKB873339$
2008-10-13 11:17:42 —-A—- C:\WINDOWS\system32\wmpns.dll
2008-10-13 11:15:32 —-A—- C:\WINDOWS\system32\comsdupd.exe
2008-10-13 11:15:23 —-A—- C:\WINDOWS\system32\ati3d1ag.dll
2008-10-13 11:15:23 —-A—- C:\WINDOWS\system32\ati2dvag.dll
2008-10-13 11:15:23 —-A—- C:\WINDOWS\system32\ati2dvaa.dll
2008-10-13 11:15:23 —-A—- C:\WINDOWS\system32\ati2cqag.dll
2008-10-13 11:15:22 —-A—- C:\WINDOWS\system32\cmsetacl.dll
2008-10-13 11:15:22 —-A—- C:\WINDOWS\system32\btpanui.dll
2008-10-13 11:15:22 —-A—- C:\WINDOWS\system32\blastcln.exe
2008-10-13 11:15:22 —-A—- C:\WINDOWS\system32\auditusr.exe
2008-10-13 11:15:22 —-A—- C:\WINDOWS\system32\ativvaxx.dll
2008-10-13 11:15:22 —-A—- C:\WINDOWS\system32\ativtmxx.dll
2008-10-13 11:15:22 —-A—- C:\WINDOWS\system32\ati3duag.dll
2008-10-13 11:15:21 —-A—- C:\WINDOWS\system32\ieencode.dll
2008-10-13 11:15:21 —-A—- C:\WINDOWS\system32\httpapi.dll
2008-10-13 11:15:21 —-A—- C:\WINDOWS\system32\hsfcisp2.dll
2008-10-13 11:15:21 —-A—- C:\WINDOWS\system32\fwcfg.dll
2008-10-13 11:15:21 —-A—- C:\WINDOWS\system32\fsquirt.exe
2008-10-13 11:15:21 —-A—- C:\WINDOWS\system32\fltmc.exe
2008-10-13 11:15:21 —-A—- C:\WINDOWS\system32\fltlib.dll
2008-10-13 11:15:21 —-A—- C:\WINDOWS\system32\extmgr.dll
2008-10-13 11:15:20 —-A—- C:\WINDOWS\system32\mdmxsdk.dll
2008-10-13 11:15:20 —-A—- C:\WINDOWS\system32\kbdukx.dll
2008-10-13 11:15:20 —-A—- C:\WINDOWS\system32\kbdsmsno.dll
2008-10-13 11:15:20 —-A—- C:\WINDOWS\system32\kbdsmsfi.dll
2008-10-13 11:15:20 —-A—- C:\WINDOWS\system32\kbdno1.dll
2008-10-13 11:15:20 —-A—- C:\WINDOWS\system32\kbdmlt48.dll
2008-10-13 11:15:20 —-A—- C:\WINDOWS\system32\kbdmlt47.dll
2008-10-13 11:15:20 —-A—- C:\WINDOWS\system32\kbdmaori.dll
2008-10-13 11:15:20 —-A—- C:\WINDOWS\system32\kbdinmal.dll
2008-10-13 11:15:20 —-A—- C:\WINDOWS\system32\kbdinben.dll
2008-10-13 11:15:20 —-A—- C:\WINDOWS\system32\kbdinbe1.dll
2008-10-13 11:15:20 —-A—- C:\WINDOWS\system32\kbdfi1.dll
2008-10-13 11:15:19 —-A—- C:\WINDOWS\system32\s3gnb.dll
2008-10-13 11:15:19 —-A—- C:\WINDOWS\system32\powercfg.exe
2008-10-13 11:15:19 —-A—- C:\WINDOWS\system32\pnrpnsp.dll
2008-10-13 11:15:19 —-A—- C:\WINDOWS\system32\p2psvc.dll
2008-10-13 11:15:19 —-A—- C:\WINDOWS\system32\p2pnetsh.dll
2008-10-13 11:15:19 —-A—- C:\WINDOWS\system32\p2pgraph.dll
2008-10-13 11:15:19 —-A—- C:\WINDOWS\system32\p2pgasvc.dll
2008-10-13 11:15:19 —-A—- C:\WINDOWS\system32\p2p.dll
2008-10-13 11:15:19 —-A—- C:\WINDOWS\system32\mtxparhd.dll
2008-10-13 11:15:19 —-A—- C:\WINDOWS\system32\msdadiag.dll
2008-10-13 11:15:18 —-A—- C:\WINDOWS\system32\wscsvc.dll
2008-10-13 11:15:18 —-A—- C:\WINDOWS\system32\wscntfy.exe
2008-10-13 11:15:18 —-A—- C:\WINDOWS\system32\winshfhc.dll
2008-10-13 11:15:18 —-A—- C:\WINDOWS\system32\w3ssl.dll
2008-10-13 11:15:18 —-A—- C:\WINDOWS\system32\twext.dll
2008-10-13 11:15:18 —-A—- C:\WINDOWS\system32\strmfilt.dll
2008-10-13 11:15:18 —-A—- C:\WINDOWS\system32\smbinst.exe
2008-10-13 11:15:18 —-A—- C:\WINDOWS\system32\slserv.exe
2008-10-13 11:15:18 —-A—- C:\WINDOWS\system32\slrundll.exe
2008-10-13 11:15:18 —-A—- C:\WINDOWS\system32\slgen.dll
2008-10-13 11:15:18 —-A—- C:\WINDOWS\system32\slextspk.dll
2008-10-13 11:15:18 —-A—- C:\WINDOWS\system32\slcoinst.dll
2008-10-13 11:15:18 —-A—- C:\WINDOWS\system32\sdhcinst.dll
2008-10-13 11:15:17 —-N—- C:\WINDOWS\slrundll.exe
2008-10-13 11:15:17 —-A—- C:\WINDOWS\system32\xmlprovi.dll
2008-10-13 11:15:17 —-A—- C:\WINDOWS\system32\xmlprov.dll
2008-10-13 11:15:16 —-D—- C:\WINDOWS\peernet
2008-10-13 11:15:15 —-D—- C:\WINDOWS\provisioning
2008-10-13 11:12:23 —-D—- C:\WINDOWS\ServicePackFiles
2008-10-13 11:08:16 —-A—- C:\WINDOWS\002424_.tmp
2008-10-13 11:05:19 —-HDC—- C:\WINDOWS\$NtServicePackUninstall$
2008-10-13 11:05:07 —-D—- C:\WINDOWS\EHome
2008-10-13 10:25:58 —-D—- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-10-13 10:25:55 —-D—- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2008-10-13 07:42:52 —-A—- C:\freespace.txt
2008-10-12 10:09:23 —-D—- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-10-10 14:57:34 —-A—- C:\WINDOWS\system32\ssqPjjgg.dll
2008-09-22 10:02:06 —-D—- C:\Documents and Settings\rstone\Application Data\U3

======List of files/folders modified in the last 1 months======

2008-10-13 13:48:09 —-AD—- C:\WINDOWS\system32
2008-10-13 13:45:36 —-D—- C:\WINDOWS\Temp
2008-10-13 13:42:46 —-D—- C:\Program Files\Symantec AntiVirus
2008-10-13 13:42:25 —-AD—- C:\WINDOWS
2008-10-13 13:40:48 —-A—- C:\WINDOWS\SchedLgU.Txt
2008-10-13 13:34:46 —-D—- C:\ACT Databases
2008-10-13 13:27:06 —-A—- C:\WINDOWS\system32\PerfStringBackup.INI
2008-10-13 13:26:40 —-SHD—- C:\WINDOWS\Installer
2008-10-13 13:26:37 —-HD—- C:\Config.Msi
2008-10-13 13:26:25 —-D—- C:\Program Files\MSN Messenger
2008-10-13 13:24:16 —-D—- C:\WINDOWS\Debug
2008-10-13 13:20:44 —-SD—- C:\WINDOWS\Tasks
2008-10-13 12:17:35 —-D—- C:\Program Files\PokerStars
2008-10-13 11:47:27 —-SD—- C:\Documents and Settings\rstone\Application Data\Microsoft
2008-10-13 11:44:49 —-A—- C:\WINDOWS\OEWABLog.txt
2008-10-13 11:43:37 —-D—- C:\WINDOWS\system32\inetsrv
2008-10-13 11:42:56 —-D—- C:\WINDOWS\system32\wbem
2008-10-13 11:42:42 —-D—- C:\WINDOWS\system32\CatRoot2
2008-10-13 11:42:38 —-HD—- C:\WINDOWS\inf
2008-10-13 11:42:19 —-A—- C:\WINDOWS\setuplog.txt
2008-10-13 11:41:10 —-SHD—- C:\System Volume Information
2008-10-13 11:41:01 —-D—- C:\WINDOWS\msagent
2008-10-13 11:41:00 —-D—- C:\WINDOWS\AppPatch
2008-10-13 11:41:00 —-D—- C:\Program Files\Internet Explorer
2008-10-13 11:40:55 —-RSD—- C:\WINDOWS\Fonts
2008-10-13 11:40:30 —-D—- C:\WINDOWS\system32\drivers
2008-10-13 11:39:11 —-A—- C:\WINDOWS\imsins.BAK
2008-10-13 11:38:50 —-D—- C:\WINDOWS\system32\CatRoot
2008-10-13 11:35:34 —-D—- C:\WINDOWS\system32\Com
2008-10-13 11:17:45 —-RASH—- C:\BOOT.INI
2008-10-13 11:16:45 —-D—- C:\WINDOWS\security
2008-10-13 11:15:46 —-D—- C:\WINDOWS\WinSxS
2008-10-13 11:15:40 —-D—- C:\Program Files\Messenger
2008-10-13 11:15:32 —-D—- C:\WINDOWS\system32\Setup
2008-10-13 11:15:32 —-D—- C:\WINDOWS\Help
2008-10-13 11:15:31 —-D—- C:\WINDOWS\ime
2008-10-13 11:15:17 —-D—- C:\Program Files\Windows Media Player
2008-10-13 11:15:17 —-AD—- C:\WINDOWS\system32\oobe
2008-10-13 11:15:16 —-D—- C:\Program Files\Movie Maker
2008-10-13 11:15:15 —-D—- C:\WINDOWS\Media
2008-10-13 11:12:03 —-D—- C:\WINDOWS\system32\Restore
2008-10-13 11:12:02 —-D—- C:\WINDOWS\system32\npp
2008-10-13 11:12:02 —-D—- C:\WINDOWS\mui
2008-10-13 11:11:56 —-D—- C:\WINDOWS\srchasst
2008-10-13 11:11:55 —-D—- C:\Program Files\NetMeeting
2008-10-13 11:11:49 —-D—- C:\Program Files\Windows NT
2008-10-13 11:11:49 —-D—- C:\Program Files\Outlook Express
2008-10-13 11:11:41 —-D—- C:\Program Files\Common Files\System
2008-10-13 11:11:26 —-D—- C:\WINDOWS\system32\usmt
2008-10-13 11:11:24 —-D—- C:\WINDOWS\system
2008-10-13 11:09:28 —-RD—- C:\WINDOWS\Web
2008-10-13 11:09:01 —-RASH—- C:\NTDETECT.COM
2008-10-13 11:08:56 —-RSHD—- C:\WINDOWS\system32\dllcache
2008-10-13 11:08:15 —-D—- C:\WINDOWS\system32\ReinstallBackups
2008-10-13 10:54:40 —-SD—- C:\WINDOWS\Downloaded Program Files
2008-10-13 10:35:07 —-D—- C:\WINDOWS\system32\config
2008-10-13 10:34:58 —-D—- C:\WINDOWS\Registration
2008-10-13 09:48:35 —-A—- C:\WINDOWS\ntbtlog.txt
2008-10-12 10:09:52 —-D—- C:\Program Files\Lavasoft
2008-10-12 10:09:50 —-SD—- C:\Documents and Settings\All Users\Application Data\Microsoft
2008-10-12 10:09:50 —-D—- C:\Documents and Settings\rstone\Application Data\Lavasoft
2008-10-12 10:08:33 —-D—- C:\Program Files\Common Files\Wise Installation Wizard
2008-10-10 15:24:26 —-D—- C:\Program Files\Spybot - Search & Destroy
2008-10-10 08:23:09 —-D—- C:\Documents and Settings\rstone\Application Data\VMware
2008-10-08 09:31:51 —-A—- C:\WINDOWS\fsmss.ini
2008-10-06 08:36:36 —-D—- C:\fsuser
2008-09-24 16:03:46 —-D—- C:\Program Files\Spark
2008-09-23 09:08:20 —-A—- C:\Phonelog.txt

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys []
R1 intelppm;Intel Processor Driver; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2004-08-03 36096]
R1 SAVRT;SAVRT; \??\C:\Program Files\Symantec AntiVirus\savrt.sys []
R1 SAVRTPEL;SAVRTPEL; \??\C:\Program Files\Symantec AntiVirus\Savrtpel.sys []
R1 SYMTDI;SYMTDI; \??\C:\WINDOWS\System32\Drivers\SYMTDI.SYS []
R2 EGATHDRV;IBM Access Support; \??\C:\WINDOWS\SYSTEM32\EGATHDRV.SYS []
R2 PMEM;PMEM; \??\C:\WINDOWS\system32\drivers\PMEMNT.SYS []
R2 Ynsernet;Ynsernet; C:\WINDOWS\system32\drivers\Ynsernet.sys [2002-08-19 59736]
R3 {6080A529-897E-4629-A488-ABA0C29B635E};Intel® Graphics Platform (SoftBIOS) Driver; C:\WINDOWS\system32\drivers\ialmsbw.sys [2003-07-22 120062]
R3 {D31A0762-0CEB-444e-ACFF-B049A1F6FE91};Intel® Graphics Chipset (KCH) Driver; C:\WINDOWS\system32\drivers\ialmkchw.sys [2003-07-22 96858]
R3 aeaudio;aeaudio; C:\WINDOWS\system32\drivers\aeaudio.sys [2002-08-22 98752]
R3 dsNcAdpt;Juniper Network Connect Adapter; C:\WINDOWS\System32\DRIVERS\dsNcAdpt.sys [2005-11-09 23552]
R3 E100B;Intel® PRO Adapter Driver; C:\WINDOWS\System32\DRIVERS\e100b325.sys [2003-03-04 145408]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2001-08-17 9600]
R3 ialm;ialm; C:\WINDOWS\System32\DRIVERS\ialmnt5.sys [2003-07-22 91419]
R3 NAVENG;NAVENG; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20081011.003\naveng.sys []
R3 NAVEX15;NAVEX15; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20081011.003\navex15.sys []
R3 nv;nv; C:\WINDOWS\System32\DRIVERS\nv4_mini.sys [2005-07-20 3198368]
R3 pepifilter;Volume Adapter; C:\WINDOWS\System32\DRIVERS\lv302af.sys [2004-01-20 5915]
R3 PID_08A0;Labtec WebCam Pro(PID_08A0); C:\WINDOWS\System32\DRIVERS\LV302AV.SYS [2004-01-20 271360]
R3 smwdm;smwdm; C:\WINDOWS\system32\drivers\smwdm.sys [2002-11-25 537152]
R3 SYMREDRV;SYMREDRV; \??\C:\WINDOWS\System32\Drivers\SYMREDRV.SYS []
R3 usbaudio;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-03 59264]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2004-08-03 31616]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2004-08-03 26624]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2004-08-03 20480]
R4 SymEvent;SymEvent; \??\C:\Program Files\Symantec\SYMEVENT.SYS []
S2 Aspi32;Aspi32; C:\WINDOWS\System32\drivers\aspi32.sys []
S3 ac97intc;Intel® 82801 Audio Driver Install Service (WDM); C:\WINDOWS\system32\drivers\ac97intc.sys [2001-08-17 96256]
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 EraserUtilDrvI7;EraserUtilDrvI7; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrvI7.sys []
S3 fixustor;fixustor; C:\WINDOWS\system32\drivers\fixustor.sys [2004-01-05 6016]
S3 HidBatt;HID UPS Battery Driver; C:\WINDOWS\System32\DRIVERS\HidBatt.sys [2001-08-17 19200]
S3 mouhid;Mouse HID Driver; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-08-17 12160]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\System32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 nm;Network Monitor Driver; C:\WINDOWS\System32\DRIVERS\NMnt.sys [2004-08-03 40320]
S3 NPF;NetGroup Packet Filter Driver; C:\WINDOWS\system32\drivers\npf.sys [2007-11-06 34064]
S3 pelmouse;Mouse Suite Driver; C:\WINDOWS\System32\DRIVERS\pelmouse.sys [2003-01-10 16384]
S3 pelusblf;USB Mouse Low Filter Driver; C:\WINDOWS\System32\DRIVERS\pelusblf.sys [2003-02-11 9216]
S3 psadd;IBM PSA Access Driver; \??\C:\WINDOWS\system32\Drivers\psadd.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\System32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 SPBBCDrv;SPBBCDrv; \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys []
S3 streamip;BDA IPSink; C:\WINDOWS\System32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 tgiul50;tgiul50; C:\WINDOWS\System32\DRIVERS\tgiulnt5.sys [2001-08-17 138528]
S3 TVICHW32;TVICHW32; \??\C:\WINDOWS\System32\DRIVERS\TVICHW32.SYS []
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\System32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\System32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S4 agp440;Intel AGP Bus Filter; C:\WINDOWS\System32\DRIVERS\agp440.sys [2004-08-03 42368]
S4 agpCPQ;Compaq AGP Bus Filter; C:\WINDOWS\System32\DRIVERS\agpCPQ.sys [2004-08-03 44928]
S4 alim1541;ALI AGP Bus Filter; C:\WINDOWS\System32\DRIVERS\alim1541.sys [2004-08-03 42752]
S4 amdagp;AMD AGP Bus Filter Driver; C:\WINDOWS\System32\DRIVERS\amdagp.sys [2004-08-03 43008]
S4 cbidf;cbidf; C:\WINDOWS\System32\DRIVERS\cbidf2k.sys [2001-08-17 13952]
S4 IntelIde;IntelIde; C:\WINDOWS\System32\DRIVERS\intelide.sys [2004-08-03 5504]
S4 sisagp;SIS AGP Bus Filter; C:\WINDOWS\System32\DRIVERS\sisagp.sys [2004-08-03 41088]
S4 viaagp;VIA AGP Bus Filter; C:\WINDOWS\System32\DRIVERS\viaagp.sys [2004-08-03 42240]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2008-10-12 611664]
R2 APC UPS Service;APC UPS Service; C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe [2005-12-12 176193]
R2 ccEvtMgr;Symantec Event Manager; C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe [2005-04-08 185968]
R2 ccSetMgr;Symantec Settings Manager; C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe [2005-04-08 161392]
R2 DefWatch;Symantec AntiVirus Definition Watcher; C:\Program Files\Symantec AntiVirus\DefWatch.exe [2005-04-17 19648]
R2 dsNcService;Juniper Network Connect Service; C:\Program Files\Juniper Networks\Common Files\dsNcService.exe [2005-11-09 335872]
R2 LexBceS;LexBce Server; C:\WINDOWS\system32\LEXBCES.EXE [2003-04-18 286720]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\System32\nvsvc32.exe [2005-07-20 127043]
R2 SoundMAX Agent Service (default);SoundMAX Agent Service; C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe [2002-09-20 45056]
R2 Symantec AntiVirus;Symantec AntiVirus; C:\Program Files\Symantec AntiVirus\Rtvscan.exe [2005-04-17 1706176]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\System32\wdfmgr.exe [2004-09-22 38912]
R2 winvnc;VNC Server; C:\Program Files\ORL\VNC\WinVNC.exe [2000-05-23 208896]
R3 usnjsvc;Messenger Sharing Folders USN Journal Reader service; C:\Program Files\MSN Messenger\usnsvc.exe [2007-01-19 97136]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2003-02-20 32768]
S3 ccPwdSvc;Symantec Password Validation; C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe [2005-04-08 83568]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 NetSvc;Intel NCS NetService; C:\Program Files\Intel\NCS\Sync\NetSvc.exe [2003-03-03 143360]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 PsaSrv;IBM PSA Access Driver Control; C:\WINDOWS\system32\PsaSrv.exe [2002-08-12 26624]
S3 rpcapd;Remote Packet Capture Protocol v.0 (experimental); C:\Program Files\WinPcap\rpcapd.exe [2007-11-06 92792]
S3 SavRoam;SAVRoam; C:\Program Files\Symantec AntiVirus\SavRoam.exe [2005-04-17 124608]
S3 SNDSrvc;Symantec Network Drivers Service; C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe [2005-04-05 206552]
S3 SPBBCSvc;Symantec SPBBCSvc; C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe [2005-03-30 992864]

—————–EOF—————–

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI