This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Baseline

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi I have problems with my PC due to some annoying pop up's offering ie. some free Antivirus 2009. I know this is some malware that has been infected my pc. I have scanned and removed files and registry entries with AD-aware - Windows Defender and Malwarebytes without success. Attached is is the logfiles from Hijackthis and Malwarebytes. Can someone help? Thanks in advance
Don't attach the logs

Disable resident protections (Antivirus…); you'll re-enable them after the scan

Download Lop S&D < here

Double-click Lop S&D.exe
Choose the language, then choose Option 1 (Search)
Wait till the end of the scan
Post the log which is created: (%SystemDrive%\lopR.txt)
——————–\\ Lop S&D 4.2.4-5 XP/Vista

Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 2
X86-based PC ( Multiprocessor Free : Intel® Core™2 CPU T7200 @ 2.00GHz )
BIOS : Default System BIOS
USER : a683791 ( Not Administrator ! )
BOOT : Normal boot
Antivirus : Symantec AntiVirus Corporate Edition 10.1.5.5010 (Not Activated)
Firewall : Symantec Client Firewall 8.7.4.104 (Not Activated)
C:\ (Local Disk) - NTFS - Total : 74 Go Free : 62 Go
D:\ (CD or DVD)

"C:\Lop SD" ( MAJ : 02-10-2008|23:42 )
Option : [1] ( 2008-10-15|21:22 )

——————–\\ Listing folders in APPLIC~1

[2008-10-14|09:11] C:\DOCUME~1\a683791\APPLIC~1\Adobe
[2007-08-10|02:41] C:\DOCUME~1\a683791\APPLIC~1\Ahead
[2007-08-10|02:03] C:\DOCUME~1\a683791\APPLIC~1\ATI
[2008-08-31|20:22] C:\DOCUME~1\a683791\APPLIC~1\Google
[2008-08-12|08:06] C:\DOCUME~1\a683791\APPLIC~1\Hydro
[2008-08-12|12:34] C:\DOCUME~1\a683791\APPLIC~1\ICAClient
[2007-08-09|02:31] C:\DOCUME~1\a683791\APPLIC~1\Identities
[2008-09-29|16:48] C:\DOCUME~1\a683791\APPLIC~1\InterVideo
[2008-08-21|12:54] C:\DOCUME~1\a683791\APPLIC~1\Juniper Networks
[2008-08-12|11:25] C:\DOCUME~1\a683791\APPLIC~1\Macromedia
[2008-10-14|09:30] C:\DOCUME~1\a683791\APPLIC~1\Malwarebytes
[2008-09-04|09:04] C:\DOCUME~1\a683791\APPLIC~1\Microsoft
[2008-08-12|11:41] C:\DOCUME~1\a683791\APPLIC~1\Nokia
[2008-08-12|11:41] C:\DOCUME~1\a683791\APPLIC~1\PC Suite
[2008-08-14|08:38] C:\DOCUME~1\a683791\APPLIC~1\Sun
[2008-08-12|22:37] C:\DOCUME~1\a683791\APPLIC~1\Webshots

[2007-08-10|02:41] C:\DOCUME~1\a715626\APPLIC~1\Ahead
[2007-08-10|02:03] C:\DOCUME~1\a715626\APPLIC~1\ATI
[2008-07-17|10:40] C:\DOCUME~1\a715626\APPLIC~1\Hydro
[2007-08-09|02:31] C:\DOCUME~1\a715626\APPLIC~1\Identities
[2007-08-09|21:08] C:\DOCUME~1\a715626\APPLIC~1\Microsoft

[2007-08-10|02:41] C:\DOCUME~1\a794220\APPLIC~1\Ahead
[2007-08-10|02:03] C:\DOCUME~1\a794220\APPLIC~1\ATI
[2008-07-17|10:01] C:\DOCUME~1\a794220\APPLIC~1\Hydro
[2007-08-09|02:31] C:\DOCUME~1\a794220\APPLIC~1\Identities
[2008-07-17|10:00] C:\DOCUME~1\a794220\APPLIC~1\Microsoft

[2007-08-10|02:41] C:\DOCUME~1\ADMINI~1\APPLIC~1\Ahead
[2007-08-10|02:03] C:\DOCUME~1\ADMINI~1\APPLIC~1\ATI
[2008-10-13|10:30] C:\DOCUME~1\ADMINI~1\APPLIC~1\Hydro
[2007-08-09|02:31] C:\DOCUME~1\ADMINI~1\APPLIC~1\Identities
[2008-10-13|10:47] C:\DOCUME~1\ADMINI~1\APPLIC~1\Malwarebytes
[2007-08-09|21:08] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft

[2008-07-17|10:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[2008-08-15|11:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\DVD Shrink
[2008-10-14|08:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\fkpshuri
[2008-08-29|22:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[2008-10-15|13:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google Updater
[2008-08-18|12:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Hewlett-Packard
[2008-07-17|10:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Hydro
[2008-08-26|07:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Installations
[2008-10-14|20:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
[2008-10-13|10:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[2008-10-14|08:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[2008-08-12|11:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PC Suite
[2008-08-12|08:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[2008-08-12|09:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TechSmith
[2007-08-09|20:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage

[2007-08-10|02:41] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Ahead
[2007-08-10|02:03] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ATI
[2007-08-09|02:31] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
[2007-08-09|21:08] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft

[2008-10-13|13:37] C:\DOCUME~1\LOCALS~1\APPLIC~1\Google
[2007-08-09|02:02] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

[2008-10-14|08:01] C:\DOCUME~1\NETWOR~1\APPLIC~1\Adobe
[2008-10-13|12:00] C:\DOCUME~1\NETWOR~1\APPLIC~1\Google
[2008-10-14|08:02] C:\DOCUME~1\NETWOR~1\APPLIC~1\Macromedia
[2007-08-09|02:02] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

——————–\\ Scheduled Tasks located in C:\WINDOWS\Tasks

[2008-10-15 17:39][–ah—–] C:\WINDOWS\tasks\MP Scheduled Scan.job
[2008-10-10 21:20][–a——] C:\WINDOWS\tasks\At24.job
[2008-10-15 07:26][–a——] C:\WINDOWS\tasks\At23.job
[2008-10-15 21:00][–a——] C:\WINDOWS\tasks\At22.job
[2008-10-15 20:00][–a——] C:\WINDOWS\tasks\At21.job
[2008-10-15 19:00][–a——] C:\WINDOWS\tasks\At20.job
[2008-10-15 18:00][–a——] C:\WINDOWS\tasks\At19.job
[2008-10-14 20:11][–a——] C:\WINDOWS\tasks\At18.job
[2008-10-14 16:00][–a——] C:\WINDOWS\tasks\At17.job
[2008-10-14 15:00][–a——] C:\WINDOWS\tasks\At16.job
[2008-10-15 14:00][–a——] C:\WINDOWS\tasks\At15.job
[2008-10-15 13:00][–a——] C:\WINDOWS\tasks\At14.job
[2008-10-15 12:00][–a——] C:\WINDOWS\tasks\At13.job
[2008-10-15 11:00][–a——] C:\WINDOWS\tasks\At12.job
[2008-10-15 10:00][–a——] C:\WINDOWS\tasks\At11.job
[2008-10-15 09:00][–a——] C:\WINDOWS\tasks\At10.job
[2008-10-10 21:20][–a——] C:\WINDOWS\tasks\At8.job
[2008-10-15 08:03][–a——] C:\WINDOWS\tasks\At9.job
[2008-10-10 21:20][–a——] C:\WINDOWS\tasks\At6.job
[2008-10-10 21:20][–a——] C:\WINDOWS\tasks\At7.job
[2008-10-10 21:20][–a——] C:\WINDOWS\tasks\At5.job
[2008-10-10 21:20][–a——] C:\WINDOWS\tasks\At4.job
[2008-10-10 21:20][–a——] C:\WINDOWS\tasks\At3.job
[2008-10-10 21:20][–a——] C:\WINDOWS\tasks\At2.job
[2008-10-10 21:20][–a——] C:\WINDOWS\tasks\At1.job
[2008-10-15 19:32][–a——] C:\WINDOWS\tasks\GoogleUpdateTaskUser.job
[2008-10-15 17:36][–ah—–] C:\WINDOWS\tasks\SA.DAT
[2004-08-04 14:00][-r-h—–] C:\WINDOWS\tasks\desktop.ini

——————–\\ Listing Folders in C:\Program Files

[2008-10-14|16:05] C:\Program Files\2321_Remote Access
[2008-09-16|11:35] C:\Program Files\Adobe
[2008-08-13|07:55] C:\Program Files\AR System
[2007-08-10|01:27] C:\Program Files\ATI Technologies
[2008-07-17|10:33] C:\Program Files\BinDFWS
[2008-09-19|12:11] C:\Program Files\Citrix
[2008-10-15|17:47] C:\Program Files\Clue
[2008-10-14|20:49] C:\Program Files\Common Files
[2007-08-09|01:59] C:\Program Files\ComPlus Applications
[2008-03-22|16:54] C:\Program Files\DIFX
[2008-08-15|11:19] C:\Program Files\DVD Shrink
[2008-10-13|10:46] C:\Program Files\ERUNT
[2007-08-09|20:39] C:\Program Files\Fujitsu
[2008-09-01|16:00] C:\Program Files\Google
[2008-10-15|14:36] C:\Program Files\Hijackthis
[2008-05-06|01:37] C:\Program Files\Hydro
[2008-08-13|07:54] C:\Program Files\InstallShield Installation Information
[2008-03-22|16:53] C:\Program Files\Intel
[2008-08-20|08:01] C:\Program Files\Internet Explorer
[2007-08-10|02:43] C:\Program Files\InterVideo
[2008-08-29|22:30] C:\Program Files\Java
[2008-07-17|10:36] C:\Program Files\JavaSoft
[2008-10-14|20:50] C:\Program Files\Lavasoft
[2008-07-17|10:44] C:\Program Files\Lotus
[2008-10-13|10:47] C:\Program Files\Malwarebytes' Anti-Malware
[2008-08-20|08:01] C:\Program Files\Messenger
[2008-07-17|10:09] C:\Program Files\Metro Extension Library
[2008-07-17|10:57] C:\Program Files\Microsoft ActiveSync
[2008-07-17|10:11] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2007-08-09|02:16] C:\Program Files\microsoft frontpage
[2008-08-12|09:24] C:\Program Files\Microsoft Office
[2008-07-17|11:03] C:\Program Files\Microsoft Works
[2008-07-17|10:55] C:\Program Files\Microsoft.NET
[2007-08-09|02:00] C:\Program Files\Movie Maker
[2008-08-12|11:30] C:\Program Files\MSBuild
[2008-07-17|11:08] C:\Program Files\MSECache
[2007-08-09|01:58] C:\Program Files\MSN
[2007-08-09|01:59] C:\Program Files\MSN Gaming Zone
[2007-09-14|04:48] C:\Program Files\MSXML 4.0
[2007-09-14|04:48] C:\Program Files\MSXML 6.0
[2007-08-10|02:37] C:\Program Files\Nero
[2008-08-19|12:04] C:\Program Files\NetMeeting
[2008-08-26|07:31] C:\Program Files\Nokia
[2008-08-12|08:11] C:\Program Files\Novadigm
[2007-08-10|01:45] C:\Program Files\O2Micro
[2007-08-10|01:37] C:\Program Files\O2Micro OZ711 SCR Driver
[2007-08-09|20:30] C:\Program Files\Online Services
[2007-08-09|02:00] C:\Program Files\Outlook Express
[2008-08-26|07:30] C:\Program Files\PC Connectivity Solution
[2008-08-12|11:28] C:\Program Files\Reference Assemblies
[2008-08-12|09:44] C:\Program Files\SAP
[2008-08-12|10:19] C:\Program Files\SapCommon
[2008-07-17|11:16] C:\Program Files\SGE440EN
[2008-07-17|10:09] C:\Program Files\Sun Java Runtime Environment
[2008-08-12|08:44] C:\Program Files\Symantec
[2008-08-12|08:43] C:\Program Files\Symantec AntiVirus
[2008-08-12|08:43] C:\Program Files\Symantec Client Security
[2007-08-09|03:43] C:\Program Files\Synaptics
[2008-08-12|09:17] C:\Program Files\TechSmith
[2008-03-22|18:41] C:\Program Files\Toshiba
[2008-08-15|10:59] C:\Program Files\Tracker Software
[2008-08-12|09:41] C:\Program Files\UltraEdit
[2007-08-09|02:31] C:\Program Files\Uninstall Information
[2008-07-17|11:24] C:\Program Files\Utimaco
[2008-08-15|08:11] C:\Program Files\VPN
[2008-08-12|22:37] C:\Program Files\Webshots
[2008-10-14|08:31] C:\Program Files\Windows Defender
[2007-08-09|02:22] C:\Program Files\Windows Media Connect 2
[2007-08-09|02:22] C:\Program Files\Windows Media Player
[2007-08-09|01:58] C:\Program Files\Windows NT
[2007-08-09|02:01] C:\Program Files\WindowsUpdate
[2007-08-09|02:16] C:\Program Files\xerox

——————–\\ Listing Folders in C:\Program Files\Common Files

[2008-09-16|11:35] C:\Program Files\Common Files\Adobe
[2007-08-10|02:41] C:\Program Files\Common Files\Ahead
[2008-08-13|07:54] C:\Program Files\Common Files\Crystal Decisions
[2008-07-17|10:57] C:\Program Files\Common Files\DESIGNER
[2008-08-19|08:42] C:\Program Files\Common Files\EMC
[2008-08-12|10:10] C:\Program Files\Common Files\ESRI
[2008-08-18|12:05] C:\Program Files\Common Files\Hewlett-Packard
[2008-08-13|07:54] C:\Program Files\Common Files\InstallShield
[2007-08-10|02:43] C:\Program Files\Common Files\InterVideo
[2008-08-29|22:29] C:\Program Files\Common Files\Java
[2008-08-12|09:25] C:\Program Files\Common Files\Microsoft Shared
[2007-08-09|02:00] C:\Program Files\Common Files\MSSoap
[2008-08-26|07:31] C:\Program Files\Common Files\Nokia
[2007-08-08|18:52] C:\Program Files\Common Files\ODBC
[2008-08-26|07:31] C:\Program Files\Common Files\PCSuite
[2008-08-12|10:19] C:\Program Files\Common Files\SAP Shared
[2007-08-09|02:00] C:\Program Files\Common Files\Services
[2007-08-08|18:52] C:\Program Files\Common Files\SpeechEngines
[2008-10-15|17:36] C:\Program Files\Common Files\Symantec Shared
[2007-08-09|01:59] C:\Program Files\Common Files\System
[2008-10-14|20:49] C:\Program Files\Common Files\Wise Installation Wizard

——————–\\ Process

( 88 Processes )

IEXPLORE.EXE ~ [PID:4780]
iexplore.exe ~ [PID:9108]

——————–\\ Searching with S_Lop

No Lop folder found !

——————–\\ Searching for Lop Files - Folders

C:\DOCUME~1\a683791\Cookies\a683791@advertising[1].txt
C:\DOCUME~1\a683791\Cookies\a683791@pacificpoker[1].txt
C:\DOCUME~1\a683791\Cookies\a683791@888[2].txt

——————–\\ Searching within the Registry

….. OK !

——————–\\ Checking the Hosts file

Hosts file CLEAN


——————–\\ Searching for hidden files with Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-15 21:29:27
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden files: 0

——————–\\ Searching for other infections

C:\WINDOWS\Tasks\At1.job
C:\WINDOWS\Tasks\At10.job
C:\WINDOWS\Tasks\At11.job
C:\WINDOWS\Tasks\At12.job
C:\WINDOWS\Tasks\At13.job
C:\WINDOWS\Tasks\At14.job
C:\WINDOWS\Tasks\At15.job
C:\WINDOWS\Tasks\At16.job
C:\WINDOWS\Tasks\At17.job
C:\WINDOWS\Tasks\At18.job
C:\WINDOWS\Tasks\At19.job
C:\WINDOWS\Tasks\At2.job
C:\WINDOWS\Tasks\At20.job
C:\WINDOWS\Tasks\At21.job
C:\WINDOWS\Tasks\At22.job
C:\WINDOWS\Tasks\At23.job
C:\WINDOWS\Tasks\At24.job
C:\WINDOWS\Tasks\At3.job
C:\WINDOWS\Tasks\At4.job
C:\WINDOWS\Tasks\At5.job
C:\WINDOWS\Tasks\At6.job
C:\WINDOWS\Tasks\At7.job
C:\WINDOWS\Tasks\At8.job
C:\WINDOWS\Tasks\At9.job

C:\WINDOWS\system32\JSAIknmp.ini
C:\WINDOWS\system32\JSAIknmp.ini2
==> VUNDO <==



[F:300][D:58]-> C:\WINDOWS\TEMP
[F:118][D:0]-> C:\DOCUME~1\a683791\Cookies
[F:3303][D:4]-> C:\DOCUME~1\a683791\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - 2008-10-15|21:32 - Option : [1]

——————–\\ Scan completed at 21:32:24
Hello

Please download the OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    
    :Files
    C:\WINDOWS\tasks\At*.job
    C:\WINDOWS\system32\JSAIknmp.ini
    C:\WINDOWS\system32\JSAIknmp.ini2
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.




  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<info.txt (<
========== PROCESSES ========== Process explorer.exe killed successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== C:\WINDOWS\tasks\At1.job moved successfully. C:\WINDOWS\tasks\At10.job moved successfully. C:\WINDOWS\tasks\At11.job moved successfully. C:\WINDOWS\tasks\At12.job moved successfully. C:\WINDOWS\tasks\At13.job moved successfully. C:\WINDOWS\tasks\At14.job moved successfully. C:\WINDOWS\tasks\At15.job moved successfully. C:\WINDOWS\tasks\At16.job moved successfully. C:\WINDOWS\tasks\At17.job moved successfully. C:\WINDOWS\tasks\At18.job moved successfully. C:\WINDOWS\tasks\At19.job moved successfully. C:\WINDOWS\tasks\At2.job moved successfully. C:\WINDOWS\tasks\At20.job moved successfully. C:\WINDOWS\tasks\At21.job moved successfully. C:\WINDOWS\tasks\At22.job moved successfully. C:\WINDOWS\tasks\At23.job moved successfully. C:\WINDOWS\tasks\At24.job moved successfully. C:\WINDOWS\tasks\At3.job moved successfully. C:\WINDOWS\tasks\At4.job moved successfully. C:\WINDOWS\tasks\At5.job moved successfully. C:\WINDOWS\tasks\At6.job moved successfully. C:\WINDOWS\tasks\At7.job moved successfully. C:\WINDOWS\tasks\At8.job moved successfully. C:\WINDOWS\tasks\At9.job moved successfully. File/Folder C:\WINDOWS\system32\JSAIknmp.ini not found. File/Folder C:\WINDOWS\system32\JSAIknmp.ini2 not found. ========== COMMANDS ========== File delete failed. C:\WINDOWS\TEMP\etilqs_5LNk5kdJiqzNYhO scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\TEMP\etilqs_iPd50vZ2o6dXag4 scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\TEMP\NGLALog.txt scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\TEMP\Perflib_Perfdata_118c.dat scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\TEMP\Perflib_Perfdata_540.dat scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\TEMP\Perflib_Perfdata_cc.dat scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\etilqs_5LNk5kdJiqzNYhO scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\etilqs_iPd50vZ2o6dXag4 scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\NGLALog.txt scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_118c.dat scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_540.dat scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_cc.dat scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. Temp folders emptied. Explorer started successfully OTMoveIt3 by OldTimer - Version 1.0.5.0 log created on 10152008_221737
Logfile of random's system information tool 1.04 (written by random/random)
Run by [removed] at 2008-10-16 07:44:04
Microsoft Windows XP Professional Service Pack 2
System drive C: has 65 GB (85%) free of 76 GB
Total RAM: 2046 MB (67% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 07:44:15, on 2008-10-16
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Lotus\Notes\nslsvice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\agrsmsvc.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\WINDOWS\system32\o2flash.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Novadigm\radexecd.exe
C:\Program Files\Novadigm\radsched.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Utimaco\SafeGuard Easy\SgeCtl.exe
C:\WINDOWS\system32\SgLogPlayer.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\Program Files\Utimaco\SafeGuard Easy\WksCfgSrv.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Lotus\Notes\NLNOTES.EXE
C:\Program Files\Lotus\Notes\ntaskldr.EXE
C:\Program Files\AR System\aruser.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\totalcmd\TOTALCMD.EXE
c:\Download\RSIT.exe
C:\Program Files\trend micro\a683791.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://inside.ispartner.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://inside.ispartner.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://inside.ispartner.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://inside.ispartner.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://proxycf.net.ispartner.com/pac
O2 - BHO: {40a906b8-ac8e-4b49-a3f4-414372c751a7} - {7a157c27-3414-4f3a-94b4-e8ca8b609a04} - C:\WINDOWS\system32\wnjnhq.dll
O2 - BHO: (no name) - {81236011-4154-4E9F-BE9A-A07B2DDCBB9B} - C:\WINDOWS\system32\awturSJa.dll
O2 - BHO: (no name) - {EC22E79C-7702-4C38-9691-C139D6C359C9} - C:\WINDOWS\system32\pmnoPgfc.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [IndicatorUtility] C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [PSUtility] C:\Program Files\Fujitsu\PSUtility\TrayManager.exe
O4 - HKLM\..\Run: [TvOutSwitch] C:\Program Files\Fujitsu\DispSwitch\DispSwitchLauncher.exe
O4 - HKLM\..\Run: [LoadFUJ02E3] C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe
O4 - HKLM\..\Run: [LoadFujitsuQuickTouch] C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe
O4 - HKLM\..\Run: [LoadBtnHnd] C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [RunOSSettings] C:\Program Files\Hydro\Image\2ndRegSett.vbs
O4 - HKLM\..\Run: [BinD Manager] C:\Program Files\Hydro\BinD\B_Manager\B_Manager.exe
O4 - HKLM\..\Run: [BinD Maintenance Run Scripts] C:\WINDOWS\system32\wscript.exe "C:\PROGRA~1\Hydro\BinD\B_RunHook.vbs"
O4 - HKLM\..\Run: [BinD Scheduler] "C:\PROGRA~1\Hydro\BinD\B_Sched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SgeEcView] "C:\Program Files\Utimaco\SafeGuard Easy\Ecview.exe"
O4 - HKLM\..\Run: [EdWizard] "C:\Program Files\Utimaco\SafeGuard Easy\EdWizard.exe" as
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~2\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [FFAKNNVF] %systemroot%\FFAKNNVF.exe
O4 - HKLM\..\Run: [bivfffcz] %systemroot%\bivfffcz.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [b4472bb5] rundll32.exe "C:\WINDOWS\system32\qhhkjwam.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe" /NoDialog
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\a683791\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'Default user')
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1189737859843
O16 - DPF: {759FD3DE-F0EF-4A76-909C-88CF840D4173} (DmDragDrop Class) - https://webtop.hda.hydro.com/webtop/wdk/nat…dkPluginCab.CAB
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl.sun.com/webapps/download/AutoDL?BundleId=23100
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) - https://isadmin.hydroispartner.com/dana-cac…perSetupSP1.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = adi.ispartner.com
O17 - HKLM\Software\..\Telephony: DomainName = adi.ispartner.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = adi.ispartner.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = adi.ispartner.com,ispartner.com,hydro.com,nh.ad.hydro.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = adi.ispartner.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = adi.ispartner.com,ispartner.com,hydro.com,nh.ad.hydro.com
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = adi.ispartner.com
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: SearchList = adi.ispartner.com,ispartner.com,hydro.com,nh.ad.hydro.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = adi.ispartner.com,ispartner.com,hydro.com,nh.ad.hydro.com
O20 - AppInit_DLLs: wnjnhq.dll
O20 - Winlogon Notify: FJWSEL - C:\WINDOWS\SYSTEM32\FJWSWNP.dll
O20 - Winlogon Notify: NotLog - C:\WINDOWS\SYSTEM32\SGLogEx.dll
O20 - Winlogon Notify: pmnoPgfc - C:\WINDOWS\SYSTEM32\pmnoPgfc.dll
O20 - Winlogon Notify: PSUTY - C:\WINDOWS\SYSTEM32\PSUWNP.dll
O20 - Winlogon Notify: SGLogNotification - C:\WINDOWS\SYSTEM32\SGLogNotification.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: IS Service (ISSVC) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Lotus Notes Single Logon - IBM Corp - C:\Program Files\Lotus\Notes\nslsvice.exe
O23 - Service: O2Micro Flash Memory (O2Flash) - O2Micro International - C:\WINDOWS\system32\o2flash.exe
O23 - Service: Radia Notify Daemon (radexecd) - Hewlett-Packard - C:\Program Files\Novadigm\radexecd.exe
O23 - Service: Radia Scheduler Daemon (radsched) - Hewlett-Packard - C:\Program Files\Novadigm\radsched.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SafeGuard Easy Control (SgeCtl) - Utimaco Safeware AG - C:\Program Files\Utimaco\SafeGuard Easy\SgeCtl.exe
O23 - Service: SafeGuard SGLOG Player (SgLogPlayer) - Utimaco Safeware AG - C:\WINDOWS\system32\SgLogPlayer.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Symantec SecurePort (SymSecurePort) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: SafeGuard Easy Workstation Server (WksCfgSrv) - Utimaco Safeware AG - C:\Program Files\Utimaco\SafeGuard Easy\WksCfgSrv.exe

–
End of file - 13036 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskUser.job
C:\WINDOWS\tasks\MP Scheduled Scan.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7a157c27-3414-4f3a-94b4-e8ca8b609a04}]
C:\WINDOWS\system32\wnjnhq.dll [2008-10-15 109056]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{81236011-4154-4E9F-BE9A-A07B2DDCBB9B}]
C:\WINDOWS\system32\awturSJa.dll [2008-10-15 267776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EC22E79C-7702-4C38-9691-C139D6C359C9}]
C:\WINDOWS\system32\pmnoPgfc.dll [2008-10-14 37376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - SnagIt - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll [2007-02-16 161352]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google; - c:\program files\google\googletoolbar2.dll [2008-08-31 2403392]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"=C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE [2004-08-04 208952]
"PHIME2002ASync"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2004-08-04 455168]
"PHIME2002A"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2004-08-04 455168]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2007-03-12 16125440]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2007-03-12 69632]
"AGRSMMSG"=C:\WINDOWS\AGRSMMSG.exe [2006-06-29 89541]
"IndicatorUtility"=C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe [2006-04-20 90112]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2007-07-12 794713]
"PSUtility"=C:\Program Files\Fujitsu\PSUtility\TrayManager.exe [2007-07-12 118784]
"TvOutSwitch"=C:\Program Files\Fujitsu\DispSwitch\DispSwitchLauncher.exe [2007-07-12 81920]
"LoadFUJ02E3"=C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe [2006-11-18 80688]
"LoadFujitsuQuickTouch"=C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe [2005-11-02 353792]
"LoadBtnHnd"=C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe [2005-11-02 61440]
"ATICCC"=C:\Program Files\ATI Technologies\ATI.ACE\cli.exe [2006-01-03 45056]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2006-01-13 155648]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2008-02-15 135168]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2008-02-15 159744]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2008-02-15 131072]
"MSPY2002"=C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe [2004-08-04 59392]
"RunOSSettings"=C:\Program Files\Hydro\Image\2ndRegSett.vbs [2006-08-10 1907]
"BinD Manager"=C:\Program Files\Hydro\BinD\B_Manager\B_Manager.exe [2007-03-19 20480]
"BinD Maintenance Run Scripts"=C:\WINDOWS\system32\wscript.exe [2004-08-04 114688]
"BinD Scheduler"=C:\PROGRA~1\Hydro\BinD\B_Sched.exe [2002-12-02 650752]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
"SgeEcView"=C:\Program Files\Utimaco\SafeGuard Easy\Ecview.exe [2007-09-05 24576]
"EdWizard"=C:\Program Files\Utimaco\SafeGuard Easy\EdWizard.exe [2007-09-05 245760]
"ccApp"=C:\Program Files\Common Files\Symantec Shared\ccApp.exe [2006-11-22 52840]
"vptray"=C:\PROGRA~1\SYMANT~2\SYMANT~1\VPTray.exe [2006-12-20 125632]
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]
"FFAKNNVF"=C:\WINDOWS\FFAKNNVF.exe []
"bivfffcz"=C:\WINDOWS\bivfffcz.exe []
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2006-11-03 866584]
"b4472bb5"=C:\WINDOWS\system32\qhhkjwam.dll [2008-10-15 71168]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360]
"PC Suite Tray"=C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe [2008-08-11 1124352]
"Nokia.PCSync"=C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe [2008-06-17 1249280]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-09-01 39408]
"Google Update"=C:\Documents and Settings\a683791\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-03 133104]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe

C:\Documents and Settings\a683791\Start Menu\Programs\Startup
Webshots.lnk - C:\Program Files\Webshots\Launcher.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="wnjnhq.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2007-08-10 61440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\FJWSEL]
C:\WINDOWS\system32\FJWSWNP.dll [2007-07-12 32768]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2008-02-15 208896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon]
C:\WINDOWS\system32\NavLogon.dll [2006-12-20 43712]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NotLog]
C:\WINDOWS\system32\SGLogEx.dll [2002-01-22 110592]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmnoPgfc]
C:\WINDOWS\system32\pmnoPgfc.dll [2008-10-14 37376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\PSUTY]
C:\WINDOWS\system32\PSUWNP.dll [2007-07-12 32768]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SGLogNotification]
C:\WINDOWS\system32\SGLogNotification.dll [2005-03-31 69632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2007-04-10 236928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-19 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{0574D50F-C261-490D-BF39-4E91183C4EFB}"= []
"{EC22E79C-7702-4C38-9691-C139D6C359C9}"=C:\WINDOWS\system32\pmnoPgfc.dll [2008-10-14 37376]
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"=C:\PROGRA~1\WIFD1F~1\MpShHook.dll [2006-11-03 83224]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
C:\WINDOWS\system32\awturSJa

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"NoDispScrSavPage"=0
"DisableTaskMgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"disablecad"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"ForceStartMenuLogOff"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Hydro\Image\GetSiteInfo\B_GetSiteInfo.exe"="C:\Program Files\Hydro\Image\GetSiteInfo\B_GetSiteInfo.exe:*:Enabled:B_GetSiteInfo Configuration Setting Utility"
"C:\Program Files\Hydro\Image\ntpdate.exe"="C:\Program Files\Hydro\Image\ntpdate.exe:*:Enabled:ntpdate"
"C:\Program Files\InterVideo\DVD7\WinDVD.exe"="C:\Program Files\InterVideo\DVD7\WinDVD.exe:*:Enabled:WinDVD"
"C:\Program Files\InterVideo\DVD8\WinDVD.exe"="C:\Program Files\InterVideo\DVD8\WinDVD.exe:*:Enabled:WinDVD"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======File associations======

.bat - edit - "C:\Program Files\UltraEdit\uedit32.exe" "%1"
.cmd - edit - "C:\Program Files\UltraEdit\uedit32.exe" "%1"
.inf - open - "C:\Program Files\UltraEdit\uedit32.exe" "%1"
.ini - open - notepad.exe %1
.reg - edit - "C:\Program Files\UltraEdit\uedit32.exe" "%1"
.txt - open - notepad.exe %1

======List of files/folders created in the last 1 months======

2008-10-16 07:44:05 —-D—- C:\Program Files\trend micro
2008-10-16 07:44:04 —-D—- C:\rsit
2008-10-15 22:17:37 —-D—- C:\_OTMoveIt
2008-10-15 21:57:37 —-A—- C:\WINDOWS\system32\wnjnhq.dll
2008-10-15 21:57:36 —-A—- C:\WINDOWS\system32\xaoawvju.dll
2008-10-15 21:55:19 —-SH—- C:\WINDOWS\system32\mawjkhhq.ini
2008-10-15 21:55:16 —-A—- C:\WINDOWS\system32\qhhkjwam.dll
2008-10-15 21:54:36 —-ASH—- C:\WINDOWS\system32\aJSrutwa.ini2
2008-10-15 21:54:36 —-ASH—- C:\WINDOWS\system32\aJSrutwa.ini
2008-10-15 21:54:32 —-A—- C:\WINDOWS\system32\awturSJa.dll
2008-10-15 21:21:55 —-A—- C:\lopR.txt
2008-10-15 21:21:12 —-D—- C:\Lop SD
2008-10-15 17:46:22 —-A—- C:\WINDOWS\system32\akchgl.dll
2008-10-15 17:46:21 —-A—- C:\WINDOWS\system32\gojcxhkj.dll
2008-10-15 14:07:19 —-D—- C:\Program Files\Hijackthis
2008-10-15 07:34:43 —-A—- C:\WINDOWS\system32\tpaylrvh.dll
2008-10-15 07:34:43 —-A—- C:\WINDOWS\system32\oegrjj.dll
2008-10-14 20:50:06 —-D—- C:\Program Files\Lavasoft
2008-10-14 20:50:06 —-D—- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-10-14 20:49:25 —-D—- C:\Program Files\Common Files\Wise Installation Wizard
2008-10-14 20:18:30 —-A—- C:\WINDOWS\system32\hdkxtc.dll
2008-10-14 20:18:29 —-A—- C:\WINDOWS\system32\lclcvsrq.dll
2008-10-14 12:43:12 —-ASH—- C:\WINDOWS\system32\thfwryvd.ini
2008-10-14 12:40:48 —-A—- C:\WINDOWS\system32\pvemwg.dll
2008-10-14 12:40:48 —-A—- C:\WINDOWS\system32\bgalxkua.dll
2008-10-14 11:53:23 —-D—- C:\WINDOWS\system32\%APPDATA%
2008-10-14 11:25:03 —-A—- C:\WINDOWS\system32\myumtr.dll
2008-10-14 11:25:02 —-A—- C:\WINDOWS\system32\lugfjvhk.dll
2008-10-14 09:37:23 —-A—- C:\WINDOWS\system32\hbbvzh.dll
2008-10-14 09:37:22 —-A—- C:\WINDOWS\system32\xrggvrtq.dll
2008-10-14 09:30:07 —-D—- C:\Documents and Settings\a683791\Application Data\Malwarebytes
2008-10-14 08:31:17 —-D—- C:\Program Files\Windows Defender
2008-10-14 08:31:08 —-A—- C:\WINDOWS\system32\zabhqd.dll
2008-10-14 08:31:07 —-A—- C:\WINDOWS\system32\ghmkgxfx.dll
2008-10-14 08:30:40 —-A—- C:\WINDOWS\system32\bf64efcb-.txt
2008-10-14 08:26:22 —-A—- C:\WINDOWS\system32\wini104552664.exe
2008-10-14 08:21:09 —-D—- C:\Documents and Settings\All Users\Application Data\fkpshuri
2008-10-14 08:20:44 —-A—- C:\WINDOWS\system32\pmnoPgfc.dll
2008-10-14 08:20:44 —-A—- C:\WINDOWS\system32\khfFUMGv.dll
2008-10-13 10:47:36 —-D—- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-13 10:47:36 —-D—- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-13 10:46:43 —-D—- C:\WINDOWS\ERDNT
2008-10-13 10:46:24 —-D—- C:\Program Files\ERUNT
2008-10-13 10:07:55 —-A—- C:\WINDOWS\VPC32.INI
2008-10-10 21:34:34 —-A—- C:\WINDOWS\ntbtlog.txt
2008-10-10 21:28:35 —-D—- C:\WINDOWS\Minidump
2008-10-10 21:21:07 —-A—- C:\WINDOWS\system32\isiefwfo.tmp
2008-10-10 21:20:35 —-A—- C:\WINDOWS\system32\4jQhIhF4.exe
2008-09-29 16:48:33 —-D—- C:\Documents and Settings\a683791\Application Data\InterVideo
2008-09-25 09:07:04 —-D—- C:\lotus
2008-09-23 07:30:38 —-HDC—- C:\WINDOWS\$NtUninstallKB954154_WM11$
2008-09-23 07:30:26 —-HDC—- C:\WINDOWS\$NtUninstallKB938464$

======List of files/folders modified in the last 1 months======

2008-10-16 07:44:05 —-RD—- C:\Program Files
2008-10-16 07:43:07 —-A—- C:\WINDOWS\wincmd.ini
2008-10-16 07:42:51 —-D—- C:\Download
2008-10-16 07:35:42 —-D—- C:\WINDOWS\Temp
2008-10-16 07:18:36 —-SD—- C:\WINDOWS\Tasks
2008-10-16 07:15:53 —-D—- C:\WINDOWS\security
2008-10-16 07:15:40 —-D—- C:\Program Files\Common Files\Symantec Shared
2008-10-15 22:30:57 —-A—- C:\WINDOWS\SchedLgU.Txt
2008-10-15 21:57:38 —-D—- C:\WINDOWS\Prefetch
2008-10-15 21:57:37 —-D—- C:\WINDOWS\system32
2008-10-15 21:52:01 —-A—- C:\BinD.mif.txt
2008-10-15 21:51:25 —-D—- C:\WINDOWS
2008-10-15 21:51:18 —-A—- C:\WINDOWS\Bridge.ini
2008-10-15 21:50:50 —-D—- C:\WINDOWS\system32\CatRoot2
2008-10-15 21:48:00 —-D—- C:\WINDOWS\system32\drivers
2008-10-15 17:47:31 —-D—- C:\Program Files\Clue
2008-10-15 17:41:03 —-A—- C:\BinD.mif.bak
2008-10-15 14:56:21 —-A—- C:\WINDOWS\Notes.ini
2008-10-15 13:45:02 —-D—- C:\Documents and Settings\All Users\Application Data\Google Updater
2008-10-14 20:50:49 —-SHD—- C:\WINDOWS\Installer
2008-10-14 20:49:25 —-D—- C:\Program Files\Common Files
2008-10-14 16:05:59 —-D—- C:\Program Files\2321_Remote Access
2008-10-14 12:36:51 —-SHD—- C:\System Volume Information
2008-10-14 12:36:51 —-D—- C:\WINDOWS\system32\Restore
2008-10-14 09:11:17 —-D—- C:\Documents and Settings\a683791\Application Data\Adobe
2008-10-14 08:31:18 —-HD—- C:\WINDOWS\inf
2008-10-14 08:31:17 —-SD—- C:\Documents and Settings\All Users\Application Data\Microsoft
2008-10-14 08:21:09 —-RSHDC—- C:\WINDOWS\system32\dllcache
2008-10-13 09:00:02 —-D—- C:\Tmp
2008-10-13 08:58:15 —-SHD—- C:\RECYCLER
2008-10-10 21:21:58 —-D—- C:\Privat
2008-10-10 13:31:42 —-A—- C:\WINDOWS\Uedit32.ini
2008-09-30 09:40:04 —-D—- C:\SOL
2008-09-29 17:03:10 —-D—- C:\MyDocs
2008-09-23 07:30:31 —-A—- C:\WINDOWS\imsins.BAK
2008-09-23 07:30:26 —-D—- C:\WINDOWS\WinSxS
2008-09-23 07:30:25 —-HD—- C:\WINDOWS\$hf_mig$
2008-09-23 07:29:36 —-D—- C:\WINDOWS\system32\CatRoot
2008-09-19 12:11:14 —-D—- C:\Program Files\Citrix

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys []
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2007-08-31 36352]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-04 14848]
R1 SAVRT;SAVRT; \??\C:\Program Files\Symantec Client Security\Symantec AntiVirus\savrt.sys []
R1 SAVRTPEL;SAVRTPEL; \??\C:\Program Files\Symantec Client Security\Symantec AntiVirus\Savrtpel.sys []
R1 SPBBCDrv;SPBBCDrv; \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys []
R1 SYMTDI;SYMTDI; C:\WINDOWS\System32\Drivers\SYMTDI.SYS [2006-08-07 195776]
R1 Tosrfcom;Bluetooth RFCOMM; C:\WINDOWS\System32\Drivers\tosrfcom.sys [2005-08-02 64896]
R2 BtnHnd;BtnHnd; \??\C:\Program Files\Fujitsu\BtnHnd\BtnHnd.sys []
R2 irda;IrDA Protocol; C:\WINDOWS\system32\DRIVERS\irda.sys [2004-08-04 87424]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\WINDOWS\system32\DRIVERS\AGRSM.sys [2006-11-29 1161888]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-04 60800]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2007-08-10 1578496]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2004-08-04 14080]
R3 Eacfilt;Eacfilt Miniport; C:\WINDOWS\system32\DRIVERS\eacfilt.sys [2004-01-26 9817]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys []
R3 FUJ02B1;Fujitsu FUJ02B1 Device Driver; C:\WINDOWS\system32\DRIVERS\FUJ02B1.sys [2001-08-01 5248]
R3 FUJ02E1;%FUJ02E1.DeviceDesc%; C:\WINDOWS\System32\Drivers\FUJ02E1.sys [2004-10-18 5632]
R3 FUJ02E3;Fujitsu FUJ02E3 Device Driver; C:\WINDOWS\system32\DRIVERS\FUJ02E3.sys [2004-01-17 4864]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-08 138752]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-03-12 4486144]
R3 IPSECSHM;Nortel IPSECSHM Adapter; C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys [2004-01-26 117696]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 NAVENG;NAVENG; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20081015.003\naveng.sys []
R3 NAVEX15;NAVEX15; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20081015.003\navex15.sys []
R3 NETw4x32;Intel® Wireless WiFi Link Adapter Driver for Windows XP 32 Bit; C:\WINDOWS\system32\DRIVERS\NETw4x32.sys [2008-03-18 2236032]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-04 61824]
R3 O2SCBUS;O2Micro SmartCardBus Reader; C:\WINDOWS\system32\DRIVERS\ozscr.sys [2006-12-08 92552]
R3 Rasirda;WAN Miniport (IrDA); C:\WINDOWS\system32\DRIVERS\rasirda.sys [2001-08-17 19584]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2004-08-04 5888]
R3 SMCIRDA;SMC IrCC Miniport Device Driver; C:\WINDOWS\system32\DRIVERS\smcirda.sys [2001-08-17 35913]
R3 SymEvent;SymEvent; \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS []
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2007-07-12 193120]
R3 tosporte;Bluetooth COM Port; C:\WINDOWS\system32\DRIVERS\tosporte.sys [2006-10-11 41600]
R3 Tosrfbd;Bluetooth RFBUS; C:\WINDOWS\System32\Drivers\tosrfbd.sys [2007-04-24 113920]
R3 Tosrfhid;Bluetooth RFHID; C:\WINDOWS\system32\DRIVERS\Tosrfhid.sys [2007-03-02 73728]
R3 Tosrfusb;Bluetooth USB Controller; C:\WINDOWS\System32\Drivers\tosrfusb.sys [2007-06-11 41856]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-04 31616]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2006-10-23 30208]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2006-10-23 59264]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2006-10-23 20608]
R3 yukonwxp;NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller; C:\WINDOWS\system32\DRIVERS\yk51x86.sys [2008-03-18 286336]
S2 IPSECEXT;Nortel Extranet Access Protocol; C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys [2004-01-26 117696]
S3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2008-02-15 5854752]
S3 OZSCR;O2Micro SmartCardBus Smartcard Reader; C:\WINDOWS\system32\DRIVERS\ozscr.sys [2006-12-08 92552]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2007-09-17 21632]
S3 sdbus;sdbus; C:\WINDOWS\system32\DRIVERS\sdbus.sys [2004-08-04 67584]
S3 SYMDNS;SYMDNS; C:\WINDOWS\System32\Drivers\SYMDNS.SYS [2006-08-07 12992]
S3 SYMFW;SYMFW; C:\WINDOWS\System32\Drivers\SYMFW.SYS [2006-08-07 110784]
S3 SYMIDS;SYMIDS; C:\WINDOWS\System32\Drivers\SYMIDS.SYS [2006-08-07 31936]
S3 SYMIDSCO;SYMIDSCO; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\SymcData\SCFIDS~1\20081010.002\symidsco.sys []
S3 SYMNDIS;SYMNDIS; C:\WINDOWS\System32\Drivers\SYMNDIS.SYS [2006-08-07 28352]
S3 SYMREDRV;SYMREDRV; C:\WINDOWS\System32\Drivers\SYMREDRV.SYS [2006-08-07 24768]
S3 tosrfbnp;Bluetooth RFBNEP; C:\WINDOWS\System32\Drivers\tosrfbnp.sys [2006-11-21 36480]
S3 tosrfnds;Bluetooth Personal Area Network; C:\WINDOWS\system32\DRIVERS\tosrfnds.sys [2005-01-06 18612]
S3 TosRfSnd;Bluetooth Audio; C:\WINDOWS\system32\drivers\tosrfsnd.sys [2007-01-22 53376]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-15 82688]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 sr;System Restore Filter Driver; C:\WINDOWS\C:\WINDOWS\system32\DRIVERS\sr.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\WINDOWS\system32\agrsmsvc.exe [2006-10-06 9216]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2007-08-10 409600]
R2 ccEvtMgr;Symantec Event Manager; C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe [2006-11-22 192104]
R2 ccProxy;Symantec Network Proxy; C:\Program Files\Common Files\Symantec Shared\ccProxy.exe [2006-11-22 202344]
R2 ccSetMgr;Symantec Settings Manager; C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe [2006-11-22 169576]
R2 DefWatch;Symantec AntiVirus Definition Watcher; C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe [2006-12-20 31424]
R2 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-09-01 137200]
R2 Irmon;Infrared Monitor; C:\WINDOWS\system32\svchost.exe [2004-08-04 14336]
R2 ISSVC;IS Service; C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe [2006-12-14 87680]
R2 IviRegMgr;IviRegMgr; C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe [2007-01-05 112152]
R2 Lotus Notes Single Logon;Lotus Notes Single Logon; C:\Program Files\Lotus\Notes\nslsvice.exe [2007-09-27 8192]
R2 O2Flash;O2Micro Flash Memory; C:\WINDOWS\system32\o2flash.exe [2005-09-13 57344]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2004-08-04 14336]
R2 radexecd;Radia Notify Daemon; C:\Program Files\Novadigm\radexecd.exe [2005-05-04 217268]
R2 radsched;Radia Scheduler Daemon; C:\Program Files\Novadigm\radsched.exe [2004-08-25 245940]
R2 SavRoam;SAVRoam; C:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe [2006-12-20 116928]
R2 SgeCtl;SafeGuard Easy Control; C:\Program Files\Utimaco\SafeGuard Easy\SgeCtl.exe [2007-09-05 90112]
R2 SgLogPlayer;SafeGuard SGLOG Player; C:\WINDOWS\system32\SgLogPlayer.exe [2005-03-31 61440]
R2 SPBBCSvc;Symantec SPBBCSvc; C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe [2006-04-11 1160848]
R2 Symantec AntiVirus;Symantec AntiVirus; C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe [2006-12-20 1814720]
R2 SymSecurePort;Symantec SecurePort; C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe [2006-12-14 173696]
R2 TOSHIBA Bluetooth Service;TOSHIBA Bluetooth Service; C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe [2007-02-26 125048]
R2 WinDefend;Windows Defender; C:\Program Files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
R2 WksCfgSrv;SafeGuard Easy Workstation Server; C:\Program Files\Utimaco\SafeGuard Easy\WksCfgSrv.exe [2007-09-05 155648]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-04 14336]
R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2008-10-14 611664]
R3 SNDSrvc;Symantec Network Drivers Service; C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe [2006-08-07 214720]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2006-10-20 36864]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2006-10-30 741376]
S3 LiveUpdate;LiveUpdate; C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE [2006-08-25 2528960]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2008-08-07 575488]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-19 913408]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2006-10-30 122880]

—————–EOF—————–

info.txt logfile of random's system information tool 1.04 2008-10-16 07:44:17

======Uninstall list======

–>"C:\WINDOWS\$NtUninstallKB950759$\spuninst\spuninst.exe"
–>"C:\WINDOWS\$NtUninstallKB953838$\spuninst\spuninst.exe"
–>C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL
–>C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
–>C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
–>C:\WINDOWS\UNNeroVision.exe /UNINSTALL
–>C:\WINDOWS\UNRecode.exe /UNINSTALL
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EF964A78-078C-11D1-B7A7-0000C0134CE6}\setup.exe" Uninstall
–>rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Ad-Aware–>MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
Adjustments for Hydro IS Partner–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" MSIEOP15000 remove
Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)–>MsiExec.exe /X{6846389C-BAC0-4374-808E-B120F86AF5D7}
Adobe Flash Player ActiveX–>C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player Plugin–>C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 8.1.2–>MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81200000003}
Adobe Reader–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" ADOBEREADER8 remove
Adobe Shockwave Player–>C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
Agere Systems HDA Modem–>agrsmdel
ATI - Software Uninstall Utility–>C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
ATI Catalyst Control Center–>MsiExec.exe /I{A7F2E70B-BB00-47F7-B7FA-6D8892478FD2}
ATI Display Driver–>rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
Bluetooth Stack for Windows by Toshiba–>MsiExec.exe /X{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}
Clue 7.0 License for Hydro IS Partner–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" CLUE709OP15000L remove
Clue 7.0–>MsiExec.exe /I{4FF5AA69-144E-445F-AAFB-231106E5E13A}
Clue–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" CLUE709 remove
Compatibility Pack for the 2007 Office system–>MsiExec.exe /X{90120000-0020-0409-0000-0000000FF1CE}
Configurations for MS Office 2003–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" MSO2003PROCFG remove
Copy IS Partner Remote Access installation locally–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" ISPREMACCLOCALCOPY remove
Digital Certificates–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" Cert remove
Domino.Doc Desktop Enabler Configuration for OP15000–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" DDOCDTENOP15000 remove
DVD Shrink 3.2–>"C:\Program Files\DVD Shrink\unins000.exe"
EMC Archive Services for Email MRE–>MsiExec.exe /I{C99CB077-30C0-4587-A322-CD1E1D85163F}
ERUNT 1.1j–>"C:\Program Files\ERUNT\unins000.exe"
Fiberlink Global Remote–>MsiExec.exe /X{CD96CA48-FA2F-410E-8994-E635DDED0E0D}
Fujitsu Display Manager–>C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{FCCDD334-D813-4FD7-B3F7-F5410EB90EB1}
Fujitsu Hotkey Utility–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{272979FC-6D4A-4C25-B71A-32DD4974A022}\setup.exe"
Fujitsu System Extension Utility–>C:\Program Files\InstallShield Installation Information\{E8A5B78F-4456-4511-AB3D-E7BFFB974A7A}\setup.exe -runfromtemp -l0x0409
Google Earth–>MsiExec.exe /I{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}
Google Gears–>MsiExec.exe /I{552171BC-30F8-3B29-9C4F-E3FE590B7CAC}
Google Toolbar for Internet Explorer–>regsvr32 /u /s "c:\program files\google\googletoolbar2.dll"
Google Updater–>"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
Hijackthis 1.99.1–>"C:\Program Files\Hijackthis\unins000.exe"
HijackThis 2.0.2–>"C:\Program Files\trend micro\HijackThis.exe" /uninstall
HISP Configuration for Microsoft Office Professional–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" MSO2003PROOP15000 remove
HP Color LaserJet 4700 PS (02/24/2007 61.071.661.41)–>"C:\Program Files\Common Files\Hewlett-Packard\HPDIU 2.0\HPDIU_Uninstall.exe" /d "C:\Program Files\Common Files\Hewlett-Packard\HPDIU 2.0\DriverInf\hpc4700d.inx"
Hydro CPSS Client–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" CPSSCLIENT remove
Intel® Graphics Media Accelerator Driver–>C:\WINDOWS\system32\igxpun.exe -uninstall
Internet Explorer Updates–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" MSIEUpdates remove
Internet Explorer–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" MSIE remove
InterVideo WinDVD 8–>C:\Program Files\InstallShield Installation Information\{20471B27-D702-4FE8-8DEC-0702CC8C0A85}\setup.exe -runfromtemp -l0x0409
IS Partner Remote access transition–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" ISPREMACCTRANS remove
Java Runtime Environment–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" SUNJRE_131_16 remove
Java Runtime Environment–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" SUNJRE_142_10 remove
Java Runtime Environment–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" SUNJRE_150_06 remove
Java™ 6 Update 7–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
Lifebook Application Panel–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9C5BCA32-C81D-4063-B036-6C085A1D333E}\setup.exe"
LiveUpdate 3.1 (Symantec Corporation)–>"C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U
Lotus Notes (English)–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" NOTES7EN remove
Lotus Notes 7.0.3–>MsiExec.exe /I{F10572FA-588C-4653-AD22-96AC843D5733}
Malwarebytes' Anti-Malware–>"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
MDAC, JET and ODBC drivers–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" MDAC remove
MetaFrame Presentation Server Web Client for Win32–>C:\WINDOWS\system32\ctxsetup.exe /uninst C:\PROGRA~1\Citrix\icaweb32\uninst.inf
METRO Configuration–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" B_CONFIG remove
Metro Extension Library–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" MELIBRARY remove
METRO InfoScan Client–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" INFOSCAN remove
METRO Initialization–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" BinD remove
METRO OS Configuration–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" BinDOsConfig remove
METRO Shared Data Client–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" B_SDC remove
METRO Shared Data Provider–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" B_SDP remove
Metro Update configuration (HISP)–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" BindUpdateHISP remove
Metro Update Engine–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" BindUpdateEngine remove
Microsoft .NET Framework 1.1–>MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0 Service Pack 1–>MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
Microsoft .NET Framework 3.0–>c:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setup.exe
Microsoft .NET Framework 3.0–>MsiExec.exe /X{15095BF3-A3D7-4DDF-B193-3A496881E003}
Microsoft .NET Framework–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" DOTNETFW20 remove
Microsoft Compression Client Pack 1.0 for Windows XP–>"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Java Virtual Machine–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" MSJVM remove
Microsoft Office CD Source–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" MSO2003COMMON remove
Microsoft Office Professional Edition 2003–>MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
Microsoft Office Professional–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" MSO2003PRO remove
Microsoft Office Visio Professional 2003–>MsiExec.exe /I{90510409-6000-11D3-8CFE-0150048383C9}
Microsoft OS Security Source–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" SECURITYSOURCE remove
Microsoft User-Mode Driver Framework Feature Pack 1.5–>"C:\WINDOWS\$NtUninstallWudf01005$\spuninst\spuninst.exe"
Microsoft Visio Professional–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" MSVISIO remove
Microsoft Visual C++ 2005 Redistributable–>MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
MSVC80_x86–>MsiExec.exe /I{212748BB-0DA5-46DE-82A1-403736DC9F27}
MSXML 4.0 SP2 (KB936181)–>MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 6.0 Parser (KB933579)–>MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
Nero 7 Essentials–>MsiExec.exe /I{D34D82E0-4600-407B-9478-8506C1DD1033}
Nokia Connectivity Cable Driver–>MsiExec.exe /X{C3F19A5F-35A8-4FDB-A6ED-0F4CE398DA48}
Nokia Map Loader–>MsiExec.exe /I{18B5996A-643E-4176-9BEB-27C45C9F1FC3}
Nokia PC Suite–>C:\Documents and Settings\All Users\Application Data\Installations\{A8C3710A-0BCA-4F10-9EC3-A302A1F1FA82}\Nokia_PC_Suite_rel_7_0_8_2_nor.exe
Nokia PC Suite–>MsiExec.exe /I{A8C3710A-0BCA-4F10-9EC3-A302A1F1FA82}
Notes adjustments (OP15000)–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" NOTES7OP15000 remove
O2Micro Flash Memory Card Windows Driver–>C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{E1E58954-D885-44E7-B8C2-F0E9A6DA1652} /l1033
OZ711 SCR Driver V3.0.0.9A–>C:\Program Files\InstallShield Installation Information\{33E6FA96-31C0-4CEF-B385-C20D51C0FA06}\setup.exe -runfromtemp -l0x0409
PC Connectivity Solution–>MsiExec.exe /I{1A524CFE-DF85-4555-8BC2-0C89DBD8BC2C}
PDF-XChange 3.0 Pro–>"C:\Program Files\Tracker Software\PDF-XChange 3 Pro\unins000.exe"
Power Saving Utility–>C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{79821CAD-999C-443D-B420-96F914C84E27}
Radia Agent for ISP–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" RADIAAGENTISP remove
Realtek High Definition Audio Driver–>RtlUpd.exe -r -m
Remedy User 6.3–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{437B532F-EB2B-40A2-8585-DEFA15F92C76}\Setup.exe" -l0x9 Useruninstall
Remote Access Client–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" ISPREMACC remove
SafeGuard Easy–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" SGE440EN remove
SafeGuard® Easy Client 4.40.2 –>MsiExec.exe /I{43216FBE-D869-489D-90DE-87D22E816757}
Sap Common Files–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" SAP_COMMON remove
Sap Custom Package for all–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" SAPCUSTOM_ALL remove
Sap Custom Package for Hydro–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" SAPCUSTOM_HYDRO remove
SAP Front End–>"C:\WINDOWS\SAPwksta\setup\sapsetup.exe" /uninstall
SAP GUI, SAP R/3 Frontend–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" SAPGUI640 remove
Sap Patch, BW 3.x - Web Application Designer,–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" SAP_PATCH_WEBAPPLICATIONDESIGNER640 remove
Sap Patch, GUI640_–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" SAP_PATCH_GUI640LVL20 remove
Sap Patch, SETUP640_–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" SAP_PATCH_SETUP640 remove
SAPlogon Language Selector–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" SAP_LANGUAGE remove
Security Update for CAPICOM (KB931906)–>MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906)–>MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for Windows XP (KB938464)–>"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)–>"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)–>"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)–>"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)–>"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Updates–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" Security remove
Service Pack 1 for Microsoft .NET Framework–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" DOTNETFW11SP1 remove
SGE Admin domain 005 for IS Partner–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" SGE440EN_005 remove
ShockWave, Flash and MediaPlayer–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" MultiMed remove
SnagIt 8–>MsiExec.exe /I{B6F0BE9B-41D7-45A2-9A76-D3DB1A89EC6A}
SnagIT License For HISP–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" SNAGIT8OP15000L remove
SnagIt–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" SNAGIT8 remove
Sun Java configurations for Hydro IS Partner–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" SUNJRE_CONFIG_ONH12924 remove
Sun Java configurations–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" SUNJRE_CONFIG remove
Sun Java Runtime Environment–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" SUNJRE remove
Symantec Client Security Config for SN–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" SCS30EN_SN remove
Symantec Client Security Config Selector–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" SCS30EN_CFG_SELECT remove
Symantec Client Security–>MsiExec.exe /I{0698CECB-9072-47B1-AEA1-94CA350989B8}
Symantec Client Security–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" SCS30EN remove
Synaptics Pointing Device Driver–>rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
Tight Virtual Network Computing–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" TIGHTVNC remove
Total Commander (Remove or Repair)–>c:\totalcmd\tcuninst.exe
UltraEdit Configuration for IS Partner Client–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" ULTRAEDITOP15000 remove
UltraEdit–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" ULTRAEDIT remove
UltraEdit-32–>"C:\Program Files\UltraEdit\Uninstall.exe" "C:\Program Files\UltraEdit\ueinstall.log"
Update for Windows XP (KB912945)–>"C:\WINDOWS\$NtUninstallKB912945$\spuninst\spuninst.exe"
Webshots Desktop–>"C:\Program Files\Webshots\unins000.exe"
Windows Automatic Updates Config–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" WSUSCLNT_CONFIG remove
Windows Automatic Updates–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" WSUSCLNT remove
Windows Communication Foundation–>MsiExec.exe /X{491DD792-AD81-429C-9EB4-86DD3D22E333}
Windows Defender–>MsiExec.exe /I{A06275F4-324B-4E85-95E6-87B2CD729401}
Windows Driver Package - Intel (NETw4x32) net (09/26/2007 11.5.0.32)–>C:\PROGRA~1\DIFX\D6ACC4BE676423A2B130B78A4B627FC457D98997\DPInst32.EXE /u C:\WINDOWS\system32\DRVSTORE\netw4x32_B0AEEEEDA759744D7D2AC236F54CA6D4CFC0961C\netw4x32.inf
Windows Driver Package - Intel (w29n51) net (07/25/2007 9.0.4.37)–>C:\PROGRA~1\DIFX\D6ACC4BE676423A2B130B78A4B627FC457D98997\DPInst32.EXE /u C:\WINDOWS\system32\DRVSTORE\w29n51_E99959A506B0423451BFDD2FE3C8B527B6AF45BD\w29n51.inf
Windows Driver Package - Intel net (09/26/2007 11.5.0.32)–>C:\PROGRA~1\DIFX\D6ACC4BE676423A2B130B78A4B627FC457D98997\DPInst32.EXE /u C:\WINDOWS\system32\DRVSTORE\netw4k32_4CD46BE21BE74C8D663C65B8DC2D7EEA091E50F5\netw4k32.inf
Windows Driver Package - Nokia Modem (05/22/2008 3.8)–>C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\nokia_blue_6F90B0F4A73A2F780A1010B5D6CB5DDFB098181E\nokia_bluetooth.inf
Windows Driver Package - Nokia Modem (05/22/2008 7.00.0.1)–>C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\nokbtmdm_E68D50F7E25BFE399D47C864C3B52557346242A9\nokbtmdm.inf
Windows Driver Package - Nokia pccsmcfd (10/12/2007 6.85.4.0)–>C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\pccsmcfd_4A1E30386F4D0DEC8F5DF262CFBD8845EEBAB175\pccsmcfd.inf
Windows Imaging Component–>"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
Windows Media Format 11 runtime–>"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime–>"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11–>"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11–>"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows Presentation Foundation–>MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}
Windows Workflow Foundation–>MsiExec.exe /I{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}
Windows XP Servicepack–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" WXPSP2 remove
Windows XP SP2 adjustments–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" WXPSP2ADJUST remove
Wireless Selector–>C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{BF91B0A2-52DC-4230-B44F-7C34FA861D41}

======Security center information======

AV: Symantec AntiVirus Corporate Edition
FW: Symantec Client Firewall (disabled)

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=C:\Program Files\PC Connectivity Solution\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\ATI Technologies\ATI.ACE\;c:\util;C:\Program Files\Utimaco\SafeGuard Easy\;C:\Program Files\UltraEdit;C:\Program Files\Common Files\EMC
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 6, GenuineIntel
"PROCESSOR_REVISION"=0f06
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP

—————–EOF—————–
Hello

Please download the OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    
    :Files
    C:\WINDOWS\system32\wnjnhq.dll
    C:\WINDOWS\system32\xaoawvju.dll
    C:\WINDOWS\system32\mawjkhhq.ini
    C:\WINDOWS\system32\qhhkjwam.dll
    C:\WINDOWS\system32\aJSrutwa.ini2
    C:\WINDOWS\system32\aJSrutwa.ini
    C:\WINDOWS\system32\awturSJa.dll
    C:\WINDOWS\system32\akchgl.dll
    C:\WINDOWS\system32\gojcxhkj.dll
    C:\WINDOWS\system32\tpaylrvh.dll
    C:\WINDOWS\system32\oegrjj.dll
    C:\WINDOWS\system32\hdkxtc.dll
    C:\WINDOWS\system32\lclcvsrq.dll
    C:\WINDOWS\system32\thfwryvd.ini
    C:\WINDOWS\system32\pvemwg.dll
    C:\WINDOWS\system32\bgalxkua.dll
    C:\WINDOWS\system32\myumtr.dll
    C:\WINDOWS\system32\lugfjvhk.dll
    C:\WINDOWS\system32\hbbvzh.dll
    C:\WINDOWS\system32\xrggvrtq.dll
    C:\WINDOWS\system32\zabhqd.dll
    C:\WINDOWS\system32\ghmkgxfx.dll
    C:\WINDOWS\system32\bf64efcb-.txt
    C:\WINDOWS\system32\wini104552664.exe
    C:\WINDOWS\system32\pmnoPgfc.dll
    C:\WINDOWS\system32\khfFUMGv.dll
    C:\WINDOWS\system32\isiefwfo.tmp
    C:\WINDOWS\system32\4jQhIhF4.exe
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.


Also post a new Rsit log
Good afternoon Thanks for helping me. Here are the last log… ========== PROCESSES ========== Process explorer.exe killed successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== DllUnregisterServer procedure not found in C:\WINDOWS\system32\wnjnhq.dll C:\WINDOWS\system32\wnjnhq.dll NOT unregistered. C:\WINDOWS\system32\wnjnhq.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\xaoawvju.dll C:\WINDOWS\system32\xaoawvju.dll NOT unregistered. C:\WINDOWS\system32\xaoawvju.dll moved successfully. C:\WINDOWS\system32\mawjkhhq.ini moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\qhhkjwam.dll C:\WINDOWS\system32\qhhkjwam.dll NOT unregistered. C:\WINDOWS\system32\qhhkjwam.dll moved successfully. C:\WINDOWS\system32\aJSrutwa.ini2 moved successfully. C:\WINDOWS\system32\aJSrutwa.ini moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\awturSJa.dll C:\WINDOWS\system32\awturSJa.dll NOT unregistered. C:\WINDOWS\system32\awturSJa.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\akchgl.dll C:\WINDOWS\system32\akchgl.dll NOT unregistered. C:\WINDOWS\system32\akchgl.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\gojcxhkj.dll C:\WINDOWS\system32\gojcxhkj.dll NOT unregistered. C:\WINDOWS\system32\gojcxhkj.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\tpaylrvh.dll C:\WINDOWS\system32\tpaylrvh.dll NOT unregistered. C:\WINDOWS\system32\tpaylrvh.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\oegrjj.dll C:\WINDOWS\system32\oegrjj.dll NOT unregistered. C:\WINDOWS\system32\oegrjj.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\hdkxtc.dll C:\WINDOWS\system32\hdkxtc.dll NOT unregistered. C:\WINDOWS\system32\hdkxtc.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\lclcvsrq.dll C:\WINDOWS\system32\lclcvsrq.dll NOT unregistered. C:\WINDOWS\system32\lclcvsrq.dll moved successfully. C:\WINDOWS\system32\thfwryvd.ini moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\pvemwg.dll C:\WINDOWS\system32\pvemwg.dll NOT unregistered. C:\WINDOWS\system32\pvemwg.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\bgalxkua.dll C:\WINDOWS\system32\bgalxkua.dll NOT unregistered. C:\WINDOWS\system32\bgalxkua.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\myumtr.dll C:\WINDOWS\system32\myumtr.dll NOT unregistered. C:\WINDOWS\system32\myumtr.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\lugfjvhk.dll C:\WINDOWS\system32\lugfjvhk.dll NOT unregistered. C:\WINDOWS\system32\lugfjvhk.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\hbbvzh.dll C:\WINDOWS\system32\hbbvzh.dll NOT unregistered. C:\WINDOWS\system32\hbbvzh.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\xrggvrtq.dll C:\WINDOWS\system32\xrggvrtq.dll NOT unregistered. C:\WINDOWS\system32\xrggvrtq.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\zabhqd.dll C:\WINDOWS\system32\zabhqd.dll NOT unregistered. C:\WINDOWS\system32\zabhqd.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\ghmkgxfx.dll C:\WINDOWS\system32\ghmkgxfx.dll NOT unregistered. C:\WINDOWS\system32\ghmkgxfx.dll moved successfully. C:\WINDOWS\system32\bf64efcb-.txt moved successfully. C:\WINDOWS\system32\wini104552664.exe moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\pmnoPgfc.dll C:\WINDOWS\system32\pmnoPgfc.dll NOT unregistered. File move failed. C:\WINDOWS\system32\pmnoPgfc.dll scheduled to be moved on reboot. DllUnregisterServer procedure not found in C:\WINDOWS\system32\khfFUMGv.dll C:\WINDOWS\system32\khfFUMGv.dll NOT unregistered. C:\WINDOWS\system32\khfFUMGv.dll moved successfully. C:\WINDOWS\system32\isiefwfo.tmp moved successfully. C:\WINDOWS\system32\4jQhIhF4.exe moved successfully. ========== COMMANDS ========== User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. Windows Temp folder emptied. Java cache emptied. Temp folders emptied. Explorer started successfully OTMoveIt3 by OldTimer - Version 1.0.5.0 log created on 10162008_174103 Files moved on Reboot… DllUnregisterServer procedure not found in C:\WINDOWS\system32\pmnoPgfc.dll C:\WINDOWS\system32\pmnoPgfc.dll NOT unregistered. File move failed. C:\WINDOWS\system32\pmnoPgfc.dll scheduled to be moved on reboot. File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
Logfile of random's system information tool 1.04 (written by random/random)
Run by [removed] at 2008-10-16 18:50:13
Microsoft Windows XP Professional Service Pack 2
System drive C: has 64 GB (85%) free of 76 GB
Total RAM: 2046 MB (62% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:50:17, on 2008-10-16
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Lotus\Notes\nslsvice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\agrsmsvc.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\WINDOWS\system32\o2flash.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Novadigm\radexecd.exe
C:\Program Files\Novadigm\radsched.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Utimaco\SafeGuard Easy\SgeCtl.exe
C:\WINDOWS\system32\SgLogPlayer.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\Program Files\Utimaco\SafeGuard Easy\WksCfgSrv.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Fujitsu\PSUtility\TrayManager.exe
C:\Program Files\Fujitsu\DispSwitch\DispSwitchLauncher.exe
C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe
C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe
C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Hydro\BinD\B_Manager\B_Manager.exe
C:\PROGRA~1\Hydro\BinD\B_Sched.exe
C:\Program Files\Utimaco\SafeGuard Easy\Ecview.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~2\SYMANT~1\VPTray.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Documents and Settings\a683791\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\PC Connectivity Solution\Transports\NclIrSrv.exe
C:\Program Files\Common Files\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
C:\Program Files\PC Connectivity Solution\Transports\NclToBTSrv.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\rundll32.exe
C:\Documents and Settings\a683791\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\rundll32.exe
C:\Documents and Settings\a683791\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\totalcmd\TOTALCMD.EXE
c:\Download\RSIT.exe
C:\Program Files\trend micro\a683791.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://inside.ispartner.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://inside.ispartner.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://inside.ispartner.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://inside.ispartner.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://proxycf.net.ispartner.com/pac
O2 - BHO: {77c4b652-b419-8bbb-fdd4-868db2f64803} - {30846f2b-d868-4ddf-bbb8-914b256b4c77} - C:\WINDOWS\system32\uzhysa.dll
O2 - BHO: (no name) - {3FCFD9B4-660E-418D-8FA5-C73BC5EA16DE} - C:\WINDOWS\system32\awturSJa.dll (file missing)
O2 - BHO: (no name) - {8DDA7038-2E38-4A41-9411-978DC02EF143} - C:\WINDOWS\system32\qoMdDVoM.dll
O2 - BHO: (no name) - {EC22E79C-7702-4C38-9691-C139D6C359C9} - C:\WINDOWS\system32\pmnoPgfc.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [IndicatorUtility] C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [PSUtility] C:\Program Files\Fujitsu\PSUtility\TrayManager.exe
O4 - HKLM\..\Run: [TvOutSwitch] C:\Program Files\Fujitsu\DispSwitch\DispSwitchLauncher.exe
O4 - HKLM\..\Run: [LoadFUJ02E3] C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe
O4 - HKLM\..\Run: [LoadFujitsuQuickTouch] C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe
O4 - HKLM\..\Run: [LoadBtnHnd] C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [RunOSSettings] C:\Program Files\Hydro\Image\2ndRegSett.vbs
O4 - HKLM\..\Run: [BinD Manager] C:\Program Files\Hydro\BinD\B_Manager\B_Manager.exe
O4 - HKLM\..\Run: [BinD Maintenance Run Scripts] C:\WINDOWS\system32\wscript.exe "C:\PROGRA~1\Hydro\BinD\B_RunHook.vbs"
O4 - HKLM\..\Run: [BinD Scheduler] "C:\PROGRA~1\Hydro\BinD\B_Sched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SgeEcView] "C:\Program Files\Utimaco\SafeGuard Easy\Ecview.exe"
O4 - HKLM\..\Run: [EdWizard] "C:\Program Files\Utimaco\SafeGuard Easy\EdWizard.exe" as
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~2\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [FFAKNNVF] %systemroot%\FFAKNNVF.exe
O4 - HKLM\..\Run: [bivfffcz] %systemroot%\bivfffcz.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [b4472bb5] rundll32.exe "C:\WINDOWS\system32\rqqmmstk.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe" /NoDialog
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\a683791\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'Default user')
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1189737859843
O16 - DPF: {759FD3DE-F0EF-4A76-909C-88CF840D4173} (DmDragDrop Class) - https://webtop.hda.hydro.com/webtop/wdk/nat…dkPluginCab.CAB
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl.sun.com/webapps/download/AutoDL?BundleId=23100
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) - https://isadmin.hydroispartner.com/dana-cac…perSetupSP1.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = adi.ispartner.com
O17 - HKLM\Software\..\Telephony: DomainName = adi.ispartner.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = adi.ispartner.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = adi.ispartner.com,ispartner.com,hydro.com,nh.ad.hydro.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = adi.ispartner.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = adi.ispartner.com,ispartner.com,hydro.com,nh.ad.hydro.com
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = adi.ispartner.com
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: SearchList = adi.ispartner.com,ispartner.com,hydro.com,nh.ad.hydro.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = adi.ispartner.com,ispartner.com,hydro.com,nh.ad.hydro.com
O20 - AppInit_DLLs: uzhysa.dll
O20 - Winlogon Notify: FJWSEL - C:\WINDOWS\SYSTEM32\FJWSWNP.dll
O20 - Winlogon Notify: NotLog - C:\WINDOWS\SYSTEM32\SGLogEx.dll
O20 - Winlogon Notify: pmnoPgfc - C:\WINDOWS\SYSTEM32\pmnoPgfc.dll
O20 - Winlogon Notify: PSUTY - C:\WINDOWS\SYSTEM32\PSUWNP.dll
O20 - Winlogon Notify: SGLogNotification - C:\WINDOWS\SYSTEM32\SGLogNotification.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: IS Service (ISSVC) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Lotus Notes Single Logon - IBM Corp - C:\Program Files\Lotus\Notes\nslsvice.exe
O23 - Service: O2Micro Flash Memory (O2Flash) - O2Micro International - C:\WINDOWS\system32\o2flash.exe
O23 - Service: Radia Notify Daemon (radexecd) - Hewlett-Packard - C:\Program Files\Novadigm\radexecd.exe
O23 - Service: Radia Scheduler Daemon (radsched) - Hewlett-Packard - C:\Program Files\Novadigm\radsched.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SafeGuard Easy Control (SgeCtl) - Utimaco Safeware AG - C:\Program Files\Utimaco\SafeGuard Easy\SgeCtl.exe
O23 - Service: SafeGuard SGLOG Player (SgLogPlayer) - Utimaco Safeware AG - C:\WINDOWS\system32\SgLogPlayer.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Symantec SecurePort (SymSecurePort) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: SafeGuard Easy Workstation Server (WksCfgSrv) - Utimaco Safeware AG - C:\Program Files\Utimaco\SafeGuard Easy\WksCfgSrv.exe

–
End of file - 15176 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskUser.job
C:\WINDOWS\tasks\MP Scheduled Scan.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30846f2b-d868-4ddf-bbb8-914b256b4c77}]
C:\WINDOWS\system32\uzhysa.dll [2008-10-16 108544]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3FCFD9B4-660E-418D-8FA5-C73BC5EA16DE}]
C:\WINDOWS\system32\awturSJa.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8DDA7038-2E38-4A41-9411-978DC02EF143}]
C:\WINDOWS\system32\qoMdDVoM.dll [2008-10-16 265216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EC22E79C-7702-4C38-9691-C139D6C359C9}]
C:\WINDOWS\system32\pmnoPgfc.dll [2008-10-14 37376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - SnagIt - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll [2007-02-16 161352]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program files\google\googletoolbar2.dll [2008-08-31 2403392]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"=C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE [2004-08-04 208952]
"PHIME2002ASync"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2004-08-04 455168]
"PHIME2002A"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2004-08-04 455168]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2007-03-12 16125440]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2007-03-12 69632]
"AGRSMMSG"=C:\WINDOWS\AGRSMMSG.exe [2006-06-29 89541]
"IndicatorUtility"=C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe [2006-04-20 90112]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2007-07-12 794713]
"PSUtility"=C:\Program Files\Fujitsu\PSUtility\TrayManager.exe [2007-07-12 118784]
"TvOutSwitch"=C:\Program Files\Fujitsu\DispSwitch\DispSwitchLauncher.exe [2007-07-12 81920]
"LoadFUJ02E3"=C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe [2006-11-18 80688]
"LoadFujitsuQuickTouch"=C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe [2005-11-02 353792]
"LoadBtnHnd"=C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe [2005-11-02 61440]
"ATICCC"=C:\Program Files\ATI Technologies\ATI.ACE\cli.exe [2006-01-03 45056]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2006-01-13 155648]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2008-02-15 135168]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2008-02-15 159744]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2008-02-15 131072]
"MSPY2002"=C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe [2004-08-04 59392]
"RunOSSettings"=C:\Program Files\Hydro\Image\2ndRegSett.vbs [2006-08-10 1907]
"BinD Manager"=C:\Program Files\Hydro\BinD\B_Manager\B_Manager.exe [2007-03-19 20480]
"BinD Maintenance Run Scripts"=C:\WINDOWS\system32\wscript.exe [2004-08-04 114688]
"BinD Scheduler"=C:\PROGRA~1\Hydro\BinD\B_Sched.exe [2002-12-02 650752]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
"SgeEcView"=C:\Program Files\Utimaco\SafeGuard Easy\Ecview.exe [2007-09-05 24576]
"EdWizard"=C:\Program Files\Utimaco\SafeGuard Easy\EdWizard.exe [2007-09-05 245760]
"ccApp"=C:\Program Files\Common Files\Symantec Shared\ccApp.exe [2006-11-22 52840]
"vptray"=C:\PROGRA~1\SYMANT~2\SYMANT~1\VPTray.exe [2006-12-20 125632]
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]
"FFAKNNVF"=C:\WINDOWS\FFAKNNVF.exe []
"bivfffcz"=C:\WINDOWS\bivfffcz.exe []
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2006-11-03 866584]
"b4472bb5"=C:\WINDOWS\system32\rqqmmstk.dll [2008-10-16 75264]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360]
"PC Suite Tray"=C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe [2008-08-11 1124352]
"Nokia.PCSync"=C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe [2008-06-17 1249280]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-09-01 39408]
"Google Update"=C:\Documents and Settings\a683791\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-03 133104]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe

C:\Documents and Settings\a683791\Start Menu\Programs\Startup
Webshots.lnk - C:\Program Files\Webshots\Launcher.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="uzhysa.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2007-08-10 61440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\FJWSEL]
C:\WINDOWS\system32\FJWSWNP.dll [2007-07-12 32768]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2008-02-15 208896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon]
C:\WINDOWS\system32\NavLogon.dll [2006-12-20 43712]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NotLog]
C:\WINDOWS\system32\SGLogEx.dll [2002-01-22 110592]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmnoPgfc]
C:\WINDOWS\system32\pmnoPgfc.dll [2008-10-14 37376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\PSUTY]
C:\WINDOWS\system32\PSUWNP.dll [2007-07-12 32768]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SGLogNotification]
C:\WINDOWS\system32\SGLogNotification.dll [2005-03-31 69632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2007-04-10 236928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-19 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{0574D50F-C261-490D-BF39-4E91183C4EFB}"= []
"{EC22E79C-7702-4C38-9691-C139D6C359C9}"=C:\WINDOWS\system32\pmnoPgfc.dll [2008-10-14 37376]
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"=C:\PROGRA~1\WIFD1F~1\MpShHook.dll [2006-11-03 83224]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
C:\WINDOWS\system32\qoMdDVoM

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"NoDispScrSavPage"=0
"DisableTaskMgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"disablecad"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"ForceStartMenuLogOff"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Hydro\Image\GetSiteInfo\B_GetSiteInfo.exe"="C:\Program Files\Hydro\Image\GetSiteInfo\B_GetSiteInfo.exe:*:Enabled:B_GetSiteInfo Configuration Setting Utility"
"C:\Program Files\Hydro\Image\ntpdate.exe"="C:\Program Files\Hydro\Image\ntpdate.exe:*:Enabled:ntpdate"
"C:\Program Files\InterVideo\DVD7\WinDVD.exe"="C:\Program Files\InterVideo\DVD7\WinDVD.exe:*:Enabled:WinDVD"
"C:\Program Files\InterVideo\DVD8\WinDVD.exe"="C:\Program Files\InterVideo\DVD8\WinDVD.exe:*:Enabled:WinDVD"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======File associations======

.bat - edit - "C:\Program Files\UltraEdit\uedit32.exe" "%1"
.cmd - edit - "C:\Program Files\UltraEdit\uedit32.exe" "%1"
.inf - open - "C:\Program Files\UltraEdit\uedit32.exe" "%1"
.ini - open - notepad.exe %1
.reg - edit - "C:\Program Files\UltraEdit\uedit32.exe" "%1"
.txt - open - notepad.exe %1

======List of files/folders created in the last 1 months======

2008-10-16 17:56:34 —-SH—- C:\WINDOWS\system32\ktsmmqqr.ini
2008-10-16 17:56:32 —-A—- C:\WINDOWS\system32\rqqmmstk.dll
2008-10-16 17:54:12 —-A—- C:\WINDOWS\system32\uzhysa.dll
2008-10-16 17:54:12 —-A—- C:\WINDOWS\system32\lmpxpdjv.dll
2008-10-16 17:53:45 —-A—- C:\WINDOWS\system32\bf64efcb-.txt
2008-10-16 17:53:31 —-ASH—- C:\WINDOWS\system32\MoVDdMoq.ini2
2008-10-16 17:53:31 —-ASH—- C:\WINDOWS\system32\MoVDdMoq.ini
2008-10-16 17:53:27 —-A—- C:\WINDOWS\system32\qoMdDVoM.dll
2008-10-16 07:44:05 —-D—- C:\Program Files\trend micro
2008-10-16 07:44:04 —-D—- C:\rsit
2008-10-15 22:17:37 —-D—- C:\_OTMoveIt
2008-10-15 21:21:55 —-A—- C:\lopR.txt
2008-10-15 21:21:12 —-D—- C:\Lop SD
2008-10-15 14:07:19 —-D—- C:\Program Files\Hijackthis
2008-10-14 20:50:06 —-D—- C:\Program Files\Lavasoft
2008-10-14 20:50:06 —-D—- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-10-14 20:49:25 —-D—- C:\Program Files\Common Files\Wise Installation Wizard
2008-10-14 11:53:23 —-D—- C:\WINDOWS\system32\%APPDATA%
2008-10-14 09:30:07 —-D—- C:\Documents and Settings\a683791\Application Data\Malwarebytes
2008-10-14 08:31:17 —-D—- C:\Program Files\Windows Defender
2008-10-14 08:21:09 —-D—- C:\Documents and Settings\All Users\Application Data\fkpshuri
2008-10-14 08:20:44 —-A—- C:\WINDOWS\system32\pmnoPgfc.dll
2008-10-13 10:47:36 —-D—- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-13 10:47:36 —-D—- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-13 10:46:43 —-D—- C:\WINDOWS\ERDNT
2008-10-13 10:46:24 —-D—- C:\Program Files\ERUNT
2008-10-13 10:07:55 —-A—- C:\WINDOWS\VPC32.INI
2008-10-10 21:34:34 —-A—- C:\WINDOWS\ntbtlog.txt
2008-10-10 21:28:35 —-D—- C:\WINDOWS\Minidump
2008-09-29 16:48:33 —-D—- C:\Documents and Settings\a683791\Application Data\InterVideo
2008-09-25 09:07:04 —-D—- C:\lotus
2008-09-23 07:30:38 —-HDC—- C:\WINDOWS\$NtUninstallKB954154_WM11$
2008-09-23 07:30:26 —-HDC—- C:\WINDOWS\$NtUninstallKB938464$

======List of files/folders modified in the last 1 months======

2008-10-16 18:50:03 —-A—- C:\WINDOWS\wincmd.ini
2008-10-16 18:19:46 —-D—- C:\WINDOWS\Prefetch
2008-10-16 18:17:08 —-D—- C:\WINDOWS\Temp
2008-10-16 17:56:36 —-D—- C:\WINDOWS\system32
2008-10-16 17:51:10 —-A—- C:\BinD.mif.txt
2008-10-16 17:50:38 —-D—- C:\WINDOWS
2008-10-16 17:50:37 —-SD—- C:\WINDOWS\Tasks
2008-10-16 17:50:24 —-D—- C:\WINDOWS\system32\CatRoot2
2008-10-16 17:50:19 —-A—- C:\WINDOWS\Bridge.ini
2008-10-16 17:47:37 —-D—- C:\Program Files\Common Files\Symantec Shared
2008-10-16 17:46:22 —-A—- C:\WINDOWS\SchedLgU.Txt
2008-10-16 17:45:55 —-D—- C:\MyDocs
2008-10-16 17:37:47 —-D—- C:\Download
2008-10-16 07:44:05 —-RD—- C:\Program Files
2008-10-16 07:15:53 —-D—- C:\WINDOWS\security
2008-10-15 21:52:01 —-A—- C:\BinD.mif.bak
2008-10-15 21:48:00 —-D—- C:\WINDOWS\system32\drivers
2008-10-15 17:47:31 —-D—- C:\Program Files\Clue
2008-10-15 14:56:21 —-A—- C:\WINDOWS\Notes.ini
2008-10-15 13:45:02 —-D—- C:\Documents and Settings\All Users\Application Data\Google Updater
2008-10-14 20:50:49 —-SHD—- C:\WINDOWS\Installer
2008-10-14 20:49:25 —-D—- C:\Program Files\Common Files
2008-10-14 16:05:59 —-D—- C:\Program Files\2321_Remote Access
2008-10-14 12:36:51 —-SHD—- C:\System Volume Information
2008-10-14 12:36:51 —-D—- C:\WINDOWS\system32\Restore
2008-10-14 09:11:17 —-D—- C:\Documents and Settings\a683791\Application Data\Adobe
2008-10-14 08:31:18 —-HD—- C:\WINDOWS\inf
2008-10-14 08:31:17 —-SD—- C:\Documents and Settings\All Users\Application Data\Microsoft
2008-10-14 08:21:09 —-RSHDC—- C:\WINDOWS\system32\dllcache
2008-10-13 09:00:02 —-D—- C:\Tmp
2008-10-13 08:58:15 —-SHD—- C:\RECYCLER
2008-10-10 21:21:58 —-D—- C:\Privat
2008-10-10 13:31:42 —-A—- C:\WINDOWS\Uedit32.ini
2008-09-30 09:40:04 —-D—- C:\SOL
2008-09-23 07:30:31 —-A—- C:\WINDOWS\imsins.BAK
2008-09-23 07:30:26 —-D—- C:\WINDOWS\WinSxS
2008-09-23 07:30:25 —-HD—- C:\WINDOWS\$hf_mig$
2008-09-23 07:29:36 —-D—- C:\WINDOWS\system32\CatRoot
2008-09-19 12:11:14 —-D—- C:\Program Files\Citrix

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys []
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2007-08-31 36352]
R1 SAVRT;SAVRT; \??\C:\Program Files\Symantec Client Security\Symantec AntiVirus\savrt.sys []
R1 SAVRTPEL;SAVRTPEL; \??\C:\Program Files\Symantec Client Security\Symantec AntiVirus\Savrtpel.sys []
R1 SPBBCDrv;SPBBCDrv; \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys []
R1 SYMTDI;SYMTDI; C:\WINDOWS\System32\Drivers\SYMTDI.SYS [2006-08-07 195776]
R1 Tosrfcom;Bluetooth RFCOMM; C:\WINDOWS\System32\Drivers\tosrfcom.sys [2005-08-02 64896]
R2 BtnHnd;BtnHnd; \??\C:\Program Files\Fujitsu\BtnHnd\BtnHnd.sys []
R2 irda;IrDA Protocol; C:\WINDOWS\system32\DRIVERS\irda.sys [2004-08-04 87424]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\WINDOWS\system32\DRIVERS\AGRSM.sys [2006-11-29 1161888]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-04 60800]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2007-08-10 1578496]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2004-08-04 14080]
R3 Eacfilt;Eacfilt Miniport; C:\WINDOWS\system32\DRIVERS\eacfilt.sys [2004-01-26 9817]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys []
R3 FUJ02B1;Fujitsu FUJ02B1 Device Driver; C:\WINDOWS\system32\DRIVERS\FUJ02B1.sys [2001-08-01 5248]
R3 FUJ02E1;%FUJ02E1.DeviceDesc%; C:\WINDOWS\System32\Drivers\FUJ02E1.sys [2004-10-18 5632]
R3 FUJ02E3;Fujitsu FUJ02E3 Device Driver; C:\WINDOWS\system32\DRIVERS\FUJ02E3.sys [2004-01-17 4864]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-08 138752]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-03-12 4486144]
R3 IPSECSHM;Nortel IPSECSHM Adapter; C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys [2004-01-26 117696]
R3 NAVENG;NAVENG; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20081015.003\naveng.sys []
R3 NAVEX15;NAVEX15; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20081015.003\navex15.sys []
R3 NETw4x32;Intel® Wireless WiFi Link Adapter Driver for Windows XP 32 Bit; C:\WINDOWS\system32\DRIVERS\NETw4x32.sys [2008-03-18 2236032]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-04 61824]
R3 O2SCBUS;O2Micro SmartCardBus Reader; C:\WINDOWS\system32\DRIVERS\ozscr.sys [2006-12-08 92552]
R3 Rasirda;WAN Miniport (IrDA); C:\WINDOWS\system32\DRIVERS\rasirda.sys [2001-08-17 19584]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2004-08-04 5888]
R3 SMCIRDA;SMC IrCC Miniport Device Driver; C:\WINDOWS\system32\DRIVERS\smcirda.sys [2001-08-17 35913]
R3 SymEvent;SymEvent; \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS []
R3 SYMREDRV;SYMREDRV; C:\WINDOWS\System32\Drivers\SYMREDRV.SYS [2006-08-07 24768]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2007-07-12 193120]
R3 tosporte;Bluetooth COM Port; C:\WINDOWS\system32\DRIVERS\tosporte.sys [2006-10-11 41600]
R3 Tosrfbd;Bluetooth RFBUS; C:\WINDOWS\System32\Drivers\tosrfbd.sys [2007-04-24 113920]
R3 tosrfbnp;Bluetooth RFBNEP; C:\WINDOWS\System32\Drivers\tosrfbnp.sys [2006-11-21 36480]
R3 Tosrfhid;Bluetooth RFHID; C:\WINDOWS\system32\DRIVERS\Tosrfhid.sys [2007-03-02 73728]
R3 tosrfnds;Bluetooth Personal Area Network; C:\WINDOWS\system32\DRIVERS\tosrfnds.sys [2005-01-06 18612]
R3 Tosrfusb;Bluetooth USB Controller; C:\WINDOWS\System32\Drivers\tosrfusb.sys [2007-06-11 41856]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2006-10-23 30208]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2006-10-23 59264]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2006-10-23 20608]
R3 yukonwxp;NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller; C:\WINDOWS\system32\DRIVERS\yk51x86.sys [2008-03-18 286336]
S1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-04 14848]
S2 IPSECEXT;Nortel Extranet Access Protocol; C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys [2004-01-26 117696]
S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
S3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2008-02-15 5854752]
S3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
S3 OZSCR;O2Micro SmartCardBus Smartcard Reader; C:\WINDOWS\system32\DRIVERS\ozscr.sys [2006-12-08 92552]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2007-09-17 21632]
S3 sdbus;sdbus; C:\WINDOWS\system32\DRIVERS\sdbus.sys [2004-08-04 67584]
S3 SYMDNS;SYMDNS; C:\WINDOWS\System32\Drivers\SYMDNS.SYS [2006-08-07 12992]
S3 SYMFW;SYMFW; C:\WINDOWS\System32\Drivers\SYMFW.SYS [2006-08-07 110784]
S3 SYMIDS;SYMIDS; C:\WINDOWS\System32\Drivers\SYMIDS.SYS [2006-08-07 31936]
S3 SYMIDSCO;SYMIDSCO; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\SymcData\SCFIDS~1\20081010.002\symidsco.sys []
S3 SYMNDIS;SYMNDIS; C:\WINDOWS\System32\Drivers\SYMNDIS.SYS [2006-08-07 28352]
S3 TosRfSnd;Bluetooth Audio; C:\WINDOWS\system32\drivers\tosrfsnd.sys [2007-01-22 53376]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-04 31616]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-15 82688]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 sr;System Restore Filter Driver; C:\WINDOWS\C:\WINDOWS\system32\DRIVERS\sr.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\WINDOWS\system32\agrsmsvc.exe [2006-10-06 9216]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2007-08-10 409600]
R2 ccEvtMgr;Symantec Event Manager; C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe [2006-11-22 192104]
R2 ccProxy;Symantec Network Proxy; C:\Program Files\Common Files\Symantec Shared\ccProxy.exe [2006-11-22 202344]
R2 ccSetMgr;Symantec Settings Manager; C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe [2006-11-22 169576]
R2 DefWatch;Symantec AntiVirus Definition Watcher; C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe [2006-12-20 31424]
R2 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-09-01 137200]
R2 Irmon;Infrared Monitor; C:\WINDOWS\system32\svchost.exe [2004-08-04 14336]
R2 ISSVC;IS Service; C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe [2006-12-14 87680]
R2 IviRegMgr;IviRegMgr; C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe [2007-01-05 112152]
R2 Lotus Notes Single Logon;Lotus Notes Single Logon; C:\Program Files\Lotus\Notes\nslsvice.exe [2007-09-27 8192]
R2 O2Flash;O2Micro Flash Memory; C:\WINDOWS\system32\o2flash.exe [2005-09-13 57344]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2004-08-04 14336]
R2 radexecd;Radia Notify Daemon; C:\Program Files\Novadigm\radexecd.exe [2005-05-04 217268]
R2 radsched;Radia Scheduler Daemon; C:\Program Files\Novadigm\radsched.exe [2004-08-25 245940]
R2 SavRoam;SAVRoam; C:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe [2006-12-20 116928]
R2 SgeCtl;SafeGuard Easy Control; C:\Program Files\Utimaco\SafeGuard Easy\SgeCtl.exe [2007-09-05 90112]
R2 SgLogPlayer;SafeGuard SGLOG Player; C:\WINDOWS\system32\SgLogPlayer.exe [2005-03-31 61440]
R2 SPBBCSvc;Symantec SPBBCSvc; C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe [2006-04-11 1160848]
R2 Symantec AntiVirus;Symantec AntiVirus; C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe [2006-12-20 1814720]
R2 SymSecurePort;Symantec SecurePort; C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe [2006-12-14 173696]
R2 TOSHIBA Bluetooth Service;TOSHIBA Bluetooth Service; C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe [2007-02-26 125048]
R2 WinDefend;Windows Defender; C:\Program Files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
R2 WksCfgSrv;SafeGuard Easy Workstation Server; C:\Program Files\Utimaco\SafeGuard Easy\WksCfgSrv.exe [2007-09-05 155648]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-04 14336]
R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2008-10-14 611664]
R3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2008-08-07 575488]
R3 SNDSrvc;Symantec Network Drivers Service; C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe [2006-08-07 214720]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2006-10-20 36864]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2006-10-30 741376]
S3 LiveUpdate;LiveUpdate; C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE [2006-08-25 2528960]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-19 913408]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2006-10-30 122880]

—————–EOF—————–
Hello

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
ComboFix 08-10-15.08 - a683791 2008-10-16 19:19:34.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1247 [GMT 2:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\WINDOWS\system32\ktsmmqqr.ini
C:\WINDOWS\system32\lmpxpdjv.dll
C:\WINDOWS\system32\MoVDdMoq.ini
C:\WINDOWS\system32\MoVDdMoq.ini2
C:\WINDOWS\system32\pmnoPgfc.dll
C:\WINDOWS\system32\qoMdDVoM.dll
C:\WINDOWS\system32\rqqmmstk.dll
C:\WINDOWS\system32\uzhysa.dll
C:\WINDOWS\system32\x64

—– BITS: Possible infected sites —–

hxxp://78.157.143.163
hxxp://78.157.143.198
.
((((((((((((((((((((((((( Files Created from 2008-09-16 to 2008-10-16 )))))))))))))))))))))))))))))))
.

2008-10-16 07:44 . 2008-10-16 07:44 d——– C:\rsit
2008-10-16 07:44 . 2008-10-16 18:50 d——– C:\Program Files\trend micro
2008-10-15 22:17 . 2008-10-15 22:17 d——– C:\_OTMoveIt
2008-10-15 21:21 . 2008-10-15 21:32 d——– C:\Lop SD
2008-10-14 20:50 . 2008-10-14 20:50 d——– C:\Program Files\Lavasoft
2008-10-14 20:50 . 2008-10-14 20:50 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-10-14 20:49 . 2008-10-14 20:49 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-10-14 11:53 . 2008-10-14 11:53 d——– C:\WINDOWS\system32\%APPDATA%
2008-10-14 09:30 . 2008-10-14 09:30 d——– C:\Documents and Settings\a683791\Application Data\Malwarebytes
2008-10-14 08:31 . 2008-10-14 08:31 d——– C:\Program Files\Windows Defender
2008-10-14 08:21 . 2008-10-14 08:21 d——– C:\Documents and Settings\All Users\Application Data\fkpshuri
2008-10-13 10:47 . 2008-10-13 10:47 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-10-13 10:47 . 2008-10-13 10:47 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-13 10:47 . 2008-10-13 10:47 d——– C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2008-10-13 10:47 . 2008-09-10 00:04 38,528 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-13 10:47 . 2008-09-10 00:03 17,200 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-10-13 10:46 . 2008-10-13 10:46 d——– C:\Program Files\ERUNT
2008-10-13 10:30 . 2008-10-13 10:30 d——– C:\Documents and Settings\Administrator\Application Data\Hydro
2008-10-13 10:28 . 2008-10-10 09:30 1,024 –a—— C:\WINDOWS\system32\SGSAL.dat
2008-10-13 10:07 . 2008-10-13 10:07 0 –a—— C:\WINDOWS\VPC32.INI
2008-09-29 16:48 . 2008-09-29 16:48 d——– C:\Documents and Settings\a683791\Application Data\InterVideo
2008-09-25 09:07 . 2008-09-25 09:07 d——– C:\lotus
2008-09-19 12:10 . 2008-09-19 12:10 60,744 –a—— C:\Documents and Settings\a683791\g2mdlhlpx.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-16 17:27 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-10-15 15:47 ——— d—–w C:\Program Files\Clue
2008-10-15 11:45 ——— d—–w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-10-14 14:05 ——— d—–w C:\Program Files\2321_Remote Access
2008-09-19 10:11 ——— d—–w C:\Program Files\Citrix
2008-09-16 09:35 ——— d—–w C:\Program Files\Common Files\Adobe
2008-09-01 14:00 ——— d—–w C:\Program Files\Google
2008-08-29 20:30 ——— d—–w C:\Program Files\Java
2008-08-29 20:29 ——— d—–w C:\Program Files\Common Files\Java
2008-08-26 05:31 ——— d—–w C:\Program Files\Nokia
2008-08-26 05:31 ——— d—–w C:\Program Files\Common Files\PCSuite
2008-08-26 05:31 ——— d—–w C:\Program Files\Common Files\Nokia
2008-08-26 05:30 ——— d—–w C:\Program Files\PC Connectivity Solution
2008-08-26 05:28 ——— d—–w C:\Documents and Settings\All Users\Application Data\Installations
2008-08-21 10:54 ——— d—–w C:\Documents and Settings\a683791\Application Data\Juniper Networks
2008-08-19 06:42 ——— d—–w C:\Program Files\Common Files\EMC
2008-08-18 10:05 ——— d—–w C:\Program Files\Common Files\Hewlett-Packard
2008-08-18 10:04 ——— d—–w C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
2008-07-17 08:29 155,995 —-a-w C:\WINDOWS\java\Packages\IXBNF1BJ.ZIP
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"PC Suite Tray"="C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2008-08-11 1124352]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe" [2008-06-17 1249280]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-09-01 39408]
"Google Update"="C:\Documents and Settings\a683791\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-03 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"IndicatorUtility"="C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe" [2006-04-20 90112]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-07-12 794713]
"PSUtility"="C:\Program Files\Fujitsu\PSUtility\TrayManager.exe" [2007-07-12 118784]
"TvOutSwitch"="C:\Program Files\Fujitsu\DispSwitch\DispSwitchLauncher.exe" [2007-07-12 81920]
"LoadFUJ02E3"="C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe" [2006-11-18 80688]
"LoadFujitsuQuickTouch"="C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe" [2005-11-02 353792]
"LoadBtnHnd"="C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe" [2005-11-02 61440]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-03 45056]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-13 155648]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2008-02-15 135168]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2008-02-15 159744]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2008-02-15 131072]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"RunOSSettings"="C:\Program Files\Hydro\Image\2ndRegSett.vbs" [2006-08-10 1907]
"BinD Manager"="C:\Program Files\Hydro\BinD\B_Manager\B_Manager.exe" [2007-03-19 20480]
"BinD Maintenance Run Scripts"="C:\WINDOWS\system32\wscript.exe" [2004-08-04 114688]
"BinD Scheduler"="C:\PROGRA~1\Hydro\BinD\B_Sched.exe" [2002-12-02 650752]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SgeEcView"="C:\Program Files\Utimaco\SafeGuard Easy\Ecview.exe" [2007-09-05 24576]
"EdWizard"="C:\Program Files\Utimaco\SafeGuard Easy\EdWizard.exe" [2007-09-05 245760]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-11-22 52840]
"vptray"="C:\PROGRA~1\SYMANT~2\SYMANT~1\VPTray.exe" [2006-12-20 125632]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"RTHDCPL"="RTHDCPL.EXE" [2007-03-12 C:\WINDOWS\RTHDCPL.EXE]
"AGRSMMSG"="AGRSMMSG.exe" [2006-06-29 C:\WINDOWS\AGRSMMSG.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"TSClientMSIUninstaller"="C:\WINDOWS\Installer\TSClientMsiTrans\tscuinst.vbs" [2006-11-07 12451]

C:\Documents and Settings\a683791\Start Menu\Programs\Startup\
Webshots.lnk - C:\Program Files\Webshots\Launcher.exe [2008-08-12 157000]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-05-23 2756608]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"disablecad"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceStartMenuLogOff"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\FJWSEL]
2007-07-12 16:48 32768 C:\WINDOWS\system32\FJWSWNP.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\NotLog]
2002-01-22 15:28 110592 C:\WINDOWS\system32\SGLogEx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PSUTY]
2007-07-12 16:48 32768 C:\WINDOWS\system32\PSUWNP.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SGLogNotification]
2005-03-31 11:27 69632 C:\WINDOWS\system32\SGLogNotification.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=uzhysa.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2999592156-3707333719-387015933-5187\Scripts\logon\0\0]
"Script"=login.vbs

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2999592156-3707333719-387015933-5284\Scripts\Logon\0\0]
"Script"=login.vbs

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2999592156-3707333719-387015933-5594\Scripts\Logon\0\0]
"Script"=login.vbs

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Hydro\\Image\\GetSiteInfo\\B_GetSiteInfo.exe"=
"C:\\Program Files\\Hydro\\Image\\ntpdate.exe"=
"C:\\Program Files\\InterVideo\\DVD8\\WinDVD.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R0 BLOWFISH-16;BLOWFISH-16;C:\WINDOWS\system32\DRIVERS\BLOWF16.SYS [2007-09-05 6016]
R0 O2MDRDR;O2MDRDR;C:\WINDOWS\system32\DRIVERS\o2media.sys [2005-07-08 34176]
R0 O2SDRDR;O2SDRDR;C:\WINDOWS\system32\DRIVERS\o2sd.sys [2005-09-23 28544]
R0 SgeFlt;SgeFlt;C:\WINDOWS\system32\DRIVERS\SGEFLT.SYS [2007-09-05 62720]
R2 radexecd;Radia Notify Daemon;C:\Program Files\Novadigm\radexecd.exe [2005-05-04 217268]
R2 radsched;Radia Scheduler Daemon;C:\Program Files\Novadigm\radsched.exe [2004-08-25 245940]
R3 Eacfilt;Eacfilt Miniport;C:\WINDOWS\system32\DRIVERS\eacfilt.sys [2004-01-26 9817]
R3 FUJ02E1;%FUJ02E1.DeviceDesc%;C:\WINDOWS\system32\Drivers\FUJ02E1.sys [2004-10-18 5632]
R3 FUJ02E3;Fujitsu FUJ02E3 Device Driver;C:\WINDOWS\system32\DRIVERS\FUJ02E3.sys [2004-01-17 4864]
R3 IPSECSHM;Nortel IPSECSHM Adapter;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys [2004-01-26 117696]
S2 IPSECEXT;Nortel Extranet Access Protocol;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys [2004-01-26 117696]
S3 OZSCR;O2Micro SmartCardBus Smartcard Reader;C:\WINDOWS\system32\DRIVERS\ozscr.sys [2006-12-08 92552]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder

2008-10-16 C:\WINDOWS\Tasks\GoogleUpdateTaskUser.job
- C:\Documents and Settings\a683791\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-03 14:22]

2008-10-16 C:\WINDOWS\Tasks\MP Scheduled Scan.job
- C:\Program Files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
.
- - - - ORPHANS REMOVED - - - -

BHO-{30846f2b-d868-4ddf-bbb8-914b256b4c77} - C:\WINDOWS\system32\uzhysa.dll
BHO-{3FCFD9B4-660E-418D-8FA5-C73BC5EA16DE} - C:\WINDOWS\system32\awturSJa.dll
BHO-{8DDA7038-2E38-4A41-9411-978DC02EF143} - C:\WINDOWS\system32\qoMdDVoM.dll
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
ShellIconOverlayIdentifiers-{ba930330-a721-11d3-a7b9-00500464ee16} - Sgedrse.Dll
ShellIconOverlayIdentifiers-{2030D939-54A7-4fea-9B06-49EA77EFC87F} - Sgedrse.Dll
HKLM-Run-FFAKNNVF - C:\WINDOWS\FFAKNNVF.exe
HKLM-Run-bivfffcz - C:\WINDOWS\bivfffcz.exe
HKLM-Run-b4472bb5 - C:\WINDOWS\system32\rqqmmstk.dll
ShellExecuteHooks-{0574D50F-C261-490D-BF39-4E91183C4EFB} - (no file)


.
——- Supplementary Scan ——-
.
R0 -: HKCU-Main,Start Page = hxxp://inside.ispartner.com/
R0 -: HKCU-Main,Search Page = hxxp://www.google.com
R0 -: HKCU-Main,Search Bar = hxxp://www.google.com/ie
R0 -: HKLM-Main,Default_Search_URL = hxxp://www.google.com/ie
R0 -: HKLM-Main,Start Page = hxxp://www.google.com
R1 -: HKCU-Internet Connection Wizard,ShellNext = hxxp://inside.ispartner.com/
R0 -: HKCU-Search,SearchAssistant = hxxp://www.google.com/ie
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s
R0 -: HKLM-Search,SearchAssistant = hxxp://www.google.com/ie
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O16 -: Microsoft XML Parser for Java - file://C:\WINDOWS\Java\classes\xmldso.cab
C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd

O16 -: {759FD3DE-F0EF-4A76-909C-88CF840D4173} - hxxps://webtop.hda.hydro.com/webtop/wdk/native/WdkPluginCab.CAB
C:\WINDOWS\Downloaded Program Files\WdkPluginCab.inf
C:\WINDOWS\Downloaded Program Files\WdkPlugin.dll
.
.
——- File Associations ——-
.
inffile="C:\Program Files\UltraEdit\uedit32.exe" "%1"
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-16 19:28:51
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\SGEGINATHK.DLL
-> C:\Program Files\Utimaco\SafeGuard Easy\SGUICL.MSG
-> C:\Program Files\Utimaco\SafeGuard Easy\SGE_ERR0409.DLL
-> C:\Program Files\Utimaco\SafeGuard Easy\SGE_MSG0409.DLL
-> C:\Program Files\Utimaco\SafeGuard Easy\SGE_INFO0409.DLL
-> C:\Program Files\Utimaco\SafeGuard Easy\SecClassFactoryPS.dll
-> C:\Program Files\Utimaco\SafeGuard Easy\wkscfgsrvps.dll
.
———————— Other Running Processes ————————
.
C:\Program Files\Lotus\Notes\nslsvice.exe
C:\Program Files\Lotus\Notes\nsl.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\scardsvr.exe
C:\WINDOWS\system32\agrsmsvc.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\WINDOWS\system32\o2flash.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Utimaco\SafeGuard Easy\SgeCtl.exe
C:\WINDOWS\system32\SgLogPlayer.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\Program Files\Utimaco\SafeGuard Easy\WksCfgSrv.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\PROGRA~1\Webshots\Webshots.scr
C:\Program Files\Symantec Client Security\Symantec AntiVirus\DoScan.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
C:\Program Files\Common Files\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclIrSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclToBTSrv.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosOBEX.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtProc.exe
.
**************************************************************************
.
Completion time: 2008-10-16 19:34:20 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-16 17:34:16

Pre-Run: 67 498 192 896 bytes free
Post-Run: 67,408,576,512 bytes free

277 — E O F — 2008-09-23 05:38:42
Hello


1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\Documents and Settings\a683791\g2mdlhlpx.exe

Folder::
C:\Documents and Settings\All Users\Application Data\fkpshuri

Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=""

Driver::


Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.





  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:

    • C:\WINDOWS\java\Packages\IXBNF1BJ.ZIP
  • Click on the Upload button
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.
Hello
First.

I got this error when trying to upload C:\WINDOWS\java\Packages\IXBNF1BJ.ZIP on VirSCAN.org
ERROR:Compress files limit 10 files, IXBNF1BJ.ZIP is zip archive, include 48 files!


Here is the last log from ComboFix :


ComboFix 08-10-15.08 - 2008-10-16 22:29:25.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1325 [GMT 2:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\a683791\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\Documents and Settings\a683791\g2mdlhlpx.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\a683791\g2mdlhlpx.exe
C:\Documents and Settings\All Users\Application Data\fkpshuri
C:\Documents and Settings\All Users\Application Data\fkpshuri\tizuvwxe.exe

.
((((((((((((((((((((((((( Files Created from 2008-09-16 to 2008-10-16 )))))))))))))))))))))))))))))))
.

2008-10-16 07:44 . 2008-10-16 07:44 d——– C:\rsit
2008-10-16 07:44 . 2008-10-16 18:50 d——– C:\Program Files\trend micro
2008-10-15 22:17 . 2008-10-15 22:17 d——– C:\_OTMoveIt
2008-10-15 21:21 . 2008-10-15 21:32 d——– C:\Lop SD
2008-10-14 20:50 . 2008-10-14 20:50 d——– C:\Program Files\Lavasoft
2008-10-14 20:50 . 2008-10-14 20:50 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-10-14 20:49 . 2008-10-14 20:49 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-10-14 11:53 . 2008-10-14 11:53 d——– C:\WINDOWS\system32\%APPDATA%
2008-10-14 09:30 . 2008-10-14 09:30 d——– C:\Documents and Settings\a683791\Application Data\Malwarebytes
2008-10-14 08:31 . 2008-10-14 08:31 d——– C:\Program Files\Windows Defender
2008-10-13 10:47 . 2008-10-13 10:47 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-10-13 10:47 . 2008-10-13 10:47 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-13 10:47 . 2008-10-13 10:47 d——– C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2008-10-13 10:47 . 2008-09-10 00:04 38,528 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-13 10:47 . 2008-09-10 00:03 17,200 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-10-13 10:46 . 2008-10-13 10:46 d——– C:\Program Files\ERUNT
2008-10-13 10:30 . 2008-10-13 10:30 d——– C:\Documents and Settings\Administrator\Application Data\Hydro
2008-10-13 10:28 . 2008-10-10 09:30 1,024 –a—— C:\WINDOWS\system32\SGSAL.dat
2008-10-13 10:07 . 2008-10-13 10:07 0 –a—— C:\WINDOWS\VPC32.INI
2008-09-29 16:48 . 2008-09-29 16:48 d——– C:\Documents and Settings\a683791\Application Data\InterVideo
2008-09-25 09:07 . 2008-09-25 09:07 d——– C:\lotus

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-16 17:27 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-10-15 15:47 ——— d—–w C:\Program Files\Clue
2008-10-15 11:45 ——— d—–w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-10-14 14:05 ——— d—–w C:\Program Files\2321_Remote Access
2008-09-19 10:11 ——— d—–w C:\Program Files\Citrix
2008-09-16 09:35 ——— d—–w C:\Program Files\Common Files\Adobe
2008-09-01 14:00 ——— d—–w C:\Program Files\Google
2008-08-29 20:30 ——— d—–w C:\Program Files\Java
2008-08-29 20:29 ——— d—–w C:\Program Files\Common Files\Java
2008-08-26 05:31 ——— d—–w C:\Program Files\Nokia
2008-08-26 05:31 ——— d—–w C:\Program Files\Common Files\PCSuite
2008-08-26 05:31 ——— d—–w C:\Program Files\Common Files\Nokia
2008-08-26 05:30 ——— d—–w C:\Program Files\PC Connectivity Solution
2008-08-26 05:28 ——— d—–w C:\Documents and Settings\All Users\Application Data\Installations
2008-08-21 10:54 ——— d—–w C:\Documents and Settings\a683791\Application Data\Juniper Networks
2008-08-19 06:42 ——— d—–w C:\Program Files\Common Files\EMC
2008-08-18 10:05 ——— d—–w C:\Program Files\Common Files\Hewlett-Packard
2008-08-18 10:04 ——— d—–w C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
2008-08-12 06:44 48,768 —-a-w C:\WINDOWS\system32\S32EVNT1.DLL
2008-07-17 08:29 155,995 —-a-w C:\WINDOWS\java\Packages\IXBNF1BJ.ZIP
.

((((((((((((((((((((((((((((( snapshot@2008-10-16_19.33.56.14 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-10-16 17:28:50 53,248 —-a-w C:\WINDOWS\Temp\catchme.dll
+ 2008-10-16 20:30:28 53,248 —-a-w C:\WINDOWS\Temp\catchme.dll
+ 2008-10-16 17:31:26 16,384 —-atw C:\WINDOWS\Temp\Perflib_Perfdata_1198.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"PC Suite Tray"="C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2008-08-11 1124352]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe" [2008-06-17 1249280]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-09-01 39408]
"Google Update"="C:\Documents and Settings\a683791\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-03 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"IndicatorUtility"="C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe" [2006-04-20 90112]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-07-12 794713]
"PSUtility"="C:\Program Files\Fujitsu\PSUtility\TrayManager.exe" [2007-07-12 118784]
"TvOutSwitch"="C:\Program Files\Fujitsu\DispSwitch\DispSwitchLauncher.exe" [2007-07-12 81920]
"LoadFUJ02E3"="C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe" [2006-11-18 80688]
"LoadFujitsuQuickTouch"="C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe" [2005-11-02 353792]
"LoadBtnHnd"="C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe" [2005-11-02 61440]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-03 45056]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-13 155648]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2008-02-15 135168]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2008-02-15 159744]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2008-02-15 131072]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"RunOSSettings"="C:\Program Files\Hydro\Image\2ndRegSett.vbs" [2006-08-10 1907]
"BinD Manager"="C:\Program Files\Hydro\BinD\B_Manager\B_Manager.exe" [2007-03-19 20480]
"BinD Maintenance Run Scripts"="C:\WINDOWS\system32\wscript.exe" [2004-08-04 114688]
"BinD Scheduler"="C:\PROGRA~1\Hydro\BinD\B_Sched.exe" [2002-12-02 650752]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SgeEcView"="C:\Program Files\Utimaco\SafeGuard Easy\Ecview.exe" [2007-09-05 24576]
"EdWizard"="C:\Program Files\Utimaco\SafeGuard Easy\EdWizard.exe" [2007-09-05 245760]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-11-22 52840]
"vptray"="C:\PROGRA~1\SYMANT~2\SYMANT~1\VPTray.exe" [2006-12-20 125632]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"RTHDCPL"="RTHDCPL.EXE" [2007-03-12 C:\WINDOWS\RTHDCPL.EXE]
"AGRSMMSG"="AGRSMMSG.exe" [2006-06-29 C:\WINDOWS\AGRSMMSG.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"TSClientMSIUninstaller"="C:\WINDOWS\Installer\TSClientMsiTrans\tscuinst.vbs" [2006-11-07 12451]

C:\Documents and Settings\a683791\Start Menu\Programs\Startup\
Webshots.lnk - C:\Program Files\Webshots\Launcher.exe [2008-08-12 157000]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-05-23 2756608]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"disablecad"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceStartMenuLogOff"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\FJWSEL]
2007-07-12 16:48 32768 C:\WINDOWS\system32\FJWSWNP.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\NotLog]
2002-01-22 15:28 110592 C:\WINDOWS\system32\SGLogEx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PSUTY]
2007-07-12 16:48 32768 C:\WINDOWS\system32\PSUWNP.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SGLogNotification]
2005-03-31 11:27 69632 C:\WINDOWS\system32\SGLogNotification.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2999592156-3707333719-387015933-5187\Scripts\logon\0\0]
"Script"=login.vbs

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2999592156-3707333719-387015933-5284\Scripts\Logon\0\0]
"Script"=login.vbs

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2999592156-3707333719-387015933-5594\Scripts\Logon\0\0]
"Script"=login.vbs

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Hydro\\Image\\GetSiteInfo\\B_GetSiteInfo.exe"=
"C:\\Program Files\\Hydro\\Image\\ntpdate.exe"=
"C:\\Program Files\\InterVideo\\DVD8\\WinDVD.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R0 BLOWFISH-16;BLOWFISH-16;C:\WINDOWS\system32\DRIVERS\BLOWF16.SYS [2007-09-05 6016]
R0 O2MDRDR;O2MDRDR;C:\WINDOWS\system32\DRIVERS\o2media.sys [2005-07-08 34176]
R0 O2SDRDR;O2SDRDR;C:\WINDOWS\system32\DRIVERS\o2sd.sys [2005-09-23 28544]
R0 SgeFlt;SgeFlt;C:\WINDOWS\system32\DRIVERS\SGEFLT.SYS [2007-09-05 62720]
R2 radexecd;Radia Notify Daemon;C:\Program Files\Novadigm\radexecd.exe [2005-05-04 217268]
R2 radsched;Radia Scheduler Daemon;C:\Program Files\Novadigm\radsched.exe [2004-08-25 245940]
R3 Eacfilt;Eacfilt Miniport;C:\WINDOWS\system32\DRIVERS\eacfilt.sys [2004-01-26 9817]
R3 FUJ02E1;%FUJ02E1.DeviceDesc%;C:\WINDOWS\system32\Drivers\FUJ02E1.sys [2004-10-18 5632]
R3 FUJ02E3;Fujitsu FUJ02E3 Device Driver;C:\WINDOWS\system32\DRIVERS\FUJ02E3.sys [2004-01-17 4864]
R3 IPSECSHM;Nortel IPSECSHM Adapter;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys [2004-01-26 117696]
S2 IPSECEXT;Nortel Extranet Access Protocol;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys [2004-01-26 117696]
S3 OZSCR;O2Micro SmartCardBus Smartcard Reader;C:\WINDOWS\system32\DRIVERS\ozscr.sys [2006-12-08 92552]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder

2008-10-16 C:\WINDOWS\Tasks\GoogleUpdateTaskUser.job
- C:\Documents and Settings\a683791\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-03 14:22]

2008-10-16 C:\WINDOWS\Tasks\MP Scheduled Scan.job
- C:\Program Files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-16 22:30:29
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\SGEGINATHK.DLL
-> C:\Program Files\Utimaco\SafeGuard Easy\SGUICL.MSG
-> C:\Program Files\Utimaco\SafeGuard Easy\SGE_ERR0409.DLL
-> C:\Program Files\Utimaco\SafeGuard Easy\SGE_MSG0409.DLL
-> C:\Program Files\Utimaco\SafeGuard Easy\SGE_INFO0409.DLL
-> C:\Program Files\Utimaco\SafeGuard Easy\SecClassFactoryPS.dll
-> C:\Program Files\Utimaco\SafeGuard Easy\wkscfgsrvps.dll
.
Completion time: 2008-10-16 22:31:07
ComboFix-quarantined-files.txt 2008-10-16 20:31:04
ComboFix2.txt 2008-10-16 17:34:21

Pre-Run: 67,388,137,472 bytes free
Post-Run: 67,372,851,200 bytes free

195 — E O F — 2008-09-23 05:38:42

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI