This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved]  got a trojan and i'm clueless

27 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

there is nothing called log.txt.


i sent you the logs in two separate emails….. i sent one…then i chatted about some of the other problems i was having with the computer, then i sent you the second one…..

this is all i have in that file:

info.txt logfile of random's system information tool 1.04 2008-10-25 01:44:30

======Uninstall list======

–>C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
–>C:\Program Files\Nero\Nero 7\\nero\uninstall\UNNERO.exe /UNINSTALL
–>C:\WINDOWS\NuNInst.exe /UNINSTALL
–>C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
–>rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Acronis True Image Home–>MsiExec.exe /X{419CF344-3D94-4DAD-99C8-EA7B00E5EA8B}
Adobe Flash Player ActiveX–>C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 7.0.9–>MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70900000002}
ArcSoft PhotoBase 3–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A5460871-42FF-45CD-A634-01C755E9CEA1}\SETUP.EXE" -l0x9 -uninst
ArcSoft PhotoImpression–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{797703D4-461B-4BC9-AACA-292917F3A47F}\SETUP.EXE" -l0x9 -uninst
Desktop Taipei version 2.2–>"C:\Program Files\Desktop Taipei\unins000.exe"
DivX Codec–>C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
DivX Content Uploader–>C:\Program Files\DivX\DivXContentUploaderUninstall.exe /CUPLOADER
DivX Converter–>C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
DivX Player–>C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
DivX Web Player–>C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
DV Series–>C:\Program Files\DV Series\uninst.exe
DVC301–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5AA4D39A-C9FE-4EC9-8DA5-57015C4260C1}\Setup.exe"
High Definition Audio Driver Package - KB888111–>"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
Hijackthis 1.99.1–>"C:\Program Files\Hijackthis\unins000.exe"
HijackThis 2.0.2–>"C:\Program Files\trend micro\HijackThis.exe" /uninstall
Hotfix for Windows Media Format 11 SDK (KB929399)–>"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Hotfix for Windows Media Player 11 (KB939683)–>"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB952287)–>"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
InterVideo WinDVD–>"C:\Program Files\InstallShield Installation Information\{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}\setup.exe" REMOVEALL
Java™ 6 Update 10–>MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216010FF}
Luxor (remove only)–>"C:\Program Files\MumboJumbo\Luxor\uninstall.exe"
Malwarebytes' Anti-Malware–>"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Microsoft .NET Framework 1.1 Hotfix (KB928366)–>"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1–>msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1–>MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft Compression Client Pack 1.0 for Windows XP–>"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Home Publishing 2000–>MsiExec.exe /I{0CD3BB5C-BBCA-11D2-8C20-00C04FBBCFF9}
Microsoft Internationalized Domain Names Mitigation APIs–>"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs–>"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office 2000 SR-1 Premium–>MsiExec.exe /I{00000409-78E1-11D2-B60F-006097C998E7}
Microsoft User-Mode Driver Framework Feature Pack 1.0–>"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable–>MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
MSXML 4.0 SP2 (KB936181)–>MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
Nero 7 Essentials–>MsiExec.exe /X{9B4E6CB9-E54D-47F7-A414-E2D5740E1033}
neroxml–>MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
Prime95–>"C:\Program Files\Prime95\Uninstall.exe" "C:\Program Files\Prime95\install.log"
Realtek High Definition Audio Driver–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x9 -removeonly
Security Update for Windows Internet Explorer 7 (KB938127)–>"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB942615)–>"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB944533)–>"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB950759)–>"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB953838)–>"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB956390)–>"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB936782)–>"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB954154)–>"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923789)–>C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
Security Update for Windows XP (KB938464)–>"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)–>"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)–>"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950760)–>"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)–>"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)–>"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)–>"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)–>"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)–>"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)–>"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)–>"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953839)–>"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954211)–>"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956391)–>"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)–>"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956841)–>"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957095)–>"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)–>"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Sound'Em 1.0–>C:\Program Files\DV Series\UNWISE.EXE C:\Program Files\DV Series\install.log
Update for Windows XP (KB951072-v2)–>"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Update for Windows XP (KB951978)–>"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Verizon Broadband Toolbar–>C:\Program Files\vol_toolbar\uninstall.exe
Verizon Online Help and Support–>C:\PROGRA~1\Verizon\UNWISE.EXE C:\PROGRA~1\Verizon\INSTALL.LOG
Verizon Servicepoint 1.5.20–>"C:\Program Files\Verizon\VSP\unins000.exe"
VIA Rhine-Family Fast-Ethernet Adapter–>Rundll32.exe vuins32.dll,vuins32Ex $Rhine $VIA
VIA/S3G Display Driver 6.14.10.0075–>C:\PROGRA~1\S3\UChromeP\s3minset.exe /u UChromeP.uns
Windows Driver Package - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0)–>C:\PROGRA~1\DIFX\7B44739871F4D539FA473F57A832EA4B6A59EF06\DPInst.exe /d /u C:\WINDOWS\system32\DRVSTORE\amdk8_C074F64CC74B03BC354BB5DC973CCF768D5A7194\amdk8.inf
Windows Media Format 11 runtime–>"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime–>"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11–>"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11–>"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows XP Service Pack 3–>"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
Zuma Deluxe 1.0–>C:\Program Files\PopCap Games\Zuma Deluxe\PopUninstall.exe "C:\Program Files\PopCap Games\Zuma Deluxe\Install.log"

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 107 Stepping 1, AuthenticAMD
"PROCESSOR_REVISION"=6b01
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP

—————–EOF—————–

ogfile of random's system information tool 1.04 (written by random/random)
Run by [removed] at 2008-10-25 01:44:13
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 67 GB (87%) free of 76 GB
Total RAM: 894 MB (64% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:44:28 AM, on 10/25/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\S3trayp.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Verizon\McciTrayApp.exe
C:\Program Files\Verizon\VSP\VerizonServicepoint.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\DV Series\Console\Watch.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\YWJJX5QM\RSIT[1].exe
C:\Program Files\trend micro\User.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.netzero.net/s/search?r=minisearch
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-8CB0-AB60BB9AAE22} - C:\PROGRA~1\VOL_TO~1\VOL_TO~1.DLL (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [S3Trayp] S3trayp.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SecurDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe
O4 - HKLM\..\Run: [VerizonServicepoint.exe] "C:\Program Files\Verizon\VSP\VerizonServicepoint.exe" /AUTORUN
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Watch.lnk = C:\Program Files\DV Series\Console\Watch.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon…20Installer.cab
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe

–
End of file - 5753 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-12-18 59032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4E7BD74F-2B8D-469E-8CB0-AB60BB9AAE22}]
Verizon Broadband Toolbar - C:\PROGRA~1\VOL_TO~1\VOL_TO~1.DLL []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre6\bin\ssv.dll [2008-10-25 320920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-10-25 34816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2008-10-25 73728]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"=C:\WINDOWS\system32\VTTimer.exe [2006-09-21 53248]
"S3Trayp"=C:\WINDOWS\system32\S3trayp.exe [2006-10-09 176128]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2007-08-10 16384000]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-01 153136]
"SecurDisc"=C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe [2007-05-15 1628208]
"InCD"=C:\Program Files\Nero\Nero 7\InCD\InCD.exe [2007-05-15 1057328]
"TrueImageMonitor.exe"=C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe [2006-10-16 1164912]
"AcronisTimounterMonitor"=C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe [2006-10-16 1941784]
"Acronis Scheduler2 Service"=C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe [2006-10-16 87584]
"Verizon_McciTrayApp"=C:\Program Files\Verizon\McciTrayApp.exe [2007-09-28 936960]
"VerizonServicepoint.exe"=C:\Program Files\Verizon\VSP\VerizonServicepoint.exe [2008-02-13 2065648]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2008-10-25 136600]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-13 1695232]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE
Microsoft Works Calendar Reminders.lnk - C:\WINDOWS\Installer\{0CD3BB5C-BBCA-11D2-8C20-00C04FBBCFF9}\A94AAB13.exe
Watch.lnk - C:\Program Files\DV Series\Console\Watch.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
relog_ap

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Grisoft\AVG7\avginet.exe"="C:\Program Files\Grisoft\AVG7\avginet.exe:*:Enabled:avginet.exe"
"C:\Program Files\Grisoft\AVG7\avgamsvr.exe"="C:\Program Files\Grisoft\AVG7\avgamsvr.exe:*:Enabled:avgamsvr.exe"
"C:\Program Files\Grisoft\AVG7\avgcc.exe"="C:\Program Files\Grisoft\AVG7\avgcc.exe:*:Enabled:avgcc.exe"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2c203ae0-c126-11dc-9e32-001d92410860}]
shell\AutoRun\command - E:\lzext.exe


======List of files/folders created in the last 1 months======

2008-10-25 01:44:13 —-D—- C:\rsit
2008-10-25 01:44:13 —-D—- C:\Program Files\trend micro
2008-10-25 01:08:44 —-A—- C:\WINDOWS\system32\javaws.exe
2008-10-25 01:08:44 —-A—- C:\WINDOWS\system32\javaw.exe
2008-10-25 01:08:44 —-A—- C:\WINDOWS\system32\java.exe
2008-10-25 01:08:44 —-A—- C:\WINDOWS\system32\deploytk.dll
2008-10-24 23:14:42 —-D—- C:\Documents and Settings\User\Application Data\Malwarebytes
2008-10-24 23:14:37 —-D—- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-24 23:14:37 —-D—- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-24 10:09:56 —-HDC—- C:\WINDOWS\$NtUninstallKB958644$
2008-10-24 07:28:00 —-A—- C:\WINDOWS\system32\CF11254.exe
2008-10-24 07:27:09 —-A—- C:\WINDOWS\system32\CF11087.exe
2008-10-24 07:25:36 —-A—- C:\WINDOWS\system32\CF10781.exe
2008-10-24 07:25:35 —-A—- C:\Bug.txt
2008-10-24 07:19:55 —-D—- C:\Documents and Settings\All Users\Application Data\Avg8
2008-10-23 22:19:40 —-D—- C:\Program Files\Hijackthis
2008-10-23 20:05:03 —-D—- C:\Program Files\AVG
2008-10-20 12:45:28 —-A—- C:\WINDOWS\system32\kbdkor.dll
2008-10-20 12:45:28 —-A—- C:\WINDOWS\system32\kbdjpn.dll
2008-10-20 12:45:28 —-A—- C:\WINDOWS\system32\kbd103.dll
2008-10-20 12:45:28 —-A—- C:\WINDOWS\system32\kbd101c.dll
2008-10-20 12:45:26 —-A—- C:\WINDOWS\system32\kbd101b.dll
2008-10-20 12:45:25 —-A—- C:\WINDOWS\system32\kbd106.dll
2008-10-18 03:00:29 —-HDC—- C:\WINDOWS\$NtUninstallKB951978$
2008-10-17 10:43:28 —-D—- C:\WINDOWS\Prefetch
2008-10-17 10:42:06 —-HDC—- C:\WINDOWS\$NtUninstallKB957095$
2008-10-17 10:42:01 —-HDC—- C:\WINDOWS\$NtUninstallKB956841$
2008-10-17 10:41:56 —-HDC—- C:\WINDOWS\$NtUninstallKB956803$
2008-10-17 10:41:51 —-HDC—- C:\WINDOWS\$NtUninstallKB954211$
2008-10-17 10:41:46 —-HDC—- C:\WINDOWS\$NtUninstallKB952954$
2008-10-17 10:41:42 —-HDC—- C:\WINDOWS\$NtUninstallKB952287$
2008-10-17 10:41:38 —-HDC—- C:\WINDOWS\$NtUninstallKB951748$
2008-10-17 10:41:34 —-HDC—- C:\WINDOWS\$NtUninstallKB951698$
2008-10-17 10:41:30 —-HDC—- C:\WINDOWS\$NtUninstallKB951376-v2$
2008-10-17 10:41:24 —-HDC—- C:\WINDOWS\$NtUninstallKB951066$
2008-10-17 10:41:20 —-HDC—- C:\WINDOWS\$NtUninstallKB950974$
2008-10-17 10:41:16 —-HDC—- C:\WINDOWS\$NtUninstallKB950762$
2008-10-17 10:41:11 —-HDC—- C:\WINDOWS\$NtUninstallKB946648$
2008-10-17 10:41:08 —-HDC—- C:\WINDOWS\$NtUninstallKB938464$
2008-10-17 10:38:50 —-D—- C:\WINDOWS\system32\scripting
2008-10-17 10:38:50 —-D—- C:\WINDOWS\system32\en
2008-10-17 10:38:50 —-D—- C:\WINDOWS\l2schemas
2008-10-17 10:38:49 —-D—- C:\WINDOWS\system32\bits
2008-10-17 10:37:29 —-D—- C:\WINDOWS\ServicePackFiles
2008-10-17 10:33:10 —-HDC—- C:\WINDOWS\$NtServicePackUninstall$
2008-10-17 10:33:09 —-D—- C:\WINDOWS\EHome
2008-10-14 19:45:31 —-HDC—- C:\WINDOWS\$NtUninstallKB956803_0$
2008-10-14 19:45:27 —-HDC—- C:\WINDOWS\$NtUninstallKB956391$
2008-10-14 19:45:23 —-HDC—- C:\WINDOWS\$NtUninstallKB957095_0$
2008-10-14 19:45:01 —-HDC—- C:\WINDOWS\$NtUninstallKB954211_0$
2008-10-14 19:44:52 —-HDC—- C:\WINDOWS\$NtUninstallKB956841_0$
2008-09-29 03:01:32 —-D—- C:\Documents and Settings\User\Application Data\ArcSoft
2008-09-29 02:58:07 —-A—- C:\WINDOWS\PB_setup.ini
2008-09-29 02:57:05 —-D—- C:\Program Files\ArcSoft
2008-09-29 02:57:05 —-A—- C:\WINDOWS\PI_setup.ini
2008-09-29 02:57:05 —-A—- C:\WINDOWS\pcdlib32.dll
2008-09-29 02:32:22 —-A—- C:\WINDOWS\Active Setup Log.txt
2008-09-29 02:16:36 —-D—- C:\Documents and Settings\User\Application Data\Help
2008-09-29 02:09:56 —-A—- C:\WINDOWS\Ulead32.ini
2008-09-29 02:09:54 —-D—- C:\Program Files\Ulead Systems
2008-09-29 02:08:18 —-A—- C:\WINDOWS\system32\MKCoInstaller.dll
2008-09-29 02:06:47 —-D—- C:\Program Files\DV Series
2008-09-28 18:18:10 —-D—- C:\Documents and Settings\User\Application Data\Motive

======List of files/folders modified in the last 1 months======

2008-10-25 01:44:13 —-RD—- C:\Program Files
2008-10-25 01:23:10 —-SHD—- C:\WINDOWS\Installer
2008-10-25 01:22:27 —-D—- C:\Program Files\Java
2008-10-25 01:22:26 —-D—- C:\Program Files\Common Files
2008-10-25 01:22:18 —-D—- C:\WINDOWS\system32
2008-10-25 01:17:31 —-D—- C:\WINDOWS\Temp
2008-10-25 01:16:54 —-A—- C:\WINDOWS\SchedLgU.Txt
2008-10-25 01:05:40 —-SD—- C:\WINDOWS\Downloaded Program Files
2008-10-24 23:14:40 —-D—- C:\WINDOWS\system32\drivers
2008-10-24 11:57:18 —-D—- C:\WINDOWS
2008-10-24 10:10:00 —-HD—- C:\WINDOWS\inf
2008-10-24 10:09:58 —-RSHDC—- C:\WINDOWS\system32\dllcache
2008-10-24 10:09:35 —-HD—- C:\WINDOWS\$hf_mig$
2008-10-24 10:09:34 —-D—- C:\WINDOWS\system32\CatRoot2
2008-10-24 07:19:07 —-SD—- C:\Documents and Settings\User\Application Data\Microsoft
2008-10-24 07:18:23 —-D—- C:\Documents and Settings\User\Application Data\SUPERAntiSpyware.com
2008-10-24 07:18:19 —-D—- C:\Program Files\SUPERAntiSpyware
2008-10-24 07:17:59 —-D—- C:\Program Files\SpywareBlaster
2008-10-23 20:09:57 —-D—- C:\Program Files\vol_toolbar
2008-10-20 12:45:35 —-D—- C:\WINDOWS\Help
2008-10-20 12:45:31 —-RSD—- C:\WINDOWS\Fonts
2008-10-20 03:10:00 —-A—- C:\WINDOWS\win.ini
2008-10-18 03:00:33 —-A—- C:\WINDOWS\imsins.BAK
2008-10-17 10:45:01 —-A—- C:\WINDOWS\system32\PerfStringBackup.INI
2008-10-17 10:43:51 —-A—- C:\WINDOWS\OEWABLog.txt
2008-10-17 10:43:31 —-A—- C:\WINDOWS\setuplog.txt
2008-10-17 10:43:01 —-D—- C:\WINDOWS\system32\Setup
2008-10-17 10:43:01 —-D—- C:\WINDOWS\AppPatch
2008-10-17 10:43:01 —-D—- C:\Program Files\Messenger
2008-10-17 10:43:00 —-D—- C:\WINDOWS\system32\wbem
2008-10-17 10:42:28 —-D—- C:\WINDOWS\security
2008-10-17 10:42:07 —-D—- C:\WINDOWS\system32\CatRoot
2008-10-17 10:39:05 —-D—- C:\WINDOWS\WinSxS
2008-10-17 10:38:59 —-D—- C:\WINDOWS\network diagnostic
2008-10-17 10:38:59 —-D—- C:\WINDOWS\ime
2008-10-17 10:38:51 —-D—- C:\WINDOWS\system32\usmt
2008-10-17 10:38:51 —-D—- C:\WINDOWS\system32\en-US
2008-10-17 10:38:49 —-D—- C:\WINDOWS\PeerNet
2008-10-17 10:38:49 —-D—- C:\Program Files\Movie Maker
2008-10-17 10:37:26 —-D—- C:\WINDOWS\system32\Restore
2008-10-17 10:37:26 —-D—- C:\WINDOWS\system32\npp
2008-10-17 10:37:25 —-D—- C:\WINDOWS\msagent
2008-10-17 10:37:24 —-D—- C:\WINDOWS\srchasst
2008-10-17 10:37:24 —-D—- C:\Program Files\NetMeeting
2008-10-17 10:37:23 —-D—- C:\WINDOWS\system32\Com
2008-10-17 10:37:21 —-D—- C:\Program Files\Windows NT
2008-10-17 10:37:21 —-D—- C:\Program Files\Windows Media Player
2008-10-17 10:37:21 —-D—- C:\Program Files\Outlook Express
2008-10-17 10:37:18 —-D—- C:\Program Files\Common Files\System
2008-10-17 10:37:05 —-D—- C:\WINDOWS\system32\oobe
2008-10-17 10:37:04 —-D—- C:\WINDOWS\system
2008-10-15 12:34:24 —-A—- C:\WINDOWS\system32\netapi32.dll
2008-10-14 19:45:15 —-D—- C:\Program Files\Internet Explorer
2008-10-07 12:19:42 —-A—- C:\WINDOWS\system32\MRT.exe
2008-10-03 13:41:15 —-A—- C:\WINDOWS\system32\ieframe.dll
2008-09-29 18:06:06 —-D—- C:\Program Files\Verizon
2008-09-29 02:58:06 —-HD—- C:\Program Files\InstallShield Installation Information
2008-09-29 02:57:39 —-D—- C:\WINDOWS\twain_32
2008-09-28 18:06:38 —-D—- C:\Documents and Settings\All Users\Application Data\Motive

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AmdK8;AMD Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-07-02 36864]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-04 12032]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2004-08-03 11868]
R2 tifsfilter;Acronis True Image FS Filter; C:\WINDOWS\system32\DRIVERS\tifsfilt.sys [2008-01-12 39264]
R3 FET5X86V;VIA Rhine-Family Fast-Ethernet Adapter Driver Service; C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [2007-04-16 42496]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HSF_DP;HSF_DP; C:\WINDOWS\system32\DRIVERS\HSFDPSP2.sys [2004-08-03 1041536]
R3 HSFHWBS2;HSFHWBS2; C:\WINDOWS\system32\DRIVERS\HSFBS2S2.sys [2004-08-03 220032]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-08-10 4603904]
R3 S3GIGP;S3GIGP; C:\WINDOWS\system32\DRIVERS\S3gIGPm.sys [2006-11-09 634880]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSFCXTS2.sys [2004-08-03 685056]
S1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
S1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
S1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys []
S3 ADSFilter;ADSFilter - (Aluria Filter Driver); C:\WINDOWS\system32\DRIVERS\ADSFilter.sys []
S3 BFAIFILT;BFAIFILT; C:\WINDOWS\System32\Drivers\bfaifilt.sys [2004-07-13 3264]
S3 BW2NDIS5;BW2NDIS5; C:\WINDOWS\System32\Drivers\BW2NDIS5.sys []
S3 dot4;MS IEEE-1284.4 Driver; C:\WINDOWS\system32\DRIVERS\Dot4.sys [2008-04-13 206976]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\WINDOWS\system32\DRIVERS\Dot4Prt.sys [2001-08-17 12928]
S3 Dot4Scan;Scan Class Driver for IEEE-1284.4; C:\WINDOWS\system32\DRIVERS\Dot4Scan.sys [2001-08-17 8704]
S3 dot4usb;Dot4USB Filter Dot4USB Filter; C:\WINDOWS\system32\DRIVERS\dot4usb.sys [2001-08-17 23808]
S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\fetnd5.sys [2001-08-17 27165]
S3 GMSIPCI;GMSIPCI; \??\D:\INSTALL\GMSIPCI.SYS []
S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 MREMPR5;MREMPR5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS []
S3 MRENDIS5;MRENDIS5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS []
S3 MRV6X32P;Vista 32-bits Native WiFi Driver; C:\WINDOWS\system32\DRIVERS\MRVW13B.sys [2006-11-02 253952]
S3 SASENUM;SASENUM; \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS []
S3 U2KG54;BUFFALO WLI-U2-KG54 Wireless LAN Adapter Service; C:\WINDOWS\system32\DRIVERS\U2KG54.sys [2005-10-17 245376]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 W8335XP;802.11g/b Driver for Windows XP (8335); C:\WINDOWS\system32\DRIVERS\Mrvw125.sys [2005-12-29 282624]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AcrSch2Svc;Acronis Scheduler2 Service; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe [2006-10-16 230944]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2008-10-25 152984]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-04-13 792112]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
S4 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-05-08 271920]

—————–EOF—————–

Logfile of random's system information tool 1.04 (written by random/random)
Run by [removed] at 2008-10-25 01:44:13
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 67 GB (87%) free of 76 GB
Total RAM: 894 MB (64% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:44:28 AM, on 10/25/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\S3trayp.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Verizon\McciTrayApp.exe
C:\Program Files\Verizon\VSP\VerizonServicepoint.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\DV Series\Console\Watch.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\YWJJX5QM\RSIT[1].exe
C:\Program Files\trend micro\User.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.netzero.net/s/search?r=minisearch
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-8CB0-AB60BB9AAE22} - C:\PROGRA~1\VOL_TO~1\VOL_TO~1.DLL (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [S3Trayp] S3trayp.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SecurDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe
O4 - HKLM\..\Run: [VerizonServicepoint.exe] "C:\Program Files\Verizon\VSP\VerizonServicepoint.exe" /AUTORUN
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Watch.lnk = C:\Program Files\DV Series\Console\Watch.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon…20Installer.cab
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe

–
End of file - 5753 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-12-18 59032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4E7BD74F-2B8D-469E-8CB0-AB60BB9AAE22}]
Verizon Broadband Toolbar - C:\PROGRA~1\VOL_TO~1\VOL_TO~1.DLL []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre6\bin\ssv.dll [2008-10-25 320920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-10-25 34816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2008-10-25 73728]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"=C:\WINDOWS\system32\VTTimer.exe [2006-09-21 53248]
"S3Trayp"=C:\WINDOWS\system32\S3trayp.exe [2006-10-09 176128]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2007-08-10 16384000]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-01 153136]
"SecurDisc"=C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe [2007-05-15 1628208]
"InCD"=C:\Program Files\Nero\Nero 7\InCD\InCD.exe [2007-05-15 1057328]
"TrueImageMonitor.exe"=C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe [2006-10-16 1164912]
"AcronisTimounterMonitor"=C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe [2006-10-16 1941784]
"Acronis Scheduler2 Service"=C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe [2006-10-16 87584]
"Verizon_McciTrayApp"=C:\Program Files\Verizon\McciTrayApp.exe [2007-09-28 936960]
"VerizonServicepoint.exe"=C:\Program Files\Verizon\VSP\VerizonServicepoint.exe [2008-02-13 2065648]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2008-10-25 136600]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-13 1695232]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE
Microsoft Works Calendar Reminders.lnk - C:\WINDOWS\Installer\{0CD3BB5C-BBCA-11D2-8C20-00C04FBBCFF9}\A94AAB13.exe
Watch.lnk - C:\Program Files\DV Series\Console\Watch.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
relog_ap

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Grisoft\AVG7\avginet.exe"="C:\Program Files\Grisoft\AVG7\avginet.exe:*:Enabled:avginet.exe"
"C:\Program Files\Grisoft\AVG7\avgamsvr.exe"="C:\Program Files\Grisoft\AVG7\avgamsvr.exe:*:Enabled:avgamsvr.exe"
"C:\Program Files\Grisoft\AVG7\avgcc.exe"="C:\Program Files\Grisoft\AVG7\avgcc.exe:*:Enabled:avgcc.exe"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2c203ae0-c126-11dc-9e32-001d92410860}]
shell\AutoRun\command - E:\lzext.exe


======List of files/folders created in the last 1 months======

2008-10-25 01:44:13 —-D—- C:\rsit
2008-10-25 01:44:13 —-D—- C:\Program Files\trend micro
2008-10-25 01:08:44 —-A—- C:\WINDOWS\system32\javaws.exe
2008-10-25 01:08:44 —-A—- C:\WINDOWS\system32\javaw.exe
2008-10-25 01:08:44 —-A—- C:\WINDOWS\system32\java.exe
2008-10-25 01:08:44 —-A—- C:\WINDOWS\system32\deploytk.dll
2008-10-24 23:14:42 —-D—- C:\Documents and Settings\User\Application Data\Malwarebytes
2008-10-24 23:14:37 —-D—- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-24 23:14:37 —-D—- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-24 10:09:56 —-HDC—- C:\WINDOWS\$NtUninstallKB958644$
2008-10-24 07:28:00 —-A—- C:\WINDOWS\system32\CF11254.exe
2008-10-24 07:27:09 —-A—- C:\WINDOWS\system32\CF11087.exe
2008-10-24 07:25:36 —-A—- C:\WINDOWS\system32\CF10781.exe
2008-10-24 07:25:35 —-A—- C:\Bug.txt
2008-10-24 07:19:55 —-D—- C:\Documents and Settings\All Users\Application Data\Avg8
2008-10-23 22:19:40 —-D—- C:\Program Files\Hijackthis
2008-10-23 20:05:03 —-D—- C:\Program Files\AVG
2008-10-20 12:45:28 —-A—- C:\WINDOWS\system32\kbdkor.dll
2008-10-20 12:45:28 —-A—- C:\WINDOWS\system32\kbdjpn.dll
2008-10-20 12:45:28 —-A—- C:\WINDOWS\system32\kbd103.dll
2008-10-20 12:45:28 —-A—- C:\WINDOWS\system32\kbd101c.dll
2008-10-20 12:45:26 —-A—- C:\WINDOWS\system32\kbd101b.dll
2008-10-20 12:45:25 —-A—- C:\WINDOWS\system32\kbd106.dll
2008-10-18 03:00:29 —-HDC—- C:\WINDOWS\$NtUninstallKB951978$
2008-10-17 10:43:28 —-D—- C:\WINDOWS\Prefetch
2008-10-17 10:42:06 —-HDC—- C:\WINDOWS\$NtUninstallKB957095$
2008-10-17 10:42:01 —-HDC—- C:\WINDOWS\$NtUninstallKB956841$
2008-10-17 10:41:56 —-HDC—- C:\WINDOWS\$NtUninstallKB956803$
2008-10-17 10:41:51 —-HDC—- C:\WINDOWS\$NtUninstallKB954211$
2008-10-17 10:41:46 —-HDC—- C:\WINDOWS\$NtUninstallKB952954$
2008-10-17 10:41:42 —-HDC—- C:\WINDOWS\$NtUninstallKB952287$
2008-10-17 10:41:38 —-HDC—- C:\WINDOWS\$NtUninstallKB951748$
2008-10-17 10:41:34 —-HDC—- C:\WINDOWS\$NtUninstallKB951698$
2008-10-17 10:41:30 —-HDC—- C:\WINDOWS\$NtUninstallKB951376-v2$
2008-10-17 10:41:24 —-HDC—- C:\WINDOWS\$NtUninstallKB951066$
2008-10-17 10:41:20 —-HDC—- C:\WINDOWS\$NtUninstallKB950974$
2008-10-17 10:41:16 —-HDC—- C:\WINDOWS\$NtUninstallKB950762$
2008-10-17 10:41:11 —-HDC—- C:\WINDOWS\$NtUninstallKB946648$
2008-10-17 10:41:08 —-HDC—- C:\WINDOWS\$NtUninstallKB938464$
2008-10-17 10:38:50 —-D—- C:\WINDOWS\system32\scripting
2008-10-17 10:38:50 —-D—- C:\WINDOWS\system32\en
2008-10-17 10:38:50 —-D—- C:\WINDOWS\l2schemas
2008-10-17 10:38:49 —-D—- C:\WINDOWS\system32\bits
2008-10-17 10:37:29 —-D—- C:\WINDOWS\ServicePackFiles
2008-10-17 10:33:10 —-HDC—- C:\WINDOWS\$NtServicePackUninstall$
2008-10-17 10:33:09 —-D—- C:\WINDOWS\EHome
2008-10-14 19:45:31 —-HDC—- C:\WINDOWS\$NtUninstallKB956803_0$
2008-10-14 19:45:27 —-HDC—- C:\WINDOWS\$NtUninstallKB956391$
2008-10-14 19:45:23 —-HDC—- C:\WINDOWS\$NtUninstallKB957095_0$
2008-10-14 19:45:01 —-HDC—- C:\WINDOWS\$NtUninstallKB954211_0$
2008-10-14 19:44:52 —-HDC—- C:\WINDOWS\$NtUninstallKB956841_0$
2008-09-29 03:01:32 —-D—- C:\Documents and Settings\User\Application Data\ArcSoft
2008-09-29 02:58:07 —-A—- C:\WINDOWS\PB_setup.ini
2008-09-29 02:57:05 —-D—- C:\Program Files\ArcSoft
2008-09-29 02:57:05 —-A—- C:\WINDOWS\PI_setup.ini
2008-09-29 02:57:05 —-A—- C:\WINDOWS\pcdlib32.dll
2008-09-29 02:32:22 —-A—- C:\WINDOWS\Active Setup Log.txt
2008-09-29 02:16:36 —-D—- C:\Documents and Settings\User\Application Data\Help
2008-09-29 02:09:56 —-A—- C:\WINDOWS\Ulead32.ini
2008-09-29 02:09:54 —-D—- C:\Program Files\Ulead Systems
2008-09-29 02:08:18 —-A—- C:\WINDOWS\system32\MKCoInstaller.dll
2008-09-29 02:06:47 —-D—- C:\Program Files\DV Series
2008-09-28 18:18:10 —-D—- C:\Documents and Settings\User\Application Data\Motive

======List of files/folders modified in the last 1 months======

2008-10-25 01:44:13 —-RD—- C:\Program Files
2008-10-25 01:23:10 —-SHD—- C:\WINDOWS\Installer
2008-10-25 01:22:27 —-D—- C:\Program Files\Java
2008-10-25 01:22:26 —-D—- C:\Program Files\Common Files
2008-10-25 01:22:18 —-D—- C:\WINDOWS\system32
2008-10-25 01:17:31 —-D—- C:\WINDOWS\Temp
2008-10-25 01:16:54 —-A—- C:\WINDOWS\SchedLgU.Txt
2008-10-25 01:05:40 —-SD—- C:\WINDOWS\Downloaded Program Files
2008-10-24 23:14:40 —-D—- C:\WINDOWS\system32\drivers
2008-10-24 11:57:18 —-D—- C:\WINDOWS
2008-10-24 10:10:00 —-HD—- C:\WINDOWS\inf
2008-10-24 10:09:58 —-RSHDC—- C:\WINDOWS\system32\dllcache
2008-10-24 10:09:35 —-HD—- C:\WINDOWS\$hf_mig$
2008-10-24 10:09:34 —-D—- C:\WINDOWS\system32\CatRoot2
2008-10-24 07:19:07 —-SD—- C:\Documents and Settings\User\Application Data\Microsoft
2008-10-24 07:18:23 —-D—- C:\Documents and Settings\User\Application Data\SUPERAntiSpyware.com
2008-10-24 07:18:19 —-D—- C:\Program Files\SUPERAntiSpyware
2008-10-24 07:17:59 —-D—- C:\Program Files\SpywareBlaster
2008-10-23 20:09:57 —-D—- C:\Program Files\vol_toolbar
2008-10-20 12:45:35 —-D—- C:\WINDOWS\Help
2008-10-20 12:45:31 —-RSD—- C:\WINDOWS\Fonts
2008-10-20 03:10:00 —-A—- C:\WINDOWS\win.ini
2008-10-18 03:00:33 —-A—- C:\WINDOWS\imsins.BAK
2008-10-17 10:45:01 —-A—- C:\WINDOWS\system32\PerfStringBackup.INI
2008-10-17 10:43:51 —-A—- C:\WINDOWS\OEWABLog.txt
2008-10-17 10:43:31 —-A—- C:\WINDOWS\setuplog.txt
2008-10-17 10:43:01 —-D—- C:\WINDOWS\system32\Setup
2008-10-17 10:43:01 —-D—- C:\WINDOWS\AppPatch
2008-10-17 10:43:01 —-D—- C:\Program Files\Messenger
2008-10-17 10:43:00 —-D—- C:\WINDOWS\system32\wbem
2008-10-17 10:42:28 —-D—- C:\WINDOWS\security
2008-10-17 10:42:07 —-D—- C:\WINDOWS\system32\CatRoot
2008-10-17 10:39:05 —-D—- C:\WINDOWS\WinSxS
2008-10-17 10:38:59 —-D—- C:\WINDOWS\network diagnostic
2008-10-17 10:38:59 —-D—- C:\WINDOWS\ime
2008-10-17 10:38:51 —-D—- C:\WINDOWS\system32\usmt
2008-10-17 10:38:51 —-D—- C:\WINDOWS\system32\en-US
2008-10-17 10:38:49 —-D—- C:\WINDOWS\PeerNet
2008-10-17 10:38:49 —-D—- C:\Program Files\Movie Maker
2008-10-17 10:37:26 —-D—- C:\WINDOWS\system32\Restore
2008-10-17 10:37:26 —-D—- C:\WINDOWS\system32\npp
2008-10-17 10:37:25 —-D—- C:\WINDOWS\msagent
2008-10-17 10:37:24 —-D—- C:\WINDOWS\srchasst
2008-10-17 10:37:24 —-D—- C:\Program Files\NetMeeting
2008-10-17 10:37:23 —-D—- C:\WINDOWS\system32\Com
2008-10-17 10:37:21 —-D—- C:\Program Files\Windows NT
2008-10-17 10:37:21 —-D—- C:\Program Files\Windows Media Player
2008-10-17 10:37:21 —-D—- C:\Program Files\Outlook Express
2008-10-17 10:37:18 —-D—- C:\Program Files\Common Files\System
2008-10-17 10:37:05 —-D—- C:\WINDOWS\system32\oobe
2008-10-17 10:37:04 —-D—- C:\WINDOWS\system
2008-10-15 12:34:24 —-A—- C:\WINDOWS\system32\netapi32.dll
2008-10-14 19:45:15 —-D—- C:\Program Files\Internet Explorer
2008-10-07 12:19:42 —-A—- C:\WINDOWS\system32\MRT.exe
2008-10-03 13:41:15 —-A—- C:\WINDOWS\system32\ieframe.dll
2008-09-29 18:06:06 —-D—- C:\Program Files\Verizon
2008-09-29 02:58:06 —-HD—- C:\Program Files\InstallShield Installation Information
2008-09-29 02:57:39 —-D—- C:\WINDOWS\twain_32
2008-09-28 18:06:38 —-D—- C:\Documents and Settings\All Users\Application Data\Motive

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AmdK8;AMD Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-07-02 36864]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-04 12032]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2004-08-03 11868]
R2 tifsfilter;Acronis True Image FS Filter; C:\WINDOWS\system32\DRIVERS\tifsfilt.sys [2008-01-12 39264]
R3 FET5X86V;VIA Rhine-Family Fast-Ethernet Adapter Driver Service; C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [2007-04-16 42496]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HSF_DP;HSF_DP; C:\WINDOWS\system32\DRIVERS\HSFDPSP2.sys [2004-08-03 1041536]
R3 HSFHWBS2;HSFHWBS2; C:\WINDOWS\system32\DRIVERS\HSFBS2S2.sys [2004-08-03 220032]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-08-10 4603904]
R3 S3GIGP;S3GIGP; C:\WINDOWS\system32\DRIVERS\S3gIGPm.sys [2006-11-09 634880]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSFCXTS2.sys [2004-08-03 685056]
S1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
S1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
S1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys []
S3 ADSFilter;ADSFilter - (Aluria Filter Driver); C:\WINDOWS\system32\DRIVERS\ADSFilter.sys []
S3 BFAIFILT;BFAIFILT; C:\WINDOWS\System32\Drivers\bfaifilt.sys [2004-07-13 3264]
S3 BW2NDIS5;BW2NDIS5; C:\WINDOWS\System32\Drivers\BW2NDIS5.sys []
S3 dot4;MS IEEE-1284.4 Driver; C:\WINDOWS\system32\DRIVERS\Dot4.sys [2008-04-13 206976]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\WINDOWS\system32\DRIVERS\Dot4Prt.sys [2001-08-17 12928]
S3 Dot4Scan;Scan Class Driver for IEEE-1284.4; C:\WINDOWS\system32\DRIVERS\Dot4Scan.sys [2001-08-17 8704]
S3 dot4usb;Dot4USB Filter Dot4USB Filter; C:\WINDOWS\system32\DRIVERS\dot4usb.sys [2001-08-17 23808]
S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\fetnd5.sys [2001-08-17 27165]
S3 GMSIPCI;GMSIPCI; \??\D:\INSTALL\GMSIPCI.SYS []
S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 MREMPR5;MREMPR5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS []
S3 MRENDIS5;MRENDIS5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS []
S3 MRV6X32P;Vista 32-bits Native WiFi Driver; C:\WINDOWS\system32\DRIVERS\MRVW13B.sys [2006-11-02 253952]
S3 SASENUM;SASENUM; \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS []
S3 U2KG54;BUFFALO WLI-U2-KG54 Wireless LAN Adapter Service; C:\WINDOWS\system32\DRIVERS\U2KG54.sys [2005-10-17 245376]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 W8335XP;802.11g/b Driver for Windows XP (8335); C:\WINDOWS\system32\DRIVERS\Mrvw125.sys [2005-12-29 282624]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AcrSch2Svc;Acronis Scheduler2 Service; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe [2006-10-16 230944]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2008-10-25 152984]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-04-13 792112]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
S4 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-05-08 271920]

—————–EOF—————–


Logfile of random's system information tool 1.04 (written by random/random)
Run by [removed] at 2008-10-25 01:44:13
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 67 GB (87%) free of 76 GB
Total RAM: 894 MB (64% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:44:28 AM, on 10/25/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\S3trayp.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Verizon\McciTrayApp.exe
C:\Program Files\Verizon\VSP\VerizonServicepoint.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\DV Series\Console\Watch.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\YWJJX5QM\RSIT[1].exe
C:\Program Files\trend micro\User.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.netzero.net/s/search?r=minisearch
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-8CB0-AB60BB9AAE22} - C:\PROGRA~1\VOL_TO~1\VOL_TO~1.DLL (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [S3Trayp] S3trayp.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SecurDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe
O4 - HKLM\..\Run: [VerizonServicepoint.exe] "C:\Program Files\Verizon\VSP\VerizonServicepoint.exe" /AUTORUN
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Watch.lnk = C:\Program Files\DV Series\Console\Watch.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon…20Installer.cab
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe

–
End of file - 5753 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-12-18 59032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4E7BD74F-2B8D-469E-8CB0-AB60BB9AAE22}]
Verizon Broadband Toolbar - C:\PROGRA~1\VOL_TO~1\VOL_TO~1.DLL []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre6\bin\ssv.dll [2008-10-25 320920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-10-25 34816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2008-10-25 73728]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"=C:\WINDOWS\system32\VTTimer.exe [2006-09-21 53248]
"S3Trayp"=C:\WINDOWS\system32\S3trayp.exe [2006-10-09 176128]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2007-08-10 16384000]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-01 153136]
"SecurDisc"=C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe [2007-05-15 1628208]
"InCD"=C:\Program Files\Nero\Nero 7\InCD\InCD.exe [2007-05-15 1057328]
"TrueImageMonitor.exe"=C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe [2006-10-16 1164912]
"AcronisTimounterMonitor"=C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe [2006-10-16 1941784]
"Acronis Scheduler2 Service"=C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe [2006-10-16 87584]
"Verizon_McciTrayApp"=C:\Program Files\Verizon\McciTrayApp.exe [2007-09-28 936960]
"VerizonServicepoint.exe"=C:\Program Files\Verizon\VSP\VerizonServicepoint.exe [2008-02-13 2065648]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2008-10-25 136600]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-13 1695232]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE
Microsoft Works Calendar Reminders.lnk - C:\WINDOWS\Installer\{0CD3BB5C-BBCA-11D2-8C20-00C04FBBCFF9}\A94AAB13.exe
Watch.lnk - C:\Program Files\DV Series\Console\Watch.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
relog_ap

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Grisoft\AVG7\avginet.exe"="C:\Program Files\Grisoft\AVG7\avginet.exe:*:Enabled:avginet.exe"
"C:\Program Files\Grisoft\AVG7\avgamsvr.exe"="C:\Program Files\Grisoft\AVG7\avgamsvr.exe:*:Enabled:avgamsvr.exe"
"C:\Program Files\Grisoft\AVG7\avgcc.exe"="C:\Program Files\Grisoft\AVG7\avgcc.exe:*:Enabled:avgcc.exe"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2c203ae0-c126-11dc-9e32-001d92410860}]
shell\AutoRun\command - E:\lzext.exe


======List of files/folders created in the last 1 months======

2008-10-25 01:44:13 —-D—- C:\rsit
2008-10-25 01:44:13 —-D—- C:\Program Files\trend micro
2008-10-25 01:08:44 —-A—- C:\WINDOWS\system32\javaws.exe
2008-10-25 01:08:44 —-A—- C:\WINDOWS\system32\javaw.exe
2008-10-25 01:08:44 —-A—- C:\WINDOWS\system32\java.exe
2008-10-25 01:08:44 —-A—- C:\WINDOWS\system32\deploytk.dll
2008-10-24 23:14:42 —-D—- C:\Documents and Settings\User\Application Data\Malwarebytes
2008-10-24 23:14:37 —-D—- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-24 23:14:37 —-D—- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-24 10:09:56 —-HDC—- C:\WINDOWS\$NtUninstallKB958644$
2008-10-24 07:28:00 —-A—- C:\WINDOWS\system32\CF11254.exe
2008-10-24 07:27:09 —-A—- C:\WINDOWS\system32\CF11087.exe
2008-10-24 07:25:36 —-A—- C:\WINDOWS\system32\CF10781.exe
2008-10-24 07:25:35 —-A—- C:\Bug.txt
2008-10-24 07:19:55 —-D—- C:\Documents and Settings\All Users\Application Data\Avg8
2008-10-23 22:19:40 —-D—- C:\Program Files\Hijackthis
2008-10-23 20:05:03 —-D—- C:\Program Files\AVG
2008-10-20 12:45:28 —-A—- C:\WINDOWS\system32\kbdkor.dll
2008-10-20 12:45:28 —-A—- C:\WINDOWS\system32\kbdjpn.dll
2008-10-20 12:45:28 —-A—- C:\WINDOWS\system32\kbd103.dll
2008-10-20 12:45:28 —-A—- C:\WINDOWS\system32\kbd101c.dll
2008-10-20 12:45:26 —-A—- C:\WINDOWS\system32\kbd101b.dll
2008-10-20 12:45:25 —-A—- C:\WINDOWS\system32\kbd106.dll
2008-10-18 03:00:29 —-HDC—- C:\WINDOWS\$NtUninstallKB951978$
2008-10-17 10:43:28 —-D—- C:\WINDOWS\Prefetch
2008-10-17 10:42:06 —-HDC—- C:\WINDOWS\$NtUninstallKB957095$
2008-10-17 10:42:01 —-HDC—- C:\WINDOWS\$NtUninstallKB956841$
2008-10-17 10:41:56 —-HDC—- C:\WINDOWS\$NtUninstallKB956803$
2008-10-17 10:41:51 —-HDC—- C:\WINDOWS\$NtUninstallKB954211$
2008-10-17 10:41:46 —-HDC—- C:\WINDOWS\$NtUninstallKB952954$
2008-10-17 10:41:42 —-HDC—- C:\WINDOWS\$NtUninstallKB952287$
2008-10-17 10:41:38 —-HDC—- C:\WINDOWS\$NtUninstallKB951748$
2008-10-17 10:41:34 —-HDC—- C:\WINDOWS\$NtUninstallKB951698$
2008-10-17 10:41:30 —-HDC—- C:\WINDOWS\$NtUninstallKB951376-v2$
2008-10-17 10:41:24 —-HDC—- C:\WINDOWS\$NtUninstallKB951066$
2008-10-17 10:41:20 —-HDC—- C:\WINDOWS\$NtUninstallKB950974$
2008-10-17 10:41:16 —-HDC—- C:\WINDOWS\$NtUninstallKB950762$
2008-10-17 10:41:11 —-HDC—- C:\WINDOWS\$NtUninstallKB946648$
2008-10-17 10:41:08 —-HDC—- C:\WINDOWS\$NtUninstallKB938464$
2008-10-17 10:38:50 —-D—- C:\WINDOWS\system32\scripting
2008-10-17 10:38:50 —-D—- C:\WINDOWS\system32\en
2008-10-17 10:38:50 —-D—- C:\WINDOWS\l2schemas
2008-10-17 10:38:49 —-D—- C:\WINDOWS\system32\bits
2008-10-17 10:37:29 —-D—- C:\WINDOWS\ServicePackFiles
2008-10-17 10:33:10 —-HDC—- C:\WINDOWS\$NtServicePackUninstall$
2008-10-17 10:33:09 —-D—- C:\WINDOWS\EHome
2008-10-14 19:45:31 —-HDC—- C:\WINDOWS\$NtUninstallKB956803_0$
2008-10-14 19:45:27 —-HDC—- C:\WINDOWS\$NtUninstallKB956391$
2008-10-14 19:45:23 —-HDC—- C:\WINDOWS\$NtUninstallKB957095_0$
2008-10-14 19:45:01 —-HDC—- C:\WINDOWS\$NtUninstallKB954211_0$
2008-10-14 19:44:52 —-HDC—- C:\WINDOWS\$NtUninstallKB956841_0$
2008-09-29 03:01:32 —-D—- C:\Documents and Settings\User\Application Data\ArcSoft
2008-09-29 02:58:07 —-A—- C:\WINDOWS\PB_setup.ini
2008-09-29 02:57:05 —-D—- C:\Program Files\ArcSoft
2008-09-29 02:57:05 —-A—- C:\WINDOWS\PI_setup.ini
2008-09-29 02:57:05 —-A—- C:\WINDOWS\pcdlib32.dll
2008-09-29 02:32:22 —-A—- C:\WINDOWS\Active Setup Log.txt
2008-09-29 02:16:36 —-D—- C:\Documents and Settings\User\Application Data\Help
2008-09-29 02:09:56 —-A—- C:\WINDOWS\Ulead32.ini
2008-09-29 02:09:54 —-D—- C:\Program Files\Ulead Systems
2008-09-29 02:08:18 —-A—- C:\WINDOWS\system32\MKCoInstaller.dll
2008-09-29 02:06:47 —-D—- C:\Program Files\DV Series
2008-09-28 18:18:10 —-D—- C:\Documents and Settings\User\Application Data\Motive

======List of files/folders modified in the last 1 months======

2008-10-25 01:44:13 —-RD—- C:\Program Files
2008-10-25 01:23:10 —-SHD—- C:\WINDOWS\Installer
2008-10-25 01:22:27 —-D—- C:\Program Files\Java
2008-10-25 01:22:26 —-D—- C:\Program Files\Common Files
2008-10-25 01:22:18 —-D—- C:\WINDOWS\system32
2008-10-25 01:17:31 —-D—- C:\WINDOWS\Temp
2008-10-25 01:16:54 —-A—- C:\WINDOWS\SchedLgU.Txt
2008-10-25 01:05:40 —-SD—- C:\WINDOWS\Downloaded Program Files
2008-10-24 23:14:40 —-D—- C:\WINDOWS\system32\drivers
2008-10-24 11:57:18 —-D—- C:\WINDOWS
2008-10-24 10:10:00 —-HD—- C:\WINDOWS\inf
2008-10-24 10:09:58 —-RSHDC—- C:\WINDOWS\system32\dllcache
2008-10-24 10:09:35 —-HD—- C:\WINDOWS\$hf_mig$
2008-10-24 10:09:34 —-D—- C:\WINDOWS\system32\CatRoot2
2008-10-24 07:19:07 —-SD—- C:\Documents and Settings\User\Application Data\Microsoft
2008-10-24 07:18:23 —-D—- C:\Documents and Settings\User\Application Data\SUPERAntiSpyware.com
2008-10-24 07:18:19 —-D—- C:\Program Files\SUPERAntiSpyware
2008-10-24 07:17:59 —-D—- C:\Program Files\SpywareBlaster
2008-10-23 20:09:57 —-D—- C:\Program Files\vol_toolbar
2008-10-20 12:45:35 —-D—- C:\WINDOWS\Help
2008-10-20 12:45:31 —-RSD—- C:\WINDOWS\Fonts
2008-10-20 03:10:00 —-A—- C:\WINDOWS\win.ini
2008-10-18 03:00:33 —-A—- C:\WINDOWS\imsins.BAK
2008-10-17 10:45:01 —-A—- C:\WINDOWS\system32\PerfStringBackup.INI
2008-10-17 10:43:51 —-A—- C:\WINDOWS\OEWABLog.txt
2008-10-17 10:43:31 —-A—- C:\WINDOWS\setuplog.txt
2008-10-17 10:43:01 —-D—- C:\WINDOWS\system32\Setup
2008-10-17 10:43:01 —-D—- C:\WINDOWS\AppPatch
2008-10-17 10:43:01 —-D—- C:\Program Files\Messenger
2008-10-17 10:43:00 —-D—- C:\WINDOWS\system32\wbem
2008-10-17 10:42:28 —-D—- C:\WINDOWS\security
2008-10-17 10:42:07 —-D—- C:\WINDOWS\system32\CatRoot
2008-10-17 10:39:05 —-D—- C:\WINDOWS\WinSxS
2008-10-17 10:38:59 —-D—- C:\WINDOWS\network diagnostic
2008-10-17 10:38:59 —-D—- C:\WINDOWS\ime
2008-10-17 10:38:51 —-D—- C:\WINDOWS\system32\usmt
2008-10-17 10:38:51 —-D—- C:\WINDOWS\system32\en-US
2008-10-17 10:38:49 —-D—- C:\WINDOWS\PeerNet
2008-10-17 10:38:49 —-D—- C:\Program Files\Movie Maker
2008-10-17 10:37:26 —-D—- C:\WINDOWS\system32\Restore
2008-10-17 10:37:26 —-D—- C:\WINDOWS\system32\npp
2008-10-17 10:37:25 —-D—- C:\WINDOWS\msagent
2008-10-17 10:37:24 —-D—- C:\WINDOWS\srchasst
2008-10-17 10:37:24 —-D—- C:\Program Files\NetMeeting
2008-10-17 10:37:23 —-D—- C:\WINDOWS\system32\Com
2008-10-17 10:37:21 —-D—- C:\Program Files\Windows NT
2008-10-17 10:37:21 —-D—- C:\Program Files\Windows Media Player
2008-10-17 10:37:21 —-D—- C:\Program Files\Outlook Express
2008-10-17 10:37:18 —-D—- C:\Program Files\Common Files\System
2008-10-17 10:37:05 —-D—- C:\WINDOWS\system32\oobe
2008-10-17 10:37:04 —-D—- C:\WINDOWS\system
2008-10-15 12:34:24 —-A—- C:\WINDOWS\system32\netapi32.dll
2008-10-14 19:45:15 —-D—- C:\Program Files\Internet Explorer
2008-10-07 12:19:42 —-A—- C:\WINDOWS\system32\MRT.exe
2008-10-03 13:41:15 —-A—- C:\WINDOWS\system32\ieframe.dll
2008-09-29 18:06:06 —-D—- C:\Program Files\Verizon
2008-09-29 02:58:06 —-HD—- C:\Program Files\InstallShield Installation Information
2008-09-29 02:57:39 —-D—- C:\WINDOWS\twain_32
2008-09-28 18:06:38 —-D—- C:\Documents and Settings\All Users\Application Data\Motive

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AmdK8;AMD Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-07-02 36864]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-04 12032]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2004-08-03 11868]
R2 tifsfilter;Acronis True Image FS Filter; C:\WINDOWS\system32\DRIVERS\tifsfilt.sys [2008-01-12 39264]
R3 FET5X86V;VIA Rhine-Family Fast-Ethernet Adapter Driver Service; C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [2007-04-16 42496]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HSF_DP;HSF_DP; C:\WINDOWS\system32\DRIVERS\HSFDPSP2.sys [2004-08-03 1041536]
R3 HSFHWBS2;HSFHWBS2; C:\WINDOWS\system32\DRIVERS\HSFBS2S2.sys [2004-08-03 220032]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-08-10 4603904]
R3 S3GIGP;S3GIGP; C:\WINDOWS\system32\DRIVERS\S3gIGPm.sys [2006-11-09 634880]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSFCXTS2.sys [2004-08-03 685056]
S1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
S1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
S1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys []
S3 ADSFilter;ADSFilter - (Aluria Filter Driver); C:\WINDOWS\system32\DRIVERS\ADSFilter.sys []
S3 BFAIFILT;BFAIFILT; C:\WINDOWS\System32\Drivers\bfaifilt.sys [2004-07-13 3264]
S3 BW2NDIS5;BW2NDIS5; C:\WINDOWS\System32\Drivers\BW2NDIS5.sys []
S3 dot4;MS IEEE-1284.4 Driver; C:\WINDOWS\system32\DRIVERS\Dot4.sys [2008-04-13 206976]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\WINDOWS\system32\DRIVERS\Dot4Prt.sys [2001-08-17 12928]
S3 Dot4Scan;Scan Class Driver for IEEE-1284.4; C:\WINDOWS\system32\DRIVERS\Dot4Scan.sys [2001-08-17 8704]
S3 dot4usb;Dot4USB Filter Dot4USB Filter; C:\WINDOWS\system32\DRIVERS\dot4usb.sys [2001-08-17 23808]
S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\fetnd5.sys [2001-08-17 27165]
S3 GMSIPCI;GMSIPCI; \??\D:\INSTALL\GMSIPCI.SYS []
S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 MREMPR5;MREMPR5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS []
S3 MRENDIS5;MRENDIS5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS []
S3 MRV6X32P;Vista 32-bits Native WiFi Driver; C:\WINDOWS\system32\DRIVERS\MRVW13B.sys [2006-11-02 253952]
S3 SASENUM;SASENUM; \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS []
S3 U2KG54;BUFFALO WLI-U2-KG54 Wireless LAN Adapter Service; C:\WINDOWS\system32\DRIVERS\U2KG54.sys [2005-10-17 245376]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 W8335XP;802.11g/b Driver for Windows XP (8335); C:\WINDOWS\system32\DRIVERS\Mrvw125.sys [2005-12-29 282624]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AcrSch2Svc;Acronis Scheduler2 Service; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe [2006-10-16 230944]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2008-10-25 152984]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-04-13 792112]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
S4 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-05-08 271920]

—————–EOF—————–
ok, i did that all wrong, let's try again….jeesh…i can't get it to do it….. control V is not putting the content on here…

ok, trying again.


info.txt logfile of random's system information tool 1.04 2008-10-25 01:44:30

======Uninstall list======

–>C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
–>C:\Program Files\Nero\Nero 7\\nero\uninstall\UNNERO.exe /UNINSTALL
–>C:\WINDOWS\NuNInst.exe /UNINSTALL
–>C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
–>rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Acronis True Image Home–>MsiExec.exe /X{419CF344-3D94-4DAD-99C8-EA7B00E5EA8B}
Adobe Flash Player ActiveX–>C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 7.0.9–>MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70900000002}
ArcSoft PhotoBase 3–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A5460871-42FF-45CD-A634-01C755E9CEA1}\SETUP.EXE" -l0x9 -uninst
ArcSoft PhotoImpression–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{797703D4-461B-4BC9-AACA-292917F3A47F}\SETUP.EXE" -l0x9 -uninst
Desktop Taipei version 2.2–>"C:\Program Files\Desktop Taipei\unins000.exe"
DivX Codec–>C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
DivX Content Uploader–>C:\Program Files\DivX\DivXContentUploaderUninstall.exe /CUPLOADER
DivX Converter–>C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
DivX Player–>C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
DivX Web Player–>C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
DV Series–>C:\Program Files\DV Series\uninst.exe
DVC301–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5AA4D39A-C9FE-4EC9-8DA5-57015C4260C1}\Setup.exe"
High Definition Audio Driver Package - KB888111–>"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
Hijackthis 1.99.1–>"C:\Program Files\Hijackthis\unins000.exe"
HijackThis 2.0.2–>"C:\Program Files\trend micro\HijackThis.exe" /uninstall
Hotfix for Windows Media Format 11 SDK (KB929399)–>"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Hotfix for Windows Media Player 11 (KB939683)–>"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB952287)–>"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
InterVideo WinDVD–>"C:\Program Files\InstallShield Installation Information\{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}\setup.exe" REMOVEALL
Java™ 6 Update 10–>MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216010FF}
Luxor (remove only)–>"C:\Program Files\MumboJumbo\Luxor\uninstall.exe"
Malwarebytes' Anti-Malware–>"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Microsoft .NET Framework 1.1 Hotfix (KB928366)–>"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1–>msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1–>MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft Compression Client Pack 1.0 for Windows XP–>"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Home Publishing 2000–>MsiExec.exe /I{0CD3BB5C-BBCA-11D2-8C20-00C04FBBCFF9}
Microsoft Internationalized Domain Names Mitigation APIs–>"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs–>"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office 2000 SR-1 Premium–>MsiExec.exe /I{00000409-78E1-11D2-B60F-006097C998E7}
Microsoft User-Mode Driver Framework Feature Pack 1.0–>"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable–>MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
MSXML 4.0 SP2 (KB936181)–>MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
Nero 7 Essentials–>MsiExec.exe /X{9B4E6CB9-E54D-47F7-A414-E2D5740E1033}
neroxml–>MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
Prime95–>"C:\Program Files\Prime95\Uninstall.exe" "C:\Program Files\Prime95\install.log"
Realtek High Definition Audio Driver–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x9 -removeonly
Security Update for Windows Internet Explorer 7 (KB938127)–>"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB942615)–>"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB944533)–>"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB950759)–>"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB953838)–>"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB956390)–>"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB936782)–>"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB954154)–>"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923789)–>C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
Security Update for Windows XP (KB938464)–>"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)–>"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)–>"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950760)–>"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)–>"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)–>"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)–>"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)–>"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)–>"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)–>"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)–>"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953839)–>"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954211)–>"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956391)–>"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)–>"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956841)–>"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957095)–>"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)–>"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Sound'Em 1.0–>C:\Program Files\DV Series\UNWISE.EXE C:\Program Files\DV Series\install.log
Update for Windows XP (KB951072-v2)–>"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Update for Windows XP (KB951978)–>"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Verizon Broadband Toolbar–>C:\Program Files\vol_toolbar\uninstall.exe
Verizon Online Help and Support–>C:\PROGRA~1\Verizon\UNWISE.EXE C:\PROGRA~1\Verizon\INSTALL.LOG
Verizon Servicepoint 1.5.20–>"C:\Program Files\Verizon\VSP\unins000.exe"
VIA Rhine-Family Fast-Ethernet Adapter–>Rundll32.exe vuins32.dll,vuins32Ex $Rhine $VIA
VIA/S3G Display Driver 6.14.10.0075–>C:\PROGRA~1\S3\UChromeP\s3minset.exe /u UChromeP.uns
Windows Driver Package - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0)–>C:\PROGRA~1\DIFX\7B44739871F4D539FA473F57A832EA4B6A59EF06\DPInst.exe /d /u C:\WINDOWS\system32\DRVSTORE\amdk8_C074F64CC74B03BC354BB5DC973CCF768D5A7194\amdk8.inf
Windows Media Format 11 runtime–>"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime–>"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11–>"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11–>"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows XP Service Pack 3–>"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
Zuma Deluxe 1.0–>C:\Program Files\PopCap Games\Zuma Deluxe\PopUninstall.exe "C:\Program Files\PopCap Games\Zuma Deluxe\Install.log"

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 107 Stepping 1, AuthenticAMD
"PROCESSOR_REVISION"=6b01
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP

—————–EOF—————–
info.txt logfile of random's system information tool 1.04 2008-10-25 01:44:30

======Uninstall list======

–>C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
–>C:\Program Files\Nero\Nero 7\\nero\uninstall\UNNERO.exe /UNINSTALL
–>C:\WINDOWS\NuNInst.exe /UNINSTALL
–>C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
–>rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Acronis True Image Home–>MsiExec.exe /X{419CF344-3D94-4DAD-99C8-EA7B00E5EA8B}
Adobe Flash Player ActiveX–>C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 7.0.9–>MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70900000002}
ArcSoft PhotoBase 3–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A5460871-42FF-45CD-A634-01C755E9CEA1}\SETUP.EXE" -l0x9 -uninst
ArcSoft PhotoImpression–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{797703D4-461B-4BC9-AACA-292917F3A47F}\SETUP.EXE" -l0x9 -uninst
Desktop Taipei version 2.2–>"C:\Program Files\Desktop Taipei\unins000.exe"
DivX Codec–>C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
DivX Content Uploader–>C:\Program Files\DivX\DivXContentUploaderUninstall.exe /CUPLOADER
DivX Converter–>C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
DivX Player–>C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
DivX Web Player–>C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
DV Series–>C:\Program Files\DV Series\uninst.exe
DVC301–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5AA4D39A-C9FE-4EC9-8DA5-57015C4260C1}\Setup.exe"
High Definition Audio Driver Package - KB888111–>"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
Hijackthis 1.99.1–>"C:\Program Files\Hijackthis\unins000.exe"
HijackThis 2.0.2–>"C:\Program Files\trend micro\HijackThis.exe" /uninstall
Hotfix for Windows Media Format 11 SDK (KB929399)–>"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Hotfix for Windows Media Player 11 (KB939683)–>"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB952287)–>"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
InterVideo WinDVD–>"C:\Program Files\InstallShield Installation Information\{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}\setup.exe" REMOVEALL
Java™ 6 Update 10–>MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216010FF}
Luxor (remove only)–>"C:\Program Files\MumboJumbo\Luxor\uninstall.exe"
Malwarebytes' Anti-Malware–>"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Microsoft .NET Framework 1.1 Hotfix (KB928366)–>"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1–>msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1–>MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft Compression Client Pack 1.0 for Windows XP–>"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Home Publishing 2000–>MsiExec.exe /I{0CD3BB5C-BBCA-11D2-8C20-00C04FBBCFF9}
Microsoft Internationalized Domain Names Mitigation APIs–>"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs–>"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office 2000 SR-1 Premium–>MsiExec.exe /I{00000409-78E1-11D2-B60F-006097C998E7}
Microsoft User-Mode Driver Framework Feature Pack 1.0–>"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable–>MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
MSXML 4.0 SP2 (KB936181)–>MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
Nero 7 Essentials–>MsiExec.exe /X{9B4E6CB9-E54D-47F7-A414-E2D5740E1033}
neroxml–>MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
Prime95–>"C:\Program Files\Prime95\Uninstall.exe" "C:\Program Files\Prime95\install.log"
Realtek High Definition Audio Driver–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x9 -removeonly
Security Update for Windows Internet Explorer 7 (KB938127)–>"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB942615)–>"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB944533)–>"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB950759)–>"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB953838)–>"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB956390)–>"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB936782)–>"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB954154)–>"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923789)–>C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
Security Update for Windows XP (KB938464)–>"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)–>"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)–>"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950760)–>"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)–>"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)–>"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)–>"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)–>"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)–>"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)–>"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)–>"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953839)–>"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954211)–>"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956391)–>"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)–>"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956841)–>"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957095)–>"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)–>"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Sound'Em 1.0–>C:\Program Files\DV Series\UNWISE.EXE C:\Program Files\DV Series\install.log
Update for Windows XP (KB951072-v2)–>"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Update for Windows XP (KB951978)–>"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Verizon Broadband Toolbar–>C:\Program Files\vol_toolbar\uninstall.exe
Verizon Online Help and Support–>C:\PROGRA~1\Verizon\UNWISE.EXE C:\PROGRA~1\Verizon\INSTALL.LOG
Verizon Servicepoint 1.5.20–>"C:\Program Files\Verizon\VSP\unins000.exe"
VIA Rhine-Family Fast-Ethernet Adapter–>Rundll32.exe vuins32.dll,vuins32Ex $Rhine $VIA
VIA/S3G Display Driver 6.14.10.0075–>C:\PROGRA~1\S3\UChromeP\s3minset.exe /u UChromeP.uns
Windows Driver Package - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0)–>C:\PROGRA~1\DIFX\7B44739871F4D539FA473F57A832EA4B6A59EF06\DPInst.exe /d /u C:\WINDOWS\system32\DRVSTORE\amdk8_C074F64CC74B03BC354BB5DC973CCF768D5A7194\amdk8.inf
Windows Media Format 11 runtime–>"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime–>"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11–>"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11–>"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows XP Service Pack 3–>"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
Zuma Deluxe 1.0–>C:\Program Files\PopCap Games\Zuma Deluxe\PopUninstall.exe "C:\Program Files\PopCap Games\Zuma Deluxe\Install.log"

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 107 Stepping 1, AuthenticAMD
"PROCESSOR_REVISION"=6b01
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP

—————–EOF—————–
info.txt logfile of random's system information tool 1.04 2008-10-25 01:44:30

======Uninstall list======

–>C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
–>C:\Program Files\Nero\Nero 7\\nero\uninstall\UNNERO.exe /UNINSTALL
–>C:\WINDOWS\NuNInst.exe /UNINSTALL
–>C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
–>rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Acronis True Image Home–>MsiExec.exe /X{419CF344-3D94-4DAD-99C8-EA7B00E5EA8B}
Adobe Flash Player ActiveX–>C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 7.0.9–>MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70900000002}
ArcSoft PhotoBase 3–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A5460871-42FF-45CD-A634-01C755E9CEA1}\SETUP.EXE" -l0x9 -uninst
ArcSoft PhotoImpression–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{797703D4-461B-4BC9-AACA-292917F3A47F}\SETUP.EXE" -l0x9 -uninst
Desktop Taipei version 2.2–>"C:\Program Files\Desktop Taipei\unins000.exe"
DivX Codec–>C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
DivX Content Uploader–>C:\Program Files\DivX\DivXContentUploaderUninstall.exe /CUPLOADER
DivX Converter–>C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
DivX Player–>C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
DivX Web Player–>C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
DV Series–>C:\Program Files\DV Series\uninst.exe
DVC301–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5AA4D39A-C9FE-4EC9-8DA5-57015C4260C1}\Setup.exe"
High Definition Audio Driver Package - KB888111–>"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
Hijackthis 1.99.1–>"C:\Program Files\Hijackthis\unins000.exe"
HijackThis 2.0.2–>"C:\Program Files\trend micro\HijackThis.exe" /uninstall
Hotfix for Windows Media Format 11 SDK (KB929399)–>"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Hotfix for Windows Media Player 11 (KB939683)–>"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB952287)–>"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
InterVideo WinDVD–>"C:\Program Files\InstallShield Installation Information\{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}\setup.exe" REMOVEALL
Java™ 6 Update 10–>MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216010FF}
Luxor (remove only)–>"C:\Program Files\MumboJumbo\Luxor\uninstall.exe"
Malwarebytes' Anti-Malware–>"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Microsoft .NET Framework 1.1 Hotfix (KB928366)–>"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1–>msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1–>MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft Compression Client Pack 1.0 for Windows XP–>"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Home Publishing 2000–>MsiExec.exe /I{0CD3BB5C-BBCA-11D2-8C20-00C04FBBCFF9}
Microsoft Internationalized Domain Names Mitigation APIs–>"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs–>"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office 2000 SR-1 Premium–>MsiExec.exe /I{00000409-78E1-11D2-B60F-006097C998E7}
Microsoft User-Mode Driver Framework Feature Pack 1.0–>"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable–>MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
MSXML 4.0 SP2 (KB936181)–>MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
Nero 7 Essentials–>MsiExec.exe /X{9B4E6CB9-E54D-47F7-A414-E2D5740E1033}
neroxml–>MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
Prime95–>"C:\Program Files\Prime95\Uninstall.exe" "C:\Program Files\Prime95\install.log"
Realtek High Definition Audio Driver–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x9 -removeonly
Security Update for Windows Internet Explorer 7 (KB938127)–>"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB942615)–>"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB944533)–>"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB950759)–>"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB953838)–>"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB956390)–>"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB936782)–>"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB954154)–>"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923789)–>C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
Security Update for Windows XP (KB938464)–>"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)–>"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)–>"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950760)–>"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)–>"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)–>"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)–>"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)–>"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)–>"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)–>"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)–>"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953839)–>"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954211)–>"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956391)–>"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)–>"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956841)–>"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957095)–>"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)–>"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Sound'Em 1.0–>C:\Program Files\DV Series\UNWISE.EXE C:\Program Files\DV Series\install.log
Update for Windows XP (KB951072-v2)–>"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Update for Windows XP (KB951978)–>"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Verizon Broadband Toolbar–>C:\Program Files\vol_toolbar\uninstall.exe
Verizon Online Help and Support–>C:\PROGRA~1\Verizon\UNWISE.EXE C:\PROGRA~1\Verizon\INSTALL.LOG
Verizon Servicepoint 1.5.20–>"C:\Program Files\Verizon\VSP\unins000.exe"
VIA Rhine-Family Fast-Ethernet Adapter–>Rundll32.exe vuins32.dll,vuins32Ex $Rhine $VIA
VIA/S3G Display Driver 6.14.10.0075–>C:\PROGRA~1\S3\UChromeP\s3minset.exe /u UChromeP.uns
Windows Driver Package - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0)–>C:\PROGRA~1\DIFX\7B44739871F4D539FA473F57A832EA4B6A59EF06\DPInst.exe /d /u C:\WINDOWS\system32\DRVSTORE\amdk8_C074F64CC74B03BC354BB5DC973CCF768D5A7194\amdk8.inf
Windows Media Format 11 runtime–>"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime–>"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11–>"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11–>"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows XP Service Pack 3–>"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
Zuma Deluxe 1.0–>C:\Program Files\PopCap Games\Zuma Deluxe\PopUninstall.exe "C:\Program Files\PopCap Games\Zuma Deluxe\Install.log"

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 107 Stepping 1, AuthenticAMD
"PROCESSOR_REVISION"=6b01
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP

—————–EOF—————–



ok…. there's one….there are four files in the folder, that was one…there wasn't one with the title you wanted

here's the second:


Logfile of random's system information tool 1.04 (written by random/random)
Run by [removed] at 2008-10-25 01:44:13
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 67 GB (87%) free of 76 GB
Total RAM: 894 MB (64% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:44:28 AM, on 10/25/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\S3trayp.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Verizon\McciTrayApp.exe
C:\Program Files\Verizon\VSP\VerizonServicepoint.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\DV Series\Console\Watch.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\YWJJX5QM\RSIT[1].exe
C:\Program Files\trend micro\User.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.netzero.net/s/search?r=minisearch
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-8CB0-AB60BB9AAE22} - C:\PROGRA~1\VOL_TO~1\VOL_TO~1.DLL (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [S3Trayp] S3trayp.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SecurDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe
O4 - HKLM\..\Run: [VerizonServicepoint.exe] "C:\Program Files\Verizon\VSP\VerizonServicepoint.exe" /AUTORUN
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Watch.lnk = C:\Program Files\DV Series\Console\Watch.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon…20Installer.cab
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe

–
End of file - 5753 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-12-18 59032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4E7BD74F-2B8D-469E-8CB0-AB60BB9AAE22}]
Verizon Broadband Toolbar - C:\PROGRA~1\VOL_TO~1\VOL_TO~1.DLL []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre6\bin\ssv.dll [2008-10-25 320920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-10-25 34816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2008-10-25 73728]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"=C:\WINDOWS\system32\VTTimer.exe [2006-09-21 53248]
"S3Trayp"=C:\WINDOWS\system32\S3trayp.exe [2006-10-09 176128]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2007-08-10 16384000]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-01 153136]
"SecurDisc"=C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe [2007-05-15 1628208]
"InCD"=C:\Program Files\Nero\Nero 7\InCD\InCD.exe [2007-05-15 1057328]
"TrueImageMonitor.exe"=C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe [2006-10-16 1164912]
"AcronisTimounterMonitor"=C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe [2006-10-16 1941784]
"Acronis Scheduler2 Service"=C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe [2006-10-16 87584]
"Verizon_McciTrayApp"=C:\Program Files\Verizon\McciTrayApp.exe [2007-09-28 936960]
"VerizonServicepoint.exe"=C:\Program Files\Verizon\VSP\VerizonServicepoint.exe [2008-02-13 2065648]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2008-10-25 136600]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-13 1695232]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE
Microsoft Works Calendar Reminders.lnk - C:\WINDOWS\Installer\{0CD3BB5C-BBCA-11D2-8C20-00C04FBBCFF9}\A94AAB13.exe
Watch.lnk - C:\Program Files\DV Series\Console\Watch.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
relog_ap

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Grisoft\AVG7\avginet.exe"="C:\Program Files\Grisoft\AVG7\avginet.exe:*:Enabled:avginet.exe"
"C:\Program Files\Grisoft\AVG7\avgamsvr.exe"="C:\Program Files\Grisoft\AVG7\avgamsvr.exe:*:Enabled:avgamsvr.exe"
"C:\Program Files\Grisoft\AVG7\avgcc.exe"="C:\Program Files\Grisoft\AVG7\avgcc.exe:*:Enabled:avgcc.exe"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2c203ae0-c126-11dc-9e32-001d92410860}]
shell\AutoRun\command - E:\lzext.exe


======List of files/folders created in the last 1 months======

2008-10-25 01:44:13 —-D—- C:\rsit
2008-10-25 01:44:13 —-D—- C:\Program Files\trend micro
2008-10-25 01:08:44 —-A—- C:\WINDOWS\system32\javaws.exe
2008-10-25 01:08:44 —-A—- C:\WINDOWS\system32\javaw.exe
2008-10-25 01:08:44 —-A—- C:\WINDOWS\system32\java.exe
2008-10-25 01:08:44 —-A—- C:\WINDOWS\system32\deploytk.dll
2008-10-24 23:14:42 —-D—- C:\Documents and Settings\User\Application Data\Malwarebytes
2008-10-24 23:14:37 —-D—- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-24 23:14:37 —-D—- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-24 10:09:56 —-HDC—- C:\WINDOWS\$NtUninstallKB958644$
2008-10-24 07:28:00 —-A—- C:\WINDOWS\system32\CF11254.exe
2008-10-24 07:27:09 —-A—- C:\WINDOWS\system32\CF11087.exe
2008-10-24 07:25:36 —-A—- C:\WINDOWS\system32\CF10781.exe
2008-10-24 07:25:35 —-A—- C:\Bug.txt
2008-10-24 07:19:55 —-D—- C:\Documents and Settings\All Users\Application Data\Avg8
2008-10-23 22:19:40 —-D—- C:\Program Files\Hijackthis
2008-10-23 20:05:03 —-D—- C:\Program Files\AVG
2008-10-20 12:45:28 —-A—- C:\WINDOWS\system32\kbdkor.dll
2008-10-20 12:45:28 —-A—- C:\WINDOWS\system32\kbdjpn.dll
2008-10-20 12:45:28 —-A—- C:\WINDOWS\system32\kbd103.dll
2008-10-20 12:45:28 —-A—- C:\WINDOWS\system32\kbd101c.dll
2008-10-20 12:45:26 —-A—- C:\WINDOWS\system32\kbd101b.dll
2008-10-20 12:45:25 —-A—- C:\WINDOWS\system32\kbd106.dll
2008-10-18 03:00:29 —-HDC—- C:\WINDOWS\$NtUninstallKB951978$
2008-10-17 10:43:28 —-D—- C:\WINDOWS\Prefetch
2008-10-17 10:42:06 —-HDC—- C:\WINDOWS\$NtUninstallKB957095$
2008-10-17 10:42:01 —-HDC—- C:\WINDOWS\$NtUninstallKB956841$
2008-10-17 10:41:56 —-HDC—- C:\WINDOWS\$NtUninstallKB956803$
2008-10-17 10:41:51 —-HDC—- C:\WINDOWS\$NtUninstallKB954211$
2008-10-17 10:41:46 —-HDC—- C:\WINDOWS\$NtUninstallKB952954$
2008-10-17 10:41:42 —-HDC—- C:\WINDOWS\$NtUninstallKB952287$
2008-10-17 10:41:38 —-HDC—- C:\WINDOWS\$NtUninstallKB951748$
2008-10-17 10:41:34 —-HDC—- C:\WINDOWS\$NtUninstallKB951698$
2008-10-17 10:41:30 —-HDC—- C:\WINDOWS\$NtUninstallKB951376-v2$
2008-10-17 10:41:24 —-HDC—- C:\WINDOWS\$NtUninstallKB951066$
2008-10-17 10:41:20 —-HDC—- C:\WINDOWS\$NtUninstallKB950974$
2008-10-17 10:41:16 —-HDC—- C:\WINDOWS\$NtUninstallKB950762$
2008-10-17 10:41:11 —-HDC—- C:\WINDOWS\$NtUninstallKB946648$
2008-10-17 10:41:08 —-HDC—- C:\WINDOWS\$NtUninstallKB938464$
2008-10-17 10:38:50 —-D—- C:\WINDOWS\system32\scripting
2008-10-17 10:38:50 —-D—- C:\WINDOWS\system32\en
2008-10-17 10:38:50 —-D—- C:\WINDOWS\l2schemas
2008-10-17 10:38:49 —-D—- C:\WINDOWS\system32\bits
2008-10-17 10:37:29 —-D—- C:\WINDOWS\ServicePackFiles
2008-10-17 10:33:10 —-HDC—- C:\WINDOWS\$NtServicePackUninstall$
2008-10-17 10:33:09 —-D—- C:\WINDOWS\EHome
2008-10-14 19:45:31 —-HDC—- C:\WINDOWS\$NtUninstallKB956803_0$
2008-10-14 19:45:27 —-HDC—- C:\WINDOWS\$NtUninstallKB956391$
2008-10-14 19:45:23 —-HDC—- C:\WINDOWS\$NtUninstallKB957095_0$
2008-10-14 19:45:01 —-HDC—- C:\WINDOWS\$NtUninstallKB954211_0$
2008-10-14 19:44:52 —-HDC—- C:\WINDOWS\$NtUninstallKB956841_0$
2008-09-29 03:01:32 —-D—- C:\Documents and Settings\User\Application Data\ArcSoft
2008-09-29 02:58:07 —-A—- C:\WINDOWS\PB_setup.ini
2008-09-29 02:57:05 —-D—- C:\Program Files\ArcSoft
2008-09-29 02:57:05 —-A—- C:\WINDOWS\PI_setup.ini
2008-09-29 02:57:05 —-A—- C:\WINDOWS\pcdlib32.dll
2008-09-29 02:32:22 —-A—- C:\WINDOWS\Active Setup Log.txt
2008-09-29 02:16:36 —-D—- C:\Documents and Settings\User\Application Data\Help
2008-09-29 02:09:56 —-A—- C:\WINDOWS\Ulead32.ini
2008-09-29 02:09:54 —-D—- C:\Program Files\Ulead Systems
2008-09-29 02:08:18 —-A—- C:\WINDOWS\system32\MKCoInstaller.dll
2008-09-29 02:06:47 —-D—- C:\Program Files\DV Series
2008-09-28 18:18:10 —-D—- C:\Documents and Settings\User\Application Data\Motive

======List of files/folders modified in the last 1 months======

2008-10-25 01:44:13 —-RD—- C:\Program Files
2008-10-25 01:23:10 —-SHD—- C:\WINDOWS\Installer
2008-10-25 01:22:27 —-D—- C:\Program Files\Java
2008-10-25 01:22:26 —-D—- C:\Program Files\Common Files
2008-10-25 01:22:18 —-D—- C:\WINDOWS\system32
2008-10-25 01:17:31 —-D—- C:\WINDOWS\Temp
2008-10-25 01:16:54 —-A—- C:\WINDOWS\SchedLgU.Txt
2008-10-25 01:05:40 —-SD—- C:\WINDOWS\Downloaded Program Files
2008-10-24 23:14:40 —-D—- C:\WINDOWS\system32\drivers
2008-10-24 11:57:18 —-D—- C:\WINDOWS
2008-10-24 10:10:00 —-HD—- C:\WINDOWS\inf
2008-10-24 10:09:58 —-RSHDC—- C:\WINDOWS\system32\dllcache
2008-10-24 10:09:35 —-HD—- C:\WINDOWS\$hf_mig$
2008-10-24 10:09:34 —-D—- C:\WINDOWS\system32\CatRoot2
2008-10-24 07:19:07 —-SD—- C:\Documents and Settings\User\Application Data\Microsoft
2008-10-24 07:18:23 —-D—- C:\Documents and Settings\User\Application Data\SUPERAntiSpyware.com
2008-10-24 07:18:19 —-D—- C:\Program Files\SUPERAntiSpyware
2008-10-24 07:17:59 —-D—- C:\Program Files\SpywareBlaster
2008-10-23 20:09:57 —-D—- C:\Program Files\vol_toolbar
2008-10-20 12:45:35 —-D—- C:\WINDOWS\Help
2008-10-20 12:45:31 —-RSD—- C:\WINDOWS\Fonts
2008-10-20 03:10:00 —-A—- C:\WINDOWS\win.ini
2008-10-18 03:00:33 —-A—- C:\WINDOWS\imsins.BAK
2008-10-17 10:45:01 —-A—- C:\WINDOWS\system32\PerfStringBackup.INI
2008-10-17 10:43:51 —-A—- C:\WINDOWS\OEWABLog.txt
2008-10-17 10:43:31 —-A—- C:\WINDOWS\setuplog.txt
2008-10-17 10:43:01 —-D—- C:\WINDOWS\system32\Setup
2008-10-17 10:43:01 —-D—- C:\WINDOWS\AppPatch
2008-10-17 10:43:01 —-D—- C:\Program Files\Messenger
2008-10-17 10:43:00 —-D—- C:\WINDOWS\system32\wbem
2008-10-17 10:42:28 —-D—- C:\WINDOWS\security
2008-10-17 10:42:07 —-D—- C:\WINDOWS\system32\CatRoot
2008-10-17 10:39:05 —-D—- C:\WINDOWS\WinSxS
2008-10-17 10:38:59 —-D—- C:\WINDOWS\network diagnostic
2008-10-17 10:38:59 —-D—- C:\WINDOWS\ime
2008-10-17 10:38:51 —-D—- C:\WINDOWS\system32\usmt
2008-10-17 10:38:51 —-D—- C:\WINDOWS\system32\en-US
2008-10-17 10:38:49 —-D—- C:\WINDOWS\PeerNet
2008-10-17 10:38:49 —-D—- C:\Program Files\Movie Maker
2008-10-17 10:37:26 —-D—- C:\WINDOWS\system32\Restore
2008-10-17 10:37:26 —-D—- C:\WINDOWS\system32\npp
2008-10-17 10:37:25 —-D—- C:\WINDOWS\msagent
2008-10-17 10:37:24 —-D—- C:\WINDOWS\srchasst
2008-10-17 10:37:24 —-D—- C:\Program Files\NetMeeting
2008-10-17 10:37:23 —-D—- C:\WINDOWS\system32\Com
2008-10-17 10:37:21 —-D—- C:\Program Files\Windows NT
2008-10-17 10:37:21 —-D—- C:\Program Files\Windows Media Player
2008-10-17 10:37:21 —-D—- C:\Program Files\Outlook Express
2008-10-17 10:37:18 —-D—- C:\Program Files\Common Files\System
2008-10-17 10:37:05 —-D—- C:\WINDOWS\system32\oobe
2008-10-17 10:37:04 —-D—- C:\WINDOWS\system
2008-10-15 12:34:24 —-A—- C:\WINDOWS\system32\netapi32.dll
2008-10-14 19:45:15 —-D—- C:\Program Files\Internet Explorer
2008-10-07 12:19:42 —-A—- C:\WINDOWS\system32\MRT.exe
2008-10-03 13:41:15 —-A—- C:\WINDOWS\system32\ieframe.dll
2008-09-29 18:06:06 —-D—- C:\Program Files\Verizon
2008-09-29 02:58:06 —-HD—- C:\Program Files\InstallShield Installation Information
2008-09-29 02:57:39 —-D—- C:\WINDOWS\twain_32
2008-09-28 18:06:38 —-D—- C:\Documents and Settings\All Users\Application Data\Motive

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AmdK8;AMD Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-07-02 36864]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-04 12032]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2004-08-03 11868]
R2 tifsfilter;Acronis True Image FS Filter; C:\WINDOWS\system32\DRIVERS\tifsfilt.sys [2008-01-12 39264]
R3 FET5X86V;VIA Rhine-Family Fast-Ethernet Adapter Driver Service; C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [2007-04-16 42496]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HSF_DP;HSF_DP; C:\WINDOWS\system32\DRIVERS\HSFDPSP2.sys [2004-08-03 1041536]
R3 HSFHWBS2;HSFHWBS2; C:\WINDOWS\system32\DRIVERS\HSFBS2S2.sys [2004-08-03 220032]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-08-10 4603904]
R3 S3GIGP;S3GIGP; C:\WINDOWS\system32\DRIVERS\S3gIGPm.sys [2006-11-09 634880]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSFCXTS2.sys [2004-08-03 685056]
S1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
S1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
S1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys []
S3 ADSFilter;ADSFilter - (Aluria Filter Driver); C:\WINDOWS\system32\DRIVERS\ADSFilter.sys []
S3 BFAIFILT;BFAIFILT; C:\WINDOWS\System32\Drivers\bfaifilt.sys [2004-07-13 3264]
S3 BW2NDIS5;BW2NDIS5; C:\WINDOWS\System32\Drivers\BW2NDIS5.sys []
S3 dot4;MS IEEE-1284.4 Driver; C:\WINDOWS\system32\DRIVERS\Dot4.sys [2008-04-13 206976]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\WINDOWS\system32\DRIVERS\Dot4Prt.sys [2001-08-17 12928]
S3 Dot4Scan;Scan Class Driver for IEEE-1284.4; C:\WINDOWS\system32\DRIVERS\Dot4Scan.sys [2001-08-17 8704]
S3 dot4usb;Dot4USB Filter Dot4USB Filter; C:\WINDOWS\system32\DRIVERS\dot4usb.sys [2001-08-17 23808]
S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\fetnd5.sys [2001-08-17 27165]
S3 GMSIPCI;GMSIPCI; \??\D:\INSTALL\GMSIPCI.SYS []
S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 MREMPR5;MREMPR5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS []
S3 MRENDIS5;MRENDIS5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS []
S3 MRV6X32P;Vista 32-bits Native WiFi Driver; C:\WINDOWS\system32\DRIVERS\MRVW13B.sys [2006-11-02 253952]
S3 SASENUM;SASENUM; \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS []
S3 U2KG54;BUFFALO WLI-U2-KG54 Wireless LAN Adapter Service; C:\WINDOWS\system32\DRIVERS\U2KG54.sys [2005-10-17 245376]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 W8335XP;802.11g/b Driver for Windows XP (8335); C:\WINDOWS\system32\DRIVERS\Mrvw125.sys [2005-12-29 282624]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AcrSch2Svc;Acronis Scheduler2 Service; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe [2006-10-16 230944]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2008-10-25 152984]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-04-13 792112]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
S4 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-05-08 271920]

—————–EOF—————–


jeesh, this isn't working very well for me….

i'm trying the third file now:

info.txt logfile of random's system information tool 1.04 2008-10-25 01:44:30

======Uninstall list======

–>C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
–>C:\Program Files\Nero\Nero 7\\nero\uninstall\UNNERO.exe /UNINSTALL
–>C:\WINDOWS\NuNInst.exe /UNINSTALL
–>C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
–>rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Acronis True Image Home–>MsiExec.exe /X{419CF344-3D94-4DAD-99C8-EA7B00E5EA8B}
Adobe Flash Player ActiveX–>C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 7.0.9–>MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70900000002}
ArcSoft PhotoBase 3–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A5460871-42FF-45CD-A634-01C755E9CEA1}\SETUP.EXE" -l0x9 -uninst
ArcSoft PhotoImpression–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{797703D4-461B-4BC9-AACA-292917F3A47F}\SETUP.EXE" -l0x9 -uninst
Desktop Taipei version 2.2–>"C:\Program Files\Desktop Taipei\unins000.exe"
DivX Codec–>C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
DivX Content Uploader–>C:\Program Files\DivX\DivXContentUploaderUninstall.exe /CUPLOADER
DivX Converter–>C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
DivX Player–>C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
DivX Web Player–>C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
DV Series–>C:\Program Files\DV Series\uninst.exe
DVC301–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5AA4D39A-C9FE-4EC9-8DA5-57015C4260C1}\Setup.exe"
High Definition Audio Driver Package - KB888111–>"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
Hijackthis 1.99.1–>"C:\Program Files\Hijackthis\unins000.exe"
HijackThis 2.0.2–>"C:\Program Files\trend micro\HijackThis.exe" /uninstall
Hotfix for Windows Media Format 11 SDK (KB929399)–>"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Hotfix for Windows Media Player 11 (KB939683)–>"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB952287)–>"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
InterVideo WinDVD–>"C:\Program Files\InstallShield Installation Information\{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}\setup.exe" REMOVEALL
Java™ 6 Update 10–>MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216010FF}
Luxor (remove only)–>"C:\Program Files\MumboJumbo\Luxor\uninstall.exe"
Malwarebytes' Anti-Malware–>"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Microsoft .NET Framework 1.1 Hotfix (KB928366)–>"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1–>msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1–>MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft Compression Client Pack 1.0 for Windows XP–>"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Home Publishing 2000–>MsiExec.exe /I{0CD3BB5C-BBCA-11D2-8C20-00C04FBBCFF9}
Microsoft Internationalized Domain Names Mitigation APIs–>"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs–>"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office 2000 SR-1 Premium–>MsiExec.exe /I{00000409-78E1-11D2-B60F-006097C998E7}
Microsoft User-Mode Driver Framework Feature Pack 1.0–>"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable–>MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
MSXML 4.0 SP2 (KB936181)–>MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
Nero 7 Essentials–>MsiExec.exe /X{9B4E6CB9-E54D-47F7-A414-E2D5740E1033}
neroxml–>MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
Prime95–>"C:\Program Files\Prime95\Uninstall.exe" "C:\Program Files\Prime95\install.log"
Realtek High Definition Audio Driver–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x9 -removeonly
Security Update for Windows Internet Explorer 7 (KB938127)–>"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB942615)–>"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB944533)–>"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB950759)–>"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB953838)–>"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB956390)–>"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB936782)–>"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB954154)–>"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923789)–>C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
Security Update for Windows XP (KB938464)–>"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)–>"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)–>"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950760)–>"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)–>"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)–>"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)–>"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)–>"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)–>"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)–>"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)–>"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953839)–>"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954211)–>"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956391)–>"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)–>"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956841)–>"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957095)–>"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)–>"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Sound'Em 1.0–>C:\Program Files\DV Series\UNWISE.EXE C:\Program Files\DV Series\install.log
Update for Windows XP (KB951072-v2)–>"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Update for Windows XP (KB951978)–>"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Verizon Broadband Toolbar–>C:\Program Files\vol_toolbar\uninstall.exe
Verizon Online Help and Support–>C:\PROGRA~1\Verizon\UNWISE.EXE C:\PROGRA~1\Verizon\INSTALL.LOG
Verizon Servicepoint 1.5.20–>"C:\Program Files\Verizon\VSP\unins000.exe"
VIA Rhine-Family Fast-Ethernet Adapter–>Rundll32.exe vuins32.dll,vuins32Ex $Rhine $VIA
VIA/S3G Display Driver 6.14.10.0075–>C:\PROGRA~1\S3\UChromeP\s3minset.exe /u UChromeP.uns
Windows Driver Package - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0)–>C:\PROGRA~1\DIFX\7B44739871F4D539FA473F57A832EA4B6A59EF06\DPInst.exe /d /u C:\WINDOWS\system32\DRVSTORE\amdk8_C074F64CC74B03BC354BB5DC973CCF768D5A7194\amdk8.inf
Windows Media Format 11 runtime–>"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime–>"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11–>"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11–>"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows XP Service Pack 3–>"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
Zuma Deluxe 1.0–>C:\Program Files\PopCap Games\Zuma Deluxe\PopUninstall.exe "C:\Program Files\PopCap Games\Zuma Deluxe\Install.log"

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 107 Stepping 1, AuthenticAMD
"PROCESSOR_REVISION"=6b01
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP

—————–EOF—————–

here's the fourth one:
Logfile of random's system information tool 1.04 (written by random/random)
Run by [removed] at 2008-10-25 01:44:13
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 67 GB (87%) free of 76 GB
Total RAM: 894 MB (64% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:44:28 AM, on 10/25/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\S3trayp.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Verizon\McciTrayApp.exe
C:\Program Files\Verizon\VSP\VerizonServicepoint.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\DV Series\Console\Watch.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\YWJJX5QM\RSIT[1].exe
C:\Program Files\trend micro\User.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.netzero.net/s/search?r=minisearch
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-8CB0-AB60BB9AAE22} - C:\PROGRA~1\VOL_TO~1\VOL_TO~1.DLL (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [S3Trayp] S3trayp.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SecurDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe
O4 - HKLM\..\Run: [VerizonServicepoint.exe] "C:\Program Files\Verizon\VSP\VerizonServicepoint.exe" /AUTORUN
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Watch.lnk = C:\Program Files\DV Series\Console\Watch.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon…20Installer.cab
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe

–
End of file - 5753 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-12-18 59032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4E7BD74F-2B8D-469E-8CB0-AB60BB9AAE22}]
Verizon Broadband Toolbar - C:\PROGRA~1\VOL_TO~1\VOL_TO~1.DLL []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre6\bin\ssv.dll [2008-10-25 320920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-10-25 34816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2008-10-25 73728]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"=C:\WINDOWS\system32\VTTimer.exe [2006-09-21 53248]
"S3Trayp"=C:\WINDOWS\system32\S3trayp.exe [2006-10-09 176128]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2007-08-10 16384000]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-01 153136]
"SecurDisc"=C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe [2007-05-15 1628208]
"InCD"=C:\Program Files\Nero\Nero 7\InCD\InCD.exe [2007-05-15 1057328]
"TrueImageMonitor.exe"=C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe [2006-10-16 1164912]
"AcronisTimounterMonitor"=C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe [2006-10-16 1941784]
"Acronis Scheduler2 Service"=C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe [2006-10-16 87584]
"Verizon_McciTrayApp"=C:\Program Files\Verizon\McciTrayApp.exe [2007-09-28 936960]
"VerizonServicepoint.exe"=C:\Program Files\Verizon\VSP\VerizonServicepoint.exe [2008-02-13 2065648]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2008-10-25 136600]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-13 1695232]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE
Microsoft Works Calendar Reminders.lnk - C:\WINDOWS\Installer\{0CD3BB5C-BBCA-11D2-8C20-00C04FBBCFF9}\A94AAB13.exe
Watch.lnk - C:\Program Files\DV Series\Console\Watch.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
relog_ap

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Grisoft\AVG7\avginet.exe"="C:\Program Files\Grisoft\AVG7\avginet.exe:*:Enabled:avginet.exe"
"C:\Program Files\Grisoft\AVG7\avgamsvr.exe"="C:\Program Files\Grisoft\AVG7\avgamsvr.exe:*:Enabled:avgamsvr.exe"
"C:\Program Files\Grisoft\AVG7\avgcc.exe"="C:\Program Files\Grisoft\AVG7\avgcc.exe:*:Enabled:avgcc.exe"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2c203ae0-c126-11dc-9e32-001d92410860}]
shell\AutoRun\command - E:\lzext.exe


======List of files/folders created in the last 1 months======

2008-10-25 01:44:13 —-D—- C:\rsit
2008-10-25 01:44:13 —-D—- C:\Program Files\trend micro
2008-10-25 01:08:44 —-A—- C:\WINDOWS\system32\javaws.exe
2008-10-25 01:08:44 —-A—- C:\WINDOWS\system32\javaw.exe
2008-10-25 01:08:44 —-A—- C:\WINDOWS\system32\java.exe
2008-10-25 01:08:44 —-A—- C:\WINDOWS\system32\deploytk.dll
2008-10-24 23:14:42 —-D—- C:\Documents and Settings\User\Application Data\Malwarebytes
2008-10-24 23:14:37 —-D—- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-24 23:14:37 —-D—- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-24 10:09:56 —-HDC—- C:\WINDOWS\$NtUninstallKB958644$
2008-10-24 07:28:00 —-A—- C:\WINDOWS\system32\CF11254.exe
2008-10-24 07:27:09 —-A—- C:\WINDOWS\system32\CF11087.exe
2008-10-24 07:25:36 —-A—- C:\WINDOWS\system32\CF10781.exe
2008-10-24 07:25:35 —-A—- C:\Bug.txt
2008-10-24 07:19:55 —-D—- C:\Documents and Settings\All Users\Application Data\Avg8
2008-10-23 22:19:40 —-D—- C:\Program Files\Hijackthis
2008-10-23 20:05:03 —-D—- C:\Program Files\AVG
2008-10-20 12:45:28 —-A—- C:\WINDOWS\system32\kbdkor.dll
2008-10-20 12:45:28 —-A—- C:\WINDOWS\system32\kbdjpn.dll
2008-10-20 12:45:28 —-A—- C:\WINDOWS\system32\kbd103.dll
2008-10-20 12:45:28 —-A—- C:\WINDOWS\system32\kbd101c.dll
2008-10-20 12:45:26 —-A—- C:\WINDOWS\system32\kbd101b.dll
2008-10-20 12:45:25 —-A—- C:\WINDOWS\system32\kbd106.dll
2008-10-18 03:00:29 —-HDC—- C:\WINDOWS\$NtUninstallKB951978$
2008-10-17 10:43:28 —-D—- C:\WINDOWS\Prefetch
2008-10-17 10:42:06 —-HDC—- C:\WINDOWS\$NtUninstallKB957095$
2008-10-17 10:42:01 —-HDC—- C:\WINDOWS\$NtUninstallKB956841$
2008-10-17 10:41:56 —-HDC—- C:\WINDOWS\$NtUninstallKB956803$
2008-10-17 10:41:51 —-HDC—- C:\WINDOWS\$NtUninstallKB954211$
2008-10-17 10:41:46 —-HDC—- C:\WINDOWS\$NtUninstallKB952954$
2008-10-17 10:41:42 —-HDC—- C:\WINDOWS\$NtUninstallKB952287$
2008-10-17 10:41:38 —-HDC—- C:\WINDOWS\$NtUninstallKB951748$
2008-10-17 10:41:34 —-HDC—- C:\WINDOWS\$NtUninstallKB951698$
2008-10-17 10:41:30 —-HDC—- C:\WINDOWS\$NtUninstallKB951376-v2$
2008-10-17 10:41:24 —-HDC—- C:\WINDOWS\$NtUninstallKB951066$
2008-10-17 10:41:20 —-HDC—- C:\WINDOWS\$NtUninstallKB950974$
2008-10-17 10:41:16 —-HDC—- C:\WINDOWS\$NtUninstallKB950762$
2008-10-17 10:41:11 —-HDC—- C:\WINDOWS\$NtUninstallKB946648$
2008-10-17 10:41:08 —-HDC—- C:\WINDOWS\$NtUninstallKB938464$
2008-10-17 10:38:50 —-D—- C:\WINDOWS\system32\scripting
2008-10-17 10:38:50 —-D—- C:\WINDOWS\system32\en
2008-10-17 10:38:50 —-D—- C:\WINDOWS\l2schemas
2008-10-17 10:38:49 —-D—- C:\WINDOWS\system32\bits
2008-10-17 10:37:29 —-D—- C:\WINDOWS\ServicePackFiles
2008-10-17 10:33:10 —-HDC—- C:\WINDOWS\$NtServicePackUninstall$
2008-10-17 10:33:09 —-D—- C:\WINDOWS\EHome
2008-10-14 19:45:31 —-HDC—- C:\WINDOWS\$NtUninstallKB956803_0$
2008-10-14 19:45:27 —-HDC—- C:\WINDOWS\$NtUninstallKB956391$
2008-10-14 19:45:23 —-HDC—- C:\WINDOWS\$NtUninstallKB957095_0$
2008-10-14 19:45:01 —-HDC—- C:\WINDOWS\$NtUninstallKB954211_0$
2008-10-14 19:44:52 —-HDC—- C:\WINDOWS\$NtUninstallKB956841_0$
2008-09-29 03:01:32 —-D—- C:\Documents and Settings\User\Application Data\ArcSoft
2008-09-29 02:58:07 —-A—- C:\WINDOWS\PB_setup.ini
2008-09-29 02:57:05 —-D—- C:\Program Files\ArcSoft
2008-09-29 02:57:05 —-A—- C:\WINDOWS\PI_setup.ini
2008-09-29 02:57:05 —-A—- C:\WINDOWS\pcdlib32.dll
2008-09-29 02:32:22 —-A—- C:\WINDOWS\Active Setup Log.txt
2008-09-29 02:16:36 —-D—- C:\Documents and Settings\User\Application Data\Help
2008-09-29 02:09:56 —-A—- C:\WINDOWS\Ulead32.ini
2008-09-29 02:09:54 —-D—- C:\Program Files\Ulead Systems
2008-09-29 02:08:18 —-A—- C:\WINDOWS\system32\MKCoInstaller.dll
2008-09-29 02:06:47 —-D—- C:\Program Files\DV Series
2008-09-28 18:18:10 —-D—- C:\Documents and Settings\User\Application Data\Motive

======List of files/folders modified in the last 1 months======

2008-10-25 01:44:13 —-RD—- C:\Program Files
2008-10-25 01:23:10 —-SHD—- C:\WINDOWS\Installer
2008-10-25 01:22:27 —-D—- C:\Program Files\Java
2008-10-25 01:22:26 —-D—- C:\Program Files\Common Files
2008-10-25 01:22:18 —-D—- C:\WINDOWS\system32
2008-10-25 01:17:31 —-D—- C:\WINDOWS\Temp
2008-10-25 01:16:54 —-A—- C:\WINDOWS\SchedLgU.Txt
2008-10-25 01:05:40 —-SD—- C:\WINDOWS\Downloaded Program Files
2008-10-24 23:14:40 —-D—- C:\WINDOWS\system32\drivers
2008-10-24 11:57:18 —-D—- C:\WINDOWS
2008-10-24 10:10:00 —-HD—- C:\WINDOWS\inf
2008-10-24 10:09:58 —-RSHDC—- C:\WINDOWS\system32\dllcache
2008-10-24 10:09:35 —-HD—- C:\WINDOWS\$hf_mig$
2008-10-24 10:09:34 —-D—- C:\WINDOWS\system32\CatRoot2
2008-10-24 07:19:07 —-SD—- C:\Documents and Settings\User\Application Data\Microsoft
2008-10-24 07:18:23 —-D—- C:\Documents and Settings\User\Application Data\SUPERAntiSpyware.com
2008-10-24 07:18:19 —-D—- C:\Program Files\SUPERAntiSpyware
2008-10-24 07:17:59 —-D—- C:\Program Files\SpywareBlaster
2008-10-23 20:09:57 —-D—- C:\Program Files\vol_toolbar
2008-10-20 12:45:35 —-D—- C:\WINDOWS\Help
2008-10-20 12:45:31 —-RSD—- C:\WINDOWS\Fonts
2008-10-20 03:10:00 —-A—- C:\WINDOWS\win.ini
2008-10-18 03:00:33 —-A—- C:\WINDOWS\imsins.BAK
2008-10-17 10:45:01 —-A—- C:\WINDOWS\system32\PerfStringBackup.INI
2008-10-17 10:43:51 —-A—- C:\WINDOWS\OEWABLog.txt
2008-10-17 10:43:31 —-A—- C:\WINDOWS\setuplog.txt
2008-10-17 10:43:01 —-D—- C:\WINDOWS\system32\Setup
2008-10-17 10:43:01 —-D—- C:\WINDOWS\AppPatch
2008-10-17 10:43:01 —-D—- C:\Program Files\Messenger
2008-10-17 10:43:00 —-D—- C:\WINDOWS\system32\wbem
2008-10-17 10:42:28 —-D—- C:\WINDOWS\security
2008-10-17 10:42:07 —-D—- C:\WINDOWS\system32\CatRoot
2008-10-17 10:39:05 —-D—- C:\WINDOWS\WinSxS
2008-10-17 10:38:59 —-D—- C:\WINDOWS\network diagnostic
2008-10-17 10:38:59 —-D—- C:\WINDOWS\ime
2008-10-17 10:38:51 —-D—- C:\WINDOWS\system32\usmt
2008-10-17 10:38:51 —-D—- C:\WINDOWS\system32\en-US
2008-10-17 10:38:49 —-D—- C:\WINDOWS\PeerNet
2008-10-17 10:38:49 —-D—- C:\Program Files\Movie Maker
2008-10-17 10:37:26 —-D—- C:\WINDOWS\system32\Restore
2008-10-17 10:37:26 —-D—- C:\WINDOWS\system32\npp
2008-10-17 10:37:25 —-D—- C:\WINDOWS\msagent
2008-10-17 10:37:24 —-D—- C:\WINDOWS\srchasst
2008-10-17 10:37:24 —-D—- C:\Program Files\NetMeeting
2008-10-17 10:37:23 —-D—- C:\WINDOWS\system32\Com
2008-10-17 10:37:21 —-D—- C:\Program Files\Windows NT
2008-10-17 10:37:21 —-D—- C:\Program Files\Windows Media Player
2008-10-17 10:37:21 —-D—- C:\Program Files\Outlook Express
2008-10-17 10:37:18 —-D—- C:\Program Files\Common Files\System
2008-10-17 10:37:05 —-D—- C:\WINDOWS\system32\oobe
2008-10-17 10:37:04 —-D—- C:\WINDOWS\system
2008-10-15 12:34:24 —-A—- C:\WINDOWS\system32\netapi32.dll
2008-10-14 19:45:15 —-D—- C:\Program Files\Internet Explorer
2008-10-07 12:19:42 —-A—- C:\WINDOWS\system32\MRT.exe
2008-10-03 13:41:15 —-A—- C:\WINDOWS\system32\ieframe.dll
2008-09-29 18:06:06 —-D—- C:\Program Files\Verizon
2008-09-29 02:58:06 —-HD—- C:\Program Files\InstallShield Installation Information
2008-09-29 02:57:39 —-D—- C:\WINDOWS\twain_32
2008-09-28 18:06:38 —-D—- C:\Documents and Settings\All Users\Application Data\Motive

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AmdK8;AMD Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-07-02 36864]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-04 12032]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2004-08-03 11868]
R2 tifsfilter;Acronis True Image FS Filter; C:\WINDOWS\system32\DRIVERS\tifsfilt.sys [2008-01-12 39264]
R3 FET5X86V;VIA Rhine-Family Fast-Ethernet Adapter Driver Service; C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [2007-04-16 42496]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HSF_DP;HSF_DP; C:\WINDOWS\system32\DRIVERS\HSFDPSP2.sys [2004-08-03 1041536]
R3 HSFHWBS2;HSFHWBS2; C:\WINDOWS\system32\DRIVERS\HSFBS2S2.sys [2004-08-03 220032]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-08-10 4603904]
R3 S3GIGP;S3GIGP; C:\WINDOWS\system32\DRIVERS\S3gIGPm.sys [2006-11-09 634880]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSFCXTS2.sys [2004-08-03 685056]
S1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
S1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
S1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys []
S3 ADSFilter;ADSFilter - (Aluria Filter Driver); C:\WINDOWS\system32\DRIVERS\ADSFilter.sys []
S3 BFAIFILT;BFAIFILT; C:\WINDOWS\System32\Drivers\bfaifilt.sys [2004-07-13 3264]
S3 BW2NDIS5;BW2NDIS5; C:\WINDOWS\System32\Drivers\BW2NDIS5.sys []
S3 dot4;MS IEEE-1284.4 Driver; C:\WINDOWS\system32\DRIVERS\Dot4.sys [2008-04-13 206976]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\WINDOWS\system32\DRIVERS\Dot4Prt.sys [2001-08-17 12928]
S3 Dot4Scan;Scan Class Driver for IEEE-1284.4; C:\WINDOWS\system32\DRIVERS\Dot4Scan.sys [2001-08-17 8704]
S3 dot4usb;Dot4USB Filter Dot4USB Filter; C:\WINDOWS\system32\DRIVERS\dot4usb.sys [2001-08-17 23808]
S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\fetnd5.sys [2001-08-17 27165]
S3 GMSIPCI;GMSIPCI; \??\D:\INSTALL\GMSIPCI.SYS []
S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 MREMPR5;MREMPR5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS []
S3 MRENDIS5;MRENDIS5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS []
S3 MRV6X32P;Vista 32-bits Native WiFi Driver; C:\WINDOWS\system32\DRIVERS\MRVW13B.sys [2006-11-02 253952]
S3 SASENUM;SASENUM; \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS []
S3 U2KG54;BUFFALO WLI-U2-KG54 Wireless LAN Adapter Service; C:\WINDOWS\system32\DRIVERS\U2KG54.sys [2005-10-17 245376]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 W8335XP;802.11g/b Driver for Windows XP (8335); C:\WINDOWS\system32\DRIVERS\Mrvw125.sys [2005-12-29 282624]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AcrSch2Svc;Acronis Scheduler2 Service; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe [2006-10-16 230944]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2008-10-25 152984]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-04-13 792112]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
S4 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-05-08 271920]

—————–EOF—————–
Logfile of random's system information tool 1.04 (written by random/random)
Run by [removed] at 2008-10-25 01:44:13
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 67 GB (87%) free of 76 GB
Total RAM: 894 MB (64% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:44:28 AM, on 10/25/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\S3trayp.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Verizon\McciTrayApp.exe
C:\Program Files\Verizon\VSP\VerizonServicepoint.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\DV Series\Console\Watch.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\YWJJX5QM\RSIT[1].exe
C:\Program Files\trend micro\User.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.netzero.net/s/search?r=minisearch
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-8CB0-AB60BB9AAE22} - C:\PROGRA~1\VOL_TO~1\VOL_TO~1.DLL (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [S3Trayp] S3trayp.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SecurDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe
O4 - HKLM\..\Run: [VerizonServicepoint.exe] "C:\Program Files\Verizon\VSP\VerizonServicepoint.exe" /AUTORUN
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Watch.lnk = C:\Program Files\DV Series\Console\Watch.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon…20Installer.cab
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe

–
End of file - 5753 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-12-18 59032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4E7BD74F-2B8D-469E-8CB0-AB60BB9AAE22}]
Verizon Broadband Toolbar - C:\PROGRA~1\VOL_TO~1\VOL_TO~1.DLL []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre6\bin\ssv.dll [2008-10-25 320920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-10-25 34816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2008-10-25 73728]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"=C:\WINDOWS\system32\VTTimer.exe [2006-09-21 53248]
"S3Trayp"=C:\WINDOWS\system32\S3trayp.exe [2006-10-09 176128]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2007-08-10 16384000]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-01 153136]
"SecurDisc"=C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe [2007-05-15 1628208]
"InCD"=C:\Program Files\Nero\Nero 7\InCD\InCD.exe [2007-05-15 1057328]
"TrueImageMonitor.exe"=C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe [2006-10-16 1164912]
"AcronisTimounterMonitor"=C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe [2006-10-16 1941784]
"Acronis Scheduler2 Service"=C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe [2006-10-16 87584]
"Verizon_McciTrayApp"=C:\Program Files\Verizon\McciTrayApp.exe [2007-09-28 936960]
"VerizonServicepoint.exe"=C:\Program Files\Verizon\VSP\VerizonServicepoint.exe [2008-02-13 2065648]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2008-10-25 136600]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-13 1695232]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE
Microsoft Works Calendar Reminders.lnk - C:\WINDOWS\Installer\{0CD3BB5C-BBCA-11D2-8C20-00C04FBBCFF9}\A94AAB13.exe
Watch.lnk - C:\Program Files\DV Series\Console\Watch.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
relog_ap

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Grisoft\AVG7\avginet.exe"="C:\Program Files\Grisoft\AVG7\avginet.exe:*:Enabled:avginet.exe"
"C:\Program Files\Grisoft\AVG7\avgamsvr.exe"="C:\Program Files\Grisoft\AVG7\avgamsvr.exe:*:Enabled:avgamsvr.exe"
"C:\Program Files\Grisoft\AVG7\avgcc.exe"="C:\Program Files\Grisoft\AVG7\avgcc.exe:*:Enabled:avgcc.exe"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2c203ae0-c126-11dc-9e32-001d92410860}]
shell\AutoRun\command - E:\lzext.exe


======List of files/folders created in the last 1 months======

2008-10-25 01:44:13 —-D—- C:\rsit
2008-10-25 01:44:13 —-D—- C:\Program Files\trend micro
2008-10-25 01:08:44 —-A—- C:\WINDOWS\system32\javaws.exe
2008-10-25 01:08:44 —-A—- C:\WINDOWS\system32\javaw.exe
2008-10-25 01:08:44 —-A—- C:\WINDOWS\system32\java.exe
2008-10-25 01:08:44 —-A—- C:\WINDOWS\system32\deploytk.dll
2008-10-24 23:14:42 —-D—- C:\Documents and Settings\User\Application Data\Malwarebytes
2008-10-24 23:14:37 —-D—- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-24 23:14:37 —-D—- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-24 10:09:56 —-HDC—- C:\WINDOWS\$NtUninstallKB958644$
2008-10-24 07:28:00 —-A—- C:\WINDOWS\system32\CF11254.exe
2008-10-24 07:27:09 —-A—- C:\WINDOWS\system32\CF11087.exe
2008-10-24 07:25:36 —-A—- C:\WINDOWS\system32\CF10781.exe
2008-10-24 07:25:35 —-A—- C:\Bug.txt
2008-10-24 07:19:55 —-D—- C:\Documents and Settings\All Users\Application Data\Avg8
2008-10-23 22:19:40 —-D—- C:\Program Files\Hijackthis
2008-10-23 20:05:03 —-D—- C:\Program Files\AVG
2008-10-20 12:45:28 —-A—- C:\WINDOWS\system32\kbdkor.dll
2008-10-20 12:45:28 —-A—- C:\WINDOWS\system32\kbdjpn.dll
2008-10-20 12:45:28 —-A—- C:\WINDOWS\system32\kbd103.dll
2008-10-20 12:45:28 —-A—- C:\WINDOWS\system32\kbd101c.dll
2008-10-20 12:45:26 —-A—- C:\WINDOWS\system32\kbd101b.dll
2008-10-20 12:45:25 —-A—- C:\WINDOWS\system32\kbd106.dll
2008-10-18 03:00:29 —-HDC—- C:\WINDOWS\$NtUninstallKB951978$
2008-10-17 10:43:28 —-D—- C:\WINDOWS\Prefetch
2008-10-17 10:42:06 —-HDC—- C:\WINDOWS\$NtUninstallKB957095$
2008-10-17 10:42:01 —-HDC—- C:\WINDOWS\$NtUninstallKB956841$
2008-10-17 10:41:56 —-HDC—- C:\WINDOWS\$NtUninstallKB956803$
2008-10-17 10:41:51 —-HDC—- C:\WINDOWS\$NtUninstallKB954211$
2008-10-17 10:41:46 —-HDC—- C:\WINDOWS\$NtUninstallKB952954$
2008-10-17 10:41:42 —-HDC—- C:\WINDOWS\$NtUninstallKB952287$
2008-10-17 10:41:38 —-HDC—- C:\WINDOWS\$NtUninstallKB951748$
2008-10-17 10:41:34 —-HDC—- C:\WINDOWS\$NtUninstallKB951698$
2008-10-17 10:41:30 —-HDC—- C:\WINDOWS\$NtUninstallKB951376-v2$
2008-10-17 10:41:24 —-HDC—- C:\WINDOWS\$NtUninstallKB951066$
2008-10-17 10:41:20 —-HDC—- C:\WINDOWS\$NtUninstallKB950974$
2008-10-17 10:41:16 —-HDC—- C:\WINDOWS\$NtUninstallKB950762$
2008-10-17 10:41:11 —-HDC—- C:\WINDOWS\$NtUninstallKB946648$
2008-10-17 10:41:08 —-HDC—- C:\WINDOWS\$NtUninstallKB938464$
2008-10-17 10:38:50 —-D—- C:\WINDOWS\system32\scripting
2008-10-17 10:38:50 —-D—- C:\WINDOWS\system32\en
2008-10-17 10:38:50 —-D—- C:\WINDOWS\l2schemas
2008-10-17 10:38:49 —-D—- C:\WINDOWS\system32\bits
2008-10-17 10:37:29 —-D—- C:\WINDOWS\ServicePackFiles
2008-10-17 10:33:10 —-HDC—- C:\WINDOWS\$NtServicePackUninstall$
2008-10-17 10:33:09 —-D—- C:\WINDOWS\EHome
2008-10-14 19:45:31 —-HDC—- C:\WINDOWS\$NtUninstallKB956803_0$
2008-10-14 19:45:27 —-HDC—- C:\WINDOWS\$NtUninstallKB956391$
2008-10-14 19:45:23 —-HDC—- C:\WINDOWS\$NtUninstallKB957095_0$
2008-10-14 19:45:01 —-HDC—- C:\WINDOWS\$NtUninstallKB954211_0$
2008-10-14 19:44:52 —-HDC—- C:\WINDOWS\$NtUninstallKB956841_0$
2008-09-29 03:01:32 —-D—- C:\Documents and Settings\User\Application Data\ArcSoft
2008-09-29 02:58:07 —-A—- C:\WINDOWS\PB_setup.ini
2008-09-29 02:57:05 —-D—- C:\Program Files\ArcSoft
2008-09-29 02:57:05 —-A—- C:\WINDOWS\PI_setup.ini
2008-09-29 02:57:05 —-A—- C:\WINDOWS\pcdlib32.dll
2008-09-29 02:32:22 —-A—- C:\WINDOWS\Active Setup Log.txt
2008-09-29 02:16:36 —-D—- C:\Documents and Settings\User\Application Data\Help
2008-09-29 02:09:56 —-A—- C:\WINDOWS\Ulead32.ini
2008-09-29 02:09:54 —-D—- C:\Program Files\Ulead Systems
2008-09-29 02:08:18 —-A—- C:\WINDOWS\system32\MKCoInstaller.dll
2008-09-29 02:06:47 —-D—- C:\Program Files\DV Series
2008-09-28 18:18:10 —-D—- C:\Documents and Settings\User\Application Data\Motive

======List of files/folders modified in the last 1 months======

2008-10-25 01:44:13 —-RD—- C:\Program Files
2008-10-25 01:23:10 —-SHD—- C:\WINDOWS\Installer
2008-10-25 01:22:27 —-D—- C:\Program Files\Java
2008-10-25 01:22:26 —-D—- C:\Program Files\Common Files
2008-10-25 01:22:18 —-D—- C:\WINDOWS\system32
2008-10-25 01:17:31 —-D—- C:\WINDOWS\Temp
2008-10-25 01:16:54 —-A—- C:\WINDOWS\SchedLgU.Txt
2008-10-25 01:05:40 —-SD—- C:\WINDOWS\Downloaded Program Files
2008-10-24 23:14:40 —-D—- C:\WINDOWS\system32\drivers
2008-10-24 11:57:18 —-D—- C:\WINDOWS
2008-10-24 10:10:00 —-HD—- C:\WINDOWS\inf
2008-10-24 10:09:58 —-RSHDC—- C:\WINDOWS\system32\dllcache
2008-10-24 10:09:35 —-HD—- C:\WINDOWS\$hf_mig$
2008-10-24 10:09:34 —-D—- C:\WINDOWS\system32\CatRoot2
2008-10-24 07:19:07 —-SD—- C:\Documents and Settings\User\Application Data\Microsoft
2008-10-24 07:18:23 —-D—- C:\Documents and Settings\User\Application Data\SUPERAntiSpyware.com
2008-10-24 07:18:19 —-D—- C:\Program Files\SUPERAntiSpyware
2008-10-24 07:17:59 —-D—- C:\Program Files\SpywareBlaster
2008-10-23 20:09:57 —-D—- C:\Program Files\vol_toolbar
2008-10-20 12:45:35 —-D—- C:\WINDOWS\Help
2008-10-20 12:45:31 —-RSD—- C:\WINDOWS\Fonts
2008-10-20 03:10:00 —-A—- C:\WINDOWS\win.ini
2008-10-18 03:00:33 —-A—- C:\WINDOWS\imsins.BAK
2008-10-17 10:45:01 —-A—- C:\WINDOWS\system32\PerfStringBackup.INI
2008-10-17 10:43:51 —-A—- C:\WINDOWS\OEWABLog.txt
2008-10-17 10:43:31 —-A—- C:\WINDOWS\setuplog.txt
2008-10-17 10:43:01 —-D—- C:\WINDOWS\system32\Setup
2008-10-17 10:43:01 —-D—- C:\WINDOWS\AppPatch
2008-10-17 10:43:01 —-D—- C:\Program Files\Messenger
2008-10-17 10:43:00 —-D—- C:\WINDOWS\system32\wbem
2008-10-17 10:42:28 —-D—- C:\WINDOWS\security
2008-10-17 10:42:07 —-D—- C:\WINDOWS\system32\CatRoot
2008-10-17 10:39:05 —-D—- C:\WINDOWS\WinSxS
2008-10-17 10:38:59 —-D—- C:\WINDOWS\network diagnostic
2008-10-17 10:38:59 —-D—- C:\WINDOWS\ime
2008-10-17 10:38:51 —-D—- C:\WINDOWS\system32\usmt
2008-10-17 10:38:51 —-D—- C:\WINDOWS\system32\en-US
2008-10-17 10:38:49 —-D—- C:\WINDOWS\PeerNet
2008-10-17 10:38:49 —-D—- C:\Program Files\Movie Maker
2008-10-17 10:37:26 —-D—- C:\WINDOWS\system32\Restore
2008-10-17 10:37:26 —-D—- C:\WINDOWS\system32\npp
2008-10-17 10:37:25 —-D—- C:\WINDOWS\msagent
2008-10-17 10:37:24 —-D—- C:\WINDOWS\srchasst
2008-10-17 10:37:24 —-D—- C:\Program Files\NetMeeting
2008-10-17 10:37:23 —-D—- C:\WINDOWS\system32\Com
2008-10-17 10:37:21 —-D—- C:\Program Files\Windows NT
2008-10-17 10:37:21 —-D—- C:\Program Files\Windows Media Player
2008-10-17 10:37:21 —-D—- C:\Program Files\Outlook Express
2008-10-17 10:37:18 —-D—- C:\Program Files\Common Files\System
2008-10-17 10:37:05 —-D—- C:\WINDOWS\system32\oobe
2008-10-17 10:37:04 —-D—- C:\WINDOWS\system
2008-10-15 12:34:24 —-A—- C:\WINDOWS\system32\netapi32.dll
2008-10-14 19:45:15 —-D—- C:\Program Files\Internet Explorer
2008-10-07 12:19:42 —-A—- C:\WINDOWS\system32\MRT.exe
2008-10-03 13:41:15 —-A—- C:\WINDOWS\system32\ieframe.dll
2008-09-29 18:06:06 —-D—- C:\Program Files\Verizon
2008-09-29 02:58:06 —-HD—- C:\Program Files\InstallShield Installation Information
2008-09-29 02:57:39 —-D—- C:\WINDOWS\twain_32
2008-09-28 18:06:38 —-D—- C:\Documents and Settings\All Users\Application Data\Motive

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AmdK8;AMD Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-07-02 36864]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-04 12032]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2004-08-03 11868]
R2 tifsfilter;Acronis True Image FS Filter; C:\WINDOWS\system32\DRIVERS\tifsfilt.sys [2008-01-12 39264]
R3 FET5X86V;VIA Rhine-Family Fast-Ethernet Adapter Driver Service; C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [2007-04-16 42496]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HSF_DP;HSF_DP; C:\WINDOWS\system32\DRIVERS\HSFDPSP2.sys [2004-08-03 1041536]
R3 HSFHWBS2;HSFHWBS2; C:\WINDOWS\system32\DRIVERS\HSFBS2S2.sys [2004-08-03 220032]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-08-10 4603904]
R3 S3GIGP;S3GIGP; C:\WINDOWS\system32\DRIVERS\S3gIGPm.sys [2006-11-09 634880]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSFCXTS2.sys [2004-08-03 685056]
S1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
S1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
S1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys []
S3 ADSFilter;ADSFilter - (Aluria Filter Driver); C:\WINDOWS\system32\DRIVERS\ADSFilter.sys []
S3 BFAIFILT;BFAIFILT; C:\WINDOWS\System32\Drivers\bfaifilt.sys [2004-07-13 3264]
S3 BW2NDIS5;BW2NDIS5; C:\WINDOWS\System32\Drivers\BW2NDIS5.sys []
S3 dot4;MS IEEE-1284.4 Driver; C:\WINDOWS\system32\DRIVERS\Dot4.sys [2008-04-13 206976]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\WINDOWS\system32\DRIVERS\Dot4Prt.sys [2001-08-17 12928]
S3 Dot4Scan;Scan Class Driver for IEEE-1284.4; C:\WINDOWS\system32\DRIVERS\Dot4Scan.sys [2001-08-17 8704]
S3 dot4usb;Dot4USB Filter Dot4USB Filter; C:\WINDOWS\system32\DRIVERS\dot4usb.sys [2001-08-17 23808]
S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\fetnd5.sys [2001-08-17 27165]
S3 GMSIPCI;GMSIPCI; \??\D:\INSTALL\GMSIPCI.SYS []
S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 MREMPR5;MREMPR5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS []
S3 MRENDIS5;MRENDIS5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS []
S3 MRV6X32P;Vista 32-bits Native WiFi Driver; C:\WINDOWS\system32\DRIVERS\MRVW13B.sys [2006-11-02 253952]
S3 SASENUM;SASENUM; \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS []
S3 U2KG54;BUFFALO WLI-U2-KG54 Wireless LAN Adapter Service; C:\WINDOWS\system32\DRIVERS\U2KG54.sys [2005-10-17 245376]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 W8335XP;802.11g/b Driver for Windows XP (8335); C:\WINDOWS\system32\DRIVERS\Mrvw125.sys [2005-12-29 282624]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AcrSch2Svc;Acronis Scheduler2 Service; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe [2006-10-16 230944]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2008-10-25 152984]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-04-13 792112]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
S4 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-05-08 271920]

—————–EOF—————–
Logfile of random's system information tool 1.04 (written by random/random)
Run by [removed] at 2008-10-25 01:44:13
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 67 GB (87%) free of 76 GB
Total RAM: 894 MB (64% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:44:28 AM, on 10/25/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\S3trayp.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Verizon\McciTrayApp.exe
C:\Program Files\Verizon\VSP\VerizonServicepoint.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\DV Series\Console\Watch.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\YWJJX5QM\RSIT[1].exe
C:\Program Files\trend micro\User.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.netzero.net/s/search?r=minisearch
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-8CB0-AB60BB9AAE22} - C:\PROGRA~1\VOL_TO~1\VOL_TO~1.DLL (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [S3Trayp] S3trayp.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SecurDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe
O4 - HKLM\..\Run: [VerizonServicepoint.exe] "C:\Program Files\Verizon\VSP\VerizonServicepoint.exe" /AUTORUN
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Watch.lnk = C:\Program Files\DV Series\Console\Watch.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon…20Installer.cab
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe

–
End of file - 5753 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-12-18 59032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4E7BD74F-2B8D-469E-8CB0-AB60BB9AAE22}]
Verizon Broadband Toolbar - C:\PROGRA~1\VOL_TO~1\VOL_TO~1.DLL []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre6\bin\ssv.dll [2008-10-25 320920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-10-25 34816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2008-10-25 73728]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"=C:\WINDOWS\system32\VTTimer.exe [2006-09-21 53248]
"S3Trayp"=C:\WINDOWS\system32\S3trayp.exe [2006-10-09 176128]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2007-08-10 16384000]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-01 153136]
"SecurDisc"=C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe [2007-05-15 1628208]
"InCD"=C:\Program Files\Nero\Nero 7\InCD\InCD.exe [2007-05-15 1057328]
"TrueImageMonitor.exe"=C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe [2006-10-16 1164912]
"AcronisTimounterMonitor"=C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe [2006-10-16 1941784]
"Acronis Scheduler2 Service"=C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe [2006-10-16 87584]
"Verizon_McciTrayApp"=C:\Program Files\Verizon\McciTrayApp.exe [2007-09-28 936960]
"VerizonServicepoint.exe"=C:\Program Files\Verizon\VSP\VerizonServicepoint.exe [2008-02-13 2065648]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2008-10-25 136600]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-13 1695232]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE
Microsoft Works Calendar Reminders.lnk - C:\WINDOWS\Installer\{0CD3BB5C-BBCA-11D2-8C20-00C04FBBCFF9}\A94AAB13.exe
Watch.lnk - C:\Program Files\DV Series\Console\Watch.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
relog_ap

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Grisoft\AVG7\avginet.exe"="C:\Program Files\Grisoft\AVG7\avginet.exe:*:Enabled:avginet.exe"
"C:\Program Files\Grisoft\AVG7\avgamsvr.exe"="C:\Program Files\Grisoft\AVG7\avgamsvr.exe:*:Enabled:avgamsvr.exe"
"C:\Program Files\Grisoft\AVG7\avgcc.exe"="C:\Program Files\Grisoft\AVG7\avgcc.exe:*:Enabled:avgcc.exe"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2c203ae0-c126-11dc-9e32-001d92410860}]
shell\AutoRun\command - E:\lzext.exe


======List of files/folders created in the last 1 months======

2008-10-25 01:44:13 —-D—- C:\rsit
2008-10-25 01:44:13 —-D—- C:\Program Files\trend micro
2008-10-25 01:08:44 —-A—- C:\WINDOWS\system32\javaws.exe
2008-10-25 01:08:44 —-A—- C:\WINDOWS\system32\javaw.exe
2008-10-25 01:08:44 —-A—- C:\WINDOWS\system32\java.exe
2008-10-25 01:08:44 —-A—- C:\WINDOWS\system32\deploytk.dll
2008-10-24 23:14:42 —-D—- C:\Documents and Settings\User\Application Data\Malwarebytes
2008-10-24 23:14:37 —-D—- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-24 23:14:37 —-D—- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-24 10:09:56 —-HDC—- C:\WINDOWS\$NtUninstallKB958644$
2008-10-24 07:28:00 —-A—- C:\WINDOWS\system32\CF11254.exe
2008-10-24 07:27:09 —-A—- C:\WINDOWS\system32\CF11087.exe
2008-10-24 07:25:36 —-A—- C:\WINDOWS\system32\CF10781.exe
2008-10-24 07:25:35 —-A—- C:\Bug.txt
2008-10-24 07:19:55 —-D—- C:\Documents and Settings\All Users\Application Data\Avg8
2008-10-23 22:19:40 —-D—- C:\Program Files\Hijackthis
2008-10-23 20:05:03 —-D—- C:\Program Files\AVG
2008-10-20 12:45:28 —-A—- C:\WINDOWS\system32\kbdkor.dll
2008-10-20 12:45:28 —-A—- C:\WINDOWS\system32\kbdjpn.dll
2008-10-20 12:45:28 —-A—- C:\WINDOWS\system32\kbd103.dll
2008-10-20 12:45:28 —-A—- C:\WINDOWS\system32\kbd101c.dll
2008-10-20 12:45:26 —-A—- C:\WINDOWS\system32\kbd101b.dll
2008-10-20 12:45:25 —-A—- C:\WINDOWS\system32\kbd106.dll
2008-10-18 03:00:29 —-HDC—- C:\WINDOWS\$NtUninstallKB951978$
2008-10-17 10:43:28 —-D—- C:\WINDOWS\Prefetch
2008-10-17 10:42:06 —-HDC—- C:\WINDOWS\$NtUninstallKB957095$
2008-10-17 10:42:01 —-HDC—- C:\WINDOWS\$NtUninstallKB956841$
2008-10-17 10:41:56 —-HDC—- C:\WINDOWS\$NtUninstallKB956803$
2008-10-17 10:41:51 —-HDC—- C:\WINDOWS\$NtUninstallKB954211$
2008-10-17 10:41:46 —-HDC—- C:\WINDOWS\$NtUninstallKB952954$
2008-10-17 10:41:42 —-HDC—- C:\WINDOWS\$NtUninstallKB952287$
2008-10-17 10:41:38 —-HDC—- C:\WINDOWS\$NtUninstallKB951748$
2008-10-17 10:41:34 —-HDC—- C:\WINDOWS\$NtUninstallKB951698$
2008-10-17 10:41:30 —-HDC—- C:\WINDOWS\$NtUninstallKB951376-v2$
2008-10-17 10:41:24 —-HDC—- C:\WINDOWS\$NtUninstallKB951066$
2008-10-17 10:41:20 —-HDC—- C:\WINDOWS\$NtUninstallKB950974$
2008-10-17 10:41:16 —-HDC—- C:\WINDOWS\$NtUninstallKB950762$
2008-10-17 10:41:11 —-HDC—- C:\WINDOWS\$NtUninstallKB946648$
2008-10-17 10:41:08 —-HDC—- C:\WINDOWS\$NtUninstallKB938464$
2008-10-17 10:38:50 —-D—- C:\WINDOWS\system32\scripting
2008-10-17 10:38:50 —-D—- C:\WINDOWS\system32\en
2008-10-17 10:38:50 —-D—- C:\WINDOWS\l2schemas
2008-10-17 10:38:49 —-D—- C:\WINDOWS\system32\bits
2008-10-17 10:37:29 —-D—- C:\WINDOWS\ServicePackFiles
2008-10-17 10:33:10 —-HDC—- C:\WINDOWS\$NtServicePackUninstall$
2008-10-17 10:33:09 —-D—- C:\WINDOWS\EHome
2008-10-14 19:45:31 —-HDC—- C:\WINDOWS\$NtUninstallKB956803_0$
2008-10-14 19:45:27 —-HDC—- C:\WINDOWS\$NtUninstallKB956391$
2008-10-14 19:45:23 —-HDC—- C:\WINDOWS\$NtUninstallKB957095_0$
2008-10-14 19:45:01 —-HDC—- C:\WINDOWS\$NtUninstallKB954211_0$
2008-10-14 19:44:52 —-HDC—- C:\WINDOWS\$NtUninstallKB956841_0$
2008-09-29 03:01:32 —-D—- C:\Documents and Settings\User\Application Data\ArcSoft
2008-09-29 02:58:07 —-A—- C:\WINDOWS\PB_setup.ini
2008-09-29 02:57:05 —-D—- C:\Program Files\ArcSoft
2008-09-29 02:57:05 —-A—- C:\WINDOWS\PI_setup.ini
2008-09-29 02:57:05 —-A—- C:\WINDOWS\pcdlib32.dll
2008-09-29 02:32:22 —-A—- C:\WINDOWS\Active Setup Log.txt
2008-09-29 02:16:36 —-D—- C:\Documents and Settings\User\Application Data\Help
2008-09-29 02:09:56 —-A—- C:\WINDOWS\Ulead32.ini
2008-09-29 02:09:54 —-D—- C:\Program Files\Ulead Systems
2008-09-29 02:08:18 —-A—- C:\WINDOWS\system32\MKCoInstaller.dll
2008-09-29 02:06:47 —-D—- C:\Program Files\DV Series
2008-09-28 18:18:10 —-D—- C:\Documents and Settings\User\Application Data\Motive

======List of files/folders modified in the last 1 months======

2008-10-25 01:44:13 —-RD—- C:\Program Files
2008-10-25 01:23:10 —-SHD—- C:\WINDOWS\Installer
2008-10-25 01:22:27 —-D—- C:\Program Files\Java
2008-10-25 01:22:26 —-D—- C:\Program Files\Common Files
2008-10-25 01:22:18 —-D—- C:\WINDOWS\system32
2008-10-25 01:17:31 —-D—- C:\WINDOWS\Temp
2008-10-25 01:16:54 —-A—- C:\WINDOWS\SchedLgU.Txt
2008-10-25 01:05:40 —-SD—- C:\WINDOWS\Downloaded Program Files
2008-10-24 23:14:40 —-D—- C:\WINDOWS\system32\drivers
2008-10-24 11:57:18 —-D—- C:\WINDOWS
2008-10-24 10:10:00 —-HD—- C:\WINDOWS\inf
2008-10-24 10:09:58 —-RSHDC—- C:\WINDOWS\system32\dllcache
2008-10-24 10:09:35 —-HD—- C:\WINDOWS\$hf_mig$
2008-10-24 10:09:34 —-D—- C:\WINDOWS\system32\CatRoot2
2008-10-24 07:19:07 —-SD—- C:\Documents and Settings\User\Application Data\Microsoft
2008-10-24 07:18:23 —-D—- C:\Documents and Settings\User\Application Data\SUPERAntiSpyware.com
2008-10-24 07:18:19 —-D—- C:\Program Files\SUPERAntiSpyware
2008-10-24 07:17:59 —-D—- C:\Program Files\SpywareBlaster
2008-10-23 20:09:57 —-D—- C:\Program Files\vol_toolbar
2008-10-20 12:45:35 —-D—- C:\WINDOWS\Help
2008-10-20 12:45:31 —-RSD—- C:\WINDOWS\Fonts
2008-10-20 03:10:00 —-A—- C:\WINDOWS\win.ini
2008-10-18 03:00:33 —-A—- C:\WINDOWS\imsins.BAK
2008-10-17 10:45:01 —-A—- C:\WINDOWS\system32\PerfStringBackup.INI
2008-10-17 10:43:51 —-A—- C:\WINDOWS\OEWABLog.txt
2008-10-17 10:43:31 —-A—- C:\WINDOWS\setuplog.txt
2008-10-17 10:43:01 —-D—- C:\WINDOWS\system32\Setup
2008-10-17 10:43:01 —-D—- C:\WINDOWS\AppPatch
2008-10-17 10:43:01 —-D—- C:\Program Files\Messenger
2008-10-17 10:43:00 —-D—- C:\WINDOWS\system32\wbem
2008-10-17 10:42:28 —-D—- C:\WINDOWS\security
2008-10-17 10:42:07 —-D—- C:\WINDOWS\system32\CatRoot
2008-10-17 10:39:05 —-D—- C:\WINDOWS\WinSxS
2008-10-17 10:38:59 —-D—- C:\WINDOWS\network diagnostic
2008-10-17 10:38:59 —-D—- C:\WINDOWS\ime
2008-10-17 10:38:51 —-D—- C:\WINDOWS\system32\usmt
2008-10-17 10:38:51 —-D—- C:\WINDOWS\system32\en-US
2008-10-17 10:38:49 —-D—- C:\WINDOWS\PeerNet
2008-10-17 10:38:49 —-D—- C:\Program Files\Movie Maker
2008-10-17 10:37:26 —-D—- C:\WINDOWS\system32\Restore
2008-10-17 10:37:26 —-D—- C:\WINDOWS\system32\npp
2008-10-17 10:37:25 —-D—- C:\WINDOWS\msagent
2008-10-17 10:37:24 —-D—- C:\WINDOWS\srchasst
2008-10-17 10:37:24 —-D—- C:\Program Files\NetMeeting
2008-10-17 10:37:23 —-D—- C:\WINDOWS\system32\Com
2008-10-17 10:37:21 —-D—- C:\Program Files\Windows NT
2008-10-17 10:37:21 —-D—- C:\Program Files\Windows Media Player
2008-10-17 10:37:21 —-D—- C:\Program Files\Outlook Express
2008-10-17 10:37:18 —-D—- C:\Program Files\Common Files\System
2008-10-17 10:37:05 —-D—- C:\WINDOWS\system32\oobe
2008-10-17 10:37:04 —-D—- C:\WINDOWS\system
2008-10-15 12:34:24 —-A—- C:\WINDOWS\system32\netapi32.dll
2008-10-14 19:45:15 —-D—- C:\Program Files\Internet Explorer
2008-10-07 12:19:42 —-A—- C:\WINDOWS\system32\MRT.exe
2008-10-03 13:41:15 —-A—- C:\WINDOWS\system32\ieframe.dll
2008-09-29 18:06:06 —-D—- C:\Program Files\Verizon
2008-09-29 02:58:06 —-HD—- C:\Program Files\InstallShield Installation Information
2008-09-29 02:57:39 —-D—- C:\WINDOWS\twain_32
2008-09-28 18:06:38 —-D—- C:\Documents and Settings\All Users\Application Data\Motive

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AmdK8;AMD Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-07-02 36864]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-04 12032]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2004-08-03 11868]
R2 tifsfilter;Acronis True Image FS Filter; C:\WINDOWS\system32\DRIVERS\tifsfilt.sys [2008-01-12 39264]
R3 FET5X86V;VIA Rhine-Family Fast-Ethernet Adapter Driver Service; C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [2007-04-16 42496]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HSF_DP;HSF_DP; C:\WINDOWS\system32\DRIVERS\HSFDPSP2.sys [2004-08-03 1041536]
R3 HSFHWBS2;HSFHWBS2; C:\WINDOWS\system32\DRIVERS\HSFBS2S2.sys [2004-08-03 220032]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-08-10 4603904]
R3 S3GIGP;S3GIGP; C:\WINDOWS\system32\DRIVERS\S3gIGPm.sys [2006-11-09 634880]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSFCXTS2.sys [2004-08-03 685056]
S1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
S1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
S1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys []
S3 ADSFilter;ADSFilter - (Aluria Filter Driver); C:\WINDOWS\system32\DRIVERS\ADSFilter.sys []
S3 BFAIFILT;BFAIFILT; C:\WINDOWS\System32\Drivers\bfaifilt.sys [2004-07-13 3264]
S3 BW2NDIS5;BW2NDIS5; C:\WINDOWS\System32\Drivers\BW2NDIS5.sys []
S3 dot4;MS IEEE-1284.4 Driver; C:\WINDOWS\system32\DRIVERS\Dot4.sys [2008-04-13 206976]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\WINDOWS\system32\DRIVERS\Dot4Prt.sys [2001-08-17 12928]
S3 Dot4Scan;Scan Class Driver for IEEE-1284.4; C:\WINDOWS\system32\DRIVERS\Dot4Scan.sys [2001-08-17 8704]
S3 dot4usb;Dot4USB Filter Dot4USB Filter; C:\WINDOWS\system32\DRIVERS\dot4usb.sys [2001-08-17 23808]
S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\fetnd5.sys [2001-08-17 27165]
S3 GMSIPCI;GMSIPCI; \??\D:\INSTALL\GMSIPCI.SYS []
S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 MREMPR5;MREMPR5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS []
S3 MRENDIS5;MRENDIS5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS []
S3 MRV6X32P;Vista 32-bits Native WiFi Driver; C:\WINDOWS\system32\DRIVERS\MRVW13B.sys [2006-11-02 253952]
S3 SASENUM;SASENUM; \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS []
S3 U2KG54;BUFFALO WLI-U2-KG54 Wireless LAN Adapter Service; C:\WINDOWS\system32\DRIVERS\U2KG54.sys [2005-10-17 245376]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 W8335XP;802.11g/b Driver for Windows XP (8335); C:\WINDOWS\system32\DRIVERS\Mrvw125.sys [2005-12-29 282624]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AcrSch2Svc;Acronis Scheduler2 Service; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe [2006-10-16 230944]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2008-10-25 152984]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-04-13 792112]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
S4 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-05-08 271920]

—————–EOF—————–


ok…that's it…. i think i got one of them twice.
compudodo,

  • Click Start, then Settings, then click Control Panel.
  • In Control Panel, double-click Add or Remove Programs.
  • In Add or Remove Programs, Remove Hijackthis 1.99.1.

Please download the OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    SASDIFSV
    SASKUTIL
    ADSFilter
    BW2NDIS5
    GMSIPCI
    SASENUM
    
    :Reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4E7BD74F-2B8D-469E-8CB0-AB60BB9AAE22}]
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2c203ae0-c126-11dc-9e32-001d92410860}]
    
    :Files
    C:\WINDOWS\system32\CF11254.exe
    C:\WINDOWS\system32\CF11087.exe
    C:\WINDOWS\system32\CF10781.exe
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

Also, please provide a new RSIT report (there will only be one this time)
oh my gawd…why don't i just get an engineering degree from MIT or apply for a chair at Harvard U???? Do you really think I can do all of that? I am going to make a total hash of this next round of commands. Are you in real time, real life an interrogator at Abu Graib or Guantanamo??? can you give me an idea when this torture is going to end? Oh gawd….. if you only knew how difficult this all is for me. ok…let's try to figure this out….. will probably take half the day: (what has really been fun is the fact that never once does this computer ask me to download anything to my desktop….. maybe your computer will download things and ask you if you want to put them on your desktop…but mine doesn't give me that option…it just downloads it and then have to find it) ========== PROCESSES ========== Process explorer.exe killed successfully. ========== SERVICES/DRIVERS ========== Service SASDIFSV stopped successfully. Service SASDIFSV deleted successfully. Service SASKUTIL stopped successfully. Service SASKUTIL deleted successfully. Service ADSFilter stopped successfully. Service ADSFilter deleted successfully. Service BW2NDIS5 stopped successfully. Service BW2NDIS5 deleted successfully. Service GMSIPCI stopped successfully. Service GMSIPCI deleted successfully. Service SASENUM stopped successfully. Service SASENUM deleted successfully. ========== REGISTRY ========== Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4E7BD74F-2B8D-469E-8CB0-AB60BB9AAE22}\\ deleted successfully. Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2c203ae0-c126-11dc-9e32-001d92410860}\\ deleted successfully. ========== FILES ========== C:\WINDOWS\system32\CF11254.exe moved successfully. C:\WINDOWS\system32\CF11087.exe moved successfully. C:\WINDOWS\system32\CF10781.exe moved successfully. ========== COMMANDS ========== User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_224.dat scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. Temp folders emptied. Explorer started successfully OTMoveIt3 by OldTimer - Version 1.0.5.0 log created on 10252008_170346 ok…i'm rebooting now
========== PROCESSES ========== Process explorer.exe killed successfully. ========== SERVICES/DRIVERS ========== Service SASDIFSV stopped successfully. Service SASDIFSV deleted successfully. Service SASKUTIL stopped successfully. Service SASKUTIL deleted successfully. Service ADSFilter stopped successfully. Service ADSFilter deleted successfully. Service BW2NDIS5 stopped successfully. Service BW2NDIS5 deleted successfully. Service GMSIPCI stopped successfully. Service GMSIPCI deleted successfully. Service SASENUM stopped successfully. Service SASENUM deleted successfully. ========== REGISTRY ========== Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4E7BD74F-2B8D-469E-8CB0-AB60BB9AAE22}\\ deleted successfully. Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2c203ae0-c126-11dc-9e32-001d92410860}\\ deleted successfully. ========== FILES ========== C:\WINDOWS\system32\CF11254.exe moved successfully. C:\WINDOWS\system32\CF11087.exe moved successfully. C:\WINDOWS\system32\CF10781.exe moved successfully. ========== COMMANDS ========== User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_224.dat scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. Temp folders emptied. Explorer started successfully OTMoveIt3 by OldTimer - Version 1.0.5.0 log created on 10252008_170346 Files moved on Reboot… File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot. File C:\WINDOWS\temp\Perflib_Perfdata_224.dat not found!
compudodo,

why don't i just get an engineering degree from MIT or apply for a chair at Harvard U????

Looks like you already have one. You did perfect.

Are you in real time, real life an interrogator at Abu Graib or Guantanamo??

Not any more. Got fired. Enjoyed my work to much. :rofl:

can you give me an idea when this torture is going to end?

Yep. I want to try Combofix again to be sure everything is ok. If we can't get it to work, we will clean up and I'll let you go.

First though, here is how you download to the desktop. This is important in order to get Combofix to work correctly.

  • Click on the download link
  • A window should open that asks if you want to run or save the file. Click save.
  • A new window should open that says Save As in the upper left corner.
  • Toward the top of this window it should say Save In with a window to the right.
  • On the right side of that window there should be a little arrow pointing down. Click on that arrow.
  • A drop down window should open. The first or second item on the list should be Desktop. Click on Desktop
  • Click on Save in the lower right.
  • You've done it. You've saved the file to the desktop. :thumbup:

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://www.bleepingcomputer.com/forums/topic114351.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
ok…. clicked on save…. box came up…. there was a little arrow all the way to the right like you said, next to a blue box with little different colored dots in it… when i clicked on the arrow, all it said was thumbnails, tiles, icons, list, details….no desktop… a black dot was next to list.
compudodo,

My fault. I wasn't clear with the instructions.

There is a white box immediately to the right of the words Save in: that has a folder name in it. It maybe says My documents or Recent document. There is a little arrow pointing down on the right edge of that white box. Then there are some icons and then the arrow you pushed.
You want to click the first one, the one on the right edge of the white box.
ahhhhhhhhhhhhhhhhhhhhh…ok….there wasn't any arrow there either…………………. but GUESS WHAT??????? there was a box that said Recent documents… and right underneath it, in big ole honking letters it said DESKTOP!!!!! GUESS WHAT? ???????? THE BRAIN CELLS FINALLY KICKED IN AND I CLICKED ON THAT!!!! AND IT WORKED!!!! WHOOO-HOOOO!!! EINSTEIN AIN'T GOT NUTTIN' OVER ME!!!! OK, now that I totally feel like I have half a brain left…here is the log from the combo fix: ComboFix 08-10-24.02 - User 2008-10-25 21:55:48.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.615 [GMT -4:00] Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe * Created a new restore point . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\xcrashdump.dat . ((((((((((((((((((((((((( Files Created from 2008-09-26 to 2008-10-26 ))))))))))))))))))))))))))))))) . 2008-10-25 17:03 . 2008-10-25 17:03 d——– C:\_OTMoveIt 2008-10-25 01:44 . 2008-10-25 01:57 d——– C:\rsit 2008-10-25 01:44 . 2008-10-25 01:44 d——– C:\Program Files\trend micro 2008-10-25 01:08 . 2008-10-25 01:08 410,976 –a—— C:\WINDOWS\system32\deploytk.dll 2008-10-24 23:14 . 2008-10-24 23:14 d——– C:\Program Files\Malwarebytes' Anti-Malware 2008-10-24 23:14 . 2008-10-24 23:14 d——– C:\Documents and Settings\User\Application Data\Malwarebytes 2008-10-24 23:14 . 2008-10-24 23:14 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes 2008-10-24 23:14 . 2008-10-22 16:10 38,496 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys 2008-10-24 23:14 . 2008-10-22 16:10 15,504 –a—— C:\WINDOWS\system32\drivers\mbam.sys 2008-10-24 07:19 . 2008-10-24 07:19 d——– C:\Documents and Settings\All Users\Application Data\Avg8 2008-10-24 07:01 . 2008-10-15 12:34 337,408 —–c— C:\WINDOWS\system32\dllcache\netapi32.dll 2008-10-23 21:59 . 2008-10-23 22:06 d——– C:\Documents and Settings\User\.SunDownloadManager 2008-10-23 20:05 . 2008-10-23 20:05 d——– C:\Program Files\AVG 2008-10-20 12:45 . 2001-08-17 22:36 8,704 –a—— C:\WINDOWS\system32\kbdjpn.dll 2008-10-20 12:45 . 2001-08-17 22:36 8,704 –a–c— C:\WINDOWS\system32\dllcache\kbdjpn.dll 2008-10-20 12:45 . 2001-08-17 22:36 8,192 –a—— C:\WINDOWS\system32\kbdkor.dll 2008-10-20 12:45 . 2001-08-17 22:36 8,192 –a–c— C:\WINDOWS\system32\dllcache\kbdkor.dll 2008-10-20 12:45 . 2008-04-13 20:09 6,144 –a—— C:\WINDOWS\system32\kbd106.dll 2008-10-20 12:45 . 2001-08-17 14:55 6,144 –a—— C:\WINDOWS\system32\kbd101c.dll 2008-10-20 12:45 . 2001-08-17 14:55 6,144 –a—— C:\WINDOWS\system32\kbd101b.dll 2008-10-20 12:45 . 2008-04-13 20:09 6,144 –a–c— C:\WINDOWS\system32\dllcache\kbd106.dll 2008-10-20 12:45 . 2001-08-17 14:55 6,144 –a–c— C:\WINDOWS\system32\dllcache\kbd101c.dll 2008-10-20 12:45 . 2001-08-17 14:55 6,144 –a–c— C:\WINDOWS\system32\dllcache\kbd101b.dll 2008-10-20 12:45 . 2001-08-17 14:55 5,632 –a—— C:\WINDOWS\system32\kbd103.dll 2008-10-20 12:45 . 2001-08-17 14:55 5,632 –a–c— C:\WINDOWS\system32\dllcache\kbd103.dll 2008-10-17 10:38 . 2008-10-17 10:38 d——– C:\WINDOWS\system32\scripting 2008-10-17 10:38 . 2008-10-17 10:38 d——– C:\WINDOWS\system32\en 2008-10-17 10:38 . 2008-10-17 10:38 d——– C:\WINDOWS\system32\bits 2008-10-17 10:38 . 2008-10-17 10:38 d——– C:\WINDOWS\l2schemas 2008-10-17 10:37 . 2008-10-17 10:37 d——– C:\WINDOWS\ServicePackFiles 2008-10-17 10:33 . 2008-10-17 10:33 d——– C:\WINDOWS\EHome 2008-10-14 17:38 . 2008-09-15 08:12 1,846,400 —–c— C:\WINDOWS\system32\dllcache\win32k.sys 2008-10-14 17:38 . 2008-09-08 06:41 333,824 —–c— C:\WINDOWS\system32\dllcache\srv.sys 2008-10-14 17:37 . 2008-08-14 06:11 2,189,184 —–c— C:\WINDOWS\system32\dllcache\ntoskrnl.exe 2008-10-14 17:37 . 2008-08-14 06:09 2,145,280 —–c— C:\WINDOWS\system32\dllcache\ntkrnlmp.exe 2008-10-14 17:37 . 2008-08-14 05:33 2,066,048 —–c— C:\WINDOWS\system32\dllcache\ntkrnlpa.exe 2008-10-14 17:37 . 2008-08-14 05:33 2,023,936 —–c— C:\WINDOWS\system32\dllcache\ntkrpamp.exe 2008-09-29 03:01 . 2008-09-29 03:01 d——– C:\Documents and Settings\User\Application Data\ArcSoft 2008-09-29 02:58 . 2001-06-19 19:38 21 –a—— C:\WINDOWS\PB_setup.ini 2008-09-29 02:57 . 2008-09-29 02:58 d——– C:\Program Files\ArcSoft 2008-09-29 02:57 . 1999-05-26 09:46 212,480 –a—— C:\WINDOWS\pcdlib32.dll 2008-09-29 02:57 . 2001-06-20 11:09 21 –a—— C:\WINDOWS\PI_setup.ini 2008-09-29 02:56 . 2008-09-29 02:56 d——– C:\WINDOWS\system\IOSUBSYS 2008-09-29 02:56 . 2002-09-12 15:34 20,020 –a—— C:\WINDOWS\system32\drivers\UMSS.sys 2008-09-29 02:09 . 2008-09-29 02:09 d——– C:\Program Files\Ulead Systems 2008-09-29 02:09 . 1998-08-18 20:30 168,960 –a—— C:\WINDOWS\system32\Xcdzip35.ocx 2008-09-29 02:09 . 1998-08-18 20:30 109,578 –a—— C:\WINDOWS\system32\Xcdsfx32.bin 2008-09-29 02:09 . 1998-08-18 20:30 1,024 –a—— C:\WINDOWS\system32\Xcdzpsfx.lic 2008-09-29 02:09 . 1998-08-18 20:30 1,024 –a—— C:\WINDOWS\system32\Xcdzpocx.lic 2008-09-29 02:09 . 2008-09-29 02:48 328 –a—— C:\WINDOWS\Ulead32.ini 2008-09-29 02:06 . 2008-09-29 02:09 d——– C:\Program Files\DV Series 2008-09-28 18:18 . 2008-09-28 18:18 d——– C:\Documents and Settings\User\Application Data\Motive . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-10-25 05:22 ——— d—–w C:\Program Files\Java 2008-10-24 11:18 ——— d—–w C:\Program Files\SUPERAntiSpyware 2008-10-24 11:18 ——— d—–w C:\Documents and Settings\User\Application Data\SUPERAntiSpyware.com 2008-10-24 11:17 ——— d—–w C:\Program Files\SpywareBlaster 2008-10-24 00:09 ——— d—–w C:\Program Files\vol_toolbar Ok….. is this all you need??? Can you tell from any of this just when I got that nasty virus??? did it come thru that attachment from the real estate agent??? are we done yet??? :) cause now i want to know about these 2 error boxes that are popping up saying INCD - INCD helper service is not installed properly and the other box that says NBHGUI- with the same message
compudodo,

I'm sorry to be such a pain, but that is only the first half of the report. I need to see the whole thing.

Please:
  • Right click on START on the left end of your Windows toolbar (lower left corner of your screen)
  • Click on Explore
  • Click on Local Disk (C:) in the left-hand window pane
  • Look for ComboFix.txt in the right-hand window pane and right click on it
  • Put your cursor (arrow) on Open With
  • Move your cursor to the new menu that opens and click on Choose Program…
  • Click on Notepad

When file opens, Copy/Paste text here

The easiest way to reinstall AVG is to click here and redownload by clicking on the Get it Now button in the Free Basic Protection window. (We'll get to SpywareBlaster later)
i already went to avg and downloaded the free version…… tried downloading spyblaster, but whatever version i downloaded doesn't remove anything…so after about 20 different bogus websites, i finally got the correct website for adaware….downloaded it and it is running as we speak….. i'm just ticked my disc that had both programs on it isn't working. oh well…..

ok, i'll try to find the whole thing.

jeesh, this scan is taking forever….. why do i have 139,000 files in this computer??? how do i get rid of the ones i don't need???

it finished scanning…i had 100 spywares deleted. ok…i'm going to try to find the whole thing:

ComboFix 08-10-24.02 - User 2008-10-25 21:55:48.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.615 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\xcrashdump.dat

.
((((((((((((((((((((((((( Files Created from 2008-09-26 to 2008-10-26 )))))))))))))))))))))))))))))))
.

2008-10-25 17:03 . 2008-10-25 17:03 d——– C:\_OTMoveIt
2008-10-25 01:44 . 2008-10-25 01:57 d——– C:\rsit
2008-10-25 01:44 . 2008-10-25 01:44 d——– C:\Program Files\trend micro
2008-10-25 01:08 . 2008-10-25 01:08 410,976 –a—— C:\WINDOWS\system32\deploytk.dll
2008-10-24 23:14 . 2008-10-24 23:14 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-10-24 23:14 . 2008-10-24 23:14 d——– C:\Documents and Settings\User\Application Data\Malwarebytes
2008-10-24 23:14 . 2008-10-24 23:14 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-24 23:14 . 2008-10-22 16:10 38,496 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-24 23:14 . 2008-10-22 16:10 15,504 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-10-24 07:19 . 2008-10-24 07:19 d——– C:\Documents and Settings\All Users\Application Data\Avg8
2008-10-24 07:01 . 2008-10-15 12:34 337,408 —–c— C:\WINDOWS\system32\dllcache\netapi32.dll
2008-10-23 21:59 . 2008-10-23 22:06 d——– C:\Documents and Settings\User\.SunDownloadManager
2008-10-23 20:05 . 2008-10-23 20:05 d——– C:\Program Files\AVG
2008-10-20 12:45 . 2001-08-17 22:36 8,704 –a—— C:\WINDOWS\system32\kbdjpn.dll
2008-10-20 12:45 . 2001-08-17 22:36 8,704 –a–c— C:\WINDOWS\system32\dllcache\kbdjpn.dll
2008-10-20 12:45 . 2001-08-17 22:36 8,192 –a—— C:\WINDOWS\system32\kbdkor.dll
2008-10-20 12:45 . 2001-08-17 22:36 8,192 –a–c— C:\WINDOWS\system32\dllcache\kbdkor.dll
2008-10-20 12:45 . 2008-04-13 20:09 6,144 –a—— C:\WINDOWS\system32\kbd106.dll
2008-10-20 12:45 . 2001-08-17 14:55 6,144 –a—— C:\WINDOWS\system32\kbd101c.dll
2008-10-20 12:45 . 2001-08-17 14:55 6,144 –a—— C:\WINDOWS\system32\kbd101b.dll
2008-10-20 12:45 . 2008-04-13 20:09 6,144 –a–c— C:\WINDOWS\system32\dllcache\kbd106.dll
2008-10-20 12:45 . 2001-08-17 14:55 6,144 –a–c— C:\WINDOWS\system32\dllcache\kbd101c.dll
2008-10-20 12:45 . 2001-08-17 14:55 6,144 –a–c— C:\WINDOWS\system32\dllcache\kbd101b.dll
2008-10-20 12:45 . 2001-08-17 14:55 5,632 –a—— C:\WINDOWS\system32\kbd103.dll
2008-10-20 12:45 . 2001-08-17 14:55 5,632 –a–c— C:\WINDOWS\system32\dllcache\kbd103.dll
2008-10-17 10:38 . 2008-10-17 10:38 d——– C:\WINDOWS\system32\scripting
2008-10-17 10:38 . 2008-10-17 10:38 d——– C:\WINDOWS\system32\en
2008-10-17 10:38 . 2008-10-17 10:38 d——– C:\WINDOWS\system32\bits
2008-10-17 10:38 . 2008-10-17 10:38 d——– C:\WINDOWS\l2schemas
2008-10-17 10:37 . 2008-10-17 10:37 d——– C:\WINDOWS\ServicePackFiles
2008-10-17 10:33 . 2008-10-17 10:33 d——– C:\WINDOWS\EHome
2008-10-14 17:38 . 2008-09-15 08:12 1,846,400 —–c— C:\WINDOWS\system32\dllcache\win32k.sys
2008-10-14 17:38 . 2008-09-08 06:41 333,824 —–c— C:\WINDOWS\system32\dllcache\srv.sys
2008-10-14 17:37 . 2008-08-14 06:11 2,189,184 —–c— C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-10-14 17:37 . 2008-08-14 06:09 2,145,280 —–c— C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-10-14 17:37 . 2008-08-14 05:33 2,066,048 —–c— C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-10-14 17:37 . 2008-08-14 05:33 2,023,936 —–c— C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-09-29 03:01 . 2008-09-29 03:01 d——– C:\Documents and Settings\User\Application Data\ArcSoft
2008-09-29 02:58 . 2001-06-19 19:38 21 –a—— C:\WINDOWS\PB_setup.ini
2008-09-29 02:57 . 2008-09-29 02:58 d——– C:\Program Files\ArcSoft
2008-09-29 02:57 . 1999-05-26 09:46 212,480 –a—— C:\WINDOWS\pcdlib32.dll
2008-09-29 02:57 . 2001-06-20 11:09 21 –a—— C:\WINDOWS\PI_setup.ini
2008-09-29 02:56 . 2008-09-29 02:56 d——– C:\WINDOWS\system\IOSUBSYS
2008-09-29 02:56 . 2002-09-12 15:34 20,020 –a—— C:\WINDOWS\system32\drivers\UMSS.sys
2008-09-29 02:09 . 2008-09-29 02:09 d——– C:\Program Files\Ulead Systems
2008-09-29 02:09 . 1998-08-18 20:30 168,960 –a—— C:\WINDOWS\system32\Xcdzip35.ocx
2008-09-29 02:09 . 1998-08-18 20:30 109,578 –a—— C:\WINDOWS\system32\Xcdsfx32.bin
2008-09-29 02:09 . 1998-08-18 20:30 1,024 –a—— C:\WINDOWS\system32\Xcdzpsfx.lic
2008-09-29 02:09 . 1998-08-18 20:30 1,024 –a—— C:\WINDOWS\system32\Xcdzpocx.lic
2008-09-29 02:09 . 2008-09-29 02:48 328 –a—— C:\WINDOWS\Ulead32.ini
2008-09-29 02:06 . 2008-09-29 02:09 d——– C:\Program Files\DV Series
2008-09-28 18:18 . 2008-09-28 18:18 d——– C:\Documents and Settings\User\Application Data\Motive

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-25 05:22 ——— d—–w C:\Program Files\Java
2008-10-24 11:18 ——— d—–w C:\Program Files\SUPERAntiSpyware
2008-10-24 11:18 ——— d—–w C:\Documents and Settings\User\Application Data\SUPERAntiSpyware.com
2008-10-24 11:17 ——— d—–w C:\Program Files\SpywareBlaster
2008-10-24 00:09 ——— d—–w C:\Program Files\vol_toolbar
2008-09-29 22:06 ——— d—–w C:\Program Files\Verizon
2008-09-29 06:58 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-09-28 22:06 ——— d—–w C:\Documents and Settings\All Users\Application Data\Motive
2008-09-22 23:55 ——— d—–w C:\Documents and Settings\User\Application Data\vol_toolbar
2008-09-20 23:33 ——— d—–w C:\Documents and Settings\User\Application Data\Verizon
2008-09-20 23:33 ——— d—–w C:\Documents and Settings\All Users\Application Data\Verizon
2008-09-20 22:20 ——— d—–w C:\Program Files\Common Files\Motive
2008-09-20 22:13 ——— d—–w C:\Documents and Settings\All Users\Application Data\Verizon Games on Demand Player
2008-09-20 22:08 ——— d—–w C:\Program Files\StarzPlay
2008-09-20 21:57 ——— d—–w C:\Program Files\Common Files\SupportSoft
2008-09-20 20:39 ——— d—–w C:\Program Files\EarthLink TotalAccess
2008-09-20 20:34 2,560 —-a-w C:\WINDOWS\_MSRSTRT.EXE
2008-09-20 20:33 32,768 —-a-w C:\AluriaCacheFile.dat
2008-09-15 12:12 1,846,400 —-a-w C:\WINDOWS\system32\win32k.sys
2008-09-08 10:41 333,824 —-a-w C:\WINDOWS\system32\drivers\srv.sys
2008-08-26 07:24 826,368 —-a-w C:\WINDOWS\system32\wininet.dll
2008-08-14 10:09 2,145,280 —-a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 09:33 2,023,936 —-a-w C:\WINDOWS\system32\ntkrnlpa.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-04-13 1695232]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"SecurDisc"="C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe" [2007-05-15 1628208]
"InCD"="C:\Program Files\Nero\Nero 7\InCD\InCD.exe" [2007-05-15 1057328]
"TrueImageMonitor.exe"="C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2006-10-16 1164912]
"AcronisTimounterMonitor"="C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe" [2006-10-16 1941784]
"Acronis Scheduler2 Service"="C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe" [2006-10-16 87584]
"Verizon_McciTrayApp"="C:\Program Files\Verizon\McciTrayApp.exe" [2007-09-28 936960]
"VerizonServicepoint.exe"="C:\Program Files\Verizon\VSP\VerizonServicepoint.exe" [2008-02-13 2065648]
"SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" [2008-10-25 136600]
"VTTimer"="VTTimer.exe" [2006-09-21 C:\WINDOWS\system32\VTTimer.exe]
"S3Trayp"="S3trayp.exe" [2006-10-09 C:\WINDOWS\system32\S3Trayp.exe]
"RTHDCPL"="RTHDCPL.EXE" [2007-08-10 C:\WINDOWS\RTHDCPL.exe]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe [2008-01-08 114688]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2000-01-20 65588]
Microsoft Works Calendar Reminders.lnk - C:\WINDOWS\Installer\{0CD3BB5C-BBCA-11D2-8C20-00C04FBBCFF9}\A94AAB13.exe [2008-01-08 30720]
Watch.lnk - C:\Program Files\DV Series\Console\Watch.exe [2008-09-29 217088]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8097:TCP"= 8097:TCP:EarthLink UHP Modem Support

R0 videX32;videX32;C:\WINDOWS\system32\DRIVERS\videX32.sys [2006-10-17 9216]
R2 JavaQuickStarterService;Java Quick Starter;C:\Program Files\Java\jre6\bin\jqs.exe [2008-10-25 152984]
R3 FET5X86V;VIA Rhine-Family Fast-Ethernet Adapter Driver Service;C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [2007-04-16 42496]
R3 S3GIGP;S3GIGP;C:\WINDOWS\system32\DRIVERS\S3gIGPm.sys [2006-11-09 634880]
S3 BFAIFILT;BFAIFILT;C:\WINDOWS\system32\Drivers\bfaifilt.sys [2004-07-13 3264]
S3 MRV6X32P;Vista 32-bits Native WiFi Driver;C:\WINDOWS\system32\DRIVERS\MRVW13B.sys [2006-11-02 253952]
S3 U2KG54;BUFFALO WLI-U2-KG54 Wireless LAN Adapter Service;C:\WINDOWS\system32\DRIVERS\U2KG54.sys [2005-10-17 245376]
.
.
——- Supplementary Scan ——-
.
R1 -: HKCU-SearchURL,(Default) = hxxp://my.netzero.net/s/search?r=minisearch
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-25 21:58:03
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-10-25 21:59:29 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-26 01:59:26

Pre-Run: 70,254,170,112 bytes free
Post-Run: 70,241,316,864 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect /usepmtimer

166 — E O F — 2008-10-24 14:10:00
compudodo,

You did great. As far as I can tell you look clean. :D

I'm not able to tell if anything was related to the real estate letters. Sorry.

I'm not seeing any reason for the inCD problems. It is possible that you will have to reinstall it. :wacko:

Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK
  • Note the space between the X and the U, it needs to be there.
  • [external image: Posted Image]
The above procedure will:
  • Delete the following:
    • ComboFix and its associated files and folders.
    • VundoFix backups, if present
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Reset System Restore.

Please re-enable any security that was disabled.

Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
(Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
Without a firewall your computer is succeptible to being hacked and taken over.
I am very serious about this and see it happen almost every day with my clients.
Simply using a Firewall in its default configuration can lower your risk greatly.

For a tutorial on Firewalls and a listing of some available ones see the link below:

Understanding and Using Firewalls

Keep Microsoft Windows Updated - This will ensure your computer has always the latest security updates available installed on your computer. The easiest way to do this is to turn on Automatic Updates. Do this by:
  • From your desktop, right-click on My Computer,
  • click on Properties
  • Select the Automatic Updates tab
  • Click on Automatic
  • Click on Apply button
  • Click on OK to exit.
If there are new updates to install, install them immediately, until there are no more critical updates.

Install SpywareBlaster - SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.

A tutorial on installing & using this product can be found here:

Using SpywareBlaster to protect your computer from Spyware and Malware

Download and install the free version of WinPatrol - This program protects your computer in a variety of ways and will work well with your existing security software.
Winpatrol


Update all these programs regularly - Make sure you update all the programs I have listed regularly.
Without regular updates you WILL NOT be protected when new malicious programs are released.


Only run one Anti-Virus and Firewall program.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein

Also: "How to prevent malware"
by miekiemoes

I would further suggest that you also read this tutorial on slow running computers.

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:
well, i have avg back on the machine…. i installed that win thingy too….i don't understand why the spyblaster program has no button to push for a scan and i have no idea why i would uninstall that INCD…. how would I get it back??? I turned back on the windows firewall….. i also clicked on yes for a bunch of activex controls with spyblaster that i do not understand…. i know sometime in the next month or so, some window will pop up asking me if i want to allow something, and i'll check the wrong option, sending my computer to that region known as 'let's make life miserable for the computer idiots out there"…. i still have that malwarebytes program on my desktop…should i just leave it there, cause gawd knows i'll be back soon??? thanks for this three day marathon of fun fun fun Tom….. there must be a special place in heaven for wonderful people like you…. I know i am supposed to have all this stuff on my computer….i forget why i turned it all off, something was interfering with something else..that's usually why i do stuff….. i have no clue with the boxes that pop up, asking me if i want to do this or that…that is why i just unstall everything…and then just re-install it. i'm really totally clueless. ….. maybe the disc that the kid sent me with the avg/spyblaster was only good for a certain amount of downloads????? the version i have now is not the version of spyblaster i had….there is definitely no way to scan….. i just don't get it. oh well…. let me know if you have any idea how i am supposed to uninstall that INCD and where I go to find another one?? oh…also, now i have to type in my user name and passwords every place i usually go…is there someplace to go to in the computer that let's it remember those??? i just find it a pain in the neck to have to type all that junk every time i want to get onto a website. again….thanks for the hard work….. I'll try to read all the other stuff….and that page about turning things off…i tried the first time, but i just didn't get it.
compudodo,

SpywareBlaster doesn't have a scan button. Could you be thinking of SuperAntiSpyware?


i still have that malwarebytes program on my desktop…should i just leave it there

Yes. It's a good program to run every once in awhile. When you start it, there is a tab to update it. It's free and won't interfere with anything else you have running.

InCD is part of Nero. Do you have a Nero disc?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI