This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

I think something is wrong

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:45:57 PM, on 12/1/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: 124909 helper - {51FC8C8A-A290-44BB-9331-C2D3289976A6} - (no file)
O2 - BHO: (no name) - {716FCFD2-1417-42C9-B802-188DA57A8195} - (no file)
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {C5BF49A2-94F3-42BD-F434-3604812C897D} - (no file)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
O8 - Extra context menu item: Send to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/betapit/PCPitStop.CAB
O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC Class) - http://www.pcpitstop.com/internet/pcpConnCheck.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.7.109.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1203904463796
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1203900267250
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/optimize2/pcpitstop2.dll
O20 - Winlogon Notify: jkklMCss - jkklMCss.dll (file missing)
O20 - Winlogon Notify: winowl32 - winowl32.dll (file missing)
O22 - SharedTaskScheduler: mcb7uehuj3n8weuhejsw - {C5BF49A2-94F3-42BD-F434-3604812C897D} - (no file)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Unknown owner - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe (file missing)

–
End of file - 6659 bytes


Ok, sorry, I fixed the regedit problem. Something isn't right though. Thanks for the help.
Hi BigSteve-E-.

My name is revel and I will be working with you to resolve the issues you're experiencing.

As I am still in training, all of my instructions must be checked by one of our malware experts before they are given to you. Thus, there may be some delay in responding. I know that you would like your computer working as quickly as possible and I will work hard to see that happen.

Before we begin, please review these important notes:
  • The fixes are specific to your machine and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you that your machine is clean. Absence of symptoms does not mean that everything is clear.
  • If you don't understand the instructions, please stop and ask for clarification before proceeding.
  • Continue to reply to this topic; do not start another.

I will be back as soon as possible with instructions.
Hi BigSteve-E-
Are you still unable to install an antivirus? It's important that you have one installed.

Please do the following:

Download random's system information tool (RSIT) by random/random from >> HERE << and save it to your desktop.
  • Double click on RSIT.exe to run the program.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (will be maximized) and info.txt (will be minimized)

In your next reply, please copy/paste:
  • RSIT logs (log.txt and info.txt)
It finally installed actually after several restarts. I guess all I need now is to make sure my box is clean.
Logfile of random's system information tool 1.04 (written by random/random)
Run by [removed] at 2008-12-03 22:47:57
Microsoft Windows XP Professional Service Pack 3
System drive C: has 10 GB (29%) free of 35 GB
Total RAM: 2047 MB (79% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:48:06 PM, on 12/3/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AT&T;\AT&T; Internet Security Suite\Fws.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\AT&T;\Internet Security Wizard\ISW.exe
C:\Program Files\AT&T;\AT&T; Internet Security Suite\Rps.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
C:\Program Files\AT&T;\Internet Security Wizard\ISWComHandler.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AT&T;\AT&T; Internet Security Suite\rpsupdaterR.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Xfire\xfire.exe
C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\theone\Local Settings\Temporary Internet Files\Content.IE5\12X3VLV7\RSIT[1].exe
C:\Program Files\Trend Micro\HijackThis\theone.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\AT&T;\AT&T; Internet Security Suite\pkR.dll
O2 - BHO: 124909 helper - {51FC8C8A-A290-44BB-9331-C2D3289976A6} - (no file)
O2 - BHO: (no name) - {716FCFD2-1417-42C9-B802-188DA57A8195} - (no file)
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {C5BF49A2-94F3-42BD-F434-3604812C897D} - (no file)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [ISW.exe] "C:\Program Files\AT&T;\Internet Security Wizard\ISW.exe" /AUTORUN
O4 - HKLM\..\Run: [AT&T; Internet Security Suite] "C:\Program Files\AT&T;\AT&T; Internet Security Suite\Rps.exe"
O4 - HKLM\..\Run: [-FreedomNeedsReboot] "C:\Program Files\AT&T;\AT&T; Internet Security Suite\ZkRunOnceR.exe"
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
O8 - Extra context menu item: Send to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/betapit/PCPitStop.CAB
O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC Class) - http://www.pcpitstop.com/internet/pcpConnCheck.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.7.109.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1203904463796
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1203900267250
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/optimize2/pcpitstop2.dll
O20 - Winlogon Notify: jkklMCss - jkklMCss.dll (file missing)
O20 - Winlogon Notify: winowl32 - winowl32.dll (file missing)
O22 - SharedTaskScheduler: mcb7uehuj3n8weuhejsw - {C5BF49A2-94F3-42BD-F434-3604812C897D} - (no file)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Unknown owner - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe (file missing)
O23 - Service: AT&T; Internet Security Suite Service (RPSUpdaterR) - Radialpoint Inc. - C:\Program Files\AT&T;\AT&T; Internet Security Suite\rpsupdaterR.exe
O23 - Service: AT&T; Internet Security Suite AT&T; Firewall (RP_FWS) - AT&T; - C:\Program Files\AT&T;\AT&T; Internet Security Suite\Fws.exe

–
End of file - 8523 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\nyotmrqu.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3C060EA2-E6A9-4E49-A530-D4657B8C449A}]
PopKill Class - C:\Program Files\AT&T;\AT&T; Internet Security Suite\pkR.dll [2007-06-28 55024]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{51FC8C8A-A290-44BB-9331-C2D3289976A6}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{716FCFD2-1417-42C9-B802-188DA57A8195}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java™ Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2008-11-20 320920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C5BF49A2-94F3-42BD-F434-3604812C897D}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-11-20 34816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2008-11-20 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google; - c:\program files\google\googletoolbar2.dll [2008-10-19 2549368]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SBDrvDet"=C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe [2002-12-03 45056]
"UpdReg"=C:\WINDOWS\UpdReg.EXE [2000-05-11 90112]
"CTHelper"=C:\WINDOWS\system32\CTHELPER.EXE [2007-04-09 19456]
"Kernel and Hardware Abstraction Layer"=C:\WINDOWS\KHALMNPR.EXE [2008-02-29 76304]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2008-10-01 289576]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2008-09-06 413696]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2008-11-20 136600]
"ISW.exe"=C:\Program Files\AT&T;\Internet Security Wizard\ISW.exe [2007-05-03 2061816]
"AT&T; Internet Security Suite"=C:\Program Files\AT&T;\AT&T; Internet Security Suite\Rps.exe [2007-06-28 310000]
"-FreedomNeedsReboot"=C:\Program Files\AT&T;\AT&T; Internet Security Suite\ZkRunOnceR.exe [2007-06-28 13552]
"UnlockerAssistant"=C:\Program Files\Unlocker\UnlockerAssistant.exe []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]

C:\Documents and Settings\theone\Start Menu\Programs\Startup
Picture Motion Browser Media Check Tool.lnk - C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2008-01-22 122880]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\jkklMCss]
jkklMCss.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2008-09-05 241704]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winowl32]
winowl32.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
mcb7uehuj3n8weuhejsw - {C5BF49A2-94F3-42BD-F434-3604812C897D}

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{E9681C1C-C1DF-4970-97BB-86C3E716AFA3}"= []

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
C:\WINDOWS\system32\iifGxvVO
"notification packages"=
scecli
scecli
scecli

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoFolderOptions"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Xfire\xfire.exe"="C:\Program Files\Xfire\xfire.exe:*:Enabled:Xfire"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\EA GAMES\Battlefield 2\BF2.exe"="C:\Program Files\EA GAMES\Battlefield 2\BF2.exe:*:Enabled:Battlefield 2"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\Program Files\Ares\Ares.exe"="C:\Program Files\Ares\Ares.exe:*:Enabled:Ares p2p for windows"
"C:\Program Files\Internet Explorer\iexplore.exe"="C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\Program Files\Yahoo!\Messenger\YServer.exe"="C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe"="C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:*:Enabled:Call of Duty® 4 - Modern Warfare™ "

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{66810a38-e332-11dc-8e68-806d6172696f}]
shell\AutoRun\command - D:\Autorun.exe


======List of files/folders created in the last 1 months======

2008-12-03 22:47:57 —-D—- C:\rsit
2008-12-03 16:26:40 —-D—- C:\WINDOWS\LastGood
2008-12-02 00:45:02 —-D—- C:\Documents and Settings\All Users\Application Data\SecTaskMan
2008-12-01 23:08:18 —-D—- C:\Program Files\Unlocker
2008-12-01 20:15:23 —-D—- C:\Program Files\Raxco
2008-12-01 20:15:23 —-D—- C:\Documents and Settings\All Users\Application Data\Raxco
2008-12-01 20:11:07 —-D—- C:\Program Files\Common Files\Authentium
2008-12-01 20:10:59 —-D—- C:\Program Files\Common Files\Scanner
2008-12-01 20:10:13 —-D—- C:\Program Files\AT&T;
2008-12-01 19:45:46 —-D—- C:\Program Files\Trend Micro
2008-12-01 19:22:34 —-D—- C:\Documents and Settings\All Users\Application Data\Avg8
2008-11-23 17:38:07 —-D—- C:\WINDOWS\Prefetch
2008-11-23 17:35:06 —-HDC—- C:\WINDOWS\$NtUninstallKB958644$
2008-11-23 17:34:32 —-HDC—- C:\WINDOWS\$NtUninstallKB957097$
2008-11-23 17:33:57 —-HDC—- C:\WINDOWS\$NtUninstallKB957095$
2008-11-23 17:33:26 —-HDC—- C:\WINDOWS\$NtUninstallKB956841$
2008-11-23 17:32:57 —-HDC—- C:\WINDOWS\$NtUninstallKB956803$
2008-11-23 17:32:27 —-HDC—- C:\WINDOWS\$NtUninstallKB955069$
2008-11-23 17:31:57 —-HDC—- C:\WINDOWS\$NtUninstallKB954211$
2008-11-23 17:31:28 —-HDC—- C:\WINDOWS\$NtUninstallKB952954$
2008-11-23 17:31:00 —-HDC—- C:\WINDOWS\$NtUninstallKB952287$
2008-11-23 17:30:29 —-HDC—- C:\WINDOWS\$NtUninstallKB951748$
2008-11-23 17:30:00 —-HDC—- C:\WINDOWS\$NtUninstallKB951698$
2008-11-23 17:29:33 —-HDC—- C:\WINDOWS\$NtUninstallKB951376-v2$
2008-11-23 17:29:04 —-HDC—- C:\WINDOWS\$NtUninstallKB951066$
2008-11-23 17:28:37 —-HDC—- C:\WINDOWS\$NtUninstallKB950974$
2008-11-23 17:28:10 —-HDC—- C:\WINDOWS\$NtUninstallKB950762$
2008-11-23 17:27:43 —-HDC—- C:\WINDOWS\$NtUninstallKB946648$
2008-11-23 17:27:17 —-HDC—- C:\WINDOWS\$NtUninstallKB938464$
2008-11-23 17:13:17 —-HDC—- C:\WINDOWS\$NtServicePackUninstall$
2008-11-23 17:01:20 —-N—- C:\WINDOWS\system32\wlanapi.dll
2008-11-23 17:01:16 —-N—- C:\WINDOWS\system32\tspkg.dll
2008-11-23 17:01:10 —-N—- C:\WINDOWS\system32\setupn.exe
2008-11-23 17:01:08 —-N—- C:\WINDOWS\system32\rasqec.dll
2008-11-23 17:01:08 —-N—- C:\WINDOWS\system32\qutil.dll
2008-11-23 17:01:07 —-N—- C:\WINDOWS\system32\qcliprov.dll
2008-11-23 17:01:07 —-N—- C:\WINDOWS\system32\qagentrt.dll
2008-11-23 17:01:07 —-N—- C:\WINDOWS\system32\qagent.dll
2008-11-23 17:01:06 —-N—- C:\WINDOWS\system32\onex.dll
2008-11-23 17:01:03 —-N—- C:\WINDOWS\system32\napstat.exe
2008-11-23 17:01:03 —-N—- C:\WINDOWS\system32\napmontr.dll
2008-11-23 17:01:03 —-N—- C:\WINDOWS\system32\napipsec.dll
2008-11-23 17:01:03 —-A—- C:\WINDOWS\system32\msxml6r.dll
2008-11-23 17:01:02 —-N—- C:\WINDOWS\system32\msshavmsg.dll
2008-11-23 17:01:02 —-N—- C:\WINDOWS\system32\mssha.dll
2008-11-23 17:00:56 —-N—- C:\WINDOWS\system32\mmcperf.exe
2008-11-23 17:00:56 —-N—- C:\WINDOWS\system32\mmcfxcommon.dll
2008-11-23 17:00:56 —-N—- C:\WINDOWS\system32\mmcex.dll
2008-11-23 17:00:56 —-N—- C:\WINDOWS\system32\microsoft.managementconsole.dll
2008-11-23 17:00:50 —-N—- C:\WINDOWS\system32\l2gpstore.dll
2008-11-23 17:00:50 —-N—- C:\WINDOWS\system32\kmsvc.dll
2008-11-23 17:00:50 —-N—- C:\WINDOWS\system32\kbdpash.dll
2008-11-23 17:00:49 —-N—- C:\WINDOWS\system32\kbdnepr.dll
2008-11-23 17:00:49 —-N—- C:\WINDOWS\system32\kbdiultn.dll
2008-11-23 17:00:49 —-N—- C:\WINDOWS\system32\kbdbhc.dll
2008-11-23 17:00:37 —-A—- C:\WINDOWS\003843_.tmp
2008-11-23 17:00:36 —-N—- C:\WINDOWS\system32\eapsvc.dll
2008-11-23 17:00:36 —-N—- C:\WINDOWS\system32\eapqec.dll
2008-11-23 17:00:36 —-N—- C:\WINDOWS\system32\eappprxy.dll
2008-11-23 17:00:36 —-N—- C:\WINDOWS\system32\eapphost.dll
2008-11-23 17:00:36 —-N—- C:\WINDOWS\system32\eappgnui.dll
2008-11-23 17:00:36 —-N—- C:\WINDOWS\system32\eappcfg.dll
2008-11-23 17:00:36 —-N—- C:\WINDOWS\system32\eapp3hst.dll
2008-11-23 17:00:36 —-N—- C:\WINDOWS\system32\eapolqec.dll
2008-11-23 17:00:35 —-N—- C:\WINDOWS\system32\dot3ui.dll
2008-11-23 17:00:35 —-N—- C:\WINDOWS\system32\dot3svc.dll
2008-11-23 17:00:35 —-N—- C:\WINDOWS\system32\dot3msm.dll
2008-11-23 17:00:35 —-N—- C:\WINDOWS\system32\dot3gpclnt.dll
2008-11-23 17:00:35 —-N—- C:\WINDOWS\system32\dot3dlg.dll
2008-11-23 17:00:35 —-N—- C:\WINDOWS\system32\dot3cfg.dll
2008-11-23 17:00:35 —-N—- C:\WINDOWS\system32\dot3api.dll
2008-11-23 17:00:34 —-N—- C:\WINDOWS\system32\dimsroam.dll
2008-11-23 17:00:34 —-N—- C:\WINDOWS\system32\dimsntfy.dll
2008-11-23 17:00:34 —-N—- C:\WINDOWS\system32\dhcpqec.dll
2008-11-23 17:00:33 —-N—- C:\WINDOWS\system32\credssp.dll
2008-11-23 17:00:27 —-N—- C:\WINDOWS\system32\bitsprx4.dll
2008-11-23 17:00:27 —-N—- C:\WINDOWS\system32\azroles.dll
2008-11-23 16:14:00 —-HDC—- C:\WINDOWS\$NtUninstallKB932823-v3$
2008-11-23 16:13:36 —-HDC—- C:\WINDOWS\$NtUninstallKB950749$
2008-11-23 16:12:33 —-HDC—- C:\WINDOWS\$NtUninstallKB948590$
2008-11-23 16:11:57 —-HDC—- C:\WINDOWS\$NtUninstallKB945553$
2008-11-23 16:04:53 —-A—- C:\WINDOWS\system32\wmpns.dll
2008-11-23 16:01:17 —-HDC—- C:\WINDOWS\$NtUninstallKB924496$
2008-11-23 16:01:11 —-HDC—- C:\WINDOWS\$NtUninstallKB924191$
2008-11-23 16:01:04 —-HDC—- C:\WINDOWS\$NtUninstallKB923414$
2008-11-23 16:00:57 —-HDC—- C:\WINDOWS\$NtUninstallKB923191$
2008-11-23 16:00:51 —-HDC—- C:\WINDOWS\$NtUninstallKB922819$
2008-11-23 16:00:45 —-HDC—- C:\WINDOWS\$NtUninstallKB922616$
2008-11-23 16:00:38 —-HDC—- C:\WINDOWS\$NtUninstallKB921883$
2008-11-23 16:00:33 —-HDC—- C:\WINDOWS\$NtUninstallKB921398$
2008-11-23 16:00:26 —-HDC—- C:\WINDOWS\$NtUninstallKB920685$
2008-11-23 16:00:20 —-HDC—- C:\WINDOWS\$NtUninstallKB920683$
2008-11-23 16:00:15 —-HDC—- C:\WINDOWS\$NtUninstallKB920670$
2008-11-23 16:00:08 —-HDC—- C:\WINDOWS\$NtUninstallKB919007$
2008-11-23 16:00:01 —-HDC—- C:\WINDOWS\$NtUninstallKB917953$
2008-11-23 15:59:56 —-HDC—- C:\WINDOWS\$NtUninstallKB917422$
2008-11-23 15:59:47 —-HDC—- C:\WINDOWS\$NtUninstallKB914389$
2008-11-23 15:59:42 —-HDC—- C:\WINDOWS\$NtUninstallKB914388$
2008-11-23 15:59:36 —-HDC—- C:\WINDOWS\$NtUninstallKB913580$
2008-11-23 15:59:31 —-HDC—- C:\WINDOWS\$NtUninstallKB912919$
2008-11-23 15:59:26 —-HDC—- C:\WINDOWS\$NtUninstallKB911927$
2008-11-23 15:59:21 —-HDC—- C:\WINDOWS\$NtUninstallKB911562$
2008-11-23 15:59:16 —-HDC—- C:\WINDOWS\$NtUninstallKB911280$
2008-11-23 15:59:11 —-HDC—- C:\WINDOWS\$NtUninstallKB910437$
2008-11-23 15:59:06 —-HDC—- C:\WINDOWS\$NtUninstallKB908531$
2008-11-23 15:59:02 —-HDC—- C:\WINDOWS\$NtUninstallKB908519$
2008-11-23 15:58:57 —-HDC—- C:\WINDOWS\$NtUninstallKB905749$
2008-11-23 15:58:52 —-HDC—- C:\WINDOWS\$NtUninstallKB905414$
2008-11-23 15:58:46 —-HDC—- C:\WINDOWS\$NtUninstallKB904706$
2008-11-23 15:58:36 —-HDC—- C:\WINDOWS\$NtUninstallKB901017$
2008-11-23 15:58:31 —-HDC—- C:\WINDOWS\$NtUninstallKB900725$
2008-11-23 15:58:24 —-HDC—- C:\WINDOWS\$NtUninstallKB899591$
2008-11-23 15:58:19 —-HDC—- C:\WINDOWS\$NtUninstallKB899589$
2008-11-23 15:58:14 —-HDC—- C:\WINDOWS\$NtUninstallKB899587$
2008-11-23 15:58:08 —-HDC—- C:\WINDOWS\$NtUninstallKB896428$
2008-11-23 15:58:03 —-HDC—- C:\WINDOWS\$NtUninstallKB896424$
2008-11-23 15:57:59 —-HDC—- C:\WINDOWS\$NtUninstallKB896423$
2008-11-23 15:57:54 —-HDC—- C:\WINDOWS\$NtUninstallKB896358$
2008-11-23 15:57:49 —-HDC—- C:\WINDOWS\$NtUninstallKB893756$
2008-11-23 15:57:44 —-HDC—- C:\WINDOWS\$NtUninstallKB891781$
2008-11-23 15:57:39 —-HDC—- C:\WINDOWS\$NtUninstallKB890859$
2008-11-23 15:57:34 —-HDC—- C:\WINDOWS\$NtUninstallKB890046$
2008-11-23 15:57:29 —-HDC—- C:\WINDOWS\$NtUninstallKB888302$
2008-11-23 15:57:22 —-HDC—- C:\WINDOWS\$NtUninstallKB885836$
2008-11-23 15:57:17 —-HDC—- C:\WINDOWS\$NtUninstallKB885835$
2008-11-23 15:57:09 —-HDC—- C:\WINDOWS\$NtUninstallKB873339$
2008-11-23 15:56:51 —-N—- C:\WINDOWS\system32\smtpapi.dll
2008-11-23 15:56:51 —-N—- C:\WINDOWS\system32\rwnh.dll
2008-11-23 15:55:57 —-A—- C:\WINDOWS\000001_.tmp
2008-11-20 22:32:35 —-D—- C:\WINDOWS\Sun
2008-11-20 22:28:28 —-A—- C:\WINDOWS\system32\javaws.exe
2008-11-20 22:28:28 —-A—- C:\WINDOWS\system32\javaw.exe
2008-11-20 22:28:28 —-A—- C:\WINDOWS\system32\java.exe
2008-11-20 22:28:28 —-A—- C:\WINDOWS\system32\deploytk.dll
2008-11-20 22:28:13 —-D—- C:\Program Files\Java
2008-11-20 22:27:36 —-D—- C:\Documents and Settings\theone\Application Data\Sun
2008-11-20 18:58:57 —-D—- C:\Program Files\AVG
2008-11-20 18:44:47 —-D—- C:\Program Files\CA
2008-11-20 18:24:35 —-D—- C:\Program Files\Common Files\Adobe AIR
2008-11-20 18:24:00 —-D—- C:\Program Files\Common Files\Adobe
2008-11-20 18:24:00 —-D—- C:\Program Files\Adobe
2008-11-20 18:21:06 —-D—- C:\Documents and Settings\All Users\Application Data\NOS
2008-11-20 18:21:05 —-D—- C:\Program Files\NOS
2008-11-20 18:10:53 —-D—- C:\Documents and Settings\All Users\Application Data\TEMP
2008-11-20 18:10:49 —-A—- C:\WINDOWS\system32\MSSTDFMT.DLL
2008-11-20 18:08:41 —-D—- C:\Documents and Settings\theone\Application Data\Windows Search
2008-11-20 18:08:37 —-HDC—- C:\WINDOWS\$NtUninstallKB943729$
2008-11-20 18:08:01 —-HD—- C:\WINDOWS\system32\GroupPolicy
2008-11-20 18:08:01 —-D—- C:\Program Files\Windows Desktop Search
2008-11-20 18:07:46 —-HDC—- C:\WINDOWS\$NtUninstallKB915800-v4$
2008-11-20 16:58:55 —-A—- C:\WINDOWS\system32\bf3ecef6-.txt
2008-11-20 16:53:45 —-A—- C:\psqrhqn.exe
2008-11-20 16:53:45 —-A—- C:\nriljal.exe
2008-11-20 16:53:45 —-A—- C:\naxv.exe
2008-11-20 16:53:45 —-A—- C:\cvqkuk.exe
2008-11-20 16:53:28 —-N—- C:\WINDOWS\SchedLgU.Txt
2008-11-20 14:44:26 —-A—- C:\WINDOWS\system32\xfcodec.dll
2008-11-11 22:38:08 —-A—- C:\WINDOWS\AviSplitter.INI
2008-11-11 22:17:07 —-D—- C:\Program Files\Essentials Codec Pack
2008-11-11 19:21:13 —-HDC—- C:\WINDOWS\$NtUninstallKB957097_0$
2008-11-11 19:21:08 —-HDC—- C:\WINDOWS\$NtUninstallKB954459$
2008-11-11 19:20:53 —-HDC—- C:\WINDOWS\$NtUninstallKB955069_0$

======List of files/folders modified in the last 1 months======

2008-12-03 22:46:12 —-D—- C:\Program Files\Xfire
2008-12-03 22:27:13 —-A—- C:\WINDOWS\system32\PnkBstrB.exe
2008-12-03 22:25:55 —-SHD—- C:\RECYCLER
2008-12-03 22:25:54 —-SHD—- C:\WINDOWS\Installer
2008-12-03 22:25:54 —-SHD—- C:\Config.Msi
2008-12-03 22:25:51 —-D—- C:\WINDOWS\Temp
2008-12-03 17:35:58 —-D—- C:\Documents and Settings\theone\Application Data\Xfire
2008-12-03 17:19:39 —-D—- C:\WINDOWS
2008-12-03 16:26:52 —-RSHDC—- C:\WINDOWS\system32\dllcache
2008-12-03 16:26:48 —-D—- C:\WINDOWS\system32\CatRoot2
2008-12-03 16:26:48 —-D—- C:\WINDOWS\system32
2008-12-03 16:26:47 —-HD—- C:\WINDOWS\inf
2008-12-03 16:26:44 —-D—- C:\WINDOWS\Help
2008-12-02 00:53:14 —-D—- C:\Documents and Settings\theone\Application Data\wsInspector
2008-12-02 00:52:29 —-D—- C:\Program Files
2008-12-01 20:26:31 —-D—- C:\Program Files\Ares
2008-12-01 20:15:23 —-D—- C:\WINDOWS\system32\drivers
2008-12-01 20:13:42 —-D—- C:\Documents and Settings\theone\Application Data\AT&T;
2008-12-01 20:11:07 —-D—- C:\Program Files\Common Files
2008-12-01 20:10:55 —-D—- C:\WINDOWS\Registration
2008-12-01 20:10:53 —-D—- C:\WINDOWS\WinSxS
2008-12-01 20:10:46 —-D—- C:\Documents and Settings\All Users\Application Data\AT&T;
2008-12-01 19:22:30 —-SD—- C:\Documents and Settings\theone\Application Data\Microsoft
2008-11-30 22:53:43 —-D—- C:\Documents and Settings\All Users\Application Data\Google Updater
2008-11-24 17:28:37 —-A—- C:\Cucu_Video_log.txt
2008-11-23 23:18:35 —-D—- C:\WINDOWS\Debug
2008-11-23 17:42:26 —-D—- C:\WINDOWS\system32\CatRoot
2008-11-23 17:41:58 —-HDC—- C:\WINDOWS\$NtUninstallKB951978$
2008-11-23 17:41:15 —-A—- C:\WINDOWS\system32\PerfStringBackup.INI
2008-11-23 17:37:32 —-D—- C:\WINDOWS\system32\Setup
2008-11-23 17:37:32 —-D—- C:\WINDOWS\AppPatch
2008-11-23 17:37:31 —-RSD—- C:\WINDOWS\Fonts
2008-11-23 17:37:31 —-D—- C:\WINDOWS\system32\wbem
2008-11-23 17:27:44 —-D—- C:\Program Files\Messenger
2008-11-23 17:27:05 —-D—- C:\WINDOWS\security
2008-11-23 17:23:08 —-D—- C:\WINDOWS\system32\inetsrv
2008-11-23 17:23:08 —-D—- C:\WINDOWS\network diagnostic
2008-11-23 17:23:00 —-D—- C:\WINDOWS\ime
2008-11-23 17:22:41 —-D—- C:\WINDOWS\system32\usmt
2008-11-23 17:22:41 —-D—- C:\WINDOWS\system32\en-us
2008-11-23 17:22:40 —-D—- C:\WINDOWS\system32\scripting
2008-11-23 17:22:39 —-D—- C:\WINDOWS\system32\en
2008-11-23 17:22:39 —-D—- C:\WINDOWS\l2schemas
2008-11-23 17:22:38 —-D—- C:\WINDOWS\system32\bits
2008-11-23 17:22:38 —-D—- C:\WINDOWS\peernet
2008-11-23 17:22:38 —-D—- C:\Program Files\Movie Maker
2008-11-23 17:18:25 —-D—- C:\WINDOWS\system32\Restore
2008-11-23 17:18:25 —-D—- C:\WINDOWS\system32\npp
2008-11-23 17:18:25 —-D—- C:\WINDOWS\mui
2008-11-23 17:18:24 —-D—- C:\WINDOWS\msagent
2008-11-23 17:18:22 —-D—- C:\WINDOWS\srchasst
2008-11-23 17:18:21 —-D—- C:\Program Files\NetMeeting
2008-11-23 17:18:15 —-D—- C:\WINDOWS\system32\Com
2008-11-23 17:18:13 —-D—- C:\Program Files\Windows Media Player
2008-11-23 17:18:12 —-D—- C:\Program Files\Windows NT
2008-11-23 17:18:12 —-D—- C:\Program Files\Outlook Express
2008-11-23 17:18:09 —-D—- C:\Program Files\Common Files\System
2008-11-23 17:17:51 —-D—- C:\WINDOWS\system32\oobe
2008-11-23 17:17:46 —-D—- C:\WINDOWS\system
2008-11-23 17:13:16 —-D—- C:\WINDOWS\EHome
2008-11-23 16:38:11 —-D—- C:\WINDOWS\Media
2008-11-23 16:38:11 —-D—- C:\Program Files\Internet Explorer
2008-11-23 16:19:38 —-HDC—- C:\WINDOWS\$NtUninstallKB958644_0$
2008-11-23 16:19:16 —-HDC—- C:\WINDOWS\$NtUninstallKB957095_0$
2008-11-23 16:18:51 —-HDC—- C:\WINDOWS\$NtUninstallKB956841_0$
2008-11-23 16:18:28 —-HDC—- C:\WINDOWS\$NtUninstallKB956803_0$
2008-11-23 16:18:07 —-HDC—- C:\WINDOWS\$NtUninstallKB956391$
2008-11-23 16:17:45 —-HDC—- C:\WINDOWS\$NtUninstallKB954211_0$
2008-11-23 16:17:24 —-HDC—- C:\WINDOWS\$NtUninstallKB938464_0$
2008-11-23 16:17:23 —-HD—- C:\WINDOWS\$hf_mig$
2008-11-23 16:17:04 —-HDC—- C:\WINDOWS\$NtUninstallKB952287_0$
2008-11-23 16:16:43 —-HDC—- C:\WINDOWS\$NtUninstallKB950974_0$
2008-11-23 16:16:23 —-HDC—- C:\WINDOWS\$NtUninstallKB952954_0$
2008-11-23 16:16:02 —-HDC—- C:\WINDOWS\$NtUninstallKB946648_0$
2008-11-23 16:15:40 —-HDC—- C:\WINDOWS\$NtUninstallKB951066_0$
2008-11-23 16:15:18 —-HDC—- C:\WINDOWS\$NtUninstallKB951748_0$
2008-11-23 16:14:57 —-HDC—- C:\WINDOWS\$NtUninstallKB951698_0$
2008-11-23 16:14:37 —-HDC—- C:\WINDOWS\$NtUninstallKB951376-v2_0$
2008-11-23 16:14:19 —-HDC—- C:\WINDOWS\$NtUninstallKB950762_0$
2008-11-23 16:04:40 —-SD—- C:\WINDOWS\Tasks
2008-11-23 16:03:17 —-RASH—- C:\boot.ini
2008-11-23 16:03:17 —-A—- C:\WINDOWS\win.ini
2008-11-23 16:03:17 —-A—- C:\WINDOWS\system.ini
2008-11-23 15:45:33 —-D—- C:\WINDOWS\ServicePackFiles
2008-11-20 19:25:59 —-D—- C:\Documents and Settings\All Users\Application Data\pypmdude
2008-11-20 18:58:54 —-D—- C:\Program Files\Common Files\Microsoft Shared
2008-11-20 18:38:46 —-D—- C:\WINDOWS\system32\config
2008-11-20 18:33:54 —-SD—- C:\WINDOWS\Downloaded Program Files
2008-11-20 18:28:38 —-D—- C:\Documents and Settings\theone\Application Data\Adobe
2008-11-20 18:24:25 —-D—- C:\Documents and Settings\All Users\Application Data\Adobe
2008-11-20 18:08:45 —-D—- C:\WINDOWS\system32\ReinstallBackups
2008-11-20 18:08:12 —-SD—- C:\Documents and Settings\All Users\Application Data\Microsoft
2008-11-20 17:05:08 —-A—- C:\rapport.txt
2008-11-20 17:04:13 —-A—- C:\WINDOWS\system32\tmp.txt
2008-11-11 22:55:44 —-D—- C:\Program Files\FLV Player
2008-11-09 19:24:58 —-D—- C:\Program Files\XAC
2008-11-09 19:24:37 —-D—- C:\Program Files\NuGardt Software
2008-11-04 20:23:12 —-D—- C:\Documents and Settings\theone\Application Data\Ventrilo

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AmdPPM;AMD HwPState Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdPPM.sys [2007-04-16 33792]
R1 DLACDBHM;DLACDBHM; C:\WINDOWS\System32\Drivers\DLACDBHM.SYS [2006-03-17 5660]
R1 DLARTL_N;DLARTL_N; C:\WINDOWS\System32\Drivers\DLARTL_N.SYS [2006-03-17 22684]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\System32\DRIVERS\kbdhid.sys [2008-04-13 14592]
R1 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys [2007-02-20 5632]
R2 CSS DVP;Dynamic Virus Protection; C:\WINDOWS\system32\DRIVERS\css-dvp.sys [2007-11-26 835792]
R2 DLABOIOM;DLABOIOM; C:\WINDOWS\System32\DLA\DLABOIOM.SYS [2006-06-13 25724]
R2 DLADResN;DLADResN; C:\WINDOWS\System32\DLA\DLADResN.SYS [2006-06-13 2496]
R2 DLAIFS_M;DLAIFS_M; C:\WINDOWS\System32\DLA\DLAIFS_M.SYS [2006-06-13 86844]
R2 DLAOPIOM;DLAOPIOM; C:\WINDOWS\System32\DLA\DLAOPIOM.SYS [2006-06-13 14716]
R2 DLAPoolM;DLAPoolM; C:\WINDOWS\System32\DLA\DLAPoolM.SYS [2006-06-13 6364]
R2 DLAUDF_M;DLAUDF_M; C:\WINDOWS\System32\DLA\DLAUDF_M.SYS [2006-06-13 88476]
R2 DLAUDFAM;DLAUDFAM; C:\WINDOWS\System32\DLA\DLAUDFAM.SYS [2006-06-13 94460]
R2 DRVNDDM;DRVNDDM; C:\WINDOWS\System32\Drivers\DRVNDDM.SYS [2006-03-17 40544]
R2 PfDetNT;PfDetNT; \??\C:\WINDOWS\System32\drivers\PfModNT.sys []
R2 RPSKT;Security Services Driver (x86); C:\WINDOWS\system32\DRIVERS\rp_skt32.sys [2008-12-01 53192]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\System32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 ati2mtag;ati2mtag; C:\WINDOWS\System32\DRIVERS\ati2mtag.sys [2008-01-22 2845696]
R3 COMMONFX.DLL;COMMONFX.DLL; C:\WINDOWS\system32\COMMONFX.DLL [2007-04-18 98600]
R3 ctac32k;Creative AC3 Software Decoder; C:\WINDOWS\System32\drivers\ctac32k.sys [2007-04-10 511272]
R3 ctaud2k;Creative Audio Driver (WDM); C:\WINDOWS\system32\drivers\ctaud2k.sys [2007-04-10 520488]
R3 CTAUDFX.DLL;CTAUDFX.DLL; C:\WINDOWS\system32\CTAUDFX.DLL [2007-04-12 546048]
R3 ctprxy2k;Creative Proxy Driver; C:\WINDOWS\System32\drivers\ctprxy2k.sys [2007-04-10 14632]
R3 CTSBLFX.DLL;CTSBLFX.DLL; C:\WINDOWS\system32\CTSBLFX.DLL [2007-04-12 560384]
R3 ctsfm2k;Creative SoundFont Management Device Driver; C:\WINDOWS\System32\drivers\ctsfm2k.sys [2007-04-10 157480]
R3 emupia;E-mu Plug-in Architecture Driver; C:\WINDOWS\System32\drivers\emupia2k.sys [2007-04-10 92968]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys [2008-04-17 15464]
R3 ha10kx2k;Creative Hardware Abstract Layer Driver; C:\WINDOWS\System32\drivers\ha10kx2k.sys [2007-04-10 797992]
R3 hap16v2k;Creative P16V HAL Driver; C:\WINDOWS\System32\drivers\hap16v2k.sys [2007-04-10 163112]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys [2008-02-29 35344]
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys [2008-02-29 36880]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\System32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\System32\DRIVERS\NVENETFD.sys [2004-03-15 33408]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\System32\DRIVERS\nvnetbus.sys [2004-03-15 12928]
R3 ossrv;Creative OS Services Driver; C:\WINDOWS\system32\drivers\ctoss2k.sys [2007-04-10 126760]
R3 RPPKT;Radialpoint Filter (x86); C:\WINDOWS\system32\DRIVERS\rp_pkt32.sys [2007-04-19 48384]
R3 SaiK0728;SaiK0728; C:\WINDOWS\system32\DRIVERS\SaiK0728.sys [2008-03-13 104960]
R3 SaiMini;SaiMini; C:\WINDOWS\system32\DRIVERS\SaiMini.sys [2007-10-30 14080]
R3 SaiNtBus;SaiNtBus; C:\WINDOWS\system32\drivers\SaiBus.sys [2007-10-30 35328]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbohci.sys [2008-04-13 17152]
R3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2006-11-02 492000]
S1 AmdK8;AMD Athlon64 Processor Driver; C:\WINDOWS\System32\DRIVERS\AmdK8.sys [2003-11-06 35328]
S3 btaudio;Bluetooth Audio Device; C:\WINDOWS\system32\drivers\btaudio.sys []
S3 BTDriver;Bluetooth Virtual Communications Driver; C:\WINDOWS\system32\DRIVERS\btport.sys []
S3 BTWDNDIS;Bluetooth LAN Access Server; C:\WINDOWS\system32\DRIVERS\btwdndis.sys []
S3 btwhid;btwhid; C:\WINDOWS\system32\DRIVERS\btwhid.sys []
S3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\WINDOWS\System32\Drivers\btwusb.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 CT20XUT.DLL;CT20XUT.DLL; C:\WINDOWS\system32\CT20XUT.DLL [2007-04-12 164608]
S3 ctdvda2k;Creative DVD-Audio Device Driver; C:\WINDOWS\System32\drivers\ctdvda2k.sys [2007-04-10 347128]
S3 CTEAPSFX.DLL;CTEAPSFX.DLL; C:\WINDOWS\system32\CTEAPSFX.DLL [2007-04-12 168192]
S3 CTEDSPFX.DLL;CTEDSPFX.DLL; C:\WINDOWS\system32\CTEDSPFX.DLL [2007-04-12 280320]
S3 CTEDSPIO.DLL;CTEDSPIO.DLL; C:\WINDOWS\system32\CTEDSPIO.DLL [2007-04-12 128768]
S3 CTEDSPSY.DLL;CTEDSPSY.DLL; C:\WINDOWS\system32\CTEDSPSY.DLL [2007-04-12 323328]
S3 CTERFXFX.DLL;CTERFXFX.DLL; C:\WINDOWS\system32\CTERFXFX.DLL [2007-04-12 94976]
S3 CTEXFIFX.DLL;CTEXFIFX.DLL; C:\WINDOWS\system32\CTEXFIFX.DLL [2007-04-12 1317632]
S3 CTHWIUT.DLL;CTHWIUT.DLL; C:\WINDOWS\system32\CTHWIUT.DLL [2007-04-12 66816]
S3 GcKernel;Microsoft SideWinder Value Add - Filter Driver; C:\WINDOWS\System32\DRIVERS\GcKernel.sys [2008-04-13 59136]
S3 GMSIPCI;GMSIPCI; \??\D:\INSTALL\GMSIPCI.SYS []
S3 hap17v2k;Creative P17V HAL Driver; C:\WINDOWS\system32\drivers\hap17v2k.sys [2007-04-10 189736]
S3 HIDSwvd;Microsoft SideWinder Virtual HID Device Mini-Driver; C:\WINDOWS\System32\DRIVERS\HIDSwvd.sys [2000-06-02 3636]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 PhilCam8116;Logitech QuickCam Pro 3000 (08B0); C:\WINDOWS\system32\DRIVERS\CamDrO21.sys [2001-08-17 314752]
S3 RimUsb;BlackBerry Device; C:\WINDOWS\System32\Drivers\RimUsb.sys []
S3 RimVSerPort;RIM Virtual Serial Port v2; C:\WINDOWS\system32\DRIVERS\RimSerial.sys [2007-01-18 26496]
S3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2003-03-31 5888]
S3 SaiH0728;SaiH0728; C:\WINDOWS\system32\DRIVERS\SaiH0728.sys [2007-10-30 136448]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usb_rndisx;USB RNDIS Adapter; C:\WINDOWS\system32\DRIVERS\usb8023x.sys [2008-04-13 12800]
S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys [2008-10-01 32000]
S3 usbaudio;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-13 60032]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-10-01 116040]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2008-01-22 512000]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-08-29 238888]
R2 dvpapi;DvpApi; C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe [2007-11-27 177448]
R2 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-10-12 168432]
R2 ITMRTSVC;CA Pest Patrol Realtime Protection Service; C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe [2006-12-19 280080]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2008-11-20 152984]
R2 PDAgent;PDAgent; C:\Program Files\Raxco\PerfectDisk\PDAgent.exe [2008-04-28 414984]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2008-10-30 66872]
R2 PnkBstrB;PnkBstrB; C:\WINDOWS\system32\PnkBstrB.exe [2008-12-03 202040]
R2 RP_FWS;AT&T; Internet Security Suite AT&T; Firewall; C:\Program Files\AT&T;\AT&T; Internet Security Suite\Fws.exe [2007-06-28 293104]
R3 RPSUpdaterR;AT&T; Internet Security Suite Service; C:\Program Files\AT&T;\AT&T; Internet Security Suite\rpsupdaterR.exe [2008-12-01 99056]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2008-01-22 593920]
S2 RoxLiveShare9;LiveShare P2P Server 9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe []
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2007-10-09 36864]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2007-10-11 864256]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2008-10-01 536872]
S3 PDEngine;PDEngine; C:\Program Files\Raxco\PerfectDisk\PDEngine.exe [2008-04-28 738568]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2007-10-11 122880]

—————–EOF—————–
Hi BigSteve-E-,

RSIT needs to be saved to the desktop so that we can use it again if we need to.
  • Click this link: random's system information tool (RSIT) by random/random from >> HERE.
  • When the File Download box appears, click Save and save it directly to your desktop.

Next, RSIT produces two logs (log.txt and info.txt) but you only posted log.txt.
Navigate to C:\rsit and copy/paste the contents of info.txt into your next reply.

Thanks, revel
info.txt logfile of random's system information tool 1.04 2008-12-03 22:48:08 ======Uninstall list====== –>"C:\Program Files\Creative\SBAudigy2ZS\Program\Ctzapxx.EXE" /W /U /S –>C:\Program Files\InstallShield Installation Information\{36C41D70-56F5-4E2B-81DA-6BEB7502D7A1}\setup.exe -runfromtemp -l0x0009 -removeonly –>C:\Program Files\InstallShield Installation Information\{B2C4A8C4-AA20-425D-9FEE-C78039238C81}\setup.exe -runfromtemp -l0x0009 -removeonly –>C:\WINDOWS\system32\\MSIEXEC.EXE /x {1206EF92-2E83-4859-ACCB-2048C3CB7DA6} –>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{87499F38-FD69-4A2B-B41A-BAB8DE9B94FE}\setup.exe" -l0x9 –>rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf ACE Mega CoDecS Pack–>"C:\Program Files\ACE Mega CoDecS Pack\unins000.exe" Acrobat.com–>C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe -uninstall com.adobe.mauby 4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 Acrobat.com–>MsiExec.exe /I{77DCDCE3-2DED-62F3-8154-05E745472D07} Adobe AIR–>C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Updater.exe -arp:uninstall Adobe AIR–>MsiExec.exe /I{00203668-8170-44A0-BE44-B632FA4D780F} Adobe Flash Player ActiveX–>C:\WINDOWS\System32\Macromed\Flash\uninstall_activeX.exe Adobe Reader 8.1.2–>MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81200000003} Apple Mobile Device Support–>MsiExec.exe /I{976C2B2A-CE59-4AB3-83FB-BF895E28F2E6} Apple Software Update–>MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033} Ares 2.0.9–>"C:\Program Files\Ares\uninstall.exe" AT&T Internet Security Suite–>C:\Program Files\InstallShield Installation Information\{D7DF917E-C963-42B4-AD48-837ACA6D8859}\setup.exe -runfromtemp -l0x0009 -removeonly AT&T Internet Security Wizard 1.5.11–>"C:\Program Files\AT&T\Internet Security Wizard\unins000.exe" ATI - Software Uninstall Utility–>C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe ATI Display Driver–>rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean Audacity 1.2.6–>"C:\Program Files\Audacity\unins000.exe" Authentium AntiVirus SDK - 2–>MsiExec.exe /I{C70EF769-8296-4ED0-966F-D624BC6D4927} Battlefield 1942–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{698D7E61-E4BF-4CA6-8A09-CF6BDBFDEF65}\Setup.exe" -l0x9 Battlefield 2™–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{04858915-9F49-4B2A-AED4-DC49A7DE6A7B}\setup.exe" -l0x9 -removeonly Bejeweled 2 Deluxe–>C:\WINDOWS\iun6002ev.exe "C:\Program Files\Bejeweled 2 Deluxe\irunin.ini" Bonjour–>MsiExec.exe /I{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959} Call of Duty® 4 - Modern Warfare™ 1.4 Patch–>C:\Program Files\InstallShield Installation Information\{3BD633E0-4BF8-4499-9149-88F0767D449C}\setup.exe -runfromtemp -l0x0409 Call of Duty® 4 - Modern Warfare™ 1.5 Multiplayer Patch–>C:\Program Files\InstallShield Installation Information\{8503C901-85D7-4262-88D2-8D8B2A7B08B8}\setup.exe -runfromtemp -l0x0409 Call of Duty® 4 - Modern Warfare™ 1.5 Singleplayer Patch–>C:\Program Files\InstallShield Installation Information\{D1B7EF59-A3E2-452A-882E-076E1A18D94A}\setup.exe -runfromtemp -l0x0409 Call of Duty® 4 - Modern Warfare™ 1.6 Patch–>C:\Program Files\InstallShield Installation Information\{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}\setup.exe -runfromtemp -l0x0409 Call of Duty® 4 - Modern Warfare™ 1.7 Patch–>C:\Program Files\InstallShield Installation Information\{931C37FC-594D-43A9-B10F-A2F2B1F03498}\setup.exe -runfromtemp -l0x0409 Call of Duty® 4 - Modern Warfare™–>C:\Program Files\InstallShield Installation Information\{E48469CC-635E-4FD5-A122-1497C286D217}\setup.exe -runfromtemp -l0x0409 CCleaner (remove only)–>"C:\Program Files\CCleaner\uninst.exe" Creative System Information–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{87499F38-FD69-4A2B-B41A-BAB8DE9B94FE}\setup.exe" -l0x9 /remove Cucusoft DVD to iPod + iPod Video Converter Suite 7.18.7.11–>"C:\Program Files\Cucusoft\ipod-converter\unins000.exe" DesertCombat 0.7–>C:\WINDOWS\iun6002.exe "C:\Program Files\EA GAMES\Battlefield 1942\DesertCombat.ini" DivX Codec–>C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC Download Manager 2.3.6–>C:\Program Files\Download Manager\uninst.exe ffdshow [rev 2228] [2008-10-17]–>"C:\Program Files\ffdshow\unins000.exe" FLV Player 2.0 (build 25)–>C:\Program Files\FLV Player\uninst.exe Google Toolbar for Internet Explorer–>MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29} Google Toolbar for Internet Explorer–>regsvr32 /u /s "c:\program files\google\googletoolbar2.dll" Google Updater–>"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall HijackThis 2.0.2–>"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall Hotfix for Microsoft .NET Framework 3.0 (KB932471)–>C:\WINDOWS\system32\msiexec.exe /promptrestart /uninstall {ECD292A0-0347-4244-8C24-5DBCE990FB40} /package {BAF78226-3200-4DB4-BE33-4D922A799840} Hotfix for Windows Media Format 11 SDK (KB929399)–>"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe" Hotfix for Windows Media Format SDK (KB902344)–>"C:\WINDOWS\$NtUninstallKB902344$\spuninst\spuninst.exe" Hotfix for Windows Media Player 11 (KB939683)–>"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe" Hotfix for Windows XP (KB952287)–>"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe" IrfanView (remove only)–>C:\Program Files\IrfanView\iv_uninstall.exe iTunes–>MsiExec.exe /I{DDDE0BE3-0CBE-4BF6-B75A-E3F69C947843} Java™ 6 Update 10–>MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216010FF} KhalInstallWrapper–>MsiExec.exe /I{3101CB58-3482-4D21-AF1A-7057FC935355} Logitech Registration–>MsiExec.exe /I{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C} Logitech SetPoint–>C:\Program Files\InstallShield Installation Information\{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}\setup.exe -runfromtemp -l0x0009 -removeonly Microsoft .NET Framework 1.1 Hotfix (KB928366)–>"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp" Microsoft .NET Framework 1.1–>msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} Microsoft .NET Framework 1.1–>MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} Microsoft .NET Framework 2.0 Service Pack 1–>MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28} Microsoft .NET Framework 3.0 Service Pack 1–>MsiExec.exe /I{2BA00471-0328-3743-93BD-FA813353A783} Microsoft Base Smart Card Cryptographic Service Provider Package–>"C:\WINDOWS\$NtUninstallbasecsp$\spuninst\spuninst.exe" Microsoft Compression Client Pack 1.0 for Windows XP–>"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe" Microsoft Internationalized Domain Names Mitigation APIs–>"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe" Microsoft Kernel-Mode Driver Framework Feature Pack 1.5–>"C:\WINDOWS\$NtUninstallWdf01005$\spuninst\spuninst.exe" Microsoft National Language Support Downlevel APIs–>"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe" Microsoft Silverlight–>MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} Microsoft User-Mode Driver Framework Feature Pack 1.0–>"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe" Microsoft Visual C++ 2005 Redistributable–>MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d} MSXML 4.0 SP2 (KB936181)–>MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF} MSXML 4.0 SP2 (KB954430)–>MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71} MSXML 6 Service Pack 2 (KB954459)–>MsiExec.exe /I{1A528690-6A2D-4BC5-B143-8C4AE8D19D96} NVIDIA Drivers–>C:\WINDOWS\System32\NVUninst.exe UninstallGUI PerfectDisk–>MsiExec.exe /I{212F5777-1190-4DEF-8E4D-6B2F313B45E7} PPSDKRedistributables–>MsiExec.exe /I{C869F4FF-E5FF-4FBB-9A31-33C23605E170} PunkBuster Services–>C:\WINDOWS\system32\pbsvc.exe -u QuickTime–>MsiExec.exe /I{8DC42D05-680B-41B0-8878-6C14D24602DB} Radialpoint Security Services–>MsiExec.exe /X{5DFDEAAA-E050-482E-A5B6-138CAE53F7BF} RPS Ad Blocker–>MsiExec.exe /I{BAF99E78-879B-4811-BFEF-3CC7057BC00D} RPS AntiFraud–>MsiExec.exe /I{537654FC-556A-4992-BF3D-ADC05E7009DC} RPS AntiSpyware–>MsiExec.exe /I{99E6E9E1-BBCD-4294-93C6-08537A9E92CB} RPS AntiVirus–>MsiExec.exe /I{E85A45C2-290F-4C4A-9363-B6399EE648A9} RPS App Detector–>MsiExec.exe /I{2F4BFC9D-17D7-447A-AEA2-467892D876B3} RPS AsRealtime–>MsiExec.exe /I{1E164156-3FA1-4389-9B0B-28E88B879639} RPS Backup–>MsiExec.exe /I{904847DA-FBC0-4726-BE73-830FCB9D4E8A} RPS Burn–>MsiExec.exe /I{7D11FED9-4214-40A6-A6CA-3CFBAC20DA36} RPS Diagnostic Utility–>MsiExec.exe /I{0345520E-2A04-4A36-BC31-353AE87A6092} RPS Firewall–>MsiExec.exe /I{0818687F-F41F-496D-9D6D-DB98F147FC62} RPS ParentalControl–>MsiExec.exe /I{E5E7B0D0-20E1-4B1A-B8C9-B9E2B93DE1DE} RPS Performance Tool–>MsiExec.exe /I{3DE72179-FEF4-4846-BF82-62CBFC61F8D7} RPS PopupBlocker–>MsiExec.exe /I{310F26F3-C769-48E5-BD0D-53D4366C34CD} RPS Privacy Manager–>MsiExec.exe /I{AC82BF06-223B-42AA-A89F-2D3BCD247366} RPS RpsCore–>MsiExec.exe /I{295F5142-A223-4164-9A6D-6683C08409FC} RPS Security Cleanup–>MsiExec.exe /I{58A2663B-56DC-488F-8E29-D44C6DE053B5} RPS Zip–>MsiExec.exe /I{4AA73DA8-8D69-44ED-B5D7-CB815C81F83E} Saitek SD6 Programming Software 6.0.12.2–>MsiExec.exe /X{C8D644EE-8053-45D5-A73F-D784F3D22F56} Security Update for CAPICOM (KB931906)–>MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A} Security Update for CAPICOM (KB931906)–>MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A} Security Update for Windows Internet Explorer 7 (KB938127)–>"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe" Security Update for Windows Internet Explorer 7 (KB942615)–>"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe" Security Update for Windows Internet Explorer 7 (KB944533)–>"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe" Security Update for Windows Internet Explorer 7 (KB950759)–>"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe" Security Update for Windows Internet Explorer 7 (KB953838)–>"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe" Security Update for Windows Internet Explorer 7 (KB956390)–>"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe" Security Update for Windows Media Player 11 (KB936782)–>"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe" Security Update for Windows Media Player 11 (KB954154)–>"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe" Security Update for Windows Media Player 8 (KB917734)–>"C:\WINDOWS\$NtUninstallKB917734_WMP8$\spuninst\spuninst.exe" Security Update for Windows XP (KB938464)–>"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe" Security Update for Windows XP (KB941569)–>"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe" Security Update for Windows XP (KB946648)–>"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe" Security Update for Windows XP (KB950760)–>"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe" Security Update for Windows XP (KB950762)–>"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe" Security Update for Windows XP (KB950974)–>"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe" Security Update for Windows XP (KB951066)–>"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe" Security Update for Windows XP (KB951376-v2)–>"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe" Security Update for Windows XP (KB951698)–>"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe" Security Update for Windows XP (KB951748)–>"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe" Security Update for Windows XP (KB952954)–>"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe" Security Update for Windows XP (KB953839)–>"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe" Security Update for Windows XP (KB954211)–>"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe" Security Update for Windows XP (KB954459)–>"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe" Security Update for Windows XP (KB955069)–>"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe" Security Update for Windows XP (KB956391)–>"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe" Security Update for Windows XP (KB956803)–>"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe" Security Update for Windows XP (KB956841)–>"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe" Security Update for Windows XP (KB957095)–>"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe" Security Update for Windows XP (KB957097)–>"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe" Security Update for Windows XP (KB958644)–>"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe" SideWinder Precision 2–>C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Microsoft Hardware\Game Controllers\Precision 2\Uninst.isu" -c"C:\Program Files\Microsoft Hardware\Game Controllers\Precision 2\Uninstall.dll" Sonic UDF Reader–>MsiExec.exe /I{1206EF92-2E83-4859-ACCB-2048C3CB7DA6} Sony Picture Utility–>C:\Program Files\InstallShield Installation Information\{D5068583-D569-468B-9755-5FBF5848F46F}\setup.exe -runfromtemp -l0x0009 uninstall -removeonly Sound Blaster Audigy 2 ZS–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9E2514D9-DC24-4634-B348-61F3EF0F1628}\SETUP.EXE" -l0x9 TeamSpeak 2 RC2–>"C:\Program Files\Teamspeak2_RC2\unins000.exe" Uninstall Startup Inspector–>"C:\Program Files\Startup Inspector for Windows\unins000.exe" Update for Windows XP (KB951072-v2)–>"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe" Update for Windows XP (KB951978)–>"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe" Ventrilo Client–>MsiExec.exe /I{789289CA-F73A-4A16-A331-54D498CE069F} WildTangent Web Driver–>C:\Program Files\WildTangent\Apps\CDA\CDAUninstall.exe Windows Imaging Component–>"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe" Windows Media Format 11 runtime–>"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll Windows Media Format 11 runtime–>"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe" Windows Media Format SDK Hotfix - KB891122–>"C:\WINDOWS\$NtUninstallKB891122$\spuninst\spuninst.exe" Windows Media Player 11–>"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall Windows Media Player 11–>"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe" Windows Presentation Foundation–>MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840} Windows XP Service Pack 3–>"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe" WinRAR archiver–>C:\Program Files\WinRAR\uninstall.exe Xfire (remove only)–>"C:\Program Files\Xfire\uninst.exe" Xvid 1.1.3 final uninstall–>"C:\Program Files\Xvid\unins000.exe" Yahoo! Messenger–>C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE /U C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG =====HijackThis Backups===== O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Unknown owner - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe (file missing) ======Security center information====== AV: AT&T Internet Security Suite AT&T Anti-Virus FW: AT&T Internet Security Suite AT&T Firewall ======Environment variables====== "ComSpec"=%SystemRoot%\system32\cmd.exe "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\;C:\Program Files\QuickTime\QTSystem\;C:\Program Files\CA\PPRT\bin "windir"=%SystemRoot% "OS"=Windows_NT "PROCESSOR_ARCHITECTURE"=x86 "PROCESSOR_LEVEL"=15 "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 12 Stepping 0, AuthenticAMD "PROCESSOR_REVISION"=0c00 "NUMBER_OF_PROCESSORS"=1 "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH "TEMP"=%SystemRoot%\TEMP "TMP"=%SystemRoot%\TEMP "FP_NO_HOST_CHECK"=NO "CLASSPATH"=.;C:\Program Files\QuickTime\QTSystem\QTJava.zip "QTJAVA"=C:\Program Files\QuickTime\QTSystem\QTJava.zip —————–EOF—————–
Hi BigSteve-E-,

If you already have a copy of Combofix, delete your copy.
Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications as they may otherwise interfere with our tools. This is usually done via a right-click on the program's System Tray icon.

  • Double-click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]



Click Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:
1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making IE the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

In your next post, please copy/paste
  • Combofix log
  • new HijackThis log
regards, revel
ComboFix 08-12-05.02 - theone 2008-12-05 15:50:49.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1531 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\Tasks\nyotmrqu.job

.
((((((((((((((((((((((((( Files Created from 2008-11-05 to 2008-12-05 )))))))))))))))))))))))))))))))
.

2008-12-05 10:51 . 2008-12-05 10:51 d——– c:\documents and settings\theone\Application Data\Research In Motion
2008-12-05 10:51 . 2008-12-05 10:51 d——– c:\documents and settings\theone\Application Data\Blackberry Desktop
2008-12-05 08:05 . 2008-12-05 08:07 d——– c:\program files\eToro
2008-12-03 22:47 . 2008-12-03 22:48 d——– C:\rsit
2008-12-02 00:45 . 2008-12-02 00:52 d——– c:\documents and settings\All Users\Application Data\SecTaskMan
2008-12-01 23:08 . 2008-12-02 00:41 d——– c:\program files\Unlocker
2008-12-01 20:15 . 2008-12-01 20:15 d——– c:\program files\Raxco
2008-12-01 20:15 . 2008-12-01 20:15 d——– c:\documents and settings\All Users\Application Data\Raxco
2008-12-01 20:11 . 2008-12-01 20:11 d——– c:\program files\Common Files\Authentium
2008-12-01 20:11 . 2008-12-01 20:15 53,192 –a—— c:\windows\system32\drivers\rp_skt32.sys
2008-12-01 20:11 . 2007-04-19 11:24 48,384 –a—— c:\windows\system32\drivers\rp_pkt32.sys
2008-12-01 20:10 . 2008-12-01 20:11 d——– c:\program files\Common Files\Scanner
2008-12-01 20:10 . 2008-12-01 20:10 d——– c:\program files\AT&T
2008-12-01 19:45 . 2008-12-01 19:45 d——– c:\program files\Trend Micro
2008-12-01 19:22 . 2008-12-01 19:22 d——– c:\documents and settings\All Users\Application Data\Avg8
2008-11-23 17:00 . 2008-04-13 18:11 650,752 ——— c:\windows\system32\dot3ui.dll
2008-11-23 16:09 . 2008-08-14 04:11 2,189,184 —–c— c:\windows\system32\dllcache\ntoskrnl.exe
2008-11-23 16:09 . 2008-08-14 04:09 2,145,280 —–c— c:\windows\system32\dllcache\ntkrnlmp.exe
2008-11-23 16:09 . 2008-08-14 03:33 2,066,048 —–c— c:\windows\system32\dllcache\ntkrnlpa.exe
2008-11-23 16:09 . 2008-08-14 03:33 2,023,936 —–c— c:\windows\system32\dllcache\ntkrpamp.exe
2008-11-23 16:09 . 2008-09-15 06:12 1,846,400 —–c— c:\windows\system32\dllcache\win32k.sys
2008-11-23 16:09 . 2008-04-11 13:04 691,712 —–c— c:\windows\system32\dllcache\inetcomm.dll
2008-11-23 16:09 . 2008-09-08 04:41 333,824 —–c— c:\windows\system32\dllcache\srv.sys
2008-11-23 16:09 . 2008-06-13 05:05 272,128 —–c— c:\windows\system32\dllcache\bthport.sys
2008-11-23 16:09 . 2008-05-08 08:02 203,136 —–c— c:\windows\system32\dllcache\rmcast.sys
2008-11-23 16:08 . 2008-10-24 05:21 455,296 —–c— c:\windows\system32\dllcache\mrxsmb.sys
2008-11-23 16:08 . 2008-10-15 10:34 337,408 —–c— c:\windows\system32\dllcache\netapi32.dll
2008-11-23 16:04 . 2004-08-04 01:56 221,184 –a—— c:\windows\system32\wmpns.dll
2008-11-23 15:56 . 2008-04-13 18:12 10,752 ——— c:\windows\system32\smtpapi.dll
2008-11-23 15:56 . 2008-04-13 18:12 9,728 ——— c:\windows\system32\rwnh.dll
2008-11-23 15:55 . 2004-07-17 11:40 19,528 –a—— c:\windows\000001_.tmp
2008-11-20 22:32 . 2008-11-20 22:32 d——– c:\windows\Sun
2008-11-20 22:28 . 2008-11-20 22:28 d——– c:\program files\Java
2008-11-20 22:28 . 2008-11-20 22:28 410,976 –a—— c:\windows\system32\deploytk.dll
2008-11-20 22:28 . 2008-11-20 22:28 73,728 –a—— c:\windows\system32\javacpl.cpl
2008-11-20 18:58 . 2008-11-20 18:58 d——– c:\program files\AVG
2008-11-20 18:44 . 2008-12-01 19:41 d——– c:\program files\CA
2008-11-20 18:34 . 2008-11-20 18:34 d–hs—- c:\documents and settings\theone\PrivacIE
2008-11-20 18:24 . 2008-11-20 18:24 d——– c:\program files\Common Files\Adobe AIR
2008-11-20 18:24 . 2008-11-20 18:24 d——– c:\program files\Common Files\Adobe
2008-11-20 18:21 . 2008-11-20 18:33 d——– c:\program files\NOS
2008-11-20 18:21 . 2008-11-20 18:33 d——– c:\documents and settings\All Users\Application Data\NOS
2008-11-20 18:10 . 2008-11-20 18:10 d——– c:\documents and settings\All Users\Application Data\TEMP
2008-11-20 18:10 . 2005-08-25 19:18 118,784 –a—— c:\windows\system32\MSSTDFMT.DLL
2008-11-20 18:08 . 2008-12-01 17:40 d–h—– c:\windows\system32\GroupPolicy
2008-11-20 18:08 . 2008-11-20 18:15 d——– c:\program files\Windows Desktop Search
2008-11-20 18:08 . 2008-11-20 18:08 d——– c:\documents and settings\theone\Application Data\Windows Search
2008-11-20 18:08 . 2008-11-20 18:08 0 –ah—– c:\windows\system32\drivers\Msft_Kernel_SaiK0728_01005.Wdf
2008-11-20 18:07 . 2008-03-07 11:02 192,000 —–c— c:\windows\system32\dllcache\offfilt.dll
2008-11-20 18:07 . 2008-03-07 11:02 98,304 —–c— c:\windows\system32\dllcache\nlhtml.dll
2008-11-20 16:53 . 2008-11-20 16:53 0 –a—— C:\psqrhqn.exe
2008-11-20 16:53 . 2008-11-20 16:53 0 –a—— C:\nriljal.exe
2008-11-20 16:53 . 2008-11-20 16:53 0 –a—— C:\naxv.exe
2008-11-20 16:53 . 2008-11-20 16:53 0 –a—— C:\cvqkuk.exe
2008-11-20 16:53 . 2008-11-20 16:53 0 –a—— C:\-1273165273
2008-11-20 14:44 . 2008-11-20 14:44 42,320 –a—— c:\windows\system32\xfcodec.dll
2008-11-11 22:38 . 2008-11-11 22:38 38 –a—— c:\windows\AviSplitter.INI
2008-11-11 22:17 . 2008-11-11 22:39 d——– c:\program files\Essentials Codec Pack
2008-11-11 19:19 . 2008-09-04 11:15 1,106,944 –a–c— c:\windows\system32\dllcache\msxml3.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-05 21:51 ——— d—–w c:\documents and settings\theone\Application Data\Xfire
2008-12-05 20:31 137,688 —-a-w c:\windows\system32\drivers\PnkBstrK.sys
2008-12-05 17:16 256 —-a-w c:\documents and settings\theone\pool.bin
2008-12-05 13:46 ——— d—–w c:\program files\PCPitstop
2008-12-05 13:27 ——— d—–w c:\documents and settings\All Users\Application Data\Google Updater
2008-12-04 06:44 ——— d—–w c:\documents and settings\All Users\Application Data\PCPitstop
2008-12-04 06:02 ——— d—–w c:\documents and settings\theone\Application Data\wsInspector
2008-12-04 04:46 ——— d—–w c:\program files\Xfire
2008-12-02 02:26 ——— d—–w c:\program files\Ares
2008-12-02 02:13 ——— d—–w c:\documents and settings\theone\Application Data\AT&T
2008-12-02 02:10 ——— d—–w c:\documents and settings\All Users\Application Data\AT&T
2008-11-21 01:25 ——— d—–w c:\documents and settings\All Users\Application Data\pypmdude
2008-11-12 04:55 ——— d—–w c:\program files\FLV Player
2008-11-10 01:24 ——— d—–w c:\program files\XAC
2008-11-10 01:24 ——— d—–w c:\program files\NuGardt Software
2008-11-05 02:23 ——— d—–w c:\documents and settings\theone\Application Data\Ventrilo
2008-11-03 02:29 ——— d–h–w c:\program files\InstallShield Installation Information
2008-11-03 02:25 729,088 —-a-w c:\windows\iun6002.exe
2008-11-03 00:13 ——— d—–w c:\program files\Ventrilo
2008-11-03 00:12 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2008-11-02 03:47 ——— d—–w c:\program files\EA GAMES
2008-11-02 00:13 ——— d—–w c:\program files\InterActual
2008-11-01 20:44 ——— d—–w c:\program files\GameSpy Arcade
2008-10-30 15:09 ——— d—–w c:\program files\Activision
2008-10-30 14:58 22,328 —-a-w c:\documents and settings\theone\Application Data\PnkBstrK.sys
2008-10-30 13:46 ——— d—–w c:\documents and settings\theone\Application Data\IGN_DLM
2008-10-26 08:14 ——— d—–w c:\program files\ffdshow
2008-10-26 07:35 ——— d—–w c:\program files\ACE Mega CoDecS Pack
2008-10-26 06:11 ——— d—–w c:\program files\qzcgjue
2008-10-26 06:05 ——— d—–w c:\documents and settings\theone\Application Data\Malwarebytes
2008-10-26 06:05 ——— d—–w c:\documents and settings\All Users\Application Data\Malwarebytes
2008-10-24 11:21 455,296 —-a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-21 04:17 ——— d—–w c:\program files\Common Files\Real
2008-10-21 03:52 ——— d—–w c:\program files\DivX
2008-10-21 03:47 ——— d—–w c:\program files\Xvid
2008-10-20 21:39 ——— d—–w c:\program files\Microsoft Silverlight
2008-10-20 00:17 ——— d—–w c:\program files\Microsoft ActiveSync
2008-10-20 00:15 ——— d—–w c:\documents and settings\All Users\Application Data\Roxio
2008-10-19 21:57 ——— d—–w c:\program files\Download Manager
2008-10-19 06:59 ——— d—–w c:\program files\Google
2008-10-19 06:27 ——— d—–w c:\program files\Logitech
2008-10-12 22:33 ——— d—–w c:\program files\CCleaner
2008-10-11 13:50 ——— d—–w c:\program files\iTunes
2008-10-11 13:49 ——— d—–w c:\program files\iPod
2008-10-11 13:49 ——— d—–w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISW.exe"="c:\program files\AT&T\Internet Security Wizard\ISW.exe" [2007-05-03 2061816]
"AT&T Internet Security Suite"="c:\program files\AT&T\AT&T Internet Security Suite\Rps.exe" [2007-06-28 310000]
"-FreedomNeedsReboot"="c:\program files\AT&T\AT&T Internet Security Suite\ZkRunOnceR.exe" [2007-06-28 13552]

c:\documents and settings\theone\Start Menu\Programs\Startup\
Picture Motion Browser Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe [2008-05-06 385024]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XFR1"= xfcodec.dll
"msacm.sl_anet"= c:\progra~1\ACEMEG~1\SystemS\sl_anet.acm
"vidc.3ivx"= c:\progra~1\ACEMEG~1\SystemS\3ivx\3IVXVF~1.DLL
"vidc.3iv0"= c:\progra~1\ACEMEG~1\SystemS\3ivx\3IVXVF~1.DLL
"vidc.3iv1"= c:\progra~1\ACEMEG~1\SystemS\3ivx\3IVXVF~1.DLL
"vidc.3iv2"= c:\progra~1\ACEMEG~1\SystemS\3ivx\3IVXVF~1.DLL
"vidc.3ivd"= c:\progra~1\ACEMEG~1\SystemS\3ivx\3IVXVF~1.DLL
"msacm.msaudio1"= c:\progra~1\ACEMEG~1\SystemS\MICROS~1\msaud32.acm
"vidc.yv12"= c:\progra~1\ACEMEG~1\SystemS\ATI\atiyuv12.DLL
"vidc.divx"= c:\progra~1\ACEMEG~1\SystemS\DivX\DivX511.dll
"vidc.iyuv"= c:\progra~1\ACEMEG~1\SystemS\Intel\iyuv_32.dll
"vidc.yvu9"= c:\progra~1\ACEMEG~1\SystemS\Intel\Iyvu9_32.dll
"vidc.uyvy"= c:\progra~1\ACEMEG~1\SystemS\MICROS~1\msyuv.dll
"vidc.yuy2"= c:\progra~1\ACEMEG~1\SystemS\MICROS~1\msyuv.dll
"vidc.yvyu"= c:\progra~1\ACEMEG~1\SystemS\MICROS~1\msyuv.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a—— 2008-04-13 18:12 15360 c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SBDrvDet]
–a—— 2002-12-03 18:06 45056 c:\program files\Creative\SB Drive Det\SBDrvDet.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
——— 2000-05-11 01:00 90112 c:\windows\Updreg.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTHelper]
–a—— 2007-04-09 12:32 19456 c:\windows\system32\CtHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kernel and Hardware Abstraction Layer]
–a—— 2008-02-29 03:12 76304 c:\windows\KHALMNPR.Exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Xfire\\xfire.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=

R2 PfDetNT;PfDetNT;\??\c:\windows\System32\drivers\PfModNT.sys [2007-04-10 16168]
R3 SaiK0728;SaiK0728;c:\windows\system32\DRIVERS\SaiK0728.sys [2008-03-13 104960]
S3 SaiH0728;SaiH0728;c:\windows\system32\DRIVERS\SaiH0728.sys [2008-08-23 136448]
.
Contents of the 'Scheduled Tasks' folder

2008-11-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
- - - - ORPHANS REMOVED - - - -

BHO-{716FCFD2-1417-42C9-B802-188DA57A8195} - (no file)
HKLM-Run-PC Pitstop Optimize Reminder - c:\program files\PCPitstop\Optimize2\Reminder.exe
ShellExecuteHooks-{E9681C1C-C1DF-4970-97BB-86C3E716AFA3} - (no file)
Notify-jkklMCss - jkklMCss.dll



**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-05 15:53:20
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(976)
c:\windows\system32\Ati2evxx.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\program files\AT&T\AT&T Internet Security Suite\Fws.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\program files\CA\PPRT\bin\ITMRTSVC.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Raxco\PerfectDisk\PDAgent.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\program files\AT&T\AT&T Internet Security Suite\rpsupdaterR.exe
c:\program files\Raxco\PerfectDisk\PDEngine.exe
c:\windows\system32\msiexec.exe
.
**************************************************************************
.
Completion time: 2008-12-05 15:55:51 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-05 21:55:48

Pre-Run: 11,261,997,056 bytes free
Post-Run: 11,275,841,536 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptOut

231 — E O F — 2008-03-12 03:36:51
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:00:43 PM, on 12/5/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AT&T\AT&T Internet Security Suite\Fws.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\AT&T\Internet Security Wizard\ISW.exe
C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AT&T\AT&T Internet Security Suite\rpsupdaterR.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\AT&T\AT&T Internet Security Suite\pkR.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ISW.exe] "C:\Program Files\AT&T\Internet Security Wizard\ISW.exe" /AUTORUN
O4 - HKLM\..\Run: [AT&T Internet Security Suite] "C:\Program Files\AT&T\AT&T Internet Security Suite\Rps.exe"
O4 - HKLM\..\Run: [-FreedomNeedsReboot] "C:\Program Files\AT&T\AT&T Internet Security Suite\ZkRunOnceR.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
O8 - Extra context menu item: Send to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/betapit/PCPitStop.CAB
O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC Class) - http://www.pcpitstop.com/internet/pcpConnCheck.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.7.109.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1203904463796
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1203900267250
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/Optimize2/pcpitstop2.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Unknown owner - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe (file missing)
O23 - Service: AT&T Internet Security Suite Service (RPSUpdaterR) - Radialpoint Inc. - C:\Program Files\AT&T\AT&T Internet Security Suite\rpsupdaterR.exe
O23 - Service: AT&T Internet Security Suite AT&T Firewall (RP_FWS) - AT&T - C:\Program Files\AT&T\AT&T Internet Security Suite\Fws.exe

–
End of file - 7029 bytes
Hi BigSteve-E-,

  • Open notepad (Start > Run > type notepad)
  • Copy/paste the text in the quotebox below into Notepad:

    File::
    C:\psqrhqn.exe
    C:\nriljal.exe
    C:\naxv.exe
    C:\cvqkuk.exe
    C:\-1273165273

    DirLook::
    c:\program files\qzcgjue

  • Save this notepad to your desktop as "CFScript.txt" and as Type: All Files (*.*).


    IMPORTANT: Before running Combofix:

    Please close any open browsers.
    Close/disable all antivirus and antimalware programs so they do not interfere with the running of Combofix.


  • Referring to the picture below, drag CFScript.txt onto ComboFix.exe. This will start Combofix.

    [external image: Posted Image]

  • When finished, it shall produce a log for you at C:\ComboFix.txt.

———————————————

Kaspersky Online scanner

  • Temporarily disable your resident antivirus to prevent it from interfering with this scan.

    :: IMPORTANT :: With your resident antivirus disabled, I advise you not to use the internet for any purpose aside from the scan below.

    Note: It is recommended to use Internet Explorer for this scan
  • Visit this link >> Kaspersky <<
  • Read the requirements and privacy statement and click Accept
  • The scanner and virus definitions will start downloading. When prompted to install an ActiveX by Kaspersky, click Run
  • When the downloads have completed, click on Settings
  • Be sure that the following boxes are checked. If not, please check them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
    • Mail databases
  • Click on My Computer under Scan
  • When the scan is complete, it will display the scan results. Click on View Scan Report button. You will see a list of infected items. Click on Save Report As…. Change the Files of type to Text file (.txt) and then Save the scan report to your desktop. Post the contents of the scan report with your next reply.
  • :: IMPORTANT :: Re-enable your Antivirus program

In your next reply, please provide (copy/paste):
  • Combofix report (C:\Combofix.txt)
  • Kaspersky scan results
Hi BigSteve-E-, I'm glad that everything appears to be working, however, I noticed while verifying your logs that your system was still infected. If you ran through the last set of instructions, provide the Combofix log and Kaspersky log in your next reply. If you have not run through the last set of instructions, it is important that you do so and post the results back in your next reply. Thanks, revel

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI