This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] microsoft security center (download antispyware now)

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

my computer is running slow and when i try to go www.youtube.com it
takes me to microsoft security center instead and say's that my
computer is infected and i need to download antispyware now and i have
read about it and know that is a virus and have heard about it so
i didn't (download antispyware now)luckley but i still think it got
me some how.i have ran 4 or 5 spyware removers and i still havin
the same problems.i have a emachines desktop with vista.any help
will be greatly appriciated.

Thanks,
Brett.


this is my hijackthis info,



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:48:06 AM, on 12/4/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16757)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\mobsync.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Norton AntiVirus\Engine\16.1.0.33\ccSvcHst.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: 61.157.217.210 www.youtube.com
O1 - Hosts: 61.157.217.210 www.facebook.com
O1 - Hosts: 61.157.217.210 www.antispy.com
O1 - Hosts: 61.157.217.210 www.yahoo.co.uk
O1 - Hosts: 61.157.217.210 www.antispyware.com
O1 - Hosts: 61.157.217.210 antispyware.com
O1 - Hosts: 61.157.217.210 antispy.com
O1 - Hosts: 123.251.143.110 www.asdfasdfd.com
O1 - Hosts: 123.251.143.110 www.gg.com
O1 - Hosts: 123.251.143.110 www.ghfhj.com
O1 - Hosts: 123.251.143.110 www.cvnbcvnb.com
O1 - Hosts: 123.251.143.110 www.1.com
O1 - Hosts: 123.251.143.110 www.3.com
O1 - Hosts: 123.251.143.110 www.asdf4asdfd.com
O1 - Hosts: 123.251.143.110 www.asdfawsdfd.com
O1 - Hosts: 123.251.143.110 www.asdfatsdfd.com
O1 - Hosts: 123.251.143.110 www.asdfasdfd.com
O1 - Hosts: 123.251.143.110 www.asdfadsdfd.com
O1 - Hosts: 123.251.143.110 www.asdfasdfd.com
O1 - Hosts: 123.251.143.110 www.asdfafsdfd.com
O1 - Hosts: 123.251.143.110 www.asdfasdfd.com
O1 - Hosts: 123.251.143.110 www.asdfagsdfd.com
O1 - Hosts: 123.251.143.110 www.asdfasgdfd.com
O1 - Hosts: 123.251.143.110 www.asdfasdhfd.com
O1 - Hosts: 123.251.143.110 www.asdfasdfjd.com
O1 - Hosts: 123.251.143.110 www.asdfasdfkd.com
O1 - Hosts: 123.251.143.110 www.asdfasdfld.com
O1 - Hosts: 123.251.143.110 www.asdfasdf,d.com
O1 - Hosts: 123.251.143.110 www.asxdfasdfd.com
O1 - Hosts: 123.251.143.110 www.asdzfasdfd.com
O1 - Hosts: 123.251.143.110 www.asdcfasdfd.com
O1 - Hosts: 123.251.143.110 www.asdfvasdfd.com
O1 - Hosts: 123.251.143.110 www.asdfabsdfd.com
O1 - Hosts: 123.251.143.110 www.asdfasndfd.com
O1 - Hosts: 123.251.143.110 www.asdfasdmfd.com
O1 - Hosts: 123.251.143.110 www.asdfasdfd.com
O1 - Hosts: 123.251.143.110 www.11asdfasdfd.com
O1 - Hosts: 123.251.143.110 www.as222dfasdfd.com
O1 - Hosts: 123.251.143.110 www.asdfa33sdfd.com
O1 - Hosts: 123.251.143.110 www.asdfasd44fd.com
O1 - Hosts: 123.251.143.110 www.asdfasdfd5.com
O1 - Hosts: 123.251.143.110 www.as66dfasdfd.com
O1 - Hosts: 123.251.143.110 www.asdf77asdfd.com
O1 - Hosts: 123.251.143.110 www.asdf8asdfd.com
O1 - Hosts: 123.251.143.110 www.asdf9asdfd.com
O1 - Hosts: 123.251.143.110 www.asdf0asdfd.com
O1 - Hosts: 123.251.143.110 www.asdf-asdfd.com
O1 - Hosts: 123.251.143.110 www.aqqsdfasdfd.com
O1 - Hosts: 123.251.143.110 www.aswwdfasdfd.com
O1 - Hosts: 123.16.197.121 www.asdhhfasdfdyy.com
O1 - Hosts: 61.157.217.210 www.live.com
O1 - Hosts: 123.251.143.110 www.asdwwwfasdfd.com
O1 - Hosts: 123.251.143.110 www.asdfeasdfd.com
O1 - Hosts: 123.251.143.110 www.asdfrrasdfd.com
O1 - Hosts: 123.251.143.110 www.asdfttasdfd.com
O1 - Hosts: 123.251.143.110 www.asdfyyasdfd.com
O1 - Hosts: 123.251.143.110 www.asdfuuuasdfd.com
O1 - Hosts: 123.251.143.110 www.asdfaiisdfd.com
O1 - Hosts: 123.251.143.110 www.asdfaoosdfd.com
O1 - Hosts: 123.251.143.110 www.asdfappsdfd.com
O1 - Hosts: 123.251.143.110 www.asdfasssdfd.com
O1 - Hosts: 123.251.143.110 www.aswwdfasdfd.com
O1 - Hosts: 123.251.143.110 www.asdeefasdfd.com
O1 - Hosts: 123.251.143.110 www.asdfffasdfd.com
O1 - Hosts: 123.251.143.110 www.asdfavvvsdfd.com
O1 - Hosts: 123.251.143.110 www.asnnndfasdfd.com
O1 - Hosts: 123.251.143.110 www.asdmmmfasdfd.com
O1 - Hosts: 123.251.143.110 www.asdfaffsdfd.com
O1 - Hosts: 123.251.143.110 www.asdhhfasdfd.com
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\16.1.0.33\IPSBHO.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O13 - Gopher Prefix:
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: Norton AntiVirus - Symantec Corporation - C:\Program Files\Norton AntiVirus\Engine\16.1.0.33\ccSvcHst.exe
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 7737 bytes

thank for you'r time
Hi and welcome to the forums here at WTT.

Your hosts file has definitely been corrupted, so we'll fix that.

Download HostsXpert v4.1 and unzip it to your computer, somewhere where you can find it.
  • Double click on HostsXpert.exe to launch the program.
  • Click on Restore MS Hosts File to restore your Hosts file to its default condition.
  • Click on Make ReadOnly to secure it against further infection.
  • Exit the program.
Visit the Website for more information.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Next, use Use ATF Cleaner to remove temp files,
cookies, cache, ect…

Please download ATF Cleaner by Atribune.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.


Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and Paste the entire report in your next reply along with a Hijackthis log.
Also let me know how it's running.
i cant find malwarebytes on one link and the other one's not workin. im run alot better with just the first 2 things that you had me do thank you so much
Glad it's running better. Hate it when they change the links….you can download the free version here.

http://www.malwarebytes.org/mbam.php

Sorry about that.
malwarebytes log:Malwarebytes' Anti-Malware 1.31Database version: 1464Windows 6.0.6000 12/5/2008 8:39:49 PMmbam-log-2008-12-05 (20-39-49).txtScan type: Quick ScanObjects scanned: 40686Time elapsed: 4 minute(s), 46 second(s)Memory Processes Infected: 0Memory Modules Infected: 0Registry Keys Infected: 0Registry Values Infected: 0Registry Data Items Infected: 0Folders Infected: 0Files Infected: 0Memory Processes Infected:(No malicious items detected)Memory Modules Infected:(No malicious items detected)Registry Keys Infected:(No malicious items detected)Registry Values Infected:(No malicious items detected)Registry Data Items Infected:(No malicious items detected)Folders Infected:(No malicious items detected)Files Infected:(No malicious items detected)highjackthis log:Logfile of Trend Micro HijackThis v2.0.2Scan saved at 8:43:31 PM, on 12/5/2008Platform: Windows Vista  (WinNT 6.00.1904)MSIE: Internet Explorer v7.00 (7.00.6000.16757)Boot mode: NormalRunning processes:C:\Windows\system32\taskeng.exeC:\Windows\system32\Dwm.exeC:\Windows\Explorer.EXEC:\Windows\System32\hkcmd.exeC:\Windows\System32\igfxpers.exeC:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exeC:\Program Files\Windows Media Player\wmpnscfg.exeC:\Windows\System32\mobsync.exeC:\Program Files\Norton AntiVirus\Engine\16.1.0.33\ccSvcHst.exeC:\Windows\system32\igfxsrvc.exeC:\Windows\system32\wuauclt.exeC:\Program Files\HP\Smart Web Printing\hpswp_clipbook.exeC:\Windows\system32\Macromed\Flash\FlashUtil10a.exeC:\Program Files\Internet Explorer\ieuser.exeC:\Program Files\Internet Explorer\iexplore.exeC:\Windows\system32\SearchFilterHost.exeC:\Program Files\Trend Micro\HijackThis\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dllO2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dllO2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dllO2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\16.1.0.33\IPSBHO.DLLO2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dllO4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hideO4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exeO4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exeO4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exeO4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silentO4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exeO4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exeO4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dllO9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dllO13 - Gopher Prefix: O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exeO23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exeO23 - Service: Norton AntiVirus - Symantec Corporation - C:\Program Files\Norton AntiVirus\Engine\16.1.0.33\ccSvcHst.exeO23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exeO23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exeO23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe–End of file - 4659 bytes thank's again !!
Wow that's pretty much unreadable… Well it looks like MBAM didn't find any infection. Where did you copy and paste the HijackThis log from? Notepad? Can you try again? Make sure Word Wrap is turned off. Thanks
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:32:55 PM, on 12/5/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16757)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Norton AntiVirus\Engine\16.1.0.33\ccSvcHst.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\16.1.0.33\IPSBHO.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O13 - Gopher Prefix:
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: Norton AntiVirus - Symantec Corporation - C:\Program Files\Norton AntiVirus\Engine\16.1.0.33\ccSvcHst.exe
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 4218 bytes
yes i did use notpad sorry about that i dont know what did lol thanks again if you need the malwarebytes log again just let me know
Hi,

No problem, that looks better. Looks like you cleaned out the hosts file, how's it running?

We should probably do a virus scan also.

Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
Let me know how it's running too.
——————————————————————————– KASPERSKY ONLINE SCANNER 7 REPORT Saturday, December 6, 2008 Operating System: Microsoft Windows Vista Home Basic Edition, 32-bit (build 6000) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Saturday, December 06, 2008 02:29:08 Records in database: 1439709 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ G:\ H:\ I:\ Scan statistics: Files scanned: 99986 Threat name: 0 Infected objects: 0 Suspicious objects: 0 Duration of the scan: 01:20:37 No malware has been detected. The scan area is clean. The selected area was scanned.
  • Download random's system information tool (RSIT) by random/random from here.
  • It is important that is saved to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<info.txt (<
Logfile of random's system information tool 1.04 (written by random/random)
Run by [removed] at 2008-12-06 16:19:09
Microsoft® Windows Vista™ Home Basic
System drive C: has 91 GB (86%) free of 106 GB
Total RAM: 501 MB (33% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:19:47 PM, on 12/6/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16757)
Boot mode: Normal

Running processes:
C:\Program Files\Norton AntiVirus\Engine\16.1.0.33\ccSvcHst.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HP\Smart Web Printing\hpswp_clipbook.exe
C:\Users\desktop\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\desktop.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\16.1.0.33\IPSBHO.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O13 - Gopher Prefix:
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD5/JSCDL/jre…ows-i586-jc.cab
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: Norton AntiVirus - Symantec Corporation - C:\Program Files\Norton AntiVirus\Engine\16.1.0.33\ccSvcHst.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 4801 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{053F9267-DC04-4294-A72C-58F732D338C0}]
HP Print Clips - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll [2007-03-02 177768]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2008-12-02 304736]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
Symantec Intrusion Prevention - C:\Program Files\Norton AntiVirus\Engine\16.1.0.33\IPSBHO.DLL [2008-12-03 107896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java™ Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2008-12-05 320920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - c:\program files\google\googletoolbar1.dll [2008-12-02 2403392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-12-05 34816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program files\google\googletoolbar1.dll [2008-12-02 2403392]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-12-02 1006264]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2008-01-02 141848]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2008-01-02 166424]
"Persistence"=C:\Windows\system32\igfxpers.exe [2008-01-02 133656]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2008-12-05 136600]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe [2008-12-02 171448]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2006-11-02 201728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2008-01-02 200704]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======List of files/folders created in the last 1 months======

2008-12-06 16:19:09 —-D—- C:\rsit
2008-12-06 04:11:20 —-A—- C:\Windows\system32\igfxres.dll
2008-12-05 22:53:45 —-A—- C:\Windows\system32\javaws.exe
2008-12-05 22:53:45 —-A—- C:\Windows\system32\javaw.exe
2008-12-05 22:53:45 —-A—- C:\Windows\system32\java.exe
2008-12-05 22:53:45 —-A—- C:\Windows\system32\deploytk.dll
2008-12-05 22:52:27 —-D—- C:\Program Files\Java
2008-12-05 20:28:57 —-D—- C:\Program Files\Malwarebytes' Anti-Malware
2008-12-04 03:20:40 —-D—- C:\Program Files\MSXML 4.0
2008-12-04 03:06:36 —-D—- C:\Program Files\ThreatExpert Memory Scanner
2008-12-03 22:31:33 —-D—- C:\ProgramData\Symantec
2008-12-03 22:29:19 —-D—- C:\Program Files\Symantec
2008-12-03 22:29:19 —-D—- C:\Program Files\Common Files\Symantec Shared
2008-12-03 22:28:33 —-D—- C:\Program Files\Norton AntiVirus
2008-12-03 22:23:58 —-D—- C:\ProgramData\Norton
2008-12-03 22:23:51 —-D—- C:\ProgramData\NortonInstaller
2008-12-03 22:23:51 —-D—- C:\Program Files\NortonInstaller
2008-12-03 22:20:35 —-D—- C:\ProgramData\Symantec Temporary Files
2008-12-03 21:27:33 —-D—- C:\Users\desktop\AppData\Roaming\Malwarebytes
2008-12-03 21:27:23 —-D—- C:\ProgramData\Malwarebytes
2008-12-03 16:05:40 —-D—- C:\ProgramData\vsosdk
2008-12-03 05:52:58 —-D—- C:\ProgramData\SUPERAntiSpyware.com
2008-12-03 05:52:20 —-D—- C:\Users\desktop\AppData\Roaming\SUPERAntiSpyware.com
2008-12-03 05:52:20 —-D—- C:\Program Files\SUPERAntiSpyware
2008-12-03 05:17:46 —-D—- C:\Windows\SoftwareDistribution
2008-12-03 05:15:34 —-D—- C:\Windows\Debug
2008-12-03 05:12:57 —-D—- C:\Windows\Prefetch
2008-12-03 05:11:50 —-D—- C:\Windows\Panther
2008-12-03 05:11:35 —-RAS—- C:\BOOTSECT.BAK
2008-12-03 04:50:37 —-D—- C:\Program Files\Trend Micro
2008-12-03 02:34:28 —-D—- C:\Users\desktop\AppData\Roaming\Nero
2008-12-03 01:26:59 —-A—- C:\Windows\Irremote.ini
2008-12-03 00:18:16 —-D—- C:\Program Files\Nero
2008-12-03 00:15:42 —-D—- C:\ProgramData\Nero
2008-12-03 00:15:33 —-D—- C:\Program Files\Common Files\Nero
2008-12-03 00:13:00 —-A—- C:\Windows\system32\d3dx9_30.dll
2008-12-02 23:29:11 —-A—- C:\Windows\system32\es.dll
2008-12-02 22:58:13 —-A—- C:\Windows\system32\wups2.dll
2008-12-02 22:58:13 —-A—- C:\Windows\system32\wucltux.dll
2008-12-02 22:58:13 —-A—- C:\Windows\system32\wuaueng.dll
2008-12-02 22:58:13 —-A—- C:\Windows\system32\wuauclt.exe
2008-12-02 22:56:41 —-A—- C:\Windows\system32\wups.dll
2008-12-02 22:56:41 —-A—- C:\Windows\system32\wudriver.dll
2008-12-02 22:56:41 —-A—- C:\Windows\system32\wuapi.dll
2008-12-02 22:55:03 —-A—- C:\Windows\system32\wuwebv.dll
2008-12-02 22:55:03 —-A—- C:\Windows\system32\wuapp.exe
2008-12-02 22:23:04 —-D—- C:\Users\desktop\AppData\Roaming\Vso
2008-12-02 22:23:04 —-A—- C:\Users\desktop\AppData\Roaming\inst.exe
2008-12-02 22:22:39 —-D—- C:\Program Files\DVDFab 5
2008-12-02 18:12:43 —-D—- C:\ProgramData\WEBREG
2008-12-02 18:08:56 —-D—- C:\Users\desktop\AppData\Roaming\HPAppData
2008-12-02 18:08:38 —-D—- C:\ProgramData\HPSSUPPLY
2008-12-02 18:06:50 —-D—- C:\ProgramData\HP Product Assistant
2008-12-02 18:02:24 —-D—- C:\Program Files\Common Files\HP
2008-12-02 18:00:13 —-D—- C:\ProgramData\Hewlett-Packard
2008-12-02 17:56:43 —-A—- C:\Windows\system32\hpzids01.dll
2008-12-02 17:56:37 —-A—- C:\Windows\system32\hpzll5ha.dll
2008-12-02 17:55:57 —-D—- C:\Program Files\HP
2008-12-02 17:54:20 —-D—- C:\ProgramData\HP
2008-12-02 06:57:17 —-D—- C:\Program Files\Common Files\Adobe AIR
2008-12-02 06:52:41 —-D—- C:\ProgramData\Adobe
2008-12-02 06:51:28 —-D—- C:\Program Files\Common Files\Adobe
2008-12-02 06:51:28 —-D—- C:\Program Files\Adobe
2008-12-02 06:47:24 —-D—- C:\Users\desktop\AppData\Roaming\Macromedia
2008-12-02 06:47:23 —-D—- C:\Users\desktop\AppData\Roaming\Adobe
2008-12-02 06:46:00 —-D—- C:\Windows\system32\Macromed
2008-12-02 06:44:52 —-D—- C:\ProgramData\NOS
2008-12-02 06:44:51 —-D—- C:\Program Files\NOS
2008-12-02 05:58:38 —-D—- C:\Users\desktop\AppData\Roaming\Google
2008-12-02 05:31:58 —-A—- C:\Windows\system32\msvcr80.dll
2008-12-02 05:28:25 —-D—- C:\Users\desktop\AppData\Roaming\WinRAR
2008-12-02 05:26:14 —-A—- C:\Windows\cdplayer.ini
2008-12-02 05:25:25 —-D—- C:\Program Files\Common Files\xing shared
2008-12-02 05:25:11 —-A—- C:\Windows\system32\rmoc3260.dll
2008-12-02 05:25:03 —-D—- C:\Program Files\Real
2008-12-02 05:25:03 —-A—- C:\Windows\system32\pndx5032.dll
2008-12-02 05:25:03 —-A—- C:\Windows\system32\pndx5016.dll
2008-12-02 05:25:03 —-A—- C:\Windows\system32\pncrt.dll
2008-12-02 05:25:03 —-A—- C:\Windows\system32\msvcr71.dll
2008-12-02 05:25:03 —-A—- C:\Windows\system32\msvcp71.dll
2008-12-02 05:24:56 —-D—- C:\Program Files\Common Files\Real
2008-12-02 05:24:52 —-D—- C:\Users\desktop\AppData\Roaming\Real
2008-12-02 05:24:09 —-D—- C:\ProgramData\Google
2008-12-02 05:24:04 —-D—- C:\Program Files\Google
2008-12-02 05:22:27 —-D—- C:\Program Files\Voobys
2008-12-02 05:19:48 —-D—- C:\Windows\system32\URTTEMP
2008-12-02 05:18:40 —-SHD—- C:\Windows\Installer
2008-12-02 05:17:14 —-D—- C:\Program Files\WinRAR
2008-12-02 04:00:53 —-A—- C:\Windows\system32\winipsec.dll
2008-12-02 04:00:53 —-A—- C:\Windows\system32\polstore.dll
2008-12-02 04:00:53 —-A—- C:\Windows\system32\IPSECSVC.DLL
2008-12-02 04:00:53 —-A—- C:\Windows\system32\FwRemoteSvr.dll
2008-12-02 04:00:04 —-A—- C:\Windows\system32\riched32.dll
2008-12-02 04:00:04 —-A—- C:\Windows\system32\riched20.dll
2008-12-02 04:00:02 —-A—- C:\Windows\system32\rasser.dll
2008-12-02 04:00:02 —-A—- C:\Windows\system32\rasmxs.dll
2008-12-02 04:00:02 —-A—- C:\Windows\system32\rasdiag.dll
2008-12-02 04:00:02 —-A—- C:\Windows\system32\rascfg.dll
2008-12-02 04:00:01 —-A—- C:\Windows\system32\netcfgx.dll
2008-12-02 04:00:01 —-A—- C:\Windows\system32\msftedit.dll
2008-12-02 04:00:01 —-A—- C:\Windows\system32\icsunattend.exe
2008-12-02 04:00:00 —-A—- C:\Windows\system32\wshqos.dll
2008-12-02 04:00:00 —-A—- C:\Windows\system32\traffic.dll
2008-12-02 04:00:00 —-A—- C:\Windows\system32\ipnathlp.dll
2008-12-02 03:59:59 —-A—- C:\Windows\system32\pacerprf.dll
2008-12-02 03:59:59 —-A—- C:\Windows\system32\localspl.dll
2008-12-02 03:59:59 —-A—- C:\Windows\system32\dps.dll
2008-12-02 03:59:59 —-A—- C:\Windows\system32\cdd.dll
2008-12-02 03:59:14 —-A—- C:\Windows\system32\PortableDeviceTypes.dll
2008-12-02 03:59:14 —-A—- C:\Windows\system32\PortableDeviceClassExtension.dll
2008-12-02 03:59:14 —-A—- C:\Windows\system32\PortableDeviceApi.dll
2008-12-02 03:58:26 —-A—- C:\Windows\system32\Apphlpdm.dll
2008-12-02 03:58:24 —-A—- C:\Windows\system32\GameUXLegacyGDFs.dll
2008-12-02 03:58:24 —-A—- C:\Windows\system32\gameux.dll
2008-12-02 03:57:31 —-A—- C:\Windows\system32\msoert2.dll
2008-12-02 03:57:31 —-A—- C:\Windows\system32\msoeacct.dll
2008-12-02 03:57:31 —-A—- C:\Windows\system32\ACCTRES.dll
2008-12-02 03:56:39 —-A—- C:\Windows\system32\wtsapi32.dll
2008-12-02 03:56:37 —-A—- C:\Windows\explorer.exe
2008-12-02 03:56:36 —-A—- C:\Windows\system32\sysmain.dll
2008-12-02 03:56:34 —-A—- C:\Windows\system32\wlansvc.dll
2008-12-02 03:56:34 —-A—- C:\Windows\system32\wlansec.dll
2008-12-02 03:56:34 —-A—- C:\Windows\system32\wlanmsm.dll
2008-12-02 03:56:34 —-A—- C:\Windows\system32\wlanhlp.dll
2008-12-02 03:56:34 —-A—- C:\Windows\system32\wlanapi.dll
2008-12-02 03:55:50 —-A—- C:\Windows\system32\WebClnt.dll
2008-12-02 03:53:51 —-A—- C:\Windows\system32\csrsrv.dll
2008-12-02 03:53:50 —-A—- C:\Windows\system32\winsrv.dll
2008-12-02 03:51:51 —-A—- C:\Windows\system32\shell32.dll
2008-12-02 03:42:18 —-D—- C:\Windows\system32\x64
2008-12-02 03:42:18 —-A—- C:\Windows\system32\igxpun.exe
2008-12-02 03:42:17 —-A—- C:\Windows\system32\difxapi.dll
2008-12-02 03:40:52 —-A—- C:\Windows\system32\tzres.dll
2008-12-02 03:39:52 —-A—- C:\Windows\system32\mcupdate_GenuineIntel.dll
2008-12-02 03:38:28 —-A—- C:\Windows\system32\wmpeffects.dll
2008-12-02 03:37:13 —-A—- C:\Windows\system32\msxml3r.dll
2008-12-02 03:37:13 —-A—- C:\Windows\system32\msxml3.dll
2008-12-02 03:36:34 —-A—- C:\Windows\system32\msscp.dll
2008-12-02 03:35:56 —-A—- C:\Windows\system32\wmploc.DLL
2008-12-02 03:35:55 —-A—- C:\Windows\system32\wmp.dll
2008-12-02 03:35:55 —-A—- C:\Windows\system32\spwmp.dll
2008-12-02 03:35:54 —-A—- C:\Windows\system32\MediaMetadataHandler.dll
2008-12-02 03:35:54 —-A—- C:\Windows\system32\dxmasf.dll
2008-12-02 03:35:15 —-A—- C:\Windows\system32\FirewallAPI.dll
2008-12-02 03:35:14 —-A—- C:\Windows\system32\wfapigp.dll
2008-12-02 03:35:14 —-A—- C:\Windows\system32\MPSSVC.dll
2008-12-02 03:35:14 —-A—- C:\Windows\system32\icfupgd.dll
2008-12-02 03:35:14 —-A—- C:\Windows\system32\cmifw.dll
2008-12-02 03:35:13 —-A—- C:\Windows\system32\iphlpsvc.dll
2008-12-02 03:34:39 —-A—- C:\Windows\system32\netapi32.dll
2008-12-02 03:32:50 —-A—- C:\Windows\system32\DWWIN.EXE
2008-12-02 03:31:45 —-A—- C:\Windows\system32\hcrstco.dll
2008-12-02 03:31:45 —-A—- C:\Windows\system32\hccoin.dll
2008-12-02 03:30:39 —-A—- C:\Windows\system32\netcfg.exe
2008-12-02 03:30:38 —-A—- C:\Windows\system32\tcpipcfg.dll
2008-12-02 03:30:38 —-A—- C:\Windows\system32\netiougc.exe
2008-12-02 03:30:04 —-A—- C:\Windows\system32\NlsLexicons0049.dll
2008-12-02 03:30:04 —-A—- C:\Windows\system32\NlsLexicons0047.dll
2008-12-02 03:30:04 —-A—- C:\Windows\system32\NlsLexicons0046.dll
2008-12-02 03:30:04 —-A—- C:\Windows\system32\NlsLexicons0045.dll
2008-12-02 03:30:04 —-A—- C:\Windows\system32\NlsLexicons0020.dll
2008-12-02 03:30:03 —-A—- C:\Windows\system32\NlsLexicons0039.dll
2008-12-02 03:30:03 —-A—- C:\Windows\system32\NlsLexicons0022.dll
2008-12-02 03:30:03 —-A—- C:\Windows\system32\NlsLexicons0021.dll
2008-12-02 03:30:02 —-A—- C:\Windows\system32\NlsLexicons0026.dll
2008-12-02 03:30:02 —-A—- C:\Windows\system32\NlsLexicons0024.dll
2008-12-02 03:30:01 —-A—- C:\Windows\system32\NlsLexicons0027.dll
2008-12-02 03:29:58 —-A—- C:\Windows\system32\NlsLexicons0010.dll
2008-12-02 03:29:57 —-A—- C:\Windows\system32\NlsLexicons0013.dll
2008-12-02 03:29:57 —-A—- C:\Windows\system32\NlsLexicons0011.dll
2008-12-02 03:29:56 —-A—- C:\Windows\system32\NlsLexicons0019.dll
2008-12-02 03:29:56 —-A—- C:\Windows\system32\NlsLexicons0018.dll
2008-12-02 03:29:56 —-A—- C:\Windows\system32\NlsLexicons0001.dll
2008-12-02 03:29:55 —-A—- C:\Windows\system32\NlsLexicons0003.dll
2008-12-02 03:29:55 —-A—- C:\Windows\system32\NlsLexicons0002.dll
2008-12-02 03:29:54 —-A—- C:\Windows\system32\NlsLexicons004b.dll
2008-12-02 03:29:54 —-A—- C:\Windows\system32\NlsLexicons004a.dll
2008-12-02 03:29:54 —-A—- C:\Windows\system32\NlsLexicons0009.dll
2008-12-02 03:29:54 —-A—- C:\Windows\system32\NlsLexicons0007.dll
2008-12-02 03:29:53 —-A—- C:\Windows\system32\NlsLexicons004e.dll
2008-12-02 03:29:53 —-A—- C:\Windows\system32\NlsLexicons004c.dll
2008-12-02 03:29:53 —-A—- C:\Windows\system32\NlsLexicons003e.dll
2008-12-02 03:29:53 —-A—- C:\Windows\system32\NlsLexicons002a.dll
2008-12-02 03:29:52 —-A—- C:\Windows\system32\NlsLexicons001b.dll
2008-12-02 03:29:52 —-A—- C:\Windows\system32\NlsLexicons001a.dll
2008-12-02 03:29:51 —-A—- C:\Windows\system32\NlsLexicons001d.dll
2008-12-02 03:29:51 —-A—- C:\Windows\system32\NlsLexicons000a.dll
2008-12-02 03:29:50 —-A—- C:\Windows\system32\NlsLexicons000d.dll
2008-12-02 03:29:50 —-A—- C:\Windows\system32\NlsLexicons000c.dll
2008-12-02 03:29:49 —-A—- C:\Windows\system32\NlsLexicons0816.dll
2008-12-02 03:29:49 —-A—- C:\Windows\system32\NlsLexicons0416.dll
2008-12-02 03:29:49 —-A—- C:\Windows\system32\NlsLexicons0414.dll
2008-12-02 03:29:49 —-A—- C:\Windows\system32\NlsLexicons000f.dll
2008-12-02 03:29:48 —-A—- C:\Windows\system32\NlsLexicons081a.dll
2008-12-02 03:29:47 —-A—- C:\Windows\system32\NlsModels0011.dll
2008-12-02 03:29:47 —-A—- C:\Windows\system32\NlsData0047.dll
2008-12-02 03:29:47 —-A—- C:\Windows\system32\NlsData0046.dll
2008-12-02 03:29:47 —-A—- C:\Windows\system32\NlsData0045.dll
2008-12-02 03:29:46 —-A—- C:\Windows\system32\NlsData0049.dll
2008-12-02 03:29:46 —-A—- C:\Windows\system32\NlsData0039.dll
2008-12-02 03:29:46 —-A—- C:\Windows\system32\NlsData0021.dll
2008-12-02 03:29:46 —-A—- C:\Windows\system32\NlsData0020.dll
2008-12-02 03:29:45 —-A—- C:\Windows\system32\NlsData0027.dll
2008-12-02 03:29:45 —-A—- C:\Windows\system32\NlsData0026.dll
2008-12-02 03:29:45 —-A—- C:\Windows\system32\NlsData0024.dll
2008-12-02 03:29:45 —-A—- C:\Windows\system32\NlsData0022.dll
2008-12-02 03:29:45 —-A—- C:\Windows\system32\NlsData0010.dll
2008-12-02 03:29:44 —-A—- C:\Windows\system32\NlsData0019.dll
2008-12-02 03:29:44 —-A—- C:\Windows\system32\NlsData0018.dll
2008-12-02 03:29:44 —-A—- C:\Windows\system32\NlsData0013.dll
2008-12-02 03:29:44 —-A—- C:\Windows\system32\NlsData0011.dll
2008-12-02 03:29:44 —-A—- C:\Windows\system32\NlsData0000.dll
2008-12-02 03:29:43 —-A—- C:\Windows\system32\NlsData0007.dll
2008-12-02 03:29:43 —-A—- C:\Windows\system32\NlsData0003.dll
2008-12-02 03:29:43 —-A—- C:\Windows\system32\NlsData0002.dll
2008-12-02 03:29:43 —-A—- C:\Windows\system32\NlsData0001.dll
2008-12-02 03:29:42 —-A—- C:\Windows\system32\NlsData004b.dll
2008-12-02 03:29:42 —-A—- C:\Windows\system32\NlsData004a.dll
2008-12-02 03:29:42 —-A—- C:\Windows\system32\NlsData0009.dll
2008-12-02 03:29:41 —-A—- C:\Windows\system32\NlsData004e.dll
2008-12-02 03:29:41 —-A—- C:\Windows\system32\NlsData004c.dll
2008-12-02 03:29:41 —-A—- C:\Windows\system32\NlsData003e.dll
2008-12-02 03:29:41 —-A—- C:\Windows\system32\NlsData002a.dll
2008-12-02 03:29:40 —-A—- C:\Windows\system32\NlsData001d.dll
2008-12-02 03:29:40 —-A—- C:\Windows\system32\NlsData001b.dll
2008-12-02 03:29:40 —-A—- C:\Windows\system32\NlsData001a.dll
2008-12-02 03:29:39 —-A—- C:\Windows\system32\NlsData000f.dll
2008-12-02 03:29:39 —-A—- C:\Windows\system32\NlsData000d.dll
2008-12-02 03:29:39 —-A—- C:\Windows\system32\NlsData000c.dll
2008-12-02 03:29:39 —-A—- C:\Windows\system32\NlsData000a.dll
2008-12-02 03:29:38 —-A—- C:\Windows\system32\NlsData0816.dll
2008-12-02 03:29:38 —-A—- C:\Windows\system32\NlsData0416.dll
2008-12-02 03:29:38 —-A—- C:\Windows\system32\NlsData0414.dll
2008-12-02 03:29:38 —-A—- C:\Windows\system32\NaturalLanguage6.dll
2008-12-02 03:29:37 —-A—- C:\Windows\system32\NlsLexicons0c1a.dll
2008-12-02 03:29:37 —-A—- C:\Windows\system32\NlsData0c1a.dll
2008-12-02 03:29:37 —-A—- C:\Windows\system32\NlsData081a.dll
2008-12-02 03:26:39 —-A—- C:\Windows\system32\setupapi.dll
2008-12-02 03:26:11 —-A—- C:\Windows\system32\wpd_ci.dll
2008-12-02 03:26:11 —-A—- C:\Windows\system32\srdelayed.exe
2008-12-02 03:26:11 —-A—- C:\Windows\system32\srcore.dll
2008-12-02 03:26:11 —-A—- C:\Windows\system32\srclient.dll
2008-12-02 03:26:11 —-A—- C:\Windows\system32\rstrui.exe
2008-12-02 03:26:10 —-A—- C:\Windows\system32\winresume.exe
2008-12-02 03:26:10 —-A—- C:\Windows\system32\winload.exe
2008-12-02 03:26:10 —-A—- C:\Windows\system32\kd1394.dll
2008-12-02 03:26:10 —-A—- C:\Windows\system32\ci.dll
2008-12-02 03:26:09 —-A—- C:\Windows\system32\umpnpmgr.dll
2008-12-02 03:26:09 —-A—- C:\Windows\system32\nshhttp.dll
2008-12-02 03:26:09 —-A—- C:\Windows\system32\kbd106n.dll
2008-12-02 03:26:09 —-A—- C:\Windows\system32\drvinst.exe
2008-12-02 03:26:09 —-A—- C:\Windows\system32\dpx.dll
2008-12-02 03:26:09 —-A—- C:\Windows\system32\cfgmgr32.dll
2008-12-02 03:26:08 —-A—- C:\Windows\system32\unlodctr.exe
2008-12-02 03:26:08 —-A—- C:\Windows\system32\prflbmsg.dll
2008-12-02 03:26:08 —-A—- C:\Windows\system32\oleaut32.dll
2008-12-02 03:26:08 —-A—- C:\Windows\system32\lodctr.exe
2008-12-02 03:26:08 —-A—- C:\Windows\system32\loadperf.dll
2008-12-02 03:26:07 —-A—- C:\Windows\system32\schedsvc.dll
2008-12-02 03:26:06 —-A—- C:\Windows\system32\f3ahvoas.dll
2008-12-02 03:26:06 —-A—- C:\Windows\system32\dispci.dll
2008-12-02 03:26:06 —-A—- C:\Windows\system32\batt.dll
2008-12-02 03:24:30 —-D—- C:\Program Files\CONEXANT
2008-12-02 03:23:23 —-A—- C:\Windows\system32\WMASF.DLL
2008-12-02 03:23:23 —-A—- C:\Windows\system32\LAPRXY.DLL
2008-12-02 03:23:23 —-A—- C:\Windows\system32\asferror.dll
2008-12-02 03:22:24 —-A—- C:\Windows\system32\gdi32.dll
2008-12-02 03:21:50 —-A—- C:\Windows\system32\slwmi.dll
2008-12-02 03:21:50 —-A—- C:\Windows\system32\SLC.dll
2008-12-02 03:21:50 —-A—- C:\Windows\system32\mcbuilder.exe
2008-12-02 03:21:49 —-A—- C:\Windows\system32\SLUINotify.dll
2008-12-02 03:21:49 —-A—- C:\Windows\system32\SLUI.exe
2008-12-02 03:21:49 —-A—- C:\Windows\system32\SLLUA.exe
2008-12-02 03:21:49 —-A—- C:\Windows\system32\SLCommDlg.dll
2008-12-02 03:21:48 —-A—- C:\Windows\system32\SLsvc.exe
2008-12-02 03:21:48 —-A—- C:\Windows\system32\slcinst.dll
2008-12-02 03:21:10 —-A—- C:\Windows\system32\WindowsCodecs.dll
2008-12-02 03:21:10 —-A—- C:\Windows\system32\PhotoMetadataHandler.dll
2008-12-02 03:21:09 —-A—- C:\Windows\system32\WindowsCodecsExt.dll
2008-12-02 03:19:56 —-A—- C:\Windows\system32\schannel.dll
2008-12-02 03:19:55 —-A—- C:\Windows\system32\ntprint.exe
2008-12-02 03:19:55 —-A—- C:\Windows\system32\ntprint.dll
2008-12-02 03:19:54 —-A—- C:\Windows\system32\dhcpcsvc6.dll
2008-12-02 03:19:54 —-A—- C:\Windows\system32\dhcpcsvc.dll
2008-12-02 03:19:54 —-A—- C:\Windows\system32\dhcpcmonitor.dll
2008-12-02 03:19:54 —-A—- C:\Windows\system32\authui.dll
2008-12-02 03:19:53 —-A—- C:\Windows\system32\msvfw32.dll
2008-12-02 03:19:53 —-A—- C:\Windows\system32\mciavi32.dll
2008-12-02 03:19:53 —-A—- C:\Windows\system32\avicap32.dll
2008-12-02 03:19:52 —-A—- C:\Windows\system32\sendmail.dll
2008-12-02 03:19:52 —-A—- C:\Windows\system32\msvidc32.dll
2008-12-02 03:19:52 —-A—- C:\Windows\system32\msrle32.dll
2008-12-02 03:19:52 —-A—- C:\Windows\system32\avifil32.dll
2008-12-02 03:19:19 —-A—- C:\Windows\system32\win32spl.dll
2008-12-02 03:19:19 —-A—- C:\Windows\system32\printcom.dll
2008-12-02 03:18:57 —-A—- C:\Windows\system32\wshrm.dll
2008-12-02 03:18:34 —-A—- C:\Windows\system32\sbunattend.exe
2008-12-02 03:17:54 —-A—- C:\Windows\system32\dnsrslvr.dll
2008-12-02 03:17:54 —-A—- C:\Windows\system32\dnscacheugc.exe
2008-12-02 03:17:54 —-A—- C:\Windows\system32\dnsapi.dll
2008-12-02 03:17:02 —-A—- C:\Windows\system32\rpcrt4.dll
2008-12-02 03:16:27 —-A—- C:\Windows\system32\INETRES.dll
2008-12-02 03:16:27 —-A—- C:\Windows\system32\inetcomm.dll
2008-12-02 03:16:05 —-A—- C:\Windows\system32\connect.dll
2008-12-02 03:15:43 —-A—- C:\Windows\system32\wmi.dll
2008-12-02 03:15:43 —-A—- C:\Windows\system32\imagehlp.dll
2008-12-02 03:15:21 —-A—- C:\Windows\system32\quartz.dll
2008-12-02 03:14:25 —-A—- C:\Windows\system32\crypt32.dll
2008-12-02 03:13:51 —-A—- C:\Windows\system32\ntoskrnl.exe
2008-12-02 03:13:51 —-A—- C:\Windows\system32\ntkrnlpa.exe
2008-12-02 03:13:32 —-A—- C:\Windows\system32\user32.dll
2008-12-02 03:13:14 —-A—- C:\Windows\system32\msxml6r.dll
2008-12-02 03:13:14 —-A—- C:\Windows\system32\msxml6.dll
2008-12-02 03:12:19 —-A—- C:\Windows\system32\advpack.dll
2008-12-02 03:12:18 —-A—- C:\Windows\system32\wininet.dll
2008-12-02 03:12:18 —-A—- C:\Windows\system32\jsproxy.dll
2008-12-02 03:12:18 —-A—- C:\Windows\system32\ieapfltr.dll
2008-12-02 03:12:17 —-A—- C:\Windows\system32\dxtrans.dll
2008-12-02 03:12:17 —-A—- C:\Windows\system32\dxtmsft.dll
2008-12-02 03:12:15 —-A—- C:\Windows\system32\ieui.dll
2008-12-02 03:12:14 —-A—- C:\Windows\system32\ieframe.dll
2008-12-02 03:12:13 —-A—- C:\Windows\system32\mshtmled.dll
2008-12-02 03:12:12 —-A—- C:\Windows\system32\mshtml.dll
2008-12-02 03:12:10 —-A—- C:\Windows\system32\mstime.dll
2008-12-02 03:12:10 —-A—- C:\Windows\system32\icardie.dll
2008-12-02 03:12:08 —-A—- C:\Windows\system32\ieUnatt.exe
2008-12-02 03:12:07 —-A—- C:\Windows\system32\urlmon.dll
2008-12-02 03:12:07 —-A—- C:\Windows\system32\pngfilt.dll
2008-12-02 03:12:06 —-A—- C:\Windows\system32\iesetup.dll
2008-12-02 03:12:06 —-A—- C:\Windows\system32\iertutil.dll
2008-12-02 03:12:06 —-A—- C:\Windows\system32\iernonce.dll
2008-12-02 03:12:06 —-A—- C:\Windows\system32\ie4uinit.exe
2008-12-02 03:11:01 —-A—- C:\Windows\system32\qmgr.dll
2008-12-02 02:39:23 —-D—- C:\Users\desktop\AppData\Roaming\Identities
2008-12-02 02:39:04 —-SD—- C:\Users\desktop\AppData\Roaming\Microsoft

======List of files/folders modified in the last 1 months======

2008-12-06 16:19:01 —-D—- C:\Windows\Temp
2008-12-06 16:12:18 —-D—- C:\Windows\System32
2008-12-06 16:12:18 —-D—- C:\Windows\inf
2008-12-06 16:12:18 —-A—- C:\Windows\system32\PerfStringBackup.INI
2008-12-06 02:49:51 —-SHD—- C:\System Volume Information
2008-12-06 02:41:43 —-RD—- C:\Program Files
2008-12-06 02:41:41 —-D—- C:\Windows\system32\drivers
2008-12-06 02:40:40 —-D—- C:\Windows
2008-12-06 02:40:04 —-HD—- C:\Config.Msi
2008-12-06 02:40:04 —-D—- C:\Program Files\MSN
2008-12-06 02:10:32 —-D—- C:\Windows\system32\WDI
2008-12-05 22:55:01 —-SD—- C:\Windows\Downloaded Program Files
2008-12-05 04:03:00 —-D—- C:\Program Files\Common Files
2008-12-04 03:55:58 —-D—- C:\Windows\system32\NDF
2008-12-04 03:21:12 —-D—- C:\Windows\winsxs
2008-12-04 00:53:20 —-D—- C:\Windows\system32\catroot2
2008-12-04 00:53:20 —-D—- C:\Windows\system32\catroot
2008-12-03 22:31:33 —-HD—- C:\ProgramData
2008-12-03 05:22:36 —-D—- C:\Windows\system32\CodeIntegrity
2008-12-03 05:13:02 —-D—- C:\Windows\servicing
2008-12-03 05:11:34 —-SHD—- C:\Boot
2008-12-03 02:46:23 —-SD—- C:\ProgramData\Microsoft
2008-12-03 00:09:46 —-D—- C:\Program Files\Common Files\microsoft shared
2008-12-02 23:39:57 —-D—- C:\Windows\rescache
2008-12-02 23:37:11 —-D—- C:\Windows\system32\en-US
2008-12-02 23:26:02 —-D—- C:\Windows\Registration
2008-12-02 23:24:20 —-D—- C:\Program Files\Internet Explorer
2008-12-02 05:21:19 —-RSD—- C:\Windows\assembly
2008-12-02 04:34:30 —-D—- C:\Windows\Microsoft.NET
2008-12-02 04:32:41 —-ASH—- C:\Program Files\desktop.ini
2008-12-02 04:27:05 —-D—- C:\Windows\system32\ras
2008-12-02 04:27:05 —-D—- C:\Windows\system32\icsxml
2008-12-02 04:27:05 —-D—- C:\Program Files\Windows Calendar
2008-12-02 04:27:03 —-D—- C:\Windows\system32\XPSViewer
2008-12-02 04:27:03 —-D—- C:\Windows\system32\wbem
2008-12-02 04:27:03 —-D—- C:\Windows\AppPatch
2008-12-02 04:27:03 —-D—- C:\Program Files\Windows Mail
2008-12-02 04:27:03 —-D—- C:\Program Files\Common Files\System
2008-12-02 04:27:02 —-D—- C:\Program Files\Windows Defender
2008-12-02 04:27:01 —-D—- C:\Program Files\Windows Media Player
2008-12-02 04:26:59 —-D—- C:\Windows\system32\migration
2008-12-02 04:26:54 —-D—- C:\Windows\system32\SLUI
2008-12-02 04:26:52 —-D—- C:\Program Files\Windows Sidebar
2008-12-02 02:45:21 —-D—- C:\Windows\Logs
2008-12-02 02:44:30 —-D—- C:\Windows\system32\LogFiles
2008-12-02 02:39:42 —-SHD—- C:\$Recycle.Bin
2008-12-02 02:38:53 —-RD—- C:\Users
2008-12-02 02:30:06 —-D—- C:\Windows\system32\restore

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 BHDrvx86;Symantec Heuristics Driver; \??\C:\Windows\system32\drivers\NAV\1001000.021\BHDrvx86.sys [2008-12-03 255536]
R1 ccHP;Symantec Hash Provider; \??\C:\Windows\system32\drivers\NAV\1001000.021\ccHPx86.sys [2008-12-03 362544]
R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [2008-12-03 371248]
R1 IDSVix86;IDSVix86; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20081203.001\IDSvix86.sys [2008-12-03 289840]
R1 SRTSPX;Symantec Real Time Storage Protection (PEL); \??\C:\Windows\system32\drivers\NAV\1001000.021\SRTSPX.SYS [2008-12-03 43696]
R1 SymIM;Symantec Network Security Intermediate Filter Driver; C:\Windows\system32\DRIVERS\SymIMv.sys [2008-12-03 25136]
R1 SYMTDI;SYMTDI; \??\C:\Windows\system32\drivers\NAV\1001000.021\SYMTDI.SYS [2008-12-03 198192]
R2 mdmxsdk;mdmxsdk; C:\Windows\system32\DRIVERS\mdmxsdk.sys [2006-06-19 12672]
R2 XAudio;XAudio; C:\Windows\system32\DRIVERS\xaudio.sys [2007-06-29 8704]
R3 E100B;Intel® PRO Adapter Driver; C:\Windows\system32\DRIVERS\e100b325.sys [2006-11-02 163328]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-12-03 99376]
R3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
R3 HSF_DPV;HSF_DPV; C:\Windows\system32\DRIVERS\HSX_DPV.sys [2007-06-20 984064]
R3 HSXHWBS2;HSXHWBS2; C:\Windows\system32\DRIVERS\HSXHWBS2.sys [2007-06-20 267264]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-01-02 2016256]
R3 NAVENG;NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20081206.003\NAVENG.SYS [2008-12-03 89104]
R3 NAVEX15;NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20081206.003\NAVEX15.SYS [2008-12-03 876112]
R3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2008-12-02 47360]
R3 SRTSP;Symantec Real Time Storage Protection; \??\C:\Windows\system32\drivers\NAV\1001000.021\SRTSP.SYS [2008-12-03 306736]
R3 SYMDNS;SYMDNS; \??\C:\Windows\system32\drivers\NAV\1001000.021\SYMDNS.SYS [2008-12-03 12976]
R3 SymEvent;SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT.SYS [2008-12-03 124464]
R3 SYMFW;SYMFW; \??\C:\Windows\system32\drivers\NAV\1001000.021\SYMFW.SYS [2008-12-03 89904]
R3 SYMNDISV;SYMNDISV; \??\C:\Windows\system32\drivers\NAV\1001000.021\SYMNDISV.SYS [2008-12-03 40496]
R3 SYMREDRV;SYMREDRV; \??\C:\Windows\system32\drivers\NAV\1001000.021\SYMREDRV.SYS [2008-12-03 24752]
R3 winachsf;winachsf; C:\Windows\system32\DRIVERS\HSX_CNXT.sys [2007-06-20 660480]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2006-11-02 82560]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2006-11-02 5632]
S3 ialm;ialm; C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-01-02 2016256]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2006-11-02 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2006-11-02 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2006-11-02 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2006-11-02 6016]
S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys [2006-11-02 11264]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 hpqddsvc;HP CUE DeviceDiscovery Service; C:\Windows\system32\svchost.exe [2006-11-02 22016]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2008-09-30 935208]
R2 Norton AntiVirus;Norton AntiVirus; C:\Program Files\Norton AntiVirus\Engine\16.1.0.33\ccSvcHst.exe [2008-12-03 115560]
R2 XAudioService;XAudioService; C:\Windows\system32\DRIVERS\xaudio.exe [2007-06-29 386560]
R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2006-11-02 22016]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-12-02 138168]

—————–EOF—————–
info.txt logfile of random's system information tool 1.04 2008-12-06 16:19:56 ======Uninstall list====== –>C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0 Adobe AIR–>C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Updater.exe -arp:uninstall Adobe AIR–>MsiExec.exe /I{00203668-8170-44A0-BE44-B632FA4D780F} Adobe Flash Player 10 ActiveX–>C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe Adobe Reader 9–>MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A90000000001} DVDFab (Platinum/Gold/HD Decrypter) (Option: Mobile) 5.1.0.0–>"C:\Program Files\DVDFab 5\unins000.exe" Google Toolbar for Internet Explorer–>MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29} Google Toolbar for Internet Explorer–>regsvr32 /u /s "c:\program files\google\googletoolbar1.dll" HijackThis 2.0.2–>"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall HP Customer Participation Program 9.0–>C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat HP Deskjet Printer Driver Software 9.0–>C:\Program Files\HP\Digital Imaging\{03E66394-42F0-4745-85F7-0A2F8F35C09F}\setup\hpzscr01.exe -datfile hphscr15.dat -showdisconnect -forcereboot HP Imaging Device Functions 9.0–>C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat HP Photosmart Essential 2.01–>C:\Program Files\HP\Digital Imaging\PhotoSmartEssential\hpzscr01.exe -datfile hpqbud13.dat HP Smart Web Printing–>MsiExec.exe /X{415CDA53-9100-476F-A7B2-476691E117C7} HP Solution Center 9.0–>C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat HP Update–>MsiExec.exe /X{AB40272D-92AB-4F30-B36B-22EDE16F8FE5} HPSSupply–>MsiExec.exe /X{487B0B9B-DCD4-440D-89A0-A6EDE1A545A3} Intel® Graphics Media Accelerator Driver–>C:\Windows\system32\igxpun.exe -uninstall Java™ 6 Update 11–>MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF} Malwarebytes' Anti-Malware–>"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe" Microsoft .NET Framework 1.1 Hotfix (KB929729)–>"C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\M929729\M929729Uninstall.msp" Microsoft .NET Framework 1.1–>msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} Microsoft .NET Framework 1.1–>MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} Microsoft Visual C++ 2005 Redistributable–>MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d} MSXML 4.0 SP2 (KB954430)–>MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71} Nero 9–>C:\Program Files\Common Files\Nero\Nero ProductInstaller 4\SetupX.exe REMOVESERIALNUMBER="9M03-01A1-PCX7-K31A-8A94-98PT-KT2E-522A" neroxml–>MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B} Norton AntiVirus–>C:\Program Files\NortonInstaller\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV\562C4DD5\16.1.0.33\InstStub.exe /X RealPlayer–>C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0 Soft Data Fax Modem with SmartCP–>C:\Program Files\CONEXANT\CNXT_MODEM_PCI_HSF\UIU32m.exe -U -I*.INF Voobys–>MsiExec.exe /I{B72257D6-189D-4CB0-9CDC-26A93536C34B} WinRAR archiver–>C:\Program Files\WinRAR\uninstall.exe ======Hosts File====== 127.0.0.1 localhost ======Security center information====== AV: Norton AntiVirus AS: Windows Defender (disabled) AS: Norton AntiVirus ======Environment variables====== "ComSpec"=%SystemRoot%\system32\cmd.exe "FP_NO_HOST_CHECK"=NO "OS"=Windows_NT "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC "PROCESSOR_ARCHITECTURE"=x86 "TEMP"=%SystemRoot%\TEMP "TMP"=%SystemRoot%\TEMP "USERNAME"=SYSTEM "windir"=%SystemRoot% "PROCESSOR_LEVEL"=15 "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 6 Stepping 4, GenuineIntel "PROCESSOR_REVISION"=0604 "NUMBER_OF_PROCESSORS"=1 —————–EOF—————–

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI