Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie
Hi there,
There is an issue with role permissions that is being worked on at the moment.
If you are having trouble with access or permissions on regional forums please post here to get access: https://www.boards.ie/discussion/2058365403/you-do-not-have-permission-for-that#latest

Spyware detected -- lphc3 and bphc3 files

  • 06-10-2008 7:41pm
    #1
    Closed Accounts Posts: 11


    Hi,

    I was downloading software and a message appeared up saying Spyware detected please run antivirus software on the screen. This did not look like any Windows message so I knew straight away to be careful. Every few minutes I was prompted to install Windows Spyware software but I said no. I tried looking up the error message but lots of sites were blocked.

    I have AVG and CCleaner installed so I ran these but no problem was reported. I eventually managed to donwload and install XoftSpy and this identified 4 files, one an exe, under C:\Windows\system32 that were infected. It however was not able to remove them. I tried to manually delete them but it said I did not have permission as the exe was running. I hit CTRL-ALT-DEL to access Task Manager but it said I did not have permission to run it -- although I am the admin on the system. Eventually I downloaded MalwareBytes and ran that. It managed to find a lot more and remove most of them. However when I still run it the program finds 5 Trojans some of which it identifies as "Remove on reboot" but never removes when I restart.

    I have downloaded HijackThis and gotten the following log:

    Logfile of HijackThis v1.99.1
    Scan saved at 18:40:49, on 06/10/2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16705)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\WINDOWS\System32\CTsvcCDA.exe
    C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\BCMSMMSG.exe
    C:\WINDOWS\System32\DSentry.exe
    C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
    C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
    C:\Program Files\Common Files\Dell\EUSW\Support.exe
    C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
    C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
    C:\Program Files\Logitech\QuickCam\Quickcam.exe
    C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
    C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\PROGRA~1\AVG\AVG8\avgtray.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    C:\Program Files\Digital Line Detect\DLG.exe
    C:\Program Files\FinePixViewer\QuickDCF2.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\WinZip\WZQKPICK.EXE
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\Common Files\Teleca Shared\Generic.exe
    C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Internet Explorer\Iexplore.exe
    C:\Program Files\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.ie
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: BitComet Helper - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.3.28.dll
    O2 - BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
    O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
    O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
    O4 - HKLM\..\Run: [BuildBU] c:\dell\bldbubg.exe
    O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
    O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
    O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
    O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes\mbam.exe" /runcleanupscript
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    O4 - Global Startup: Digital Line Detect.lnk = ?
    O4 - Global Startup: ExifLauncher2.lnk = C:\Program Files\FinePixViewer\QuickDCF2.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
    O11 - Options group: [INTERNATIONAL] International*
    O14 - IERESET.INF: START_PAGE_URL=http://www.eircom.net
    O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} - http://www.may.ie/wfplayer/tdserver.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1139944226076
    O16 - DPF: {6F750203-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/BUM_WIN_IE_2/axofupld.cab
    O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
    O20 - AppInit_DLLs: avgrsstx.dll
    O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
    O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
    O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
    O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
    O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
    O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Oracle OLAP 9.0.1.0.1 (OLAPServer) - Oracle Corporation - C:\oracle\ora90\bin\xsolap.exe
    O23 - Service: Oracle OLAP Agent - Unknown owner - C:\oracle\ora90\bin\xsaagent.exe
    O23 - Service: OracleOraHome90PagingServer - Unknown owner - C:\oracle\ora90/bin/pagntsrv.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Sony SCSI Helper Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\Fsk\SonySCSIHelperService.exe
    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe


    Can you please advise on what I should do next.

    Thanks for all your help.

    Much appreciated.

    Tom


Comments

  • Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


    Hello
    • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
    • Double click on RSIT.exe to run RSIT.
    • Click Continue at the disclaimer screen.
    • Once it has finished, two logs will open. Please post the contents of both log.txt (<<will be maximized) and info.txt (<<will be minimized)


  • Closed Accounts Posts: 11 toddyl


    Hi ActorSeeksJob,

    Did what you said.

    ##################################################
    Ouput of info.txt is:
    ##################################################

    info.txt logfile of random's system information tool 1.04 2008-10-07 22:19:17

    ======Uninstall list======

    -->"C:\Program Files\Creative\SBLive\Program\Ctzapxx.EXE" /X /U /S /R
    -->C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu
    -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{435E969D-867E-4364-8E74-3DC8A69C5BDB}\setup.exe" -l0x9
    -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{435E969D-867E-4364-8E74-3DC8A69C5BDB}\setup.exe" -l0x9 /remove
    -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{44DC86A0-248D-11D6-9BAF-0090271AF8A4}\setup.exe" -l0x9
    -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{44DC86A0-248D-11D6-9BAF-0090271AF8A4}\setup.exe" -l0x9 /remove
    -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{48E3A9E6-FA13-11D5-8CC9-00A0C98192B6}\setup.exe" -l0x9
    -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{48E3A9E6-FA13-11D5-8CC9-00A0C98192B6}\setup.exe" -l0x9 /remove
    -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{51F5239C-197B-11D6-9BAF-0090271AF8A4}\setup.exe" -l0x9
    -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{51F5239C-197B-11D6-9BAF-0090271AF8A4}\setup.exe" -l0x9 /remove
    -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7052066D-7016-11D5-B89E-00B0D0D26B88}\setup.exe" UNINSTALL
    -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D54AAC0A-BE99-11D4-8FA4-00B0D02D2438}\setup.exe" UNINSTALL
    -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E7337A45-3FE5-4392-ABBB-26B794D060C9}\setup.exe" -l0x9
    -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E7337A45-3FE5-4392-ABBB-26B794D060C9}\setup.exe" -l0x9 /remove
    -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F865C2FE-25E7-11D6-9BAF-0090271AF8A4}\setup.exe" -l0x9
    -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F865C2FE-25E7-11D6-9BAF-0090271AF8A4}\setup.exe" -l0x9 /remove
    -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0015-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0016-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0018-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0019-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001A-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001B-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {3EC77D26-799B-4CD8-914F-C1565E796173}
    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {430971B1-C31E-45DA-81E0-72C095BAB72C}
    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {F7A31780-33C4-4E39-951A-5EC9B91D7BF1}
    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0044-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {FAD8A83E-9BAC-4179-9268-A35948034D85}
    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-00A1-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-00BA-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0114-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0115-0409-0000-0000000FF1CE} /uninstall {FAD8A83E-9BAC-4179-9268-A35948034D85}
    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0117-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {BEE75E01-DD3F-4D5F-B96C-609E6538D419}
    Ad-Aware-->MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
    Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)-->MsiExec.exe /X{6846389C-BAC0-4374-808E-B120F86AF5D7}
    Adobe Flash Player 9 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
    Adobe Reader 8.1.2-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81200000003}
    Apple Mobile Device Support-->MsiExec.exe /I{AA9768AA-FF0B-4C66-A085-31E934F77841}
    Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
    AutoCAD 2000 Migration Assistance-->C:\WINDOWS\uninst.exe -f"C:\Program Files\ACAD2000\migration\DeIsL1.isu"
    AutoCAD 2000-->C:\WINDOWS\uninst.exe -fC:\PROGRA~1\ACAD2000\DeIsL1.isu -c"C:\PROGRA~1\ACAD2000\unacad.dll
    AVG Free 8.0-->C:\Program Files\AVG\AVG8\setup.exe /UNINSTALL
    AviSynth 2.5-->"C:\Program Files\AviSynth 2.5\Uninstall.exe"
    BCM V.92 56K Modem-->C:\WINDOWS\BCMSMU.exe quiet
    Bonjour-->MsiExec.exe /I{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}
    Canon Camera Access Library-->"C:\Program Files\Common Files\Canon\UIW\1.3.0.0\Uninst.exe" "C:\Program Files\Canon\CAL\Uninst.ini"
    Canon Camera Support Core Library-->"C:\Program Files\Common Files\Canon\UIW\1.3.0.0\Uninst.exe" "C:\Program Files\Canon\CSCLIB\Uninst.ini"
    Canon EOS Kiss REBEL 300D WIA Driver-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{31A57C3E-30DD-421F-B5C7-974DACB0D05F}
    Canon G.726 WMP-Decoder-->"C:\Program Files\Common Files\Canon\UIW\1.3.0.0\Uninst.exe" "C:\Program Files\Canon\G726Decoder\G726DecUnInstall.ini"
    Canon MovieEdit Task for ZoomBrowser EX-->"C:\Program Files\Common Files\Canon\UIW\1.3.0.0\Uninst.exe" "C:\Program Files\Canon\ZoomBrowser EX\Program\MVWUninst.ini"
    Canon RAW Image Task for ZoomBrowser EX-->"C:\Program Files\Common Files\Canon\UIW\1.3.0.0\Uninst.exe" "C:\Program Files\Canon\RAW Image Task\Uninst.ini"
    Canon Utilities CameraWindow DC_DV 5 for ZoomBrowser EX-->"C:\Program Files\Common Files\Canon\UIW\1.3.0.0\Uninst.exe" "C:\Program Files\Canon\CameraWindow\CameraWindowDVC\Uninst.ini"
    Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX-->"C:\Program Files\Common Files\Canon\UIW\1.3.0.0\Uninst.exe" "C:\Program Files\Canon\CameraWindow\CameraWindowDVC6\Uninst.ini"
    Canon Utilities CameraWindow DC-->"C:\Program Files\Common Files\Canon\UIW\1.3.0.0\Uninst.exe" "C:\Program Files\Canon\CameraWindow\CameraWindowDC\Uninst.ini"
    Canon Utilities CameraWindow-->"C:\Program Files\Common Files\Canon\UIW\1.3.0.0\Uninst.exe" "C:\Program Files\Canon\CameraWindow\CameraWindowLauncher\Uninst.ini"
    Canon Utilities EOS Utility-->"C:\Program Files\Common Files\Canon\UIW\1.2.0.0\Uninst.exe" "C:\Program Files\Canon\EOS Utility\Uninst.ini"
    Canon Utilities MyCamera DC-->"C:\Program Files\Common Files\Canon\UIW\1.3.0.0\Uninst.exe" "C:\Program Files\Canon\CameraWindow\MyCameraDC\Uninst.ini"
    Canon Utilities MyCamera-->"C:\Program Files\Common Files\Canon\UIW\1.3.0.0\Uninst.exe" "C:\Program Files\Canon\CameraWindow\MyCamera\Uninst.ini"
    Canon Utilities RemoteCapture DC-->"C:\Program Files\Common Files\Canon\UIW\1.3.0.0\Uninst.exe" "C:\Program Files\Canon\CameraWindow\RemoteCaptureDC\Uninst.ini"
    Canon Utilities RemoteCapture Task for ZoomBrowser EX-->"C:\Program Files\Common Files\Canon\UIW\1.3.0.0\Uninst.exe" "C:\Program Files\Canon\CameraWindow\RemoteCaptureTask DC\Uninst.ini"
    Canon Utilities ZoomBrowser EX-->"C:\Program Files\Common Files\Canon\UIW\1.3.0.0\Uninst.exe" "C:\Program Files\Canon\ZoomBrowser EX\Program\Uninst.ini"
    Canon ZoomBrowser EX Memory Card Utility-->"C:\Program Files\Common Files\Canon\UIW\1.3.0.0\Uninst.exe" "C:\Program Files\Canon\ZoomBrowser EX MCU\Uninst.ini"
    CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
    Classic PhoneTools-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E3436EE2-D5CB-4249-840B-3A0140CC34C3}\setup.exe" -l0x9 ControlPanel
    Codec Pack - All In 1 6.0.3.0-->C:\WINDOWS\iun6002.exe "C:\Program Files\Codec Pack - All In 1\irunin.ini"
    CopyTrans Suite (remove only)-->"C:\Program Files\CopyPod\uninstall.exe"
    Dell Picture Studio - Dell Image Expert-->MsiExec.exe /I{151C555A-A9E7-4A2E-B6D7-165D04A3C956}
    Dell Solution Center-->MsiExec.exe /X{11F1920A-56A2-4642-B6E0-3B31A12C9288}
    Dell Support-->MsiExec.exe /X{43FCA273-9534-40DB-B7C5-D7758875616A}
    devolo dLAN Configuration Wizard-->C:\Program Files\devolo\setup.exe /remove:dlanconf
    devolo EasyClean-->C:\Program Files\devolo\setup.exe /remove:easyclean
    devolo EasyShare-->C:\Program Files\devolo\setup.exe /remove:easyshare
    devolo Informer-->C:\Program Files\devolo\setup.exe /remove:dslmon
    Digital Line Detect-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E646DCF0-5A68-11D5-B229-002078017FBF}\setup.exe" -l0x9 ControlPanelAnyText
    DVDSentry-->MsiExec.exe /I{98DF85D9-96C0-4F57-A92E-C3539477EF5E}
    Easy CD Creator 5 Basic-->MsiExec.exe /I{609F7AC8-C510-11D4-A788-009027ABA5D0}
    eBook Library by Sony-->MsiExec.exe /X{A0EAB3BE-AC3F-4F9F-ACC0-ED1809B607E3}
    FinePix Studio-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E3B3AB03-8ABC-46CF-8CA9-DB5581E1F368}\SETUP.EXE" -l0x9
    FinePixViewer Resource-->C:\Program Files\InstallShield Installation Information\{B44529FF-501E-47CD-A06D-223C161BE058}\SETUP.EXE -runfromtemp -l0x0009 -removeonly
    FinePixViewer Ver.5.4-->C:\Program Files\InstallShield Installation Information\{24ED4D80-8294-11D5-96CD-0040266301AD}\SETUP.EXE -runfromtemp -l0x0009 -removeonly
    FUJIFILM USB Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5490882C-6961-11D5-BAE5-00E0188E010B}\SETUP.EXE"
    Garmin WebUpdater-->MsiExec.exe /X{366FFC89-C800-4366-B903-B9C4314109A5}
    HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
    Hotfix for Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
    HP Customer Participation Program 7.0-->C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
    HP Document Viewer 7.0-->C:\Program Files\HP\Digital Imaging\DocumentViewer\hpzscr01.exe -datfile hpqbud04.dat
    HP Imaging Device Functions 7.0-->C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
    HP Photosmart Premier Software 6.5-->C:\Program Files\HP\Digital Imaging\uninstall\hpzscr01.exe -datfile hpqscr01.dat
    HP Photosmart, Officejet and Deskjet 7.0.A-->C:\Program Files\HP\Digital Imaging\{BDBE2F3E-42DB-4d4a-8CB1-19BA765DBC6C}\setup\hpzscr01.exe -datfile hposcr11.dat
    HP Software Update-->MsiExec.exe /X{BB85ED9C-AFC9-43BD-B8DC-258C3C7DF72E}
    HP Solution Center 7.0-->C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
    ImageMixer VCD for FinePix-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D3AA158A-9421-4883-8767-E771B0964A1D}\setup.exe"
    Intel(R) PRO Ethernet Adapter and Software-->Prounstl.exe
    Intel(R) PROSet II-->MsiExec.exe /I{01A4AEDE-F219-49A2-B855-16A016EAF9A4}
    iTunes-->MsiExec.exe /I{41B9E2CF-0B3F-442A-B5B3-592A4A355634}
    J2ME Wireless Toolkit 2.0 Beta 2-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7307D640-98C9-11D6-96B8-0001021A3A3C}\Setup.exe" -l0x9 -uninst
    Java 2 Runtime Environment, SE v1.4.1_02-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EFCE5837-FC21-11D6-9D24-00010240CE95}\Setup.exe"
    Java 2 SDK, SE v1.4.1_02-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B7915B05-FC28-11D6-9D24-00010240CE95}\setup.exe" Anytext
    Java Web Start-->"C:\Program Files\Java Web Start\uninst-javaws.exe"
    Java(TM) 6 Update 2-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
    Java(TM) 6 Update 3-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
    Java(TM) 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
    LiveUpdate 2.6 (Symantec Corporation)-->C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE /U
    Logitech Audio Echo Cancellation Component-->MsiExec.exe /X{BEF726DD-4037-4214-8C6A-E625C02D2870}
    Logitech Desktop Messenger-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}\Setup.exe" -l0x9 UNINSTALL
    Logitech Legacy USB Camera Driver Package-->"C:\Program Files\Common Files\LogiShrd\LogiDriverStore\legacyqcam\10.51.2023\LgDrvInst.exe" -remove -instdir"C:\Program Files\Common Files\LogiShrd\LogiDriverStore\legacyqcam\" -enumdelay=2000 -enabledifx -forcedelete -usbhubsfirst -forceremove -cumulativeremove -promptuninstall -arpregkey"legacyqcam_10.51" /clone_wait /hide_progress
    Logitech QuickCam Driver Package-->"C:\Program Files\Common Files\LogiShrd\LogiDriverStore\lvdrivers\11.50.1145\LgDrvInst.exe" -remove -instdir"C:\Program Files\Common Files\LogiShrd\LogiDriverStore\lvdrivers\" -enumdelay=2000 -enabledifx -forcedelete -usbhubsfirst -forceremove -cumulativeremove -promptuninstall -arpregkey"lvdrivers_11.50" /clone_wait /hide_progress
    Logitech QuickCam-->MsiExec.exe /X{945AC98B-3DC8-45BE-BAE0-22CEEE37A103}
    Logitech Video Enumerator-->MsiExec.exe /X{EA516024-D84D-41F1-814F-83175A6188F2}
    Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes\unins000.exe"
    MarkelSoft Dupe Eliminator for iTunes 3.63-->C:\Program Files\DupeEliminator\uninstall.exe
    Microsoft .NET Framework (English) v1.0.3705-->C:\WINDOWS\Microsoft.NET\Framework\Install.exe /u /p Microsoft .NET Framework Full v1.0.3705 (1033)
    Microsoft .NET Framework (English)-->MsiExec.exe /X{B43357AA-3A6D-4D94-B56E-43C44D09E548}
    Microsoft .NET Framework 1.0 Hotfix (KB928367)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\Updates\M928367\M928367Uninstall.msp"
    Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
    Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
    Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
    Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
    Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
    Microsoft Kernel-Mode Driver Framework Feature Pack 1.5-->"C:\WINDOWS\$NtUninstallWdf01005$\spuninst\spuninst.exe"
    Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
    Microsoft Office Access MUI (English) 2007-->MsiExec.exe /X{90120000-0015-0409-0000-0000000FF1CE}
    Microsoft Office Access Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0117-0409-0000-0000000FF1CE}
    Microsoft Office Enterprise 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall ENTERPRISER /dll OSETUP.DLL
    Microsoft Office Enterprise 2007-->MsiExec.exe /X{91120000-0030-0000-0000-0000000FF1CE}
    Microsoft Office Excel MUI (English) 2007-->MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE}
    Microsoft Office Groove MUI (English) 2007-->MsiExec.exe /X{90120000-00BA-0409-0000-0000000FF1CE}
    Microsoft Office Groove Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0114-0409-0000-0000000FF1CE}
    Microsoft Office InfoPath MUI (English) 2007-->MsiExec.exe /X{90120000-0044-0409-0000-0000000FF1CE}
    Microsoft Office OneNote MUI (English) 2007-->MsiExec.exe /X{90120000-00A1-0409-0000-0000000FF1CE}
    Microsoft Office Outlook MUI (English) 2007-->MsiExec.exe /X{90120000-001A-0409-0000-0000000FF1CE}
    Microsoft Office PowerPoint MUI (English) 2007-->MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE}
    Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
    Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
    Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
    Microsoft Office Proofing (English) 2007-->MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
    Microsoft Office Publisher MUI (English) 2007-->MsiExec.exe /X{90120000-0019-0409-0000-0000000FF1CE}
    Microsoft Office Shared MUI (English) 2007-->MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
    Microsoft Office Shared Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
    Microsoft Office Word MUI (English) 2007-->MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
    Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
    Microsoft Works 7.0-->MsiExec.exe /I{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}
    MicroStaff WINASPI-->C:\MWASPI\uninst.exe
    MobileMe Control Panel-->MsiExec.exe /I{6DA9102E-199F-43A0-A36B-6EF48081A658}
    Modem Helper-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F142D56-3326-11D5-B229-002078017FBF}\setup.exe" -l0x9 ControlPanel
    Mozilla Firefox (3.0.3)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
    MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
    MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
    MVision-->MsiExec.exe /I{35725FBC-A136-4A46-9F29-091759D9BB93}
    Norton WMI Update-->MsiExec.exe /X{1526D87C-A955-4FAB-BF18-697BA457E352}
    NVIDIA Display Driver-->C:\WINDOWS\system32\nvudisp.exe Uninstall C:\WINDOWS\system32\nvdisp.nvu,NVIDIA Display Driver
    NVIDIA Windows 2000/XP Display Drivers-->rundll32.exe C:\WINDOWS\System32\nvinstnt.dll,NvUninstallNT4 nvdd.inf
    OCR Software by I.R.I.S 7.0-->C:\Program Files\HP\Digital Imaging\OCR\hpzscr01.exe -datfile hpqbud11.dat
    Paint Shop Pro 7-->MsiExec.exe /I{D6DE02C7-1F47-11D4-9515-00105AE4B89A}
    PowerDVD-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\setup.exe" -uninstall
    PRS-500 Operation Guide-->MsiExec.exe /X{057F209F-EE8A-4E35-9E47-B0269528D8A8}
    QuickTime-->MsiExec.exe /I{8DC42D05-680B-41B0-8878-6C14D24602DB}
    Security Update for 2007 Microsoft Office System (KB951596)-->msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {1AFF2298-CC00-4A3B-866A-C62B8373794E}
    Security Update for 2007 Microsoft Office System (KB951944)-->msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {797AE457-BA17-4BBC-B501-25FB3A0103C7}
    Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
    Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
    Security Update for Microsoft Office Excel 2007 (KB951546)-->msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {7399DD71-8E24-4E60-B6A8-6CED89C0AC26}
    Security Update for Microsoft Office OneNote 2007 (KB950130)-->msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {F1B2401C-B610-4BF2-AA1C-52C55827A8F4}
    Security Update for Microsoft Office PowerPoint 2007 (KB951338)-->msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {558B709B-821B-4FC5-90FC-9A8890641E77}
    Security Update for Microsoft Office Publisher 2007 (KB950114)-->msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {F9C3CDBA-1F00-4D4D-959D-75C9D3ACDD85}
    Security Update for Microsoft Office system 2007 (KB951808)-->msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {8F375E11-4FD6-4B89-9E2B-A76D48B51E00}
    Security Update for Microsoft Office system 2007 (KB954326)-->msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {5F7F6FFF-395D-480E-8450-64F385D82C5F}
    Security Update for Microsoft Office Word 2007 (KB950113)-->msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {AD72BABE-C733-4FCF-9674-4314466191B9}
    Security Update for Visio 2007 (KB947590)-->msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {6BAD036C-261F-4BEF-96CF-C20678D07A41}
    Security Update for Windows Internet Explorer 7 (KB937143)-->"C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe"
    Security Update for Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
    Security Update for Windows Internet Explorer 7 (KB939653)-->"C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
    Security Update for Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
    Security Update for Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
    Security Update for Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
    Security Update for Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
    Skype™ 3.2-->MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
    Sony Ericsson PC Suite-->MsiExec.exe /I{FC906D5C-91F9-4DA4-A765-6DCBB669F317}
    Sound Blaster Live!-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{96E16100-A77F-4B31-B9AD-FFBA040EE1BD}\setup.exe" -l0x9
    UMVPLStandalone-->MsiExec.exe /X{8AC049F7-1383-45C3-9E7D-F93CA667F9E1}
    Update for Microsoft Office Outlook 2007 (KB952142)-->msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {4AD3A076-427C-491F-A5B7-7D1DE788A756}
    Update for Office 2007 (KB946691)-->msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {A420F522-7395-4872-9882-C591B4B92278}
    Update for Outlook 2007 Junk Email Filter (kb956080)-->msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {96CC215F-3F22-4E1E-A101-F0041934A456}
    Update Service-->C:\Program Files\Sony Ericsson\Update Service\uninst.exe
    Videora iPod Converter 3.07-->C:\Program Files\Red Kawa\Video Converter\Video Converter 3\uninstaller.exe
    Videora Trial Version 2.15-->C:\Program Files\Videora\uninst.exe
    Windows Driver Package - Sony Corporation (PRSUSB) USB (08/08/2006 1.0.03.08080)-->rundll32.exe C:\PROGRA~1\DIFX\15B7F172FC21855D\DIFxAppA.dll, DIFxARPUninstallDriverPackage C:\WINDOWS\system32\DRVSTORE\PRSUSB_0200B6D60DA90847167AFB40E87ADFDB0591D0A1\PRSUSB.inf
    Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
    WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe
    WinZip 11.1-->MsiExec.exe /X{CD95F661-A5C4-44F5-A6AA-ECDD91C240B5}
    Wondershare DVD to iPod Ripper(Build 2.5.0.0)-->"C:\Program Files\DVD2iPodRipper\unins000.exe"
    XoftSpySE-->C:\Program Files\XoftSpySE\uninstall.exe
    Yahoo! Install Manager-->C:\WINDOWS\system32\regsvr32 /u C:\PROGRA~1\Yahoo!\Common\YINSTH~1.DLL

    ======Security center information======

    AV: AVG Anti-Virus Free

    ======Environment variables======

    "ComSpec"=%SystemRoot%\system32\cmd.exe
    "NUMBER_OF_PROCESSORS"=1
    "OS"=Windows_NT
    "Path"=C:\oracle\ora90\bin;C:\oracle\ora90\Apache\Perl\5.00503\bin\mswin32-x86;C:\Program Files\Oracle\jre\1.1.8\bin;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Common Files\Adaptec Shared\System;C:\j2sdk1.4.1_02\bin;C:\PROGRA~1\COMMON~1\AUTODE~1;C:\Program Files\Common Files\Teleca Shared;C:\Program Files\QuickTime\QTSystem\
    "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
    "PROCESSOR_ARCHITECTURE"=x86
    "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 2 Stepping 7, GenuineIntel
    "PROCESSOR_LEVEL"=15
    "PROCESSOR_REVISION"=0207
    "TEMP"=%SystemRoot%\TEMP
    "TMP"=%SystemRoot%\TEMP
    "windir"=%SystemRoot%
    "OLAP_HOME"=C:\oracle\ora90\olap
    "FP_NO_HOST_CHECK"=NO
    "CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_05\lib\ext\QTJava.zip
    "QTJAVA"=C:\Program Files\Java\jre1.6.0_05\lib\ext\QTJava.zip

    EOF

    ################################################
    Output of log.txt is:
    ################################################

    Logfile of random's system information tool 1.04 (written by random/random)
    Run by Tom at 2008-10-07 22:19:05
    Microsoft Windows XP Home Edition Service Pack 3
    System drive C: has 61 GB (54%) free of 114 GB
    Total RAM: 511 MB (14% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 22:19:15, on 07/10/2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16705)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\WINDOWS\System32\CTsvcCDA.exe
    C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\Program Files\Internet Explorer\Iexplore.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\BCMSMMSG.exe
    C:\WINDOWS\System32\DSentry.exe
    C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
    C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
    C:\Program Files\Common Files\Dell\EUSW\Support.exe
    C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
    C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
    C:\Program Files\Logitech\QuickCam\Quickcam.exe
    C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
    C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\PROGRA~1\AVG\AVG8\avgtray.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    C:\Program Files\Digital Line Detect\DLG.exe
    C:\Program Files\FinePixViewer\QuickDCF2.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\WinZip\WZQKPICK.EXE
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Common Files\Teleca Shared\Generic.exe
    C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
    C:\Documents and Settings\Tom.TODDY\Desktop\RSIT.exe
    C:\Program Files\trend micro\Tom.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.ie
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: BitComet Helper - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.3.28.dll
    O2 - BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
    O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
    O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
    O4 - HKLM\..\Run: [BuildBU] c:\dell\bldbubg.exe
    O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
    O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
    O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
    O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: Digital Line Detect.lnk = ?
    O4 - Global Startup: ExifLauncher2.lnk = C:\Program Files\FinePixViewer\QuickDCF2.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://www.eircom.net
    O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} - http://www.may.ie/wfplayer/tdserver.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1139944226076
    O16 - DPF: {6F750203-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/BUM_WIN_IE_2/axofupld.cab
    O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O20 - AppInit_DLLs: avgrsstx.dll
    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
    O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
    O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
    O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
    O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
    O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Oracle OLAP 9.0.1.0.1 (OLAPServer) - Oracle Corporation - C:\oracle\ora90\bin\xsolap.exe
    O23 - Service: Oracle OLAP Agent - Unknown owner - C:\oracle\ora90\bin\xsaagent.exe
    O23 - Service: OracleOraHome90PagingServer - Unknown owner - C:\oracle\ora90/bin/pagntsrv.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Sony SCSI Helper Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\Fsk\SonySCSIHelperService.exe
    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

    --
    End of file - 12268 bytes

    ======Scheduled tasks folder======

    C:\WINDOWS\tasks\AppleSoftwareUpdate.job
    C:\WINDOWS\tasks\Symantec NetDetect.job
    C:\WINDOWS\tasks\XoftSpySE 2.job
    C:\WINDOWS\tasks\XoftSpySE.job

    ======Registry dump======

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
    Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}]
    BitComet Helper - C:\Program Files\BitComet\tools\BitCometBHO_1.1.3.28.dll [2007-03-29 394816]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
    AVG Safe Search - C:\Program Files\AVG\AVG8\avgssie.dll [2008-09-25 455960]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
    Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2007-08-24 2212224]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
    SSVHelper Class - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll [2008-02-22 509328]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
    AVG Security Toolbar - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2008-09-25 2055960]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    {A057A204-BACC-4D26-9990-79A187E2698E} - AVG Security Toolbar - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2008-09-25 2055960]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2003-10-06 5058560]
    "BCMSMMSG"=C:\WINDOWS\BCMSMMSG.exe [2003-08-29 122880]
    "diagent"=C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe [2002-04-03 135264]
    "UpdReg"=C:\WINDOWS\UpdReg.EXE [2000-05-11 90112]
    "DVDSentry"=C:\WINDOWS\System32\DSentry.exe [2002-08-14 28672]
    "AdaptecDirectCD"=C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe [2002-04-10 679936]
    "BuildBU"=c:\dell\bldbubg.exe [2001-12-06 53248]
    "DwlClient"=C:\Program Files\Common Files\Dell\EUSW\Support.exe [2002-12-12 221184]
    "nwiz"=nwiz.exe /install []
    "SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe [2008-02-22 144784]
    "LogitechCommunicationsManager"=C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe [2007-10-25 563984]
    "LogitechQuickCamRibbon"=C:\Program Files\Logitech\QuickCam\Quickcam.exe [2007-10-25 2178832]
    "GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2007-08-24 33648]
    "Sony Ericsson PC Suite"=C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe [2006-11-24 487424]
    "HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2006-02-19 49152]
    "REGSHAVE"=C:\Program Files\REGSHAVE\REGSHAVE.EXE [2002-02-04 53248]
    "Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
    "QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2008-09-06 413696]
    "AppleSyncNotifier"=C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe [2008-09-03 111936]
    "iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2008-09-10 289576]
    "AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe [2008-10-01 1234712]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
    "NvMediaCenter"=C:\WINDOWS\system32\NVMCTRAY.DLL [2003-10-06 49152]
    "ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
    "LDM"=C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-02-21 67128]

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup
    Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe
    ExifLauncher2.lnk - C:\Program Files\FinePixViewer\QuickDCF2.exe
    HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    HP Photosmart Premier Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
    Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "AppInit_DLLS"="avgrsstx.dll"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
    C:\WINDOWS\system32\WgaLogon.dll [2007-03-15 236928]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    "{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2007-08-24 2212224]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "DisableTaskMgr"=0
    "NoDispScrSavPage"=0
    "NoDispCPL"=0

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "dontdisplaylastusername"=0
    "legalnoticecaption"=
    "legalnoticetext"=
    "shutdownwithoutlogon"=1
    "undockwithoutlogon"=1

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDriveTypeAutoRun"=157
    "NoStartMenuMorePrograms"=0
    "StartMenuLogOff"=0
    "NoDrives"=0
    "NoToolbarCustomize"=0
    "NoSetFolders"=0

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    ""=
    "NoDriveTypeAutoRun"=

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
    "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
    "C:\Program Files\BitTorrent\bittorrent.exe"="C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent"
    "C:\Program Files\uTorrent\utorrent.exe"="C:\Program Files\uTorrent\utorrent.exe:*:Enabled:µTorrent"
    "C:\Program Files\devolo\informer\devinf.exe"="C:\Program Files\devolo\informer\devinf.exe:*:Enabled:devolo Informer"
    "C:\Program Files\devolo\easyshare\easyshare.exe"="C:\Program Files\devolo\easyshare\easyshare.exe:*:Enabled:devolo EasyShare"
    "C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
    "C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
    "C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
    "C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
    "C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
    "C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe"
    "C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe"="C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe"
    "C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
    "C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
    "C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
    "C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe"
    "C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe"
    "C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
    "C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
    "C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe"
    "C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe"
    "C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe:*:Enabled:hpqnrs08.exe"
    "C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
    "C:\Program Files\Sony\CONNECT Reader\Data\bin\eBook Library.exe"="C:\Program Files\Sony\CONNECT Reader\Data\bin\eBook Library.exe:*:Enabled:eBook Library"
    "C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
    "C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
    "C:\Program Files\AVG\AVG8\avgupd.exe"="C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
    "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"

    ======List of files/folders created in the last 1 months======

    2008-10-07 22:19:05 ----D---- C:\rsit
    2008-10-07 22:19:05 ----D---- C:\Program Files\trend micro
    2008-10-06 18:39:34 ----D---- C:\Program Files\HijackThis
    2008-10-04 18:02:31 ----D---- C:\Documents and Settings\Tom.TODDY\Application Data\Malwarebytes
    2008-10-04 18:02:20 ----D---- C:\Program Files\Malwarebytes
    2008-10-04 18:02:20 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    2008-10-04 17:46:13 ----D---- C:\Program Files\XoftSpySE
    2008-10-03 19:01:15 ----D---- C:\Documents and Settings\Tom.TODDY\Application Data\TmpRecentIcons
    2008-09-28 11:31:47 ----D---- C:\Program Files\Yahoo!
    2008-09-28 11:31:22 ----D---- C:\Program Files\CCleaner
    2008-09-27 17:20:14 ----HD---- C:\$AVG8.VAULT$
    2008-09-25 18:34:50 ----A---- C:\WINDOWS\system32\avgrsstx.dll
    2008-09-25 18:34:32 ----D---- C:\Documents and Settings\Tom.TODDY\Application Data\AVGTOOLBAR
    2008-09-25 18:34:16 ----D---- C:\Program Files\AVG
    2008-09-25 18:34:16 ----D---- C:\Documents and Settings\All Users\Application Data\avg8
    2008-09-24 03:17:39 ----D---- C:\WINDOWS\Prefetch
    2008-09-23 21:46:10 ----D---- C:\WINDOWS\system32\scripting
    2008-09-23 21:46:08 ----D---- C:\WINDOWS\l2schemas
    2008-09-23 21:46:07 ----D---- C:\WINDOWS\system32\en
    2008-09-23 21:21:16 ----D---- C:\Documents and Settings\All Users\Application Data\Marlin
    2008-09-23 20:20:54 ----N---- C:\WINDOWS\system32\wmphoto.dll
    2008-09-23 20:20:47 ----N---- C:\WINDOWS\system32\wlanapi.dll
    2008-09-23 20:20:44 ----N---- C:\WINDOWS\system32\windowscodecsext.dll
    2008-09-23 20:20:44 ----N---- C:\WINDOWS\system32\windowscodecs.dll
    2008-09-23 20:20:31 ----N---- C:\WINDOWS\system32\tspkg.dll
    2008-09-23 20:20:31 ----N---- C:\WINDOWS\system32\tsgqec.dll
    2008-09-23 20:20:09 ----N---- C:\WINDOWS\system32\setupn.exe
    2008-09-23 20:20:04 ----N---- C:\WINDOWS\system32\rhttpaa.dll
    2008-09-23 20:20:02 ----N---- C:\WINDOWS\system32\rasqec.dll
    2008-09-23 20:20:01 ----N---- C:\WINDOWS\system32\qutil.dll
    2008-09-23 20:20:00 ----N---- C:\WINDOWS\system32\qcliprov.dll
    2008-09-23 20:20:00 ----N---- C:\WINDOWS\system32\qagentrt.dll
    2008-09-23 20:20:00 ----N---- C:\WINDOWS\system32\qagent.dll
    2008-09-23 20:19:57 ----N---- C:\WINDOWS\system32\photometadatahandler.dll
    2008-09-23 20:19:53 ----N---- C:\WINDOWS\system32\onex.dll
    2008-09-23 20:19:39 ----N---- C:\WINDOWS\system32\napstat.exe
    2008-09-23 20:19:39 ----N---- C:\WINDOWS\system32\napmontr.dll
    2008-09-23 20:19:39 ----N---- C:\WINDOWS\system32\napipsec.dll
    2008-09-23 20:19:37 ----N---- C:\WINDOWS\system32\msxml6r.dll
    2008-09-23 20:19:37 ----N---- C:\WINDOWS\system32\msxml6.dll
    2008-09-23 20:19:34 ----N---- C:\WINDOWS\system32\msshavmsg.dll
    2008-09-23 20:19:34 ----N---- C:\WINDOWS\system32\mssha.dll
    2008-09-23 20:19:12 ----N---- C:\WINDOWS\system32\mmcperf.exe
    2008-09-23 20:19:11 ----N---- C:\WINDOWS\system32\mmcfxcommon.dll
    2008-09-23 20:19:11 ----N---- C:\WINDOWS\system32\mmcex.dll
    2008-09-23 20:19:11 ----N---- C:\WINDOWS\system32\microsoft.managementconsole.dll
    2008-09-23 20:18:53 ----N---- C:\WINDOWS\system32\l2gpstore.dll
    2008-09-23 20:18:52 ----N---- C:\WINDOWS\system32\kmsvc.dll
    2008-09-23 20:18:51 ----N---- C:\WINDOWS\system32\kbdpash.dll
    2008-09-23 20:18:51 ----N---- C:\WINDOWS\system32\kbdnepr.dll
    2008-09-23 20:18:51 ----N---- C:\WINDOWS\system32\kbdiultn.dll
    2008-09-23 20:18:51 ----N---- C:\WINDOWS\system32\kbdbhc.dll
    2008-09-23 20:18:30 ----A---- C:\WINDOWS\005310_.tmp
    2008-09-23 20:18:29 ----N---- C:\WINDOWS\system32\eapsvc.dll
    2008-09-23 20:18:29 ----N---- C:\WINDOWS\system32\eapqec.dll
    2008-09-23 20:18:29 ----N---- C:\WINDOWS\system32\eappprxy.dll
    2008-09-23 20:18:29 ----N---- C:\WINDOWS\system32\eapphost.dll
    2008-09-23 20:18:29 ----N---- C:\WINDOWS\system32\eappgnui.dll
    2008-09-23 20:18:29 ----N---- C:\WINDOWS\system32\eappcfg.dll
    2008-09-23 20:18:29 ----N---- C:\WINDOWS\system32\eapp3hst.dll
    2008-09-23 20:18:29 ----N---- C:\WINDOWS\system32\eapolqec.dll
    2008-09-23 20:18:23 ----N---- C:\WINDOWS\system32\dot3ui.dll
    2008-09-23 20:18:23 ----N---- C:\WINDOWS\system32\dot3svc.dll
    2008-09-23 20:18:23 ----N---- C:\WINDOWS\system32\dot3msm.dll
    2008-09-23 20:18:23 ----N---- C:\WINDOWS\system32\dot3gpclnt.dll
    2008-09-23 20:18:23 ----N---- C:\WINDOWS\system32\dot3dlg.dll
    2008-09-23 20:18:22 ----N---- C:\WINDOWS\system32\dot3cfg.dll
    2008-09-23 20:18:22 ----N---- C:\WINDOWS\system32\dot3api.dll
    2008-09-23 20:18:20 ----N---- C:\WINDOWS\system32\dimsroam.dll
    2008-09-23 20:18:20 ----N---- C:\WINDOWS\system32\dimsntfy.dll
    2008-09-23 20:18:19 ----N---- C:\WINDOWS\system32\dhcpqec.dll
    2008-09-23 20:18:16 ----N---- C:\WINDOWS\system32\credssp.dll
    2008-09-23 20:18:06 ----N---- C:\WINDOWS\system32\bitsprx4.dll
    2008-09-23 20:18:06 ----N---- C:\WINDOWS\system32\azroles.dll
    2008-09-23 20:17:55 ----N---- C:\WINDOWS\system32\aaclient.dll
    2008-09-23 19:22:06 ----D---- C:\Program Files\iPod
    2008-09-23 19:21:33 ----D---- C:\Program Files\iTunes
    2008-09-23 19:21:33 ----D---- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
    2008-09-23 19:15:17 ----D---- C:\Program Files\Bonjour
    2008-09-23 19:10:34 ----D---- C:\Program Files\QuickTime
    2008-09-20 11:49:14 ----D---- C:\Documents and Settings\All Users\Application Data\kinoma

    ======List of files/folders modified in the last 1 months======

    2008-10-07 22:19:05 ----AD---- C:\Program Files
    2008-10-07 22:17:08 ----D---- C:\Program Files\Mozilla Firefox
    2008-10-07 22:16:45 ----D---- C:\WINDOWS
    2008-10-07 22:16:09 ----AD---- C:\WINDOWS\Temp
    2008-10-07 19:31:55 ----D---- C:\WINDOWS\SYSTEM32
    2008-10-07 19:31:50 ----D---- C:\WINDOWS\system32\DRIVERS
    2008-10-06 20:44:39 ----A---- C:\WINDOWS\SchedLgU.Txt
    2008-10-04 17:46:15 ----SD---- C:\WINDOWS\Tasks
    2008-10-04 17:13:12 ----SHD---- C:\System Volume Information
    2008-10-04 17:13:12 ----D---- C:\WINDOWS\system32\Restore
    2008-10-04 17:11:30 ----D---- C:\Program Files\devolo
    2008-10-01 18:30:09 ----HD---- C:\WINDOWS\INF
    2008-10-01 18:30:07 ----D---- C:\WINDOWS\system32\CatRoot2
    2008-09-28 12:02:49 ----D---- C:\WINDOWS\system32\LogFiles
    2008-09-28 12:02:45 ----D---- C:\WINDOWS\Debug
    2008-09-27 12:49:21 ----D---- C:\Documents and Settings\Tom.TODDY\Application Data\Mozilla
    2008-09-25 18:38:38 ----RSHD---- C:\WINDOWS\system32\DLLCACHE
    2008-09-25 18:34:06 ----HD---- C:\Config.Msi
    2008-09-25 18:34:05 ----SHD---- C:\WINDOWS\Installer
    2008-09-25 18:34:05 ----D---- C:\WINDOWS\WinSxS
    2008-09-25 18:34:05 ----D---- C:\Program Files\Common Files\Microsoft Shared
    2008-09-25 18:23:46 ----HD---- C:\WINDOWS\$hf_mig$
    2008-09-25 18:21:29 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
    2008-09-24 03:16:37 ----D---- C:\WINDOWS\system32\Setup
    2008-09-24 03:16:37 ----D---- C:\WINDOWS\AppPatch
    2008-09-24 03:16:36 ----D---- C:\WINDOWS\system32\WBEM
    2008-09-24 03:16:36 ----D---- C:\Program Files\Outlook Express
    2008-09-24 03:16:35 ----RSD---- C:\WINDOWS\Fonts
    2008-09-23 22:04:45 ----D---- C:\WINDOWS\system32\CatRoot
    2008-09-23 22:01:06 ----D---- C:\WINDOWS\SECURITY
    2008-09-23 21:55:52 ----D---- C:\Program Files\Messenger
    2008-09-23 21:46:54 ----D---- C:\WINDOWS\ServicePackFiles
    2008-09-23 21:46:52 ----D---- C:\WINDOWS\Help
    2008-09-23 21:46:52 ----D---- C:\Program Files\Windows Media Player
    2008-09-23 21:46:32 ----D---- C:\WINDOWS\network diagnostic
    2008-09-23 21:46:31 ----D---- C:\WINDOWS\IME
    2008-09-23 21:46:12 ----D---- C:\WINDOWS\system32\USMT
    2008-09-23 21:46:12 ----D---- C:\WINDOWS\system32\en-US
    2008-09-23 21:46:06 ----D---- C:\WINDOWS\system32\bits
    2008-09-23 21:46:06 ----D---- C:\WINDOWS\peernet
    2008-09-23 21:46:06 ----D---- C:\Program Files\Movie Maker
    2008-09-23 21:40:09 ----D---- C:\WINDOWS\system32\NPP
    2008-09-23 21:40:07 ----D---- C:\WINDOWS\MSAGENT
    2008-09-23 21:40:04 ----D---- C:\WINDOWS\SRCHASST
    2008-09-23 21:40:02 ----D---- C:\Program Files\NetMeeting
    2008-09-23 21:39:59 ----D---- C:\WINDOWS\system32\Com
    2008-09-23 21:39:51 ----D---- C:\Program Files\Windows NT
    2008-09-23 21:39:47 ----D---- C:\Program Files\Common Files\System
    2008-09-23 21:39:25 ----D---- C:\WINDOWS\system32\OOBE
    2008-09-23 21:39:24 ----D---- C:\WINDOWS\SYSTEM
    2008-09-23 21:34:10 ----D---- C:\WINDOWS\system32\ReinstallBackups
    2008-09-23 21:33:51 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
    2008-09-23 21:27:34 ----D---- C:\WINDOWS\EHome
    2008-09-23 20:32:21 ----D---- C:\Program Files\Common Files\Symantec Shared
    2008-09-23 20:32:13 ----D---- C:\Program Files\Symantec
    2008-09-23 20:31:34 ----D---- C:\Program Files\Common Files
    2008-09-23 19:40:50 ----D---- C:\Documents and Settings\All Users\Application Data\Symantec
    2008-09-23 19:23:24 ----DC---- C:\WINDOWS\system32\DRVSTORE
    2008-09-20 11:48:34 ----D---- C:\Program Files\Sony
    2008-09-20 11:48:34 ----D---- C:\Program Files\Common Files\Sony Shared
    2008-09-14 12:36:38 ----D---- C:\Program Files\Adobe
    2008-09-11 14:09:50 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2008-09-25 97928]
    R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2008-09-25 26824]
    R1 Cdr4_xp;Cdr4_xp; C:\WINDOWS\system32\drivers\Cdr4_xp.sys [2005-08-19 2432]
    R1 Cdralw2k;Cdralw2k; C:\WINDOWS\system32\drivers\Cdralw2k.sys [2005-08-19 2560]
    R1 cdudf_xp;cdudf_xp; C:\WINDOWS\system32\drivers\cdudf_xp.sys [2002-04-10 236032]
    R1 intelppm;Intel Processor Driver; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2008-04-13 36352]
    R1 omci;OMCI WDM Device Driver; C:\WINDOWS\System32\DRIVERS\omci.sys [2002-07-19 17153]
    R1 pwd_2k;pwd_2k; C:\WINDOWS\system32\drivers\pwd_2k.sys [2002-04-10 117898]
    R1 UdfReadr_xp;UdfReadr_xp; C:\WINDOWS\system32\drivers\UdfReadr_xp.sys [2002-04-10 206336]
    R2 MASPINT;MASPINT; C:\WINDOWS\system32\drivers\MASPINT.sys [2000-03-29 8096]
    R2 PfModNT;PfModNT; \??\C:\WINDOWS\System32\PfModNT.sys []
    R2 PLCNDIS5;PLCNDIS5 NDIS Protocol Driver; C:\WINDOWS\system32\plcndis5.sys [2004-05-17 17280]
    R3 BCMModem;BCM V.92 56K Modem; C:\WINDOWS\System32\DRIVERS\BCMSM.sys [2003-08-29 1101696]
    R3 E100B;Intel(R) PRO Adapter Driver; C:\WINDOWS\System32\DRIVERS\e100b325.sys [2002-09-19 139776]
    R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys [2008-04-17 15464]
    R3 LVPr2Mon;Logitech LVPr2Mon Driver; C:\WINDOWS\system32\drivers\LVPr2Mon.sys [2007-10-11 25624]
    R3 LVUSBSta;Logitech USB Monitor Filter; C:\WINDOWS\system32\drivers\LVUSBSta.sys [2007-10-12 41752]
    R3 mmc_2K;mmc_2K; C:\WINDOWS\system32\drivers\mmc_2K.sys [2002-04-10 29638]
    R3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
    R3 nv;nv; C:\WINDOWS\System32\DRIVERS\nv4_mini.sys [2003-10-06 1550043]
    R3 P16X;Creative SB Live! Series (WDM); C:\WINDOWS\system32\drivers\P16X.sys [2002-08-30 1293440]
    R3 PID_0928;Logitech QuickCam Express(PID_0928); C:\WINDOWS\system32\DRIVERS\LV561AV.SYS [2007-10-12 490776]
    R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2008-04-13 30208]
    R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-13 59520]
    R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-13 20608]
    S1 P3;Intel PentiumIII Processor Driver; C:\WINDOWS\System32\DRIVERS\p3.sys [2008-04-13 42752]
    S3 BLKWGU(Belkin);Belkin Wireless G USB Network Adapter(Belkin); C:\WINDOWS\system32\DRIVERS\BLKWGU.sys []
    S3 bvrp_pci;bvrp_pci; C:\WINDOWS\system32\drivers\bvrp_pci.sys [2002-05-13 4272]
    S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
    S3 dvd_2K;dvd_2K; C:\WINDOWS\system32\drivers\dvd_2K.sys [2002-04-10 24554]
    S3 EL90XBC;3Com EtherLink XL 90XB/C Adapter Driver; C:\WINDOWS\System32\DRIVERS\el90xbc5.sys [2001-08-17 66591]
    S3 ggflt;SEMC USB Flash Driver Filter; C:\WINDOWS\system32\DRIVERS\ggflt.sys [2008-06-08 13352]
    S3 ggsemc;SEMC USB Flash Driver; C:\WINDOWS\system32\DRIVERS\ggsemc.sys [2008-06-08 21672]
    S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2008-04-13 10368]
    S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2006-04-13 49664]
    S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2006-04-13 16496]
    S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2005-10-21 21568]
    S3 i81x;i81x; C:\WINDOWS\System32\DRIVERS\i81xnt5.sys [2004-08-04 161020]
    S3 iAimFP0;iAimFP0; C:\WINDOWS\System32\DRIVERS\wADV01nt.sys [2004-08-04 12415]
    S3 iAimFP1;iAimFP1; C:\WINDOWS\System32\DRIVERS\wADV02NT.sys [2004-08-04 12127]
    S3 iAimFP2;iAimFP2; C:\WINDOWS\System32\DRIVERS\wADV05NT.sys [2004-08-04 11775]
    S3 iAimFP3;iAimFP3; C:\WINDOWS\System32\DRIVERS\wSiINTxx.sys [2004-08-04 12063]
    S3 iAimFP4;iAimFP4; C:\WINDOWS\System32\DRIVERS\wVchNTxx.sys [2004-08-04 19455]
    S3 iAimTV0;iAimTV0; C:\WINDOWS\System32\DRIVERS\wATV01nt.sys [2004-08-04 29311]
    S3 iAimTV1;iAimTV1; C:\WINDOWS\System32\DRIVERS\wATV02NT.sys [2004-08-04 19551]
    S3 iAimTV2;iAimTV2; C:\WINDOWS\System32\DRIVERS\wATV03nt.sys []
    S3 iAimTV3;iAimTV3; C:\WINDOWS\System32\DRIVERS\wATV04nt.sys [2004-08-04 33599]
    S3 iAimTV4;iAimTV4; C:\WINDOWS\System32\DRIVERS\wCh7xxNT.sys [2004-08-04 23615]
    S3 LVcKap;Logitech AEC Driver; C:\WINDOWS\system32\DRIVERS\LVcKap.sys [2007-10-19 2109976]
    S3 LVMVDrv;Logitech Machine Vision Engine Loader; C:\WINDOWS\system32\DRIVERS\LVMVDrv.sys [2007-10-11 2142488]
    S3 mouhid;Mouse HID Driver; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-08-17 12160]
    S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
    S3 MTK;Media Technology Kernel Driver; C:\WINDOWS\System32\Drivers\fide.sys [2006-11-01 14468]
    S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
    S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
    S3 NETMDUSB;Net MD; C:\WINDOWS\System32\Drivers\NETMDUSB.sys [2001-12-11 37087]
    S3 NMSCFG;NIC Management Service Configuration Driver; \??\C:\WINDOWS\System32\drivers\NMSCFG.SYS []
    S3 PLCMPR5;PLCMPR5 NDIS Protocol Driver; \??\C:\WINDOWS\system32\PLCMPR5.SYS []
    S3 PRSUSB;Sony Reader; C:\WINDOWS\System32\Drivers\PRSUSB.sys [2006-11-21 18944]
    S3 SE27bus;Sony Ericsson Device 039 Driver driver (WDM); C:\WINDOWS\system32\DRIVERS\SE27bus.sys [2006-09-18 61600]
    S3 SE27mdfl;Sony Ericsson Device 039 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\SE27mdfl.sys [2006-09-18 9360]
    S3 SE27mdm;Sony Ericsson Device 039 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\SE27mdm.sys [2006-09-18 97184]
    S3 SE27mgmt;Sony Ericsson Device 039 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\SE27mgmt.sys [2006-09-18 88688]
    S3 se27nd5;Sony Ericsson Device 039 USB Ethernet Emulation SEMC39 (NDIS); C:\WINDOWS\system32\DRIVERS\se27nd5.sys [2006-09-18 18704]
    S3 SE27obex;Sony Ericsson Device 039 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\SE27obex.sys [2006-09-18 86560]
    S3 se27unic;Sony Ericsson Device 039 USB Ethernet Emulation SEMC39 (WDM); C:\WINDOWS\system32\DRIVERS\se27unic.sys [2006-09-18 90800]
    S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
    S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
    S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys [2008-07-10 32000]
    S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\sys


  • Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


    Looks good

    Please download Malwarebytes' Anti-Malware from Here or Here

    Double Click mbam-setup.exe to install the application.
    • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select "Perform Quick Scan", then click Scan.
    • The scan may take some time to finish,so please be patient.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Make sure that everything is checked, and click Remove Selected.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
    • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    • Copy&Paste the entire report in your next reply.
    Extra Note:
    If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.



    Please do an online scan with Kaspersky WebScanner

    Make sure you are using Internet Explorer for this. Click on Kaspersky Online Scanner and click Accept

    You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
    • The program will launch and then begin downloading the latest definition files:
    • Once the files have been downloaded click on NEXT
    • Now click on Scan Settings
    • In the scan settings make that the following are selected:
      • Scan using the following Anti-Virus database:
        Extended (if available otherwise Standard)
      • Scan Options:
        Scan Archives
        Scan Mail Bases


        [*]Click OK
        [*]Now under select a target to scan:
          Select
        My Computer

        [*]This will program will start and scan your system.
        [*]The scan will take a while so be patient and let it run.
        [*]Once the scan is complete it will display if your system has been infected.
        • Now click on the Save as Text button:
        [*]Save the file to your desktop.
        [*]Copy and paste that information in your next post.


      • Closed Accounts Posts: 11 toddyl


        Ok, did what you said.

        ##################################################
        The Malware bytes log has:
        ##################################################

        Malwarebytes' Anti-Malware 1.28
        Database version: 1227
        Windows 5.1.2600 Service Pack 3

        08/10/2008 07:53:02
        mbam-log-2008-10-08 (07-53-02).txt

        Scan type: Quick Scan
        Objects scanned: 57744
        Time elapsed: 7 minute(s), 45 second(s)

        Memory Processes Infected: 0
        Memory Modules Infected: 0
        Registry Keys Infected: 0
        Registry Values Infected: 0
        Registry Data Items Infected: 2
        Folders Infected: 0
        Files Infected: 2

        Memory Processes Infected:
        (No malicious items detected)

        Memory Modules Infected:
        (No malicious items detected)

        Registry Keys Infected:
        (No malicious items detected)

        Registry Values Infected:
        (No malicious items detected)

        Registry Data Items Infected:
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: c:\windows\system32\ -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: system32\ -> Quarantined and deleted successfully.

        Folders Infected:
        (No malicious items detected)

        Files Infected:
        C:\WINDOWS\SYSTEM32\ (Trojan.Agent) -> Delete on reboot.
        C:\WINDOWS\SYSTEM32\DRIVERS\ (Trojan.Agent) -> Delete on reboot.

        ###############################################
        Results of online scan using Kaspersky
        ###############################################

        KASPERSKY ONLINE SCANNER 7 REPORT
        Wednesday, October 8, 2008
        Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
        Kaspersky Online Scanner 7 version: 7.0.25.0
        Program database last update: Wednesday, October 08, 2008 07:21:15
        Records in database: 1299338

        Scan settings:
        Scan using the following database: extended
        Scan archives: yes
        Scan mail databases: yes

        Scan area - My Computer:
        A:\
        C:\
        D:\

        Scan statistics:
        Files scanned: 105371
        Threat name: 2
        Infected objects: 2
        Suspicious objects: 0
        Duration of the scan: 04:07:14


        File name / Threat name / Threats count
        C:\Documents and Settings\Tom.TODDY\Local Settings\Temp\.tt2A.tmp Infected: not-a-virus:FraudTool.Win32.Devushka.ae 1
        C:\WINDOWS\SYSTEM32\TFTP3812 Infected: Backdoor.Win32.Rbot.15 1

        The selected area was scanned.


      • Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


        Think there some left overs

        Please download the OTMoveIt3 by OldTimer.
        • Save it to your desktop.
        • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
        • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
          :Processes
          explorer.exe
          
          :Services
          
          :Reg
          
          :Files
          C:\Documents and Settings\Tom.TODDY\Local Settings\Temp\.tt2A.tmp
          C:\WINDOWS\SYSTEM32\TFTP3812
          
          :Commands
          [purity]
          [emptytemp]
          [start explorer]
          [Reboot]
          
        • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
        • Click the red Moveit! button.
        • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
        • Close OTMoveIt3
        Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.




        Please visit this web page for instructions for downloading and running ComboFix

        http://www.bleepingcomputer.com/combofix/how-to-use-combofix

        This includes installing the Windows XP Recovery Console in case you have not installed it yet.

        For more information on the Windows XP Recovery Console read http://support.microsoft.com/kb/314058.

        Once you install the Recovery Console, when you reboot your computer, you'll see the option for the Recovery Console now as well. Don't select Recovery Console as we don't need it. By default, your main OS is selected there. The screen stays for 2 seconds and then it proceeds to load Windows. That is normal.

        Post the log from ComboFix when you've accomplished that, along with a new HijackThis log.


      • Advertisement
      • Closed Accounts Posts: 11 toddyl


        The log from ComboFix says:

        ========== PROCESSES ==========
        Process explorer.exe killed successfully.
        ========== SERVICES/DRIVERS ==========
        ========== REGISTRY ==========
        ========== FILES ==========
        File/Folder C:\Documents and Settings\Tom.TODDY\Local Settings\Temp\.tt2A.tmp not found.
        C:\WINDOWS\SYSTEM32\TFTP3812 moved successfully.
        ========== COMMANDS ==========
        File delete failed. C:\DOCUME~1\TOM~1.TOD\LOCALS~1\Temp\etilqs_I9NW2lccHa8DhyjUg8vb scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\TOM~1.TOD\LOCALS~1\Temp\hpodvd09.log scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\TOM~1.TOD\LOCALS~1\Temp\~DF4EC1.tmp scheduled to be deleted on reboot.
        User's Temp folder emptied.
        User's Temporary Internet Files folder emptied.
        User's Internet Explorer cache folder emptied.
        Local Service Temp folder emptied.
        File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT scheduled to be deleted on reboot.
        Local Service Temporary Internet Files folder emptied.
        Windows Temp folder emptied.
        Java cache emptied.
        File delete failed. C:\Documents and Settings\Tom.TODDY\Local Settings\Application Data\Mozilla\Firefox\Profiles\8ofl5alg.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
        File delete failed. C:\Documents and Settings\Tom.TODDY\Local Settings\Application Data\Mozilla\Firefox\Profiles\8ofl5alg.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
        File delete failed. C:\Documents and Settings\Tom.TODDY\Local Settings\Application Data\Mozilla\Firefox\Profiles\8ofl5alg.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
        File delete failed. C:\Documents and Settings\Tom.TODDY\Local Settings\Application Data\Mozilla\Firefox\Profiles\8ofl5alg.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
        File delete failed. C:\Documents and Settings\Tom.TODDY\Local Settings\Application Data\Mozilla\Firefox\Profiles\8ofl5alg.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
        File delete failed. C:\Documents and Settings\Tom.TODDY\Local Settings\Application Data\Mozilla\Firefox\Profiles\8ofl5alg.default\XUL.mfl scheduled to be deleted on reboot.
        FireFox cache emptied.
        Temp folders emptied.
        Explorer started successfully

        OTMoveIt3 by OldTimer - Version 1.0.4.2 log created on 10092008_174951

        Files moved on Reboot...
        File C:\DOCUME~1\TOM~1.TOD\LOCALS~1\Temp\etilqs_I9NW2lccHa8DhyjUg8vb not found!
        C:\DOCUME~1\TOM~1.TOD\LOCALS~1\Temp\hpodvd09.log moved successfully.
        C:\DOCUME~1\TOM~1.TOD\LOCALS~1\Temp\~DF4EC1.tmp moved successfully.
        C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT moved successfully.
        C:\Documents and Settings\Tom.TODDY\Local Settings\Application Data\Mozilla\Firefox\Profiles\8ofl5alg.default\Cache\_CACHE_001_ moved successfully.
        C:\Documents and Settings\Tom.TODDY\Local Settings\Application Data\Mozilla\Firefox\Profiles\8ofl5alg.default\Cache\_CACHE_002_ moved successfully.
        C:\Documents and Settings\Tom.TODDY\Local Settings\Application Data\Mozilla\Firefox\Profiles\8ofl5alg.default\Cache\_CACHE_003_ moved successfully.
        C:\Documents and Settings\Tom.TODDY\Local Settings\Application Data\Mozilla\Firefox\Profiles\8ofl5alg.default\Cache\_CACHE_MAP_ moved successfully.
        C:\Documents and Settings\Tom.TODDY\Local Settings\Application Data\Mozilla\Firefox\Profiles\8ofl5alg.default\urlclassifier3.sqlite moved successfully.
        C:\Documents and Settings\Tom.TODDY\Local Settings\Application Data\Mozilla\Firefox\Profiles\8ofl5alg.default\XUL.mfl moved successfully.

        ##################################
        HijackThis says:
        ##################################

        Logfile of HijackThis v1.99.1
        Scan saved at 18:01:21, on 09/10/2008
        Platform: Windows XP SP3 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16705)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
        C:\WINDOWS\notepad.exe
        C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
        C:\WINDOWS\BCMSMMSG.exe
        C:\Program Files\Bonjour\mDNSResponder.exe
        C:\WINDOWS\system32\cisvc.exe
        C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
        C:\WINDOWS\System32\DSentry.exe
        C:\WINDOWS\System32\CTsvcCDA.exe
        C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
        C:\Program Files\Common Files\Dell\EUSW\Support.exe
        C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
        C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
        C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
        C:\Program Files\Logitech\QuickCam\Quickcam.exe
        C:\WINDOWS\system32\nvsvc32.exe
        C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
        C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
        C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\iTunes\iTunesHelper.exe
        C:\PROGRA~1\AVG\AVG8\avgtray.exe
        C:\WINDOWS\system32\RUNDLL32.EXE
        C:\WINDOWS\system32\ctfmon.exe
        C:\WINDOWS\System32\MsPMSPSv.exe
        C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
        C:\PROGRA~1\AVG\AVG8\avgrsx.exe
        C:\Program Files\Canon\CAL\CALMAIN.exe
        C:\Program Files\Digital Line Detect\DLG.exe
        C:\Program Files\FinePixViewer\QuickDCF2.exe
        C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
        C:\Program Files\WinZip\WZQKPICK.EXE
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
        C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
        C:\Program Files\iPod\bin\iPodService.exe
        C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
        C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
        C:\Program Files\Internet Explorer\Iexplore.exe
        C:\Program Files\Common Files\Teleca Shared\Generic.exe
        C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
        C:\WINDOWS\system32\cidaemon.exe
        C:\WINDOWS\system32\cidaemon.exe
        C:\Program Files\HijackThis\HijackThis.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.ie
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
        R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: BitComet Helper - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.3.28.dll
        O2 - BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
        O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
        O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
        O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
        O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
        O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
        O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
        O4 - HKLM\..\Run: [BuildBU] c:\dell\bldbubg.exe
        O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
        O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
        O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
        O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
        O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
        O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
        O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
        O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
        O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
        O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
        O4 - Global Startup: Digital Line Detect.lnk = ?
        O4 - Global Startup: ExifLauncher2.lnk = C:\Program Files\FinePixViewer\QuickDCF2.exe
        O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
        O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
        O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
        O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
        O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
        O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
        O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
        O11 - Options group: [INTERNATIONAL] International*
        O14 - IERESET.INF: START_PAGE_URL=http://www.eircom.net
        O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} - http://www.may.ie/wfplayer/tdserver.cab
        O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1139944226076
        O16 - DPF: {6F750203-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/BUM_WIN_IE_2/axofupld.cab
        O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
        O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
        O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
        O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
        O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
        O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
        O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
        O20 - AppInit_DLLs: avgrsstx.dll
        O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
        O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
        O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
        O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
        O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
        O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
        O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
        O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
        O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
        O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
        O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
        O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
        O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
        O23 - Service: Oracle OLAP 9.0.1.0.1 (OLAPServer) - Oracle Corporation - C:\oracle\ora90\bin\xsolap.exe
        O23 - Service: Oracle OLAP Agent - Unknown owner - C:\oracle\ora90\bin\xsaagent.exe
        O23 - Service: OracleOraHome90PagingServer - Unknown owner - C:\oracle\ora90/bin/pagntsrv.exe
        O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
        O23 - Service: Sony SCSI Helper Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\Fsk\SonySCSIHelperService.exe
        O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
        O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe


      • Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


        Lets see what ComboFix shows, then we should be done


      • Closed Accounts Posts: 11 toddyl


        Hi. When I click on the link you suggest my IE and Firefox both say they cannot connect to server. When I try from work its fine and I can download what is required. Do I have something set that is preventing me accessing these sites. Can you please advise as I cannot get the last part you require at present.

        Thanks,

        Toddyl


      • Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


        Sounds like the rootkit is still there

        Can you transfer the tool over via a USB key or email it to yourself from your other PC


      • Closed Accounts Posts: 11 toddyl


        Finally managed to get that on PC, had to download it from work.
        Ran it and the outputted log says:

        ComboFix 08-10-09.06 - Tom 2008-10-10 17:51:58.1 - NTFSx86

        WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
        .

        ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
        .

        C:\WINDOWS\system32\tdssadw.dll
        C:\WINDOWS\system32\TDSSerrors.log
        C:\WINDOWS\system32\tdssinit.dll
        C:\WINDOWS\system32\tdssl.dll
        C:\WINDOWS\system32\tdsslog.dll
        C:\WINDOWS\system32\tdssmain.dll
        C:\WINDOWS\system32\tdssserf.dll
        C:\WINDOWS\system32\tdssserf1.dll
        C:\WINDOWS\system32\tdssservers.dat

        .
        ((((((((((((((((((((((((( Files Created from 2008-09-10 to 2008-10-10 )))))))))))))))))))))))))))))))
        .

        2008-10-09 17:49 . 2008-10-09 17:49 <DIR> d
        C:\_OTMoveIt
        2008-10-08 07:38 . 2008-10-08 07:38 <DIR> d
        C:\WINDOWS\Sun
        2008-10-07 22:19 . 2008-10-07 22:19 <DIR> d
        C:\rsit
        2008-10-07 22:19 . 2008-10-09 21:47 <DIR> d
        C:\Program Files\trend micro
        2008-10-05 01:59 . 2008-10-10 17:44 2,148 --a
        C:\WINDOWS\SYSTEM32\wpa.dbl
        2008-10-04 18:02 . 2008-10-04 18:02 <DIR> d
        C:\Program Files\Malwarebytes
        2008-10-04 18:02 . 2008-10-04 18:02 <DIR> d
        C:\Documents and Settings\Tom.TODDY\Application Data\Malwarebytes
        2008-10-04 18:02 . 2008-10-04 18:02 <DIR> d
        C:\Documents and Settings\All Users\Application Data\Malwarebytes
        2008-10-04 18:02 . 2008-09-10 00:04 38,528 --a
        C:\WINDOWS\SYSTEM32\DRIVERS\mbamswissarmy.sys
        2008-10-04 18:02 . 2008-09-10 00:03 17,200 --a
        C:\WINDOWS\SYSTEM32\DRIVERS\mbam.sys
        2008-10-04 17:46 . 2008-10-09 21:51 <DIR> d
        C:\Program Files\XoftSpySE
        2008-10-03 19:02 . 2008-10-03 19:42 <DIR> d
        C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Application Data\AVGTOOLBAR
        2008-09-28 11:31 . 2008-10-03 19:45 <DIR> d
        C:\Program Files\Yahoo!
        2008-09-28 11:31 . 2008-09-28 11:32 <DIR> d
        C:\Program Files\CCleaner
        2008-09-27 17:20 . 2008-10-08 12:35 <DIR> d--h
        C:\$AVG8.VAULT$
        2008-09-25 18:34 . 2008-10-10 17:46 <DIR> d
        C:\WINDOWS\SYSTEM32\DRIVERS\Avg
        2008-09-25 18:34 . 2008-09-25 18:34 <DIR> d
        C:\Program Files\AVG
        2008-09-25 18:34 . 2008-10-01 19:53 <DIR> d
        C:\Documents and Settings\Tom.TODDY\Application Data\AVGTOOLBAR
        2008-09-25 18:34 . 2008-10-03 19:16 <DIR> d
        C:\Documents and Settings\All Users\Application Data\avg8
        2008-09-25 18:34 . 2008-09-25 18:34 97,928 --a
        C:\WINDOWS\SYSTEM32\DRIVERS\avgldx86.sys
        2008-09-25 18:34 . 2008-09-25 18:34 10,520 --a
        C:\WINDOWS\SYSTEM32\avgrsstx.dll
        2008-09-23 21:46 . 2008-09-23 21:46 <DIR> d
        C:\WINDOWS\SYSTEM32\scripting
        2008-09-23 21:46 . 2008-09-23 21:46 <DIR> d
        C:\WINDOWS\SYSTEM32\en
        2008-09-23 21:46 . 2008-09-23 21:46 <DIR> d
        C:\WINDOWS\l2schemas
        2008-09-23 21:21 . 2008-09-23 21:21 <DIR> d
        C:\Documents and Settings\All Users\Application Data\Marlin
        2008-09-23 20:19 . 2008-04-14 01:12 1,306,624
        C:\WINDOWS\SYSTEM32\msxml6.dll
        2008-09-23 20:18 . 2008-04-14 01:11 650,752
        C:\WINDOWS\SYSTEM32\dot3ui.dll
        2008-09-23 20:17 . 2008-04-14 01:11 136,192
        C:\WINDOWS\SYSTEM32\aaclient.dll
        2008-09-23 19:22 . 2008-09-23 19:22 <DIR> d
        C:\Program Files\iPod
        2008-09-23 19:21 . 2008-09-23 19:23 <DIR> d
        C:\Program Files\iTunes
        2008-09-23 19:21 . 2008-09-23 19:23 <DIR> d
        C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
        2008-09-23 19:15 . 2008-09-23 19:15 <DIR> d
        C:\Program Files\Bonjour
        2008-09-23 19:10 . 2008-09-23 19:13 <DIR> d
        C:\Program Files\QuickTime
        2008-09-20 11:49 . 2008-09-20 11:49 <DIR> d
        C:\Documents and Settings\All Users\Application Data\kinoma

        .
        (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
        .
        2008-10-04 16:11
        d
        w C:\Program Files\devolo
        2008-09-23 19:32
        d
        w C:\Program Files\Symantec
        2008-09-23 19:32
        d
        w C:\Program Files\Common Files\Symantec Shared
        2008-09-23 18:40
        d
        w C:\Documents and Settings\All Users\Application Data\Symantec
        2008-09-20 10:48
        d
        w C:\Program Files\Sony
        2008-09-20 10:48
        d
        w C:\Program Files\Common Files\Sony Shared
        2008-09-11 13:09
        d
        w C:\Documents and Settings\All Users\Application Data\Microsoft Help
        2008-08-30 10:14
        d
        w C:\Program Files\Apple Software Update
        2008-08-29 09:18 87,336 ----a-w C:\WINDOWS\SYSTEM32\dns-sd.exe
        2008-08-29 08:53 61,440 ----a-w C:\WINDOWS\SYSTEM32\dnssd.dll
        2008-08-14 19:10
        d
        w C:\Program Files\FinePixViewer
        2008-08-14 19:07
        d
        w C:\Documents and Settings\Tom.TODDY\Application Data\ZoomBrowser EX
        2008-07-18 21:10 94,920 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\cdm.dll
        2008-07-18 21:10 94,920 ----a-w C:\WINDOWS\SYSTEM32\cdm.dll
        2008-07-18 21:10 53,448 ----a-w C:\WINDOWS\SYSTEM32\wuauclt.exe
        2008-07-18 21:10 53,448 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wuauclt.exe
        2008-07-18 21:10 45,768 ----a-w C:\WINDOWS\SYSTEM32\wups2.dll
        2008-07-18 21:10 36,552 ----a-w C:\WINDOWS\SYSTEM32\wups.dll
        2008-07-18 21:10 36,552 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wups.dll
        2008-07-18 21:09 563,912 ----a-w C:\WINDOWS\SYSTEM32\wuapi.dll
        2008-07-18 21:09 563,912 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wuapi.dll
        2008-07-18 21:09 325,832 ----a-w C:\WINDOWS\SYSTEM32\wucltui.dll
        2008-07-18 21:09 325,832 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wucltui.dll
        2008-07-18 21:09 205,000 ----a-w C:\WINDOWS\SYSTEM32\wuweb.dll
        2008-07-18 21:09 205,000 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wuweb.dll
        2008-07-18 21:09 1,811,656 ----a-w C:\WINDOWS\SYSTEM32\wuaueng.dll
        2008-07-18 21:09 1,811,656 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wuaueng.dll
        2008-07-18 21:07 270,880 ----a-w C:\WINDOWS\SYSTEM32\mucltui.dll
        2008-07-18 21:07 210,976 ----a-w C:\WINDOWS\SYSTEM32\muweb.dll
        .

        ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
        .
        .
        *Note* empty entries & legit default entries are not shown
        REGEDIT4

        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-04-14 1695232]
        "NvMediaCenter"="C:\WINDOWS\system32\NVMCTRAY.DLL" [2003-10-06 49152]
        "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
        "LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2007-02-21 67128]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2003-10-06 5058560]
        "diagent"="C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" [2002-04-03 135264]
        "UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 90112]
        "DVDSentry"="C:\WINDOWS\System32\DSentry.exe" [2002-08-14 28672]
        "AdaptecDirectCD"="C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-04-10 679936]
        "BuildBU"="c:\dell\bldbubg.exe" [2001-12-06 53248]
        "DwlClient"="C:\Program Files\Common Files\Dell\EUSW\Support.exe" [2002-12-12 221184]
        "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
        "LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 563984]
        "LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 2178832]
        "GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
        "Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2006-11-24 487424]
        "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
        "REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.EXE" [2002-02-04 53248]
        "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
        "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-09-06 413696]
        "AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-03 111936]
        "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-09-10 289576]
        "AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-10-01 1234712]
        "nwiz"="nwiz.exe" [2003-10-06 C:\WINDOWS\SYSTEM32\nwiz.exe]
        "BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 C:\WINDOWS\BCMSMMSG.exe]

        [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
        "CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2008-04-14 15360]

        C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
        Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2003-03-14 45056]
        ExifLauncher2.lnk - C:\Program Files\FinePixViewer\QuickDCF2.exe [2008-05-05 303104]
        HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]
        HP Photosmart Premier Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2006-02-10 73728]
        Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-02-21 67128]
        WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2007-12-03 394856]

        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
        "AppInit_DLLs"=avgrsstx.dll

        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
        "msacm.ctmp3"= C:\WINDOWS\System32\ctmp3.acm

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
        "%windir%\\system32\\sessmgr.exe"=
        "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
        "C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
        "C:\\Program Files\\uTorrent\\utorrent.exe"=
        "C:\\Program Files\\devolo\\informer\\devinf.exe"=
        "C:\\Program Files\\devolo\\easyshare\\easyshare.exe"=
        "C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
        "C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
        "C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
        "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
        "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
        "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
        "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
        "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
        "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
        "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
        "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
        "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
        "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
        "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
        "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
        "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
        "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
        "C:\\Program Files\\Skype\\Phone\\Skype.exe"=
        "C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
        "C:\\Program Files\\iTunes\\iTunes.exe"=
        "C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
        "10140:TCP"= 10140:TCP:BitComet 10140 TCP
        "10140:UDP"= 10140:UDP:BitComet 10140 UDP

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
        "AllowRedirect"= 1 (0x1)

        R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-09-25 97928]
        R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-09-25 231704]
        R2 PLCNDIS5;PLCNDIS5 NDIS Protocol Driver;C:\WINDOWS\system32\plcndis5.sys [2004-05-17 17280]
        S3 ggflt;SEMC USB Flash Driver Filter;C:\WINDOWS\system32\DRIVERS\ggflt.sys [2008-06-08 13352]
        S3 MTK;Media Technology Kernel Driver;C:\WINDOWS\system32\Drivers\fide.sys [2006-11-01 14468]
        S3 OracleOraHome90PagingServer;OracleOraHome90PagingServer;C:\oracle\ora90/bin/pagntsrv.exe [2001-08-28 52224]
        S3 PLCMPR5;PLCMPR5 NDIS Protocol Driver;C:\WINDOWS\system32\PLCMPR5.SYS [ ]
        S3 PRSUSB;Sony Reader;C:\WINDOWS\system32\Drivers\PRSUSB.sys [2006-11-21 18944]

        *Newly Created Service* - CATCHME
        .
        Contents of the 'Scheduled Tasks' folder

        2008-10-03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
        - C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

        2008-10-09 C:\WINDOWS\Tasks\Symantec NetDetect.job
        - C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE [2004-12-14 13:24]

        2008-10-10 C:\WINDOWS\Tasks\XoftSpySE 2.job
        - C:\Program Files\XoftSpySE\XoftSpy.exe [2008-10-01 15:37]

        2008-10-04 C:\WINDOWS\Tasks\XoftSpySE.job
        - C:\Program Files\XoftSpySE\XoftSpy.exe [2008-10-01 15:37]
        .
        .
        Supplementary Scan
        .
        FireFox -: Profile - C:\Documents and Settings\Tom.TODDY\Application Data\Mozilla\Firefox\Profiles\8ofl5alg.default\
        FF -: plugin - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
        FF -: plugin - C:\Program Files\Yahoo!\Common\npyaxmpb.dll
        .

        **************************************************************************

        catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
        Rootkit scan 2008-10-10 18:01:17
        Windows 5.1.2600 Service Pack 3 NTFS

        scanning hidden processes ...

        scanning hidden autostart entries ...

        HKLM\Software\Microsoft\Windows\CurrentVersion\Run
        DwlClient = C:\Program Files\Common Files\Dell\EUSW\Support.exe?l?e?s?\?D?e?l?l?\?E?U?S?W?\?S?u?p?p?o?r?t?.?e?x?e????????:??????x???0???X???????????0???P???? ?w? ?w)??p????????(???w????U?w????????????0??????w, ?w?M?wW??w???w)??p????????x'@?????????X????????"@?e?????

        scanning hidden files ...

        scan completed successfully
        hidden files: 0

        **************************************************************************

        [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\TDSSserv]
        "imagepath"="\systemroot\system32\drivers\TDSSserv.sys"

        [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\OracleOraHome90PagingServer]
        "ImagePath"="C:\oracle\ora90/bin/pagntsrv.exe"
        .
        Completion time: 2008-10-10 18:06:20
        ComboFix-quarantined-files.txt 2008-10-10 17:06:15

        Pre-Run: 64,720,990,208 bytes free
        Post-Run: 64,692,441,088 bytes free

        210 --- E O F --- 2008-09-25 17:38:45


      • Advertisement
      • Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


        Perfect

        1. Close any open browsers.

        2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

        3. Open notepad and copy/paste the text in the quotebox below into it:
        File::

        Folder::

        Registry::
        [-HKEY_LOCAL_MACHINE\system\ControlSet001\Services\TDSSserv]

        Sysrst::

        Driver::

        Save this as CFScript.txt, in the same location as ComboFix.exe


        CFScriptB-4.gif

        Refering to the picture above, drag CFScript into ComboFix.exe

        When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.


      • Closed Accounts Posts: 11 toddyl


        Ok, output of that is:

        ComboFix 08-10-09.06 - Tom 2008-10-11 10:36:25.2 - NTFSx86
        Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.168 [GMT 1:00]
        Running from: C:\Documents and Settings\Tom.TODDY\Desktop\ComboFix.exe
        Command switches used :: C:\Documents and Settings\Tom.TODDY\Desktop\CFScript.txt
        * Created a new restore point

        WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
        .

        ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
        .

        E:\Autorun.inf

        .
        ((((((((((((((((((((((((( Files Created from 2008-09-11 to 2008-10-11 )))))))))))))))))))))))))))))))
        .

        2008-10-10 19:03 . 2008-10-10 19:04 <DIR> d
        C:\Program Files\iTunes
        2008-10-10 19:03 . 2008-10-10 19:03 <DIR> d
        C:\Program Files\iPod
        2008-10-10 19:03 . 2008-10-10 19:04 <DIR> d
        C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
        2008-10-09 17:49 . 2008-10-09 17:49 <DIR> d
        C:\_OTMoveIt
        2008-10-08 07:38 . 2008-10-08 07:38 <DIR> d
        C:\WINDOWS\Sun
        2008-10-07 22:19 . 2008-10-07 22:19 <DIR> d
        C:\rsit
        2008-10-07 22:19 . 2008-10-09 21:47 <DIR> d
        C:\Program Files\trend micro
        2008-10-05 01:59 . 2008-10-11 10:28 2,148 --a
        C:\WINDOWS\SYSTEM32\wpa.dbl
        2008-10-04 18:02 . 2008-10-04 18:02 <DIR> d
        C:\Program Files\Malwarebytes
        2008-10-04 18:02 . 2008-10-04 18:02 <DIR> d
        C:\Documents and Settings\Tom.TODDY\Application Data\Malwarebytes
        2008-10-04 18:02 . 2008-10-04 18:02 <DIR> d
        C:\Documents and Settings\All Users\Application Data\Malwarebytes
        2008-10-04 18:02 . 2008-09-10 00:04 38,528 --a
        C:\WINDOWS\SYSTEM32\DRIVERS\mbamswissarmy.sys
        2008-10-04 18:02 . 2008-09-10 00:03 17,200 --a
        C:\WINDOWS\SYSTEM32\DRIVERS\mbam.sys
        2008-10-04 17:46 . 2008-10-09 21:51 <DIR> d
        C:\Program Files\XoftSpySE
        2008-10-03 19:02 . 2008-10-03 19:42 <DIR> d
        C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Application Data\AVGTOOLBAR
        2008-09-28 11:31 . 2008-10-03 19:45 <DIR> d
        C:\Program Files\Yahoo!
        2008-09-28 11:31 . 2008-09-28 11:32 <DIR> d
        C:\Program Files\CCleaner
        2008-09-27 17:20 . 2008-10-08 12:35 <DIR> d--h
        C:\$AVG8.VAULT$
        2008-09-25 18:34 . 2008-10-10 18:54 <DIR> d
        C:\WINDOWS\SYSTEM32\DRIVERS\Avg
        2008-09-25 18:34 . 2008-09-25 18:34 <DIR> d
        C:\Program Files\AVG
        2008-09-25 18:34 . 2008-10-01 19:53 <DIR> d
        C:\Documents and Settings\Tom.TODDY\Application Data\AVGTOOLBAR
        2008-09-25 18:34 . 2008-10-03 19:16 <DIR> d
        C:\Documents and Settings\All Users\Application Data\avg8
        2008-09-25 18:34 . 2008-09-25 18:34 97,928 --a
        C:\WINDOWS\SYSTEM32\DRIVERS\avgldx86.sys
        2008-09-25 18:34 . 2008-09-25 18:34 10,520 --a
        C:\WINDOWS\SYSTEM32\avgrsstx.dll
        2008-09-23 21:46 . 2008-09-23 21:46 <DIR> d
        C:\WINDOWS\SYSTEM32\scripting
        2008-09-23 21:46 . 2008-09-23 21:46 <DIR> d
        C:\WINDOWS\SYSTEM32\en
        2008-09-23 21:46 . 2008-09-23 21:46 <DIR> d
        C:\WINDOWS\l2schemas
        2008-09-23 21:21 . 2008-09-23 21:21 <DIR> d
        C:\Documents and Settings\All Users\Application Data\Marlin
        2008-09-23 20:19 . 2008-04-14 01:12 1,306,624
        C:\WINDOWS\SYSTEM32\msxml6.dll
        2008-09-23 20:18 . 2008-04-14 01:11 650,752
        C:\WINDOWS\SYSTEM32\dot3ui.dll
        2008-09-23 20:17 . 2008-04-14 01:11 136,192
        C:\WINDOWS\SYSTEM32\aaclient.dll
        2008-09-23 19:15 . 2008-09-23 19:15 <DIR> d
        C:\Program Files\Bonjour
        2008-09-23 19:10 . 2008-09-23 19:13 <DIR> d
        C:\Program Files\QuickTime
        2008-09-20 11:49 . 2008-09-20 11:49 <DIR> d
        C:\Documents and Settings\All Users\Application Data\kinoma

        .
        (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
        .
        2008-10-04 16:11
        d
        w C:\Program Files\devolo
        2008-09-23 19:32
        d
        w C:\Program Files\Symantec
        2008-09-23 19:32
        d
        w C:\Program Files\Common Files\Symantec Shared
        2008-09-23 18:40
        d
        w C:\Documents and Settings\All Users\Application Data\Symantec
        2008-09-20 10:48
        d
        w C:\Program Files\Sony
        2008-09-20 10:48
        d
        w C:\Program Files\Common Files\Sony Shared
        2008-09-11 13:09
        d
        w C:\Documents and Settings\All Users\Application Data\Microsoft Help
        2008-08-30 10:14
        d
        w C:\Program Files\Apple Software Update
        2008-08-29 09:18 87,336 ----a-w C:\WINDOWS\SYSTEM32\dns-sd.exe
        2008-08-29 08:53 61,440 ----a-w C:\WINDOWS\SYSTEM32\dnssd.dll
        2008-08-14 19:10
        d
        w C:\Program Files\FinePixViewer
        2008-08-14 19:07
        d
        w C:\Documents and Settings\Tom.TODDY\Application Data\ZoomBrowser EX
        2008-07-18 21:10 94,920 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\cdm.dll
        2008-07-18 21:10 94,920 ----a-w C:\WINDOWS\SYSTEM32\cdm.dll
        2008-07-18 21:10 53,448 ----a-w C:\WINDOWS\SYSTEM32\wuauclt.exe
        2008-07-18 21:10 53,448 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wuauclt.exe
        2008-07-18 21:10 45,768 ----a-w C:\WINDOWS\SYSTEM32\wups2.dll
        2008-07-18 21:10 36,552 ----a-w C:\WINDOWS\SYSTEM32\wups.dll
        2008-07-18 21:10 36,552 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wups.dll
        2008-07-18 21:09 563,912 ----a-w C:\WINDOWS\SYSTEM32\wuapi.dll
        2008-07-18 21:09 563,912 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wuapi.dll
        2008-07-18 21:09 325,832 ----a-w C:\WINDOWS\SYSTEM32\wucltui.dll
        2008-07-18 21:09 325,832 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wucltui.dll
        2008-07-18 21:09 205,000 ----a-w C:\WINDOWS\SYSTEM32\wuweb.dll
        2008-07-18 21:09 205,000 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wuweb.dll
        2008-07-18 21:09 1,811,656 ----a-w C:\WINDOWS\SYSTEM32\wuaueng.dll
        2008-07-18 21:09 1,811,656 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wuaueng.dll
        2008-07-18 21:07 270,880 ----a-w C:\WINDOWS\SYSTEM32\mucltui.dll
        2008-07-18 21:07 210,976 ----a-w C:\WINDOWS\SYSTEM32\muweb.dll
        .

        ((((((((((((((((((((((((((((( snapshot@2008-10-10_18.05.43.46 )))))))))))))))))))))))))))))))))))))))))
        .
        + 2008-10-10 18:04:32 102,400 ----a-r C:\WINDOWS\Installer\{DDDE0BE3-0CBE-4BF6-B75A-E3F69C947843}\iTunesIco.exe
        + 2008-10-01 12:01:28 32,000 -c--a-w C:\WINDOWS\SYSTEM32\DRVSTORE\usbaapl_246F92BBD6449C86FC3F3F28C40D59AC1F69C558\usbaapl.sys
        .
        ((((((((((((((((((((((((((((((((((((((( System Restore )))))))))))))))))))))))))))))))))))))))))))))))))))
        .

        C:\WINDOWS\Installer\{41B9E2CF-0B3F-442A-B5B3-592A4A355634}\iTunesIco.exe
        2008-09-23 19:25 102400 {B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0001503.exe

        C:\WINDOWS\SYSTEM32\DRIVERS\ddubmzak.sys
        {B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP0\A0001002.sysC:\WINDOWS\SYSTEM32\DRIVERS\hrhuvmt.sys
        2008-10-08 07:53 61440 {B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0001003.sys

        C:\WINDOWS\SYSTEM32\DRIVERS\etproku.sys
        2008-10-05 09:57 61440 {B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP0\A0000001.sys

        C:\WINDOWS\SYSTEM32\DRIVERS\iwdr.sys
        2008-10-06 07:46 61440 {B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP0\A0001001.sys

        C:\WINDOWS\SYSTEM32\DRIVERS\jnqkt.sys
        2008-10-09 21:44 61440 {B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0001004.sys

        C:\WINDOWS\SYSTEM32\DRIVERS\tdssserv.sys
        {B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0001005.sys

        C:\WINDOWS\SYSTEM32\DRVSTORE\DFx11.tmp\usbaapl.sys
        2008-07-10 09:35 32000 {B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0001094.sys

        C:\WINDOWS\SYSTEM32\tdssadw.dll
        2008-10-10 17:35 77824 {B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0001025.dll

        C:\WINDOWS\SYSTEM32\tdssinit.dll
        2008-10-10 17:35 53395 {B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0001026.dll

        C:\WINDOWS\SYSTEM32\TDSSl.dll
        2008-10-03 19:01 36864 {B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0001027.dll

        C:\WINDOWS\SYSTEM32\tdsslog.dll
        2008-10-10 17:35 11264 {B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0001028.dll

        C:\WINDOWS\SYSTEM32\tdssmain.dll
        2008-10-10 17:34 29696 {B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0001029.dll

        C:\WINDOWS\SYSTEM32\tdssserf.dll
        2008-10-10 17:35 12288 {B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0001030.dll

        C:\WINDOWS\SYSTEM32\tdssserf1.dll
        2008-10-08 19:32 8192 {B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0001031.dll
        .
        ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
        .
        .
        *Note* empty entries & legit default entries are not shown
        REGEDIT4

        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-04-14 1695232]
        "NvMediaCenter"="C:\WINDOWS\system32\NVMCTRAY.DLL" [2003-10-06 49152]
        "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
        "LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2007-02-21 67128]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2003-10-06 5058560]
        "diagent"="C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" [2002-04-03 135264]
        "UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 90112]
        "DVDSentry"="C:\WINDOWS\System32\DSentry.exe" [2002-08-14 28672]
        "AdaptecDirectCD"="C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-04-10 679936]
        "BuildBU"="c:\dell\bldbubg.exe" [2001-12-06 53248]
        "DwlClient"="C:\Program Files\Common Files\Dell\EUSW\Support.exe" [2002-12-12 221184]
        "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
        "LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 563984]
        "LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 2178832]
        "GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
        "Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2006-11-24 487424]
        "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
        "REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.EXE" [2002-02-04 53248]
        "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
        "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-09-06 413696]
        "AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-03 111936]
        "AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-10-01 1234712]
        "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
        "nwiz"="nwiz.exe" [2003-10-06 C:\WINDOWS\SYSTEM32\nwiz.exe]
        "BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 C:\WINDOWS\BCMSMMSG.exe]

        [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
        "CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2008-04-14 15360]

        C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
        Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2003-03-14 45056]
        ExifLauncher2.lnk - C:\Program Files\FinePixViewer\QuickDCF2.exe [2008-05-05 303104]
        HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]
        HP Photosmart Premier Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2006-02-10 73728]
        Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-02-21 67128]
        WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2007-12-03 394856]

        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
        "AppInit_DLLs"=avgrsstx.dll

        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
        "msacm.ctmp3"= C:\WINDOWS\System32\ctmp3.acm

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
        "%windir%\\system32\\sessmgr.exe"=
        "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
        "C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
        "C:\\Program Files\\uTorrent\\utorrent.exe"=
        "C:\\Program Files\\devolo\\informer\\devinf.exe"=
        "C:\\Program Files\\devolo\\easyshare\\easyshare.exe"=
        "C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
        "C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
        "C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
        "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
        "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
        "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
        "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
        "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
        "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
        "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
        "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
        "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
        "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
        "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
        "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
        "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
        "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
        "C:\\Program Files\\Skype\\Phone\\Skype.exe"=
        "C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
        "C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
        "C:\\Program Files\\iTunes\\iTunes.exe"=

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
        "10140:TCP"= 10140:TCP:BitComet 10140 TCP
        "10140:UDP"= 10140:UDP:BitComet 10140 UDP

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
        "AllowRedirect"= 1 (0x1)

        R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-09-25 97928]
        R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-09-25 231704]
        R2 PLCNDIS5;PLCNDIS5 NDIS Protocol Driver;C:\WINDOWS\system32\plcndis5.sys [2004-05-17 17280]
        S3 ggflt;SEMC USB Flash Driver Filter;C:\WINDOWS\system32\DRIVERS\ggflt.sys [2008-06-08 13352]
        S3 MTK;Media Technology Kernel Driver;C:\WINDOWS\system32\Drivers\fide.sys [2006-11-01 14468]
        S3 OracleOraHome90PagingServer;OracleOraHome90PagingServer;C:\oracle\ora90/bin/pagntsrv.exe [2001-08-28 52224]
        S3 PLCMPR5;PLCMPR5 NDIS Protocol Driver;C:\WINDOWS\system32\PLCMPR5.SYS [ ]
        S3 PRSUSB;Sony Reader;C:\WINDOWS\system32\Drivers\PRSUSB.sys [2006-11-21 18944]
        .
        Contents of the 'Scheduled Tasks' folder

        2008-10-10 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
        - C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

        2008-10-11 C:\WINDOWS\Tasks\Symantec NetDetect.job
        - C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE [2004-12-14 13:24]

        2008-10-11 C:\WINDOWS\Tasks\XoftSpySE 2.job
        - C:\Program Files\XoftSpySE\XoftSpy.exe [2008-10-01 15:37]

        2008-10-11 C:\WINDOWS\Tasks\XoftSpySE.job
        - C:\Program Files\XoftSpySE\XoftSpy.exe [2008-10-01 15:37]
        .

        **************************************************************************

        catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
        Rootkit scan 2008-10-11 10:41:50
        Windows 5.1.2600 Service Pack 3 NTFS

        scanning hidden processes ...

        scanning hidden autostart entries ...

        HKLM\Software\Microsoft\Windows\CurrentVersion\Run
        DwlClient = C:\Program Files\Common Files\Dell\EUSW\Support.exe?l?e?s?\?D?e?l?l?\?E?U?S?W?\?S?u?p?p?o?r?t?.?e?x?e????????:??????x???0???X???????????0???P???? ?w? ?w)??p????????(???w????U?w????????????0??????w, ?w?M?wW??w???w)??p????????x'@?????????X????????"@?e?????

        scanning hidden files ...

        scan completed successfully
        hidden files: 0

        **************************************************************************

        [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\OracleOraHome90PagingServer]
        "ImagePath"="C:\oracle\ora90/bin/pagntsrv.exe"
        .
        Completion time: 2008-10-11 10:46:09
        ComboFix-quarantined-files.txt 2008-10-11 09:46:02
        ComboFix2.txt 2008-10-10 17:06:22

        Pre-Run: 64,426,246,144 bytes free
        Post-Run: 64,488,407,040 bytes free

        234 --- E O F --- 2008-09-25 17:38:45


      • Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


        Hello

        Please download the OTMoveIt3 by OldTimer.
        • Save it to your desktop.
        • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
        • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
          :Processes
          explorer.exe
          
          :Services
          
          :Reg
          
          :Files
          C:\WINDOWS\SYSTEM32\DRIVERS\ddubmzak.sys
          C:\WINDOWS\SYSTEM32\DRIVERS\hrhuvmt.sys
          C:\WINDOWS\SYSTEM32\DRIVERS\etproku.sys
          C:\WINDOWS\SYSTEM32\DRIVERS\iwdr.sys
          C:\WINDOWS\SYSTEM32\DRIVERS\jnqkt.sys
          C:\WINDOWS\SYSTEM32\DRIVERS\tdssserv.sys
          
          
          :Commands
          [purity]
          [emptytemp]
          [start explorer]
          [Reboot]
          
        • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
        • Click the red Moveit! button.
        • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
        • Close OTMoveIt3
        Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.


      • Closed Accounts Posts: 11 toddyl


        Ok, output of running that is:

        ========== PROCESSES ==========
        Process explorer.exe killed successfully.
        ========== SERVICES/DRIVERS ==========
        ========== REGISTRY ==========
        ========== FILES ==========
        File/Folder C:\WINDOWS\SYSTEM32\DRIVERS\ddubmzak.sys not found.
        File/Folder C:\WINDOWS\SYSTEM32\DRIVERS\hrhuvmt.sys not found.
        File/Folder C:\WINDOWS\SYSTEM32\DRIVERS\etproku.sys not found.
        File/Folder C:\WINDOWS\SYSTEM32\DRIVERS\iwdr.sys not found.
        File/Folder C:\WINDOWS\SYSTEM32\DRIVERS\jnqkt.sys not found.
        File/Folder C:\WINDOWS\SYSTEM32\DRIVERS\tdssserv.sys not found.
        ========== COMMANDS ==========
        File delete failed. C:\DOCUME~1\TOM~1.TOD\LOCALS~1\Temp\etilqs_7dZbMatKroJbaO2oZdTA scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\TOM~1.TOD\LOCALS~1\Temp\hpodvd09.log scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\TOM~1.TOD\LOCALS~1\Temp\~DF5D29.tmp scheduled to be deleted on reboot.
        User's Temp folder emptied.
        User's Temporary Internet Files folder emptied.
        User's Internet Explorer cache folder emptied.
        Local Service Temp folder emptied.
        File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
        Local Service Temporary Internet Files folder emptied.
        File delete failed. C:\WINDOWS\temp\LVCOMSX.LOG scheduled to be deleted on reboot.
        Windows Temp folder emptied.
        Java cache emptied.
        File delete failed. C:\Documents and Settings\Tom.TODDY\Local Settings\Application Data\Mozilla\Firefox\Profiles\8ofl5alg.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
        File delete failed. C:\Documents and Settings\Tom.TODDY\Local Settings\Application Data\Mozilla\Firefox\Profiles\8ofl5alg.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
        File delete failed. C:\Documents and Settings\Tom.TODDY\Local Settings\Application Data\Mozilla\Firefox\Profiles\8ofl5alg.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
        File delete failed. C:\Documents and Settings\Tom.TODDY\Local Settings\Application Data\Mozilla\Firefox\Profiles\8ofl5alg.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
        File delete failed. C:\Documents and Settings\Tom.TODDY\Local Settings\Application Data\Mozilla\Firefox\Profiles\8ofl5alg.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
        File delete failed. C:\Documents and Settings\Tom.TODDY\Local Settings\Application Data\Mozilla\Firefox\Profiles\8ofl5alg.default\XUL.mfl scheduled to be deleted on reboot.
        FireFox cache emptied.
        Temp folders emptied.
        Explorer started successfully

        OTMoveIt3 by OldTimer - Version 1.0.4.2 log created on 10122008_181141

        Files moved on Reboot...
        File C:\DOCUME~1\TOM~1.TOD\LOCALS~1\Temp\etilqs_7dZbMatKroJbaO2oZdTA not found!
        C:\DOCUME~1\TOM~1.TOD\LOCALS~1\Temp\hpodvd09.log moved successfully.
        File C:\DOCUME~1\TOM~1.TOD\LOCALS~1\Temp\~DF5D29.tmp not found!
        C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat moved successfully.
        C:\WINDOWS\temp\LVCOMSX.LOG moved successfully.
        C:\Documents and Settings\Tom.TODDY\Local Settings\Application Data\Mozilla\Firefox\Profiles\8ofl5alg.default\Cache\_CACHE_001_ moved successfully.
        C:\Documents and Settings\Tom.TODDY\Local Settings\Application Data\Mozilla\Firefox\Profiles\8ofl5alg.default\Cache\_CACHE_002_ moved successfully.
        C:\Documents and Settings\Tom.TODDY\Local Settings\Application Data\Mozilla\Firefox\Profiles\8ofl5alg.default\Cache\_CACHE_003_ moved successfully.
        C:\Documents and Settings\Tom.TODDY\Local Settings\Application Data\Mozilla\Firefox\Profiles\8ofl5alg.default\Cache\_CACHE_MAP_ moved successfully.
        C:\Documents and Settings\Tom.TODDY\Local Settings\Application Data\Mozilla\Firefox\Profiles\8ofl5alg.default\urlclassifier3.sqlite moved successfully.
        C:\Documents and Settings\Tom.TODDY\Local Settings\Application Data\Mozilla\Firefox\Profiles\8ofl5alg.default\XUL.mfl moved successfully.


      • Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


        Your logs are clean

        Follow these steps to uninstall Combofix and tools used in the removal of malware
        • Click START then RUN
        • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.
          CF_Cleanup.png


        • Make sure you have an Internet Connection.
        • Download OTCleanIt to your desktop and run it
        • A list of tool components used in the Cleanup of malware will be downloaded.
        • If your Firewall or Real Time protection attempts to block OTCleanUp to reach the Internet, please allow the application to do so.
        • Click Yes to beging the Cleanup process and remove these components, including this application.
        • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.



        Please download JavaRa to your desktop and unzip it to its own folder
        • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
        • Accept any prompts.
        • Open JavaRa.exe again and select Search For Updates.
        • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.


        Your using an old version of Adobe Acrobat Reader, this can leave your pc open to vulnerabilities, you can update it here :
        http://www.adobe.com/products/acrobat/readstep2.html




        Below I have included a number of recommendations for how to protect your computer against malware infections.

        * Keep Windows updated by regularly checking their website at :
        http://windowsupdate.microsoft.com/
        This will ensure your computer has always the latest security updates available installed on your computer.

        * To reduce re-infection for malware in the future, I strongly recommend installing these free programs:

        SpywareBlaster protects against bad ActiveX
        IE-SPYAD puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all
        Have a look at this tutorial for IE-Spyad here

        * SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program or there will be a conflict.

        Make Internet Explorer more secure
        • Click Start > Run
        • Type Inetcpl.cpl & click OK
        • Click on the Security tab
        • Click Reset all zones to default level
        • Make sure the Internet Zone is selected & Click Custom level
        • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
        • Next Click OK, then Apply button and then OK to exit the Internet Properties page.


        *ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.

        *NoScript - Addon for Firefox that stops all scripts from running on websites. Stops malicious software from invading via flash, java, javascript, and many other entry points.

        *Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

        * MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

        * Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
        secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
        blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from
        Here

        * Take a good look at the following suggestions for malware prevention by reading Tony Klein’s article 'How Did I Get Infected In The First Place'
        Here

        Thank you for your patience, and performing all of the procedures requested.


      • Registered Users, Registered Users 2 Posts: 9 petermacn


        Lab 2009 is a particularily nasty virus doing the rounds. It infects your pc then sends you to a site where you can download a fix but you have to pay. I found a program which got rid of it . It is called Malwarebytes and it is a free download. I post this in the hope it will help someone who is stuck with it.


      Advertisement