Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

I've had trojan horses and keyloggers. Computer is slowww.

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

Re: I've had trojan horses and keyloggers. Computer is slowww.

Unread postby Shaba » September 12th, 2008, 3:47 am

Thanks for info.

Copy text below to Notepad and save it as remserv.bat (save it as all files, *.*)

@ECHO OFF
sc stop "F-Secure Gatekeeper Handler Starter"
sc stop FSAUA
sc stop FSDFWD
sc stop FSMA
sc delete "F-Secure Gatekeeper Handler Starter"
sc delete FSAUA
sc delete FSDFWD
sc delete FSMA

It should look like this -> Image

Doubleclick remserv.bat; black dos windows will flash, that's normal.

Reboot.

Re-run rsit.

Post a fresh rsit log, please.
User avatar
Shaba
Admin/Teacher Emeritus
 
Posts: 26974
Joined: March 24th, 2006, 4:42 am
Location: Finland
Advertisement
Register to Remove

Re: I've had trojan horses and keyloggers. Computer is slowww.

Unread postby VioletPurple04 » September 13th, 2008, 5:08 am

Logfile of random's system information tool (written by random/random)
Run by Mrs. Kennedy at 2008-09-13 03:03:56
Microsoft® Windows Vista™ Home Premium
System drive C: has 137 GB (60%) free of 228 GB
Total RAM: 1013 MB (27% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:04:13 AM, on 9/13/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v8.00 (8.00.6001.17184)
Boot mode: Normal

Running processes:
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Intel\IntelDH\CCU\CCU_TrayIcon.exe
C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe
C:\Windows\zHotkey.exe
C:\Windows\ModPS2Key.exe
C:\Windows\sttray.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Common Files\AOL\1171674555\ee\aolsoftware.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\PROGRAM FILES\WINDOWS DEFENDER\MSASCUI.EXE
C:\Program Files\Intel\IntelDH\CCU\CCU_Engine.exe
C:\Users\Mrs. Kennedy\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Mrs. Kennedy.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/def ... .yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/def ... .yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/def ... earch.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/def ... .yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/def ... .yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=c:\windows\system32\userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: BrowserConnector Object - {0D84AC30-5186-4CD9-8FD8-4A1382D5F0F3} - C:\Windows\system32\osbaselnj.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\google\BAE.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [CCUTRAYICON] C:\Program Files\Intel\IntelDH\CCU\CCU_TrayIcon.exe
O4 - HKLM\..\Run: [NMSSupport] "C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe" /startup
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [ShowWnd] ShowWnd.exe
O4 - HKLM\..\Run: [ModPS2] ModPS2Key.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1171674555\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [Media Codec Update Service] C:\Program Files\Essentials Codec Pack\update.exe -silent
O4 - HKLM\..\Run: [masqform.exe] C:\Users\Mrs. Kennedy\Desktop\masqform.exe -UpdateCurrentUser
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-4003477587-3145471023-3728799210-1000\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'IUSR_NMPR')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Open with WordPerfect - C:\Program Files\WordPerfect Office X3\Programs\WPLauncher.hta
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200 ... plugin.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} (get_atlcom Class) - http://apps.corel.com/nos_dl_manager_de ... Plugin.ocx
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Fac ... loader.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windows ... 0992529880
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://lance-violet.spaces.live.com/Pho ... den-us.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://3dlifeplayer.dl.3dvia.com/player ... taller.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\Windows\system32\versionx.dll,avgrsstx.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Intel(R) Alert Service (AlertService) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\EMBARQ Online Security\Anti-Virus\fsgk32st.exe
O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\EMBARQ Online Security\FSAUA\program\fsaua.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\EMBARQ Online Security\FWES\Program\fsdfwd.exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\EMBARQ Online Security\Common\FSMA32.EXE
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel(R) Software Services Manager (ISSM) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Intel(R) Viiv(TM) Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
O23 - Service: Intel(R) Application Tracker (MCLServiceATL) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: ProtexisLicensing - Unknown owner - C:\Windows\system32\PSIService.exe
O23 - Service: Intel(R) Remoting Service (Remote UI Service) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
O23 - Service: System kernel integrity service (Scprtn) - SearchHelp, Inc. - C:\Windows\system32\mtstocomk.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
O23 - Service: UStorage Server Service - OTi - C:\Windows\system32\UStorSrv.exe

--
End of file - 13694 bytes

Registry dump

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-12-18 59032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0D84AC30-5186-4CD9-8FD8-4A1382D5F0F3}]
BrowserConnector Object - C:\Windows\system32\osbaselnj.dll [2008-09-09 118784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG8\avgssie.dll [2008-08-30 455960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0\bin\ssv.dll [2006-12-21 501384]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2007-09-20 328752]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
AVG Security Toolbar - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2008-08-18 2055960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA6319C0-31B7-401E-A518-A07C3DB8F777}]
CBrowserHelperObject Object - c:\google\BAE.dll [2006-01-31 94208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{A057A204-BACC-4D26-9990-79A187E2698E} - AVG Security Toolbar - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2008-08-18 2055960]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"CCUTRAYICON"=C:\Program Files\Intel\IntelDH\CCU\CCU_TrayIcon.exe [2006-11-18 182744]
"NMSSupport"=C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe [2006-09-26 423424]
"CHotkey"=C:\Windows\zHotkey.exe [2006-11-07 547840]
"ShowWnd"=C:\Windows\ShowWnd.exe [2005-01-27 36864]
"ModPS2"=C:\Windows\ModPS2Key.exe [2006-11-07 53248]
"SigmatelSysTrayApp"=C:\Windows\sttray.exe [2006-11-01 303104]
"IAAnotif"=C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe [2006-09-29 151552]
"HostManager"=C:\Program Files\Common Files\AOL\1171674555\ee\AOLSoftware.exe [2007-05-25 42032]
"Media Codec Update Service"=C:\Program Files\Essentials Codec Pack\update.exe [2007-04-08 303104]
"masqform.exe"=C:\Users\Mrs. Kennedy\Desktop\masqform.exe -UpdateCurrentUser []
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2006-12-12 98304]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2006-12-12 106496]
"Persistence"=C:\Windows\system32\igfxpers.exe [2006-12-12 81920]
"LogitechCommunicationsManager"=C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe [2007-10-25 563984]
"AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe [2008-08-30 1235736]
"WinPatrol"=C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe [2008-07-04 333120]
"Malwarebytes Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2008-09-08 1253040]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2008-09-06 413696]
"AppleSyncNotifier"=C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe [2008-09-03 111936]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2008-09-08 289576]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2006-11-02 125440]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2008-04-10 1232896]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2006-11-02 201728]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

C:\Users\Mrs. Kennedy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\Windows\system32\versionx.dll,avgrsstx.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2006-12-12 212992]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KmReg]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NtLclIpc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Scprtn]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\KmReg]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NtLclIpc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Scprtn]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

File associations

.js - edit -

List of files/folders created in the last three months

2008-09-10 07:50:46 ----A---- C:\Windows\system32\GEARAspi.dll
2008-09-10 07:50:45 ----DC---- C:\Windows\system32\DRVSTORE
2008-09-10 07:50:23 ----D---- C:\Program Files\iPod
2008-09-10 07:50:06 ----D---- C:\ProgramData\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-09-10 07:47:23 ----D---- C:\Program Files\Bonjour
2008-09-10 07:46:18 ----D---- C:\Program Files\QuickTime
2008-09-10 07:42:33 ----D---- C:\Windows\LastGood.Tmp
2008-09-10 01:26:02 ----SHD---- C:\Config.Msi
2008-09-09 18:32:25 ----A---- C:\Windows\system32\wmicmipluginc.dll
2008-09-09 18:32:25 ----A---- C:\Windows\system32\sxssupl.dll
2008-09-09 18:32:25 ----A---- C:\Windows\system32\rdpdds.dll
2008-09-09 18:32:25 ----A---- C:\Windows\system32\qdvdv.dll
2008-09-09 18:32:25 ----A---- C:\Windows\system32\QAGENTN.DLL
2008-09-09 18:32:25 ----A---- C:\Windows\system32\pngfiltn.dll
2008-09-09 18:32:25 ----A---- C:\Windows\system32\pcadmv.dll
2008-09-09 18:32:25 ----A---- C:\Windows\system32\muifontsetupi.dll
2008-09-09 18:32:25 ----A---- C:\Windows\system32\kdcomn.dll
2008-09-09 18:32:25 ----A---- C:\Windows\system32\kbds106.dll
2008-09-09 18:32:25 ----A---- C:\Windows\system32\KBDNES.DLL
2008-09-09 18:32:25 ----A---- C:\Windows\system32\KBDHEBX.DLL
2008-09-09 18:32:24 ----A---- C:\Windows\system32\versionx.dll
2008-09-09 18:32:24 ----A---- C:\Windows\system32\themeuim.dll
2008-09-09 18:32:24 ----A---- C:\Windows\system32\swprvv.dll
2008-09-09 18:32:24 ----A---- C:\Windows\system32\softkbdk.dll
2008-09-09 18:32:24 ----A---- C:\Windows\system32\remotepgh.dll
2008-09-09 18:32:24 ----A---- C:\Windows\system32\qdvdt.dll
2008-09-09 18:32:24 ----A---- C:\Windows\system32\PresentationHostProxyx.dll
2008-09-09 18:32:24 ----A---- C:\Windows\system32\perfs45.dll
2008-09-09 18:32:24 ----A---- C:\Windows\system32\perfs44.dll
2008-09-09 18:32:24 ----A---- C:\Windows\system32\onexq.dll
2008-09-09 18:32:24 ----A---- C:\Windows\system32\msvcrtc20.dll
2008-09-09 18:32:24 ----A---- C:\Windows\system32\KBDYAKY.DLL
2008-09-09 18:32:24 ----A---- C:\Windows\system32\ialmdnti5.dll
2008-09-09 18:32:24 ----A---- C:\Windows\system32\halb.dll
2008-09-09 18:32:24 ----A---- C:\Windows\system32\cmutilb.dll
2008-09-09 18:32:24 ----A---- C:\Windows\system32\CIRCoInstv.dll
2008-09-09 18:32:23 ----A---- C:\Windows\system32\vga64kl.dll
2008-09-09 18:32:23 ----A---- C:\Windows\system32\tdhb.dll
2008-09-09 18:32:23 ----A---- C:\Windows\system32\spopkhm.dll
2008-09-09 18:32:23 ----A---- C:\Windows\system32\spopkh.dll
2008-09-09 18:32:23 ----A---- C:\Windows\system32\sfck.dll
2008-09-09 18:32:23 ----A---- C:\Windows\system32\rpcrts4.dll
2008-09-09 18:32:23 ----A---- C:\Windows\system32\rdpcfcnex.dll
2008-09-09 18:32:23 ----A---- C:\Windows\system32\perfs9.dll
2008-09-09 18:32:23 ----A---- C:\Windows\system32\perfs8.dll
2008-09-09 18:32:23 ----A---- C:\Windows\system32\perfs19.dll
2008-09-09 18:32:23 ----A---- C:\Windows\system32\perfs18.dll
2008-09-09 18:32:23 ----A---- C:\Windows\system32\osbaselnj.dll
2008-09-09 18:32:23 ----A---- C:\Windows\system32\oleproj32.dll
2008-09-09 18:32:23 ----A---- C:\Windows\system32\odexldf32.dll
2008-09-09 18:32:23 ----A---- C:\Windows\system32\odexld32.dll
2008-09-09 18:32:23 ----A---- C:\Windows\system32\NlsDatad0045.dll
2008-09-09 18:32:23 ----A---- C:\Windows\system32\NetProjWW.dll
2008-09-09 18:32:23 ----A---- C:\Windows\system32\mtstocomk.exe
2008-09-09 18:32:23 ----A---- C:\Windows\system32\mshtah.exe
2008-09-09 18:32:23 ----A---- C:\Windows\system32\loghoursi.dll
2008-09-09 18:32:23 ----A---- C:\Windows\system32\LAPRXYK.DLL
2008-09-09 18:32:23 ----A---- C:\Windows\system32\kbdw101.dll
2008-09-09 18:32:22 ----A---- C:\Windows\system32\wseceditl.dll
2008-09-09 18:32:22 ----A---- C:\Windows\system32\WMVENCODJ.DLL
2008-09-09 18:32:22 ----A---- C:\Windows\system32\wdigestr.dll
2008-09-09 18:32:22 ----A---- C:\Windows\system32\uniplata.dll
2008-09-09 18:32:22 ----A---- C:\Windows\system32\NlsDatan0047.dll
2008-09-09 18:32:22 ----A---- C:\Windows\system32\diskcopyj.dll
2008-09-09 18:32:22 ----A---- C:\Windows\system32\bidisplq.dll
2008-09-09 18:32:22 ----A---- C:\Windows\system32\adsnte.dll
2008-09-09 16:01:59 ----A---- C:\Windows\system32\gameux.dll
2008-09-09 16:01:57 ----A---- C:\Windows\system32\Apphlpdm.dll
2008-09-09 16:01:55 ----A---- C:\Windows\system32\GameUXLegacyGDFs.dll
2008-09-09 16:01:51 ----A---- C:\Windows\system32\wmpeffects.dll
2008-09-09 14:58:41 ----A---- C:\Windows\system32\d3dx9_32.dll
2008-09-09 14:57:43 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2008-09-09 14:50:45 ----SHDC---- C:\Program Files\Common Files\WindowsLiveInstaller
2008-09-09 14:50:25 ----D---- C:\Program Files\Windows Live
2008-09-09 14:49:13 ----D---- C:\ProgramData\WLInstaller
2008-09-08 23:20:26 ----D---- C:\Avenger
2008-09-08 23:20:26 ----A---- C:\avenger.txt
2008-09-08 21:39:23 ----D---- C:\Users\Mrs. Kennedy\AppData\Roaming\Malwarebytes
2008-09-08 21:39:14 ----D---- C:\ProgramData\Malwarebytes
2008-09-08 21:39:14 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2008-09-06 21:09:02 ----D---- C:\rsit
2008-08-31 17:08:33 ----D---- C:\Program Files\Lavasoft
2008-08-31 17:08:02 ----D---- C:\ProgramData\Lavasoft
2008-08-31 16:58:19 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2008-08-31 00:52:39 ----D---- C:\Program Files\Common Files\Motorola Shared
2008-08-31 00:00:47 ----A---- C:\Windows\system32\hcrstco.dll
2008-08-30 17:18:07 ----D---- C:\Program Files\BitPim
2008-08-30 01:40:55 ----D---- C:\Program Files\Trend Micro
2008-08-30 01:17:11 ----D---- C:\Users\Mrs. Kennedy\AppData\Roaming\WinPatrol
2008-08-30 01:15:27 ----D---- C:\Program Files\BillP Studios
2008-08-29 10:18:58 ----A---- C:\Windows\system32\dns-sd.exe
2008-08-29 09:53:50 ----A---- C:\Windows\system32\dnssd.dll
2008-08-26 07:56:07 ----A---- C:\Windows\system32\wups2.dll
2008-08-26 07:56:07 ----A---- C:\Windows\system32\wuauclt.exe
2008-08-26 07:56:04 ----A---- C:\Windows\system32\wucltux.dll
2008-08-26 07:56:02 ----A---- C:\Windows\system32\wuaueng.dll
2008-08-26 07:55:27 ----A---- C:\Windows\system32\wups.dll
2008-08-26 07:55:27 ----A---- C:\Windows\system32\wudriver.dll
2008-08-26 07:55:26 ----A---- C:\Windows\system32\wuapi.dll
2008-08-26 07:54:38 ----A---- C:\Windows\system32\wuwebv.dll
2008-08-26 07:54:37 ----A---- C:\Windows\system32\wuapp.exe
2008-08-23 22:18:51 ----A---- C:\Users\Mrs. Kennedy\AppData\Roaming\QuickZip45.ini
2008-08-23 22:18:44 ----D---- C:\Program Files\QuickZip4
2008-08-23 22:15:06 ----D---- C:\Program Files\TUGZip
2008-08-19 00:30:22 ----HD---- C:\$AVG8.VAULT$
2008-08-18 21:43:20 ----A---- C:\Windows\system32\avgrsstx.dll
2008-08-18 21:41:35 ----D---- C:\Program Files\AVG
2008-08-18 21:41:34 ----D---- C:\ProgramData\avg8
2008-08-17 23:32:10 ----D---- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-08-17 23:23:48 ----D---- C:\Program Files\Microsoft Silverlight
2008-08-15 15:37:33 ----D---- C:\Program Files\Virtual Earth 3D
2008-08-15 10:30:45 ----D---- C:\Windows\Minidump
2008-08-14 12:21:29 ----A---- C:\Windows\system32\msshsq.dll
2008-08-14 07:02:55 ----A---- C:\Windows\system32\tzres.dll
2008-08-14 03:22:40 ----A---- C:\Windows\system32\mshtml.dll
2008-08-14 03:22:39 ----A---- C:\Windows\system32\jsproxy.dll
2008-08-14 03:22:38 ----A---- C:\Windows\system32\wininet.dll
2008-08-14 03:12:33 ----A---- C:\Windows\system32\INETRES.dll
2008-08-14 03:12:33 ----A---- C:\Windows\system32\inetcomm.dll
2008-08-14 03:12:26 ----A---- C:\Windows\system32\winipsec.dll
2008-08-14 03:12:26 ----A---- C:\Windows\system32\polstore.dll
2008-08-14 03:12:26 ----A---- C:\Windows\system32\IPSECSVC.DLL
2008-08-14 03:12:26 ----A---- C:\Windows\system32\FwRemoteSvr.dll
2008-08-13 23:48:23 ----A---- C:\Windows\system32\es.dll
2008-08-10 21:45:09 ----A---- C:\Windows\system32\d3dx9_35.dll
2008-08-10 21:45:07 ----A---- C:\Windows\system32\d3dx9_31.dll
2008-08-10 21:44:56 ----D---- C:\Program Files\Virtools
2008-08-08 13:12:54 ----SHD---- C:\ProgramData\MPK
2008-08-07 18:36:09 ----D---- C:\Users\Mrs. Kennedy\AppData\Roaming\Picaboo
2008-08-07 18:33:40 ----D---- C:\Program Files\Picaboo
2008-08-05 14:24:40 ----A---- C:\Windows\system32\NlsLexicons0027.dll
2008-08-05 14:24:38 ----A---- C:\Windows\system32\NlsLexicons0026.dll
2008-08-05 14:24:37 ----A---- C:\Windows\system32\NlsLexicons0024.dll
2008-08-05 14:24:35 ----A---- C:\Windows\system32\NlsLexicons0022.dll
2008-08-05 14:24:33 ----A---- C:\Windows\system32\NlsLexicons0021.dll
2008-08-05 14:24:32 ----A---- C:\Windows\system32\NlsLexicons001d.dll
2008-08-05 14:24:30 ----A---- C:\Windows\system32\NlsLexicons001b.dll
2008-08-05 14:24:28 ----A---- C:\Windows\system32\NlsLexicons001a.dll
2008-08-05 14:24:27 ----A---- C:\Windows\system32\NlsLexicons0019.dll
2008-08-05 14:24:26 ----A---- C:\Windows\system32\NlsLexicons0018.dll
2008-08-05 14:24:25 ----A---- C:\Windows\system32\NlsLexicons0013.dll
2008-08-05 14:24:23 ----A---- C:\Windows\system32\NlsLexicons0011.dll
2008-08-05 14:24:22 ----A---- C:\Windows\system32\NlsLexicons0010.dll
2008-08-05 14:24:21 ----A---- C:\Windows\system32\NlsLexicons000f.dll
2008-08-05 14:24:20 ----A---- C:\Windows\system32\NlsLexicons000c.dll
2008-08-05 14:24:17 ----A---- C:\Windows\system32\NlsLexicons000a.dll
2008-08-05 14:24:14 ----A---- C:\Windows\system32\NlsLexicons0002.dll
2008-08-05 14:24:13 ----A---- C:\Windows\system32\NlsLexicons0001.dll
2008-08-05 14:24:10 ----A---- C:\Windows\system32\NlsLexicons004e.dll
2008-08-05 14:24:09 ----A---- C:\Windows\system32\NlsLexicons004b.dll
2008-08-05 14:24:09 ----A---- C:\Windows\system32\NlsLexicons0049.dll
2008-08-05 14:24:08 ----A---- C:\Windows\system32\NlsLexicons0047.dll
2008-08-05 14:24:07 ----A---- C:\Windows\system32\NlsLexicons0046.dll
2008-08-05 14:24:06 ----A---- C:\Windows\system32\NlsLexicons0045.dll
2008-08-05 14:24:05 ----A---- C:\Windows\system32\NlsLexicons0039.dll
2008-08-05 14:24:04 ----A---- C:\Windows\system32\NlsLexicons0020.dll
2008-08-05 14:24:04 ----A---- C:\Windows\system32\NlsLexicons000d.dll
2008-08-05 14:24:03 ----A---- C:\Windows\system32\NlsLexicons0003.dll
2008-08-05 14:24:02 ----A---- C:\Windows\system32\NlsLexicons002a.dll
2008-08-05 14:23:39 ----A---- C:\Windows\system32\EncDec.dll
2008-08-05 14:23:38 ----A---- C:\Windows\system32\psisdecd.dll
2008-08-05 14:23:35 ----A---- C:\Windows\system32\mcmde.dll
2008-08-05 14:21:52 ----A---- C:\Windows\system32\RacEngn.dll
2008-08-05 14:21:36 ----A---- C:\Windows\system32\shell32.dll
2008-08-05 14:21:16 ----A---- C:\Windows\system32\wshrm.dll
2008-08-05 14:20:56 ----A---- C:\Windows\system32\quartz.dll
2008-08-05 14:09:58 ----D---- C:\Users\Mrs. Kennedy\AppData\Roaming\F-Secure
2008-08-05 14:06:37 ----A---- C:\Windows\UNDPX2A.exe
2008-08-05 12:29:07 ----A---- C:\Windows\system32\NlsLexicons0007.dll
2008-08-05 12:29:04 ----A---- C:\Windows\system32\NlsLexicons0009.dll
2008-08-05 12:28:25 ----A---- C:\Windows\system32\NlsData0009.dll
2008-08-05 12:28:24 ----A---- C:\Windows\system32\NaturalLanguage6.dll
2008-08-05 12:28:23 ----A---- C:\Windows\system32\NlsData000c.dll
2008-08-05 12:28:22 ----A---- C:\Windows\system32\NlsData000a.dll
2008-08-05 12:28:20 ----A---- C:\Windows\system32\NlsData000d.dll
2008-08-05 12:28:19 ----A---- C:\Windows\system32\NlsData0027.dll
2008-08-05 12:28:18 ----A---- C:\Windows\system32\NlsData0001.dll
2008-08-05 12:28:17 ----A---- C:\Windows\system32\NlsData003e.dll
2008-08-05 12:28:17 ----A---- C:\Windows\system32\NlsData002a.dll
2008-08-05 12:28:17 ----A---- C:\Windows\system32\NlsData0022.dll
2008-08-05 12:28:17 ----A---- C:\Windows\system32\NlsData0021.dll
2008-08-05 12:28:17 ----A---- C:\Windows\system32\NlsData0011.dll
2008-08-05 12:28:17 ----A---- C:\Windows\system32\NlsData0007.dll
2008-08-05 12:28:16 ----A---- C:\Windows\system32\NlsData0024.dll
2008-08-05 12:28:16 ----A---- C:\Windows\system32\NlsData001a.dll
2008-08-05 12:28:16 ----A---- C:\Windows\system32\NlsData0018.dll
2008-08-05 12:28:16 ----A---- C:\Windows\system32\NlsData000f.dll
2008-08-05 12:28:16 ----A---- C:\Windows\system32\NlsData0002.dll
2008-08-05 12:28:15 ----A---- C:\Windows\system32\NlsData0019.dll
2008-08-05 12:28:14 ----A---- C:\Windows\system32\NlsData0816.dll
2008-08-05 12:28:14 ----A---- C:\Windows\system32\NlsData001d.dll
2008-08-05 12:28:14 ----A---- C:\Windows\system32\NlsData0010.dll
2008-08-05 12:28:13 ----A---- C:\Windows\system32\NlsData0013.dll
2008-08-05 12:28:12 ----A---- C:\Windows\system32\NlsData0039.dll
2008-08-05 12:28:11 ----A---- C:\Windows\system32\NlsData0049.dll
2008-08-05 12:28:11 ----A---- C:\Windows\system32\NlsData0020.dll
2008-08-05 12:28:10 ----A---- C:\Windows\system32\NlsData0416.dll
2008-08-05 12:28:10 ----A---- C:\Windows\system32\NlsData0414.dll
2008-08-05 12:28:09 ----A---- C:\Windows\system32\NlsData0047.dll
2008-08-05 12:28:08 ----A---- C:\Windows\system32\NlsData081a.dll
2008-08-05 12:28:08 ----A---- C:\Windows\system32\NlsData004c.dll
2008-08-05 12:28:08 ----A---- C:\Windows\system32\NlsData004a.dll
2008-08-05 12:28:07 ----A---- C:\Windows\system32\NlsData0c1a.dll
2008-08-05 12:28:07 ----A---- C:\Windows\system32\NlsData001b.dll
2008-08-05 12:28:07 ----A---- C:\Windows\system32\NlsData0000.dll
2008-08-05 12:28:06 ----A---- C:\Windows\system32\NlsData004e.dll
2008-08-05 12:28:06 ----A---- C:\Windows\system32\NlsData004b.dll
2008-08-05 12:28:06 ----A---- C:\Windows\system32\NlsData0046.dll
2008-08-05 12:28:06 ----A---- C:\Windows\system32\NlsData0045.dll
2008-08-05 12:28:05 ----A---- C:\Windows\system32\NlsData0026.dll
2008-08-05 12:28:05 ----A---- C:\Windows\system32\NlsData0003.dll
2008-08-05 12:26:46 ----A---- C:\Windows\system32\NlsModels0011.dll
2008-08-05 12:26:45 ----A---- C:\Windows\system32\NlsLexicons0c1a.dll
2008-08-05 12:26:44 ----A---- C:\Windows\system32\NlsLexicons081a.dll
2008-08-05 12:26:42 ----A---- C:\Windows\system32\NlsLexicons0816.dll
2008-08-05 12:26:40 ----A---- C:\Windows\system32\NlsLexicons0416.dll
2008-08-05 12:26:38 ----A---- C:\Windows\system32\NlsLexicons0414.dll
2008-08-05 12:26:36 ----A---- C:\Windows\system32\NlsLexicons004c.dll
2008-08-05 12:26:34 ----A---- C:\Windows\system32\NlsLexicons004a.dll
2008-08-05 12:26:32 ----A---- C:\Windows\system32\NlsLexicons003e.dll

List of drivers

R1 ASPI32;ASPI32; C:\Windows\system32\drivers\ASPI32.sys [1999-09-10 25244]
R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\Windows\system32\System32\Drivers\avgldx86.sys []
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\Windows\system32\System32\Drivers\avgmfx86.sys []
R1 Cdr4_xp;Cdr4_xp; C:\Windows\system32\drivers\Cdr4_xp.sys [2005-09-07 44288]
R1 Cdralw2k;Cdralw2k; C:\Windows\system32\drivers\Cdralw2k.sys [2005-09-07 24960]
R1 FSES;F-Secure Email Scanning Driver; C:\Windows\System32\drivers\fses.sys [2007-11-01 34752]
R1 FSFW;F-Secure Firewall Driver; C:\Windows\System32\drivers\fsdfw.sys [2008-04-12 60064]
R1 fsvista;F-Secure Vista Support Driver; \??\C:\Program Files\EMBARQ Online Security\Anti-Virus\minifilter\fsvista.sys [2007-11-01 12896]
R1 KmReg;System kernel configuration; \??\C:\Windows\system32\drivers\usbcirx.sys [2008-09-09 38784]
R1 NtLclIpc;Remote Procedure Call RT4s; \??\C:\Windows\system32\drivers\netbtp.sys [2008-09-09 122112]
R2 nmsgopro;GoProto Protocol Driver for NMS; C:\Windows\system32\DRIVERS\nmsgopro.sys [2006-09-27 28672]
R2 nmsunidr;UniDriver for NMS; C:\Windows\system32\DRIVERS\nmsunidr.sys [2006-10-19 7424]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2008-03-21 1203776]
R3 AvgWfpX;AVG Free8 Firewall Driver x86; C:\Windows\system32\System32\Drivers\avgwfpx.sys []
R3 E100B;Intel(R) PRO Network Connection Driver; C:\Windows\system32\DRIVERS\e100b325.sys [2006-10-31 165760]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper; \??\C:\Program Files\EMBARQ Online Security\Anti-Virus\minifilter\fsgk.sys [2007-11-01 59488]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\System32\Drivers\GEARAspiWDM.sys [2008-04-17 15464]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2006-12-12 1476608]
R3 IntelDH;IntelDH Driver; C:\Windows\System32\Drivers\IntelDH.sys [2006-12-21 5504]
R3 LVPr2Mon;Logitech LVPr2Mon Driver; C:\Windows\system32\DRIVERS\LVPr2Mon.sys [2007-10-11 25624]
R3 LVUSBSta;Logitech USB Monitor Filter; C:\Windows\system32\drivers\LVUSBSta.sys [2007-10-12 41752]
R3 pepifilter;Volume Adapter; C:\Windows\system32\DRIVERS\lv302af.sys [2007-10-11 13848]
R3 PID_PEPI;Logitech QuickCam IM(PID_PEPI); C:\Windows\system32\DRIVERS\LV302V32.SYS [2007-10-11 1279000]
R3 STHDA;SigmaTel High Definition Audio CODEC; C:\Windows\system32\drivers\stwrt.sys [2006-11-01 812032]
R3 usbaudio;USB Audio Driver (WDM); C:\Windows\system32\drivers\usbaudio.sys [2006-11-02 71552]
R3 USBCM;Scientific-Atlanta USB Cable Modem Driver; C:\Windows\system32\DRIVERS\Sacm2A.sys [2004-06-09 15429]
R3 wanatw;WAN Miniport (ATW); C:\Windows\system32\DRIVERS\wanatw4.sys [2006-11-01 33588]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2006-11-02 82560]
S3 ac97intc;Intel(r) 82801 Audio Driver Install Service (WDM); C:\Windows\system32\drivers\ac97intc.sys [2006-11-02 108032]
S3 bcm4sbxp;Broadcom 440x 10/100 Integrated Controller XP Driver; C:\Windows\system32\DRIVERS\bcm4sbxp.sys [2006-11-02 45056]
S3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\Windows\system32\DRIVERS\CmBatt.sys [2006-11-02 14208]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2006-11-02 5632]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 ialm;ialm; C:\Windows\system32\DRIVERS\igdkmd32.sys [2006-12-12 1476608]
S3 LVcKap;Logitech AEC Driver; C:\Windows\system32\DRIVERS\LVcKap.sys [2007-10-19 2109976]
S3 LVMVDrv;Logitech Machine Vision Engine Loader; C:\Windows\system32\DRIVERS\LVMVDrv.sys [2007-10-11 2142488]
S3 motmodem;Motorola USB CDC ACM Driver; C:\Windows\system32\DRIVERS\motmodem.sys [2007-06-18 23680]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2006-11-02 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2006-11-02 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2006-11-02 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2006-11-02 6016]
S3 NETw2v32;Intel(R) PRO/Wireless 2200BG Network Connection Driver for Windows Vista; C:\Windows\system32\DRIVERS\NETw2v32.sys [2006-11-02 2589184]
S3 SDDMI2;SDDMI2; \??\C:\Windows\system32\DDMI2.sys []
S3 TSHWMDTCP;TSHWMDTCP; \??\C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.sys [2006-11-18 18904]
S3 USB_RNDIS;Compact Wireless-G USB Network Adapter with SpeedBooster; C:\Windows\system32\DRIVERS\usb8023.sys [2006-11-02 14848]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2006-11-02 39936]
S4 F-Secure Filter;F-Secure File System Filter; \??\C:\Program Files\EMBARQ Online Security\Anti-Virus\Win2K\FSfilter.sys [2007-11-01 39776]
S4 F-Secure Recognizer;F-Secure File System Recognizer; \??\C:\Program Files\EMBARQ Online Security\Anti-Virus\Win2K\FSrec.sys [2007-11-01 25184]
S4 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2006-11-02 82432]
S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\system32\drivers\wmiacpi.sys []

List of services

R2 a2free;a-squared Free Service; C:\Program Files\a-squared Free\a2service.exe [2007-08-26 217208]
R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2008-08-31 611664]
R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Windows\system32\agrsmsvc.exe [2008-03-18 13312]
R2 AlertService;Intel(R) Alert Service; C:\Program Files\Intel\IntelDH\CCU\AlertService.exe [2006-11-18 195032]
R2 AOL ACS;AOL Connectivity Service; C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe [2006-10-23 46640]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-09-05 116040]
R2 avg8emc;AVG Free8 E-mail Scanner; C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-08-30 875288]
R2 avg8wd;AVG Free8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-08-30 231704]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-08-29 238888]
R2 DQLWinService;DQLWinService; C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe [2006-10-29 208896]
R2 F-Secure Gatekeeper Handler Starter;FSGKHS; C:\Program Files\EMBARQ Online Security\Anti-Virus\fsgk32st.exe [2007-11-01 47800]
R2 FSMA;F-Secure Management Agent; C:\Program Files\EMBARQ Online Security\Common\FSMA32.EXE [2007-11-01 113304]
R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe [2006-09-29 81920]
R2 ISSM;Intel(R) Software Services Manager; C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe [2006-11-18 81880]
R2 LVCOMSer;LVCOMSer; C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe [2007-10-19 186904]
R2 LVPrcSrv;Process Monitor; C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe [2007-10-19 141848]
R2 M1 Server;Intel(R) Viiv(TM) Media Server; C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe [2006-11-18 32216]
R2 MCLServiceATL;Intel(R) Application Tracker; C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe [2006-11-18 174552]
R2 PrismXL;PrismXL; C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS [2006-12-21 65536]
R2 ProtexisLicensing;ProtexisLicensing; C:\Windows\system32\PSIService.exe [2006-11-02 174656]
R2 Remote UI Service;Intel(R) Remoting Service; C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe [2006-11-18 550872]
R2 Scprtn;System kernel integrity service; C:\Windows\system32\mtstocomk.exe [2008-09-09 179712]
R2 STacSV;SigmaTel Audio Service; C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe [2006-11-01 90112]
R2 UStorage Server Service;UStorage Server Service; C:\Windows\system32\UStorSrv.exe [2004-12-01 139264]
R3 FSAUA;F-Secure Automatic Update Agent; C:\Program Files\EMBARQ Online Security\FSAUA\program\fsaua.exe [2007-11-01 461408]
R3 FSDFWD;F-Secure Anti-Virus Firewall Daemon; C:\Program Files\EMBARQ Online Security\FWES\Program\fsdfwd.exe [2007-11-01 453216]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2008-09-08 536872]
S2 LVSrvLauncher;LVSrvLauncher; C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe [2007-10-19 141848]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2007-02-18 72704]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2007-08-24 443776]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 usnjsvc;Messenger Sharing Folders USN Journal Reader service; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]

-----------------EOF-----------------
VioletPurple04
Active Member
 
Posts: 13
Joined: August 30th, 2008, 4:04 am

Re: I've had trojan horses and keyloggers. Computer is slowww.

Unread postby Shaba » September 13th, 2008, 5:22 am

Looks like they are still there.

Right-click that remserv.bat and choose run as administrator.

Reboot.

Re-run rsit.

Post a fresh rsit log, please.
User avatar
Shaba
Admin/Teacher Emeritus
 
Posts: 26974
Joined: March 24th, 2006, 4:42 am
Location: Finland

Re: I've had trojan horses and keyloggers. Computer is slowww.

Unread postby VioletPurple04 » September 13th, 2008, 10:46 pm

Logfile of random's system information tool (written by random/random)
Run by Mrs. Kennedy at 2008-09-13 20:39:44
Microsoft® Windows Vista™ Home Premium
System drive C: has 136 GB (60%) free of 228 GB
Total RAM: 1013 MB (26% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:39:59 PM, on 9/13/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v8.00 (8.00.6001.17184)
Boot mode: Normal

Running processes:
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Intel\IntelDH\CCU\CCU_TrayIcon.exe
C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe
C:\Windows\zHotkey.exe
C:\Windows\ModPS2Key.exe
C:\Windows\sttray.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Common Files\AOL\1171674555\ee\aolsoftware.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Intel\IntelDH\CCU\CCU_Engine.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\PROGRAM FILES\WINDOWS DEFENDER\MSASCUI.EXE
C:\PROGRAM FILES\CANON\MYPRINTER\BJMYPRT.EXE
C:\Users\Mrs. Kennedy\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Mrs. Kennedy.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/def ... .yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/def ... .yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/def ... earch.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/def ... .yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/def ... .yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=c:\windows\system32\userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: BrowserConnector Object - {0D84AC30-5186-4CD9-8FD8-4A1382D5F0F3} - C:\Windows\system32\osbaselnj.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\google\BAE.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [CCUTRAYICON] C:\Program Files\Intel\IntelDH\CCU\CCU_TrayIcon.exe
O4 - HKLM\..\Run: [NMSSupport] "C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe" /startup
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [ShowWnd] ShowWnd.exe
O4 - HKLM\..\Run: [ModPS2] ModPS2Key.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1171674555\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [Media Codec Update Service] C:\Program Files\Essentials Codec Pack\update.exe -silent
O4 - HKLM\..\Run: [masqform.exe] C:\Users\Mrs. Kennedy\Desktop\masqform.exe -UpdateCurrentUser
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-4003477587-3145471023-3728799210-1000\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'IUSR_NMPR')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Open with WordPerfect - C:\Program Files\WordPerfect Office X3\Programs\WPLauncher.hta
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200 ... plugin.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} (get_atlcom Class) - http://apps.corel.com/nos_dl_manager_de ... Plugin.ocx
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Fac ... loader.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windows ... 0992529880
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://lance-violet.spaces.live.com/Pho ... den-us.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://3dlifeplayer.dl.3dvia.com/player ... taller.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\Windows\system32\versionx.dll,avgrsstx.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Intel(R) Alert Service (AlertService) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel(R) Software Services Manager (ISSM) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Intel(R) Viiv(TM) Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
O23 - Service: Intel(R) Application Tracker (MCLServiceATL) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: ProtexisLicensing - Unknown owner - C:\Windows\system32\PSIService.exe
O23 - Service: Intel(R) Remoting Service (Remote UI Service) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
O23 - Service: System kernel integrity service (Scprtn) - SearchHelp, Inc. - C:\Windows\system32\mtstocomk.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
O23 - Service: UStorage Server Service - OTi - C:\Windows\system32\UStorSrv.exe

--
End of file - 13106 bytes

Registry dump

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-12-18 59032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0D84AC30-5186-4CD9-8FD8-4A1382D5F0F3}]
BrowserConnector Object - C:\Windows\system32\osbaselnj.dll [2008-09-09 118784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG8\avgssie.dll [2008-08-30 455960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0\bin\ssv.dll [2006-12-21 501384]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2007-09-20 328752]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
AVG Security Toolbar - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2008-08-18 2055960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA6319C0-31B7-401E-A518-A07C3DB8F777}]
CBrowserHelperObject Object - c:\google\BAE.dll [2006-01-31 94208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{A057A204-BACC-4D26-9990-79A187E2698E} - AVG Security Toolbar - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2008-08-18 2055960]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"CCUTRAYICON"=C:\Program Files\Intel\IntelDH\CCU\CCU_TrayIcon.exe [2006-11-18 182744]
"NMSSupport"=C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe [2006-09-26 423424]
"CHotkey"=C:\Windows\zHotkey.exe [2006-11-07 547840]
"ShowWnd"=C:\Windows\ShowWnd.exe [2005-01-27 36864]
"ModPS2"=C:\Windows\ModPS2Key.exe [2006-11-07 53248]
"SigmatelSysTrayApp"=C:\Windows\sttray.exe [2006-11-01 303104]
"IAAnotif"=C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe [2006-09-29 151552]
"HostManager"=C:\Program Files\Common Files\AOL\1171674555\ee\AOLSoftware.exe [2007-05-25 42032]
"Media Codec Update Service"=C:\Program Files\Essentials Codec Pack\update.exe [2007-04-08 303104]
"masqform.exe"=C:\Users\Mrs. Kennedy\Desktop\masqform.exe -UpdateCurrentUser []
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2006-12-12 98304]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2006-12-12 106496]
"Persistence"=C:\Windows\system32\igfxpers.exe [2006-12-12 81920]
"LogitechCommunicationsManager"=C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe [2007-10-25 563984]
"AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe [2008-08-30 1235736]
"WinPatrol"=C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe [2008-07-04 333120]
"Malwarebytes Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2008-09-08 1253040]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2008-09-06 413696]
"AppleSyncNotifier"=C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe [2008-09-03 111936]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2008-09-08 289576]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2006-11-02 125440]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2008-04-10 1232896]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2006-11-02 201728]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

C:\Users\Mrs. Kennedy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\Windows\system32\versionx.dll,avgrsstx.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2006-12-12 212992]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KmReg]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NtLclIpc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Scprtn]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\KmReg]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NtLclIpc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Scprtn]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

File associations

.js - edit -

List of files/folders created in the last three months

2008-09-10 07:50:46 ----A---- C:\Windows\system32\GEARAspi.dll
2008-09-10 07:50:45 ----DC---- C:\Windows\system32\DRVSTORE
2008-09-10 07:50:23 ----D---- C:\Program Files\iPod
2008-09-10 07:50:06 ----D---- C:\ProgramData\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-09-10 07:47:23 ----D---- C:\Program Files\Bonjour
2008-09-10 07:46:18 ----D---- C:\Program Files\QuickTime
2008-09-10 01:26:02 ----SHD---- C:\Config.Msi
2008-09-09 18:32:25 ----A---- C:\Windows\system32\wmicmipluginc.dll
2008-09-09 18:32:25 ----A---- C:\Windows\system32\sxssupl.dll
2008-09-09 18:32:25 ----A---- C:\Windows\system32\rdpdds.dll
2008-09-09 18:32:25 ----A---- C:\Windows\system32\qdvdv.dll
2008-09-09 18:32:25 ----A---- C:\Windows\system32\QAGENTN.DLL
2008-09-09 18:32:25 ----A---- C:\Windows\system32\pngfiltn.dll
2008-09-09 18:32:25 ----A---- C:\Windows\system32\pcadmv.dll
2008-09-09 18:32:25 ----A---- C:\Windows\system32\muifontsetupi.dll
2008-09-09 18:32:25 ----A---- C:\Windows\system32\kdcomn.dll
2008-09-09 18:32:25 ----A---- C:\Windows\system32\kbds106.dll
2008-09-09 18:32:25 ----A---- C:\Windows\system32\KBDNES.DLL
2008-09-09 18:32:25 ----A---- C:\Windows\system32\KBDHEBX.DLL
2008-09-09 18:32:24 ----A---- C:\Windows\system32\versionx.dll
2008-09-09 18:32:24 ----A---- C:\Windows\system32\themeuim.dll
2008-09-09 18:32:24 ----A---- C:\Windows\system32\swprvv.dll
2008-09-09 18:32:24 ----A---- C:\Windows\system32\softkbdk.dll
2008-09-09 18:32:24 ----A---- C:\Windows\system32\remotepgh.dll
2008-09-09 18:32:24 ----A---- C:\Windows\system32\qdvdt.dll
2008-09-09 18:32:24 ----A---- C:\Windows\system32\PresentationHostProxyx.dll
2008-09-09 18:32:24 ----A---- C:\Windows\system32\perfs45.dll
2008-09-09 18:32:24 ----A---- C:\Windows\system32\perfs44.dll
2008-09-09 18:32:24 ----A---- C:\Windows\system32\onexq.dll
2008-09-09 18:32:24 ----A---- C:\Windows\system32\msvcrtc20.dll
2008-09-09 18:32:24 ----A---- C:\Windows\system32\KBDYAKY.DLL
2008-09-09 18:32:24 ----A---- C:\Windows\system32\ialmdnti5.dll
2008-09-09 18:32:24 ----A---- C:\Windows\system32\halb.dll
2008-09-09 18:32:24 ----A---- C:\Windows\system32\cmutilb.dll
2008-09-09 18:32:24 ----A---- C:\Windows\system32\CIRCoInstv.dll
2008-09-09 18:32:23 ----A---- C:\Windows\system32\vga64kl.dll
2008-09-09 18:32:23 ----A---- C:\Windows\system32\tdhb.dll
2008-09-09 18:32:23 ----A---- C:\Windows\system32\spopkhm.dll
2008-09-09 18:32:23 ----A---- C:\Windows\system32\spopkh.dll
2008-09-09 18:32:23 ----A---- C:\Windows\system32\sfck.dll
2008-09-09 18:32:23 ----A---- C:\Windows\system32\rpcrts4.dll
2008-09-09 18:32:23 ----A---- C:\Windows\system32\rdpcfcnex.dll
2008-09-09 18:32:23 ----A---- C:\Windows\system32\perfs9.dll
2008-09-09 18:32:23 ----A---- C:\Windows\system32\perfs8.dll
2008-09-09 18:32:23 ----A---- C:\Windows\system32\perfs19.dll
2008-09-09 18:32:23 ----A---- C:\Windows\system32\perfs18.dll
2008-09-09 18:32:23 ----A---- C:\Windows\system32\osbaselnj.dll
2008-09-09 18:32:23 ----A---- C:\Windows\system32\oleproj32.dll
2008-09-09 18:32:23 ----A---- C:\Windows\system32\odexldf32.dll
2008-09-09 18:32:23 ----A---- C:\Windows\system32\odexld32.dll
2008-09-09 18:32:23 ----A---- C:\Windows\system32\NlsDatad0045.dll
2008-09-09 18:32:23 ----A---- C:\Windows\system32\NetProjWW.dll
2008-09-09 18:32:23 ----A---- C:\Windows\system32\mtstocomk.exe
2008-09-09 18:32:23 ----A---- C:\Windows\system32\mshtah.exe
2008-09-09 18:32:23 ----A---- C:\Windows\system32\loghoursi.dll
2008-09-09 18:32:23 ----A---- C:\Windows\system32\LAPRXYK.DLL
2008-09-09 18:32:23 ----A---- C:\Windows\system32\kbdw101.dll
2008-09-09 18:32:22 ----A---- C:\Windows\system32\wseceditl.dll
2008-09-09 18:32:22 ----A---- C:\Windows\system32\WMVENCODJ.DLL
2008-09-09 18:32:22 ----A---- C:\Windows\system32\wdigestr.dll
2008-09-09 18:32:22 ----A---- C:\Windows\system32\uniplata.dll
2008-09-09 18:32:22 ----A---- C:\Windows\system32\NlsDatan0047.dll
2008-09-09 18:32:22 ----A---- C:\Windows\system32\diskcopyj.dll
2008-09-09 18:32:22 ----A---- C:\Windows\system32\bidisplq.dll
2008-09-09 18:32:22 ----A---- C:\Windows\system32\adsnte.dll
2008-09-09 16:01:59 ----A---- C:\Windows\system32\gameux.dll
2008-09-09 16:01:57 ----A---- C:\Windows\system32\Apphlpdm.dll
2008-09-09 16:01:55 ----A---- C:\Windows\system32\GameUXLegacyGDFs.dll
2008-09-09 16:01:51 ----A---- C:\Windows\system32\wmpeffects.dll
2008-09-09 14:58:41 ----A---- C:\Windows\system32\d3dx9_32.dll
2008-09-09 14:57:43 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2008-09-09 14:50:45 ----SHDC---- C:\Program Files\Common Files\WindowsLiveInstaller
2008-09-09 14:50:25 ----D---- C:\Program Files\Windows Live
2008-09-09 14:49:13 ----D---- C:\ProgramData\WLInstaller
2008-09-08 23:20:26 ----D---- C:\Avenger
2008-09-08 23:20:26 ----A---- C:\avenger.txt
2008-09-08 21:39:23 ----D---- C:\Users\Mrs. Kennedy\AppData\Roaming\Malwarebytes
2008-09-08 21:39:14 ----D---- C:\ProgramData\Malwarebytes
2008-09-08 21:39:14 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2008-09-06 21:09:02 ----D---- C:\rsit
2008-08-31 17:08:33 ----D---- C:\Program Files\Lavasoft
2008-08-31 17:08:02 ----D---- C:\ProgramData\Lavasoft
2008-08-31 16:58:19 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2008-08-31 00:52:39 ----D---- C:\Program Files\Common Files\Motorola Shared
2008-08-31 00:00:47 ----A---- C:\Windows\system32\hcrstco.dll
2008-08-30 17:18:07 ----D---- C:\Program Files\BitPim
2008-08-30 01:40:55 ----D---- C:\Program Files\Trend Micro
2008-08-30 01:17:11 ----D---- C:\Users\Mrs. Kennedy\AppData\Roaming\WinPatrol
2008-08-30 01:15:27 ----D---- C:\Program Files\BillP Studios
2008-08-29 10:18:58 ----A---- C:\Windows\system32\dns-sd.exe
2008-08-29 09:53:50 ----A---- C:\Windows\system32\dnssd.dll
2008-08-26 07:56:07 ----A---- C:\Windows\system32\wups2.dll
2008-08-26 07:56:07 ----A---- C:\Windows\system32\wuauclt.exe
2008-08-26 07:56:04 ----A---- C:\Windows\system32\wucltux.dll
2008-08-26 07:56:02 ----A---- C:\Windows\system32\wuaueng.dll
2008-08-26 07:55:27 ----A---- C:\Windows\system32\wups.dll
2008-08-26 07:55:27 ----A---- C:\Windows\system32\wudriver.dll
2008-08-26 07:55:26 ----A---- C:\Windows\system32\wuapi.dll
2008-08-26 07:54:38 ----A---- C:\Windows\system32\wuwebv.dll
2008-08-26 07:54:37 ----A---- C:\Windows\system32\wuapp.exe
2008-08-23 22:18:51 ----A---- C:\Users\Mrs. Kennedy\AppData\Roaming\QuickZip45.ini
2008-08-23 22:18:44 ----D---- C:\Program Files\QuickZip4
2008-08-23 22:15:06 ----D---- C:\Program Files\TUGZip
2008-08-19 00:30:22 ----HD---- C:\$AVG8.VAULT$
2008-08-18 21:43:20 ----A---- C:\Windows\system32\avgrsstx.dll
2008-08-18 21:41:35 ----D---- C:\Program Files\AVG
2008-08-18 21:41:34 ----D---- C:\ProgramData\avg8
2008-08-17 23:32:10 ----D---- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-08-17 23:23:48 ----D---- C:\Program Files\Microsoft Silverlight
2008-08-15 15:37:33 ----D---- C:\Program Files\Virtual Earth 3D
2008-08-15 10:30:45 ----D---- C:\Windows\Minidump
2008-08-14 12:21:29 ----A---- C:\Windows\system32\msshsq.dll
2008-08-14 07:02:55 ----A---- C:\Windows\system32\tzres.dll
2008-08-14 03:22:40 ----A---- C:\Windows\system32\mshtml.dll
2008-08-14 03:22:39 ----A---- C:\Windows\system32\jsproxy.dll
2008-08-14 03:22:38 ----A---- C:\Windows\system32\wininet.dll
2008-08-14 03:12:33 ----A---- C:\Windows\system32\INETRES.dll
2008-08-14 03:12:33 ----A---- C:\Windows\system32\inetcomm.dll
2008-08-14 03:12:26 ----A---- C:\Windows\system32\winipsec.dll
2008-08-14 03:12:26 ----A---- C:\Windows\system32\polstore.dll
2008-08-14 03:12:26 ----A---- C:\Windows\system32\IPSECSVC.DLL
2008-08-14 03:12:26 ----A---- C:\Windows\system32\FwRemoteSvr.dll
2008-08-13 23:48:23 ----A---- C:\Windows\system32\es.dll
2008-08-10 21:45:09 ----A---- C:\Windows\system32\d3dx9_35.dll
2008-08-10 21:45:07 ----A---- C:\Windows\system32\d3dx9_31.dll
2008-08-10 21:44:56 ----D---- C:\Program Files\Virtools
2008-08-08 13:12:54 ----SHD---- C:\ProgramData\MPK
2008-08-07 18:36:09 ----D---- C:\Users\Mrs. Kennedy\AppData\Roaming\Picaboo
2008-08-07 18:33:40 ----D---- C:\Program Files\Picaboo
2008-08-05 14:24:40 ----A---- C:\Windows\system32\NlsLexicons0027.dll
2008-08-05 14:24:38 ----A---- C:\Windows\system32\NlsLexicons0026.dll
2008-08-05 14:24:37 ----A---- C:\Windows\system32\NlsLexicons0024.dll
2008-08-05 14:24:35 ----A---- C:\Windows\system32\NlsLexicons0022.dll
2008-08-05 14:24:33 ----A---- C:\Windows\system32\NlsLexicons0021.dll
2008-08-05 14:24:32 ----A---- C:\Windows\system32\NlsLexicons001d.dll
2008-08-05 14:24:30 ----A---- C:\Windows\system32\NlsLexicons001b.dll
2008-08-05 14:24:28 ----A---- C:\Windows\system32\NlsLexicons001a.dll
2008-08-05 14:24:27 ----A---- C:\Windows\system32\NlsLexicons0019.dll
2008-08-05 14:24:26 ----A---- C:\Windows\system32\NlsLexicons0018.dll
2008-08-05 14:24:25 ----A---- C:\Windows\system32\NlsLexicons0013.dll
2008-08-05 14:24:23 ----A---- C:\Windows\system32\NlsLexicons0011.dll
2008-08-05 14:24:22 ----A---- C:\Windows\system32\NlsLexicons0010.dll
2008-08-05 14:24:21 ----A---- C:\Windows\system32\NlsLexicons000f.dll
2008-08-05 14:24:20 ----A---- C:\Windows\system32\NlsLexicons000c.dll
2008-08-05 14:24:17 ----A---- C:\Windows\system32\NlsLexicons000a.dll
2008-08-05 14:24:14 ----A---- C:\Windows\system32\NlsLexicons0002.dll
2008-08-05 14:24:13 ----A---- C:\Windows\system32\NlsLexicons0001.dll
2008-08-05 14:24:10 ----A---- C:\Windows\system32\NlsLexicons004e.dll
2008-08-05 14:24:09 ----A---- C:\Windows\system32\NlsLexicons004b.dll
2008-08-05 14:24:09 ----A---- C:\Windows\system32\NlsLexicons0049.dll
2008-08-05 14:24:08 ----A---- C:\Windows\system32\NlsLexicons0047.dll
2008-08-05 14:24:07 ----A---- C:\Windows\system32\NlsLexicons0046.dll
2008-08-05 14:24:06 ----A---- C:\Windows\system32\NlsLexicons0045.dll
2008-08-05 14:24:05 ----A---- C:\Windows\system32\NlsLexicons0039.dll
2008-08-05 14:24:04 ----A---- C:\Windows\system32\NlsLexicons0020.dll
2008-08-05 14:24:04 ----A---- C:\Windows\system32\NlsLexicons000d.dll
2008-08-05 14:24:03 ----A---- C:\Windows\system32\NlsLexicons0003.dll
2008-08-05 14:24:02 ----A---- C:\Windows\system32\NlsLexicons002a.dll
2008-08-05 14:23:39 ----A---- C:\Windows\system32\EncDec.dll
2008-08-05 14:23:38 ----A---- C:\Windows\system32\psisdecd.dll
2008-08-05 14:23:35 ----A---- C:\Windows\system32\mcmde.dll
2008-08-05 14:21:52 ----A---- C:\Windows\system32\RacEngn.dll
2008-08-05 14:21:36 ----A---- C:\Windows\system32\shell32.dll
2008-08-05 14:21:16 ----A---- C:\Windows\system32\wshrm.dll
2008-08-05 14:20:56 ----A---- C:\Windows\system32\quartz.dll
2008-08-05 14:09:58 ----D---- C:\Users\Mrs. Kennedy\AppData\Roaming\F-Secure
2008-08-05 14:06:37 ----A---- C:\Windows\UNDPX2A.exe
2008-08-05 12:29:07 ----A---- C:\Windows\system32\NlsLexicons0007.dll
2008-08-05 12:29:04 ----A---- C:\Windows\system32\NlsLexicons0009.dll
2008-08-05 12:28:25 ----A---- C:\Windows\system32\NlsData0009.dll
2008-08-05 12:28:24 ----A---- C:\Windows\system32\NaturalLanguage6.dll
2008-08-05 12:28:23 ----A---- C:\Windows\system32\NlsData000c.dll
2008-08-05 12:28:22 ----A---- C:\Windows\system32\NlsData000a.dll
2008-08-05 12:28:20 ----A---- C:\Windows\system32\NlsData000d.dll
2008-08-05 12:28:19 ----A---- C:\Windows\system32\NlsData0027.dll
2008-08-05 12:28:18 ----A---- C:\Windows\system32\NlsData0001.dll
2008-08-05 12:28:17 ----A---- C:\Windows\system32\NlsData003e.dll
2008-08-05 12:28:17 ----A---- C:\Windows\system32\NlsData002a.dll
2008-08-05 12:28:17 ----A---- C:\Windows\system32\NlsData0022.dll
2008-08-05 12:28:17 ----A---- C:\Windows\system32\NlsData0021.dll
2008-08-05 12:28:17 ----A---- C:\Windows\system32\NlsData0011.dll
2008-08-05 12:28:17 ----A---- C:\Windows\system32\NlsData0007.dll
2008-08-05 12:28:16 ----A---- C:\Windows\system32\NlsData0024.dll
2008-08-05 12:28:16 ----A---- C:\Windows\system32\NlsData001a.dll
2008-08-05 12:28:16 ----A---- C:\Windows\system32\NlsData0018.dll
2008-08-05 12:28:16 ----A---- C:\Windows\system32\NlsData000f.dll
2008-08-05 12:28:16 ----A---- C:\Windows\system32\NlsData0002.dll
2008-08-05 12:28:15 ----A---- C:\Windows\system32\NlsData0019.dll
2008-08-05 12:28:14 ----A---- C:\Windows\system32\NlsData0816.dll
2008-08-05 12:28:14 ----A---- C:\Windows\system32\NlsData001d.dll
2008-08-05 12:28:14 ----A---- C:\Windows\system32\NlsData0010.dll
2008-08-05 12:28:13 ----A---- C:\Windows\system32\NlsData0013.dll
2008-08-05 12:28:12 ----A---- C:\Windows\system32\NlsData0039.dll
2008-08-05 12:28:11 ----A---- C:\Windows\system32\NlsData0049.dll
2008-08-05 12:28:11 ----A---- C:\Windows\system32\NlsData0020.dll
2008-08-05 12:28:10 ----A---- C:\Windows\system32\NlsData0416.dll
2008-08-05 12:28:10 ----A---- C:\Windows\system32\NlsData0414.dll
2008-08-05 12:28:09 ----A---- C:\Windows\system32\NlsData0047.dll
2008-08-05 12:28:08 ----A---- C:\Windows\system32\NlsData081a.dll
2008-08-05 12:28:08 ----A---- C:\Windows\system32\NlsData004c.dll
2008-08-05 12:28:08 ----A---- C:\Windows\system32\NlsData004a.dll
2008-08-05 12:28:07 ----A---- C:\Windows\system32\NlsData0c1a.dll
2008-08-05 12:28:07 ----A---- C:\Windows\system32\NlsData001b.dll
2008-08-05 12:28:07 ----A---- C:\Windows\system32\NlsData0000.dll
2008-08-05 12:28:06 ----A---- C:\Windows\system32\NlsData004e.dll
2008-08-05 12:28:06 ----A---- C:\Windows\system32\NlsData004b.dll
2008-08-05 12:28:06 ----A---- C:\Windows\system32\NlsData0046.dll
2008-08-05 12:28:06 ----A---- C:\Windows\system32\NlsData0045.dll
2008-08-05 12:28:05 ----A---- C:\Windows\system32\NlsData0026.dll
2008-08-05 12:28:05 ----A---- C:\Windows\system32\NlsData0003.dll
2008-08-05 12:26:46 ----A---- C:\Windows\system32\NlsModels0011.dll
2008-08-05 12:26:45 ----A---- C:\Windows\system32\NlsLexicons0c1a.dll
2008-08-05 12:26:44 ----A---- C:\Windows\system32\NlsLexicons081a.dll
2008-08-05 12:26:42 ----A---- C:\Windows\system32\NlsLexicons0816.dll
2008-08-05 12:26:40 ----A---- C:\Windows\system32\NlsLexicons0416.dll
2008-08-05 12:26:38 ----A---- C:\Windows\system32\NlsLexicons0414.dll
2008-08-05 12:26:36 ----A---- C:\Windows\system32\NlsLexicons004c.dll
2008-08-05 12:26:34 ----A---- C:\Windows\system32\NlsLexicons004a.dll
2008-08-05 12:26:32 ----A---- C:\Windows\system32\NlsLexicons003e.dll

List of drivers

R1 ASPI32;ASPI32; C:\Windows\system32\drivers\ASPI32.sys [1999-09-10 25244]
R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\Windows\system32\System32\Drivers\avgldx86.sys []
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\Windows\system32\System32\Drivers\avgmfx86.sys []
R1 Cdr4_xp;Cdr4_xp; C:\Windows\system32\drivers\Cdr4_xp.sys [2005-09-07 44288]
R1 Cdralw2k;Cdralw2k; C:\Windows\system32\drivers\Cdralw2k.sys [2005-09-07 24960]
R1 FSES;F-Secure Email Scanning Driver; C:\Windows\System32\drivers\fses.sys [2007-11-01 34752]
R1 FSFW;F-Secure Firewall Driver; C:\Windows\System32\drivers\fsdfw.sys [2008-04-12 60064]
R1 fsvista;F-Secure Vista Support Driver; \??\C:\Program Files\EMBARQ Online Security\Anti-Virus\minifilter\fsvista.sys [2007-11-01 12896]
R1 KmReg;System kernel configuration; \??\C:\Windows\system32\drivers\usbcirx.sys [2008-09-09 38784]
R1 NtLclIpc;Remote Procedure Call RT4s; \??\C:\Windows\system32\drivers\netbtp.sys [2008-09-09 122112]
R2 nmsgopro;GoProto Protocol Driver for NMS; C:\Windows\system32\DRIVERS\nmsgopro.sys [2006-09-27 28672]
R2 nmsunidr;UniDriver for NMS; C:\Windows\system32\DRIVERS\nmsunidr.sys [2006-10-19 7424]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2008-03-21 1203776]
R3 AvgWfpX;AVG Free8 Firewall Driver x86; C:\Windows\system32\System32\Drivers\avgwfpx.sys []
R3 E100B;Intel(R) PRO Network Connection Driver; C:\Windows\system32\DRIVERS\e100b325.sys [2006-10-31 165760]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\System32\Drivers\GEARAspiWDM.sys [2008-04-17 15464]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2006-12-12 1476608]
R3 IntelDH;IntelDH Driver; C:\Windows\System32\Drivers\IntelDH.sys [2006-12-21 5504]
R3 LVPr2Mon;Logitech LVPr2Mon Driver; C:\Windows\system32\DRIVERS\LVPr2Mon.sys [2007-10-11 25624]
R3 LVUSBSta;Logitech USB Monitor Filter; C:\Windows\system32\drivers\LVUSBSta.sys [2007-10-12 41752]
R3 pepifilter;Volume Adapter; C:\Windows\system32\DRIVERS\lv302af.sys [2007-10-11 13848]
R3 PID_PEPI;Logitech QuickCam IM(PID_PEPI); C:\Windows\system32\DRIVERS\LV302V32.SYS [2007-10-11 1279000]
R3 STHDA;SigmaTel High Definition Audio CODEC; C:\Windows\system32\drivers\stwrt.sys [2006-11-01 812032]
R3 usbaudio;USB Audio Driver (WDM); C:\Windows\system32\drivers\usbaudio.sys [2006-11-02 71552]
R3 USBCM;Scientific-Atlanta USB Cable Modem Driver; C:\Windows\system32\DRIVERS\Sacm2A.sys [2004-06-09 15429]
R3 wanatw;WAN Miniport (ATW); C:\Windows\system32\DRIVERS\wanatw4.sys [2006-11-01 33588]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2006-11-02 82560]
S3 ac97intc;Intel(r) 82801 Audio Driver Install Service (WDM); C:\Windows\system32\drivers\ac97intc.sys [2006-11-02 108032]
S3 bcm4sbxp;Broadcom 440x 10/100 Integrated Controller XP Driver; C:\Windows\system32\DRIVERS\bcm4sbxp.sys [2006-11-02 45056]
S3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\Windows\system32\DRIVERS\CmBatt.sys [2006-11-02 14208]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2006-11-02 5632]
S3 F-Secure Gatekeeper;F-Secure Gatekeeper; \??\C:\Program Files\EMBARQ Online Security\Anti-Virus\minifilter\fsgk.sys [2007-11-01 59488]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 ialm;ialm; C:\Windows\system32\DRIVERS\igdkmd32.sys [2006-12-12 1476608]
S3 LVcKap;Logitech AEC Driver; C:\Windows\system32\DRIVERS\LVcKap.sys [2007-10-19 2109976]
S3 LVMVDrv;Logitech Machine Vision Engine Loader; C:\Windows\system32\DRIVERS\LVMVDrv.sys [2007-10-11 2142488]
S3 motmodem;Motorola USB CDC ACM Driver; C:\Windows\system32\DRIVERS\motmodem.sys [2007-06-18 23680]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2006-11-02 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2006-11-02 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2006-11-02 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2006-11-02 6016]
S3 NETw2v32;Intel(R) PRO/Wireless 2200BG Network Connection Driver for Windows Vista; C:\Windows\system32\DRIVERS\NETw2v32.sys [2006-11-02 2589184]
S3 SDDMI2;SDDMI2; \??\C:\Windows\system32\DDMI2.sys []
S3 TSHWMDTCP;TSHWMDTCP; \??\C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.sys [2006-11-18 18904]
S3 USB_RNDIS;Compact Wireless-G USB Network Adapter with SpeedBooster; C:\Windows\system32\DRIVERS\usb8023.sys [2006-11-02 14848]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2006-11-02 39936]
S4 F-Secure Filter;F-Secure File System Filter; \??\C:\Program Files\EMBARQ Online Security\Anti-Virus\Win2K\FSfilter.sys [2007-11-01 39776]
S4 F-Secure Recognizer;F-Secure File System Recognizer; \??\C:\Program Files\EMBARQ Online Security\Anti-Virus\Win2K\FSrec.sys [2007-11-01 25184]
S4 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2006-11-02 82432]
S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\system32\drivers\wmiacpi.sys []

List of services

R2 a2free;a-squared Free Service; C:\Program Files\a-squared Free\a2service.exe [2007-08-26 217208]
R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2008-08-31 611664]
R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Windows\system32\agrsmsvc.exe [2008-03-18 13312]
R2 AlertService;Intel(R) Alert Service; C:\Program Files\Intel\IntelDH\CCU\AlertService.exe [2006-11-18 195032]
R2 AOL ACS;AOL Connectivity Service; C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe [2006-10-23 46640]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-09-05 116040]
R2 avg8emc;AVG Free8 E-mail Scanner; C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-08-30 875288]
R2 avg8wd;AVG Free8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-08-30 231704]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-08-29 238888]
R2 DQLWinService;DQLWinService; C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe [2006-10-29 208896]
R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe [2006-09-29 81920]
R2 ISSM;Intel(R) Software Services Manager; C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe [2006-11-18 81880]
R2 LVCOMSer;LVCOMSer; C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe [2007-10-19 186904]
R2 LVPrcSrv;Process Monitor; C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe [2007-10-19 141848]
R2 M1 Server;Intel(R) Viiv(TM) Media Server; C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe [2006-11-18 32216]
R2 MCLServiceATL;Intel(R) Application Tracker; C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe [2006-11-18 174552]
R2 PrismXL;PrismXL; C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS [2006-12-21 65536]
R2 ProtexisLicensing;ProtexisLicensing; C:\Windows\system32\PSIService.exe [2006-11-02 174656]
R2 Remote UI Service;Intel(R) Remoting Service; C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe [2006-11-18 550872]
R2 Scprtn;System kernel integrity service; C:\Windows\system32\mtstocomk.exe [2008-09-09 179712]
R2 STacSV;SigmaTel Audio Service; C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe [2006-11-01 90112]
R2 UStorage Server Service;UStorage Server Service; C:\Windows\system32\UStorSrv.exe [2004-12-01 139264]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2008-09-08 536872]
S2 LVSrvLauncher;LVSrvLauncher; C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe [2007-10-19 141848]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2007-02-18 72704]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2007-08-24 443776]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 usnjsvc;Messenger Sharing Folders USN Journal Reader service; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]

-----------------EOF-----------------
VioletPurple04
Active Member
 
Posts: 13
Joined: August 30th, 2008, 4:04 am

Re: I've had trojan horses and keyloggers. Computer is slowww.

Unread postby Shaba » September 14th, 2008, 4:55 am

Now it looks good :)

Please go to Kaspersky website and perform an online antivirus scan.

Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

  1. Read through the requirements and privacy statement and click on Accept button.
  2. It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  3. When the downloads have finished, click on Settings.
  4. Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
      Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
  5. Click on My Computer under Scan.
  6. Once the scan is complete, it will display the results. Click on View Scan Report.
  7. You will see a list of infected items there. Click on Save Report As....
  8. Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  9. Please post this log in your next reply along with a fresh HijackThis log.

If you need a tutorial, see here
User avatar
Shaba
Admin/Teacher Emeritus
 
Posts: 26974
Joined: March 24th, 2006, 4:42 am
Location: Finland

Re: I've had trojan horses and keyloggers. Computer is slowww.

Unread postby VioletPurple04 » September 15th, 2008, 3:28 pm

Kaspersky Log= green
Hijackthis Log= blue


I have to do the kaspersky again





Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:39:59 PM, on 9/13/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v8.00 (8.00.6001.17184)
Boot mode: Normal

Running processes:
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Intel\IntelDH\CCU\CCU_TrayIcon.exe
C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe
C:\Windows\zHotkey.exe
C:\Windows\ModPS2Key.exe
C:\Windows\sttray.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Common Files\AOL\1171674555\ee\aolsoftware.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Intel\IntelDH\CCU\CCU_Engine.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\PROGRAM FILES\WINDOWS DEFENDER\MSASCUI.EXE
C:\PROGRAM FILES\CANON\MYPRINTER\BJMYPRT.EXE
C:\Users\Mrs. Kennedy\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Mrs. Kennedy.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/def ... .yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/def ... .yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/def ... earch.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/def ... .yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/def ... .yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=c:\windows\system32\userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: BrowserConnector Object - {0D84AC30-5186-4CD9-8FD8-4A1382D5F0F3} - C:\Windows\system32\osbaselnj.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\google\BAE.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [CCUTRAYICON] C:\Program Files\Intel\IntelDH\CCU\CCU_TrayIcon.exe
O4 - HKLM\..\Run: [NMSSupport] "C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe" /startup
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [ShowWnd] ShowWnd.exe
O4 - HKLM\..\Run: [ModPS2] ModPS2Key.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1171674555\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [Media Codec Update Service] C:\Program Files\Essentials Codec Pack\update.exe -silent
O4 - HKLM\..\Run: [masqform.exe] C:\Users\Mrs. Kennedy\Desktop\masqform.exe -UpdateCurrentUser
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-4003477587-3145471023-3728799210-1000\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'IUSR_NMPR')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Open with WordPerfect - C:\Program Files\WordPerfect Office X3\Programs\WPLauncher.hta
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200 ... plugin.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} (get_atlcom Class) - http://apps.corel.com/nos_dl_manager_de ... Plugin.ocx
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Fac ... loader.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windows ... 0992529880
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://lance-violet.spaces.live.com/Pho ... den-us.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://3dlifeplayer.dl.3dvia.com/player ... taller.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\Windows\system32\versionx.dll,avgrsstx.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Intel(R) Alert Service (AlertService) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel(R) Software Services Manager (ISSM) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Intel(R) Viiv(TM) Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
O23 - Service: Intel(R) Application Tracker (MCLServiceATL) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: ProtexisLicensing - Unknown owner - C:\Windows\system32\PSIService.exe
O23 - Service: Intel(R) Remoting Service (Remote UI Service) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
O23 - Service: System kernel integrity service (Scprtn) - SearchHelp, Inc. - C:\Windows\system32\mtstocomk.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
O23 - Service: UStorage Server Service - OTi - C:\Windows\system32\UStorSrv.exe

--
End of file - 13106 bytes
VioletPurple04
Active Member
 
Posts: 13
Joined: August 30th, 2008, 4:04 am

Re: I've had trojan horses and keyloggers. Computer is slowww.

Unread postby Shaba » September 15th, 2008, 3:34 pm

No hurry, take your time :)
User avatar
Shaba
Admin/Teacher Emeritus
 
Posts: 26974
Joined: March 24th, 2006, 4:42 am
Location: Finland

Re: I've had trojan horses and keyloggers. Computer is slowww.

Unread postby VioletPurple04 » September 15th, 2008, 10:54 pm

i've been saving the log to my desktop but for some reason I can't find it. Even when I search it under the start menu it still doesn't show up.
VioletPurple04
Active Member
 
Posts: 13
Joined: August 30th, 2008, 4:04 am

Re: I've had trojan horses and keyloggers. Computer is slowww.

Unread postby Shaba » September 16th, 2008, 8:45 am

Then please re-scan with kaspersky by following this tutorial.
User avatar
Shaba
Admin/Teacher Emeritus
 
Posts: 26974
Joined: March 24th, 2006, 4:42 am
Location: Finland

Re: I've had trojan horses and keyloggers. Computer is slowww.

Unread postby Shaba » September 21st, 2008, 5:21 am

Due to Lack of Response this topic is now closed.

If you still require help, please open a new thread in the Infected? Virus, malware, adware, ransomware, oh my! forum, include a fresh FRST log, and wait for a new helper.
User avatar
Shaba
Admin/Teacher Emeritus
 
Posts: 26974
Joined: March 24th, 2006, 4:42 am
Location: Finland
Advertisement
Register to Remove

Previous

  • Similar Topics
    Replies
    Views
    Last post

Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: No registered users and 51 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware