Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

Search Redirect Malware

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

Search Redirect Malware

Unread postby rjj76 » February 15th, 2010, 5:06 pm

I am having an issue with search redirect. I've combed through the forums trying to find different potential solutions - many Malware programs/java removal/firefox reinstallations later, I'm hoping to get a bit of help. Hopefully I've gotten things most of the way there but don't understand the OTL and Combofix programs so thought it be best to seek professional help.

I've pasted my HijackThis logs below. Thank you so much in advance for your help.



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:53:40 PM, on 2/15/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16981)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Dell\DellDock\DockLogin.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Dell\DellDock\DellDock.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Battery Meter\BTMeter.exe
C:\Program Files\Elantech\ETDCtrl.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\CapsLKNotify\CapsLKNotify.exe
C:\Program Files\WSED\WSED.exe
C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\PersistenceThread.exe
C:\Program Files\Mindjet\MindManager 8\MMReminderService.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\XoftSpySE6\XoftSpySE.exe
C:\Documents and Settings\Robert Jericho\Start Menu\Programs\Startup\osd_vol.exe
C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\XoftSpySE\6\xoftspyservice.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: ShopSafe Browser Helper Object - {333F6B96-3992-4D58-A499-145A10FE48C3} - C:\Program Files\ShopSafe\BhoSSafe.dll
O2 - BHO: CmjBrowserHelperObject Object - {6FE6A929-59D1-4763-91AD-29B61CFFB35B} - C:\Program Files\Mindjet\MindManager 8\Mm8InternetExplorer.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [BTMeter] C:\Program Files\Battery Meter\BTMeter.exe
O4 - HKLM\..\Run: [ETDWare] C:\Program Files\Elantech\ETDCtrl.exe
O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
O4 - HKLM\..\Run: [CapsLKNotify] C:\Program Files\CapsLKNotify\CapsLKNotify.exe
O4 - HKLM\..\Run: [WSED] C:\Program Files\WSED\WSED.exe
O4 - HKLM\..\Run: [Dell Webcam Central] "C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe" /mode2
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [SBAMTray] C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [PersistenceThread] C:\WINDOWS\system32\PersistenceThread.exe
O4 - HKLM\..\Run: [MMReminderService] C:\Program Files\Mindjet\MindManager 8\MMReminderService.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [XoftSpySE] "C:\Program Files\XoftSpySE6\XoftSpySE.exe" -NM -hidesplash
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Robert Jericho\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
O4 - Startup: osd_vol.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Send to Mindjet MindManager - {2F72393D-2472-4F82-B600-ED77F354B7FF} - C:\Program Files\Mindjet\MindManager 8\Mm8InternetExplorer.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/s ... wflash.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: igdlogin - C:\WINDOWS\SYSTEM32\igdlogin.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: VIPRE Antivirus + Antispyware (SBAMSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe
O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
O23 - Service: XoftSpyService - ParetoLogic Inc. - C:\Program Files\Common Files\XoftSpySE\6\xoftspyservice.exe

--
End of file - 11113 bytes



Uninstall Log:


Acronis True Image Home
Adobe Acrobat 7.1.0 Professional
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Advanced Audio FX Engine
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Battery Meter
Bonjour
CapsLKNotify
CDBurnerXP
Citrix XenApp Plugin for Hosted Apps
Codec Pack - All In 1 6.0.3.0
Dell 5530 Wireless Broadband Package
Dell Dock
Dell Dock
Dell Resource CD
Dell Support Center (Support Software)
Dell Webcam Central
Dell Wireless WLAN Card Utility
EMSC
ETDWare PS/2-x86 7.0.4.4 WHQL
Google Talk Plugin
High Definition Audio Driver Package - KB888111
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB976098-v2)
Integrated Webcam Driver (1.01.01.0116)
Intel(R) Graphics Media Accelerator 500
iTunes
Java DB 10.5.3.0
Java(TM) 6 Update 18
Java(TM) SE Development Kit 6 Update 18
Live! Cam Avatar Creator
Malwarebytes' Anti-Malware
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
Microsoft National Language Support Downlevel APIs
Microsoft Office Professional Edition 2003
Microsoft Silverlight
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Mindjet MindManager 8
Mozilla Firefox (3.6)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 6 Service Pack 2 (KB973686)
OGA Notifier 2.0.0048.0
PDF-XChange 3
QuickTime
QuickTime Alternative 1.90
Real Alternative 1.9.0
Realtek Card Reader
REALTEK GbE & FE Ethernet PCI-E NIC Driver
Realtek High Definition Audio Driver
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB976325)
Security Update for Windows Internet Explorer 7 (KB978207)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB973540)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978706)
SpyHunter
SUPERAntiSpyware Free Edition
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Update for Windows XP (KB978207)
VLC media player 1.0.3
WIDCOMM Bluetooth Software
Windows Imaging Component
Windows Media Format Runtime
Windows XP Service Pack 3
WinRAR archiver
XoftSpySE
rjj76
Regular Member
 
Posts: 16
Joined: February 15th, 2010, 4:56 pm
Advertisement
Register to Remove

Re: Search Redirect Malware

Unread postby muppy03 » February 20th, 2010, 12:32 am

Hello and welcome to Malware Removal Forums

IMPORTANT

Whatever repairs we make, are for fixing your computer problems only and by no means should be used on another computer.
To make cleaning this machine easier:-
  • Continue to respond to this thread until I give you the All Clean!
  • Please DO NOT uninstall/install any programs unless asked to. It is more difficult when files/programs appear or disappear from the logs.
  • Please do not run any scans other than those requested and do not post any logs/reports unless specifically requested to do so.
  • Please follow all instructions in the order posted.
  • If you have any questions or do not understand instructions, please ask before continuing.
  • Please reply to this thread. Do not start a new topic.

I recommend uninstalling the following:-

XoftSpySE

NEXT Download and Run: RSIT

  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<<will be maximized) and info.txt (<<will be minimized)

GMER Rootkit Scanner
Download GMER Rootkit Scanner from here.
  • Double click the .exe file. If asked to allow gmer.sys driver to load, please consent
  • If it gives you a warning about rootkit activity and asks if you want to run scan...click on NO

    Image
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following ...
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file
  • Save it where you can easily find it, such as your desktop, and post it in reply
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries


Please reply with:-
  • RSIT logs ( info.txt and log.txt)
  • GMER Log
User avatar
muppy03
MRU Emeritus
MRU Emeritus
 
Posts: 4782
Joined: December 4th, 2007, 5:30 am
Location: Australia

Re: Search Redirect Malware

Unread postby rjj76 » February 21st, 2010, 4:58 pm

I'll post the RSIT logs in my next post - GMER did not run properly on my computer. The first time resulted in a blue screen.

The second running has resulted in the computer locking up - I'm typing what is on the screen now that's frozen in case that helps -

Type; Name; Value (some entries are cut off)
SSDT; \SystemRoot\System32\drivers\sbaphd.sys {Sunbelt ActiveProtect... ; ZwCreateKey...
SSDT; \SystemRoot\System32\drivers\sbaphd.sys {Sunbelt ActiveProtect... ; ZwSetValueKey
AttachedID...; \Driver\Tcpip \Device\Ip; sbtis.sys (Sunbel...
AttachedID...; \Driver\Tcpip \Device\Tcp; sbtis.sys (Sunbel...
AttachedID...; \Driver\Fdisk \Device\HarddiskVolume1; snapman.sys(Ac...
AttachedID...; \Driver\Fdisk \Device\HarddiskVolume2; snapman.sys(Ac...
Device; \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3; [F74E9B3A] atap...
Device; \Driver\atapi \Device\Ide\IdePort0; [F74E9B3A] atap...
Device; \Driver\atapi \Device\Ide\IdePort1; [F74E9B3A] atap...
AttachedID...; \Driver\Tcpip \Device\Udp; sbtis.sys (Sunbel...
AttachedID...; \Driver\Tcpip \Device\Rawlp; sbtis.sys (Sunbel...
AttachedID...; \FileSystem\Fastfat \Fat; fltmgr.sys (Micros...
rjj76
Regular Member
 
Posts: 16
Joined: February 15th, 2010, 4:56 pm

Re: Search Redirect Malware

Unread postby rjj76 » February 21st, 2010, 5:07 pm

info.txt logfile of random's system information tool 1.06 2010-02-20 11:07:19

======Uninstall list======

-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{88564CEF-20A5-4EF2-A05F-309F2EBA9B06}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BC12448A-0B41-4E11-B242-B1129512F5B7}\setup.exe" -l0x9
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Acronis True Image Home-->MsiExec.exe /X{419CF344-3D94-4DAD-99C8-EA7B00E5EA8B}
Adobe Acrobat 7.1.0 Professional-->msiexec /I {AC76BA86-1033-0000-7760-000000000002}
Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Advanced Audio FX Engine-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{88564CEF-20A5-4EF2-A05F-309F2EBA9B06}\setup.exe" -l0x9 /remove
Apple Application Support-->MsiExec.exe /I{3FA365DF-2D68-45ED-8F83-8C8A33E65143}
Apple Mobile Device Support-->MsiExec.exe /I{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}
Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
Battery Meter-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{543A4F31-9590-416A-A621-42CEB4C6A694} /l1033
Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
CapsLKNotify-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{90578106-70AF-4198-B9DE-1924FA83B03A}
CDBurnerXP-->"C:\Program Files\CDBurnerXP\unins000.exe"
Citrix XenApp Plugin for Hosted Apps-->MsiExec.exe /I{388C130B-0079-46B4-A0D5-DC2DD7A89A7B}
Codec Pack - All In 1 6.0.3.0-->C:\WINDOWS\iun6002.exe "C:\Program Files\Codec Pack - All In 1\irunin.ini"
Dell 5530 Wireless Broadband Package-->MsiExec.exe /X{580E3E43-F5EB-41C9-A348-1B7DCF002C2C}
Dell Dock-->"C:\Documents and Settings\All Users\Application Data\{7322D736-AA5F-4DD0-8E33-EA48318CC276}\delldock.exe" REMOVE=TRUE MODIFY=FALSE
Dell Dock-->C:\Documents and Settings\All Users\Application Data\{7322D736-AA5F-4DD0-8E33-EA48318CC276}\delldock.exe
Dell Resource CD-->MsiExec.exe /X{42929F0F-CE14-47AF-9FC7-FF297A603021}
Dell Support Center (Support Software)-->MsiExec.exe /X{E3BFEE55-39E2-4BE0-B966-89FE583822C1}
Dell Webcam Central-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BC12448A-0B41-4E11-B242-B1129512F5B7}\setup.exe" -l0x9 /remove
Dell Wireless WLAN Card Utility-->"C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwlu00.exe" verbose /rootkey="Software\Broadcom\802.11\UninstallInfo" /rootdir="C:\Program Files\Dell\Dell Wireless WLAN Card"
EMSC-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{FEF06E73-A519-4510-8CF3-B66041B91D8A}
ETDWare PS/2-x86 7.0.4.4 WHQL-->C:\Program Files\Elantech\ETDUninst.exe
Google Talk Plugin-->MsiExec.exe /I{BBF6D0CD-A081-369F-B0B8-F168594CBB6B}
High Definition Audio Driver Package - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
Hotfix for Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB961118)-->"C:\WINDOWS\$NtUninstallKB961118$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB976098-v2)-->"C:\WINDOWS\$NtUninstallKB976098-v2$\spuninst\spuninst.exe"
Integrated Webcam Driver (1.01.01.0116) -->C:\WINDOWS\CtDrvIns.exe -uninstall -script OA012.uns -plugin OA012Pin.dll -pluginres OA012Pin.crl -nodisconprompt -langid 0x0409
Intel(R) Graphics Media Accelerator 500-->C:\WINDOWS\system32\lpgun.exe -uninstall
iTunes-->MsiExec.exe /I{A6FDF86A-F541-4E7B-AEA0-8849A2A700D5}
Java DB 10.5.3.0-->MsiExec.exe /X{00BA866C-F2A2-4BB9-A308-3DFA695B6F7C}
Java(TM) 6 Update 18-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216018FF}
Java(TM) SE Development Kit 6 Update 18-->MsiExec.exe /I{32A3A4F4-B792-11D6-A78A-00B0D0160180}
Live! Cam Avatar Creator-->C:\Program Files\InstallShield Installation Information\{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}\setup.exe -runfromtemp -l0x0009 -removeonly /remove
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft Kernel-Mode Driver Framework Feature Pack 1.7-->"C:\WINDOWS\$NtUninstallWdf01007$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office Professional Edition 2003-->MsiExec.exe /I{91110409-6000-11D3-8CFE-0150048383C9}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148-->MsiExec.exe /X{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
Mindjet MindManager 8-->MsiExec.exe /I{D7FD752A-DDB9-4685-83FD-E20C7C59BD84}
Mozilla Firefox (3.6)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
MSXML 6 Service Pack 2 (KB973686)-->MsiExec.exe /I{56EA8BC0-3751-4B93-BC9D-6651CC36E5AA}
OGA Notifier 2.0.0048.0-->MsiExec.exe /I{B2544A03-10D0-4E5E-BA69-0362FFC20D18}
Opera 10.50-->MsiExec.exe /X{88840901-1811-4214-99AA-B7AAF96EDC5A}
PDF-XChange 3-->"C:\Program Files\Mindjet\MindManager 8\PDF-XChange\unins000.exe"
QuickTime Alternative 1.90-->"C:\Program Files\QuickTime Alternative\unins000.exe"
QuickTime-->MsiExec.exe /I{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}
Real Alternative 1.9.0-->"C:\Program Files\Real Alternative\unins000.exe"
Realtek Card Reader-->C:\Program Files\InstallShield Installation Information\{D10CB652-9332-4242-B7A9-2D61570144F7}\setup.exe -runfromtemp -l0x0009 -removeonly
REALTEK GbE & FE Ethernet PCI-E NIC Driver-->C:\Program Files\InstallShield Installation Information\{C9BED750-1211-4480-B1A5-718A3BE15525}\setup.exe -runfromtemp -l0x0009 -removeonly
Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\setup.exe" -l0x9 -removeonly
Security Update for Windows Internet Explorer 7 (KB938127-v2)-->"C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB976325)-->"C:\WINDOWS\ie7updates\KB976325-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB978207)-->"C:\WINDOWS\ie7updates\KB978207-IE7\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB954155)-->"C:\WINDOWS\$NtUninstallKB954155_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB968816)-->"C:\WINDOWS\$NtUninstallKB968816_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB973540)-->"C:\WINDOWS\$NtUninstallKB973540_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB973540)-->"C:\WINDOWS\$NtUninstallKB973540_WM9L$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
Security Update for Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956744)-->"C:\WINDOWS\$NtUninstallKB956744$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956844)-->"C:\WINDOWS\$NtUninstallKB956844$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958869)-->"C:\WINDOWS\$NtUninstallKB958869$\spuninst\spuninst.exe"
Security Update for Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960859)-->"C:\WINDOWS\$NtUninstallKB960859$\spuninst\spuninst.exe"
Security Update for Windows XP (KB961501)-->"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
Security Update for Windows XP (KB969059)-->"C:\WINDOWS\$NtUninstallKB969059$\spuninst\spuninst.exe"
Security Update for Windows XP (KB969947)-->"C:\WINDOWS\$NtUninstallKB969947$\spuninst\spuninst.exe"
Security Update for Windows XP (KB970238)-->"C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
Security Update for Windows XP (KB970430)-->"C:\WINDOWS\$NtUninstallKB970430$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971468)-->"C:\WINDOWS\$NtUninstallKB971468$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971486)-->"C:\WINDOWS\$NtUninstallKB971486$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971557)-->"C:\WINDOWS\$NtUninstallKB971557$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971633)-->"C:\WINDOWS\$NtUninstallKB971633$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971657)-->"C:\WINDOWS\$NtUninstallKB971657$\spuninst\spuninst.exe"
Security Update for Windows XP (KB972270)-->"C:\WINDOWS\$NtUninstallKB972270$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973354)-->"C:\WINDOWS\$NtUninstallKB973354$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973507)-->"C:\WINDOWS\$NtUninstallKB973507$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973525)-->"C:\WINDOWS\$NtUninstallKB973525$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973869)-->"C:\WINDOWS\$NtUninstallKB973869$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973904)-->"C:\WINDOWS\$NtUninstallKB973904$\spuninst\spuninst.exe"
Security Update for Windows XP (KB974112)-->"C:\WINDOWS\$NtUninstallKB974112$\spuninst\spuninst.exe"
Security Update for Windows XP (KB974318)-->"C:\WINDOWS\$NtUninstallKB974318$\spuninst\spuninst.exe"
Security Update for Windows XP (KB974392)-->"C:\WINDOWS\$NtUninstallKB974392$\spuninst\spuninst.exe"
Security Update for Windows XP (KB974571)-->"C:\WINDOWS\$NtUninstallKB974571$\spuninst\spuninst.exe"
Security Update for Windows XP (KB975025)-->"C:\WINDOWS\$NtUninstallKB975025$\spuninst\spuninst.exe"
Security Update for Windows XP (KB975467)-->"C:\WINDOWS\$NtUninstallKB975467$\spuninst\spuninst.exe"
Security Update for Windows XP (KB975560)-->"C:\WINDOWS\$NtUninstallKB975560$\spuninst\spuninst.exe"
Security Update for Windows XP (KB975713)-->"C:\WINDOWS\$NtUninstallKB975713$\spuninst\spuninst.exe"
Security Update for Windows XP (KB977165)-->"C:\WINDOWS\$NtUninstallKB977165$\spuninst\spuninst.exe"
Security Update for Windows XP (KB977914)-->"C:\WINDOWS\$NtUninstallKB977914$\spuninst\spuninst.exe"
Security Update for Windows XP (KB978037)-->"C:\WINDOWS\$NtUninstallKB978037$\spuninst\spuninst.exe"
Security Update for Windows XP (KB978251)-->"C:\WINDOWS\$NtUninstallKB978251$\spuninst\spuninst.exe"
Security Update for Windows XP (KB978262)-->"C:\WINDOWS\$NtUninstallKB978262$\spuninst\spuninst.exe"
Security Update for Windows XP (KB978706)-->"C:\WINDOWS\$NtUninstallKB978706$\spuninst\spuninst.exe"
SpyHunter-->"C:\Program Files\Enigma Software Group\SpyHunter\Uninstall.exe" "C:\Program Files\Enigma Software Group\SpyHunter\install.log" -u
SUPERAntiSpyware Free Edition-->MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
Update for Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Update for Windows XP (KB955759)-->"C:\WINDOWS\$NtUninstallKB955759$\spuninst\spuninst.exe"
Update for Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
Update for Windows XP (KB968389)-->"C:\WINDOWS\$NtUninstallKB968389$\spuninst\spuninst.exe"
Update for Windows XP (KB971737)-->"C:\WINDOWS\$NtUninstallKB971737$\spuninst\spuninst.exe"
Update for Windows XP (KB973687)-->"C:\WINDOWS\$NtUninstallKB973687$\spuninst\spuninst.exe"
Update for Windows XP (KB973815)-->"C:\WINDOWS\$NtUninstallKB973815$\spuninst\spuninst.exe"
Update for Windows XP (KB978207)-->"C:\WINDOWS\$NtUninstallKB978207$\spuninst\spuninst.exe"
VLC media player 1.0.3-->C:\Program Files\VideoLAN\VLC\uninstall.exe
WIDCOMM Bluetooth Software-->MsiExec.exe /X{84814E6B-2581-46EC-926A-823BD1C670F6}
Windows Imaging Component-->"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
Windows Media Format Runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe

======Hosts File======

127.0.0.1 localhost

======Security center information======

AV: Sunbelt VIPRE

======System event log======

Computer Name: MINI10
Event Code: 11
Message: The driver detected a controller error on \Device\CdRom0.

Record Number: 42
Source Name: Cdrom
Time Written: 20100123004442.000000-360
Event Type: error
User:

Computer Name: MINI10
Event Code: 11
Message: The driver detected a controller error on \Device\CdRom0.

Record Number: 41
Source Name: Cdrom
Time Written: 20100123004409.000000-360
Event Type: error
User:

Computer Name: MINI10
Event Code: 11
Message: The driver detected a controller error on \Device\CdRom0.

Record Number: 40
Source Name: Cdrom
Time Written: 20100123004403.000000-360
Event Type: error
User:

Computer Name: MINI10
Event Code: 11
Message: The driver detected a controller error on \Device\CdRom0.

Record Number: 39
Source Name: Cdrom
Time Written: 20100123004403.000000-360
Event Type: error
User:

Computer Name: MINI10
Event Code: 11
Message: The driver detected a controller error on \Device\CdRom0.

Record Number: 37
Source Name: Cdrom
Time Written: 20100123003336.000000-360
Event Type: error
User:

=====Application event log=====

Computer Name: MINI10
Event Code: 5603
Message: A provider, Rsop Planning Mode Provider, has been registered in the WMI namespace, root\RSOP, but did not specify the HostingModel property. This provider will be run using the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests. Ensure that provider has been reviewed for security behavior and update the HostingModel property of the provider registration to an account with the least privileges possible for the required functionality.

Record Number: 18
Source Name: WinMgmt
Time Written: 20100123001751.000000-360
Event Type: warning
User: NT AUTHORITY\SYSTEM

Computer Name: MINI10
Event Code: 5603
Message: A provider, Rsop Planning Mode Provider, has been registered in the WMI namespace, root\RSOP, but did not specify the HostingModel property. This provider will be run using the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests. Ensure that provider has been reviewed for security behavior and update the HostingModel property of the provider registration to an account with the least privileges possible for the required functionality.

Record Number: 17
Source Name: WinMgmt
Time Written: 20100123001751.000000-360
Event Type: warning
User: NT AUTHORITY\SYSTEM

Computer Name: MINI10
Event Code: 63
Message: A provider, CmdTriggerConsumer, has been registered in the WMI namespace, Root\cimv2, to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.

Record Number: 13
Source Name: WinMgmt
Time Written: 20100123001418.000000-360
Event Type: warning
User: NT AUTHORITY\SYSTEM

Computer Name: MINI10
Event Code: 63
Message: A provider, CmdTriggerConsumer, has been registered in the WMI namespace, Root\cimv2, to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.

Record Number: 12
Source Name: WinMgmt
Time Written: 20100123001418.000000-360
Event Type: warning
User: NT AUTHORITY\SYSTEM

Computer Name: MINI10
Event Code: 63
Message: A provider, HiPerfCooker_v1, has been registered in the WMI namespace, Root\WMI, to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.

Record Number: 11
Source Name: WinMgmt
Time Written: 20100123001414.000000-360
Event Type: warning
User: NT AUTHORITY\SYSTEM

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\system32\wbem;C:\Program Files\QuickTime\QTSystem
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 28 Stepping 2, GenuineIntel
"PROCESSOR_REVISION"=1c02
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"CLASSPATH"=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip

-----------------EOF-----------------


Logfile of random's system information tool 1.06 (written by random/random)
Run by Robert Jericho at 2010-02-21 11:00:12
Microsoft Windows XP Professional Service Pack 3
System drive C: has 62 GB (40%) free of 153 GB
Total RAM: 1014 MB (14% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:00:21 AM, on 2/21/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16981)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Dell\DellDock\DockLogin.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Dell\DellDock\DellDock.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Elantech\ETDCtrl.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\CapsLKNotify\CapsLKNotify.exe
C:\Program Files\WSED\WSED.exe
C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\igfxtray.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\WINDOWS\system32\PersistenceThread.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe
C:\Program Files\Mindjet\MindManager 8\MMReminderService.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Battery Meter\BTMeter.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Documents and Settings\Robert Jericho\Start Menu\Programs\Startup\osd_vol.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Robert Jericho\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Robert Jericho.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: ShopSafe Browser Helper Object - {333F6B96-3992-4D58-A499-145A10FE48C3} - C:\Program Files\ShopSafe\BhoSSafe.dll
O2 - BHO: CmjBrowserHelperObject Object - {6FE6A929-59D1-4763-91AD-29B61CFFB35B} - C:\Program Files\Mindjet\MindManager 8\Mm8InternetExplorer.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [ETDWare] C:\Program Files\Elantech\ETDCtrl.exe
O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
O4 - HKLM\..\Run: [CapsLKNotify] C:\Program Files\CapsLKNotify\CapsLKNotify.exe
O4 - HKLM\..\Run: [WSED] C:\Program Files\WSED\WSED.exe
O4 - HKLM\..\Run: [Dell Webcam Central] "C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe" /mode2
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [SBAMTray] C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [PersistenceThread] C:\WINDOWS\system32\PersistenceThread.exe
O4 - HKLM\..\Run: [MMReminderService] C:\Program Files\Mindjet\MindManager 8\MMReminderService.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [BTMeter] C:\Program Files\Battery Meter\BTMeter.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Robert Jericho\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
O4 - Startup: osd_vol.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Send to Mindjet MindManager - {2F72393D-2472-4F82-B600-ED77F354B7FF} - C:\Program Files\Mindjet\MindManager 8\Mm8InternetExplorer.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/s ... wflash.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O20 - Winlogon Notify: igdlogin - C:\WINDOWS\SYSTEM32\igdlogin.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: VIPRE Antivirus + Antispyware (SBAMSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe
O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

--
End of file - 10732 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1993962763-746137067-1801674531-1003Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1993962763-746137067-1801674531-1003UA.job
C:\WINDOWS\tasks\OGALogon.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-12-18 59032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{333F6B96-3992-4D58-A499-145A10FE48C3}]
ShopSafeBrowserHelper Class - C:\Program Files\ShopSafe\BhoSSafe.dll [2007-03-13 143360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6FE6A929-59D1-4763-91AD-29B61CFFB35B}]
CmjBrowserHelperObject Object - C:\Program Files\Mindjet\MindManager 8\Mm8InternetExplorer.dll [2008-11-14 70944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2006-12-18 231160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-02-12 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-02-12 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2006-12-18 231160]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"=C:\WINDOWS\system32\WLTRAY.exe [2008-11-26 2289664]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2008-12-09 18063872]
"ETDWare"=C:\Program Files\Elantech\ETDCtrl.exe [2009-03-30 418816]
"dellsupportcenter"=C:\Program Files\Dell Support Center\bin\sprtcmd.exe [2009-06-03 206064]
"CapsLKNotify"=C:\Program Files\CapsLKNotify\CapsLKNotify.exe [2009-03-17 320808]
"WSED"=C:\Program Files\WSED\WSED.exe [2009-05-27 247080]
"Dell Webcam Central"=C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe [2008-11-11 442536]
"TrueImageMonitor.exe"=C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe [2006-10-16 1164912]
"AcronisTimounterMonitor"=C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe [2006-10-16 1941784]
"Acronis Scheduler2 Service"=C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe [2006-10-16 87584]
"SBAMTray"=C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe [2010-01-04 959824]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-11-10 417792]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2009-11-12 141600]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2009-03-18 131072]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2009-03-18 348160]
"PersistenceThread"=C:\WINDOWS\system32\PersistenceThread.exe [2010-01-24 86016]
"MMReminderService"=C:\Program Files\Mindjet\MindManager 8\MMReminderService.exe [2008-11-14 37656]
"Acrobat Assistant 7.0"=C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe [2008-04-23 483328]
"BTMeter"=C:\Program Files\Battery Meter\BTMeter.exe [2008-11-04 623912]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Documents and Settings\Robert Jericho\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-02-10 135664]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe

C:\Documents and Settings\Robert Jericho\Start Menu\Programs\Startup
Dell Dock.lnk - C:\Program Files\Dell\DellDock\DellDock.exe
osd_vol.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [2009-09-03 548352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\GoToAssist]
C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll [2010-02-20 10536]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igdlogin]
C:\WINDOWS\system32\igdlogin.dll [2009-03-18 65536]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 239496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
relog_ap

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\GoToAssist]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SBAMSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\BitLord\BitLord.exe"="C:\Program Files\BitLord\BitLord.exe:*:Enabled:BitLord"
"C:\Documents and Settings\Robert Jericho\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.dll"="C:\Documents and Settings\Robert Jericho\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.dll:*:Enabled:Google Talk Plugin"
"C:\Documents and Settings\Robert Jericho\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe"="C:\Documents and Settings\Robert Jericho\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin"
"C:\Program Files\Opera 10.50 Beta\opera.exe"="C:\Program Files\Opera 10.50 Beta\opera.exe:*:Enabled:Opera Internet Browser"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2010-02-20 13:45:33 ----D---- C:\Documents and Settings\All Users\Application Data\Citrix
2010-02-20 13:22:45 ----D---- C:\Program Files\Elantech
2010-02-20 12:58:48 ----D---- C:\Program Files\Battery Meter
2010-02-20 11:06:54 ----D---- C:\rsit
2010-02-16 20:32:03 ----D---- C:\Documents and Settings\Robert Jericho\Application Data\Opera
2010-02-16 20:31:29 ----D---- C:\Program Files\Opera 10.50 Beta
2010-02-15 18:01:12 ----D---- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2010-02-15 18:01:07 ----D---- C:\Documents and Settings\Robert Jericho\Application Data\Office Genuine Advantage
2010-02-15 14:53:15 ----D---- C:\Program Files\Trend Micro
2010-02-15 13:56:20 ----D---- C:\Program Files\Mozilla Firefox
2010-02-15 13:22:11 ----D---- C:\Program Files\Enigma Software Group
2010-02-15 13:16:44 ----D---- C:\Documents and Settings\All Users\Application Data\XoftSpySE
2010-02-13 09:59:27 ----D---- C:\Documents and Settings\Robert Jericho\Application Data\Canneverbe Limited
2010-02-13 09:59:25 ----D---- C:\Documents and Settings\All Users\Application Data\Canneverbe Limited
2010-02-13 09:58:17 ----D---- C:\Program Files\CDBurnerXP
2010-02-13 08:57:04 ----D---- C:\Program Files\Alwil Software
2010-02-13 08:57:04 ----D---- C:\Documents and Settings\All Users\Application Data\Alwil Software
2010-02-12 22:07:26 ----SHD---- C:\RECYCLER
2010-02-12 17:49:38 ----D---- C:\Documents and Settings\All Users\Application Data\Sun
2010-02-12 17:48:09 ----D---- C:\Program Files\Sun
2010-02-12 17:47:53 ----A---- C:\WINDOWS\system32\javaws.exe
2010-02-12 17:47:53 ----A---- C:\WINDOWS\system32\javaw.exe
2010-02-12 17:47:53 ----A---- C:\WINDOWS\system32\java.exe
2010-02-12 17:38:24 ----D---- C:\WINDOWS\temp
2010-02-12 17:38:21 ----A---- C:\ComboFix.txt
2010-02-12 17:24:39 ----A---- C:\Boot.bak
2010-02-12 17:24:33 ----RASHD---- C:\cmdcons
2010-02-12 17:22:21 ----A---- C:\WINDOWS\zip.exe
2010-02-12 17:22:21 ----A---- C:\WINDOWS\SWXCACLS.exe
2010-02-12 17:22:21 ----A---- C:\WINDOWS\SWSC.exe
2010-02-12 17:22:21 ----A---- C:\WINDOWS\SWREG.exe
2010-02-12 17:22:21 ----A---- C:\WINDOWS\sed.exe
2010-02-12 17:22:21 ----A---- C:\WINDOWS\PEV.exe
2010-02-12 17:22:21 ----A---- C:\WINDOWS\NIRCMD.exe
2010-02-12 17:22:21 ----A---- C:\WINDOWS\MBR.exe
2010-02-12 17:22:21 ----A---- C:\WINDOWS\grep.exe
2010-02-12 17:11:23 ----D---- C:\WINDOWS\ERDNT
2010-02-12 17:10:33 ----D---- C:\Qoobox
2010-02-12 17:00:47 ----D---- C:\WINDOWS\system32\appmgmt
2010-02-12 11:38:01 ----D---- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2010-02-12 11:37:37 ----D---- C:\Program Files\SUPERAntiSpyware
2010-02-12 11:37:37 ----D---- C:\Documents and Settings\Robert Jericho\Application Data\SUPERAntiSpyware.com
2010-02-12 11:37:13 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2010-02-12 08:31:11 ----D---- C:\Documents and Settings\Robert Jericho\Application Data\Malwarebytes
2010-02-12 08:31:01 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2010-02-12 08:31:00 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-02-12 06:58:52 ----A---- C:\SfeErrors.txt
2010-02-10 18:33:38 ----D---- C:\WINDOWS\Sun
2010-02-10 03:09:24 ----HDC---- C:\WINDOWS\$NtUninstallKB978262$
2010-02-10 03:08:20 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2010-02-10 03:04:59 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2010-02-10 03:04:49 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2010-02-10 03:04:38 ----HDC---- C:\WINDOWS\$NtUninstallKB978251$
2010-02-10 03:04:27 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2010-02-10 03:04:05 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2010-02-10 03:02:16 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2010-02-10 03:01:44 ----HDC---- C:\WINDOWS\$NtUninstallKB977165$
2010-02-08 21:19:02 ----D---- C:\WINDOWS\system32\zh-TW
2010-02-08 21:19:02 ----D---- C:\WINDOWS\system32\zh-HK
2010-02-08 21:19:02 ----D---- C:\WINDOWS\system32\tr-TR
2010-02-08 21:19:02 ----D---- C:\WINDOWS\system32\sv-SE
2010-02-08 21:19:02 ----D---- C:\WINDOWS\system32\pt-BR
2010-02-08 21:19:02 ----D---- C:\WINDOWS\system32\nl-NL
2010-02-08 21:19:02 ----D---- C:\WINDOWS\system32\nb-NO
2010-02-08 21:19:02 ----D---- C:\WINDOWS\system32\ko-KR
2010-02-08 21:19:02 ----D---- C:\WINDOWS\system32\it-IT
2010-02-08 21:19:02 ----D---- C:\WINDOWS\system32\he-IL
2010-02-08 21:19:02 ----D---- C:\WINDOWS\system32\fr-FR
2010-02-08 21:19:02 ----D---- C:\WINDOWS\system32\fi-FI
2010-02-08 21:19:01 ----D---- C:\WINDOWS\system32\es-ES
2010-02-08 21:19:01 ----D---- C:\WINDOWS\system32\el-GR
2010-02-08 21:19:01 ----D---- C:\WINDOWS\system32\de-DE
2010-02-08 21:19:01 ----D---- C:\WINDOWS\system32\da-DK
2010-02-08 21:19:01 ----D---- C:\WINDOWS\system32\ar-SA
2010-02-05 00:41:18 ----A---- C:\WINDOWS\system32\muweb.dll
2010-02-05 00:41:18 ----A---- C:\WINDOWS\system32\mucltui.dll.mui
2010-02-05 00:41:18 ----A---- C:\WINDOWS\system32\mucltui.dll
2010-02-04 23:24:57 ----D---- C:\Documents and Settings\Robert Jericho\Application Data\AdobeUM
2010-02-04 20:40:00 ----D---- C:\Program Files\Microsoft Silverlight
2010-02-01 03:01:25 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2010-02-01 03:01:12 ----HDC---- C:\WINDOWS\$NtUninstallKB956744$
2010-02-01 03:00:30 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9$
2010-01-31 20:13:48 ----D---- C:\WINDOWS\Prefetch
2010-01-31 20:10:55 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2010-01-31 20:10:42 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2010-01-31 20:10:28 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2010-01-31 20:10:15 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2010-01-31 20:10:00 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2010-01-31 20:09:47 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2010-01-31 20:09:31 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2010-01-31 20:09:18 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
2010-01-31 20:09:05 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$
2010-01-31 20:08:49 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
2010-01-31 20:08:36 ----HDC---- C:\WINDOWS\$NtUninstallKB973354$
2010-01-31 20:08:23 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
2010-01-31 20:08:07 ----HDC---- C:\WINDOWS\$NtUninstallKB971737$
2010-01-31 20:07:54 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2010-01-31 20:07:41 ----HDC---- C:\WINDOWS\$NtUninstallKB971633$
2010-01-31 20:07:28 ----HDC---- C:\WINDOWS\$NtUninstallKB971557$
2010-01-31 20:07:12 ----HDC---- C:\WINDOWS\$NtUninstallKB971486$
2010-01-31 20:06:56 ----HDC---- C:\WINDOWS\$NtUninstallKB970430$
2010-01-31 20:06:43 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
2010-01-31 20:06:28 ----HDC---- C:\WINDOWS\$NtUninstallKB969947$
2010-01-31 20:06:14 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2010-01-31 20:05:57 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2010-01-31 20:05:40 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2010-01-31 20:05:25 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2010-01-31 20:04:55 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
2010-01-31 20:04:41 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2010-01-31 20:04:26 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2010-01-31 20:04:12 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2010-01-31 20:03:57 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2010-01-31 20:03:43 ----HDC---- C:\WINDOWS\$NtUninstallKB958687$
2010-01-31 20:03:28 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2010-01-31 20:03:14 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
2010-01-31 20:03:00 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2010-01-31 20:02:46 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2010-01-31 20:02:32 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2010-01-31 20:02:10 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2010-01-31 20:01:53 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2010-01-31 20:01:37 ----HDC---- C:\WINDOWS\$NtUninstallKB973687_1$
2010-01-31 20:01:24 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2010-01-31 20:01:09 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2010-01-31 20:00:55 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2010-01-31 20:00:39 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2010-01-31 20:00:23 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2010-01-31 20:00:09 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2010-01-31 19:59:54 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2010-01-31 19:59:41 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2010-01-31 19:59:27 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2010-01-31 19:59:13 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2010-01-31 19:58:57 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2010-01-31 19:52:21 ----D---- C:\WINDOWS\system32\scripting
2010-01-31 19:52:20 ----D---- C:\WINDOWS\l2schemas
2010-01-31 19:52:18 ----D---- C:\WINDOWS\system32\en
2010-01-31 19:52:18 ----D---- C:\WINDOWS\system32\bits
2010-01-31 19:36:52 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2010-01-25 18:55:41 ----D---- C:\Documents and Settings\Robert Jericho\Application Data\vlc
2010-01-25 18:53:25 ----D---- C:\Program Files\VideoLAN
2010-01-25 18:34:16 ----D---- C:\Documents and Settings\Robert Jericho\Application Data\WinRAR
2010-01-25 16:32:51 ----HDC---- C:\WINDOWS\$NtUninstallKB961118_0$
2010-01-25 16:31:30 ----HDC---- C:\WINDOWS\$NtUninstallKB925720$
2010-01-25 16:30:21 ----D---- C:\Program Files\MSXML 4.0
2010-01-25 03:09:27 ----D---- C:\WINDOWS\system32\XPSViewer
2010-01-25 03:09:22 ----D---- C:\Program Files\MSBuild
2010-01-25 03:09:11 ----D---- C:\Program Files\Reference Assemblies
2010-01-25 03:08:26 ----N---- C:\WINDOWS\system32\xpssvcs.dll
2010-01-25 03:08:26 ----N---- C:\WINDOWS\system32\xpsshhdr.dll
2010-01-25 03:08:26 ----N---- C:\WINDOWS\system32\prntvpt.dll
2010-01-25 03:08:25 ----D---- C:\a3eb26cc20e43dea7a4c6a64
2010-01-25 03:02:20 ----HDC---- C:\WINDOWS\$NtUninstallWIC$
2010-01-24 20:10:18 ----HD---- C:\WINDOWS\system32\GroupPolicy
2010-01-24 17:59:43 ----D---- C:\Program Files\ShopSafe
2010-01-24 17:56:28 ----D---- C:\Documents and Settings\Robert Jericho\Application Data\Macromedia
2010-01-24 17:39:58 ----D---- C:\Program Files\Citrix
2010-01-24 17:29:22 ----D---- C:\Program Files\WinRAR
2010-01-24 17:18:52 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe Systems
2010-01-24 17:18:46 ----D---- C:\Documents and Settings\Robert Jericho\Application Data\Adobe
2010-01-24 17:18:39 ----D---- C:\Program Files\Common Files\Adobe Systems Shared
2010-01-24 17:17:02 ----D---- C:\Program Files\Common Files\Adobe
2010-01-24 17:13:25 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2010-01-24 17:12:27 ----D---- C:\Program Files\Adobe
2010-01-24 17:07:59 ----A---- C:\WINDOWS\system32\pxc25pm.dll
2010-01-24 17:07:57 ----A---- C:\WINDOWS\system32\unicows.dll
2010-01-24 17:05:51 ----D---- C:\Documents and Settings\All Users\Application Data\Mindjet
2010-01-24 17:05:36 ----D---- C:\Program Files\Mindjet
2010-01-24 17:04:35 ----D---- C:\Program Files\MSXML 6.0
2010-01-24 15:00:18 ----A---- C:\WINDOWS\system32\igdlogin.dll
2010-01-24 14:51:43 ----A---- C:\WINDOWS\iun6002.exe
2010-01-24 14:51:35 ----D---- C:\Program Files\Codec Pack - All In 1
2010-01-24 14:50:47 ----A---- C:\WINDOWS\Codec Pack - All In 1 Setup Log.txt
2010-01-24 14:34:05 ----D---- C:\Documents and Settings\Robert Jericho\Application Data\Media Player Classic
2010-01-24 14:31:16 ----A---- C:\WINDOWS\system32\rmoc3260.dll
2010-01-24 14:31:16 ----A---- C:\WINDOWS\system32\pndx5032.dll
2010-01-24 14:31:16 ----A---- C:\WINDOWS\system32\pndx5016.dll
2010-01-24 14:31:15 ----A---- C:\WINDOWS\system32\pncrt.dll
2010-01-24 14:31:13 ----D---- C:\Program Files\Real Alternative
2010-01-24 14:31:13 ----D---- C:\Documents and Settings\Robert Jericho\Application Data\Real
2010-01-24 14:31:13 ----D---- C:\Documents and Settings\All Users\Application Data\Real
2010-01-24 14:31:01 ----D---- C:\Program Files\QuickTime Alternative
2010-01-24 14:30:31 ----D---- C:\Program Files\All in 1 Media Codecs Pack
2010-01-24 14:23:35 ----D---- C:\WINDOWS\Minidump
2010-01-24 13:30:51 ----D---- C:\Program Files\Duplicate Music Files Finder
2010-01-24 13:16:51 ----D---- C:\Documents and Settings\All Users\Application Data\Vistanita
2010-01-24 12:10:53 ----D---- C:\Documents and Settings\All Users\Application Data\Google
2010-01-24 12:01:13 ----D---- C:\Documents and Settings\Robert Jericho\Application Data\Apple Computer
2010-01-24 12:00:46 ----A---- C:\WINDOWS\system32\GEARAspi.dll
2010-01-24 11:59:50 ----D---- C:\Program Files\iPod
2010-01-24 11:59:45 ----D---- C:\Program Files\iTunes
2010-01-24 11:59:45 ----D---- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2010-01-24 11:59:34 ----A---- C:\WINDOWS\system32\hidserv.dll
2010-01-24 11:59:01 ----D---- C:\Program Files\Bonjour
2010-01-24 11:57:45 ----D---- C:\Program Files\QuickTime
2010-01-24 11:57:43 ----D---- C:\Documents and Settings\All Users\Application Data\Apple Computer
2010-01-24 11:57:00 ----D---- C:\Program Files\Apple Software Update
2010-01-24 11:55:23 ----D---- C:\Program Files\Common Files\Apple
2010-01-24 11:55:23 ----D---- C:\Documents and Settings\All Users\Application Data\Apple
2010-01-24 11:23:07 ----D---- C:\WINDOWS\ie7updates
2010-01-24 11:22:19 ----D---- C:\WINDOWS\WBEM
2010-01-24 11:22:17 ----D---- C:\WINDOWS\system32\en-US
2010-01-24 11:20:49 ----HDC---- C:\WINDOWS\ie7
2010-01-24 11:20:31 ----HDC---- C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$
2010-01-24 11:20:03 ----HDC---- C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$
2010-01-24 11:19:16 ----HDC---- C:\WINDOWS\$NtUninstallKB915865$
2010-01-24 11:19:09 ----N---- C:\WINDOWS\system32\xmllite.dll
2010-01-24 11:16:51 ----D---- C:\WINDOWS\network diagnostic
2010-01-24 11:16:50 ----HDC---- C:\WINDOWS\$NtUninstallKB914440$
2010-01-24 10:25:09 ----A---- C:\WINDOWS\ODBC.INI
2010-01-24 10:25:02 ----A---- C:\WINDOWS\system32\mdimon.dll
2010-01-24 10:23:29 ----D---- C:\Program Files\Common Files\L&H
2010-01-24 10:23:16 ----D---- C:\Program Files\Microsoft ActiveSync
2010-01-24 10:22:40 ----D---- C:\Program Files\Common Files\DESIGNER
2010-01-24 10:22:33 ----D---- C:\Program Files\Microsoft Works
2010-01-24 10:22:23 ----D---- C:\Program Files\Microsoft Visual Studio
2010-01-24 10:22:14 ----D---- C:\WINDOWS\SHELLNEW
2010-01-24 10:22:12 ----D---- C:\Program Files\Microsoft.NET
2010-01-24 10:22:11 ----D---- C:\Program Files\Microsoft Office
2010-01-24 10:16:02 ----RD---- C:\MSOCache
2010-01-24 10:15:13 ----HDC---- C:\WINDOWS\$NtUninstallKB959426_0$
2010-01-24 10:14:59 ----HDC---- C:\WINDOWS\$NtUninstallKB970430_0$
2010-01-24 10:13:47 ----HDC---- C:\WINDOWS\$NtUninstallKB941569$
2010-01-24 10:11:14 ----A---- C:\WINDOWS\system32\MRT.exe
2010-01-24 10:11:04 ----HDC---- C:\WINDOWS\$NtUninstallKB971737_0$
2010-01-24 10:10:47 ----HDC---- C:\WINDOWS\$NtUninstallKB971961$
2010-01-24 09:51:59 ----D---- C:\Documents and Settings\Robert Jericho\Application Data\Sunbelt
2010-01-24 09:50:37 ----D---- C:\Documents and Settings\All Users\Application Data\Sunbelt
2010-01-24 09:49:23 ----D---- C:\Program Files\Sunbelt Software
2010-01-24 09:44:11 ----D---- C:\Program Files\BitLord
2010-01-24 09:36:33 ----D---- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2010-01-24 09:33:17 ----A---- C:\WINDOWS\system32\AutoPartNt.exe
2010-01-24 03:09:55 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2_0$
2010-01-24 03:09:47 ----HDC---- C:\WINDOWS\$NtUninstallKB952954_0$
2010-01-24 03:09:38 ----HDC---- C:\WINDOWS\$NtUninstallKB946648_0$
2010-01-24 03:09:30 ----HDC---- C:\WINDOWS\$NtUninstallKB956803_0$
2010-01-24 03:09:21 ----HDC---- C:\WINDOWS\$NtUninstallKB960859_0$
2010-01-24 03:09:11 ----HDC---- C:\WINDOWS\$NtUninstallKB935448$
2010-01-24 03:08:49 ----HDC---- C:\WINDOWS\$NtUninstallKB978207$
2010-01-24 03:08:38 ----HDC---- C:\WINDOWS\$NtUninstallKB958869$
2010-01-24 03:08:30 ----HDC---- C:\WINDOWS\$NtUninstallKB954155_WM9$
2010-01-24 03:08:24 ----HDC---- C:\WINDOWS\$NtUninstallKB976098-v2$
2010-01-24 03:08:17 ----HDC---- C:\WINDOWS\$NtUninstallKB955759_0$
2010-01-24 03:07:53 ----HDC---- C:\WINDOWS\$NtUninstallKB974318_0$
2010-01-24 03:07:43 ----HDC---- C:\WINDOWS\$NtUninstallKB969059_0$
2010-01-24 03:07:34 ----HDC---- C:\WINDOWS\$NtUninstallKB950974_0$
2010-01-24 03:07:24 ----HDC---- C:\WINDOWS\$NtUninstallKB971657_0$
2010-01-24 03:07:16 ----HDC---- C:\WINDOWS\$NtUninstallKB971557_0$
2010-01-24 03:07:08 ----HDC---- C:\WINDOWS\$NtUninstallKB960225_0$
2010-01-24 03:06:59 ----HDC---- C:\WINDOWS\$NtUninstallKB972270_0$
2010-01-24 03:06:50 ----HDC---- C:\WINDOWS\$NtUninstallKB974112_0$
2010-01-24 03:06:31 ----HDC---- C:\WINDOWS\$NtUninstallKB956572_0$
2010-01-24 03:06:17 ----HDC---- C:\WINDOWS\$NtUninstallKB956844_0$
2010-01-24 03:06:09 ----HDC---- C:\WINDOWS\$NtUninstallKB961501_0$
2010-01-24 03:06:00 ----HDC---- C:\WINDOWS\$NtUninstallKB968816_WM9$
2010-01-24 03:05:54 ----HDC---- C:\WINDOWS\$NtUninstallKB971633_0$
2010-01-24 03:05:45 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$
2010-01-24 03:05:39 ----HDC---- C:\WINDOWS\$NtUninstallKB973869_0$
2010-01-24 03:05:31 ----HDC---- C:\WINDOWS\$NtUninstallKB975025_0$
2010-01-24 03:05:26 ----A---- C:\WINDOWS\system32\wmpns.dll
2010-01-24 03:05:19 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9L$
2010-01-24 03:05:10 ----HDC---- C:\WINDOWS\$NtUninstallKB952004_0$
2010-01-24 03:05:01 ----HDC---- C:\WINDOWS\$NtUninstallKB974571_0$
2010-01-24 03:04:52 ----HDC---- C:\WINDOWS\$NtUninstallKB973507_0$
2010-01-24 03:04:44 ----HDC---- C:\WINDOWS\$NtUninstallKB973687_0$
2010-01-24 03:04:36 ----HDC---- C:\WINDOWS\$NtUninstallKB950762_0$
2010-01-24 03:04:28 ----HDC---- C:\WINDOWS\$NtUninstallKB957097_0$
2010-01-24 03:04:20 ----HDC---- C:\WINDOWS\$NtUninstallKB958687_0$
2010-01-24 03:04:12 ----HDC---- C:\WINDOWS\$NtUninstallKB952287_0$
2010-01-24 03:04:03 ----HDC---- C:\WINDOWS\$NtUninstallKB973354_0$
2010-01-24 03:03:53 ----HDC---- C:\WINDOWS\$NtUninstallKB973904$
2010-01-24 03:03:41 ----HDC---- C:\WINDOWS\$NtUninstallKB967715_0$
2010-01-24 03:03:31 ----HDC---- C:\WINDOWS\$NtUninstallKB951066_0$
2010-01-24 03:03:23 ----HDC---- C:\WINDOWS\$NtUninstallKB974392_0$
2010-01-24 03:03:12 ----HDC---- C:\WINDOWS\$NtUninstallKB951748_0$
2010-01-24 03:03:02 ----HDC---- C:\WINDOWS\$NtUninstallKB970238_0$
2010-01-24 03:02:51 ----HDC---- C:\WINDOWS\$NtUninstallKB971486_0$
2010-01-24 03:02:39 ----D---- C:\WINDOWS\ServicePackFiles
2010-01-24 03:02:37 ----HDC---- C:\WINDOWS\$NtUninstallKB958470$
2010-01-24 03:02:28 ----HDC---- C:\WINDOWS\$NtUninstallKB960803_0$
2010-01-24 03:02:20 ----HDC---- C:\WINDOWS\$NtUninstallKB973815_0$
2010-01-24 03:02:12 ----HDC---- C:\WINDOWS\$NtUninstallKB973525$
2010-01-24 03:02:00 ----HDC---- C:\WINDOWS\$NtUninstallKB971032$
2010-01-24 03:01:49 ----HDC---- C:\WINDOWS\$NtUninstallKB958644_0$
2010-01-24 03:01:40 ----HDC---- C:\WINDOWS\$NtUninstallKB955069_0$
2010-01-24 03:01:31 ----HDC---- C:\WINDOWS\$NtUninstallKB956802_0$
2010-01-24 03:01:17 ----HDC---- C:\WINDOWS\$NtUninstallKB944338-v2$
2010-01-24 03:01:07 ----HDC---- C:\WINDOWS\$NtUninstallKB923561_0$
2010-01-24 03:00:58 ----HDC---- C:\WINDOWS\$NtUninstallKB975467_0$
2010-01-24 03:00:46 ----HDC---- C:\WINDOWS\$NtUninstallKB968389_0$
2010-01-24 03:00:33 ----HDC---- C:\WINDOWS\$NtUninstallKB969947_0$
2010-01-23 16:29:16 ----D---- C:\Documents and Settings\All Users\Application Data\Acronis
2010-01-23 16:24:45 ----D---- C:\Program Files\Common Files\Acronis
2010-01-23 16:24:45 ----D---- C:\Program Files\Acronis
2010-01-23 16:16:47 ----D---- C:\Documents and Settings\Robert Jericho\Application Data\Dell
2010-01-23 16:12:27 ----HDC---- C:\Documents and Settings\All Users\Application Data\{7322D736-AA5F-4DD0-8E33-EA48318CC276}
2010-01-23 16:02:51 ----D---- C:\Documents and Settings\Robert Jericho\Application Data\Mozilla
2010-01-23 16:00:16 ----D---- C:\WINDOWS\CtDrvInstall
2010-01-23 15:58:59 ----D---- C:\Program Files\Common Files\Reallusion
2010-01-23 15:58:32 ----D---- C:\Program Files\Creative
2010-01-23 15:58:09 ----D---- C:\WINDOWS\RegisteredPackages
2010-01-23 15:57:20 ----D---- C:\Program Files\Dell Webcam
2010-01-23 15:57:10 ----D---- C:\Program Files\Creative Live! Cam
2010-01-23 15:51:56 ----D---- C:\Documents and Settings\All Users\Application Data\Vista32
2010-01-23 15:51:55 ----D---- C:\Documents and Settings\All Users\Application Data\XP32
2010-01-23 15:51:55 ----D---- C:\Documents and Settings\All Users\Application Data\Win764
2010-01-23 15:51:55 ----D---- C:\Documents and Settings\All Users\Application Data\Win732
2010-01-23 15:51:55 ----D---- C:\Documents and Settings\All Users\Application Data\Vista64
2010-01-23 15:51:26 ----D---- C:\Program Files\WSED
2010-01-23 15:48:56 ----D---- C:\Program Files\CapsLKNotify
2010-01-23 15:45:25 ----A---- C:\WINDOWS\system32\OA012Srv.exe
2010-01-23 15:45:25 ----A---- C:\WINDOWS\system32\OA012Pin.dll
2010-01-23 15:45:25 ----A---- C:\WINDOWS\OA012Cfg.exe
2010-01-23 15:45:25 ----A---- C:\WINDOWS\CtDrvIns.exe
2010-01-23 15:33:58 ----D---- C:\Program Files\Function Keys
2010-01-23 15:32:57 ----A---- C:\WINDOWS\system32\deploytk.dll
2010-01-23 15:32:35 ----D---- C:\Program Files\Java
2010-01-23 15:32:12 ----D---- C:\Documents and Settings\Robert Jericho\Application Data\Sun
2010-01-23 15:28:05 ----D---- C:\Documents and Settings\All Users\Application Data\SupportSoft
2010-01-23 15:28:00 ----D---- C:\Documents and Settings\All Users\Application Data\PCDr
2010-01-23 15:28:00 ----D---- C:\Documents and Settings\All Users\Application Data\PC-Doctor
2010-01-23 15:27:20 ----D---- C:\Program Files\Dell Support Center
2010-01-23 15:27:19 ----D---- C:\Program Files\Common Files\supportsoft
2010-01-23 15:27:18 ----N---- C:\WINDOWS\system32\xpsp4res.dll
2010-01-23 15:27:18 ----A---- C:\WINDOWS\system32\xpsp3res.dll
2010-01-23 15:26:52 ----N---- C:\WINDOWS\system32\tzchange.exe
2010-01-23 15:14:37 ----HDC---- C:\WINDOWS\$MSI31Uninstall_KB893803v2$
2010-01-23 15:14:07 ----D---- C:\WINDOWS\system32\PreInstall
2010-01-23 15:14:05 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$
2010-01-23 15:14:05 ----HD---- C:\WINDOWS\$hf_mig$
2010-01-23 15:13:16 ----D---- C:\Documents and Settings\All Users\Application Data\Dell
2010-01-23 14:49:35 ----RSD---- C:\WINDOWS\assembly
2010-01-23 14:48:56 ----D---- C:\WINDOWS\Microsoft.NET
2010-01-23 14:44:54 ----N---- C:\WINDOWS\system32\spmsg.dll
2010-01-23 14:44:52 ----HDC---- C:\WINDOWS\$NtUninstallWdf01007$
2010-01-23 14:44:17 ----A---- C:\WINDOWS\system32\EMSC.DLL
2010-01-23 14:43:30 ----D---- C:\WINDOWS\Downloaded Installations
2010-01-23 14:41:58 ----A---- C:\WINDOWS\system32\btw_ci.dll
2010-01-23 14:41:51 ----D---- C:\Program Files\WIDCOMM
2010-01-23 14:24:10 ----D---- C:\WINDOWS\system32\RTCOM
2010-01-23 14:23:23 ----A---- C:\WINDOWS\system32\spupdsvc.exe
2010-01-23 14:23:21 ----HDC---- C:\WINDOWS\$NtUninstallKB888111WXPSP2$
2010-01-23 14:23:17 ----A---- C:\WINDOWS\vncutil.exe
2010-01-23 14:23:17 ----A---- C:\WINDOWS\SOUNDMAN.EXE
2010-01-23 14:23:17 ----A---- C:\WINDOWS\SkyTel.exe
2010-01-23 14:23:17 ----A---- C:\WINDOWS\RtlUpd.exe
2010-01-23 14:23:17 ----A---- C:\WINDOWS\RTLCPL.EXE
2010-01-23 14:23:16 ----A---- C:\WINDOWS\system32\RtkCoInstXP.dll
2010-01-23 14:23:16 ----A---- C:\WINDOWS\RtkAudioService.exe
2010-01-23 14:23:15 ----A---- C:\WINDOWS\RTHDCPL.EXE
2010-01-23 14:23:15 ----A---- C:\WINDOWS\MicCal.exe
2010-01-23 14:23:14 ----A---- C:\WINDOWS\ALCWZRD.EXE
2010-01-23 14:23:14 ----A---- C:\WINDOWS\ALCMTR.EXE
2010-01-23 14:23:06 ----A---- C:\WINDOWS\RtlExUpd.dll
2010-01-23 14:23:01 ----D---- C:\Program Files\Common Files\InstallShield
2010-01-23 14:21:26 ----A---- C:\WINDOWS\system32\RTS5121icon.dll
2010-01-23 14:21:26 ----A---- C:\WINDOWS\system32\rts5121.dll
2010-01-23 14:20:35 ----A---- C:\WINDOWS\system32\RtNicProp32.dll
2010-01-23 14:20:34 ----HD---- C:\Program Files\InstallShield Installation Information
2010-01-23 14:20:34 ----D---- C:\WINDOWS\OPTIONS
2010-01-23 14:20:34 ----D---- C:\Program Files\Realtek
2010-01-23 01:17:42 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2010-01-23 01:14:13 ----A---- C:\WINDOWS\system32\BCMLogon.dll
2010-01-23 01:14:13 ----A---- C:\WINDOWS\bcm63.tmp
2010-01-23 01:14:11 ----A---- C:\WINDOWS\system32\vcredist_x86.exe
2010-01-23 01:14:11 ----A---- C:\WINDOWS\system32\vcredist_x86.bat
2010-01-23 01:14:11 ----A---- C:\WINDOWS\system32\preflib.dll
2010-01-23 01:14:11 ----A---- C:\WINDOWS\system32\bcmwlu00.exe
2010-01-23 01:14:11 ----A---- C:\WINDOWS\bcm3B.tmp
2010-01-23 01:14:10 ----A---- C:\WINDOWS\system32\WLTRYSVC.EXE
2010-01-23 01:14:10 ----A---- C:\WINDOWS\system32\wltrynt.dll
2010-01-23 01:14:10 ----A---- C:\WINDOWS\system32\WLTRAY.EXE
2010-01-23 01:14:10 ----A---- C:\WINDOWS\system32\WLBCGCBPRO731.DLL
2010-01-23 01:14:10 ----A---- C:\WINDOWS\system32\BCMWLTRY.EXE
2010-01-23 01:14:10 ----A---- C:\WINDOWS\system32\bcmwlpkt.dll
2010-01-23 01:14:10 ----A---- C:\WINDOWS\system32\bcmwlapi.dll
2010-01-23 01:14:10 ----A---- C:\WINDOWS\system32\bcm1xsup.dll
2010-01-23 01:14:01 ----D---- C:\Documents and Settings\Robert Jericho\Application Data\InstallShield
2010-01-23 01:05:07 ----D---- C:\WINDOWS\system32\Lang
2010-01-23 01:05:07 ----A---- C:\WINDOWS\system32\lpgun.ini
2010-01-23 01:05:07 ----A---- C:\WINDOWS\system32\lpgun.exe
2010-01-23 01:05:07 ----A---- C:\WINDOWS\system32\difxapi.dll
2010-01-23 01:04:46 ----A---- C:\WINDOWS\system32\PersistenceThread.exe
2010-01-23 01:04:46 ----A---- C:\WINDOWS\system32\igxprd32.dll
2010-01-23 01:04:46 ----A---- C:\WINDOWS\system32\igfxtray.exe
2010-01-23 01:04:46 ----A---- C:\WINDOWS\system32\igfxres.dll
2010-01-23 01:04:46 ----A---- C:\WINDOWS\system32\igfxext.exe
2010-01-23 01:04:45 ----A---- C:\WINDOWS\system32\igxpdd32.dll
2010-01-23 01:04:45 ----A---- C:\WINDOWS\system32\igfxsrvc.exe
2010-01-23 01:04:45 ----A---- C:\WINDOWS\system32\igfxsrvc.dll
2010-01-23 01:04:45 ----A---- C:\WINDOWS\system32\igfxextps.dll
2010-01-23 01:04:45 ----A---- C:\WINDOWS\system32\igfxcfg.exe
2010-01-23 01:04:45 ----A---- C:\WINDOWS\system32\hkcmd.exe
2010-01-23 01:04:45 ----A---- C:\WINDOWS\system32\hccutils.dll
2010-01-23 01:04:44 ----A---- C:\WINDOWS\system32\igfxress.dll
2010-01-23 01:04:44 ----A---- C:\WINDOWS\system32\igfxpph.dll
2010-01-23 01:04:44 ----A---- C:\WINDOWS\system32\igfxdo.dll
2010-01-23 01:01:05 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-01-23 01:01:01 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-01-23 01:01:01 ----D---- C:\Program Files\Intel
2010-01-23 01:01:01 ----A---- C:\WINDOWS\system32\CSVer.dll
2010-01-23 01:00:33 ----D---- C:\Intel
2010-01-23 00:54:21 ----D---- C:\WINDOWS\system32\vmm32
2010-01-23 00:54:21 ----D---- C:\Program Files\Dell
2010-01-23 00:28:29 ----D---- C:\Documents and Settings\Robert Jericho\Application Data\Identities
2010-01-23 00:28:26 ----HD---- C:\Program Files\Uninstall Information
2010-01-23 00:28:18 ----SD---- C:\Documents and Settings\Robert Jericho\Application Data\Microsoft
2010-01-23 00:28:18 ----ASH---- C:\Documents and Settings\Robert Jericho\Application Data\desktop.ini
2010-01-23 00:26:13 ----D---- C:\WINDOWS\SoftwareDistribution
2010-01-23 00:26:11 ----SD---- C:\WINDOWS\system32\Microsoft
2010-01-23 00:26:11 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-01-23 00:19:10 ----D---- C:\WINDOWS\system32\xircom
2010-01-23 00:19:10 ----D---- C:\Program Files\xerox
2010-01-23 00:19:10 ----D---- C:\Program Files\microsoft frontpage
2010-01-23 00:18:34 ----D---- C:\DELL
2010-01-23 00:18:23 ----A---- C:\WINDOWS\control.ini
2010-01-23 00:18:23 ----A---- C:\AUTOEXEC.BAT
2010-01-23 00:18:09 ----A---- C:\WINDOWS\OEWABLog.txt
2010-01-23 00:18:04 ----A---- C:\WINDOWS\system32\mapi32.dll
2010-01-23 00:16:46 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-01-23 00:16:46 ----RD---- C:\WINDOWS\Offline Web Pages
2010-01-23 00:16:46 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest
2010-01-23 00:16:37 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest
2010-01-23 00:16:30 ----HD---- C:\Program Files\WindowsUpdate
2010-01-23 00:16:03 ----D---- C:\WINDOWS\system32\DirectX
2010-01-23 00:15:36 ----A---- C:\WINDOWS\system32\atrace.dll
2010-01-23 00:15:33 ----A---- C:\WINDOWS\system32\desktop.ini
2010-01-23 00:15:33 ----A---- C:\WINDOWS\desktop.ini
2010-01-23 00:15:24 ----A---- C:\WINDOWS\system32\nmevtmsg.dll
2010-01-23 00:15:22 ----A---- C:\WINDOWS\system32\acctres.dll
2010-01-23 00:15:21 ----D---- C:\Program Files\Common Files\Services
2010-01-23 00:15:18 ----SD---- C:\WINDOWS\Tasks
2010-01-23 00:15:18 ----A---- C:\WINDOWS\system32\icfgnt5.dll
2010-01-23 00:15:16 ----D---- C:\Program Files\Common Files\MSSoap
2010-01-23 00:15:12 ----D---- C:\WINDOWS\srchasst
2010-01-23 00:15:11 ----D---- C:\WINDOWS\system32\Macromed
2010-01-23 00:15:07 ----A---- C:\WINDOWS\system32\wuweb.dll
2010-01-23 00:15:07 ----A---- C:\WINDOWS\system32\wups.dll
2010-01-23 00:15:07 ----A---- C:\WINDOWS\system32\wucltui.dll
2010-01-23 00:15:07 ----A---- C:\WINDOWS\system32\wuauserv.dll
2010-01-23 00:15:07 ----A---- C:\WINDOWS\system32\wuaueng1.dll
2010-01-23 00:15:07 ----A---- C:\WINDOWS\system32\wuaueng.dll.wusetup.134890.bak
2010-01-23 00:15:07 ----A---- C:\WINDOWS\system32\wuaueng.dll
2010-01-23 00:15:07 ----A---- C:\WINDOWS\system32\wuaucpl.cpl.wusetup.134671.bak
2010-01-23 00:15:06 ----N---- C:\WINDOWS\system32\wuauclt.exe
2010-01-23 00:15:06 ----N---- C:\WINDOWS\system32\qmgr.dll
2010-01-23 00:15:06 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2010-01-23 00:15:06 ----A---- C:\WINDOWS\system32\wuauclt.exe.wusetup.134406.bak
2010-01-23 00:15:06 ----A---- C:\WINDOWS\system32\wuapi.dll
2010-01-23 00:15:06 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
2010-01-23 00:15:06 ----A---- C:\WINDOWS\system32\bitsprx3.dll
2010-01-23 00:15:06 ----A---- C:\WINDOWS\system32\bitsprx2.dll
2010-01-23 00:15:01 ----D---- C:\Program Files\Movie Maker
2010-01-23 00:14:56 ----A---- C:\WINDOWS\system32\safrslv.dll
2010-01-23 00:14:56 ----A---- C:\WINDOWS\system32\safrdm.dll
2010-01-23 00:14:56 ----A---- C:\WINDOWS\system32\safrcdlg.dll
2010-01-23 00:14:56 ----A---- C:\WINDOWS\system32\racpldlg.dll
2010-01-23 00:14:52 ----A---- C:\WINDOWS\system32\fltmc.exe
2010-01-23 00:14:52 ----A---- C:\WINDOWS\system32\fltlib.dll
2010-01-23 00:14:51 ----N---- C:\WINDOWS\system32\srsvc.dll
2010-01-23 00:14:51 ----D---- C:\WINDOWS\system32\Restore
2010-01-23 00:14:51 ----A---- C:\WINDOWS\system32\srrstr.dll
2010-01-23 00:14:51 ----A---- C:\WINDOWS\system32\srclient.dll
2010-01-23 00:14:50 ----A---- C:\WINDOWS\system32\nmmkcert.dll
2010-01-23 00:14:50 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2010-01-23 00:14:50 ----A---- C:\WINDOWS\system32\mnmdd.dll
2010-01-23 00:14:50 ----A---- C:\WINDOWS\system32\isrdbg32.dll
2010-01-23 00:14:50 ----A---- C:\WINDOWS\system32\ils.dll
2010-01-23 00:14:49 ----A---- C:\WINDOWS\system32\msconf.dll
2010-01-23 00:14:46 ----D---- C:\Program Files\NetMeeting
2010-01-23 00:14:46 ----A---- C:\WINDOWS\system32\msoert2.dll
2010-01-23 00:14:46 ----A---- C:\WINDOWS\system32\msoeacct.dll
2010-01-23 00:14:45 ----A---- C:\WINDOWS\system32\inetres.dll
2010-01-23 00:14:45 ----A---- C:\WINDOWS\system32\inetcomm.dll
2010-01-23 00:14:43 ----N---- C:\WINDOWS\system32\schedsvc.dll
2010-01-23 00:14:43 ----D---- C:\Program Files\Outlook Express
2010-01-23 00:14:42 ----A---- C:\WINDOWS\system32\mstinit.exe
2010-01-23 00:14:42 ----A---- C:\WINDOWS\system32\mstask.dll
2010-01-23 00:14:42 ----A---- C:\WINDOWS\system32\icwphbk.dll
2010-01-23 00:14:42 ----A---- C:\WINDOWS\system32\icwdial.dll
2010-01-23 00:14:41 ----A---- C:\WINDOWS\system32\isign32.dll
2010-01-23 00:14:41 ----A---- C:\WINDOWS\system32\inetcfg.dll
2010-01-23 00:14:34 ----D---- C:\Program Files\Common Files\System
2010-01-23 00:14:28 ----D---- C:\Program Files\Internet Explorer
2010-01-23 00:13:41 ----D---- C:\Program Files\ComPlus Applications
2010-01-23 00:13:39 ----A---- C:\WINDOWS\vbaddin.ini
2010-01-23 00:13:39 ----A---- C:\WINDOWS\vb.ini
2010-01-23 00:13:34 ----D---- C:\WINDOWS\Registration
2010-01-23 00:13:26 ----D---- C:\Program Files\Windows Media Player
2010-01-23 00:13:26 ----D---- C:\Program Files\Online Services
2010-01-23 00:13:19 ----D---- C:\Program Files\Messenger
2010-01-23 00:13:14 ----D---- C:\Program Files\MSN Gaming Zone
2010-01-23 00:13:14 ----A---- C:\WINDOWS\system32\write.exe
2010-01-23 00:13:01 ----A---- C:\WINDOWS\system32\sndvol32.exe
2010-01-23 00:13:01 ----A---- C:\WINDOWS\system32\hticons.dll
2010-01-23 00:13:00 ----A---- C:\WINDOWS\system32\winchat.exe
2010-01-23 00:13:00 ----A---- C:\WINDOWS\system32\avwav.dll
2010-01-23 00:13:00 ----A---- C:\WINDOWS\system32\avtapi.dll
2010-01-23 00:13:00 ----A---- C:\WINDOWS\system32\avmeter.dll
2010-01-23 00:12:50 ----A---- C:\WINDOWS\system32\getuname.dll
2010-01-23 00:12:50 ----A---- C:\WINDOWS\system32\charmap.exe
2010-01-23 00:12:49 ----A---- C:\WINDOWS\system32\winmine.exe
2010-01-23 00:12:49 ----A---- C:\WINDOWS\system32\sol.exe
2010-01-23 00:12:49 ----A---- C:\WINDOWS\system32\calc.exe
2010-01-23 00:12:48 ----A---- C:\WINDOWS\system32\usrlogon.cmd
2010-01-23 00:12:48 ----A---- C:\WINDOWS\system32\reset.exe
2010-01-23 00:12:48 ----A---- C:\WINDOWS\system32\mshearts.exe
2010-01-23 00:12:48 ----A---- C:\WINDOWS\system32\freecell.exe
2010-01-23 00:12:47 ----A---- C:\WINDOWS\system32\tsshutdn.exe
2010-01-23 00:12:47 ----A---- C:\WINDOWS\system32\tslabels.ini
2010-01-23 00:12:47 ----A---- C:\WINDOWS\system32\tskill.exe
2010-01-23 00:12:47 ----A---- C:\WINDOWS\system32\tsdiscon.exe
2010-01-23 00:12:47 ----A---- C:\WINDOWS\system32\tscon.exe
2010-01-23 00:12:47 ----A---- C:\WINDOWS\system32\shadow.exe
2010-01-23 00:12:47 ----A---- C:\WINDOWS\system32\rwinsta.exe
2010-01-23 00:12:47 ----A---- C:\WINDOWS\system32\regini.exe
2010-01-23 00:12:47 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
2010-01-23 00:12:47 ----A---- C:\WINDOWS\system32\qwinsta.exe
2010-01-23 00:12:46 ----A---- C:\WINDOWS\system32\qappsrv.exe
2010-01-23 00:12:46 ----A---- C:\WINDOWS\system32\msg.exe
2010-01-23 00:12:46 ----A---- C:\WINDOWS\system32\msdtcprf.ini
2010-01-23 00:12:46 ----A---- C:\WINDOWS\system32\logoff.exe
2010-01-23 00:12:46 ----A---- C:\WINDOWS\system32\cdmodem.dll
2010-01-23 00:12:45 ----A---- C:\WINDOWS\system32\mtxlegih.dll
2010-01-23 00:12:45 ----A---- C:\WINDOWS\system32\mtxex.dll
2010-01-23 00:12:45 ----A---- C:\WINDOWS\system32\mtxdm.dll
2010-01-23 00:12:45 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2010-01-23 00:12:44 ----A---- C:\WINDOWS\system32\stclient.dll
2010-01-23 00:12:44 ----A---- C:\WINDOWS\system32\comsnap.dll
2010-01-23 00:12:44 ----A---- C:\WINDOWS\system32\comrepl.dll
2010-01-23 00:12:44 ----A---- C:\WINDOWS\system32\comaddin.dll
2010-01-23 00:12:37 ----A---- C:\WINDOWS\system32\wmimgmt.msc
2010-01-23 00:12:26 ----D---- C:\Program Files\MSN
2010-01-23 00:12:25 ----A---- C:\WINDOWS\system32\sndrec32.exe
2010-01-23 00:12:25 ----A---- C:\WINDOWS\system32\accwiz.exe
2010-01-23 00:12:24 ----D---- C:\Program Files\Windows NT
2010-01-23 00:12:24 ----A---- C:\WINDOWS\system32\mplay32.exe
2010-01-23 00:12:24 ----A---- C:\WINDOWS\system32\hypertrm.dll
2010-01-23 00:12:23 ----A---- C:\WINDOWS\system32\spider.exe
2010-01-23 00:12:23 ----A---- C:\WINDOWS\system32\mspaint.exe
2010-01-23 00:12:23 ----A---- C:\WINDOWS\system32\clipbrd.exe
2010-01-23 00:12:22 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
2010-01-23 00:12:22 ----A---- C:\WINDOWS\system32\mstscax.dll
2010-01-23 00:12:22 ----A---- C:\WINDOWS\system32\mstsc.exe
2010-01-23 00:12:21 ----A---- C:\WINDOWS\system32\tscupgrd.exe
2010-01-23 00:12:21 ----A---- C:\WINDOWS\system32\sessmgr.exe
2010-01-23 00:12:21 ----A---- C:\WINDOWS\system32\remotepg.dll
2010-01-23 00:12:21 ----A---- C:\WINDOWS\system32\rdshost.exe
2010-01-23 00:12:21 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2010-01-23 00:12:21 ----A---- C:\WINDOWS\system32\rdchost.dll
2010-01-23 00:12:20 ----N---- C:\WINDOWS\system32\termsrv.dll
2010-01-23 00:12:20 ----A---- C:\WINDOWS\system32\rdpwsx.dll
2010-01-23 00:12:20 ----A---- C:\WINDOWS\system32\rdpsnd.dll
2010-01-23 00:12:20 ----A---- C:\WINDOWS\system32\rdpclip.exe
2010-01-23 00:12:20 ----A---- C:\WINDOWS\system32\qprocess.exe
2010-01-23 00:12:20 ----A---- C:\WINDOWS\system32\icaapi.dll
2010-01-23 00:12:20 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2010-01-23 00:12:19 ----D---- C:\WINDOWS\system32\MsDtc
2010-01-23 00:12:19 ----A---- C:\WINDOWS\system32\mtxoci.dll
2010-01-23 00:12:19 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
2010-01-23 00:12:19 ----A---- C:\WINDOWS\system32\msdtctm.dll
2010-01-23 00:12:19 ----A---- C:\WINDOWS\system32\msdtcprx.dll
2010-01-23 00:12:18 ----A---- C:\WINDOWS\system32\xolehlp.dll
2010-01-23 00:12:18 ----A---- C:\WINDOWS\system32\msdtclog.dll
2010-01-23 00:12:18 ----A---- C:\WINDOWS\system32\msdtc.exe
2010-01-23 00:12:17 ----D---- C:\WINDOWS\system32\Com
2010-01-23 00:12:17 ----A---- C:\WINDOWS\system32\colbact.dll
2010-01-23 00:12:17 ----A---- C:\WINDOWS\system32\clbcatex.dll
2010-01-23 00:12:17 ----A---- C:\WINDOWS\system32\catsrvut.dll
2010-01-23 00:12:17 ----A---- C:\WINDOWS\system32\catsrvps.dll
2010-01-23 00:12:17 ----A---- C:\WINDOWS\system32\catsrv.dll
2010-01-23 00:12:16 ----A---- C:\WINDOWS\system32\comuid.dll
2010-01-23 00:12:16 ----A---- C:\WINDOWS\system32\comsvcs.dll
2010-01-23 00:12:16 ----A---- C:\WINDOWS\system32\clbcatq.dll
2010-01-23 00:12:08 ----A---- C:\WINDOWS\system32\servdeps.dll
2010-01-23 00:12:08 ----A---- C:\WINDOWS\system32\mmfutil.dll
2010-01-23 00:12:08 ----A---- C:\WINDOWS\system32\licwmi.dll
2010-01-23 00:12:08 ----A---- C:\WINDOWS\system32\cmprops.dll
2010-01-22 18:10:47 ----A---- C:\WINDOWS\system32\h323log.txt
2010-01-22 18:08:43 ----A---- C:\WINDOWS\system32\vfwwdm32.dll
2010-01-22 18:08:43 ----A---- C:\WINDOWS\system32\ksuser.dll
2010-01-22 18:07:41 ----A---- C:\WINDOWS\system32\usbui.dll
2010-01-22 18:06:09 ----A---- C:\WINDOWS\imsins.BAK
2010-01-22 18:06:05 ----SHD---- C:\WINDOWS\Installer
2010-01-22 18:06:05 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-01-22 18:06:04 ----D---- C:\Program Files\Common Files\ODBC
2010-01-22 18:06:04 ----A---- C:\WINDOWS\ODBCINST.INI
2010-01-22 18:06:00 ----RD---- C:\Program Files
2010-01-22 18:06:00 ----D---- C:\Program Files\Common Files\SpeechEngines
2010-01-22 18:06:00 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-01-22 18:06:00 ----D---- C:\Program Files\Common Files
2010-01-22 18:05:56 ----RA---- C:\WINDOWS\system32\kbdazel.dll
2010-01-22 18:05:55 ----RA---- C:\WINDOWS\system32\kbdtuq.dll
2010-01-22 18:05:55 ----RA---- C:\WINDOWS\system32\kbdtuf.dll
2010-01-22 18:05:53 ----RA---- C:\WINDOWS\system32\kbdycc.dll
2010-01-22 18:05:53 ----RA---- C:\WINDOWS\system32\kbduzb.dll
2010-01-22 18:05:53 ----RA---- C:\WINDOWS\system32\kbdur.dll
2010-01-22 18:05:53 ----RA---- C:\WINDOWS\system32\kbdtat.dll
2010-01-22 18:05:53 ----RA---- C:\WINDOWS\system32\kbdmon.dll
2010-01-22 18:05:53 ----RA---- C:\WINDOWS\system32\kbdkyr.dll
2010-01-22 18:05:53 ----RA---- C:\WINDOWS\system32\kbdkaz.dll
2010-01-22 18:05:53 ----RA---- C:\WINDOWS\system32\kbdaze.dll
2010-01-22 18:05:52 ----RA---- C:\WINDOWS\system32\kbdru1.dll
2010-01-22 18:05:52 ----RA---- C:\WINDOWS\system32\kbdru.dll
2010-01-22 18:05:52 ----RA---- C:\WINDOWS\system32\kbdbu.dll
2010-01-22 18:05:52 ----RA---- C:\WINDOWS\system32\kbdblr.dll
2010-01-22 18:05:50 ----RA---- C:\WINDOWS\system32\kbdhept.dll
2010-01-22 18:05:50 ----RA---- C:\WINDOWS\system32\kbdhela3.dll
2010-01-22 18:05:50 ----RA---- C:\WINDOWS\system32\kbdhela2.dll
2010-01-22 18:05:50 ----RA---- C:\WINDOWS\system32\kbdhe319.dll
2010-01-22 18:05:50 ----RA---- C:\WINDOWS\system32\kbdhe220.dll
2010-01-22 18:05:50 ----RA---- C:\WINDOWS\system32\kbdhe.dll
2010-01-22 18:05:50 ----RA---- C:\WINDOWS\system32\kbdgkl.dll
2010-01-22 18:05:48 ----RA---- C:\WINDOWS\system32\kbdlv1.dll
2010-01-22 18:05:48 ----RA---- C:\WINDOWS\system32\kbdlt1.dll
2010-01-22 18:05:48 ----RA---- C:\WINDOWS\system32\kbdlt.dll
2010-01-22 18:05:47 ----RA---- C:\WINDOWS\system32\kbdlv.dll
2010-01-22 18:05:47 ----RA---- C:\WINDOWS\system32\kbdest.dll
2010-01-22 18:05:42 ----RA---- C:\WINDOWS\system32\kbdycl.dll
2010-01-22 18:05:42 ----RA---- C:\WINDOWS\system32\kbdsl1.dll
2010-01-22 18:05:42 ----RA---- C:\WINDOWS\system32\kbdsl.dll
2010-01-22 18:05:42 ----RA---- C:\WINDOWS\system32\kbdro.dll
2010-01-22 18:05:42 ----RA---- C:\WINDOWS\system32\kbdpl1.dll
2010-01-22 18:05:42 ----RA---- C:\WINDOWS\system32\kbdpl.dll
2010-01-22 18:05:42 ----RA---- C:\WINDOWS\system32\kbdhu1.dll
2010-01-22 18:05:42 ----RA---- C:\WINDOWS\system32\kbdhu.dll
2010-01-22 18:05:42 ----RA---- C:\WINDOWS\system32\kbdcz2.dll
2010-01-22 18:05:42 ----RA---- C:\WINDOWS\system32\kbdcz1.dll
2010-01-22 18:05:42 ----RA---- C:\WINDOWS\system32\kbdcz.dll
2010-01-22 18:05:42 ----RA---- C:\WINDOWS\system32\kbdcr.dll
2010-01-22 18:05:42 ----RA---- C:\WINDOWS\system32\KBDAL.DLL
2010-01-22 18:05:38 ----A---- C:\WINDOWS\system32\irclass.dll
2010-01-22 18:05:38 ----A---- C:\WINDOWS\system32\dgsetup.dll
2010-01-22 18:05:38 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
2010-01-22 18:05:37 ----A---- C:\WINDOWS\system32\spxcoins.dll
2010-01-22 18:05:37 ----A---- C:\WINDOWS\system32\EqnClass.Dll
2010-01-22 18:05:34 ----N---- C:\WINDOWS\system32\CONFIG.TMP
2010-01-22 18:05:34 ----A---- C:\WINDOWS\TASKMAN.EXE
2010-01-22 18:05:33 ----A---- C:\WINDOWS\system32\batt.dll
2010-01-22 18:05:32 ----A---- C:\WINDOWS\notepad.exe
2010-01-22 18:05:31 ----A---- C:\WINDOWS\system32\storprop.dll
2010-01-22 18:05:21 ----ASH---- C:\Documents and Settings\All Users\Application Data\desktop.ini
2010-01-22 18:05:14 ----RA---- C:\WINDOWS\SET8.tmp
2010-01-22 18:05:10 ----RA---- C:\WINDOWS\SET4.tmp
2010-01-22 18:05:08 ----RA---- C:\WINDOWS\SET3.tmp
2010-01-22 18:05:02 ----D---- C:\WINDOWS\system32\CatRoot2
2010-01-22 18:05:02 ----D---- C:\WINDOWS\system32\CatRoot
2010-01-22 18:04:56 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2010-01-22 18:04:28 ----A---- C:\WINDOWS\setuplog.txt
2010-01-22 18:04:25 ----SHD---- C:\System Volume Information
2010-01-22 18:04:25 ----D---- C:\Documents and Settings
2010-01-22 18:03:46 ----RASH---- C:\boot.ini
2010-01-22 17:56:04 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-01-22 17:56:04 ----RSD---- C:\WINDOWS\Fonts
2010-01-22 17:56:04 ----RD---- C:\WINDOWS\Web
2010-01-22 17:56:04 ----HD---- C:\WINDOWS\inf
2010-01-22 17:56:04 ----D---- C:\WINDOWS\WinSxS
2010-01-22 17:56:04 ----D---- C:\WINDOWS\twain_32
2010-01-22 17:56:04 ----D---- C:\WINDOWS\system32\wins
2010-01-22 17:56:04 ----D---- C:\WINDOWS\system32\wbem
2010-01-22 17:56:04 ----D---- C:\WINDOWS\system32\usmt
2010-01-22 17:56:04 ----D---- C:\WINDOWS\system32\spool
2010-01-22 17:56:04 ----D---- C:\WINDOWS\system32\ShellExt
2010-01-22 17:56:04 ----D---- C:\WINDOWS\system32\Setup
2010-01-22 17:56:04 ----D---- C:\WINDOWS\system32\ras
2010-01-22 17:56:04 ----D---- C:\WINDOWS\system32\oobe
2010-01-22 17:56:04 ----D---- C:\WINDOWS\system32\npp
2010-01-22 17:56:04 ----D---- C:\WINDOWS\system32\mui
2010-01-22 17:56:04 ----D---- C:\WINDOWS\system32\inetsrv
2010-01-22 17:56:04 ----D---- C:\WINDOWS\system32\IME
2010-01-22 17:56:04 ----D---- C:\WINDOWS\system32\icsxml
2010-01-22 17:56:04 ----D---- C:\WINDOWS\system32\ias
2010-01-22 17:56:04 ----D---- C:\WINDOWS\system32\export
2010-01-22 17:56:04 ----D---- C:\WINDOWS\system32\drivers
2010-01-22 17:56:04 ----D---- C:\WINDOWS\system32\dhcp
2010-01-22 17:56:04 ----D---- C:\WINDOWS\system32\config
2010-01-22 17:56:04 ----D---- C:\WINDOWS\system32\3com_dmi
2010-01-22 17:56:04 ----D---- C:\WINDOWS\system32\3076
2010-01-22 17:56:04 ----D---- C:\WINDOWS\system32\2052
2010-01-22 17:56:04 ----D---- C:\WINDOWS\system32\1054
2010-01-22 17:56:04 ----D---- C:\WINDOWS\system32\1042
2010-01-22 17:56:04 ----D---- C:\WINDOWS\system32\1041
2010-01-22 17:56:04 ----D---- C:\WINDOWS\system32\1037
2010-01-22 17:56:04 ----D---- C:\WINDOWS\system32\1033
2010-01-22 17:56:04 ----D---- C:\WINDOWS\system32\1031
2010-01-22 17:56:04 ----D---- C:\WINDOWS\system32\1028
2010-01-22 17:56:04 ----D---- C:\WINDOWS\system32\1025
2010-01-22 17:56:04 ----D---- C:\WINDOWS\system32
2010-01-22 17:56:04 ----D---- C:\WINDOWS\system
2010-01-22 17:56:04 ----D---- C:\WINDOWS\security
2010-01-22 17:56:04 ----D---- C:\WINDOWS\Resources
2010-01-22 17:56:04 ----D---- C:\WINDOWS\repair
2010-01-22 17:56:04 ----D---- C:\WINDOWS\Provisioning
2010-01-22 17:56:04 ----D---- C:\WINDOWS\PeerNet
2010-01-22 17:56:04 ----D---- C:\WINDOWS\pchealth
2010-01-22 17:56:04 ----D---- C:\WINDOWS\mui
2010-01-22 17:56:04 ----D---- C:\WINDOWS\msapps
2010-01-22 17:56:04 ----D---- C:\WINDOWS\msagent
2010-01-22 17:56:04 ----D---- C:\WINDOWS\Media
2010-01-22 17:56:04 ----D---- C:\WINDOWS\java
2010-01-22 17:56:04 ----D---- C:\WINDOWS\ime
2010-01-22 17:56:04 ----D---- C:\WINDOWS\Help
2010-01-22 17:56:04 ----D---- C:\WINDOWS\ehome
2010-01-22 17:56:04 ----D---- C:\WINDOWS\Driver Cache
2010-01-22 17:56:04 ----D---- C:\WINDOWS\dell
2010-01-22 17:56:04 ----D---- C:\WINDOWS\Debug
2010-01-22 17:56:04 ----D---- C:\WINDOWS\Cursors
2010-01-22 17:56:04 ----D---- C:\WINDOWS\Connection Wizard
2010-01-22 17:56:04 ----D---- C:\WINDOWS\Config
2010-01-22 17:56:04 ----D---- C:\WINDOWS\AppPatch
2010-01-22 17:56:04 ----D---- C:\WINDOWS\addins
2010-01-22 17:56:04 ----D---- C:\WINDOWS

======List of files/folders modified in the last 1 months======

2010-02-12 17:35:30 ----A---- C:\WINDOWS\system.ini
2010-01-23 00:18:23 ----A---- C:\WINDOWS\win.ini

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys []
R1 sbaphd;sbaphd; C:\WINDOWS\system32\drivers\sbaphd.sys [2009-05-13 13360]
R1 SBRE;SBRE; \??\C:\WINDOWS\system32\drivers\SBREdrv.sys []
R1 sbtis;sbtis; C:\WINDOWS\system32\drivers\sbtis.sys [2008-10-09 202928]
R2 sbapifs;sbapifs; C:\WINDOWS\system32\drivers\sbapifs.sys [2009-08-10 69936]
R2 tifsfilter;Acronis True Image FS Filter; C:\WINDOWS\system32\DRIVERS\tifsfilt.sys [2010-01-23 39264]
R3 BCM43XX;Dell Wireless WLAN Card Driver; C:\WINDOWS\system32\DRIVERS\bcmwl5.sys [2008-11-26 1391104]
R3 btaudio;Bluetooth Audio Device; C:\WINDOWS\system32\drivers\btaudio.sys [2008-05-30 534568]
R3 BTDriver;Bluetooth Virtual Communications Driver; C:\WINDOWS\system32\DRIVERS\btport.sys [2008-02-04 37160]
R3 BTKRNL;Bluetooth Bus Enumerator; C:\WINDOWS\system32\DRIVERS\btkrnl.sys [2008-09-30 991656]
R3 BTWDNDIS;Bluetooth LAN Access Server; C:\WINDOWS\system32\DRIVERS\btwdndis.sys [2008-07-24 156816]
R3 btwhid;btwhid; C:\WINDOWS\system32\DRIVERS\btwhid.sys [2008-03-10 57384]
R3 btwmodem;Bluetooth Modem; C:\WINDOWS\system32\DRIVERS\btwmodem.sys [2008-02-04 37032]
R3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\WINDOWS\System32\Drivers\btwusb.sys [2008-09-26 47272]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2008-04-13 13952]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver; C:\WINDOWS\system32\DRIVERS\CtClsFlt.sys [2008-10-28 135936]
R3 ETD;ELAN PS/2 Port Input Device; C:\WINDOWS\system32\DRIVERS\ETD.sys [2009-03-30 129024]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 igd;igd; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2009-03-18 5088896]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-12-11 4959232]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI Service; C:\WINDOWS\system32\drivers\IntcHdmi.sys [2008-07-30 110080]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 OA012Afx;Provides a software interface to control audio effects of OA012 camera.; \??\C:\WINDOWS\system32\Drivers\OA012Afx.sys []
R3 OA012Ufd;Creative Camera OA012 Upper Filter Driver; C:\WINDOWS\system32\DRIVERS\OA012Ufd.sys [2008-11-26 133472]
R3 OA012Vid;Creative Camera OA012 Function Driver; C:\WINDOWS\system32\DRIVERS\OA012Vid.sys [2009-01-14 271328]
R3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader; C:\WINDOWS\System32\Drivers\RTS5121.sys [2008-08-26 157696]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2008-09-25 115328]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2007-06-27 501640]
S3 catchme;catchme; \??\C:\DOCUME~1\ROBERT~1\LOCALS~1\Temp\catchme.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
S3 Ktp;Elantech Smart-Pad; C:\WINDOWS\system32\DRIVERS\ETD.sys [2009-03-30 129024]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 Rts516xIR;Realtek IR Driver; C:\WINDOWS\system32\DRIVERS\Rts516xIR.sys []
S3 SASENUM;SASENUM; \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys [2009-11-12 7168]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 USBCCID;Realtek Smartcard Reader Driver; C:\WINDOWS\system32\DRIVERS\Rts5161ccid.sys []
S3 usbstor;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 usbvideo;USB Video Device (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-13 121984]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AcrSch2Svc;Acronis Scheduler2 Service; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe [2006-10-16 230944]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-08-28 144672]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe [2008-09-29 346720]
R2 DockLoginService;Dock Login Service; C:\Program Files\Dell\DellDock\DockLogin.exe [2009-06-09 155648]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-02-12 153376]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 NMSAccessU;NMSAccessU; C:\Program Files\CDBurnerXP\NMSAccessU.exe [2009-11-12 71096]
R2 SBAMSvc;VIPRE Antivirus + Antispyware; C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe [2010-01-04 1012080]
R2 sprtsvc_DellSupportCenter;SupportSoft Sprocket Service (DellSupportCenter); C:\Program Files\Dell Support Center\bin\sprtsvc.exe [2008-10-04 201968]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-10-11 38912]
R2 wltrysvc;Dell Wireless WLAN Tray Service; C:\WINDOWS\System32\WLTRYSVC.EXE [2008-11-26 24576]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2009-11-12 545568]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2010-01-24 69632]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 GoToAssist;GoToAssist; C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe [2010-02-20 16680]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------
rjj76
Regular Member
 
Posts: 16
Joined: February 15th, 2010, 4:56 pm

Re: Search Redirect Malware

Unread postby muppy03 » February 22nd, 2010, 5:12 am

Hi,

Before we go any further I would like some more information regarding this computer.

1. It appears to you have recently reinstalled?
2. You appear to have run Combofix? I would like to see the log it produced.

IMPORTANT I notice there are signs of one or more P2P (Peer to Peer) File Sharing Programs on your computer. This is probably the cause of your infection.

BitLord

I'd like you to read the MRU policy for P2P Programs.

Please go to Control Panel > Add/Remove Programs and uninstall the programs listed above (in red). Also take note that remnants of the above program/s and any other P2P program found will be removed when cleaning.

WGA Diagnostic Tool

Please follow this WGA troubleshooting procedure:

Please post (reply) with the results.


Download CKScanner from here:http://downloads.malwareremoval.com/CKScanner.exe
Important - Save it to your desktop.
Doubleclick CKScanner.exe and click Search For Files.
After a very short time, when the cursor hourglass disappears, click Save List To File.
A message box will verify the file saved.
Double-click the CKFiles.txt icon on your desktop and copy/paste the contents in your next reply.


Please re run RSIT and post the one log it produces this time.

Please reply with:-
  • WGA log
  • CK Scanner log
  • RSIT log
  • Combofix log from previous run
User avatar
muppy03
MRU Emeritus
MRU Emeritus
 
Posts: 4782
Joined: December 4th, 2007, 5:30 am
Location: Australia

Re: Search Redirect Malware

Unread postby rjj76 » February 22nd, 2010, 10:23 am

Yes, computer was rebuilt / restored a little while ago. During the restore, Bitlord components were on there but did the uninstall. Just found the registry keys in the previous log and wiped those out - thanks for the heads up. There was a site that I think exploited a lower version of Java - during my wrestles to fix things and do some research, I discovered that I had an old version of Java. Please note the ComboFix file has a reference to the old Bitlord directory and the registry key that you pointed out from the previous log - those are wiped out now.

Thank you again for all the help. Just read about the Malaware University - a year of training is pretty heavy. Thank you for your committment.


Here's the logs:

WGA:

Diagnostic Report (1.9.0019.0):
-----------------------------------------
WGA Data-->
Validation Status: Genuine
Validation Code: 0

Cached Validation Code: N/A
Windows Product Key: *****-*****-T6DFB-Y934T-YD4YT
Windows Product Key Hash: 3g4CZGFEDgbKmn/oB4pa2FZsssU=
Windows Product ID: 76487-OEM-2211906-00102
Windows Product ID Type: 2
Windows License Type: OEM SLP
Windows OS version: 5.1.2600.2.00010100.3.0.pro
ID: {3AD3EA8B-FB9D-4057-B7A7-95A6E469252B}(3)
Is Admin: Yes
TestCab: 0x0
WGA Version: Registered, 1.9.40.0
Signed By: Microsoft
Product Name: N/A
Architecture: N/A
Build lab: N/A
TTS Error: N/A
Validation Diagnostic: 025D1FF3-230-1
Resolution Status: N/A

WgaER Data-->
ThreatID(s): N/A
Version: N/A

WGA Notifications Data-->
Cached Result: 0
File Exists: Yes
Version: 1.9.40.0
WgaTray.exe Signed By: Microsoft
WgaLogon.dll Signed By: Microsoft

OGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
Version: 2.0.48.0
OGAExec.exe Signed By: Microsoft
OGAAddin.dll Signed By: Microsoft

OGA Data-->
Office Status: 100 Genuine
Microsoft Office Professional Edition 2003 - 100 Genuine
OGA Version: Registered, 2.0.48.0
Signed By: Microsoft
Office Diagnostics: 025D1FF3-230-1

Browser Data-->
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 7.0; Win32)
Default Browser: C:\Program Files\Mozilla Firefox\firefox.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed

File Scan Data-->

Other data-->
Office Details: <GenuineResults><MachineData><UGUID>{3AD3EA8B-FB9D-4057-B7A7-95A6E469252B}</UGUID><Version>1.9.0019.0</Version><OS>5.1.2600.2.00010100.3.0.pro</OS><Architecture>x32</Architecture><PKey>*****-*****-*****-*****-YD4YT</PKey><PID>76487-OEM-2211906-00102</PID><PIDType>2</PIDType><SID>S-1-5-21-1993962763-746137067-1801674531</SID><SYSTEM><Manufacturer>Dell Inc.</Manufacturer><Model>Inspiron 1010 </Model></SYSTEM><BIOS><Manufacturer>Dell Inc.</Manufacturer><Version>A03</Version><SMBIOSVersion major="2" minor="5"/><Date>20090227000000.000000+000</Date><SLPBIOS>Dell System,Dell Computer,Dell System,Dell System</SLPBIOS></BIOS><HWID>48E10A380184A065</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Central Standard Time(GMT-06:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM/><GANotification><File Name="WgaTray.exe" Version="1.9.40.0"/><File Name="WgaLogon.dll" Version="1.9.40.0"/><File Name="OGAAddin.dll" Version="2.0.48.0"/></GANotification></MachineData><Software><Office><Result>100</Result><Products><Product GUID="{91110409-6000-11D3-8CFE-0150048383C9}"><LegitResult>100</LegitResult><Name>Microsoft Office Professional Edition 2003</Name><Ver>11</Ver><Val>1C47B287612DDD6</Val><Hash>X1EIAlw+S9xE4AmxGwS3X/GrxDc=</Hash><Pid>70145-747-5547491-57465</Pid><PidType>1</PidType></Product></Products><Applications><App Id="15" Version="11" Result="100"/><App Id="16" Version="11" Result="100"/><App Id="18" Version="11" Result="100"/><App Id="19" Version="11" Result="100"/><App Id="1A" Version="11" Result="100"/><App Id="1B" Version="11" Result="100"/><App Id="44" Version="11" Result="100"/></Applications></Office></Software></GenuineResults>

Licensing Data-->
N/A

Windows Activation Technologies-->
N/A

HWID Data-->
N/A

OEM Activation 1.0 Data-->
BIOS string matches: yes
Marker string from BIOS: BACB:Dell Inc|BACB:Microsoft Corporation
Marker string from OEMBIOS.DAT: Dell System,Dell Computer,Dell System,Dell System

OEM Activation 2.0 Data-->
N/A



CK Scanner:

CKScanner - Additional Security Risks - These are not necessarily bad
scanner sequence 3.RP.11
----- EOF -----


RSIT Log:

info:

info.txt logfile of random's system information tool 1.06 2010-02-22 08:09:33

======Uninstall list======

-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{88564CEF-20A5-4EF2-A05F-309F2EBA9B06}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BC12448A-0B41-4E11-B242-B1129512F5B7}\setup.exe" -l0x9
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Acronis True Image Home-->MsiExec.exe /X{419CF344-3D94-4DAD-99C8-EA7B00E5EA8B}
Adobe Acrobat 7.1.0 Professional-->msiexec /I {AC76BA86-1033-0000-7760-000000000002}
Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Advanced Audio FX Engine-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{88564CEF-20A5-4EF2-A05F-309F2EBA9B06}\setup.exe" -l0x9 /remove
Apple Application Support-->MsiExec.exe /I{3FA365DF-2D68-45ED-8F83-8C8A33E65143}
Apple Mobile Device Support-->MsiExec.exe /I{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}
Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
Battery Meter-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{543A4F31-9590-416A-A621-42CEB4C6A694} /l1033
Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
CapsLKNotify-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{90578106-70AF-4198-B9DE-1924FA83B03A}
CDBurnerXP-->"C:\Program Files\CDBurnerXP\unins000.exe"
Citrix XenApp Plugin for Hosted Apps-->MsiExec.exe /I{388C130B-0079-46B4-A0D5-DC2DD7A89A7B}
Codec Pack - All In 1 6.0.3.0-->C:\WINDOWS\iun6002.exe "C:\Program Files\Codec Pack - All In 1\irunin.ini"
Dell 5530 Wireless Broadband Package-->MsiExec.exe /X{580E3E43-F5EB-41C9-A348-1B7DCF002C2C}
Dell Dock-->"C:\Documents and Settings\All Users\Application Data\{7322D736-AA5F-4DD0-8E33-EA48318CC276}\delldock.exe" REMOVE=TRUE MODIFY=FALSE
Dell Dock-->C:\Documents and Settings\All Users\Application Data\{7322D736-AA5F-4DD0-8E33-EA48318CC276}\delldock.exe
Dell Resource CD-->MsiExec.exe /X{42929F0F-CE14-47AF-9FC7-FF297A603021}
Dell Support Center (Support Software)-->MsiExec.exe /X{E3BFEE55-39E2-4BE0-B966-89FE583822C1}
Dell Webcam Central-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BC12448A-0B41-4E11-B242-B1129512F5B7}\setup.exe" -l0x9 /remove
Dell Wireless WLAN Card Utility-->"C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwlu00.exe" verbose /rootkey="Software\Broadcom\802.11\UninstallInfo" /rootdir="C:\Program Files\Dell\Dell Wireless WLAN Card"
EMSC-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{FEF06E73-A519-4510-8CF3-B66041B91D8A}
ETDWare PS/2-x86 7.0.4.6 WHQL-->C:\Program Files\Elantech\ETDUninst.exe
Google Talk Plugin-->MsiExec.exe /I{BBF6D0CD-A081-369F-B0B8-F168594CBB6B}
GoToAssist 8.0.0.514-->C:\Program Files\Citrix\GoToAssist\514\G2AUninstaller.exe /uninstall
High Definition Audio Driver Package - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
Hotfix for Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB961118)-->"C:\WINDOWS\$NtUninstallKB961118$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB976098-v2)-->"C:\WINDOWS\$NtUninstallKB976098-v2$\spuninst\spuninst.exe"
Integrated Webcam Driver (1.01.01.0116) -->C:\WINDOWS\CtDrvIns.exe -uninstall -script OA012.uns -plugin OA012Pin.dll -pluginres OA012Pin.crl -nodisconprompt -langid 0x0409
Intel(R) Graphics Media Accelerator 500-->C:\WINDOWS\system32\lpgun.exe -uninstall
iTunes-->MsiExec.exe /I{A6FDF86A-F541-4E7B-AEA0-8849A2A700D5}
Java DB 10.5.3.0-->MsiExec.exe /X{00BA866C-F2A2-4BB9-A308-3DFA695B6F7C}
Java(TM) 6 Update 18-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216018FF}
Java(TM) SE Development Kit 6 Update 18-->MsiExec.exe /I{32A3A4F4-B792-11D6-A78A-00B0D0160180}
Live! Cam Avatar Creator-->C:\Program Files\InstallShield Installation Information\{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}\setup.exe -runfromtemp -l0x0009 -removeonly /remove
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft Kernel-Mode Driver Framework Feature Pack 1.7-->"C:\WINDOWS\$NtUninstallWdf01007$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office Professional Edition 2003-->MsiExec.exe /I{91110409-6000-11D3-8CFE-0150048383C9}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148-->MsiExec.exe /X{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
Mindjet MindManager 8-->MsiExec.exe /I{D7FD752A-DDB9-4685-83FD-E20C7C59BD84}
Mozilla Firefox (3.6)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
MSXML 6 Service Pack 2 (KB973686)-->MsiExec.exe /I{56EA8BC0-3751-4B93-BC9D-6651CC36E5AA}
OGA Notifier 2.0.0048.0-->MsiExec.exe /I{B2544A03-10D0-4E5E-BA69-0362FFC20D18}
Opera 10.50-->MsiExec.exe /X{88840901-1811-4214-99AA-B7AAF96EDC5A}
PDF-XChange 3-->"C:\Program Files\Mindjet\MindManager 8\PDF-XChange\unins000.exe"
QuickTime Alternative 1.90-->"C:\Program Files\QuickTime Alternative\unins000.exe"
QuickTime-->MsiExec.exe /I{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}
Real Alternative 1.9.0-->"C:\Program Files\Real Alternative\unins000.exe"
Realtek Card Reader-->C:\Program Files\InstallShield Installation Information\{D10CB652-9332-4242-B7A9-2D61570144F7}\setup.exe -runfromtemp -l0x0009 -removeonly
REALTEK GbE & FE Ethernet PCI-E NIC Driver-->C:\Program Files\InstallShield Installation Information\{C9BED750-1211-4480-B1A5-718A3BE15525}\setup.exe -runfromtemp -l0x0009 -removeonly
Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\setup.exe" -l0x9 -removeonly
Security Update for Windows Internet Explorer 7 (KB938127-v2)-->"C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB976325)-->"C:\WINDOWS\ie7updates\KB976325-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB978207)-->"C:\WINDOWS\ie7updates\KB978207-IE7\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB954155)-->"C:\WINDOWS\$NtUninstallKB954155_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB968816)-->"C:\WINDOWS\$NtUninstallKB968816_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB973540)-->"C:\WINDOWS\$NtUninstallKB973540_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB973540)-->"C:\WINDOWS\$NtUninstallKB973540_WM9L$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
Security Update for Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956744)-->"C:\WINDOWS\$NtUninstallKB956744$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956844)-->"C:\WINDOWS\$NtUninstallKB956844$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958869)-->"C:\WINDOWS\$NtUninstallKB958869$\spuninst\spuninst.exe"
Security Update for Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960859)-->"C:\WINDOWS\$NtUninstallKB960859$\spuninst\spuninst.exe"
Security Update for Windows XP (KB961501)-->"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
Security Update for Windows XP (KB969059)-->"C:\WINDOWS\$NtUninstallKB969059$\spuninst\spuninst.exe"
Security Update for Windows XP (KB969947)-->"C:\WINDOWS\$NtUninstallKB969947$\spuninst\spuninst.exe"
Security Update for Windows XP (KB970238)-->"C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
Security Update for Windows XP (KB970430)-->"C:\WINDOWS\$NtUninstallKB970430$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971468)-->"C:\WINDOWS\$NtUninstallKB971468$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971486)-->"C:\WINDOWS\$NtUninstallKB971486$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971557)-->"C:\WINDOWS\$NtUninstallKB971557$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971633)-->"C:\WINDOWS\$NtUninstallKB971633$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971657)-->"C:\WINDOWS\$NtUninstallKB971657$\spuninst\spuninst.exe"
Security Update for Windows XP (KB972270)-->"C:\WINDOWS\$NtUninstallKB972270$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973354)-->"C:\WINDOWS\$NtUninstallKB973354$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973507)-->"C:\WINDOWS\$NtUninstallKB973507$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973525)-->"C:\WINDOWS\$NtUninstallKB973525$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973869)-->"C:\WINDOWS\$NtUninstallKB973869$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973904)-->"C:\WINDOWS\$NtUninstallKB973904$\spuninst\spuninst.exe"
Security Update for Windows XP (KB974112)-->"C:\WINDOWS\$NtUninstallKB974112$\spuninst\spuninst.exe"
Security Update for Windows XP (KB974318)-->"C:\WINDOWS\$NtUninstallKB974318$\spuninst\spuninst.exe"
Security Update for Windows XP (KB974392)-->"C:\WINDOWS\$NtUninstallKB974392$\spuninst\spuninst.exe"
Security Update for Windows XP (KB974571)-->"C:\WINDOWS\$NtUninstallKB974571$\spuninst\spuninst.exe"
Security Update for Windows XP (KB975025)-->"C:\WINDOWS\$NtUninstallKB975025$\spuninst\spuninst.exe"
Security Update for Windows XP (KB975467)-->"C:\WINDOWS\$NtUninstallKB975467$\spuninst\spuninst.exe"
Security Update for Windows XP (KB975560)-->"C:\WINDOWS\$NtUninstallKB975560$\spuninst\spuninst.exe"
Security Update for Windows XP (KB975713)-->"C:\WINDOWS\$NtUninstallKB975713$\spuninst\spuninst.exe"
Security Update for Windows XP (KB977165)-->"C:\WINDOWS\$NtUninstallKB977165$\spuninst\spuninst.exe"
Security Update for Windows XP (KB977914)-->"C:\WINDOWS\$NtUninstallKB977914$\spuninst\spuninst.exe"
Security Update for Windows XP (KB978037)-->"C:\WINDOWS\$NtUninstallKB978037$\spuninst\spuninst.exe"
Security Update for Windows XP (KB978251)-->"C:\WINDOWS\$NtUninstallKB978251$\spuninst\spuninst.exe"
Security Update for Windows XP (KB978262)-->"C:\WINDOWS\$NtUninstallKB978262$\spuninst\spuninst.exe"
Security Update for Windows XP (KB978706)-->"C:\WINDOWS\$NtUninstallKB978706$\spuninst\spuninst.exe"
SpyHunter-->"C:\Program Files\Enigma Software Group\SpyHunter\Uninstall.exe" "C:\Program Files\Enigma Software Group\SpyHunter\install.log" -u
SUPERAntiSpyware Free Edition-->MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
Update for Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Update for Windows XP (KB955759)-->"C:\WINDOWS\$NtUninstallKB955759$\spuninst\spuninst.exe"
Update for Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
Update for Windows XP (KB968389)-->"C:\WINDOWS\$NtUninstallKB968389$\spuninst\spuninst.exe"
Update for Windows XP (KB971737)-->"C:\WINDOWS\$NtUninstallKB971737$\spuninst\spuninst.exe"
Update for Windows XP (KB973687)-->"C:\WINDOWS\$NtUninstallKB973687$\spuninst\spuninst.exe"
Update for Windows XP (KB973815)-->"C:\WINDOWS\$NtUninstallKB973815$\spuninst\spuninst.exe"
Update for Windows XP (KB978207)-->"C:\WINDOWS\$NtUninstallKB978207$\spuninst\spuninst.exe"
VLC media player 1.0.3-->C:\Program Files\VideoLAN\VLC\uninstall.exe
WIDCOMM Bluetooth Software-->MsiExec.exe /X{84814E6B-2581-46EC-926A-823BD1C670F6}
Windows Imaging Component-->"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
Windows Media Format Runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe

======Hosts File======

127.0.0.1 localhost

======Security center information======

AV: Sunbelt VIPRE

======System event log======

Computer Name: MINI10
Event Code: 7022
Message: The Sunbelt VIPRE Antivirus Service service hung on starting.

Record Number: 784
Source Name: Service Control Manager
Time Written: 20100124100121.000000-360
Event Type: error
User:

Computer Name: MINI10
Event Code: 7
Message: The device, \Device\Harddisk1\D, has a bad block.

Record Number: 718
Source Name: Disk
Time Written: 20100124084954.000000-360
Event Type: error
User:

Computer Name: MINI10
Event Code: 7
Message: The device, \Device\Harddisk1\D, has a bad block.

Record Number: 717
Source Name: Disk
Time Written: 20100124084952.000000-360
Event Type: error
User:

Computer Name: MINI10
Event Code: 7
Message: The device, \Device\Harddisk1\D, has a bad block.

Record Number: 716
Source Name: Disk
Time Written: 20100124084945.000000-360
Event Type: error
User:

Computer Name: MINI10
Event Code: 10000
Message: Unable to start a DCOM Server: {28DD3979-0566-4ED3-9B14-1548B3187491}.
The error:
"%2"
Happened while starting this command:
? Ÿ c

Record Number: 571
Source Name: DCOM
Time Written: 20100123162647.000000-360
Event Type: error
User: MINI10\Robert Jericho

=====Application event log=====

Computer Name: MINI10
Event Code: 5603
Message: A provider, Rsop Planning Mode Provider, has been registered in the WMI namespace, root\RSOP, but did not specify the HostingModel property. This provider will be run using the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests. Ensure that provider has been reviewed for security behavior and update the HostingModel property of the provider registration to an account with the least privileges possible for the required functionality.

Record Number: 18
Source Name: WinMgmt
Time Written: 20100123001751.000000-360
Event Type: warning
User: NT AUTHORITY\SYSTEM

Computer Name: MINI10
Event Code: 5603
Message: A provider, Rsop Planning Mode Provider, has been registered in the WMI namespace, root\RSOP, but did not specify the HostingModel property. This provider will be run using the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests. Ensure that provider has been reviewed for security behavior and update the HostingModel property of the provider registration to an account with the least privileges possible for the required functionality.

Record Number: 17
Source Name: WinMgmt
Time Written: 20100123001751.000000-360
Event Type: warning
User: NT AUTHORITY\SYSTEM

Computer Name: MINI10
Event Code: 63
Message: A provider, CmdTriggerConsumer, has been registered in the WMI namespace, Root\cimv2, to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.

Record Number: 13
Source Name: WinMgmt
Time Written: 20100123001418.000000-360
Event Type: warning
User: NT AUTHORITY\SYSTEM

Computer Name: MINI10
Event Code: 63
Message: A provider, CmdTriggerConsumer, has been registered in the WMI namespace, Root\cimv2, to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.

Record Number: 12
Source Name: WinMgmt
Time Written: 20100123001418.000000-360
Event Type: warning
User: NT AUTHORITY\SYSTEM

Computer Name: MINI10
Event Code: 63
Message: A provider, HiPerfCooker_v1, has been registered in the WMI namespace, Root\WMI, to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.

Record Number: 11
Source Name: WinMgmt
Time Written: 20100123001414.000000-360
Event Type: warning
User: NT AUTHORITY\SYSTEM

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\system32\wbem;C:\Program Files\QuickTime\QTSystem
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 28 Stepping 2, GenuineIntel
"PROCESSOR_REVISION"=1c02
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"CLASSPATH"=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip

-----------------EOF-----------------


Logfile of random's system information tool 1.06 (written by random/random)
Run by Robert Jericho at 2010-02-22 08:09:14
Microsoft Windows XP Professional Service Pack 3
System drive C: has 62 GB (40%) free of 153 GB
Total RAM: 1014 MB (45% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:09:25 AM, on 2/22/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16981)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Dell\DellDock\DockLogin.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Dell\DellDock\DellDock.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Elantech\ETDCtrl.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\CapsLKNotify\CapsLKNotify.exe
C:\Program Files\WSED\WSED.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\PersistenceThread.exe
C:\Program Files\Mindjet\MindManager 8\MMReminderService.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Battery Meter\BTMeter.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Documents and Settings\Robert Jericho\Start Menu\Programs\Startup\osd_vol.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Robert Jericho\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Robert Jericho.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: ShopSafe Browser Helper Object - {333F6B96-3992-4D58-A499-145A10FE48C3} - C:\Program Files\ShopSafe\BhoSSafe.dll
O2 - BHO: CmjBrowserHelperObject Object - {6FE6A929-59D1-4763-91AD-29B61CFFB35B} - C:\Program Files\Mindjet\MindManager 8\Mm8InternetExplorer.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [ETDWare] C:\Program Files\Elantech\ETDCtrl.exe
O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
O4 - HKLM\..\Run: [CapsLKNotify] C:\Program Files\CapsLKNotify\CapsLKNotify.exe
O4 - HKLM\..\Run: [WSED] C:\Program Files\WSED\WSED.exe
O4 - HKLM\..\Run: [Dell Webcam Central] "C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe" /mode2
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [SBAMTray] C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [PersistenceThread] C:\WINDOWS\system32\PersistenceThread.exe
O4 - HKLM\..\Run: [MMReminderService] C:\Program Files\Mindjet\MindManager 8\MMReminderService.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [BTMeter] C:\Program Files\Battery Meter\BTMeter.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Robert Jericho\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
O4 - Startup: osd_vol.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Send to Mindjet MindManager - {2F72393D-2472-4F82-B600-ED77F354B7FF} - C:\Program Files\Mindjet\MindManager 8\Mm8InternetExplorer.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/s ... wflash.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O20 - Winlogon Notify: igdlogin - C:\WINDOWS\SYSTEM32\igdlogin.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: VIPRE Antivirus + Antispyware (SBAMSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe
O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

--
End of file - 10685 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1993962763-746137067-1801674531-1003Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1993962763-746137067-1801674531-1003UA.job
C:\WINDOWS\tasks\OGALogon.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-12-18 59032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{333F6B96-3992-4D58-A499-145A10FE48C3}]
ShopSafeBrowserHelper Class - C:\Program Files\ShopSafe\BhoSSafe.dll [2007-03-13 143360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6FE6A929-59D1-4763-91AD-29B61CFFB35B}]
CmjBrowserHelperObject Object - C:\Program Files\Mindjet\MindManager 8\Mm8InternetExplorer.dll [2008-11-14 70944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2006-12-18 231160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-02-12 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-02-12 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2006-12-18 231160]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"=C:\WINDOWS\system32\WLTRAY.exe [2008-11-26 2289664]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2008-12-09 18063872]
"ETDWare"=C:\Program Files\Elantech\ETDCtrl.exe [2009-03-30 418816]
"dellsupportcenter"=C:\Program Files\Dell Support Center\bin\sprtcmd.exe [2009-06-03 206064]
"CapsLKNotify"=C:\Program Files\CapsLKNotify\CapsLKNotify.exe [2009-03-17 320808]
"WSED"=C:\Program Files\WSED\WSED.exe [2009-05-27 247080]
"Dell Webcam Central"=C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe [2008-11-11 442536]
"TrueImageMonitor.exe"=C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe [2006-10-16 1164912]
"AcronisTimounterMonitor"=C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe [2006-10-16 1941784]
"Acronis Scheduler2 Service"=C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe [2006-10-16 87584]
"SBAMTray"=C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe [2010-01-04 959824]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-11-10 417792]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2009-11-12 141600]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2009-03-18 131072]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2009-03-18 348160]
"PersistenceThread"=C:\WINDOWS\system32\PersistenceThread.exe [2010-01-24 86016]
"MMReminderService"=C:\Program Files\Mindjet\MindManager 8\MMReminderService.exe [2008-11-14 37656]
"Acrobat Assistant 7.0"=C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe [2008-04-23 483328]
"BTMeter"=C:\Program Files\Battery Meter\BTMeter.exe [2008-11-04 623912]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Documents and Settings\Robert Jericho\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-02-10 135664]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe

C:\Documents and Settings\Robert Jericho\Start Menu\Programs\Startup
Dell Dock.lnk - C:\Program Files\Dell\DellDock\DellDock.exe
osd_vol.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [2009-09-03 548352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\GoToAssist]
C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll [2010-02-20 10536]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igdlogin]
C:\WINDOWS\system32\igdlogin.dll [2009-03-18 65536]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 239496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
relog_ap

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\GoToAssist]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SBAMSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Documents and Settings\Robert Jericho\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.dll"="C:\Documents and Settings\Robert Jericho\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.dll:*:Enabled:Google Talk Plugin"
"C:\Documents and Settings\Robert Jericho\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe"="C:\Documents and Settings\Robert Jericho\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin"
"C:\Program Files\Opera 10.50 Beta\opera.exe"="C:\Program Files\Opera 10.50 Beta\opera.exe:*:Enabled:Opera Internet Browser"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2010-02-20 13:45:33 ----D---- C:\Documents and Settings\All Users\Application Data\Citrix
2010-02-20 13:22:45 ----D---- C:\Program Files\Elantech
2010-02-20 12:58:48 ----D---- C:\Program Files\Battery Meter
2010-02-20 11:06:54 ----D---- C:\rsit
2010-02-16 20:32:03 ----D---- C:\Documents and Settings\Robert Jericho\Application Data\Opera
2010-02-16 20:31:29 ----D---- C:\Program Files\Opera 10.50 Beta
2010-02-15 18:01:12 ----D---- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2010-02-15 18:01:07 ----D---- C:\Documents and Settings\Robert Jericho\Application Data\Office Genuine Advantage
2010-02-15 14:53:15 ----D---- C:\Program Files\Trend Micro
2010-02-15 13:56:20 ----D---- C:\Program Files\Mozilla Firefox
2010-02-15 13:22:11 ----D---- C:\Program Files\Enigma Software Group
2010-02-15 13:16:44 ----D---- C:\Documents and Settings\All Users\Application Data\XoftSpySE
2010-02-13 09:59:27 ----D---- C:\Documents and Settings\Robert Jericho\Application Data\Canneverbe Limited
2010-02-13 09:59:25 ----D---- C:\Documents and Settings\All Users\Application Data\Canneverbe Limited
2010-02-13 09:58:17 ----D---- C:\Program Files\CDBurnerXP
2010-02-13 08:57:04 ----D---- C:\Program Files\Alwil Software
2010-02-13 08:57:04 ----D---- C:\Documents and Settings\All Users\Application Data\Alwil Software
2010-02-12 22:07:26 ----SHD---- C:\RECYCLER
2010-02-12 17:49:38 ----D---- C:\Documents and Settings\All Users\Application Data\Sun
2010-02-12 17:48:09 ----D---- C:\Program Files\Sun
2010-02-12 17:47:53 ----A---- C:\WINDOWS\system32\javaws.exe
2010-02-12 17:47:53 ----A---- C:\WINDOWS\system32\javaw.exe
2010-02-12 17:47:53 ----A---- C:\WINDOWS\system32\java.exe
2010-02-12 17:38:24 ----D---- C:\WINDOWS\temp
2010-02-12 17:24:39 ----A---- C:\Boot.bak
2010-02-12 17:24:33 ----RASHD---- C:\cmdcons
2010-02-12 17:22:21 ----A---- C:\WINDOWS\zip.exe
2010-02-12 17:22:21 ----A---- C:\WINDOWS\SWXCACLS.exe
2010-02-12 17:22:21 ----A---- C:\WINDOWS\SWSC.exe
2010-02-12 17:22:21 ----A---- C:\WINDOWS\SWREG.exe
2010-02-12 17:22:21 ----A---- C:\WINDOWS\sed.exe
2010-02-12 17:22:21 ----A---- C:\WINDOWS\PEV.exe
2010-02-12 17:22:21 ----A---- C:\WINDOWS\NIRCMD.exe
2010-02-12 17:22:21 ----A---- C:\WINDOWS\MBR.exe
2010-02-12 17:22:21 ----A---- C:\WINDOWS\grep.exe
2010-02-12 17:11:23 ----D---- C:\WINDOWS\ERDNT
2010-02-12 17:10:33 ----D---- C:\Qoobox
2010-02-12 17:00:47 ----D---- C:\WINDOWS\system32\appmgmt
2010-02-12 11:38:01 ----D---- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2010-02-12 11:37:37 ----D---- C:\Program Files\SUPERAntiSpyware
2010-02-12 11:37:37 ----D---- C:\Documents and Settings\Robert Jericho\Application Data\SUPERAntiSpyware.com
2010-02-12 11:37:13 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2010-02-12 08:31:11 ----D---- C:\Documents and Settings\Robert Jericho\Application Data\Malwarebytes
2010-02-12 08:31:01 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2010-02-12 08:31:00 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-02-10 18:33:38 ----D---- C:\WINDOWS\Sun
2010-02-10 03:09:24 ----HDC---- C:\WINDOWS\$NtUninstallKB978262$
2010-02-10 03:08:20 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2010-02-10 03:04:59 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2010-02-10 03:04:49 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2010-02-10 03:04:38 ----HDC---- C:\WINDOWS\$NtUninstallKB978251$
2010-02-10 03:04:27 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2010-02-10 03:04:05 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2010-02-10 03:02:16 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2010-02-10 03:01:44 ----HDC---- C:\WINDOWS\$NtUninstallKB977165$
2010-02-08 21:19:02 ----D---- C:\WINDOWS\system32\zh-TW
2010-02-08 21:19:02 ----D---- C:\WINDOWS\system32\zh-HK
2010-02-08 21:19:02 ----D---- C:\WINDOWS\system32\tr-TR
2010-02-08 21:19:02 ----D---- C:\WINDOWS\system32\sv-SE
2010-02-08 21:19:02 ----D---- C:\WINDOWS\system32\pt-BR
2010-02-08 21:19:02 ----D---- C:\WINDOWS\system32\nl-NL
2010-02-08 21:19:02 ----D---- C:\WINDOWS\system32\nb-NO
2010-02-08 21:19:02 ----D---- C:\WINDOWS\system32\ko-KR
2010-02-08 21:19:02 ----D---- C:\WINDOWS\system32\it-IT
2010-02-08 21:19:02 ----D---- C:\WINDOWS\system32\he-IL
2010-02-08 21:19:02 ----D---- C:\WINDOWS\system32\fr-FR
2010-02-08 21:19:02 ----D---- C:\WINDOWS\system32\fi-FI
2010-02-08 21:19:01 ----D---- C:\WINDOWS\system32\es-ES
2010-02-08 21:19:01 ----D---- C:\WINDOWS\system32\el-GR
2010-02-08 21:19:01 ----D---- C:\WINDOWS\system32\de-DE
2010-02-08 21:19:01 ----D---- C:\WINDOWS\system32\da-DK
2010-02-08 21:19:01 ----D---- C:\WINDOWS\system32\ar-SA
2010-02-05 00:41:18 ----A---- C:\WINDOWS\system32\muweb.dll
2010-02-05 00:41:18 ----A---- C:\WINDOWS\system32\mucltui.dll.mui
2010-02-05 00:41:18 ----A---- C:\WINDOWS\system32\mucltui.dll
2010-02-04 23:24:57 ----D---- C:\Documents and Settings\Robert Jericho\Application Data\AdobeUM
2010-02-04 20:40:00 ----D---- C:\Program Files\Microsoft Silverlight
2010-02-01 03:01:25 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2010-02-01 03:01:12 ----HDC---- C:\WINDOWS\$NtUninstallKB956744$
2010-02-01 03:00:30 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9$
2010-01-31 20:13:48 ----D---- C:\WINDOWS\Prefetch
2010-01-31 20:10:55 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2010-01-31 20:10:42 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2010-01-31 20:10:28 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2010-01-31 20:10:15 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2010-01-31 20:10:00 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2010-01-31 20:09:47 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2010-01-31 20:09:31 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2010-01-31 20:09:18 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
2010-01-31 20:09:05 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$
2010-01-31 20:08:49 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
2010-01-31 20:08:36 ----HDC---- C:\WINDOWS\$NtUninstallKB973354$
2010-01-31 20:08:23 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
2010-01-31 20:08:07 ----HDC---- C:\WINDOWS\$NtUninstallKB971737$
2010-01-31 20:07:54 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2010-01-31 20:07:41 ----HDC---- C:\WINDOWS\$NtUninstallKB971633$
2010-01-31 20:07:28 ----HDC---- C:\WINDOWS\$NtUninstallKB971557$
2010-01-31 20:07:12 ----HDC---- C:\WINDOWS\$NtUninstallKB971486$
2010-01-31 20:06:56 ----HDC---- C:\WINDOWS\$NtUninstallKB970430$
2010-01-31 20:06:43 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
2010-01-31 20:06:28 ----HDC---- C:\WINDOWS\$NtUninstallKB969947$
2010-01-31 20:06:14 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2010-01-31 20:05:57 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2010-01-31 20:05:40 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2010-01-31 20:05:25 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2010-01-31 20:04:55 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
2010-01-31 20:04:41 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2010-01-31 20:04:26 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2010-01-31 20:04:12 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2010-01-31 20:03:57 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2010-01-31 20:03:43 ----HDC---- C:\WINDOWS\$NtUninstallKB958687$
2010-01-31 20:03:28 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2010-01-31 20:03:14 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
2010-01-31 20:03:00 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2010-01-31 20:02:46 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2010-01-31 20:02:32 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2010-01-31 20:02:10 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2010-01-31 20:01:53 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2010-01-31 20:01:37 ----HDC---- C:\WINDOWS\$NtUninstallKB973687_1$
2010-01-31 20:01:24 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2010-01-31 20:01:09 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2010-01-31 20:00:55 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2010-01-31 20:00:39 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2010-01-31 20:00:23 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2010-01-31 20:00:09 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2010-01-31 19:59:54 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2010-01-31 19:59:41 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2010-01-31 19:59:27 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2010-01-31 19:59:13 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2010-01-31 19:58:57 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2010-01-31 19:52:21 ----D---- C:\WINDOWS\system32\scripting
2010-01-31 19:52:20 ----D---- C:\WINDOWS\l2schemas
2010-01-31 19:52:18 ----D---- C:\WINDOWS\system32\en
2010-01-31 19:52:18 ----D---- C:\WINDOWS\system32\bits
2010-01-31 19:36:52 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2010-01-25 18:55:41 ----D---- C:\Documents and Settings\Robert Jericho\Application Data\vlc
2010-01-25 18:53:25 ----D---- C:\Program Files\VideoLAN
2010-01-25 18:34:16 ----D---- C:\Documents and Settings\Robert Jericho\Application Data\WinRAR
2010-01-25 16:32:51 ----HDC---- C:\WINDOWS\$NtUninstallKB961118_0$
2010-01-25 16:31:30 ----HDC---- C:\WINDOWS\$NtUninstallKB925720$
2010-01-25 16:30:21 ----D---- C:\Program Files\MSXML 4.0
2010-01-25 03:09:27 ----D---- C:\WINDOWS\system32\XPSViewer
2010-01-25 03:09:22 ----D---- C:\Program Files\MSBuild
2010-01-25 03:09:11 ----D---- C:\Program Files\Reference Assemblies
2010-01-25 03:08:26 ----N---- C:\WINDOWS\system32\xpssvcs.dll
2010-01-25 03:08:26 ----N---- C:\WINDOWS\system32\xpsshhdr.dll
2010-01-25 03:08:26 ----N---- C:\WINDOWS\system32\prntvpt.dll
2010-01-25 03:08:25 ----D---- C:\a3eb26cc20e43dea7a4c6a64
2010-01-25 03:02:20 ----HDC---- C:\WINDOWS\$NtUninstallWIC$
2010-01-24 20:10:18 ----HD---- C:\WINDOWS\system32\GroupPolicy
2010-01-24 17:59:43 ----D---- C:\Program Files\ShopSafe
2010-01-24 17:56:28 ----D---- C:\Documents and Settings\Robert Jericho\Application Data\Macromedia
2010-01-24 17:39:58 ----D---- C:\Program Files\Citrix
2010-01-24 17:29:22 ----D---- C:\Program Files\WinRAR
2010-01-24 17:18:52 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe Systems
2010-01-24 17:18:46 ----D---- C:\Documents and Settings\Robert Jericho\Application Data\Adobe
2010-01-24 17:18:39 ----D---- C:\Program Files\Common Files\Adobe Systems Shared
2010-01-24 17:17:02 ----D---- C:\Program Files\Common Files\Adobe
2010-01-24 17:13:25 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2010-01-24 17:12:27 ----D---- C:\Program Files\Adobe
2010-01-24 17:07:59 ----A---- C:\WINDOWS\system32\pxc25pm.dll
2010-01-24 17:07:57 ----A---- C:\WINDOWS\system32\unicows.dll
2010-01-24 17:05:51 ----D---- C:\Documents and Settings\All Users\Application Data\Mindjet
2010-01-24 17:05:36 ----D---- C:\Program Files\Mindjet
2010-01-24 17:04:35 ----D---- C:\Program Files\MSXML 6.0
2010-01-24 15:00:18 ----A---- C:\WINDOWS\system32\igdlogin.dll
2010-01-24 14:51:43 ----A---- C:\WINDOWS\iun6002.exe
2010-01-24 14:51:35 ----D---- C:\Program Files\Codec Pack - All In 1
2010-01-24 14:50:47 ----A---- C:\WINDOWS\Codec Pack - All In 1 Setup Log.txt
2010-01-24 14:34:05 ----D---- C:\Documents and Settings\Robert Jericho\Application Data\Media Player Classic
2010-01-24 14:31:16 ----A---- C:\WINDOWS\system32\rmoc3260.dll
2010-01-24 14:31:16 ----A---- C:\WINDOWS\system32\pndx5032.dll
2010-01-24 14:31:16 ----A---- C:\WINDOWS\system32\pndx5016.dll
2010-01-24 14:31:15 ----A---- C:\WINDOWS\system32\pncrt.dll
2010-01-24 14:31:13 ----D---- C:\Program Files\Real Alternative
2010-01-24 14:31:13 ----D---- C:\Documents and Settings\Robert Jericho\Application Data\Real
2010-01-24 14:31:13 ----D---- C:\Documents and Settings\All Users\Application Data\Real
2010-01-24 14:31:01 ----D---- C:\Program Files\QuickTime Alternative
2010-01-24 14:30:31 ----D---- C:\Program Files\All in 1 Media Codecs Pack
2010-01-24 14:23:35 ----D---- C:\WINDOWS\Minidump
2010-01-24 13:30:51 ----D---- C:\Program Files\Duplicate Music Files Finder
2010-01-24 13:16:51 ----D---- C:\Documents and Settings\All Users\Application Data\Vistanita
2010-01-24 12:10:53 ----D---- C:\Documents and Settings\All Users\Application Data\Google
2010-01-24 12:01:13 ----D---- C:\Documents and Settings\Robert Jericho\Application Data\Apple Computer
2010-01-24 12:00:46 ----A---- C:\WINDOWS\system32\GEARAspi.dll
2010-01-24 11:59:50 ----D---- C:\Program Files\iPod
2010-01-24 11:59:45 ----D---- C:\Program Files\iTunes
2010-01-24 11:59:45 ----D---- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2010-01-24 11:59:34 ----A---- C:\WINDOWS\system32\hidserv.dll
2010-01-24 11:59:01 ----D---- C:\Program Files\Bonjour
2010-01-24 11:57:45 ----D---- C:\Program Files\QuickTime
2010-01-24 11:57:43 ----D---- C:\Documents and Settings\All Users\Application Data\Apple Computer
2010-01-24 11:57:00 ----D---- C:\Program Files\Apple Software Update
2010-01-24 11:55:23 ----D---- C:\Program Files\Common Files\Apple
2010-01-24 11:55:23 ----D---- C:\Documents and Settings\All Users\Application Data\Apple
2010-01-24 11:23:07 ----D---- C:\WINDOWS\ie7updates
2010-01-24 11:22:19 ----D---- C:\WINDOWS\WBEM
2010-01-24 11:22:17 ----D---- C:\WINDOWS\system32\en-US
2010-01-24 11:20:49 ----HDC---- C:\WINDOWS\ie7
2010-01-24 11:20:31 ----HDC---- C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$
2010-01-24 11:20:03 ----HDC---- C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$
2010-01-24 11:19:16 ----HDC---- C:\WINDOWS\$NtUninstallKB915865$
2010-01-24 11:19:09 ----N---- C:\WINDOWS\system32\xmllite.dll
2010-01-24 11:16:51 ----D---- C:\WINDOWS\network diagnostic
2010-01-24 11:16:50 ----HDC---- C:\WINDOWS\$NtUninstallKB914440$
2010-01-24 10:25:09 ----A---- C:\WINDOWS\ODBC.INI
2010-01-24 10:25:02 ----A---- C:\WINDOWS\system32\mdimon.dll
2010-01-24 10:23:29 ----D---- C:\Program Files\Common Files\L&H
2010-01-24 10:23:16 ----D---- C:\Program Files\Microsoft ActiveSync
2010-01-24 10:22:40 ----D---- C:\Program Files\Common Files\DESIGNER
2010-01-24 10:22:33 ----D---- C:\Program Files\Microsoft Works
2010-01-24 10:22:23 ----D---- C:\Program Files\Microsoft Visual Studio
2010-01-24 10:22:14 ----D---- C:\WINDOWS\SHELLNEW
2010-01-24 10:22:12 ----D---- C:\Program Files\Microsoft.NET
2010-01-24 10:22:11 ----D---- C:\Program Files\Microsoft Office
2010-01-24 10:16:02 ----RD---- C:\MSOCache
2010-01-24 10:15:13 ----HDC---- C:\WINDOWS\$NtUninstallKB959426_0$
2010-01-24 10:14:59 ----HDC---- C:\WINDOWS\$NtUninstallKB970430_0$
2010-01-24 10:13:47 ----HDC---- C:\WINDOWS\$NtUninstallKB941569$
2010-01-24 10:11:14 ----A---- C:\WINDOWS\system32\MRT.exe
2010-01-24 10:11:04 ----HDC---- C:\WINDOWS\$NtUninstallKB971737_0$
2010-01-24 10:10:47 ----HDC---- C:\WINDOWS\$NtUninstallKB971961$
2010-01-24 09:51:59 ----D---- C:\Documents and Settings\Robert Jericho\Application Data\Sunbelt
2010-01-24 09:50:37 ----D---- C:\Documents and Settings\All Users\Application Data\Sunbelt
2010-01-24 09:49:23 ----D---- C:\Program Files\Sunbelt Software
2010-01-24 09:36:33 ----D---- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2010-01-24 09:33:17 ----A---- C:\WINDOWS\system32\AutoPartNt.exe
2010-01-24 03:09:55 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2_0$
2010-01-24 03:09:47 ----HDC---- C:\WINDOWS\$NtUninstallKB952954_0$
2010-01-24 03:09:38 ----HDC---- C:\WINDOWS\$NtUninstallKB946648_0$
2010-01-24 03:09:30 ----HDC---- C:\WINDOWS\$NtUninstallKB956803_0$
2010-01-24 03:09:21 ----HDC---- C:\WINDOWS\$NtUninstallKB960859_0$
2010-01-24 03:09:11 ----HDC---- C:\WINDOWS\$NtUninstallKB935448$
2010-01-24 03:08:49 ----HDC---- C:\WINDOWS\$NtUninstallKB978207$
2010-01-24 03:08:38 ----HDC---- C:\WINDOWS\$NtUninstallKB958869$
2010-01-24 03:08:30 ----HDC---- C:\WINDOWS\$NtUninstallKB954155_WM9$
2010-01-24 03:08:24 ----HDC---- C:\WINDOWS\$NtUninstallKB976098-v2$
2010-01-24 03:08:17 ----HDC---- C:\WINDOWS\$NtUninstallKB955759_0$
2010-01-24 03:07:53 ----HDC---- C:\WINDOWS\$NtUninstallKB974318_0$
2010-01-24 03:07:43 ----HDC---- C:\WINDOWS\$NtUninstallKB969059_0$
2010-01-24 03:07:34 ----HDC---- C:\WINDOWS\$NtUninstallKB950974_0$
2010-01-24 03:07:24 ----HDC---- C:\WINDOWS\$NtUninstallKB971657_0$
2010-01-24 03:07:16 ----HDC---- C:\WINDOWS\$NtUninstallKB971557_0$
2010-01-24 03:07:08 ----HDC---- C:\WINDOWS\$NtUninstallKB960225_0$
2010-01-24 03:06:59 ----HDC---- C:\WINDOWS\$NtUninstallKB972270_0$
2010-01-24 03:06:50 ----HDC---- C:\WINDOWS\$NtUninstallKB974112_0$
2010-01-24 03:06:31 ----HDC---- C:\WINDOWS\$NtUninstallKB956572_0$
2010-01-24 03:06:17 ----HDC---- C:\WINDOWS\$NtUninstallKB956844_0$
2010-01-24 03:06:09 ----HDC---- C:\WINDOWS\$NtUninstallKB961501_0$
2010-01-24 03:06:00 ----HDC---- C:\WINDOWS\$NtUninstallKB968816_WM9$
2010-01-24 03:05:54 ----HDC---- C:\WINDOWS\$NtUninstallKB971633_0$
2010-01-24 03:05:45 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$
2010-01-24 03:05:39 ----HDC---- C:\WINDOWS\$NtUninstallKB973869_0$
2010-01-24 03:05:31 ----HDC---- C:\WINDOWS\$NtUninstallKB975025_0$
2010-01-24 03:05:26 ----A---- C:\WINDOWS\system32\wmpns.dll
2010-01-24 03:05:19 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9L$
2010-01-24 03:05:10 ----HDC---- C:\WINDOWS\$NtUninstallKB952004_0$
2010-01-24 03:05:01 ----HDC---- C:\WINDOWS\$NtUninstallKB974571_0$
2010-01-24 03:04:52 ----HDC---- C:\WINDOWS\$NtUninstallKB973507_0$
2010-01-24 03:04:44 ----HDC---- C:\WINDOWS\$NtUninstallKB973687_0$
2010-01-24 03:04:36 ----HDC---- C:\WINDOWS\$NtUninstallKB950762_0$
2010-01-24 03:04:28 ----HDC---- C:\WINDOWS\$NtUninstallKB957097_0$
2010-01-24 03:04:20 ----HDC---- C:\WINDOWS\$NtUninstallKB958687_0$
2010-01-24 03:04:12 ----HDC---- C:\WINDOWS\$NtUninstallKB952287_0$
2010-01-24 03:04:03 ----HDC---- C:\WINDOWS\$NtUninstallKB973354_0$
2010-01-24 03:03:53 ----HDC---- C:\WINDOWS\$NtUninstallKB973904$
2010-01-24 03:03:41 ----HDC---- C:\WINDOWS\$NtUninstallKB967715_0$
2010-01-24 03:03:31 ----HDC---- C:\WINDOWS\$NtUninstallKB951066_0$
2010-01-24 03:03:23 ----HDC---- C:\WINDOWS\$NtUninstallKB974392_0$
2010-01-24 03:03:12 ----HDC---- C:\WINDOWS\$NtUninstallKB951748_0$
2010-01-24 03:03:02 ----HDC---- C:\WINDOWS\$NtUninstallKB970238_0$
2010-01-24 03:02:51 ----HDC---- C:\WINDOWS\$NtUninstallKB971486_0$
2010-01-24 03:02:39 ----D---- C:\WINDOWS\ServicePackFiles
2010-01-24 03:02:37 ----HDC---- C:\WINDOWS\$NtUninstallKB958470$
2010-01-24 03:02:28 ----HDC---- C:\WINDOWS\$NtUninstallKB960803_0$
2010-01-24 03:02:20 ----HDC---- C:\WINDOWS\$NtUninstallKB973815_0$
2010-01-24 03:02:12 ----HDC---- C:\WINDOWS\$NtUninstallKB973525$
2010-01-24 03:02:00 ----HDC---- C:\WINDOWS\$NtUninstallKB971032$
2010-01-24 03:01:49 ----HDC---- C:\WINDOWS\$NtUninstallKB958644_0$
2010-01-24 03:01:40 ----HDC---- C:\WINDOWS\$NtUninstallKB955069_0$
2010-01-24 03:01:31 ----HDC---- C:\WINDOWS\$NtUninstallKB956802_0$
2010-01-24 03:01:17 ----HDC---- C:\WINDOWS\$NtUninstallKB944338-v2$
2010-01-24 03:01:07 ----HDC---- C:\WINDOWS\$NtUninstallKB923561_0$
2010-01-24 03:00:58 ----HDC---- C:\WINDOWS\$NtUninstallKB975467_0$
2010-01-24 03:00:46 ----HDC---- C:\WINDOWS\$NtUninstallKB968389_0$
2010-01-24 03:00:33 ----HDC---- C:\WINDOWS\$NtUninstallKB969947_0$
2010-01-23 16:29:16 ----D---- C:\Documents and Settings\All Users\Application Data\Acronis
2010-01-23 16:24:45 ----D---- C:\Program Files\Common Files\Acronis
2010-01-23 16:24:45 ----D---- C:\Program Files\Acronis
2010-01-23 16:16:47 ----D---- C:\Documents and Settings\Robert Jericho\Application Data\Dell
2010-01-23 16:12:27 ----HDC---- C:\Documents and Settings\All Users\Application Data\{7322D736-AA5F-4DD0-8E33-EA48318CC276}
2010-01-23 16:02:51 ----D---- C:\Documents and Settings\Robert Jericho\Application Data\Mozilla
2010-01-23 16:00:16 ----D---- C:\WINDOWS\CtDrvInstall
2010-01-23 15:58:59 ----D---- C:\Program Files\Common Files\Reallusion
2010-01-23 15:58:32 ----D---- C:\Program Files\Creative
2010-01-23 15:58:09 ----D---- C:\WINDOWS\RegisteredPackages
2010-01-23 15:57:20 ----D---- C:\Program Files\Dell Webcam
2010-01-23 15:57:10 ----D---- C:\Program Files\Creative Live! Cam
2010-01-23 15:51:56 ----D---- C:\Documents and Settings\All Users\Application Data\Vista32
2010-01-23 15:51:55 ----D---- C:\Documents and Settings\All Users\Application Data\XP32
2010-01-23 15:51:55 ----D---- C:\Documents and Settings\All Users\Application Data\Win764
2010-01-23 15:51:55 ----D---- C:\Documents and Settings\All Users\Application Data\Win732
2010-01-23 15:51:55 ----D---- C:\Documents and Settings\All Users\Application Data\Vista64
2010-01-23 15:51:26 ----D---- C:\Program Files\WSED
2010-01-23 15:48:56 ----D---- C:\Program Files\CapsLKNotify
2010-01-23 15:45:25 ----A---- C:\WINDOWS\system32\OA012Srv.exe
2010-01-23 15:45:25 ----A---- C:\WINDOWS\system32\OA012Pin.dll
2010-01-23 15:45:25 ----A---- C:\WINDOWS\OA012Cfg.exe
2010-01-23 15:45:25 ----A---- C:\WINDOWS\CtDrvIns.exe
2010-01-23 15:33:58 ----D---- C:\Program Files\Function Keys
2010-01-23 15:32:57 ----A---- C:\WINDOWS\system32\deploytk.dll
2010-01-23 15:32:35 ----D---- C:\Program Files\Java
2010-01-23 15:32:12 ----D---- C:\Documents and Settings\Robert Jericho\Application Data\Sun
2010-01-23 15:28:05 ----D---- C:\Documents and Settings\All Users\Application Data\SupportSoft
2010-01-23 15:28:00 ----D---- C:\Documents and Settings\All Users\Application Data\PCDr
2010-01-23 15:28:00 ----D---- C:\Documents and Settings\All Users\Application Data\PC-Doctor
2010-01-23 15:27:20 ----D---- C:\Program Files\Dell Support Center
2010-01-23 15:27:19 ----D---- C:\Program Files\Common Files\supportsoft
2010-01-23 15:27:18 ----N---- C:\WINDOWS\system32\xpsp4res.dll
2010-01-23 15:27:18 ----A---- C:\WINDOWS\system32\xpsp3res.dll
2010-01-23 15:26:52 ----N---- C:\WINDOWS\system32\tzchange.exe
2010-01-23 15:14:37 ----HDC---- C:\WINDOWS\$MSI31Uninstall_KB893803v2$
2010-01-23 15:14:07 ----D---- C:\WINDOWS\system32\PreInstall
2010-01-23 15:14:05 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$
2010-01-23 15:14:05 ----HD---- C:\WINDOWS\$hf_mig$
2010-01-23 15:13:16 ----D---- C:\Documents and Settings\All Users\Application Data\Dell
2010-01-23 14:49:35 ----RSD---- C:\WINDOWS\assembly
2010-01-23 14:48:56 ----D---- C:\WINDOWS\Microsoft.NET
2010-01-23 14:44:54 ----N---- C:\WINDOWS\system32\spmsg.dll
2010-01-23 14:44:52 ----HDC---- C:\WINDOWS\$NtUninstallWdf01007$
2010-01-23 14:44:17 ----A---- C:\WINDOWS\system32\EMSC.DLL
2010-01-23 14:43:30 ----D---- C:\WINDOWS\Downloaded Installations
2010-01-23 14:41:58 ----A---- C:\WINDOWS\system32\btw_ci.dll
2010-01-23 14:41:51 ----D---- C:\Program Files\WIDCOMM
2010-01-23 14:24:10 ----D---- C:\WINDOWS\system32\RTCOM
2010-01-23 14:23:23 ----A---- C:\WINDOWS\system32\spupdsvc.exe
2010-01-23 14:23:21 ----HDC---- C:\WINDOWS\$NtUninstallKB888111WXPSP2$
2010-01-23 14:23:17 ----A---- C:\WINDOWS\vncutil.exe
2010-01-23 14:23:17 ----A---- C:\WINDOWS\SOUNDMAN.EXE
2010-01-23 14:23:17 ----A---- C:\WINDOWS\SkyTel.exe
2010-01-23 14:23:17 ----A---- C:\WINDOWS\RtlUpd.exe
2010-01-23 14:23:17 ----A---- C:\WINDOWS\RTLCPL.EXE
2010-01-23 14:23:16 ----A---- C:\WINDOWS\system32\RtkCoInstXP.dll
2010-01-23 14:23:16 ----A---- C:\WINDOWS\RtkAudioService.exe
2010-01-23 14:23:15 ----A---- C:\WINDOWS\RTHDCPL.EXE
2010-01-23 14:23:15 ----A---- C:\WINDOWS\MicCal.exe
2010-01-23 14:23:14 ----A---- C:\WINDOWS\ALCWZRD.EXE
2010-01-23 14:23:14 ----A---- C:\WINDOWS\ALCMTR.EXE
2010-01-23 14:23:06 ----A---- C:\WINDOWS\RtlExUpd.dll
2010-01-23 14:23:01 ----D---- C:\Program Files\Common Files\InstallShield
2010-01-23 14:21:26 ----A---- C:\WINDOWS\system32\RTS5121icon.dll
2010-01-23 14:21:26 ----A---- C:\WINDOWS\system32\rts5121.dll
2010-01-23 14:20:35 ----A---- C:\WINDOWS\system32\RtNicProp32.dll
2010-01-23 14:20:34 ----HD---- C:\Program Files\InstallShield Installation Information
2010-01-23 14:20:34 ----D---- C:\WINDOWS\OPTIONS
2010-01-23 14:20:34 ----D---- C:\Program Files\Realtek
2010-01-23 01:17:42 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2010-01-23 01:14:13 ----A---- C:\WINDOWS\system32\BCMLogon.dll
2010-01-23 01:14:13 ----A---- C:\WINDOWS\bcm63.tmp
2010-01-23 01:14:11 ----A---- C:\WINDOWS\system32\vcredist_x86.exe
2010-01-23 01:14:11 ----A---- C:\WINDOWS\system32\vcredist_x86.bat
2010-01-23 01:14:11 ----A---- C:\WINDOWS\system32\preflib.dll
2010-01-23 01:14:11 ----A---- C:\WINDOWS\system32\bcmwlu00.exe
2010-01-23 01:14:11 ----A---- C:\WINDOWS\bcm3B.tmp
2010-01-23 01:14:10 ----A---- C:\WINDOWS\system32\WLTRYSVC.EXE
2010-01-23 01:14:10 ----A---- C:\WINDOWS\system32\wltrynt.dll
2010-01-23 01:14:10 ----A---- C:\WINDOWS\system32\WLTRAY.EXE
2010-01-23 01:14:10 ----A---- C:\WINDOWS\system32\WLBCGCBPRO731.DLL
2010-01-23 01:14:10 ----A---- C:\WINDOWS\system32\BCMWLTRY.EXE
2010-01-23 01:14:10 ----A---- C:\WINDOWS\system32\bcmwlpkt.dll
2010-01-23 01:14:10 ----A---- C:\WINDOWS\system32\bcmwlapi.dll
2010-01-23 01:14:10 ----A---- C:\WINDOWS\system32\bcm1xsup.dll
2010-01-23 01:14:01 ----D---- C:\Documents and Settings\Robert Jericho\Application Data\InstallShield
2010-01-23 01:05:07 ----D---- C:\WINDOWS\system32\Lang
2010-01-23 01:05:07 ----A---- C:\WINDOWS\system32\lpgun.ini
2010-01-23 01:05:07 ----A---- C:\WINDOWS\system32\lpgun.exe
2010-01-23 01:05:07 ----A---- C:\WINDOWS\system32\difxapi.dll
2010-01-23 01:04:46 ----A---- C:\WINDOWS\system32\PersistenceThread.exe
2010-01-23 01:04:46 ----A---- C:\WINDOWS\system32\igxprd32.dll
2010-01-23 01:04:46 ----A---- C:\WINDOWS\system32\igfxtray.exe
2010-01-23 01:04:46 ----A---- C:\WINDOWS\system32\igfxres.dll
2010-01-23 01:04:46 ----A---- C:\WINDOWS\system32\igfxext.exe
2010-01-23 01:04:45 ----A---- C:\WINDOWS\system32\igxpdd32.dll
2010-01-23 01:04:45 ----A---- C:\WINDOWS\system32\igfxsrvc.exe
2010-01-23 01:04:45 ----A---- C:\WINDOWS\system32\igfxsrvc.dll
2010-01-23 01:04:45 ----A---- C:\WINDOWS\system32\igfxextps.dll
2010-01-23 01:04:45 ----A---- C:\WINDOWS\system32\igfxcfg.exe
2010-01-23 01:04:45 ----A---- C:\WINDOWS\system32\hkcmd.exe
2010-01-23 01:04:45 ----A---- C:\WINDOWS\system32\hccutils.dll
2010-01-23 01:04:44 ----A---- C:\WINDOWS\system32\igfxress.dll
2010-01-23 01:04:44 ----A---- C:\WINDOWS\system32\igfxpph.dll
2010-01-23 01:04:44 ----A---- C:\WINDOWS\system32\igfxdo.dll
2010-01-23 01:01:05 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-01-23 01:01:01 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-01-23 01:01:01 ----D---- C:\Program Files\Intel
2010-01-23 01:01:01 ----A---- C:\WINDOWS\system32\CSVer.dll
2010-01-23 01:00:33 ----D---- C:\Intel
2010-01-23 00:54:21 ----D---- C:\WINDOWS\system32\vmm32
2010-01-23 00:54:21 ----D---- C:\Program Files\Dell
2010-01-23 00:28:29 ----D---- C:\Documents and Settings\Robert Jericho\Application Data\Identities
2010-01-23 00:28:26 ----HD---- C:\Program Files\Uninstall Information
2010-01-23 00:28:18 ----SD---- C:\Documents and Settings\Robert Jericho\Application Data\Microsoft
2010-01-23 00:28:18 ----ASH---- C:\Documents and Settings\Robert Jericho\Application Data\desktop.ini
2010-01-23 00:26:13 ----D---- C:\WINDOWS\SoftwareDistribution
2010-01-23 00:26:11 ----SD---- C:\WINDOWS\system32\Microsoft
2010-01-23 00:26:11 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-01-23 00:19:10 ----D---- C:\WINDOWS\system32\xircom
2010-01-23 00:19:10 ----D---- C:\Program Files\xerox
2010-01-23 00:19:10 ----D---- C:\Program Files\microsoft frontpage
2010-01-23 00:18:34 ----D---- C:\DELL
2010-01-23 00:18:23 ----A---- C:\WINDOWS\control.ini
2010-01-23 00:18:23 ----A---- C:\AUTOEXEC.BAT
2010-01-23 00:18:09 ----A---- C:\WINDOWS\OEWABLog.txt
2010-01-23 00:18:04 ----A---- C:\WINDOWS\system32\mapi32.dll
2010-01-23 00:16:46 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-01-23 00:16:46 ----RD---- C:\WINDOWS\Offline Web Pages
2010-01-23 00:16:46 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest
2010-01-23 00:16:37 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest
2010-01-23 00:16:30 ----HD---- C:\Program Files\WindowsUpdate
2010-01-23 00:16:03 ----D---- C:\WINDOWS\system32\DirectX
2010-01-23 00:15:36 ----A---- C:\WINDOWS\system32\atrace.dll
2010-01-23 00:15:33 ----A---- C:\WINDOWS\system32\desktop.ini
2010-01-23 00:15:33 ----A---- C:\WINDOWS\desktop.ini
2010-01-23 00:15:24 ----A---- C:\WINDOWS\system32\nmevtmsg.dll
2010-01-23 00:15:22 ----A---- C:\WINDOWS\system32\acctres.dll
2010-01-23 00:15:21 ----D---- C:\Program Files\Common Files\Services
2010-01-23 00:15:18 ----SD---- C:\WINDOWS\Tasks
2010-01-23 00:15:18 ----A---- C:\WINDOWS\system32\icfgnt5.dll
2010-01-23 00:15:16 ----D---- C:\Program Files\Common Files\MSSoap
2010-01-23 00:15:12 ----D---- C:\WINDOWS\srchasst
2010-01-23 00:15:11 ----D---- C:\WINDOWS\system32\Macromed
2010-01-23 00:15:07 ----A---- C:\WINDOWS\system32\wuweb.dll
2010-01-23 00:15:07 ----A---- C:\WINDOWS\system32\wups.dll
2010-01-23 00:15:07 ----A---- C:\WINDOWS\system32\wucltui.dll
2010-01-23 00:15:07 ----A---- C:\WINDOWS\system32\wuauserv.dll
2010-01-23 00:15:07 ----A---- C:\WINDOWS\system32\wuaueng1.dll
2010-01-23 00:15:07 ----A---- C:\WINDOWS\system32\wuaueng.dll.wusetup.134890.bak
2010-01-23 00:15:07 ----A---- C:\WINDOWS\system32\wuaueng.dll
2010-01-23 00:15:07 ----A---- C:\WINDOWS\system32\wuaucpl.cpl.wusetup.134671.bak
2010-01-23 00:15:06 ----N---- C:\WINDOWS\system32\wuauclt.exe
2010-01-23 00:15:06 ----N---- C:\WINDOWS\system32\qmgr.dll
2010-01-23 00:15:06 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2010-01-23 00:15:06 ----A---- C:\WINDOWS\system32\wuauclt.exe.wusetup.134406.bak
2010-01-23 00:15:06 ----A---- C:\WINDOWS\system32\wuapi.dll
2010-01-23 00:15:06 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
2010-01-23 00:15:06 ----A---- C:\WINDOWS\system32\bitsprx3.dll
2010-01-23 00:15:06 ----A---- C:\WINDOWS\system32\bitsprx2.dll
2010-01-23 00:15:01 ----D---- C:\Program Files\Movie Maker
2010-01-23 00:14:56 ----A---- C:\WINDOWS\system32\safrslv.dll
2010-01-23 00:14:56 ----A---- C:\WINDOWS\system32\safrdm.dll
2010-01-23 00:14:56 ----A---- C:\WINDOWS\system32\safrcdlg.dll
2010-01-23 00:14:56 ----A---- C:\WINDOWS\system32\racpldlg.dll
2010-01-23 00:14:52 ----A---- C:\WINDOWS\system32\fltmc.exe
2010-01-23 00:14:52 ----A---- C:\WINDOWS\system32\fltlib.dll
2010-01-23 00:14:51 ----N---- C:\WINDOWS\system32\srsvc.dll
2010-01-23 00:14:51 ----D---- C:\WINDOWS\system32\Restore
2010-01-23 00:14:51 ----A---- C:\WINDOWS\system32\srrstr.dll
2010-01-23 00:14:51 ----A---- C:\WINDOWS\system32\srclient.dll
2010-01-23 00:14:50 ----A---- C:\WINDOWS\system32\nmmkcert.dll
2010-01-23 00:14:50 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2010-01-23 00:14:50 ----A---- C:\WINDOWS\system32\mnmdd.dll
2010-01-23 00:14:50 ----A---- C:\WINDOWS\system32\isrdbg32.dll
2010-01-23 00:14:50 ----A---- C:\WINDOWS\system32\ils.dll
2010-01-23 00:14:49 ----A---- C:\WINDOWS\system32\msconf.dll
2010-01-23 00:14:46 ----D---- C:\Program Files\NetMeeting
2010-01-23 00:14:46 ----A---- C:\WINDOWS\system32\msoert2.dll
2010-01-23 00:14:46 ----A---- C:\WINDOWS\system32\msoeacct.dll
2010-01-23 00:14:45 ----A---- C:\WINDOWS\system32\inetres.dll
2010-01-23 00:14:45 ----A---- C:\WINDOWS\system32\inetcomm.dll
2010-01-23 00:14:43 ----N---- C:\WINDOWS\system32\schedsvc.dll
2010-01-23 00:14:43 ----D---- C:\Program Files\Outlook Express
2010-01-23 00:14:42 ----A---- C:\WINDOWS\system32\mstinit.exe
2010-01-23 00:14:42 ----A---- C:\WINDOWS\system32\mstask.dll
2010-01-23 00:14:42 ----A---- C:\WINDOWS\system32\icwphbk.dll
2010-01-23 00:14:42 ----A---- C:\WINDOWS\system32\icwdial.dll
2010-01-23 00:14:41 ----A---- C:\WINDOWS\system32\isign32.dll
2010-01-23 00:14:41 ----A---- C:\WINDOWS\system32\inetcfg.dll
2010-01-23 00:14:34 ----D---- C:\Program Files\Common Files\System
2010-01-23 00:14:28 ----D---- C:\Program Files\Internet Explorer
2010-01-23 00:13:41 ----D---- C:\Program Files\ComPlus Applications
2010-01-23 00:13:39 ----A---- C:\WINDOWS\vbaddin.ini
2010-01-23 00:13:39 ----A---- C:\WINDOWS\vb.ini
2010-01-23 00:13:34 ----D---- C:\WINDOWS\Registration
2010-01-23 00:13:26 ----D---- C:\Program Files\Windows Media Player
2010-01-23 00:13:26 ----D---- C:\Program Files\Online Services
2010-01-23 00:13:19 ----D---- C:\Program Files\Messenger
2010-01-23 00:13:14 ----D---- C:\Program Files\MSN Gaming Zone
2010-01-23 00:13:14 ----A---- C:\WINDOWS\system32\write.exe
2010-01-23 00:13:01 ----A---- C:\WINDOWS\system32\sndvol32.exe
2010-01-23 00:13:01 ----A---- C:\WINDOWS\system32\hticons.dll
2010-01-23 00:13:00 ----A---- C:\WINDOWS\system32\winchat.exe
2010-01-23 00:13:00 ----A---- C:\WINDOWS\system32\avwav.dll
2010-01-23 00:13:00 ----A---- C:\WINDOWS\system32\avtapi.dll
2010-01-23 00:13:00 ----A---- C:\WINDOWS\system32\avmeter.dll
2010-01-23 00:12:50 ----A---- C:\WINDOWS\system32\getuname.dll
2010-01-23 00:12:50 ----A---- C:\WINDOWS\system32\charmap.exe
2010-01-23 00:12:49 ----A---- C:\WINDOWS\system32\winmine.exe
2010-01-23 00:12:49 ----A---- C:\WINDOWS\system32\sol.exe
2010-01-23 00:12:49 ----A---- C:\WINDOWS\system32\calc.exe
2010-01-23 00:12:48 ----A---- C:\WINDOWS\system32\usrlogon.cmd
2010-01-23 00:12:48 ----A---- C:\WINDOWS\system32\reset.exe
2010-01-23 00:12:48 ----A---- C:\WINDOWS\system32\mshearts.exe
2010-01-23 00:12:48 ----A---- C:\WINDOWS\system32\freecell.exe
2010-01-23 00:12:47 ----A---- C:\WINDOWS\system32\tsshutdn.exe
2010-01-23 00:12:47 ----A---- C:\WINDOWS\system32\tslabels.ini
2010-01-23 00:12:47 ----A---- C:\WINDOWS\system32\tskill.exe
2010-01-23 00:12:47 ----A---- C:\WINDOWS\system32\tsdiscon.exe
2010-01-23 00:12:47 ----A---- C:\WINDOWS\system32\tscon.exe
2010-01-23 00:12:47 ----A---- C:\WINDOWS\system32\shadow.exe
2010-01-23 00:12:47 ----A---- C:\WINDOWS\system32\rwinsta.exe
2010-01-23 00:12:47 ----A---- C:\WINDOWS\system32\regini.exe
2010-01-23 00:12:47 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
2010-01-23 00:12:47 ----A---- C:\WINDOWS\system32\qwinsta.exe
2010-01-23 00:12:46 ----A---- C:\WINDOWS\system32\qappsrv.exe
2010-01-23 00:12:46 ----A---- C:\WINDOWS\system32\msg.exe
2010-01-23 00:12:46 ----A---- C:\WINDOWS\system32\msdtcprf.ini
2010-01-23 00:12:46 ----A---- C:\WINDOWS\system32\logoff.exe
2010-01-23 00:12:46 ----A---- C:\WINDOWS\system32\cdmodem.dll
2010-01-23 00:12:45 ----A---- C:\WINDOWS\system32\mtxlegih.dll
2010-01-23 00:12:45 ----A---- C:\WINDOWS\system32\mtxex.dll
2010-01-23 00:12:45 ----A---- C:\WINDOWS\system32\mtxdm.dll
2010-01-23 00:12:45 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2010-01-23 00:12:44 ----A---- C:\WINDOWS\system32\stclient.dll
2010-01-23 00:12:44 ----A---- C:\WINDOWS\system32\comsnap.dll
2010-01-23 00:12:44 ----A---- C:\WINDOWS\system32\comrepl.dll
2010-01-23 00:12:44 ----A---- C:\WINDOWS\system32\comaddin.dll
2010-01-23 00:12:37 ----A---- C:\WINDOWS\system32\wmimgmt.msc
2010-01-23 00:12:26 ----D---- C:\Program Files\MSN
2010-01-23 00:12:25 ----A---- C:\WINDOWS\system32\sndrec32.exe
2010-01-23 00:12:25 ----A---- C:\WINDOWS\system32\accwiz.exe
2010-01-23 00:12:24 ----D---- C:\Program Files\Windows NT
2010-01-23 00:12:24 ----A---- C:\WINDOWS\system32\mplay32.exe
2010-01-23 00:12:24 ----A---- C:\WINDOWS\system32\hypertrm.dll
2010-01-23 00:12:23 ----A---- C:\WINDOWS\system32\spider.exe
2010-01-23 00:12:23 ----A---- C:\WINDOWS\system32\mspaint.exe
2010-01-23 00:12:23 ----A---- C:\WINDOWS\system32\clipbrd.exe
2010-01-23 00:12:22 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
2010-01-23 00:12:22 ----A---- C:\WINDOWS\system32\mstscax.dll
2010-01-23 00:12:22 ----A---- C:\WINDOWS\system32\mstsc.exe
2010-01-23 00:12:21 ----A---- C:\WINDOWS\system32\tscupgrd.exe
2010-01-23 00:12:21 ----A---- C:\WINDOWS\system32\sessmgr.exe
2010-01-23 00:12:21 ----A---- C:\WINDOWS\system32\remotepg.dll
2010-01-23 00:12:21 ----A---- C:\WINDOWS\system32\rdshost.exe
2010-01-23 00:12:21 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2010-01-23 00:12:21 ----A---- C:\WINDOWS\system32\rdchost.dll
2010-01-23 00:12:20 ----N---- C:\WINDOWS\system32\termsrv.dll
2010-01-23 00:12:20 ----A---- C:\WINDOWS\system32\rdpwsx.dll
2010-01-23 00:12:20 ----A---- C:\WINDOWS\system32\rdpsnd.dll
2010-01-23 00:12:20 ----A---- C:\WINDOWS\system32\rdpclip.exe
2010-01-23 00:12:20 ----A---- C:\WINDOWS\system32\qprocess.exe
2010-01-23 00:12:20 ----A---- C:\WINDOWS\system32\icaapi.dll
2010-01-23 00:12:20 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2010-01-23 00:12:19 ----D---- C:\WINDOWS\system32\MsDtc
2010-01-23 00:12:19 ----A---- C:\WINDOWS\system32\mtxoci.dll
2010-01-23 00:12:19 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
2010-01-23 00:12:19 ----A---- C:\WINDOWS\system32\msdtctm.dll
2010-01-23 00:12:19 ----A---- C:\WINDOWS\system32\msdtcprx.dll
2010-01-23 00:12:18 ----A---- C:\WINDOWS\system32\xolehlp.dll
2010-01-23 00:12:18 ----A---- C:\WINDOWS\system32\msdtclog.dll
2010-01-23 00:12:18 ----A---- C:\WINDOWS\system32\msdtc.exe
2010-01-23 00:12:17 ----D---- C:\WINDOWS\system32\Com
2010-01-23 00:12:17 ----A---- C:\WINDOWS\system32\colbact.dll
2010-01-23 00:12:17 ----A---- C:\WINDOWS\system32\clbcatex.dll
2010-01-23 00:12:17 ----A---- C:\WINDOWS\system32\catsrvut.dll
2010-01-23 00:12:17 ----A---- C:\WINDOWS\system32\catsrvps.dll
2010-01-23 00:12:17 ----A---- C:\WINDOWS\system32\catsrv.dll
2010-01-23 00:12:16 ----A---- C:\WINDOWS\system32\comuid.dll
2010-01-23 00:12:16 ----A---- C:\WINDOWS\system32\comsvcs.dll
2010-01-23 00:12:16 ----A---- C:\WINDOWS\system32\clbcatq.dll
2010-01-23 00:12:08 ----A---- C:\WINDOWS\system32\servdeps.dll
2010-01-23 00:12:08 ----A---- C:\WINDOWS\system32\mmfutil.dll
2010-01-23 00:12:08 ----A---- C:\WINDOWS\system32\licwmi.dll
2010-01-23 00:12:08 ----A---- C:\WINDOWS\system32\cmprops.dll

======List of files/folders modified in the last 1 months======

2010-02-22 08:00:49 ----D---- C:\WINDOWS\system32\CatRoot2
2010-02-22 07:55:16 ----RD---- C:\Program Files
2010-02-22 07:45:19 ----D---- C:\WINDOWS
2010-02-22 02:52:10 ----D---- C:\WINDOWS\system32
2010-02-21 15:10:54 ----HD---- C:\WINDOWS\inf
2010-02-20 13:57:14 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-02-20 13:57:08 ----D---- C:\WINDOWS\system32\drivers
2010-02-20 12:58:50 ----SHD---- C:\WINDOWS\Installer
2010-02-17 17:21:29 ----D---- C:\Program Files\Common Files
2010-02-13 08:57:24 ----D---- C:\WINDOWS\WinSxS
2010-02-12 17:35:30 ----A---- C:\WINDOWS\system.ini
2010-02-12 17:31:57 ----D---- C:\WINDOWS\AppPatch
2010-02-12 17:24:39 ----RASH---- C:\boot.ini
2010-02-10 03:08:27 ----A---- C:\WINDOWS\imsins.BAK
2010-02-05 03:03:37 ----RSD---- C:\WINDOWS\Fonts
2010-02-05 03:03:03 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-02-01 03:00:39 ----D---- C:\WINDOWS\system32\CatRoot
2010-01-31 20:16:39 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-01-31 20:14:05 ----A---- C:\WINDOWS\setuplog.txt
2010-01-31 20:13:16 ----D---- C:\WINDOWS\system32\Setup
2010-01-31 20:13:15 ----D---- C:\WINDOWS\system32\wbem
2010-01-31 20:12:31 ----D---- C:\WINDOWS\security
2010-01-31 19:52:42 ----D---- C:\WINDOWS\system32\inetsrv
2010-01-31 19:52:42 ----D---- C:\WINDOWS\ime
2010-01-31 19:52:42 ----D---- C:\WINDOWS\Help
2010-01-31 19:52:22 ----D---- C:\WINDOWS\system32\usmt
2010-01-31 19:52:18 ----D---- C:\WINDOWS\PeerNet
2010-01-31 19:47:35 ----D---- C:\WINDOWS\system32\npp
2010-01-31 19:47:34 ----D---- C:\WINDOWS\mui
2010-01-31 19:47:33 ----D---- C:\WINDOWS\msagent
2010-01-31 19:46:56 ----D---- C:\WINDOWS\system32\oobe
2010-01-31 19:46:52 ----D---- C:\WINDOWS\system
2010-01-31 19:36:48 ----D---- C:\WINDOWS\ehome
2010-01-25 03:08:44 ----D---- C:\WINDOWS\system32\spool
2010-01-25 03:05:52 ----D---- C:\WINDOWS\system32\mui
2010-01-24 11:22:11 ----D---- C:\WINDOWS\Media
2010-01-24 10:25:16 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2010-01-24 10:11:17 ----D---- C:\WINDOWS\Debug
2010-01-23 00:28:17 ----D---- C:\Documents and Settings
2010-01-23 00:26:14 ----SHD---- C:\System Volume Information
2010-01-23 00:25:27 ----D---- C:\WINDOWS\system32\config
2010-01-23 00:19:09 ----D---- C:\WINDOWS\repair
2010-01-23 00:18:23 ----A---- C:\WINDOWS\win.ini
2010-01-23 00:18:04 ----A---- C:\WINDOWS\ODBCINST.INI
2010-01-23 00:17:44 ----D---- C:\WINDOWS\system32\ias
2010-01-23 00:16:50 ----RD---- C:\WINDOWS\Web
2010-01-23 00:14:56 ----D---- C:\WINDOWS\pchealth
2010-01-23 00:13:09 ----D---- C:\WINDOWS\Cursors

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys []
R1 sbaphd;sbaphd; C:\WINDOWS\system32\drivers\sbaphd.sys [2009-05-13 13360]
R1 SBRE;SBRE; \??\C:\WINDOWS\system32\drivers\SBREdrv.sys []
R1 sbtis;sbtis; C:\WINDOWS\system32\drivers\sbtis.sys [2008-10-09 202928]
R2 sbapifs;sbapifs; C:\WINDOWS\system32\drivers\sbapifs.sys [2009-08-10 69936]
R2 tifsfilter;Acronis True Image FS Filter; C:\WINDOWS\system32\DRIVERS\tifsfilt.sys [2010-01-23 39264]
R3 BCM43XX;Dell Wireless WLAN Card Driver; C:\WINDOWS\system32\DRIVERS\bcmwl5.sys [2008-11-26 1391104]
R3 btaudio;Bluetooth Audio Device; C:\WINDOWS\system32\drivers\btaudio.sys [2008-05-30 534568]
R3 BTDriver;Bluetooth Virtual Communications Driver; C:\WINDOWS\system32\DRIVERS\btport.sys [2008-02-04 37160]
R3 BTKRNL;Bluetooth Bus Enumerator; C:\WINDOWS\system32\DRIVERS\btkrnl.sys [2008-09-30 991656]
R3 BTWDNDIS;Bluetooth LAN Access Server; C:\WINDOWS\system32\DRIVERS\btwdndis.sys [2008-07-24 156816]
R3 btwhid;btwhid; C:\WINDOWS\system32\DRIVERS\btwhid.sys [2008-03-10 57384]
R3 btwmodem;Bluetooth Modem; C:\WINDOWS\system32\DRIVERS\btwmodem.sys [2008-02-04 37032]
R3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\WINDOWS\System32\Drivers\btwusb.sys [2008-09-26 47272]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2008-04-13 13952]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver; C:\WINDOWS\system32\DRIVERS\CtClsFlt.sys [2008-10-28 135936]
R3 ETD;ELAN PS/2 Port Input Device; C:\WINDOWS\system32\DRIVERS\ETD.sys [2009-03-30 129024]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 igd;igd; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2009-03-18 5088896]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-12-11 4959232]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI Service; C:\WINDOWS\system32\drivers\IntcHdmi.sys [2008-07-30 110080]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 OA012Afx;Provides a software interface to control audio effects of OA012 camera.; \??\C:\WINDOWS\system32\Drivers\OA012Afx.sys []
R3 OA012Ufd;Creative Camera OA012 Upper Filter Driver; C:\WINDOWS\system32\DRIVERS\OA012Ufd.sys [2008-11-26 133472]
R3 OA012Vid;Creative Camera OA012 Function Driver; C:\WINDOWS\system32\DRIVERS\OA012Vid.sys [2009-01-14 271328]
R3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader; C:\WINDOWS\System32\Drivers\RTS5121.sys [2008-08-26 157696]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2008-09-25 115328]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2007-06-27 501640]
S3 catchme;catchme; \??\C:\DOCUME~1\ROBERT~1\LOCALS~1\Temp\catchme.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
S3 Ktp;Elantech Smart-Pad; C:\WINDOWS\system32\DRIVERS\ETD.sys [2009-03-30 129024]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 Rts516xIR;Realtek IR Driver; C:\WINDOWS\system32\DRIVERS\Rts516xIR.sys []
S3 SASENUM;SASENUM; \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys [2009-11-12 7168]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 USBCCID;Realtek Smartcard Reader Driver; C:\WINDOWS\system32\DRIVERS\Rts5161ccid.sys []
S3 usbstor;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 usbvideo;USB Video Device (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-13 121984]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AcrSch2Svc;Acronis Scheduler2 Service; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe [2006-10-16 230944]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-08-28 144672]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe [2008-09-29 346720]
R2 DockLoginService;Dock Login Service; C:\Program Files\Dell\DellDock\DockLogin.exe [2009-06-09 155648]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-02-12 153376]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 NMSAccessU;NMSAccessU; C:\Program Files\CDBurnerXP\NMSAccessU.exe [2009-11-12 71096]
R2 SBAMSvc;VIPRE Antivirus + Antispyware; C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe [2010-01-04 1012080]
R2 sprtsvc_DellSupportCenter;SupportSoft Sprocket Service (DellSupportCenter); C:\Program Files\Dell Support Center\bin\sprtsvc.exe [2008-10-04 201968]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-10-11 38912]
R2 wltrysvc;Dell Wireless WLAN Tray Service; C:\WINDOWS\System32\WLTRYSVC.EXE [2008-11-26 24576]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2009-11-12 545568]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2010-01-24 69632]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 GoToAssist;GoToAssist; C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe [2010-02-20 16680]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------


ComboFix is in the following post.
rjj76
Regular Member
 
Posts: 16
Joined: February 15th, 2010, 4:56 pm

Re: Search Redirect Malware

Unread postby rjj76 » February 22nd, 2010, 10:26 am

OLD ComboFix (lots has been done since)

ComboFix 10-02-12.01 - Robert Jericho 02/12/2010 17:28:03.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.546 [GMT -6:00]
Running from: c:\documents and settings\Robert Jericho\Desktop\ComboFix.exe
AV: Sunbelt VIPRE *On-access scanning disabled* (Updated) {964FCE60-0B18-4D30-ADD6-EB178909041C}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk

.
((((((((((((((((((((((((( Files Created from 2010-01-12 to 2010-02-12 )))))))))))))))))))))))))))))))
.

2010-02-12 17:38 . 2010-02-12 17:38 52224 ----a-w- c:\documents and settings\Robert Jericho\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-02-12 17:38 . 2010-02-12 17:38 117760 ----a-w- c:\documents and settings\Robert Jericho\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-02-12 17:38 . 2010-02-12 17:38 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-02-12 17:37 . 2010-02-12 17:37 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-02-12 17:37 . 2010-02-12 17:37 -------- d-----w- c:\documents and settings\Robert Jericho\Application Data\SUPERAntiSpyware.com
2010-02-12 17:37 . 2010-02-12 17:37 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-02-12 14:31 . 2010-02-12 14:31 -------- d-----w- c:\documents and settings\Robert Jericho\Application Data\Malwarebytes
2010-02-12 14:31 . 2010-01-07 22:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-12 14:31 . 2010-02-12 14:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-02-12 14:31 . 2010-02-12 14:31 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-12 14:31 . 2010-01-07 22:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-02-11 02:48 . 2010-02-11 02:48 -------- d-----w- c:\documents and settings\Robert Jericho\Local Settings\Application Data\Temp
2010-02-11 00:33 . 2010-02-11 00:33 -------- d-----w- c:\windows\Sun
2010-02-05 06:41 . 2009-08-07 01:23 274288 ----a-w- c:\windows\system32\mucltui.dll
2010-02-05 06:41 . 2009-08-07 01:23 215920 ----a-w- c:\windows\system32\muweb.dll
2010-02-05 05:24 . 2010-02-12 15:02 -------- d-----w- c:\documents and settings\Robert Jericho\Application Data\AdobeUM
2010-02-05 02:40 . 2010-02-05 02:40 -------- d-----w- c:\program files\Microsoft Silverlight
2010-02-04 04:22 . 2010-02-04 04:22 -------- d-----w- c:\documents and settings\Robert Jericho\Local Settings\Application Data\Identities
2010-02-01 01:52 . 2010-02-01 01:52 -------- d-----w- c:\windows\system32\scripting
2010-02-01 01:52 . 2010-02-01 01:52 -------- d-----w- c:\windows\l2schemas
2010-02-01 01:52 . 2010-02-01 01:52 -------- d-----w- c:\windows\system32\en
2010-02-01 01:52 . 2010-02-01 01:52 -------- d-----w- c:\windows\system32\bits
2010-01-27 03:55 . 2010-01-27 03:55 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2010-01-26 00:55 . 2010-02-12 18:08 -------- d-----w- c:\documents and settings\Robert Jericho\Application Data\vlc
2010-01-26 00:53 . 2010-01-26 00:53 -------- d-----w- c:\program files\VideoLAN
2010-01-25 22:30 . 2010-01-25 22:30 -------- d-----w- c:\program files\MSXML 4.0
2010-01-25 09:33 . 2010-01-25 09:33 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\SupportSoft
2010-01-25 09:09 . 2010-01-25 09:09 -------- d-----w- c:\windows\system32\XPSViewer
2010-01-25 09:09 . 2010-01-25 09:09 -------- d-----w- c:\program files\MSBuild
2010-01-25 09:09 . 2010-01-25 09:09 -------- d-----w- c:\program files\Reference Assemblies
2010-01-25 09:08 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2010-01-25 09:08 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-01-25 09:08 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-01-25 09:08 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2010-01-25 09:08 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2010-01-25 09:08 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2010-01-25 09:08 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2010-01-25 09:08 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-01-25 09:08 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2010-01-25 09:08 . 2010-01-25 09:08 -------- d-----w- C:\a3eb26cc20e43dea7a4c6a64
2010-01-25 02:10 . 2010-01-25 02:10 -------- d--h--w- c:\windows\system32\GroupPolicy
2010-01-24 23:59 . 2010-01-24 23:59 -------- d-----w- c:\program files\ShopSafe
2010-01-24 23:39 . 2010-01-24 23:39 -------- d-----w- c:\program files\Citrix
2010-01-24 23:18 . 2010-01-24 23:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Adobe Systems
2010-01-24 23:18 . 2010-01-27 04:14 -------- d-----w- c:\documents and settings\Robert Jericho\Local Settings\Application Data\Adobe
2010-01-24 23:18 . 2010-01-24 23:18 -------- d-----w- c:\program files\Common Files\Adobe Systems Shared
2010-01-24 23:17 . 2010-02-11 03:26 -------- d-----w- c:\program files\Common Files\Adobe
2010-01-24 23:07 . 2006-01-30 14:32 5632 ----a-w- c:\windows\system32\pxc25pm.dll
2010-01-24 23:07 . 2004-12-07 12:11 258352 ----a-w- c:\windows\system32\unicows.dll
2010-01-24 23:05 . 2010-01-24 23:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Mindjet
2010-01-24 23:05 . 2010-01-24 23:05 -------- d-----w- c:\program files\Mindjet
2010-01-24 23:04 . 2010-01-24 23:04 -------- d-----w- c:\documents and settings\Robert Jericho\Local Settings\Application Data\{18494770-F03A-4F99-93F7-AE7D4080F8F8}
2010-01-24 23:04 . 2010-01-24 23:04 -------- d-----w- c:\program files\MSXML 6.0
2010-01-24 21:00 . 2009-03-18 13:01 65536 ----a-w- c:\windows\system32\igdlogin.dll
2010-01-24 20:51 . 2010-01-24 20:50 737280 ----a-w- c:\windows\iun6002.exe
2010-01-24 20:51 . 2010-01-24 20:51 -------- d-----w- c:\program files\Codec Pack - All In 1
2010-01-24 20:34 . 2010-01-24 20:34 -------- d-----w- c:\documents and settings\Robert Jericho\Application Data\Media Player Classic
2010-01-24 20:31 . 2010-01-24 20:31 -------- d-----w- c:\program files\Real Alternative
2010-01-24 20:31 . 2010-01-24 20:31 -------- d-----w- c:\documents and settings\Robert Jericho\Local Settings\Application Data\Real
2010-01-24 20:31 . 2010-01-24 20:31 -------- d-----w- c:\program files\QuickTime Alternative
2010-01-24 20:30 . 2010-01-24 21:02 -------- d-----w- c:\program files\All in 1 Media Codecs Pack
2010-01-24 19:42 . 2008-07-30 15:44 110080 ----a-w- c:\windows\system32\drivers\IntcHdmi.sys
2010-01-24 19:30 . 2010-01-24 19:31 -------- d-----w- c:\program files\Duplicate Music Files Finder
2010-01-24 19:16 . 2010-01-24 19:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Vistanita
2010-01-24 18:59 . 2009-12-16 22:05 43008 ----a-w- c:\documents and settings\Robert Jericho\Application Data\Mozilla\Firefox\Profiles\vubdatlo.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2010-01-24 18:59 . 2009-12-16 22:05 471040 ----a-w- c:\documents and settings\Robert Jericho\Application Data\Mozilla\Firefox\Profiles\vubdatlo.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\DictionaryCompressionFF.dll
2010-01-24 18:59 . 2009-12-16 22:05 347136 ----a-w- c:\documents and settings\Robert Jericho\Application Data\Mozilla\Firefox\Profiles\vubdatlo.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2010-01-24 18:59 . 2009-12-16 22:05 340992 ----a-w- c:\documents and settings\Robert Jericho\Application Data\Mozilla\Firefox\Profiles\vubdatlo.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2010-01-24 18:59 . 2009-12-16 22:05 1452032 ----a-w- c:\documents and settings\Robert Jericho\Application Data\Mozilla\Firefox\Profiles\vubdatlo.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
2010-01-24 18:10 . 2010-02-11 02:48 -------- d-----w- c:\documents and settings\Robert Jericho\Local Settings\Application Data\Google
2010-01-24 18:01 . 2010-01-25 03:29 -------- d-----w- c:\documents and settings\Robert Jericho\Application Data\Apple Computer
2010-01-24 18:00 . 2009-05-18 20:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-01-24 18:00 . 2008-04-17 19:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2010-01-24 17:55 . 2010-01-24 17:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2010-01-24 17:54 . 2010-01-24 18:15 -------- d-----w- c:\documents and settings\Robert Jericho\Local Settings\Application Data\Apple Computer
2010-01-24 17:22 . 2010-01-05 10:00 52224 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2010-01-24 17:22 . 2010-01-05 10:00 459264 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2010-01-24 17:22 . 2010-01-05 10:00 268288 -c----w- c:\windows\system32\dllcache\iertutil.dll
2010-01-24 17:22 . 2009-12-31 15:33 13824 -c----w- c:\windows\system32\dllcache\ieudinit.exe
2010-01-24 17:22 . 2010-01-05 10:00 6067200 -c----w- c:\windows\system32\dllcache\ieframe.dll
2010-01-24 17:22 . 2010-01-05 10:00 63488 -c----w- c:\windows\system32\dllcache\icardie.dll
2010-01-24 17:22 . 2010-01-05 10:00 380928 -c----w- c:\windows\system32\dllcache\ieapfltr.dll
2010-01-24 17:22 . 2009-06-29 08:33 2452872 -c----w- c:\windows\system32\dllcache\ieapfltr.dat
2010-01-24 16:25 . 2007-04-09 19:23 28552 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\mdippr.dll
2010-01-24 16:25 . 2007-04-09 19:23 28040 ----a-w- c:\windows\system32\mdimon.dll
2010-01-24 16:23 . 2010-01-24 16:23 -------- d-----w- c:\program files\Common Files\L&H
2010-01-24 16:23 . 2010-01-24 16:23 -------- d-----w- c:\program files\Microsoft ActiveSync
2010-01-24 16:22 . 2010-02-05 09:03 -------- d-----w- c:\program files\Microsoft Works
2010-01-24 16:22 . 2010-01-24 16:23 -------- d-----w- c:\windows\SHELLNEW
2010-01-24 16:22 . 2010-01-24 16:22 -------- d-----w- c:\program files\Microsoft.NET
2010-01-24 16:16 . 2010-01-24 16:16 -------- d-----r- C:\MSOCache
2010-01-24 16:01 . 2009-08-11 01:06 69936 ----a-w- c:\windows\system32\drivers\sbapifs.sys
2010-01-24 16:00 . 2009-05-13 22:30 13360 ----a-w- c:\windows\system32\drivers\sbaphd.sys
2010-01-24 15:51 . 2010-01-24 15:51 -------- d-----w- c:\documents and settings\Robert Jericho\Application Data\Sunbelt
2010-01-24 15:50 . 2010-01-24 15:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Sunbelt
2010-01-24 15:49 . 2008-10-09 16:21 202928 ----a-w- c:\windows\system32\drivers\sbtis.sys
2010-01-24 15:49 . 2010-01-24 15:49 -------- d-----w- c:\program files\Sunbelt Software
2010-01-24 15:44 . 2010-01-25 02:36 -------- d-----w- c:\program files\BitLord
2010-01-24 15:33 . 2010-01-24 15:33 1243680 ----a-w- c:\windows\system32\AutoPartNt.exe
2010-01-24 09:05 . 2008-04-14 00:12 221184 ----a-w- c:\windows\system32\wmpns.dll
2010-01-24 09:02 . 2010-02-01 01:47 -------- d-----w- c:\windows\ServicePackFiles
2010-01-23 22:29 . 2004-08-04 04:29 73216 ------w- c:\windows\system32\drivers\atintuxx.sys
2010-01-23 22:26 . 2010-01-23 22:26 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Stardock_Corporation
2010-01-23 22:25 . 2010-01-23 22:25 395744 ----a-w- c:\windows\system32\drivers\timntr.sys
2010-01-23 22:25 . 2010-01-23 22:25 39264 ----a-w- c:\windows\system32\drivers\tifsfilt.sys
2010-01-23 22:24 . 2010-01-23 22:24 114048 ----a-w- c:\windows\system32\drivers\snapman.sys
2010-01-23 22:24 . 2010-01-23 22:24 -------- d-----w- c:\program files\Common Files\Acronis
2010-01-23 22:24 . 2010-01-23 22:24 -------- d-----w- c:\program files\Acronis
2010-01-23 22:16 . 2010-01-23 22:16 -------- d-----w- c:\documents and settings\Robert Jericho\Application Data\Dell
2010-01-23 22:12 . 2010-01-23 22:12 -------- d-----w- c:\documents and settings\Robert Jericho\Local Settings\Application Data\Stardock_Corporation
2010-01-23 22:12 . 2010-01-23 22:12 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{7322D736-AA5F-4DD0-8E33-EA48318CC276}
2010-01-23 22:12 . 2009-10-19 16:56 3295808 -c--a-w- c:\documents and settings\All Users\Application Data\{7322D736-AA5F-4DD0-8E33-EA48318CC276}\delldock.exe
2010-01-23 22:11 . 2010-01-23 22:11 -------- d-----w- c:\documents and settings\Robert Jericho\Local Settings\Application Data\PackageAware
2010-01-23 22:08 . 2010-01-23 22:08 152576 ----a-w- c:\documents and settings\Robert Jericho\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2010-01-23 22:02 . 2010-01-23 22:02 0 ----a-w- c:\windows\nsreg.dat
2010-01-23 22:02 . 2010-01-23 22:02 -------- d-----w- c:\documents and settings\Robert Jericho\Local Settings\Application Data\Mozilla
2010-01-23 22:00 . 2010-01-23 22:00 -------- d-----w- c:\windows\CtDrvInstall
2010-01-23 21:59 . 2010-01-23 21:59 75 --sh--r- c:\windows\CT4CET.bin
2010-01-23 21:58 . 2010-01-23 21:58 -------- d-----w- c:\program files\Common Files\Reallusion
2010-01-23 21:58 . 2010-01-23 21:58 -------- d-----w- c:\program files\Creative
2010-01-23 21:57 . 2010-01-23 21:58 -------- d-----w- c:\program files\Dell Webcam
2010-01-23 21:57 . 2008-10-28 16:48 135936 ----a-w- c:\windows\system32\drivers\CtClsFlt.sys
2010-01-23 21:57 . 2010-01-23 21:57 -------- d-----w- c:\program files\Creative Live! Cam
2010-01-23 21:52 . 2008-11-05 02:24 14248 ----a-w- c:\windows\system32\drivers\EMSC.sys
2010-01-23 21:51 . 2010-01-23 21:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Vista32

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-01 01:56 . 2010-01-23 06:17 87263 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-01-24 20:59 . 2010-01-23 07:04 86016 ----a-w- c:\windows\system32\PersistenceThread.exe
2010-01-24 18:00 . 2010-01-24 17:59 -------- d-----w- c:\program files\iTunes
2010-01-24 18:00 . 2010-01-24 17:59 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2010-01-24 17:59 . 2010-01-24 17:59 -------- d-----w- c:\program files\iPod
2010-01-24 17:59 . 2010-01-24 17:55 -------- d-----w- c:\program files\Common Files\Apple
2010-01-24 17:59 . 2010-01-24 17:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-01-24 17:59 . 2010-01-24 17:59 -------- d-----w- c:\program files\Bonjour
2010-01-24 17:58 . 2010-01-24 17:57 -------- d-----w- c:\program files\QuickTime
2010-01-24 17:57 . 2010-01-24 17:57 -------- d-----w- c:\program files\Apple Software Update
2010-01-23 22:12 . 2010-01-23 06:54 -------- d-----w- c:\program files\Dell
2010-01-23 20:44 . 2010-01-23 20:44 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2010-01-23 20:43 . 2010-01-23 20:23 -------- d-----w- c:\program files\Common Files\InstallShield
2010-01-23 20:25 . 2010-01-23 20:25 0 ----a-w- c:\windows\system32\drivers\SETBA.tmp
2010-01-23 07:14 . 2010-01-23 07:14 -------- d-----w- c:\documents and settings\Robert Jericho\Application Data\InstallShield
2010-01-23 06:54 . 2010-01-23 06:54 45056 ----a-r- c:\documents and settings\Robert Jericho\Application Data\Microsoft\Installer\{42929F0F-CE14-47AF-9FC7-FF297A603021}\NewShortcut1_42929F0FCE1447AF9FC7FF297A603021_1.exe
2010-01-23 06:54 . 2010-01-23 06:54 10134 ----a-r- c:\documents and settings\Robert Jericho\Application Data\Microsoft\Installer\{42929F0F-CE14-47AF-9FC7-FF297A603021}\ARPPRODUCTICON.exe
2010-01-23 06:19 . 2010-01-23 06:19 -------- d-----w- c:\program files\microsoft frontpage
2010-01-23 06:13 . 2010-01-23 06:13 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2010-01-05 10:00 . 2004-08-12 13:33 832512 ----a-w- c:\windows\system32\wininet.dll
2010-01-05 10:00 . 2004-08-12 13:19 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-01-05 10:00 . 2004-08-12 13:18 17408 ------w- c:\windows\system32\corpol.dll
2010-01-04 23:02 . 2010-01-04 23:02 27984 ----a-w- c:\windows\system32\sbbd.exe
2009-12-31 16:50 . 2004-08-12 13:30 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-16 18:43 . 2010-01-23 06:12 343040 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:08 . 2004-08-12 13:18 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-12-08 19:26 . 2004-08-12 13:25 2145280 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-12-08 18:43 . 2004-08-03 22:59 2023936 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-12-04 18:22 . 2004-08-12 13:22 455424 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-12-04 16:03 . 2009-12-04 16:03 251376 ----a-w- c:\documents and settings\Robert Jericho\Application Data\Mozilla\plugins\npgoogletalk.dll
2009-11-27 17:11 . 2004-08-12 13:26 1291776 ----a-w- c:\windows\system32\quartz.dll
2009-11-27 17:11 . 2004-08-04 00:56 17920 ----a-w- c:\windows\system32\msyuv.dll
2009-11-27 16:07 . 2004-08-12 13:23 28672 ----a-w- c:\windows\system32\msvidc32.dll
2009-11-27 16:07 . 2001-08-17 22:36 8704 ----a-w- c:\windows\system32\tsbyuv.dll
2009-11-27 16:07 . 2004-08-12 13:23 11264 ----a-w- c:\windows\system32\msrle32.dll
2009-11-27 16:07 . 2004-08-12 13:17 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-11-27 16:07 . 2004-08-04 00:56 48128 ----a-w- c:\windows\system32\iyuv_32.dll
2009-11-21 15:51 . 2004-08-12 13:17 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2008-08-16 23:42 . 2008-08-16 23:42 13112 ----a-w- c:\program files\mozilla firefox\plugins\cgpcfg.dll
2008-08-16 23:42 . 2008-08-16 23:42 70456 ----a-w- c:\program files\mozilla firefox\plugins\CgpCore.dll
2008-08-16 23:42 . 2008-08-16 23:42 91448 ----a-w- c:\program files\mozilla firefox\plugins\confmgr.dll
2008-08-16 23:42 . 2008-08-16 23:42 20800 ----a-w- c:\program files\mozilla firefox\plugins\ctxlogging.dll
2008-08-16 23:43 . 2008-08-16 23:43 206136 ----a-w- c:\program files\mozilla firefox\plugins\ctxmui.dll
2008-08-16 23:42 . 2008-08-16 23:42 31032 ----a-w- c:\program files\mozilla firefox\plugins\icafile.dll
2008-08-16 23:42 . 2008-08-16 23:42 40248 ----a-w- c:\program files\mozilla firefox\plugins\icalogon.dll
2008-05-21 14:41 . 2008-05-21 14:41 479232 ----a-w- c:\program files\mozilla firefox\plugins\msvcm80.dll
2008-05-21 14:41 . 2008-05-21 14:41 548864 ----a-w- c:\program files\mozilla firefox\plugins\msvcp80.dll
2008-05-21 14:41 . 2008-05-21 14:41 626688 ----a-w- c:\program files\mozilla firefox\plugins\msvcr80.dll
2008-06-05 19:58 . 2008-06-05 19:58 648504 ----a-w- c:\program files\mozilla firefox\plugins\sslsdk_b.dll
2008-08-16 23:42 . 2008-08-16 23:42 23864 ----a-w- c:\program files\mozilla firefox\plugins\TcpPServ.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Robert Jericho\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-02-11 135664]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-01-05 2002160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-11-26 2289664]
"RTHDCPL"="RTHDCPL.EXE" [2008-12-09 18063872]
"BTMeter"="c:\program files\Battery Meter\BTMeter.exe" [2008-11-05 623912]
"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2009-01-23 416768]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-06-03 206064]
"CapsLKNotify"="c:\program files\CapsLKNotify\CapsLKNotify.exe" [2009-03-18 320808]
"WSED"="c:\program files\WSED\WSED.exe" [2009-05-27 247080]
"Dell Webcam Central"="c:\program files\Dell Webcam\Dell Webcam Central\WebcamDell.exe" [2008-11-11 442536]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2006-10-17 1164912]
"AcronisTimounterMonitor"="c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe" [2006-10-17 1941784]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2006-10-17 87584]
"SBAMTray"="c:\program files\Sunbelt Software\VIPRE\SBAMTray.exe" [2010-01-04 959824]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-03-18 131072]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-03-18 348160]
"PersistenceThread"="c:\windows\system32\PersistenceThread.exe" [2010-01-24 86016]
"MMReminderService"="c:\program files\Mindjet\MindManager 8\MMReminderService.exe" [2008-11-14 37656]
"Acrobat Assistant 7.0"="c:\program files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2008-04-23 483328]

c:\documents and settings\Robert Jericho\Start Menu\Programs\Startup\
Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-10-19 1316192]
osd_vol.exe [2005-8-6 64512]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2010-1-24 25214]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 20:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\igdlogin]
2009-03-18 13:01 65536 ----a-w- c:\windows\system32\igdlogin.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\BitLord\\BitLord.exe"=
"c:\\Documents and Settings\\Robert Jericho\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\Robert Jericho\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=

R0 EMSC;COMPAL Embedded System Control;c:\windows\system32\drivers\EMSC.sys [1/23/2010 3:52 PM 14248]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [1/5/2010 7:56 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [1/5/2010 7:56 AM 74480]
R1 sbaphd;sbaphd;c:\windows\system32\drivers\sbaphd.sys [1/24/2010 10:00 AM 13360]
R1 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [10/13/2009 8:22 AM 95024]
R1 sbtis;sbtis;c:\windows\system32\drivers\sbtis.sys [1/24/2010 9:49 AM 202928]
R2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [6/9/2009 8:11 AM 155648]
R2 sbapifs;sbapifs;c:\windows\system32\drivers\sbapifs.sys [1/24/2010 10:01 AM 69936]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\drivers\CtClsFlt.sys [1/23/2010 3:57 PM 135936]
R3 igd;igd;c:\windows\system32\drivers\igxpmp32.sys [1/23/2010 1:04 AM 5088896]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [1/24/2010 1:42 PM 110080]
R3 OA012Afx;Provides a software interface to control audio effects of OA012 camera.;c:\windows\system32\drivers\OA012Afx.sys [1/23/2010 3:45 PM 148056]
R3 OA012Ufd;Creative Camera OA012 Upper Filter Driver;c:\windows\system32\drivers\OA012Ufd.sys [1/23/2010 3:45 PM 133472]
R3 OA012Vid;Creative Camera OA012 Function Driver;c:\windows\system32\drivers\OA012Vid.sys [1/23/2010 3:45 PM 271328]
R3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RTS5121.sys [1/23/2010 2:21 PM 157696]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [1/5/2010 7:56 AM 7408]
S2 SBAMSvc;VIPRE Antivirus + Antispyware;c:\program files\Sunbelt Software\VIPRE\SBAMSvc.exe [1/4/2010 5:02 PM 1012080]
S3 Rts516xIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys --> c:\windows\system32\DRIVERS\Rts516xIR.sys [?]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - APPMGMT
*NewlyCreated* - SASDIFSV
*NewlyCreated* - SASENUM
*NewlyCreated* - SASKUTIL
.
Contents of the 'Scheduled Tasks' folder

2010-02-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 18:34]

2010-02-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1993962763-746137067-1801674531-1003Core.job
- c:\documents and settings\Robert Jericho\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-02-11 02:47]

2010-02-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1993962763-746137067-1801674531-1003UA.job
- c:\documents and settings\Robert Jericho\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-02-11 02:47]

2010-02-12 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 21:07]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
FF - ProfilePath - c:\documents and settings\Robert Jericho\Application Data\Mozilla\Firefox\Profiles\vubdatlo.default\
FF - prefs.js: browser.search.selectedEngine - eBay
FF - component: c:\documents and settings\Robert Jericho\Application Data\Mozilla\Firefox\Profiles\vubdatlo.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\DictionaryCompressionFF.dll
FF - component: c:\documents and settings\Robert Jericho\Application Data\Mozilla\Firefox\Profiles\vubdatlo.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\documents and settings\Robert Jericho\Application Data\Mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\Robert Jericho\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npicaN.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-12 17:35
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe catchme.sys CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys >>UNKNOWN [0x86FCA8C8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf76d1f28
\Driver\ACPI -> ACPI.sys @ 0xf7554cb8
\Driver\atapi -> atapi.sys @ 0xf74e9b3a
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
NDIS: -> SendCompleteHandler -> 0x0
PacketIndicateHandler -> 0x0
SendHandler -> 0x0
user & kernel MBR OK

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1016)
c:\windows\System32\BCMLogon.dll

- - - - - - - > 'lsass.exe'(1072)
c:\windows\system32\relog_ap.dll
.
Completion time: 2010-02-12 17:38:19
ComboFix-quarantined-files.txt 2010-02-12 23:38

Pre-Run: 61,411,332,096 bytes free
Post-Run: 61,554,040,832 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - 3AE4D82845D610F59D42B159F942827B
rjj76
Regular Member
 
Posts: 16
Joined: February 15th, 2010, 4:56 pm

Re: Search Redirect Malware

Unread postby muppy03 » February 23rd, 2010, 7:16 am

I gather you are still having the re-directs? Are they in IE and Firefox both?

Please go to Virus Total <http://www.virustotal.com/> or Jotti
and upload C:\WINDOWS\system32\igdlogin.dll for scanning.

For Virus Total
1. Please copy and paste C:\WINDOWS\system32\igdlogin.dll in the text box next to the Browse button.
2. Click on Send File.

For Jotti
1. Please copy and paste C:\WINDOWS\system32\igdlogin.dll in the text box next to the Browse button.
2. Click on Submit.


Please post back the results of the scan in your next post.

HostXpert
Download HostXpert from here & save it to your desktop
  • Right click on HostsXpert.zip and select Extract All...
  • Click Next on seeing the Welcome to the Compressed (zipped) Folders Extraction Wizard
  • Click on the Browse button. Click on Desktop. Then click OK
  • Once done, check (tick) the Show extracted files box and click Finish
  • Once extracted, HostsXpert folder will open
  • Double click on HostsXpert.exe to start it
  • On your left hand side, click on Restore MS Hosts File
  • Exit HostsXpert


Delete the version of Combofix that you have and re download as below. Make sure all Antivirus and Antispyware is disabled.

Download and run Combofix
This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper


Please download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools.
  • If you need help to disable your protection programs see here.
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Image
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Image
Click on Yes, to continue scanning for malware.

When finished, it will produce a log for you. Please include the C:\ComboFix.txt in your next reply along with a fresh HijackThis log.

If you need help, see this link:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix


Please reply with:-
  • Combofix log
  • New HJT log
User avatar
muppy03
MRU Emeritus
MRU Emeritus
 
Posts: 4782
Joined: December 4th, 2007, 5:30 am
Location: Australia

Re: Search Redirect Malware

Unread postby rjj76 » February 23rd, 2010, 10:12 pm

I am still getting the redirects in Firefox. I don't use Internet Explorer. (Opera is completely unaffected and is darn fast to use though!)

Virus Total Results:

Antivirus Version Last Update Result
a-squared 4.5.0.50 2010.02.24 -
AhnLab-V3 5.0.0.2 2010.02.23 -
AntiVir 8.2.1.172 2010.02.23 -
Antiy-AVL 2.0.3.7 2010.02.23 -
Authentium 5.2.0.5 2010.02.24 -
Avast 4.8.1351.0 2010.02.23 -
AVG 9.0.0.730 2010.02.24 -
BitDefender 7.2 2010.02.24 -
CAT-QuickHeal 10.00 2010.02.23 -
ClamAV 0.96.0.0-git 2010.02.23 -
Comodo 4041 2010.02.24 -
DrWeb 5.0.1.12222 2010.02.24 -
eSafe 7.0.17.0 2010.02.23 -
eTrust-Vet 35.2.7323 2010.02.23 -
F-Prot 4.5.1.85 2010.02.23 -
F-Secure 9.0.15370.0 2010.02.24 -
Fortinet 4.0.14.0 2010.02.21 -
GData 19 2010.02.24 -
Ikarus T3.1.1.80.0 2010.02.24 -
Jiangmin 13.0.900 2010.02.23 -
K7AntiVirus 7.10.981 2010.02.23 -
Kaspersky 7.0.0.125 2010.02.24 -
McAfee 5901 2010.02.23 -
McAfee+Artemis 5901 2010.02.23 -
McAfee-GW-Edition 6.8.5 2010.02.23 -
Microsoft 1.5406 2010.02.23 -
NOD32 4891 2010.02.23 -
Norman 6.04.08 2010.02.23 -
nProtect 2009.1.8.0 2010.02.23 -
Panda 10.0.2.2 2010.02.23 -
PCTools 7.0.3.5 2010.02.23 -
Prevx 3.0 2010.02.24 -
Rising 22.34.01.03 2010.02.11 -
Sophos 4.50.0 2010.02.24 -
Sunbelt 5696 2010.02.24 -
Symantec 20091.2.0.41 2010.02.24 -
TheHacker 6.5.1.6.208 2010.02.24 -
TrendMicro 9.120.0.1004 2010.02.23 -
VBA32 3.12.12.2 2010.02.23 -
ViRobot 2010.2.23.2198 2010.02.23 -
VirusBuster 5.0.27.0 2010.02.24 -
Additional information
File size: 65536 bytes
MD5...: 71f8b9c36c3696ae71e3609be8d3bfd8
SHA1..: 826e5ec2160fb17294119272cd8ed625b9338aa9
SHA256: f47c13889a0a301b174771d53ca08da5aaa3d64169e184d368ac76006cd61274
ssdeep: 768:2D20qZFK192vMnBQa9BnWeV+BaOa/JbpnmLr4ykhi+tVtyq9or/:Y/eFU20W
eV+Bbam4yLCtF+
PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x14e6
timedatestamp.....: 0x49c0fec1 (Wed Mar 18 14:01:37 2009)
machinetype.......: 0x14c (I386)

( 5 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x78d9 0x8000 6.40 9d7331785a323aff7377f7616f6bdb49
.rdata 0x9000 0x27c7 0x3000 4.79 ea95f89c9e8bad62a596d21908be99a0
.data 0xc000 0x191c 0x1000 2.28 07ef728933bebf94ddae648ffeb251a4
.rsrc 0xe000 0xb0 0x1000 3.06 d5c55328f98c49f685b2c5e53e2b75a4
.reloc 0xf000 0x132e 0x2000 2.59 0652f4d85310ad30ca94c0d47cb4e1b7

( 2 imports )
> KERNEL32.dll: SetEvent, DisableThreadLibraryCalls, OpenEventW, CloseHandle, GetCurrentThreadId, GetCommandLineA, HeapFree, GetVersionExA, HeapAlloc, GetProcessHeap, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, GetProcAddress, GetModuleHandleA, ExitProcess, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, InterlockedIncrement, SetLastError, GetLastError, InterlockedDecrement, Sleep, SetHandleCount, GetStdHandle, GetFileType, GetStartupInfoA, DeleteCriticalSection, GetModuleFileNameA, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, WideCharToMultiByte, GetEnvironmentStringsW, HeapDestroy, HeapCreate, VirtualFree, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, GetSystemTimeAsFileTime, WriteFile, LeaveCriticalSection, EnterCriticalSection, LoadLibraryA, InitializeCriticalSection, GetCPInfo, GetACP, GetOEMCP, VirtualAlloc, HeapReAlloc, RtlUnwind, HeapSize, MultiByteToWideChar, GetLocaleInfoA, GetStringTypeA, GetStringTypeW, LCMapStringA, LCMapStringW, RaiseException
> ole32.dll: CoUninitialize, CoCreateInstance, CoInitializeEx

( 2 exports )
PWL_EventHandler_Lock, PWL_EventHandler_UnLock
RDS...: NSRL Reference Data Set
-
pdfid.: -
trid..: Win32 Executable MS Visual C++ (generic) (65.2%)
Win32 Executable Generic (14.7%)
Win32 Dynamic Link Library (generic) (13.1%)
Generic Win/DOS Executable (3.4%)
DOS Executable Generic (3.4%)
sigcheck:
publisher....: n/a
copyright....: n/a
product......: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned



Jotti:::

All items say 'Found Nothing' next to them.



Performing next steps now....
rjj76
Regular Member
 
Posts: 16
Joined: February 15th, 2010, 4:56 pm

Re: Search Redirect Malware

Unread postby rjj76 » February 23rd, 2010, 10:40 pm

Combo Fix Log:

ComboFix 10-02-23.03 - Robert Jericho 02/23/2010 20:26:45.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.351 [GMT -6:00]
Running from: c:\documents and settings\Robert Jericho\Desktop\ComboFix.exe
AV: Sunbelt VIPRE *On-access scanning disabled* (Updated) {964FCE60-0B18-4D30-ADD6-EB178909041C}
.

((((((((((((((((((((((((( Files Created from 2010-01-24 to 2010-02-24 )))))))))))))))))))))))))))))))
.

2010-02-20 19:45 . 2010-02-20 19:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Citrix
2010-02-20 19:44 . 2010-02-20 19:44 -------- d-----w- c:\documents and settings\Robert Jericho\Local Settings\Application Data\Citrix
2010-02-20 19:44 . 2010-02-20 19:44 61224 ----a-w- c:\documents and settings\Robert Jericho\GoToAssistDownloadHelper.exe
2010-02-20 19:22 . 2010-02-20 19:58 -------- d-----w- c:\program files\Elantech
2010-02-20 18:58 . 2010-02-20 18:58 -------- d-----w- c:\program files\Battery Meter
2010-02-20 17:06 . 2010-02-22 14:09 -------- d-----w- C:\rsit
2010-02-18 03:03 . 2010-02-18 03:03 -------- d-----w- c:\documents and settings\Robert Jericho\Local Settings\Application Data\GoogleToolBar
2010-02-17 02:32 . 2010-02-18 03:03 -------- d-----w- c:\documents and settings\Robert Jericho\Local Settings\Application Data\Opera
2010-02-17 02:31 . 2010-02-18 03:51 -------- d-----w- c:\program files\Opera 10.50 Beta
2010-02-16 00:01 . 2010-02-16 00:01 -------- d-----w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2010-02-16 00:01 . 2010-02-16 00:01 -------- d-----w- c:\documents and settings\Robert Jericho\Application Data\Office Genuine Advantage
2010-02-15 20:53 . 2010-02-15 20:53 -------- d-----w- c:\program files\Trend Micro
2010-02-15 20:39 . 2009-12-16 22:05 43008 ----a-w- c:\documents and settings\Robert Jericho\Application Data\Mozilla\Firefox\Profiles\pnr3u3tv.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2010-02-15 20:39 . 2009-12-16 22:05 340992 ----a-w- c:\documents and settings\Robert Jericho\Application Data\Mozilla\Firefox\Profiles\pnr3u3tv.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2010-02-15 20:39 . 2009-12-16 22:05 347136 ----a-w- c:\documents and settings\Robert Jericho\Application Data\Mozilla\Firefox\Profiles\pnr3u3tv.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2010-02-15 20:38 . 2009-12-16 22:05 1452032 ----a-w- c:\documents and settings\Robert Jericho\Application Data\Mozilla\Firefox\Profiles\pnr3u3tv.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
2010-02-15 20:38 . 2009-12-16 22:05 471040 ----a-w- c:\documents and settings\Robert Jericho\Application Data\Mozilla\Firefox\Profiles\pnr3u3tv.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\DictionaryCompressionFF.dll
2010-02-15 19:56 . 2010-02-15 19:56 -------- d-----w- c:\documents and settings\Robert Jericho\Local Settings\Application Data\Mozilla
2010-02-15 19:22 . 2010-02-15 19:22 -------- d-----w- c:\program files\Enigma Software Group
2010-02-15 19:16 . 2010-02-15 19:16 -------- d-----w- c:\documents and settings\All Users\Application Data\XoftSpySE
2010-02-13 15:59 . 2010-02-13 15:59 -------- d-----w- c:\documents and settings\Robert Jericho\Application Data\Canneverbe Limited
2010-02-13 15:59 . 2010-02-13 15:59 -------- d-----w- c:\documents and settings\All Users\Application Data\Canneverbe Limited
2010-02-13 15:58 . 2009-11-12 19:48 7168 ----a-w- c:\windows\system32\drivers\StarOpen.sys
2010-02-13 15:58 . 2010-02-13 15:58 -------- d-----w- c:\program files\CDBurnerXP
2010-02-13 14:57 . 2010-02-13 14:57 -------- d-----w- c:\program files\Alwil Software
2010-02-13 14:57 . 2010-02-13 14:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-02-12 23:48 . 2010-02-12 23:48 -------- d-----w- c:\program files\Sun
2010-02-12 17:38 . 2010-02-12 17:38 52224 ----a-w- c:\documents and settings\Robert Jericho\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-02-12 17:38 . 2010-02-12 17:38 117760 ----a-w- c:\documents and settings\Robert Jericho\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-02-12 17:38 . 2010-02-12 17:38 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-02-12 17:37 . 2010-02-12 17:37 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-02-12 17:37 . 2010-02-12 17:37 -------- d-----w- c:\documents and settings\Robert Jericho\Application Data\SUPERAntiSpyware.com
2010-02-12 17:37 . 2010-02-12 17:37 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-02-12 14:31 . 2010-02-12 14:31 -------- d-----w- c:\documents and settings\Robert Jericho\Application Data\Malwarebytes
2010-02-12 14:31 . 2010-01-07 22:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-12 14:31 . 2010-02-12 14:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-02-12 14:31 . 2010-02-12 14:31 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-12 14:31 . 2010-01-07 22:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-02-11 02:48 . 2010-02-13 19:53 -------- d-----w- c:\documents and settings\Robert Jericho\Local Settings\Application Data\Temp
2010-02-11 00:33 . 2010-02-11 00:33 -------- d-----w- c:\windows\Sun
2010-02-05 16:39 . 2010-02-05 16:39 251376 ----a-w- c:\documents and settings\Robert Jericho\Application Data\Mozilla\plugins\npgoogletalk.dll
2010-02-05 06:41 . 2009-08-07 01:23 274288 ----a-w- c:\windows\system32\mucltui.dll
2010-02-05 06:41 . 2009-08-07 01:23 215920 ----a-w- c:\windows\system32\muweb.dll
2010-02-05 05:24 . 2010-02-12 15:02 -------- d-----w- c:\documents and settings\Robert Jericho\Application Data\AdobeUM
2010-02-05 02:40 . 2010-02-05 02:40 -------- d-----w- c:\program files\Microsoft Silverlight
2010-02-04 04:22 . 2010-02-04 04:22 -------- d-----w- c:\documents and settings\Robert Jericho\Local Settings\Application Data\Identities
2010-02-01 01:52 . 2010-02-01 01:52 -------- d-----w- c:\windows\system32\scripting
2010-02-01 01:52 . 2010-02-01 01:52 -------- d-----w- c:\windows\l2schemas
2010-02-01 01:52 . 2010-02-01 01:52 -------- d-----w- c:\windows\system32\en
2010-02-01 01:52 . 2010-02-01 01:52 -------- d-----w- c:\windows\system32\bits
2010-01-27 03:55 . 2010-01-27 03:55 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2010-01-26 00:55 . 2010-02-18 05:11 -------- d-----w- c:\documents and settings\Robert Jericho\Application Data\vlc
2010-01-26 00:53 . 2010-01-26 00:53 -------- d-----w- c:\program files\VideoLAN
2010-01-25 22:30 . 2010-01-25 22:30 -------- d-----w- c:\program files\MSXML 4.0
2010-01-25 09:33 . 2010-01-25 09:33 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\SupportSoft
2010-01-25 09:09 . 2010-01-25 09:09 -------- d-----w- c:\windows\system32\XPSViewer
2010-01-25 09:09 . 2010-01-25 09:09 -------- d-----w- c:\program files\MSBuild
2010-01-25 09:09 . 2010-01-25 09:09 -------- d-----w- c:\program files\Reference Assemblies
2010-01-25 09:08 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2010-01-25 09:08 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-01-25 09:08 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-01-25 09:08 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2010-01-25 09:08 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2010-01-25 09:08 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2010-01-25 09:08 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2010-01-25 09:08 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-01-25 09:08 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2010-01-25 09:08 . 2010-01-25 09:08 -------- d-----w- C:\a3eb26cc20e43dea7a4c6a64

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-20 19:44 . 2010-01-24 23:39 -------- d-----w- c:\program files\Citrix
2010-02-20 18:58 . 2010-01-23 20:20 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-02-12 23:47 . 2010-01-23 21:32 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-02-12 23:44 . 2010-01-23 21:32 -------- d-----w- c:\program files\Java
2010-02-11 03:26 . 2010-01-24 23:17 -------- d-----w- c:\program files\Common Files\Adobe
2010-02-08 04:30 . 2010-01-23 21:43 64368 ----a-w- c:\documents and settings\Robert Jericho\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-05 09:03 . 2010-01-24 16:22 -------- d-----w- c:\program files\Microsoft Works
2010-02-01 01:56 . 2010-01-23 06:17 87263 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-01-25 03:29 . 2010-01-24 18:01 -------- d-----w- c:\documents and settings\Robert Jericho\Application Data\Apple Computer
2010-01-24 23:59 . 2010-01-24 23:59 -------- d-----w- c:\program files\ShopSafe
2010-01-24 23:18 . 2010-01-24 23:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Adobe Systems
2010-01-24 23:18 . 2010-01-24 23:18 -------- d-----w- c:\program files\Common Files\Adobe Systems Shared
2010-01-24 23:05 . 2010-01-24 23:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Mindjet
2010-01-24 23:05 . 2010-01-24 23:05 -------- d-----w- c:\program files\Mindjet
2010-01-24 23:04 . 2010-01-24 23:04 -------- d-----w- c:\program files\MSXML 6.0
2010-01-24 21:39 . 2010-01-23 21:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Dell
2010-01-24 21:02 . 2010-01-24 20:30 -------- d-----w- c:\program files\All in 1 Media Codecs Pack
2010-01-24 20:59 . 2010-01-23 07:04 86016 ----a-w- c:\windows\system32\PersistenceThread.exe
2010-01-24 20:51 . 2010-01-24 20:51 -------- d-----w- c:\program files\Codec Pack - All In 1
2010-01-24 20:50 . 2010-01-24 20:51 737280 ----a-w- c:\windows\iun6002.exe
2010-01-24 20:34 . 2010-01-24 20:34 -------- d-----w- c:\documents and settings\Robert Jericho\Application Data\Media Player Classic
2010-01-24 20:31 . 2010-01-24 20:31 -------- d-----w- c:\program files\Real Alternative
2010-01-24 20:31 . 2010-01-24 20:31 -------- d-----w- c:\program files\QuickTime Alternative
2010-01-24 19:31 . 2010-01-24 19:30 -------- d-----w- c:\program files\Duplicate Music Files Finder
2010-01-24 19:16 . 2010-01-24 19:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Vistanita
2010-01-24 18:00 . 2010-01-24 17:59 -------- d-----w- c:\program files\iTunes
2010-01-24 18:00 . 2010-01-24 17:59 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2010-01-24 17:59 . 2010-01-24 17:59 -------- d-----w- c:\program files\iPod
2010-01-24 17:59 . 2010-01-24 17:55 -------- d-----w- c:\program files\Common Files\Apple
2010-01-24 17:59 . 2010-01-24 17:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-01-24 17:59 . 2010-01-24 17:59 -------- d-----w- c:\program files\Bonjour
2010-01-24 17:58 . 2010-01-24 17:57 -------- d-----w- c:\program files\QuickTime
2010-01-24 17:57 . 2010-01-24 17:57 -------- d-----w- c:\program files\Apple Software Update
2010-01-24 17:55 . 2010-01-24 17:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2010-01-24 16:23 . 2010-01-24 16:23 -------- d-----w- c:\program files\Common Files\L&H
2010-01-24 16:23 . 2010-01-24 16:23 -------- d-----w- c:\program files\Microsoft ActiveSync
2010-01-24 16:22 . 2010-01-24 16:22 -------- d-----w- c:\program files\Microsoft.NET
2010-01-24 15:51 . 2010-01-24 15:51 -------- d-----w- c:\documents and settings\Robert Jericho\Application Data\Sunbelt
2010-01-24 15:50 . 2010-01-24 15:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Sunbelt
2010-01-24 15:49 . 2010-01-24 15:49 -------- d-----w- c:\program files\Sunbelt Software
2010-01-24 15:33 . 2010-01-24 15:33 1243680 ----a-w- c:\windows\system32\AutoPartNt.exe
2010-01-23 22:25 . 2010-01-23 22:25 395744 ----a-w- c:\windows\system32\drivers\timntr.sys
2010-01-23 22:25 . 2010-01-23 22:25 39264 ----a-w- c:\windows\system32\drivers\tifsfilt.sys
2010-01-23 22:24 . 2010-01-23 22:24 114048 ----a-w- c:\windows\system32\drivers\snapman.sys
2010-01-23 22:24 . 2010-01-23 22:24 -------- d-----w- c:\program files\Common Files\Acronis
2010-01-23 22:24 . 2010-01-23 22:24 -------- d-----w- c:\program files\Acronis
2010-01-23 22:16 . 2010-01-23 22:16 -------- d-----w- c:\documents and settings\Robert Jericho\Application Data\Dell
2010-01-23 22:12 . 2010-01-23 22:12 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{7322D736-AA5F-4DD0-8E33-EA48318CC276}
2010-01-23 22:12 . 2010-01-23 06:54 -------- d-----w- c:\program files\Dell
2010-01-23 22:08 . 2010-01-23 22:08 152576 ----a-w- c:\documents and settings\Robert Jericho\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2010-01-23 22:08 . 2010-01-23 21:42 79488 ----a-w- c:\documents and settings\Robert Jericho\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-01-23 22:02 . 2010-01-23 22:02 0 ----a-w- c:\windows\nsreg.dat
2010-01-23 21:59 . 2010-01-23 21:59 75 --sh--r- c:\windows\CT4CET.bin
2010-01-23 21:58 . 2010-01-23 21:58 -------- d-----w- c:\program files\Common Files\Reallusion
2010-01-23 21:58 . 2010-01-23 21:57 -------- d-----w- c:\program files\Dell Webcam
2010-01-23 21:58 . 2010-01-23 21:58 -------- d-----w- c:\program files\Creative
2010-01-23 21:57 . 2010-01-23 21:57 -------- d-----w- c:\program files\Creative Live! Cam
2010-01-23 21:51 . 2010-01-23 21:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Win764
2010-01-23 21:51 . 2010-01-23 21:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Vista32
2010-01-23 21:51 . 2010-01-23 21:51 -------- d-----w- c:\documents and settings\All Users\Application Data\XP32
2010-01-23 21:51 . 2010-01-23 21:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Win732
2010-01-23 21:51 . 2010-01-23 21:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Vista64
2010-01-23 21:51 . 2010-01-23 21:51 -------- d-----w- c:\program files\WSED
2010-01-23 21:48 . 2010-01-23 21:48 -------- d-----w- c:\program files\CapsLKNotify
2010-01-23 21:33 . 2010-01-23 21:33 -------- d-----w- c:\program files\Function Keys
2010-01-23 21:28 . 2010-01-23 21:28 69120 ----a-w- c:\documents and settings\All Users\Application Data\SupportSoft\DellSupportCenter\_default\data\f9cd5860-4b46-43fa-aa04-46ba9e956204\7e7d3c88-958b-4607-85a7-8c1cc5188887.1\NOTEPAD.EXE
2010-01-23 21:28 . 2010-01-23 21:28 -------- d-----w- c:\documents and settings\All Users\Application Data\SupportSoft
2010-01-23 21:28 . 2010-01-23 21:28 -------- d-----w- c:\documents and settings\All Users\Application Data\PCDr
2010-01-23 21:28 . 2010-01-23 21:28 -------- d-----w- c:\documents and settings\All Users\Application Data\PC-Doctor
2010-01-23 21:27 . 2010-01-23 21:27 -------- d-----w- c:\program files\Dell Support Center
2010-01-23 21:27 . 2010-01-23 21:27 -------- d-----w- c:\program files\Common Files\supportsoft
2010-01-23 20:44 . 2010-01-23 20:44 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2010-01-23 20:43 . 2010-01-23 20:23 -------- d-----w- c:\program files\Common Files\InstallShield
2010-01-23 20:41 . 2010-01-23 20:41 -------- d-----w- c:\program files\WIDCOMM
2010-01-23 20:25 . 2010-01-23 20:25 0 ----a-w- c:\windows\system32\drivers\SETBA.tmp
2010-01-23 20:23 . 2010-01-23 20:20 -------- d-----w- c:\program files\Realtek
2010-01-23 07:14 . 2010-01-23 07:14 -------- d-----w- c:\documents and settings\Robert Jericho\Application Data\InstallShield
2010-01-23 07:01 . 2010-01-23 07:01 -------- d-----w- c:\program files\Intel
2010-01-23 06:54 . 2010-01-23 06:54 45056 ----a-r- c:\documents and settings\Robert Jericho\Application Data\Microsoft\Installer\{42929F0F-CE14-47AF-9FC7-FF297A603021}\NewShortcut1_42929F0FCE1447AF9FC7FF297A603021_1.exe
2010-01-23 06:54 . 2010-01-23 06:54 10134 ----a-r- c:\documents and settings\Robert Jericho\Application Data\Microsoft\Installer\{42929F0F-CE14-47AF-9FC7-FF297A603021}\ARPPRODUCTICON.exe
2010-01-23 06:19 . 2010-01-23 06:19 -------- d-----w- c:\program files\microsoft frontpage
2010-01-23 06:13 . 2010-01-23 06:13 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2010-01-05 10:00 . 2004-08-12 13:33 832512 ------w- c:\windows\system32\wininet.dll
2010-01-05 10:00 . 2004-08-12 13:19 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-01-05 10:00 . 2004-08-12 13:18 17408 ------w- c:\windows\system32\corpol.dll
2010-01-04 23:02 . 2010-01-04 23:02 27984 ----a-w- c:\windows\system32\sbbd.exe
2009-12-31 16:50 . 2004-08-12 13:30 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-16 18:43 . 2010-01-23 06:12 343040 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:08 . 2004-08-12 13:18 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-12-08 19:26 . 2004-08-12 13:25 2145280 ------w- c:\windows\system32\ntoskrnl.exe
2009-12-08 18:43 . 2004-08-03 22:59 2023936 ------w- c:\windows\system32\ntkrnlpa.exe
2009-12-04 18:22 . 2004-08-12 13:22 455424 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-11-27 17:11 . 2004-08-12 13:26 1291776 ----a-w- c:\windows\system32\quartz.dll
2009-11-27 17:11 . 2004-08-04 00:56 17920 ----a-w- c:\windows\system32\msyuv.dll
2009-11-27 16:07 . 2004-08-12 13:23 28672 ----a-w- c:\windows\system32\msvidc32.dll
2009-11-27 16:07 . 2001-08-17 22:36 8704 ----a-w- c:\windows\system32\tsbyuv.dll
2009-11-27 16:07 . 2004-08-12 13:23 11264 ----a-w- c:\windows\system32\msrle32.dll
2009-11-27 16:07 . 2004-08-12 13:17 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-11-27 16:07 . 2004-08-04 00:56 48128 ----a-w- c:\windows\system32\iyuv_32.dll
.

((((((((((((((((((((((((((((( SnapShot@2010-02-12_23.35.29 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-12 06:02 . 2009-07-12 06:02 51008 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_f0ccd4aa\vcomp90.dll
+ 2009-07-12 06:02 . 2009-07-12 06:02 59728 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90rus.dll
+ 2009-07-12 06:02 . 2009-07-12 06:02 42832 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90kor.dll
+ 2009-07-12 06:02 . 2009-07-12 06:02 43344 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90jpn.dll
+ 2009-07-12 06:02 . 2009-07-12 06:02 61264 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90ita.dll
+ 2009-07-12 06:02 . 2009-07-12 06:02 62800 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90fra.dll
+ 2009-07-12 06:02 . 2009-07-12 06:02 61760 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90esp.dll
+ 2009-07-12 06:02 . 2009-07-12 06:02 61776 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90esn.dll
+ 2009-07-12 06:02 . 2009-07-12 06:02 53568 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90enu.dll
+ 2009-07-12 06:02 . 2009-07-12 06:02 63296 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90deu.dll
+ 2009-07-12 06:02 . 2009-07-12 06:02 36688 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90cht.dll
+ 2009-07-12 06:02 . 2009-07-12 06:02 35648 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90chs.dll
+ 2009-07-12 06:05 . 2009-07-12 06:05 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfcm90u.dll
+ 2009-07-12 06:05 . 2009-07-12 06:05 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfcm90.dll
+ 2010-02-23 02:48 . 2010-02-23 02:48 16384 c:\windows\temp\Perflib_Perfdata_694.dat
+ 2004-08-03 22:58 . 2008-04-13 18:39 23040 c:\windows\system32\drivers\mouclass.sys
- 2004-08-03 22:58 . 2008-04-13 18:39 23040 c:\windows\system32\drivers\mouclass.sys
+ 2004-08-03 22:58 . 2008-04-13 18:39 23040 c:\windows\system32\dllcache\mouclass.sys
+ 2004-08-12 13:19 . 2008-04-13 19:18 52480 c:\windows\system32\dllcache\i8042prt.sys
+ 2009-07-12 06:02 . 2009-07-12 06:02 653120 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll
+ 2009-07-12 06:02 . 2009-07-12 06:02 569664 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcp90.dll
+ 2009-07-12 06:05 . 2009-07-12 06:05 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcm90.dll
+ 2009-07-12 06:02 . 2009-07-12 06:02 159032 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_353599c2\atl90.dll
+ 2006-12-21 19:18 . 2006-12-21 19:18 497496 c:\windows\system32\XceedZip.dll
+ 2006-09-11 15:53 . 2006-09-11 15:53 276352 c:\windows\system32\XceedSco.dll
+ 2006-09-11 15:56 . 2006-09-11 15:56 526184 c:\windows\system32\XceedCry.dll
+ 2010-02-12 23:47 . 2010-02-12 23:47 153376 c:\windows\system32\javaws.exe
+ 2010-02-12 23:47 . 2010-02-12 23:47 145184 c:\windows\system32\javaw.exe
+ 2010-02-12 23:47 . 2010-02-12 23:47 145184 c:\windows\system32\java.exe
+ 2010-01-23 20:35 . 2009-03-30 21:32 129024 c:\windows\system32\drivers\ETD.sys
+ 2010-02-15 19:37 . 2010-02-15 19:37 262144 c:\windows\system32\config\systemprofile\NtUser.dat
+ 2010-02-13 19:53 . 2010-02-13 19:53 301568 c:\windows\Installer\45651bf.msi
+ 2010-02-13 14:57 . 2010-02-13 14:57 219648 c:\windows\Installer\3474885.msi
+ 2010-02-12 23:49 . 2010-02-12 23:49 386048 c:\windows\Installer\31710.msi
+ 2010-02-12 23:47 . 2010-02-12 23:47 570880 c:\windows\Installer\3170b.msi
+ 2010-02-12 23:44 . 2010-02-12 23:44 434688 c:\windows\Installer\31707.msi
- 2010-01-23 20:43 . 2010-01-23 20:43 192512 c:\windows\Installer\{543A4F31-9590-416A-A621-42CEB4C6A694}\ARPPRODUCTICON.exe
+ 2010-02-20 18:58 . 2010-02-20 18:58 192512 c:\windows\Installer\{543A4F31-9590-416A-A621-42CEB4C6A694}\ARPPRODUCTICON.exe
+ 2009-07-12 06:02 . 2009-07-12 06:02 3780424 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfc90u.dll
+ 2009-07-12 06:02 . 2009-07-12 06:02 3765048 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfc90.dll
+ 2010-02-17 02:31 . 2010-02-17 02:31 2216960 c:\windows\Installer\69fb043.msi
+ 2010-02-20 18:58 . 2010-02-20 18:58 15831040 c:\windows\Installer\4717a4.msi
+ 2010-01-23 20:43 . 2010-02-20 18:56 16138752 c:\windows\Downloaded Installations\{FE84E1B1-4157-4A10-9799-13AE8F3B7D9F}\Battery Meter.msi
- 2010-01-23 20:43 . 2010-01-23 20:43 16138752 c:\windows\Downloaded Installations\{FE84E1B1-4157-4A10-9799-13AE8F3B7D9F}\Battery Meter.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Robert Jericho\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-02-11 135664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-11-26 2289664]
"RTHDCPL"="RTHDCPL.EXE" [2008-12-09 18063872]
"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2009-03-30 418816]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-06-03 206064]
"CapsLKNotify"="c:\program files\CapsLKNotify\CapsLKNotify.exe" [2009-03-18 320808]
"WSED"="c:\program files\WSED\WSED.exe" [2009-05-27 247080]
"Dell Webcam Central"="c:\program files\Dell Webcam\Dell Webcam Central\WebcamDell.exe" [2008-11-11 442536]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2006-10-17 1164912]
"AcronisTimounterMonitor"="c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe" [2006-10-17 1941784]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2006-10-17 87584]
"SBAMTray"="c:\program files\Sunbelt Software\VIPRE\SBAMTray.exe" [2010-01-04 959824]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-03-18 131072]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-03-18 348160]
"PersistenceThread"="c:\windows\system32\PersistenceThread.exe" [2010-01-24 86016]
"MMReminderService"="c:\program files\Mindjet\MindManager 8\MMReminderService.exe" [2008-11-14 37656]
"Acrobat Assistant 7.0"="c:\program files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2008-04-23 483328]
"BTMeter"="c:\program files\Battery Meter\BTMeter.exe" [2008-11-05 623912]

c:\documents and settings\Robert Jericho\Start Menu\Programs\Startup\
Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-10-19 1316192]
osd_vol.exe [2005-8-6 64512]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2010-1-24 25214]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 20:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2010-02-20 19:44 10536 ----a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\igdlogin]
2009-03-18 13:01 65536 ----a-w- c:\windows\system32\igdlogin.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Documents and Settings\\Robert Jericho\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\Robert Jericho\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Opera 10.50 Beta\\opera.exe"=

R0 EMSC;COMPAL Embedded System Control;c:\windows\system32\drivers\EMSC.sys [1/23/2010 3:52 PM 14248]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [1/5/2010 7:56 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [1/5/2010 7:56 AM 74480]
R1 sbaphd;sbaphd;c:\windows\system32\drivers\sbaphd.sys [1/24/2010 10:00 AM 13360]
R1 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [10/13/2009 8:22 AM 95024]
R1 sbtis;sbtis;c:\windows\system32\drivers\sbtis.sys [1/24/2010 9:49 AM 202928]
R2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [6/9/2009 8:11 AM 155648]
R2 sbapifs;sbapifs;c:\windows\system32\drivers\sbapifs.sys [1/24/2010 10:01 AM 69936]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\drivers\CtClsFlt.sys [1/23/2010 3:57 PM 135936]
R3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\drivers\ETD.sys [1/23/2010 2:35 PM 129024]
R3 igd;igd;c:\windows\system32\drivers\igxpmp32.sys [1/23/2010 1:04 AM 5088896]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [1/24/2010 1:42 PM 110080]
R3 OA012Afx;Provides a software interface to control audio effects of OA012 camera.;c:\windows\system32\drivers\OA012Afx.sys [1/23/2010 3:45 PM 148056]
R3 OA012Ufd;Creative Camera OA012 Upper Filter Driver;c:\windows\system32\drivers\OA012Ufd.sys [1/23/2010 3:45 PM 133472]
R3 OA012Vid;Creative Camera OA012 Function Driver;c:\windows\system32\drivers\OA012Vid.sys [1/23/2010 3:45 PM 271328]
R3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RTS5121.sys [1/23/2010 2:21 PM 157696]
S2 SBAMSvc;VIPRE Antivirus + Antispyware;c:\program files\Sunbelt Software\VIPRE\SBAMSvc.exe [1/4/2010 5:02 PM 1012080]
S3 Rts516xIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys --> c:\windows\system32\DRIVERS\Rts516xIR.sys [?]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [1/5/2010 7:56 AM 7408]
.
Contents of the 'Scheduled Tasks' folder

2010-02-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 18:34]

2010-02-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1993962763-746137067-1801674531-1003Core.job
- c:\documents and settings\Robert Jericho\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-02-11 02:47]

2010-02-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1993962763-746137067-1801674531-1003UA.job
- c:\documents and settings\Robert Jericho\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-02-11 02:47]

2010-02-23 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 21:07]
.
.
------- Supplementary Scan -------
.
uStart Page =
uInternet Settings,ProxyOverride = *.local
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
FF - ProfilePath - c:\documents and settings\Robert Jericho\Application Data\Mozilla\Firefox\Profiles\pnr3u3tv.default\
FF - component: c:\documents and settings\Robert Jericho\Application Data\Mozilla\Firefox\Profiles\pnr3u3tv.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\DictionaryCompressionFF.dll
FF - component: c:\documents and settings\Robert Jericho\Application Data\Mozilla\Firefox\Profiles\pnr3u3tv.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\documents and settings\Robert Jericho\Application Data\Mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\Robert Jericho\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Opera 10.50 Beta\program\plugins\npdsplay.dll
FF - plugin: c:\program files\Opera 10.50 Beta\program\plugins\npwmsdrm.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-23 20:35
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe catchme.sys CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys >>UNKNOWN [0x86F5D8C8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf76c1f28
\Driver\ACPI -> ACPI.sys @ 0xf7554cb8
\Driver\atapi -> atapi.sys @ 0xf74e9b3a
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
NDIS: -> SendCompleteHandler -> 0x0
PacketIndicateHandler -> 0x0
SendHandler -> 0x0
user & kernel MBR OK

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1008)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
c:\program files\Citrix\GoToAssist\514\G2AWinLogon.dll
c:\windows\System32\BCMLogon.dll

- - - - - - - > 'lsass.exe'(1064)
c:\windows\system32\relog_ap.dll

- - - - - - - > 'explorer.exe'(2952)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\program files\SUPERAntiSpyware\SASSEH.DLL
c:\program files\Acronis\TrueImageHome\tishell.dll
c:\program files\Acronis\TrueImageHome\timounter.dll
c:\program files\WinRAR\rarext.dll
c:\program files\Malwarebytes' Anti-Malware\mbamext.dll
c:\program files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
c:\program files\Mindjet\MindManager 8\Mm8InternetExplorer.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\program files\Microsoft Office\OFFICE11\msohev.dll
c:\program files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll
.
Completion time: 2010-02-23 20:38:16
ComboFix-quarantined-files.txt 2010-02-24 02:38

Pre-Run: 64,529,137,664 bytes free
Post-Run: 64,506,400,768 bytes free

- - End Of File - - 0AFA10C632BF9CEC4E82EE042E80A40D



Hijaak This Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:40:17 PM, on 2/23/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16981)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Dell\DellDock\DockLogin.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\WSED\WSED.exe
C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\PersistenceThread.exe
C:\Program Files\Mindjet\MindManager 8\MMReminderService.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Program Files\Battery Meter\BTMeter.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Documents and Settings\Robert Jericho\Start Menu\Programs\Startup\osd_vol.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: ShopSafe Browser Helper Object - {333F6B96-3992-4D58-A499-145A10FE48C3} - C:\Program Files\ShopSafe\BhoSSafe.dll
O2 - BHO: CmjBrowserHelperObject Object - {6FE6A929-59D1-4763-91AD-29B61CFFB35B} - C:\Program Files\Mindjet\MindManager 8\Mm8InternetExplorer.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [ETDWare] C:\Program Files\Elantech\ETDCtrl.exe
O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
O4 - HKLM\..\Run: [CapsLKNotify] C:\Program Files\CapsLKNotify\CapsLKNotify.exe
O4 - HKLM\..\Run: [WSED] C:\Program Files\WSED\WSED.exe
O4 - HKLM\..\Run: [Dell Webcam Central] "C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe" /mode2
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [SBAMTray] C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [PersistenceThread] C:\WINDOWS\system32\PersistenceThread.exe
O4 - HKLM\..\Run: [MMReminderService] C:\Program Files\Mindjet\MindManager 8\MMReminderService.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [BTMeter] C:\Program Files\Battery Meter\BTMeter.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Robert Jericho\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
O4 - Startup: osd_vol.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Send to Mindjet MindManager - {2F72393D-2472-4F82-B600-ED77F354B7FF} - C:\Program Files\Mindjet\MindManager 8\Mm8InternetExplorer.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/s ... wflash.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O20 - Winlogon Notify: igdlogin - C:\WINDOWS\SYSTEM32\igdlogin.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: VIPRE Antivirus + Antispyware (SBAMSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe
O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

--
End of file - 10398 bytes
rjj76
Regular Member
 
Posts: 16
Joined: February 15th, 2010, 4:56 pm

Re: Search Redirect Malware

Unread postby muppy03 » February 24th, 2010, 4:40 am

TDSSKiller

  • Please Download TDSSKiller.zip and save it on your desktop.
  • Next extract (unzip) its contents to your Desktop.
  • Next double-click the TDSSKiller Folder on your desktop.
  • Next right-click on TDSSKiller.exe and click Copy then Paste it directly on to your Desktop.<---Important
  • Next Highlight and copy all the text (including the quote marks) in the codebox below.
    Code: Select all
    "%userprofile%\desktop\tdsskiller.exe" -l "%userprofile%\desktop\tdsskiller.txt"
  • Click Start, click Run... and paste the text above into the Open: line and click OK.
  • If malicious services or files have been detected, the utility will prompt to reboot the PC in order to complete the disinfection procedure. Please reboot when prompted.
  • After reboot, the driver will delete malicious registry keys and files as well as remove itself from the services list.
  • When finished a log file should be created on your desktop named tdsskiller.txt
  • Copy the contents of the log & post in your next reply.

RootRepeal
Download RootRepeal.zip from here & unzip it to your Desktop.
  • Double click RootRepeal.exe to start the program
  • Click the Report tab at the bottom of the program window
  • Click the Scan button
  • In the Select Scan dialog, check:
      Drivers
      Files
      Processes
      SSDT
      Stealth Objects
      Hidden Services
  • Click the OK button
  • In the next dialog, select all drives showing
  • Click OK to start the scan
Note: The scan can take some time. DO NOT run any other programs while the scan is running
  • When the scan is complete, the Save Report button will become available
  • Click this and save the report to your Desktop as RootRepeal.txt
  • Go to File then Exit to close the program

Please reply with:-
  • TDSS killer log
  • Root repeal log
  • New HJT log
  • Update on redirects
User avatar
muppy03
MRU Emeritus
MRU Emeritus
 
Posts: 4782
Joined: December 4th, 2007, 5:30 am
Location: Australia

Re: Search Redirect Malware

Unread postby rjj76 » February 24th, 2010, 10:45 pm

20:21:15:500 2764 TDSS rootkit removing tool 2.2.6 Feb 21 2010 21:24:13
20:21:15:500 2764 ================================================================================
20:21:15:500 2764 SystemInfo:

20:21:15:500 2764 OS Version: 5.1.2600 ServicePack: 3.0
20:21:15:500 2764 Product type: Workstation
20:21:15:500 2764 ComputerName: MINI10
20:21:15:500 2764 UserName: Robert Jericho
20:21:15:500 2764 Windows directory: C:\WINDOWS
20:21:15:500 2764 Processor architecture: Intel x86
20:21:15:500 2764 Number of processors: 2
20:21:15:500 2764 Page size: 0x1000
20:21:15:500 2764 Boot type: Normal boot
20:21:15:500 2764 ================================================================================
20:21:15:515 2764 UnloadDriverW: NtUnloadDriver error 1
20:21:15:515 2764 ForceUnloadDriverW: UnloadDriverW(klmd21) error 1
20:21:15:546 2764 LoadDriverW: Driver already loaded
20:21:15:546 2764 KLMD_DropNLoadW: LoadDriverW(klmd21) error 1056
20:21:15:546 2764 Initialize success
20:21:15:546 2764
20:21:15:546 2764 Scanning Services ...
20:21:15:546 2764 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\system
20:21:15:546 2764 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
20:21:15:546 2764 wfopen_ex: Trying to KLMD file open
20:21:15:546 2764 wfopen_ex: File opened ok (Flags 2)
20:21:15:546 2764 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\software
20:21:15:562 2764 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
20:21:15:562 2764 wfopen_ex: Trying to KLMD file open
20:21:15:562 2764 wfopen_ex: File opened ok (Flags 2)
20:21:16:046 2764 GetAdvancedServicesInfo: Raw services enum returned 356 services
20:21:16:046 2764 fclose_ex: Trying to close file C:\WINDOWS\system32\config\system
20:21:16:046 2764 fclose_ex: Trying to close file C:\WINDOWS\system32\config\software
20:21:16:046 2764
20:21:16:046 2764 Scanning Kernel memory ...
20:21:16:046 2764 Devices to scan: 3
20:21:16:046 2764
20:21:16:046 2764 Driver Name: Disk
20:21:16:046 2764 IRP_MJ_CREATE : F76C3BB0
20:21:16:046 2764 IRP_MJ_CREATE_NAMED_PIPE : 804F4562
20:21:16:046 2764 IRP_MJ_CLOSE : F76C3BB0
20:21:16:046 2764 IRP_MJ_READ : F76BDD1F
20:21:16:046 2764 IRP_MJ_WRITE : F76BDD1F
20:21:16:046 2764 IRP_MJ_QUERY_INFORMATION : 804F4562
20:21:16:062 2764 IRP_MJ_SET_INFORMATION : 804F4562
20:21:16:062 2764 IRP_MJ_QUERY_EA : 804F4562
20:21:16:062 2764 IRP_MJ_SET_EA : 804F4562
20:21:16:062 2764 IRP_MJ_FLUSH_BUFFERS : F76BE2E2
20:21:16:062 2764 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4562
20:21:16:062 2764 IRP_MJ_SET_VOLUME_INFORMATION : 804F4562
20:21:16:062 2764 IRP_MJ_DIRECTORY_CONTROL : 804F4562
20:21:16:062 2764 IRP_MJ_FILE_SYSTEM_CONTROL : 804F4562
20:21:16:062 2764 IRP_MJ_DEVICE_CONTROL : F76BE3BB
20:21:16:062 2764 IRP_MJ_INTERNAL_DEVICE_CONTROL : F76C1F28
20:21:16:062 2764 IRP_MJ_SHUTDOWN : F76BE2E2
20:21:16:062 2764 IRP_MJ_LOCK_CONTROL : 804F4562
20:21:16:062 2764 IRP_MJ_CLEANUP : 804F4562
20:21:16:062 2764 IRP_MJ_CREATE_MAILSLOT : 804F4562
20:21:16:062 2764 IRP_MJ_QUERY_SECURITY : 804F4562
20:21:16:062 2764 IRP_MJ_SET_SECURITY : 804F4562
20:21:16:062 2764 IRP_MJ_POWER : F76BFC82
20:21:16:062 2764 IRP_MJ_SYSTEM_CONTROL : F76C499E
20:21:16:062 2764 IRP_MJ_DEVICE_CHANGE : 804F4562
20:21:16:062 2764 IRP_MJ_QUERY_QUOTA : 804F4562
20:21:16:062 2764 IRP_MJ_SET_QUOTA : 804F4562
20:21:16:062 2764 sion
20:21:16:078 2764 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
20:21:16:078 2764
20:21:16:078 2764 Driver Name: Disk
20:21:16:078 2764 IRP_MJ_CREATE : F76C3BB0
20:21:16:078 2764 IRP_MJ_CREATE_NAMED_PIPE : 804F4562
20:21:16:078 2764 IRP_MJ_CLOSE : F76C3BB0
20:21:16:078 2764 IRP_MJ_READ : F76BDD1F
20:21:16:078 2764 IRP_MJ_WRITE : F76BDD1F
20:21:16:078 2764 IRP_MJ_QUERY_INFORMATION : 804F4562
20:21:16:078 2764 IRP_MJ_SET_INFORMATION : 804F4562
20:21:16:078 2764 IRP_MJ_QUERY_EA : 804F4562
20:21:16:078 2764 IRP_MJ_SET_EA : 804F4562
20:21:16:078 2764 IRP_MJ_FLUSH_BUFFERS : F76BE2E2
20:21:16:078 2764 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4562
20:21:16:078 2764 IRP_MJ_SET_VOLUME_INFORMATION : 804F4562
20:21:16:078 2764 IRP_MJ_DIRECTORY_CONTROL : 804F4562
20:21:16:078 2764 IRP_MJ_FILE_SYSTEM_CONTROL : 804F4562
20:21:16:078 2764 IRP_MJ_DEVICE_CONTROL : F76BE3BB
20:21:16:078 2764 IRP_MJ_INTERNAL_DEVICE_CONTROL : F76C1F28
20:21:16:078 2764 IRP_MJ_SHUTDOWN : F76BE2E2
20:21:16:078 2764 IRP_MJ_LOCK_CONTROL : 804F4562
20:21:16:078 2764 IRP_MJ_CLEANUP : 804F4562
20:21:16:078 2764 IRP_MJ_CREATE_MAILSLOT : 804F4562
20:21:16:078 2764 IRP_MJ_QUERY_SECURITY : 804F4562
20:21:16:078 2764 IRP_MJ_SET_SECURITY : 804F4562
20:21:16:078 2764 IRP_MJ_POWER : F76BFC82
20:21:16:078 2764 IRP_MJ_SYSTEM_CONTROL : F76C499E
20:21:16:078 2764 IRP_MJ_DEVICE_CHANGE : 804F4562
20:21:16:078 2764 IRP_MJ_QUERY_QUOTA : 804F4562
20:21:16:078 2764 IRP_MJ_SET_QUOTA : 804F4562
20:21:16:078 2764 sion
20:21:16:093 2764 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
20:21:16:093 2764
20:21:16:093 2764 Driver Name: atapi
20:21:16:093 2764 IRP_MJ_CREATE : F74E9B3A
20:21:16:093 2764 IRP_MJ_CREATE_NAMED_PIPE : F74E9B3A
20:21:16:093 2764 IRP_MJ_CLOSE : F74E9B3A
20:21:16:093 2764 IRP_MJ_READ : F74E9B3A
20:21:16:093 2764 IRP_MJ_WRITE : F74E9B3A
20:21:16:093 2764 IRP_MJ_QUERY_INFORMATION : F74E9B3A
20:21:16:093 2764 IRP_MJ_SET_INFORMATION : F74E9B3A
20:21:16:093 2764 IRP_MJ_QUERY_EA : F74E9B3A
20:21:16:093 2764 IRP_MJ_SET_EA : F74E9B3A
20:21:16:093 2764 IRP_MJ_FLUSH_BUFFERS : F74E9B3A
20:21:16:093 2764 IRP_MJ_QUERY_VOLUME_INFORMATION : F74E9B3A
20:21:16:093 2764 IRP_MJ_SET_VOLUME_INFORMATION : F74E9B3A
20:21:16:093 2764 IRP_MJ_DIRECTORY_CONTROL : F74E9B3A
20:21:16:093 2764 IRP_MJ_FILE_SYSTEM_CONTROL : F74E9B3A
20:21:16:093 2764 IRP_MJ_DEVICE_CONTROL : F74E9B3A
20:21:16:093 2764 IRP_MJ_INTERNAL_DEVICE_CONTROL : F74E9B3A
20:21:16:093 2764 IRP_MJ_SHUTDOWN : F74E9B3A
20:21:16:093 2764 IRP_MJ_LOCK_CONTROL : F74E9B3A
20:21:16:093 2764 IRP_MJ_CLEANUP : F74E9B3A
20:21:16:093 2764 IRP_MJ_CREATE_MAILSLOT : F74E9B3A
20:21:16:093 2764 IRP_MJ_QUERY_SECURITY : F74E9B3A
20:21:16:093 2764 IRP_MJ_SET_SECURITY : F74E9B3A
20:21:16:093 2764 IRP_MJ_POWER : F74E9B3A
20:21:16:093 2764 IRP_MJ_SYSTEM_CONTROL : F74E9B3A
20:21:16:093 2764 IRP_MJ_DEVICE_CHANGE : F74E9B3A
20:21:16:093 2764 IRP_MJ_QUERY_QUOTA : F74E9B3A
20:21:16:093 2764 IRP_MJ_SET_QUOTA : F74E9B3A
20:21:16:093 2764 TDL3_IrpHookDetect: TDL3 Stub signature found, trying to get hook true addr
20:21:16:093 2764 TDL3_IrpHookDetect: New IrpHandler addr: 86F358C8
20:21:16:093 2764 TDL3_IrpHookDetect: TDL3 is already cured
20:21:16:093 2764 siohd: 0
20:21:16:140 2764 C:\WINDOWS\system32\drivers\tskCD.tmp - Verdict: Clean
20:21:16:140 2764
20:21:16:140 2764 Completed
20:21:16:140 2764
20:21:16:140 2764 Results:
20:21:16:140 2764 Memory objects infected / cured / cured on reboot: 0 / 0 / 0
20:21:16:140 2764 Registry objects infected / cured / cured on reboot: 0 / 0 / 0
20:21:16:140 2764 File objects infected / cured / cured on reboot: 0 / 0 / 0
20:21:16:140 2764
20:21:16:140 2764 UnloadDriverW: NtUnloadDriver error 1
20:21:16:140 2764 KLMD_Unload: UnloadDriverW(klmd21) error 1
20:21:16:156 2764 KLMD(ARK) unloaded successfully



ROOTREPEAL (c) AD, 2007-2009
==================================================
Scan Start Time: 2010/02/24 20:28
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================

Drivers
-------------------
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xF5818000 Size: 98304 File Visible: No Signed: -
Status: -

Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF7C01000 Size: 8192 File Visible: No Signed: -
Status: -

Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xEBA86000 Size: 49152 File Visible: No Signed: -
Status: -

Hidden/Locked Files
-------------------
Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Interop.IWshRuntimeLibrary.cdf-ms
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Interop.IWshRuntimeLibrary.manifest
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\stdole.cdf-ms
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\stdole.manifest
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Xceed.Compression.cdf-ms
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Xceed.Compression.manifest
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\DellDriverDownloadManager.exe.cdf-ms
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\DellDriverDownloadManager.exe.manifest
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\DellDriverDownloadManager.cdf-ms
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\DellDriverDownloadManager.manifest
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Core.cdf-ms
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Core.manifest
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.ISOImage.cdf-ms
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.ISOImage.manifest
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.cdf-ms
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Robert Jericho\Local Settings\Apps\2.0\8BQ3Z9AV.MBD\ACQQCCGG.APT\manifests\Dell.eSupport.DownloadManager.Localization.manifest
Status: Locked to the Windows API!

SSDT
-------------------
#: 041 Function Name: NtCreateKey
Status: Hooked by "C:\WINDOWS\system32\drivers\sbaphd.sys" at address 0xf7bc74d0

#: 247 Function Name: NtSetValueKey
Status: Hooked by "C:\WINDOWS\system32\drivers\sbaphd.sys" at address 0xf7bc7520

==EOF==


HijackThis Log - -

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:40:10 PM, on 2/24/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16981)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Dell\DellDock\DockLogin.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Dell\DellDock\DellDock.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Elantech\ETDCtrl.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\CapsLKNotify\CapsLKNotify.exe
C:\Program Files\WSED\WSED.exe
C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\PersistenceThread.exe
C:\Program Files\Mindjet\MindManager 8\MMReminderService.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Battery Meter\BTMeter.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Documents and Settings\Robert Jericho\Start Menu\Programs\Startup\osd_vol.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: ShopSafe Browser Helper Object - {333F6B96-3992-4D58-A499-145A10FE48C3} - C:\Program Files\ShopSafe\BhoSSafe.dll
O2 - BHO: CmjBrowserHelperObject Object - {6FE6A929-59D1-4763-91AD-29B61CFFB35B} - C:\Program Files\Mindjet\MindManager 8\Mm8InternetExplorer.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [ETDWare] C:\Program Files\Elantech\ETDCtrl.exe
O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
O4 - HKLM\..\Run: [CapsLKNotify] C:\Program Files\CapsLKNotify\CapsLKNotify.exe
O4 - HKLM\..\Run: [WSED] C:\Program Files\WSED\WSED.exe
O4 - HKLM\..\Run: [Dell Webcam Central] "C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe" /mode2
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [SBAMTray] C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [PersistenceThread] C:\WINDOWS\system32\PersistenceThread.exe
O4 - HKLM\..\Run: [MMReminderService] C:\Program Files\Mindjet\MindManager 8\MMReminderService.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [BTMeter] C:\Program Files\Battery Meter\BTMeter.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Robert Jericho\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
O4 - Startup: osd_vol.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Send to Mindjet MindManager - {2F72393D-2472-4F82-B600-ED77F354B7FF} - C:\Program Files\Mindjet\MindManager 8\Mm8InternetExplorer.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/s ... wflash.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O20 - Winlogon Notify: igdlogin - C:\WINDOWS\SYSTEM32\igdlogin.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: VIPRE Antivirus + Antispyware (SBAMSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe
O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

--
End of file - 10594 bytes



It appears that you've got it whipped!

Thank you so much - anything else that you see in the logs?
rjj76
Regular Member
 
Posts: 16
Joined: February 15th, 2010, 4:56 pm

Re: Search Redirect Malware

Unread postby muppy03 » February 25th, 2010, 3:39 am

It appears that you've got it whipped!

Phew he was a pesky [insert appropriate word] :D .

You have the latest Java on board = Java(TM) 6 Update 18
You can uninstall the others:-

Java DB 10.5.3.0
Java(TM) SE Development Kit 6 Update 18


This next step is your choice. The below items I am getting you to fix with HJT are for programs that do not need to start up when you turn your computer on. Doing the below step WILL NOT UNINSTALL these programs ONLY stop them from running at startup. All will be available when you need them. The bonus is it will make your startup time a bit shorter

Open Hijack This and select Do a System Scan Only place a check next to the below lines if still present

    O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
    O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
    O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?


Once selected close all windows except HJT an click on Fix Checked

You also have a few others that could probably be stopped but they are deemed “users choice’, so you will have to investigate and see what you want stopped.

At this stage it is also beneficial to run an online scan. Be warned it will take ages.

Kaspersky Online Scan
Do an online scan with >Kaspersky Online Scanner<
  • Read through the requirements and privacy statement and click on Accept button
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run
  • When the downloads have finished, click on Settings
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
      Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan
  • Once the scan is complete, it will display the results. Click on View Scan Report
  • You will see a list of infected items there. Click on Save Report As...
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button
  • Please post this log in your next reply

Please reply with:-
  • Kaspersky log
  • New HJT log
User avatar
muppy03
MRU Emeritus
MRU Emeritus
 
Posts: 4782
Joined: December 4th, 2007, 5:30 am
Location: Australia

Re: Search Redirect Malware

Unread postby rjj76 » February 27th, 2010, 9:08 am

Kapersky was a little stubborn when I ran it the first time - computer didn't want to come off of the dark screen.

Here's the log -

--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0: scan report
Saturday, February 27, 2010
Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Friday, February 26, 2010 22:30:38
Records in database: 3654551
--------------------------------------------------------------------------------

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
C:\

Scan statistics:
Objects scanned: 63105
Threats found: 1
Infected objects found: 1
Suspicious objects found: 0
Scan duration: 06:15:29


File name / Threat / Threats count
C:\WINDOWS\system32\drivers\atapi.sys Infected: Rootkit.Win32.TDSS.u 1

Selected area has been scanned.



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:05:54 AM, on 2/27/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16981)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Dell\DellDock\DockLogin.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Dell\DellDock\DellDock.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Elantech\ETDCtrl.exe
C:\Program Files\CapsLKNotify\CapsLKNotify.exe
C:\Program Files\WSED\WSED.exe
C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\PersistenceThread.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Mindjet\MindManager 8\MMReminderService.exe
C:\Program Files\Battery Meter\BTMeter.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Robert Jericho\Start Menu\Programs\Startup\osd_vol.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: ShopSafe Browser Helper Object - {333F6B96-3992-4D58-A499-145A10FE48C3} - C:\Program Files\ShopSafe\BhoSSafe.dll
O2 - BHO: CmjBrowserHelperObject Object - {6FE6A929-59D1-4763-91AD-29B61CFFB35B} - C:\Program Files\Mindjet\MindManager 8\Mm8InternetExplorer.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [ETDWare] C:\Program Files\Elantech\ETDCtrl.exe
O4 - HKLM\..\Run: [CapsLKNotify] C:\Program Files\CapsLKNotify\CapsLKNotify.exe
O4 - HKLM\..\Run: [WSED] C:\Program Files\WSED\WSED.exe
O4 - HKLM\..\Run: [Dell Webcam Central] "C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe" /mode2
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [SBAMTray] C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [PersistenceThread] C:\WINDOWS\system32\PersistenceThread.exe
O4 - HKLM\..\Run: [MMReminderService] C:\Program Files\Mindjet\MindManager 8\MMReminderService.exe
O4 - HKLM\..\Run: [BTMeter] C:\Program Files\Battery Meter\BTMeter.exe
O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Robert Jericho\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
O4 - Startup: osd_vol.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Send to Mindjet MindManager - {2F72393D-2472-4F82-B600-ED77F354B7FF} - C:\Program Files\Mindjet\MindManager 8\Mm8InternetExplorer.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/s ... wflash.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O20 - Winlogon Notify: igdlogin - C:\WINDOWS\SYSTEM32\igdlogin.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: VIPRE Antivirus + Antispyware (SBAMSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe
O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

--
End of file - 10061 bytes


Looks like we've isolated the file at least.
rjj76
Regular Member
 
Posts: 16
Joined: February 15th, 2010, 4:56 pm

Re: Search Redirect Malware

Unread postby muppy03 » February 27th, 2010, 7:26 pm

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    Code: Select all
    :filefind
    atapi* 

  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
User avatar
muppy03
MRU Emeritus
MRU Emeritus
 
Posts: 4782
Joined: December 4th, 2007, 5:30 am
Location: Australia
Advertisement
Register to Remove

Next

  • Similar Topics
    Replies
    Views
    Last post

Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: No registered users and 19 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware